Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Fintech Fetch
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Fintech Fetch
    Home»Crypto News»DeFi»$1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny
    $1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny
    DeFi

    $1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny

    February 18, 20264 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Customgpt

    Moonwell, a decentralized finance (DeFi) lending protocol deployed on Base and Optimism, was exploited for about $1.78 million after a pricing oracle for Coinbase Wrapped Staked ETH (cbETH) returned a value of about $1.12 instead of $2,200, creating a mispricing that attackers were able to use for profit.

    Moonwell said in an incident post-mortem that a governance proposal executed on Sunday misconfigured the cbETH oracle by using the cbETH/ETH exchange rate alone, causing the system to report cbETH at about $1.12. The protocol said liquidation bots and opportunistic borrowers exploited the mispricing, leaving roughly $1.78 million in bad debt.

    The pull requests for the affected contracts show multiple commits co-authored by Anthropic’s Claude Opus 4.6, prompting security auditor Pashov to publicly flag the incident as an example of artificial intelligence-written or AI-assisted Solidity backfiring.

    Speaking to Cointelegraph about the incident, he said that he had linked the case to Claude because there were multiple commits in the pull requests that were co-authored by Claude, meaning that “the developer was using Claude to write the code, and this has led to the vulnerability.”

    Pashov cautioned, however, against treating the flaw as uniquely AI-driven. He described the oracle issue as the kind of mistake “even a senior Solidity developer could have made,” arguing that the real problem was a lack of sufficiently rigorous checks and end-to-end validation.

    aistudios
    Vulnerable code led to Moonwell exploit. Source: Pashov

    Initially, he said that he believed there had been no testing or audit at all, but later acknowledged that the team said it had unit and integration tests in a separate pull request and had commissioned an audit from Halborn.

    In his view, the mispricing “could have been caught with an integration test, a proper one, integrating with the blockchain,” but he declined to criticise other security firms directly.

    Small loss, big governance questions

    The dollar amount of the exploit is small compared to some of DeFi’s largest incidents, such as the Ronin bridge exploit in March 2022, where attackers stole more than $600 million, or other nine-figure bridge and lending protocol hacks.

    What makes Moonwell notable is the mix of AI co-authorship, a basic-seeming price configuration failure on a major asset, and existing audits and tests that failed to catch it.

    Pashov said his own company would not fundamentally change its process, but if code appeared “vibe coded,” his team would “have a bit more wide open eyes” and expect a higher density of low-hanging issues, even though this particular oracle bug “was not that easy” to spot.

    “Vibe coding” vs disciplined AI use

    Fraser Edwards, co-founder and CEO of cheqd, a decentralized identity infrastructure provider, told Cointelegraph that the debate around vibe coding masks “two very different interpretations” of how AI is used.

    On one side, he said, are non-technical founders prompting AI to generate code they cannot independently review; on the other, experienced developers using AI to accelerate refactors, pattern exploration and testing inside a mature engineering process.

    AI-assisted development “can be valuable, particularly at the MVP [minimal viable product] stage,” he noted, but “should not be treated as a shortcut to production-ready infrastructure,” especially in capital-intensive systems like DeFi.

    Edwards argued that all AI-generated smart contract code should be treated as untrusted input, subject to strict version control, clear code ownership, multi-person peer review and advanced testing, especially around high-risk areas such as access controls, oracle and pricing logic, and upgrade mechanisms.

    “Ultimately, responsible AI integration comes down to governance and discipline,” he said, with clear review gates, separation between code generation and validation, and an assumption that any contract deployed in an adversarial environment may contain latent risk.

    quillbot
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Fintech Fetch Editorial Team
    • Website

    Related Posts

    DerivaDEX Launches Bermuda-Licensed DAO Derivatives Exchange

    DerivaDEX Launches Bermuda-Licensed DAO Derivatives Exchange

    February 19, 2026
    SOL Traders Lose Reasons To Hold As Solana Activity Slumps

    SOL Traders Lose Reasons To Hold As Solana Activity Slumps

    February 19, 2026
    ETH Mass Adoption Across TradFi Backs $2.5K Price Target

    ETH Mass Adoption Across TradFi Backs $2.5K Price Target

    February 18, 2026
    Starknet Taps EY’s Nightfall for Institutional Privacy on Ethereum Rails

    Starknet Taps EY’s Nightfall for Institutional Privacy on Ethereum Rails

    February 17, 2026
    Add A Comment

    Comments are closed.

    Join our email newsletter and get news & updates into your inbox for free.


    Privacy Policy

    Thanks! We sent confirmation message to your inbox.

    murf
    Latest Posts
    Bitcoin Bottom Signal That Preceded 1,900% Rally Flashes Again

    Signal Indicating Bitcoin’s Bottom, Preceding a 1,900% Surge, Reemerges

    February 19, 2026
    Bitcoin Charts Project Fresh Lows In $50K Range: Will Altcoins Follow?

    Bitcoin Charts Indicate New Lows in $50K Range: Will Altcoins Follow Suit?

    February 19, 2026

    Foundation for Transitioning from Optimistic Tech Stack to a ‘Unified’ Framework

    February 19, 2026
    SOL Traders Lose Reasons To Hold As Solana Activity Slumps

    SOL Traders Withdraw Support Amid Decline in Solana Activity

    February 19, 2026
    Down Nearly 40% From Its All-Time High, Is Netflix Stock Too Cheap to Ignore?

    Down Almost 40% from Its Peak, Is Netflix Stock Too Attractive to Overlook?

    February 19, 2026
    bybit
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights
    Google Gemini 3.1 Pro first impressions: a 'Deep Think Mini' with adjustable reasoning on demand

    Google Gemini 3.1 Pro first impressions: a ‘Deep Think Mini’ with adjustable reasoning on demand

    February 19, 2026
    Whop Clipping Using AI: The Complete Beginner Tutorial (2026)

    Whop Clipping Using AI: The Complete Beginner Tutorial (2026)

    February 19, 2026
    aistudios
    Facebook X (Twitter) Instagram Pinterest
    © 2026 FintechFetch.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.