2307 hack event(s)
Description of the event: BitBay’s Polygon DAI/USDC vault, UsdcDaiV4Vault, was exploited. The attacker first called reposition() to force the vault’s liquidity to zero, then redeemed only one minimal share. Because _withdraw() sends the contract’s entire token balance when liquidity == 0 instead of the user’s proportional share, about 14,838.47 DAI (roughly $14,000) was drained.
Amount of loss: $ 14,000 Attack method: Smart Contract Vulnerability
Description of the event: EtherVista’s liquidity pool was exploited due to an integer overflow in the K-invariant check inside EtherVistaPair.swap(). Both reserves are uint112, so their product can wrap around and the check can pass even when the real reserve product drops sharply. The attacker registered a self-controlled contract as an authorized router and ran two crafted swaps to drain WETH and VISTA, with a loss of about $18,600.
Amount of loss: $ 18600 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited an accounting bug in X7Pioneer’s claimRewards(). The function adds address(this).balance - lastETHBalance to totalRewards on every call, but updates lastETHBalance only when claimable > 0. An empty array leaves claimable at 0, so the same unaccounted balance is added repeatedly and inflates per-token rewards. The attacker donated ETH to widen the delta, then drained about 6.78 ETH.
Amount of loss: $ 16,514 Attack method: Smart Contract Vulnerability
Description of the event: An operator hot-wallet private key of 79th Vault was compromised. Using an OPERATOR_ROLE function, the attacker moved 2.01 million 79AU out of the PancakeSwap 79AU/USDT pair in seven transfers, sold them back in about 95 swaps, cut the pool’s USDT reserves from about $15,200,000 to about $3,900,000, and cashed out 16,249 BNB (about $12,500,000). Forty-one seconds later the same operator key sent 3.79 BNB to the attacker address.
Amount of loss: $ 12,500,000 Attack method: Private Key Leakage
Description of the event: The attacker abused Set Protocol’s actualizeFee(). Even though no fee was minted, the function rounded unitShares upward from 4,927 to 4,928. The attacker issued shares before the update and redeemed the same quantity afterward, extracting extra collateral from the rounding-induced unit increase. Uniswap v4 flash accounting supplied temporary liquidity to scale the exploit.
Amount of loss: $ 13,700 Attack method: Smart Contract Vulnerability
Description of the event: A Tornado Cash-funded address called an unprotected drain function on a dormant MakerDAO ETH-A liquidation keeper. The upgradeable proxy had won auctions #1457–1460 in 2020 (200 WETH total) but never called deal(), leaving the collateral in the Flipper. The attacker called deal(), moved the collateral to the keeper via Vat.flux, then used GemJoin.exit() to withdraw 200 WETH to an attacker-chosen address and unwrap it to ETH. The flaw was in the third-party keeper, not MakerDAO core.
Amount of loss: $ 538000 Attack method: Smart Contract Vulnerability
Description of the event: Web3 financial platform Based discovered that an unauthorized third party had accessed an internal dashboard used to manage the Based Visa Card program and contained the incident shortly after detection. KYC data collected by the card issuer for some cardholders (including name, ID/passport number, date of birth, and address) may have been obtained. Card numbers, CVV, PIN, ID photos, liveness records, the Based Wallet, and card funds were not affected, and cards continue to work normally. Affected users were notified by email, authorities were informed, and users were warned about phishing and social-engineering risks.
Amount of loss: 0 Attack method: Unauthorized Access to Internal Systems
Description of the event: An attacker exploited a logic flaw in MALT’s swap function. With negligible input they triggered an external rebalanceHook that pulled DAI from the protocol’s Capital Source into the same pool. The swap then checked its invariant against the post-hook balances and treated the treasury-funded DAI as caller-supplied funds, allowing a disproportionate MALT withdrawal and a loss of about $ 72,000.
Amount of loss: $ 72000 Attack method: Smart Contract Vulnerability
Description of the event: On Base, an attacker exploited GoldPesa’s GPXHooks. The hook rebalanced through a shared, flash-accounted PositionManager without checking that the GPX/USDC currency deltas were zero. The attacker opened an unlock, minted an unsettled WETH/USDC position (about 115,000 USDC of phantom debt), then swapped on the GPX pool to trigger the hourly reBalance. The hook’s burn credit was netted against that debt, and the attacker burned its own position and withdrew about 114,900 USDC from the PoolManager.
Amount of loss: $ 114900 Attack method: Smart Contract Vulnerability
Description of the event: Microsoft’s official X account was accessed without authorization for about 30 minutes. Attackers changed the profile picture to Clippy, followed and reposted an impersonator account, and promoted an unauthorized Clippy meme coin to roughly 13 million followers; a later “apology” post was also unauthorized and deleted. Microsoft told The Verge and others that the account was secured, the posts removed, and that it never authorized any token tied to Clippy or $MSFT.
Amount of loss: 0 Attack method: The X account was hacked
Description of the event: NEAR Intents suffered a security incident caused by a bug in the Omni deposit and withdrawal infrastructure’s interaction with its smart contract, with a preliminary loss of approximately $3.8 million. The contract-side vulnerability has been patched, full compensation has been pledged, and the team has reported the incident to law enforcement while working to trace and recover the funds.
Amount of loss: $ 3,800,000 Attack method: Smart Contract Vulnerability
Description of the event: The attacker exploited an access-control vulnerability in FlashLoopAdapter by spoofing Safe authentication and bypassing the module authorization check. By controlling the swapRouter and swapCalldata, the attacker targeted the victim Safes with execTransactionFromModule() and executed unauthorized transactions. The attacker also used a Morpho WETH flash loan to repay the affected Safe’s Aave V3 debt and unlock its collateral, ultimately draining weETH from two Safes and retaining approximately 114.09 ETH, worth about $305,000.
Amount of loss: $ 305,000 Attack method: Smart Contract Vulnerability
Description of the event: The MCN Labs–related LPBonus contract used inconsistent MSN reserve values in reward accounting. Accrual updated the reward index with the reserve at that moment, while withdrawal applied a user weight based on the reserve at claim time. The attacker first lowered the reserve to ~89.33 MSN during accrual, then raised it to ~491.11 MSN before calling UserRemoveLp, allowing a newly registered LP to claim ~1,442,165.71 FIST against only ~940,041.61 FIST of intervening reward funding—about $92,600 in losses.
Amount of loss: $ 92,600 Attack method: Smart Contract Vulnerability
Description of the event: MUSystem’s deposit() counted the first-deposit bonus in both the immediate ETH refund and the user’s MUS allocation, while withdraw() allowed same-transaction redemption without capping returned ETH to the amount deposited. Sixteen fresh addresses repeated this cycle and drained ETH from the contract, causing about $36,900 in losses.
Amount of loss: $ 36,900 Attack method: Smart Contract Vulnerability
Description of the event: Scammers deployed a fake GIWA L2 network using the legitimate Chain ID 9134, complete with a functional bridge and batcher. Approximately 1,335 addresses bridged ~767.65 ETH believing it was the official mainnet launch. The attackers drained ~766.25 ETH (~$2M). The real GIWA mainnet had not launched. DYORSWAP initially listed the fake network due to the matching Chain ID and later compensated affected users from its treasury.
Amount of loss: $ 2,000,000 Attack method: Fake Chain / Fake Bridge Scam
Description of the event: Crypto casino and sportsbook Duelbits had its hot wallets drained across Ethereum, BNB Chain, Tron, Solana and Bitcoin in under an hour. The team confirmed a loss of about $7,000,000 and took the site offline. Security firms assessed the incident as a hot-wallet private-key compromise, not a smart-contract exploit. The attacker then bridged and swapped most of the stolen assets into ETH and consolidated them in one address. Duelbits said user balances were unaffected, relaunched on September 27 with about $8,000,000 across hot and cold wallets for payouts, and no public recovery or freeze of the stolen funds has been reported.
Amount of loss: $ 7,000,000 Attack method: Private Key Leakage
Description of the event: Blockaid reported an ongoing exploit of Meter.io’s Meter Passport bridge on BNB Chain. An attacker minted a large amount of unbacked wrapped MTRG through the bridge and sold part of it on PancakeSwap. About $2,300,000 of unbacked wMTRG had been minted in roughly two transactions when the alert went out, and the attack was still ongoing.
Amount of loss: $ 2,300,000 Attack method: Smart Contract Vulnerability
Description of the event: Unauthorized transfers drained about $387.5 million from some of Bitget’s hot and warm wallets. The attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then issued fraudulent withdrawal commands that the wallet authorization process treated as legitimate. Private keys and cold wallets were not compromised. Customer balances remain covered by Bitget’s User Protection Fund.
Amount of loss: $ 387,500,000 Attack method: Third-party Security Product Exploit
Description of the event: Payy’s Ethereum bridge contract was exploited and fully drained, with about 1,832,149 USDC leaving the contract. Payy said the stolen funds were users’ non-custodial deposits to Payy Network / Payy Wallet, paused all transactions, and said it is working on fund retrieval and a root-cause analysis.
Amount of loss: $ 1,832,149 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a bug in Limit Break’s Payment Processor V2, abusing stale Magic Eden EVM marketplace approvals to steal blue-chip NFTs via zero-price “sales” and to drain WETH in reverse. V2 could not be paused, so Yuga Labs VP of Blockchain @0xQuit led a whitehat rescue that moved 23,155 NFTs worth over $5.7M to safety; about 660 WETH could not be recovered in time. Magic Eden and Limit Break later urged users to revoke V2/V3 approvals immediately.
Amount of loss: $ 2,800,000 Attack method: Smart Contract Vulnerability