Two separate DeFi security breaches have shaken the cryptocurrency sector, with BeatXswap and Liquid BTC suffering exploits that drained funds and exposed serious weaknesses in smart contract and verification logic.
BeatXswap reported a loss of 2,984,557 BTX, worth approximately $77,512, after an attacker manipulated its liquidity pool using a flash loan. According to SlowMist, the exploit targeted the LiquidityVestingConvert contract, which relied solely on the IUniswapV3Pool.slot0() price as an oracle. By crashing the spot price of BTX, the attacker drained BTX from liquidity provider positions.
Liquid BTC, meanwhile, disclosed a more severe incident that began on September 6, 2026, when an attacker exploited a cache key collision vulnerability in rangeproof verification. This allowed the fraudulent minting of 3,998.5 L-BTC without corresponding peg-ins. The attack used a crafted payload embedded in locking scripts. Within minutes, approximately 3,400 BTC were returned to the federation peg wallet, but about 598.5 BTC remains under the attacker's control.
Both breaches underscore the persistent security risks in decentralized finance and sidechain infrastructure. Traders are expected to scrutinize DeFi protocols more closely, and regulators may increase pressure on security standards. BeatXswap has not yet disclosed a full recovery plan, while the Liquid BTC incident continues to raise questions about asset recovery and auditing practices.