The post $1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny appeared on BitcoinEthereumNews.com. Moonwell, a decentralized finance (DeFiThe post $1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny appeared on BitcoinEthereumNews.com. Moonwell, a decentralized finance (DeFi

$1.78M ‘Vibe-Coded’ Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Moonwell, a decentralized finance (DeFi) lending protocol deployed on Base and Optimism, was exploited for about $1.78 million after a pricing oracle for Coinbase Wrapped Staked ETH (cbETH) returned a value of about $1.12 instead of $2,200, creating a mispricing that attackers were able to use for profit.

Moonwell said in an incident post-mortem that a governance proposal executed on Sunday misconfigured the cbETH oracle by using the cbETH/ETH exchange rate alone, causing the system to report cbETH at about $1.12. The protocol said liquidation bots and opportunistic borrowers exploited the mispricing, leaving roughly $1.78 million in bad debt.

The pull requests for the affected contracts show multiple commits co-authored by Anthropic’s Claude Opus 4.6, prompting security auditor Pashov to publicly flag the incident as an example of artificial intelligence-written or AI-assisted Solidity backfiring. 

Speaking to Cointelegraph about the incident, he said that he had linked the case to Claude because there were multiple commits in the pull requests that were co-authored by Claude, meaning that “the developer was using Claude to write the code, and this has led to the vulnerability.”

Pashov cautioned, however, against treating the flaw as uniquely AI-driven. He described the oracle issue as the kind of mistake “even a senior Solidity developer could have made,” arguing that the real problem was a lack of sufficiently rigorous checks and end-to-end validation.

Vulnerable code led to Moonwell exploit. Source: Pashov

Initially, he said that he believed there had been no testing or audit at all, but later acknowledged that the team said it had unit and integration tests in a separate pull request and had commissioned an audit from Halborn. 

In his view, the mispricing “could have been caught with an integration test, a proper one, integrating with the blockchain,” but he declined to criticise other security firms directly.

Related: How South Korea is using AI to detect crypto market manipulation

Small loss, big governance questions

The dollar amount of the exploit is small compared to some of DeFi’s largest incidents, such as the Ronin bridge exploit in March 2022, where attackers stole more than $600 million, or other nine-figure bridge and lending protocol hacks. 

What makes Moonwell notable is the mix of AI co-authorship, a basic-seeming price configuration failure on a major asset, and existing audits and tests that failed to catch it. 

Pashov said his own company would not fundamentally change its process, but if code appeared “vibe coded,” his team would “have a bit more wide open eyes” and expect a higher density of low-hanging issues, even though this particular oracle bug “was not that easy” to spot.

“Vibe coding” vs disciplined AI use

Fraser Edwards, co-founder and CEO of cheqd, a decentralized identity infrastructure provider, told Cointelegraph that the debate around vibe coding masks “two very different interpretations” of how AI is used. 

Related: How AI crypto trading will make and break human roles

On one side, he said, are non-technical founders prompting AI to generate code they cannot independently review; on the other, experienced developers using AI to accelerate refactors, pattern exploration and testing inside a mature engineering process.

AI-assisted development “can be valuable, particularly at the MVP [minimal viable product] stage,” he noted, but “should not be treated as a shortcut to production-ready infrastructure,” especially in capital-intensive systems like DeFi.

Edwards argued that all AI-generated smart contract code should be treated as untrusted input, subject to strict version control, clear code ownership, multi-person peer review and advanced testing, especially around high-risk areas such as access controls, oracle and pricing logic, and upgrade mechanisms.

“Ultimately, responsible AI integration comes down to governance and discipline,” he said, with clear review gates, separation between code generation and validation, and an assumption that any contract deployed in an adversarial environment may contain latent risk.

Magazine: South Korea gets rich from crypto… North Korea gets weapons

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/moonwell-exploit-cbeth-oracle-misprice-ai-commits-testing-audits?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0004507
$0.0004507$0.0004507
-0.04%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why the UK Is Seeing an Uplift in Property Sales in 2026

Why the UK Is Seeing an Uplift in Property Sales in 2026

After several turbulent years for the housing market, the UK property sector is showing signs of renewed momentum in 2026. While the market remains cautious, several
Share
Techbullion2026/03/05 01:17
Shiba Inu Coin Burn Mechanics: How Many SHIB Coins Have Been Burned so Far?

Shiba Inu Coin Burn Mechanics: How Many SHIB Coins Have Been Burned so Far?

Shiba Inu coin burn explained: how SHIB tokens are removed from circulation, why over 410T tokens were burned, and how Shibarium affects supply and price.
Share
coincheckup2026/03/05 00:52
Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple!

Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple!

Buterin unveils Ethereum’s strategy to tackle quantum security challenges ahead. Ethereum focuses on simplifying architecture while boosting security for users. Ethereum’s market stability grows as Buterin’s roadmap gains investor confidence. Ethereum founder Vitalik Buterin has unveiled his long-term vision for the blockchain, focusing on making Ethereum quantum-secure while maintaining its simplicity for users. Buterin presented his roadmap at the Japanese Developer Conference, and splits the future of Ethereum into three phases: short-term, mid-term, and long-term. Buterin’s most ambitious goal for Ethereum is to safeguard the blockchain against the threats posed by quantum computing.  The danger of such future developments is that the future may call into question the cryptographic security of most blockchain systems, and Ethereum will be able to remain ahead thanks to more sophisticated mathematical techniques to ensure the safety and integrity of its protocols. Buterin is committed to ensuring that Ethereum evolves in a way that not only meets today’s security challenges but also prepares for the unknowns of tomorrow. Also Read: Ethereum Giant The Ether Machine Takes Major Step Toward Going Public! However, in spite of such high ambitions, Buterin insisted that Ethereum also needed to simplify its architecture. An important aspect of this vision is to remove unnecessary complexity and make Ethereum more accessible and maintainable without losing its strong security capabilities. Security and simplicity form the core of Buterin’s strategy, as they guarantee that the users of Ethereum experience both security and smooth processes. Focus on Speed and Efficiency in the Short-Term In the short term, Buterin aims to enhance Ethereum’s transaction efficiency, a crucial step toward improving scalability and reducing transaction costs. These advantages are attributed to the fact that, within the mid-term, Ethereum is planning to enhance the speed of transactions in layer-2 networks. According to Butterin, this is part of Ethereum’s expansion, particularly because there is still more need to use blockchain technology to date. The other important aspect of Ethereum’s development is the layer-2 solutions. Buterin supports an approach in which the layer-2 networks are dependent on layer-1 to perform some essential tasks like data security, proof, and censorship resistance. This will enable the layer-2 systems of Ethereum to be concerned with verifying and sequencing transactions, which will improve the overall speed and efficiency of the network. Ethereum’s Market Stability Reflects Confidence in Long-Term Strategy Ethereum’s market performance has remained solid, with the cryptocurrency holding steady above $4,000. Currently priced at $4,492.15, Ethereum has experienced a slight 0.93% increase over the last 24 hours, while its trading volume surged by 8.72%, reaching $34.14 billion. These figures point to growing investor confidence in Ethereum’s long-term vision. The crypto community remains optimistic about Ethereum’s future, with many predicting the price could rise to $5,500 by mid-October. Buterin’s clear, forward-thinking strategy continues to build trust in Ethereum as one of the most secure and scalable blockchain platforms in the market. Also Read: Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? The post Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple! appeared first on 36Crypto.
Share
Coinstats2025/09/18 01:22