Security Desk · live log

Crypto Exploit Tracker

$4.92bn drained across 118 logged incidents

Every major crypto exploit we log: what was hit, how much was lost, and how the attack actually worked, with the on-chain references and sources attached. Maintained by the Security Desk; updated as incidents are verified.

Updated 06 Aug 2026 · 118 incidents · 19 months tracked

Total lossAll time$4.92bnCumulative, 2025/01 to date
2026 so farYear to date$1.49bn64 incidents · 2025 full year $3.42bn
Biggest single hitAll time$1.40bnBybit Multisig Cold-Wallet Hack · 28% of all losses
Major incidentsAll time118Logged per month, 2025/01 to date
Most common vectorAll timeAccess Control32 of 118 incidents
Days since last hackLoggedDays between the last 25 hacks

Where the money went · by vector

  1. Access Control$2.38bn48.4%
  2. Phishing$798M16.2%
  3. Other$679M13.8%
  4. Bridge Exploit$322M6.6%
  5. Rugpull$298M6.1%
  6. Private Key Compromise$274M5.6%
  7. Oracle Manipulation$75M1.5%
  8. Smart Contract Bug$39M0.8%
  9. Governance Attack$20M0.4%
  10. Flash Loan$20M0.4%
  11. Bridge$8M0.2%
  12. Supply Chain$3M0.1%

Losses · last 12 months

Loss severity · all time

118total
LowUnder $10M
7160.2%
Medium$10M – $50M
3126.3%
High$50M and above
1613.6%

Showing 118 of 118 incidents

  1. Coldcard Mk3 Seed Entropy SweepPrivate Key CompromiseBitcoinWallet$116M

    On 30 July 2026, bitcoin began draining out of Coldcard-generated addresses in waves, the first taking about 594 BTC from roughly 500 wallets in 25 minutes. TRM Labs' 5 August analysis puts the running total at about 1,816 BTC, roughly $116m, from more than 5,200 addresses across at least four waves, making it the largest hardware-wallet exploit of 2026 by TRM's accounting. Coinkite had disclosed the same day the draining began that a build flag set to zero in March 2021 replaced the hardware random number generator with a software fallback, cutting Mk3 seeds to roughly 40 bits of real randomness against a 128-bit target. No device was touched: the seeds were guessable.

    A preprocessor guard tested whether MICROPY_HW_ENABLE_RNG was defined rather than whether it was set, so a value of zero satisfied it and the #error never fired. Coinkite puts the effective search space at about 40 bits on Mk3 and about 72 bits on Mk4, Mk5 and Q; 2^40 is roughly 1.1 trillion candidates, a search a computer can finish. Updating the firmware does not repair a seed that already exists. The attacker's signature is an identical hardcoded fee of about 30 sat/vB on every sweep, against a 0.4 to 1.0 median that week, though TRM notes transaction construction differs between waves, so there may be more than one attacker. Laundering has started at the margins: 64.9 BTC went into Wasabi and 200 ETH into Tornado Cash on 4 August, with the bulk still sitting in attacker addresses in public view. Coinkite destroyed its remaining vulnerable stock and halted shipments on 2 August, opened a permanent disclosure record on 4 August, and notes that AI-assisted review failed to catch the bug. It has not confirmed the theft was caused by its flaw. Figures are TRM's on-chain estimates and still moving.

  2. Crypto DAO Vault DrainAccess ControlBNB ChainDeFi$8M

    On 28 July 2026, an attacker drained about $8.2M in USDT from the vault behind Crypto DAO's Pro token by calling a state-changing exec() function that had been left publicly callable, in a single flash-loan-assisted transaction. Blockaid flagged the drain the same day.

    The flaw is the elementary access-control class: a vault function anyone could call, with no permission check between the caller and the funds. The project had published no acknowledgement or postmortem at the time of logging, so the figure is an on-chain estimate rather than a reconciled one. SlowMist's database lists the incident against Ethereum, which is consistent with the stolen USDT being moved there; contemporary reporting places the exploited contract on BNB Chain, and that is the attribution used here.

  3. WEMIX$ Stablecoin Contract TakeoverAccess ControlWEMIX3.0Stablecoin$731k

    On 26 July 2026 an attacker compromised ownership of a contract behind WEMIX$, the dollar stablecoin of the WEMIX gaming chain, and issued 5,225,525 tokens without authorisation. WEMIX says those were converted into 30,736 WEMIX and 724,198.27 USDC.e, which was bridged to Ethereum and BNB Smart Chain, swapped into ETH and USDT and spread across wallets, with some deposited at centralised exchanges.

    The nominal mint was about $5.2m at par, but the tokens were sold into WEMIX's own liquidity pools, so the assets that actually left came to roughly $731,000. WEMIX suspended all bridges to and from WEMIX3.0 along with Chainlink CCIP and the PLAY Bridge, halted trading in five pools, withdrew foundation liquidity, paused the WEMIX$ module and PNIX DEX, and disabled NFT trading and some in-game blockchain features. WEMIX$ lost its peg, falling about 99 per cent to roughly $0.0109. The first public notice came 5 hours 33 minutes after the attack, against three days for the company's February 2025 Play Bridge incident. All figures are WEMIX's preliminary account.

  4. Triple-A Hot Wallet DrainOtherMultichainPayments$10M

    On 25 July 2026, wallets belonging to Triple-A, a licensed digital payments company, were drained of more than $9.7M across TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated about 5,227 ETH into a single address. The analyst who flagged it reported that deposits had not been disabled, so each new deposit was being taken as it arrived.

    Triple-A holds a Major Payment Institution licence from the Monetary Authority of Singapore, an ACPR payment institution licence and French CASP registration, FinCEN and NMLS registration in the United States, and FINTRAC registration in Canada, and had secured in-principle approval from Dubai VARA ten days earlier. The vector is unconfirmed and logged as Other for that reason: losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at compromised hot wallet signing keys rather than a contract flaw. Triple-A published no incident notice, so the loss is an on-chain estimate rather than a reconciled figure.

  5. B² Network Staking ExploitAccess ControlBitcoin L2Staking$4M

    On 23 July 2026, B² Network, a Bitcoin layer-2, lost about $3.86M after an attacker seized the upgrade authority on its staking contract. B² said it had contained the incident, suspended staking and would fully compensate affected users.

    The third protocol drained on the same day, after the attacker gained control of the staking contract's upgrade authority.

  6. Verus Ethereum Bridge Exploit (second)BridgeEthereumBridge$8M

    On 23 July 2026, the Verus Ethereum bridge was drained of about $7.54M through the same contract flaw as its May 2026 hack. An attacker forged the cross-chain proof the bridge failed to verify and triggered unbacked payouts, taking ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.

    Funds had been redeposited on 8 July and were drained again two weeks later. The stolen funds were converted into roughly 3,916 ETH and moved through Tornado Cash. Verus held close to $100M in total value locked at the start of 2025 and is down to single-digit millions.

  7. AFX Trade Bridge ExploitAccess ControlArbitrumDerivatives$24M

    On 23 July 2026, AFX Trade, a decentralised perpetuals exchange settling in USDC, lost about $24.15M after attackers compromised the validator signing keys behind a bridge it runs on Arbitrum and authorised withdrawals. The team suspended bridge operations.

    Arbitrum confirmed its own native bridge was not involved; the failure was in AFX's own bridge and its key handling. The stolen USDC was moved to Ethereum. It was the largest of three protocol losses logged on the same day.

  8. CascadeSmart Contract BugArbitrumPerps$1M

    Polychain-backed Arbitrum trading platform Cascade reported on 16 July 2026 that its CLS vault was exploited, with 1.34 million USDC of locked user funds drained.

    The incident came barely a day after the Ostium oracle exploit on the same network, extending a run of attacks on Arbitrum-based perpetuals platforms. Cascade confirmed the drain affected user funds in the CLS vault; a full root-cause disclosure had not been published as of 17 July 2026.

  9. OstiumOracle ManipulationArbitrumPerps$24M

    Arbitrum perpetuals DEX Ostium suspended trading on 15 July 2026 after an attacker compromised the off-chain infrastructure that signs its price feeds and submitted fabricated Bitcoin quotes, taking 23,752,746 USDC out of the public OLP vault in five and a half minutes.

    Between 14:18:23 and 14:23:52 UTC, eight transactions moved 23,753,539 USDC from the Ostium Vault (0x20D419a8) to one wallet, 72.6% of the $32.71m the vault then held. Twenty-four price reports went in through the PrivatePriceUpKeep contract, every one naming BTC/USD at exactly $5,000 or exactly $60,000 while Bitcoin traded near $65,250, and every one timestamped to the block that carried it, so the signing capability was live rather than replayed. Twelve open-and-close rounds each returned 8.987x the stake, Ostium's automatic 900% take-profit ceiling, so the attacker escalated the stake from 100 USDC to 700,000. Trader collateral in the separate storage contract was untouched. Ostium froze trading within 60 minutes, engaged Mandiant, zeroShadow, Collisionless and SEAL 911, and reopened in stages on 23 July; the funds were swapped to about 12,080 ETH with roughly 10,540 ETH sent to Tornado Cash. Deposits remain frozen and the vault's own loss counter still carried $19.2m on 30 July.

  10. Bonzo LendOracle ManipulationHederaLending$9M

    Hedera's largest DeFi lender, Bonzo Lend, was exploited for about $9 million at 00:51 UTC on 11 July 2026 after a third-party oracle accepted a forged SAUCE token price.

    The attacker submitted a SAUCE price inflated by twelve orders of magnitude, which the Supra oracle accepted after a signature verification bypass (a zeroed signature), then used 250 SAUCE worth about $1 as collateral to borrow $9.05 million from the protocol. Around $5.25 million was bridged to Ethereum, a white hat returned roughly $1 million, Bonzo paused the protocol and Supra acknowledged the flaw and deployed a fix; PeckShield tracked the bridged funds.

  11. BonkDAOGovernance AttackSolanaDeFi$20M

    On 6 July 2026 an attacker drained roughly $20 million in BONK tokens from BonkDAO's treasury by passing a malicious governance proposal; BONK fell around 8–10%.

    The attacker accumulated an estimated $4 million of BONK to dominate token-weighted voting on Solana's Realms platform, then pushed through 'BIP #76', submitted on 30 June and dressed as a governance renewal plan, whose operative clause transferred 4.43 trillion BONK to an attacker-controlled wallet; only 7 of more than 18,000 eligible wallets voted, and the attacker cast 99.878% of votes. The DAO coordinated with the Solana Foundation, law enforcement and exchanges, with Upbit, Bithumb and Kraken suspending BONK deposits and withdrawals; no recovery had been confirmed by mid-July.

  12. Summer.fiFlash LoanEthereumYield$6M

    On 6 July 2026 Summer.fi's Lazy Summer vaults were exploited for about $6 million in DAI via a flash-loan-assisted price manipulation, prompting the protocol to pause all vaults.

    PeckShield confirmed roughly $6 million was extracted after the attacker used a $65.4 million flash loan to manipulate vault share pricing (described by trackers as a donation-style attack), with the largest single victim losing about 8.6 million USDC. Summer.fi paused all Lazy Summer vaults and zeroed deposit caps; researchers linked the exploited pricing weakness to stale tokens left over from the Stream Finance collapse the previous November.

  13. PolymarketSupply ChainPolygonDeFi$3M

    In late June 2026 Polymarket users lost about $3 million after a compromised third-party vendor was used to inject malicious JavaScript into the prediction market's front end.

    The injected script ran silently in users' browsers on the legitimate site and prompted routine-looking wallet signatures that authorised unintended transfers; 11 user wallets were affected. Stolen funds were bridged from Polygon to Ethereum, swapped to roughly 1,893 ETH and consolidated into a single wallet. Polymarket's smart contracts were not exploited, and the company promised full refunds to victims holding its PUSD collateral.

  14. SecondFiPrivate Key CompromiseCardanoWallet$2M

    Cardano wallet project SecondFi confirmed three attacks between 21 and 23 June 2026 that drained 16 million ADA (about $2.4 million) from 374 wallets, with SlowMist estimating up to $20 million potentially at risk.

    The flaw was a deterministic nonce derivation bug in SecondFi's proprietary software signer: every signed transaction leaked cryptographic information that allowed attackers to reconstruct users' private keys from public blockchain data alone. The team rescued a further 129 million ADA to a third-party custodian before attackers could reach it and, with EMURGO, launched a two-week recovery and restitution plan with a checking tool for affected wallets.

  15. Taiko BridgeBridge ExploitEthereumBridge$2M

    Ethereum layer-2 Taiko halted block production in late June 2026 after an attacker used forged cross-chain proofs to withdraw about $1.7 million from its bridge without matching deposits.

    The root cause was an SGX signing key left exposed on GitHub: Taiko's permissionless prover registration allowed a rogue SGX instance to register and submit invalid proofs that the system accepted, letting fake withdrawal requests clear on Ethereum. The team froze activity within hours and urged users to withdraw; the attacker had already moved about 2 million TAIKO (roughly $170,000) to MEXC before the freeze, and the TAIKO token fell around 10%.

  16. JaredFromSubway MEV BotPhishingEthereumInfrastructure$8M

    On 20 June 2026 the notorious jaredfromsubway.eth MEV bot was drained of roughly $7.5 million in WETH, USDC and USDT by a counter-MEV honeypot (some outlets put the figure as high as $15 million).

    The attacker deployed 66 fake token contracts and rigged liquidity pools that looked like profitable trades; when the bot took the bait it granted token approvals to attacker-controlled contracts, and those dangling approvals were later used to sweep the bot's holdings in a single coordinated transaction. Blockaid had flagged the attacker's wallets and contracts as malicious before the final drain, and Chainalysis and The Block documented the incident as the most prominent case of a predator bot being drained by its own logic.

  17. Aztec Private Rollup BridgeSmart Contract BugEthereumBridge$2M

    Three days after the Aztec Connect exploit, an attacker drained about $2.16 million (roughly 1,158 ETH) from Aztec's deprecated Private Rollup Bridge on 17 June 2026 via its escape-hatch mechanism.

    The attacker constructed a fake zero-knowledge claim proof accepted by the RollupProcessor's verification logic: the proof system did not correctly bind a victim's final output note to its rightful recipient, letting a malicious escape-hatch caller substitute arbitrary outputs. Aztec confirmed the exploit targeted a deprecated product unrelated to the current network.

  18. Aztec ConnectSmart Contract BugEthereumInfrastructure$2M

    On 14 June 2026 an attacker drained about $2.1 million from Aztec Connect, the deprecated privacy rollup product, using a crafted zero-knowledge proof that the verification logic wrongly accepted.

    This was the first of two Aztec legacy-contract exploits in three days, together costing over $4 million. Aztec attributed the issues to proof-verification bugs in deprecated contracts; the Aztec Foundation stressed the affected products have no link to the current Aztec network or the AZTEC token.

  19. Secret NetworkBridge ExploitSecret NetworkBridge$5M

    Starting 10 June 2026, an attacker exploited an infinite-mint bug in Secret Network's Axelar bridge contract, draining about $4.67 million in Axelar-wrapped assets; the theft went unnoticed for seven days.

    The deployed contract was a modified CW20-ICS20 fork with core security checks removed, so it did not verify the source channel of inbound IBC packets; the attacker spun up a single-validator Cosmos chain, self-relayed forged packets to mint unbacked saTokens, then redeemed them over the legitimate Axelar channel to drain real escrowed assets including saUSDT, saUSDC, saDAI, saWETH and saWBTC. The hole was discovered on 17 June when a failed transaction produced an insufficient-funds error, prompting investigation of the bridge's reserves.

  20. RaydiumSmart Contract BugSolanaDEX$1M

    On 10 June 2026 an attacker drained about $1.34 million from five deprecated Raydium legacy AMM V3 pools on Solana using forged LP tokens.

    The legacy AMM V3 program, phased out in 2021 but never immobilised, did not validate the LP mint address, so a fake LP mint let the attacker withdraw real pool assets — roughly 893,700 USDC, 5,603 SOL and 150,177 RAY. The funds were bridged to Ethereum and routed through KuCoin and FixedFloat into Tornado Cash; Raydium said no current users were affected and pledged full repayment from its treasury.

  21. Humanity ProtocolPrivate Key CompromiseEthereumInfrastructure$31M

    Identity network Humanity Protocol lost at least $31 million (estimates ranged to $36 million) on 8–9 June 2026 after seven private keys stored on a malware-infected developer machine were compromised; the H token crashed more than 80%.

    The infected device held the admin hot wallet key plus three Ethereum Safe owner keys and three BNB Chain Safe owner keys backed up during the 2025 mainnet launch. Using three of six ETH Safe keys, the attacker transferred Bridge ProxyAdmin ownership, upgraded the bridge to a malicious implementation, swept about 141.2 million H in one transaction and minted a further 200 million H via malicious upgrades. PeckShield ranked it June's largest incident, and HTX Insights reported that around 15,403 ETH of proceeds later commingled on Bitcoin with funds from the Kelp DAO exploit, suggesting a possible link between the actors.

  22. Syscoin BridgeBridge ExploitSyscoinBridge$10M

    In early June 2026 an attacker exploited a proof-parsing flaw in the Syscoin bridge relay to mint roughly 5 billion unauthorised SYS tokens, an incident valued at about $10 million; SYS fell around 20%.

    The bridge relay's proof-validation code misparsed a deliberately malformed proof, treating it as valid evidence of a burn on the NEVM side that never happened, which authorised minting on the UTXO side. Syscoin halted the bridge, coordinated freezes with exchanges and partners, and later said it had recovered and burnt all 5 billion minted SYS, restoring the pre-exploit supply, though the bridge remained offline.

  23. Gravity BridgePrivate Key CompromiseEthereumBridge$5M

    The Ethereum–Cosmos Gravity Bridge was drained of about $5.4 million on 30 May 2026 in what researchers assessed as a compromised signing key rather than a code flaw.

    With enough valid validator signing keys, forged withdrawals are treated as legitimate; the attacker took about $4.3 million in USDC, 274 WETH, $434,000 in USDT and 14.16 PAXG, laundering a portion through ChangeNow and Binance while retaining roughly 2,100 ETH. Researchers cited the incident as part of 2026's pattern of bridge losses driven by key compromises rather than smart contract bugs.

  24. DxSaleAccess ControlBNB ChainDeFi$7M

    Launchpad and locker platform DxSale lost about $7.3 million in late May 2026 when more than 1,400 legacy BNB Chain liquidity lockers were unlocked and drained in a single coordinated flow.

    On 26 May the locker contract's owner called transferOwnership, passing control to the attacker after admin rights had reportedly moved through roughly 80 obscuring wallet transfers; auditor Coinsult traced the drain to a privileged setFee function (reset to 1 wei) combined with backdated lock configurations that made locked deposits withdrawable, executed via EIP-7702 batch delegation. Community researchers raised the possibility of insider involvement or a leaked owner key; roughly 1,400 liquidity providers were affected.

  25. Ill Bloom Wallet VulnerabilityPrivate Key CompromiseMultichainWallet$5M

    A coordinated sweep on 27 May 2026 drained about $3.1 million from 431 wallets whose seed phrases were generated with a weak random-number generator — the 'Ill Bloom' flaw — with a further $2.1 million in USDT stolen later, pushing confirmed losses past $5 million.

    Certain older or lesser-known software wallets used an insecure pseudorandom number generator during seed phrase creation, shrinking the keyspace enough for attackers to brute-force recovery phrases and derive private keys. Security firm Coinspect, which disclosed the flaw publicly in early July, traced 2,114 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon, with first-funding dates from 2018 to May 2026; hardware wallets and mainstream software wallets were not affected.

  26. New Market TradingAccess ControlEthereumDeFi$4M

    New Market Trading was exploited for about $3.98 million across Ethereum, Base and Arbitrum on 25 May 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as an access-control exploit in the protocol's contracts. Detailed independent reporting on the incident is limited.

  27. StablRPrivate Key CompromiseEthereumStablecoin$3M

    Stablecoin issuer StablR suffered a private key compromise on 23 May 2026, with an attacker minting 8.35 million USDR and 4.5 million EURR and extracting about $2.8 million.

    The unauthorised minting depegged both tokens, with EURR falling to about $0.85 and USDR to about $0.40 before the situation was contained. Global Ledger classified the incident as a compromised-key attack on the issuer's minting controls rather than a smart contract flaw.

  28. RetoSwapSmart Contract BugMoneroDEX$3M

    On 20 May 2026 the Monero P2P exchange RetoSwap, a Haveno Protocol fork, was exploited for about 7,000 XMR (roughly $2.7 million) via a forged-message flaw in its trade arbitration flow.

    The client accepted a forged, out-of-order ACK message without verifying the sender's signature, letting the attacker overwrite the arbitrator's stored Tor address with their own; the attacker then held two of three keys to newly created trade multisig wallets and swept victims' XMR the moment deposits landed. RetoSwap suspended trading, and Haveno's lead developer shipped a fix the same day preventing node-address updates before multisig creation.

  29. Echo ProtocolPrivate Key CompromiseMonadYield$77M

    On 19 May 2026 an attacker used a compromised admin key to mint about 1,000 unauthorised eBTC on Echo Protocol's Monad deployment, a paper value of roughly $76.7 million, though the realised take was far smaller.

    The eBTC minting contract had no multisig, timelock or mint limits, so the stolen admin key gave the attacker unilateral minting rights. Thin liquidity on Monad limited the realised proceeds to roughly $816,000 in ETH sent to Tornado Cash, plus about $3.45 million in WBTC borrowed against minted eBTC on Curvance. Echo regained control of the admin keys, burnt the remaining 955 eBTC, paused Monad cross-chain functionality and upgraded the affected contract.

  30. Verus–Ethereum BridgeBridge ExploitEthereumBridge$12M

    The Verus–Ethereum bridge was exploited on 18 May 2026 for roughly $11.5 million, the largest single incident of the month by most trackers.

    Attackers bypassed the bridge's verification logic and withdrew about 1,625 ETH (~$3.44 million), 103.57 tBTC v2 (~$8.06 million) and 147,659 USDC from the Ethereum side. The project's incident report followed around eight hours after the initial theft; BlockSec and monthly trackers including CertiK-linked reporting flagged cross-chain bridges as May's most-targeted category, with this incident at the top.

  31. THORChainPrivate Key CompromiseMultichainDEX$11M

    On 15 May 2026 an attacker drained about $10.7 million from one of THORChain's five Asgard vaults across Bitcoin, Ethereum, Base and BNB Chain, crashing RUNE around 15%.

    The attacker was a newly churned node operator who had joined the network two days earlier; the working theory supported by PeckShield, Cyvers and THORChain's own report is that vault key material leaked through a vulnerability in the GG20 threshold signature scheme implementation during keygen or signing rounds. Node operators paused the network within hours via the Mimir governance module, and trading resumed after a five-week halt alongside a $10 million compensation portal for affected users.

  32. Transit FinanceSmart Contract BugTronDEX$2M

    Cross-chain swap aggregator Transit Finance lost about $1.88 million on 13 May 2026 through an exploit of a deprecated smart contract on Tron.

    DefiLlama classifies the incident as a deprecated smart contract exploit, and Nominis records it as a contract logic flaw. Funds were drained from legacy contracts that remained callable despite no longer being part of the active product.

  33. TrustedVolumesAccess ControlEthereumDeFi$6M

    Liquidity provider TrustedVolumes lost about $5.87 million in WETH, USDT, WBTC and USDC on 7 May 2026 after an attacker exploited its request-for-quote (RFQ) order flow.

    Analysts described the incident as an access-control failure in which forged RFQ orders were used to pull funds from the market maker; the exploiter began laundering proceeds through Tornado Cash, RailGun and THORChain. Global Ledger noted the firm's public incident report followed roughly 11 minutes after the initial transaction.

  34. EkuboSmart Contract BugEthereumDEX$1M

    On 6 May 2026 attackers drained about $1.4 million, mostly in wrapped bitcoin, from users of Ekubo's EVM swap router contracts via an approval-based exploit.

    The router's IPayer.pay callback failed to verify that the payer matched the lock initiator, so attackers could craft a malicious lock payload naming any address as payer and call transferFrom against wallets that had approved the routers, looping the exploit roughly 85 times at about 0.2 WBTC per iteration. Only the Ethereum V2/V3 and Arbitrum V3 routers were affected; Starknet's core deployment and all liquidity providers were untouched, and Ekubo urged users to revoke approvals on the three affected immutable contracts.

  35. Wasabi ProtocolPrivate Key CompromiseEthereumPerps$5M

    Perpetuals platform Wasabi Protocol was drained of roughly $5 million (initially reported at $4.5 million) on 30 April 2026 after its deployer admin key was compromised.

    The attacker used the compromised deployer key to call grantRole with zero delay, then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining vaults across Ethereum, Base, Berachain and Blast, including wWETH, sUSDC, wBITCOIN and wPEPE pools. Reporting highlighted the absence of a timelock or multisig on the admin role as the key safeguard failure.

  36. Sweat EconomySmart Contract BugNEARDeFi$4M

    On 29 April 2026 an attacker exploited a refund-logic bug in the SWEAT token contract on NEAR, draining about 13.71 billion tokens — roughly 65% of supply, worth up to $3.5 million — in around 30 seconds.

    The contract was missing an access-restriction macro: the attacker chained a no-op call returning empty bytes into ft_resolve_transfer, which the contract interpreted as 'receiver consumed zero tokens' and refunded victims' entire balances to the attacker. The team paused the contract, MEXC froze the attacker's account and Rhea Finance halted SWEAT trading; the team subsequently restored all external user balances and deployed a patched contract.

  37. Aftermath PerpsSmart Contract BugSuiPerps$1M

    Sui-based perpetuals platform Aftermath was exploited for about $1.14 million on 29 April 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as a fee-accounting logic flaw in the perps contracts on Sui. Detailed independent reporting on the incident is limited.

  38. PurrlendSmart Contract BugHyperliquidLending$2M

    Lending protocol Purrlend was exploited for about $1.5 million on 25 April 2026, according to DefiLlama's hacks database.

    DefiLlama records the incident across MegaETH and Hyperliquid L1 and attributes it to a fake bridge address exploit in the protocol's logic. Detailed independent reporting on the incident is limited.

  39. GiddySmart Contract BugEthereumWallet$1M

    Smart wallet platform Giddy was exploited for about $1.3 million on 23 April 2026, according to DefiLlama's hacks database.

    DefiLlama classifies the incident as a protocol logic exploit caused by incomplete EIP-712 signature coverage, which allowed signed messages to be abused to move user funds on Ethereum. Detailed independent reporting on the incident is limited.

  40. VoloPrivate Key CompromiseSuiYield$4M

    Sui liquid staking protocol Volo lost about $3.5 million from three vaults (WBTC, XAUm and USDC) on 21 April 2026 after a privileged admin key was compromised.

    GoPlus Security and ExVul attributed the breach to a compromised operator key obtained through social engineering rather than any flaw in Volo's audited contracts. Volo self-disclosed within hours, froze the vaults, worked with the Sui Foundation, blocked a WBTC bridge attempt and clawed back around $2 million quickly; the team said it recovered nearly all funds, leaving a net loss of roughly $60,000, and absorbed user losses.

  41. Kelp DAOBridge ExploitMultichainYield$292M

    On 18 April 2026 attackers stole about 116,500 rsETH worth roughly $292 million from liquid restaking protocol Kelp DAO's LayerZero-powered bridge — the largest crypto theft of 2026 so far.

    Attackers reportedly compromised a LayerZero Labs developer in early March, poisoned internal RPC nodes and DDoSed external ones so the single verifying DVN read fake burn events, causing the bridge to release rsETH against burns that never happened; rsETH was configured with only one verifier. Kelp paused contracts to block a further $95 million theft, and the Arbitrum Security Council froze over 30,000 ETH of downstream funds. Chainalysis and multiple outlets attributed the attack to North Korea-linked actors, and the exploit triggered $6.2 billion of Aave withdrawals before a 'DeFi United' effort raised about 132,650 ETH to backstop bad debt; Kelp and LayerZero publicly disputed responsibility for the single-verifier configuration.

  42. Rhea FinanceSmart Contract BugNEARLending$18M

    NEAR-based lending and trading protocol Rhea Finance was exploited in mid-April 2026 via a flaw in its margin-trading slippage protection, with losses revised from an initial $7.6 million to about $18.4 million on 17 April.

    The attacker constructed a series of swaps that bypassed slippage checks — the system aggregated expected output values across multiple swap steps without accounting for tokens reused across transactions — diverting borrowed reserve assets into attacker-controlled liquidity pools. Rhea paused its lending contracts, and the attacker returned roughly $3.3 million in USDC and 1.56 million NEAR, while around $4.34 million in USDT was frozen.

  43. GrinexPrivate Key CompromiseTronCEX$15M

    Sanctioned Russia-linked exchange Grinex was drained of roughly $13.7–15 million from its hot wallets on 15 April 2026 and halted all operations the following day.

    The theft began around 12:00 UTC on 15 April, with stolen USDT swapped into TRX and ETH to avoid issuer freezes and split across dozens of wallets; TRM Labs later identified around 70 drained addresses, raising the confirmed estimate to about $15 million. Grinex, the successor to sanctioned exchange Garantex, blamed 'Western special services' — a claim no independent researcher has verified. Elliptic and Chainalysis both documented the shutdown of the exchange.

  44. CoW SwapPhishingEthereumDEX$1M

    On 14 April 2026 CoW Swap's cow.fi domain was hijacked and users were redirected to a wallet-draining phishing site, with reported losses of about $1.2 million.

    Attackers used forged documents and weaknesses in the .fi domain registration process to seize the domain at around 14:54 UTC, serving a fake front end that drained connected wallets. CoW DAO confirmed its smart contracts, backend and APIs were not compromised, paused the protocol as a precaution, identified the breach within 19 minutes and restored the domain within 26 hours, later adding RegistryLock protection.

  45. HyperbridgeBridge ExploitEthereumBridge$3M

    On 13 April 2026 an attacker submitted forged state proofs to Hyperbridge's Token Gateway on Ethereum, minting 1 billion bridged DOT and draining escrowed assets; losses were later revised from about $237,000 to roughly $2.5 million.

    The attacker exploited a flaw in the Merkle Mountain Range proof verification logic of the HandlerV1 contract — the proof was not bound to a specific request and a zero-second challenge period allowed immediate execution — seizing admin control of the bridged DOT token. DOT pools on Ethereum, Base, BNB Chain and Arbitrum were affected, though Polkadot's core network and native DOT were untouched. Hyperbridge said a significant portion of the funds was traced to Binance and that it was working with the exchange's compliance team and law enforcement on freezes.

  46. Drift ProtocolAccess ControlSolanaPerps$286M

    On April 1, 2026, Drift Protocol suffered a roughly $286M exploit after attackers gained unauthorised administrative control and drained multiple protocol vaults on Solana.

    Early reporting indicated this was not a routine smart-contract math bug but a privileged-control failure. The attacker rapidly drained several core vaults, with stolen assets including JLP, USDC, SOL, cbBTC and wBTC. Drift suspended deposits and withdrawals while investigators traced the outflows. Later reporting from Elliptic said the laundering patterns and on-chain behaviour were consistent with previous DPRK-linked operations, though that remains an attribution claim rather than a court finding.

  47. Resolv LabsAccess ControlEthereumStablecoin$25M

    On March 22, 2026, Resolv Labs suffered an infrastructure breach after attackers gained privileged access through a compromised private key and minted a large block of uncollateralised USR.

    This was not a contract-logic failure so much as the old classic: somebody got access they should not have had. The attacker used the compromised mint authority to create roughly $80M in fake USR, staked part of it into wstUSR, swapped into real assets, and tried to force value out before the protocol could shut the doors. Resolv moved quickly, paused the relevant contracts, burned a chunk of attacker-held supply, and said the realised damage before the pause was far smaller than the headline nominal mint. The important distinction is that the collateral base was not directly emptied; the danger came from fake liabilities being created against it.

  48. USDC Permit Signature PhishPhishingEthereumWallet$2M

    On March 16, 2026, a victim lost $1.76M in USDC after signing a malicious Permit approval that handed spending rights to an attacker-controlled contract.

    No fancy contract math here. The victim was tricked into signing what looked like a routine approval flow, but the Permit granted the attacker's contract the power to transfer the victim's USDC. The funds were drained immediately, swapped into ETH, and split across several wallets. Another reminder that one bad signature can be as fatal as a leaked seed phrase.

    On-chain

  49. VenusOtherBNB ChainBorrowing$2M

    On March 16, 2026, Venus Protocol on BSC was left with about $2.18M in bad debt after an attacker abused a supply-cap enforcement gap around THE and then pumped the token in thin liquidity.

    This one was slow-cooked, not smash-and-grab. Over roughly nine months, the attacker built a giant uncapped THE position by routing around the normal deposit path and bypassing the intended supply ceiling. Once the position was in place, they started the recursive part: borrow assets, buy THE in low liquidity, push the price higher, transfer more THE into the market, inflate collateral value, repeat. The oracle did what it was told and reflected the manipulated market. When the unwind came, the collateral could not cover the borrowings and Venus was left with bad debt.

    On-chain

    • Attacker Wallet 10x7a79969a0b9d51d922c4810d2950560360f6f234
    • Attacker Wallet 20x737bc98f1d34e19539c074b8ad1169d5d45da619
    • Attacker Wallet 30x1a35bd28efd46cfc46c2136f878777d69ae16231
  50. Solv ProtocolOtherEthereumVault$3M

    On March 5, 2026, Solv's BRO vault was exploited through a double-mint flaw that let the attacker turn a tiny BRO position into a cartoonishly large one and swap it for real SolvBTC.

    The vulnerable BRO contract effectively paid twice in the same mint path. When the ERC-3525 NFT transfer callback fired, tokens were minted once, and then the outer mint routine minted them again. The attacker just looped burn/mint repeatedly until 135 BRO had been inflated into hundreds of millions. Once the fake balance existed, it was exchanged for real SolvBTC. Solv said the impact was confined to the affected vault and committed to covering losses.

    On-chain

  51. Blend ProtocolOracle ManipulationStellarBorrowing$11M

    On February 22, 2026, the YieldBlox DAO Pool on Blend V2 was exploited for about $10.86M after an attacker pushed USTRY's SDEX price roughly 100x higher and let the oracle swallow it whole.

    The attacker found an absurdly thin order book and did what attackers do when markets are basically decorative: they walked the price into the sky. Reflector picked up the manipulated SDEX price and Blend treated the attacker's USTRY as prime collateral instead of what it actually was. That opened the door to borrowing tens of millions in XLM and USDC against collateral worth a fraction of that. Once again, the oracle was not hacked in the Hollywood sense; it was just far too trusting.

    On-chain

    • Attacker AddressGBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC
    • YieldBlox DAO PoolCCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS
    • Oracle AdapterCD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR
    • Reflector OracleCALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M
  52. IoTeX ioTube BridgeAccess ControlEthereumBridge$4M

    On February 21, 2026, IoTeX's ioTube bridge lost about $4.4M on the Ethereum side after attackers compromised the Validator owner account and upgraded it to bypass the bridge's security checks.

    Once the owner account was in hostile hands, the attacker replaced the Validator logic with something that effectively waved everything through. That broke the trust boundary protecting the MintPool and TokenSafe contracts, letting the attacker mint bridge-side assets and drain reserve tokens. IoTeX managed to freeze and blacklist a meaningful slice of the fallout, but not before real value had already left.

    On-chain

    • Attacker Address0x6487B5006904f3Db3C4a3654409AE92b87eD442f
  53. Moonwell cbETH Oracle IncidentOracle ManipulationBaseBorrowing$2M

    On February 15, 2026, Moonwell on Base suffered about $1.78M in losses when cbETH was mispriced at roughly $1.12 instead of around $2,200, triggering mass liquidations and cheap borrowing.

    This was not subtle. The oracle pipeline effectively passed through a token ratio without multiplying it back into the dollar value of ETH. That meant the protocol treated cbETH as almost worthless. Liquidation bots stepped in, repaid pocket change, and received outsized chunks of collateral. Other users borrowed against the same broken number. Moonwell moved to clamp the market fast, but not before the bad price had already done its damage.

    On-chain

    • Affected AssetscbETH (primary), cbBTC, tBTC
  54. CrossCurveOtherMultichainBridge$3M

    On February 1, 2026, CrossCurve lost roughly $2.9M after an attacker exploited an authorisation bypass in ReceiverAxelar's express execution flow.

    Axelar's model is supposed to bind execution to validated cross-chain messages. The weak point here was a path that skipped that validation and relied too heavily on attacker-controlled metadata. The result was spoofed messages that looked close enough to pass local checks, letting the attacker trigger unlocks they had no right to trigger. CrossCurve responded with a white-hat ultimatum and threat of legal follow-through, which is usually what teams say when the chain has already spoken.

    On-chain

    • Funds Holder 10xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE
    • Funds Holder 20x8c259f1e53e79408095d0ba805554d4cdda15285
    • Funds Holder 30x851c01d014b1ad2b1266ca48a4b5578b67194834
  55. Step Finance Treasury BreachAccess ControlSolanaTreasury$30M

    On January 31, 2026, Step Finance suffered a treasury breach of roughly $27M-30M after multiple treasury wallets were compromised and stake authority was transferred away.

    Step described the route as a well-known attack vector, which usually means something operational and ugly rather than elegantly novel. Once the attacker had the relevant wallet access, they moved stake authority, unstaked, and drained a huge SOL position. The key point is that this appears to have been treasury-specific rather than a user-fund contract exploit, but $30M disappearing is still $30M disappearing.

    On-chain

    • Compromised Stake Account6G53KAWtQnZSSN6HUxnBs3yYsK1aCuJRbrcPbWGY71LL
    • Attack Transaction2w8sgATZwcmRMHEsG3nutmZJrskVkp74LAwTTEyxSMBJhnZ7Ux4ticeYAYnTb6K44m1XYziPvqonSkZeukAAFadZ
  56. Aperture FinanceOtherMultichainRouting$4M

    On January 25, 2026, Aperture Finance V3/V4 contracts were exploited for about $3.67M across multiple chains through a similar arbitrary-call / approval-abuse flaw.

    The attacker did not need users to do anything in the moment. The damage came from approvals that already existed. Once the vulnerable call path was abused, ERC-20 and even NFT-style approvals could be cashed in. The exploit also overlapped with the wider SwapNet incident, which suggests the attackers were not improvising but moving through a known pattern.

    On-chain

    • Affected Contract 10xD83...8913
    • Affected Contract 20x008...d857
    • Affected Contract 30xe00...05cB
  57. SwapNetOtherMultichainExchange$17M

    On January 25, 2026, SwapNet was hit for about $17M after attackers abused an arbitrary-call style flaw to weaponise existing token approvals.

    This one was grimly practical. Users had already approved router-style contracts, and the vulnerable logic let attackers steer those approvals into unauthorised transferFrom calls. In other words, the protocol became a machine for cashing in permissions users had granted earlier under normal conditions. This was linked to the same broader approval-abuse wave that also hit Aperture.

    On-chain

    • Router Contract0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e
  58. SagaEVMOtherSagaEVMChainlet$7M

    On January 21, 2026, SagaEVM suffered a roughly $7M incident involving coordinated malicious deployments and cross-chain exits to Ethereum.

    Saga's account of this is important: they said there was no validator compromise, no consensus failure, and no signer key leak. That suggests the failure lived inside the chainlet or attached execution environment rather than the network's deeper trust layer. Still, the attacker got real assets out before the chainlet was halted, which is all users and markets tend to care about.

    On-chain

    • Exploiter Wallet0x2044697623afa31459642708c83f04ecef8c6ecb
  59. Makina FinanceFlash LoanEthereumYield Aggregator$5M

    On January 20, 2026, Makina Finance suffered a $5M oracle-manipulation exploit against the DUSD/USDC Curve pool, with part of the value intercepted by an MEV builder.

    The attacker pulled a giant USDC flash loan, distorted the MachineShareOracle's pricing, and used the bad number to drain the relevant stablecoin liquidity. The funny detail, if one can call it funny, is that a big chunk of the exploit value was frontrun and effectively stolen from the thief by an MEV builder. DeFi increasingly has these nested theft structures now: protocol gets robbed, then the robber gets partially robbed on the way out.

  60. Yo YieldOtherEthereumYield Aggregator$4M

    On January 13, 2026, Yo Yield lost about $3.7M when 3.84M GHO was swapped into just 112K USDC during a vault operation.

    Sometimes the exploit is simply dreadful execution. The protocol converted something that should have behaved roughly like a stable-for-stable trade into catastrophic slippage. Whether you label that a bug, controls failure, or operator negligence, the effect is the same: a vault did something economically insane and users wore the damage.

  61. NYC MemecoinRugpullSolanaToken$3M

    On January 13, 2026, the $NYC memecoin was accused of a classic rug after liquidity was pulled shortly after promotion from a high-profile account.

    There is not much technical subtlety here. The pattern described by researchers is the standard memecoin circus: public hype, fast inflows, liquidity removed, late buyers stranded. Once again, the interesting part is not the code but the distribution mechanism -- credibility and audience were the real attack surface.

  62. Social Engineering TheftPhishingMultichainWallet$282M

    On January 10, 2026, a victim lost more than $282M in BTC and LTC through a hardware-wallet social-engineering scam, after which the attacker moved rapidly across THORChain, CEXs and privacy rails.

    This was not a protocol failure at all; it was human compromise followed by industrial-grade laundering. The attacker started bridging and swapping almost immediately, moving large slices through THORChain into ETH, XRP and other assets, then dispersing funds across exchanges and mixers. It was a reminder that in raw dollar terms, social engineering still competes comfortably with every smart-contract exploit you care to name.

    On-chain

    • BTC Theft Address 1bc1qluxw46r55wf3dnk9c652vrt4duadm3hpuktf86
    • BTC Theft Address 2bc1qpsmh26ja0fzzf286zulmt9eywujc2pggj40wzm
    • LTC Theft Addressltc1qly43c2prj4c2e85dcspzpjd36jnapnenldnr70
  63. TruebitOtherEthereumToken$27M

    On January 8, 2026, Truebit lost about $26.5M after an integer overflow in getPurchasePrice() let the attacker mint TRU for effectively zero ETH and dump it.

    This is the kind of bug that makes smart-contract veterans sigh and stare into the middle distance. A large input caused the pricing math to overflow, the division result collapsed to zero, and the attacker could repeatedly mint huge amounts of TRU without paying meaningful cost. The market did the rest. Once the newly minted supply hit liquidity, the token price fell off a cliff and the attacker walked away with ETH.

  64. TMXOtherArbitrumExchange$1M

    On January 6, 2026, TMX on Arbitrum lost around $1.4M when an attacker found a profitable mint/stake/swap/unstake loop and repeated it until the pools were drained.

    The contract was unverified, which never helps, but the core pattern was simple enough: each cycle returned more value than went in. Once that kind of mechanical edge exists, the attacker's job is just to keep pressing the button until the pool stops paying. That appears to be what happened here.

  65. Unleash ProtocolAccess ControlStoryGovernance$4M

    On December 30, 2025, Unleash Protocol's multisig governance was compromised, enabling an unauthorised upgrade and a drain of roughly $3.9M.

    This was a permissions story. Once the attacker acquired governance-side control, the rest followed in depressingly familiar fashion: upgrade logic, withdraw assets, bridge out, launder through Tornado. Story itself said its core infrastructure was unaffected, which may be true, but that is cold comfort when the application sitting on top of it has been opened with admin keys.

    On-chain

  66. Flow NetworkOtherFlowExecution Layer$4M

    On December 27, 2025, an attacker exploited a flaw in Flow's execution layer and moved roughly $3.9M off-network through bridges before validators coordinated a halt.

    Flow stressed that existing user balances were not touched, which matters. The vulnerability appears to have been in the exit/execution path rather than a direct user-account drain. That said, once assets are already riding bridges to Ethereum and the attacker is sending value through THORChain and Chainflip, the distinction becomes more architectural than comforting.

    On-chain

    • Exploiter0x2e7C4b71397f10c93dC0C2ba6f8f179a47F994e1
  67. Trust Wallet Browser ExtensionAccess ControlMultichainWallet$7M

    On December 26, 2025, Trust Wallet Browser Extension v2.68 was compromised, leading to about $6M-7M being drained from affected users.

    This was a supply-chain style wallet incident. The bad version reportedly gave the attackers access to sensitive wallet material or signing capability, and once a malicious update is sitting in a live extension channel the blast radius can expand quickly. Trust Wallet pushed users to disable the version and move fast, but malicious updates are brutal because they hijack the trust users have already granted.

  68. Address Poisoning AttackPhishingEthereumWallet$50M

    On December 20, 2025, a victim lost almost $50M in USDT after copying a poisoned lookalike address from transaction history.

    This was pure human-interface exploitation. The attacker exploited how people rely on recent transaction history and glance at the first and last few characters of an address instead of verifying the whole thing. After the victim sent a small test amount, the poisoned address appeared in their history and the main transfer followed. The attacker then started laundering almost immediately through stablecoin swaps and Tornado.

  69. Yearn Finance Legacy yETH ExploitFlash LoanEthereumYield Aggregator$9M

    On November 30, 2025, a legacy Yearn yETH product was exploited, letting the attacker infinitely mint yETH and drain almost $9M from connected liquidity pools.

    The vulnerable path sat in old yETH logic rather than Yearn's later vault architecture. Once the attacker could mint effectively unbacked yETH, those fake claims were pushed into Balancer and Curve-style liquidity to pull out real ETH and LSDs. Yearn later coordinated some recovery and treasury support, but the broader lesson was the usual one: old code with live liquidity attached is still live risk.

  70. Upbit Solana Hot-Wallet BreachAccess ControlSolanaExchange$36M

    On November 27, 2025, Upbit reported about $36M in unauthorised outflows from a production Solana hot wallet and suspended Solana rails.

    The outflows hit multiple Solana assets, and the important operational point was that Upbit said cold wallets were not compromised and customer balances would be made whole. That suggests an exchange hot-wallet security failure rather than a total infrastructure collapse. Still, when a major exchange says unauthorised outflow, the words are polite but the meaning is not.

  71. GANA Payment Liquidity DrainOtherBNB ChainToken$3M

    On November 20, 2025, GANA Payment on BSC was stripped of roughly $3.1M before the proceeds were washed through Tornado Cash on BSC and Ethereum.

    The exact technical cause remained murky, but the money trail was clear enough: liquidity drained, proceeds converted, laundering began. GANA looked like one of those thinly documented projects where public code and public explanation lag far behind the actual economic damage.

  72. Stream Finance External Manager Blow-UpOtherMultichainSynthetic / Credit$93M

    On November 4, 2025, Stream Finance said an external fund manager had effectively vaporised around $93M, triggering a much wider synthetic-debt unwind.

    This was less a smart-contract exploit than a systemic collateral crisis. Stream's synthetic stack was wired into multiple lenders and related stable structures, so once confidence broke the damage spread quickly. These are often the messiest incidents because the initial hole is smaller than the eventual credit crater it opens.

  73. Moonwell wrsETH Oracle MeltdownOracle ManipulationBaseBorrowing$4M

    On November 4, 2025, Moonwell's Base deployment was left with around $3.7M in bad debt after a wrsETH oracle briefly valued one token like a small country.

    The attacker used a nonsense oracle print to treat dust-sized wrsETH as enormous collateral. Once that happened, the rest was routine: borrow real assets, cycle through markets fast, leave the protocol holding the embarrassment. Moonwell clamped supply and borrow caps quickly, but fast clamps do not un-create bad debt.

  74. Balancer V2 Stable Pool ExploitOtherMultichainAMM$116M

    On November 3, 2025, Balancer's V2 Stable and Composable Stable v5 pool logic was exploited for about $116M across multiple deployments.

    Balancer's preliminary write-up tied the attack to stable-pool rounding / upscale behaviour in EXACT_OUT swap flows combined with flash loans and BatchSwaps. Put simply: old, complex pool math was pushed into states it should never have tolerated, and the attacker extracted value faster than mitigations could contain it.

  75. Beets Fi Balancer V2 Sonic IncidentOtherSonicAMM$3M

    On November 3, 2025, Beets' Balancer V2 pools on Sonic were hit in the wider Balancer exploit wave, but Sonic's freeze mechanism trapped around $3M on-chain.

    This is the rare exploit where a chain-level intervention materially limited the attacker's ability to get paid. The underlying pool logic was still broken, but Sonic's security tooling prevented the normal exit route of bridge-and-launder.

  76. Garden Finance Multi-Chain Liquidity DrainOtherMultichainCross-chain$11M

    On October 30, 2025, Garden Finance lost about $11M across multiple networks in a coordinated drain of WBTC, USDC and USDT liquidity.

    Garden argued its core contracts were fine and pointed to integrations; outside observers were less generous. Whatever the precise fault line, the practical result was that value moved out across chains, into ETH, and into laundering routes. That is usually the moment when debates about root cause become secondary.

  77. Typus Finance Oracle ManipulationOracle ManipulationSuiBorrowing$3M

    On October 15, 2025, Typus Finance on Sui lost about $3.44M after a broken auth gate in the oracle module let the attacker publish bogus prices.

    A public price feed without real authentication is less an oracle than a suggestion box. Once the attacker could publish values the protocol treated as trusted, draining the TLP became straightforward. Typus paused quickly, but the bug was the kind that should never have made it to production.

  78. Hyperliquid Private Key CompromiseAccess ControlHyperliquidWallet$21M

    On October 10, 2025, a leaked signing key let attackers bridge out about $21M from a Hyperliquid user.

    This was key compromise, not clever protocol exploitation. The funds moved with attacker-signed transactions, which is a much duller but more common cause of loss than people like to admit.

  79. Hypervault Suspected RugpullRugpullHyperliquidYield$4M

    On September 26, 2025, Hypervault appeared to pull a classic exit, moving about $3.6M in user funds off Hyperliquid and into laundering channels.

    Team disappears, funds consolidate, bridges light up, Tornado appears in the distance: everyone knows the choreography by now.

  80. GriffinAI GAIN Cross-Chain Peer ExploitAccess ControlBNB ChainToken$3M

    On September 25, 2025, GriffinAI's GAIN token was exploited after a rogue LayerZero peer was accepted as trusted, enabling mass minting and a token collapse.

    Trusted-peer design is only as trustworthy as the peer registration. Once the attacker got a malicious contract accepted, they could mint GAIN as if it were legitimate cross-chain flow and dump it into real liquidity.

  81. SBI Crypto Hot-Wallet HeistAccess ControlMultichainExchange$24M

    On September 24, 2025, attackers drained about $24M across BTC, ETH, LTC, DOGE and BCH in a multi-asset hot-wallet breach tied to SBI infrastructure.

    The case had all the usual custodial red flags: hot-wallet exposure, fast laundering, and uncertainty over whether the initial compromise was keys, servers, or something adjacent. Either way, the exchange side of the stack failed before chain logic had any chance to matter.

  82. UXLINK Multi-Sig & Mint AbuseAccess ControlArbitrumToken$48M

    On September 22, 2025, UXLINK suffered a multi-sig takeover, asset sweep and huge unauthorised token mint, with losses around $48M.

    Once multi-sig control broke, it ceased to be a protocol and became the attacker's toy. Funds were swept first, inflation weaponised next, and then the attacker themselves reportedly got partially phished later in a kind of criminal slapstick sequel.

  83. Aqua Solana Presale RugRugpullSolanaToken$5M

    On September 9, 2025, Aqua's team allegedly rugged a Solana presale worth roughly $4.65M despite audits, partnerships and heavy credibility theatre.

    The familiar pattern: build a trust wrapper, borrow legitimacy, pull liquidity, vanish. The scam's sophistication tends to live in its marketing, not its code.

  84. SwissBorg SOL Earn BreachAccess ControlSolanaStaking$42M

    On September 8, 2025, a compromised Kiln integration led to about $41.5M in SOL losses from SwissBorg's SOL Earn product.

    SwissBorg said the issue was isolated to the partner integration and covered users from treasury. That distinction matters operationally, but from the user side it still feels like the platform's stack failed where it most needed not to.

  85. Venus Protocol Delegate PhishPhishingBNB ChainBorrowing$13M

    On September 2, 2025, a malicious delegation flow let an attacker borrow and redeem roughly $13M on a user's behalf -- though the funds were later recovered.

    The protocol itself was not mathematically broken; the permission model around the victim account was. That is increasingly common: not code failure exactly, but trust granted to the wrong address or contract.

  86. Bunni v4 Hooks Liquidity DrainOtherEthereumAMM$8M

    On September 2, 2025, Bunni's custom v4 hook logic was exploited for about $8.4M across Ethereum and Unichain.

    Uniswap v4 lets builders get creative. Creativity is not always the same thing as safety. Bunni's rebalancing and share-accounting logic could be pushed into states that credited more value than it should have.

  87. Better Bank Bonus-Mint ExploitOtherPulseChainBorrowing$5M

    On August 26, 2025, Better Bank lost about $5M after an attacker abused a bonus-mint path tied to its Favor / Esteem mechanics.

    The attacker found a route where the protocol rewarded itself into insolvency. Once a contract can be induced to create more redeemable value than should exist, the rest is just path optimisation.

  88. Phishing: 783 BTC DrainedPhishingBitcoinWallet$91M

    On August 19, 2025, a victim lost 783 BTC -- roughly $91M -- in a high-touch support-impersonation theft.

    This was not a smart-contract exploit but a trust exploit. The attacker posed as support staff, won access, and then started the slow hygiene of laundering. In cash terms, social engineering is still one of the industry's strongest recurring primitives.

  89. BtcTurk HackAccess ControlMultichainExchange$48M

    On August 14, 2025, BtcTurk suffered a roughly $48M hot-wallet breach across several chains.

    This was another exchange hot-wallet event: assets drained, emergency measures triggered, assurances about cold storage made after the fact.

  90. Odin.fun ExploitOtherBitcoinAMM$7M

    On August 12, 2025, Bitcoin launchpad Odin.fun lost about 58.2 BTC, roughly $7M, after liquidity manipulation in its AMM tool.

    Spoofed or cheaply inserted assets distorted the AMM's assumptions, letting the attacker walk out with real BTC while the accounting insisted the pool was behaving normally enough.

  91. Phishing USDT TheftPhishingEthereumWallet$3M

    On August 6, 2025, a victim was tricked into signing an approval and lost about $3.05M in USDT.

    The simplest scams remain brutally effective. The attacker got approval, moved fast, and routed the funds away before the victim could react.

  92. CrediX ExploitAccess ControlSonicBorrowing$5M

    On August 4, 2025, CrediX on Sonic lost around $4.5M after misassigned admin roles let attackers mint unbacked assets and drain pools.

    Access-control failures do not need technical glamour to be expensive. The wrong permissions existed, the attacker used them, the pool paid.

  93. WOO X Phishing BreachPhishingMultichainExchange$14M

    On July 24, 2025, WOO X lost about $14M after a targeted phishing attack hit a team member's device and opened the way to account drains.

    Infrastructure can be excellent and still be undone by the human endpoint sitting in front of it.

  94. CoinDCX BreachAccess ControlMultichainExchange$44M

    On July 20, 2025, CoinDCX lost roughly $44M after attackers compromised an internal liquidity account.

    Server-side or key-side compromise remains one of the cleanest paths to very large exchange losses. Once the attacker is inside the liquidity machinery, chain-level sophistication is optional.

  95. BigONE Exchange HackAccess ControlMultichainExchange$28M

    On July 16, 2025, BigONE lost around $28M in a hot-wallet breach spanning Bitcoin, Ethereum, Tron and Solana.

    Another custodial wallet failure, another multi-chain scramble, another assurance that reimbursements will follow.

  96. Arcadia Finance ExploitOtherBaseRebalancing$3M

    On July 15, 2025, Arcadia lost about $2.5M on Base after a router validation flaw let attackers smuggle malicious calls through rebalance logic.

    The protocol executed instructions it should never have trusted. That is often the heart of these router-style exploits.

  97. GMX ExploitOtherArbitrumPerps$42M

    On July 9, 2025, GMX was exploited for about $42M on Arbitrum. The attacker later returned the funds after accepting a $5M white-hat bounty.

    The exploit targeted GMX's older vault logic. After a public bounty offer of 10%, the attacker returned the stolen funds, making this one of the larger successful white-hat recoveries. Recovery does not erase the underlying issue, but it stopped the headline from becoming even worse.

  98. Resupply ExploitOracle ManipulationEthereumBorrowing$10M

    On June 26, 2025, Resupply lost about $9.5M after an oracle manipulation attack let the attacker borrow against inflated collateral.

    Again: bad number in, bad debt out.

  99. Nobitex HackAccess ControlMultichainExchange$82M

    On June 18, 2025, Iranian exchange Nobitex was hit for about $82M in a major hot-wallet compromise.

    Large centralised exchanges remain giant, tempting concentrations of key risk. Nobitex joined the long and unhappy list. The breach was later analysed by Chainalysis and TRM Labs, the latter noting that leaked source code revealed structural weaknesses in the exchange's infrastructure.

  100. AlexLab ExploitAccess ControlStacksDeFi$16M

    On June 6, 2025, AlexLab on Stacks lost around $16.1M after private keys were compromised, allowing the attacker to drain protocol funds.

    Protocol logic was secondary here. Once keys are gone, user-facing assurances tend to follow them. AlexLab later committed to reimbursing affected users and published a detailed breakdown of losses.

  101. Nervos ForceBridge ExploitAccess ControlMultichainBridge$4M

    On June 2, 2025, Nervos's ForceBridge lost about $3.7M after flawed cross-chain validation let attackers mint synthetic assets and dump them.

    Bridge validation is the whole game. When it is wrong, the bridge stops being a bridge and turns into a mint.

  102. Cork Protocol wstETH ExploitOtherEthereumYield$12M

    On May 28, 2025, Cork Protocol lost about $12M after a flaw around wrapped staking asset exchange-rate logic was abused via a Uniswap v4 hook vulnerability.

    Counterfeit or distorted pricing inside wrapped-asset accounting is a reliable way to make real collateral vanish. Dedaub's analysis highlighted this as a critical lesson in Uniswap v4 hook security, given that Cork was an a16z-backed project.

  103. Cetus Protocol ExploitOtherSuiAMM$260M

    On May 22, 2025, Cetus Protocol on Sui was hit for roughly $260M in a devastating AMM manipulation exploit that sent connected token prices down over 90%.

    Cetus was one of the year's defining DeFi disasters. By injecting or exploiting false value relationships inside the pool design, the attacker pulled real assets out en masse and left prices across connected tokens shattered. Multiple security firms published detailed root-cause analyses. The Sui ecosystem ultimately coordinated a partial freeze and recovery effort, but the scale of the damage was immense.

  104. Bitcoin TheftPhishingBitcoinWallet$331M

    On April 27, 2025, 3,520 BTC -- about $330.7M -- was stolen from an elderly US victim in a social-engineering attack, then funnelled through instant exchanges into Monero, briefly spiking XMR's price.

    This was one of those rare incidents large enough to shake adjacent markets. Laundering pressure into XMR caused a visible price reaction. ZachXBT traced the theft and identified the victim as an elderly person in the US targeted through social engineering. Roughly $7M was later frozen with Binance's help, but the vast majority was successfully laundered through privacy rails.

  105. Loopscale HackOracle ManipulationSolanaBorrowing$6M

    On April 26, 2025, Loopscale on Solana lost about $5.8M after a pricing bug around RateX PT collateral let attackers borrow against inflated value, just two weeks after launch.

    Oracle and collateral design failures are often boring on paper and expensive in practice. This was both.

  106. ZKsync Airdrop Contract ExploitAccess ControlZKsyncAirdrop$5M

    On April 15, 2025, a compromised admin wallet swept around $5M in unclaimed ZK tokens from an airdrop contract.

    The exploit path was boring but effective: privileged function, wrong hands, real tokens gone. The ZK token price dropped sharply on the news before partially recovering.

  107. KiloEx Oracle ManipulationOracle ManipulationEthereumPerps$7M

    On April 14, 2025, KiloEx lost about $7M across multiple chains after forged or unauthorised oracle inputs were used to juice leveraged PnL.

    The attacker manipulated how the price feed was trusted and then harvested the obvious economic imbalance. Once again, if your oracle lies and your protocol believes it, the attacker just has to submit the paperwork.

  108. UPCX ProxyAdmin Take-OverAccess ControlEthereumToken$70M

    On April 1, 2025, a hijacked ProxyAdmin let attackers insert malicious logic and drain about $70M worth of UPC tokens.

    Proxy upgrade power is effectively absolute power. Once lost, every downstream assurance becomes theatre.

  109. Abracadabra GMX-Cauldron BugOtherArbitrumBorrowing$13M

    On March 25, 2025, Abracadabra lost about $13M after a bookkeeping flaw let an attacker self-liquidate, re-borrow and recycle collateral in cauldrons tied to GMX liquidity tokens.

    This was accounting getting confused in exactly the way attackers pray for: debt gone from the books before the collateral had really stopped mattering. PeckShield flagged the exploit in real time and multiple security firms published detailed breakdowns.

  110. Zoth Logic-Contract SwapAccess ControlEthereumRWA$8M

    On March 21, 2025, leaked admin rights let attackers swap Zoth's implementation contract and drain around $8.32M from the RWA protocol.

    Upgradeable systems are wonderful right up to the point someone else becomes the upgrader.

  111. 1inch Fusion v1 Re-entrancyOtherEthereumDEX Aggregation$3M

    On March 6, 2025, a re-entrancy issue in 1inch Fusion v1's resolver contract let attackers repeatedly reuse approvals and drain roughly $2.6M.

    Recursive control flow plus user-supplied values remains a classic way to manufacture losses out of otherwise respectable code. 1inch published an official statement confirming the vulnerability was in the resolver contract, not the core aggregation protocol.

  112. Suji Yan Wallet HackPhishingEthereumWallet$4M

    On February 27, 2025, Mask Network founder Suji Yan lost roughly $4M after what appeared to be an offline phone or wallet compromise.

    No protocol bug, just a personal-security disaster with on-chain consequences.

  113. Infini Insider DrainAccess ControlEthereumTreasury$50M

    On February 24, 2025, Infini lost about $50M after retained administrative privileges were allegedly used to drain funds from the stablecoin payment card issuer.

    Insider or insider-style privilege abuse tends to be especially poisonous because it destroys both the money and the story the team can tell about how secure the system was. Infini offered a bounty for return of funds, but the damage to trust was already done.

  114. Bybit Multisig Cold-Wallet HackAccess ControlEthereumExchange$1.40bn

    On February 21, 2025, Bybit suffered the largest single crypto theft on record after a phished multisig flow led to $1.4B in ETH being drained. The FBI attributed the attack to North Korea's Lazarus Group (TraderTraitor).

    The key lesson was brutal and simple: a multisig is only as safe as the signing environment and the humans using it. The interface showed one thing, the underlying permission change did another, and the largest single crypto theft on record followed. The FBI publicly attributed the hack to the DPRK-linked threat actor known as TraderTraitor (Lazarus Group / APT38) and issued a formal PSA. Bybit published a detailed incident timeline and committed to full transparency throughout the recovery process.

  115. LIBRA Rug PullRugpullSolanaToken$286M

    On February 16, 2025, LIBRA imploded in what looked far more like insider distribution and rug mechanics than some tragic accident, wiping out roughly $286M. The incident sparked a political scandal in Argentina.

    When memecoin theatrics overlap with politics, the post-mortem gets noisy fast. The money, unfortunately, was quieter and more final. TRM Labs published a detailed fund-tracing analysis, and the incident eventually warranted its own Wikipedia article due to the political dimensions involved.

  116. zkLend ExploitOtherStarknetBorrowing$10M

    On February 12, 2025, zkLend lost about $9.5M in a flash-loan exploit on Starknet. The attacker later attempted to launder through Railgun but funds were flagged and partially recovered.

    The protocol still failed first. The partial recovery narrative is interesting, but it came after the money had already been stolen. BlockSec published a detailed post-mortem clarifying several misunderstandings about the attack mechanics.

  117. DogWifTools ExploitOtherMultichainTooling$10M

    On January 28, 2025, DogWifTools users were hit in a roughly $10M supply-chain exploit that drained wallets through a compromised version of the Solana pump.fun trading tool.

    When wallet-adjacent software is compromised, the distinction between application risk and wallet risk disappears immediately. BleepingComputer covered this as a supply-chain attack where the tool itself was trojaned to exfiltrate private keys.

  118. Phemex ExploitAccess ControlMultichainExchange$37M

    On January 23, 2025, Phemex lost about $37M amid a multi-chain hot-wallet breach. The exchange published a timeline and compensation plan shortly after.

    Another exchange reminder that once the hot-wallet layer is compromised, attackers do not need deep protocol wizardry to do large damage fast. Phemex was relatively transparent in their response, publishing a detailed timeline and reassuring users with a compensation framework.

All losses in USD, best public estimate at the time of logging, verified against on-chain analysis and named sources. Attribution claims are reported as claims, not findings.Last update · 06 Aug 2026