- USD value
- Unknown
Discover
Workspace
Yield Alpha
Founding Partner
Exclusive founding placement. Rankings independent.
Apply→Lending liquidations and protocol incidents from on-chain events and De.Fi reports.
On-chain liquidation events from Aave V3, Morpho, and Compound V3 on Ethereum, Base, and Arbitrum. USD values appear only when evidence exists.
50 shown
| When | Protocol | Collateral | Debt | USD | Tx |
|---|---|---|---|---|---|
4h ago Oct 6, 2026 | Aave V3 Base | 112,651 | 107,800 | Unknown | View↗ |
4h ago Oct 6, 2026 | Aave V3 Base | 30,676 | 34 | Unknown | View↗ |
5h ago Oct 6, 2026 | Aave V3 Base | 28,833 | 32 | Unknown | View↗ |
8h ago Oct 6, 2026 | Aave V3 Arbitrum | 7.2895 | 6.9737 | Unknown | View↗ |
9h ago Oct 6, 2026 | Aave V3 Base | 24,835 | 23,764,125,830 | Unknown | View↗ |
10h ago Oct 6, 2026 | Aave V3 Base | 61,049 | 68 | Unknown | View↗ |
11h ago Oct 6, 2026 | Aave V3 Base | 230 | 82,007 | Unknown | View↗ |
1d ago Oct 5, 2026 | Aave V3 Base | 574.8084 | 550.0559 | Unknown | View↗ |
1d ago Oct 4, 2026 | Aave V3 Base | 341,704 | 326,973,972,603 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Base | 103,544 | 32,219,880 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Base | 27,574 | 31 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Base | 50,567 | 48,390 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Base | 46,571 | 44,566 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 13,019,741,984 | 10,002,870,840 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 440,968 | 156,120,598 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 470,108 | 166,437,985 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 584,128,962,810 | 558,936 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 440,014 | 421,005 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 583,848 | 558,707 | Unknown | View↗ |
2d ago Oct 4, 2026 | Aave V3 Arbitrum | 936,983,943 | 896,635,352 | Unknown | View↗ |
2d ago Oct 3, 2026 | Aave V3 Arbitrum | 3,965 | 3.1575 | Unknown | View↗ |
3d ago Oct 3, 2026 | Aave V3 Ethereum | 16.1079 | 15.8231 | Unknown | View↗ |
3d ago Oct 3, 2026 | Aave V3 Ethereum | 21,624,231,506 | 3.5822 | Unknown | View↗ |
3d ago Oct 2, 2026 | Aave V3 Base | 302 | 108,810 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 1,537,895,566 | 3.9021 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Ethereum | 194.0785 | 2,476 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 141,777,152,857 | 363.0144 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 2,965 | 2,523 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Ethereum | 147.4028 | 1,959 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 11.7844 | 11.2778 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 37,494 | 42 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 958,065,373,038 | 916,808,969,414 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 554,035 | 530,178 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 583,137 | 558,027 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Arbitrum | 795,150 | 760,910 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 2,459 | 854,587 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 50,831 | 57 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 124,108 | 138 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Ethereum | 145.5082 | 1,959 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 418,637,575,022 | 1.2633 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 248 | 86,956 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 15,033 | 5,283,976 | Unknown | View↗ |
4d ago Oct 2, 2026 | Aave V3 Base | 25,647 | 9,069,171 | Unknown | View↗ |
4d ago Oct 1, 2026 | Aave V3 Base | 30,344 | 10,743,427 | Unknown | View↗ |
4d ago Oct 1, 2026 | Aave V3 Base | 367,473,427 | 318,275,695 | Unknown | View↗ |
5d ago Oct 1, 2026 | Aave V3 Ethereum | 808,710,281,725 | 2.4659 | Unknown | View↗ |
5d ago Oct 1, 2026 | Aave V3 Arbitrum | 1,077,429 | 2,794 | Unknown | View↗ |
5d ago Oct 1, 2026 | Aave V3 Arbitrum | 24,046,561,018 | 4,428 | Unknown | View↗ |
5d ago Oct 1, 2026 | Aave V3 Arbitrum | 17,022,570 | 219,814,553,176 | Unknown | View↗ |
5d ago Oct 1, 2026 | Aave V3 Arbitrum | 148,716,013 | 1.9204 | Unknown | View↗ |
Exploit and incident reports from De.Fi. Yield.ly does not verify incident severity or completeness.
50 shown
Impact
Quick Summary On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum. Details of the Exploit The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d). Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched. Block Data Reference Target Adapter Contract: 0xd1895f2019c2152fc2b9022d57f19198c4cfcabc Owner Safe Address (3-of-7): 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4 Attacker Deployer Address: 0x0B5126e1bc27C0de77e02e97945760A674EdB034 Attacker Whitelisted Contract: 0xcdfe91301356da873562ef513828a60dba1f569d Fund Destination Address: 0xC73448432a05deeA5Ea18a07D3b5d9ccf6297f8D
Impact
Quick Summary On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions. Details of the Exploit The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router. Block Data Reference Attack Transaction Hash: 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9 Attacker Address: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F Vulnerable Contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8
Impact
Quick Summary On October 1, 2026, cross-chain protocol NEAR Intents was exploited for approximately $3,8 million following a hot wallet drain on BNB Smart Chain caused by an integration bug in its Omni bridge infrastructure. On-chain analysis linked the attacker to North Korea's Lazarus Group, while the protocol team patched the flaw and pledged full user reimbursement. Details of the Exploit The attack stemmed from an integration logic flaw between NEAR Intents smart contracts and its Omni deposit/withdrawal layer on BNB Smart Chain, allowing the attacker to execute unauthorized hot wallet withdrawals. The attacker extracted ~$3.865M on BSC, routed a portion toward KuCoin, bridged funds to Ethereum, and executed seven Chainflip swaps to acquire ~33.7 BTC (~$2.9M), which remains parked across four unspent Bitcoin addresses. On-chain tracking confirmed the attacker interacted with known Lazarus Group infrastructure (0x098B7...E2f96). In response, NEAR Intents patched the contract-side flaw, temporarily suspended Omni bridge operations across 11 chains, and guaranteed 100% user compensation from protocol reserves. Block Data Reference BSC Attack Hashes: 0x9fe58e031f73bbd880c782bc9e7446bcda32cadb304a729209871a4a81856c4c 0x0381265d6a1bb09de899f49f410a8b907cd548358a7e3c91076c3a52656b8220 0x69d1c68c7e961a0199d3c9f3b6a31cb168ed775ef34b51a42762253ac1efcceb 0x9c10b967da0c85631ec105e3b322c0a851fcd01b69ff390ff58f860e5cce003a
Impact
Quick Summary On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations. Details of the Exploit The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time. The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Attacker Address: 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a Vulnerable Contract: 0x52272524a22f941f5489c1233732797314bb054b
Impact
Quick Summary On September 29, 2026, the FastSwap protocol on BNB Smart Chain was exploited in an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $92,600 USD. Details of the Exploit An attacker executed a malicious transaction targeting the FIST token and FastSwap smart contracts (0xc9882def23bc42d53895b8361d0b1edc7570bc6a) on BNB Smart Chain. The exploit allowed the attacker to manipulate protocol contracts and drain liquidity pools, extracting ~$92.6K in value within a single transaction. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Target Token / Contract: 0xc9882def23bc42d53895b8361d0b1edc7570bc6a
Impact
Quick Summary On September 26–27, 2026, scammers deployed a fake OP Stack Layer 2 network impersonating the unreleased GIWA Mainnet (Chain ID 9134) and set up a fraudulent bridge. 1,335 user addresses deposited 767.65 ETH into the fake bridge to trade on DYORSWAP, allowing the scammers to extract 766.25 ETH (~$2.0 million USD) on Ethereum. Details of the Exploit The incident was a fake infrastructure scam rather than a smart contract flaw in DYORSWAP's protocols. Scammers configured a malicious network using GIWA's official Chain ID (9134) alongside a fake bridge and OP Stack batcher. When traders connected to the fake RPC and deposited ETH to trade on DYORSWAP, the malicious bridge contract captured the L1 funds. The scammers drained 766.25 ETH at Ethereum block 26,067,309. DYORSWAP confirmed its core contracts were safe, published a claims collection form, and distributed over 200 ETH from its treasury to compensate affected users while tracing the scammers' funding sources.
Impact
Quick Summary On September 24, 2026, crypto casino and sportsbook platform Duelbits suffered a multi-chain hot wallet compromise resulting in estimated total losses of $4.9M to $7.0M across Ethereum, BNB Chain, Tron, Bitcoin, and Solana. The platform took its services offline to investigate and refill operational hot wallets while user cold storage remained unaffected. Details of the Exploit The attack was executed via a private key compromise targeting Duelbits' operational hot wallets across five blockchains. On EVM chains, the attacker extracted 836 ETH, 1.146M USDT, 209 BNB, 96.8K USDC, 31.5K DAI, and 12.4B SHIB, alongside 8.1 BTC on Bitcoin and 192K TRX on Tron. The attacker routed the stolen multi-chain assets through swap protocols and cross-chain bridges, converting the proceeds into Ether and consolidating approximately 2,234.6 ETH (~$6.0M) into a single destination Ethereum address. Duelbits confirmed the hot wallet breach and suspended operations pending system remediation and hot wallet refilling. Block Data Reference Attacker EVM Address 1: 0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76 Attacker EVM Address 2: 0x6761c9b15815f4051773EDe39B42B95bdDB3EF1c Attacker Bitcoin Address: bc1qhtu84kz3y94lvgl2t05zk84tqh57grvd82zvcl Attacker Tron Address: TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK Attacker Solana Address: A3EBrhMBEGzcPgmbwywSPhW39G6PFGrorU8ib99T6yKw
Impact
Quick Summary On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses. Details of the Exploit The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved. An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts.
Impact
Quick Summary On September 24, 2026, centralized exchange Bitget suffered a major infrastructure breach resulting in ~$351.6 million stolen from its hot and warm wallet layers. Bitget paused withdrawals while confirming its cold wallets remained secure and stating that its $464M+ User Protection Fund will fully reimburse user losses. Details of the Exploit The attacker penetrated Bitget's core wallet backend infrastructure and spoofed internal transaction data to trigger authorized withdrawals across multiple blockchains without compromising private keys. Stolen assets included ETH, XRP, USDT, USDC, AVAX, and BNB. On EVM chains, the attacker converted most of the stolen proceeds into 67,982 ETH (~$183 million). On-chain analysis and VPN traffic patterns linked the attack to North Korea's Lazarus Group (specifically the TraderTraitor subgroup) through bridged funds connected to the earlier AFX Trade exploit. Bitget contained the breach, stopped further unauthorized transfers, and is preparing system recovery before resuming withdrawals.
Impact
Quick Summary On September 23–24, 2026, Meter.io suffered a dual consensus and bridge exploit after an attacker leveraged a block validation flaw on Meter mainnet and exploited the Meter Passport bridge on BNB Chain, resulting in ~$2.3 million in unbacked wMTRG minted and partially dumped on PancakeSwap. Details of the Exploit On September 23 at 21:14 UTC, an attacker exploited a block validation flaw on the Meter mainnet consensus layer to mint unbacked MTR and MTRG tokens. The attacker then used the Meter Passport bridge on BNB Chain across two main transactions to mint approximately $2.3 million in unbacked wrapped MTRG (wMTRG), dumping a portion into PancakeSwap liquidity pools and bridging funds out. Meter paused both mainnet and bridge operations, invalidated transactions post-block 100731417, and issued a 72-hour whitehat bounty offer of 10% for the return of funds. Block Data Reference Attacker Addresses: 0xee2eeeed4ed8580669ed924abeb49f27f7d0bd65 0x44cf94496091150865e192a86c07b90a9760b43d 0x7db6ac6Fa3c8aa2c6FB9BdCD4800e8BAacDd2EE8 Abused Token Contract (BSC): 0xBd2949F67DcdC549c6Ebe98696449Fa79D988A9F Sample Exploit Transaction (BSC): 0x2745dd5121eb03d1979cf229f432a422137942ede186d9fa0129a2f83401eeef Bounty Return Address: 0xB980Ff36A99C0C3B408279E025d8E2DA7eF65105
Impact
Quick Summary On September 22, 2026, Cosmos ecosystem DEX Astroport suffered a security breach on the Neutron chain that exposed protocol admin controls. Validators halted Neutron and Cosmos Hub to coordinate an emergency response, intercepting approximately 1.396 million ATOM (~$2.53 million USD) before the attacker could cash out. Details of the Exploit The attacker compromised admin privileges for Astroport contracts on Neutron, placing liquidity across connected pools at risk. The attacker converted stolen funds into ATOM and initiated a streaming swap of 200,000 ATOM to ETH via THORChain. Only 15.5% of the swap filled (19.92 ETH) before Cosmos Hub halted at block 33,086,740. Cosmos Hub validators deployed a binary upgrade that transferred 1,227,121 ATOM from the attacker's account to a recovery multisig and added an ante-handler to block the attacker's key from signing future transactions. An additional 168,990 ATOM refund remains queued on THORChain, requiring a secondary sweep once GAIA chain processing unhalts. Astroport contracts on Terra were unaffected after their admin connection to Neutron was severed. Block Data Reference Attacker Cosmos Address: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n
Impact
Quick Summary On September 21, 2026, the RWC token protocol on BNB Smart Chain was hit by an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $109,000 USD. Details of the Exploit An attacker executed a malicious transaction targeting the RWC contract on BNB Smart Chain, exploiting a smart contract vulnerability to drain funds from the project's liquidity or protocol pools. Security monitoring systems flagged the atomic execution trace after ~$109,000 in value was extracted. Block Data Reference Attack Transaction Hash: 0x9c919da34696425913f32587f00d2838031a8726a2c5ddfa39e33a45b36e6427
Impact
Quick Summary On September 21, 2026, the Internet Token protocol on Base was exploited for 5.85 WETH and 764 million INT after an attacker leveraged an unvalidated Uniswap V3 pool callback parameter to arbitrarily mint ~925 million INT tokens. Details of the Exploit The vulnerability was present in INT's LiquidityUnifier contract (0x837d...), which held MINTER_ROLE rights and exposed an unvalidated swapV3(token, pool) function. The function only validated that the passed pool parameter contained bytecode and that its token0() and token1() getters returned the INT token address. The attacker deployed a malicious contract returning INT for both token endpoints, causing swapV3 to invoke pool.swap(). This callback re-entered uniswapV3SwapCallback and minted an arbitrary amount of INT tokens directly to the fake pool. The attacker routed the minted tokens through a Convertor contract round-trip to bypass validateSupply sanity checks, created ~925 million INT, dumped a portion into the official INT/WETH V3 pool for 5.85 WETH, and kept the remaining ~764 million INT. Block Data Reference Attack Transaction Hash: 0xed62bb27bd1058d3d7cc93d55421d6d0001ced8cb4529b02773f5126a4edb08b Attacker Address: 0x5f7ce6395818857ac20730dc990f614356d1ec68 Victim Contract: 0x837dbabc4f5fa78baf177597edbda09645822032
Impact
Quick Summary On September 19–20, 2026, an attacker used compromised SingularityNET bridge and NuNet deployer private keys to drain $FET and mint unauthorized supplies of $AGIX,$NTX, $WMTx, and $CGV on Ethereum. The attacker extracted ~$1.44M to $1.67M in liquid ETH before project teams paused bridges and revoked minting authorities. Details of the Exploit The exploit resulted from compromised private signing keys rather than smart contract logic bugs. On September 19, the attacker called conversionIn on Fetch.ai's TokenConversionManagerV3 using a stolen SingularityNET authorizer signature to drain 8.72M $FET (~$1.53M) and swap it for ETH. Minutes later, a compromised NuNet deployer account minted 408.53M $NTX to reach its 1 billion supply cap. On September 20, the attacker used the SingularityNET bridge authority to mint 260M $AGIX, 53.84M $WMTx, and ~500M$CGV. High slippage on low liquidity pools limited total extracted value to 546–649 ETH (~$1.44M–$1.67M), while token market prices collapsed by 65% to 99%. Affected protocols responded by pausing bridges, revoking signing authorities, and contacting exchanges to freeze funds. Block Data Reference Attacker Address: 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE NuNet Deployer Address: 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Fetch.ai Conversion Contract: 0xab424A430CC09864fA1277A38193111705ADF3A3
Impact
Quick Summary On September 17, 2026, Starknet money market Nostra Finance suffered an oracle price manipulation exploit resulting in ~$3.53 million in unauthorized borrows across ETH, STRK, USDC, USDT, WBTC, and DAIv1 against inflated NSTR collateral, forcing the protocol to pause all lending, borrowing, and liquidation operations. Details of the Exploit The attacker exploited Nostra Finance's collateral valuation oracle for NSTR by manipulating its underlying price pool on Ekubo DEX. The attacker withdrew existing liquidity around NSTR's real market price, seeded a decoy liquidity band at $99 per NSTR, and routed a $14.72 dust swap (190 NSTR) through the gap to artificially inflate the oracle price by 16,645x. Using just 294,177 NSTR collateral, normally worth ~$1,756, the attacker leveraged the inflated valuation to draw $3,531,922.97 in mixed assets across six borrowing legs. The attacker then bridged ~$1.93 million (234.57 ETH and 1.3M DAI) to Ethereum while leaving ~$1.55 million in assets on Starknet. Block Data Reference Starknet Attacker Contract: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 Ethereum Destination Address: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37
Impact
Quick Summary On September 16, 2026, an attacker executed a batched approval-drain sweep targeting holders of the Bonfire (BONFIRE) token on BNB Chain, resulting in a loss of approximately 66.08 WBNB (~$47.4K USD). T Details of the Exploit The attack was executed across two distinct phases within transaction 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f. In the harvesting phase, the attacking contract iterated through a pre-compiled list of 65 addresses that had standing approvals to 0x17e801.... Using transferFrom(), the contract pulled each victim's BONFIRE balance directly into the BONFIRE/WBNB liquidity pair. The contract then called swap() to route tokens out to a collector wallet (0x28E976Ea...), netting the inbound deposits against the outbound legs and steadily increasing the pair's token reserves without swapping for WBNB on each individual transfer. The decaying size of the pulled balances across the iterations indicates a script executing against victims ordered by remaining balance size. In the cash-out phase, the collector address approved the attacking contract and passed its accumulated ~4,576 BONFIRE back into the liquidity pool across two major sell swaps. These swaps extracted 33.223 WBNB and 32.857 WBNB respectively, totaling 66.08 WBNB, which was subsequently unwrapped to native BNB. Standard events such as SwapAndLiquify observed during the execution were simply Bonfire's automated liquidity tax mechanism firing as intended through its legacy PancakeSwap V1 router. The root vulnerability remains off-chain, stemming either from historical phishing campaigns or compromised keys associated with a legacy custom router contract. Block Data Reference Attack Transaction Hash: 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f Harvesting Contract: 0x17e801E17CeFC6334059189c178D4783830E03D3 Collector Address: 0x28E976Ea7b83553d6D1D45CE81334156A2632127
Impact
Quick Summary On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan. Details of the Exploit The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit. Block Data Reference On-Chain Key Addresses: Attacker Primary Address: 0x83381e7f7232775735169d72d237b858ffc36871 Target Strategy / Vault: 0xb8d6471ca573c92c7096ab8600347f6a9fe268a5 Exploit Contract 1: 0x875da4bd7b4a52a806a533b1cf6d6ff92365d2e6 Exploit Contract 2: 0x1c7eacef3630e764519e6ea2e8caa2bdb7d8b486
Impact
Quick Summary On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000. Details of the Exploit Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader.
Impact
Quick Summary On September 12, 2026, cross-chain swap protocol Chainflip suffered a memo-manipulation exploit on its Tron settlement layer, resulting in six unauthorized payouts totaling 736,442.17 USDT after an attacker attached custom memos to already-signed transactions to trigger duplicate refund payouts. Details of the Exploit Unlike other blockchains supported by Chainflip that pass swap instructions via dedicated contract functions, the protocol's Tron integration parses swap parameters directly from transaction memo fields. The attacker discovered a vulnerability allowing a custom memo to be appended to a Tron transaction that Chainflip validators had already signed. Chainflip's backend misread the altered memo as a new, separate swap instruction, classified it as failed, and automatically triggered a refund, effectively paying out against the same underlying deposit a second time. The attacker executed eight attempts over ~90 minutes in the early hours of Saturday, scaling up transaction sizes until six successful attempts extracted 736,442.17 USDT. Chainflip detected the incident after subsequent legitimate USDT payouts began failing due to drained vault reserves. Network operations were paused, a code fix was finalized, and operators committed to making all impacted users whole upon restart.
Impact
Quick Summary On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap. Details of the Exploit Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens. The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB. Block Data Reference Attack Transactions: Main Exploit: 0x29eb97259b5c8d1bbfe791ad5d7bdc981f538ac37c857cc30d6296b31f08afc5 Liquidation: 0x99c9969ab97f97b56766a9d75ec4f82a463bb8e7f9603eecc77b6bb57485d3ba
Impact
Quick Summary On September 9, 2026, a flaw in Nomic's custom forwarding mechanism allowed an attacker to double-spend nBTC and send ~39.84 unbacked nBTC vouchers (~$3.15M USD) to Osmosis, compromising roughly 36% of the backing behind Osmosis's Alloyed BTC (allBTC) token. Details of the Exploit The attacker exploited a vulnerability in Nomic's custom transaction forwarding system to double-spend nBTC and issue unbacked vouchers through the Inter-Blockchain Communication (IBC) protocol onto Osmosis. Because nBTC serves as a reserve component for Osmosis's unified Alloyed BTC pool, the forged vouchers left allBTC ~36% undercollateralized. Core IBC and Osmosis smart contracts were not directly breached. Following detection, Osmosis paused all minting, redemptions, inflows, and outflows for Nomic and Alloyed BTC. Osmosis validators then executed an emergency chain upgrade that successfully froze 22.65 BTC residing in the attacker's Osmosis account. Osmosis announced plans for a governance vote to seize the 22.65 frozen BTC and reimburse the remaining ~17.19 BTC shortfall from the community pool's BTC reserves to fully restore 1:1 backing.
Impact
Quick Summary On September 6–7, 2026, Bitcoin sidechain Liquid Network suffered an Elements consensus bug exploit resulting in losses of ~4,000 BTC (~$320 million USD), after unbacked L-BTC tokens were minted and redeemed for real Bitcoin, forcing operators to halt the network while whitehat negotiations proceed on-chain. Details of the Exploit The attacker exploited a consensus vulnerability in the underlying Elements software to forge ~4,000 unbacked L-BTC on Liquid without depositing collateral. These unbacked tokens were submitted through SideSwap's Peg-out Authorization Key service, prompting the Liquid Federation multisig to release ~3,996 real BTC from reserves—draining ~95% of backing. Federation operators subsequently halted the sidechain and exchanges paused L-BTC deposits. The attacker consolidated funds into a single Bitcoin address and left an OP_RETURN message offering to return most of the BTC once Blockstream deploys a network-wide patch. Block Data Reference Mainnet Attacker Address: bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte Federation Reserve Address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr
Impact
Quick Summary On September 4, 2026, lending protocol Notional Finance suffered an integer truncation and rounding error exploit on Ethereum, resulting in an estimated loss of $1.73 million in DAI and USDC, which the attacker swapped into 689.2 ETH and deposited into Tornado Cash. Details of the Exploit The exploit targeted Notional Finance's escrow and fCash accounting mechanism via a combination of a free-collateral calculation rounding error and an integer downcasting flaw. The attacker executed a two-step transaction sequence calling the mintfCashPair() function. In the first call (mintfCashPair(1)), a small liability (-1) was rounded down to 0 during the DAI-to-ETH free-collateral conversion due to a rounding precision flaw. In the second call (mintfCashPair(2^256 - 1)), the contract aggregated the account's liabilities in int256, producing a negative balance of $-2^{128}$. However, when validating free-collateral requirements, the valuation logic performed an unsafe downcast using uint128(balance.abs()). Because $2^{128}$ overflows a standard 128-bit unsigned integer, the massive liability truncated directly to zero. This bypassed the protocol's collateral checks entirely, allowing the attacker to draw down 69,257 DAI and 1,658,525 USDC from the escrow contract. The attacker then consolidated the stablecoins, converted them to 689.2 ETH, and routed the funds into Tornado Cash across multiple transactions. Block Data Reference Setup Transaction: 0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a
Impact
Quick Summary On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window. Details of the Exploit On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7. The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash. Block Data Reference Attacker Address: 0x003FE7359A4E03C85Ac2f521eC699ED84C7c5ccB
Impact
Quick Summary On August 31, 2026, Solana-based automated market maker Aquifer suffered an unverified CPI token program injection exploit resulting in approximately $2.5 million in total losses across 90+ attack transactions, after which the protocol issued an on-chain whitehat offer allowing the attacker to keep 20% if 80% of the stolen funds are returned by September 3, 2026. Details of the Exploit The exploit targeted Aquifer's swap function on Solana. When executing a token swap, the protocol allowed callers to supply an unverified, caller-controlled token program parameter (tokenProgramA) for the input token rather than enforcing a check against canonical SPL Token Program addresses. The attacker deployed a custom, dummy Solana program (DMBpPM...) designed to mirror SPL Token Transfer instruction formats and return a success signal without performing any actual token transfers. During the attack, the adversary initiated swap instructions passing USDC as the nominal input token parameter alongside their malicious token program, targeting real liquidity vaults such as HYPE. Aquifer invoked the malicious program via Cross-Program Invocation (CPI), which accepted the parameters and reported a successful transfer. Because Aquifer relied entirely on the CPI return status without verifying actual input token balance deltas, it released output tokens from its vaults without receiving any input tokens. The stolen assets were swapped to SOL, bridged to Ethereum, and converted into approximately 1,000.8 ETH. On the same day, Aquifer's upgrade authority published an on-chain message offering a 20% whitehat bounty if 80% of the funds are returned to designated recovery addresses. Block Data Reference On-Chain Key Addresses: Upgrade Authority: 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA Attacker Solana Address: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J Attacker Ethereum Address: 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 Solana Recovery Address: 8af8RnA
Impact
Quick Summary On August 30, 2026, decentralized lending protocol Tectonic on Cronos suffered an oracle price manipulation exploit resulting in estimated total losses between $75 million and $119.5 million, with approximately $6 million successfully bridged to Ethereum before Cronos network validators took the emergency step of halting the blockchain to freeze the remaining $68 million+ on-chain. Details of the Exploit The attacker targeted Tectonic's illiquid native token, TONIC, which had low trading volume but was accepted as loan collateral. By executing rapid buy orders on decentralized exchanges, the attacker artificially pumped TONIC's price by roughly 100 times in under 20 minutes. Tectonic's price oracle picked up this inflated price, allowing the attacker to post the pumped tokens as collateral and borrow tens of millions of dollars in stablecoins, WETH, and other liquid assets across the protocol's lending pools. Before protocol operators could intervene, the attacker managed to bridge approximately $6 million in stolen funds to Ethereum. To prevent the remaining stolen funds from exiting the ecosystem, Cronos network validators took the emergency step of halting block production on the entire Cronos blockchain. This action trapped over $68 million of the exploit proceeds in the attacker's Cronos addresses, while leaving Tectonic with massive bad debt and forcing a complete pause of its platform Block Data Reference Key Addresses: Attacker Address 1: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc Attacker Address 2: 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc Attacker Contract: 0x085f3115ca368aa262246d22f9476e1e2c87e8be
Impact
Quick Summary On August 28, 2026, crypto card provider Avici and three other card programs suffered an exploit totaling approximately $1.02 million (~10,000 SOL) due to an instruction verification flaw in their shared card contract managed by partner Rain. The attacker exploited the bug to grant themselves admin rights, drained card collateral pools, swapped the funds to USDC, bridged them to Ethereum, and deposited ~418 ETH into Tornado Cash. Details of the Exploit The vulnerability was present in an older Solana smart contract developed by card issuer Rain, which managed user card top-up balances independently from self-custodial user wallets. The exploit relied on an instruction index trick in Solana's Ed25519 signature verification precompile. The attacker submitted a transaction with two Ed25519 instructions: the first carried a genuine signature from a newly generated throwaway key, while the second instruction set its signature, public key, and message indexes to point back to the index of the first instruction. The precompile re-verified the valid signature from the first instruction rather than checking the admin key in the second instruction, leading the contract to incorrectly register two valid admin signatures and grant the attacker full admin privileges (AddCollateralAdmin). Using these elevated privileges, the attacker drained four card programs, collecting 10,000 SOL (~$1.02M USD). They converted the SOL to USDC on Solana, transferred the funds to Ethereum address 0x2cE21E4921d3Eb116526c3651Dac0257657338D5, swapped the proceeds into ~418 ETH, and routed the entire balance through Tornado Cash. Self-custodial Avici wallets were unaffected. Avici reported that $500,859.22 in card balances across 1,685 users was impacted, and confirmed that all affected users will receive full refunds. Block Data Reference Solana Attacker Address: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Ethereum Attacker Address: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5
Impact
Quick Summary On August 27, 2026, Moonwell’s MAMO lending market on Base was exploited through a combination of collateral-accounting manipulation and DEX oracle manipulation. The attacker deployed roughly $1.95 million in starting capital, inflated their collateral value to borrow over $11 million in mixed crypto assets, and extracted $8.73 million via Circle CCTP to Ethereum, leaving the protocol with around $9.13 million in bad debt. Details of the Exploit The attack began when the exploiter withdrew 800 ETH from Tornado Cash, swapped most of it into about $1.95 million USDC, and bridged those funds to Base to accumulate MAMO tokens. They first deposited 15 million MAMO into Moonwell to mint receipt tokens (mMAMO). Next, instead of using the normal deposit route, they transferred another 53.4 million MAMO directly into the mMAMO contract address. Because this direct transfer bypassed the protocol's minting function and supply caps, it artificially increased the underlying token backing behind every existing mMAMO share by nearly 3.7 times. Holding three-quarters of all receipt tokens, the attacker captured almost all of this sudden collateral equity boost. At the same time, the attacker used aggressive DEX trades across low-liquidity pools to inflate the market price of MAMO from around $0.01 to over $0.40. With both the share backing ratio and the oracle price drastically spiked, Moonwell valued the attacker’s collateral at over $22 million, allowing them to draw 18 separate loans totaling $11.03 million in WETH, cbBTC, USDC, and wstETH. The attacker quickly converted these assets, burned $8.73 million USDC through Circle's cross-chain bridge to Ethereum, and swapped it into DAI. Liquidators stepped in seconds after the final borrow and seized the attacker's remaining collateral shares, but the steep price drop left Moonwell with a net shortfall of roughly $9.13 million. Block Data Reference Key Addresses: Operational / Funds Destination Account: 0xD71dD9B6e6344
Impact
Quick Summary On August 23, 2026, fixed-rate lending provider Term Labs suffered a governance exploit affecting its Term Vaults (built on Yearn v3 vault infrastructure), resulting in the loss of approximately $8.5 million in digital assets (~2,843 ETH and ~1.68M USDC). Details of the Exploit The incident occurred not through a code bug or reentrancy flaw, but through the manipulation of vault governance rules enabled by low voter participation and float. The attacker initially funded with 2 ETH routed through Tornado Cash acquired sufficient voting influence to pass parameter changes as designed by the protocol's governance architecture. Once vault control was secured, the attacker executed a structured sequence of transactions that unraveled integrated positions across external lending protocols (including Aave and Morpho), unwinding staked ETH positions and draining approximately 2,843 ETH alongside 1.68 million USDC. The attacker subsequently swapped the stolen USDC for roughly 1.6 million DAI and consolidated the funds in wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Block Data Reference Key Attacker Address: 0xD5183d8BfC65a50863C62aF2538198A8288FFc13
Impact
Quick Summary On August 21–22, 2026, The Sandbox gaming platform experienced an exploit targeting its LayerZero-based Omnichain Fungible Token (OFT) bridge deployments on Base and BNB Smart Chain (BSC). By hijacking LayerZero delegate permissions via approveAndCall, the attacker minted massive quantities of unbacked SAND tokens on destination chains. The attacker then initiated cross-chain redemptions back to Ethereum L1, completely draining the ~14.75 million SAND (~14,753,431 SAND) backing escrow held in the Ethereum OFT adapter contract. Details of the Exploit The attack exploited a permission configuration flaw in the LayerZero OFT delegate settings for the SAND token on Base and BSC. By leveraging approveAndCall, the attacker hijacked the protocol's delegate permissions and issued unauthorized minting calls across 700+ transactions to 173 addresses, generating trillions of face-value unbacked SAND tokens on Base. While the majority of the unbacked L2 mints were hyper-inflated tokens isolated on destination chains, the attacker successfully submitted cross-chain redemption messages back to Ethereum mainnet. Between 00:32:11 and 01:22:11 UTC on August 22, the Ethereum OFT adapter escrow (0xac531eb26ca1d21b85126de8fb87e80e09002dcf) was drained from 14,769,723 SAND down to ~0.0056 SAND across 15 exit transactions (with ~14.1 million SAND transferred to a single EOA in 6 transactions). Total L1 supply remained unchanged at 3 billion SAND, but the mainnet bridge escrow backing L2 tokens was completely depleted (~14.75M SAND, representing <0.01% of total SAND supply). Block Data Reference Ethereum SAND Token / OFT Contract: 0x3845badade8e6dff049820680d1f14bd3903a5d0 Ethereum OFT Adapter Escrow: 0xac531eb26ca1d21b85126de8fb87e80e09002dcf
Impact
Quick Summary On August 19, 2026, cross-chain liquidity network Maya Protocol was exploited for approximately $1.7 million in assets (including 20.83 BTC valued at ~$1.4M), leading to an overall liquidity pool valuation drop of ~$11 million. Details of the Exploit The exploit targeted Trade Accounts (ported from THORChain in mid-2025) that were never integrated into Maya's solvency checker (vault.Coins) or outbound transaction-matching logic. The attacker deposited 8 ETH and 2 LINK into trade accounts, then submitted a 23-message MsgDeposit batch consisting of 22 trade withdrawals (each incremented by ~263 units to prevent outbound batching) and 1 donation. Because the nodes observed 22 simultaneous L1 outbounds unmatched by standard TxOutItems, the security system incorrectly flagged the attacker's own legitimate withdrawals as external theft. This false alert triggered the automated subsidizePoolsWithSlashBond() theft-compensation handler. Lacking an upper cap, the handler attempted to dump ~49.42 million CACAO into the pools to compensate for the non-existent theft. Although the transaction failed on-chain due to insufficient reserve funds (~168,000 CACAO actual reserve), a state accounting flaw saved the inflated pool balance regardless. Having pre-positioned in an almost empty ARB.LINK liquidity pool with 100 CACAO, the attacker withdrew 99% of their LP position, extracting 48,869,502 CACAO. The attacker then executed 10 consecutive CACAO-to-BTC swaps, siphoning 20.83 BTC directly to a Bitcoin address and triggering secondary arbitrage extraction across the network. Block Data Reference Key Attacker Bitcoin Address: bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646
Impact
Quick Summary On August 15, 2026, BSC-based bond market protocol Fox Market was exploited via an atomic flash-loan attack. The attacker utilized ~$482 million in flash-loaned stablecoins to trigger over-minting of protocol bonds and siphon ~$678,000 from the PancakeSwap FOX/USDT liquidity pool, yielding ~$117,000 in net attacker profit after flash-loan fees. Details of the Exploit The attack targeted a critical ordering vulnerability in the stake() function on contract 0x9fa6d8a13b35e051bfc145918db0111dec13d1a0. When executed, stake() sampled the FOX token spot price ($5.44) prior to executing the swap of injected USDT into the underlying PancakeSwap pool. Attacker 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 borrowed ~$482 million in USDT across Lista, Venus, and Aave, passing the capital into the bond minting routine. Because the mint valuation calculated token issuance based on the pre-swap spot price rather than the post-swap execution price, the protocol printed ~181x more bond tokens (88.66M sFOX) than intended. The contract then burned the newly created LP tokens to 0x00...dead and instantly paid an unlocked 3% referral bonus in FOX (2.66M tokens) to an inviter address. The attacker dumped these referral tokens directly into the newly USDT-heavy PancakeSwap pool, drained ~$678,000 from existing pool liquidity, fully repaid all $482 million in flash loans, and extracted ~$117,000 in net profit. Block Data Reference Exploit Transaction: 0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514 Attacker: 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 Attack Helper Contract: 0x3A82A2A77061017927e5331fFFd07c0308a1D2DA
Impact
Q uick Summary On August 13, 2026, an unknown victim address (0x13e382dfe53207E9ce2eeEab330F69da2794179E) was drained of approximately $25.6 million in cryptocurrency assets, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M). This marks the second major exploit targeting this exact whale address, which previously lost $24.23 million to a malicious token approval phishing attack in September 2023. Details of the Exploit The attacker executed unauthorized transfers siphoning $25.6 million in multi-asset holdings, including WBTC, cbBTC, aWBTC, LDO, USDS, CRV, DAI, and ETH out of the victim's wallet. Immediately following the drain, the attacker swapped the stolen assets across decentralized protocols to consolidate the loot into stable capital, converting the holdings into approximately 20 million DAI and 3,000 ETH (~$5.64M). The consolidated funds were subsequently split across four target collector addresses (including 0x61ce24326d713641583e6a337a69bef7458fcf76), while security monitoring teams track potential recovery or laundering attempts. Block Data Reference Attacker / Theft Address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae Primary Consolidation Address: 0x61ce24326d713641583e6a337a69bef7458fcf76
Impact
Quick Summary On August 12, 2026, Layer-1 blockchain Harmony Protocol suffered a major protocol-level security incident when an attacker exploited an "empty blocks" vulnerability to fraudulently mint approximately 4 billion ONE tokens representing roughly 26% of the token's total circulating supply and causing the price of ONE to crash between 26% and 34%. Details of the Exploit The exploit targeted a consensus or state-update bug involving empty blocks, allowing the attacker to mint ~4 billion ONE tokens out of thin air while bypassing standard protocol reporting endpoints (leaving totalSupply metrics temporarily unchanged). The attacker rapidly transferred approximately 2.8 billion ONE (~97% of the fraudulently created tokens) directly into centralized crypto exchanges for liquidation, leaving only around 115 million ONE in on-chain addresses. In response, Harmony requested exchanges to freeze funds from four identified attacker wallet addresses while the core team began developing a software patch and evaluating blockchain rollback options. Block Data Reference Key Attacker Addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510) one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5)
Impact
Quick Summary On August 10, 2026, cryptocurrency payment platform Coinsbuy suffered a coordinated hot wallet compromise across both TRON and Ethereum, losing approximately $7.9 million to $8.07 million in under an hour. Coinsbuy temporarily halted deposits and withdrawals to contain the incident before fully covering all affected balances from its corporate reserves and resuming normal operations without client loss. Details of the Exploit The attacker executed a rapid, cross-chain operation impacting multiple hot wallet addresses simultaneously. On TRON, the perpetrator drained roughly $6.04 million in USDT across eight wallets within an hour. Concurrently on Ethereum, three hot wallets were emptied of approximately 1.89 million USDT along with native ETH. The attacker leveraged cross-chain swap services (including Bridgers) and non-custodial exchanges (FixedFloat, ChangeNOW, and BingX) to route ~79% of the stolen funds through a non-clusterable pattern, splitting transactions across 50 single-use addresses to convert the capital into Monero (XMR). While ChangeNOW managed to freeze a six-figure sum of the illicit transfer, the majority of the stolen assets were converted into untraceable privacy coins. Coinsbuy subsequently refilled the drained hot wallets from its balance sheet, indicating the underlying platform infrastructure remained secure. Block Data Reference Key Attacker Addresses: TRON Collector: TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR Ethereum Collector: 0x4d1bef2fe998b3e3c4029ef9ea6a0534d95661d3 Ethereum Swap Wallet: 0x66790b54b891e2ebdef58a15b969ff6fb4374b17
Impact
Quick Summary On August 9, 2026, the Coreum cross-chain bridge connecting to the XRP Ledger (XRPL) was exploited due to a deposit verification flaw, resulting in the theft of 199,916 XRP (valued at approximately $200,000) across 94 transactions within 97 minutes. Details of the Exploit The attack targeted a vulnerability in the Coreum bridge's deposit verification logic and multisig relayer infrastructure connecting the Coreum blockchain to the XRP Ledger. By exploiting a flaw in how incoming cross-chain deposit proofs were validated, the attacker tricked the relayer system into recognizing unverified or forged deposit events as legitimate. Over a 97-minute window, the attacker executed 94 consecutive fraudulent withdrawal requests, systematically siphoning 199,916 XRP out of the bridge liquidity before operations could be suspended.
Impact
Quick Summary On August 3, 2026, perpetual exchange protocol RISEx experienced an unauthorized withdrawal of 673,011.56 USDC from the Real-World Asset (RWA) yield strategy linked to its XLP liquidity vault due to a smart contract misconfiguration. The team patched the vulnerability within minutes and fully reimbursed XLP depositors using protocol fee revenue, resulting in zero user losses. Details of the Exploit The exploit was caused by a configuration flaw in the RWA yield strategy connected to RISEx's XLP vault, which had been present since its deployment on July 13, 2026. An unauthorized user took advantage of this misconfiguration at 07:21 UTC to execute an unverified withdrawal of 673,011.56 USDC. Because the withdrawal amount sat below the protocol's automatic rate-limiting and throttling thresholds, the transaction executed on-chain. RISEx engineering detected the transaction within minutes and deployed a patch by 08:09 UTC. The protocol covered 100% of the lost capital using a portion of its July trading fee revenue. Block Data Reference Attack Transaction: 0xc52560bec154a3d5533a321bd9805305a5076194573ddb2fbb059059ace3e987
Impact
Quick Summary On August 2, 2026, LOOPSDAO's LpdFi protocol on BNB Chain was exploited for approximately $690,000 in USDC (netting ~$573,000 in profit) through a combination of spot price oracle manipulation and a flaw in the protocol's discrete daily interest accrual logic. Details of the Exploit The attack targeted Lpd.price(), which derived token valuations directly from the instantaneous reserves of a PancakeSwap LPD/USDC liquidity pair without TWAP, liquidity thresholds, or price deviation guards. The attacker temporarily inflated the LPD spot price by ~5,163x via temporary liquidity swaps and invoked buy(), allowing them to record a massive $140M nominal USDC interest-bearing principal for a minimal LPD deposit. After rebalancing the pool and stepping across the daily issue boundary in the subsequent block (just one second later), the attacker called claimInterest(), which accrued a full 0.5% interest period on the bloated principal and forced the protocol to burn 1.68 million of its own Cake-LP tokens (with zero slippage bounds) to pay out the unbacked USDC. Block Data Reference Attacker Address: 0x5d289266d85ef671561ba3f253fb79327c193f33 Attack Executor Contract: 0x7f5ad0a998dcb3f5006f0d152bebc055979ef711 Victim / Vulnerable Contract: 0xce6a6e4413d85a136bbac8aae6fb46eaa77f295e Setup Transaction: 0xbb5b8573d7203e00f8fb9d4839dbeea46a8efd367eac8bed81e4ece2341c3588 Claim Transaction: 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6
Impact
Quick Summary On August 2, 2026, the MOKE token protocol on BNB Chain was exploited for approximately $907,700 (~1,546 BNB) due to a critical access control flaw in its smart contract architecture. Details of the Exploit The exploit was caused by an unprotected public claim() function within the MokeToken.releaseContract() contract, which lacked caller eligibility checks or role-based access control. The attacker repeatedly called claim() to drain roughly 166 million MOKE tokens directly from the protocol's internal reserve pool. To realize their profit, the attacker combined flash loans, Venus Protocol leverage, liquidity pool removal, and internal dividend distribution mechanics to swap the extracted tokens into 1,546 BNB. Block Data Reference Attack Transaction: 0x0776048b1b58064fb31b6513721811e7b44d6bdbe7bf5833158b241ca6756a8f
Impact
Unmatched project for pending review.
Impact
Quick Summary Starting July 30, 2026, Bitcoin hardware wallet manufacturer Coldcard (by Coinkite) disclosed a critical firmware entropy defect that enabled attackers to systematically brute-force and drain user funds offline, resulting in cumulative losses estimated between $85 million and $130 million+ (~1,900 to 2,055+ BTC) across multiple organized attack waves. Details of the Exploit The vulnerability originated from a firmware code refactoring introduced in version 4.0.1 (March 2021), where seed phrase generation calls were migrated from ckcc.rng_bytes() to ngu.random.bytes(). This migration unintentionally caused the underlying rng_get() function to resolve to MicroPython's software Pseudo-Random Number Generator (PRNG) fallback instead of Coldcard's dedicated True Hardware Random Number Generator (TRNG). Consequently, generated wallet seeds possessed severely degraded entropy, approximately 40 bits on Mk3 devices and ~72 bits on newer models, down from the intended 128/256 bits. Attackers leveraged this reduced search space to pre-compute and offline brute-force the predictable private keys for affected single-signature addresses, executing sweeping transactions across four distinct waves without requiring physical access to the hardware devices. Coinkite issued security advisories across affected models (Mk3, Mk4, Q, Mk5) while security researchers worked with victims to perform Replace-By-Fee (RBF) cancellations for pending mempool sweeps.
Impact
Quick Summary On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan. Details of the Exploit The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios. This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit. Block Data Reference Attack Transaction: 0xa219ab9d57e520e5235b15a8801f4ebac8cc45551be0430ce4e49caea0411d7c
Impact
Quick Summary On July 26, 2026, WEMIX (the blockchain ecosystem backed by South Korean gaming company Wemade) suffered a smart contract compromise affecting its WEMIX$ stablecoin contract, resulting in an unauthorized minting and transfer of approximately $6.25 million worth of tokens. Details of the Exploit The incident occurred when an unauthorized party compromised the contract ownership privileges of a WEMIX$-related smart contract. Using these administrative rights, the attacker fraudulently minted 5,225,525 WEMIX$ and transferred USDC.e out of the protocol. The attacker converted the fraudulently minted tokens into 30,736 WEMIX and 724,198.27 USDC.e, before bridging the USDC.e over to Ethereum and BNB Smart Chain (BSC). On those destination networks, the funds were swapped into assets including ETH and USDT, with a portion subsequently deposited into centralized exchanges. In response, the WEMIX team temporarily suspended all connected bridges (including Chainlink CCIP and PLAY Bridge), withdrew Foundation-provided liquidity, halted trading across affected liquidity pools (WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$), paused the WEMIX$ Module and PNIX DEX, and coordinated with global exchanges to freeze attacker-linked addresses.
Impact
Quick Summary On July 26, 2026, cross-chain atomic swap protocol Garden Finance suffered a supply chain compromise affecting its Hash Time-Locked Contracts (HTLC), resulting in an initial drain of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, BNB Chain, and Solana. Details of the Exploit The exploit was an off-chain supply chain attack rather than a direct smart contract code vulnerability. An attacker compromised the off-chain database of an independent solver integrated with Garden Finance and injected forged transaction records. Because the protocol relies on solver state data to process cross-chain atomic swaps between Bitcoin and EVM/Solana networks, these fraudulent records deceived the HTLC contracts into releasing escrowed USDT assets directly to the attacker without valid matching inputs. Garden Finance immediately took its front-end web application offline to prevent further improper fund releases, confirming that while core smart contracts remained secure, the breach stemmed entirely from off-chain solver infrastructure. Block Data Reference EVM Attacker Address: 0x25b224c05f6cc5e132165c1621de1a4c3b316999 Solana Attacker Address: WZy4xxpqktWa1b6MPMRiWsD487CT8mDcapB6GufBJCH Example EVM Exploit Transaction: 0x9d7a961aa340156b7342839e9f6448a26dea9acd38dc7b2638966eb19e29d395
Impact
Quick Summary On July 25, 2026, Singapore-based licensed stablecoin payment gateway Triple-A suffered a hot wallet compromise across multiple blockchains, resulting in the unauthorized extraction of approximately $9.7 million to $11.8 million in company-owned treasury assets. Details of the Exploit The incident occurred when an unauthorized party obtained compromise access to Triple-A's multi-chain hot wallet infrastructure across TRON, Ethereum, Polygon, and Arbitrum. The attacker drained the company's operational treasury accounts, swapped the stolen digital assets, and bridged them to Ethereum Mainnet, consolidating 5,227 ETH into a single holding wallet. Client funds were entirely unaffected because Triple-A does not provide digital asset custody for its users, keeping client balances strictly segregated in trust accounts with safeguarding financial institutions. Triple-A temporarily placed certain services into maintenance mode for approximately three hours to secure the affected infrastructure before fully restoring normal payment processing, transaction settlements, and global operations.
Impact
Quick Summary On July 25, 2026, the Projekt (GREEN/GOLD) reward vault on Ethereum was exploited, resulting in the loss of approximately 301.7 ETH (valued at ~$560,000) due to a logic flaw in its buy-to-earn reward allocation tracking. Details of the Exploit The exploit targeted a logic error in the reward vault's permissionless trackPurchase(buyer) function, which was designed to credit ETH allocations to buyers based on token balance deltas. Crucially, trackPurchase relied solely on token balance increases to calculate reward sizing without validating whether genuine ETH was spent to acquire those tokens. To execute the attack, the exploiter secured a flash loan of approximately 14,000 WETH from Morpho. They pushed these funds into dozens of Uniswap V2 memecoin liquidity pairs (such as Kirby Inu and ROTTSCHILD) and invoked skim() to transfer the tokens directly to their contract. This self-dealing token movement inflated the buyer's balance delta, tricking the unverified trackPurchase function into registering massive fake "purchase" reward allocations at virtually zero net cost. Once the fake allocations were credited and the flash loan repaid in the same transaction, the attacker called massWithdraw() to drain ~301.7 ETH from the vault's reward pool. Block Data Reference Attacker Address: 0x61e7ad696215688d274c729a4cd0fbbc88fc4f85 Victim / Vulnerable Contract: 0x574fc478bc45ce144105fa44d98b4b2e4bd442cb Attack Transaction: 0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64
Impact
Quick Summary On July 23, 2026, Solido Cash on the Supra blockchain was exploited due to an oracle fallback misconfiguration on its SOLID vault. An attacker leveraged an invalid stale price fallback to over-mint CASH stablecoins and extract approximately 293.7 million SUPRA tokens (~$73,400 net value), with protocol reserves absorbing the loss so zero user funds were affected. Details of the Exploit The exploit stemmed from an oracle misassignment where a stale primary price feed for the SOLID token incorrectly fell back to the $1.00 CASH stablecoin oracle instead of halting or using a proper secondary feed. Treating cheap SOLID collateral as equivalent in value to CASH, the attacker executed atomic contract interactions and manual secondary wallet mints to generate unbacked CASH stablecoins, which were immediately swapped for native SUPRA tokens across local decentralized exchanges. Solido Cash subsequently paused vault interactions and patched the oracle fallback mappings.
Impact
Quick Summary On July 23, 2026, the cross-chain bridge connecting the Verus blockchain to Ethereum was exploited for the second time in two months, resulting in the unauthorized extraction of approximately $7.53 million across multiple digital assets. Details of the Exploit The exploit targeted a semantic and authority validation flaw in how the Ethereum-side bridge contract verifies cross-chain export outputs from Verus. While the contract verified that a given export payload existed within a valid Verus block and matched a genuine state root notarized on Ethereum, it failed to verify that the Verus network itself had authorized the payload as a legitimate primary export. The attacker initiated a tiny 0.01 VRSC bridge transaction to create a valid export state, then authored a custom Verus transaction spending that output and attaching a handwritten export commitment declaring 8 transfer instructions to the attacker's wallet. After relaying two legitimate notarizations to Ethereum containing the state root of their custom transaction, the attacker submitted the import request. Because the cryptographic Merkle proofs and payload hash checks matched the attacker-controlled input data, the bridge executed the transfer, releasing $7.53 million in tBTC, DAI, USDC, scrvUSD, USDT, MKR, and EURC. The stolen assets were immediately swapped on-chain for 3,916.1 ETH and deposited into Tornado Cash. Block Data Reference Attacker Address: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
Impact
Quick Summary On July 23, 2026, the cross-chain custody bridge operated by decentralized exchange AFX on Arbitrum was exploited, resulting in the unauthorized withdrawal of 24.15 million USDC. Details of the Exploit The incident was carried out via a private key or backend validator infrastructure compromise. The attacker forged an on-chain withdrawal request on Arbitrum that carried valid cryptographic signatures from five bridge validators. Because these signatures satisfied the bridge contract's multi-signature authorization threshold, the contract executed the transaction as legitimate and released 24.15 million USDC from custody. The attacker immediately bridged the stolen stablecoins from Arbitrum to Ethereum Mainnet and swapped them for approximately 12,467.5 ETH. Following detection, AFX suspended bridge operations to isolate the vulnerability, confirming that the platform's core trading engine, mainnet, and Arbitrum's native bridge remained uncompromised while security teams began tracing the funds. Block Data Reference Arbitrum Creation Transaction: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Arbitrum Finalize Transaction: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b Ethereum Attacker Wallet: 0x627654b2782bfc57580ecd11d40869b350b6ebac
Impact
Quick Summary On July 23, 2026, Bitcoin Layer-2 protocol B² Network suffered a security incident on BNB Chain targeting its B2 token staking service, resulting in the unauthorized extraction of approximately 8.59 million B2 tokens (valued at ~$3.86 million). Details of the Exploit The exploit was caused by a compromise of the administrative upgrade authority governing the upgradeable proxy contract for B² Network's staking service. An address (0x35fE...b287d) that had granted itself privileged admin permissions over a year prior (May 2025) executed an upgradeToAndCall function call on the live staking proxy contract. This replaced the legitimate contract implementation with a malicious logic contract (0x0B875E...C9DCa). Six minutes after the proxy upgrade, the attacker invoked draining functions through the newly deployed logic, extracting ~8.59 million B2 tokens across nine batch calls within 45 minutes. The stolen B2 tokens were swapped on-chain for 5,409 WBNB, converted to 1,128 ETH, and bridged out of BNB Chain via Near Intents. Block Data Reference Malicious Implementation Contract: 0x0B875E23C6b04D3683f1D4c4f0FFf7f2b5cC9DCa Upgrade Transaction: 0x2069714bbe6671f7737f85c5caee7fbccd15ed8f045b2cd6f6b52229cd47d769
| When | Protocol | Type | Impact | Source |
|---|---|---|---|---|
2d ago Oct 4, 2026 | Adapter Vault Drain Unknown chainreported | Access control | Quick Summary On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum. Details of the Exploit The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d). Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched. Block Data Reference Target Adapter Contract: 0xd1895f2019c2152fc2b9022d57f19198c4cfcabc Owner Safe Address (3-of-7): 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4 Attacker Deployer Address: 0x0B5126e1bc27C0de77e02e97945760A674EdB034 Attacker Whitelisted Contract: 0xcdfe91301356da873562ef513828a60dba1f569d Fund Destination Address: 0xC73448432a05deeA5Ea18a07D3b5d9ccf6297f8D | De.Fi↗ |
4d ago Oct 2, 2026 | Goldpesa Unknown chainreported | Other | Quick Summary On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions. Details of the Exploit The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router. Block Data Reference Attack Transaction Hash: 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9 Attacker Address: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F Vulnerable Contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8 | De.Fi↗ |
5d ago Oct 1, 2026 | Near Intents Ethereumreported | Other | Quick Summary On October 1, 2026, cross-chain protocol NEAR Intents was exploited for approximately $3,8 million following a hot wallet drain on BNB Smart Chain caused by an integration bug in its Omni bridge infrastructure. On-chain analysis linked the attacker to North Korea's Lazarus Group, while the protocol team patched the flaw and pledged full user reimbursement. Details of the Exploit The attack stemmed from an integration logic flaw between NEAR Intents smart contracts and its Omni deposit/withdrawal layer on BNB Smart Chain, allowing the attacker to execute unauthorized hot wallet withdrawals. The attacker extracted ~$3.865M on BSC, routed a portion toward KuCoin, bridged funds to Ethereum, and executed seven Chainflip swaps to acquire ~33.7 BTC (~$2.9M), which remains parked across four unspent Bitcoin addresses. On-chain tracking confirmed the attacker interacted with known Lazarus Group infrastructure (0x098B7...E2f96). In response, NEAR Intents patched the contract-side flaw, temporarily suspended Omni bridge operations across 11 chains, and guaranteed 100% user compensation from protocol reserves. Block Data Reference BSC Attack Hashes: 0x9fe58e031f73bbd880c782bc9e7446bcda32cadb304a729209871a4a81856c4c 0x0381265d6a1bb09de899f49f410a8b907cd548358a7e3c91076c3a52656b8220 0x69d1c68c7e961a0199d3c9f3b6a31cb168ed775ef34b51a42762253ac1efcceb 0x9c10b967da0c85631ec105e3b322c0a851fcd01b69ff390ff58f860e5cce003a | De.Fi↗ |
6d ago Sep 30, 2026 | MCN Labs BNB Chainreported | Other | Quick Summary On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations. Details of the Exploit The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time. The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Attacker Address: 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a Vulnerable Contract: 0x52272524a22f941f5489c1233732797314bb054b | De.Fi↗ |
7d ago Sep 29, 2026 | Fastswap BNB Chainreported | Other | Quick Summary On September 29, 2026, the FastSwap protocol on BNB Smart Chain was exploited in an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $92,600 USD. Details of the Exploit An attacker executed a malicious transaction targeting the FIST token and FastSwap smart contracts (0xc9882def23bc42d53895b8361d0b1edc7570bc6a) on BNB Smart Chain. The exploit allowed the attacker to manipulate protocol contracts and drain liquidity pools, extracting ~$92.6K in value within a single transaction. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Target Token / Contract: 0xc9882def23bc42d53895b8361d0b1edc7570bc6a | De.Fi↗ |
10d ago Sep 26, 2026 | Dyorswap Ethereumconfirmed | Phishing | Quick Summary On September 26–27, 2026, scammers deployed a fake OP Stack Layer 2 network impersonating the unreleased GIWA Mainnet (Chain ID 9134) and set up a fraudulent bridge. 1,335 user addresses deposited 767.65 ETH into the fake bridge to trade on DYORSWAP, allowing the scammers to extract 766.25 ETH (~$2.0 million USD) on Ethereum. Details of the Exploit The incident was a fake infrastructure scam rather than a smart contract flaw in DYORSWAP's protocols. Scammers configured a malicious network using GIWA's official Chain ID (9134) alongside a fake bridge and OP Stack batcher. When traders connected to the fake RPC and deposited ETH to trade on DYORSWAP, the malicious bridge contract captured the L1 funds. The scammers drained 766.25 ETH at Ethereum block 26,067,309. DYORSWAP confirmed its core contracts were safe, published a claims collection form, and distributed over 200 ETH from its treasury to compensate affected users while tracing the scammers' funding sources. | De.Fi↗ |
12d ago Sep 24, 2026 | Duelbits Ethereumreported | Access control | Quick Summary On September 24, 2026, crypto casino and sportsbook platform Duelbits suffered a multi-chain hot wallet compromise resulting in estimated total losses of $4.9M to $7.0M across Ethereum, BNB Chain, Tron, Bitcoin, and Solana. The platform took its services offline to investigate and refill operational hot wallets while user cold storage remained unaffected. Details of the Exploit The attack was executed via a private key compromise targeting Duelbits' operational hot wallets across five blockchains. On EVM chains, the attacker extracted 836 ETH, 1.146M USDT, 209 BNB, 96.8K USDC, 31.5K DAI, and 12.4B SHIB, alongside 8.1 BTC on Bitcoin and 192K TRX on Tron. The attacker routed the stolen multi-chain assets through swap protocols and cross-chain bridges, converting the proceeds into Ether and consolidating approximately 2,234.6 ETH (~$6.0M) into a single destination Ethereum address. Duelbits confirmed the hot wallet breach and suspended operations pending system remediation and hot wallet refilling. Block Data Reference Attacker EVM Address 1: 0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76 Attacker EVM Address 2: 0x6761c9b15815f4051773EDe39B42B95bdDB3EF1c Attacker Bitcoin Address: bc1qhtu84kz3y94lvgl2t05zk84tqh57grvd82zvcl Attacker Tron Address: TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK Attacker Solana Address: A3EBrhMBEGzcPgmbwywSPhW39G6PFGrorU8ib99T6yKw | De.Fi↗ |
12d ago Sep 24, 2026 | Payy Network Ethereumreported | Access control | Quick Summary On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses. Details of the Exploit The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved. An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts. | De.Fi↗ |
12d ago Sep 24, 2026 | Bitget Ethereumreported | Access control | Quick Summary On September 24, 2026, centralized exchange Bitget suffered a major infrastructure breach resulting in ~$351.6 million stolen from its hot and warm wallet layers. Bitget paused withdrawals while confirming its cold wallets remained secure and stating that its $464M+ User Protection Fund will fully reimburse user losses. Details of the Exploit The attacker penetrated Bitget's core wallet backend infrastructure and spoofed internal transaction data to trigger authorized withdrawals across multiple blockchains without compromising private keys. Stolen assets included ETH, XRP, USDT, USDC, AVAX, and BNB. On EVM chains, the attacker converted most of the stolen proceeds into 67,982 ETH (~$183 million). On-chain analysis and VPN traffic patterns linked the attack to North Korea's Lazarus Group (specifically the TraderTraitor subgroup) through bridged funds connected to the earlier AFX Trade exploit. Bitget contained the breach, stopped further unauthorized transfers, and is preparing system recovery before resuming withdrawals. | De.Fi↗ |
13d ago Sep 23, 2026 | Meter Protocol BNB Chainreported | Other | Quick Summary On September 23–24, 2026, Meter.io suffered a dual consensus and bridge exploit after an attacker leveraged a block validation flaw on Meter mainnet and exploited the Meter Passport bridge on BNB Chain, resulting in ~$2.3 million in unbacked wMTRG minted and partially dumped on PancakeSwap. Details of the Exploit On September 23 at 21:14 UTC, an attacker exploited a block validation flaw on the Meter mainnet consensus layer to mint unbacked MTR and MTRG tokens. The attacker then used the Meter Passport bridge on BNB Chain across two main transactions to mint approximately $2.3 million in unbacked wrapped MTRG (wMTRG), dumping a portion into PancakeSwap liquidity pools and bridging funds out. Meter paused both mainnet and bridge operations, invalidated transactions post-block 100731417, and issued a 72-hour whitehat bounty offer of 10% for the return of funds. Block Data Reference Attacker Addresses: 0xee2eeeed4ed8580669ed924abeb49f27f7d0bd65 0x44cf94496091150865e192a86c07b90a9760b43d 0x7db6ac6Fa3c8aa2c6FB9BdCD4800e8BAacDd2EE8 Abused Token Contract (BSC): 0xBd2949F67DcdC549c6Ebe98696449Fa79D988A9F Sample Exploit Transaction (BSC): 0x2745dd5121eb03d1979cf229f432a422137942ede186d9fa0129a2f83401eeef Bounty Return Address: 0xB980Ff36A99C0C3B408279E025d8E2DA7eF65105 | De.Fi↗ |
14d ago Sep 22, 2026 | Astroport Unknown chainreported | Access control | Quick Summary On September 22, 2026, Cosmos ecosystem DEX Astroport suffered a security breach on the Neutron chain that exposed protocol admin controls. Validators halted Neutron and Cosmos Hub to coordinate an emergency response, intercepting approximately 1.396 million ATOM (~$2.53 million USD) before the attacker could cash out. Details of the Exploit The attacker compromised admin privileges for Astroport contracts on Neutron, placing liquidity across connected pools at risk. The attacker converted stolen funds into ATOM and initiated a streaming swap of 200,000 ATOM to ETH via THORChain. Only 15.5% of the swap filled (19.92 ETH) before Cosmos Hub halted at block 33,086,740. Cosmos Hub validators deployed a binary upgrade that transferred 1,227,121 ATOM from the attacker's account to a recovery multisig and added an ante-handler to block the attacker's key from signing future transactions. An additional 168,990 ATOM refund remains queued on THORChain, requiring a secondary sweep once GAIA chain processing unhalts. Astroport contracts on Terra were unaffected after their admin connection to Neutron was severed. Block Data Reference Attacker Cosmos Address: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n | De.Fi↗ |
15d ago Sep 21, 2026 | RWC Token BNB Chainreported | Other | Quick Summary On September 21, 2026, the RWC token protocol on BNB Smart Chain was hit by an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $109,000 USD. Details of the Exploit An attacker executed a malicious transaction targeting the RWC contract on BNB Smart Chain, exploiting a smart contract vulnerability to drain funds from the project's liquidity or protocol pools. Security monitoring systems flagged the atomic execution trace after ~$109,000 in value was extracted. Block Data Reference Attack Transaction Hash: 0x9c919da34696425913f32587f00d2838031a8726a2c5ddfa39e33a45b36e6427 | De.Fi↗ |
15d ago Sep 21, 2026 | Internet Token INT Unknown chainreported | Other | Quick Summary On September 21, 2026, the Internet Token protocol on Base was exploited for 5.85 WETH and 764 million INT after an attacker leveraged an unvalidated Uniswap V3 pool callback parameter to arbitrarily mint ~925 million INT tokens. Details of the Exploit The vulnerability was present in INT's LiquidityUnifier contract (0x837d...), which held MINTER_ROLE rights and exposed an unvalidated swapV3(token, pool) function. The function only validated that the passed pool parameter contained bytecode and that its token0() and token1() getters returned the INT token address. The attacker deployed a malicious contract returning INT for both token endpoints, causing swapV3 to invoke pool.swap(). This callback re-entered uniswapV3SwapCallback and minted an arbitrary amount of INT tokens directly to the fake pool. The attacker routed the minted tokens through a Convertor contract round-trip to bypass validateSupply sanity checks, created ~925 million INT, dumped a portion into the official INT/WETH V3 pool for 5.85 WETH, and kept the remaining ~764 million INT. Block Data Reference Attack Transaction Hash: 0xed62bb27bd1058d3d7cc93d55421d6d0001ced8cb4529b02773f5126a4edb08b Attacker Address: 0x5f7ce6395818857ac20730dc990f614356d1ec68 Victim Contract: 0x837dbabc4f5fa78baf177597edbda09645822032 | De.Fi↗ |
17d ago Sep 19, 2026 | ASI Alliance Singularitynet Ethereumreported | Access control | Quick Summary On September 19–20, 2026, an attacker used compromised SingularityNET bridge and NuNet deployer private keys to drain $FET and mint unauthorized supplies of $AGIX,$NTX, $WMTx, and $CGV on Ethereum. The attacker extracted ~$1.44M to $1.67M in liquid ETH before project teams paused bridges and revoked minting authorities. Details of the Exploit The exploit resulted from compromised private signing keys rather than smart contract logic bugs. On September 19, the attacker called conversionIn on Fetch.ai's TokenConversionManagerV3 using a stolen SingularityNET authorizer signature to drain 8.72M $FET (~$1.53M) and swap it for ETH. Minutes later, a compromised NuNet deployer account minted 408.53M $NTX to reach its 1 billion supply cap. On September 20, the attacker used the SingularityNET bridge authority to mint 260M $AGIX, 53.84M $WMTx, and ~500M$CGV. High slippage on low liquidity pools limited total extracted value to 546–649 ETH (~$1.44M–$1.67M), while token market prices collapsed by 65% to 99%. Affected protocols responded by pausing bridges, revoking signing authorities, and contacting exchanges to freeze funds. Block Data Reference Attacker Address: 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE NuNet Deployer Address: 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Fetch.ai Conversion Contract: 0xab424A430CC09864fA1277A38193111705ADF3A3 | De.Fi↗ |
19d ago Sep 17, 2026 | Nostra Finance Unknown chainreported | Oracle issue | Quick Summary On September 17, 2026, Starknet money market Nostra Finance suffered an oracle price manipulation exploit resulting in ~$3.53 million in unauthorized borrows across ETH, STRK, USDC, USDT, WBTC, and DAIv1 against inflated NSTR collateral, forcing the protocol to pause all lending, borrowing, and liquidation operations. Details of the Exploit The attacker exploited Nostra Finance's collateral valuation oracle for NSTR by manipulating its underlying price pool on Ekubo DEX. The attacker withdrew existing liquidity around NSTR's real market price, seeded a decoy liquidity band at $99 per NSTR, and routed a $14.72 dust swap (190 NSTR) through the gap to artificially inflate the oracle price by 16,645x. Using just 294,177 NSTR collateral, normally worth ~$1,756, the attacker leveraged the inflated valuation to draw $3,531,922.97 in mixed assets across six borrowing legs. The attacker then bridged ~$1.93 million (234.57 ETH and 1.3M DAI) to Ethereum while leaving ~$1.55 million in assets on Starknet. Block Data Reference Starknet Attacker Contract: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 Ethereum Destination Address: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37 | De.Fi↗ |
20d ago Sep 16, 2026 | Bonfire BNB Chainconfirmed | Phishing | Quick Summary On September 16, 2026, an attacker executed a batched approval-drain sweep targeting holders of the Bonfire (BONFIRE) token on BNB Chain, resulting in a loss of approximately 66.08 WBNB (~$47.4K USD). T Details of the Exploit The attack was executed across two distinct phases within transaction 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f. In the harvesting phase, the attacking contract iterated through a pre-compiled list of 65 addresses that had standing approvals to 0x17e801.... Using transferFrom(), the contract pulled each victim's BONFIRE balance directly into the BONFIRE/WBNB liquidity pair. The contract then called swap() to route tokens out to a collector wallet (0x28E976Ea...), netting the inbound deposits against the outbound legs and steadily increasing the pair's token reserves without swapping for WBNB on each individual transfer. The decaying size of the pulled balances across the iterations indicates a script executing against victims ordered by remaining balance size. In the cash-out phase, the collector address approved the attacking contract and passed its accumulated ~4,576 BONFIRE back into the liquidity pool across two major sell swaps. These swaps extracted 33.223 WBNB and 32.857 WBNB respectively, totaling 66.08 WBNB, which was subsequently unwrapped to native BNB. Standard events such as SwapAndLiquify observed during the execution were simply Bonfire's automated liquidity tax mechanism firing as intended through its legacy PancakeSwap V1 router. The root vulnerability remains off-chain, stemming either from historical phishing campaigns or compromised keys associated with a legacy custom router contract. Block Data Reference Attack Transaction Hash: 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f Harvesting Contract: 0x17e801E17CeFC6334059189c178D4783830E03D3 Collector Address: 0x28E976Ea7b83553d6D1D45CE81334156A2632127 | De.Fi↗ |
20d ago Sep 16, 2026 | Flamincome Ethereumreported | Flash loan attack | Quick Summary On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan. Details of the Exploit The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit. Block Data Reference On-Chain Key Addresses: Attacker Primary Address: 0x83381e7f7232775735169d72d237b858ffc36871 Target Strategy / Vault: 0xb8d6471ca573c92c7096ab8600347f6a9fe268a5 Exploit Contract 1: 0x875da4bd7b4a52a806a533b1cf6d6ff92365d2e6 Exploit Contract 2: 0x1c7eacef3630e764519e6ea2e8caa2bdb7d8b486 | De.Fi↗ |
20d ago Sep 16, 2026 | Meme Coin Phishing Scam Unknown chainconfirmed | Phishing | Quick Summary On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000. Details of the Exploit Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader. | De.Fi↗ |
24d ago Sep 12, 2026 | Chainflip Unknown chainreported | Other | Quick Summary On September 12, 2026, cross-chain swap protocol Chainflip suffered a memo-manipulation exploit on its Tron settlement layer, resulting in six unauthorized payouts totaling 736,442.17 USDT after an attacker attached custom memos to already-signed transactions to trigger duplicate refund payouts. Details of the Exploit Unlike other blockchains supported by Chainflip that pass swap instructions via dedicated contract functions, the protocol's Tron integration parses swap parameters directly from transaction memo fields. The attacker discovered a vulnerability allowing a custom memo to be appended to a Tron transaction that Chainflip validators had already signed. Chainflip's backend misread the altered memo as a new, separate swap instruction, classified it as failed, and automatically triggered a refund, effectively paying out against the same underlying deposit a second time. The attacker executed eight attempts over ~90 minutes in the early hours of Saturday, scaling up transaction sizes until six successful attempts extracted 736,442.17 USDT. Chainflip detected the incident after subsequent legitimate USDT payouts began failing due to drained vault reserves. Network operations were paused, a code fix was finalized, and operators committed to making all impacted users whole upon restart. | De.Fi↗ |
27d ago Sep 9, 2026 | Amnext BNB Chainreported | Reentrancy | Quick Summary On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap. Details of the Exploit Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens. The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB. Block Data Reference Attack Transactions: Main Exploit: 0x29eb97259b5c8d1bbfe791ad5d7bdc981f538ac37c857cc30d6296b31f08afc5 Liquidation: 0x99c9969ab97f97b56766a9d75ec4f82a463bb8e7f9603eecc77b6bb57485d3ba | De.Fi↗ |
27d ago Sep 9, 2026 | Nomic Nbtc Bridge Unknown chainreported | Other | Quick Summary On September 9, 2026, a flaw in Nomic's custom forwarding mechanism allowed an attacker to double-spend nBTC and send ~39.84 unbacked nBTC vouchers (~$3.15M USD) to Osmosis, compromising roughly 36% of the backing behind Osmosis's Alloyed BTC (allBTC) token. Details of the Exploit The attacker exploited a vulnerability in Nomic's custom transaction forwarding system to double-spend nBTC and issue unbacked vouchers through the Inter-Blockchain Communication (IBC) protocol onto Osmosis. Because nBTC serves as a reserve component for Osmosis's unified Alloyed BTC pool, the forged vouchers left allBTC ~36% undercollateralized. Core IBC and Osmosis smart contracts were not directly breached. Following detection, Osmosis paused all minting, redemptions, inflows, and outflows for Nomic and Alloyed BTC. Osmosis validators then executed an emergency chain upgrade that successfully froze 22.65 BTC residing in the attacker's Osmosis account. Osmosis announced plans for a governance vote to seize the 22.65 frozen BTC and reimburse the remaining ~17.19 BTC shortfall from the community pool's BTC reserves to fully restore 1:1 backing. | De.Fi↗ |
Sep 6, 2026 Sep 6, 2026 | Liquid Network Unknown chainmitigated | Other | Quick Summary On September 6–7, 2026, Bitcoin sidechain Liquid Network suffered an Elements consensus bug exploit resulting in losses of ~4,000 BTC (~$320 million USD), after unbacked L-BTC tokens were minted and redeemed for real Bitcoin, forcing operators to halt the network while whitehat negotiations proceed on-chain. Details of the Exploit The attacker exploited a consensus vulnerability in the underlying Elements software to forge ~4,000 unbacked L-BTC on Liquid without depositing collateral. These unbacked tokens were submitted through SideSwap's Peg-out Authorization Key service, prompting the Liquid Federation multisig to release ~3,996 real BTC from reserves—draining ~95% of backing. Federation operators subsequently halted the sidechain and exchanges paused L-BTC deposits. The attacker consolidated funds into a single Bitcoin address and left an OP_RETURN message offering to return most of the BTC once Blockstream deploys a network-wide patch. Block Data Reference Mainnet Attacker Address: bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte Federation Reserve Address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr | De.Fi↗ |
Sep 4, 2026 Sep 4, 2026 | Notional Finance Ethereumreported | Other | Quick Summary On September 4, 2026, lending protocol Notional Finance suffered an integer truncation and rounding error exploit on Ethereum, resulting in an estimated loss of $1.73 million in DAI and USDC, which the attacker swapped into 689.2 ETH and deposited into Tornado Cash. Details of the Exploit The exploit targeted Notional Finance's escrow and fCash accounting mechanism via a combination of a free-collateral calculation rounding error and an integer downcasting flaw. The attacker executed a two-step transaction sequence calling the mintfCashPair() function. In the first call (mintfCashPair(1)), a small liability (-1) was rounded down to 0 during the DAI-to-ETH free-collateral conversion due to a rounding precision flaw. In the second call (mintfCashPair(2^256 - 1)), the contract aggregated the account's liabilities in int256, producing a negative balance of $-2^{128}$. However, when validating free-collateral requirements, the valuation logic performed an unsafe downcast using uint128(balance.abs()). Because $2^{128}$ overflows a standard 128-bit unsigned integer, the massive liability truncated directly to zero. This bypassed the protocol's collateral checks entirely, allowing the attacker to draw down 69,257 DAI and 1,658,525 USDC from the escrow contract. The attacker then consolidated the stablecoins, converted them to 689.2 ETH, and routed the funds into Tornado Cash across multiple transactions. Block Data Reference Setup Transaction: 0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a | De.Fi↗ |
Sep 2, 2026 Sep 2, 2026 | Cozy Finance Unknown chainreported | Oracle issue | Quick Summary On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window. Details of the Exploit On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7. The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash. Block Data Reference Attacker Address: 0x003FE7359A4E03C85Ac2f521eC699ED84C7c5ccB | De.Fi↗ |
Aug 31, 2026 Aug 31, 2026 | Aquifer Ethereumreported | Other | Quick Summary On August 31, 2026, Solana-based automated market maker Aquifer suffered an unverified CPI token program injection exploit resulting in approximately $2.5 million in total losses across 90+ attack transactions, after which the protocol issued an on-chain whitehat offer allowing the attacker to keep 20% if 80% of the stolen funds are returned by September 3, 2026. Details of the Exploit The exploit targeted Aquifer's swap function on Solana. When executing a token swap, the protocol allowed callers to supply an unverified, caller-controlled token program parameter (tokenProgramA) for the input token rather than enforcing a check against canonical SPL Token Program addresses. The attacker deployed a custom, dummy Solana program (DMBpPM...) designed to mirror SPL Token Transfer instruction formats and return a success signal without performing any actual token transfers. During the attack, the adversary initiated swap instructions passing USDC as the nominal input token parameter alongside their malicious token program, targeting real liquidity vaults such as HYPE. Aquifer invoked the malicious program via Cross-Program Invocation (CPI), which accepted the parameters and reported a successful transfer. Because Aquifer relied entirely on the CPI return status without verifying actual input token balance deltas, it released output tokens from its vaults without receiving any input tokens. The stolen assets were swapped to SOL, bridged to Ethereum, and converted into approximately 1,000.8 ETH. On the same day, Aquifer's upgrade authority published an on-chain message offering a 20% whitehat bounty if 80% of the funds are returned to designated recovery addresses. Block Data Reference On-Chain Key Addresses: Upgrade Authority: 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA Attacker Solana Address: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J Attacker Ethereum Address: 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 Solana Recovery Address: 8af8RnA | De.Fi↗ |
Aug 30, 2026 Aug 30, 2026 | Tectonic Protocol Unknown chainreported | Oracle issue | Quick Summary On August 30, 2026, decentralized lending protocol Tectonic on Cronos suffered an oracle price manipulation exploit resulting in estimated total losses between $75 million and $119.5 million, with approximately $6 million successfully bridged to Ethereum before Cronos network validators took the emergency step of halting the blockchain to freeze the remaining $68 million+ on-chain. Details of the Exploit The attacker targeted Tectonic's illiquid native token, TONIC, which had low trading volume but was accepted as loan collateral. By executing rapid buy orders on decentralized exchanges, the attacker artificially pumped TONIC's price by roughly 100 times in under 20 minutes. Tectonic's price oracle picked up this inflated price, allowing the attacker to post the pumped tokens as collateral and borrow tens of millions of dollars in stablecoins, WETH, and other liquid assets across the protocol's lending pools. Before protocol operators could intervene, the attacker managed to bridge approximately $6 million in stolen funds to Ethereum. To prevent the remaining stolen funds from exiting the ecosystem, Cronos network validators took the emergency step of halting block production on the entire Cronos blockchain. This action trapped over $68 million of the exploit proceeds in the attacker's Cronos addresses, while leaving Tectonic with massive bad debt and forcing a complete pause of its platform Block Data Reference Key Addresses: Attacker Address 1: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc Attacker Address 2: 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc Attacker Contract: 0x085f3115ca368aa262246d22f9476e1e2c87e8be | De.Fi↗ |
Aug 28, 2026 Aug 28, 2026 | Avici Unknown chainreported | Access control | Quick Summary On August 28, 2026, crypto card provider Avici and three other card programs suffered an exploit totaling approximately $1.02 million (~10,000 SOL) due to an instruction verification flaw in their shared card contract managed by partner Rain. The attacker exploited the bug to grant themselves admin rights, drained card collateral pools, swapped the funds to USDC, bridged them to Ethereum, and deposited ~418 ETH into Tornado Cash. Details of the Exploit The vulnerability was present in an older Solana smart contract developed by card issuer Rain, which managed user card top-up balances independently from self-custodial user wallets. The exploit relied on an instruction index trick in Solana's Ed25519 signature verification precompile. The attacker submitted a transaction with two Ed25519 instructions: the first carried a genuine signature from a newly generated throwaway key, while the second instruction set its signature, public key, and message indexes to point back to the index of the first instruction. The precompile re-verified the valid signature from the first instruction rather than checking the admin key in the second instruction, leading the contract to incorrectly register two valid admin signatures and grant the attacker full admin privileges (AddCollateralAdmin). Using these elevated privileges, the attacker drained four card programs, collecting 10,000 SOL (~$1.02M USD). They converted the SOL to USDC on Solana, transferred the funds to Ethereum address 0x2cE21E4921d3Eb116526c3651Dac0257657338D5, swapped the proceeds into ~418 ETH, and routed the entire balance through Tornado Cash. Self-custodial Avici wallets were unaffected. Avici reported that $500,859.22 in card balances across 1,685 users was impacted, and confirmed that all affected users will receive full refunds. Block Data Reference Solana Attacker Address: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Ethereum Attacker Address: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5 | De.Fi↗ |
Aug 27, 2026 Aug 27, 2026 | Moonwell Unknown chainreported | Oracle issue | Quick Summary On August 27, 2026, Moonwell’s MAMO lending market on Base was exploited through a combination of collateral-accounting manipulation and DEX oracle manipulation. The attacker deployed roughly $1.95 million in starting capital, inflated their collateral value to borrow over $11 million in mixed crypto assets, and extracted $8.73 million via Circle CCTP to Ethereum, leaving the protocol with around $9.13 million in bad debt. Details of the Exploit The attack began when the exploiter withdrew 800 ETH from Tornado Cash, swapped most of it into about $1.95 million USDC, and bridged those funds to Base to accumulate MAMO tokens. They first deposited 15 million MAMO into Moonwell to mint receipt tokens (mMAMO). Next, instead of using the normal deposit route, they transferred another 53.4 million MAMO directly into the mMAMO contract address. Because this direct transfer bypassed the protocol's minting function and supply caps, it artificially increased the underlying token backing behind every existing mMAMO share by nearly 3.7 times. Holding three-quarters of all receipt tokens, the attacker captured almost all of this sudden collateral equity boost. At the same time, the attacker used aggressive DEX trades across low-liquidity pools to inflate the market price of MAMO from around $0.01 to over $0.40. With both the share backing ratio and the oracle price drastically spiked, Moonwell valued the attacker’s collateral at over $22 million, allowing them to draw 18 separate loans totaling $11.03 million in WETH, cbBTC, USDC, and wstETH. The attacker quickly converted these assets, burned $8.73 million USDC through Circle's cross-chain bridge to Ethereum, and swapped it into DAI. Liquidators stepped in seconds after the final borrow and seized the attacker's remaining collateral shares, but the steep price drop left Moonwell with a net shortfall of roughly $9.13 million. Block Data Reference Key Addresses: Operational / Funds Destination Account: 0xD71dD9B6e6344 | De.Fi↗ |
Aug 23, 2026 Aug 23, 2026 | Term Labs Ethereumreported | Other | Quick Summary On August 23, 2026, fixed-rate lending provider Term Labs suffered a governance exploit affecting its Term Vaults (built on Yearn v3 vault infrastructure), resulting in the loss of approximately $8.5 million in digital assets (~2,843 ETH and ~1.68M USDC). Details of the Exploit The incident occurred not through a code bug or reentrancy flaw, but through the manipulation of vault governance rules enabled by low voter participation and float. The attacker initially funded with 2 ETH routed through Tornado Cash acquired sufficient voting influence to pass parameter changes as designed by the protocol's governance architecture. Once vault control was secured, the attacker executed a structured sequence of transactions that unraveled integrated positions across external lending protocols (including Aave and Morpho), unwinding staked ETH positions and draining approximately 2,843 ETH alongside 1.68 million USDC. The attacker subsequently swapped the stolen USDC for roughly 1.6 million DAI and consolidated the funds in wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Block Data Reference Key Attacker Address: 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 | De.Fi↗ |
Aug 21, 2026 Aug 21, 2026 | THE Sandbox Ethereumreported | Access control | Quick Summary On August 21–22, 2026, The Sandbox gaming platform experienced an exploit targeting its LayerZero-based Omnichain Fungible Token (OFT) bridge deployments on Base and BNB Smart Chain (BSC). By hijacking LayerZero delegate permissions via approveAndCall, the attacker minted massive quantities of unbacked SAND tokens on destination chains. The attacker then initiated cross-chain redemptions back to Ethereum L1, completely draining the ~14.75 million SAND (~14,753,431 SAND) backing escrow held in the Ethereum OFT adapter contract. Details of the Exploit The attack exploited a permission configuration flaw in the LayerZero OFT delegate settings for the SAND token on Base and BSC. By leveraging approveAndCall, the attacker hijacked the protocol's delegate permissions and issued unauthorized minting calls across 700+ transactions to 173 addresses, generating trillions of face-value unbacked SAND tokens on Base. While the majority of the unbacked L2 mints were hyper-inflated tokens isolated on destination chains, the attacker successfully submitted cross-chain redemption messages back to Ethereum mainnet. Between 00:32:11 and 01:22:11 UTC on August 22, the Ethereum OFT adapter escrow (0xac531eb26ca1d21b85126de8fb87e80e09002dcf) was drained from 14,769,723 SAND down to ~0.0056 SAND across 15 exit transactions (with ~14.1 million SAND transferred to a single EOA in 6 transactions). Total L1 supply remained unchanged at 3 billion SAND, but the mainnet bridge escrow backing L2 tokens was completely depleted (~14.75M SAND, representing <0.01% of total SAND supply). Block Data Reference Ethereum SAND Token / OFT Contract: 0x3845badade8e6dff049820680d1f14bd3903a5d0 Ethereum OFT Adapter Escrow: 0xac531eb26ca1d21b85126de8fb87e80e09002dcf | De.Fi↗ |
Aug 19, 2026 Aug 19, 2026 | Maya Protocol Unknown chainreported | Other | Quick Summary On August 19, 2026, cross-chain liquidity network Maya Protocol was exploited for approximately $1.7 million in assets (including 20.83 BTC valued at ~$1.4M), leading to an overall liquidity pool valuation drop of ~$11 million. Details of the Exploit The exploit targeted Trade Accounts (ported from THORChain in mid-2025) that were never integrated into Maya's solvency checker (vault.Coins) or outbound transaction-matching logic. The attacker deposited 8 ETH and 2 LINK into trade accounts, then submitted a 23-message MsgDeposit batch consisting of 22 trade withdrawals (each incremented by ~263 units to prevent outbound batching) and 1 donation. Because the nodes observed 22 simultaneous L1 outbounds unmatched by standard TxOutItems, the security system incorrectly flagged the attacker's own legitimate withdrawals as external theft. This false alert triggered the automated subsidizePoolsWithSlashBond() theft-compensation handler. Lacking an upper cap, the handler attempted to dump ~49.42 million CACAO into the pools to compensate for the non-existent theft. Although the transaction failed on-chain due to insufficient reserve funds (~168,000 CACAO actual reserve), a state accounting flaw saved the inflated pool balance regardless. Having pre-positioned in an almost empty ARB.LINK liquidity pool with 100 CACAO, the attacker withdrew 99% of their LP position, extracting 48,869,502 CACAO. The attacker then executed 10 consecutive CACAO-to-BTC swaps, siphoning 20.83 BTC directly to a Bitcoin address and triggering secondary arbitrage extraction across the network. Block Data Reference Key Attacker Bitcoin Address: bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646 | De.Fi↗ |
Aug 15, 2026 Aug 15, 2026 | FOX BNB Chainreported | Flash loan attack | Quick Summary On August 15, 2026, BSC-based bond market protocol Fox Market was exploited via an atomic flash-loan attack. The attacker utilized ~$482 million in flash-loaned stablecoins to trigger over-minting of protocol bonds and siphon ~$678,000 from the PancakeSwap FOX/USDT liquidity pool, yielding ~$117,000 in net attacker profit after flash-loan fees. Details of the Exploit The attack targeted a critical ordering vulnerability in the stake() function on contract 0x9fa6d8a13b35e051bfc145918db0111dec13d1a0. When executed, stake() sampled the FOX token spot price ($5.44) prior to executing the swap of injected USDT into the underlying PancakeSwap pool. Attacker 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 borrowed ~$482 million in USDT across Lista, Venus, and Aave, passing the capital into the bond minting routine. Because the mint valuation calculated token issuance based on the pre-swap spot price rather than the post-swap execution price, the protocol printed ~181x more bond tokens (88.66M sFOX) than intended. The contract then burned the newly created LP tokens to 0x00...dead and instantly paid an unlocked 3% referral bonus in FOX (2.66M tokens) to an inviter address. The attacker dumped these referral tokens directly into the newly USDT-heavy PancakeSwap pool, drained ~$678,000 from existing pool liquidity, fully repaid all $482 million in flash loans, and extracted ~$117,000 in net profit. Block Data Reference Exploit Transaction: 0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514 Attacker: 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 Attack Helper Contract: 0x3A82A2A77061017927e5331fFFd07c0308a1D2DA | De.Fi↗ |
Aug 13, 2026 Aug 13, 2026 | Whale Wallet Drain Ethereumconfirmed | Phishing | Q uick Summary On August 13, 2026, an unknown victim address (0x13e382dfe53207E9ce2eeEab330F69da2794179E) was drained of approximately $25.6 million in cryptocurrency assets, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M). This marks the second major exploit targeting this exact whale address, which previously lost $24.23 million to a malicious token approval phishing attack in September 2023. Details of the Exploit The attacker executed unauthorized transfers siphoning $25.6 million in multi-asset holdings, including WBTC, cbBTC, aWBTC, LDO, USDS, CRV, DAI, and ETH out of the victim's wallet. Immediately following the drain, the attacker swapped the stolen assets across decentralized protocols to consolidate the loot into stable capital, converting the holdings into approximately 20 million DAI and 3,000 ETH (~$5.64M). The consolidated funds were subsequently split across four target collector addresses (including 0x61ce24326d713641583e6a337a69bef7458fcf76), while security monitoring teams track potential recovery or laundering attempts. Block Data Reference Attacker / Theft Address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae Primary Consolidation Address: 0x61ce24326d713641583e6a337a69bef7458fcf76 | De.Fi↗ |
Aug 12, 2026 Aug 12, 2026 | Harmony Unknown chainreported | Other | Quick Summary On August 12, 2026, Layer-1 blockchain Harmony Protocol suffered a major protocol-level security incident when an attacker exploited an "empty blocks" vulnerability to fraudulently mint approximately 4 billion ONE tokens representing roughly 26% of the token's total circulating supply and causing the price of ONE to crash between 26% and 34%. Details of the Exploit The exploit targeted a consensus or state-update bug involving empty blocks, allowing the attacker to mint ~4 billion ONE tokens out of thin air while bypassing standard protocol reporting endpoints (leaving totalSupply metrics temporarily unchanged). The attacker rapidly transferred approximately 2.8 billion ONE (~97% of the fraudulently created tokens) directly into centralized crypto exchanges for liquidation, leaving only around 115 million ONE in on-chain addresses. In response, Harmony requested exchanges to freeze funds from four identified attacker wallet addresses while the core team began developing a software patch and evaluating blockchain rollback options. Block Data Reference Key Attacker Addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510) one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5) | De.Fi↗ |
Aug 10, 2026 Aug 10, 2026 | Coinsbuy Ethereumreported | Access control | Quick Summary On August 10, 2026, cryptocurrency payment platform Coinsbuy suffered a coordinated hot wallet compromise across both TRON and Ethereum, losing approximately $7.9 million to $8.07 million in under an hour. Coinsbuy temporarily halted deposits and withdrawals to contain the incident before fully covering all affected balances from its corporate reserves and resuming normal operations without client loss. Details of the Exploit The attacker executed a rapid, cross-chain operation impacting multiple hot wallet addresses simultaneously. On TRON, the perpetrator drained roughly $6.04 million in USDT across eight wallets within an hour. Concurrently on Ethereum, three hot wallets were emptied of approximately 1.89 million USDT along with native ETH. The attacker leveraged cross-chain swap services (including Bridgers) and non-custodial exchanges (FixedFloat, ChangeNOW, and BingX) to route ~79% of the stolen funds through a non-clusterable pattern, splitting transactions across 50 single-use addresses to convert the capital into Monero (XMR). While ChangeNOW managed to freeze a six-figure sum of the illicit transfer, the majority of the stolen assets were converted into untraceable privacy coins. Coinsbuy subsequently refilled the drained hot wallets from its balance sheet, indicating the underlying platform infrastructure remained secure. Block Data Reference Key Attacker Addresses: TRON Collector: TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR Ethereum Collector: 0x4d1bef2fe998b3e3c4029ef9ea6a0534d95661d3 Ethereum Swap Wallet: 0x66790b54b891e2ebdef58a15b969ff6fb4374b17 | De.Fi↗ |
Aug 9, 2026 Aug 9, 2026 | Coreum Unknown chainreported | Other | Quick Summary On August 9, 2026, the Coreum cross-chain bridge connecting to the XRP Ledger (XRPL) was exploited due to a deposit verification flaw, resulting in the theft of 199,916 XRP (valued at approximately $200,000) across 94 transactions within 97 minutes. Details of the Exploit The attack targeted a vulnerability in the Coreum bridge's deposit verification logic and multisig relayer infrastructure connecting the Coreum blockchain to the XRP Ledger. By exploiting a flaw in how incoming cross-chain deposit proofs were validated, the attacker tricked the relayer system into recognizing unverified or forged deposit events as legitimate. Over a 97-minute window, the attacker executed 94 consecutive fraudulent withdrawal requests, systematically siphoning 199,916 XRP out of the bridge liquidity before operations could be suspended. | De.Fi↗ |
Aug 3, 2026 Aug 3, 2026 | Risex Unknown chainreported | Other | Quick Summary On August 3, 2026, perpetual exchange protocol RISEx experienced an unauthorized withdrawal of 673,011.56 USDC from the Real-World Asset (RWA) yield strategy linked to its XLP liquidity vault due to a smart contract misconfiguration. The team patched the vulnerability within minutes and fully reimbursed XLP depositors using protocol fee revenue, resulting in zero user losses. Details of the Exploit The exploit was caused by a configuration flaw in the RWA yield strategy connected to RISEx's XLP vault, which had been present since its deployment on July 13, 2026. An unauthorized user took advantage of this misconfiguration at 07:21 UTC to execute an unverified withdrawal of 673,011.56 USDC. Because the withdrawal amount sat below the protocol's automatic rate-limiting and throttling thresholds, the transaction executed on-chain. RISEx engineering detected the transaction within minutes and deployed a patch by 08:09 UTC. The protocol covered 100% of the lost capital using a portion of its July trading fee revenue. Block Data Reference Attack Transaction: 0xc52560bec154a3d5533a321bd9805305a5076194573ddb2fbb059059ace3e987 | De.Fi↗ |
Aug 2, 2026 Aug 2, 2026 | Loopsdao BNB Chainreported | Oracle issue | Quick Summary On August 2, 2026, LOOPSDAO's LpdFi protocol on BNB Chain was exploited for approximately $690,000 in USDC (netting ~$573,000 in profit) through a combination of spot price oracle manipulation and a flaw in the protocol's discrete daily interest accrual logic. Details of the Exploit The attack targeted Lpd.price(), which derived token valuations directly from the instantaneous reserves of a PancakeSwap LPD/USDC liquidity pair without TWAP, liquidity thresholds, or price deviation guards. The attacker temporarily inflated the LPD spot price by ~5,163x via temporary liquidity swaps and invoked buy(), allowing them to record a massive $140M nominal USDC interest-bearing principal for a minimal LPD deposit. After rebalancing the pool and stepping across the daily issue boundary in the subsequent block (just one second later), the attacker called claimInterest(), which accrued a full 0.5% interest period on the bloated principal and forced the protocol to burn 1.68 million of its own Cake-LP tokens (with zero slippage bounds) to pay out the unbacked USDC. Block Data Reference Attacker Address: 0x5d289266d85ef671561ba3f253fb79327c193f33 Attack Executor Contract: 0x7f5ad0a998dcb3f5006f0d152bebc055979ef711 Victim / Vulnerable Contract: 0xce6a6e4413d85a136bbac8aae6fb46eaa77f295e Setup Transaction: 0xbb5b8573d7203e00f8fb9d4839dbeea46a8efd367eac8bed81e4ece2341c3588 Claim Transaction: 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6 | De.Fi↗ |
Aug 2, 2026 Aug 2, 2026 | Moke Token BNB Chainreported | Access control | Quick Summary On August 2, 2026, the MOKE token protocol on BNB Chain was exploited for approximately $907,700 (~1,546 BNB) due to a critical access control flaw in its smart contract architecture. Details of the Exploit The exploit was caused by an unprotected public claim() function within the MokeToken.releaseContract() contract, which lacked caller eligibility checks or role-based access control. The attacker repeatedly called claim() to drain roughly 166 million MOKE tokens directly from the protocol's internal reserve pool. To realize their profit, the attacker combined flash loans, Venus Protocol leverage, liquidity pool removal, and internal dividend distribution mechanics to swap the extracted tokens into 1,546 BNB. Block Data Reference Attack Transaction: 0x0776048b1b58064fb31b6513721811e7b44d6bdbe7bf5833158b241ca6756a8f | De.Fi↗ |
Aug 1, 2026 Aug 1, 2026 | Totally Unknown Protocol XYZ Ethereumconfirmed | Rugpull | Unmatched project for pending review. | De.Fi↗ |
Jul 30, 2026 Jul 30, 2026 | Coldcard Unknown chainreported | Other | Quick Summary Starting July 30, 2026, Bitcoin hardware wallet manufacturer Coldcard (by Coinkite) disclosed a critical firmware entropy defect that enabled attackers to systematically brute-force and drain user funds offline, resulting in cumulative losses estimated between $85 million and $130 million+ (~1,900 to 2,055+ BTC) across multiple organized attack waves. Details of the Exploit The vulnerability originated from a firmware code refactoring introduced in version 4.0.1 (March 2021), where seed phrase generation calls were migrated from ckcc.rng_bytes() to ngu.random.bytes(). This migration unintentionally caused the underlying rng_get() function to resolve to MicroPython's software Pseudo-Random Number Generator (PRNG) fallback instead of Coldcard's dedicated True Hardware Random Number Generator (TRNG). Consequently, generated wallet seeds possessed severely degraded entropy, approximately 40 bits on Mk3 devices and ~72 bits on newer models, down from the intended 128/256 bits. Attackers leveraged this reduced search space to pre-compute and offline brute-force the predictable private keys for affected single-signature addresses, executing sweeping transactions across four distinct waves without requiring physical access to the hardware devices. Coinkite issued security advisories across affected models (Mk3, Mk4, Q, Mk5) while security researchers worked with victims to perform Replace-By-Fee (RBF) cancellations for pending mempool sweeps. | De.Fi↗ |
Jul 28, 2026 Jul 28, 2026 | Lula Token BNB Chainreported | Flash loan attack | Quick Summary On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan. Details of the Exploit The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios. This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit. Block Data Reference Attack Transaction: 0xa219ab9d57e520e5235b15a8801f4ebac8cc45551be0430ce4e49caea0411d7c | De.Fi↗ |
Jul 26, 2026 Jul 26, 2026 | Wemix Unknown chainreported | Access control | Quick Summary On July 26, 2026, WEMIX (the blockchain ecosystem backed by South Korean gaming company Wemade) suffered a smart contract compromise affecting its WEMIX$ stablecoin contract, resulting in an unauthorized minting and transfer of approximately $6.25 million worth of tokens. Details of the Exploit The incident occurred when an unauthorized party compromised the contract ownership privileges of a WEMIX$-related smart contract. Using these administrative rights, the attacker fraudulently minted 5,225,525 WEMIX$ and transferred USDC.e out of the protocol. The attacker converted the fraudulently minted tokens into 30,736 WEMIX and 724,198.27 USDC.e, before bridging the USDC.e over to Ethereum and BNB Smart Chain (BSC). On those destination networks, the funds were swapped into assets including ETH and USDT, with a portion subsequently deposited into centralized exchanges. In response, the WEMIX team temporarily suspended all connected bridges (including Chainlink CCIP and PLAY Bridge), withdrew Foundation-provided liquidity, halted trading across affected liquidity pools (WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$), paused the WEMIX$ Module and PNIX DEX, and coordinated with global exchanges to freeze attacker-linked addresses. | De.Fi↗ |
Jul 26, 2026 Jul 26, 2026 | Garden Finance Ethereumreported | Other | Quick Summary On July 26, 2026, cross-chain atomic swap protocol Garden Finance suffered a supply chain compromise affecting its Hash Time-Locked Contracts (HTLC), resulting in an initial drain of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, BNB Chain, and Solana. Details of the Exploit The exploit was an off-chain supply chain attack rather than a direct smart contract code vulnerability. An attacker compromised the off-chain database of an independent solver integrated with Garden Finance and injected forged transaction records. Because the protocol relies on solver state data to process cross-chain atomic swaps between Bitcoin and EVM/Solana networks, these fraudulent records deceived the HTLC contracts into releasing escrowed USDT assets directly to the attacker without valid matching inputs. Garden Finance immediately took its front-end web application offline to prevent further improper fund releases, confirming that while core smart contracts remained secure, the breach stemmed entirely from off-chain solver infrastructure. Block Data Reference EVM Attacker Address: 0x25b224c05f6cc5e132165c1621de1a4c3b316999 Solana Attacker Address: WZy4xxpqktWa1b6MPMRiWsD487CT8mDcapB6GufBJCH Example EVM Exploit Transaction: 0x9d7a961aa340156b7342839e9f6448a26dea9acd38dc7b2638966eb19e29d395 | De.Fi↗ |
Jul 25, 2026 Jul 25, 2026 | Triple A Ethereumreported | Access control | Quick Summary On July 25, 2026, Singapore-based licensed stablecoin payment gateway Triple-A suffered a hot wallet compromise across multiple blockchains, resulting in the unauthorized extraction of approximately $9.7 million to $11.8 million in company-owned treasury assets. Details of the Exploit The incident occurred when an unauthorized party obtained compromise access to Triple-A's multi-chain hot wallet infrastructure across TRON, Ethereum, Polygon, and Arbitrum. The attacker drained the company's operational treasury accounts, swapped the stolen digital assets, and bridged them to Ethereum Mainnet, consolidating 5,227 ETH into a single holding wallet. Client funds were entirely unaffected because Triple-A does not provide digital asset custody for its users, keeping client balances strictly segregated in trust accounts with safeguarding financial institutions. Triple-A temporarily placed certain services into maintenance mode for approximately three hours to secure the affected infrastructure before fully restoring normal payment processing, transaction settlements, and global operations. | De.Fi↗ |
Jul 25, 2026 Jul 25, 2026 | Projekt Green Gold Ethereumreported | Flash loan attack | Quick Summary On July 25, 2026, the Projekt (GREEN/GOLD) reward vault on Ethereum was exploited, resulting in the loss of approximately 301.7 ETH (valued at ~$560,000) due to a logic flaw in its buy-to-earn reward allocation tracking. Details of the Exploit The exploit targeted a logic error in the reward vault's permissionless trackPurchase(buyer) function, which was designed to credit ETH allocations to buyers based on token balance deltas. Crucially, trackPurchase relied solely on token balance increases to calculate reward sizing without validating whether genuine ETH was spent to acquire those tokens. To execute the attack, the exploiter secured a flash loan of approximately 14,000 WETH from Morpho. They pushed these funds into dozens of Uniswap V2 memecoin liquidity pairs (such as Kirby Inu and ROTTSCHILD) and invoked skim() to transfer the tokens directly to their contract. This self-dealing token movement inflated the buyer's balance delta, tricking the unverified trackPurchase function into registering massive fake "purchase" reward allocations at virtually zero net cost. Once the fake allocations were credited and the flash loan repaid in the same transaction, the attacker called massWithdraw() to drain ~301.7 ETH from the vault's reward pool. Block Data Reference Attacker Address: 0x61e7ad696215688d274c729a4cd0fbbc88fc4f85 Victim / Vulnerable Contract: 0x574fc478bc45ce144105fa44d98b4b2e4bd442cb Attack Transaction: 0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64 | De.Fi↗ |
Jul 23, 2026 Jul 23, 2026 | Solido Cash Unknown chainreported | Oracle issue | Quick Summary On July 23, 2026, Solido Cash on the Supra blockchain was exploited due to an oracle fallback misconfiguration on its SOLID vault. An attacker leveraged an invalid stale price fallback to over-mint CASH stablecoins and extract approximately 293.7 million SUPRA tokens (~$73,400 net value), with protocol reserves absorbing the loss so zero user funds were affected. Details of the Exploit The exploit stemmed from an oracle misassignment where a stale primary price feed for the SOLID token incorrectly fell back to the $1.00 CASH stablecoin oracle instead of halting or using a proper secondary feed. Treating cheap SOLID collateral as equivalent in value to CASH, the attacker executed atomic contract interactions and manual secondary wallet mints to generate unbacked CASH stablecoins, which were immediately swapped for native SUPRA tokens across local decentralized exchanges. Solido Cash subsequently paused vault interactions and patched the oracle fallback mappings. | De.Fi↗ |
Jul 23, 2026 Jul 23, 2026 | Verus Unknown chainreported | Other | Quick Summary On July 23, 2026, the cross-chain bridge connecting the Verus blockchain to Ethereum was exploited for the second time in two months, resulting in the unauthorized extraction of approximately $7.53 million across multiple digital assets. Details of the Exploit The exploit targeted a semantic and authority validation flaw in how the Ethereum-side bridge contract verifies cross-chain export outputs from Verus. While the contract verified that a given export payload existed within a valid Verus block and matched a genuine state root notarized on Ethereum, it failed to verify that the Verus network itself had authorized the payload as a legitimate primary export. The attacker initiated a tiny 0.01 VRSC bridge transaction to create a valid export state, then authored a custom Verus transaction spending that output and attaching a handwritten export commitment declaring 8 transfer instructions to the attacker's wallet. After relaying two legitimate notarizations to Ethereum containing the state root of their custom transaction, the attacker submitted the import request. Because the cryptographic Merkle proofs and payload hash checks matched the attacker-controlled input data, the bridge executed the transfer, releasing $7.53 million in tBTC, DAI, USDC, scrvUSD, USDT, MKR, and EURC. The stolen assets were immediately swapped on-chain for 3,916.1 ETH and deposited into Tornado Cash. Block Data Reference Attacker Address: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 | De.Fi↗ |
Jul 23, 2026 Jul 23, 2026 | AFX Unknown chainreported | Access control | Quick Summary On July 23, 2026, the cross-chain custody bridge operated by decentralized exchange AFX on Arbitrum was exploited, resulting in the unauthorized withdrawal of 24.15 million USDC. Details of the Exploit The incident was carried out via a private key or backend validator infrastructure compromise. The attacker forged an on-chain withdrawal request on Arbitrum that carried valid cryptographic signatures from five bridge validators. Because these signatures satisfied the bridge contract's multi-signature authorization threshold, the contract executed the transaction as legitimate and released 24.15 million USDC from custody. The attacker immediately bridged the stolen stablecoins from Arbitrum to Ethereum Mainnet and swapped them for approximately 12,467.5 ETH. Following detection, AFX suspended bridge operations to isolate the vulnerability, confirming that the platform's core trading engine, mainnet, and Arbitrum's native bridge remained uncompromised while security teams began tracing the funds. Block Data Reference Arbitrum Creation Transaction: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Arbitrum Finalize Transaction: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b Ethereum Attacker Wallet: 0x627654b2782bfc57580ecd11d40869b350b6ebac | De.Fi↗ |
Jul 23, 2026 Jul 23, 2026 | B Network BNB Chainreported | Access control | Quick Summary On July 23, 2026, Bitcoin Layer-2 protocol B² Network suffered a security incident on BNB Chain targeting its B2 token staking service, resulting in the unauthorized extraction of approximately 8.59 million B2 tokens (valued at ~$3.86 million). Details of the Exploit The exploit was caused by a compromise of the administrative upgrade authority governing the upgradeable proxy contract for B² Network's staking service. An address (0x35fE...b287d) that had granted itself privileged admin permissions over a year prior (May 2025) executed an upgradeToAndCall function call on the live staking proxy contract. This replaced the legitimate contract implementation with a malicious logic contract (0x0B875E...C9DCa). Six minutes after the proxy upgrade, the attacker invoked draining functions through the newly deployed logic, extracting ~8.59 million B2 tokens across nine batch calls within 45 minutes. The stolen B2 tokens were swapped on-chain for 5,409 WBNB, converted to 1,128 ETH, and bridged out of BNB Chain via Near Intents. Block Data Reference Malicious Implementation Contract: 0x0B875E23C6b04D3683f1D4c4f0FFf7f2b5cC9DCa Upgrade Transaction: 0x2069714bbe6671f7737f85c5caee7fbccd15ed8f045b2cd6f6b52229cd47d769 | De.Fi↗ |
Liquidations updated 4h ago · Incidents updated 2d ago