Security Desk · Tool

Crypto Exploit Tracker

$4.78bn drained across 115 logged incidents

Every major crypto exploit we log: what was hit, how much was lost, and how the attack actually worked, with the on-chain references and sources attached. Maintained by the Security Desk; updated as incidents are verified.

2026 so far$1.36bn61 incidents
2025 full year$3.42bn54 incidents
Biggest single hit$1.40bnBybit Multisig Cold-Wallet Hack
Days since last major hackTriple-A Hot Wallet Drain
Most common vectorAccess Control30 of 115 incidents

WHERE THE MONEY WENT · BY VECTOR

  1. Access Control$2.37bn
  2. Phishing$798M
  3. Other$679M
  4. Bridge Exploit$322M
  5. Rugpull$298M

LOSSES · LAST 12 MONTHS

sort:
  1. Triple-A Hot Wallet Drain$10MOtherMultichainPayments

    On 25 July 2026, wallets belonging to Triple-A, a licensed digital payments company, were drained of more than $9.7M across TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated about 5,227 ETH into a single address. The analyst who flagged it reported that deposits had not been disabled, so each new deposit was being taken as it arrived.

    Triple-A holds a Major Payment Institution licence from the Monetary Authority of Singapore, an ACPR payment institution licence and French CASP registration, FinCEN and NMLS registration in the United States, and FINTRAC registration in Canada, and had secured in-principle approval from Dubai VARA ten days earlier. The vector is unconfirmed and logged as Other for that reason: losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at compromised hot wallet signing keys rather than a contract flaw. Triple-A published no incident notice, so the loss is an on-chain estimate rather than a reconciled figure.

  2. B² Network Staking Exploit$4MAccess ControlBitcoin L2Staking

    On 23 July 2026, B² Network, a Bitcoin layer-2, lost about $3.86M after an attacker seized the upgrade authority on its staking contract. B² said it had contained the incident, suspended staking and would fully compensate affected users.

    The third protocol drained on the same day, after the attacker gained control of the staking contract's upgrade authority.

  3. Verus Ethereum Bridge Exploit (second)$8MBridgeEthereumBridge

    On 23 July 2026, the Verus Ethereum bridge was drained of about $7.54M through the same contract flaw as its May 2026 hack. An attacker forged the cross-chain proof the bridge failed to verify and triggered unbacked payouts, taking ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.

    Funds had been redeposited on 8 July and were drained again two weeks later. The stolen funds were converted into roughly 3,916 ETH and moved through Tornado Cash. Verus held close to $100M in total value locked at the start of 2025 and is down to single-digit millions.

  4. AFX Trade Bridge Exploit$24MAccess ControlArbitrumDerivatives

    On 23 July 2026, AFX Trade, a decentralised perpetuals exchange settling in USDC, lost about $24.15M after attackers compromised the validator signing keys behind a bridge it runs on Arbitrum and authorised withdrawals. The team suspended bridge operations.

    Arbitrum confirmed its own native bridge was not involved; the failure was in AFX's own bridge and its key handling. The stolen USDC was moved to Ethereum. It was the largest of three protocol losses logged on the same day.

  5. Cascade$1MSmart Contract BugArbitrumPerps

    Polychain-backed Arbitrum trading platform Cascade reported on 16 July 2026 that its CLS vault was exploited, with 1.34 million USDC of locked user funds drained.

    The incident came barely a day after the Ostium oracle exploit on the same network, extending a run of attacks on Arbitrum-based perpetuals platforms. Cascade confirmed the drain affected user funds in the CLS vault; a full root-cause disclosure had not been published as of 17 July 2026.

  6. Ostium$18MOracle ManipulationArbitrumPerps

    Arbitrum perpetuals DEX Ostium suspended trading on 15 July 2026 after an attacker used a compromised oracle signer key to submit future-dated price reports, draining an estimated $18 million in USDC from its liquidity vault in five minutes.

    Between 14:18 and 14:23 UTC the attacker, using a registered PriceUpKeep forwarder and around 20 looped trades via delegated actions, submitted oracle reports with manipulated future timestamps so losing trades paid out as winners from the public OLP vault. Blockaid identified the exploit and put extraction at about $18 million, while CertiK estimated closer to $22 million, ExVul reported $11.86 million leaving the vault and some outlets cited up to $24 million; Ostium paused trading within the hour, preserving trader funds and open positions, with a full post-mortem pending.

  7. Bonzo Lend$9MOracle ManipulationHederaLending

    Hedera's largest DeFi lender, Bonzo Lend, was exploited for about $9 million at 00:51 UTC on 11 July 2026 after a third-party oracle accepted a forged SAUCE token price.

    The attacker submitted a SAUCE price inflated by twelve orders of magnitude, which the Supra oracle accepted after a signature verification bypass (a zeroed signature), then used 250 SAUCE worth about $1 as collateral to borrow $9.05 million from the protocol. Around $5.25 million was bridged to Ethereum, a white hat returned roughly $1 million, Bonzo paused the protocol and Supra acknowledged the flaw and deployed a fix; PeckShield tracked the bridged funds.

  8. BonkDAO$20MGovernance AttackSolanaDeFi

    On 6 July 2026 an attacker drained roughly $20 million in BONK tokens from BonkDAO's treasury by passing a malicious governance proposal; BONK fell around 8–10%.

    The attacker accumulated an estimated $4 million of BONK to dominate token-weighted voting on Solana's Realms platform, then pushed through 'BIP #76', submitted on 30 June and dressed as a governance renewal plan, whose operative clause transferred 4.43 trillion BONK to an attacker-controlled wallet; only 7 of more than 18,000 eligible wallets voted, and the attacker cast 99.878% of votes. The DAO coordinated with the Solana Foundation, law enforcement and exchanges, with Upbit, Bithumb and Kraken suspending BONK deposits and withdrawals; no recovery had been confirmed by mid-July.

  9. Summer.fi$6MFlash LoanEthereumYield

    On 6 July 2026 Summer.fi's Lazy Summer vaults were exploited for about $6 million in DAI via a flash-loan-assisted price manipulation, prompting the protocol to pause all vaults.

    PeckShield confirmed roughly $6 million was extracted after the attacker used a $65.4 million flash loan to manipulate vault share pricing (described by trackers as a donation-style attack), with the largest single victim losing about 8.6 million USDC. Summer.fi paused all Lazy Summer vaults and zeroed deposit caps; researchers linked the exploited pricing weakness to stale tokens left over from the Stream Finance collapse the previous November.

  10. Polymarket$3MSupply ChainPolygonDeFi

    In late June 2026 Polymarket users lost about $3 million after a compromised third-party vendor was used to inject malicious JavaScript into the prediction market's front end.

    The injected script ran silently in users' browsers on the legitimate site and prompted routine-looking wallet signatures that authorised unintended transfers; 11 user wallets were affected. Stolen funds were bridged from Polygon to Ethereum, swapped to roughly 1,893 ETH and consolidated into a single wallet. Polymarket's smart contracts were not exploited, and the company promised full refunds to victims holding its PUSD collateral.

  11. SecondFi$2MPrivate Key CompromiseCardanoWallet

    Cardano wallet project SecondFi confirmed three attacks between 21 and 23 June 2026 that drained 16 million ADA (about $2.4 million) from 374 wallets, with SlowMist estimating up to $20 million potentially at risk.

    The flaw was a deterministic nonce derivation bug in SecondFi's proprietary software signer: every signed transaction leaked cryptographic information that allowed attackers to reconstruct users' private keys from public blockchain data alone. The team rescued a further 129 million ADA to a third-party custodian before attackers could reach it and, with EMURGO, launched a two-week recovery and restitution plan with a checking tool for affected wallets.

  12. Taiko Bridge$2MBridge ExploitEthereumBridge

    Ethereum layer-2 Taiko halted block production in late June 2026 after an attacker used forged cross-chain proofs to withdraw about $1.7 million from its bridge without matching deposits.

    The root cause was an SGX signing key left exposed on GitHub: Taiko's permissionless prover registration allowed a rogue SGX instance to register and submit invalid proofs that the system accepted, letting fake withdrawal requests clear on Ethereum. The team froze activity within hours and urged users to withdraw; the attacker had already moved about 2 million TAIKO (roughly $170,000) to MEXC before the freeze, and the TAIKO token fell around 10%.

  13. JaredFromSubway MEV Bot$8MPhishingEthereumInfrastructure

    On 20 June 2026 the notorious jaredfromsubway.eth MEV bot was drained of roughly $7.5 million in WETH, USDC and USDT by a counter-MEV honeypot (some outlets put the figure as high as $15 million).

    The attacker deployed 66 fake token contracts and rigged liquidity pools that looked like profitable trades; when the bot took the bait it granted token approvals to attacker-controlled contracts, and those dangling approvals were later used to sweep the bot's holdings in a single coordinated transaction. Blockaid had flagged the attacker's wallets and contracts as malicious before the final drain, and Chainalysis and The Block documented the incident as the most prominent case of a predator bot being drained by its own logic.

  14. Aztec Private Rollup Bridge$2MSmart Contract BugEthereumBridge

    Three days after the Aztec Connect exploit, an attacker drained about $2.16 million (roughly 1,158 ETH) from Aztec's deprecated Private Rollup Bridge on 17 June 2026 via its escape-hatch mechanism.

    The attacker constructed a fake zero-knowledge claim proof accepted by the RollupProcessor's verification logic: the proof system did not correctly bind a victim's final output note to its rightful recipient, letting a malicious escape-hatch caller substitute arbitrary outputs. Aztec confirmed the exploit targeted a deprecated product unrelated to the current network.

  15. Aztec Connect$2MSmart Contract BugEthereumInfrastructure

    On 14 June 2026 an attacker drained about $2.1 million from Aztec Connect, the deprecated privacy rollup product, using a crafted zero-knowledge proof that the verification logic wrongly accepted.

    This was the first of two Aztec legacy-contract exploits in three days, together costing over $4 million. Aztec attributed the issues to proof-verification bugs in deprecated contracts; the Aztec Foundation stressed the affected products have no link to the current Aztec network or the AZTEC token.

  16. Secret Network$5MBridge ExploitSecret NetworkBridge

    Starting 10 June 2026, an attacker exploited an infinite-mint bug in Secret Network's Axelar bridge contract, draining about $4.67 million in Axelar-wrapped assets; the theft went unnoticed for seven days.

    The deployed contract was a modified CW20-ICS20 fork with core security checks removed, so it did not verify the source channel of inbound IBC packets; the attacker spun up a single-validator Cosmos chain, self-relayed forged packets to mint unbacked saTokens, then redeemed them over the legitimate Axelar channel to drain real escrowed assets including saUSDT, saUSDC, saDAI, saWETH and saWBTC. The hole was discovered on 17 June when a failed transaction produced an insufficient-funds error, prompting investigation of the bridge's reserves.

  17. Raydium$1MSmart Contract BugSolanaDEX

    On 10 June 2026 an attacker drained about $1.34 million from five deprecated Raydium legacy AMM V3 pools on Solana using forged LP tokens.

    The legacy AMM V3 program, phased out in 2021 but never immobilised, did not validate the LP mint address, so a fake LP mint let the attacker withdraw real pool assets — roughly 893,700 USDC, 5,603 SOL and 150,177 RAY. The funds were bridged to Ethereum and routed through KuCoin and FixedFloat into Tornado Cash; Raydium said no current users were affected and pledged full repayment from its treasury.

  18. Humanity Protocol$31MPrivate Key CompromiseEthereumInfrastructure

    Identity network Humanity Protocol lost at least $31 million (estimates ranged to $36 million) on 8–9 June 2026 after seven private keys stored on a malware-infected developer machine were compromised; the H token crashed more than 80%.

    The infected device held the admin hot wallet key plus three Ethereum Safe owner keys and three BNB Chain Safe owner keys backed up during the 2025 mainnet launch. Using three of six ETH Safe keys, the attacker transferred Bridge ProxyAdmin ownership, upgraded the bridge to a malicious implementation, swept about 141.2 million H in one transaction and minted a further 200 million H via malicious upgrades. PeckShield ranked it June's largest incident, and HTX Insights reported that around 15,403 ETH of proceeds later commingled on Bitcoin with funds from the Kelp DAO exploit, suggesting a possible link between the actors.

  19. Syscoin Bridge$10MBridge ExploitSyscoinBridge

    In early June 2026 an attacker exploited a proof-parsing flaw in the Syscoin bridge relay to mint roughly 5 billion unauthorised SYS tokens, an incident valued at about $10 million; SYS fell around 20%.

    The bridge relay's proof-validation code misparsed a deliberately malformed proof, treating it as valid evidence of a burn on the NEVM side that never happened, which authorised minting on the UTXO side. Syscoin halted the bridge, coordinated freezes with exchanges and partners, and later said it had recovered and burnt all 5 billion minted SYS, restoring the pre-exploit supply, though the bridge remained offline.

  20. Gravity Bridge$5MPrivate Key CompromiseEthereumBridge

    The Ethereum–Cosmos Gravity Bridge was drained of about $5.4 million on 30 May 2026 in what researchers assessed as a compromised signing key rather than a code flaw.

    With enough valid validator signing keys, forged withdrawals are treated as legitimate; the attacker took about $4.3 million in USDC, 274 WETH, $434,000 in USDT and 14.16 PAXG, laundering a portion through ChangeNow and Binance while retaining roughly 2,100 ETH. Researchers cited the incident as part of 2026's pattern of bridge losses driven by key compromises rather than smart contract bugs.

  21. DxSale$7MAccess ControlBNB ChainDeFi

    Launchpad and locker platform DxSale lost about $7.3 million in late May 2026 when more than 1,400 legacy BNB Chain liquidity lockers were unlocked and drained in a single coordinated flow.

    On 26 May the locker contract's owner called transferOwnership, passing control to the attacker after admin rights had reportedly moved through roughly 80 obscuring wallet transfers; auditor Coinsult traced the drain to a privileged setFee function (reset to 1 wei) combined with backdated lock configurations that made locked deposits withdrawable, executed via EIP-7702 batch delegation. Community researchers raised the possibility of insider involvement or a leaked owner key; roughly 1,400 liquidity providers were affected.

  22. Ill Bloom Wallet Vulnerability$5MPrivate Key CompromiseMultichainWallet

    A coordinated sweep on 27 May 2026 drained about $3.1 million from 431 wallets whose seed phrases were generated with a weak random-number generator — the 'Ill Bloom' flaw — with a further $2.1 million in USDT stolen later, pushing confirmed losses past $5 million.

    Certain older or lesser-known software wallets used an insecure pseudorandom number generator during seed phrase creation, shrinking the keyspace enough for attackers to brute-force recovery phrases and derive private keys. Security firm Coinspect, which disclosed the flaw publicly in early July, traced 2,114 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon, with first-funding dates from 2018 to May 2026; hardware wallets and mainstream software wallets were not affected.

  23. New Market Trading$4MAccess ControlEthereumDeFi

    New Market Trading was exploited for about $3.98 million across Ethereum, Base and Arbitrum on 25 May 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as an access-control exploit in the protocol's contracts. Detailed independent reporting on the incident is limited.

  24. StablR$3MPrivate Key CompromiseEthereumStablecoin

    Stablecoin issuer StablR suffered a private key compromise on 23 May 2026, with an attacker minting 8.35 million USDR and 4.5 million EURR and extracting about $2.8 million.

    The unauthorised minting depegged both tokens, with EURR falling to about $0.85 and USDR to about $0.40 before the situation was contained. Global Ledger classified the incident as a compromised-key attack on the issuer's minting controls rather than a smart contract flaw.

  25. RetoSwap$3MSmart Contract BugMoneroDEX

    On 20 May 2026 the Monero P2P exchange RetoSwap, a Haveno Protocol fork, was exploited for about 7,000 XMR (roughly $2.7 million) via a forged-message flaw in its trade arbitration flow.

    The client accepted a forged, out-of-order ACK message without verifying the sender's signature, letting the attacker overwrite the arbitrator's stored Tor address with their own; the attacker then held two of three keys to newly created trade multisig wallets and swept victims' XMR the moment deposits landed. RetoSwap suspended trading, and Haveno's lead developer shipped a fix the same day preventing node-address updates before multisig creation.

  26. Echo Protocol$77MPrivate Key CompromiseMonadYield

    On 19 May 2026 an attacker used a compromised admin key to mint about 1,000 unauthorised eBTC on Echo Protocol's Monad deployment, a paper value of roughly $76.7 million, though the realised take was far smaller.

    The eBTC minting contract had no multisig, timelock or mint limits, so the stolen admin key gave the attacker unilateral minting rights. Thin liquidity on Monad limited the realised proceeds to roughly $816,000 in ETH sent to Tornado Cash, plus about $3.45 million in WBTC borrowed against minted eBTC on Curvance. Echo regained control of the admin keys, burnt the remaining 955 eBTC, paused Monad cross-chain functionality and upgraded the affected contract.

  27. Verus–Ethereum Bridge$12MBridge ExploitEthereumBridge

    The Verus–Ethereum bridge was exploited on 18 May 2026 for roughly $11.5 million, the largest single incident of the month by most trackers.

    Attackers bypassed the bridge's verification logic and withdrew about 1,625 ETH (~$3.44 million), 103.57 tBTC v2 (~$8.06 million) and 147,659 USDC from the Ethereum side. The project's incident report followed around eight hours after the initial theft; BlockSec and monthly trackers including CertiK-linked reporting flagged cross-chain bridges as May's most-targeted category, with this incident at the top.

  28. THORChain$11MPrivate Key CompromiseMultichainDEX

    On 15 May 2026 an attacker drained about $10.7 million from one of THORChain's five Asgard vaults across Bitcoin, Ethereum, Base and BNB Chain, crashing RUNE around 15%.

    The attacker was a newly churned node operator who had joined the network two days earlier; the working theory supported by PeckShield, Cyvers and THORChain's own report is that vault key material leaked through a vulnerability in the GG20 threshold signature scheme implementation during keygen or signing rounds. Node operators paused the network within hours via the Mimir governance module, and trading resumed after a five-week halt alongside a $10 million compensation portal for affected users.

  29. Transit Finance$2MSmart Contract BugTronDEX

    Cross-chain swap aggregator Transit Finance lost about $1.88 million on 13 May 2026 through an exploit of a deprecated smart contract on Tron.

    DefiLlama classifies the incident as a deprecated smart contract exploit, and Nominis records it as a contract logic flaw. Funds were drained from legacy contracts that remained callable despite no longer being part of the active product.

  30. TrustedVolumes$6MAccess ControlEthereumDeFi

    Liquidity provider TrustedVolumes lost about $5.87 million in WETH, USDT, WBTC and USDC on 7 May 2026 after an attacker exploited its request-for-quote (RFQ) order flow.

    Analysts described the incident as an access-control failure in which forged RFQ orders were used to pull funds from the market maker; the exploiter began laundering proceeds through Tornado Cash, RailGun and THORChain. Global Ledger noted the firm's public incident report followed roughly 11 minutes after the initial transaction.

  31. Ekubo$1MSmart Contract BugEthereumDEX

    On 6 May 2026 attackers drained about $1.4 million, mostly in wrapped bitcoin, from users of Ekubo's EVM swap router contracts via an approval-based exploit.

    The router's IPayer.pay callback failed to verify that the payer matched the lock initiator, so attackers could craft a malicious lock payload naming any address as payer and call transferFrom against wallets that had approved the routers, looping the exploit roughly 85 times at about 0.2 WBTC per iteration. Only the Ethereum V2/V3 and Arbitrum V3 routers were affected; Starknet's core deployment and all liquidity providers were untouched, and Ekubo urged users to revoke approvals on the three affected immutable contracts.

  32. Wasabi Protocol$5MPrivate Key CompromiseEthereumPerps

    Perpetuals platform Wasabi Protocol was drained of roughly $5 million (initially reported at $4.5 million) on 30 April 2026 after its deployer admin key was compromised.

    The attacker used the compromised deployer key to call grantRole with zero delay, then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining vaults across Ethereum, Base, Berachain and Blast, including wWETH, sUSDC, wBITCOIN and wPEPE pools. Reporting highlighted the absence of a timelock or multisig on the admin role as the key safeguard failure.

  33. Sweat Economy$4MSmart Contract BugNEARDeFi

    On 29 April 2026 an attacker exploited a refund-logic bug in the SWEAT token contract on NEAR, draining about 13.71 billion tokens — roughly 65% of supply, worth up to $3.5 million — in around 30 seconds.

    The contract was missing an access-restriction macro: the attacker chained a no-op call returning empty bytes into ft_resolve_transfer, which the contract interpreted as 'receiver consumed zero tokens' and refunded victims' entire balances to the attacker. The team paused the contract, MEXC froze the attacker's account and Rhea Finance halted SWEAT trading; the team subsequently restored all external user balances and deployed a patched contract.

  34. Aftermath Perps$1MSmart Contract BugSuiPerps

    Sui-based perpetuals platform Aftermath was exploited for about $1.14 million on 29 April 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as a fee-accounting logic flaw in the perps contracts on Sui. Detailed independent reporting on the incident is limited.

  35. Purrlend$2MSmart Contract BugHyperliquidLending

    Lending protocol Purrlend was exploited for about $1.5 million on 25 April 2026, according to DefiLlama's hacks database.

    DefiLlama records the incident across MegaETH and Hyperliquid L1 and attributes it to a fake bridge address exploit in the protocol's logic. Detailed independent reporting on the incident is limited.

  36. Giddy$1MSmart Contract BugEthereumWallet

    Smart wallet platform Giddy was exploited for about $1.3 million on 23 April 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as a protocol logic exploit caused by incomplete EIP-712 signature coverage, which allowed signed messages to be abused to move user funds on Ethereum. Detailed independent reporting on the incident is limited.

  37. Volo$4MPrivate Key CompromiseSuiYield

    Sui liquid staking protocol Volo lost about $3.5 million from three vaults (WBTC, XAUm and USDC) on 21 April 2026 after a privileged admin key was compromised.

    GoPlus Security and ExVul attributed the breach to a compromised operator key obtained through social engineering rather than any flaw in Volo's audited contracts. Volo self-disclosed within hours, froze the vaults, worked with the Sui Foundation, blocked a WBTC bridge attempt and clawed back around $2 million quickly; the team said it recovered nearly all funds, leaving a net loss of roughly $60,000, and absorbed user losses.

  38. Kelp DAO$292MBridge ExploitMultichainYield

    On 18 April 2026 attackers stole about 116,500 rsETH worth roughly $292 million from liquid restaking protocol Kelp DAO's LayerZero-powered bridge — the largest crypto theft of 2026 so far.

    Attackers reportedly compromised a LayerZero Labs developer in early March, poisoned internal RPC nodes and DDoSed external ones so the single verifying DVN read fake burn events, causing the bridge to release rsETH against burns that never happened; rsETH was configured with only one verifier. Kelp paused contracts to block a further $95 million theft, and the Arbitrum Security Council froze over 30,000 ETH of downstream funds. Chainalysis and multiple outlets attributed the attack to North Korea-linked actors, and the exploit triggered $6.2 billion of Aave withdrawals before a 'DeFi United' effort raised about 132,650 ETH to backstop bad debt; Kelp and LayerZero publicly disputed responsibility for the single-verifier configuration.

  39. Rhea Finance$18MSmart Contract BugNEARLending

    NEAR-based lending and trading protocol Rhea Finance was exploited in mid-April 2026 via a flaw in its margin-trading slippage protection, with losses revised from an initial $7.6 million to about $18.4 million on 17 April.

    The attacker constructed a series of swaps that bypassed slippage checks — the system aggregated expected output values across multiple swap steps without accounting for tokens reused across transactions — diverting borrowed reserve assets into attacker-controlled liquidity pools. Rhea paused its lending contracts, and the attacker returned roughly $3.3 million in USDC and 1.56 million NEAR, while around $4.34 million in USDT was frozen.

  40. Grinex$15MPrivate Key CompromiseTronCEX

    Sanctioned Russia-linked exchange Grinex was drained of roughly $13.7–15 million from its hot wallets on 15 April 2026 and halted all operations the following day.

    The theft began around 12:00 UTC on 15 April, with stolen USDT swapped into TRX and ETH to avoid issuer freezes and split across dozens of wallets; TRM Labs later identified around 70 drained addresses, raising the confirmed estimate to about $15 million. Grinex, the successor to sanctioned exchange Garantex, blamed 'Western special services' — a claim no independent researcher has verified. Elliptic and Chainalysis both documented the shutdown of the exchange.

  41. CoW Swap$1MPhishingEthereumDEX

    On 14 April 2026 CoW Swap's cow.fi domain was hijacked and users were redirected to a wallet-draining phishing site, with reported losses of about $1.2 million.

    Attackers used forged documents and weaknesses in the .fi domain registration process to seize the domain at around 14:54 UTC, serving a fake front end that drained connected wallets. CoW DAO confirmed its smart contracts, backend and APIs were not compromised, paused the protocol as a precaution, identified the breach within 19 minutes and restored the domain within 26 hours, later adding RegistryLock protection.

  42. Hyperbridge$3MBridge ExploitEthereumBridge

    On 13 April 2026 an attacker submitted forged state proofs to Hyperbridge's Token Gateway on Ethereum, minting 1 billion bridged DOT and draining escrowed assets; losses were later revised from about $237,000 to roughly $2.5 million.

    The attacker exploited a flaw in the Merkle Mountain Range proof verification logic of the HandlerV1 contract — the proof was not bound to a specific request and a zero-second challenge period allowed immediate execution — seizing admin control of the bridged DOT token. DOT pools on Ethereum, Base, BNB Chain and Arbitrum were affected, though Polkadot's core network and native DOT were untouched. Hyperbridge said a significant portion of the funds was traced to Binance and that it was working with the exchange's compliance team and law enforcement on freezes.

  43. Drift Protocol$286MAccess ControlSolanaPerps

    On April 1, 2026, Drift Protocol suffered a roughly $286M exploit after attackers gained unauthorised administrative control and drained multiple protocol vaults on Solana.

    Early reporting indicated this was not a routine smart-contract math bug but a privileged-control failure. The attacker rapidly drained several core vaults, with stolen assets including JLP, USDC, SOL, cbBTC and wBTC. Drift suspended deposits and withdrawals while investigators traced the outflows. Later reporting from Elliptic said the laundering patterns and on-chain behaviour were consistent with previous DPRK-linked operations, though that remains an attribution claim rather than a court finding.

  44. Resolv Labs$25MAccess ControlEthereumStablecoin

    On March 22, 2026, Resolv Labs suffered an infrastructure breach after attackers gained privileged access through a compromised private key and minted a large block of uncollateralised USR.

    This was not a contract-logic failure so much as the old classic: somebody got access they should not have had. The attacker used the compromised mint authority to create roughly $80M in fake USR, staked part of it into wstUSR, swapped into real assets, and tried to force value out before the protocol could shut the doors. Resolv moved quickly, paused the relevant contracts, burned a chunk of attacker-held supply, and said the realised damage before the pause was far smaller than the headline nominal mint. The important distinction is that the collateral base was not directly emptied; the danger came from fake liabilities being created against it.

  45. USDC Permit Signature Phish$2MPhishingEthereumWallet

    On March 16, 2026, a victim lost $1.76M in USDC after signing a malicious Permit approval that handed spending rights to an attacker-controlled contract.

    No fancy contract math here. The victim was tricked into signing what looked like a routine approval flow, but the Permit granted the attacker's contract the power to transfer the victim's USDC. The funds were drained immediately, swapped into ETH, and split across several wallets. Another reminder that one bad signature can be as fatal as a leaked seed phrase.

    ON-CHAIN

  46. Venus$2MOtherBNB ChainBorrowing

    On March 16, 2026, Venus Protocol on BSC was left with about $2.18M in bad debt after an attacker abused a supply-cap enforcement gap around THE and then pumped the token in thin liquidity.

    This one was slow-cooked, not smash-and-grab. Over roughly nine months, the attacker built a giant uncapped THE position by routing around the normal deposit path and bypassing the intended supply ceiling. Once the position was in place, they started the recursive part: borrow assets, buy THE in low liquidity, push the price higher, transfer more THE into the market, inflate collateral value, repeat. The oracle did what it was told and reflected the manipulated market. When the unwind came, the collateral could not cover the borrowings and Venus was left with bad debt.

    ON-CHAIN

    • Attacker Wallet 10x7a79969a0b9d51d922c4810d2950560360f6f234
    • Attacker Wallet 20x737bc98f1d34e19539c074b8ad1169d5d45da619
    • Attacker Wallet 30x1a35bd28efd46cfc46c2136f878777d69ae16231
  47. Solv Protocol$3MOtherEthereumVault

    On March 5, 2026, Solv's BRO vault was exploited through a double-mint flaw that let the attacker turn a tiny BRO position into a cartoonishly large one and swap it for real SolvBTC.

    The vulnerable BRO contract effectively paid twice in the same mint path. When the ERC-3525 NFT transfer callback fired, tokens were minted once, and then the outer mint routine minted them again. The attacker just looped burn/mint repeatedly until 135 BRO had been inflated into hundreds of millions. Once the fake balance existed, it was exchanged for real SolvBTC. Solv said the impact was confined to the affected vault and committed to covering losses.

    ON-CHAIN

  48. Blend Protocol$11MOracle ManipulationStellarBorrowing

    On February 22, 2026, the YieldBlox DAO Pool on Blend V2 was exploited for about $10.86M after an attacker pushed USTRY's SDEX price roughly 100x higher and let the oracle swallow it whole.

    The attacker found an absurdly thin order book and did what attackers do when markets are basically decorative: they walked the price into the sky. Reflector picked up the manipulated SDEX price and Blend treated the attacker's USTRY as prime collateral instead of what it actually was. That opened the door to borrowing tens of millions in XLM and USDC against collateral worth a fraction of that. Once again, the oracle was not hacked in the Hollywood sense; it was just far too trusting.

    ON-CHAIN

    • Attacker AddressGBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC
    • YieldBlox DAO PoolCCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS
    • Oracle AdapterCD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR
    • Reflector OracleCALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M
  49. IoTeX ioTube Bridge$4MAccess ControlEthereumBridge

    On February 21, 2026, IoTeX's ioTube bridge lost about $4.4M on the Ethereum side after attackers compromised the Validator owner account and upgraded it to bypass the bridge's security checks.

    Once the owner account was in hostile hands, the attacker replaced the Validator logic with something that effectively waved everything through. That broke the trust boundary protecting the MintPool and TokenSafe contracts, letting the attacker mint bridge-side assets and drain reserve tokens. IoTeX managed to freeze and blacklist a meaningful slice of the fallout, but not before real value had already left.

    ON-CHAIN

    • Attacker Address0x6487B5006904f3Db3C4a3654409AE92b87eD442f
  50. Moonwell cbETH Oracle Incident$2MOracle ManipulationBaseBorrowing

    On February 15, 2026, Moonwell on Base suffered about $1.78M in losses when cbETH was mispriced at roughly $1.12 instead of around $2,200, triggering mass liquidations and cheap borrowing.

    This was not subtle. The oracle pipeline effectively passed through a token ratio without multiplying it back into the dollar value of ETH. That meant the protocol treated cbETH as almost worthless. Liquidation bots stepped in, repaid pocket change, and received outsized chunks of collateral. Other users borrowed against the same broken number. Moonwell moved to clamp the market fast, but not before the bad price had already done its damage.

    ON-CHAIN

    • Affected AssetscbETH (primary), cbBTC, tBTC
  51. CrossCurve$3MOtherMultichainBridge

    On February 1, 2026, CrossCurve lost roughly $2.9M after an attacker exploited an authorisation bypass in ReceiverAxelar's express execution flow.

    Axelar's model is supposed to bind execution to validated cross-chain messages. The weak point here was a path that skipped that validation and relied too heavily on attacker-controlled metadata. The result was spoofed messages that looked close enough to pass local checks, letting the attacker trigger unlocks they had no right to trigger. CrossCurve responded with a white-hat ultimatum and threat of legal follow-through, which is usually what teams say when the chain has already spoken.

    ON-CHAIN

    • Funds Holder 10xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE
    • Funds Holder 20x8c259f1e53e79408095d0ba805554d4cdda15285
    • Funds Holder 30x851c01d014b1ad2b1266ca48a4b5578b67194834
  52. Step Finance Treasury Breach$30MAccess ControlSolanaTreasury

    On January 31, 2026, Step Finance suffered a treasury breach of roughly $27M-30M after multiple treasury wallets were compromised and stake authority was transferred away.

    Step described the route as a well-known attack vector, which usually means something operational and ugly rather than elegantly novel. Once the attacker had the relevant wallet access, they moved stake authority, unstaked, and drained a huge SOL position. The key point is that this appears to have been treasury-specific rather than a user-fund contract exploit, but $30M disappearing is still $30M disappearing.

    ON-CHAIN

    • Compromised Stake Account6G53KAWtQnZSSN6HUxnBs3yYsK1aCuJRbrcPbWGY71LL
    • Attack Transaction2w8sgATZwcmRMHEsG3nutmZJrskVkp74LAwTTEyxSMBJhnZ7Ux4ticeYAYnTb6K44m1XYziPvqonSkZeukAAFadZ
  53. Aperture Finance$4MOtherMultichainRouting

    On January 25, 2026, Aperture Finance V3/V4 contracts were exploited for about $3.67M across multiple chains through a similar arbitrary-call / approval-abuse flaw.

    The attacker did not need users to do anything in the moment. The damage came from approvals that already existed. Once the vulnerable call path was abused, ERC-20 and even NFT-style approvals could be cashed in. The exploit also overlapped with the wider SwapNet incident, which suggests the attackers were not improvising but moving through a known pattern.

    ON-CHAIN

    • Affected Contract 10xD83...8913
    • Affected Contract 20x008...d857
    • Affected Contract 30xe00...05cB
  54. SwapNet$17MOtherMultichainExchange

    On January 25, 2026, SwapNet was hit for about $17M after attackers abused an arbitrary-call style flaw to weaponise existing token approvals.

    This one was grimly practical. Users had already approved router-style contracts, and the vulnerable logic let attackers steer those approvals into unauthorised transferFrom calls. In other words, the protocol became a machine for cashing in permissions users had granted earlier under normal conditions. This was linked to the same broader approval-abuse wave that also hit Aperture.

    ON-CHAIN

    • Router Contract0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e
  55. SagaEVM$7MOtherSagaEVMChainlet

    On January 21, 2026, SagaEVM suffered a roughly $7M incident involving coordinated malicious deployments and cross-chain exits to Ethereum.

    Saga's account of this is important: they said there was no validator compromise, no consensus failure, and no signer key leak. That suggests the failure lived inside the chainlet or attached execution environment rather than the network's deeper trust layer. Still, the attacker got real assets out before the chainlet was halted, which is all users and markets tend to care about.

    ON-CHAIN

    • Exploiter Wallet0x2044697623afa31459642708c83f04ecef8c6ecb
  56. Makina Finance$5MFlash LoanEthereumYield Aggregator

    On January 20, 2026, Makina Finance suffered a $5M oracle-manipulation exploit against the DUSD/USDC Curve pool, with part of the value intercepted by an MEV builder.

    The attacker pulled a giant USDC flash loan, distorted the MachineShareOracle's pricing, and used the bad number to drain the relevant stablecoin liquidity. The funny detail, if one can call it funny, is that a big chunk of the exploit value was frontrun and effectively stolen from the thief by an MEV builder. DeFi increasingly has these nested theft structures now: protocol gets robbed, then the robber gets partially robbed on the way out.

  57. Yo Yield$4MOtherEthereumYield Aggregator

    On January 13, 2026, Yo Yield lost about $3.7M when 3.84M GHO was swapped into just 112K USDC during a vault operation.

    Sometimes the exploit is simply dreadful execution. The protocol converted something that should have behaved roughly like a stable-for-stable trade into catastrophic slippage. Whether you label that a bug, controls failure, or operator negligence, the effect is the same: a vault did something economically insane and users wore the damage.

  58. NYC Memecoin$3MRugpullSolanaToken

    On January 13, 2026, the $NYC memecoin was accused of a classic rug after liquidity was pulled shortly after promotion from a high-profile account.

    There is not much technical subtlety here. The pattern described by researchers is the standard memecoin circus: public hype, fast inflows, liquidity removed, late buyers stranded. Once again, the interesting part is not the code but the distribution mechanism -- credibility and audience were the real attack surface.

  59. Social Engineering Theft$282MPhishingMultichainWallet

    On January 10, 2026, a victim lost more than $282M in BTC and LTC through a hardware-wallet social-engineering scam, after which the attacker moved rapidly across THORChain, CEXs and privacy rails.

    This was not a protocol failure at all; it was human compromise followed by industrial-grade laundering. The attacker started bridging and swapping almost immediately, moving large slices through THORChain into ETH, XRP and other assets, then dispersing funds across exchanges and mixers. It was a reminder that in raw dollar terms, social engineering still competes comfortably with every smart-contract exploit you care to name.

    ON-CHAIN

    • BTC Theft Address 1bc1qluxw46r55wf3dnk9c652vrt4duadm3hpuktf86
    • BTC Theft Address 2bc1qpsmh26ja0fzzf286zulmt9eywujc2pggj40wzm
    • LTC Theft Addressltc1qly43c2prj4c2e85dcspzpjd36jnapnenldnr70
  60. Truebit$27MOtherEthereumToken

    On January 8, 2026, Truebit lost about $26.5M after an integer overflow in getPurchasePrice() let the attacker mint TRU for effectively zero ETH and dump it.

    This is the kind of bug that makes smart-contract veterans sigh and stare into the middle distance. A large input caused the pricing math to overflow, the division result collapsed to zero, and the attacker could repeatedly mint huge amounts of TRU without paying meaningful cost. The market did the rest. Once the newly minted supply hit liquidity, the token price fell off a cliff and the attacker walked away with ETH.

  61. TMX$1MOtherArbitrumExchange

    On January 6, 2026, TMX on Arbitrum lost around $1.4M when an attacker found a profitable mint/stake/swap/unstake loop and repeated it until the pools were drained.

    The contract was unverified, which never helps, but the core pattern was simple enough: each cycle returned more value than went in. Once that kind of mechanical edge exists, the attacker's job is just to keep pressing the button until the pool stops paying. That appears to be what happened here.

  62. Unleash Protocol$4MAccess ControlStoryGovernance

    On December 30, 2025, Unleash Protocol's multisig governance was compromised, enabling an unauthorised upgrade and a drain of roughly $3.9M.

    This was a permissions story. Once the attacker acquired governance-side control, the rest followed in depressingly familiar fashion: upgrade logic, withdraw assets, bridge out, launder through Tornado. Story itself said its core infrastructure was unaffected, which may be true, but that is cold comfort when the application sitting on top of it has been opened with admin keys.

    ON-CHAIN

  63. Flow Network$4MOtherFlowExecution Layer

    On December 27, 2025, an attacker exploited a flaw in Flow's execution layer and moved roughly $3.9M off-network through bridges before validators coordinated a halt.

    Flow stressed that existing user balances were not touched, which matters. The vulnerability appears to have been in the exit/execution path rather than a direct user-account drain. That said, once assets are already riding bridges to Ethereum and the attacker is sending value through THORChain and Chainflip, the distinction becomes more architectural than comforting.

    ON-CHAIN

    • Exploiter0x2e7C4b71397f10c93dC0C2ba6f8f179a47F994e1
  64. Trust Wallet Browser Extension$7MAccess ControlMultichainWallet

    On December 26, 2025, Trust Wallet Browser Extension v2.68 was compromised, leading to about $6M-7M being drained from affected users.

    This was a supply-chain style wallet incident. The bad version reportedly gave the attackers access to sensitive wallet material or signing capability, and once a malicious update is sitting in a live extension channel the blast radius can expand quickly. Trust Wallet pushed users to disable the version and move fast, but malicious updates are brutal because they hijack the trust users have already granted.

  65. Address Poisoning Attack$50MPhishingEthereumWallet

    On December 20, 2025, a victim lost almost $50M in USDT after copying a poisoned lookalike address from transaction history.

    This was pure human-interface exploitation. The attacker exploited how people rely on recent transaction history and glance at the first and last few characters of an address instead of verifying the whole thing. After the victim sent a small test amount, the poisoned address appeared in their history and the main transfer followed. The attacker then started laundering almost immediately through stablecoin swaps and Tornado.

  66. Yearn Finance Legacy yETH Exploit$9MFlash LoanEthereumYield Aggregator

    On November 30, 2025, a legacy Yearn yETH product was exploited, letting the attacker infinitely mint yETH and drain almost $9M from connected liquidity pools.

    The vulnerable path sat in old yETH logic rather than Yearn's later vault architecture. Once the attacker could mint effectively unbacked yETH, those fake claims were pushed into Balancer and Curve-style liquidity to pull out real ETH and LSDs. Yearn later coordinated some recovery and treasury support, but the broader lesson was the usual one: old code with live liquidity attached is still live risk.

  67. Upbit Solana Hot-Wallet Breach$36MAccess ControlSolanaExchange

    On November 27, 2025, Upbit reported about $36M in unauthorised outflows from a production Solana hot wallet and suspended Solana rails.

    The outflows hit multiple Solana assets, and the important operational point was that Upbit said cold wallets were not compromised and customer balances would be made whole. That suggests an exchange hot-wallet security failure rather than a total infrastructure collapse. Still, when a major exchange says unauthorised outflow, the words are polite but the meaning is not.

  68. GANA Payment Liquidity Drain$3MOtherBNB ChainToken

    On November 20, 2025, GANA Payment on BSC was stripped of roughly $3.1M before the proceeds were washed through Tornado Cash on BSC and Ethereum.

    The exact technical cause remained murky, but the money trail was clear enough: liquidity drained, proceeds converted, laundering began. GANA looked like one of those thinly documented projects where public code and public explanation lag far behind the actual economic damage.

  69. Stream Finance External Manager Blow-Up$93MOtherMultichainSynthetic / Credit

    On November 4, 2025, Stream Finance said an external fund manager had effectively vaporised around $93M, triggering a much wider synthetic-debt unwind.

    This was less a smart-contract exploit than a systemic collateral crisis. Stream's synthetic stack was wired into multiple lenders and related stable structures, so once confidence broke the damage spread quickly. These are often the messiest incidents because the initial hole is smaller than the eventual credit crater it opens.

  70. Moonwell wrsETH Oracle Meltdown$4MOracle ManipulationBaseBorrowing

    On November 4, 2025, Moonwell's Base deployment was left with around $3.7M in bad debt after a wrsETH oracle briefly valued one token like a small country.

    The attacker used a nonsense oracle print to treat dust-sized wrsETH as enormous collateral. Once that happened, the rest was routine: borrow real assets, cycle through markets fast, leave the protocol holding the embarrassment. Moonwell clamped supply and borrow caps quickly, but fast clamps do not un-create bad debt.

  71. Balancer V2 Stable Pool Exploit$116MOtherMultichainAMM

    On November 3, 2025, Balancer's V2 Stable and Composable Stable v5 pool logic was exploited for about $116M across multiple deployments.

    Balancer's preliminary write-up tied the attack to stable-pool rounding / upscale behaviour in EXACT_OUT swap flows combined with flash loans and BatchSwaps. Put simply: old, complex pool math was pushed into states it should never have tolerated, and the attacker extracted value faster than mitigations could contain it.

  72. Beets Fi Balancer V2 Sonic Incident$3MOtherSonicAMM

    On November 3, 2025, Beets' Balancer V2 pools on Sonic were hit in the wider Balancer exploit wave, but Sonic's freeze mechanism trapped around $3M on-chain.

    This is the rare exploit where a chain-level intervention materially limited the attacker's ability to get paid. The underlying pool logic was still broken, but Sonic's security tooling prevented the normal exit route of bridge-and-launder.

  73. Garden Finance Multi-Chain Liquidity Drain$11MOtherMultichainCross-chain

    On October 30, 2025, Garden Finance lost about $11M across multiple networks in a coordinated drain of WBTC, USDC and USDT liquidity.

    Garden argued its core contracts were fine and pointed to integrations; outside observers were less generous. Whatever the precise fault line, the practical result was that value moved out across chains, into ETH, and into laundering routes. That is usually the moment when debates about root cause become secondary.

  74. Typus Finance Oracle Manipulation$3MOracle ManipulationSuiBorrowing

    On October 15, 2025, Typus Finance on Sui lost about $3.44M after a broken auth gate in the oracle module let the attacker publish bogus prices.

    A public price feed without real authentication is less an oracle than a suggestion box. Once the attacker could publish values the protocol treated as trusted, draining the TLP became straightforward. Typus paused quickly, but the bug was the kind that should never have made it to production.

  75. Hyperliquid Private Key Compromise$21MAccess ControlHyperliquidWallet

    On October 10, 2025, a leaked signing key let attackers bridge out about $21M from a Hyperliquid user.

    This was key compromise, not clever protocol exploitation. The funds moved with attacker-signed transactions, which is a much duller but more common cause of loss than people like to admit.

  76. Hypervault Suspected Rugpull$4MRugpullHyperliquidYield

    On September 26, 2025, Hypervault appeared to pull a classic exit, moving about $3.6M in user funds off Hyperliquid and into laundering channels.

    Team disappears, funds consolidate, bridges light up, Tornado appears in the distance: everyone knows the choreography by now.

  77. GriffinAI GAIN Cross-Chain Peer Exploit$3MAccess ControlBNB ChainToken

    On September 25, 2025, GriffinAI's GAIN token was exploited after a rogue LayerZero peer was accepted as trusted, enabling mass minting and a token collapse.

    Trusted-peer design is only as trustworthy as the peer registration. Once the attacker got a malicious contract accepted, they could mint GAIN as if it were legitimate cross-chain flow and dump it into real liquidity.

  78. SBI Crypto Hot-Wallet Heist$24MAccess ControlMultichainExchange

    On September 24, 2025, attackers drained about $24M across BTC, ETH, LTC, DOGE and BCH in a multi-asset hot-wallet breach tied to SBI infrastructure.

    The case had all the usual custodial red flags: hot-wallet exposure, fast laundering, and uncertainty over whether the initial compromise was keys, servers, or something adjacent. Either way, the exchange side of the stack failed before chain logic had any chance to matter.

  79. UXLINK Multi-Sig & Mint Abuse$48MAccess ControlArbitrumToken

    On September 22, 2025, UXLINK suffered a multi-sig takeover, asset sweep and huge unauthorised token mint, with losses around $48M.

    Once multi-sig control broke, it ceased to be a protocol and became the attacker's toy. Funds were swept first, inflation weaponised next, and then the attacker themselves reportedly got partially phished later in a kind of criminal slapstick sequel.

  80. Aqua Solana Presale Rug$5MRugpullSolanaToken

    On September 9, 2025, Aqua's team allegedly rugged a Solana presale worth roughly $4.65M despite audits, partnerships and heavy credibility theatre.

    The familiar pattern: build a trust wrapper, borrow legitimacy, pull liquidity, vanish. The scam's sophistication tends to live in its marketing, not its code.

  81. SwissBorg SOL Earn Breach$42MAccess ControlSolanaStaking

    On September 8, 2025, a compromised Kiln integration led to about $41.5M in SOL losses from SwissBorg's SOL Earn product.

    SwissBorg said the issue was isolated to the partner integration and covered users from treasury. That distinction matters operationally, but from the user side it still feels like the platform's stack failed where it most needed not to.

  82. Venus Protocol Delegate Phish$13MPhishingBNB ChainBorrowing

    On September 2, 2025, a malicious delegation flow let an attacker borrow and redeem roughly $13M on a user's behalf -- though the funds were later recovered.

    The protocol itself was not mathematically broken; the permission model around the victim account was. That is increasingly common: not code failure exactly, but trust granted to the wrong address or contract.

  83. Bunni v4 Hooks Liquidity Drain$8MOtherEthereumAMM

    On September 2, 2025, Bunni's custom v4 hook logic was exploited for about $8.4M across Ethereum and Unichain.

    Uniswap v4 lets builders get creative. Creativity is not always the same thing as safety. Bunni's rebalancing and share-accounting logic could be pushed into states that credited more value than it should have.

  84. Better Bank Bonus-Mint Exploit$5MOtherPulseChainBorrowing

    On August 26, 2025, Better Bank lost about $5M after an attacker abused a bonus-mint path tied to its Favor / Esteem mechanics.

    The attacker found a route where the protocol rewarded itself into insolvency. Once a contract can be induced to create more redeemable value than should exist, the rest is just path optimisation.

  85. Phishing: 783 BTC Drained$91MPhishingBitcoinWallet

    On August 19, 2025, a victim lost 783 BTC -- roughly $91M -- in a high-touch support-impersonation theft.

    This was not a smart-contract exploit but a trust exploit. The attacker posed as support staff, won access, and then started the slow hygiene of laundering. In cash terms, social engineering is still one of the industry's strongest recurring primitives.

  86. BtcTurk Hack$48MAccess ControlMultichainExchange

    On August 14, 2025, BtcTurk suffered a roughly $48M hot-wallet breach across several chains.

    This was another exchange hot-wallet event: assets drained, emergency measures triggered, assurances about cold storage made after the fact.

  87. Odin.fun Exploit$7MOtherBitcoinAMM

    On August 12, 2025, Bitcoin launchpad Odin.fun lost about 58.2 BTC, roughly $7M, after liquidity manipulation in its AMM tool.

    Spoofed or cheaply inserted assets distorted the AMM's assumptions, letting the attacker walk out with real BTC while the accounting insisted the pool was behaving normally enough.

  88. Phishing USDT Theft$3MPhishingEthereumWallet

    On August 6, 2025, a victim was tricked into signing an approval and lost about $3.05M in USDT.

    The simplest scams remain brutally effective. The attacker got approval, moved fast, and routed the funds away before the victim could react.

  89. CrediX Exploit$5MAccess ControlSonicBorrowing

    On August 4, 2025, CrediX on Sonic lost around $4.5M after misassigned admin roles let attackers mint unbacked assets and drain pools.

    Access-control failures do not need technical glamour to be expensive. The wrong permissions existed, the attacker used them, the pool paid.

  90. WOO X Phishing Breach$14MPhishingMultichainExchange

    On July 24, 2025, WOO X lost about $14M after a targeted phishing attack hit a team member's device and opened the way to account drains.

    Infrastructure can be excellent and still be undone by the human endpoint sitting in front of it.

  91. CoinDCX Breach$44MAccess ControlMultichainExchange

    On July 20, 2025, CoinDCX lost roughly $44M after attackers compromised an internal liquidity account.

    Server-side or key-side compromise remains one of the cleanest paths to very large exchange losses. Once the attacker is inside the liquidity machinery, chain-level sophistication is optional.

  92. BigONE Exchange Hack$28MAccess ControlMultichainExchange

    On July 16, 2025, BigONE lost around $28M in a hot-wallet breach spanning Bitcoin, Ethereum, Tron and Solana.

    Another custodial wallet failure, another multi-chain scramble, another assurance that reimbursements will follow.

  93. Arcadia Finance Exploit$3MOtherBaseRebalancing

    On July 15, 2025, Arcadia lost about $2.5M on Base after a router validation flaw let attackers smuggle malicious calls through rebalance logic.

    The protocol executed instructions it should never have trusted. That is often the heart of these router-style exploits.

  94. GMX Exploit$42MOtherArbitrumPerps

    On July 9, 2025, GMX was exploited for about $42M on Arbitrum. The attacker later returned the funds after accepting a $5M white-hat bounty.

    The exploit targeted GMX's older vault logic. After a public bounty offer of 10%, the attacker returned the stolen funds, making this one of the larger successful white-hat recoveries. Recovery does not erase the underlying issue, but it stopped the headline from becoming even worse.

  95. Resupply Exploit$10MOracle ManipulationEthereumBorrowing

    On June 26, 2025, Resupply lost about $9.5M after an oracle manipulation attack let the attacker borrow against inflated collateral.

    Again: bad number in, bad debt out.

  96. Nobitex Hack$82MAccess ControlMultichainExchange

    On June 18, 2025, Iranian exchange Nobitex was hit for about $82M in a major hot-wallet compromise.

    Large centralised exchanges remain giant, tempting concentrations of key risk. Nobitex joined the long and unhappy list. The breach was later analysed by Chainalysis and TRM Labs, the latter noting that leaked source code revealed structural weaknesses in the exchange's infrastructure.

  97. AlexLab Exploit$16MAccess ControlStacksDeFi

    On June 6, 2025, AlexLab on Stacks lost around $16.1M after private keys were compromised, allowing the attacker to drain protocol funds.

    Protocol logic was secondary here. Once keys are gone, user-facing assurances tend to follow them. AlexLab later committed to reimbursing affected users and published a detailed breakdown of losses.

  98. Nervos ForceBridge Exploit$4MAccess ControlMultichainBridge

    On June 2, 2025, Nervos's ForceBridge lost about $3.7M after flawed cross-chain validation let attackers mint synthetic assets and dump them.

    Bridge validation is the whole game. When it is wrong, the bridge stops being a bridge and turns into a mint.

  99. Cork Protocol wstETH Exploit$12MOtherEthereumYield

    On May 28, 2025, Cork Protocol lost about $12M after a flaw around wrapped staking asset exchange-rate logic was abused via a Uniswap v4 hook vulnerability.

    Counterfeit or distorted pricing inside wrapped-asset accounting is a reliable way to make real collateral vanish. Dedaub's analysis highlighted this as a critical lesson in Uniswap v4 hook security, given that Cork was an a16z-backed project.

  100. Cetus Protocol Exploit$260MOtherSuiAMM

    On May 22, 2025, Cetus Protocol on Sui was hit for roughly $260M in a devastating AMM manipulation exploit that sent connected token prices down over 90%.

    Cetus was one of the year's defining DeFi disasters. By injecting or exploiting false value relationships inside the pool design, the attacker pulled real assets out en masse and left prices across connected tokens shattered. Multiple security firms published detailed root-cause analyses. The Sui ecosystem ultimately coordinated a partial freeze and recovery effort, but the scale of the damage was immense.

  101. Bitcoin Theft$331MPhishingBitcoinWallet

    On April 27, 2025, 3,520 BTC -- about $330.7M -- was stolen from an elderly US victim in a social-engineering attack, then funnelled through instant exchanges into Monero, briefly spiking XMR's price.

    This was one of those rare incidents large enough to shake adjacent markets. Laundering pressure into XMR caused a visible price reaction. ZachXBT traced the theft and identified the victim as an elderly person in the US targeted through social engineering. Roughly $7M was later frozen with Binance's help, but the vast majority was successfully laundered through privacy rails.

  102. Loopscale Hack$6MOracle ManipulationSolanaBorrowing

    On April 26, 2025, Loopscale on Solana lost about $5.8M after a pricing bug around RateX PT collateral let attackers borrow against inflated value, just two weeks after launch.

    Oracle and collateral design failures are often boring on paper and expensive in practice. This was both.

  103. ZKsync Airdrop Contract Exploit$5MAccess ControlZKsyncAirdrop

    On April 15, 2025, a compromised admin wallet swept around $5M in unclaimed ZK tokens from an airdrop contract.

    The exploit path was boring but effective: privileged function, wrong hands, real tokens gone. The ZK token price dropped sharply on the news before partially recovering.

  104. KiloEx Oracle Manipulation$7MOracle ManipulationEthereumPerps

    On April 14, 2025, KiloEx lost about $7M across multiple chains after forged or unauthorised oracle inputs were used to juice leveraged PnL.

    The attacker manipulated how the price feed was trusted and then harvested the obvious economic imbalance. Once again, if your oracle lies and your protocol believes it, the attacker just has to submit the paperwork.

  105. UPCX ProxyAdmin Take-Over$70MAccess ControlEthereumToken

    On April 1, 2025, a hijacked ProxyAdmin let attackers insert malicious logic and drain about $70M worth of UPC tokens.

    Proxy upgrade power is effectively absolute power. Once lost, every downstream assurance becomes theatre.

  106. Abracadabra GMX-Cauldron Bug$13MOtherArbitrumBorrowing

    On March 25, 2025, Abracadabra lost about $13M after a bookkeeping flaw let an attacker self-liquidate, re-borrow and recycle collateral in cauldrons tied to GMX liquidity tokens.

    This was accounting getting confused in exactly the way attackers pray for: debt gone from the books before the collateral had really stopped mattering. PeckShield flagged the exploit in real time and multiple security firms published detailed breakdowns.

  107. Zoth Logic-Contract Swap$8MAccess ControlEthereumRWA

    On March 21, 2025, leaked admin rights let attackers swap Zoth's implementation contract and drain around $8.32M from the RWA protocol.

    Upgradeable systems are wonderful right up to the point someone else becomes the upgrader.

  108. 1inch Fusion v1 Re-entrancy$3MOtherEthereumDEX Aggregation

    On March 6, 2025, a re-entrancy issue in 1inch Fusion v1's resolver contract let attackers repeatedly reuse approvals and drain roughly $2.6M.

    Recursive control flow plus user-supplied values remains a classic way to manufacture losses out of otherwise respectable code. 1inch published an official statement confirming the vulnerability was in the resolver contract, not the core aggregation protocol.

  109. Suji Yan Wallet Hack$4MPhishingEthereumWallet

    On February 27, 2025, Mask Network founder Suji Yan lost roughly $4M after what appeared to be an offline phone or wallet compromise.

    No protocol bug, just a personal-security disaster with on-chain consequences.

  110. Infini Insider Drain$50MAccess ControlEthereumTreasury

    On February 24, 2025, Infini lost about $50M after retained administrative privileges were allegedly used to drain funds from the stablecoin payment card issuer.

    Insider or insider-style privilege abuse tends to be especially poisonous because it destroys both the money and the story the team can tell about how secure the system was. Infini offered a bounty for return of funds, but the damage to trust was already done.

  111. Bybit Multisig Cold-Wallet Hack$1.40bnAccess ControlEthereumExchange

    On February 21, 2025, Bybit suffered the largest single crypto theft on record after a phished multisig flow led to $1.4B in ETH being drained. The FBI attributed the attack to North Korea's Lazarus Group (TraderTraitor).

    The key lesson was brutal and simple: a multisig is only as safe as the signing environment and the humans using it. The interface showed one thing, the underlying permission change did another, and the largest single crypto theft on record followed. The FBI publicly attributed the hack to the DPRK-linked threat actor known as TraderTraitor (Lazarus Group / APT38) and issued a formal PSA. Bybit published a detailed incident timeline and committed to full transparency throughout the recovery process.

  112. LIBRA Rug Pull$286MRugpullSolanaToken

    On February 16, 2025, LIBRA imploded in what looked far more like insider distribution and rug mechanics than some tragic accident, wiping out roughly $286M. The incident sparked a political scandal in Argentina.

    When memecoin theatrics overlap with politics, the post-mortem gets noisy fast. The money, unfortunately, was quieter and more final. TRM Labs published a detailed fund-tracing analysis, and the incident eventually warranted its own Wikipedia article due to the political dimensions involved.

  113. zkLend Exploit$10MOtherStarknetBorrowing

    On February 12, 2025, zkLend lost about $9.5M in a flash-loan exploit on Starknet. The attacker later attempted to launder through Railgun but funds were flagged and partially recovered.

    The protocol still failed first. The partial recovery narrative is interesting, but it came after the money had already been stolen. BlockSec published a detailed post-mortem clarifying several misunderstandings about the attack mechanics.

  114. DogWifTools Exploit$10MOtherMultichainTooling

    On January 28, 2025, DogWifTools users were hit in a roughly $10M supply-chain exploit that drained wallets through a compromised version of the Solana pump.fun trading tool.

    When wallet-adjacent software is compromised, the distinction between application risk and wallet risk disappears immediately. BleepingComputer covered this as a supply-chain attack where the tool itself was trojaned to exfiltrate private keys.

  115. Phemex Exploit$37MAccess ControlMultichainExchange

    On January 23, 2025, Phemex lost about $37M amid a multi-chain hot-wallet breach. The exchange published a timeline and compensation plan shortly after.

    Another exchange reminder that once the hot-wallet layer is compromised, attackers do not need deep protocol wizardry to do large damage fast. Phemex was relatively transparent in their response, publishing a detailed timeline and reassuring users with a compensation framework.

Losses are best-public-estimate at time of logging. Attribution claims are reported as claims, not findings. Updated 25 Jul 2026.