Crypto Hack Registry: Every Major Hack, Exploit and Theft
Every cryptocurrency hack, exploit and theft of $100k or more that we can verify, in one permanent place. Each entry carries the sources behind it, so any figure here can be checked rather than taken on trust.
- Verified incidents
- 346
- Verified losses
- $12.9B
- Recovered
- $1.8B
- Covering
- 2021–2026
Totals above count verified entries only. A further 46 incidents are listed as reported but not independently confirmed, and are excluded from every figure on this page.
Verified losses by year
$12.9B across 346 incidents
Each bar is the value of assets removed in that year, counting verified entries only. Recent years are still filling in as incidents are added.
Second row is the number of verified incidents recorded in that year. The lighter bar is 2026, which is incomplete by definition.
Take the data
No key, no sign-up, no rate limit for ordinary use. Published under CC BY 4.0 — reuse it commercially if you credit iTokenly and link back.
| Date | Target | Loss | Method | Type | Chains | Evidence |
|---|---|---|---|---|---|---|
| Unnamed Ethereum whale (repeat victim)Nothing has been published about how control of the wallet was obtained | $25.6M | Other or undisclosed | Individual holder | Ethereum | Reported2 sources | |
| Harmony (ONE) unauthorized mintAn attacker minted ONE outside the protocol's issuance rules | $2.2M–$4.8M | Other or undisclosed | Blockchain or validator set | Harmony | Verified4 sources | |
| Unnamed holder (address poisoning)A look-alike address was planted in the wallet's transaction history 66 days ahead of time, then copied from that… | $100k | Phishing signature | Individual holder | — | Reported1 source | |
| tx XRPL bridge (formerly Coreum)The relayers' deposit-detection logic accepted transactions that delivered no XRP as real deposits, minting unbacked… | $202k | Contract logic error | Cross-chain bridge | XRP Ledger, Other | Verified3 sources | |
| CoinsbuyEleven hot wallets on two chains drained in under an hour | $8.1M | Other or undisclosed | Custodian or payment processor | Ethereum, Tron | Verified4 sources | |
| Coldcard (Coinkite) seed entropy flawA 2021 firmware build fell back to a software PRNG, leaving seeds with too little entropy to resist offline enumeration | $114M–$130M | Private key compromise | Wallet software or provider | Bitcoin | Verified5 sources | |
| Crypto DAOA vault function on the Pro token contract was reported to be publicly callable with no access control on a… | $8.2M | Access control flaw | DAO or treasury | BNB Chain | Reported3 sources | |
| WEMIXAttacker obtained owner privileges over the WEMIX$ stablecoin contract and minted 5.23m unauthorised tokens | $724k–$6.3M | Access control flaw | Stablecoin or yield protocol | Ethereum, BNB Chain, Other | Verified3 sources | |
| Triple-ACompromise of hot wallets holding Triple-A's own corporate digital assets across seven chains | $9.7M–$11.8M | Private key compromise | Other | Ethereum, Tron, Polygon, Arbitrum, Solana, TON, Bitcoin | Verified4 sources | |
| Verus-Ethereum Bridge (July 2026)Missing source-value validation in the bridge's cross-chain import path | $7.5M | Contract logic error | Cross-chain bridge | Ethereum, Other | Verified3 sources | |
| AFX TradeSocial-engineering entry followed by a software supply-chain compromise that ended in validator key control | $24.2M | Private key compromise | Cross-chain bridge | Arbitrum, Ethereum | Verified4 sources | |
| Wanchain Cardano–BNB Chain bridgeNon-injective signed-message encoding in the bridge's TreasuryCheck validator | $9M–$13M | Signature verification flaw | Cross-chain bridge | Cardano, BNB Chain | Verified4 sources | |
| Allbridge CoreAn attacker borrowed roughly $1.12 million in USDC from the Solana lending protocol Kamino and swapped rapidly between… | $1.7M | Flash loan attack | Cross-chain bridge | Solana, Ethereum | Verified3 sources | |
| Across ProtocolForged Solana deposit events | $3.6M–$4.5M | Contract logic error | Cross-chain bridge | Solana | Verified4 sources | |
| ≈ | Cascade (CLS Vault)Root cause never published | $1.3M | Other or undisclosed | Decentralised exchange | Arbitrum | Verified4 sources |
| OstiumThe attacker gained unauthorised access to Ostium's off-chain price-reporting infrastructure and pushed fraudulent… | $18M–$23.8M | Infrastructure compromise | Decentralised exchange | Arbitrum | Verified4 sources | |
| Bonzo LendBonzo Lend priced collateral using Supra, a third-party oracle | $9.1M–$10.1M | Oracle or price manipulation | Lending protocol | Other | Verified4 sources | |
| Lazy Summer ProtocolLazy Summer vaults route deposits to external strategies through adapters called Arks and derive share price from the… | $6M | Oracle or price manipulation | Other | Ethereum | Verified5 sources | |
| BonkDAOThe attacker bought just over 1 percent of BONK's supply on the open market for roughly $4.4 million, enough to meet… | $20M | Governance attack | DAO or treasury | Solana | Verified4 sources | |
| PolymarketClient-side supply-chain compromise | $3M | Supply chain or frontend compromise | Other | Polygon, Ethereum | Verified4 sources | |
| ≈ | SecondFi (formerly Yoroi Wallet)SecondFi's wallet software generated per-transaction signatures using a nonce that was not sufficiently random | $2.4M–$2.6M | Private key compromise | Wallet software or provider | Cardano | Verified4 sources |
| Taiko BridgeTaiko's Bridge delegated authentication of source-chain messages to its SignalService, which accepted a Merkle proof… | $1M–$1.7M | Signature verification flaw | Cross-chain bridge | Ethereum | Verified4 sources | |
| PancakeSwap OLPC/LABUBI liquidity poolThe OLPC token contract treated transfers initiated by the PancakeSwap V2 pair as buys and burned the transferred… | $960k–$1.1M | Contract logic error | Decentralised exchange | BNB Chain | Verified4 sources | |
| JaredFromSubway.eth MEV BotCounter-MEV honeypot | $7.5M | Other or undisclosed | Other | Ethereum | Verified4 sources | |
| Aztec 2.0 Rollup BridgeA soundness flaw in the escape-hatch withdrawal path of the deprecated Aztec 2.0 RollupProcessor | $2.2M | Contract logic error | Cross-chain bridge | Ethereum | Verified3 sources | |
| Aztec ConnectThe deprecated rollup contract's settlement loop processed transactions only up to a declared numRealTxs value, while… | $2.3M | Contract logic error | Cross-chain bridge | Ethereum | Verified5 sources | |
| RaydiumThe remove-liquidity instruction in Raydium's deprecated legacy AMM V3 program did not verify that the LP token account… | $1.3M | Contract logic error | Decentralised exchange | Solana | Verified3 sources | |
| Secret Network – Axelar IBC bridgeSecret Network's ics20-for-axelar contract was a customised fork of CW20-ICS20 in which two validation routines had… | $4.7M | Contract logic error | Cross-chain bridge | Other, Ethereum | Verified3 sources | |
| Token of PowerGovernance takeover of an Aragon DAO with no timelock and voting weight proportional to a 16,384-token supply | $1.6M | Governance attack | Token contract | Ethereum | Verified3 sources | |
| ≈ | Humanity Protocolmultisig signer keys backed up to one compromised laptop, used to seize bridge and token ProxyAdmin control | $32M–$36M | Private key compromise | Other | Ethereum, BNB Chain | Verified6 sources |
| Syscoin bridgeA cross-layer interpretation mismatch in the Syscoin UTXO-to-NEVM bridge | $8.4M–$10M$8.4M back | Contract logic error | Cross-chain bridge | Other | Verified3 sources | |
| TesseraDAO (TSR)An address holding privileged mint rights over the TSR token contract called mint() for 99,000,000 TSR at 11:38:25 UTC… | $2.5M | Access control flaw | Token contract | BNB Chain, Ethereum | Verified4 sources | |
| Gravity BridgeDenomination-mapping poisoning | $5.4M | Contract logic error | Cross-chain bridge | Ethereum, Other | Verified4 sources | |
| DxSaleOwnership of a legacy BNB Chain liquidity-locker contract was transferred to an attacker-controlled address after… | $7.3M | Access control flaw | Infrastructure provider | BNB Chain | Verified5 sources | |
| New Market TradingNew Market Trading's SquidRouterModule exposed an express-execution entry point inherited from Axelar's gateway… | $3M–$3.8M | Access control flaw | Other | Ethereum, Base, Arbitrum | Verified4 sources | |
| StablRA single key belonging to an owner of the minting multisig was compromised | $2.8M–$13.5M | Private key compromise | Stablecoin or yield protocol | Ethereum | Verified4 sources | |
| ≈ | RetoSwapHaveno trades settle through a 2-of-3 multisig whose third key belongs to an arbitrator | $2.7M | Access control flaw | Decentralised exchange | Other | Verified3 sources |
| ≈ | Verus-Ethereum BridgeThe Ethereum-side import path verified notarised state roots and notary signatures but never required transfer inputs… | $11M–$11.6M$8.5M back | Contract logic error | Cross-chain bridge | Ethereum, Other | Verified5 sources |
| THORChainA validator that had churned into the active set two days earlier exploited THORChain's GG20 threshold signature… | $10M–$11M | Signature verification flaw | Blockchain or validator set | Ethereum, Bitcoin, BNB Chain, Base | Verified5 sources | |
| ≈ | Transit FinanceExploitation of an early-version Transit Finance smart contract deployed on TRON | $1.9M | Contract logic error | Decentralised exchange | Tron | Reported3 sources |
| TrustedVolumesTrustedVolumes' custom request-for-quote swap proxy exposed a public registerAllowedOrderSigner function with no access… | $5.9M–$6.7M$2M back | Access control flaw | Other | Ethereum | Verified4 sources | |
| EkuboThe EVM swap router's payment callback accepted payer, token and amount values directly from attacker-supplied payload… | $1.4M | Access control flaw | Decentralised exchange | Ethereum | Reported3 sources | |
| Wasabi ProtocolCompromise of the protocol's deployer account, wasabideployer.eth, a single externally owned account that held… | $4.6M–$5M | Private key compromise | Decentralised exchange | Ethereum, Base, Blast, Other | Verified4 sources | |
| Aftermath Finance (Perps)Missing lower-bound validation on the integrator ("builder code") taker fee in the perpetual futures clearing house | $1.1M | Contract logic error | Decentralised exchange | Sui | Verified5 sources | |
| Sweat EconomyA logic flaw in the SWEAT fungible token contract on NEAR let a purpose-built drainer contract sweep balances out of… | $2.5M–$3.5M | Contract logic error | Token contract | Other | Verified5 sources | |
| PurrlendCompromise of Purrlend's 2-of-3 admin multisig | $1.5M | Private key compromise | Lending protocol | Other | Verified4 sources | |
| GiddyGiddyVaultV3 authorised swaps with a backend-issued EIP-712 signature, but the signed digest covered only the data… | $1.3M | Signature verification flaw | Other | Ethereum | Verified3 sources | |
| Volo ProtocolCompromise of a high-privilege vault operator private key | $3.5M | Private key compromise | Other | Sui | Verified5 sources | |
| Kelp DAOcompromised RPC nodes feeding a 1-of-1 LayerZero DVN, which attested to a forged cross-chain message | $292M | Infrastructure compromise | Cross-chain bridge | Ethereum, Unichain, Arbitrum, Base, Multiple chains | Verified7 sources | |
| Rhea FinanceFlawed slippage protection in the margin trading feature: the check aggregated expected outputs across every step of a… | $18.4M | Contract logic error | Lending protocol | Other | Reported4 sources | |
| GrinexUnauthorised outflows of USDT from Grinex-controlled hot wallets on Tron and Ethereum beginning around 12:00 UTC on 15… | $13.1M–$15M | Private key compromise | Centralised exchange | Tron, Ethereum | Reported4 sources | |
| Hyperbridge Token GatewayThe Token Gateway's Merkle Mountain Range (MMR) proof verifier failed to check that every leaf in a submitted proof… | $237k–$2.5M | Signature verification flaw | Cross-chain bridge | Ethereum, Base, BNB Chain, Arbitrum | Verified4 sources | |
| TMM/USDT pool (BNB Chain)Flash-loaned USDT was drawn simultaneously from ListaDAO Moolah, Venus, Aave V3, PancakeSwap's vault and Uniswap's… | $1.7M | Flash loan attack | Token contract | BNB Chain | Reported3 sources | |
| Drift ProtocolMultisig signers manipulated into surrendering admin control, then oracles moved with a fake token | $285M | Social engineering | Decentralised exchange | Solana | Verified3 sources | |
| ≈ | Cyrus FinanceThe CyrusTreasury contract sized liquidity withdrawals from its managed PancakeSwap V3 positions by reading… | $520k | Oracle or price manipulation | Other | BNB Chain | Verified3 sources |
| Resolv (USR)Unauthorised control of the SERVICE_ROLE signing key that authorises USR issuance, held in a cloud key management… | $23M–$25M | Private key compromise | Stablecoin or yield protocol | Ethereum | Verified4 sources | |
| Venus Protocol Core Pool (THE market)A donation attack on the vTHE market | $2.2M–$3.7M | Contract logic error | Lending protocol | BNB Chain | Verified5 sources | |
| Solv Protocol (BRO Vault)A callback-driven double mint, described by the cited analyses as a double-accounting bug rather than classic reentrancy | $2.7M$2.7M back | Other or undisclosed | Other | Ethereum | Verified4 sources | |
| Foom.CashThe Groth16 verifier embedded in the contracts had its verifying-key parameters gamma and delta set to the same… | $1.6M–$2.3M$1.8M back | Signature verification flaw | Other | Ethereum, Base | Verified4 sources | |
| YieldBloxThe YieldBlox DAO pool, a community-managed deployment on Blend V2 on Stellar, priced USTRY collateral using the… | $10.2M–$11M | Oracle or price manipulation | Lending protocol | Other | Verified4 sources | |
| YieldBlox (Blend V2 pool)USTRY collateral was priced through the Reflector oracle, which computed a volume-weighted average from the thin… | $10.2M–$10.9M | Oracle or price manipulation | Lending protocol | Other | Verified4 sources | |
| IoTeX (ioTube bridge)A private key controlling the owner account of the ioTube Validator contract on Ethereum was used to upgrade that… | $4.3M–$8.8M | Private key compromise | Cross-chain bridge | Ethereum, Other | Verified4 sources | |
| CrossCurveThe ReceiverAxelar contract's expressExecute function was callable by any address and did not verify the supplied… | $2.8M–$3M | Access control flaw | Cross-chain bridge | Ethereum, Arbitrum, Optimism, Base, Blast, Other | Verified4 sources | |
| ≈ | Individual holder (4,556 ETH)Address poisoning | $12.3M | Phishing signature | Individual holder | Ethereum | Reported4 sources |
| Step FinanceExecutive team devices compromised, giving control of treasury and fee wallets | $27M–$40M$4.7M back | Private key compromise | Decentralised exchange | Solana | Verified5 sources | |
| Aperture FinanceArbitrary external call in the protocol's closed-source position-manager contract | $3.7M | Access control flaw | Other | Ethereum, Arbitrum, Base | Verified5 sources | |
| Matcha Meta / SwapNet router exploitAn arbitrary external call in SwapNet's router contract let an attacker supply calldata that the contract executed on… | $13.3M | Contract logic error | Decentralised exchange | Base, Ethereum | Verified3 sources | |
| Saga (SagaEVM)A helper contract fed crafted IBC messages to an EVM precompile bridge on the SagaEVM chainlet | $7M | Contract logic error | Blockchain or validator set | Other, Ethereum | Verified3 sources | |
| Makina FinanceFlash-loan-driven manipulation of an internal assets-under-management calculation | $4.1M | Oracle or price manipulation | Other | Ethereum | Verified3 sources | |
| Individual holder (bitcoin and litecoin, January 2026)An attacker impersonating hardware-wallet support persuaded the holder to disclose the wallet's recovery seed phrase… | $282M | Social engineering | Individual holder | Bitcoin, Other | Reported2 sources | |
| Truebit ProtocolInteger overflow in the getPurchasePrice function of Truebit's legacy TRU bonding-curve Purchase contract… | $26.4M | Contract logic error | Infrastructure provider | Ethereum | Verified4 sources | |
| ≈ | TMX TribeAccounting flaw in the assets-under-management calculation used to price the TLP liquidity token | $1.4M | Contract logic error | Decentralised exchange | Arbitrum | Reported2 sources |
| ≈ | Unleash ProtocolAn externally owned address obtained administrative control through the project's multisig governance and pushed an… | $3.9M | Access control flaw | Other | Other, Ethereum | Verified3 sources |
| FlowA type-confusion vulnerability in the Cadence runtime | $3.9M | Contract logic error | Blockchain or validator set | Other, Ethereum | Verified4 sources | |
| ≈ | Trust Wallet browser extensionTrust Wallet said developer secrets exposed in the November 2025 "Sha1-Hulud" npm supply-chain campaign gave an… | $7M–$8.5M | Supply chain or frontend compromise | Wallet software or provider | Multiple chains | Verified5 sources |
| ≈ | Individual holder (49,999,950 USDT address poisoning)Address poisoning | $50M | Phishing signature | Individual holder | Ethereum | Reported4 sources |
| Ribbon Finance DeFi Option Vaults (Aevo)An upgrade to the Opyn/Ribbon oracle stack deployed on 6 December 2025 left the price-setting path for newly added… | $2.7M | Oracle or price manipulation | Other | Ethereum | Verified3 sources | |
| ≈ | Rari Capital (Fuse pools, December 2025)Undisclosed | $2M | Other or undisclosed | Lending protocol | Ethereum | Reported3 sources |
| US Permissionless Dollar (USPD)CPIMP ("clandestine proxy in the middle of proxy") | $1M–$1.1M | Access control flaw | Stablecoin or yield protocol | Ethereum | Verified12 sources | |
| Yearn Finance (yETH pool)Imbalanced add_liquidity deposits drove the yETH weighted-stableswap pool's iterative fixed-point solver into a… | $9M$2.4M back | Contract logic error | Other | Ethereum | Verified3 sources | |
| UpbitUnauthorised transfers from a Solana hot wallet, reportedly via hijacked or impersonated administrator credentials | $30M–$37M | Access control flaw | Centralised exchange | Solana | Verified4 sources | |
| GANA PaymentThe attacker obtained owner-level control of GANA Payment's staking contract on BNB Chain | $3.1M | Private key compromise | Token contract | BNB Chain, Ethereum | Verified3 sources | |
| MoonwellThe wrsETH/ETH price feed malfunctioned rather than being manipulated by the attacker, returning 1 wrsETH =… | $1M–$3.7M | Oracle or price manipulation | Lending protocol | Base | Verified4 sources | |
| Balancer V2Rounding truncation in scaled EXACT_OUT swaps suppressed the stable-pool invariant | $94.8M–$129M$45.7M back | Contract logic error | Decentralised exchange | Ethereum, Arbitrum, Base, Optimism, Polygon, Other | Verified6 sources | |
| GardenAn attacker obtained the SSH key of an independent solver operator running infrastructure for Garden's cross-chain swap… | $10.8M–$11.4M | Private key compromise | Cross-chain bridge | Multiple chains | Verified4 sources | |
| Typus FinanceThe update_v2 function of Typus's in-house oracle module lacked an authorisation check, so any address could write an… | $3.3M–$3.4M | Access control flaw | Decentralised exchange | Sui | Verified4 sources | |
| Abracadabra.money (October 2025)A solvency-check bypass in CauldronV4's cook() batching entry point | $1.7M–$1.8M | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| Hypervault FinanceVaults holding depositor assets were emptied and the proceeds bridged off Hyperliquid's HyperEVM to Ethereum, swapped… | $3.6M | Rug pull or exit scam | Other | Other | Reported3 sources | |
| ≈ | GriffinAIGAIN was a LayerZero omnichain token | $2.5M–$4M | Private key compromise | Token contract | Ethereum, BNB Chain | Verified4 sources |
| SBI CryptoAssets moved out of hot addresses controlled by SBI Crypto across five networks in a single day | $16.9M–$21M | Other or undisclosed | Mining or staking operation | Bitcoin, Ethereum, Other | Verified5 sources | |
| SeedifyA compromised developer key held owner rights over Seedify's LayerZero OFT bridge contract on Avalanche | $1.2M–$1.7M | Private key compromise | Cross-chain bridge | Avalanche, BNB Chain, Ethereum, Arbitrum, Base | Verified5 sources | |
| UXLINKA delegateCall executed in the context of UXLINK's multi-signature wallet removed the existing signers and installed… | $11.3M–$41M | Access control flaw | Token contract | Ethereum, Arbitrum | Verified5 sources | |
| ≈ | Kame AggregatorThe AggregationRouter's swap() function executed an arbitrary call to a caller-supplied executor address with… | $1M–$1.3M | Access control flaw | Decentralised exchange | Other | Verified4 sources |
| Shibarium BridgeSigning power for 10 of Shibarium's 12 validators was compromised | $2.4M–$4.1M | Private key compromise | Cross-chain bridge | Ethereum, Other | Verified4 sources | |
| SwissBorgstolen GitHub token let attackers inject a payload into staking provider Kiln's Connect API that rewrote Solana stake… | $41M | Supply chain or frontend compromise | Centralised exchange | Solana | Verified4 sources | |
| ≈ | Nemo ProtocolTwo defects in code deployed after the protocol's audit | $2.4M–$2.6M | Contract logic error | Other | Sui, Ethereum | Verified4 sources |
| Bunni V2Rounding-direction bug in BunniHubLogic::withdraw | $8.4M | Contract logic error | Decentralised exchange | Ethereum, Other | Verified5 sources | |
| OlaXBTUndisclosed | $2M | Other or undisclosed | Token contract | BNB Chain | Verified4 sources | |
| Sinqia (Evertec)Attackers used the credentials of legitimate Sinqia IT vendors to inject unauthorised business-to-business Pix… | $130M$108M back | Supply chain or frontend compromise | Infrastructure provider | Off-chain systems | Verified4 sources | |
| ≈ | BetterBankUnbounded reward minting | $4.1M–$5M$2.7M back | Contract logic error | Decentralised exchange | Other | Verified4 sources |
| BtcTurkunauthorised outflows from hot wallets on seven chains; root cause never disclosed by the exchange | $48M | Private key compromise | Centralised exchange | Ethereum, Avalanche, Arbitrum, Base, Optimism, Polygon, Other | Reported3 sources | |
| ≈ | Odin.funA flaw introduced in an update to the platform's internal automated market maker let an attacker seed pools with… | $7M | Contract logic error | Decentralised exchange | Bitcoin, Other | Verified4 sources |
| CrediX FinanceAn externally funded address was added as a signer on CrediX's multisig six days before the incident and was then… | $4.5M | Access control flaw | Lending protocol | Other, Ethereum | Reported4 sources | |
| WOO XWOO X's post-mortem describes a three-stage intrusion | $14M | Social engineering | Centralised exchange | Bitcoin, Ethereum, BNB Chain, Arbitrum | Verified3 sources | |
| ≈ | CoinDCXserver breach reaching an internal liquidity-provisioning account held at a partner exchange; mechanism never disclosed | $44.2M | Infrastructure compromise | Centralised exchange | Solana, Ethereum | Verified4 sources |
| BigONECompromise of the exchange's backend build and deployment infrastructure | $27M | Supply chain or frontend compromise | Centralised exchange | Bitcoin, Ethereum, Tron, Solana, BNB Chain | Verified3 sources | |
| Arcadia FinanceThe RebalancerSpot contract passed a user-supplied swapData parameter, including the address of the router that would… | $3.5M | Contract logic error | Lending protocol | Base, Ethereum | Verified4 sources | |
| KintoCPIMP ('Clandestine Proxy In the Middle of Proxy') | $1.6M | Access control flaw | Token contract | Arbitrum | Verified5 sources | |
| TextureThe vault rebalance path did not verify ownership of every account passed to it | $2.2M$2M back | Access control flaw | Lending protocol | Solana | Verified3 sources | |
| GMX V1re-entrancy through the ETH execution-fee refund in PositionManager.executeDecreaseOrder, which handed control to an… | $42M$37M back | Reentrancy | Decentralised exchange | Arbitrum | Verified4 sources | |
| C&M SoftwareAn IT employee of C&M Software, the technology provider that connects smaller Brazilian institutions to the central… | $100M–$140M$49M back | Insider action | Infrastructure provider | Off-chain systems | Verified4 sources | |
| ResupplyDonation-based share-price inflation against an empty CurveLend vault, which then triggered an integer-division… | $9.3M–$10M | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| Nobitexattackers reached internal infrastructure and hot wallet signing keys, then swept the hot wallets to unspendable vanity… | $81.7M–$90M | Private key compromise | Centralised exchange | Multiple chains, Ethereum, Tron, Bitcoin, Solana, TON | Verified6 sources | |
| ALEX ProtocolFlaw in ALEX's self-listing verification logic on Stacks | $8.4M–$16.2M | Access control flaw | Decentralised exchange | Other | Verified4 sources | |
| Force BridgeThe attacker reached privileged functions in the bridge's contracts and used them to unlock and release wrapped assets… | $3.8M | Access control flaw | Cross-chain bridge | Ethereum, BNB Chain | Verified5 sources | |
| Cork ProtocolMalicious Uniswap v4 hook spoofed callback data to bypass authorization in Cork's hook and FlashSwapRouter, combined… | $12M–$14.5M | Access control flaw | Other | Ethereum | Verified3 sources | |
| Cetus ProtocolOverflow in the checked_shlw helper of the integer-mate maths library | $223M–$260M$162M back | Contract logic error | Decentralised exchange | Sui, Ethereum | Verified3 sources | |
| Mobius Token (MBU)Decimal-scaling error in the unverified implementation contract behind the MBU deposit proxy on BNB Chain | $2.2M | Contract logic error | Token contract | BNB Chain | Verified3 sources | |
| LNDA developer with control of the protocol's deployment address published modified AToken and VariableDebtToken contracts… | $1.2M–$1.4M | Insider action | Lending protocol | Other | Verified3 sources | |
| BitoProAttackers used social engineering to plant malware on the device of a BitoPro employee who managed the exchange's cloud… | $11.5M | Social engineering | Centralised exchange | Ethereum, Tron, Solana, Polygon | Verified4 sources | |
| ≈ | Coinbase customer social-engineering theft wave (May 2025)Impersonation of exchange support | $45M | Social engineering | Individual holder | Multiple chains | Reported4 sources |
| Individual holder (3,520 BTC)Impersonation of support staff using spoofed websites and telephone calls, used to get an elderly self-custody holder… | $331M | Social engineering | Individual holder | Bitcoin | Reported3 sources | |
| LoopscaleLoopscale accepted RateX principal tokens as collateral but validated the RateX program only partially | $5.8M$5.8M back | Oracle or price manipulation | Lending protocol | Solana | Verified3 sources | |
| KiloExKiloEx's TrustedForwarder contract inherited OpenZeppelin's MinimalForwarderUpgradeable but did not override the… | $7M–$7.5M$6.8M back | Access control flaw | Decentralised exchange | Base, BNB Chain, Other | Verified4 sources | |
| ZKsyncAn attacker in possession of the private key to a 1/1 multisig admin address… | $5M | Private key compromise | Blockchain or validator set | Other, Ethereum | Verified3 sources | |
| Abracadabra Money GM cauldronsA collateral-accounting flaw in the GmxV2CauldronV4 contract | $13.4M | Contract logic error | Lending protocol | Arbitrum, Ethereum | Verified5 sources | |
| ZothThe private key controlling Zoth's deployer address, which held admin rights over the protocol's proxy contracts, was… | $8.4M–$8.9M | Private key compromise | Stablecoin or yield protocol | Ethereum | Verified4 sources | |
| 1inch Fusion v1 Resolver (TrustedVolumes)An integer underflow in the deprecated Fusion v1 Settlement contract's _settleOrder() routine | $5M | Contract logic error | Decentralised exchange | Ethereum | Verified4 sources | |
| Infinian administrative role over the vault, granted when the contract was set up and never revoked, was used to withdraw | $49.5M | Access control flaw | Custodian or payment processor | Ethereum | Verified3 sources | |
| BybitCompromised Safe{Wallet} infrastructure served a malicious signing interface | $1.4B–$1.5B | Supply chain or frontend compromise | Centralised exchange | Ethereum | Verified3 sources | |
| zkLendThree weaknesses combined in a newly launched wstETH market on Starknet: an empty pool let the first deposit set the… | $9.5M–$10M | Contract logic error | Lending protocol | Other | Verified3 sources | |
| ≈ | Ionic MoneyAttackers impersonated the Lombard Finance team and persuaded Ionic Money to list a counterfeit LBTC token contract… | $6.9M–$8.8M | Social engineering | Lending protocol | Other, Ethereum | Verified6 sources |
| Sirio FinanceThree sequential attacks used flash loans of HBAR borrowed from Bonzo Finance to defeat Sirio's collateral… | $2M–$3M | Flash loan attack | Lending protocol | Other | Reported2 sources | |
| ≈ | DogWifToolsAccording to the developers, an attacker reverse-engineered the DogWifTools desktop software to extract a GitHub token… | $10M | Supply chain or frontend compromise | Other | Solana, Multiple chains | Reported3 sources |
| Phemexhot wallet signing keys compromised across roughly fourteen chains | $69M–$85M | Private key compromise | Centralised exchange | Multiple chains, Ethereum, Solana, Bitcoin | Verified5 sources | |
| Ledger co-founder kidnapping ransom (France)Armed home invasion and kidnap-for-ransom | $3M$3M back | Other or undisclosed | Individual holder | Ethereum, Solana | Reported5 sources | |
| MobyA private key with proxy-admin rights over Moby's vault contracts was compromised | $2.5M$1.5M back | Private key compromise | Decentralised exchange | Arbitrum | Verified4 sources | |
| ≈ | Coinbase support-contractor data breach and downstream theftsCriminals paid overseas outsourced customer-support agents to copy customer records out of Coinbase's internal support… | $180M–$400M | Insider action | Centralised exchange | Multiple chains | Verified4 sources |
| ≈ | GemPadReentrancy in the collectFees function of GemPad's shared token/LP locker template | $1.9M–$2.1M | Reentrancy | Infrastructure provider | Ethereum, BNB Chain, Base | Verified3 sources |
| XT.comUnauthorised outflow from the exchange's hot wallets across several chains | $1.7M | Private key compromise | Centralised exchange | Ethereum, Polygon, Optimism | Verified4 sources | |
| ≈ | Polter FinancePolter priced the BOO token through a ChainlinkUniV2Adapter contract that derived value from the reserve ratio of a… | $7M–$12M | Oracle or price manipulation | Lending protocol | Fantom | Verified4 sources |
| DEXXDEXX generated and custodied users' wallet private keys on its own infrastructure | $21M–$30M | Private key compromise | Wallet software or provider | Solana, Ethereum, BNB Chain, Base | Verified4 sources | |
| Thala (ThalaSwap)Missing bounds check in an unstake_max function added to Thala's v1 boosted farming contracts by a two-line patch… | $25.5M$25.2M back | Contract logic error | Decentralised exchange | Aptos | Verified4 sources | |
| DeltaPrime (November 2024)Missing input validation in DeltaPrime's Prime Account logic | $4.8M | Contract logic error | Lending protocol | Avalanche, Arbitrum | Verified3 sources | |
| M2 ExchangeSimultaneous draining of hot wallets on Bitcoin, Ethereum and Solana | $13.7M | Other or undisclosed | Centralised exchange | Bitcoin, Ethereum, Solana | Verified4 sources | |
| ≈ | Sunray FinanceA compromised owner key was used to upgrade the project's administrative contract in a single transaction to a version… | $2.7M–$2.9M | Private key compromise | Decentralised exchange | Arbitrum | Verified3 sources |
| Tapioca DAOA core contributor with admin roles on live contracts was approached on LinkedIn and Telegram by an attacker using a… | $4.4M–$4.8M$2.7M back | Social engineering | Lending protocol | Arbitrum, Ethereum | Verified4 sources | |
| Radiant Capitalmalware substituted transferOwnership payloads in the Safe multisig UI; 3 of 11 signers blind-signed | $50M–$53M | Social engineering | Lending protocol | Arbitrum, BNB Chain | Verified4 sources | |
| ≈ | Individual holder (15,079 fwDETH on Blast)Off-chain EIP-2612 'permit' signature obtained through a drainer phishing page | $35M | Phishing signature | Individual holder | Blast | Reported4 sources |
| ≈ | Individual holder (12,083 spWETH)Permit-signature phishing delivered through a spoofed DeFi front-end | $32.4M | Phishing signature | Individual holder | Ethereum | Verified3 sources |
| Bedrock (uniBTC)One path of uniBTC's minting logic omitted the exchange-rate conversion between ether and bitcoin, so depositing ETH… | $1.7M–$2M | Contract logic error | Other | Ethereum | Verified4 sources | |
| Onyx ProtocolCompound v2 fork rounding behaviour in a near-empty VUSD market allowed the exchange rate to be distorted with small… | $3.8M | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| TruflationMalware planted on a team machine harvested the private keys to Truflation's treasury multisignature wallet and to… | $4.6M–$5.3M | Private key compromise | Infrastructure provider | Ethereum | Verified4 sources | |
| ShezmuA Shezmu vault contract exposed an unprotected mint function, letting any caller mint the ShezUSD stablecoin without… | $4.9M | Access control flaw | Lending protocol | Ethereum | Verified3 sources | |
| BingXunauthorised intrusion into a hot wallet; BingX has never disclosed how signing keys or systems were reached | $43M–$52M | Private key compromise | Centralised exchange | Ethereum, BNB Chain, Polygon | Verified5 sources | |
| Banana GunBanana Gun attributed the breach to a vulnerability in the third-party Telegram message oracle its bot relied on to… | $1.4M–$3M | Infrastructure compromise | Wallet software or provider | Ethereum, Solana | Verified3 sources | |
| DeltaPrimeThe private key of an externally owned account that still held proxy-admin rights over DeltaPrime's DepositIndex… | $6M | Private key compromise | Lending protocol | Arbitrum | Verified4 sources | |
| ≈ | IndodaxUnexplained drain of Indodax hot wallets across at least five chains (Ethereum, Bitcoin, Tron, Polygon and Optimism)… | $20.5M–$25.5M | Private key compromise | Centralised exchange | Ethereum, Bitcoin, Tron, Polygon, Optimism | Verified5 sources |
| PenpieMissing reentrancy guard on PendleStakingBaseUpg::batchHarvestMarketRewards(), combined with a registration helper that… | $27.3M | Reentrancy | Other | Ethereum, Arbitrum | Verified3 sources | |
| ≈ | Individual holder (55.47M DAI, Maker vault)The holder signed a phishing transaction that transferred ownership of the DSProxy smart contract controlling their… | $55.5M | Phishing signature | Individual holder | Ethereum | Verified2 sources |
| Individual Genesis creditor (4,064 BTC)Staged voice-phishing chain | $230M–$244M$70M back | Social engineering | Individual holder | Bitcoin | Verified4 sources | |
| NexeraMalware executed on an employee's machine harvested the credentials used to administer Nexera's smart contracts | $449k–$1.8M$1.2M back | Private key compromise | Token contract | Ethereum, Avalanche | Verified4 sources | |
| ≈ | Terra 2.0A reentrancy condition in the timeout callback of IBC hooks, a third-party Cosmos module that lets incoming ICS-20… | $4M–$5M | Reentrancy | Blockchain or validator set | Other | Verified4 sources |
| ≈ | MonoSwapAttackers posing as venture capital investors persuaded a MonoSwap developer to install an application in order to join… | $1M–$1.3M | Private key compromise | Decentralised exchange | Blast | Verified5 sources |
| DeltaPrimeTwo initialisation paths in the DiamondBeaconProxy architecture each read the _initialized flag from a different… | $1M$900k back | Access control flaw | Lending protocol | Arbitrum | Verified3 sources | |
| Rho MarketsOracle misconfiguration rather than active manipulation | $7.6M$7.6M back | Oracle or price manipulation | Lending protocol | Other | Verified4 sources | |
| WazirXSigners approved a malicious contract upgrade shown differently by the custody interface | $235M | Social engineering | Centralised exchange | Ethereum | Verified3 sources | |
| LI.FIA newly deployed facet of LI.FI's diamond-pattern contract, GasZipFacet, lacked the whitelist validation applied to… | $8M–$11.6M | Access control flaw | Cross-chain bridge | Ethereum, Arbitrum | Verified4 sources | |
| MinterestReentrancy into lendRUSDY combined with an exchange rate that updated immediately after a borrow | $1.4M | Reentrancy | Lending protocol | Other | Verified3 sources | |
| Dough FinanceUnvalidated calldata in the ConnectorDeleverageParaswap contract | $1.8M–$2.5M | Contract logic error | Lending protocol | Ethereum | Verified3 sources | |
| BittensorA malicious version 6.12.2 of the official Bittensor Python package was published to PyPI | $8M | Supply chain or frontend compromise | Blockchain or validator set | Other | Verified4 sources | |
| CoinStatsCoinStats says an attacker obtained unauthorised access to parts of its infrastructure and to third-party providers… | $2.2M | Private key compromise | Wallet software or provider | Multiple chains | Verified3 sources | |
| BtcTurkhot wallet keys compromised; balances of ten listed assets withdrawn | $54.2M–$100M | Private key compromise | Centralised exchange | Multiple chains, Avalanche, Bitcoin | Reported6 sources | |
| UwU Lend (second exploit)After the 10 June oracle attack the protocol was patched and unpaused, but according to CertiK it continued to treat… | $3.5M–$3.7M | Contract logic error | Lending protocol | Ethereum | Verified4 sources | |
| HolographA former technical contractor retained unauthorised administrative rights over Holograph Protocol v1 contracts and used… | $6.4M–$14.4M | Insider action | Token contract | Ethereum | Verified4 sources | |
| YOLO Games (Bazaar LBP)The Bazaar LBP contract's exitPool() function accepted a caller-supplied 'sender' argument without verifying the caller… | $1.4M–$1.5M$1.3M back | Access control flaw | Gaming or metaverse | Blast | Reported2 sources | |
| LoopringAttackers compromised the AWS-hosted servers running Loopring's centralised two-factor authentication service, using… | $5M | Infrastructure compromise | Wallet software or provider | Ethereum | Verified4 sources | |
| VelocoreMissing caller validation on the ConstantProductPool contract's velocore__execute() function let anyone invoke it… | $6.8M–$7.6M | Contract logic error | Decentralised exchange | Multiple chains | Verified4 sources | |
| ≈ | DMM BitcoinFake recruiter compromised an employee at wallet vendor Ginco, then altered a transaction request | $308M | Social engineering | Centralised exchange | Bitcoin | Verified3 sources |
| Gala GamesAn attacker gained control of a privileged account holding the minting role on the GALA ERC-20 token contract | $22.2M$22.2M back | Private key compromise | Gaming or metaverse | Ethereum | Verified4 sources | |
| pump.funA former developer retained the platform's bonding-curve 'withdraw authority' credentials after leaving, then used… | $1.9M–$2M | Insider action | Other | Solana | Verified4 sources | |
| ≈ | ALEX Lab (XLink bridge)A private key controlling ALEX Lab's XLink bridge was compromised — CertiK attributed the compromise to a phishing… | $4.3M–$27.4M | Private key compromise | Cross-chain bridge | BNB Chain, Ethereum, Other | Verified6 sources |
| GNUS.ai (Genius AI)The team's deployment key (address beginning 0x18) was compromised | $1.3M | Private key compromise | Token contract | Fantom, Ethereum | Verified3 sources | |
| Individual holder (1,155 WBTC)Address poisoning, also called a dusting attack | $68M$65.7M back | Phishing signature | Individual holder | Ethereum | Verified2 sources | |
| Pike Finance V1Storage-layout collision introduced by an emergency upgrade | $1.7M | Access control flaw | Lending protocol | Ethereum, Arbitrum, Optimism | Verified6 sources | |
| RainAccording to a U.S | $14.8M–$16M$760k back | Social engineering | Centralised exchange | Bitcoin, Ethereum, Solana, Other | Verified5 sources | |
| XBridge (SaitaChain)The bridge contract's listToken function performed no owner or caller check, so where the base token matched the… | $1.2M–$1.4M | Access control flaw | Cross-chain bridge | Ethereum, BNB Chain | Reported3 sources | |
| Hedgey FinanceERC-20 allowance granted on campaign creation was never revoked on cancellation, and the lockup address parameter was… | $2M–$45M | Contract logic error | Other | Ethereum, Arbitrum, Fantom, Polygon, BNB Chain, Other | Verified4 sources | |
| Grand BaseControl of the project's deployer wallet was used to mint GB tokens without limit - one transaction alone created 22.5… | $1.7M–$2.5M | Private key compromise | Other | Base | Verified4 sources | |
| ≈ | SolareumUS prosecutors allege a developer hired onto the Solareum team in December 2023, working covertly for North Korea, used… | $523k–$1.4M | Insider action | Wallet software or provider | Solana | Verified3 sources |
| Prisma FinanceUnvalidated onFlashloan callback in the MigrateTroveZap helper contract let anyone act on troves that had granted it… | $11M–$12M | Access control flaw | Lending protocol | Ethereum | Verified3 sources | |
| Munchablesa developer pre-wrote a fabricated 1,000,000 ETH deposit balance into proxy storage before an implementation upgrade… | $62.5M$62.5M back | Insider action | Gaming or metaverse | Blast | Verified3 sources | |
| Curio DAOA voting-power privilege check in Curio's MakerDAO-derived governance contracts could be satisfied with a trivially… | $178k–$16M | Access control flaw | DAO or treasury | Ethereum, BNB Chain | Verified3 sources | |
| Super Sushi SamuraiThe SSS token contract's transfer function read the sender's balance and then wrote both the debited sender balance and… | $4.6M | Contract logic error | Gaming or metaverse | Blast | Verified4 sources | |
| Dolomite (legacy Ethereum contract)The decommissioned 2019 Ethereum product settled trades through Loopring ring-matching contracts, with user approvals… | $1.8M$1.6M back | Signature verification flaw | Decentralised exchange | Ethereum | Verified3 sources | |
| UnizenA gas-optimisation upgrade to the proxy behind Unizen's DEX-aggregation contract on Ethereum introduced an external… | $2.1M | Access control flaw | Decentralised exchange | Ethereum | Verified4 sources | |
| WOOFi SwapFlash-loan-driven manipulation of WOOFi's synthetic proactive market making (sPMM) pricing algorithm on Arbitrum | $8.8M | Oracle or price manipulation | Decentralised exchange | Arbitrum | Verified4 sources | |
| ShidoOwnership of the Ethereum StakingV4Proxy contract was transferred to an attacker-controlled address, which then… | $3.3M–$35M | Private key compromise | Token contract | Ethereum | Reported5 sources | |
| Seneca ProtocolThe Chamber contract's public performOperations() function accepted an action code plus arbitrary calldata and a target… | $6.4M$5.3M back | Access control flaw | Lending protocol | Ethereum, Arbitrum | Verified6 sources | |
| Blueberry ProtocolFaulty oracle deployment rather than a flaw in the lending logic | $1.3M$1M back | Contract logic error | Lending protocol | Ethereum | Verified3 sources | |
| ≈ | FixedFloatExternal compromise of FixedFloat's server infrastructure, leading to the draining of the service's own hot wallets on… | $26.1M | Infrastructure compromise | Other | Bitcoin, Ethereum | Verified4 sources |
| ≈ | DuelbitsUnauthorised outbound transfers from Duelbits' own hot wallets on Ethereum and BNB Chain | $4.6M | Private key compromise | Gaming or metaverse | Ethereum, BNB Chain | Reported3 sources |
| Abracadabra.money (Cauldrons)An accounting inconsistency in the Cauldron borrow logic | $6.5M | Contract logic error | Lending protocol | Ethereum | Verified3 sources | |
| ConcentricA targeted social engineering attack on a team member yielded the private key to a deployer/admin wallet | $1.6M–$1.9M | Social engineering | Other | Arbitrum | Verified4 sources | |
| Socket / BungeeA recently added route on the SocketGateway router exposed a performAction() function that passed user-supplied… | $3.3M$2.3M back | Contract logic error | Cross-chain bridge | Multiple chains | Verified5 sources | |
| MangoFarmSOLOperators withdrew all SOL held in the farming contract on behalf of depositors, then served a malicious frontend… | $1.3M–$2M | Rug pull or exit scam | Other | Solana | Verified3 sources | |
| Gamma StrategiesAn arithmetic error in Gamma's automation scripts set the deposit price-deviation guard to a window of -50%/+100%… | $3.4M–$6.2M | Oracle or price manipulation | Other | Arbitrum | Verified3 sources | |
| Radiant Capital (Arbitrum USDC market)Radiant activated a new native USDC market on Arbitrum with empty reserves | $4.5M–$4.8M | Contract logic error | Lending protocol | Arbitrum | Verified3 sources | |
| Orbit Bridgeunexplained compromise of bridge operator systems | $81.5M | Infrastructure compromise | Cross-chain bridge | Ethereum | Verified6 sources | |
| ≈ | Levana ProtocolPyth price feeds were accepted with up to 120 seconds of staleness | $1.1M | Oracle or price manipulation | Decentralised exchange | Other | Verified3 sources |
| OKX DEX aggregatorThe private key of the proxy admin owner of an OKX DEX contract was compromised | $370k–$2.8M | Private key compromise | Decentralised exchange | Ethereum | Verified3 sources | |
| ≈ | Florence FinanceAddress poisoning | $1.5M | Phishing signature | Lending protocol | Ethereum | Reported3 sources |
| ≈ | Inferno Drainer phishing-as-a-service campaignDrainer-as-a-service kit rented to affiliates | $70M–$81M | Phishing signature | Other | Multiple chains | Verified4 sources |
| HTX (Huobi) hot wallet exploitCompromise of HTX exchange hot wallets | $13.6M–$30M | Private key compromise | Centralised exchange | Ethereum | Verified5 sources | |
| HTX and Heco BridgeThe operator key for the Heco Bridge, which links Ethereum to the Heco chain, was compromised, letting the attacker… | $113M | Private key compromise | Cross-chain bridge | Ethereum, Tron, Bitcoin | Verified3 sources | |
| KyberSwap Elasticrounding error in concentrated-liquidity tick accounting caused liquidity to be double-counted during a… | $47M–$56.2M$5.7M back | Contract logic error | Decentralised exchange | Ethereum, Arbitrum, Optimism, Polygon, Base, Avalanche | Verified4 sources | |
| Heco Bridgethe bridge operator account's keys were compromised, letting the attacker sign withdrawals directly against the… | $86.6M | Private key compromise | Cross-chain bridge | Ethereum, Other | Verified5 sources | |
| dYdX v3Coordinated spot buying across exchanges pushed the index price used by dYdX v3 perpetual markets, inflating 5x… | $9M | Oracle or price manipulation | Decentralised exchange | Ethereum | Verified4 sources | |
| Kronos ResearchCompromise of Kronos Research's exchange API keys, which are trading credentials held at centralised venues rather than… | $26M | Infrastructure compromise | Other | Ethereum, BNB Chain | Verified3 sources | |
| RaftA precision/rounding error in the share-minting path of the InterestRatePositionManager | $3.3M–$3.6M | Contract logic error | Stablecoin or yield protocol | Ethereum | Verified3 sources | |
| PoloniexHot wallet private keys compromised; method never disclosed | $100M–$126M | Private key compromise | Centralised exchange | Ethereum, Tron, Bitcoin | Reported3 sources | |
| ≈ | CoinSpotTwo CoinSpot hot wallets made outbound transfers of 1,262 ETH and 20.99 ETH to an address with no prior relationship to… | $2M–$2.4M | Private key compromise | Centralised exchange | Ethereum, Bitcoin | Reported4 sources |
| Onyx ProtocolPrecision-loss and rounding bug inherited from the Compound V2 codebase, combined with a newly deployed oPEPE market… | $2.1M | Contract logic error | Lending protocol | Ethereum | Reported4 sources | |
| Platypus Finance (October 2023)Three flash-loan-funded transactions, sent from two externally owned addresses, manipulated the pricing math of the… | $2.2M$575k back | Flash loan attack | Decentralised exchange | Avalanche | Verified4 sources | |
| Stars ArenaThe attacker deposited 1 AVAX | $2.9M | Reentrancy | Other | Avalanche | Verified3 sources | |
| ≈ | Social Engineering Enterprise cryptocurrency theftsA division-of-labour criminal enterprise: members hacked or bought databases of cryptocurrency users, cold-called… | $230M–$263M | Social engineering | Individual holder | Bitcoin, Multiple chains | Verified3 sources |
| HTXThe private key to one of HTX's Ethereum hot wallets was compromised and used to move the balance out in a single… | $8M$8M back | Private key compromise | Centralised exchange | Ethereum | Verified4 sources | |
| Mixin NetworkCloud database provider compromised, exposing the network's hot wallets | $142M–$200M | Infrastructure compromise | Infrastructure provider | Multiple chains | Verified3 sources | |
| RemitanoCompromise of the exchange's Ethereum hot wallet keys, used to make unauthorised withdrawals to a freshly created… | $2.7M$1.4M back | Private key compromise | Centralised exchange | Ethereum | Verified4 sources | |
| CoinExhot wallet private key leaked, enabling withdrawals across many chains | $54M–$80M | Private key compromise | Centralised exchange | Multiple chains, Ethereum, Tron, Bitcoin, Solana | Verified5 sources | |
| Individual holder (9,579 stETH and 4,851 rETH)Approval phishing | $24.1M | Phishing signature | Individual holder | Ethereum | Verified3 sources | |
| Stake.comhot wallet compromise, described in reporting as a leaked or stolen private key; never confirmed by Stake or the FBI | $41.3M | Private key compromise | Gaming or metaverse | Ethereum, BNB Chain, Polygon | Verified3 sources | |
| Magnate FinanceWhoever held the protocol's administrative keys manually altered the price oracle the lending markets relied on… | $6.4M | Rug pull or exit scam | Lending protocol | Base | Verified2 sources | |
| Exactly ProtocolThe DebtManager periphery contract validated the permit argument rather than the market argument, and because the… | $7.2M–$7.6M | Reentrancy | Lending protocol | Optimism | Verified4 sources | |
| Zunami ProtocolThe protocol valued collateral by reading spot prices from external DEX pools rather than a manipulation-resistant… | $2.2M | Oracle or price manipulation | Stablecoin or yield protocol | Ethereum | Verified3 sources | |
| Cypher ProtocolBugs in the isolated-margin sub-account mechanism: switching an account to an isolated state was not tracked by the… | $1M–$1.9M$600k back | Contract logic error | Decentralised exchange | Solana | Verified6 sources | |
| SteadefiThe private key to Steadefi's deployer wallet, which owned every contract the project had deployed, was compromised | $1.1M | Private key compromise | Lending protocol | Arbitrum, Avalanche | Verified3 sources | |
| Curve FinanceVyper 0.2.15–0.3.0 compiled broken reentrancy guards into affected pools | $52M–$73M | Reentrancy | Decentralised exchange | Ethereum | Verified3 sources | |
| ≈ | Kannagi FinanceYield-aggregator vault contracts holding user deposits were emptied and the project's website, social accounts and code… | $2.1M | Rug pull or exit scam | Other | Other | Reported4 sources |
| EraLendRead-only reentrancy against a SyncSwap liquidity pair used as EraLend's price source: the pair makes an external… | $2.7M–$3.4M | Reentrancy | Lending protocol | Other | Verified3 sources | |
| CoinsPaidFake recruiter job test installed malware, giving access to withdrawal infrastructure | $37.3M | Social engineering | Custodian or payment processor | Tron, Bitcoin, Ethereum | Verified6 sources | |
| ≈ | AlphaPohot wallets drained by unauthorised transfers; the compromise method has never been published | $60M–$100M | Other or undisclosed | Custodian or payment processor | Ethereum, Tron, Bitcoin | Verified5 sources |
| Conic FinanceRead-only reentrancy against the ETH Omnipool | $3.2M$150k back | Reentrancy | Other | Ethereum | Verified5 sources | |
| MultichainUnauthorised access to MPC node servers held on the detained CEO's personal cloud account | $125M | Private key compromise | Cross-chain bridge | Ethereum, Fantom, Other | Verified3 sources | |
| Poly Network (2023)Poly Network's cross-chain bridge relied on a 3-of-4 multisignature scheme held by four externally owned accounts that… | $5.5M–$10.1M | Private key compromise | Cross-chain bridge | Multiple chains, Ethereum, BNB Chain, Polygon | Verified4 sources | |
| Atomic WalletRoot cause never publicly disclosed; user keys compromised at scale | $35M–$100M | Other or undisclosed | Wallet software or provider | Multiple chains | Verified3 sources | |
| Jimbos ProtocolThe attacker used a flash loan to buy JIMBO and push its price up inside the protocol's Trader Joe Liquidity Book pool… | $7.5M | Flash loan attack | Token contract | Arbitrum | Verified4 sources | |
| SwaprumThe deployer account upgraded the protocol's MasterChef-style staking proxy to an unaudited implementation in which the… | $3M | Rug pull or exit scam | Decentralised exchange | Arbitrum | Verified3 sources | |
| DEUS Finance (DEI stablecoin)The DEI stablecoin contract's publicly callable burnFrom() function read the allowance mapping with its arguments… | $6M–$6.5M | Contract logic error | Stablecoin or yield protocol | Arbitrum, BNB Chain, Ethereum | Verified5 sources | |
| Level FinanceThe claimMultiple() function of LevelReferralControllerV2 did not check whether a reward epoch had already been… | $1M–$1.1M | Contract logic error | Decentralised exchange | BNB Chain | Verified4 sources | |
| 0VIX ProtocolFlash-loan funded manipulation of the vGHST price oracle | $2M–$4.3M | Oracle or price manipulation | Lending protocol | Polygon | Verified4 sources | |
| Merlin DEXThe pair contracts' initialize function granted the deployment-controlled "feeTo" address an unlimited allowance over… | $1.8M–$2M$160k back | Rug pull or exit scam | Decentralised exchange | Other | Verified6 sources | |
| Hundred FinanceTwo flaws in forked Compound code were combined: an unused hWBTC market was reduced to a residual supply and then… | $7.4M | Contract logic error | Lending protocol | Optimism, Ethereum | Verified4 sources | |
| BitrueOne of Bitrue's hot wallets was drained of six ERC-20 assets in a single incident | $23M | Other or undisclosed | Centralised exchange | Ethereum | Verified4 sources | |
| Yearn Finance (yUSDT)Legacy iEarn yUSDT vault was deployed referencing Fulcrum's iUSDC token instead of iUSDT, breaking share-price… | $10M–$11.6M | Contract logic error | Other | Ethereum | Verified4 sources | |
| SushiSwapThe newly deployed RouteProcessor2 router accepted route parameters from the caller without adequate validation, so an… | $3.3M | Contract logic error | Decentralised exchange | Multiple chains | Verified3 sources | |
| GDACAssets moved directly out of GDAC-controlled hot wallets to attacker addresses, beginning with a 0.5 ETH test transfer… | $13M | Private key compromise | Centralised exchange | Bitcoin, Ethereum, Other | Verified3 sources | |
| SentimentRead-only reentrancy against Balancer's Vault: exitPool transferred tokens out before finishing its accounting update… | $1M–$1.1M$873k back | Reentrancy | Lending protocol | Arbitrum | Verified3 sources | |
| SafeMoonA contract upgrade deployed the previous day added a burn() function for bridging but left it public and unguarded… | $8.9M$7.2M back | Access control flaw | Token contract | BNB Chain | Verified4 sources | |
| Kokomo FinanceProject deployer swapped the upgradeable cBTC market implementation for a malicious contract it had deployed shortly… | $4M–$5.5M | Rug pull or exit scam | Lending protocol | Optimism | Verified5 sources | |
| ParaSpaceCollateral valuation error in cAPE, ParaSpace's auto-compounding wrapper for staked ApeCoin | $5M$4.9M back | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| Euler FinancedonateToReserves skipped the health check, leaving a self-liquidatable position | $197M$197M back | Flash loan attack | Lending protocol | Ethereum | Verified3 sources | |
| Tender.fiTender.fi had switched its GMX price feed to a Chainlink feed, and the adapter consuming it scaled the price… | $1.6M$1.5M back | Contract logic error | Lending protocol | Arbitrum | Verified3 sources | |
| Hope FinancePrivileged contract substitution by an insider rather than an externally exploitable flaw | $1.9M–$2M | Rug pull or exit scam | Stablecoin or yield protocol | Arbitrum | Verified2 sources | |
| ≈ | MyAlgoMalicious JavaScript served to users through MyAlgo's content delivery network, sitting between wallet.myalgo.com and… | $9.2M | Supply chain or frontend compromise | Wallet software or provider | Other | Verified6 sources |
| Dexible V2The selfSwap function let callers supply their own router address and calldata without checking it against an approved… | $2M | Access control flaw | Decentralised exchange | Ethereum, Arbitrum | Verified3 sources | |
| Platypus FinanceOrdering flaw in MasterPlatypusV4::emergencyWithdraw on Avalanche: the USP solvency check ran before LP token balances… | $8.5M–$9.2M$2.4M back | Contract logic error | Decentralised exchange | Avalanche | Verified6 sources | |
| dForceRead-only reentrancy in a Curve wstETH/ETH pool used as a price oracle | $3.7M–$5.4M$3.7M back | Reentrancy | Lending protocol | Arbitrum, Optimism | Verified4 sources | |
| Orion ProtocolReentrancy in Orion's exchange contract (0x98a877bb507f19eb43130b688f522a13885cf604 on Ethereum) | $3M | Reentrancy | Decentralised exchange | Ethereum, BNB Chain | Verified4 sources | |
| BonqDAOBonqDAO consumed the latest value submitted to the permissionless Tellor oracle with no delay or averaging | $1.2M–$120M | Oracle or price manipulation | Lending protocol | Polygon | Verified4 sources | |
| OmmMissing validation in Omm's Redeem call, which accepted the address representing the collateral being redeemed without… | $1.9M | Contract logic error | Lending protocol | Other | Reported3 sources | |
| LendHubAn incomplete migration left a deprecated IBSV cToken market live alongside its replacement, both pricing the same… | $6M | Contract logic error | Lending protocol | Other | Verified3 sources | |
| RubicThe RubicProxy router's routerCallNative function did not validate the target address it was instructed to call… | $1.4M | Contract logic error | Decentralised exchange | Ethereum | Verified4 sources | |
| ≈ | Defrost FinanceTwo-stage incident | $12M–$12.9M$12.9M back | Private key compromise | Lending protocol | Avalanche | Verified5 sources |
| RaydiumCompromise of the account holding the pool-owner (admin) authority over Raydium's constant-product AMM pools on Solana | $4.4M–$5.5M | Private key compromise | Decentralised exchange | Solana | Verified4 sources | |
| Lodestar FinanceLodestar's GLPOracle priced plvGLP from the assets-to-shares ratio of PlutusDAO's depositor contract | $5.8M–$6.9M | Oracle or price manipulation | Lending protocol | Arbitrum, Ethereum | Verified4 sources | |
| AnkrA malicious code package inserted ahead of a legitimate update compromised the private key of Ankr's deployer account… | $5M–$20M | Supply chain or frontend compromise | Infrastructure provider | BNB Chain | Verified4 sources | |
| ≈ | LastPass vault-breach victims (cumulative)Attackers who exfiltrated encrypted LastPass password vaults in the 2022 breaches brute-forced weak master passwords… | $35M–$250M$24M back | Private key compromise | Individual holder | Multiple chains | Reported3 sources |
| ≈ | AAX (Atom Asset Exchange)Hong Kong police allege that after AAX halted trading and withdrawals behind a false 'system upgrade' notice, the… | $10.4M–$81M | Insider action | Centralised exchange | Multiple chains | Reported3 sources |
| FTXSIM swap of an FTX employee's phone number, used to capture account authentication codes | $400M–$477M | Social engineering | Centralised exchange | Ethereum, Bitcoin | Verified4 sources | |
| DFX FinanceThe flash() function in DFX V2's Curve.sol was written without the nonReentrant modifier used elsewhere | $4.3M–$7.6M | Reentrancy | Decentralised exchange | Ethereum | Verified5 sources | |
| Pando RingsThe attacker manipulated the price Pando Rings' oracle assigned to sBTC-WBTC, the liquidity provider token of the… | $21.9M$2.4M back | Oracle or price manipulation | Lending protocol | Ethereum, Bitcoin, EOS | Reported3 sources | |
| pNetwork (pGALA bridge)The pGALA token contract on BNB Chain was deployed with a misconfiguration that left mint authority outside pNetwork's… | $4.3M–$4.6M | Access control flaw | Cross-chain bridge | BNB Chain | Verified4 sources | |
| Solend (now Save)Solend's USDH price came from a Switchboard feed reading a single venue, the USDH/USDC pool on Saber | $1.3M | Oracle or price manipulation | Lending protocol | Solana | Verified3 sources | |
| Skyward FinanceThe treasury's redeem_skyward() function accepted a list of token account IDs and paid the caller's proportional share… | $3M–$3.2M | Contract logic error | Other | Other | Verified3 sources | |
| DeribitCompromise of the hot wallets holding BTC, ETH and USDC | $28M | Private key compromise | Centralised exchange | Bitcoin, Ethereum | Verified4 sources | |
| Team FinanceThe migrate function on Team Finance's Liquidity Locks contract, used to move locked positions from Uniswap v2 to… | $14.5M–$15.8M | Contract logic error | Other | Ethereum | Verified4 sources | |
| Moola MarketThe lending market priced its own thinly traded governance token MOO from a live on-chain feed | $8.4M–$10M | Oracle or price manipulation | Lending protocol | Other | Verified4 sources | |
| TempleDAO (STAX Liquidity Vault)The StaxLPStaking contract on Ethereum exposed a migrateStake() function intended to be callable only by a designated… | $2.3M | Access control flaw | DAO or treasury | Ethereum | Verified3 sources | |
| Mango Marketsspot-bought MNGO across the three thin venues feeding the platform oracle to inflate perpetual swap collateral, then… | $114M$67M back | Oracle or price manipulation | Decentralised exchange | Solana | Verified4 sources | |
| BNB Chain Token HubForged IAVL Merkle proof allowed the attacker to mint 2 million BNB | $100M–$570M | Signature verification flaw | Cross-chain bridge | BNB Chain | Verified3 sources | |
| SovrynCross-contract reentrancy in the iRBTC and iUSDT lending pools | $1.1M–$1.2M | Reentrancy | Lending protocol | Other | Verified5 sources | |
| Wintermuteprivate key of a Profanity-generated vanity admin address recovered by brute force against a 32-bit RNG seed | $160M | Private key compromise | Other | Ethereum | Verified5 sources | |
| Acala NetworkA misconfigured DexSavingRewardRates parameter on the deprecated accumulate_dex_saving function in Acala's incentives… | $1.6M–$5.8M | Contract logic error | Stablecoin or yield protocol | Other | Verified5 sources | |
| Slope WalletUsers' BIP39 mnemonic seed phrases were transmitted in plaintext from Slope's iOS and Android wallet apps to a… | $4M–$5M | Private key compromise | Wallet software or provider | Solana | Verified4 sources | |
| Nomadan upgrade left the committed Merkle root at bytes32(0), so any unproven message passed the Replica contract's… | $186M$37.5M back | Contract logic error | Cross-chain bridge | Ethereum | Verified6 sources | |
| Nomad BridgeA routine upgrade set the trusted Merkle root to zero, so every message verified | $190M | Contract logic error | Cross-chain bridge | Ethereum | Verified3 sources | |
| Nirvana FinanceFlash loan used to inflate the protocol's own reserve valuation, which the ANA bonding curve used to price mints and… | $3.6M | Flash loan attack | Decentralised exchange | Solana | Verified3 sources | |
| AudiusA storage-layout collision between the proxy and implementation contracts put AudiusAdminUpgradeabilityProxy.proxyAdmin… | $1.1M–$6.1M | Governance attack | DAO or treasury | Ethereum | Verified4 sources | |
| Crema FinanceThe Claim instruction did not validate that the tick account passed to it belonged to the pool, so the attacker… | $8.8M$8.3M back | Access control flaw | Decentralised exchange | Solana | Verified4 sources | |
| Harmony Horizon BridgeControl of the bridge multisig obtained through compromised signer keys | $99.7M$40M back | Private key compromise | Cross-chain bridge | Ethereum, Other | Verified3 sources | |
| GYM NetworkAn externally callable depositFromOtherContract() function in the GymSinglePool contract had no caller restriction and… | $716k–$2.1M | Access control flaw | Other | BNB Chain | Verified4 sources | |
| Wintermute (Optimism OP grant)Cross-chain address collision | $15M–$35M$15.6M back | Access control flaw | Other | Optimism | Verified5 sources | |
| ≈ | Blizz FinanceNot an active manipulation but a stale price feed | $8.3M | Oracle or price manipulation | Lending protocol | Avalanche | Verified4 sources |
| Fortress ProtocolFortress drew prices from the third-party Umbrella Network oracle, whose chain contract exposed a submit function with… | $3M | Oracle or price manipulation | Lending protocol | BNB Chain | Verified3 sources | |
| MM FinanceFrontend compromise rather than a contract flaw | $2M | Supply chain or frontend compromise | Decentralised exchange | Other | Verified3 sources | |
| Saddle FinanceThe sUSD metapool's swap path from an underlying token to LP tokens omitted the base pool's virtual price, mispricing… | $10M–$13.8M$3.8M back | Contract logic error | Decentralised exchange | Ethereum | Verified3 sources | |
| Rari Capital / Fei Protocol Fuse poolscross-function reentrancy calling exitMarket() during an ETH borrow in a Compound fork, releasing collateral before the… | $80M | Reentrancy | Lending protocol | Ethereum, Arbitrum | Verified3 sources | |
| DEUS FinanceDEUS's lending contracts priced its DEI stablecoin from the spot state of a USDC/DEI pool on Fantom rather than a… | $13.4M–$15.7M | Oracle or price manipulation | Lending protocol | Fantom, Ethereum | Verified3 sources | |
| Beanstalkflash-loan-funded supermajority used to vote and execute a malicious proposal in one transaction via emergencyCommit | $77M | Governance attack | Stablecoin or yield protocol | Ethereum | Verified4 sources | |
| Elephant MoneyThe ElephantReserve contract valued the native ELEPHANT token from spot automated market maker reserves when minting… | $11.2M | Oracle or price manipulation | Stablecoin or yield protocol | BNB Chain | Verified3 sources | |
| Inverse Finance (Frontier/Anchor)Anchor, the money market Inverse Finance later renamed Frontier, priced its own governance token INV using a… | $14.5M–$15.6M | Oracle or price manipulation | Lending protocol | Ethereum | Verified5 sources | |
| Ola FinanceRe-entrancy through the ERC677 token-transfer callback in Ola's Compound-fork lending markets: the callback fired… | $3.6M–$4.7M | Reentrancy | Lending protocol | Other | Verified4 sources | |
| Revest FinanceThe FNFT minting path lacked reentrancy protection | $2M | Reentrancy | Other | Ethereum | Verified2 sources | |
| Cashiomissing account validation let forged Crate and Arrow accounts pass as collateral, minting 2 billion uncollateralised… | $28M–$52.8M | Contract logic error | Stablecoin or yield protocol | Solana | Verified4 sources | |
| Ronin BridgeFive of nine validator keys controlled after a social-engineering campaign | $624M | Private key compromise | Cross-chain bridge | Ronin, Ethereum | Verified3 sources | |
| AgaveReentrancy through the non-standard bridged tokens used on Gnosis Chain, whose contracts call back into the receiving… | $5.5M | Reentrancy | Lending protocol | Other | Verified5 sources | |
| Hundred Finance (Gnosis Chain)Tokens bridged to Gnosis Chain through the official bridge are non-standard ERC-677-style tokens that call… | $6.4M | Reentrancy | Lending protocol | Other | Verified4 sources | |
| ParaluniThe MasterChef contract's depositByAddLiquidity function accepted a pool identifier and a token array without checking… | $1.7M | Reentrancy | Other | BNB Chain | Verified3 sources | |
| Fantasm FinanceMinting the synthetic asset XFTM was meant to require a minimum amount of native FTM alongside the FSM token | $2.6M | Contract logic error | Other | Fantom | Verified4 sources | |
| TreasureDAOMissing zero-check in the TreasureMarketplace buyItem() function | $1.4M | Contract logic error | NFT project or marketplace | Arbitrum | Verified4 sources | |
| ≈ | Dego Finance and Cocos-BCXDego Finance told the security firm PeckShield that a private key had been compromised | $10M–$14.4M | Private key compromise | Other | BNB Chain, Ethereum, Other | Reported3 sources |
| SuperfluidSuperfluid's Host contract passes a serialised context object (ctx) to agreement contracts carrying the identity of the… | $8.7M–$13M | Access control flaw | Infrastructure provider | Polygon | Verified4 sources | |
| IRA Financial TrustCompromise of the 'master key' credential that Gemini issued to IRA Financial for its omnibus account structure | $36M | Access control flaw | Custodian or payment processor | Bitcoin, Ethereum | Verified5 sources | |
| Meter PassportMissing validation in the ERC20 handler's deposit method | $4.3M–$7.7M | Contract logic error | Cross-chain bridge | BNB Chain, Ethereum, Other | Verified3 sources | |
| WormholeDeprecated function let a forged guardian signature pass verification | $326M | Signature verification flaw | Cross-chain bridge | Solana, Ethereum | Verified3 sources | |
| BitbnsNever disclosed | $7.5M | Other or undisclosed | Centralised exchange | Ethereum | Reported3 sources | |
| Qubit Financedeprecated QBridge deposit() minted bridged ETH with no deposit because the zero token address made safeTransferFrom… | $80M | Contract logic error | Lending protocol | BNB Chain, Ethereum | Verified5 sources | |
| Crypto.comWithdrawals approved without the account holder entering a second authentication factor | $33.8M | Access control flaw | Centralised exchange | Ethereum, Bitcoin | Verified2 sources | |
| LCXUnauthorised transfers out of a single LCX-controlled Ethereum hot wallet | $5.3M–$7.9M | Private key compromise | Centralised exchange | Ethereum | Verified4 sources | |
| ≈ | Arbix FinanceCertiK's incident analysis found that the ARBX token contract carried a mint() function restricted to the contract owner | $10M | Rug pull or exit scam | Other | BNB Chain, Ethereum | Reported4 sources |
| ≈ | Bent FinanceAn unverified contract update pushed from the project's own deployer address hardcoded an enormous cvxCRV/MIM balance… | $1.6M–$2.1M | Insider action | Other | Ethereum | Verified4 sources |
| Visor FinanceThe RewardsHypervisor deposit function accepted an arbitrary contract address from the caller and called owner() and… | $8.1M | Access control flaw | Other | Ethereum | Verified4 sources | |
| ≈ | Grim Financeunguarded depositFor() in GrimBoostVault re-entered five times, minting vault shares for a single real deposit | $30M | Reentrancy | Other | Fantom | Reported5 sources |
| Vulcan ForgedPlatform servers compromised, wallet-provider credentials abused to export user private keys | $140M | Private key compromise | Gaming or metaverse | Ethereum, Polygon | Verified3 sources | |
| AscendEXunauthorised passthrough access to hot wallet infrastructure, attributed by AscendEX to a hardware-level vulnerability… | $77.7M$10M back | Infrastructure compromise | Centralised exchange | Ethereum, Polygon, BNB Chain, Other | Verified4 sources | |
| ≈ | 8ight FinanceTreasury private keys were held by two developers and had been passed between them over a Facebook group chat and… | $1.7M | Private key compromise | DAO or treasury | Other | Reported3 sources |
| BitMartstolen private keys for one Ethereum and one BNB Chain hot wallet; method of compromise never disclosed | $150M–$196M | Private key compromise | Centralised exchange | Ethereum, BNB Chain | Verified3 sources | |
| BadgerDAOMalicious script injected through a compromised Cloudflare API key added unlimited spend approvals | $120M | Supply chain or frontend compromise | DAO or treasury | Ethereum | Verified3 sources | |
| MonoX Financeswap accepted the same token as tokenIn and tokenOut | $31M | Contract logic error | Decentralised exchange | Ethereum, Polygon | Verified3 sources | |
| bZxphishing macro stole a developer's mnemonic and the Polygon and BNB Chain deployer keys | $55M | Private key compromise | Lending protocol | Polygon, BNB Chain | Verified4 sources | |
| Vesper FinanceThe attacker cornered the Uniswap v3 VUSD/USDC 0.05% fee tier and opened a 0.1 USDC liquidity position priced at… | $3.5M | Oracle or price manipulation | Lending protocol | Ethereum | Verified4 sources | |
| AnubisDAOsingle-signer wallet withdrew the entire liquidity bootstrapping pool | $56M–$60M | Rug pull or exit scam | DAO or treasury | Ethereum | Verified4 sources | |
| C.R.E.A.M. FinanceFlash-loaned capital used to inflate yUSD price-per-share in Cream's hybrid oracle | $130M | Oracle or price manipulation | Lending protocol | Ethereum | Verified4 sources | |
| Indexed FinanceIndexed's pool controller used an approximate value derived from a Uniswap oracle to set the target balance for a newly… | $16M | Oracle or price manipulation | Other | Ethereum | Verified6 sources | |
| ≈ | Mirror Protocolthe collateral-unlock contract never recorded which position IDs had been redeemed, so the same ID could be replayed to… | $90M | Contract logic error | Other | Other | Reported3 sources |
| Compound COMP Distribution BugReward accounting error in upgraded Comptroller let users over-claim COMP | $80M–$90M | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| ≈ | Vee FinanceSingle Pangolin price oracle manipulated, plus a token-decimals error that defeated slippage checks | $35M | Oracle or price manipulation | Lending protocol | Avalanche | Verified4 sources |
| pNetwork pBTC-on-BSC bridgeThe Rust code that extracted peg-out request events from logs did not validate that those events had been emitted by… | $12.4M | Contract logic error | Cross-chain bridge | BNB Chain, Bitcoin | Verified6 sources | |
| Jay Pegs Auto Mart (SushiSwap MISO)Malicious commit pushed directly to the master branch of SushiSwap's MISO launchpad front-end repository, replacing the… | $2.9M–$3.1M$2.9M back | Supply chain or frontend compromise | Other | Ethereum | Verified3 sources | |
| NowSwapAn incomplete constant update left one of three checks on the constant-product invariant validating a tenth of the… | $1M | Contract logic error | Decentralised exchange | Ethereum | Verified3 sources | |
| Zabu FinanceThe ZABUFarm staking contract recorded the amount a user declared they were staking rather than the smaller amount… | $3.2M | Contract logic error | Other | Avalanche | Verified3 sources | |
| ≈ | DAO Maker (September 2021 vesting exploit)The init() function on DAO Maker's Strong Holder Offering vesting contracts had no access control, so the attacker was… | $4M | Access control flaw | Other | Ethereum | Reported3 sources |
| Siren ProtocolReentrancy through the ERC-1155 onERC1155Received acceptance-check callback in MinterAmm.withdrawCapital /… | $3.5M | Reentrancy | Decentralised exchange | Polygon | Reported2 sources | |
| xToken (xSNX)A callback function in the xSNXAdmin contract, intended to be reachable only by dYdX's SoloMargin flash loan contract… | $4.5M | Access control flaw | Other | Ethereum | Verified3 sources | |
| Liquid GlobalCompromise of Liquid's internet-connected 'warm' wallets, which held liquidity for customer withdrawals across Bitcoin… | $81M–$97M | Private key compromise | Centralised exchange | Bitcoin, Ethereum, Other | Verified3 sources | |
| SurgeBNB (xSurge)The SurgeBNB token contract acted as its own market maker | $5M | Reentrancy | Token contract | BNB Chain | Verified4 sources | |
| DAO MakerDAO Maker said the loss came from "malicious use of one of our wallets with access to admin privileges", and chief… | $7M–$7.4M | Private key compromise | Other | Ethereum | Verified3 sources | |
| Punk ProtocolThe initialize() function of the CompoundModel contract was deployed without an initializer or access-control modifier… | $9M$5M back | Access control flaw | Other | Ethereum | Reported4 sources | |
| Poly NetworkCross-chain manager contract could be instructed to change its own keeper | $611M$611M back | Access control flaw | Cross-chain bridge | Ethereum, BNB Chain, Polygon | Verified3 sources | |
| LevyathanPrivate key controlling the protocol's Timelock was left publicly visible in the governance repository of the project's… | $1.5M$265k back | Private key compromise | Other | BNB Chain, Ethereum | Reported4 sources | |
| THORChain ERC-20 Router ExploitThe attacker deployed a fake router contract that emitted a deposit event with a malformed memo and named the… | $8M | Contract logic error | Decentralised exchange | Ethereum | Verified4 sources | |
| PolyBunny (PancakeBunny on Polygon)The Bunny vault calculated a depositor's realised profit from the balance sitting in the external farm contract rather… | $2.4M | Flash loan attack | Other | Polygon | Verified3 sources | |
| Bondly FinancePer the project's own post-mortem, the attacker gained access to a password-manager account belonging to Bondly's chief… | $5.9M–$7.5M | Private key compromise | Token contract | Ethereum, BNB Chain, Polygon | Verified5 sources | |
| ApeRocket FinanceVault performance-fee accounting counted any tokens sitting in the contract as earned yield | $1.3M | Flash loan attack | Other | BNB Chain, Polygon | Verified3 sources | |
| ≈ | ChainSwapChainSwap's cross-chain bridge minted wrapped partner-project tokens on Ethereum and BNB Chain against a per-address… | $4M–$8M | Access control flaw | Cross-chain bridge | Ethereum, BNB Chain | Verified5 sources |
| Anyswap Multichain Router V3ECDSA nonce reuse | $7.9M | Private key compromise | Cross-chain bridge | Ethereum, BNB Chain, Fantom | Verified3 sources | |
| StableMagnetThe deployed SwapUtils linked library did not match the verified source code, because block explorers do not verify… | $25M–$27M$22.3M back | Rug pull or exit scam | Decentralised exchange | BNB Chain | Verified5 sources | |
| Eleven FinanceThe emergencyBurn function of the ElevenNeverSellVault contract returned a depositor's underlying assets without… | $4.5M | Contract logic error | Other | BNB Chain | Verified3 sources | |
| Alchemix alETH vaultA deployment-script error accidentally created additional alETH vaults | $4.8M–$6.5M | Contract logic error | Lending protocol | Ethereum | Verified5 sources | |
| ≈ | CoinbasePro.com spoofing scheme (Chirag Tomar)Spoofed website plus support impersonation | $20M–$37M | Phishing signature | Individual holder | Multiple chains | Verified5 sources |
| Belt FinanceThe attacker deployed a contract that drew flash loans of BUSD from PancakeSwap and used the borrowed size to distort… | $6.2M | Flash loan attack | Other | BNB Chain | Verified3 sources | |
| BurgerSwapThe attacker deployed a counterfeit BEP-20 token and created a trading pair between it and BURGER | $7.2M | Reentrancy | Decentralised exchange | BNB Chain | Verified4 sources | |
| PancakeBunnyflash loans skewed the PancakeSwap V1 WBNB pool used by Bunny's PriceCalculatorBSCV1 to value LP tokens, inflating… | $30M–$45M | Oracle or price manipulation | Other | BNB Chain | Verified4 sources | |
| bEarn FiInconsistent asset denomination between the BvaultsBank vault contract and the BvaultsStrategy it delegated to | $10.9M–$18M | Contract logic error | Other | BNB Chain | Verified4 sources | |
| xTokenTwo flaws exploited in one Ethereum transaction | $24.5M | Oracle or price manipulation | Other | Ethereum | Verified4 sources | |
| Rari CapitalRari's Ethereum Pool derived the ibETH/ETH exchange rate itself from ibETH.totalETH() divided by ibETH.totalSupply() | $10M–$11M | Reentrancy | Other | Ethereum | Verified4 sources | |
| Value DeFi vSwapIncorrect enforcement of the weighted constant-product invariant in vSwap pools whose two assets were not weighted 50/50 | $11M | Contract logic error | Decentralised exchange | BNB Chain | Verified4 sources | |
| Value DeFi (vStake pool)The vStake profit-sharing pool contract had an initialize() function that was missing the line setting the initialized… | $6M–$10M | Access control flaw | Other | BNB Chain | Verified3 sources | |
| Spartan ProtocolLP-share payout computed against the live pool balance instead of cached reserves, inflated with flash-loaned WBNB | $30M–$40M | Flash loan attack | Decentralised exchange | BNB Chain | Verified4 sources | |
| Uranium Financepair contract balance sanity check used a constant one hundred times too large | $50M–$53.3M$31M back | Contract logic error | Decentralised exchange | BNB Chain | Verified5 sources | |
| ThodexOperator exit scam | $43M–$2B | Rug pull or exit scam | Centralised exchange | Multiple chains | Verified3 sources | |
| EasyFimalware-altered MetaMask on the founder's machine exposed the admin mnemonic | $6M–$81M | Private key compromise | Lending protocol | Polygon, Ethereum | Verified5 sources | |
| TurtleDexRoughly 9,000 BNB of TTDX liquidity, seeded on PancakeSwap and ApeSwap with proceeds from a presale that began on 15… | $2.4M | Rug pull or exit scam | Token contract | BNB Chain, Ethereum | Verified3 sources | |
| RollPrivate keys to Roll's hot wallet were obtained by an unknown means | $5.7M | Private key compromise | Custodian or payment processor | Ethereum | Verified4 sources | |
| DODOThe init() function on DODO V2 Crowdpooling contracts could be called again on pools that had already been initialised | $2.1M–$3.8M$3.1M back | Access control flaw | Decentralised exchange | Ethereum, BNB Chain | Verified3 sources | |
| PAID NetworkA single private key controlling upgrades to the PAID token's proxy contract was compromised | $3.1M | Private key compromise | Token contract | Ethereum | Verified4 sources | |
| Meerkat Financeupgradeable vault proxies re-pointed to a draining implementation using owner/deployer privileges | $31M | Access control flaw | Other | BNB Chain | Verified4 sources | |
| FurucomboFurucombo's proxy contract used a single whitelist covering both permitted callers and permitted call targets, and the… | $14M–$15M | Access control flaw | Other | Ethereum | Verified4 sources | |
| Alpha FinanceDebt-share rounding bug in an unfunded sUSD pool, amplified by Aave flash loans and unrestricted custom spells | $38.2M | Contract logic error | Lending protocol | Ethereum | Verified3 sources | |
| ≈ | Growth DeFiThe single-asset deposit function of the stkGRO/rAAVE staking contract accepted a token address and a Uniswap pool… | $1.4M | Contract logic error | Other | Ethereum | Verified4 sources |
| Yearn FinanceThe v1 yDAI vault routed deposits into Curve's 3pool through a permissionless earn() function and realised value at… | $11M | Oracle or price manipulation | Other | Ethereum | Verified4 sources |
Every row has a permanent anchor: append #slug to this page's address to link straight to an entry.
What “verified” means here
A verified entry has at least two independent sources. A post-mortem, an exchange statement, an indictment or a court filing counts as one. Our own confirmation of a transaction against the chain counts as another, because we derive the figure rather than repeat it. Five outlets restating the same original count once. Entries that never clear that bar stay in the table marked as reported and are left out of every total.
Corrections
Figures move as investigations progress. When a published number changes, the entry records what changed and why, and the change stays visible. If something here is wrong, write to [email protected] and it will be checked against the sources.
Common questions about crypto hacks
- How much cryptocurrency has been stolen?
- Between 2021 and 2026 this registry records $12.89 billion taken across 346 verified incidents of $100,000 or more, of which $1.82 billion was later recovered, returned or frozen. The figure counts assets removed from their owner's control, valued at the time of each incident. It excludes investment fraud and it excludes falls in a token's price after an attack, both of which inflate widely-quoted totals.
- What is the biggest crypto hack ever?
- Bybit, on February 21, 2025, at $1.46 billion. Compromised Safe{Wallet} infrastructure served a malicious signing interface. It is the largest single theft in this registry by value taken.
- Which year was the worst for crypto hacks?
- 2022, with $3.3 billion taken across 53 verified incidents. Year totals are driven by a handful of very large thefts rather than by how many incidents occurred, so a quiet-looking year can still hold one record-breaking loss.
- How many crypto hacks happen each year?
- This registry records roughly 58 verified incidents of $100,000 or more per year between 2021 and 2026. The true number is higher: smaller thefts are under-reported, and incidents only enter the registry once at least two independent sources exist.
- How is most cryptocurrency stolen?
- Contract logic error is the most common cause here, behind 82 of 346 verified incidents. Contract flaws, compromised keys and social engineering of the people holding those keys account for most of the total; attacks on a blockchain's own consensus are rare.
- Can I use this data in my own reporting?
- Yes. The registry is published under CC BY 4.0, so you may republish, adapt and build on it, including commercially, as long as you credit iTokenly and link back. CSV and JSON exports are linked at the top of the page and need no key or account. Every entry lists its sources so you can check a figure rather than take it from us.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, iTokenly, accessed 2026-08-19, https://itokenly.com/hackshttps://itokenly.com/hacksPermalinks never change. If an entry is renamed, the old address keeps working.
Last updated August 13, 2026. Read the methodology for inclusion criteria, how losses are valued, and how conflicting figures are resolved.