$292M drained from a DeFi lending protocol via a flash loan exploit. Biggest hack of 2026. Auditors missed the attack vector entirely.
The uncomfortable truth: this happened the same week Wall Street firms announced new onchain strategies. The gap between institutional interest and DeFi security readiness is massive and widening.
Industry insiders are calling for fundamental risk model changes. Flash loan attacks aren't new — the fact that a $292M protocol still fell for one suggests the auditing ecosystem isn't keeping up with exploit sophistication.
Expect regulators to point to this as proof that DeFi needs more oversight. They're not wrong — but more rules won't fix bad code.