The DGLD Cross-Chain Minting Exploit: How an OP Stack Bridge Vulnerability Let Attackers Print Gold-Backed Tokens From NothingMar 30, 2026·8 min read
The Private Key Epidemic: Why Q1 2026's Three Biggest DeFi Hacks ($100M+) All Bypassed Audited Smart ContractsMar 30, 2026·3 min read
Aderyn vs Slither in 2026: The Rust-vs-Python Static Analysis Showdown That Decides Your CI/CD Pipeline's FutureEvery Solidity auditor's CI pipeline runs Slither. It's been the default since 2019 — Trail of Bits built it, the community adopted it, and 92+ detectors later, it's the static analysis tool most developers never think to question. Then Cyfrin shippe...Mar 30, 2026·5 min read
The AI Audit Pipeline: How ItyFuzz, Certora AI Composer, and Medusa ML Are Making Manual Invariant Discovery ObsoleteMar 30, 2026·8 min read
The $679K BCE Burn Exploit: How a Defective Burn Mechanism Drained a PancakeSwap PoolMar 30, 2026·3 min read
Read-Only Reentrancy: The Silent Price Oracle Killer Every DeFi Protocol Still Gets WrongTraditional reentrancy has a signature that every auditor can spot — a state change after an external call. But read-only reentrancy hides in plain sight: it targets view functions that return stale data during an ongoing callback, poisoning every pr...Mar 30, 2026·4 min read
The $58K ACPRoute Exploit: How a Single `memory` Keyword Let an Attacker Double-Claim Every Escrow on an AI Agent Commerce ProtocolThe $58K ACPRoute Exploit: How a Single memory Keyword Let an Attacker Double-Claim Every Escrow on an AI Agent Commerce Protocol On March 2, 2026, an attacker drained ~$58,000 from the ACPRoute protocol on Base by calling claimBudget() after escrow ...Mar 29, 2026·7 min read
The $40M Step Finance Kill: How Compromised Executive Devices Bypassed Every On-Chain DefenseOn January 31, 2026, Step Finance — one of Solana's most established DeFi analytics platforms — watched helplessly as 261,854 SOL walked out of its treasury wallets during APAC trading hours. Not through a flash loan. Not through a reentrancy bug. Th...Mar 29, 2026·8 min read
The $7M SagaEVM Precompile Exploit: How a Cross-Chain Validation Bypass Minted Stablecoins From Thin AirOn January 21, 2026, an attacker drained $7 million from SagaEVM — a gasless EVM chainlet in the Saga ecosystem — by crafting transactions that tricked the protocol into minting uncollateralized stablecoins. The Saga Dollar (DUSD) depegged to $0.75, ...Mar 29, 2026·8 min read
The $26M Configuration Error: How Aave's CAPO Oracle Misfired — And 5 Oracle Hardening Patterns Every DeFi Protocol NeedsOn March 10, 2026, Aave — the largest decentralized lending protocol by TVL — saw $26 million in automated liquidations fire across 34 user accounts. No hacker was involved. No smart contract was exploited. A single configuration mismatch in the Corr...Mar 29, 2026·7 min read
The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — TwiceOn March 15, 2026, Venus Protocol on BNB Chain was hit by an exploit that left it with $2.15 million in bad debt. The attack targeted the THENA (THE) token market using a donation attack — a vulnerability class so well-known it was literally flagged ...Mar 28, 2026·3 min read