2275 hack event(s)
Description of the event: Nostra, a DeFi lending protocol on Starknet, suffered an exploit after the NSTR oracle price was manipulated. An attacker used inflated NSTR as collateral to borrow about $3.5 million in ETH, STRK, USDC, USDT, WBTC and DAI from the money market. The market has been paused while the team traces funds; about $1.92 million has already been bridged to Ethereum, and the final loss and recoveries are not yet confirmed.
Amount of loss: $ 3,500,000 Attack method: Oracle Manipulation
Description of the event: The BonfireSwap router’s transfer lacked access control: it did not require msg.sender == from or check the caller’s allowance on from. An attacker set approved holders as from and themselves as to, drained TOKEN via existing victim→router allowances, then forwarded funds through a same-token pool swap. About 41 approved holders were hit; loss ~$50,000.
Amount of loss: $ 50,000 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome (legacy contracts of Flamingo Finance) was exploited due to unsafe asset accounting and valuation. The attacker flash-loaned ~$18M USDT, injected USDP/3CRV LP into the Strategy (treating a permissionlessly injectable Convex BaseRewardPool balance as its own assets and overvaluing it via Curve’s get_virtual_price() in a depegged pool), inflated the VaultYUSDT share price, and redeemed real Aave aUSDT liquidity for ~$345.9K profit.
Amount of loss: $ 345,900 Attack method: Smart Contract Vulnerability
Description of the event: Startale’s ERC-7579 smart accounts on Ethereum were exploited. The attacker abused a transient-storage initialization flag in initializeAccount that persists for the entire transaction, allowing re-initialization with a malicious bootstrap in the same tx after factory deployment. This enabled draining ~330 pre-funded counterfactual accounts (no signatures or capital required) for a total of ~$2,876. The Soneium network itself was unaffected.
Amount of loss: $ 2,876 Attack method: Smart Contract Vulnerability
Description of the event: An attacker abused an OpenGSN meta-transaction auth flaw on Polygon HTLC contracts: open/execute accepted a spoofed from without a real user signature. Posing as liquidity wallet 0x24cb…6773, they used leftover near-unlimited ERC-20 allowances to lock 26,130.64171 USDC, 24,332.489269 USDT0 and 0.661117 USDC.e into HTLCs with attacker-chosen recipient and secretHash=sha256(1), then redeemed via a CREATE2 contract with secret=1. Single-tx loss was about $50,463.
Amount of loss: $ 50,463 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome’s legacy USDT strategy (VaultYUSDT) was exploited. The attacker took an ~$18 million USDT flash loan via Morpho, staked manipulated Curve USDP LP into the Strategy to inflate the vault share price, then redeemed aUSDT for about $345,900 in profit.4.
Amount of loss: $ 345,900 Attack method: Flash Loan Price Manipulation
Description of the event: An unidentified user’s Gnosis Safe wallet on Ethereum was drained of about $7,730,000. The attacker exploited an authorization bypass in a Router multicall function, used the victim Safe module to DelegateCall attacker-crafted data, injected aEthrsETH into a malicious Uniswap V4 hooked pool, then swapped and redeemed it as rsETH. Kelp later placed a 24-hour pause on an address that received the stolen rsETH.
Amount of loss: $ 7,730,000 Attack method: Smart Contract Vulnerability
Description of the event: On September 16, 2026, DCENT (formerly D'CENT) issued an urgent security alert stating that abnormal asset transfers had been detected in its mobile App Wallet (software wallet) and that an emergency investigation was underway. Initial findings indicate the issue is limited to the App Wallet, with no confirmed impact on hardware wallets themselves. Users holding assets in the App Wallet, or using the same mnemonic for both the App Wallet and a hardware wallet, are strongly advised to immediately transfer funds to a secure hardware wallet or other trusted address, and to remain vigilant against scams.
Amount of loss: $ 6,570,000 Attack method: Unknown
Description of the event: The attacker manipulated the Uniswap V4 pool spot price. SpiralHookV2.borrow() valued collateral using poolManager.getSlot0() without TWAP or price-change limits. The noSameBlockSwap guard (keyed by tx.origin) was bypassed via 6 different EOAs, allowing borrowing against inflated collateral in the same block as the pump, resulting in a loss of ~10.7 ETH.
Amount of loss: $ 26,800 Attack method: Price Manipulation
Description of the event: Long’s custodial bridge released 46.7928 WETH (about $118,000) from its Robinhood Chain vault after a third-party RPC fed the keeper fabricated Arc withdrawal events. No on-chain contract or key was breached. The team halted the keeper, rebuilt verification, and refilled the vault the same day from platform revenue. Users did not lose funds.
Amount of loss: $ 118,000 Attack method: Supply Chain Attack
Description of the event: Cross-chain protocol Chainflip was exploited on its TRON USDT integration. The attacker abused TRON memo handling by attaching a custom memo to a transaction already signed by validators, causing the system to treat the same deposit as a separate failed swap and issue a duplicate refund. The attack was repeated eight times over about 90 minutes, producing six unauthorized payouts totaling 736,442.17 USDT. A pending user swap of 115,654.41 USDT remains safely in the vault. The network is paused, a fix is ready, restart is expected as early as Monday, and affected users will be made whole.
Amount of loss: $ 736,442.17 Attack method: Protocol logic vulnerability
Description of the event: Users of ether.fi Liquid (liquidETH) lost ~15.45 ETH after an attacker exploited missing access control in AtomicQueue.solve() on the caller-supplied solver parameter. The attacker crafted a malicious AtomicRequest, forced already-approved victim addresses to act as solver, and drained funds via existing ERC-20 allowances with transferFrom. About 11 users were affected.
Amount of loss: $ 38130 Attack method: Smart Contract Vulnerability
Description of the event: Ethereum ERC-404 token OMNI404 (O404) derived NFT mint/burn counts from integer balanceOf/units diffs in _transfer(). Its transfer() treated values ≤50 as ERC-721 IDs but still moved a fixed 1e18 units. Using flash loans and Uniswap V3 exact-output swaps (transfer(recipient, 1/2/.../21)), the attacker received full-unit tokens while the pool booked wei-level amounts, draining about 2.4 WETH.
Amount of loss: $ 5,923 Attack method: Smart Contract Vulnerability
Description of the event: Attackers exploited ORBToken’s receive() function (which auto-granted max allowance) and ORBCore’s whitelist tax exemption. The addPoolAndSell function lacked a reentrancy guard, enabling repeated tax-free sells. Combined with burnLP destroying large amounts of ORB in the LP and a subsequent sync() to manipulate reserves, the attacker extracted about $32,610.72.
Amount of loss: $ 32,610.72 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a vulnerability in Symbiosis’ Bitcoin Bridge (BridgeV2) by abusing incorrect parsing of Bitcoin transaction data and negative fee settings, minting approximately 2622^{62}2^{62} unbacked syBTC (notional face value ~46.1 billion) across BSC, Ethereum and Rootstock within about four minutes, then sold ~4.39 WBTC on Ethereum’s Uniswap V4 for ~$336,000. The team immediately paused native BTC routes, isolated the affected component, evacuated ~15.2 BTC of portal funds to reserve addresses, and offered a 20% white-hat bounty. The post-mortem confirmed total losses for LPs and affected users at 9.97 BTC. Other routes (EVM, TRON, TON, etc.) remained unaffected.
Amount of loss: $ 775,000 Attack method: Smart Contract Vulnerability
Description of the event: Dominion Market’s Solana silver token $SILV suffered a treasury multisig compromise. With 3-of-5 keys, the attacker emptied the treasury and pulled SILV from loans, dumping about 46,909 tokens (face value ~$3 million) into thin DEX pools and realizing about $238,000 as the peg broke. The team pulled liquidity, rotated hardware, froze tokens bought in the incident window, and planned USDC refunds plus a repeg.
Amount of loss: $ 238,000 Attack method: Private Key Leakage
Description of the event: The old BNB Chain DeFi protocol Amnext (AMC), a no-loss lottery/prize-pool product, was exploited. The attacker mass-minted Ticket AMC and drained about 154.02 WBNB from the protocol via PancakeSwap, causing a loss of approximately $ 116,100.
Amount of loss: $ 116,100 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a bug in Nomic’s custom forwarding mechanism to double-spend nBTC and send unbacked vouchers to Osmosis. Osmosis and IBC themselves were not compromised. 39.84 nBTC of the minted supply sat in Alloyed BTC (~36% of its backing). Osmosis froze Nomic and Alloyed BTC flows, upgraded with validators, and froze 22.65 BTC in the attacker’s address. Governance will be asked to seize those funds and cover the rest from the community pool.
Amount of loss: $ 3,150,000 Attack method: Double-Spending Attack
Description of the event: On September 9, 2026, an attacker used a single transaction on Citrea mainnet and ~200,000 USDC.e of flash liquidity as temporary collateral to drain 140,000 ctUSD and 30 USDC.e from Zentra’s lending pool. The root cause was an accounting edge case in repayWithATokens: the debt path could complete while the matching aToken burn was reduced to zero. The operations multisig paused all markets about 17 minutes later; no second exploit occurred.
Amount of loss: $ 140,030 Attack method: Smart Contract Vulnerability
Description of the event: BeatXswap’s LiquidityVestingConvert used the Uniswap/Pancake V3 slot0() spot price as its only oracle, with no TWAP or deviation checks. An attacker flash-loaned 6,000,000 BTX, dumped it to crash the pool price, then called deposit() twice (10,000 + 2,000 USDT) to mint LP at the manipulated quote and drain 2,984,557 BTX (~$77,512).
Amount of loss: $ 77,512 Attack method: Price Manipulation