Submit incident
Documented

A Math Error in AI-Generated Code Cost a DeFi Lending Protocol $1.8 Million

January 1, 2026
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC2211View source ↗
LinkedInX

What happened

In February 2026, the decentralized finance protocol Moonwell lost USD 1.8 million after deploying a smart contract update that contained a mathematical error in AI-generated code. The error originated in a GitHub pull request co-authored by an AI coding assistant, merged into a live lending system without the end-to-end integration testing that would have surfaced the flaw before it reached users with real funds at stake.

The mistake was concrete and catchable. The code was designed to calculate a token's value in US dollars by multiplying an exchange rate by a USD price feed. The AI-generated logic instead returned only a relative ratio between the two figures, producing a price of roughly $1.12. That figure, in the context of an active lending protocol, should have registered immediately as anomalous during any structured review of the contract's outputs. No such review stood between the AI-generated code and the live deployment.

Post-incident documentation described the failure pattern as vibe coding: using generative AI to write financial logic and shipping it without performing the adversarial, end-to-end verification that high-stakes systems demand. Writing smart contract code with an AI assistant does not change what that code must do. A pricing function in a lending protocol carries direct monetary consequences for every user whose collateral depends on it, and the standard for confirming that logic does not fall because a machine wrote the first draft. The commits were made transparently, but transparency is not the same as correctness.

The incident sharpened a debate about responsibility that the DeFi industry has been deferring. An audited protocol is only as safe as its most recent changes, and if those changes include AI-generated code that no human has independently verified, the audit provides less assurance than it appears to. Multiple Moonwell users absorbed real losses. Policy observers cited the case as an argument for Software Liability frameworks requiring Human-in-the-Loop certification before AI-assisted code reaches production in financial systems, placing formal accountability on the humans who approve, not only those who author.

What was missing was not technical capability. Integration tests that validate a price output against a known oracle reference would have caught this error in minutes, and those tests existed as standard practice before this pull request was written. What was missing is an accountability layer: a provable record of what a system produced, which human reviewed and approved that output, and what verification steps were completed before deployment. Without that record as a precondition for release, AI involvement in financial code remains invisible to the audit trail until a loss event makes it visible.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
A Math Error in AI-Generated Code Cost a DeFi Lending Protocol $1.8 Million
2026