Blockchain security firm Blockaid flagged an active exploit on Cozy Finance on Optimism at on September 7, reporting that approximately $170,000 had been drained from the protocol. The attacker moved the funds through a bridge and exited within 13 minutes of the initial transaction.

The exploit transaction landed at 05:43 UTC, according to OP Mainnet explorer data. It moved approximately 163,326 USDC.e out of the protocol across 63 token transfers while the same transaction burned roughly 1.6 million Cozy PToken. The attacker approved a token and pushed the funds through a bridge at 05:56 UTC, before Blockaid had published its alert. Explorer records showed no further movement from the identified wallet after that point.

The attack contract went live five days before the drain

Blockchain records show the attack contract was deployed on September 2, five days before the theft. The wallet drew its first funds from a Relay solver. Blockaid also named Cozy Set as the abused token contract, which remains unverified on-chain and still held approximately $4,168 in USDC.e at the time of reporting.

The same protocol lost $427,000 on the same chain a year earlier

The September 7 incident is not Cozy Finance's first loss on Optimism. Security firm Verichains found that an attacker took approximately $427,000 from the protocol in August 2025. That earlier breach exposed a flaw in the withdrawal code that never verified who completed a redemption, meaning any address could trigger a withdrawal regardless of entitlement.

Cozy Finance describes itself as a protection market protocol where users can purchase cover against DeFi failures, including smart contract exploits, oracle manipulations, and liquidation events. The protocol occupies a specific niche within the broader DeFi insurance sector alongside platforms like Nexus Mutual and InsurAce. The irony of an insurance-adjacent protocol suffering repeat exploits on the same network has been noted previously in security research circles. Cozy Finance currently ranks fifth among insurance protocols on DefiLlama with approximately $1.3 million in total value locked across its deployments.

A second exploit on the same chain within 13 months raises a specific question about patch completeness. When a protocol suffers an exploit and issues a fix, the repair typically addresses the identified vector. A second breach on the same network suggests either the original flaw was incompletely patched, a related vulnerability existed in adjacent code, or an entirely separate attack surface was found.

How the September 7 attack fits the broader DeFi exploit pattern

The Cozy Finance incident landed during a particularly active period for DeFi security failures. Notional Finance lost $1.73 million the previous week to an integer overflow bug. Full Sail wound down operations on Optimism's parent ecosystem after an attacker drained approximately $91,000 through a Switchboard oracle exploit on Sui on August 29. On the same day as the Cozy Finance incident, purported white-hat hackers withdrew approximately $320 million in Bitcoin from Liquid Network's federation wallet.

Integer overflow vulnerabilities, the class that hit Notional Finance, occur when a calculation produces a result too large for the data type used to store it, causing the value to wrap around to a small or negative number. In DeFi contexts, these bugs frequently affect calculations involving token amounts, share prices, or fee accumulators. The Cozy Finance 2025 exploit involved a different class, an access control failure in withdrawal logic. The two incidents reflect distinct vulnerability categories, which means a protocol that patched one does not automatically become protected against the other.

Blockaid's alert sizing warrants note. The firm previously sized an August Flow exploit at $9.3 million before the network revised the damage figure to approximately $410,000. Early loss figures in DeFi exploits frequently shift as investigators trace fund flows and identify what was recovered or returned. The $170,000 figure for the Cozy Finance incident represents Blockaid's initial assessment.

Cozy Finance had not published a post-incident statement at the time of writing. Blockaid said it was continuing to trace the funds.

Vitalik Disputes AI Will Crash Bitcoin 50% in Two Years | HODL FM NEWS
Vitalik publicly countered Liron Shapira’s claim that AI would crash Bitcoin 50% in two years. Shapira lowered his confidence from 50% to 40% after the exchange.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.