Two decentralized finance protocols suffered serious security breaches on September 8, 2026, reigniting concerns about smart contract vulnerabilities and centralization of trust.
KelpDAO lost approximately $292 million after attackers exploited its reliance on a single verifier, according to Fireblocks. Fireblocks said the attacker fed false data to the only trusted verifier, a weakness highlighted in its 2026 Threat Report. The incident underscores the urgent need for diversified verification methods to protect user assets.
In a separate incident, WealthManagementV2 reported a 26,414 USDT loss following a suspected contract breach. Security firm SlowMist said unauthorized transfer of owner privileges likely resulted from a leaked private key. Once the attacker controlled ownership, they could alter plan parameters and trigger inflated interest minting. The attacker's externally owned address was identified as 0xe439422afdd247503f75b4143c4a973eced04a36.
Both events highlight persistent structural weaknesses: single points of trust in verification and insufficient private key management. Investor confidence in similar DeFi protocols may suffer, and regulators may increase scrutiny of security practices across the sector.