68 hack event(s)
Description of the event: Ramon Recuero, co-founder of Kinto, a modular exchange platform in the Arbitrum ecosystem, tweeted about the recent attack, stating that the hacker exploited a vulnerability on Arbitrum that allowed unlimited minting of K tokens. The attacker minted 110,000 K and launched an attack targeting the Morpho Vault and a Uniswap v4 pool. The incident resulted in approximately $1.55 million in losses (ETH and USDC) and caused significant volatility in the price of the K token.
Amount of loss: $ 1,550,000 Attack method: Contract Vulnerability
Description of the event: On July 9, according to monitoring by MistTrack’s MistEye security system, the well-known decentralized trading platform GMX (@GMX_IO) suffered an attack, resulting in asset losses exceeding $42 million. Analysis indicates that the core of this attack lies in the exploitation of two features: the use of leverage when the Keeper system executes orders, and the update mechanism where the global average price adjusts during shorting operations but does not update when closing short positions. Leveraging these mechanics, the attacker conducted a reentrancy attack to create large short positions, manipulating the global short average price and the size of the global short position. This, in turn, artificially inflated the price of GLP, which the attacker then redeemed for profit. Following negotiation, the attacker returned all stolen funds and received a $5 million bounty.
Amount of loss: $ 42,000,000 Attack method: Contract Vulnerability
Description of the event: On May 16th, Demex's lending market Nitron was exploited, resulting in a loss of $950,559 in user funds. According to Demex's post-incident analysis, the root cause of the exploit was a donation-based oracle manipulation attack targeting the deprecated dGLP vault.
Amount of loss: $ 950,559 Attack method: Price Manipulation
Description of the event: NUMA was attacked on the Arbitrum chain, resulting in a loss of approximately $530,000. The attacker swapped all assets to ETH, bridged them to Ethereum mainnet, and deposited the funds into Tornado Cash.
Amount of loss: $ 530,000 Attack method: Price Manipulation
Description of the event: According to Moby Post-Mortem Report, on January 8, an attacker took control of the Private Key used to authorize upgrades to Moby’s core contracts, compromising the protocol. This led to the exposure of 3.77 wBTC, 207.76 wETH, and 1,500,351.5 USDC in the sOLP and mOLP liquidity pools. Of the stolen funds, 1,470,091.74 USDC was recovered with the assistance of Seal911 team.
Amount of loss: $ 2,500,000 Attack method: Private Key Leakage
Description of the event: The Arbitrum-based liquidity management project Orange Finance suffered a $830,000 asset theft due to a misconfigured multi-sig. The attacker gained ownership of each vault, modified their implementations, and withdrew both the deposited assets and excessively approved funds. About 94% (roughly $780,000) of the total loss came from deposited assets, while the remaining 6% (around $47,000) resulted from excessive approvals.
Amount of loss: $ 830,000 Attack method: Private Key Leakage
Description of the event: The contract of Ramses Exchange on Arbitrum was attacked, resulting in a loss of approximately $93,000.
Amount of loss: $ 93,000 Attack method: Contract Vulnerability
Description of the event: Tapioca DAO experienced a significant security breach, with attackers obtaining relevant private keys through social engineering attacks and stealing approximately $4.7 million in cryptocurrency. On October 25, Tapioca DAO released an incident analysis report stating that the security breach occurred because attackers successfully compromised the private keys of a core contributor responsible for smart contract development. SEAL911 confirmed that the attackers were part of a North Korean hacking group that used a contagious interview attack method to inject malware onto the contributor's computer, thereby gaining access to the private keys of their address to carry out the theft.
Amount of loss: $ 4,700,000 Attack method: Malware Attack
Description of the event: DeFi project DeltaPrime has officially confirmed on platform X that a security incident occurred. DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M. This was due to a compromised private key.
Amount of loss: $ 5,980,000 Attack method: Private Key Leakage
Description of the event: According to on-chain detective ZachXBT, Sorta Finance is likely to conduct an exit scam on Arbitrum in the future, so do not use the protocol. This scammer has previously stolen over $25 million through scams such as Magnate, Kokomo, Lendora, Solfire, Crolend, and HashDAO.
Amount of loss: - Attack method: Scam
Description of the event: The arbitrum.com website appears to have been hacked and is being redirected to the official website of the Meme project MOG. Please stay vigilant and ensure the safety of your assets.
Amount of loss: - Attack method: DNS Attack
Description of the event: According to monitoring by the SlowMist security team, the MixedSwapRouter on Arbitrum was attacked, resulting in a loss of approximately 293,000 WINR, valued at around $16,000.
Amount of loss: $ 16,000 Attack method: Contract Vulnerability
Description of the event: The decentralized exchange Predy Finance on the Arbitrum chain was attacked, resulting in the loss of $464k worth of crypto assets from its lending pool.
Amount of loss: $ 464,000 Attack method: Contract Vulnerability
Description of the event: A hacker stole approximately $181,000 worth of crypto assets from Yield’s strategic contracts present on the Arbitrum blockchain. The hacker exploited a discrepancy between the pool token balance and total supply with flash-loaned assets and then withdrew extra pool tokens.
Amount of loss: $ 181,000 Attack method: Contract Vulnerability
Description of the event: Hedgey Finance suffered two exploits, one on the Ethereum and another on the Arbitrum network. The ETH attack resulted in a loss of $1.9 million, while the Arbitrum exploit led to a theft of $42.8 million in ARB tokens.
Amount of loss: $ 44,700,000 Attack method: Flash Loan Attack
Description of the event: Lava suffered a flash loan attack, resulting in approximately $340,000 in losses. All lending markets are reportedly paused as the investigation is ongoing.
Amount of loss: $ 340,000 Attack method: Flash Loan Attack
Description of the event: On March 20th, Dolomite, a decentralized trading protocol in the Arbitrum ecosystem, was attacked due to a vulnerability in its old contracts on the Ethereum mainnet. Approximately 187 victims suffered asset losses totaling $1.8 million, including 1,245,271 USDC, 94,423 DAI, and 165.9 WETH. As of March 24th, Dolomite has recovered 90% of the assets taken by the attacker.
Amount of loss: $ 1,800,000 Attack method: Contract Vulnerability
Description of the event: The DeFi project Mozaic was exploited, who stole approximately $2 million from the project. According to Mozaic, this individual was a Mozaic developer who had illegally obtained the private keys of a security module by compromising the data of a core team member. They also stated that about 90% of the stolen funds have now been frozen on MEXC.
Amount of loss: $ 2,000,000 Attack method: Insider Manipulation
Description of the event: The sPMM algorithm controlling the pricing of WOOFi trades on DEX WOOFi was exploited on Arbitrum. The exploit consisted of a sequence of flash loans that took advantage of low liquidity to manipulate the price of WOO in order to repay the flash loans at a cheaper price. The exploiter repeated this attack 3 times within a very short period of time, which netted about $8.75m in profits after returning the flash loans.
Amount of loss: $ 8,750,000 Attack method: Flash Loan Attack
Description of the event: The CEO of SocialFi xPET tweeted that SocialFi was attacked due to vulnerabilities related to the newly launched PvP feature, resulting in hackers stealing 91.5 ETH (approximately $25,400).
Amount of loss: $ 254,000 Attack method: Contract Vulnerability