A serious security incident has occurred on the DeFi lending protocol Moonwell after the smart contract code was allegedly written with the involvement of AI model Claude Opus 4.6. According to smart contract auditor Pashov, the code generated by Claude Opus 4.6 contains a critical vulnerability, leading to an exploit that caused approximately $1.78 million in damages.
Specifically, the price of cbETH was set incorrectly at $1.12 instead of around $2,200, enabling attackers to manipulate the system. The project’s pull requests (PRs) show several commits co-authored by Claude, raising the possibility that this is the first hack related to Solidity code in a “vibe-coding” style supported by AI.
SlowMist founder Cos stated that the root cause stemmed from a low-level error in the oracle price feed formula.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
A user experienced 89 address poisoning attacks within 30 minutes after completing two transfers
Etherscan recently issued a security warning alerting users to beware of address poisoning attacks. Attackers create fake addresses similar to addresses users have previously interacted with to trick users into sending funds to the wrong destination. It is recommended that users confirm the complete address when transferring funds and use address highlighting features to avoid risks.
GateNews9m ago
Ledger Donjon Finds MediaTek Flaw Exposing Android Wallet Seeds
_Ledger Donjon exposed a MediaTek vulnerability that extracts Android wallet seed phrases in under 45 seconds, affecting millions of devices. CVE-2025-20435._
Ledger Donjon has uncovered a serious MediaTek vulnerability. It lets attackers pull wallet seed phrases from Android phones in seconds.
LiveBTCNews6h ago
Authorities Freeze $3.5M in Crypto as Europol, DOJ Disrupt ‘SocksEscort’ Proxy Network
In brief
Europol and partners announced the disruption of the “SocksEscort” malicious proxy service and the freezing of $3.5 million in cryptocurrency linked to the operation.
The network allegedly compromised more than 369,000 routers and IoT devices and offered customers more than 35,000 p
Decrypt7h ago
CertiK Report: Cryptocurrency ATM Fraud Losses Reach $330 Million in 2025, AI Technology Escalates Criminal Sophistication
CertiK released a report showing that cryptocurrency ATM fraud losses in the United States reached $330 million in 2025, with a 33% increase. Fraud tactics are gradually escalating, with elderly people becoming the primary targets. AI-driven fraud has 4.5 times the profitability of traditional methods, and the threat from transnational criminal organizations continues to rise.
GateNews11h ago
China AI Industry Development Alliance Continuously Tracks OpenClaw Security Risks, Compiles Enterprise-Level Deployment Risk Management Guidelines
Gate News reports that on March 12, the China Artificial Intelligence Industry Development Alliance is continuously tracking the security risk dynamics of OpenClaw and compiling an enterprise-level OpenClaw deployment risk management guide.
GateNews12h ago
Tencent Launches OpenClaw Security Toolbox to Address Security Challenges of Lobster AI Agent
Tencent launched the OpenClaw Security Toolkit on March 12th to address security challenges brought by AI Agents, providing multi-layered protection for enterprises and users. The toolkit includes security solutions for cloud and personal computers, supporting environment isolation and monitoring of anomalous instructions.
GateNews12h ago