Yield.ly
LearnFind My Yield Alpha
LearnAlpha

Discover

Workspace

Yield Alpha

Founding Partner

Exclusive founding placement. Rankings independent.

Apply→
Skip to main content
Yield.ly
LearnFind My Yield Alpha
LearnAlpha

Discover

Workspace

Yield Alpha

Founding Partner

Exclusive founding placement. Rankings independent.

Apply→
  1. Dashboard
  2. /Rekt

Rekt

Lending liquidations and protocol incidents from on-chain events and De.Fi reports.

Recent lending liquidations

On-chain liquidation events from Aave V3, Morpho, and Compound V3 on Ethereum, Base, and Arbitrum. USD values appear only when evidence exists.

50 shown

  • Aave V3
    Base
    4h ago
    Collateral seized
    112,651
    Debt repaid
    107,800
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4h ago
    Collateral seized
    30,676
    Debt repaid
    34
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    5h ago
    Collateral seized
    28,833
    Debt repaid
    32
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    8h ago
    Collateral seized
    7.2895
    Debt repaid
    6.9737
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    9h ago
    Collateral seized
    24,835
    Debt repaid
    23,764,125,830
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    10h ago
    Collateral seized
    61,049
    Debt repaid
    68
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    11h ago
    Collateral seized
    230
    Debt repaid
    82,007
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    1d ago
    Collateral seized
    574.8084
    Debt repaid
    550.0559
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    1d ago
    Collateral seized
    341,704
    Debt repaid
    326,973,972,603
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    2d ago
    Collateral seized
    103,544
    Debt repaid
    32,219,880
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    2d ago
    Collateral seized
    27,574
    Debt repaid
    31
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    2d ago
    Collateral seized
    50,567
    Debt repaid
    48,390
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    2d ago
    Collateral seized
    46,571
    Debt repaid
    44,566
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    13,019,741,984
    Debt repaid
    10,002,870,840
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    440,968
    Debt repaid
    156,120,598
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    470,108
    Debt repaid
    166,437,985
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    584,128,962,810
    Debt repaid
    558,936
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    440,014
    Debt repaid
    421,005
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    583,848
    Debt repaid
    558,707
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    936,983,943
    Debt repaid
    896,635,352
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    2d ago
    Collateral seized
    3,965
    Debt repaid
    3.1575
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    3d ago
    Collateral seized
    16.1079
    Debt repaid
    15.8231
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    3d ago
    Collateral seized
    21,624,231,506
    Debt repaid
    3.5822
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    3d ago
    Collateral seized
    302
    Debt repaid
    108,810
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    1,537,895,566
    Debt repaid
    3.9021
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    4d ago
    Collateral seized
    194.0785
    Debt repaid
    2,476
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    141,777,152,857
    Debt repaid
    363.0144
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    2,965
    Debt repaid
    2,523
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    4d ago
    Collateral seized
    147.4028
    Debt repaid
    1,959
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    11.7844
    Debt repaid
    11.2778
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    37,494
    Debt repaid
    42
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    958,065,373,038
    Debt repaid
    916,808,969,414
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    554,035
    Debt repaid
    530,178
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    583,137
    Debt repaid
    558,027
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    4d ago
    Collateral seized
    795,150
    Debt repaid
    760,910
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    2,459
    Debt repaid
    854,587
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    50,831
    Debt repaid
    57
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    124,108
    Debt repaid
    138
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    4d ago
    Collateral seized
    145.5082
    Debt repaid
    1,959
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    418,637,575,022
    Debt repaid
    1.2633
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    248
    Debt repaid
    86,956
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    15,033
    Debt repaid
    5,283,976
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    25,647
    Debt repaid
    9,069,171
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    30,344
    Debt repaid
    10,743,427
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Base
    4d ago
    Collateral seized
    367,473,427
    Debt repaid
    318,275,695
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Ethereum
    5d ago
    Collateral seized
    808,710,281,725
    Debt repaid
    2.4659
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    5d ago
    Collateral seized
    1,077,429
    Debt repaid
    2,794
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    5d ago
    Collateral seized
    24,046,561,018
    Debt repaid
    4,428
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    5d ago
    Collateral seized
    17,022,570
    Debt repaid
    219,814,553,176
    USD value
    Unknown
    View transaction↗
  • Aave V3
    Arbitrum
    5d ago
    Collateral seized
    148,716,013
    Debt repaid
    1.9204
    USD value
    Unknown
    View transaction↗
Recent lending liquidations
WhenProtocolCollateralDebtUSDTx
4h ago
Oct 6, 2026
Aave V3
Base
112,651107,800UnknownView↗
4h ago
Oct 6, 2026
Aave V3
Base
30,67634UnknownView↗
5h ago
Oct 6, 2026
Aave V3
Base
28,83332UnknownView↗
8h ago
Oct 6, 2026
Aave V3
Arbitrum
7.28956.9737UnknownView↗
9h ago
Oct 6, 2026
Aave V3
Base
24,83523,764,125,830UnknownView↗
10h ago
Oct 6, 2026
Aave V3
Base
61,04968UnknownView↗
11h ago
Oct 6, 2026
Aave V3
Base
23082,007UnknownView↗
1d ago
Oct 5, 2026
Aave V3
Base
574.8084550.0559UnknownView↗
1d ago
Oct 4, 2026
Aave V3
Base
341,704326,973,972,603UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Base
103,54432,219,880UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Base
27,57431UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Base
50,56748,390UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Base
46,57144,566UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
13,019,741,98410,002,870,840UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
440,968156,120,598UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
470,108166,437,985UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
584,128,962,810558,936UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
440,014421,005UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
583,848558,707UnknownView↗
2d ago
Oct 4, 2026
Aave V3
Arbitrum
936,983,943896,635,352UnknownView↗
2d ago
Oct 3, 2026
Aave V3
Arbitrum
3,9653.1575UnknownView↗
3d ago
Oct 3, 2026
Aave V3
Ethereum
16.107915.8231UnknownView↗
3d ago
Oct 3, 2026
Aave V3
Ethereum
21,624,231,5063.5822UnknownView↗
3d ago
Oct 2, 2026
Aave V3
Base
302108,810UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
1,537,895,5663.9021UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Ethereum
194.07852,476UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
141,777,152,857363.0144UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
2,9652,523UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Ethereum
147.40281,959UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
11.784411.2778UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
37,49442UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
958,065,373,038916,808,969,414UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
554,035530,178UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
583,137558,027UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Arbitrum
795,150760,910UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
2,459854,587UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
50,83157UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
124,108138UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Ethereum
145.50821,959UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
418,637,575,0221.2633UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
24886,956UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
15,0335,283,976UnknownView↗
4d ago
Oct 2, 2026
Aave V3
Base
25,6479,069,171UnknownView↗
4d ago
Oct 1, 2026
Aave V3
Base
30,34410,743,427UnknownView↗
4d ago
Oct 1, 2026
Aave V3
Base
367,473,427318,275,695UnknownView↗
5d ago
Oct 1, 2026
Aave V3
Ethereum
808,710,281,7252.4659UnknownView↗
5d ago
Oct 1, 2026
Aave V3
Arbitrum
1,077,4292,794UnknownView↗
5d ago
Oct 1, 2026
Aave V3
Arbitrum
24,046,561,0184,428UnknownView↗
5d ago
Oct 1, 2026
Aave V3
Arbitrum
17,022,570219,814,553,176UnknownView↗
5d ago
Oct 1, 2026
Aave V3
Arbitrum
148,716,0131.9204UnknownView↗

Protocol incidents

Exploit and incident reports from De.Fi. Yield.ly does not verify incident severity or completeness.

50 shown

  • Adapter Vault Drain
    Unknown chainAccess controlreported
    2d ago

    Impact

    Quick Summary On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum.    Details of the Exploit The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d). Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched.   Block Data Reference Target Adapter Contract: 0xd1895f2019c2152fc2b9022d57f19198c4cfcabc    Owner Safe Address (3-of-7): 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4 Attacker Deployer Address: 0x0B5126e1bc27C0de77e02e97945760A674EdB034    Attacker Whitelisted Contract: 0xcdfe91301356da873562ef513828a60dba1f569d Fund Destination Address: 0xC73448432a05deeA5Ea18a07D3b5d9ccf6297f8D

    View on De.Fi↗
  • Goldpesa
    Unknown chainOtherreported
    4d ago

    Impact

    Quick Summary On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions. Details of the Exploit The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router. Block Data Reference Attack Transaction Hash: 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9 Attacker Address: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F Vulnerable Contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8

    View on De.Fi↗
  • Near Intents
    EthereumOtherreported
    5d ago

    Impact

    Quick Summary On October 1, 2026, cross-chain protocol NEAR Intents was exploited for approximately $3,8 million following a hot wallet drain on BNB Smart Chain caused by an integration bug in its Omni bridge infrastructure. On-chain analysis linked the attacker to North Korea's Lazarus Group, while the protocol team patched the flaw and pledged full user reimbursement. Details of the Exploit The attack stemmed from an integration logic flaw between NEAR Intents smart contracts and its Omni deposit/withdrawal layer on BNB Smart Chain, allowing the attacker to execute unauthorized hot wallet withdrawals. The attacker extracted ~$3.865M on BSC, routed a portion toward KuCoin, bridged funds to Ethereum, and executed seven Chainflip swaps to acquire ~33.7 BTC (~$2.9M), which remains parked across four unspent Bitcoin addresses. On-chain tracking confirmed the attacker interacted with known Lazarus Group infrastructure (0x098B7...E2f96). In response, NEAR Intents patched the contract-side flaw, temporarily suspended Omni bridge operations across 11 chains, and guaranteed 100% user compensation from protocol reserves. Block Data Reference BSC Attack Hashes: 0x9fe58e031f73bbd880c782bc9e7446bcda32cadb304a729209871a4a81856c4c 0x0381265d6a1bb09de899f49f410a8b907cd548358a7e3c91076c3a52656b8220 0x69d1c68c7e961a0199d3c9f3b6a31cb168ed775ef34b51a42762253ac1efcceb 0x9c10b967da0c85631ec105e3b322c0a851fcd01b69ff390ff58f860e5cce003a

    View on De.Fi↗
  • MCN Labs
    BNB ChainOtherreported
    6d ago

    Impact

    Quick Summary On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations. Details of the Exploit The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time. The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Attacker Address: 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a Vulnerable Contract: 0x52272524a22f941f5489c1233732797314bb054b

    View on De.Fi↗
  • Fastswap
    BNB ChainOtherreported
    7d ago

    Impact

    Quick Summary On September 29, 2026, the FastSwap protocol on BNB Smart Chain was exploited in an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $92,600 USD. Details of the Exploit An attacker executed a malicious transaction targeting the FIST token and FastSwap smart contracts (0xc9882def23bc42d53895b8361d0b1edc7570bc6a) on BNB Smart Chain. The exploit allowed the attacker to manipulate protocol contracts and drain liquidity pools, extracting ~$92.6K in value within a single transaction. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Target Token / Contract: 0xc9882def23bc42d53895b8361d0b1edc7570bc6a

    View on De.Fi↗
  • Dyorswap
    EthereumPhishingconfirmed
    10d ago

    Impact

    Quick Summary On September 26–27, 2026, scammers deployed a fake OP Stack Layer 2 network impersonating the unreleased GIWA Mainnet (Chain ID 9134) and set up a fraudulent bridge. 1,335 user addresses deposited 767.65 ETH into the fake bridge to trade on DYORSWAP, allowing the scammers to extract 766.25 ETH (~$2.0 million USD) on Ethereum. Details of the Exploit The incident was a fake infrastructure scam rather than a smart contract flaw in DYORSWAP's protocols. Scammers configured a malicious network using GIWA's official Chain ID (9134) alongside a fake bridge and OP Stack batcher. When traders connected to the fake RPC and deposited ETH to trade on DYORSWAP, the malicious bridge contract captured the L1 funds. The scammers drained 766.25 ETH at Ethereum block 26,067,309. DYORSWAP confirmed its core contracts were safe, published a claims collection form, and distributed over 200 ETH from its treasury to compensate affected users while tracing the scammers' funding sources.

    View on De.Fi↗
  • Duelbits
    EthereumAccess controlreported
    12d ago

    Impact

    Quick Summary On September 24, 2026, crypto casino and sportsbook platform Duelbits suffered a multi-chain hot wallet compromise resulting in estimated total losses of $4.9M to $7.0M across Ethereum, BNB Chain, Tron, Bitcoin, and Solana. The platform took its services offline to investigate and refill operational hot wallets while user cold storage remained unaffected. Details of the Exploit The attack was executed via a private key compromise targeting Duelbits' operational hot wallets across five blockchains. On EVM chains, the attacker extracted 836 ETH, 1.146M USDT, 209 BNB, 96.8K USDC, 31.5K DAI, and 12.4B SHIB, alongside 8.1 BTC on Bitcoin and 192K TRX on Tron. The attacker routed the stolen multi-chain assets through swap protocols and cross-chain bridges, converting the proceeds into Ether and consolidating approximately 2,234.6 ETH (~$6.0M) into a single destination Ethereum address. Duelbits confirmed the hot wallet breach and suspended operations pending system remediation and hot wallet refilling. Block Data Reference Attacker EVM Address 1: 0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76 Attacker EVM Address 2: 0x6761c9b15815f4051773EDe39B42B95bdDB3EF1c Attacker Bitcoin Address: bc1qhtu84kz3y94lvgl2t05zk84tqh57grvd82zvcl Attacker Tron Address: TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK Attacker Solana Address: A3EBrhMBEGzcPgmbwywSPhW39G6PFGrorU8ib99T6yKw

    View on De.Fi↗
  • Payy Network
    EthereumAccess controlreported
    12d ago

    Impact

    Quick Summary On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses. Details of the Exploit The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved. An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts.

    View on De.Fi↗
  • Bitget
    EthereumAccess controlreported
    12d ago

    Impact

    Quick Summary On September 24, 2026, centralized exchange Bitget suffered a major infrastructure breach resulting in ~$351.6 million stolen from its hot and warm wallet layers. Bitget paused withdrawals while confirming its cold wallets remained secure and stating that its $464M+ User Protection Fund will fully reimburse user losses. Details of the Exploit The attacker penetrated Bitget's core wallet backend infrastructure and spoofed internal transaction data to trigger authorized withdrawals across multiple blockchains without compromising private keys. Stolen assets included ETH, XRP, USDT, USDC, AVAX, and BNB. On EVM chains, the attacker converted most of the stolen proceeds into 67,982 ETH (~$183 million). On-chain analysis and VPN traffic patterns linked the attack to North Korea's Lazarus Group (specifically the TraderTraitor subgroup) through bridged funds connected to the earlier AFX Trade exploit. Bitget contained the breach, stopped further unauthorized transfers, and is preparing system recovery before resuming withdrawals.

    View on De.Fi↗
  • Meter Protocol
    BNB ChainOtherreported
    13d ago

    Impact

    Quick Summary On September 23–24, 2026, Meter.io suffered a dual consensus and bridge exploit after an attacker leveraged a block validation flaw on Meter mainnet and exploited the Meter Passport bridge on BNB Chain, resulting in ~$2.3 million in unbacked wMTRG minted and partially dumped on PancakeSwap. Details of the Exploit On September 23 at 21:14 UTC, an attacker exploited a block validation flaw on the Meter mainnet consensus layer to mint unbacked MTR and MTRG tokens. The attacker then used the Meter Passport bridge on BNB Chain across two main transactions to mint approximately $2.3 million in unbacked wrapped MTRG (wMTRG), dumping a portion into PancakeSwap liquidity pools and bridging funds out. Meter paused both mainnet and bridge operations, invalidated transactions post-block 100731417, and issued a 72-hour whitehat bounty offer of 10% for the return of funds. Block Data Reference Attacker Addresses: 0xee2eeeed4ed8580669ed924abeb49f27f7d0bd65 0x44cf94496091150865e192a86c07b90a9760b43d 0x7db6ac6Fa3c8aa2c6FB9BdCD4800e8BAacDd2EE8 Abused Token Contract (BSC): 0xBd2949F67DcdC549c6Ebe98696449Fa79D988A9F Sample Exploit Transaction (BSC): 0x2745dd5121eb03d1979cf229f432a422137942ede186d9fa0129a2f83401eeef Bounty Return Address: 0xB980Ff36A99C0C3B408279E025d8E2DA7eF65105

    View on De.Fi↗
  • Astroport
    Unknown chainAccess controlreported
    14d ago

    Impact

    Quick Summary On September 22, 2026, Cosmos ecosystem DEX Astroport suffered a security breach on the Neutron chain that exposed protocol admin controls. Validators halted Neutron and Cosmos Hub to coordinate an emergency response, intercepting approximately 1.396 million ATOM (~$2.53 million USD) before the attacker could cash out. Details of the Exploit The attacker compromised admin privileges for Astroport contracts on Neutron, placing liquidity across connected pools at risk. The attacker converted stolen funds into ATOM and initiated a streaming swap of 200,000 ATOM to ETH via THORChain. Only 15.5% of the swap filled (19.92 ETH) before Cosmos Hub halted at block 33,086,740. Cosmos Hub validators deployed a binary upgrade that transferred 1,227,121 ATOM from the attacker's account to a recovery multisig and added an ante-handler to block the attacker's key from signing future transactions. An additional 168,990 ATOM refund remains queued on THORChain, requiring a secondary sweep once GAIA chain processing unhalts. Astroport contracts on Terra were unaffected after their admin connection to Neutron was severed. Block Data Reference Attacker Cosmos Address: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n   

    View on De.Fi↗
  • RWC Token
    BNB ChainOtherreported
    15d ago

    Impact

    Quick Summary On September 21, 2026, the RWC token protocol on BNB Smart Chain was hit by an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $109,000 USD. Details of the Exploit An attacker executed a malicious transaction targeting the RWC contract on BNB Smart Chain, exploiting a smart contract vulnerability to drain funds from the project's liquidity or protocol pools. Security monitoring systems flagged the atomic execution trace after ~$109,000 in value was extracted. Block Data Reference Attack Transaction Hash: 0x9c919da34696425913f32587f00d2838031a8726a2c5ddfa39e33a45b36e6427

    View on De.Fi↗
  • Internet Token INT
    Unknown chainOtherreported
    15d ago

    Impact

    Quick Summary On September 21, 2026, the Internet Token protocol on Base was exploited for 5.85 WETH and 764 million INT after an attacker leveraged an unvalidated Uniswap V3 pool callback parameter to arbitrarily mint ~925 million INT tokens. Details of the Exploit The vulnerability was present in INT's LiquidityUnifier contract (0x837d...), which held MINTER_ROLE rights and exposed an unvalidated swapV3(token, pool) function. The function only validated that the passed pool parameter contained bytecode and that its token0() and token1() getters returned the INT token address. The attacker deployed a malicious contract returning INT for both token endpoints, causing swapV3 to invoke pool.swap(). This callback re-entered uniswapV3SwapCallback and minted an arbitrary amount of INT tokens directly to the fake pool. The attacker routed the minted tokens through a Convertor contract round-trip to bypass validateSupply sanity checks, created ~925 million INT, dumped a portion into the official INT/WETH V3 pool for 5.85 WETH, and kept the remaining ~764 million INT. Block Data Reference Attack Transaction Hash: 0xed62bb27bd1058d3d7cc93d55421d6d0001ced8cb4529b02773f5126a4edb08b Attacker Address: 0x5f7ce6395818857ac20730dc990f614356d1ec68 Victim Contract: 0x837dbabc4f5fa78baf177597edbda09645822032

    View on De.Fi↗
  • ASI Alliance Singularitynet
    EthereumAccess controlreported
    17d ago

    Impact

    Quick Summary On September 19–20, 2026, an attacker used compromised SingularityNET bridge and NuNet deployer private keys to drain $FET and mint unauthorized supplies of $AGIX,$NTX, $WMTx, and $CGV on Ethereum. The attacker extracted ~$1.44M to $1.67M in liquid ETH before project teams paused bridges and revoked minting authorities. Details of the Exploit The exploit resulted from compromised private signing keys rather than smart contract logic bugs. On September 19, the attacker called conversionIn on Fetch.ai's TokenConversionManagerV3 using a stolen SingularityNET authorizer signature to drain 8.72M $FET (~$1.53M) and swap it for ETH. Minutes later, a compromised NuNet deployer account minted 408.53M $NTX to reach its 1 billion supply cap. On September 20, the attacker used the SingularityNET bridge authority to mint 260M $AGIX, 53.84M $WMTx, and ~500M$CGV. High slippage on low liquidity pools limited total extracted value to 546–649 ETH (~$1.44M–$1.67M), while token market prices collapsed by 65% to 99%. Affected protocols responded by pausing bridges, revoking signing authorities, and contacting exchanges to freeze funds. Block Data Reference Attacker Address: 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE NuNet Deployer Address: 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Fetch.ai Conversion Contract: 0xab424A430CC09864fA1277A38193111705ADF3A3

    View on De.Fi↗
  • Nostra Finance
    Unknown chainOracle issuereported
    19d ago

    Impact

    Quick Summary On September 17, 2026, Starknet money market Nostra Finance suffered an oracle price manipulation exploit resulting in ~$3.53 million in unauthorized borrows across ETH, STRK, USDC, USDT, WBTC, and DAIv1 against inflated NSTR collateral, forcing the protocol to pause all lending, borrowing, and liquidation operations. Details of the Exploit The attacker exploited Nostra Finance's collateral valuation oracle for NSTR by manipulating its underlying price pool on Ekubo DEX. The attacker withdrew existing liquidity around NSTR's real market price, seeded a decoy liquidity band at $99 per NSTR, and routed a $14.72 dust swap (190 NSTR) through the gap to artificially inflate the oracle price by 16,645x. Using just 294,177 NSTR collateral, normally worth ~$1,756, the attacker leveraged the inflated valuation to draw $3,531,922.97 in mixed assets across six borrowing legs. The attacker then bridged ~$1.93 million (234.57 ETH and 1.3M DAI) to Ethereum while leaving ~$1.55 million in assets on Starknet. Block Data Reference Starknet Attacker Contract: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 Ethereum Destination Address: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37

    View on De.Fi↗
  • Bonfire
    BNB ChainPhishingconfirmed
    20d ago

    Impact

    Quick Summary On September 16, 2026, an attacker executed a batched approval-drain sweep targeting holders of the Bonfire (BONFIRE) token on BNB Chain, resulting in a loss of approximately 66.08 WBNB (~$47.4K USD). T Details of the Exploit The attack was executed across two distinct phases within transaction 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f. In the harvesting phase, the attacking contract iterated through a pre-compiled list of 65 addresses that had standing approvals to 0x17e801.... Using transferFrom(), the contract pulled each victim's BONFIRE balance directly into the BONFIRE/WBNB liquidity pair. The contract then called swap() to route tokens out to a collector wallet (0x28E976Ea...), netting the inbound deposits against the outbound legs and steadily increasing the pair's token reserves without swapping for WBNB on each individual transfer. The decaying size of the pulled balances across the iterations indicates a script executing against victims ordered by remaining balance size.   In the cash-out phase, the collector address approved the attacking contract and passed its accumulated ~4,576 BONFIRE back into the liquidity pool across two major sell swaps. These swaps extracted 33.223 WBNB and 32.857 WBNB respectively, totaling 66.08 WBNB, which was subsequently unwrapped to native BNB. Standard events such as SwapAndLiquify observed during the execution were simply Bonfire's automated liquidity tax mechanism firing as intended through its legacy PancakeSwap V1 router. The root vulnerability remains off-chain, stemming either from historical phishing campaigns or compromised keys associated with a legacy custom router contract. Block Data Reference Attack Transaction Hash: 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f   Harvesting Contract: 0x17e801E17CeFC6334059189c178D4783830E03D3 Collector Address: 0x28E976Ea7b83553d6D1D45CE81334156A2632127

    View on De.Fi↗
  • Flamincome
    EthereumFlash loan attackreported
    20d ago

    Impact

    Quick Summary On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan. Details of the Exploit The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit. Block Data Reference On-Chain Key Addresses: Attacker Primary Address: 0x83381e7f7232775735169d72d237b858ffc36871 Target Strategy / Vault: 0xb8d6471ca573c92c7096ab8600347f6a9fe268a5 Exploit Contract 1: 0x875da4bd7b4a52a806a533b1cf6d6ff92365d2e6 Exploit Contract 2: 0x1c7eacef3630e764519e6ea2e8caa2bdb7d8b486

    View on De.Fi↗
  • Meme Coin Phishing Scam
    Unknown chainPhishingconfirmed
    20d ago

    Impact

    Quick Summary On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000.   Details of the Exploit Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader.

    View on De.Fi↗
  • Chainflip
    Unknown chainOtherreported
    24d ago

    Impact

    Quick Summary On September 12, 2026, cross-chain swap protocol Chainflip suffered a memo-manipulation exploit on its Tron settlement layer, resulting in six unauthorized payouts totaling 736,442.17 USDT after an attacker attached custom memos to already-signed transactions to trigger duplicate refund payouts.   Details of the Exploit Unlike other blockchains supported by Chainflip that pass swap instructions via dedicated contract functions, the protocol's Tron integration parses swap parameters directly from transaction memo fields. The attacker discovered a vulnerability allowing a custom memo to be appended to a Tron transaction that Chainflip validators had already signed. Chainflip's backend misread the altered memo as a new, separate swap instruction, classified it as failed, and automatically triggered a refund, effectively paying out against the same underlying deposit a second time. The attacker executed eight attempts over ~90 minutes in the early hours of Saturday, scaling up transaction sizes until six successful attempts extracted 736,442.17 USDT. Chainflip detected the incident after subsequent legitimate USDT payouts began failing due to drained vault reserves. Network operations were paused, a code fix was finalized, and operators committed to making all impacted users whole upon restart.  

    View on De.Fi↗
  • Amnext
    BNB ChainReentrancyreported
    27d ago

    Impact

    Quick Summary On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap. Details of the Exploit Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens. The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB. Block Data Reference Attack Transactions: Main Exploit: 0x29eb97259b5c8d1bbfe791ad5d7bdc981f538ac37c857cc30d6296b31f08afc5 Liquidation: 0x99c9969ab97f97b56766a9d75ec4f82a463bb8e7f9603eecc77b6bb57485d3ba

    View on De.Fi↗
  • Nomic Nbtc Bridge
    Unknown chainOtherreported
    27d ago

    Impact

    Quick Summary On September 9, 2026, a flaw in Nomic's custom forwarding mechanism allowed an attacker to double-spend nBTC and send ~39.84 unbacked nBTC vouchers (~$3.15M USD) to Osmosis, compromising roughly 36% of the backing behind Osmosis's Alloyed BTC (allBTC) token.   Details of the Exploit The attacker exploited a vulnerability in Nomic's custom transaction forwarding system to double-spend nBTC and issue unbacked vouchers through the Inter-Blockchain Communication (IBC) protocol onto Osmosis. Because nBTC serves as a reserve component for Osmosis's unified Alloyed BTC pool, the forged vouchers left allBTC ~36% undercollateralized. Core IBC and Osmosis smart contracts were not directly breached. Following detection, Osmosis paused all minting, redemptions, inflows, and outflows for Nomic and Alloyed BTC. Osmosis validators then executed an emergency chain upgrade that successfully froze 22.65 BTC residing in the attacker's Osmosis account. Osmosis announced plans for a governance vote to seize the 22.65 frozen BTC and reimburse the remaining ~17.19 BTC shortfall from the community pool's BTC reserves to fully restore 1:1 backing.  

    View on De.Fi↗
  • Liquid Network
    Unknown chainOthermitigated
    30d ago

    Impact

    Quick Summary On September 6–7, 2026, Bitcoin sidechain Liquid Network suffered an Elements consensus bug exploit resulting in losses of ~4,000 BTC (~$320 million USD), after unbacked L-BTC tokens were minted and redeemed for real Bitcoin, forcing operators to halt the network while whitehat negotiations proceed on-chain. Details of the Exploit The attacker exploited a consensus vulnerability in the underlying Elements software to forge ~4,000 unbacked L-BTC on Liquid without depositing collateral. These unbacked tokens were submitted through SideSwap's Peg-out Authorization Key service, prompting the Liquid Federation multisig to release ~3,996 real BTC from reserves—draining ~95% of backing. Federation operators subsequently halted the sidechain and exchanges paused L-BTC deposits. The attacker consolidated funds into a single Bitcoin address and left an OP_RETURN message offering to return most of the BTC once Blockstream deploys a network-wide patch. Block Data Reference Mainnet Attacker Address: bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte Federation Reserve Address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr

    View on De.Fi↗
  • Notional Finance
    EthereumOtherreported
    32d ago

    Impact

    Quick Summary On September 4, 2026, lending protocol Notional Finance suffered an integer truncation and rounding error exploit on Ethereum, resulting in an estimated loss of $1.73 million in DAI and USDC, which the attacker swapped into 689.2 ETH and deposited into Tornado Cash.   Details of the Exploit The exploit targeted Notional Finance's escrow and fCash accounting mechanism via a combination of a free-collateral calculation rounding error and an integer downcasting flaw. The attacker executed a two-step transaction sequence calling the mintfCashPair() function. In the first call (mintfCashPair(1)), a small liability (-1) was rounded down to 0 during the DAI-to-ETH free-collateral conversion due to a rounding precision flaw.  In the second call (mintfCashPair(2^256 - 1)), the contract aggregated the account's liabilities in int256, producing a negative balance of $-2^{128}$. However, when validating free-collateral requirements, the valuation logic performed an unsafe downcast using uint128(balance.abs()). Because $2^{128}$ overflows a standard 128-bit unsigned integer, the massive liability truncated directly to zero. This bypassed the protocol's collateral checks entirely, allowing the attacker to draw down 69,257 DAI and 1,658,525 USDC from the escrow contract. The attacker then consolidated the stablecoins, converted them to 689.2 ETH, and routed the funds into Tornado Cash across multiple transactions.   Block Data Reference Setup Transaction: 0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a

    View on De.Fi↗
  • Cozy Finance
    Unknown chainOracle issuereported
    34d ago

    Impact

    Quick Summary On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window.   Details of the Exploit On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7. The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash.   Block Data Reference Attacker Address: 0x003FE7359A4E03C85Ac2f521eC699ED84C7c5ccB

    View on De.Fi↗
  • Aquifer
    EthereumOtherreported
    36d ago

    Impact

    Quick Summary On August 31, 2026, Solana-based automated market maker Aquifer suffered an unverified CPI token program injection exploit resulting in approximately $2.5 million in total losses across 90+ attack transactions, after which the protocol issued an on-chain whitehat offer allowing the attacker to keep 20% if 80% of the stolen funds are returned by September 3, 2026.   Details of the Exploit The exploit targeted Aquifer's swap function on Solana. When executing a token swap, the protocol allowed callers to supply an unverified, caller-controlled token program parameter (tokenProgramA) for the input token rather than enforcing a check against canonical SPL Token Program addresses. The attacker deployed a custom, dummy Solana program (DMBpPM...) designed to mirror SPL Token Transfer instruction formats and return a success signal without performing any actual token transfers.  During the attack, the adversary initiated swap instructions passing USDC as the nominal input token parameter alongside their malicious token program, targeting real liquidity vaults such as HYPE. Aquifer invoked the malicious program via Cross-Program Invocation (CPI), which accepted the parameters and reported a successful transfer. Because Aquifer relied entirely on the CPI return status without verifying actual input token balance deltas, it released output tokens from its vaults without receiving any input tokens. The stolen assets were swapped to SOL, bridged to Ethereum, and converted into approximately 1,000.8 ETH. On the same day, Aquifer's upgrade authority published an on-chain message offering a 20% whitehat bounty if 80% of the funds are returned to designated recovery addresses.  Block Data Reference On-Chain Key Addresses: Upgrade Authority: 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA Attacker Solana Address: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J Attacker Ethereum Address: 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 Solana Recovery Address: 8af8RnA

    View on De.Fi↗
  • Tectonic Protocol
    Unknown chainOracle issuereported
    37d ago

    Impact

    Quick Summary On August 30, 2026, decentralized lending protocol Tectonic on Cronos suffered an oracle price manipulation exploit resulting in estimated total losses between $75 million and $119.5 million, with approximately $6 million successfully bridged to Ethereum before Cronos network validators took the emergency step of halting the blockchain to freeze the remaining $68 million+ on-chain.   Details of the Exploit The attacker targeted Tectonic's illiquid native token, TONIC, which had low trading volume but was accepted as loan collateral. By executing rapid buy orders on decentralized exchanges, the attacker artificially pumped TONIC's price by roughly 100 times in under 20 minutes. Tectonic's price oracle picked up this inflated price, allowing the attacker to post the pumped tokens as collateral and borrow tens of millions of dollars in stablecoins, WETH, and other liquid assets across the protocol's lending pools.  Before protocol operators could intervene, the attacker managed to bridge approximately $6 million in stolen funds to Ethereum. To prevent the remaining stolen funds from exiting the ecosystem, Cronos network validators took the emergency step of halting block production on the entire Cronos blockchain. This action trapped over $68 million of the exploit proceeds in the attacker's Cronos addresses, while leaving Tectonic with massive bad debt and forcing a complete pause of its platform Block Data Reference Key Addresses: Attacker Address 1: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc Attacker Address 2: 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc Attacker Contract: 0x085f3115ca368aa262246d22f9476e1e2c87e8be

    View on De.Fi↗
  • Avici
    Unknown chainAccess controlreported
    39d ago

    Impact

    Quick Summary On August 28, 2026, crypto card provider Avici and three other card programs suffered an exploit totaling approximately $1.02 million (~10,000 SOL) due to an instruction verification flaw in their shared card contract managed by partner Rain. The attacker exploited the bug to grant themselves admin rights, drained card collateral pools, swapped the funds to USDC, bridged them to Ethereum, and deposited ~418 ETH into Tornado Cash. Details of the Exploit The vulnerability was present in an older Solana smart contract developed by card issuer Rain, which managed user card top-up balances independently from self-custodial user wallets. The exploit relied on an instruction index trick in Solana's Ed25519 signature verification precompile. The attacker submitted a transaction with two Ed25519 instructions: the first carried a genuine signature from a newly generated throwaway key, while the second instruction set its signature, public key, and message indexes to point back to the index of the first instruction. The precompile re-verified the valid signature from the first instruction rather than checking the admin key in the second instruction, leading the contract to incorrectly register two valid admin signatures and grant the attacker full admin privileges (AddCollateralAdmin). Using these elevated privileges, the attacker drained four card programs, collecting 10,000 SOL (~$1.02M USD). They converted the SOL to USDC on Solana, transferred the funds to Ethereum address 0x2cE21E4921d3Eb116526c3651Dac0257657338D5, swapped the proceeds into ~418 ETH, and routed the entire balance through Tornado Cash. Self-custodial Avici wallets were unaffected. Avici reported that $500,859.22 in card balances across 1,685 users was impacted, and confirmed that all affected users will receive full refunds. Block Data Reference Solana Attacker Address: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Ethereum Attacker Address: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5

    View on De.Fi↗
  • Moonwell
    Unknown chainOracle issuereported
    40d ago

    Impact

    Quick Summary On August 27, 2026, Moonwell’s MAMO lending market on Base was exploited through a combination of collateral-accounting manipulation and DEX oracle manipulation. The attacker deployed roughly $1.95 million in starting capital, inflated their collateral value to borrow over $11 million in mixed crypto assets, and extracted $8.73 million via Circle CCTP to Ethereum, leaving the protocol with around $9.13 million in bad debt. Details of the Exploit The attack began when the exploiter withdrew 800 ETH from Tornado Cash, swapped most of it into about $1.95 million USDC, and bridged those funds to Base to accumulate MAMO tokens. They first deposited 15 million MAMO into Moonwell to mint receipt tokens (mMAMO). Next, instead of using the normal deposit route, they transferred another 53.4 million MAMO directly into the mMAMO contract address. Because this direct transfer bypassed the protocol's minting function and supply caps, it artificially increased the underlying token backing behind every existing mMAMO share by nearly 3.7 times. Holding three-quarters of all receipt tokens, the attacker captured almost all of this sudden collateral equity boost. At the same time, the attacker used aggressive DEX trades across low-liquidity pools to inflate the market price of MAMO from around $0.01 to over $0.40. With both the share backing ratio and the oracle price drastically spiked, Moonwell valued the attacker’s collateral at over $22 million, allowing them to draw 18 separate loans totaling $11.03 million in WETH, cbBTC, USDC, and wstETH. The attacker quickly converted these assets, burned $8.73 million USDC through Circle's cross-chain bridge to Ethereum, and swapped it into DAI. Liquidators stepped in seconds after the final borrow and seized the attacker's remaining collateral shares, but the steep price drop left Moonwell with a net shortfall of roughly $9.13 million. Block Data Reference Key Addresses: Operational / Funds Destination Account: 0xD71dD9B6e6344

    View on De.Fi↗
  • Term Labs
    EthereumOtherreported
    44d ago

    Impact

    Quick Summary On August 23, 2026, fixed-rate lending provider Term Labs suffered a governance exploit affecting its Term Vaults (built on Yearn v3 vault infrastructure), resulting in the loss of approximately $8.5 million in digital assets (~2,843 ETH and ~1.68M USDC). Details of the Exploit The incident occurred not through a code bug or reentrancy flaw, but through the manipulation of vault governance rules enabled by low voter participation and float. The attacker initially funded with 2 ETH routed through Tornado Cash acquired sufficient voting influence to pass parameter changes as designed by the protocol's governance architecture. Once vault control was secured, the attacker executed a structured sequence of transactions that unraveled integrated positions across external lending protocols (including Aave and Morpho), unwinding staked ETH positions and draining approximately 2,843 ETH alongside 1.68 million USDC. The attacker subsequently swapped the stolen USDC for roughly 1.6 million DAI and consolidated the funds in wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Block Data Reference Key Attacker Address: 0xD5183d8BfC65a50863C62aF2538198A8288FFc13

    View on De.Fi↗
  • THE Sandbox
    EthereumAccess controlreported
    46d ago

    Impact

    Quick Summary On August 21–22, 2026, The Sandbox gaming platform experienced an exploit targeting its LayerZero-based Omnichain Fungible Token (OFT) bridge deployments on Base and BNB Smart Chain (BSC). By hijacking LayerZero delegate permissions via approveAndCall, the attacker minted massive quantities of unbacked SAND tokens on destination chains. The attacker then initiated cross-chain redemptions back to Ethereum L1, completely draining the ~14.75 million SAND (~14,753,431 SAND) backing escrow held in the Ethereum OFT adapter contract. Details of the Exploit The attack exploited a permission configuration flaw in the LayerZero OFT delegate settings for the SAND token on Base and BSC. By leveraging approveAndCall, the attacker hijacked the protocol's delegate permissions and issued unauthorized minting calls across 700+ transactions to 173 addresses, generating trillions of face-value unbacked SAND tokens on Base. While the majority of the unbacked L2 mints were hyper-inflated tokens isolated on destination chains, the attacker successfully submitted cross-chain redemption messages back to Ethereum mainnet. Between 00:32:11 and 01:22:11 UTC on August 22, the Ethereum OFT adapter escrow (0xac531eb26ca1d21b85126de8fb87e80e09002dcf) was drained from 14,769,723 SAND down to ~0.0056 SAND across 15 exit transactions (with ~14.1 million SAND transferred to a single EOA in 6 transactions). Total L1 supply remained unchanged at 3 billion SAND, but the mainnet bridge escrow backing L2 tokens was completely depleted (~14.75M SAND, representing <0.01% of total SAND supply). Block Data Reference Ethereum SAND Token / OFT Contract: 0x3845badade8e6dff049820680d1f14bd3903a5d0 Ethereum OFT Adapter Escrow: 0xac531eb26ca1d21b85126de8fb87e80e09002dcf

    View on De.Fi↗
  • Maya Protocol
    Unknown chainOtherreported
    48d ago

    Impact

    Quick Summary On August 19, 2026, cross-chain liquidity network Maya Protocol was exploited for approximately $1.7 million in assets (including 20.83 BTC valued at ~$1.4M), leading to an overall liquidity pool valuation drop of ~$11 million.  Details of the Exploit The exploit targeted Trade Accounts (ported from THORChain in mid-2025) that were never integrated into Maya's solvency checker (vault.Coins) or outbound transaction-matching logic. The attacker deposited 8 ETH and 2 LINK into trade accounts, then submitted a 23-message MsgDeposit batch consisting of 22 trade withdrawals (each incremented by ~263 units to prevent outbound batching) and 1 donation. Because the nodes observed 22 simultaneous L1 outbounds unmatched by standard TxOutItems, the security system incorrectly flagged the attacker's own legitimate withdrawals as external theft. This false alert triggered the automated subsidizePoolsWithSlashBond() theft-compensation handler. Lacking an upper cap, the handler attempted to dump ~49.42 million CACAO into the pools to compensate for the non-existent theft. Although the transaction failed on-chain due to insufficient reserve funds (~168,000 CACAO actual reserve), a state accounting flaw saved the inflated pool balance regardless. Having pre-positioned in an almost empty ARB.LINK liquidity pool with 100 CACAO, the attacker withdrew 99% of their LP position, extracting 48,869,502 CACAO. The attacker then executed 10 consecutive CACAO-to-BTC swaps, siphoning 20.83 BTC directly to a Bitcoin address and triggering secondary arbitrage extraction across the network. Block Data Reference Key Attacker Bitcoin Address: bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646

    View on De.Fi↗
  • FOX
    BNB ChainFlash loan attackreported
    52d ago

    Impact

    Quick Summary On August 15, 2026, BSC-based bond market protocol Fox Market was exploited via an atomic flash-loan attack. The attacker utilized ~$482 million in flash-loaned stablecoins to trigger over-minting of protocol bonds and siphon ~$678,000 from the PancakeSwap FOX/USDT liquidity pool, yielding ~$117,000 in net attacker profit after flash-loan fees. Details of the Exploit The attack targeted a critical ordering vulnerability in the stake() function on contract 0x9fa6d8a13b35e051bfc145918db0111dec13d1a0. When executed, stake() sampled the FOX token spot price ($5.44) prior to executing the swap of injected USDT into the underlying PancakeSwap pool. Attacker 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 borrowed ~$482 million in USDT across Lista, Venus, and Aave, passing the capital into the bond minting routine. Because the mint valuation calculated token issuance based on the pre-swap spot price rather than the post-swap execution price, the protocol printed ~181x more bond tokens (88.66M sFOX) than intended. The contract then burned the newly created LP tokens to 0x00...dead and instantly paid an unlocked 3% referral bonus in FOX (2.66M tokens) to an inviter address. The attacker dumped these referral tokens directly into the newly USDT-heavy PancakeSwap pool, drained ~$678,000 from existing pool liquidity, fully repaid all $482 million in flash loans, and extracted ~$117,000 in net profit. Block Data Reference Exploit Transaction: 0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514 Attacker: 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 Attack Helper Contract: 0x3A82A2A77061017927e5331fFFd07c0308a1D2DA

    View on De.Fi↗
  • Whale Wallet Drain
    EthereumPhishingconfirmed
    54d ago

    Impact

    Q uick Summary On August 13, 2026, an unknown victim address (0x13e382dfe53207E9ce2eeEab330F69da2794179E) was drained of approximately $25.6 million in cryptocurrency assets, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M). This marks the second major exploit targeting this exact whale address, which previously lost $24.23 million to a malicious token approval phishing attack in September 2023. Details of the Exploit The attacker executed unauthorized transfers siphoning $25.6 million in multi-asset holdings, including WBTC, cbBTC, aWBTC, LDO, USDS, CRV, DAI, and ETH out of the victim's wallet. Immediately following the drain, the attacker swapped the stolen assets across decentralized protocols to consolidate the loot into stable capital, converting the holdings into approximately 20 million DAI and 3,000 ETH (~$5.64M). The consolidated funds were subsequently split across four target collector addresses (including 0x61ce24326d713641583e6a337a69bef7458fcf76), while security monitoring teams track potential recovery or laundering attempts. Block Data Reference Attacker / Theft Address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae Primary Consolidation Address: 0x61ce24326d713641583e6a337a69bef7458fcf76

    View on De.Fi↗
  • Harmony
    Unknown chainOtherreported
    55d ago

    Impact

    Quick Summary On August 12, 2026, Layer-1 blockchain Harmony Protocol suffered a major protocol-level security incident when an attacker exploited an "empty blocks" vulnerability to fraudulently mint approximately 4 billion ONE tokens representing roughly 26% of the token's total circulating supply and causing the price of ONE to crash between 26% and 34%. Details of the Exploit The exploit targeted a consensus or state-update bug involving empty blocks, allowing the attacker to mint ~4 billion ONE tokens out of thin air while bypassing standard protocol reporting endpoints (leaving totalSupply metrics temporarily unchanged). The attacker rapidly transferred approximately 2.8 billion ONE (~97% of the fraudulently created tokens) directly into centralized crypto exchanges for liquidation, leaving only around 115 million ONE in on-chain addresses. In response, Harmony requested exchanges to freeze funds from four identified attacker wallet addresses while the core team began developing a software patch and evaluating blockchain rollback options. Block Data Reference Key Attacker Addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510) one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4  (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5)

    View on De.Fi↗
  • Coinsbuy
    EthereumAccess controlreported
    57d ago

    Impact

    Quick Summary On August 10, 2026, cryptocurrency payment platform Coinsbuy suffered a coordinated hot wallet compromise across both TRON and Ethereum, losing approximately $7.9 million to $8.07 million in under an hour. Coinsbuy temporarily halted deposits and withdrawals to contain the incident before fully covering all affected balances from its corporate reserves and resuming normal operations without client loss. Details of the Exploit The attacker executed a rapid, cross-chain operation impacting multiple hot wallet addresses simultaneously. On TRON, the perpetrator drained roughly $6.04 million in USDT across eight wallets within an hour. Concurrently on Ethereum, three hot wallets were emptied of approximately 1.89 million USDT along with native ETH. The attacker leveraged cross-chain swap services (including Bridgers) and non-custodial exchanges (FixedFloat, ChangeNOW, and BingX) to route ~79% of the stolen funds through a non-clusterable pattern, splitting transactions across 50 single-use addresses to convert the capital into Monero (XMR). While ChangeNOW managed to freeze a six-figure sum of the illicit transfer, the majority of the stolen assets were converted into untraceable privacy coins. Coinsbuy subsequently refilled the drained hot wallets from its balance sheet, indicating the underlying platform infrastructure remained secure. Block Data Reference Key Attacker Addresses: TRON Collector: TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR Ethereum Collector: 0x4d1bef2fe998b3e3c4029ef9ea6a0534d95661d3 Ethereum Swap Wallet: 0x66790b54b891e2ebdef58a15b969ff6fb4374b17

    View on De.Fi↗
  • Coreum
    Unknown chainOtherreported
    58d ago

    Impact

    Quick Summary On August 9, 2026, the Coreum cross-chain bridge connecting to the XRP Ledger (XRPL) was exploited due to a deposit verification flaw, resulting in the theft of 199,916 XRP (valued at approximately $200,000) across 94 transactions within 97 minutes. Details of the Exploit The attack targeted a vulnerability in the Coreum bridge's deposit verification logic and multisig relayer infrastructure connecting the Coreum blockchain to the XRP Ledger. By exploiting a flaw in how incoming cross-chain deposit proofs were validated, the attacker tricked the relayer system into recognizing unverified or forged deposit events as legitimate. Over a 97-minute window, the attacker executed 94 consecutive fraudulent withdrawal requests, systematically siphoning 199,916 XRP out of the bridge liquidity before operations could be suspended.

    View on De.Fi↗
  • Risex
    Unknown chainOtherreported
    64d ago

    Impact

    Quick Summary On August 3, 2026, perpetual exchange protocol RISEx experienced an unauthorized withdrawal of 673,011.56 USDC from the Real-World Asset (RWA) yield strategy linked to its XLP liquidity vault due to a smart contract misconfiguration. The team patched the vulnerability within minutes and fully reimbursed XLP depositors using protocol fee revenue, resulting in zero user losses. Details of the Exploit The exploit was caused by a configuration flaw in the RWA yield strategy connected to RISEx's XLP vault, which had been present since its deployment on July 13, 2026. An unauthorized user took advantage of this misconfiguration at 07:21 UTC to execute an unverified withdrawal of 673,011.56 USDC. Because the withdrawal amount sat below the protocol's automatic rate-limiting and throttling thresholds, the transaction executed on-chain. RISEx engineering detected the transaction within minutes and deployed a patch by 08:09 UTC. The protocol covered 100% of the lost capital using a portion of its July trading fee revenue. Block Data Reference Attack Transaction: 0xc52560bec154a3d5533a321bd9805305a5076194573ddb2fbb059059ace3e987

    View on De.Fi↗
  • Loopsdao
    BNB ChainOracle issuereported
    65d ago

    Impact

    Quick Summary On August 2, 2026, LOOPSDAO's LpdFi protocol on BNB Chain was exploited for approximately $690,000 in USDC (netting ~$573,000 in profit) through a combination of spot price oracle manipulation and a flaw in the protocol's discrete daily interest accrual logic. Details of the Exploit The attack targeted Lpd.price(), which derived token valuations directly from the instantaneous reserves of a PancakeSwap LPD/USDC liquidity pair without TWAP, liquidity thresholds, or price deviation guards. The attacker temporarily inflated the LPD spot price by ~5,163x via temporary liquidity swaps and invoked buy(), allowing them to record a massive $140M nominal USDC interest-bearing principal for a minimal LPD deposit. After rebalancing the pool and stepping across the daily issue boundary in the subsequent block (just one second later), the attacker called claimInterest(), which accrued a full 0.5% interest period on the bloated principal and forced the protocol to burn 1.68 million of its own Cake-LP tokens (with zero slippage bounds) to pay out the unbacked USDC. Block Data Reference Attacker Address: 0x5d289266d85ef671561ba3f253fb79327c193f33 Attack Executor Contract: 0x7f5ad0a998dcb3f5006f0d152bebc055979ef711 Victim / Vulnerable Contract: 0xce6a6e4413d85a136bbac8aae6fb46eaa77f295e Setup Transaction: 0xbb5b8573d7203e00f8fb9d4839dbeea46a8efd367eac8bed81e4ece2341c3588 Claim Transaction: 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6

    View on De.Fi↗
  • Moke Token
    BNB ChainAccess controlreported
    65d ago

    Impact

    Quick Summary On August 2, 2026, the MOKE token protocol on BNB Chain was exploited for approximately $907,700 (~1,546 BNB) due to a critical access control flaw in its smart contract architecture. Details of the Exploit The exploit was caused by an unprotected public claim() function within the MokeToken.releaseContract() contract, which lacked caller eligibility checks or role-based access control. The attacker repeatedly called claim() to drain roughly 166 million MOKE tokens directly from the protocol's internal reserve pool. To realize their profit, the attacker combined flash loans, Venus Protocol leverage, liquidity pool removal, and internal dividend distribution mechanics to swap the extracted tokens into 1,546 BNB. Block Data Reference Attack Transaction: 0x0776048b1b58064fb31b6513721811e7b44d6bdbe7bf5833158b241ca6756a8f

    View on De.Fi↗
  • Totally Unknown Protocol XYZ
    EthereumRugpullconfirmed
    66d ago

    Impact

    Unmatched project for pending review.

    View on De.Fi↗
  • Coldcard
    Unknown chainOtherreported
    68d ago

    Impact

    Quick Summary Starting July 30, 2026, Bitcoin hardware wallet manufacturer Coldcard (by Coinkite) disclosed a critical firmware entropy defect that enabled attackers to systematically brute-force and drain user funds offline, resulting in cumulative losses estimated between $85 million and $130 million+ (~1,900 to 2,055+ BTC) across multiple organized attack waves. Details of the Exploit The vulnerability originated from a firmware code refactoring introduced in version 4.0.1 (March 2021), where seed phrase generation calls were migrated from ckcc.rng_bytes() to ngu.random.bytes(). This migration unintentionally caused the underlying rng_get() function to resolve to MicroPython's software Pseudo-Random Number Generator (PRNG) fallback instead of Coldcard's dedicated True Hardware Random Number Generator (TRNG). Consequently, generated wallet seeds possessed severely degraded entropy, approximately 40 bits on Mk3 devices and ~72 bits on newer models, down from the intended 128/256 bits. Attackers leveraged this reduced search space to pre-compute and offline brute-force the predictable private keys for affected single-signature addresses, executing sweeping transactions across four distinct waves without requiring physical access to the hardware devices. Coinkite issued security advisories across affected models (Mk3, Mk4, Q, Mk5) while security researchers worked with victims to perform Replace-By-Fee (RBF) cancellations for pending mempool sweeps.

    View on De.Fi↗
  • Lula Token
    BNB ChainFlash loan attackreported
    70d ago

    Impact

    Quick Summary On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan. Details of the Exploit The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios. This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit. Block Data Reference Attack Transaction: 0xa219ab9d57e520e5235b15a8801f4ebac8cc45551be0430ce4e49caea0411d7c

    View on De.Fi↗
  • Wemix
    Unknown chainAccess controlreported
    72d ago

    Impact

    Quick Summary On July 26, 2026, WEMIX (the blockchain ecosystem backed by South Korean gaming company Wemade) suffered a smart contract compromise affecting its WEMIX$ stablecoin contract, resulting in an unauthorized minting and transfer of approximately $6.25 million worth of tokens. Details of the Exploit The incident occurred when an unauthorized party compromised the contract ownership privileges of a WEMIX$-related smart contract. Using these administrative rights, the attacker fraudulently minted 5,225,525 WEMIX$ and transferred USDC.e out of the protocol. The attacker converted the fraudulently minted tokens into 30,736 WEMIX and 724,198.27 USDC.e, before bridging the USDC.e over to Ethereum and BNB Smart Chain (BSC). On those destination networks, the funds were swapped into assets including ETH and USDT, with a portion subsequently deposited into centralized exchanges. In response, the WEMIX team temporarily suspended all connected bridges (including Chainlink CCIP and PLAY Bridge), withdrew Foundation-provided liquidity, halted trading across affected liquidity pools (WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$), paused the WEMIX$ Module and PNIX DEX, and coordinated with global exchanges to freeze attacker-linked addresses.

    View on De.Fi↗
  • Garden Finance
    EthereumOtherreported
    72d ago

    Impact

    Quick Summary On July 26, 2026, cross-chain atomic swap protocol Garden Finance suffered a supply chain compromise affecting its Hash Time-Locked Contracts (HTLC), resulting in an initial drain of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, BNB Chain, and Solana. Details of the Exploit The exploit was an off-chain supply chain attack rather than a direct smart contract code vulnerability. An attacker compromised the off-chain database of an independent solver integrated with Garden Finance and injected forged transaction records. Because the protocol relies on solver state data to process cross-chain atomic swaps between Bitcoin and EVM/Solana networks, these fraudulent records deceived the HTLC contracts into releasing escrowed USDT assets directly to the attacker without valid matching inputs. Garden Finance immediately took its front-end web application offline to prevent further improper fund releases, confirming that while core smart contracts remained secure, the breach stemmed entirely from off-chain solver infrastructure. Block Data Reference EVM Attacker Address: 0x25b224c05f6cc5e132165c1621de1a4c3b316999 Solana Attacker Address: WZy4xxpqktWa1b6MPMRiWsD487CT8mDcapB6GufBJCH Example EVM Exploit Transaction: 0x9d7a961aa340156b7342839e9f6448a26dea9acd38dc7b2638966eb19e29d395

    View on De.Fi↗
  • Triple A
    EthereumAccess controlreported
    73d ago

    Impact

    Quick Summary On July 25, 2026, Singapore-based licensed stablecoin payment gateway Triple-A suffered a hot wallet compromise across multiple blockchains, resulting in the unauthorized extraction of approximately $9.7 million to $11.8 million in company-owned treasury assets. Details of the Exploit The incident occurred when an unauthorized party obtained compromise access to Triple-A's multi-chain hot wallet infrastructure across TRON, Ethereum, Polygon, and Arbitrum. The attacker drained the company's operational treasury accounts, swapped the stolen digital assets, and bridged them to Ethereum Mainnet, consolidating 5,227 ETH into a single holding wallet. Client funds were entirely unaffected because Triple-A does not provide digital asset custody for its users, keeping client balances strictly segregated in trust accounts with safeguarding financial institutions. Triple-A temporarily placed certain services into maintenance mode for approximately three hours to secure the affected infrastructure before fully restoring normal payment processing, transaction settlements, and global operations.  

    View on De.Fi↗
  • Projekt Green Gold
    EthereumFlash loan attackreported
    73d ago

    Impact

    Quick Summary On July 25, 2026, the Projekt (GREEN/GOLD) reward vault on Ethereum was exploited, resulting in the loss of approximately 301.7 ETH (valued at ~$560,000) due to a logic flaw in its buy-to-earn reward allocation tracking. Details of the Exploit The exploit targeted a logic error in the reward vault's permissionless trackPurchase(buyer) function, which was designed to credit ETH allocations to buyers based on token balance deltas. Crucially, trackPurchase relied solely on token balance increases to calculate reward sizing without validating whether genuine ETH was spent to acquire those tokens. To execute the attack, the exploiter secured a flash loan of approximately 14,000 WETH from Morpho. They pushed these funds into dozens of Uniswap V2 memecoin liquidity pairs (such as Kirby Inu and ROTTSCHILD) and invoked skim() to transfer the tokens directly to their contract. This self-dealing token movement inflated the buyer's balance delta, tricking the unverified trackPurchase function into registering massive fake "purchase" reward allocations at virtually zero net cost. Once the fake allocations were credited and the flash loan repaid in the same transaction, the attacker called massWithdraw() to drain ~301.7 ETH from the vault's reward pool. Block Data Reference Attacker Address: 0x61e7ad696215688d274c729a4cd0fbbc88fc4f85 Victim / Vulnerable Contract: 0x574fc478bc45ce144105fa44d98b4b2e4bd442cb Attack Transaction: 0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64

    View on De.Fi↗
  • Solido Cash
    Unknown chainOracle issuereported
    75d ago

    Impact

    Quick Summary On July 23, 2026, Solido Cash on the Supra blockchain was exploited due to an oracle fallback misconfiguration on its SOLID vault. An attacker leveraged an invalid stale price fallback to over-mint CASH stablecoins and extract approximately 293.7 million SUPRA tokens (~$73,400 net value), with protocol reserves absorbing the loss so zero user funds were affected. Details of the Exploit The exploit stemmed from an oracle misassignment where a stale primary price feed for the SOLID token incorrectly fell back to the $1.00 CASH stablecoin oracle instead of halting or using a proper secondary feed. Treating cheap SOLID collateral as equivalent in value to CASH, the attacker executed atomic contract interactions and manual secondary wallet mints to generate unbacked CASH stablecoins, which were immediately swapped for native SUPRA tokens across local decentralized exchanges. Solido Cash subsequently paused vault interactions and patched the oracle fallback mappings.

    View on De.Fi↗
  • Verus
    Unknown chainOtherreported
    75d ago

    Impact

    Quick Summary On July 23, 2026, the cross-chain bridge connecting the Verus blockchain to Ethereum was exploited for the second time in two months, resulting in the unauthorized extraction of approximately $7.53 million across multiple digital assets. Details of the Exploit The exploit targeted a semantic and authority validation flaw in how the Ethereum-side bridge contract verifies cross-chain export outputs from Verus. While the contract verified that a given export payload existed within a valid Verus block and matched a genuine state root notarized on Ethereum, it failed to verify that the Verus network itself had authorized the payload as a legitimate primary export. The attacker initiated a tiny 0.01 VRSC bridge transaction to create a valid export state, then authored a custom Verus transaction spending that output and attaching a handwritten export commitment declaring 8 transfer instructions to the attacker's wallet. After relaying two legitimate notarizations to Ethereum containing the state root of their custom transaction, the attacker submitted the import request. Because the cryptographic Merkle proofs and payload hash checks matched the attacker-controlled input data, the bridge executed the transfer, releasing $7.53 million in tBTC, DAI, USDC, scrvUSD, USDT, MKR, and EURC. The stolen assets were immediately swapped on-chain for 3,916.1 ETH and deposited into Tornado Cash. Block Data Reference Attacker Address: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

    View on De.Fi↗
  • AFX
    Unknown chainAccess controlreported
    75d ago

    Impact

    Quick Summary On July 23, 2026, the cross-chain custody bridge operated by decentralized exchange AFX on Arbitrum was exploited, resulting in the unauthorized withdrawal of 24.15 million USDC. Details of the Exploit The incident was carried out via a private key or backend validator infrastructure compromise. The attacker forged an on-chain withdrawal request on Arbitrum that carried valid cryptographic signatures from five bridge validators. Because these signatures satisfied the bridge contract's multi-signature authorization threshold, the contract executed the transaction as legitimate and released 24.15 million USDC from custody. The attacker immediately bridged the stolen stablecoins from Arbitrum to Ethereum Mainnet and swapped them for approximately 12,467.5 ETH. Following detection, AFX suspended bridge operations to isolate the vulnerability, confirming that the platform's core trading engine, mainnet, and Arbitrum's native bridge remained uncompromised while security teams began tracing the funds. Block Data Reference Arbitrum Creation Transaction: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Arbitrum Finalize Transaction: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b Ethereum Attacker Wallet: 0x627654b2782bfc57580ecd11d40869b350b6ebac

    View on De.Fi↗
  • B Network
    BNB ChainAccess controlreported
    75d ago

    Impact

    Quick Summary On July 23, 2026, Bitcoin Layer-2 protocol B² Network suffered a security incident on BNB Chain targeting its B2 token staking service, resulting in the unauthorized extraction of approximately 8.59 million B2 tokens (valued at ~$3.86 million). Details of the Exploit The exploit was caused by a compromise of the administrative upgrade authority governing the upgradeable proxy contract for B² Network's staking service. An address (0x35fE...b287d) that had granted itself privileged admin permissions over a year prior (May 2025) executed an upgradeToAndCall function call on the live staking proxy contract. This replaced the legitimate contract implementation with a malicious logic contract (0x0B875E...C9DCa). Six minutes after the proxy upgrade, the attacker invoked draining functions through the newly deployed logic, extracting ~8.59 million B2 tokens across nine batch calls within 45 minutes. The stolen B2 tokens were swapped on-chain for 5,409 WBNB, converted to 1,128 ETH, and bridged out of BNB Chain via Near Intents.  Block Data Reference Malicious Implementation Contract: 0x0B875E23C6b04D3683f1D4c4f0FFf7f2b5cC9DCa Upgrade Transaction: 0x2069714bbe6671f7737f85c5caee7fbccd15ed8f045b2cd6f6b52229cd47d769

    View on De.Fi↗
Protocol incidents from De.Fi
WhenProtocolTypeImpactSource
2d ago
Oct 4, 2026
Adapter Vault Drain
Unknown chainreported
Access control

Quick Summary On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum.    Details of the Exploit The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d). Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched.   Block Data Reference Target Adapter Contract: 0xd1895f2019c2152fc2b9022d57f19198c4cfcabc    Owner Safe Address (3-of-7): 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4 Attacker Deployer Address: 0x0B5126e1bc27C0de77e02e97945760A674EdB034    Attacker Whitelisted Contract: 0xcdfe91301356da873562ef513828a60dba1f569d Fund Destination Address: 0xC73448432a05deeA5Ea18a07D3b5d9ccf6297f8D

De.Fi↗
4d ago
Oct 2, 2026
Goldpesa
Unknown chainreported
Other

Quick Summary On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions. Details of the Exploit The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router. Block Data Reference Attack Transaction Hash: 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9 Attacker Address: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F Vulnerable Contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8

De.Fi↗
5d ago
Oct 1, 2026
Near Intents
Ethereumreported
Other

Quick Summary On October 1, 2026, cross-chain protocol NEAR Intents was exploited for approximately $3,8 million following a hot wallet drain on BNB Smart Chain caused by an integration bug in its Omni bridge infrastructure. On-chain analysis linked the attacker to North Korea's Lazarus Group, while the protocol team patched the flaw and pledged full user reimbursement. Details of the Exploit The attack stemmed from an integration logic flaw between NEAR Intents smart contracts and its Omni deposit/withdrawal layer on BNB Smart Chain, allowing the attacker to execute unauthorized hot wallet withdrawals. The attacker extracted ~$3.865M on BSC, routed a portion toward KuCoin, bridged funds to Ethereum, and executed seven Chainflip swaps to acquire ~33.7 BTC (~$2.9M), which remains parked across four unspent Bitcoin addresses. On-chain tracking confirmed the attacker interacted with known Lazarus Group infrastructure (0x098B7...E2f96). In response, NEAR Intents patched the contract-side flaw, temporarily suspended Omni bridge operations across 11 chains, and guaranteed 100% user compensation from protocol reserves. Block Data Reference BSC Attack Hashes: 0x9fe58e031f73bbd880c782bc9e7446bcda32cadb304a729209871a4a81856c4c 0x0381265d6a1bb09de899f49f410a8b907cd548358a7e3c91076c3a52656b8220 0x69d1c68c7e961a0199d3c9f3b6a31cb168ed775ef34b51a42762253ac1efcceb 0x9c10b967da0c85631ec105e3b322c0a851fcd01b69ff390ff58f860e5cce003a

De.Fi↗
6d ago
Sep 30, 2026
MCN Labs
BNB Chainreported
Other

Quick Summary On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations. Details of the Exploit The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time. The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Attacker Address: 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a Vulnerable Contract: 0x52272524a22f941f5489c1233732797314bb054b

De.Fi↗
7d ago
Sep 29, 2026
Fastswap
BNB Chainreported
Other

Quick Summary On September 29, 2026, the FastSwap protocol on BNB Smart Chain was exploited in an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $92,600 USD. Details of the Exploit An attacker executed a malicious transaction targeting the FIST token and FastSwap smart contracts (0xc9882def23bc42d53895b8361d0b1edc7570bc6a) on BNB Smart Chain. The exploit allowed the attacker to manipulate protocol contracts and drain liquidity pools, extracting ~$92.6K in value within a single transaction. Block Data Reference Attack Transaction Hash: 0xecac1563bbb76fb8fefb4a7da4592260a8c1ddde21d7da62b78a9e3769808e6b Target Token / Contract: 0xc9882def23bc42d53895b8361d0b1edc7570bc6a

De.Fi↗
10d ago
Sep 26, 2026
Dyorswap
Ethereumconfirmed
Phishing

Quick Summary On September 26–27, 2026, scammers deployed a fake OP Stack Layer 2 network impersonating the unreleased GIWA Mainnet (Chain ID 9134) and set up a fraudulent bridge. 1,335 user addresses deposited 767.65 ETH into the fake bridge to trade on DYORSWAP, allowing the scammers to extract 766.25 ETH (~$2.0 million USD) on Ethereum. Details of the Exploit The incident was a fake infrastructure scam rather than a smart contract flaw in DYORSWAP's protocols. Scammers configured a malicious network using GIWA's official Chain ID (9134) alongside a fake bridge and OP Stack batcher. When traders connected to the fake RPC and deposited ETH to trade on DYORSWAP, the malicious bridge contract captured the L1 funds. The scammers drained 766.25 ETH at Ethereum block 26,067,309. DYORSWAP confirmed its core contracts were safe, published a claims collection form, and distributed over 200 ETH from its treasury to compensate affected users while tracing the scammers' funding sources.

De.Fi↗
12d ago
Sep 24, 2026
Duelbits
Ethereumreported
Access control

Quick Summary On September 24, 2026, crypto casino and sportsbook platform Duelbits suffered a multi-chain hot wallet compromise resulting in estimated total losses of $4.9M to $7.0M across Ethereum, BNB Chain, Tron, Bitcoin, and Solana. The platform took its services offline to investigate and refill operational hot wallets while user cold storage remained unaffected. Details of the Exploit The attack was executed via a private key compromise targeting Duelbits' operational hot wallets across five blockchains. On EVM chains, the attacker extracted 836 ETH, 1.146M USDT, 209 BNB, 96.8K USDC, 31.5K DAI, and 12.4B SHIB, alongside 8.1 BTC on Bitcoin and 192K TRX on Tron. The attacker routed the stolen multi-chain assets through swap protocols and cross-chain bridges, converting the proceeds into Ether and consolidating approximately 2,234.6 ETH (~$6.0M) into a single destination Ethereum address. Duelbits confirmed the hot wallet breach and suspended operations pending system remediation and hot wallet refilling. Block Data Reference Attacker EVM Address 1: 0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76 Attacker EVM Address 2: 0x6761c9b15815f4051773EDe39B42B95bdDB3EF1c Attacker Bitcoin Address: bc1qhtu84kz3y94lvgl2t05zk84tqh57grvd82zvcl Attacker Tron Address: TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK Attacker Solana Address: A3EBrhMBEGzcPgmbwywSPhW39G6PFGrorU8ib99T6yKw

De.Fi↗
12d ago
Sep 24, 2026
Payy Network
Ethereumreported
Access control

Quick Summary On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses. Details of the Exploit The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved. An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts.

De.Fi↗
12d ago
Sep 24, 2026
Bitget
Ethereumreported
Access control

Quick Summary On September 24, 2026, centralized exchange Bitget suffered a major infrastructure breach resulting in ~$351.6 million stolen from its hot and warm wallet layers. Bitget paused withdrawals while confirming its cold wallets remained secure and stating that its $464M+ User Protection Fund will fully reimburse user losses. Details of the Exploit The attacker penetrated Bitget's core wallet backend infrastructure and spoofed internal transaction data to trigger authorized withdrawals across multiple blockchains without compromising private keys. Stolen assets included ETH, XRP, USDT, USDC, AVAX, and BNB. On EVM chains, the attacker converted most of the stolen proceeds into 67,982 ETH (~$183 million). On-chain analysis and VPN traffic patterns linked the attack to North Korea's Lazarus Group (specifically the TraderTraitor subgroup) through bridged funds connected to the earlier AFX Trade exploit. Bitget contained the breach, stopped further unauthorized transfers, and is preparing system recovery before resuming withdrawals.

De.Fi↗
13d ago
Sep 23, 2026
Meter Protocol
BNB Chainreported
Other

Quick Summary On September 23–24, 2026, Meter.io suffered a dual consensus and bridge exploit after an attacker leveraged a block validation flaw on Meter mainnet and exploited the Meter Passport bridge on BNB Chain, resulting in ~$2.3 million in unbacked wMTRG minted and partially dumped on PancakeSwap. Details of the Exploit On September 23 at 21:14 UTC, an attacker exploited a block validation flaw on the Meter mainnet consensus layer to mint unbacked MTR and MTRG tokens. The attacker then used the Meter Passport bridge on BNB Chain across two main transactions to mint approximately $2.3 million in unbacked wrapped MTRG (wMTRG), dumping a portion into PancakeSwap liquidity pools and bridging funds out. Meter paused both mainnet and bridge operations, invalidated transactions post-block 100731417, and issued a 72-hour whitehat bounty offer of 10% for the return of funds. Block Data Reference Attacker Addresses: 0xee2eeeed4ed8580669ed924abeb49f27f7d0bd65 0x44cf94496091150865e192a86c07b90a9760b43d 0x7db6ac6Fa3c8aa2c6FB9BdCD4800e8BAacDd2EE8 Abused Token Contract (BSC): 0xBd2949F67DcdC549c6Ebe98696449Fa79D988A9F Sample Exploit Transaction (BSC): 0x2745dd5121eb03d1979cf229f432a422137942ede186d9fa0129a2f83401eeef Bounty Return Address: 0xB980Ff36A99C0C3B408279E025d8E2DA7eF65105

De.Fi↗
14d ago
Sep 22, 2026
Astroport
Unknown chainreported
Access control

Quick Summary On September 22, 2026, Cosmos ecosystem DEX Astroport suffered a security breach on the Neutron chain that exposed protocol admin controls. Validators halted Neutron and Cosmos Hub to coordinate an emergency response, intercepting approximately 1.396 million ATOM (~$2.53 million USD) before the attacker could cash out. Details of the Exploit The attacker compromised admin privileges for Astroport contracts on Neutron, placing liquidity across connected pools at risk. The attacker converted stolen funds into ATOM and initiated a streaming swap of 200,000 ATOM to ETH via THORChain. Only 15.5% of the swap filled (19.92 ETH) before Cosmos Hub halted at block 33,086,740. Cosmos Hub validators deployed a binary upgrade that transferred 1,227,121 ATOM from the attacker's account to a recovery multisig and added an ante-handler to block the attacker's key from signing future transactions. An additional 168,990 ATOM refund remains queued on THORChain, requiring a secondary sweep once GAIA chain processing unhalts. Astroport contracts on Terra were unaffected after their admin connection to Neutron was severed. Block Data Reference Attacker Cosmos Address: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n   

De.Fi↗
15d ago
Sep 21, 2026
RWC Token
BNB Chainreported
Other

Quick Summary On September 21, 2026, the RWC token protocol on BNB Smart Chain was hit by an on-chain attack detected by TenArmor, resulting in an estimated loss of approximately $109,000 USD. Details of the Exploit An attacker executed a malicious transaction targeting the RWC contract on BNB Smart Chain, exploiting a smart contract vulnerability to drain funds from the project's liquidity or protocol pools. Security monitoring systems flagged the atomic execution trace after ~$109,000 in value was extracted. Block Data Reference Attack Transaction Hash: 0x9c919da34696425913f32587f00d2838031a8726a2c5ddfa39e33a45b36e6427

De.Fi↗
15d ago
Sep 21, 2026
Internet Token INT
Unknown chainreported
Other

Quick Summary On September 21, 2026, the Internet Token protocol on Base was exploited for 5.85 WETH and 764 million INT after an attacker leveraged an unvalidated Uniswap V3 pool callback parameter to arbitrarily mint ~925 million INT tokens. Details of the Exploit The vulnerability was present in INT's LiquidityUnifier contract (0x837d...), which held MINTER_ROLE rights and exposed an unvalidated swapV3(token, pool) function. The function only validated that the passed pool parameter contained bytecode and that its token0() and token1() getters returned the INT token address. The attacker deployed a malicious contract returning INT for both token endpoints, causing swapV3 to invoke pool.swap(). This callback re-entered uniswapV3SwapCallback and minted an arbitrary amount of INT tokens directly to the fake pool. The attacker routed the minted tokens through a Convertor contract round-trip to bypass validateSupply sanity checks, created ~925 million INT, dumped a portion into the official INT/WETH V3 pool for 5.85 WETH, and kept the remaining ~764 million INT. Block Data Reference Attack Transaction Hash: 0xed62bb27bd1058d3d7cc93d55421d6d0001ced8cb4529b02773f5126a4edb08b Attacker Address: 0x5f7ce6395818857ac20730dc990f614356d1ec68 Victim Contract: 0x837dbabc4f5fa78baf177597edbda09645822032

De.Fi↗
17d ago
Sep 19, 2026
ASI Alliance Singularitynet
Ethereumreported
Access control

Quick Summary On September 19–20, 2026, an attacker used compromised SingularityNET bridge and NuNet deployer private keys to drain $FET and mint unauthorized supplies of $AGIX,$NTX, $WMTx, and $CGV on Ethereum. The attacker extracted ~$1.44M to $1.67M in liquid ETH before project teams paused bridges and revoked minting authorities. Details of the Exploit The exploit resulted from compromised private signing keys rather than smart contract logic bugs. On September 19, the attacker called conversionIn on Fetch.ai's TokenConversionManagerV3 using a stolen SingularityNET authorizer signature to drain 8.72M $FET (~$1.53M) and swap it for ETH. Minutes later, a compromised NuNet deployer account minted 408.53M $NTX to reach its 1 billion supply cap. On September 20, the attacker used the SingularityNET bridge authority to mint 260M $AGIX, 53.84M $WMTx, and ~500M$CGV. High slippage on low liquidity pools limited total extracted value to 546–649 ETH (~$1.44M–$1.67M), while token market prices collapsed by 65% to 99%. Affected protocols responded by pausing bridges, revoking signing authorities, and contacting exchanges to freeze funds. Block Data Reference Attacker Address: 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE NuNet Deployer Address: 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Fetch.ai Conversion Contract: 0xab424A430CC09864fA1277A38193111705ADF3A3

De.Fi↗
19d ago
Sep 17, 2026
Nostra Finance
Unknown chainreported
Oracle issue

Quick Summary On September 17, 2026, Starknet money market Nostra Finance suffered an oracle price manipulation exploit resulting in ~$3.53 million in unauthorized borrows across ETH, STRK, USDC, USDT, WBTC, and DAIv1 against inflated NSTR collateral, forcing the protocol to pause all lending, borrowing, and liquidation operations. Details of the Exploit The attacker exploited Nostra Finance's collateral valuation oracle for NSTR by manipulating its underlying price pool on Ekubo DEX. The attacker withdrew existing liquidity around NSTR's real market price, seeded a decoy liquidity band at $99 per NSTR, and routed a $14.72 dust swap (190 NSTR) through the gap to artificially inflate the oracle price by 16,645x. Using just 294,177 NSTR collateral, normally worth ~$1,756, the attacker leveraged the inflated valuation to draw $3,531,922.97 in mixed assets across six borrowing legs. The attacker then bridged ~$1.93 million (234.57 ETH and 1.3M DAI) to Ethereum while leaving ~$1.55 million in assets on Starknet. Block Data Reference Starknet Attacker Contract: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 Ethereum Destination Address: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37

De.Fi↗
20d ago
Sep 16, 2026
Bonfire
BNB Chainconfirmed
Phishing

Quick Summary On September 16, 2026, an attacker executed a batched approval-drain sweep targeting holders of the Bonfire (BONFIRE) token on BNB Chain, resulting in a loss of approximately 66.08 WBNB (~$47.4K USD). T Details of the Exploit The attack was executed across two distinct phases within transaction 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f. In the harvesting phase, the attacking contract iterated through a pre-compiled list of 65 addresses that had standing approvals to 0x17e801.... Using transferFrom(), the contract pulled each victim's BONFIRE balance directly into the BONFIRE/WBNB liquidity pair. The contract then called swap() to route tokens out to a collector wallet (0x28E976Ea...), netting the inbound deposits against the outbound legs and steadily increasing the pair's token reserves without swapping for WBNB on each individual transfer. The decaying size of the pulled balances across the iterations indicates a script executing against victims ordered by remaining balance size.   In the cash-out phase, the collector address approved the attacking contract and passed its accumulated ~4,576 BONFIRE back into the liquidity pool across two major sell swaps. These swaps extracted 33.223 WBNB and 32.857 WBNB respectively, totaling 66.08 WBNB, which was subsequently unwrapped to native BNB. Standard events such as SwapAndLiquify observed during the execution were simply Bonfire's automated liquidity tax mechanism firing as intended through its legacy PancakeSwap V1 router. The root vulnerability remains off-chain, stemming either from historical phishing campaigns or compromised keys associated with a legacy custom router contract. Block Data Reference Attack Transaction Hash: 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f   Harvesting Contract: 0x17e801E17CeFC6334059189c178D4783830E03D3 Collector Address: 0x28E976Ea7b83553d6D1D45CE81334156A2632127

De.Fi↗
20d ago
Sep 16, 2026
Flamincome
Ethereumreported
Flash loan attack

Quick Summary On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan. Details of the Exploit The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit. Block Data Reference On-Chain Key Addresses: Attacker Primary Address: 0x83381e7f7232775735169d72d237b858ffc36871 Target Strategy / Vault: 0xb8d6471ca573c92c7096ab8600347f6a9fe268a5 Exploit Contract 1: 0x875da4bd7b4a52a806a533b1cf6d6ff92365d2e6 Exploit Contract 2: 0x1c7eacef3630e764519e6ea2e8caa2bdb7d8b486

De.Fi↗
20d ago
Sep 16, 2026
Meme Coin Phishing Scam
Unknown chainconfirmed
Phishing

Quick Summary On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000.   Details of the Exploit Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader.

De.Fi↗
24d ago
Sep 12, 2026
Chainflip
Unknown chainreported
Other

Quick Summary On September 12, 2026, cross-chain swap protocol Chainflip suffered a memo-manipulation exploit on its Tron settlement layer, resulting in six unauthorized payouts totaling 736,442.17 USDT after an attacker attached custom memos to already-signed transactions to trigger duplicate refund payouts.   Details of the Exploit Unlike other blockchains supported by Chainflip that pass swap instructions via dedicated contract functions, the protocol's Tron integration parses swap parameters directly from transaction memo fields. The attacker discovered a vulnerability allowing a custom memo to be appended to a Tron transaction that Chainflip validators had already signed. Chainflip's backend misread the altered memo as a new, separate swap instruction, classified it as failed, and automatically triggered a refund, effectively paying out against the same underlying deposit a second time. The attacker executed eight attempts over ~90 minutes in the early hours of Saturday, scaling up transaction sizes until six successful attempts extracted 736,442.17 USDT. Chainflip detected the incident after subsequent legitimate USDT payouts began failing due to drained vault reserves. Network operations were paused, a code fix was finalized, and operators committed to making all impacted users whole upon restart.  

De.Fi↗
27d ago
Sep 9, 2026
Amnext
BNB Chainreported
Reentrancy

Quick Summary On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap. Details of the Exploit Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens. The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB. Block Data Reference Attack Transactions: Main Exploit: 0x29eb97259b5c8d1bbfe791ad5d7bdc981f538ac37c857cc30d6296b31f08afc5 Liquidation: 0x99c9969ab97f97b56766a9d75ec4f82a463bb8e7f9603eecc77b6bb57485d3ba

De.Fi↗
27d ago
Sep 9, 2026
Nomic Nbtc Bridge
Unknown chainreported
Other

Quick Summary On September 9, 2026, a flaw in Nomic's custom forwarding mechanism allowed an attacker to double-spend nBTC and send ~39.84 unbacked nBTC vouchers (~$3.15M USD) to Osmosis, compromising roughly 36% of the backing behind Osmosis's Alloyed BTC (allBTC) token.   Details of the Exploit The attacker exploited a vulnerability in Nomic's custom transaction forwarding system to double-spend nBTC and issue unbacked vouchers through the Inter-Blockchain Communication (IBC) protocol onto Osmosis. Because nBTC serves as a reserve component for Osmosis's unified Alloyed BTC pool, the forged vouchers left allBTC ~36% undercollateralized. Core IBC and Osmosis smart contracts were not directly breached. Following detection, Osmosis paused all minting, redemptions, inflows, and outflows for Nomic and Alloyed BTC. Osmosis validators then executed an emergency chain upgrade that successfully froze 22.65 BTC residing in the attacker's Osmosis account. Osmosis announced plans for a governance vote to seize the 22.65 frozen BTC and reimburse the remaining ~17.19 BTC shortfall from the community pool's BTC reserves to fully restore 1:1 backing.  

De.Fi↗
Sep 6, 2026
Sep 6, 2026
Liquid Network
Unknown chainmitigated
Other

Quick Summary On September 6–7, 2026, Bitcoin sidechain Liquid Network suffered an Elements consensus bug exploit resulting in losses of ~4,000 BTC (~$320 million USD), after unbacked L-BTC tokens were minted and redeemed for real Bitcoin, forcing operators to halt the network while whitehat negotiations proceed on-chain. Details of the Exploit The attacker exploited a consensus vulnerability in the underlying Elements software to forge ~4,000 unbacked L-BTC on Liquid without depositing collateral. These unbacked tokens were submitted through SideSwap's Peg-out Authorization Key service, prompting the Liquid Federation multisig to release ~3,996 real BTC from reserves—draining ~95% of backing. Federation operators subsequently halted the sidechain and exchanges paused L-BTC deposits. The attacker consolidated funds into a single Bitcoin address and left an OP_RETURN message offering to return most of the BTC once Blockstream deploys a network-wide patch. Block Data Reference Mainnet Attacker Address: bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte Federation Reserve Address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr

De.Fi↗
Sep 4, 2026
Sep 4, 2026
Notional Finance
Ethereumreported
Other

Quick Summary On September 4, 2026, lending protocol Notional Finance suffered an integer truncation and rounding error exploit on Ethereum, resulting in an estimated loss of $1.73 million in DAI and USDC, which the attacker swapped into 689.2 ETH and deposited into Tornado Cash.   Details of the Exploit The exploit targeted Notional Finance's escrow and fCash accounting mechanism via a combination of a free-collateral calculation rounding error and an integer downcasting flaw. The attacker executed a two-step transaction sequence calling the mintfCashPair() function. In the first call (mintfCashPair(1)), a small liability (-1) was rounded down to 0 during the DAI-to-ETH free-collateral conversion due to a rounding precision flaw.  In the second call (mintfCashPair(2^256 - 1)), the contract aggregated the account's liabilities in int256, producing a negative balance of $-2^{128}$. However, when validating free-collateral requirements, the valuation logic performed an unsafe downcast using uint128(balance.abs()). Because $2^{128}$ overflows a standard 128-bit unsigned integer, the massive liability truncated directly to zero. This bypassed the protocol's collateral checks entirely, allowing the attacker to draw down 69,257 DAI and 1,658,525 USDC from the escrow contract. The attacker then consolidated the stablecoins, converted them to 689.2 ETH, and routed the funds into Tornado Cash across multiple transactions.   Block Data Reference Setup Transaction: 0xe1589a19fe742f0d553889214abade69551fe944acffac014c28cc07b325d60a

De.Fi↗
Sep 2, 2026
Sep 2, 2026
Cozy Finance
Unknown chainreported
Oracle issue

Quick Summary On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window.   Details of the Exploit On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7. The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash.   Block Data Reference Attacker Address: 0x003FE7359A4E03C85Ac2f521eC699ED84C7c5ccB

De.Fi↗
Aug 31, 2026
Aug 31, 2026
Aquifer
Ethereumreported
Other

Quick Summary On August 31, 2026, Solana-based automated market maker Aquifer suffered an unverified CPI token program injection exploit resulting in approximately $2.5 million in total losses across 90+ attack transactions, after which the protocol issued an on-chain whitehat offer allowing the attacker to keep 20% if 80% of the stolen funds are returned by September 3, 2026.   Details of the Exploit The exploit targeted Aquifer's swap function on Solana. When executing a token swap, the protocol allowed callers to supply an unverified, caller-controlled token program parameter (tokenProgramA) for the input token rather than enforcing a check against canonical SPL Token Program addresses. The attacker deployed a custom, dummy Solana program (DMBpPM...) designed to mirror SPL Token Transfer instruction formats and return a success signal without performing any actual token transfers.  During the attack, the adversary initiated swap instructions passing USDC as the nominal input token parameter alongside their malicious token program, targeting real liquidity vaults such as HYPE. Aquifer invoked the malicious program via Cross-Program Invocation (CPI), which accepted the parameters and reported a successful transfer. Because Aquifer relied entirely on the CPI return status without verifying actual input token balance deltas, it released output tokens from its vaults without receiving any input tokens. The stolen assets were swapped to SOL, bridged to Ethereum, and converted into approximately 1,000.8 ETH. On the same day, Aquifer's upgrade authority published an on-chain message offering a 20% whitehat bounty if 80% of the funds are returned to designated recovery addresses.  Block Data Reference On-Chain Key Addresses: Upgrade Authority: 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA Attacker Solana Address: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J Attacker Ethereum Address: 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 Solana Recovery Address: 8af8RnA

De.Fi↗
Aug 30, 2026
Aug 30, 2026
Tectonic Protocol
Unknown chainreported
Oracle issue

Quick Summary On August 30, 2026, decentralized lending protocol Tectonic on Cronos suffered an oracle price manipulation exploit resulting in estimated total losses between $75 million and $119.5 million, with approximately $6 million successfully bridged to Ethereum before Cronos network validators took the emergency step of halting the blockchain to freeze the remaining $68 million+ on-chain.   Details of the Exploit The attacker targeted Tectonic's illiquid native token, TONIC, which had low trading volume but was accepted as loan collateral. By executing rapid buy orders on decentralized exchanges, the attacker artificially pumped TONIC's price by roughly 100 times in under 20 minutes. Tectonic's price oracle picked up this inflated price, allowing the attacker to post the pumped tokens as collateral and borrow tens of millions of dollars in stablecoins, WETH, and other liquid assets across the protocol's lending pools.  Before protocol operators could intervene, the attacker managed to bridge approximately $6 million in stolen funds to Ethereum. To prevent the remaining stolen funds from exiting the ecosystem, Cronos network validators took the emergency step of halting block production on the entire Cronos blockchain. This action trapped over $68 million of the exploit proceeds in the attacker's Cronos addresses, while leaving Tectonic with massive bad debt and forcing a complete pause of its platform Block Data Reference Key Addresses: Attacker Address 1: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc Attacker Address 2: 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc Attacker Contract: 0x085f3115ca368aa262246d22f9476e1e2c87e8be

De.Fi↗
Aug 28, 2026
Aug 28, 2026
Avici
Unknown chainreported
Access control

Quick Summary On August 28, 2026, crypto card provider Avici and three other card programs suffered an exploit totaling approximately $1.02 million (~10,000 SOL) due to an instruction verification flaw in their shared card contract managed by partner Rain. The attacker exploited the bug to grant themselves admin rights, drained card collateral pools, swapped the funds to USDC, bridged them to Ethereum, and deposited ~418 ETH into Tornado Cash. Details of the Exploit The vulnerability was present in an older Solana smart contract developed by card issuer Rain, which managed user card top-up balances independently from self-custodial user wallets. The exploit relied on an instruction index trick in Solana's Ed25519 signature verification precompile. The attacker submitted a transaction with two Ed25519 instructions: the first carried a genuine signature from a newly generated throwaway key, while the second instruction set its signature, public key, and message indexes to point back to the index of the first instruction. The precompile re-verified the valid signature from the first instruction rather than checking the admin key in the second instruction, leading the contract to incorrectly register two valid admin signatures and grant the attacker full admin privileges (AddCollateralAdmin). Using these elevated privileges, the attacker drained four card programs, collecting 10,000 SOL (~$1.02M USD). They converted the SOL to USDC on Solana, transferred the funds to Ethereum address 0x2cE21E4921d3Eb116526c3651Dac0257657338D5, swapped the proceeds into ~418 ETH, and routed the entire balance through Tornado Cash. Self-custodial Avici wallets were unaffected. Avici reported that $500,859.22 in card balances across 1,685 users was impacted, and confirmed that all affected users will receive full refunds. Block Data Reference Solana Attacker Address: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Ethereum Attacker Address: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5

De.Fi↗
Aug 27, 2026
Aug 27, 2026
Moonwell
Unknown chainreported
Oracle issue

Quick Summary On August 27, 2026, Moonwell’s MAMO lending market on Base was exploited through a combination of collateral-accounting manipulation and DEX oracle manipulation. The attacker deployed roughly $1.95 million in starting capital, inflated their collateral value to borrow over $11 million in mixed crypto assets, and extracted $8.73 million via Circle CCTP to Ethereum, leaving the protocol with around $9.13 million in bad debt. Details of the Exploit The attack began when the exploiter withdrew 800 ETH from Tornado Cash, swapped most of it into about $1.95 million USDC, and bridged those funds to Base to accumulate MAMO tokens. They first deposited 15 million MAMO into Moonwell to mint receipt tokens (mMAMO). Next, instead of using the normal deposit route, they transferred another 53.4 million MAMO directly into the mMAMO contract address. Because this direct transfer bypassed the protocol's minting function and supply caps, it artificially increased the underlying token backing behind every existing mMAMO share by nearly 3.7 times. Holding three-quarters of all receipt tokens, the attacker captured almost all of this sudden collateral equity boost. At the same time, the attacker used aggressive DEX trades across low-liquidity pools to inflate the market price of MAMO from around $0.01 to over $0.40. With both the share backing ratio and the oracle price drastically spiked, Moonwell valued the attacker’s collateral at over $22 million, allowing them to draw 18 separate loans totaling $11.03 million in WETH, cbBTC, USDC, and wstETH. The attacker quickly converted these assets, burned $8.73 million USDC through Circle's cross-chain bridge to Ethereum, and swapped it into DAI. Liquidators stepped in seconds after the final borrow and seized the attacker's remaining collateral shares, but the steep price drop left Moonwell with a net shortfall of roughly $9.13 million. Block Data Reference Key Addresses: Operational / Funds Destination Account: 0xD71dD9B6e6344

De.Fi↗
Aug 23, 2026
Aug 23, 2026
Term Labs
Ethereumreported
Other

Quick Summary On August 23, 2026, fixed-rate lending provider Term Labs suffered a governance exploit affecting its Term Vaults (built on Yearn v3 vault infrastructure), resulting in the loss of approximately $8.5 million in digital assets (~2,843 ETH and ~1.68M USDC). Details of the Exploit The incident occurred not through a code bug or reentrancy flaw, but through the manipulation of vault governance rules enabled by low voter participation and float. The attacker initially funded with 2 ETH routed through Tornado Cash acquired sufficient voting influence to pass parameter changes as designed by the protocol's governance architecture. Once vault control was secured, the attacker executed a structured sequence of transactions that unraveled integrated positions across external lending protocols (including Aave and Morpho), unwinding staked ETH positions and draining approximately 2,843 ETH alongside 1.68 million USDC. The attacker subsequently swapped the stolen USDC for roughly 1.6 million DAI and consolidated the funds in wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Block Data Reference Key Attacker Address: 0xD5183d8BfC65a50863C62aF2538198A8288FFc13

De.Fi↗
Aug 21, 2026
Aug 21, 2026
THE Sandbox
Ethereumreported
Access control

Quick Summary On August 21–22, 2026, The Sandbox gaming platform experienced an exploit targeting its LayerZero-based Omnichain Fungible Token (OFT) bridge deployments on Base and BNB Smart Chain (BSC). By hijacking LayerZero delegate permissions via approveAndCall, the attacker minted massive quantities of unbacked SAND tokens on destination chains. The attacker then initiated cross-chain redemptions back to Ethereum L1, completely draining the ~14.75 million SAND (~14,753,431 SAND) backing escrow held in the Ethereum OFT adapter contract. Details of the Exploit The attack exploited a permission configuration flaw in the LayerZero OFT delegate settings for the SAND token on Base and BSC. By leveraging approveAndCall, the attacker hijacked the protocol's delegate permissions and issued unauthorized minting calls across 700+ transactions to 173 addresses, generating trillions of face-value unbacked SAND tokens on Base. While the majority of the unbacked L2 mints were hyper-inflated tokens isolated on destination chains, the attacker successfully submitted cross-chain redemption messages back to Ethereum mainnet. Between 00:32:11 and 01:22:11 UTC on August 22, the Ethereum OFT adapter escrow (0xac531eb26ca1d21b85126de8fb87e80e09002dcf) was drained from 14,769,723 SAND down to ~0.0056 SAND across 15 exit transactions (with ~14.1 million SAND transferred to a single EOA in 6 transactions). Total L1 supply remained unchanged at 3 billion SAND, but the mainnet bridge escrow backing L2 tokens was completely depleted (~14.75M SAND, representing <0.01% of total SAND supply). Block Data Reference Ethereum SAND Token / OFT Contract: 0x3845badade8e6dff049820680d1f14bd3903a5d0 Ethereum OFT Adapter Escrow: 0xac531eb26ca1d21b85126de8fb87e80e09002dcf

De.Fi↗
Aug 19, 2026
Aug 19, 2026
Maya Protocol
Unknown chainreported
Other

Quick Summary On August 19, 2026, cross-chain liquidity network Maya Protocol was exploited for approximately $1.7 million in assets (including 20.83 BTC valued at ~$1.4M), leading to an overall liquidity pool valuation drop of ~$11 million.  Details of the Exploit The exploit targeted Trade Accounts (ported from THORChain in mid-2025) that were never integrated into Maya's solvency checker (vault.Coins) or outbound transaction-matching logic. The attacker deposited 8 ETH and 2 LINK into trade accounts, then submitted a 23-message MsgDeposit batch consisting of 22 trade withdrawals (each incremented by ~263 units to prevent outbound batching) and 1 donation. Because the nodes observed 22 simultaneous L1 outbounds unmatched by standard TxOutItems, the security system incorrectly flagged the attacker's own legitimate withdrawals as external theft. This false alert triggered the automated subsidizePoolsWithSlashBond() theft-compensation handler. Lacking an upper cap, the handler attempted to dump ~49.42 million CACAO into the pools to compensate for the non-existent theft. Although the transaction failed on-chain due to insufficient reserve funds (~168,000 CACAO actual reserve), a state accounting flaw saved the inflated pool balance regardless. Having pre-positioned in an almost empty ARB.LINK liquidity pool with 100 CACAO, the attacker withdrew 99% of their LP position, extracting 48,869,502 CACAO. The attacker then executed 10 consecutive CACAO-to-BTC swaps, siphoning 20.83 BTC directly to a Bitcoin address and triggering secondary arbitrage extraction across the network. Block Data Reference Key Attacker Bitcoin Address: bc1q0hsgwunccczelq05ucpmfz268eyy5jr2y5l646

De.Fi↗
Aug 15, 2026
Aug 15, 2026
FOX
BNB Chainreported
Flash loan attack

Quick Summary On August 15, 2026, BSC-based bond market protocol Fox Market was exploited via an atomic flash-loan attack. The attacker utilized ~$482 million in flash-loaned stablecoins to trigger over-minting of protocol bonds and siphon ~$678,000 from the PancakeSwap FOX/USDT liquidity pool, yielding ~$117,000 in net attacker profit after flash-loan fees. Details of the Exploit The attack targeted a critical ordering vulnerability in the stake() function on contract 0x9fa6d8a13b35e051bfc145918db0111dec13d1a0. When executed, stake() sampled the FOX token spot price ($5.44) prior to executing the swap of injected USDT into the underlying PancakeSwap pool. Attacker 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 borrowed ~$482 million in USDT across Lista, Venus, and Aave, passing the capital into the bond minting routine. Because the mint valuation calculated token issuance based on the pre-swap spot price rather than the post-swap execution price, the protocol printed ~181x more bond tokens (88.66M sFOX) than intended. The contract then burned the newly created LP tokens to 0x00...dead and instantly paid an unlocked 3% referral bonus in FOX (2.66M tokens) to an inviter address. The attacker dumped these referral tokens directly into the newly USDT-heavy PancakeSwap pool, drained ~$678,000 from existing pool liquidity, fully repaid all $482 million in flash loans, and extracted ~$117,000 in net profit. Block Data Reference Exploit Transaction: 0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514 Attacker: 0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9 Attack Helper Contract: 0x3A82A2A77061017927e5331fFFd07c0308a1D2DA

De.Fi↗
Aug 13, 2026
Aug 13, 2026
Whale Wallet Drain
Ethereumconfirmed
Phishing

Q uick Summary On August 13, 2026, an unknown victim address (0x13e382dfe53207E9ce2eeEab330F69da2794179E) was drained of approximately $25.6 million in cryptocurrency assets, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M). This marks the second major exploit targeting this exact whale address, which previously lost $24.23 million to a malicious token approval phishing attack in September 2023. Details of the Exploit The attacker executed unauthorized transfers siphoning $25.6 million in multi-asset holdings, including WBTC, cbBTC, aWBTC, LDO, USDS, CRV, DAI, and ETH out of the victim's wallet. Immediately following the drain, the attacker swapped the stolen assets across decentralized protocols to consolidate the loot into stable capital, converting the holdings into approximately 20 million DAI and 3,000 ETH (~$5.64M). The consolidated funds were subsequently split across four target collector addresses (including 0x61ce24326d713641583e6a337a69bef7458fcf76), while security monitoring teams track potential recovery or laundering attempts. Block Data Reference Attacker / Theft Address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae Primary Consolidation Address: 0x61ce24326d713641583e6a337a69bef7458fcf76

De.Fi↗
Aug 12, 2026
Aug 12, 2026
Harmony
Unknown chainreported
Other

Quick Summary On August 12, 2026, Layer-1 blockchain Harmony Protocol suffered a major protocol-level security incident when an attacker exploited an "empty blocks" vulnerability to fraudulently mint approximately 4 billion ONE tokens representing roughly 26% of the token's total circulating supply and causing the price of ONE to crash between 26% and 34%. Details of the Exploit The exploit targeted a consensus or state-update bug involving empty blocks, allowing the attacker to mint ~4 billion ONE tokens out of thin air while bypassing standard protocol reporting endpoints (leaving totalSupply metrics temporarily unchanged). The attacker rapidly transferred approximately 2.8 billion ONE (~97% of the fraudulently created tokens) directly into centralized crypto exchanges for liquidation, leaving only around 115 million ONE in on-chain addresses. In response, Harmony requested exchanges to freeze funds from four identified attacker wallet addresses while the core team began developing a software patch and evaluating blockchain rollback options. Block Data Reference Key Attacker Addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510) one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4  (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5)

De.Fi↗
Aug 10, 2026
Aug 10, 2026
Coinsbuy
Ethereumreported
Access control

Quick Summary On August 10, 2026, cryptocurrency payment platform Coinsbuy suffered a coordinated hot wallet compromise across both TRON and Ethereum, losing approximately $7.9 million to $8.07 million in under an hour. Coinsbuy temporarily halted deposits and withdrawals to contain the incident before fully covering all affected balances from its corporate reserves and resuming normal operations without client loss. Details of the Exploit The attacker executed a rapid, cross-chain operation impacting multiple hot wallet addresses simultaneously. On TRON, the perpetrator drained roughly $6.04 million in USDT across eight wallets within an hour. Concurrently on Ethereum, three hot wallets were emptied of approximately 1.89 million USDT along with native ETH. The attacker leveraged cross-chain swap services (including Bridgers) and non-custodial exchanges (FixedFloat, ChangeNOW, and BingX) to route ~79% of the stolen funds through a non-clusterable pattern, splitting transactions across 50 single-use addresses to convert the capital into Monero (XMR). While ChangeNOW managed to freeze a six-figure sum of the illicit transfer, the majority of the stolen assets were converted into untraceable privacy coins. Coinsbuy subsequently refilled the drained hot wallets from its balance sheet, indicating the underlying platform infrastructure remained secure. Block Data Reference Key Attacker Addresses: TRON Collector: TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR Ethereum Collector: 0x4d1bef2fe998b3e3c4029ef9ea6a0534d95661d3 Ethereum Swap Wallet: 0x66790b54b891e2ebdef58a15b969ff6fb4374b17

De.Fi↗
Aug 9, 2026
Aug 9, 2026
Coreum
Unknown chainreported
Other

Quick Summary On August 9, 2026, the Coreum cross-chain bridge connecting to the XRP Ledger (XRPL) was exploited due to a deposit verification flaw, resulting in the theft of 199,916 XRP (valued at approximately $200,000) across 94 transactions within 97 minutes. Details of the Exploit The attack targeted a vulnerability in the Coreum bridge's deposit verification logic and multisig relayer infrastructure connecting the Coreum blockchain to the XRP Ledger. By exploiting a flaw in how incoming cross-chain deposit proofs were validated, the attacker tricked the relayer system into recognizing unverified or forged deposit events as legitimate. Over a 97-minute window, the attacker executed 94 consecutive fraudulent withdrawal requests, systematically siphoning 199,916 XRP out of the bridge liquidity before operations could be suspended.

De.Fi↗
Aug 3, 2026
Aug 3, 2026
Risex
Unknown chainreported
Other

Quick Summary On August 3, 2026, perpetual exchange protocol RISEx experienced an unauthorized withdrawal of 673,011.56 USDC from the Real-World Asset (RWA) yield strategy linked to its XLP liquidity vault due to a smart contract misconfiguration. The team patched the vulnerability within minutes and fully reimbursed XLP depositors using protocol fee revenue, resulting in zero user losses. Details of the Exploit The exploit was caused by a configuration flaw in the RWA yield strategy connected to RISEx's XLP vault, which had been present since its deployment on July 13, 2026. An unauthorized user took advantage of this misconfiguration at 07:21 UTC to execute an unverified withdrawal of 673,011.56 USDC. Because the withdrawal amount sat below the protocol's automatic rate-limiting and throttling thresholds, the transaction executed on-chain. RISEx engineering detected the transaction within minutes and deployed a patch by 08:09 UTC. The protocol covered 100% of the lost capital using a portion of its July trading fee revenue. Block Data Reference Attack Transaction: 0xc52560bec154a3d5533a321bd9805305a5076194573ddb2fbb059059ace3e987

De.Fi↗
Aug 2, 2026
Aug 2, 2026
Loopsdao
BNB Chainreported
Oracle issue

Quick Summary On August 2, 2026, LOOPSDAO's LpdFi protocol on BNB Chain was exploited for approximately $690,000 in USDC (netting ~$573,000 in profit) through a combination of spot price oracle manipulation and a flaw in the protocol's discrete daily interest accrual logic. Details of the Exploit The attack targeted Lpd.price(), which derived token valuations directly from the instantaneous reserves of a PancakeSwap LPD/USDC liquidity pair without TWAP, liquidity thresholds, or price deviation guards. The attacker temporarily inflated the LPD spot price by ~5,163x via temporary liquidity swaps and invoked buy(), allowing them to record a massive $140M nominal USDC interest-bearing principal for a minimal LPD deposit. After rebalancing the pool and stepping across the daily issue boundary in the subsequent block (just one second later), the attacker called claimInterest(), which accrued a full 0.5% interest period on the bloated principal and forced the protocol to burn 1.68 million of its own Cake-LP tokens (with zero slippage bounds) to pay out the unbacked USDC. Block Data Reference Attacker Address: 0x5d289266d85ef671561ba3f253fb79327c193f33 Attack Executor Contract: 0x7f5ad0a998dcb3f5006f0d152bebc055979ef711 Victim / Vulnerable Contract: 0xce6a6e4413d85a136bbac8aae6fb46eaa77f295e Setup Transaction: 0xbb5b8573d7203e00f8fb9d4839dbeea46a8efd367eac8bed81e4ece2341c3588 Claim Transaction: 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6

De.Fi↗
Aug 2, 2026
Aug 2, 2026
Moke Token
BNB Chainreported
Access control

Quick Summary On August 2, 2026, the MOKE token protocol on BNB Chain was exploited for approximately $907,700 (~1,546 BNB) due to a critical access control flaw in its smart contract architecture. Details of the Exploit The exploit was caused by an unprotected public claim() function within the MokeToken.releaseContract() contract, which lacked caller eligibility checks or role-based access control. The attacker repeatedly called claim() to drain roughly 166 million MOKE tokens directly from the protocol's internal reserve pool. To realize their profit, the attacker combined flash loans, Venus Protocol leverage, liquidity pool removal, and internal dividend distribution mechanics to swap the extracted tokens into 1,546 BNB. Block Data Reference Attack Transaction: 0x0776048b1b58064fb31b6513721811e7b44d6bdbe7bf5833158b241ca6756a8f

De.Fi↗
Aug 1, 2026
Aug 1, 2026
Totally Unknown Protocol XYZ
Ethereumconfirmed
Rugpull

Unmatched project for pending review.

De.Fi↗
Jul 30, 2026
Jul 30, 2026
Coldcard
Unknown chainreported
Other

Quick Summary Starting July 30, 2026, Bitcoin hardware wallet manufacturer Coldcard (by Coinkite) disclosed a critical firmware entropy defect that enabled attackers to systematically brute-force and drain user funds offline, resulting in cumulative losses estimated between $85 million and $130 million+ (~1,900 to 2,055+ BTC) across multiple organized attack waves. Details of the Exploit The vulnerability originated from a firmware code refactoring introduced in version 4.0.1 (March 2021), where seed phrase generation calls were migrated from ckcc.rng_bytes() to ngu.random.bytes(). This migration unintentionally caused the underlying rng_get() function to resolve to MicroPython's software Pseudo-Random Number Generator (PRNG) fallback instead of Coldcard's dedicated True Hardware Random Number Generator (TRNG). Consequently, generated wallet seeds possessed severely degraded entropy, approximately 40 bits on Mk3 devices and ~72 bits on newer models, down from the intended 128/256 bits. Attackers leveraged this reduced search space to pre-compute and offline brute-force the predictable private keys for affected single-signature addresses, executing sweeping transactions across four distinct waves without requiring physical access to the hardware devices. Coinkite issued security advisories across affected models (Mk3, Mk4, Q, Mk5) while security researchers worked with victims to perform Replace-By-Fee (RBF) cancellations for pending mempool sweeps.

De.Fi↗
Jul 28, 2026
Jul 28, 2026
Lula Token
BNB Chainreported
Flash loan attack

Quick Summary On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan. Details of the Exploit The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios. This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit. Block Data Reference Attack Transaction: 0xa219ab9d57e520e5235b15a8801f4ebac8cc45551be0430ce4e49caea0411d7c

De.Fi↗
Jul 26, 2026
Jul 26, 2026
Wemix
Unknown chainreported
Access control

Quick Summary On July 26, 2026, WEMIX (the blockchain ecosystem backed by South Korean gaming company Wemade) suffered a smart contract compromise affecting its WEMIX$ stablecoin contract, resulting in an unauthorized minting and transfer of approximately $6.25 million worth of tokens. Details of the Exploit The incident occurred when an unauthorized party compromised the contract ownership privileges of a WEMIX$-related smart contract. Using these administrative rights, the attacker fraudulently minted 5,225,525 WEMIX$ and transferred USDC.e out of the protocol. The attacker converted the fraudulently minted tokens into 30,736 WEMIX and 724,198.27 USDC.e, before bridging the USDC.e over to Ethereum and BNB Smart Chain (BSC). On those destination networks, the funds were swapped into assets including ETH and USDT, with a portion subsequently deposited into centralized exchanges. In response, the WEMIX team temporarily suspended all connected bridges (including Chainlink CCIP and PLAY Bridge), withdrew Foundation-provided liquidity, halted trading across affected liquidity pools (WEMIX-USDC.e, WEMIX-WEMIX$, CROW-WEMIX$, TIPO-WEMIX$, and PLAY-WEMIX$), paused the WEMIX$ Module and PNIX DEX, and coordinated with global exchanges to freeze attacker-linked addresses.

De.Fi↗
Jul 26, 2026
Jul 26, 2026
Garden Finance
Ethereumreported
Other

Quick Summary On July 26, 2026, cross-chain atomic swap protocol Garden Finance suffered a supply chain compromise affecting its Hash Time-Locked Contracts (HTLC), resulting in an initial drain of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, BNB Chain, and Solana. Details of the Exploit The exploit was an off-chain supply chain attack rather than a direct smart contract code vulnerability. An attacker compromised the off-chain database of an independent solver integrated with Garden Finance and injected forged transaction records. Because the protocol relies on solver state data to process cross-chain atomic swaps between Bitcoin and EVM/Solana networks, these fraudulent records deceived the HTLC contracts into releasing escrowed USDT assets directly to the attacker without valid matching inputs. Garden Finance immediately took its front-end web application offline to prevent further improper fund releases, confirming that while core smart contracts remained secure, the breach stemmed entirely from off-chain solver infrastructure. Block Data Reference EVM Attacker Address: 0x25b224c05f6cc5e132165c1621de1a4c3b316999 Solana Attacker Address: WZy4xxpqktWa1b6MPMRiWsD487CT8mDcapB6GufBJCH Example EVM Exploit Transaction: 0x9d7a961aa340156b7342839e9f6448a26dea9acd38dc7b2638966eb19e29d395

De.Fi↗
Jul 25, 2026
Jul 25, 2026
Triple A
Ethereumreported
Access control

Quick Summary On July 25, 2026, Singapore-based licensed stablecoin payment gateway Triple-A suffered a hot wallet compromise across multiple blockchains, resulting in the unauthorized extraction of approximately $9.7 million to $11.8 million in company-owned treasury assets. Details of the Exploit The incident occurred when an unauthorized party obtained compromise access to Triple-A's multi-chain hot wallet infrastructure across TRON, Ethereum, Polygon, and Arbitrum. The attacker drained the company's operational treasury accounts, swapped the stolen digital assets, and bridged them to Ethereum Mainnet, consolidating 5,227 ETH into a single holding wallet. Client funds were entirely unaffected because Triple-A does not provide digital asset custody for its users, keeping client balances strictly segregated in trust accounts with safeguarding financial institutions. Triple-A temporarily placed certain services into maintenance mode for approximately three hours to secure the affected infrastructure before fully restoring normal payment processing, transaction settlements, and global operations.  

De.Fi↗
Jul 25, 2026
Jul 25, 2026
Projekt Green Gold
Ethereumreported
Flash loan attack

Quick Summary On July 25, 2026, the Projekt (GREEN/GOLD) reward vault on Ethereum was exploited, resulting in the loss of approximately 301.7 ETH (valued at ~$560,000) due to a logic flaw in its buy-to-earn reward allocation tracking. Details of the Exploit The exploit targeted a logic error in the reward vault's permissionless trackPurchase(buyer) function, which was designed to credit ETH allocations to buyers based on token balance deltas. Crucially, trackPurchase relied solely on token balance increases to calculate reward sizing without validating whether genuine ETH was spent to acquire those tokens. To execute the attack, the exploiter secured a flash loan of approximately 14,000 WETH from Morpho. They pushed these funds into dozens of Uniswap V2 memecoin liquidity pairs (such as Kirby Inu and ROTTSCHILD) and invoked skim() to transfer the tokens directly to their contract. This self-dealing token movement inflated the buyer's balance delta, tricking the unverified trackPurchase function into registering massive fake "purchase" reward allocations at virtually zero net cost. Once the fake allocations were credited and the flash loan repaid in the same transaction, the attacker called massWithdraw() to drain ~301.7 ETH from the vault's reward pool. Block Data Reference Attacker Address: 0x61e7ad696215688d274c729a4cd0fbbc88fc4f85 Victim / Vulnerable Contract: 0x574fc478bc45ce144105fa44d98b4b2e4bd442cb Attack Transaction: 0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64

De.Fi↗
Jul 23, 2026
Jul 23, 2026
Solido Cash
Unknown chainreported
Oracle issue

Quick Summary On July 23, 2026, Solido Cash on the Supra blockchain was exploited due to an oracle fallback misconfiguration on its SOLID vault. An attacker leveraged an invalid stale price fallback to over-mint CASH stablecoins and extract approximately 293.7 million SUPRA tokens (~$73,400 net value), with protocol reserves absorbing the loss so zero user funds were affected. Details of the Exploit The exploit stemmed from an oracle misassignment where a stale primary price feed for the SOLID token incorrectly fell back to the $1.00 CASH stablecoin oracle instead of halting or using a proper secondary feed. Treating cheap SOLID collateral as equivalent in value to CASH, the attacker executed atomic contract interactions and manual secondary wallet mints to generate unbacked CASH stablecoins, which were immediately swapped for native SUPRA tokens across local decentralized exchanges. Solido Cash subsequently paused vault interactions and patched the oracle fallback mappings.

De.Fi↗
Jul 23, 2026
Jul 23, 2026
Verus
Unknown chainreported
Other

Quick Summary On July 23, 2026, the cross-chain bridge connecting the Verus blockchain to Ethereum was exploited for the second time in two months, resulting in the unauthorized extraction of approximately $7.53 million across multiple digital assets. Details of the Exploit The exploit targeted a semantic and authority validation flaw in how the Ethereum-side bridge contract verifies cross-chain export outputs from Verus. While the contract verified that a given export payload existed within a valid Verus block and matched a genuine state root notarized on Ethereum, it failed to verify that the Verus network itself had authorized the payload as a legitimate primary export. The attacker initiated a tiny 0.01 VRSC bridge transaction to create a valid export state, then authored a custom Verus transaction spending that output and attaching a handwritten export commitment declaring 8 transfer instructions to the attacker's wallet. After relaying two legitimate notarizations to Ethereum containing the state root of their custom transaction, the attacker submitted the import request. Because the cryptographic Merkle proofs and payload hash checks matched the attacker-controlled input data, the bridge executed the transfer, releasing $7.53 million in tBTC, DAI, USDC, scrvUSD, USDT, MKR, and EURC. The stolen assets were immediately swapped on-chain for 3,916.1 ETH and deposited into Tornado Cash. Block Data Reference Attacker Address: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

De.Fi↗
Jul 23, 2026
Jul 23, 2026
AFX
Unknown chainreported
Access control

Quick Summary On July 23, 2026, the cross-chain custody bridge operated by decentralized exchange AFX on Arbitrum was exploited, resulting in the unauthorized withdrawal of 24.15 million USDC. Details of the Exploit The incident was carried out via a private key or backend validator infrastructure compromise. The attacker forged an on-chain withdrawal request on Arbitrum that carried valid cryptographic signatures from five bridge validators. Because these signatures satisfied the bridge contract's multi-signature authorization threshold, the contract executed the transaction as legitimate and released 24.15 million USDC from custody. The attacker immediately bridged the stolen stablecoins from Arbitrum to Ethereum Mainnet and swapped them for approximately 12,467.5 ETH. Following detection, AFX suspended bridge operations to isolate the vulnerability, confirming that the platform's core trading engine, mainnet, and Arbitrum's native bridge remained uncompromised while security teams began tracing the funds. Block Data Reference Arbitrum Creation Transaction: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Arbitrum Finalize Transaction: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b Ethereum Attacker Wallet: 0x627654b2782bfc57580ecd11d40869b350b6ebac

De.Fi↗
Jul 23, 2026
Jul 23, 2026
B Network
BNB Chainreported
Access control

Quick Summary On July 23, 2026, Bitcoin Layer-2 protocol B² Network suffered a security incident on BNB Chain targeting its B2 token staking service, resulting in the unauthorized extraction of approximately 8.59 million B2 tokens (valued at ~$3.86 million). Details of the Exploit The exploit was caused by a compromise of the administrative upgrade authority governing the upgradeable proxy contract for B² Network's staking service. An address (0x35fE...b287d) that had granted itself privileged admin permissions over a year prior (May 2025) executed an upgradeToAndCall function call on the live staking proxy contract. This replaced the legitimate contract implementation with a malicious logic contract (0x0B875E...C9DCa). Six minutes after the proxy upgrade, the attacker invoked draining functions through the newly deployed logic, extracting ~8.59 million B2 tokens across nine batch calls within 45 minutes. The stolen B2 tokens were swapped on-chain for 5,409 WBNB, converted to 1,128 ETH, and bridged out of BNB Chain via Near Intents.  Block Data Reference Malicious Implementation Contract: 0x0B875E23C6b04D3683f1D4c4f0FFf7f2b5cC9DCa Upgrade Transaction: 0x2069714bbe6671f7737f85c5caee7fbccd15ed8f045b2cd6f6b52229cd47d769

De.Fi↗

Liquidations updated 4h ago · Incidents updated 2d ago

Open dashboard · Methodology · Sources · Definitions