2261 hack event(s)
Description of the event: An attacker exploited a rounding/precision vulnerability in legacy Balancer V1 contracts. Using flash loans to compress WBTC reserves to near-zero, they minted a large amount of BPT with only 1 satoshi of WBTC and then proportionally exited to drain DPI, USDC, WETH and WBTC from the pool.
Amount of loss: $ 234,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 30, 2026, an attacker looped borrowing and re-supplying Tectonic’s governance token TONIC as collateral while manipulating its price by ~195x, then borrowed about $120.4 million from multiple Tectonic lending markets in one transaction. Cronos halted and rolled back the chain, restoring on-chain assets to the pre-exploit state; approximately $9.19 million that left Cronos before the halt remains unrecovered. Supply and borrow remain paused.
Amount of loss: $ 120,400,000 Attack method: Price Manipulation
Description of the event: An attacker exploited a vulnerability in Switchboard’s production code to add a controlled key to a live oracle, published false prices roughly 100 times below market, deposited into Full Sail vaults at distorted values, then restored prices and withdrew more than deposited.
Amount of loss: $ 91,000 Attack method: Oracle Manipulation
Description of the event: The Fogo Foundation experienced a compromise by an unknown actor, resulting in 400 million FOGO tokens being sent to a bad actor. The Foundation immediately alerted exchanges, law enforcement, and forensic experts. Initially stated no impact on the blockchain, but later halted the mainnet as a precaution to restrict associated addresses and prevent further asset movement. Mainnet was later restarted after recovering and permanently removing 237 million tokens.
Amount of loss: $ 3,000,000 Attack method: Private Key Compromised
Description of the event: Attackers exploited a vulnerability in an outdated version of Rain’s Solana card contract used by Avici (and a few other programs). By submitting crafted signature bundles to gain unauthorized admin rights via AddCollateralAdmin and then withdrawing collateral, they drained $500,859.22 from 1,685 users’ card balances. Self-custodial wallets were unaffected. The contract was upgraded across all programs, and full refunds were promised.
Amount of loss: $ 500,859.22 Attack method: Smart Contract Vulnerability
Description of the event: Base-based DeFi lending protocol Moonwell was attacked. The attacker inflated the price of the low-liquidity token MAMO, posted it as collateral, and borrowed real assets such as cbBTC and USDC from markets including mCBTC and mUSDC.
Amount of loss: $ 8,700,000 Attack method: Price Manipulation
Description of the event: CashCowCoin’s unverified trading router implementation contract had a flawed sell() flow. After the PancakeSwap Router completed the CCC→WBNB swap, the proxy called a privileged token function to transfer post-tax CCC from the Pair to the dead address and invoked Pair.sync(). This burned the sell-side CCC while permanently retaining the reduced WBNB reserve, enabling repeated draining of the pool’s WBNB through about 80 iterative sell cycles.
Amount of loss: $ 117,400 Attack method: Smart Contract Vulnerability
Description of the event: FH Token on the BSC chain was exploited in its FH/USDT liquidity pool on PancakeSwap V2. A flaw in the token’s _transfer function and isSell logic caused incorrect token burns during sells, allowing the attacker to drain funds from the pool through repeated buy-and-sell loops, resulting in a loss of approximately $20,000.
Amount of loss: $ 20,000 Attack method: Smart Contract Vulnerability
Description of the event: The BLND-USDC liquidity pool of CometDEX (Comet AMM) on the Stellar network was exploited due to an accounting bug that allowed same-asset swaps (USDC→USDC), corrupting reserve calculations. The attacker used flash loans from a Blend pool and repeated the process about 36 times to extract excess funds, resulting in a loss of approximately $717,518.92 USDC. Funds were subsequently moved.
Amount of loss: $ 717,518.92 Attack method: Smart Contract Vulnerability
Description of the event: Enjin’s legacy ERC-1155 Crypto Items platform on Ethereum was exploited. The attacker used a storage-layout mismatch in delegate-call adapters plus an unprotected initialize function to take over the Managed Delegate Proxy via DELEGATECALL. After gaining manager privileges, they registered a malicious adapter, transferred NFTs from about 52 wallets without approval, and melted them to redeem the backing ENJ from the reserve, draining approximately 5.24 million ENJ .
Amount of loss: $ 162,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 23, 2026, Term Finance’s Strategy Vaults (Ethereum-based fixed-rate lending protocol by Term Labs) suffered a governance exploit. The attacker acquired majority voting power (100% on several USDC vaults, ~91% on the ETH Meta Vault), passed malicious proposals to disable the timelock and drain ~2,843 ETH and 1.68M USDC (later swapped to DAI), resulting in ~$8.5 million losses (about 68% of the vaults’ then-TVL).
Amount of loss: $ 8,500,000 Attack method: Governance Attack
Description of the event: On August 23, 2026, the Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was drained via Uniswap V3 spot-price manipulation. The attacker flash-loaned 1,800 WETH from Morpho Blue, skewed the pool’s instantaneous spot price, minted vault shares at the distorted valuation, restored the price, and burned the shares for a richer token mix, netting ≈2.94 WETH. Root cause: mint()/burn() valued the Uniswap V3 position off pool.slot0() with no TWAP or deviation guard (TWAP only protected rebalance()).
Amount of loss: $ 7,018 Attack method: Flashloan Price Manipulation
Description of the event: The ERC-20 bridge of warp.green (a cross-chain messaging protocol between Chia and EVM chains) suffered an exploit due to a vulnerability in the Chia-side Chialisp puzzle. The attacker minted worthless CAT tokens, presented them as burned wUSDC, obtained validator signatures, and drained ~$93,000 USDC from the Base and Ethereum bridge contracts, later converting the funds to ETH. The CAT bridge (securing assets like wXCH) appears unaffected.
Amount of loss: $ 93,000 Attack method: Smart Contract Vulnerability
Description of the event: Layer 1 blockchain TAC was exploited when an attacker used a vulnerability in the shared Cosmos EVM precompile layer to drain approximately 2.985 billion TAC tokens (valued at around $7.5 million) from a single account. The project confirmed it was a drain (not a mint), total supply unchanged, only $TAC affected, and the flaw is not in TAC-specific code. The chain was halted at block 24,671,475; the team is coordinating with SEAL 911 and exchanges to track funds and plans to release a post-mortem and relaunch plan.
Amount of loss: $ 7,500,000 Attack method: Contract Vulnerability
Description of the event: An attacker exploited vulnerabilities in the shared Cosmos EVM module (an arithmetic underflow in the staking precompile’s balance write-back after delegation, combined with vesting account handling and other undisclosed bugs). By creating a vesting account and deploying a contract to it, the attacker repeated the technique 18 times, draining approximately 148.3 million KII from various wallets. KiiChain halted the network at block 9355723 to stop further theft.
Amount of loss: $ 9,700,000 Attack method: Smart Contract Vulnerability
Description of the event: The Sandbox’s SAND cross-chain bridge (LayerZero OFT on Base and BNB Chain) was exploited. The attacker used a configuration function to gain sole verifier rights, minting large amounts of unbacked SAND and draining approximately 14.74 million real SAND (~$675,000) from the Ethereum vault. The project quickly halted affected bridging; Ethereum and Polygon assets remained unaffected.
Amount of loss: $ 675,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited an unsigned integer underflow vulnerability in the upstream Cosmos EVM module to unauthorizedly transfer approximately 720.9 million MANTRA from two MANTRA-managed addresses (the burn address and a dormant genesis-era multisig). The chain was halted to contain the threat and later resumed after a v8.4.0 patch. No validator keys, admin privileges, or user funds were compromised.
Amount of loss: $ 3,600,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 19, 2026, the cross-chain bridge Allbridge was attacked. The attacker had prepared on July 26 by calling Circle’s MessageTransmitterV2.sendMessage on Polygon to forge a CCTP-style message claiming a 1M USDC transfer (with no actual burn) and obtained a valid attestation. On Aug 19, after a real CCTP deposit brought the Base Router balance to ~191k USDC, the attacker used the forged message via receiveCctpMessage (which lacked proper verification and credited it as a real deposit), flash-loaned ~809k USDC from Aave to match the claimed amount, and withdrew ~999k USDC, netting ~$189,800.
Amount of loss: $ 190,000 Attack method: Bridge Logic Flaw
Description of the event: An attacker exploited a protocol-level authorization flaw in the Evmos stack, transferring approximately 286.5 million BB from nine mainnet accounts across 14 transactions without the owners’ authorization. No private keys were compromised, no signatures forged, and no wallets breached. BounceBit permanently sunset the L1 chain and reissued BB as a BEP-20 token on BNB Chain based on a pre-attack snapshot.
Amount of loss: $ 3,000,000 Attack method: Smart Contract Vulnerability
Description of the event: Maya Protocol (MAYAChain) suffered a security vulnerability attack. The attacker exploited 6 chained edge-case bugs in Trade Account, outbound handling, and pool math, inflating accounting via false subsidy (e.g., ARB.LINK pool), then added/removed liquidity to extract ~48.87M CACAO and convert to ~20.83 BTC plus other assets, causing ~$1.7 million loss. The team paused global operations to fix the issues and seeks fund recovery.
Amount of loss: $ 1,700,000 Attack method: Smart Contract Vulnerability