T
iTokenly

Crypto Hack Registry: Every Major Hack, Exploit and Theft

Every cryptocurrency hack, exploit and theft of $100k or more that we can verify, in one permanent place. Each entry carries the sources behind it, so any figure here can be checked rather than taken on trust.

Verified incidents
16
Verified losses
$5.6B
Recovered
$1B
Covering
2021–2026

Take the data

No key, no sign-up, no rate limit for ordinary use. Published under CC BY 4.0 — reuse it commercially if you credit iTokenly and link back.

Showing 16 of 16
iTokenly Hack Registry16 recorded incidents
DateTargetLossMethodTypeChainsEvidence
Drift ProtocolMultisig signers manipulated into surrendering admin control, then oracles moved with a fake token$285MSocial engineeringDecentralised exchangeSolanaVerified3 sources
Cetus ProtocolOverflow in the checked_shlw helper of the integer-mate maths library$223M–$260M$162M backContract logic errorDecentralised exchangeSui, EthereumVerified3 sources
BybitCompromised Safe{Wallet} infrastructure served a malicious signing interface$1.4B–$1.5BSupply chain or frontend compromiseCentralised exchangeEthereumVerified3 sources
WazirXSigners approved a malicious contract upgrade shown differently by the custody interface$235MSocial engineeringCentralised exchangeEthereumVerified3 sources
DMM BitcoinFake recruiter compromised an employee at wallet vendor Ginco, then altered a transaction request$308MSocial engineeringCentralised exchangeBitcoinVerified3 sources
Mixin NetworkCloud database provider compromised, exposing the network's hot wallets$142M–$200MInfrastructure compromiseInfrastructure providerMultiple chainsVerified3 sources
Curve FinanceVyper 0.2.15–0.3.0 compiled broken reentrancy guards into affected pools$52M–$73MReentrancyDecentralised exchangeEthereumVerified3 sources
Atomic WalletRoot cause never publicly disclosed; user keys compromised at scale$35M–$100MOther or undisclosedWallet software or providerMultiple chainsVerified3 sources
Euler FinancedonateToReserves skipped the health check, leaving a self-liquidatable position$197M$197M backFlash loan attackLending protocolEthereumVerified3 sources
BNB Chain Token HubForged IAVL Merkle proof allowed the attacker to mint 2 million BNB$100M–$570MSignature verification flawCross-chain bridgeBNB ChainVerified3 sources
Nomad BridgeA routine upgrade set the trusted Merkle root to zero, so every message verified$190MContract logic errorCross-chain bridgeEthereumVerified3 sources
Harmony Horizon BridgeControl of the bridge multisig obtained through compromised signer keys$99.7M$40M backPrivate key compromiseCross-chain bridgeEthereum, OtherVerified3 sources
Ronin BridgeFive of nine validator keys controlled after a social-engineering campaign$624MPrivate key compromiseCross-chain bridgeRonin, EthereumVerified3 sources
WormholeDeprecated function let a forged guardian signature pass verification$326MSignature verification flawCross-chain bridgeSolana, EthereumVerified3 sources
BadgerDAOMalicious script injected through a compromised Cloudflare API key added unlimited spend approvals$120MSupply chain or frontend compromiseDAO or treasuryEthereumVerified3 sources
Poly NetworkCross-chain manager contract could be instructed to change its own keeper$611M$611M backAccess control flawCross-chain bridgeEthereum, BNB Chain, PolygonVerified3 sources

Every row has a permanent anchor: append #slug to this page's address to link straight to an entry.

What “verified” means here

A verified entry has at least two independent sources. A post-mortem, an exchange statement, an indictment or a court filing counts as one. Our own confirmation of a transaction against the chain counts as another, because we derive the figure rather than repeat it. Five outlets restating the same original count once. Entries that never clear that bar stay in the table marked as reported and are left out of every total.

Corrections

Figures move as investigations progress. When a published number changes, the entry records what changed and why, and the change stays visible. If something here is wrong, write to [email protected] and it will be checked against the sources.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, iTokenly, accessed 2026-08-01, https://itokenly.com/hacks
https://itokenly.com/hacks

Permalinks never change. If an entry is renamed, the old address keeps working.

Last updated August 1, 2026. Read the methodology for inclusion criteria, how losses are valued, and how conflicting figures are resolved.