# Defimon > Defimon is a real-time DeFi exploit detection feed. It detects on-chain attacks across major chains and streams them as structured JSON over WebSocket — a raw, sub-second feed and an LLM-confirmed feed — each payload enriched with the victim protocol, TVL, and per-address USD balance changes. Built by the security team at Decurity. Free public Telegram alerts, a $50/mo Signals channel, and a $200/mo machine-readable WebSocket feed. ## Product - [Defimon home](https://defimon.xyz/): What the feed is, how it works, live sample payloads, pricing. - [Subscribe](https://defimon.xyz/subscribe): Self-serve crypto checkout for the $200/mo WebSocket feed and the $50/mo Signals channel. - [Docs: websocket attack message](https://defimon.xyz/docs/websocket_attack_message.md): Reference documentation (Markdown). ## Security guides - [Top 10 DeFi Hacks of 2026 (So Far)](https://defimon.xyz/blog/top-10-defi-hacks-2026.md): The 10 biggest DeFi hacks of 2026 ranked: KelpDAO $292M, Drift $285M, Truebit, Resolv, Ostium and more, with the root cause of each and $1B+ lost in H1. - [DeFi Security Monitoring Tools Compared (2026)](https://defimon.xyz/blog/defi-security-monitoring-tools-compared.md): Hypernative, Chainalysis Hexagate, Forta, BlockSec and Defimon compared by detection approach, chain coverage, integration and the axis vendors hide: pricing. - [Automating DeFi Incident Response with a WebSocket Exploit Feed](https://defimon.xyz/blog/automating-defi-incident-response.md): Wire a real-time exploit feed into incident response: raw vs confirmed streams, reconnect handling, filtering by your own contracts, and what to auto-pause. - [Bridge Exploits Explained: Why Cross-Chain Is DeFi's Weakest Link](https://defimon.xyz/blog/bridge-exploits-explained.md): The four ways cross-chain bridges get hacked: validator compromise, message verification bugs, false deposits and custody failure, from Ronin to 2026. - [Oracle Manipulation Attacks in DeFi: How Price Oracles Get Exploited](https://defimon.xyz/blog/oracle-manipulation-attacks-defi.md): Ostium lost $23.75M to a manipulated settlement price. How oracle attacks work: spot-reserve pumps, rogue updates, stale feeds, and the fixes that hold. - [Flash Loan Attacks Explained: How They Work and How to Detect Them](https://defimon.xyz/blog/flash-loan-attacks-explained.md): How flash loan attacks work and the risks they pose: $211M borrowed from Morpho and Venus with zero collateral, and how the pattern is caught in a second. ## Incident reports - [Coldcard $88.6M Seed Entropy Exploit](https://defimon.xyz/blog/coldcard-hack-july-2026.md): A March 2021 build error made Coldcard seeds fall back to a weak PRNG with 40 bits of entropy. Attackers brute-forced keys offline and swept $88.6M in BTC. - [Guru.fund $96K Vault Approval Exploit](https://defimon.xyz/blog/guru-fund-hack-july-2026.md): How a whitelisted adapter in Guru.fund's shared deposit path let attackers make each vault approve and drain itself: about $96K across eight funds. - [Verus Bridge $7.54M Forged Import Exploit](https://defimon.xyz/blog/verus-bridge-hack-july-2026.md): The Verus-Ethereum bridge lost $7.54M on July 23, 2026, to a forged cross-chain import, two weeks after refilling reserves recovered from May's $11.58M hack. - [Ostium $23.75M Oracle Manipulation Exploit](https://defimon.xyz/blog/ostium-hack-july-2026.md): How an attacker opened BTC longs at $5,000 and closed near $60,000 to drain $23.75M from Ostium on Arbitrum, whose oracle trusted whoever submitted the price. - [Foom.cash $1.84M Whitehat Rescue: Groth16 Trusted Setup Exploit](https://defimon.xyz/blog/foom-cash-whitehat-rescue-february-2026.md): Foom.cash shipped a Groth16 verifier with an unfinished trusted setup, making every withdrawal proof forgeable. Defimon rescued $1.84M before an attacker could. - [Yearn yETH $9M Numerical Solver Exploit](https://defimon.xyz/blog/yearn-yeth-hack-november-2025.md): How Yearn's yETH pool lost $9M: numerical instability in its fixed-point solver collapsed the invariant to a constant-sum curve, letting the attacker over-mint. - [Balancer V2 $128M Rounding Exploit](https://defimon.xyz/blog/balancer-v2-hack-november-2025.md): How a rounding inconsistency in Balancer V2's rate scaling, live since 2021, deflated the pool invariant and cost Composable Stable Pools $128M on 9 chains. - [Typus Finance $3.44M Oracle Manipulation Attack](https://defimon.xyz/blog/typus-finance-hack-october-2025.md): How Typus Finance lost $3.44M on Sui: a missing authorization check in its custom oracle module let the attacker set any price and drain the TLP pool. - [Abracadabra Money $1.8M Exploit - Logic Flaw Bypasses Solvency](https://defimon.xyz/blog/abracadabra-hack-october-2025.md): Abracadabra Money's third exploit in two years. Logic flaw in CauldronV4 contracts allowed $1.8M unbacked MIM borrowing via status flag reset. - [NewGold Protocol $2M Flash Loan Attack - Triple Vulnerability Exploit](https://defimon.xyz/blog/newgold-protocol-hack-september-2025.md): NewGold Protocol lost $2M through flash loan manipulation exploiting broken price oracle, faulty fee logic, and whitelisted dead address bypass. - [Shibarium $3M Validator Compromise and Flash Loan Bridge Exploit](https://defimon.xyz/blog/shibarium-hack-september-2025.md): How Shibarium's bridge lost $3M: a 4.6M BONE flash loan plus 10 of 12 compromised validator keys let the attacker sign fraudulent checkpoints and drain it.