Cozy Finance Exploit Drains $170,000 From Optimism (OP) Cover Markets

An attacker drained about $170,000 in USDC.e from Cozy Finance's cover markets on Optimism (OP) and bridged the funds out within 13 minutes, Blockaid reports.

(09:34 AM UTC)
4 min read
AI SummaryAI
  • Cozy Finance exploit on Optimism drained roughly $170,000 early Monday.
  • Attacker moved 163,326 USDC.e across 63 token transfers at 05:43 UTC.
  • Funds were bridged out at 05:56 UTC, 13 minutes after the drain began.
  • An August 2025 attack cost Cozy Finance about $427,000 on Optimism.
k7rq2fdm

Cozy Finance Loses $170,000 on Optimism

DeFi cover protocol Cozy Finance lost roughly $170,000 in an exploit on Optimism (OP) early Monday, the second time the insurance provider has been drained on the Ethereum Layer 2 network. The incident became public through an emergency community alert that blockchain security firm Blockaid posted on X, flagging an ongoing exploit pulling funds from the protocol's protection markets — markets that sell users cover against failures elsewhere in DeFi, which concentrates stablecoin liquidity in a single venue.

On-chain data from the OP Mainnet explorer shows the exploit transaction landed at 05:43 UTC. It moved approximately 163,326 USDC.e out of the protocol across 63 separate token transfers and, in the same transaction, burned about 1.6 million Cozy PToken (CPT), the receipt token users hold against their coverage positions. The attacker then approved an additional token and pushed the stolen funds through a bridge at 05:56 UTC — a 13-minute window from first drain to cross-chain exit that closed before Blockaid could publish its warning. Explorer records show no further movement from the attacker's wallet since the bridge out, and no hop through a crypto mixer is visible on-chain so far. Neither Cozy Finance nor the Optimism team has issued a public statement on the exploit at the time of writing.

Second Strike After a $427,000 Loss in 2025

Monday's drain is not an isolated failure but a repeat event. An attacker took roughly $427,000 from Cozy Finance on Optimism in August 2025, and security researchers at Verichains traced that loss to a flaw in the withdrawal code: it never checked who completed a redemption, so anyone able to trigger one could redirect the payout. No comparable technical explanation has been published for the new breach, and it remains unconfirmed whether the same class of bug is involved again.

The relative scale of Monday's loss is stark. Cozy Finance currently ranks fifth among insurance protocols tracked by DefiLlama, holding about $1.3 million in total value locked, of which roughly $172,000 sits on the Optimism side. On those figures, the attacker appears to have swept close to the entire deployment on OP Mainnet — a rollup that settles back to Ethereum rather than an independent sidechain — effectively emptying the chain's coverage markets. For a protocol whose product is trust in payout mechanics, a second redemption-path failure on the same network is a reputational hit that TVL rankings understate, and it raises solvency questions across the broader Optimism ecosystem.

The breach lands in an unforgiving stretch for DeFi security. Notional Finance lost $1.73 million last week to an integer overflow bug, and days earlier Full Sail wound down operations after an attacker extracted roughly $91,000. Monday also brought a far larger case elsewhere: about $320 million in Bitcoin left the Liquid Network, with the actors claiming white hat intentions on-chain. Early loss figures tend to move as well — Blockaid initially sized the August Flow exploit at $9.3 million before the network revised the damage to near $410,000 — so the final tally for Cozy Finance may still shift as fund tracing continues.

On-Chain Record Points to a Familiar Gap

From our read of the on-chain record, this case is unusually clean for forensics: a single exploit transaction, an identified bridge exit and a wallet that has not moved since — each element independently verifiable on OP Mainnet, with Blockaid's public alert serving as the incident's official disclosure. The open question is root cause. The protocol's 2025 post-mortem traced that earlier loss to redemption code that never verified the redeemer's identity; no equivalent explanation exists yet for Monday's drain. A second breach on the same chain within roughly 13 months, sweeping nearly the whole Optimism deployment, will test whether the ecosystem's recent 546.9M OP governance reallocation toward growth funding can coexist with baseline protocol security.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Price-Impacting News