Live desk/
CriticalSecurity

A large DeFi lending protocol suffers an oracle-manipulation exploit, with roughly $120 million drained

The incident is a fresh reminder that on-chain lending markets remain exposed to price-oracle attacks even as institutional adoption of DeFi accelerates.

Hiroshi Tanaka3 min read
Broken padlock over a DeFi protocol network with red warning glow, representing an on-chain exploit

A large decentralised lending protocol was exploited in July 2026, with on-chain forensics firms estimating losses of roughly $120 million. The attacker used a price-oracle manipulation technique against a thinly traded collateral market to borrow against inflated collateral and drain reserves.

The protocol paused new borrows within minutes and offered a whitehat bounty of up to 10 percent of returned funds. Cross-chain bridges froze the attacker's outbound liquidity on two of three exit routes.

The oracle problem, again

Oracle-manipulation exploits have accounted for a persistent share of DeFi losses since 2020. The incident is likely to accelerate migration toward multi-source oracle designs and tighter listing standards for collateral assets, and it will feature in coming regulatory debates about DeFi risk disclosure.

Sources & references

Hiroshi Tanaka
Security & On-Chain Forensics

More from CryptoxInsights