Back to Blog

Smart Contract Security

5 articles on this topic.

Web3 & DeFi Security27 September 2026

Meter's Bridge Mint Bug: $2.3M in Unbacked Tokens, an 88% Price Crash

A flawed validation check in Meter Passport let an attacker mint unbacked wrapped MTR and MTRG, dump them on a DEX, and crater both tokens — forcing the chain and bridge offline.

bridge-securitydefismart-contract-security
4 min readRead
Web3 & Smart Contract Security29 August 2026

BounceBit's $3M Authorization Bug Forces It to Kill Its Own Layer 1

An unverified-account flaw in BounceBit's Evmos-based chain let an attacker drain 286.5 million BB from nine wallets — and because the underlying chain client is itself discontinued, BounceBit is retiring the L1 rather than patching it.

web3-securitysmart-contract-securityblockchain
4 min readRead
DeFi & Smart-Contract Security19 July 2026

Summer Finance's $6M Vault Accounting Bug Ends in Full Shutdown

A flash-loan attacker exploited how Summer Finance's Fleet Commander vault priced its underlying strategies, extracting $6 million in a single transaction — and the protocol has now wound down entirely.

defi-securityflash-loan-attacksmart-contract-security
4 min readRead
Web3 Security29 June 2026

Taiko Bridge Drained $1.7M After SGX Signing Key Exposed on GitHub

An attacker leveraged a publicly committed SGX enclave key to forge withdrawal proofs on Taiko's Ethereum L2 bridge, draining $1.7 million before block production was halted on 22 June 2026.

bridge-exploitethereum-l2sgx
4 min readRead
DeFi Security29 June 2026

Counter-MEV Honeypot Drains jaredfromsubway.eth of $7.5 Million

Ethereum's most-active sandwich-attack bot was beaten at its own game — tricked by 66 fake token contracts into handing over real WETH, USDC, and USDT in a single sweep transaction.

mevdefiethereum
4 min readRead