Two decentralized finance protocols have disclosed separate security breaches, highlighting persistent vulnerabilities in the DeFi sector. Cozy Finance reported a loss of approximately $160,000 after an attacker exploited the UMA Optimistic Oracle, while Notional Finance suffered a more severe breach on September 4, 2026, losing roughly $1.73 million.
The Cozy Finance incident involved an attacker submitting a false price proposal that went unchecked, allowing the exploit to trigger compensation payouts. Crypto security commentator SlowMist drew attention to the case, noting that the vulnerability in the UMA Optimistic Oracle exposed weaknesses in price feed mechanisms. In the Notional Finance attack, SlowMist said the breach involved systematic flaws in the smart contract logic, with the attacker using auxiliary contracts to manipulate transaction states.
The attacks raise concerns about the robustness of decentralized lending and oracle-dependent protocols. Notional Finance's trading volume reportedly fell to $0 after the breach, and its price remained unreported amid diminished market confidence. Broader crypto markets showed mixed signals as traders assessed the implications for DeFi security and potential regulatory scrutiny.