Security Analysis Flags 19 Vulnerabilities in Bitfinex Smart Contracts
A DeFi security research report dated September 15, 2026, identified 19 vulnerabilities across Bitfinex's on-chain smart contracts, which collectively secure approximately $18.7 billion in user funds on Ethereum and Layer 2 networks. The analysis categorized nine high-severity issues spanning access control, proxy upgradeability, and cross-chain bridge logic, alongside medium and low-severity flaws involving re-entrancy, oracle manipulation, and flash-loan exploits. Critical findings include an unguarded ownership transfer function, a missing multi-signature requirement for key lending pool operations, an open bridge operator setter, and a governance timelock bypass in the DAO contract. The protocol received an overall risk score of 7 out of 10, indicating a moderately high threat level given its complexity and asset value. Researchers called for immediate remediation of all high-severity items to reduce the protocol's risk posture to a low-to-medium level.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in