{
 "name": "YFarmX Crypto Exploit Tracker",
 "homepage": "https://yfarmx.com/tools/exploit-tracker/",
 "updated": "2026-09-15",
 "source": "Public incident reports and on-chain records, checked 15 September 2026. This refresh adds incidents with gross exposure of at least $10m; earlier smaller incidents remain in the historical log. Gross amounts and subsequent recoveries are distinguished in each entry.",
 "license": "CC BY 4.0",
 "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
 "attribution": "YFarmX, https://yfarmx.com",
 "records": [
  {
   "id": "exploit-0132",
   "title": "Liquid reserve withdrawal and partial Bitcoin recovery",
   "date": "2026-09-06",
   "lossUsd": 320000000,
   "attackVector": "Software Bug",
   "chain": "Liquid / Bitcoin",
   "sector": "Bridge",
   "summary": "Liquid acknowledged a roughly 4,000 BTC withdrawal, valued at about $320m at the time. SideSwap says the L-BTC used for the peg-out was created through an Elements bug. On 7 September, 3,400 BTC returned to the federation address; the return transaction sent 598.49955894 BTC back to the actor. The dollar figure here is the initial gross withdrawal estimate, before recovery.",
   "details": "The return confirmed at 16:09:25 UTC on 7 September in block 965,950. It restored roughly 85% of the approximately 4,000 BTC headline amount. A subsequent 8 September transaction retained 598.49988609 BTC in a large output at the actor’s address, after intervening small transfers. The actor’s white-hat description is self-asserted; the cited records establish the movement of coins, while terms for retaining them remain unconfirmed. Blockstream’s status page still listed an active public bridge incident when checked on 8 September. The Exploit Tracker’s $320m entry is gross incident value, not a $320m outstanding loss.",
   "blockData": [
    {
     "label": "3,400 BTC return",
     "text": "Block 965,950 · 7 Sep 2026, 16:09:25 UTC",
     "url": "https://mempool.space/tx/a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d"
    },
    {
     "label": "8 September actor output",
     "text": "598.49988609 BTC · block 966,087",
     "url": "https://mempool.space/tx/1d690f3b96b878067f3a445b74dfb8fab4201c0455d88ac98cc14a927e7858d7"
    }
   ],
   "links": [
    {
     "label": "Liquid incident acknowledgement",
     "url": "https://x.com/Liquid_BTC/status/2096696272447218108"
    },
    {
     "label": "SideSwap incident statement",
     "url": "https://x.com/side_swap/status/2096709838310928674"
    },
    {
     "label": "Blockstream service status",
     "url": "https://status.blockstream.com/"
    }
   ],
   "logo": "/media/brands/liquidnetwork.png",
   "article": "liquid-network-4000-btc-peg-out",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0132/"
  },
  {
   "id": "exploit-0004",
   "title": "Aquifer AMM Exploit on Solana",
   "date": "2026-08-31",
   "lossUsd": 2469729,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "AMM",
   "summary": "Aquifer, an automated market maker on Solana, was exploited on 31 August 2026. DefiLlama records the loss at $2,469,729 and classifies it as an access-control incident involving an arbitrary external call.",
   "details": "DefiLlama’s classification is the only part of this incident that can be checked. Aquifer’s own site is unreachable from here, no statement from the project could be found, and the monitoring account said to have flagged it first could not be opened. So the mechanism reported elsewhere, a wallet compromise rather than a contract flaw, along with the attacker addresses and a reported whitehat bounty and deadline, are all unverified and are deliberately left out rather than repeated.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://api.llama.fi/hacks"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0004/"
  },
  {
   "id": "exploit-0003",
   "title": "More Markets Lending Reserve Drain on Flow EVM",
   "date": "2026-08-31",
   "lossUsd": 410000,
   "attackVector": "Smart Contract Bug",
   "chain": "Flow",
   "sector": "Lending",
   "summary": "Security firm Blockaid flagged a suspected exploit on More Markets, a lending protocol on Flow EVM, on 31 August 2026, saying an attacker combined Ankr’s liquid staking token ankrFLOW with Aave V3 efficiency mode to overborrow against the mFlowWFLOW reserve. More Markets said the same day that it was investigating a claim it had been exploited. DefiLlama records the loss at $410,000, an unbacked mint.",
   "details": "Two figures are in public and they do not agree. Blockaid’s original alert cited a detected impact of about $9.3m; that post has since been deleted by its author, so the figure cannot be checked against its source and is not used here. DefiLlama’s hacks database carries the incident under Ankr on Flow at $410,000, classified as token and share accounting, unbacked mint, and that is the figure this log records. The gap between the two is unresolved in public. A reported follow-up from More Labs disputing the exploit could not be found and is not relied on.",
   "blockData": [],
   "links": [
    {
     "label": "MORE Markets, statement on the claim (31 August 2026)",
     "url": "https://x.com/MORE_DeFi/status/2094337707753222313"
    },
    {
     "label": "DefiLlama hacks database",
     "url": "https://api.llama.fi/hacks"
    }
   ],
   "logo": "/media/brands/moremarkets.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0003/"
  },
  {
   "id": "exploit-0002",
   "title": "Ontology Mainnet Halt After Malicious Attack Activity",
   "date": "2026-08-31",
   "lossUsd": null,
   "attackVector": "Other",
   "chain": "Ontology",
   "sector": "Layer 1",
   "summary": "Ontology’s core development team paused mainnet block production on 31 August 2026 after what it first described as a potential security concern found during a routine check. A follow-up on 1 September confirmed it had identified malicious attack activity targeting the network. The chain resumed on 2 September, with every sync node required to upgrade to v3.1.5.",
   "details": "Ontology’s three announcements escalate in wording across the three days, from \"a potential security concern\" to \"malicious attack activity targeting the network\". All three say the activity did not involve or compromise user assets, and that ONT, ONG and other on-chain assets were unaffected. The v3.1.5 release on GitHub was published at 03:57 UTC on 2 September, which fits the stated resumption. No loss figure, no attack vector and no post-mortem have been published, so this is logged as a chain halt with an unpublished loss rather than a valued theft.",
   "blockData": [],
   "links": [
    {
     "label": "Ontology, mainnet emergency pause (31 August 2026)",
     "url": "https://ont.io/news/ontology-mainnet-emergency-pause-for-comprehensivesecurity-review/"
    },
    {
     "label": "Ontology, security update and network upgrade (1 September 2026)",
     "url": "https://ont.io/news/ontology-mainnet-pause-security-update-and-network-upgrade/"
    },
    {
     "label": "Ontology, mainnet resumed, nodes must upgrade to v3.1.5 (2 September 2026)",
     "url": "https://ont.io/news/ontology-mainnet-has-resumed-sync-nodes-required-to-upgrade-to-v3-1-5/"
    },
    {
     "label": "Ontology v3.1.5 release",
     "url": "https://github.com/ontio/ontology/releases/tag/v3.1.5"
    }
   ],
   "logo": "/media/brands/ontology.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0002/"
  },
  {
   "id": "exploit-0001",
   "title": "Injective Binary-Options Exploit and Emergency Upgrade",
   "date": "2026-08-31",
   "lossUsd": null,
   "attackVector": "Smart Contract Bug",
   "chain": "Injective",
   "sector": "Derivatives",
   "summary": "An attacker exploited Injective’s binary-options settlement and insurance-fund logic on 31 August 2026. Block production stopped for 3 hours 42 minutes while an emergency release, v1.20.3-safeharbor.1, was deployed. Injective’s official account described the incident on 1 September as an accelerated network upgrade and said the blockchain and INJ remained secure throughout. Co-founder Eric Chen said Injective users were not affected and that the team had helped with recovery.",
   "details": "The patch in commit b994d6b disables binary-options settlement on mainnet and adds a check that the insurance fund’s denomination matches the market’s quote denomination before any transfer is made, which points at a self-created market as the route in. The pause is measurable on chain: block 181,027,006 carries a timestamp of 16:10:02 UTC on 31 August and the next block, 181,027,007, carries 19:52:14 UTC, a gap of 13,332 seconds against a median block time of 0.62 seconds across the surrounding day. Injective describes that period as an accelerated upgrade rather than a halt; the two block timestamps are recorded here so a reader can weigh the wording against the chain. A second patch followed. Governance proposal 690, v1.20.3-safeharbor.2, was submitted at 16:02 UTC on 1 September, passed, and executed at block 181,295,000 at 17:43:41 UTC on 2 September, this time with block production continuing through it. Its proposal text describes targeted chain improvements and new transfer integrations, and names neither the exploit nor a security fix, which matches Injective’s practice on the December 2025 and safeharbor.1 upgrades. As of 6 September Injective has published no loss figure and no technical post-mortem, and its blog has carried three unrelated posts since, two on 2 September and one on 4 September. A third-party trace circulated on 1 September put the amount moved at roughly $4.9m, consolidated in an Ethereum address given only in truncated form; the $4.8m figure repeated since carries no separate trace behind it. Neither is confirmed by Injective and neither is counted in this log’s totals: the loss is recorded as unpublished rather than estimated.",
   "blockData": [
    {
     "label": "Last block before the pause",
     "text": "181,027,006 · 31 Aug 2026, 16:10:02 UTC",
     "url": "https://sentry.exchange.grpc-web.injective.network/api/explorer/v1/blocks/181027006"
    },
    {
     "label": "First block after the pause",
     "text": "181,027,007 · 31 Aug 2026, 19:52:14 UTC",
     "url": "https://sentry.exchange.grpc-web.injective.network/api/explorer/v1/blocks/181027007"
    }
   ],
   "links": [
    {
     "label": "Injective, official statement (1 September 2026)",
     "url": "https://x.com/injective/status/2094784707623788664"
    },
    {
     "label": "Eric Chen, Injective co-founder",
     "url": "https://x.com/ericinjective/status/2094709402980745632"
    },
    {
     "label": "injective-core commit b994d6b, the v1.20.3-safeharbor patch",
     "url": "https://github.com/InjectiveFoundation/injective-core/commit/b994d6b"
    },
    {
     "label": "Governance proposal 690, the v1.20.3-safeharbor.2 upgrade (passed 2 September 2026)",
     "url": "https://lcd.injective.network/cosmos/gov/v1/proposals/690"
    }
   ],
   "logo": "/media/brands/injective.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0001/"
  },
  {
   "id": "exploit-0006",
   "title": "Tectonic Oracle Manipulation and Cronos Halt",
   "date": "2026-08-30",
   "lossUsd": 120400000,
   "attackVector": "Oracle Manipulation",
   "chain": "Cronos",
   "sector": "Lending",
   "summary": "Cronos's post-mortem puts Tectonic's 30 August collateral-manipulation incident at approximately $120.4m in affected borrowing. A validator-coordinated rollback reversed about $111.2m; Cronos says $9.19m had left the chain before the halt and remained unrecovered. The headline figure records gross affected borrowing, before the restoration.",
   "details": "The post-mortem, checked on 8 September, says validators halted at block 90,907,150 and restored state to block 90,896,188, with production resuming from 90,896,189 at 23:49:01 UTC on 30 August. Reconciliation with bridges and exchanges continued. YFarmX's earlier independent Borrow-event reconstruction valued the gross movement at $124,472,178, using its own asset quantities and prices; that estimate remains documented in the investigation. This tracker now uses Cronos's $120.4m official estimate for consistency with its $111.2m reversal and $9.19m unrecovered figures. The earlier $6.8m traced off-chain was a partial flow estimate, superseded here by the operator's broader reconciliation.",
   "blockData": [],
   "links": [
    {
     "label": "Cronos Network incident post-mortem",
     "url": "https://x.com/CronosNetwork/status/2097131718948094299"
    },
    {
     "label": "YFarmX earlier on-chain reconstruction",
     "url": "https://yfarmx.com/cronos-halt-tectonic-drain-on-chain-trace/"
    },
    {
     "label": "Cronos Network, announcing the halt",
     "url": "https://x.com/CronosNetwork/status/2094072333434769703"
    },
    {
     "label": "Tectonic incident notice",
     "url": "https://x.com/TectonicFi/status/2094072821630799989"
    },
    {
     "label": "Kris Marszalek, Crypto.com",
     "url": "https://x.com/kris/status/2094081766109982764"
    },
    {
     "label": "CertiK Alert on the addresses holding the proceeds",
     "url": "https://x.com/CertiKAlert/status/2094203181173817656"
    },
    {
     "label": "Tectonic money market parameters",
     "url": "https://tectonic.gitbook.io/docs/protocol/money-market-parameters"
    },
    {
     "label": "Tectonic price oracle documentation",
     "url": "https://tectonic.gitbook.io/docs/developer/price-oracle"
    }
   ],
   "logo": "/media/brands/tectonic.png",
   "article": "cronos-tectonic-forensic-postmortem",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0006/"
  },
  {
   "id": "exploit-0005",
   "title": "Balancer V1 Legacy Pool Rounding Error",
   "date": "2026-08-30",
   "lossUsd": 234000,
   "attackVector": "Smart Contract Bug",
   "chain": "Ethereum",
   "sector": "AMM",
   "summary": "An attacker exploited a rounding error in an unmaintained legacy Balancer V1 pool on Ethereum on 30 August 2026. DefiLlama, filing it under the Balancer parent protocol, records the loss at $234,000 and classifies it as a token and share accounting rounding error.",
   "details": "The interest here is the age of the code rather than the size of the loss: Balancer V1 dates from 2020 and the pool was no longer maintained, so this is a reminder that a deprecated contract keeps running and keeps holding money. The precise mechanics circulating elsewhere, and a claim that Balancer Labs dissolved as a company in March 2026, could not be confirmed against a source that opened, and are not asserted here.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://api.llama.fi/hacks"
    }
   ],
   "logo": "/media/brands/balancer.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0005/"
  },
  {
   "id": "exploit-0007",
   "title": "Avici Card Contract Drain",
   "date": "2026-08-28",
   "lossUsd": 500859,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "Payments",
   "summary": "On 28 August 2026, Avici, a Solana-based neobank, said its card-issuing partner Rain had identified a vulnerability in an outdated version of a Solana card contract holding user card balances. Avici puts the amount drained at $500,859.22 across 1,685 affected users, all of whom it says will be refunded in full. The contract was upgraded across all programs, no further unauthorised activity has been observed, and a report was filed with the FBI's IC3.",
   "details": "The attackers used the contract's SubmitSignatures, AddCollateralAdmin and WithdrawCollateralAsset functions; self-custodial wallets were untouched. SlowMist's database logs the same $500,859.22. Separate on-chain tallies circulating the same day put the theft above $1m, counting 10,005.03 SOL, roughly $1.07m, plus about $11,600 in stablecoins taken from 125 sending accounts in 14,672 attempted transactions from 16:49:48 UTC. Those tallies have not been reconciled with Avici's card-contract figure, and the smaller company number is the one logged here. The AVICI token fell 49.4 per cent to an all-time low of $0.2175.",
   "blockData": [],
   "links": [
    {
     "label": "Avici statement of 28 August",
     "url": "https://x.com/avici/status/2093408878663000074"
    },
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0007/"
  },
  {
   "id": "exploit-0008",
   "title": "Moonwell MAMO Market Exploit",
   "date": "2026-08-27",
   "lossUsd": 8700000,
   "attackVector": "Oracle Manipulation",
   "chain": "Base",
   "sector": "Borrowing",
   "summary": "On 27 August 2026, between 06:09:45 and 09:46:25 UTC, an attacker inflated the price of MAMO on Moonwell's Base deployment and borrowed against the inflated collateral, taking 71.36 cbBTC, 623.60 WETH, 2,560,000 USDC and 368 wstETH, $11,028,762 in all. PeckShield and CertiK put the attacker's proceeds at about $8.7m, aggregated in DAI on Ethereum; the postmortem by Anthias Labs estimates the net gain at $6,784,655 against roughly $1.947m of capital deployed, seeded from about 799 ETH, with residual bad debt of about $9.131m.",
   "details": "No code was hacked. The attacker supplied 15,089,595 MAMO for mMAMO receipt tokens, direct-transferred 53,393,290 MAMO to the mMAMO contract without minting, inflating the exchange rate about 3.68x, then bought roughly 94.31m MAMO through thin DEX liquidity, driving MAMO from $0.010597 to a peak of $0.43127363 before borrowing. 8,729,453 USDC was burned on Base and 8,728,318 USDC received on Ethereum, then converted to DAI at an address beginning 0xD71d, which the postmortem names as the attacker's linked operational account; SlowMist's database logs the incident at $8,790,000. Moonwell cut borrow caps on all Base Core Markets to 1 wei at 10:53:43 UTC and the MAMO supply cap to 1 wei at 11:09:43, and 595 liquidation events across 594 transactions seized close to 100 per cent of the attacker's minted mMAMO. The Anthias Labs postmortem, published on the governance forum on 28 August, carries no reimbursement decision. It is Moonwell's third incident in ten months, after the November 2025 wrsETH oracle bug and a March 2026 governance attack.",
   "blockData": [],
   "links": [
    {
     "label": "Anthias Labs postmortem, Moonwell governance forum",
     "url": "https://forum.moonwell.fi/t/post-mortem-mamo-market-incident-on-base/2208"
    },
    {
     "label": "Moonwell statement of 27 August",
     "url": "https://x.com/MoonwellDeFi/status/2092935617688805818"
    },
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/2092929813959049347"
    },
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    }
   ],
   "logo": "/media/brands/moonwell.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0008/"
  },
  {
   "id": "exploit-0009",
   "title": "CometDEX Backstop Pool Drain",
   "date": "2026-08-25",
   "lossUsd": 717519,
   "attackVector": "Smart Contract Bug",
   "chain": "Stellar",
   "sector": "AMM",
   "summary": "On 25 August 2026, an accounting bug in the Comet AMM's BLND-USDC pool on Stellar, the backstop for the Blend lending protocol, allowed same-asset swaps of USDC for USDC that corrupted the pool's reserve calculations. SlowMist logs the drain at $717,518.92. Blend's operators paused the backstop; Blend said its own contracts were not at fault and lending-pool deposits were not at risk, but backstop depositors holding Comet BLND-USDC LP shares took the loss.",
   "details": "The fallout spread well beyond the pool: Stellar DeFi TVL fell from a peak of about $270m on 22 August to roughly $98m by 27 August, with Blend's own TVL going from over $150m to near zero. Blend was already in this log for a $10.86m oracle-manipulation loss in February 2026.",
   "blockData": [],
   "links": [
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    },
    {
     "label": "Blend on X",
     "url": "https://x.com/blend_capital"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0009/"
  },
  {
   "id": "exploit-0010",
   "title": "Term Finance Vault Governance Takeover",
   "date": "2026-08-23",
   "lossUsd": 8500000,
   "attackVector": "Governance Attack",
   "chain": "Ethereum",
   "sector": "Lending",
   "summary": "On 23 August 2026, an attacker took governance control of Term Finance's Strategy and Meta Vaults, built on Yearn v3, and drained about 2,843 ETH plus 1.68m USDC, roughly $8.5m in all, swapping the stablecoins to DAI. The takeover cost about $951: the attacker bought 0.4852 tmvETH for roughly 0.5 ETH and staked it, and because the pre-drain staked supply was just 0.5352 gtmvETH, that stake carried about 90.66 per cent of all votes, per GoPlus Security's breakdown.",
   "details": "PeckShield reported the loss figures and traced the exploiter's original funding to 2 ETH via Tornado Cash; PeckShield and CertiK tracked the proceeds to a wallet beginning 0xD5183. SlowMist's database logs the method as passing malicious proposals to disable the timelock. Term Labs acknowledged the exploit, then irreversibly shut down all Term Meta Vaults and revoked the DAO's governance roles: deposits are permanently blocked while withdrawals stay open. Yearn clarified the flaw sat in Term's governance wrapper rather than in standard Yearn vaults, and the core repo lending architecture was not affected. As of 29 August there is no technical postmortem and no reimbursement plan.",
   "blockData": [],
   "links": [
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/2091452165932175659"
    },
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    }
   ],
   "logo": "/media/brands/termfinance.png",
   "article": "term-finance-vault-governance-takeover",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0010/"
  },
  {
   "id": "exploit-0011",
   "title": "TAC Cosmos EVM Balance Underflow Drain",
   "date": "2026-08-22",
   "lossUsd": 7500000,
   "attackVector": "Other",
   "chain": "TAC",
   "sector": "Layer 1",
   "summary": "On 22 August 2026, TAC, a Cosmos-based EVM chain bridging the TON ecosystem, was drained of about $7.5m from a custodial account through a flaw in the shared Cosmos EVM module, and validators halted the chain at block 24,671,475. The same day KiiChain lost 148,326,583.15 KII to 18 repeats of the technique and halted at block 9,355,723, and MANTRA halted for roughly 30 hours before restarting.",
   "details": "The public advisory landed on 28 August as GHSA-7g4w-cg88-2cq2, rated critical: the EVM StateDB tracks only spendable balances and ignores locked vesting balances, so a vesting account delegating more than its spendable balance triggers an unchecked underflow that wraps the balance to about 2^256. The fix shipped in Cosmos EVM v0.6.2 and v0.7.2; no CVE has been assigned, and credit went to @AshmitSh4rma via the bug bounty alongside independent researchers. Cosmos Labs confirmed an active incident on 24 August and urged every chain on Cosmos EVM below the patched versions to halt validators; by 26 August it said many chains had patched, with a full incident report promised. BounceBit's 19 August exploit, logged separately here, came from the same Evmos and Cosmos EVM family. SlowMist logs TAC's loss at $7,500,000; reports of how many TAC tokens moved conflict, so no token figure is carried here.",
   "blockData": [],
   "links": [
    {
     "label": "Cosmos EVM security advisory GHSA-7g4w-cg88-2cq2",
     "url": "https://github.com/cosmos/evm/security/advisories/GHSA-7g4w-cg88-2cq2"
    },
    {
     "label": "Cosmos Labs statement of 24 August",
     "url": "https://x.com/cosmoslabs_io/status/2091935066381582390"
    },
    {
     "label": "KiiChain incident article",
     "url": "https://x.com/KiiChainio/article/2091721027583709214"
    },
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    }
   ],
   "article": "cosmos-evm-underflow-six-chains",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0011/"
  },
  {
   "id": "exploit-0012",
   "title": "The Sandbox OFT Bridge Mint",
   "date": "2026-08-21",
   "lossUsd": 1496784,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Gaming",
   "summary": "From 23:41 UTC on 21 August 2026, an attacker used a call-on-behalf convenience feature in SAND's omnichain token contract on Base to register itself as bridge administrator, reconfigured the LayerZero verification settings so it alone could authorise mints, and minted unbacked SAND on Base and BNB Smart Chain. The sums extracted were far smaller than the mint: 14,742,341.84 SAND, about $697,000, was withdrawn from the Ethereum vault, and a further 93,415,334.86 SAND was sold on Base for 327.59 WETH, for a total attacker capture of about $987,000. The Sandbox's own post-mortem puts the total economic impact at about $1,496,784, and that is the figure logged here.",
   "details": "PeckShield counted 14.9bn unbacked SAND across two addresses; Blockaid put the face value near $49bn across more than 400 transactions while the attack was still running, and later stressed the flaw was in The Sandbox's SAND OFT contract, not LayerZero, whose contracts behaved as designed. The Sandbox's same-morning statement said the impact was under 0.01 per cent of total SAND supply, that SAND on Ethereum and Polygon was unaffected, and that no user wallets were compromised. Its 27 August post-mortem closed the record: bridging was shut at contract level on all three chains at 05:26 UTC on 22 August, no SAND left the vault after 02:21 UTC, about 647,880 SAND of the vault redemption was front-run by an unrelated arbitrage bot (which is why the impact figure exceeds the attacker's capture), and holders on Base and BNB Smart Chain are compensated 1:1 in Ethereum SAND from treasury, snapshots at Base block 50,283,176 and BSC block 117,321,965, with claims opening within two weeks.",
   "blockData": [],
   "links": [
    {
     "label": "The Sandbox post-mortem of 27 August",
     "url": "https://x.com/TheSandboxGame/status/2092905959723045174"
    },
    {
     "label": "The Sandbox statement of 22 August",
     "url": "https://x.com/TheSandboxGame/status/2091063415649251821"
    },
    {
     "label": "Blockaid alert",
     "url": "https://x.com/blockaid_/status/2091016046555582891"
    },
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/2091037704314339331"
    }
   ],
   "logo": "/media/brands/thesandbox.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0012/"
  },
  {
   "id": "exploit-0013",
   "title": "BounceBit Authorisation Exploit and L1 Shutdown",
   "date": "2026-08-19",
   "lossUsd": 3000000,
   "attackVector": "Access Control",
   "chain": "BounceBit",
   "sector": "Restaking",
   "summary": "Between 21:02 UTC on 19 August and 01:54 UTC on 20 August 2026, an attacker moved 286,543,148 BB in 14 transactions from nine BounceBit mainnet accounts over four hours and 52 minutes; block production was halted at height 20,702,857 at 02:36:37 UTC, 42 minutes after the final unauthorised transfer. BounceBit's own account states no dollar figure; at market prices the sum was near $3m, and that conversion is the figure logged here. The flaw sat in the Evmos stack the BTC-restaking chain was built on: a caller could name an arbitrary account as the funding source, with no check that the account had authorised it.",
   "details": "On 21 August BounceBit announced it will permanently shut down the L1 and reissue BB as a BEP-20 token on BNB Chain from a snapshot at block 20,697,260, taken at 21:02:35 UTC on 19 August, immediately before the first unauthorised transaction. The 286.5m exploited BB are excluded from the new supply, and legitimate holders, including staked and unbonding positions, receive tokens automatically at matching addresses with no claims process. Evmos was discontinued in May 2026, which BounceBit cites as the reason a patch was not viable; the same Cosmos EVM family produced the TAC and KiiChain drains of 22 August, logged separately here. The public record rests on BounceBit's own account: no investigator firm has published its own analysis.",
   "blockData": [],
   "links": [
    {
     "label": "BounceBit announcement of 21 August",
     "url": "https://x.com/bouncebit/status/2090785561800061430"
    }
   ],
   "logo": "/media/brands/bouncebit.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0013/"
  },
  {
   "id": "exploit-0014",
   "title": "Coldcard Mk3 Seed Entropy Sweep",
   "date": "2026-07-30",
   "lossUsd": 116000000,
   "attackVector": "Private Key Compromise",
   "chain": "Bitcoin",
   "sector": "Wallet",
   "summary": "On 30 July 2026, bitcoin began draining out of Coldcard-generated addresses in waves, the first taking about 594 BTC from roughly 500 wallets in 25 minutes. TRM Labs' 5 August analysis puts the running total at about 1,816 BTC, roughly $116m, from more than 5,200 addresses across at least four waves, making it the largest hardware-wallet exploit of 2026 by TRM's accounting. Coinkite had disclosed the same day the draining began that a build flag set to zero in March 2021 replaced the hardware random number generator with a software fallback, cutting Mk3 seeds to roughly 40 bits of real randomness against a 128-bit target. No device was touched: the seeds were guessable.",
   "details": "A preprocessor guard tested whether MICROPY_HW_ENABLE_RNG was defined rather than whether it was set, so a value of zero satisfied it and the #error never fired. Coinkite puts the effective search space at about 40 bits on Mk3 and about 72 bits on Mk4, Mk5 and Q; 2^40 is roughly 1.1 trillion candidates, a search a computer can finish. Updating the firmware does not repair a seed that already exists. The attacker's signature is an identical hardcoded fee of about 30 sat/vB on every sweep, against a 0.4 to 1.0 median that week, though TRM notes transaction construction differs between waves, so there may be more than one attacker. Laundering has started at the margins: 64.9 BTC went into Wasabi and 200 ETH into Tornado Cash on 4 August, with the bulk still sitting in attacker addresses in public view. Coinkite destroyed its remaining vulnerable stock and halted shipments on 2 August, opened a permanent disclosure record on 4 August, and notes that AI-assisted review failed to catch the bug. It has not confirmed the theft was caused by its flaw. Figures are TRM's on-chain estimates and still moving.",
   "blockData": [
    {
     "label": "Consolidating address (501 inputs)",
     "url": "https://mempool.space/address/bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0"
    },
    {
     "label": "The 341-input onward transaction",
     "url": "https://mempool.space/tx/0c6bf853a645b699a3b2cd6d8e3c44cf1a02a16f538df08212a44753f75d9d01"
    },
    {
     "label": "Address holding 562 BTC, unspent",
     "url": "https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r"
    }
   ],
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/coldcard-mk3-entropy-40-bits/"
    },
    {
     "label": "TRM Labs, inside the $116m Coldcard hack",
     "url": "https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack"
    },
    {
     "label": "Coinkite, Mk3 Security Advisory",
     "url": "https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/"
    },
    {
     "label": "Coinkite, Technical Deep Dive into the Entropy Issue",
     "url": "https://blog.coinkite.com/entropy-technical-backgrounder/"
    },
    {
     "label": "Coinkite, update of 2 August",
     "url": "https://blog.coinkite.com/update-sunday/"
    },
    {
     "label": "Coinkite, adding to the public record",
     "url": "https://blog.coinkite.com/adding-to-public-record/"
    }
   ],
   "logo": "/media/brands/coldcard.png",
   "article": "coldcard-mk3-entropy-40-bits",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0014/"
  },
  {
   "id": "exploit-0015",
   "title": "Crypto DAO Vault Drain",
   "date": "2026-07-28",
   "lossUsd": 52000,
   "attackVector": "Access Control",
   "chain": "BNB Chain",
   "sector": "DeFi",
   "summary": "On 28 July 2026, an attacker exploited missing access control on the vault behind Crypto DAO's Pro token, calling a state-changing exec() function that had been left publicly callable in a single flash-loan-assisted transaction. Per GoPlus Security's analysis, carried in SlowMist's database, the attacker's actual profit was about $52,000, with the contract losing around 167,200 Pro tokens.",
   "details": "The flaw is the elementary access-control class: a vault function anyone could call, with no permission check between the caller and the funds. An $8.2m figure circulated at the time and was carried here initially; SlowMist's own entry now states that sum was USDT held by related addresses Blockaid was monitoring, not the amount stolen, and this record was corrected on 22 August 2026 to GoPlus Security's ~$52,000 figure. SlowMist's database lists the incident against Ethereum, consistent with stolen funds moving there; contemporary reporting places the exploited contract on BNB Chain, and that is the attribution used here.",
   "blockData": [],
   "links": [
    {
     "label": "SlowMist Hacked database",
     "url": "https://hacked.slowmist.io/"
    },
    {
     "label": "Blockaid",
     "url": "https://x.com/blockaid_"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0015/"
  },
  {
   "id": "exploit-0016",
   "title": "WEMIX$ Stablecoin Contract Takeover",
   "date": "2026-07-26",
   "lossUsd": 731000,
   "attackVector": "Access Control",
   "chain": "WEMIX3.0",
   "sector": "Stablecoin",
   "summary": "On 26 July 2026 an attacker compromised ownership of a contract behind WEMIX$, the dollar stablecoin of the WEMIX gaming chain, and issued 5,225,525 tokens without authorisation. WEMIX says those were converted into 30,736 WEMIX and 724,198.27 USDC.e, which was bridged to Ethereum and BNB Smart Chain, swapped into ETH and USDT and spread across wallets, with some deposited at centralised exchanges.",
   "details": "The nominal mint was about $5.2m at par, but the tokens were sold into WEMIX's own liquidity pools, so the assets that actually left came to roughly $731,000. WEMIX suspended all bridges to and from WEMIX3.0 along with Chainlink CCIP and the PLAY Bridge, halted trading in five pools, withdrew foundation liquidity, paused the WEMIX$ module and PNIX DEX, and disabled NFT trading and some in-game blockchain features. WEMIX$ lost its peg, falling about 99 per cent to roughly $0.0109. The first public notice came 5 hours 33 minutes after the attack, against three days for the company's February 2025 Play Bridge incident. All figures are WEMIX's preliminary account.",
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/wemix-stablecoin-contract-takeover-mint/"
    },
    {
     "label": "WEMIX response measures",
     "url": "https://wemix.com/news/update-on-the-wemix-security-issue-and-response-measures-06359e6f2a8e"
    },
    {
     "label": "WEMIX first notice",
     "url": "https://wemix.com/news/regarding-the-wemix-security-issue-and-ongoing-investigation-1001f385826a"
    }
   ],
   "logo": "/media/brands/wemix.png",
   "article": "wemix-stablecoin-contract-takeover-mint",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0016/"
  },
  {
   "id": "exploit-0017",
   "title": "Triple-A Hot Wallet Drain",
   "date": "2026-07-25",
   "lossUsd": 9725837,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Payments",
   "summary": "On 25 July 2026, wallets belonging to Triple-A, a licensed digital payments company, were drained of more than $9.7M across TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated about 5,227 ETH into a single address. The analyst who flagged it reported that deposits had not been disabled, so each new deposit was being taken as it arrived.",
   "details": "Triple-A holds a Major Payment Institution licence from the Monetary Authority of Singapore, an ACPR payment institution licence and French CASP registration, FinCEN and NMLS registration in the United States, and FINTRAC registration in Canada, and had secured in-principle approval from Dubai VARA ten days earlier. The vector is unconfirmed and logged as Other for that reason: losing balances on four networks at once, in assets that had to be swapped before they could be moved, points at compromised hot wallet signing keys rather than a contract flaw. Triple-A published no incident notice, so the loss is an on-chain estimate rather than a reconciled figure.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/triple-a-hot-wallet-drain-licensed-payments/"
    },
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/2080833993633866106"
    },
    {
     "label": "Triple-A regulatory status",
     "url": "https://support.triple-a.io/knowledge/is-triplea-a-regulated-financial-institution"
    }
   ],
   "logo": "/media/brands/triplea.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0017/"
  },
  {
   "id": "exploit-0020",
   "title": "B² Network Staking Exploit",
   "date": "2026-07-23",
   "lossUsd": 3860000,
   "attackVector": "Access Control",
   "chain": "Bitcoin L2",
   "sector": "Staking",
   "summary": "On 23 July 2026, B² Network, a Bitcoin layer-2, lost about $3.86M after an attacker seized the upgrade authority on its staking contract. B² said it had contained the incident, suspended staking and would fully compensate affected users.",
   "details": "The third protocol drained on the same day, after the attacker gained control of the staking contract's upgrade authority.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/crypto-bridge-attacks-36m-keys-not-cryptography/"
    },
    {
     "label": "B² Network statement",
     "url": "https://x.com/BSquaredNetwork"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0020/"
  },
  {
   "id": "exploit-0019",
   "title": "Verus Ethereum Bridge Exploit (second)",
   "date": "2026-07-23",
   "lossUsd": 7540000,
   "attackVector": "Bridge",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "On 23 July 2026, the Verus Ethereum bridge was drained of about $7.54M through the same contract flaw as its May 2026 hack. An attacker forged the cross-chain proof the bridge failed to verify and triggered unbacked payouts, taking ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.",
   "details": "Funds had been redeposited on 8 July and were drained again two weeks later. The stolen funds were converted into roughly 3,916 ETH and moved through Tornado Cash. Verus held close to $100M in total value locked at the start of 2025 and is down to single-digit millions.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/crypto-bridge-attacks-36m-keys-not-cryptography/"
    },
    {
     "label": "DefiLlama (Verus TVL)",
     "url": "https://defillama.com/protocol/verus"
    }
   ],
   "logo": "/media/brands/verus.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0019/"
  },
  {
   "id": "exploit-0018",
   "title": "AFX Trade Bridge Exploit",
   "date": "2026-07-23",
   "lossUsd": 24150000,
   "attackVector": "Access Control",
   "chain": "Arbitrum",
   "sector": "Derivatives",
   "summary": "On 23 July 2026, AFX Trade, a decentralised perpetuals exchange settling in USDC, lost about $24.15M after attackers compromised the validator signing keys behind a bridge it runs on Arbitrum and authorised withdrawals. The team suspended bridge operations.",
   "details": "Arbitrum confirmed its own native bridge was not involved; the failure was in AFX's own bridge and its key handling. The stolen USDC was moved to Ethereum. It was the largest of three protocol losses logged on the same day.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX report",
     "url": "https://yfarmx.com/crypto-bridge-attacks-36m-keys-not-cryptography/"
    },
    {
     "label": "Arbitrum statement",
     "url": "https://arbitrum.io"
    },
    {
     "label": "BlockAid detection",
     "url": "https://www.blockaid.io"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0018/"
  },
  {
   "id": "exploit-0021",
   "title": "Cascade",
   "date": "2026-07-16",
   "lossUsd": 1340000,
   "attackVector": "Smart Contract Bug",
   "chain": "Arbitrum",
   "sector": "Perps",
   "summary": "Polychain-backed Arbitrum trading platform Cascade reported on 16 July 2026 that its CLS vault was exploited, with 1.34 million USDC of locked user funds drained.",
   "details": "The incident came barely a day after the Ostium oracle exploit on the same network, extending a run of attacks on Arbitrum-based perpetuals platforms. Cascade confirmed the drain affected user funds in the CLS vault; a full root-cause disclosure had not been published as of 17 July 2026.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0021/"
  },
  {
   "id": "exploit-0022",
   "title": "Ostium",
   "date": "2026-07-15",
   "lossUsd": 23752746,
   "attackVector": "Oracle Manipulation",
   "chain": "Arbitrum",
   "sector": "Perps",
   "summary": "Arbitrum perpetuals DEX Ostium suspended trading on 15 July 2026 after an attacker compromised the off-chain infrastructure that signs its price feeds and submitted fabricated Bitcoin quotes, taking 23,752,746 USDC out of the public OLP vault in five and a half minutes.",
   "details": "Between 14:18:23 and 14:23:52 UTC, eight transactions moved 23,753,539 USDC from the Ostium Vault (0x20D419a8) to one wallet, 72.6% of the $32.71m the vault then held. Twenty-four price reports went in through the PrivatePriceUpKeep contract, every one naming BTC/USD at exactly $5,000 or exactly $60,000 while Bitcoin traded near $65,250, and every one timestamped to the block that carried it, so the signing capability was live rather than replayed. Twelve open-and-close rounds each returned 8.987x the stake, Ostium's automatic 900% take-profit ceiling, so the attacker escalated the stake from 100 USDC to 700,000. Trader collateral in the separate storage contract was untouched. Ostium froze trading within 60 minutes, engaged Mandiant, zeroShadow, Collisionless and SEAL 911, and reopened in stages on 23 July; the funds were swapped to about 12,080 ETH with roughly 10,540 ETH sent to Tornado Cash. Deposits remain frozen and the vault's own loss counter still carried $19.2m on 30 July.",
   "blockData": [],
   "links": [
    {
     "title": "Ostium incident update (19 July 2026)",
     "url": "https://x.com/Ostium/status/2078640436688941194"
    },
    {
     "title": "Exploit transaction on Arbiscan",
     "url": "https://arbiscan.io/tx/0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0"
    },
    {
     "title": "YFarmX: the vault is still $19m short",
     "url": "/ostium-olp-vault-still-19m-short/"
    }
   ],
   "logo": "/media/brands/ostium.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0022/"
  },
  {
   "id": "exploit-0023",
   "title": "Bonzo Lend",
   "date": "2026-07-11",
   "lossUsd": 9000000,
   "attackVector": "Oracle Manipulation",
   "chain": "Hedera",
   "sector": "Lending",
   "summary": "Hedera's largest DeFi lender, Bonzo Lend, was exploited for about $9 million at 00:51 UTC on 11 July 2026 after a third-party oracle accepted a forged SAUCE token price.",
   "details": "The attacker submitted a SAUCE price inflated by twelve orders of magnitude, which the Supra oracle accepted after a signature verification bypass (a zeroed signature), then used 250 SAUCE worth about $1 as collateral to borrow $9.05 million from the protocol. Around $5.25 million was bridged to Ethereum, a white hat returned roughly $1 million, Bonzo paused the protocol and Supra acknowledged the flaw and deployed a fix; PeckShield tracked the bridged funds.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/bonzo.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0023/"
  },
  {
   "id": "exploit-0025",
   "title": "BonkDAO",
   "date": "2026-07-06",
   "lossUsd": 20000000,
   "attackVector": "Governance Attack",
   "chain": "Solana",
   "sector": "DeFi",
   "summary": "On 6 July 2026 an attacker drained roughly $20 million in BONK tokens from BonkDAO's treasury by passing a malicious governance proposal; BONK fell around 8–10%.",
   "details": "The attacker accumulated an estimated $4 million of BONK to dominate token-weighted voting on Solana's Realms platform, then pushed through 'BIP #76', submitted on 30 June and dressed as a governance renewal plan, whose operative clause transferred 4.43 trillion BONK to an attacker-controlled wallet; only 7 of more than 18,000 eligible wallets voted, and the attacker cast 99.878% of votes. The DAO coordinated with the Solana Foundation, law enforcement and exchanges, with Upbit, Bithumb and Kraken suspending BONK deposits and withdrawals; no recovery had been confirmed by mid-July.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0025/"
  },
  {
   "id": "exploit-0024",
   "title": "Summer.fi",
   "date": "2026-07-06",
   "lossUsd": 6000000,
   "attackVector": "Flash Loan",
   "chain": "Ethereum",
   "sector": "Yield",
   "summary": "On 6 July 2026 Summer.fi's Lazy Summer vaults were exploited for about $6 million in DAI via a flash-loan-assisted price manipulation, prompting the protocol to pause all vaults.",
   "details": "PeckShield confirmed roughly $6 million was extracted after the attacker used a $65.4 million flash loan to manipulate vault share pricing (described by trackers as a donation-style attack), with the largest single victim losing about 8.6 million USDC. Summer.fi paused all Lazy Summer vaults and zeroed deposit caps; researchers linked the exploited pricing weakness to stale tokens left over from the Stream Finance collapse the previous November.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/summerfi.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0024/"
  },
  {
   "id": "exploit-0026",
   "title": "Polymarket",
   "date": "2026-06-25",
   "lossUsd": 3000000,
   "attackVector": "Supply Chain",
   "chain": "Polygon",
   "sector": "DeFi",
   "summary": "In late June 2026 Polymarket users lost about $3 million after a compromised third-party vendor was used to inject malicious JavaScript into the prediction market's front end.",
   "details": "The injected script ran silently in users' browsers on the legitimate site and prompted routine-looking wallet signatures that authorised unintended transfers; 11 user wallets were affected. Stolen funds were bridged from Polygon to Ethereum, swapped to roughly 1,893 ETH and consolidated into a single wallet. Polymarket's smart contracts were not exploited, and the company promised full refunds to victims holding its PUSD collateral.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-polymarket-hack-june-2026"
    }
   ],
   "logo": "/media/brands/polymarket.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0026/"
  },
  {
   "id": "exploit-0027",
   "title": "SecondFi",
   "date": "2026-06-23",
   "lossUsd": 2400000,
   "attackVector": "Private Key Compromise",
   "chain": "Cardano",
   "sector": "Wallet",
   "summary": "Cardano wallet project SecondFi confirmed three attacks between 21 and 23 June 2026 that drained 16 million ADA (about $2.4 million) from 374 wallets, with SlowMist estimating up to $20 million potentially at risk.",
   "details": "The flaw was a deterministic nonce derivation bug in SecondFi's proprietary software signer: every signed transaction leaked cryptographic information that allowed attackers to reconstruct users' private keys from public blockchain data alone. The team rescued a further 129 million ADA to a third-party custodian before attackers could reach it and, with EMURGO, launched a two-week recovery and restitution plan with a checking tool for affected wallets.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0027/"
  },
  {
   "id": "exploit-0028",
   "title": "Taiko Bridge",
   "date": "2026-06-21",
   "lossUsd": 1700000,
   "attackVector": "Bridge Exploit",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "Ethereum layer-2 Taiko halted block production in late June 2026 after an attacker used forged cross-chain proofs to withdraw about $1.7 million from its bridge without matching deposits.",
   "details": "The root cause was an SGX signing key left exposed on GitHub: Taiko's permissionless prover registration allowed a rogue SGX instance to register and submit invalid proofs that the system accepted, letting fake withdrawal requests clear on Ethereum. The team froze activity within hours and urged users to withdraw; the attacker had already moved about 2 million TAIKO (roughly $170,000) to MEXC before the freeze, and the TAIKO token fell around 10%.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-taiko-bridge-hack-june-2026"
    },
    {
     "label": "thirdweb analysis",
     "url": "https://blog.thirdweb.com/taiko-bridge-exploit-explained-how-a-leaked-key-led-to-1-7m-in-forged-withdrawals/"
    }
   ],
   "logo": "/media/brands/taiko.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0028/"
  },
  {
   "id": "exploit-0029",
   "title": "JaredFromSubway MEV Bot",
   "date": "2026-06-20",
   "lossUsd": 7500000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "Infrastructure",
   "summary": "On 20 June 2026 the notorious jaredfromsubway.eth MEV bot was drained of roughly $7.5 million in WETH, USDC and USDT by a counter-MEV honeypot (some outlets put the figure as high as $15 million).",
   "details": "The attacker deployed 66 fake token contracts and rigged liquidity pools that looked like profitable trades; when the bot took the bait it granted token approvals to attacker-controlled contracts, and those dangling approvals were later used to sweep the bot's holdings in a single coordinated transaction. Blockaid had flagged the attacker's wallets and contracts as malicious before the final drain, and Chainalysis documented the incident as the most prominent case of a predator bot being drained by its own logic.",
   "blockData": [],
   "links": [
    {
     "label": "Chainalysis",
     "url": "https://www.chainalysis.com/blog/sandwich-attack-jaredfromsubway-hack/"
    },
    {
     "label": "Blockaid",
     "url": "https://www.blockaid.io/blog/the-predator-becomes-the-prey-how-a-counter-mev-honeypot-drained-75m-from-jaredfromsubway"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0029/"
  },
  {
   "id": "exploit-0030",
   "title": "Aztec Private Rollup Bridge",
   "date": "2026-06-17",
   "lossUsd": 2160000,
   "attackVector": "Smart Contract Bug",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "Three days after the Aztec Connect exploit, an attacker drained about $2.16 million (roughly 1,158 ETH) from Aztec's deprecated Private Rollup Bridge on 17 June 2026 via its escape-hatch mechanism.",
   "details": "The attacker constructed a fake zero-knowledge claim proof accepted by the RollupProcessor's verification logic: the proof system did not correctly bind a victim's final output note to its rightful recipient, letting a malicious escape-hatch caller substitute arbitrary outputs. Aztec confirmed the exploit targeted a deprecated product unrelated to the current network.",
   "blockData": [],
   "links": [
    {
     "label": "DARKNAVY analysis",
     "url": "https://www.darknavy.org/web3/exploits/aztec-private-rollup-bridge-escape-hatch-claim-proof-drain/"
    }
   ],
   "logo": "/media/brands/aztec.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0030/"
  },
  {
   "id": "exploit-0031",
   "title": "Aztec Connect",
   "date": "2026-06-14",
   "lossUsd": 2100000,
   "attackVector": "Smart Contract Bug",
   "chain": "Ethereum",
   "sector": "Infrastructure",
   "summary": "On 14 June 2026 an attacker drained about $2.1 million from Aztec Connect, the deprecated privacy rollup product, using a crafted zero-knowledge proof that the verification logic wrongly accepted.",
   "details": "This was the first of two Aztec legacy-contract exploits in three days, together costing over $4 million. Aztec attributed the issues to proof-verification bugs in deprecated contracts; the Aztec Foundation stressed the affected products have no link to the current Aztec network or the AZTEC token.",
   "blockData": [],
   "links": [
    {
     "label": "Rekt News",
     "url": "https://rekt.news/aztec-connect-rekt"
    },
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-aztec-connect-hack-june-2026"
    }
   ],
   "logo": "/media/brands/aztec.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0031/"
  },
  {
   "id": "exploit-0033",
   "title": "Secret Network",
   "date": "2026-06-10",
   "lossUsd": 4670000,
   "attackVector": "Bridge Exploit",
   "chain": "Secret Network",
   "sector": "Bridge",
   "summary": "Starting 10 June 2026, an attacker exploited an infinite-mint bug in Secret Network's Axelar bridge contract, draining about $4.67 million in Axelar-wrapped assets; the theft went unnoticed for seven days.",
   "details": "The deployed contract was a modified CW20-ICS20 fork with core security checks removed, so it did not verify the source channel of inbound IBC packets; the attacker spun up a single-validator Cosmos chain, self-relayed forged packets to mint unbacked saTokens, then redeemed them over the legitimate Axelar channel to drain real escrowed assets including saUSDT, saUSDC, saDAI, saWETH and saWBTC. The hole was discovered on 17 June when a failed transaction produced an insufficient-funds error, prompting investigation of the bridge's reserves.",
   "blockData": [],
   "links": [
    {
     "label": "Common Prefix analysis",
     "url": "https://www.commonprefix.com/blog/secret-network-exploit"
    }
   ],
   "logo": "/media/brands/secretnetwork.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0033/"
  },
  {
   "id": "exploit-0032",
   "title": "Raydium",
   "date": "2026-06-10",
   "lossUsd": 1340000,
   "attackVector": "Smart Contract Bug",
   "chain": "Solana",
   "sector": "DEX",
   "summary": "On 10 June 2026 an attacker drained about $1.34 million from five deprecated Raydium legacy AMM V3 pools on Solana using forged LP tokens.",
   "details": "The legacy AMM V3 program, phased out in 2021 but never immobilised, did not validate the LP mint address, so a fake LP mint let the attacker withdraw real pool assets: roughly 893,700 USDC, 5,603 SOL and 150,177 RAY. The funds were bridged to Ethereum and routed through KuCoin and FixedFloat into Tornado Cash; Raydium said no current users were affected and pledged full repayment from its treasury.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/raydium.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0032/"
  },
  {
   "id": "exploit-0034",
   "title": "Humanity Protocol",
   "date": "2026-06-09",
   "lossUsd": 31000000,
   "attackVector": "Private Key Compromise",
   "chain": "Ethereum",
   "sector": "Infrastructure",
   "summary": "Identity network Humanity Protocol lost at least $31 million (estimates ranged to $36 million) on 8–9 June 2026 after seven private keys stored on a malware-infected developer machine were compromised; the H token crashed more than 80%.",
   "details": "The infected device held the admin hot wallet key plus three Ethereum Safe owner keys and three BNB Chain Safe owner keys backed up during the 2025 mainnet launch. Using three of six ETH Safe keys, the attacker transferred Bridge ProxyAdmin ownership, upgraded the bridge to a malicious implementation, swept about 141.2 million H in one transaction and minted a further 200 million H via malicious upgrades. PeckShield ranked it June's largest incident, and HTX Insights reported that around 15,403 ETH of proceeds later commingled on Bitcoin with funds from the Kelp DAO exploit, suggesting a possible link between the actors.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-humanity-protocol-hack-june-2026"
    }
   ],
   "logo": "/media/brands/humanityprotocol.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0034/"
  },
  {
   "id": "exploit-0035",
   "title": "Syscoin Bridge",
   "date": "2026-06-07",
   "lossUsd": 10000000,
   "attackVector": "Bridge Exploit",
   "chain": "Syscoin",
   "sector": "Bridge",
   "summary": "In early June 2026 an attacker exploited a proof-parsing flaw in the Syscoin bridge relay to mint roughly 5 billion unauthorised SYS tokens, an incident valued at about $10 million; SYS fell around 20%.",
   "details": "The bridge relay's proof-validation code misparsed a deliberately malformed proof, treating it as valid evidence of a burn on the NEVM side that never happened, which authorised minting on the UTXO side. Syscoin halted the bridge, coordinated freezes with exchanges and partners, and later said it had recovered and burnt all 5 billion minted SYS, restoring the pre-exploit supply, though the bridge remained offline.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-syscoin-bridge-hack-june-2026"
    }
   ],
   "logo": "/media/brands/syscoin.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0035/"
  },
  {
   "id": "exploit-0036",
   "title": "Gravity Bridge",
   "date": "2026-05-30",
   "lossUsd": 5400000,
   "attackVector": "Private Key Compromise",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "The Ethereum–Cosmos Gravity Bridge was drained of about $5.4 million on 30 May 2026 in what researchers assessed as a compromised signing key rather than a code flaw.",
   "details": "With enough valid validator signing keys, forged withdrawals are treated as legitimate; the attacker took about $4.3 million in USDC, 274 WETH, $434,000 in USDT and 14.16 PAXG, laundering a portion through ChangeNow and Binance while retaining roughly 2,100 ETH. Researchers cited the incident as part of 2026's pattern of bridge losses driven by key compromises rather than smart contract bugs.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0036/"
  },
  {
   "id": "exploit-0037",
   "title": "DxSale",
   "date": "2026-05-28",
   "lossUsd": 7300000,
   "attackVector": "Access Control",
   "chain": "BNB Chain",
   "sector": "DeFi",
   "summary": "Launchpad and locker platform DxSale lost about $7.3 million in late May 2026 when more than 1,400 legacy BNB Chain liquidity lockers were unlocked and drained in a single coordinated flow.",
   "details": "On 26 May the locker contract's owner called transferOwnership, passing control to the attacker after admin rights had reportedly moved through roughly 80 obscuring wallet transfers; auditor Coinsult traced the drain to a privileged setFee function (reset to 1 wei) combined with backdated lock configurations that made locked deposits withdrawable, executed via EIP-7702 batch delegation. Community researchers raised the possibility of insider involvement or a leaked owner key; roughly 1,400 liquidity providers were affected.",
   "blockData": [],
   "links": [
    {
     "label": "Rekt News",
     "url": "https://rekt.news/dxsale-rekt"
    }
   ],
   "logo": "/media/brands/dxsale.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0037/"
  },
  {
   "id": "exploit-0038",
   "title": "Ill Bloom Wallet Vulnerability",
   "date": "2026-05-27",
   "lossUsd": 5200000,
   "attackVector": "Private Key Compromise",
   "chain": "Multichain",
   "sector": "Wallet",
   "summary": "A coordinated sweep on 27 May 2026 drained about $3.1 million from 431 wallets whose seed phrases were generated with a weak random-number generator, the 'Ill Bloom' flaw. A further $2.1 million in USDT was stolen later, pushing confirmed losses past $5 million.",
   "details": "Certain older or lesser-known software wallets used an insecure pseudorandom number generator during seed phrase creation, shrinking the keyspace enough for attackers to brute-force recovery phrases and derive private keys. Security firm Coinspect, which disclosed the flaw publicly in early July, traced 2,114 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon, with first-funding dates from 2018 to May 2026; hardware wallets and mainstream software wallets were not affected.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/bloomwallet.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0038/"
  },
  {
   "id": "exploit-0039",
   "title": "New Market Trading",
   "date": "2026-05-25",
   "lossUsd": 3980000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "DeFi",
   "summary": "New Market Trading was exploited for about $3.98 million across Ethereum, Base and Arbitrum on 25 May 2026, according to DefiLlama's hacks database.",
   "details": "DefiLlama classifies the incident as an access-control exploit in the protocol's contracts. Detailed independent reporting on the incident is limited.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0039/"
  },
  {
   "id": "exploit-0040",
   "title": "StablR",
   "date": "2026-05-23",
   "lossUsd": 2800000,
   "attackVector": "Private Key Compromise",
   "chain": "Ethereum",
   "sector": "Stablecoin",
   "summary": "Stablecoin issuer StablR suffered a private key compromise on 23 May 2026, with an attacker minting 8.35 million USDR and 4.5 million EURR and extracting about $2.8 million.",
   "details": "The unauthorised minting depegged both tokens, with EURR falling to about $0.85 and USDR to about $0.40 before the situation was contained. Global Ledger classified the incident as a compromised-key attack on the issuer's minting controls rather than a smart contract flaw.",
   "blockData": [],
   "links": [
    {
     "label": "Global Ledger",
     "url": "https://blog.globalledger.io/research-investigations/crypto-hacks-may-2026"
    },
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    }
   ],
   "logo": "/media/brands/stablr.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0040/"
  },
  {
   "id": "exploit-0041",
   "title": "RetoSwap",
   "date": "2026-05-20",
   "lossUsd": 2700000,
   "attackVector": "Smart Contract Bug",
   "chain": "Monero",
   "sector": "DEX",
   "summary": "On 20 May 2026 the Monero P2P exchange RetoSwap, a Haveno Protocol fork, was exploited for about 7,000 XMR (roughly $2.7 million) via a forged-message flaw in its trade arbitration flow.",
   "details": "The client accepted a forged, out-of-order ACK message without verifying the sender's signature, letting the attacker overwrite the arbitrator's stored Tor address with their own; the attacker then held two of three keys to newly created trade multisig wallets and swept victims' XMR the moment deposits landed. RetoSwap suspended trading, and Haveno's lead developer shipped a fix the same day preventing node-address updates before multisig creation.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-retoswap-hack-may-2026"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0041/"
  },
  {
   "id": "exploit-0042",
   "title": "Echo Protocol",
   "date": "2026-05-19",
   "lossUsd": 76700000,
   "attackVector": "Private Key Compromise",
   "chain": "Monad",
   "sector": "Yield",
   "summary": "On 19 May 2026 an attacker used a compromised admin key to mint about 1,000 unauthorised eBTC on Echo Protocol's Monad deployment, a paper value of roughly $76.7 million, though the realised take was far smaller.",
   "details": "The eBTC minting contract had no multisig, timelock or mint limits, so the stolen admin key gave the attacker unilateral minting rights. Thin liquidity on Monad limited the realised proceeds to roughly $816,000 in ETH sent to Tornado Cash, plus about $3.45 million in WBTC borrowed against minted eBTC on Curvance. Echo regained control of the admin keys, burnt the remaining 955 eBTC, paused Monad cross-chain functionality and upgraded the affected contract.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0042/"
  },
  {
   "id": "exploit-0043",
   "title": "Verus–Ethereum Bridge",
   "date": "2026-05-18",
   "lossUsd": 11500000,
   "attackVector": "Bridge Exploit",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "The Verus–Ethereum bridge was exploited on 18 May 2026 for roughly $11.5 million, the largest single incident of the month by most trackers.",
   "details": "Attackers bypassed the bridge's verification logic and withdrew about 1,625 ETH (~$3.44 million), 103.57 tBTC v2 (~$8.06 million) and 147,659 USDC from the Ethereum side. The project's incident report followed around eight hours after the initial theft; BlockSec and monthly trackers including CertiK-linked reporting flagged cross-chain bridges as May's most-targeted category, with this incident at the top.",
   "blockData": [],
   "links": [
    {
     "label": "Global Ledger",
     "url": "https://blog.globalledger.io/research-investigations/crypto-hacks-may-2026"
    },
    {
     "label": "BlockSec Weekly",
     "url": "https://blocksec.com/blog/web3-security-verus-bridge-retoswap-more"
    }
   ],
   "logo": "/media/brands/verus.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0043/"
  },
  {
   "id": "exploit-0044",
   "title": "THORChain",
   "date": "2026-05-15",
   "lossUsd": 10700000,
   "attackVector": "Private Key Compromise",
   "chain": "Multichain",
   "sector": "DEX",
   "summary": "On 15 May 2026 an attacker drained about $10.7 million from one of THORChain's five Asgard vaults across Bitcoin, Ethereum, Base and BNB Chain, crashing RUNE around 15%.",
   "details": "The attacker was a newly churned node operator who had joined the network two days earlier; the working theory supported by PeckShield, Cyvers and THORChain's own report is that vault key material leaked through a vulnerability in the GG20 threshold signature scheme implementation during keygen or signing rounds. Node operators paused the network within hours via the Mimir governance module, and trading resumed after a five-week halt alongside a $10 million compensation portal for affected users.",
   "blockData": [],
   "links": [
    {
     "label": "THORChain exploit report",
     "url": "https://thorchain.org/blog/thorchain-exploit-report-1"
    }
   ],
   "logo": "/media/brands/thorchain.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0044/"
  },
  {
   "id": "exploit-0045",
   "title": "Transit Finance",
   "date": "2026-05-13",
   "lossUsd": 1880000,
   "attackVector": "Smart Contract Bug",
   "chain": "Tron",
   "sector": "DEX",
   "summary": "Cross-chain swap aggregator Transit Finance lost about $1.88 million on 13 May 2026 through an exploit of a deprecated smart contract on Tron.",
   "details": "DefiLlama classifies the incident as a deprecated smart contract exploit, and Nominis records it as a contract logic flaw. Funds were drained from legacy contracts that remained callable despite no longer being part of the active product.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    },
    {
     "label": "Nominis May 2026 report",
     "url": "https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-may-2026"
    }
   ],
   "logo": "/media/brands/transitfinance.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0045/"
  },
  {
   "id": "exploit-0046",
   "title": "TrustedVolumes",
   "date": "2026-05-07",
   "lossUsd": 5870000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "DeFi",
   "summary": "Liquidity provider TrustedVolumes lost about $5.87 million in WETH, USDT, WBTC and USDC on 7 May 2026 after an attacker exploited its request-for-quote (RFQ) order flow.",
   "details": "Analysts described the incident as an access-control failure in which forged RFQ orders were used to pull funds from the market maker; the exploiter began laundering proceeds through Tornado Cash, RailGun and THORChain. Global Ledger noted the firm's public incident report followed roughly 11 minutes after the initial transaction.",
   "blockData": [],
   "links": [
    {
     "label": "Global Ledger",
     "url": "https://blog.globalledger.io/research-investigations/crypto-hacks-may-2026"
    },
    {
     "label": "Nominis May 2026 report",
     "url": "https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-may-2026"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0046/"
  },
  {
   "id": "exploit-0047",
   "title": "Ekubo",
   "date": "2026-05-06",
   "lossUsd": 1400000,
   "attackVector": "Smart Contract Bug",
   "chain": "Ethereum",
   "sector": "DEX",
   "summary": "On 6 May 2026 attackers drained about $1.4 million, mostly in wrapped bitcoin, from users of Ekubo's EVM swap router contracts via an approval-based exploit.",
   "details": "The router's IPayer.pay callback failed to verify that the payer matched the lock initiator, so attackers could craft a malicious lock payload naming any address as payer and call transferFrom against wallets that had approved the routers, looping the exploit roughly 85 times at about 0.2 WBTC per iteration. Only the Ethereum V2/V3 and Arbitrum V3 routers were affected; Starknet's core deployment and all liquidity providers were untouched, and Ekubo urged users to revoke approvals on the three affected immutable contracts.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/ekubo.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0047/"
  },
  {
   "id": "exploit-0048",
   "title": "Wasabi Protocol",
   "date": "2026-04-30",
   "lossUsd": 5000000,
   "attackVector": "Private Key Compromise",
   "chain": "Ethereum",
   "sector": "Perps",
   "summary": "Perpetuals platform Wasabi Protocol was drained of roughly $5 million (initially reported at $4.5 million) on 30 April 2026 after its deployer admin key was compromised.",
   "details": "The attacker used the compromised deployer key to call grantRole with zero delay, then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining vaults across Ethereum, Base, Berachain and Blast, including wWETH, sUSDC, wBITCOIN and wPEPE pools. Reporting highlighted the absence of a timelock or multisig on the admin role as the key safeguard failure.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0048/"
  },
  {
   "id": "exploit-0050",
   "title": "Sweat Economy",
   "date": "2026-04-29",
   "lossUsd": 3500000,
   "attackVector": "Smart Contract Bug",
   "chain": "NEAR",
   "sector": "DeFi",
   "summary": "On 29 April 2026 an attacker exploited a refund-logic bug in the SWEAT token contract on NEAR, draining about 13.71 billion tokens (roughly 65% of supply, worth up to $3.5 million) in around 30 seconds.",
   "details": "The contract was missing an access-restriction macro: the attacker chained a no-op call returning empty bytes into ft_resolve_transfer, which the contract interpreted as 'receiver consumed zero tokens' and refunded victims' entire balances to the attacker. The team paused the contract, MEXC froze the attacker's account and Rhea Finance halted SWEAT trading; the team subsequently restored all external user balances and deployed a patched contract.",
   "blockData": [],
   "links": [
    {
     "label": "Fireblocks",
     "url": "https://www.fireblocks.com/blog/near-zero-day-sweat-hot-token-exploit"
    }
   ],
   "logo": "/media/brands/sweateconomy.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0050/"
  },
  {
   "id": "exploit-0049",
   "title": "Aftermath Perps",
   "date": "2026-04-29",
   "lossUsd": 1140000,
   "attackVector": "Smart Contract Bug",
   "chain": "Sui",
   "sector": "Perps",
   "summary": "Sui-based perpetuals platform Aftermath was exploited for about $1.14 million on 29 April 2026, according to DefiLlama's hacks database.",
   "details": "DefiLlama classifies the incident as a fee-accounting logic flaw in the perps contracts on Sui. Detailed independent reporting on the incident is limited.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    }
   ],
   "logo": "/media/brands/aftermath.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0049/"
  },
  {
   "id": "exploit-0051",
   "title": "Purrlend",
   "date": "2026-04-25",
   "lossUsd": 1500000,
   "attackVector": "Smart Contract Bug",
   "chain": "Hyperliquid",
   "sector": "Lending",
   "summary": "Lending protocol Purrlend was exploited for about $1.5 million on 25 April 2026, according to DefiLlama's hacks database.",
   "details": "DefiLlama records the incident across MegaETH and Hyperliquid L1 and attributes it to a fake bridge address exploit in the protocol's logic. Detailed independent reporting on the incident is limited.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0051/"
  },
  {
   "id": "exploit-0052",
   "title": "Giddy",
   "date": "2026-04-23",
   "lossUsd": 1300000,
   "attackVector": "Smart Contract Bug",
   "chain": "Ethereum",
   "sector": "Wallet",
   "summary": "Smart wallet platform Giddy was exploited for about $1.3 million on 23 April 2026, according to DefiLlama's hacks database.",
   "details": "DefiLlama classifies the incident as a protocol logic exploit caused by incomplete EIP-712 signature coverage, which allowed signed messages to be abused to move user funds on Ethereum. Detailed independent reporting on the incident is limited.",
   "blockData": [],
   "links": [
    {
     "label": "DefiLlama hacks database",
     "url": "https://defillama.com/hacks"
    }
   ],
   "logo": "/media/brands/giddy.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0052/"
  },
  {
   "id": "exploit-0053",
   "title": "Volo",
   "date": "2026-04-21",
   "lossUsd": 3500000,
   "attackVector": "Private Key Compromise",
   "chain": "Sui",
   "sector": "Yield",
   "summary": "Sui liquid staking protocol Volo lost about $3.5 million from three vaults (WBTC, XAUm and USDC) on 21 April 2026 after a privileged admin key was compromised.",
   "details": "GoPlus Security and ExVul attributed the breach to a compromised operator key obtained through social engineering rather than any flaw in Volo's audited contracts. Volo self-disclosed within hours, froze the vaults, worked with the Sui Foundation, blocked a WBTC bridge attempt and clawed back around $2 million quickly; the team said it recovered nearly all funds, leaving a net loss of roughly $60,000, and absorbed user losses.",
   "blockData": [],
   "links": [
    {
     "label": "Rekt News",
     "url": "https://rekt.news/volo-rekt"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0053/"
  },
  {
   "id": "exploit-0054",
   "title": "Kelp DAO",
   "date": "2026-04-18",
   "lossUsd": 292000000,
   "attackVector": "Bridge Exploit",
   "chain": "Multichain",
   "sector": "Yield",
   "summary": "On 18 April 2026 attackers stole about 116,500 rsETH worth roughly $292 million from liquid restaking protocol Kelp DAO's LayerZero-powered bridge, the largest crypto theft of 2026 so far.",
   "details": "Attackers reportedly compromised a LayerZero Labs developer in early March, poisoned internal RPC nodes and DDoSed external ones so the single verifying DVN read fake burn events, causing the bridge to release rsETH against burns that never happened; rsETH was configured with only one verifier. Kelp paused contracts to block a further $95 million theft, and the Arbitrum Security Council froze over 30,000 ETH of downstream funds. Chainalysis and multiple outlets attributed the attack to North Korea-linked actors, and the exploit triggered $6.2 billion of Aave withdrawals before a 'DeFi United' effort raised about 132,650 ETH to backstop bad debt; Kelp and LayerZero publicly disputed responsibility for the single-verifier configuration.",
   "blockData": [],
   "links": [
    {
     "label": "Chainalysis",
     "url": "https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"
    },
    {
     "label": "LayerZero incident report",
     "url": "https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"
    }
   ],
   "logo": "/media/brands/kelpdao.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0054/"
  },
  {
   "id": "exploit-0055",
   "title": "Rhea Finance",
   "date": "2026-04-16",
   "lossUsd": 18400000,
   "attackVector": "Smart Contract Bug",
   "chain": "NEAR",
   "sector": "Lending",
   "summary": "NEAR-based lending and trading protocol Rhea Finance was exploited in mid-April 2026 via a flaw in its margin-trading slippage protection, with losses revised from an initial $7.6 million to about $18.4 million on 17 April.",
   "details": "The attacker constructed a series of swaps that bypassed slippage checks: the system aggregated expected output values across multiple swap steps without accounting for tokens reused across transactions. The swaps diverted borrowed reserve assets into attacker-controlled liquidity pools. Rhea paused its lending contracts, and the attacker returned roughly $3.3 million in USDC and 1.56 million NEAR, while around $4.34 million in USDT was frozen.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn",
     "url": "https://www.halborn.com/blog/post/explained-the-rhea-finance-hack-april-2026"
    }
   ],
   "logo": "/media/brands/rheafinance.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0055/"
  },
  {
   "id": "exploit-0056",
   "title": "Grinex",
   "date": "2026-04-15",
   "lossUsd": 15000000,
   "attackVector": "Private Key Compromise",
   "chain": "Tron",
   "sector": "CEX",
   "summary": "Sanctioned Russia-linked exchange Grinex was drained of roughly $13.7–15 million from its hot wallets on 15 April 2026 and halted all operations the following day.",
   "details": "The theft began around 12:00 UTC on 15 April, with stolen USDT swapped into TRX and ETH to avoid issuer freezes and split across dozens of wallets; TRM Labs later identified around 70 drained addresses, raising the confirmed estimate to about $15 million. Grinex, the successor to sanctioned exchange Garantex, blamed 'Western special services', a claim no independent researcher has verified. Elliptic and Chainalysis both documented the shutdown of the exchange.",
   "blockData": [],
   "links": [
    {
     "label": "Elliptic",
     "url": "https://www.elliptic.co/blog/sanctioned-russia-linked-crypto-exchange-grinex-halts-operations-following-alleged-hack"
    },
    {
     "label": "Chainalysis",
     "url": "https://www.chainalysis.com/blog/sanctioned-grinex-exchange-suspends-operations/"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0056/"
  },
  {
   "id": "exploit-0057",
   "title": "CoW Swap",
   "date": "2026-04-14",
   "lossUsd": 1200000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "DEX",
   "summary": "On 14 April 2026 CoW Swap's cow.fi domain was hijacked and users were redirected to a wallet-draining phishing site, with reported losses of about $1.2 million.",
   "details": "Attackers used forged documents and weaknesses in the .fi domain registration process to seize the domain at around 14:54 UTC, serving a fake front end that drained connected wallets. CoW DAO confirmed its smart contracts, backend and APIs were not compromised, paused the protocol as a precaution, identified the breach within 19 minutes and restored the domain within 26 hours, later adding RegistryLock protection.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/cowswap.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0057/"
  },
  {
   "id": "exploit-0058",
   "title": "Hyperbridge",
   "date": "2026-04-13",
   "lossUsd": 2500000,
   "attackVector": "Bridge Exploit",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "On 13 April 2026 an attacker submitted forged state proofs to Hyperbridge's Token Gateway on Ethereum, minting 1 billion bridged DOT and draining escrowed assets; losses were later revised from about $237,000 to roughly $2.5 million.",
   "details": "The attacker exploited a flaw in the Merkle Mountain Range proof verification logic of the HandlerV1 contract: the proof was not bound to a specific request and a zero-second challenge period allowed immediate execution, which handed the attacker admin control of the bridged DOT token. DOT pools on Ethereum, Base, BNB Chain and Arbitrum were affected, though Polkadot's core network and native DOT were untouched. Hyperbridge said a significant portion of the funds was traced to Binance and that it was working with the exchange's compliance team and law enforcement on freezes.",
   "blockData": [],
   "links": [
    {
     "label": "Hyperbridge post-mortem",
     "url": "https://blog.hyperbridge.network/april-13-post-mortem/"
    }
   ],
   "logo": "/media/brands/hyperbridge.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0058/"
  },
  {
   "id": "exploit-0059",
   "title": "Drift Protocol",
   "date": "2026-04-01",
   "lossUsd": 286000000,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "Perps",
   "summary": "On April 1, 2026, Drift Protocol suffered a roughly $286M exploit after attackers gained unauthorised administrative control and drained multiple protocol vaults on Solana.",
   "details": "Early reporting indicated this was not a routine smart-contract math bug but a privileged-control failure. The attacker rapidly drained several core vaults, with stolen assets including JLP, USDC, SOL, cbBTC and wBTC. Drift suspended deposits and withdrawals while investigators traced the outflows. Later reporting from Elliptic said the laundering patterns and on-chain behaviour were consistent with previous DPRK-linked operations, though that remains an attribution claim rather than a court finding.",
   "blockData": [],
   "links": [
    {
     "label": "Drift incident update",
     "url": "https://x.com/DriftProtocol/status/2039417136729227425"
    },
    {
     "label": "Elliptic analysis",
     "url": "https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"
    }
   ],
   "logo": "/media/brands/drift.png",
   "article": "drift-post-mortem",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0059/"
  },
  {
   "id": "exploit-0060",
   "title": "Resolv Labs",
   "date": "2026-03-22",
   "lossUsd": 25000000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "Stablecoin",
   "summary": "On March 22, 2026, Resolv Labs suffered an infrastructure breach after attackers gained privileged access through a compromised private key and minted a large block of uncollateralised USR.",
   "details": "This was not a contract-logic failure so much as the old classic: somebody got access they should not have had. The attacker used the compromised mint authority to create roughly $80M in fake USR, staked part of it into wstUSR, swapped into real assets, and tried to force value out before the protocol could shut the doors. Resolv moved quickly, paused the relevant contracts, burned a chunk of attacker-held supply, and said the realised damage before the pause was far smaller than the headline nominal mint. The important distinction is that the collateral base was not directly emptied; the danger came from fake liabilities being created against it.",
   "blockData": [
    {
     "label": "Exploiter Address",
     "text": "0x8ed8cf0c1c531c1b20848e78f1cb32fa5b99b81c"
    },
    {
     "label": "$50M mint tx",
     "url": "https://etherscan.io/tx/0xfe37f25efd67d0a4da4afe48509b258df48757b97810b28ce4c649658dc33743"
    },
    {
     "label": "$30M mint tx",
     "url": "https://etherscan.io/tx/0x41b6b9376d174165cbd54ba576c8f6675ff966f17609a7b80d27d8652db1f18f"
    },
    {
     "label": "Follow-on attacker tx",
     "url": "https://etherscan.io/tx/0x7f914328a67f7094eedb0efda7aef74aafdb7f862ad7bc78259564fd453a931d"
    }
   ],
   "links": [],
   "logo": "/media/brands/resolv.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0060/"
  },
  {
   "id": "exploit-0062",
   "title": "USDC Permit Signature Phish",
   "date": "2026-03-16",
   "lossUsd": 1760000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "Wallet",
   "summary": "On March 16, 2026, a victim lost $1.76M in USDC after signing a malicious Permit approval that handed spending rights to an attacker-controlled contract.",
   "details": "No fancy contract math here. The victim was tricked into signing what looked like a routine approval flow, but the Permit granted the attacker's contract the power to transfer the victim's USDC. The funds were drained immediately, swapped into ETH, and split across several wallets. Another reminder that one bad signature can be as fatal as a leaked seed phrase.",
   "blockData": [
    {
     "label": "Exploit tx",
     "url": "https://etherscan.io/tx/0xfd7417af8433e3d9bcbed3f965307c800a24eb4e98f42cebfab6ca6064f5a642"
    },
    {
     "label": "Victim wallet",
     "url": "https://etherscan.io/address/0x051bb76ff78366de530e293fdb1158c2079ab664"
    },
    {
     "label": "Malicious contract",
     "text": "0x9F68523efdc91ADbE53c3776Aa927f41aB4FE17E"
    }
   ],
   "links": [],
   "logo": "/media/coins/usdc.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0062/"
  },
  {
   "id": "exploit-0061",
   "title": "Venus",
   "date": "2026-03-16",
   "lossUsd": 2180000,
   "attackVector": "Other",
   "chain": "BNB Chain",
   "sector": "Borrowing",
   "summary": "On March 16, 2026, Venus Protocol on BSC was left with about $2.18M in bad debt after an attacker abused a supply-cap enforcement gap around THE and then pumped the token in thin liquidity.",
   "details": "This one was slow-cooked, not smash-and-grab. Over roughly nine months, the attacker built a giant uncapped THE position by routing around the normal deposit path and bypassing the intended supply ceiling. Once the position was in place, they started the recursive part: borrow assets, buy THE in low liquidity, push the price higher, transfer more THE into the market, inflate collateral value, repeat. The oracle did what it was told and reflected the manipulated market. When the unwind came, the collateral could not cover the borrowings and Venus was left with bad debt.",
   "blockData": [
    {
     "label": "Attacker Wallet 1",
     "text": "0x7a79969a0b9d51d922c4810d2950560360f6f234"
    },
    {
     "label": "Attacker Wallet 2",
     "text": "0x737bc98f1d34e19539c074b8ad1169d5d45da619"
    },
    {
     "label": "Attacker Wallet 3",
     "text": "0x1a35bd28efd46cfc46c2136f878777d69ae16231"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0061/"
  },
  {
   "id": "exploit-0063",
   "title": "Solv Protocol",
   "date": "2026-03-05",
   "lossUsd": 2730000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "Vault",
   "summary": "On March 5, 2026, Solv's BRO vault was exploited through a double-mint flaw that let the attacker turn a tiny BRO position into a cartoonishly large one and swap it for real SolvBTC.",
   "details": "The vulnerable BRO contract effectively paid twice in the same mint path. When the ERC-3525 NFT transfer callback fired, tokens were minted once, and then the outer mint routine minted them again. The attacker just looped burn/mint repeatedly until 135 BRO had been inflated into hundreds of millions. Once the fake balance existed, it was exchanged for real SolvBTC. Solv said the impact was confined to the affected vault and committed to covering losses.",
   "blockData": [
    {
     "label": "Vulnerable Contract",
     "text": "0x014e6F6ba7a9f4C9a51a0Aa3189B5c0a21006869"
    },
    {
     "label": "Exploit tx",
     "url": "https://etherscan.io/tx/0x44e637c7d85190d376a52d89ca75f2d208089bb02b7c4708ad2aaae3a97a958d"
    },
    {
     "label": "Exploiter",
     "text": "0x08259F9D1De695329b5a0FDF4703F72c7C2326A9"
    }
   ],
   "links": [],
   "logo": "/media/brands/solv.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0063/"
  },
  {
   "id": "exploit-0064",
   "title": "Blend Protocol",
   "date": "2026-02-22",
   "lossUsd": 10860000,
   "attackVector": "Oracle Manipulation",
   "chain": "Stellar",
   "sector": "Borrowing",
   "summary": "On February 22, 2026, the YieldBlox DAO Pool on Blend V2 was exploited for about $10.86M after an attacker pushed USTRY's SDEX price roughly 100x higher and let the oracle swallow it whole.",
   "details": "The attacker found an absurdly thin order book and did what attackers do when markets are basically decorative: they walked the price into the sky. Reflector picked up the manipulated SDEX price and Blend treated the attacker's USTRY as prime collateral instead of what it actually was. That opened the door to borrowing tens of millions in XLM and USDC against collateral worth a fraction of that. Once again, the oracle was not hacked in the Hollywood sense; it was just far too trusting.",
   "blockData": [
    {
     "label": "Attacker Address",
     "text": "GBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC"
    },
    {
     "label": "YieldBlox DAO Pool",
     "text": "CCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS"
    },
    {
     "label": "Oracle Adapter",
     "text": "CD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR"
    },
    {
     "label": "Reflector Oracle",
     "text": "CALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0064/"
  },
  {
   "id": "exploit-0065",
   "title": "IoTeX ioTube Bridge",
   "date": "2026-02-21",
   "lossUsd": 4400000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "Bridge",
   "summary": "On February 21, 2026, IoTeX's ioTube bridge lost about $4.4M on the Ethereum side after attackers compromised the Validator owner account and upgraded it to bypass the bridge's security checks.",
   "details": "Once the owner account was in hostile hands, the attacker replaced the Validator logic with something that effectively waved everything through. That broke the trust boundary protecting the MintPool and TokenSafe contracts, letting the attacker mint bridge-side assets and drain reserve tokens. IoTeX managed to freeze and blacklist a meaningful slice of the fallout, but not before real value had already left.",
   "blockData": [
    {
     "label": "Attacker Address",
     "text": "0x6487B5006904f3Db3C4a3654409AE92b87eD442f"
    }
   ],
   "links": [],
   "logo": "/media/brands/iotex.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0065/"
  },
  {
   "id": "exploit-0066",
   "title": "Moonwell cbETH Oracle Incident",
   "date": "2026-02-15",
   "lossUsd": 1780003,
   "attackVector": "Oracle Manipulation",
   "chain": "Base",
   "sector": "Borrowing",
   "summary": "On February 15, 2026, Moonwell on Base suffered about $1.78M in losses when cbETH was mispriced at roughly $1.12 instead of around $2,200, triggering mass liquidations and cheap borrowing.",
   "details": "This was not subtle. The oracle pipeline effectively passed through a token ratio without multiplying it back into the dollar value of ETH. That meant the protocol treated cbETH as almost worthless. Liquidation bots stepped in, repaid pocket change, and received outsized chunks of collateral. Other users borrowed against the same broken number. Moonwell moved to clamp the market fast, but not before the bad price had already done its damage.",
   "blockData": [
    {
     "label": "Affected Assets",
     "text": "cbETH (primary), cbBTC, tBTC"
    }
   ],
   "links": [],
   "logo": "/media/brands/moonwell.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0066/"
  },
  {
   "id": "exploit-0067",
   "title": "CrossCurve",
   "date": "2026-02-01",
   "lossUsd": 2900000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Bridge",
   "summary": "On February 1, 2026, CrossCurve lost roughly $2.9M after an attacker exploited an authorisation bypass in ReceiverAxelar's express execution flow.",
   "details": "Axelar's model is supposed to bind execution to validated cross-chain messages. The weak point here was a path that skipped that validation and relied too heavily on attacker-controlled metadata. The result was spoofed messages that looked close enough to pass local checks, letting the attacker trigger unlocks they had no right to trigger. CrossCurve responded with a white-hat ultimatum and threat of legal follow-through, which is usually what teams say when the chain has already spoken.",
   "blockData": [
    {
     "label": "Funds Holder 1",
     "text": "0xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE"
    },
    {
     "label": "Funds Holder 2",
     "text": "0x8c259f1e53e79408095d0ba805554d4cdda15285"
    },
    {
     "label": "Funds Holder 3",
     "text": "0x851c01d014b1ad2b1266ca48a4b5578b67194834"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0067/"
  },
  {
   "id": "exploit-0068",
   "title": "Step Finance Treasury Breach",
   "date": "2026-01-31",
   "lossUsd": 30000000,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "Treasury",
   "summary": "On January 31, 2026, Step Finance suffered a treasury breach of roughly $27M-30M after multiple treasury wallets were compromised and stake authority was transferred away.",
   "details": "Step described the route as a well-known attack vector, which usually means something operational and ugly rather than elegantly novel. Once the attacker had the relevant wallet access, they moved stake authority, unstaked, and drained a huge SOL position. The key point is that this appears to have been treasury-specific rather than a user-fund contract exploit, but $30M disappearing is still $30M disappearing.",
   "blockData": [
    {
     "label": "Compromised Stake Account",
     "text": "6G53KAWtQnZSSN6HUxnBs3yYsK1aCuJRbrcPbWGY71LL"
    },
    {
     "label": "Attack Transaction",
     "text": "2w8sgATZwcmRMHEsG3nutmZJrskVkp74LAwTTEyxSMBJhnZ7Ux4ticeYAYnTb6K44m1XYziPvqonSkZeukAAFadZ"
    }
   ],
   "links": [
    {
     "label": "Halborn post-mortem",
     "url": "https://www.halborn.com/blog/post/explained-the-step-finance-hack-january-2026"
    }
   ],
   "logo": "/media/brands/stepfinance.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0068/"
  },
  {
   "id": "exploit-0070",
   "title": "Aperture Finance",
   "date": "2026-01-25",
   "lossUsd": 3670000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Routing",
   "summary": "On January 25, 2026, Aperture Finance V3/V4 contracts were exploited for about $3.67M across multiple chains through a similar arbitrary-call / approval-abuse flaw.",
   "details": "The attacker did not need users to do anything in the moment. The damage came from approvals that already existed. Once the vulnerable call path was abused, ERC-20 and even NFT-style approvals could be cashed in. The exploit also overlapped with the wider SwapNet incident, which suggests the attackers were not improvising but moving through a known pattern.",
   "blockData": [
    {
     "label": "Affected Contract 1",
     "text": "0xD83...8913"
    },
    {
     "label": "Affected Contract 2",
     "text": "0x008...d857"
    },
    {
     "label": "Affected Contract 3",
     "text": "0xe00...05cB"
    }
   ],
   "links": [],
   "logo": "/media/brands/aperture.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0070/"
  },
  {
   "id": "exploit-0069",
   "title": "SwapNet",
   "date": "2026-01-25",
   "lossUsd": 17000000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On January 25, 2026, SwapNet was hit for about $17M after attackers abused an arbitrary-call style flaw to weaponise existing token approvals.",
   "details": "This one was grimly practical. Users had already approved router-style contracts, and the vulnerable logic let attackers steer those approvals into unauthorised transferFrom calls. In other words, the protocol became a machine for cashing in permissions users had granted earlier under normal conditions. This was linked to the same broader approval-abuse wave that also hit Aperture.",
   "blockData": [
    {
     "label": "Router Contract",
     "text": "0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0069/"
  },
  {
   "id": "exploit-0071",
   "title": "SagaEVM",
   "date": "2026-01-21",
   "lossUsd": 7000000,
   "attackVector": "Other",
   "chain": "SagaEVM",
   "sector": "Chainlet",
   "summary": "On January 21, 2026, SagaEVM suffered a roughly $7M incident involving coordinated malicious deployments and cross-chain exits to Ethereum.",
   "details": "Saga's account of this is important: they said there was no validator compromise, no consensus failure, and no signer key leak. That suggests the failure lived inside the chainlet or attached execution environment rather than the network's deeper trust layer. Still, the attacker got real assets out before the chainlet was halted, which is all users and markets tend to care about.",
   "blockData": [
    {
     "label": "Exploiter Wallet",
     "text": "0x2044697623afa31459642708c83f04ecef8c6ecb"
    }
   ],
   "links": [],
   "logo": "/media/brands/saga.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0071/"
  },
  {
   "id": "exploit-0072",
   "title": "Makina Finance",
   "date": "2026-01-20",
   "lossUsd": 5000000,
   "attackVector": "Flash Loan",
   "chain": "Ethereum",
   "sector": "Yield Aggregator",
   "summary": "On January 20, 2026, Makina Finance suffered a $5M oracle-manipulation exploit against the DUSD/USDC Curve pool, with part of the value intercepted by an MEV builder.",
   "details": "The attacker pulled a giant USDC flash loan, distorted the MachineShareOracle's pricing, and used the bad number to drain the relevant stablecoin liquidity. The funny detail, if one can call it funny, is that a big chunk of the exploit value was frontrun and effectively stolen from the thief by an MEV builder. DeFi increasingly has these nested theft structures now: protocol gets robbed, then the robber gets partially robbed on the way out.",
   "blockData": [
    {
     "label": "Attack Transaction",
     "url": "https://etherscan.io/tx/0x569733b8016ef9418f0b6bde8c14224d9e759e79301499908ecbcd956a0651f5"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0072/"
  },
  {
   "id": "exploit-0074",
   "title": "Yo Yield",
   "date": "2026-01-13",
   "lossUsd": 3700000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "Yield Aggregator",
   "summary": "On January 13, 2026, Yo Yield lost about $3.7M when 3.84M GHO was swapped into just 112K USDC during a vault operation.",
   "details": "Sometimes the exploit is simply dreadful execution. The protocol converted something that should have behaved roughly like a stable-for-stable trade into catastrophic slippage. Whether you label that a bug, controls failure, or operator negligence, the effect is the same: a vault did something economically insane and users wore the damage.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0074/"
  },
  {
   "id": "exploit-0073",
   "title": "NYC Memecoin",
   "date": "2026-01-13",
   "lossUsd": 3400000,
   "attackVector": "Rugpull",
   "chain": "Solana",
   "sector": "Token",
   "summary": "On January 13, 2026, the $NYC memecoin was accused of a classic rug after liquidity was pulled shortly after promotion from a high-profile account.",
   "details": "There is not much technical subtlety here. The pattern described by researchers is the standard memecoin circus: loud public promotion, fast inflows, liquidity removed, late buyers stranded. Once again, the interesting part is not the code but the distribution mechanism: credibility and audience were the real attack surface.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0073/"
  },
  {
   "id": "exploit-0075",
   "title": "Social Engineering Theft",
   "date": "2026-01-10",
   "lossUsd": 282000000,
   "attackVector": "Phishing",
   "chain": "Multichain",
   "sector": "Wallet",
   "summary": "On January 10, 2026, a victim lost more than $282M in BTC and LTC through a hardware-wallet social-engineering scam, after which the attacker moved rapidly across THORChain, CEXs and privacy rails.",
   "details": "This was not a protocol failure at all; it was human compromise followed by industrial-grade laundering. The attacker started bridging and swapping almost immediately, moving large slices through THORChain into ETH, XRP and other assets, then dispersing funds across exchanges and mixers. It was a reminder that in raw dollar terms, social engineering still competes comfortably with every smart-contract exploit you care to name.",
   "blockData": [
    {
     "label": "BTC Theft Address 1",
     "text": "bc1qluxw46r55wf3dnk9c652vrt4duadm3hpuktf86"
    },
    {
     "label": "BTC Theft Address 2",
     "text": "bc1qpsmh26ja0fzzf286zulmt9eywujc2pggj40wzm"
    },
    {
     "label": "LTC Theft Address",
     "text": "ltc1qly43c2prj4c2e85dcspzpjd36jnapnenldnr70"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0075/"
  },
  {
   "id": "exploit-0076",
   "title": "Truebit",
   "date": "2026-01-08",
   "lossUsd": 26500000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "Token",
   "summary": "On January 8, 2026, Truebit lost about $26.5M after an integer overflow in getPurchasePrice() let the attacker mint TRU for effectively zero ETH and dump it.",
   "details": "This is the kind of bug that makes smart-contract veterans sigh and stare into the middle distance. A large input caused the pricing math to overflow, the division result collapsed to zero, and the attacker could repeatedly mint huge amounts of TRU without paying meaningful cost. The market did the rest. Once the newly minted supply hit liquidity, the token price fell off a cliff and the attacker walked away with ETH.",
   "blockData": [
    {
     "label": "Exploiter",
     "url": "https://etherscan.io/address/0x6C8EC8f14bE7C01672d31CFa5f2CEfeAB2562b50"
    }
   ],
   "links": [],
   "logo": "/media/brands/truebit.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0076/"
  },
  {
   "id": "exploit-0077",
   "title": "TMX",
   "date": "2026-01-06",
   "lossUsd": 1400000,
   "attackVector": "Other",
   "chain": "Arbitrum",
   "sector": "Exchange",
   "summary": "On January 6, 2026, TMX on Arbitrum lost around $1.4M when an attacker found a profitable mint/stake/swap/unstake loop and repeated it until the pools were drained.",
   "details": "The contract was unverified, which never helps, but the core pattern was simple enough: each cycle returned more value than went in. Once that kind of mechanical edge exists, the attacker's job is just to keep pressing the button until the pool stops paying. That appears to be what happened here.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0077/"
  },
  {
   "id": "exploit-0078",
   "title": "Unleash Protocol",
   "date": "2025-12-30",
   "lossUsd": 3900000,
   "attackVector": "Access Control",
   "chain": "Story",
   "sector": "Governance",
   "summary": "On December 30, 2025, Unleash Protocol's multisig governance was compromised, enabling an unauthorised upgrade and a drain of roughly $3.9M.",
   "details": "This was a permissions story. Once the attacker acquired governance-side control, the rest followed in depressingly familiar fashion: upgrade logic, withdraw assets, bridge out, launder through Tornado. Story itself said its core infrastructure was unaffected, which may be true, but that is cold comfort when the application sitting on top of it has been opened with admin keys.",
   "blockData": [
    {
     "label": "Attacker Address",
     "text": "0xc946981F5dFBFA10cf858B95d51Fc06DCD15BfE3"
    },
    {
     "label": "Story tx",
     "url": "https://storyscan.io/tx/0x2cb543fdcb7345fd4b6512b9b37408fbaeded6a06bcc248a3a04d1e8e70ab6c3"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0078/"
  },
  {
   "id": "exploit-0079",
   "title": "Flow Network",
   "date": "2025-12-27",
   "lossUsd": 3900000,
   "attackVector": "Other",
   "chain": "Flow",
   "sector": "Execution Layer",
   "summary": "On December 27, 2025, an attacker exploited a flaw in Flow's execution layer and moved roughly $3.9M off-network through bridges before validators coordinated a halt.",
   "details": "Flow stressed that existing user balances were not touched, a real point in its favour. The vulnerability appears to have been in the exit/execution path rather than a direct user-account drain. That said, once assets are already riding bridges to Ethereum and the attacker is sending value through THORChain and Chainflip, the distinction becomes more architectural than comforting.",
   "blockData": [
    {
     "label": "Exploiter",
     "text": "0x2e7C4b71397f10c93dC0C2ba6f8f179a47F994e1"
    }
   ],
   "links": [],
   "logo": "/media/brands/flow.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0079/"
  },
  {
   "id": "exploit-0080",
   "title": "Trust Wallet Browser Extension",
   "date": "2025-12-26",
   "lossUsd": 7000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Wallet",
   "summary": "On December 26, 2025, Trust Wallet Browser Extension v2.68 was compromised, leading to about $6M-7M being drained from affected users.",
   "details": "This was a supply-chain style wallet incident. The bad version reportedly gave the attackers access to sensitive wallet material or signing capability, and once a malicious update is sitting in a live extension channel the blast radius can expand quickly. Trust Wallet pushed users to disable the version and move fast, but malicious updates are brutal because they hijack the trust users have already granted.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/trustwallet.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0080/"
  },
  {
   "id": "exploit-0081",
   "title": "Address Poisoning Attack",
   "date": "2025-12-20",
   "lossUsd": 50000000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "Wallet",
   "summary": "On December 20, 2025, a victim lost almost $50M in USDT after copying a poisoned lookalike address from transaction history.",
   "details": "This was pure human-interface exploitation. The attacker exploited how people rely on recent transaction history and glance at the first and last few characters of an address instead of verifying the whole thing. After the victim sent a small test amount, the poisoned address appeared in their history and the main transfer followed. The attacker then started laundering almost immediately through stablecoin swaps and Tornado.",
   "blockData": [
    {
     "label": "Exploit Transaction",
     "url": "https://etherscan.io/tx/0xc0514a795f065fce8a3e1238a1ba480e8a792d45f6431ee4ba8d800bedd86a0f"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0081/"
  },
  {
   "id": "exploit-0082",
   "title": "Yearn Finance Legacy yETH Exploit",
   "date": "2025-11-30",
   "lossUsd": 8900000,
   "attackVector": "Flash Loan",
   "chain": "Ethereum",
   "sector": "Yield Aggregator",
   "summary": "On November 30, 2025, a legacy Yearn yETH product was exploited, letting the attacker infinitely mint yETH and drain almost $9M from connected liquidity pools.",
   "details": "The vulnerable path sat in old yETH logic rather than Yearn's later vault architecture. Once the attacker could mint effectively unbacked yETH, those fake claims were pushed into Balancer and Curve-style liquidity to pull out real ETH and LSDs. Yearn later coordinated some recovery and treasury support, but the broader lesson was the usual one: old code with live liquidity attached is still live risk.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX post-mortem",
     "url": "https://yfarmx.com/yearn-finance-exploit-legacy-yeth-pool-drained-after-infinite-mint-bug/"
    }
   ],
   "logo": "/media/brands/yearn.png",
   "article": "yearn-finance-exploit-legacy-yeth-pool-drained-after-infinite-mint-bug",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0082/"
  },
  {
   "id": "exploit-0083",
   "title": "Upbit Solana Hot-Wallet Breach",
   "date": "2025-11-27",
   "lossUsd": 36000000,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "Exchange",
   "summary": "On November 27, 2025, Upbit reported about $36M in unauthorised outflows from a production Solana hot wallet and suspended Solana rails.",
   "details": "The outflows hit multiple Solana assets, and the important operational point was that Upbit said cold wallets were not compromised and customer balances would be made whole. That suggests an exchange hot-wallet security failure rather than a total infrastructure collapse. Still, when a major exchange says unauthorised outflow, the words are polite but the meaning is not.",
   "blockData": [],
   "links": [
    {
     "label": "YFarmX explainer",
     "url": "https://yfarmx.com/upbit-hack-explained-exchange-blames-signature-bug/"
    },
    {
     "label": "Upbit official statement",
     "url": "https://www.upbit.com/service_center/notice?id=5800&view=share"
    }
   ],
   "logo": "/media/brands/upbit.png",
   "article": "upbit-hack-explained-exchange-blames-signature-bug",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0083/"
  },
  {
   "id": "exploit-0084",
   "title": "GANA Payment Liquidity Drain",
   "date": "2025-11-20",
   "lossUsd": 3100000,
   "attackVector": "Other",
   "chain": "BNB Chain",
   "sector": "Token",
   "summary": "On November 20, 2025, GANA Payment on BSC was stripped of roughly $3.1M before the proceeds were washed through Tornado Cash on BSC and Ethereum.",
   "details": "The exact technical cause remained murky, but the money trail was clear enough: liquidity drained, proceeds converted, laundering began. GANA looked like one of those thinly documented projects where public code and public explanation lag far behind the actual economic damage.",
   "blockData": [],
   "links": [
    {
     "label": "Investigation post",
     "url": "https://t.me/investigations/289"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0084/"
  },
  {
   "id": "exploit-0086",
   "title": "Stream Finance External Manager Blow-Up",
   "date": "2025-11-04",
   "lossUsd": 93000000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Synthetic / Credit",
   "summary": "On November 4, 2025, Stream Finance said an external fund manager had effectively vaporised around $93M, triggering a much wider synthetic-debt unwind.",
   "details": "This was less a smart-contract exploit than a systemic collateral crisis. Stream's synthetic stack was wired into multiple lenders and related stable structures, so once confidence broke the damage spread quickly. These are often the messiest incidents because the initial hole is smaller than the eventual credit crater it opens.",
   "blockData": [],
   "links": [
    {
     "label": "Stream statement",
     "url": "https://x.com/StreamDefi/status/1985556360507822093"
    },
    {
     "label": "Contagion overview",
     "url": "https://x.com/yieldsandmore/status/1985571764441579649"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0086/"
  },
  {
   "id": "exploit-0085",
   "title": "Moonwell wrsETH Oracle Meltdown",
   "date": "2025-11-04",
   "lossUsd": 3700000,
   "attackVector": "Oracle Manipulation",
   "chain": "Base",
   "sector": "Borrowing",
   "summary": "On November 4, 2025, Moonwell's Base deployment was left with around $3.7M in bad debt after a wrsETH oracle briefly valued one token like a small country.",
   "details": "The attacker used a nonsense oracle print to treat dust-sized wrsETH as enormous collateral. Once that happened, the rest was routine: borrow real assets, cycle through markets fast, leave the protocol holding the embarrassment. Moonwell clamped supply and borrow caps quickly, but fast clamps do not un-create bad debt.",
   "blockData": [
    {
     "label": "First exploit tx",
     "url": "https://basescan.org/tx/0x229caeb87e0b6c31afad950150d2ba05a8d7fe823c9e5c05af63b4150b8f6cc6"
    }
   ],
   "links": [
    {
     "label": "Moonwell thread",
     "url": "https://x.com/MoonwellDeFi/status/1985775115876122650"
    }
   ],
   "logo": "/media/brands/moonwell.png",
   "article": "moonwell-exploit-highlights-perils-of-stale-oracles",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0085/"
  },
  {
   "id": "exploit-0088",
   "title": "Balancer V2 Stable Pool Exploit",
   "date": "2025-11-03",
   "lossUsd": 116000000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "AMM",
   "summary": "On November 3, 2025, Balancer's V2 Stable and Composable Stable v5 pool logic was exploited for about $116M across multiple deployments.",
   "details": "Balancer's preliminary write-up tied the attack to stable-pool rounding / upscale behaviour in EXACT_OUT swap flows combined with flash loans and BatchSwaps. Old, complex pool math was pushed into states it should never have tolerated, and the attacker extracted value faster than mitigations could contain it.",
   "blockData": [
    {
     "label": "Consolidator",
     "url": "https://etherscan.io/address/0xaa760d53541d8390074c61defeaba314675b8e3f"
    }
   ],
   "links": [
    {
     "label": "YFarmX write-up",
     "url": "https://yfarmx.com/balancer-hack-v2-vaults-drained-in-exploit/"
    }
   ],
   "logo": "/media/brands/balancer.png",
   "article": "balancer-hack-v2-vaults-drained-in-exploit",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0088/"
  },
  {
   "id": "exploit-0087",
   "title": "Beets Fi Balancer V2 Sonic Incident",
   "date": "2025-11-03",
   "lossUsd": 3000000,
   "attackVector": "Other",
   "chain": "Sonic",
   "sector": "AMM",
   "summary": "On November 3, 2025, Beets' Balancer V2 pools on Sonic were hit in the wider Balancer exploit wave, but Sonic's freeze mechanism trapped around $3M on-chain.",
   "details": "This is the rare exploit where a chain-level intervention materially limited the attacker's ability to get paid. The underlying pool logic was still broken, but Sonic's security tooling prevented the normal exit route of bridge-and-launder.",
   "blockData": [],
   "links": [
    {
     "label": "Sonic update",
     "url": "https://x.com/SonicLabs/status/1985401737096671549"
    },
    {
     "label": "Beets note",
     "url": "https://x.com/beets_fi/status/1985281285816754179"
    }
   ],
   "logo": "/media/brands/beets.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0087/"
  },
  {
   "id": "exploit-0089",
   "title": "Garden Finance Multi-Chain Liquidity Drain",
   "date": "2025-10-30",
   "lossUsd": 11000000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Cross-chain",
   "summary": "On October 30, 2025, Garden Finance lost about $11M across multiple networks in a coordinated drain of WBTC, USDC and USDT liquidity.",
   "details": "Garden argued its core contracts were fine and pointed to integrations; outside observers were less generous. Whatever the precise fault line, the practical result was that value moved out across chains, into ETH, and into laundering routes. That is usually the moment when debates about root cause become secondary.",
   "blockData": [],
   "links": [
    {
     "label": "Initial alert",
     "url": "https://x.com/De_FiSecurity/status/1983892058646704463"
    },
    {
     "label": "CertiK follow-up",
     "url": "https://x.com/CertiKAlert/status/1984054278479401330"
    }
   ],
   "logo": "/media/brands/gardenfinance.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0089/"
  },
  {
   "id": "exploit-0090",
   "title": "Typus Finance Oracle Manipulation",
   "date": "2025-10-15",
   "lossUsd": 3439998,
   "attackVector": "Oracle Manipulation",
   "chain": "Sui",
   "sector": "Borrowing",
   "summary": "On October 15, 2025, Typus Finance on Sui lost about $3.44M after a broken auth gate in the oracle module let the attacker publish bogus prices.",
   "details": "A public price feed without real authentication is less an oracle than a suggestion box. Once the attacker could publish values the protocol treated as trusted, draining the TLP became straightforward. Typus paused quickly, but the bug was the kind that should never have made it to production.",
   "blockData": [],
   "links": [
    {
     "label": "Typus post-mortem",
     "url": "https://x.com/TypusFinance/status/1978688164278702152"
    }
   ],
   "logo": "/media/brands/typus.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0090/"
  },
  {
   "id": "exploit-0091",
   "title": "Hyperliquid Private Key Compromise",
   "date": "2025-10-10",
   "lossUsd": 21000000,
   "attackVector": "Access Control",
   "chain": "Hyperliquid",
   "sector": "Wallet",
   "summary": "On October 10, 2025, a leaked signing key let attackers bridge out about $21M from a Hyperliquid user.",
   "details": "This was key compromise, not clever protocol exploitation. The funds moved with attacker-signed transactions, which is a much duller but more common cause of loss than people like to admit.",
   "blockData": [],
   "links": [
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/1976577386469839269"
    }
   ],
   "logo": "/media/brands/hyperliquid.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0091/"
  },
  {
   "id": "exploit-0092",
   "title": "Hypervault Suspected Rugpull",
   "date": "2025-09-26",
   "lossUsd": 3600000,
   "attackVector": "Rugpull",
   "chain": "Hyperliquid",
   "sector": "Yield",
   "summary": "On September 26, 2025, Hypervault appeared to pull a classic exit, moving about $3.6M in user funds off Hyperliquid and into laundering channels.",
   "details": "Team disappears, funds consolidate, bridges light up, Tornado appears in the distance: everyone knows the choreography by now.",
   "blockData": [],
   "links": [
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/1971476404173930660"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0092/"
  },
  {
   "id": "exploit-0093",
   "title": "GriffinAI GAIN Cross-Chain Peer Exploit",
   "date": "2025-09-25",
   "lossUsd": 3000000,
   "attackVector": "Access Control",
   "chain": "BNB Chain",
   "sector": "Token",
   "summary": "On September 25, 2025, GriffinAI's GAIN token was exploited after a rogue LayerZero peer was accepted as trusted, enabling mass minting and a token collapse.",
   "details": "Trusted-peer design is only as trustworthy as the peer registration. Once the attacker got a malicious contract accepted, they could mint GAIN as if it were legitimate cross-chain flow and dump it into real liquidity.",
   "blockData": [],
   "links": [
    {
     "label": "CertiK alert",
     "url": "https://x.com/CertiKAlert/status/1971053766540657069"
    },
    {
     "label": "PeckShield alert",
     "url": "https://x.com/PeckShieldAlert/status/1971045405149495520"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0093/"
  },
  {
   "id": "exploit-0094",
   "title": "SBI Crypto Hot-Wallet Heist",
   "date": "2025-09-24",
   "lossUsd": 24000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On September 24, 2025, attackers drained about $24M across BTC, ETH, LTC, DOGE and BCH in a multi-asset hot-wallet breach tied to SBI infrastructure.",
   "details": "The case had all the usual custodial red flags: hot-wallet exposure, fast laundering, and uncertainty over whether the initial compromise was keys, servers, or something adjacent. Either way, the exchange side of the stack failed before chain logic could play any part.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/sbicrypto.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0094/"
  },
  {
   "id": "exploit-0095",
   "title": "UXLINK Multi-Sig & Mint Abuse",
   "date": "2025-09-22",
   "lossUsd": 48000000,
   "attackVector": "Access Control",
   "chain": "Arbitrum",
   "sector": "Token",
   "summary": "On September 22, 2025, UXLINK suffered a multi-sig takeover, asset sweep and huge unauthorised token mint, with losses around $48M.",
   "details": "Once multi-sig control broke, it ceased to be a protocol and became the attacker's toy. Funds were swept first, inflation weaponised next, and then the attacker themselves reportedly got partially phished later in a kind of criminal slapstick sequel.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/uxlink.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0095/"
  },
  {
   "id": "exploit-0096",
   "title": "Aqua Solana Presale Rug",
   "date": "2025-09-09",
   "lossUsd": 4650000,
   "attackVector": "Rugpull",
   "chain": "Solana",
   "sector": "Token",
   "summary": "On September 9, 2025, Aqua's team allegedly rugged a Solana presale worth roughly $4.65M despite audits, partnerships and heavy credibility theatre.",
   "details": "The familiar pattern: build a trust wrapper, borrow legitimacy, pull liquidity, vanish. The scam's sophistication tends to live in its marketing, not its code.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0096/"
  },
  {
   "id": "exploit-0097",
   "title": "SwissBorg SOL Earn Breach",
   "date": "2025-09-08",
   "lossUsd": 41500000,
   "attackVector": "Access Control",
   "chain": "Solana",
   "sector": "Staking",
   "summary": "On September 8, 2025, a compromised Kiln integration led to about $41.5M in SOL losses from SwissBorg's SOL Earn product.",
   "details": "SwissBorg said the issue was isolated to the partner integration and covered users from treasury. Operationally that is a real difference, but from the user side it still feels like the platform's stack failed where it most needed not to.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/swissborg.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0097/"
  },
  {
   "id": "exploit-0099",
   "title": "Venus Protocol Delegate Phish",
   "date": "2025-09-02",
   "lossUsd": 13000000,
   "attackVector": "Phishing",
   "chain": "BNB Chain",
   "sector": "Borrowing",
   "summary": "On September 2, 2025, a malicious delegation flow let an attacker borrow and redeem roughly $13M on a user's behalf -- though the funds were later recovered.",
   "details": "The protocol itself was not mathematically broken; the permission model around the victim account was. That is increasingly common: not code failure exactly, but trust granted to the wrong address or contract.",
   "blockData": [
    {
     "label": "Exploit tx",
     "url": "https://bscscan.com/tx/0x75eee705a234bf047050140197aeb9616418435688cfed4d072be75fcb9be0e2"
    }
   ],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0099/"
  },
  {
   "id": "exploit-0098",
   "title": "Bunni v4 Hooks Liquidity Drain",
   "date": "2025-09-02",
   "lossUsd": 8400000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "AMM",
   "summary": "On September 2, 2025, Bunni's custom v4 hook logic was exploited for about $8.4M across Ethereum and Unichain.",
   "details": "Uniswap v4 lets builders get creative. Creativity is not always the same thing as safety. Bunni's rebalancing and share-accounting logic could be pushed into states that credited more value than it should have.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0098/"
  },
  {
   "id": "exploit-0100",
   "title": "Better Bank Bonus-Mint Exploit",
   "date": "2025-08-26",
   "lossUsd": 5000000,
   "attackVector": "Other",
   "chain": "PulseChain",
   "sector": "Borrowing",
   "summary": "On August 26, 2025, Better Bank lost about $5M after an attacker abused a bonus-mint path tied to its Favor / Esteem mechanics.",
   "details": "The attacker found a route where the protocol rewarded itself into insolvency. Once a contract can be induced to create more redeemable value than should exist, the rest is just path optimisation.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0100/"
  },
  {
   "id": "exploit-0101",
   "title": "Phishing: 783 BTC Drained",
   "date": "2025-08-19",
   "lossUsd": 91000000,
   "attackVector": "Phishing",
   "chain": "Bitcoin",
   "sector": "Wallet",
   "summary": "On August 19, 2025, a victim lost 783 BTC -- roughly $91M -- in a high-touch support-impersonation theft.",
   "details": "This was not a smart-contract exploit but a trust exploit. The attacker posed as support staff, won access, and then started the slow hygiene of laundering. In cash terms, social engineering is still one of the industry's strongest recurring primitives.",
   "blockData": [],
   "links": [
    {
     "label": "ZachXBT thread",
     "url": "https://x.com/zachxbt/status/1958583129356345414"
    }
   ],
   "logo": "/media/coins/btc.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0101/"
  },
  {
   "id": "exploit-0102",
   "title": "BtcTurk Hack",
   "date": "2025-08-14",
   "lossUsd": 48000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On August 14, 2025, BtcTurk suffered a roughly $48M hot-wallet breach across several chains.",
   "details": "This was another exchange hot-wallet event: assets drained, emergency measures triggered, assurances about cold storage made after the fact.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/btcturk.png",
   "article": "btcturk-hack-halts-exchange-services",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0102/"
  },
  {
   "id": "exploit-0103",
   "title": "Odin.fun Exploit",
   "date": "2025-08-12",
   "lossUsd": 7000000,
   "attackVector": "Other",
   "chain": "Bitcoin",
   "sector": "AMM",
   "summary": "On August 12, 2025, Bitcoin launchpad Odin.fun lost about 58.2 BTC, roughly $7M, after liquidity manipulation in its AMM tool.",
   "details": "Spoofed or cheaply inserted assets distorted the AMM's assumptions, letting the attacker walk out with real BTC while the accounting insisted the pool was behaving normally enough.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/odinfun.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0103/"
  },
  {
   "id": "exploit-0104",
   "title": "Phishing USDT Theft",
   "date": "2025-08-06",
   "lossUsd": 3050000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "Wallet",
   "summary": "On August 6, 2025, a victim was tricked into signing an approval and lost about $3.05M in USDT.",
   "details": "The simplest scams remain brutally effective. The attacker got approval, moved fast, and routed the funds away before the victim could react.",
   "blockData": [],
   "links": [],
   "logo": "/media/coins/usdt.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0104/"
  },
  {
   "id": "exploit-0105",
   "title": "CrediX Exploit",
   "date": "2025-08-04",
   "lossUsd": 4500000,
   "attackVector": "Access Control",
   "chain": "Sonic",
   "sector": "Borrowing",
   "summary": "On August 4, 2025, CrediX on Sonic lost around $4.5M after misassigned admin roles let attackers mint unbacked assets and drain pools.",
   "details": "Access-control failures do not need technical glamour to be expensive. The wrong permissions existed, the attacker used them, the pool paid.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0105/"
  },
  {
   "id": "exploit-0106",
   "title": "WOO X Phishing Breach",
   "date": "2025-07-24",
   "lossUsd": 14000000,
   "attackVector": "Phishing",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On July 24, 2025, WOO X lost about $14M after a targeted phishing attack hit a team member's device and opened the way to account drains.",
   "details": "Infrastructure can be excellent and still be undone by the human endpoint sitting in front of it.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/woox.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0106/"
  },
  {
   "id": "exploit-0107",
   "title": "CoinDCX Breach",
   "date": "2025-07-20",
   "lossUsd": 44000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On July 20, 2025, CoinDCX lost roughly $44M after attackers compromised an internal liquidity account.",
   "details": "Server-side or key-side compromise remains one of the cleanest paths to very large exchange losses. Once the attacker is inside the liquidity machinery, chain-level sophistication is optional.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/coindcx.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0107/"
  },
  {
   "id": "exploit-0108",
   "title": "BigONE Exchange Hack",
   "date": "2025-07-16",
   "lossUsd": 28000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On July 16, 2025, BigONE lost around $28M in a hot-wallet breach spanning Bitcoin, Ethereum, Tron and Solana.",
   "details": "Another custodial wallet failure, another multi-chain scramble, another assurance that reimbursements will follow.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/bigone.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0108/"
  },
  {
   "id": "exploit-0109",
   "title": "Arcadia Finance Exploit",
   "date": "2025-07-15",
   "lossUsd": 2500000,
   "attackVector": "Other",
   "chain": "Base",
   "sector": "Rebalancing",
   "summary": "On July 15, 2025, Arcadia lost about $2.5M on Base after a router validation flaw let attackers smuggle malicious calls through rebalance logic.",
   "details": "The protocol executed instructions it should never have trusted. That is often the heart of these router-style exploits.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/arcadia.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0109/"
  },
  {
   "id": "exploit-0110",
   "title": "GMX Exploit",
   "date": "2025-07-09",
   "lossUsd": 42000000,
   "attackVector": "Other",
   "chain": "Arbitrum",
   "sector": "Perps",
   "summary": "On July 9, 2025, GMX was exploited for about $42M on Arbitrum. The attacker later returned the funds after accepting a $5M white-hat bounty.",
   "details": "The exploit targeted GMX's older vault logic. After a public bounty offer of 10%, the attacker returned the stolen funds, making this one of the larger successful white-hat recoveries. Recovery does not erase the underlying issue, but it stopped the headline from becoming even worse.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-gmx-hack-july-2025"
    }
   ],
   "logo": "/media/brands/gmx.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0110/"
  },
  {
   "id": "exploit-0111",
   "title": "Resupply Exploit",
   "date": "2025-06-26",
   "lossUsd": 9500000,
   "attackVector": "Oracle Manipulation",
   "chain": "Ethereum",
   "sector": "Borrowing",
   "summary": "On June 26, 2025, Resupply lost about $9.5M after an oracle manipulation attack let the attacker borrow against inflated collateral.",
   "details": "Again: bad number in, bad debt out.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/resupply.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0111/"
  },
  {
   "id": "exploit-0112",
   "title": "Nobitex Hack",
   "date": "2025-06-18",
   "lossUsd": 82000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On June 18, 2025, Iranian exchange Nobitex was hit for about $82M in a major hot-wallet compromise.",
   "details": "Large centralised exchanges remain giant, tempting concentrations of key risk. Nobitex joined the long and unhappy list. The breach was later analysed by Chainalysis and TRM Labs, the latter noting that leaked source code revealed structural weaknesses in the exchange's infrastructure.",
   "blockData": [],
   "links": [
    {
     "label": "Chainalysis analysis",
     "url": "https://www.chainalysis.com/blog/nobitex-iranian-exchange-exploit-june-2025/"
    },
    {
     "label": "TRM Labs investigation",
     "url": "https://www.trmlabs.com/resources/blog/inside-the-nobitex-breach-what-the-leaked-source-code-reveals-about-irans-crypto-infrastructure"
    },
    {
     "label": "Halborn post-mortem",
     "url": "https://www.halborn.com/blog/post/explained-the-nobitex-hack-june-2025"
    }
   ],
   "logo": "/media/brands/nobitex.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0112/"
  },
  {
   "id": "exploit-0113",
   "title": "AlexLab Exploit",
   "date": "2025-06-06",
   "lossUsd": 16100000,
   "attackVector": "Access Control",
   "chain": "Stacks",
   "sector": "DeFi",
   "summary": "On June 6, 2025, AlexLab on Stacks lost around $16.1M after private keys were compromised, allowing the attacker to drain protocol funds.",
   "details": "Protocol logic was secondary here. Once keys are gone, user-facing assurances tend to follow them. AlexLab later committed to reimbursing affected users and published a detailed breakdown of losses.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-alex-protocol-hack-june-2025"
    },
    {
     "label": "Rekt News",
     "url": "https://rekt.news/alexlab-rekt2"
    }
   ],
   "logo": "/media/brands/alexlab.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0113/"
  },
  {
   "id": "exploit-0114",
   "title": "Nervos ForceBridge Exploit",
   "date": "2025-06-02",
   "lossUsd": 3700000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Bridge",
   "summary": "On June 2, 2025, Nervos's ForceBridge lost about $3.7M after flawed cross-chain validation let attackers mint synthetic assets and dump them.",
   "details": "Bridge validation is the whole game. When it is wrong, the bridge stops being a bridge and turns into a mint.",
   "blockData": [],
   "links": [],
   "logo": "/media/brands/nervos.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0114/"
  },
  {
   "id": "exploit-0115",
   "title": "Cork Protocol wstETH Exploit",
   "date": "2025-05-28",
   "lossUsd": 12000000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "Yield",
   "summary": "On May 28, 2025, Cork Protocol lost about $12M after a flaw around wrapped staking asset exchange-rate logic was abused via a Uniswap v4 hook vulnerability.",
   "details": "Counterfeit or distorted pricing inside wrapped-asset accounting is a reliable way to make real collateral vanish. Dedaub's analysis highlighted this as a critical lesson in Uniswap v4 hook security, given that Cork was an a16z-backed project.",
   "blockData": [],
   "links": [
    {
     "label": "Cork official post-mortem",
     "url": "https://www.cork.tech/blog/post-mortem"
    },
    {
     "label": "Dedaub analysis",
     "url": "https://dedaub.com/blog/the-11m-cork-protocol-hack-a-critical-lesson-in-uniswap-v4-hook-security/"
    },
    {
     "label": "CertiK incident analysis",
     "url": "https://www.certik.com/resources/blog/cork-protocol-incident-analysis"
    },
    {
     "label": "Halborn post-mortem",
     "url": "https://www.halborn.com/blog/post/explained-the-cork-protocol-hack-may-2025"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0115/"
  },
  {
   "id": "exploit-0116",
   "title": "Cetus Protocol Exploit",
   "date": "2025-05-22",
   "lossUsd": 260000000,
   "attackVector": "Other",
   "chain": "Sui",
   "sector": "AMM",
   "summary": "On May 22, 2025, Cetus Protocol on Sui was hit for roughly $260M in a devastating AMM manipulation exploit that sent connected token prices down over 90%.",
   "details": "Cetus was one of the year's defining DeFi disasters. By injecting or exploiting false value relationships inside the pool design, the attacker pulled real assets out en masse and left prices across connected tokens shattered. Multiple security firms published detailed root-cause analyses. The Sui ecosystem ultimately coordinated a partial freeze and recovery effort, but the scale of the damage was immense.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-cetus-hack-may-2025"
    },
    {
     "label": "Cyfrin root-cause analysis",
     "url": "https://www.cyfrin.io/blog/inside-the-223m-cetus-exploit-root-cause-and-impact-analysis"
    },
    {
     "label": "Elliptic analysis",
     "url": "https://www.elliptic.co/blog/cetus-protocol-hacked-for-more-than-200-million"
    }
   ],
   "logo": "/media/brands/cetus.png",
   "article": "cetus-exploit",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0116/"
  },
  {
   "id": "exploit-0117",
   "title": "Bitcoin Theft",
   "date": "2025-04-27",
   "lossUsd": 330700000,
   "attackVector": "Phishing",
   "chain": "Bitcoin",
   "sector": "Wallet",
   "summary": "On April 27, 2025, 3,520 BTC -- about $330.7M -- was stolen from an elderly US victim in a social-engineering attack, then funnelled through instant exchanges into Monero, briefly spiking XMR's price.",
   "details": "This was one of those rare incidents large enough to shake adjacent markets. Laundering pressure into XMR caused a visible price reaction. ZachXBT traced the theft and identified the victim as an elderly person in the US targeted through social engineering. Roughly $7M was later frozen with Binance's help, but the vast majority was successfully laundered through privacy rails.",
   "blockData": [],
   "links": [],
   "logo": "/media/coins/btc.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0117/"
  },
  {
   "id": "exploit-0118",
   "title": "Loopscale Hack",
   "date": "2025-04-26",
   "lossUsd": 5800000,
   "attackVector": "Oracle Manipulation",
   "chain": "Solana",
   "sector": "Borrowing",
   "summary": "On April 26, 2025, Loopscale on Solana lost about $5.8M after a pricing bug around RateX PT collateral let attackers borrow against inflated value, just two weeks after launch.",
   "details": "Oracle and collateral design failures are often boring on paper and expensive in practice. This was both.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn post-mortem",
     "url": "https://www.halborn.com/blog/post/explained-the-loopscale-hack-april-2025"
    }
   ],
   "logo": "/media/brands/loopscale.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0118/"
  },
  {
   "id": "exploit-0119",
   "title": "ZKsync Airdrop Contract Exploit",
   "date": "2025-04-15",
   "lossUsd": 5000000,
   "attackVector": "Access Control",
   "chain": "ZKsync",
   "sector": "Airdrop",
   "summary": "On April 15, 2025, a compromised admin wallet swept around $5M in unclaimed ZK tokens from an airdrop contract.",
   "details": "The exploit path was boring but effective: privileged function, wrong hands, real tokens gone. The ZK token price dropped sharply on the news before partially recovering.",
   "blockData": [
    {
     "label": "Transaction",
     "url": "https://zksync.blockscout.com/tx/0x14b120ff26e8d678fdaa26eef81cf166cb8bc1a20e9bdef6a02fd2af2ee0071e"
    }
   ],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-zksync-hack-april-2025"
    }
   ],
   "logo": "/media/brands/zksync.png",
   "article": "zksync-hack-5-million-in-controlled-return",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0119/"
  },
  {
   "id": "exploit-0120",
   "title": "KiloEx Oracle Manipulation",
   "date": "2025-04-14",
   "lossUsd": 7000000,
   "attackVector": "Oracle Manipulation",
   "chain": "Ethereum",
   "sector": "Perps",
   "summary": "On April 14, 2025, KiloEx lost about $7M across multiple chains after forged or unauthorised oracle inputs were used to juice leveraged PnL.",
   "details": "The attacker manipulated how the price feed was trusted and then harvested the obvious economic imbalance. Once again, if your oracle lies and your protocol believes it, the attacker just has to submit the paperwork.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0120/"
  },
  {
   "id": "exploit-0121",
   "title": "UPCX ProxyAdmin Take-Over",
   "date": "2025-04-01",
   "lossUsd": 70000000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "Token",
   "summary": "On April 1, 2025, a hijacked ProxyAdmin let attackers insert malicious logic and drain about $70M worth of UPC tokens.",
   "details": "Proxy upgrade power is effectively absolute power. Once lost, every downstream assurance becomes theatre.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-upcx-hack-april-2025"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0121/"
  },
  {
   "id": "exploit-0122",
   "title": "Abracadabra GMX-Cauldron Bug",
   "date": "2025-03-25",
   "lossUsd": 13000000,
   "attackVector": "Other",
   "chain": "Arbitrum",
   "sector": "Borrowing",
   "summary": "On March 25, 2025, Abracadabra lost about $13M after a bookkeeping flaw let an attacker self-liquidate, re-borrow and recycle collateral in cauldrons tied to GMX liquidity tokens.",
   "details": "This was accounting getting confused in exactly the way attackers pray for: debt gone from the books while the collateral was still in play. PeckShield flagged the exploit in real time and multiple security firms published detailed breakdowns.",
   "blockData": [
    {
     "label": "Exploit tx",
     "url": "https://arbiscan.io/tx/0xed17089aa6c57b7d5461209e853bdb56bc3460a91805e20d2590609a515ef0b0"
    },
    {
     "label": "Exploiter Address",
     "url": "https://arbiscan.io/address/0xaf9e33aa03caaa613c3ba4221f7ea3ee2ac38649"
    }
   ],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-abracadabra-money-hack-march-2025"
    },
    {
     "label": "Three Sigma exploit analysis",
     "url": "https://threesigma.xyz/blog/exploit/abracadabra-gmx-defi-exploit-explained"
    }
   ],
   "logo": "/media/brands/abracadabra.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0122/"
  },
  {
   "id": "exploit-0123",
   "title": "Zoth Logic-Contract Swap",
   "date": "2025-03-21",
   "lossUsd": 8320000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "RWA",
   "summary": "On March 21, 2025, leaked admin rights let attackers swap Zoth's implementation contract and drain around $8.32M from the RWA protocol.",
   "details": "Upgradeable systems are wonderful right up to the point someone else becomes the upgrader.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-zoth-hack-march-2025"
    },
    {
     "label": "Rekt News",
     "url": "https://rekt.news/zoth-rekt"
    },
    {
     "label": "QuillAudits analysis",
     "url": "https://www.quillaudits.com/blog/hack-analysis/zoth-loose-8.4m-dollar-due-to-access-control"
    }
   ],
   "logo": "/media/brands/zoth.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0123/"
  },
  {
   "id": "exploit-0124",
   "title": "1inch Fusion v1 Re-entrancy",
   "date": "2025-03-06",
   "lossUsd": 2600000,
   "attackVector": "Other",
   "chain": "Ethereum",
   "sector": "DEX Aggregation",
   "summary": "On March 6, 2025, a re-entrancy issue in 1inch Fusion v1's resolver contract let attackers repeatedly reuse approvals and drain roughly $2.6M.",
   "details": "Recursive control flow plus user-supplied values remains a classic way to manufacture losses out of otherwise respectable code. 1inch published an official statement confirming the vulnerability was in the resolver contract, not the core aggregation protocol.",
   "blockData": [
    {
     "label": "Exploit TX",
     "url": "https://etherscan.io/tx/0xb5c94efa0c8fd8f5c8cc2826e374a99620b01061d395b59b8f45dddc9fce1c60"
    }
   ],
   "links": [
    {
     "label": "1inch official statement",
     "url": "https://blog.1inch.com/vulnerability-discovered-in-resolver-contract/"
    },
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-1inch-hack-march-2025"
    },
    {
     "label": "Rekt News",
     "url": "https://rekt.news/1inch-rekt"
    }
   ],
   "logo": "/media/brands/1inch.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0124/"
  },
  {
   "id": "exploit-0125",
   "title": "Suji Yan Wallet Hack",
   "date": "2025-02-27",
   "lossUsd": 4000000,
   "attackVector": "Phishing",
   "chain": "Ethereum",
   "sector": "Wallet",
   "summary": "On February 27, 2025, Mask Network founder Suji Yan lost roughly $4M after what appeared to be an offline phone or wallet compromise.",
   "details": "No protocol bug, just a personal-security disaster with on-chain consequences.",
   "blockData": [],
   "links": [],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0125/"
  },
  {
   "id": "exploit-0126",
   "title": "Infini Insider Drain",
   "date": "2025-02-24",
   "lossUsd": 50000000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "Treasury",
   "summary": "On February 24, 2025, Infini lost about $50M after retained administrative privileges were allegedly used to drain funds from the stablecoin payment card issuer.",
   "details": "Insider or insider-style privilege abuse tends to be especially poisonous because it destroys both the money and the story the team can tell about how secure the system was. Infini offered a bounty for return of funds, but the damage to trust was already done.",
   "blockData": [
    {
     "label": "Exploiter Wallet",
     "url": "https://etherscan.io/address/0x3ac96134fb0e42a52d33045aee50b89790f05ed0"
    }
   ],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-infini-hack-february-2025"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0126/"
  },
  {
   "id": "exploit-0127",
   "title": "Bybit Multisig Cold-Wallet Hack",
   "date": "2025-02-21",
   "lossUsd": 1400000000,
   "attackVector": "Access Control",
   "chain": "Ethereum",
   "sector": "Exchange",
   "summary": "On February 21, 2025, Bybit suffered the largest single crypto theft on record after a phished multisig flow led to $1.4B in ETH being drained. The FBI attributed the attack to North Korea's Lazarus Group (TraderTraitor).",
   "details": "The key lesson was brutal and simple: a multisig is only as safe as the signing environment and the humans using it. The interface showed one thing, the underlying permission change did another, and the largest single crypto theft on record followed. The FBI publicly attributed the hack to the DPRK-linked threat actor known as TraderTraitor (Lazarus Group / APT38) and issued a formal PSA. Bybit published a detailed incident timeline and committed to full transparency throughout the recovery process.",
   "blockData": [
    {
     "label": "Withdraw TX",
     "url": "https://etherscan.io/tx/0xb61413c495fdad6114a7aa863a00b2e3c28945979a10885b12b30316ea9f072c"
    }
   ],
   "links": [
    {
     "label": "FBI PSA - Lazarus attribution",
     "url": "https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack"
    },
    {
     "label": "Bybit incident timeline",
     "url": "https://learn.bybit.com/en/this-week-in-bybit/bybit-security-incident-timeline"
    },
    {
     "label": "Rekt News",
     "url": "https://rekt.news/bybit-rekt"
    }
   ],
   "logo": "/media/brands/bybit.png",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0127/"
  },
  {
   "id": "exploit-0128",
   "title": "LIBRA Rug Pull",
   "date": "2025-02-16",
   "lossUsd": 286000000,
   "attackVector": "Rugpull",
   "chain": "Solana",
   "sector": "Token",
   "summary": "On February 16, 2025, LIBRA imploded in what looked far more like insider distribution and rug mechanics than some tragic accident, wiping out roughly $286M. The incident sparked a political scandal in Argentina.",
   "details": "When memecoin theatrics overlap with politics, the post-mortem gets noisy fast. The money, unfortunately, was quieter and more final. TRM Labs published a detailed fund-tracing analysis, and the incident eventually warranted its own Wikipedia article due to the political dimensions involved.",
   "blockData": [],
   "links": [
    {
     "label": "TRM Labs tracing analysis",
     "url": "https://www.trmlabs.com/resources/blog/the-libra-affair-tracking-the-memecoin-that-launched-a-scandal-in-argentina"
    },
    {
     "label": "Rekt News",
     "url": "https://rekt.news/the-wolf-of-rug-street"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0128/"
  },
  {
   "id": "exploit-0129",
   "title": "zkLend Exploit",
   "date": "2025-02-12",
   "lossUsd": 9500000,
   "attackVector": "Other",
   "chain": "Starknet",
   "sector": "Borrowing",
   "summary": "On February 12, 2025, zkLend lost about $9.5M in a flash-loan exploit on Starknet. The attacker later attempted to launder through Railgun but funds were flagged and partially recovered.",
   "details": "The protocol still failed first. The partial recovery narrative is interesting, but it came after the money had already been stolen. BlockSec published a detailed post-mortem clarifying several misunderstandings about the attack mechanics.",
   "blockData": [
    {
     "label": "Ethereum Return Address",
     "url": "https://etherscan.io/address/0xCf31e1b97790afD681723fA1398c5eAd9f69B98C"
    }
   ],
   "links": [
    {
     "label": "zkLend official post-mortem",
     "url": "https://medium.com/zklend/zklend-security-incident-post-mortem-27d9abaf66f6"
    },
    {
     "label": "BlockSec detailed analysis",
     "url": "https://blocksec.com/blog/zklend-exploit-post-mortem-unraveling-the-details-and-clarifying-misunderstandings-of-the-10m-flash-loan-attack"
    },
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-zklend-hack-february-2025"
    }
   ],
   "article": "zklend-exploit",
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0129/"
  },
  {
   "id": "exploit-0130",
   "title": "DogWifTools Exploit",
   "date": "2025-01-28",
   "lossUsd": 10000000,
   "attackVector": "Other",
   "chain": "Multichain",
   "sector": "Tooling",
   "summary": "On January 28, 2025, DogWifTools users were hit in a roughly $10M supply-chain exploit that drained wallets through a compromised version of the Solana pump.fun trading tool.",
   "details": "When wallet-adjacent software is compromised, the distinction between application risk and wallet risk disappears immediately. It was a supply-chain attack in the strict sense: the tool itself was trojaned, so it exfiltrated private keys from the machines it was installed on.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-dogwiftools-hack-january-2025"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0130/"
  },
  {
   "id": "exploit-0131",
   "title": "Phemex Exploit",
   "date": "2025-01-23",
   "lossUsd": 37000000,
   "attackVector": "Access Control",
   "chain": "Multichain",
   "sector": "Exchange",
   "summary": "On January 23, 2025, Phemex lost about $37M amid a multi-chain hot-wallet breach. The exchange published a timeline and compensation plan shortly after.",
   "details": "Another exchange reminder that once the hot-wallet layer is compromised, attackers do not need deep protocol wizardry to do large damage fast. Phemex was relatively transparent in their response, publishing a detailed timeline and reassuring users with a compensation framework.",
   "blockData": [],
   "links": [
    {
     "label": "Halborn analysis",
     "url": "https://www.halborn.com/blog/post/explained-the-phemex-hack-january-2025"
    }
   ],
   "url": "https://yfarmx.com/tools/exploit-tracker/exploit-0131/"
  }
 ]
}