๐Ÿ“… Monday, 21 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Peretas DeFi 2026 Tak Lagi Bobol Brankas - Mereka Cukup Membisiki 'Mata-Mata' Ini Harga Palsu

2026 DeFi Hackers No Longer Crack Vaults - They Just Whisper Fake Prices to This ‘Spy’

If you look at recent DeFi exploit headlines, there is a recurring pattern that is easy to miss: hackers often do not actually ‘crack’ the protocol vault. The main contract remains completely fine, with funds stored according to the rules. What they attack is a tiny, often-overlooked component - the oracle. And that is how billions of rupiah can vanish in a single transaction.

For those unfamiliar, an oracle is a ‘spy’ or information bridge for smart contracts. Blockchains are blind to the outside world - they do not know what a token is trading for on the market this very second. Yet lending protocols need that exact figure to calculate how much you can borrow against your deposited collateral. The oracle is what whispers that price into the contract. The problem: if that whisper can be faked, the entire calculation collapses.

How the Deceptive Attack Works

The principle is simple. Lending contracts blindly trust the numbers provided by oracles. If hackers manage to make an oracle report an asset price far higher than its actual value - whether by manipulating thin-liquidity markets where the oracle sources its data or by exploiting verification flaws in the oracle contract itself - pocket-change collateral is suddenly ‘read’ as worth a fortune. Using that inflated collateral, attackers borrow far more real assets than they should and walk away. The protocol is left with bad debt and an emptied vault, even though its ‘front door’ was never breached by force.

The latest incident at a lending protocol on the Hedera network this week followed the exact same playbook: a vulnerability in a third-party oracle contract was exploited to borrow assets far exceeding the collateral value, draining most of the locked funds. Notably, the underlying network itself had no issues - the hole was in the data feed, not the foundation.

Why This Matters to You

For anyone depositing funds in DeFi protocols, the takeaway is clear: platform security does not stop at how well-known the brand is or how clean its core code looks. The security chain is only as strong as its weakest link, and oracles are often the most overlooked link. Before depositing, it pays to check where the protocol pulls its price data from - whether from deep, hard-to-manipulate sources or from thin markets easily swayed. In a world promising ‘code is law’, a tiny flaw in the price translator can become a backdoor far costlier than even the most sophisticated front lock.

Reported via CoinDesk.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share