tenjin.blog
https://tenjin.blog/api/read/chain-security/defi-smart-contract-exploits-and-protocol-risk-in-2026-the-failure-taxonomy-theDeFi Smart Contract Exploits and Protocol Risk in 2026: The Failure Taxonomy, the Dated Incident Record, and How to Audit for Each Class. A dated taxonomy of DeFi failure as of August 2026: code defects such as reentrancy and access control, economic and design exploits including oracle manipulation, flash loan attacks, liquidation cascades and impermanent loss, and operational compromise. Carries the aggregate loss record, named post-mortems, measured audit and bug bounty efficacy, MEV and sandwich economics, and a defensive checklist per class. Crypto security threats sorted by what the evidence supports.
Reliability & health
Uptime and response time from our own unpaid probes, plus the reliability score built from them.
Uptime
0.0% avgResponse time
Data table
| Bucket | Uptime | Probes | Response time |
|---|---|---|---|
| 8/15/2026, 9:00:00 AM | 0% | 2 | — |
| 8/16/2026, 9:00:00 AM | 0% | 1 | — |
| 8/17/2026, 10:00:00 AM | 0% | 1 | — |
| 8/18/2026, 10:00:00 AM | 0% | 1 | — |
| 8/19/2026, 10:00:00 AM | 0% | 1 | — |
| 8/20/2026, 10:00:00 AM | 0% | 1 | — |
| 8/21/2026, 10:00:00 AM | 0% | 1 | — |
- Availability
- 0
- Latency
- not yet measured
- Security
- 100
- Transparency
- 30
- Activity
- not yet measured
How often it was reachable when we probed it (weight 35%).
How quickly it answers when it is up — fast scores high (weight 20%).
Whether it serves over working TLS / https (weight 15%).
Whether the operator disclosed what it does — description, schema, identity (weight 15%).
Observed on-chain payments to this endpoint's wallet — transactions, volume, and distinct paying wallets over the last month (weight 15%; not yet measured when we have not seen its wallet settle).
Confidence 16% — how much probe evidence backs this score. A thin history is flagged, not hidden.
See the scoring methodology for exactly how each number is computed.
Payment
- Currencies
- USDC
- Networks
- base
- Facilitator
- unknown
- SDK
- unknown
Operator
- Company
- inferred — unknown
- Jurisdiction
- —
- Registrar
- —
- Domain registered
- —
- Hosting network
- —
- Hosting country
- —
Operator context is derived from public RDAP/TLS records and unverified. Company and country are only available for endpoints that publish them (an OV/EV TLS certificate or a non-redacted domain record); most endpoints are CDN-fronted and disclose neither.
On-chain activity (base)
Settlement totals