// security reports

Incident Reports

Deep-dive analysis of DeFi exploits, vulnerabilities, and security incidents.Learn from real-world attacks.

July 2026

Guru.fund $96K Vault Approval Exploit
ethereumJuly 24, 2026-$96K

Guru.fund $96K Vault Approval Exploit

Guru.fund, a delegated fund-management protocol on Ethereum, lost about $96K across seven transactions when a whitelisted deposit adapter let attackers make each vault approve and drain itself.

Read the full analysis →
Verus Bridge $7.54M Forged Import Exploit
ethereumJuly 23, 2026-$7.54M

Verus Bridge $7.54M Forged Import Exploit

The Verus-Ethereum bridge was drained of $7.54M via a forged cross-chain import on July 23, 2026, two weeks after it refilled reserves recovered from May's $11.58M hack of the same import path.

Read the full analysis →
DeFi Security Monitoring Tools Compared (2026)
guideJuly 21, 2026

DeFi Security Monitoring Tools Compared (2026)

How real-time DeFi security monitoring tools compare in 2026: enterprise platforms (Hypernative, Hexagate), inline firewalls (Forta Firewall, BlockSec), and self-serve machine-readable feeds (Defimon), by approach, coverage, integration, and pricing.

Read the full analysis →
Automating DeFi Incident Response with a WebSocket Exploit Feed
guideJuly 16, 2026

Automating DeFi Incident Response with a WebSocket Exploit Feed

A production integration guide for the Defimon WebSocket feed: raw vs confirmed streams, reconnect handling, filtering alerts against your contracts and exposure, and what to automate versus page a human for.

Read the full analysis →
Ostium $23.75M Oracle Manipulation Exploit
arbitrumJuly 15, 2026-$23.75M

Ostium $23.75M Oracle Manipulation Exploit

Ostium, a perpetuals DEX on Arbitrum, lost $23.75M when an attacker with price-submission authority opened BTC longs at $5,000 and closed them near $60,000, draining the vault that backs every trade.

Read the full analysis →
Bridge Exploits Explained: Why Cross-Chain Is DeFi's Weakest Link
guideJuly 15, 2026

Bridge Exploits Explained: Why Cross-Chain Is DeFi's Weakest Link

How cross-chain bridges get drained: validator key compromise, message verification bugs, false deposit events and custody failure, from Ronin and Wormhole to Shibarium and KelpDAO.

Read the full analysis →
Oracle Manipulation Attacks in DeFi: How Price Oracles Get Exploited
guideJuly 15, 2026

Oracle Manipulation Attacks in DeFi: How Price Oracles Get Exploited

How DeFi price oracles get manipulated: spot-reserve pricing, missing update authorization, stale feeds and donation attacks, with real incidents and the on-chain patterns that expose them in real time.

Read the full analysis →
Flash Loan Attacks Explained: How They Work and How to Detect Them
guideJuly 15, 2026

Flash Loan Attacks Explained: How They Work and How to Detect Them

What flash loan attacks are, why the loan itself is never the vulnerability, and how exploits that borrow nine figures with zero collateral are detected on-chain within a second.

Read the full analysis →

Put the feed in your stack

Connect in minutes. Every attack across major chains, as JSON, in under a second.

@DefimonAlerts

© 2026 Defimon by Decurity

Powered by QuickNode