A large decentralised lending protocol was exploited in July 2026, with on-chain forensics firms estimating losses of roughly $120 million. The attacker used a price-oracle manipulation technique against a thinly traded collateral market to borrow against inflated collateral and drain reserves.
The protocol paused new borrows within minutes and offered a whitehat bounty of up to 10 percent of returned funds. Cross-chain bridges froze the attacker's outbound liquidity on two of three exit routes.
The oracle problem, again
Oracle-manipulation exploits have accounted for a persistent share of DeFi losses since 2020. The incident is likely to accelerate migration toward multi-source oracle designs and tighter listing standards for collateral assets, and it will feature in coming regulatory debates about DeFi risk disclosure.
The recurring failure mode
Most losses in this category are not novel cryptography failures. They are oracle assumptions, upgrade keys and rushed integrations, all of which are governance problems dressed as technical ones.
Protocols that publish incident timelines and reimbursement decisions in full recover trust faster than those that issue a statement and move on. That difference is now visible in deposit flows.



