# oracle exploit — X 热门讨论 (2026-09-26 07:29 UTC)
## @CryptoTeca__ (TECA) · 09-25 19:19 · ♥159 ↻1 💬30 Crypto has lost billions to hacks in 2026.
And at this point, it’s getting difficult to ignore how bad things have become.
The biggest lesson isn't simply that smart contracts are broken.
It's that the systems surrounding them can be.
On September 24, @bitget reported approximately $351.6M in unauthorized transfers from a limited number of hot wallets. Bitget says its cold wallets and most platform assets remained secure, while its User Protection Fund covers the affected assets. The exact attack vector is still under investigation, so claims about how the compromise happened should be treated cautiously.
But Bitget is only the latest major incident.
By late September, trackers had recorded 86 major incidents and more than $2.3B in disclosed losses.
Some of the biggest reported losses:
→ Bitget — ~$351.6M → Liquid — ~$319M → Kelp DAO — ~$292M → Drift — ~$285M → Social engineering — ~$282M → Tectonic — ~$120M → Coldcard — ~$114–116M → Echo — ~$77M → Humanity — ~$31M → Step Finance — ~$30–40M
Liquid alone saw roughly $319M drained after attackers exploited validator software to create unbacked synthetic BTC. Around 85% was later returned, leaving roughly $47M outstanding according to TRM.
Earlier in the year, Kelp DAO and Drift suffered attacks worth roughly $292M and $285M respectively.
Kelp involved cross-chain infrastructure.
Drift involved social engineering and compromise of privileged access.
And these weren't isolated technical bugs.
That's what makes the situation even more concerning.
Across 2026, we've seen:
• Oracle manipulation • Bridge and verifier exploits • Governance attacks • Hot-wallet compromises • Weak randomness • Social engineering • Compromised signing infrastructure • Phishing and impersonation • Approval exploits • Fake staking platforms • DEX rug pulls
August brought the ~$120M Tectonic incident involving price manipulation, alongside Moonwell's ~$8.7M oracle exploit and Term Finance's ~$8.5M governance attack. TRM notes that price manipulation accounted for about one in eight hacks in its H1 data.
July saw the Coldcard incident, with roughly $116M linked to weak seed entropy, alongside AFX Trade (~$24M), Ostium (~$24M), BonkDAO (~$20M) and Triple-A (~$9.7M).
April–June included Kelp DAO, Drift, Echo (~$77M), Humanity (~$31M), Rhea Finance, Resolv, Grinex and others.
January–March brought the ~$283–285M social-engineering theft, Step Finance, Truebit (~$27M), SwapNet (~$17M), Blend (~$11M) and numerous smaller exploits.
TRM's H1 data puts the scale into perspective: 207 hacks were recorded in the first six months alone, with $972M stolen. Infrastructure and operational compromises represented only about 15% of incidents but around 76% of stolen value.
That's the pattern.
And it's becoming increasingly difficult to dismiss these incidents as isolated failures.
Attackers don't always need to break the blockchain.
They can attack what the blockchain trusts:
A wallet backend. An oracle. A bridge verifier. A signing system. A governance process. A private key. A developer. A human.
Once a trusted component approves something malicious, the blockchain can execute it perfectly.
That's why crypto security in 2026 isn't just about auditing smart contracts.
It's also about securing the infrastructure, people, permissions and verification systems sitting around them.
Because the uncomfortable reality is this:
The blockchain can remain mathematically intact while billions are lost through everything built on top of it. https://x.com/CryptoTeca__/status/2103564983191880011