Cozy Finance Loses Another $170,000 on Optimism
Blockaid says the attack was quickly moved out through a bridge, while Cozy Finance had already been targeted on Optimism before. The exploit fits into a year where DeFi security is under heavy pressure.

Key Takeaways
- Cozy Finance lost about $170,000 again on Optimism in an exploit that was moved through a bridge within 13 minutes.
- The attack drained about 163,326 USDC.e and burned about 1.6 million Cozy PToken at the same time.
- Earlier, Cozy Finance had already lost about $427,000 in August 2025 in another attack on the same setup.
Cozy Finance has been hit by another exploit on Optimism. According to blockchain security firm Blockaid, about $170,000 (€146,300) was drained early Monday and moved through a bridge within 13 minutes. The incident affects a protocol that offers protection against DeFi failures and comes on top of an earlier attack on the same setup in 2025.
Fast Drain on Optimism
According to explorer data, the exploit transaction came in at 05:43 UTC. About 163,326 USDC.e was taken from the protocol through 63 token transfers. In the same transaction, about 1.6 million Cozy PToken, CPT, was also burned. Shortly after that, the attacker approved a token and sent the loot through a bridge at 05:56 UTC.
Blockaid only published its warning after the money had already been moved. According to the explorer, no further movement has been seen from the wallet since then. Notably, the attack contract went live on September 2, five days before the drain. The wallet received its first funds through a Relay solver.
Second Blow for Cozy Finance
This is not the first time Cozy Finance has lost money on Optimism. In August 2025, an earlier attack cost the protocol about $427,000 (€367,400), according to security firm Verichains. The weakness was in the withdrawal code, which did not check who completed a redemption.
The timing is especially sensitive because DeFi security is under heavy pressure in 2026. In the first eight months of this year, DeFi protocols lost at least $1.3 billion (€1.1 billion) to exploits, according to a recent overview. Compromised private keys have become a bigger attack vector than smart contract bugs. Another analysis also shows that only 41% of TVL sits in protocols with formal verification or multiple independent audits. That pattern fits broader security problems in DeFi, such as in crypto hacks in 2026, where key compromise and governance attacks show up more often than classic contract bugs.
Why This Matters for DeFi
For European crypto readers, this case shows that even niche protocols with an insurance function remain vulnerable. Cozy Finance now ranks fifth among insurance protocols on DefiLlama, with about $1.3 million (€1.1 million) in value locked. On the Optimism side, DefiLlama showed about $172,000 (€148,000) still there, which means the attacker appears to have drained almost the entire deployment there.
That makes this incident relevant beyond one protocol. The mix of repeated attacks, limited audit coverage, and a growing number of claims in DeFi insurance suggests that security and loss handling are becoming more and more important for users and providers.