# Vulnerability Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Vulnerability", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

$7.8 Billion in Theft and Losses Reveals the Truth: Security Costs Have Become an Unavoidable Liquidity Tax for DeFi

"7.8 Billion in Thefts Reveals the Truth: Security Costs Have Become DeFi's Unavoidable 'Liquidity Tax'" A summary of Q2 2026 data reveals that security risks are now a fundamental capital cost in DeFi, directly impacting user returns and liquidity decisions. DeFiLlama recorded 88 hacking incidents with quantified losses totaling $780.3 million in Q2. April was the worst month with $644.8 million lost. DeFi protocol attacks accounted for $735.8 million, while cross-chain bridge exploits resulted in $354.4 million in losses (note: some event categorizations overlap). Cumulatively, DeFi hacks have reached $7.85 billion, with bridge losses at $3.26 billion. The quarter highlighted two primary risk categories: high-value infrastructure vulnerabilities (e.g., bridges, oracles, admin keys) causing massive single losses, and more frequent contract logic bugs. This signals a critical market shift: from post-incident analysis to preemptive pricing of risk. Users and liquidity providers now implicitly factor in the security of the entire asset pathway—not just pool APY—into their decisions. This hidden "risk premium" manifests through wider spreads, higher liquidity incentives, and capital migration towards perceived safer routes. Cross-chain bridge risks, responsible for over $353 million in Q2 losses, exemplify this change. Asset routing credibility is now part of the transaction. Following incidents like KelpDAO and THORChain, markets are demanding safer bridges, asset insurance, and clearer risk disclosure, increasing the cost of capital for riskier pathways. Consequently, security spending is transforming from a defensive cost into a core distribution cost for attracting liquidity. Protocols must invest more in audits, bug bounties, real-time monitoring, and insurance to remain competitive. Users are increasingly demanding transparency about fund flow paths, associated risks, and contingency plans. The key indicators for the industry's direction will be whether capital continues consolidating in trusted channels, if projects delay launches for enhanced audits, if insurance premiums rise, and if aggregators start displaying security risk metrics. Q2 2026 may be remembered not just as a bad period, but as the point when DeFi underwent a fundamental asset risk repricing, where security became a persistent,隐性 tax on all on-chain activity.

Foresight News07/01 08:03

$7.8 Billion in Theft and Losses Reveals the Truth: Security Costs Have Become an Unavoidable Liquidity Tax for DeFi

Foresight News07/01 08:03

China's No.1, Closing in on OpenAI, Mysterious "Sweeping Monk" Rises to Top Seven Globally

A mysterious Chinese AI project named "MopMonk" (meaning "Sweeping Monk") has achieved a top-ranking result on the globally recognized CyberGym cybersecurity benchmark. With a 73.1% success rate, it ranks seventh worldwide and first among Chinese entries, performing closely behind OpenAI. The significance lies in the benchmark itself. CyberGym, created by UC Berkeley, is considered a premier "Olympics" for AI security. It tests models on over 1500 real-world software vulnerabilities, requiring them to not just identify but actually generate working exploits (PoCs) in a complex, offline environment. This moves beyond simple knowledge to testing an AI's practical "execution" capabilities. MopMonk's approach is notable. It uses the open-source MiniMax M3 model from Shanghai as its powerful reasoning "brain," leveraging its strong coding skills and long context window. However, the key to its performance is a custom-built, multi-agent security framework—its "Harness." This system uses structured "vulnerability memory" to efficiently guide the search for exploits, allowing multiple agents to explore in parallel while sharing lessons learned from failures. This engineering layer effectively translates the model's intelligence into actionable, iterative testing steps. The project remains highly secretive, with no official website or team information, embodying the "dark horse" spirit of its literary namesake. Its success highlights a potential industry shift: beyond simply scaling model size, the engineering of specialized agent systems (the Harness) is becoming a critical differentiator for real-world AI application performance, especially in complex domains like cybersecurity.

marsbit06/30 08:09

China's No.1, Closing in on OpenAI, Mysterious "Sweeping Monk" Rises to Top Seven Globally

marsbit06/30 08:09

Hackers Steal Nearly $17 Million in 40 Days as 'Zombie Contracts' Become Their ATMs

According to an analysis published by ZeroDrift on June 22, 2026, attackers have stolen approximately $16.9 million over 40 days from five deprecated but still operational smart contracts across various blockchains. The primary issue is not a specific vulnerability but the incomplete decommissioning of legacy contracts. These "zombie contracts" often retain economic value, operational permissions, and callable functions, making them prime targets long after teams cease active development. The most significant loss occurred at DxSale, where an old locker contract lost about $7.3 million due to a forgotten control path becoming accessible again. Other affected projects include TrustedVolumes (~$5.87M), Raydium's legacy AMM pool (~$1.34M), Aztec Connect (~$2.28M), and Huma Finance V1 pool (~$101k). These incidents involved diverse systems—RFQ settlement, credit pools, liquidity lockers, AMMs—demonstrating the widespread nature of the risk. The analysis highlights that automated tools are lowering the cost for attackers to systematically scan for these long-tail targets, which have public code and weaker monitoring. In contrast, defensive practices for contract retirement remain underdeveloped. While the DeFi industry has mature audit processes for new deployments, it lacks strict protocols for securely sunsetting old contracts, which only become truly "retired" after all funds, permissions, authorizations, and trust assumptions are removed.

marsbit06/26 09:13

Hackers Steal Nearly $17 Million in 40 Days as 'Zombie Contracts' Become Their ATMs

marsbit06/26 09:13

It Turns Out the First Real-World Application of AI x Crypto is in Security Auditing

The article explores the surprising trend where AI's first major impact on crypto has been in security auditing, not in areas like trading or analytics. It details how AI-powered tools are dramatically lowering the barrier to finding smart contract vulnerabilities, enabling attackers to scan thousands of contracts and execute exploits within minutes. This has rendered traditional, manually-produced audit reports with their month-long validity periods increasingly obsolete, creating a critical "structural crack" in the old security model. Cases like Drift Protocol and KelpDAO show that even extensively audited protocols can be hacked through social engineering, operational flaws, or infrastructure misconfigurations beyond pure code review. Attackers are also using AI to find and exploit vulnerabilities in years-old, deployed contracts. Notably, OpenZeppelin's co-founder has expressed a grim view that "all DeFi is insecure" due to AI's asymmetric advantage. In response, the audit industry is undergoing a fundamental shift. While there's a short-term spike in defensive re-audits, the long-term business model is changing. Firms are developing AI-assisted systems and moving from one-time report deliveries towards embedded, continuous services like real-time monitoring and formal verification. Examples include AI tools uncovering critical, previously missed vulnerabilities in heavily audited protocols like Curve Finance and Zcash. The conclusion is that security must become a continuous investment, not a one-time checkbox, and audit firms must rapidly evolve their tools and service models to survive.

marsbit06/26 07:20

It Turns Out the First Real-World Application of AI x Crypto is in Security Auditing

marsbit06/26 07:20

Never expected that the first tangible application of AI x Crypto is in security auditing

Unexpectedly, the initial major application of AI in the Crypto sphere has turned out to be security auditing. In 2026, DeFi has faced significant security challenges, with 121 hacking incidents resulting in approximately $942 million in losses. While AI was expected to first impact areas like quantitative trading, its initial breakthrough has instead transformed security auditing by drastically lowering the cost and skill barrier for finding smart contract vulnerabilities. The traditional audit model is facing obsolescence. Advanced AI models, such as Claude Mythos, enable attackers to scan thousands of contracts and identify vulnerability patterns at scale, compressing the time from discovery to execution to mere minutes. This renders the month-long validity of traditional audit reports ineffective. Notably, attacks now frequently target well-audited, established protocols by exploiting business logic flaws, operational security weaknesses, and even years-old historical contracts, demonstrating that old audit reports offer zero protection. This pressure is forcing a fundamental shift in the industry. In the short term, a wave of defensive re-auditing is occurring, driven by projects seeking to meet new AI-era security standards and regulatory requirements. In the long run, audit firms' business models are diverging. The one-time report delivery model is declining in value, as evidenced by platforms like Code4rena shutting down. Leading firms are now pivoting towards AI-powered defense, integrating continuous monitoring, real-time on-chain risk detection, and embedding security directly into the development phase, as seen with tools like OpenZeppelin's Skills system. Ultimately, the era of "audit once, secure forever" is over. Security must become a continuous, embedded infrastructure investment for projects. For audit companies, survival depends on proactively transforming from traditional service providers into platforms offering AI-native, ongoing security solutions.

链捕手06/26 07:13

Never expected that the first tangible application of AI x Crypto is in security auditing

链捕手06/26 07:13

活动图片