A large decentralised lending protocol was exploited in July 2026, with on-chain forensics firms estimating losses of roughly $120 million. The attacker used a price-oracle manipulation technique against a thinly traded collateral market to borrow against inflated collateral and drain reserves.
The protocol paused new borrows within minutes and offered a whitehat bounty of up to 10 percent of returned funds. Cross-chain bridges froze the attacker's outbound liquidity on two of three exit routes.
The oracle problem, again
Oracle-manipulation exploits have accounted for a persistent share of DeFi losses since 2020. The incident is likely to accelerate migration toward multi-source oracle designs and tighter listing standards for collateral assets, and it will feature in coming regulatory debates about DeFi risk disclosure.
