2219 hack event(s)
Description of the event: The Harmony Layer-1 blockchain was exploited, allowing an attacker to unauthorizedly mint approximately 4 billion ONE tokens (about 26% of the supply) via empty blocks and related flaws. Large amounts were quickly funneled to exchanges for sale, causing the token price to crash ~30-40%. The team confirmed the incident, paused the cross-chain bridge, released an emergency validator patch to stop further minting, coordinated with exchanges to freeze funds, and is evaluating a chain rollback.
Amount of loss: $ 3,200,000 Attack method: Protocol Logic Vulnerability
Description of the event: The USM protocol suffered an exploit due to a pricing logic flaw in the ethFromDefund() function within defund(). It uses the arithmetic mean of the current and estimated final FUM sell prices for a single redemption but lacks “split invariance.” Combined with the per-redemption state contraction (adjShrinkFactor) and integer rounding, an attacker used a flash loan to call fund() to manipulate internal pricing, then split the same FUM amount into 64 small defund() calls, extracting more ETH than a single large call and causing a loss of ~70.83 ETH.
Amount of loss: $ 136,000 Attack method: Smart Contract Vulnerability
Description of the event: Wallets linked to Coinsbuy (a B2B crypto payment processor) were drained of more than $7.9 million across Ethereum and TRON around 13:00 UTC on August 9, 2026. The attacker laundered part of the funds into Monero (XMR) via exchanges, while ChangeNOW helped freeze a six-figure amount; Coinsbuy temporarily paused deposits and withdrawals, which have since resumed.
Amount of loss: $ 7,900,000 Attack method: Unknown
Description of the event: Oraichain (AI Layer 1) suffered from a vulnerability in its EVM cross-chain transfer path, enabling unauthorized minting of ORAI tokens. The network has been halted since 04:00 UTC on August 9, 2026, with bridges, cross-chain routes, and public interfaces restricted. The exploit path has been identified and addressed; the team is working with partners and CEXs to limit fund movements and is preparing to burn the unauthorized minted balances and reconcile protocol states to restore the canonical ORAI supply.
Amount of loss: - Attack method: Cross-Chain Bridge Exploit
Description of the event: On August 9, 2026, the cross-chain bridge connecting the XRP Ledger and Coreum (now tx) was exploited. The attacker abused a flaw in the deposit-verification/relayer logic by creating fake deposits (self-transfers of the bridge’s own wrapped tokens with valid memos), tricking the relayers into authorizing real XRP withdrawals from the bridge’s reserve. Nearly 200,000 XRP (~$200,000) was drained in 94 multisig transactions over 97 minutes.
Amount of loss: $ 200,000 Attack method: Bridge Logic Vulnerability
Description of the event: Atomic Green (a non-custodial leveraged trading protocol on Arbitrum) was exploited due to a signature replay vulnerability. The same manager signature could be replayed across 21 different Uniswap V3 LP positions, combined with flashloan-based price manipulation, allowing the attacker to trigger unauthorized full LP burns and resulting in a loss of approximately 29,984.27 USDC.
Amount of loss: $ 29,984.27 Attack method: Signature Replay Attack
Description of the event: Security firm Coinspect disclosed that RRWallet (RenrenBit’s wallet) generated vulnerable seed phrases due to a weak RNG in the CryptoJS library (Ill Bloom vulnerability, CVE-2026-71851), making private keys predictable and leading to theft. One user lost approximately $2 million.
Amount of loss: $ 2,000,000 Attack method: Supply Chain Attack
Description of the event: Unistreets LaunchpadFactoryAuto contract on Ethereum was exploited via arbitrary calldata injection. The factory custodied all launched tokens’ Uniswap V4 LP NFTs; the attacker injected setApprovalForAll approval and burned multiple LP positions, draining liquidity for a loss of approximately $17,750.
Amount of loss: $ 17,750 Attack method: Smart Contract Vulnerability
Description of the event: ZEUS (Bitcoin Lightning Network wallet and LSP provider) infrastructure suffered a cybersecurity incident/attack within the last few hours; the attack was mitigated. Services were temporarily taken offline for a full systems audit out of caution; no customer funds were lost or at risk, and closed LSP channels will be replaced upon restoration. The incident appears limited to ZEUS infrastructure, with no evidence of a Lightning node software vulnerability.
Amount of loss: 0 Attack method: Infrastructure Compromise
Description of the event: On August 3, 2026, an unauthorized withdrawal of 673,011.56 USDC occurred from the RWA strategy linked to RISEx’s XLP vault due to a misconfiguration present since its July 13 deployment. The team detected it within minutes, patched it by 08:09 UTC, and fully compensated XLP depositors using a portion of July fees; the platform and other components continued operating normally.
Amount of loss: $ 673,011.56 Attack method: Smart Contract Vulnerability
Description of the event: LOOPSDAO’s LpdFi protocol on BSC was exploited. The attacker used a flash loan to manipulate the spot price of the thin PancakeSwap LPD/USDC pair (no TWAP or deviation guard), opened a massively inflated interest-bearing position with minimal LPD, and claimed interest right across the daily settlement boundary. This triggered the protocol to burn its own Cake-LP and pay out the inflated amount, draining approximately $690,000.
Amount of loss: $ 690000 Attack method: Price Manipulation
Description of the event: The MOKE token protocol on BNB Chain was exploited via a smart contract vulnerability. The attacker abused an unprotected public claim() function in MokeToken.releaseContract() (no eligibility check on the caller), repeatedly draining ~166 million MOKE from the protocol’s internal reserve pool, then used flash loans, Venus leverage, LP removal, and dividend distribution mechanisms to convert it into ~1,546 BNB, resulting in a loss of approximately $907,700.
Amount of loss: $ 907700 Attack method: Smart Contract Vulnerability
Description of the event: Coldcard hardware wallets (by Coinkite) suffered from a firmware bug (since March 2021 on certain versions) that generated seeds with insufficient entropy (~40 bits on Mk3, ~72 bits on newer models vs. the intended 128 bits). Attackers offline brute-forced predictable private keys and drained numerous single-signature Bitcoin addresses across multiple waves without ever accessing the devices, with cumulative losses exceeding $100 million and the incident ongoing.
Amount of loss: $ 100000000 Attack method: Firmware Vulnerability
Description of the event: The DeFi protocol Set Protocol (involving Index Coop’s ExchangeIssuance contract) was exploited due to insufficient state locking in the smart contract. The attacker used a malicious manager pre-issue hook to artificially inflate asset valuations (e.g., positionMultiplier), causing the contract to transfer excess assets based on falsified data, resulting in a loss of approximately $9,600.
Amount of loss: $ 9,600 Attack method: Smart Contract Vulnerability
Description of the event: The decentralized asset management protocol Swan Treasury on BNB Chain was exploited due to the leakage of an off-chain signer's private key (the _signer key hardcoded in the ZhaiquanBuy contract). The attacker forged valid signatures and used PancakeSwap flash loans to purchase approximately 687,000 STY tokens at around a 100x discount (spending approximately 19,700 USDT). The attacker then forged the related claim()/transfer signatures and dumped the tokens into the STY/USDT pool, making a profit of approximately $625,000.
Amount of loss: $ 625,000 Attack method: Private Key Leakage
Description of the event: The Pro token contract of Crypto DAO was exploited due to missing access control, with the attacker calling publicly accessible vault functions. According to GoPlus Security’s analysis, the attacker’s actual profit was approximately $52,000, while the contract lost around 167,200 Pro tokens. The related addresses monitored by Blockaid collectively held approximately $8.2 million worth of USDT (not the actual stolen amount).
Amount of loss: $ 52,000 Attack method: Smart Contract Vulnerability
Description of the event: The LULA token on BSC was exploited when attackers abused the privileged recycle() function in its contract, combined with an approximately $237 million flash loan to manipulate PancakeSwap V2 liquidity pool reserves, resulting in a loss of about $578,100.
Amount of loss: $ 578,100 Attack method: Price Manipulation Attack
Description of the event: The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before being bridged out. The team has suspended bridges and related services while working with exchanges, security firms, and law enforcement to track the funds.
Amount of loss: $ 6,250,000 Attack method: Private Key Leakage
Description of the event: Security firm Blockaid detected an ongoing exploit targeting Garden Finance’s HTLC contracts, draining about $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Chain. The project stated that an independent solver’s off-chain database was compromised and fraudulent records were inserted, causing improper fund releases; the protocol and smart contracts themselves were not compromised, and the app has been temporarily taken offline.
Amount of loss: $ 450,000 Attack method: Supply Chain Attack
Description of the event: ChainConnect’s EVM integration was compromised through unauthorized access. Approximately $650,000 in tokens was drained from the bridge contracts across Ethereum, BNB Chain, Avalanche C-Chain and Polygon in 23 transactions; bridge operations were paused immediately.
Amount of loss: $ 650,000 Attack method: Unauthorized Access