đš BLOCKCHAIN HACKS: WEEKLY RECAP đš
Over $12M was drained this week. Again.
Same bugs, same failures, same headlines.
Here are the Top 10 recurring attack vectors we still havenât learned from, and what made @Corkprotocol the hack-of-the-week. đ§”
1/ The @Corkprotocol exploit wasnât fancy.
Just a classic kill chain featuring:
đ Insufficient function access control
đŻ Price oracle manipulation
đ° Reward manipulation
Thatâs 3 textbook bugs, and $12M gone.
These arenât zero-days.
These are known, avoidable, and documented.
We still think âsmart contract auditâ = security.
Spoiler: it doesnât.
Letâs talk about Reward Manipulation.
Itâs when an attacker extracts fees/yield/emissions without risk or real value. Your protocol gets farmed. You lose.
đ„ See:
Abracadabra ($13M)
@picklefinance ($19.7M)
@eulerfinance ($197M)
Then thereâs the Price Oracle Manipulation playbook.
Still works in 2025. Still wrecking DeFi.
If your oracle relies on thin liquidity, youâve already lost.
@chainlink isnât immune either (see deUSDâs $500K liquidation this week)
Access Control Failures
One of the most boring, basic, and frequent failures.
Missing onlyOwner, unchecked function calls, role mismanagement.
and welcome back, Integer Overflow.
Yes, the bug we thought we left in 2018 is back thanks to @CetusProtocol on @SuiNetwork.
$260M, gone. Because someone didnât check their math.
New entry on the leaderboard: Supply Chain Attacks
Think Web2 vibes:
- Infected NPM packages
- compromised build tools
- CI/CD pipeline exploits
DevSecOps isnât optional anymore. Audit your whole stack or enjoy the rug.
Security isnât just on-chain.
Itâs your endpoint.
Itâs your infra.
Itâs your key management.
Stolen private keys still lead the charts. And no audit can save you from sloppy ops.
Blockchains arenât broken. We are.
Every week, the same bugs. The same losses. The same post-mortems.
Rug season ends when the space grows up.
đ§ Want more threads on DeFi exploits, smart contract risk, and blockchain security trends?
đ Follow @maikaisogawa for more
1
10.17K
The content on this page is provided by third parties. Unless otherwise stated, OKX is not the author of the cited article(s) and does not claim any copyright in the materials. The content is provided for informational purposes only and does not represent the views of OKX. It is not intended to be an endorsement of any kind and should not be considered investment advice or a solicitation to buy or sell digital assets. To the extent generative AI is utilized to provide summaries or other information, such AI generated content may be inaccurate or inconsistent. Please read the linked article for more details and information. OKX is not responsible for content hosted on third party sites. Digital asset holdings, including stablecoins and NFTs, involve a high degree of risk and can fluctuate greatly. You should carefully consider whether trading or holding digital assets is suitable for you in light of your financial condition.