The same defect, three times
Oracle manipulation is not novel — our tracker records the Cream Finance case from 2021 with the identical shape. What made July notable is the clustering: three protocols, one month, one failure mode.
In each case there is no clever exploit to reverse-engineer. The lending logic works. It works on a false input, because the input came from somewhere an attacker with temporary capital could move.
What makes a feed exploitable
The exposure is a function of three things: whether the price is instantaneous or time-weighted, whether it comes from one venue or several, and how deep the liquidity is on whatever venue is being read. A thin market read at spot, with flash-loaned capital available to move it, is the exploitable case — and it has been for five years.
See our glossary entry for the mechanism, and the tracker for the historical record.
What we are not reporting
Aggregate figures for these three incidents circulated before individual post-mortems were published. Conisec is recording the cluster and the mechanism; we will add individual incident records with confirmed per-protocol figures once each affected party publishes one. A tracker row without a primary source does not get created.
Sources
- QuillAudits, July 2026 Crypto Hacks — monthly breakdown (1 Aug 2026)
Not advice. Conisec reports for information only. Nothing in this article is financial, legal, tax or security advice. Verify against the primary sources linked above before acting on anything.