Nobody Broke the Contract — They Just Asked It Nicely With the Right Permissions
August's exploit wave barely involved code bugs. Hijacked bridge permissions, unauthorized minting, a compromised exchange. The attack surface moved to config, and almost nobody is auditing config.