
Multiple decentralised finance protocols tied to Bitcoin and Ethereum were breached in a series of attacks that unfolded within hours of each other. The combined losses have been estimated at $35 million (roughly โน292 crore), according to security firms monitoring the incidents.
The attacks appear to have been launched nearly simultaneously, raising suspicions of a coordinated effort by a single group or several groups acting in concert. Blockchain security analysts are still piecing together the exact entry points used by the hackers.
The affected protocols are built on or interoperate with the Bitcoin and Ethereum blockchains. While specific names of the protocols have not been officially disclosed by developers, on-chain data indicates that funds were drained from smart contracts and liquidity pools.
One of the attacks exploited a vulnerability in a cross-chain bridge, a common target for hackers. The other breach appears to have involved a flash loan attack, a technique where large sums are borrowed and manipulated within a single transaction.
Security firm PeckShield confirmed the $35 million figure on social media, noting that the stolen assets include a mix of Ether, wrapped Bitcoin, and several ERC-20 tokens.
Blockchain trackers have observed the attackers moving the stolen funds through decentralised exchanges and into crypto mixing services. These services are often used to obscure the trail of illicitly obtained cryptocurrency.
The hackers have already converted a portion of the stolen assets into stablecoins, likely to avoid price volatility while laundering the money. Law enforcement agencies have been alerted, but recovering funds from such attacks remains difficult.
The incident has reignited concerns about the security of decentralised finance platforms. Despite improvements in code audits, sophisticated attackers continue to find loopholes in smart contracts and cross-chain protocols.
Total losses from DeFi hacks in 2026 have already crossed $500 million, with this latest event being one of the largest single-day thefts of the year. Industry experts are calling for better standardisation of security practices across protocols.
Affected teams are working with security firms to identify the vulnerability and have temporarily paused certain functions to prevent further losses. Users have been advised to revoke approvals for the compromised contracts.
What to watch for: Investigators are combing through transaction logs for clues about the attackers' identity. The next few days will be critical as exchanges and blockchain analytics firms track the stolen funds. If the hackers attempt to cash out through a major exchange, it could lead to a freeze.