Crypto Hack Registry: Every Major Hack, Exploit and Theft
Every cryptocurrency hack, exploit and theft of $100k or more that we can verify, in one permanent place. Each entry carries the sources behind it, so any figure here can be checked rather than taken on trust.
- Verified incidents
- 16
- Verified losses
- $5.6B
- Recovered
- $1B
- Covering
- 2021–2026
Take the data
No key, no sign-up, no rate limit for ordinary use. Published under CC BY 4.0 — reuse it commercially if you credit iTokenly and link back.
| Date | Target | Loss | Method | Type | Chains | Evidence |
|---|---|---|---|---|---|---|
| Drift ProtocolMultisig signers manipulated into surrendering admin control, then oracles moved with a fake token | $285M | Social engineering | Decentralised exchange | Solana | Verified3 sources | |
| Cetus ProtocolOverflow in the checked_shlw helper of the integer-mate maths library | $223M–$260M$162M back | Contract logic error | Decentralised exchange | Sui, Ethereum | Verified3 sources | |
| BybitCompromised Safe{Wallet} infrastructure served a malicious signing interface | $1.4B–$1.5B | Supply chain or frontend compromise | Centralised exchange | Ethereum | Verified3 sources | |
| WazirXSigners approved a malicious contract upgrade shown differently by the custody interface | $235M | Social engineering | Centralised exchange | Ethereum | Verified3 sources | |
| ≈ | DMM BitcoinFake recruiter compromised an employee at wallet vendor Ginco, then altered a transaction request | $308M | Social engineering | Centralised exchange | Bitcoin | Verified3 sources |
| Mixin NetworkCloud database provider compromised, exposing the network's hot wallets | $142M–$200M | Infrastructure compromise | Infrastructure provider | Multiple chains | Verified3 sources | |
| Curve FinanceVyper 0.2.15–0.3.0 compiled broken reentrancy guards into affected pools | $52M–$73M | Reentrancy | Decentralised exchange | Ethereum | Verified3 sources | |
| Atomic WalletRoot cause never publicly disclosed; user keys compromised at scale | $35M–$100M | Other or undisclosed | Wallet software or provider | Multiple chains | Verified3 sources | |
| Euler FinancedonateToReserves skipped the health check, leaving a self-liquidatable position | $197M$197M back | Flash loan attack | Lending protocol | Ethereum | Verified3 sources | |
| BNB Chain Token HubForged IAVL Merkle proof allowed the attacker to mint 2 million BNB | $100M–$570M | Signature verification flaw | Cross-chain bridge | BNB Chain | Verified3 sources | |
| Nomad BridgeA routine upgrade set the trusted Merkle root to zero, so every message verified | $190M | Contract logic error | Cross-chain bridge | Ethereum | Verified3 sources | |
| Harmony Horizon BridgeControl of the bridge multisig obtained through compromised signer keys | $99.7M$40M back | Private key compromise | Cross-chain bridge | Ethereum, Other | Verified3 sources | |
| Ronin BridgeFive of nine validator keys controlled after a social-engineering campaign | $624M | Private key compromise | Cross-chain bridge | Ronin, Ethereum | Verified3 sources | |
| WormholeDeprecated function let a forged guardian signature pass verification | $326M | Signature verification flaw | Cross-chain bridge | Solana, Ethereum | Verified3 sources | |
| BadgerDAOMalicious script injected through a compromised Cloudflare API key added unlimited spend approvals | $120M | Supply chain or frontend compromise | DAO or treasury | Ethereum | Verified3 sources | |
| Poly NetworkCross-chain manager contract could be instructed to change its own keeper | $611M$611M back | Access control flaw | Cross-chain bridge | Ethereum, BNB Chain, Polygon | Verified3 sources |
Every row has a permanent anchor: append #slug to this page's address to link straight to an entry.
What “verified” means here
A verified entry has at least two independent sources. A post-mortem, an exchange statement, an indictment or a court filing counts as one. Our own confirmation of a transaction against the chain counts as another, because we derive the figure rather than repeat it. Five outlets restating the same original count once. Entries that never clear that bar stay in the table marked as reported and are left out of every total.
Corrections
Figures move as investigations progress. When a published number changes, the entry records what changed and why, and the change stays visible. If something here is wrong, write to [email protected] and it will be checked against the sources.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, iTokenly, accessed 2026-08-01, https://itokenly.com/hackshttps://itokenly.com/hacksPermalinks never change. If an entry is renamed, the old address keeps working.
Last updated August 1, 2026. Read the methodology for inclusion criteria, how losses are valued, and how conflicting figures are resolved.