DeFi
May 28
A security warning from Manuel Aráoz, co-founder and former CTO of smart contract auditing firm OpenZeppelin, has intensified concerns about AI-driven threats to decentralized finance. On May 27, Aráoz advised investors to exit all DeFi positions, citing the growing risk posed by autonomous AI agents capable of identifying
1 min read
DeFi
May 28
Grayscale is in negotiations to secure approximately $115 million in HYPE tokens as seed capital for a proposed Hyperliquid exchange-traded fund, signaling growing institutional appetite for the decentralized exchange's native token. The move follows 21Shares and Bitwise Investments, which earlier this month became the first firms to
1 min read
DeFi
May 28
Securitize has integrated VanEck's tokenized US Treasury fund, VBILL, as a collateral asset within an Euler lending market curated by KPK, bridging traditional fixed-income instruments with decentralized lending infrastructure. The move allows holders of VBILL — a fund backed by short-term US government debt — to deploy their
1 min read
DeFi
May 27
Solana-based decentralized exchange Orca has launched a dedicated marketplace for tokenized real-world assets, expanding its platform beyond traditional crypto trading pairs. The move positions Orca within a rapidly growing sector as crypto firms race to bring traditional financial instruments — such as bonds, equities, and commodities — onto blockchain rails.
1 min read
DeFi
May 27
A smart contract vulnerability in Stake DAO is being actively exploited on Arbitrum, allowing an attacker to mint approximately 5.4 trillion vsdCRV tokens — a figure far exceeding any legitimate supply. Security researchers flagged the attack as ongoing, noting the exploiter is already converting the artificially minted tokens into ether,
1 min read
DeFi
May 27
OpenZeppelin's CEO has warned that AI coding agents are now capable of identifying and exploiting smart contract vulnerabilities at a level beyond human ability, fundamentally undermining DeFi security. The warning comes as the sector has suffered over $1 billion in hacks over the past year, with total value
1 min read
DeFi
May 26
Total value locked across decentralized finance protocols has fallen 14% in the five weeks since the KelpDAO exploit, as the breach continues to weigh on investor confidence and risk appetite. The KelpDAO incident exposed vulnerabilities in DeFi infrastructure, triggering sustained capital outflows rather than a brief, isolated reaction. The decline
1 min read
DeFi
May 26
A May 24 disclosure by Socket revealed a supply chain attack called TrapDoor, which planted over 34 malicious packages and 384 related versions across npm, PyPI, and Crates.io — three of the most widely used developer package repositories. The campaign targets DeFi protocol developers directly, harvesting credentials and creating pathways
1 min read
DeFi
May 26
A vulnerability in StablR's 1-of-3 multisig wallet allowed an attacker to compromise a single private key and mint $13.5 million worth of unbacked USDR and EURR tokens, ultimately extracting $2.8 million in real value before the breach was detected. StablR responded by freezing both
1 min read
DeFi
May 26
Hyperliquid has introduced HIP-4, a new prediction market product that allows traders to place bets on real-world macroeconomic events such as inflation readings and central bank interest-rate decisions. Unlike Polymarket, which relies on UMA's external dispute resolution mechanism to settle outcomes, Hyperliquid routes dispute resolution
1 min read
DeFi
May 26
Ondo Finance, a prominent tokenized real-world assets protocol, announced the unexpected death of its founder and CEO Nathan Allman, marking a significant leadership transition for one of DeFi's most closely watched projects. Ian De Bode, who served as president of the company, will assume the role of
1 min read
DeFi
May 25
A third-party module called SquidRouterModule was exploited for approximately $3.2 million, but cross-chain liquidity protocol Squid says it had no involvement in deploying the vulnerable contract. Squid stated its core protocol remained fully operational and unaffected by the breach, distancing itself from the incident entirely. The team
1 min read