2248 hack event(s)
Description of the event: DeFi protection protocol Cozy Finance on Optimism was exploited for about $160,000. The attacker first bought PTokens in the Aave v2 and Curve protection markets, then submitted undisputed YES answers to the UMA Optimistic Oracle. The trigger did not independently verify a real Aave/Curve hack, and PToken payout eligibility was not tied to a pre-proposal holder snapshot. After the markets moved to TRIGGERED, the attacker burned PTokens and claimed USDC.
Amount of loss: $160,000 Attack method: Smart Contract Vulnerability
Description of the event: Purported white-hat attackers exploited a bug in Elements (Liquid’s underlying software) to create about 4,000 unbacked L-BTC, then used SideSwap’s normal peg-out flow to withdraw ~4,000 BTC (~$320 million) from the Liquid Federation wallet. No keys were compromised. The sidechain has been paused.
Amount of loss: $ 320,000,000 Attack method: Elements Software Vulnerability
Description of the event: An attacker exploited a dormant, illiquid perpetual market on Rocket. Using a burner account, they posted orders at artificially inflated prices and traded against themselves to generate fake profits on one account while bankrupting the burner. The profitable account then withdrew approximately $287K in positive PnL from the Bridge, with the loss socialized across the platform. Deposits, withdrawals and trading were paused.
Amount of loss: $ 287,000 Attack method: Price Manipulation
Description of the event: Secured Finance’s Ethereum lending market was drained after attackers used flash loans and self-trades to manipulate the current-block order-book average price, inflating fake lend positions into valid collateral. About $104,000 was extracted. The original attacker’s large WBTC attempt reverted for insufficient gas; a frontrunner then took ~0.9 WBTC.
Amount of loss: $ 104,000 Attack method: Price Manipulation
Description of the event: Reddio’s RedSonic Vault on Ethereum was exploited for about 9.25 ETH (~$22,940). After permissionlessly registering an stETH vault, the same stETH was counted in both the ETH vault and the stETH vault. The attacker used a flash loan to inflate the rsvETH share price, redeemed excess ETH, then redeemed rsvstETH to recover the same stETH.
Amount of loss: $ 22,940 Attack method: Smart Contract Vulnerability
Description of the event: Dream Health Chain’s staking/reward contracts on BSC were exploited for about 71,851 USDT. A broken award state machine allowed a claimed reward to be reset with a tiny or zero-effective DHC deposit, so the same fixed payout could be claimed repeatedly from the shared pool. The attacker looped pledge and claim, then sold about 542,070 DHC into the DHC-USDT pool.
Amount of loss: $ 71,851 Attack method: Smart Contract Vulnerability
Description of the event: Notional Finance’s legacy V1 Escrow contract was exploited. The attacker abused an unsafe uint128 cast in free-collateral valuation so that a fabricated liability of about 2^128 truncated to zero, bypassing solvency checks, minting fake fCash claims, and withdrawing about 69,257.37 DAI and 1,658,524.86 USDC (~$1.73M). The funds were swapped into roughly 689.2 ETH and deposited into Tornado Cash. The team paused the affected contract, said other user assets were not at risk, and is pursuing recovery.
Amount of loss: $ 1,730,000 Attack method: Smart Contract Vulnerability
Description of the event: The GebProxyActions contract was exploited due to missing caller access control in the quitSystem function. Victims had previously called it directly instead of via DSProxy delegatecall, setting ownsSAFE[safe] to the GebProxyActions contract. The attacker called GebProxyActions.quitSystem(manager, safe, dst) directly, bypassing GebSafeManager’s safeAllowed check and transferring collateral to themselves.
Amount of loss: $ 14,000 Attack method: Smart Contract Vulnerability
Description of the event: Solana-based proprietary AMM Aquifer was exploited for about $2.5 million. Public reporting points to compromised protocol-linked wallets or admin credentials rather than a confirmed smart-contract bug. The attacker operated addresses on both Solana and Ethereum. The same day, Aquifer’s Solana upgrade authority posted an on-chain white-hat offer: return at least 80% of stolen assets by September 3, 2026, 14:00 UTC to designated recovery addresses, and keep up to 20% as a bounty, in exchange for no civil claims by the project.
Amount of loss: $ 2,500,000 Attack method: Wallet Credential Compromise
Description of the event: An attacker exploited a vulnerability in Ankr’s ankrFLOW liquid staking contract to mint approximately 8.6 million unbacked ankrFLOW tokens, then used them as collateral with More Markets’ E-mode to drain about 15.5 million WFLOW (~$410,000 at spot) from the lending reserve. The attacker realized roughly $246,000 after slippage. The Flow Foundation stated the root cause was in Ankr’s Solidity contract, not Flow EVM or More Markets.
Amount of loss: $ 410,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker used a flash loan to execute large swaps on a Uniswap V3 pool and manipulate the spot price (slot0). This caused Float Protocol’s Hypervisor contracts to misprice LP shares. Because critical functions lacked TWAP/oracle validation and slippage protection, the attacker repeatedly deposited and withdrew at inflated share values, extracting about $28,000 (10.71 ETH).
Amount of loss: $ 28,000 Attack method: Flash Loan Price Manipulation
Description of the event: An attacker exploited a rounding/precision vulnerability in legacy Balancer V1 contracts. Using flash loans to compress WBTC reserves to near-zero, they minted a large amount of BPT with only 1 satoshi of WBTC and then proportionally exited to drain DPI, USDC, WETH and WBTC from the pool.
Amount of loss: $ 234,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker inflated the price of the thinly traded TONIC governance token by about 100x in roughly 20 minutes and used it as collateral to borrow high-value assets from Tectonic (a Mango Markets-style price manipulation attack). Cronos halted the chain and later rolled it back to contain most of the damage.
Amount of loss: $ 75,000,000 Attack method: Price Manipulation
Description of the event: An attacker exploited a vulnerability in Switchboard’s production code to add a controlled key to a live oracle, published false prices roughly 100 times below market, deposited into Full Sail vaults at distorted values, then restored prices and withdrew more than deposited.
Amount of loss: $ 91,000 Attack method: Oracle Manipulation
Description of the event: The Fogo Foundation experienced a compromise by an unknown actor, resulting in 400 million FOGO tokens being sent to a bad actor. The Foundation immediately alerted exchanges, law enforcement, and forensic experts. Initially stated no impact on the blockchain, but later halted the mainnet as a precaution to restrict associated addresses and prevent further asset movement. Mainnet was later restarted after recovering and permanently removing 237 million tokens.
Amount of loss: $ 3,000,000 Attack method: Private Key Compromised
Description of the event: Attackers exploited a vulnerability in an outdated version of Rain’s Solana card contract used by Avici (and a few other programs). By submitting crafted signature bundles to gain unauthorized admin rights via AddCollateralAdmin and then withdrawing collateral, they drained $500,859.22 from 1,685 users’ card balances. Self-custodial wallets were unaffected. The contract was upgraded across all programs, and full refunds were promised.
Amount of loss: $ 500,859.22 Attack method: Smart Contract Vulnerability
Description of the event: Base-based DeFi lending protocol Moonwell was attacked. The attacker inflated the price of the low-liquidity token MAMO, posted it as collateral, and borrowed real assets such as cbBTC and USDC from markets including mCBTC and mUSDC. Blockaid first reported about 50.6 cbBTC (over $4,000,000) drained, later updating observed outflows to about $8,790,000.
Amount of loss: $ 8,790,000 Attack method: Price Manipulation
Description of the event: FH Token on the BSC chain was exploited in its FH/USDT liquidity pool on PancakeSwap V2. A flaw in the token’s _transfer function and isSell logic caused incorrect token burns during sells, allowing the attacker to drain funds from the pool through repeated buy-and-sell loops, resulting in a loss of approximately $20,000.
Amount of loss: $ 20,000 Attack method: Smart Contract Vulnerability
Description of the event: The BLND-USDC liquidity pool of CometDEX (Comet AMM) on the Stellar network was exploited due to an accounting bug that allowed same-asset swaps (USDC→USDC), corrupting reserve calculations. The attacker used flash loans from a Blend pool and repeated the process about 36 times to extract excess funds, resulting in a loss of approximately $717,518.92 USDC. Funds were subsequently moved.
Amount of loss: $ 717,518.92 Attack method: Smart Contract Vulnerability
Description of the event: Enjin’s legacy ERC-1155 Crypto Items platform on Ethereum was exploited. The attacker used a storage-layout mismatch in delegate-call adapters plus an unprotected initialize function to take over the Managed Delegate Proxy via DELEGATECALL. After gaining manager privileges, they registered a malicious adapter, transferred NFTs from about 52 wallets without approval, and melted them to redeem the backing ENJ from the reserve, draining approximately 5.24 million ENJ .
Amount of loss: $ 162,000 Attack method: Smart Contract Vulnerability