96 hack event(s)
Description of the event: An attacker exploited vulnerabilities in the shared Cosmos EVM module (an arithmetic underflow in the staking precompile’s balance write-back after delegation, combined with vesting account handling and other undisclosed bugs). By creating a vesting account and deploying a contract to it, the attacker repeated the technique 18 times, draining approximately 148.3 million KII from various wallets. KiiChain halted the network at block 9355723 to stop further theft.
Amount of loss: $ 9,700,000 Attack method: Smart Contract Vulnerability
Description of the event: Layer 1 blockchain TAC was exploited when an attacker used a vulnerability in the shared Cosmos EVM precompile layer to drain approximately 2.985 billion TAC tokens (valued at around $7.5 million) from a single account. The project confirmed it was a drain (not a mint), total supply unchanged, only $TAC affected, and the flaw is not in TAC-specific code. The chain was halted at block 24,671,475; the team is coordinating with SEAL 911 and exchanges to track funds and plans to release a post-mortem and relaunch plan.
Amount of loss: $ 7,500,000 Attack method: Contract Vulnerability
Description of the event: An attacker exploited an unsigned integer underflow vulnerability in the upstream Cosmos EVM module to unauthorizedly transfer approximately 720.9 million MANTRA from two MANTRA-managed addresses (the burn address and a dormant genesis-era multisig). The chain was halted to contain the threat and later resumed after a v8.4.0 patch. No validator keys, admin privileges, or user funds were compromised.
Amount of loss: $ 3,600,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a protocol-level authorization flaw in the Evmos stack, transferring approximately 286.5 million BB from nine mainnet accounts across 14 transactions without the owners’ authorization. No private keys were compromised, no signatures forged, and no wallets breached. BounceBit permanently sunset the L1 chain and reissued BB as a BEP-20 token on BNB Chain based on a pre-attack snapshot.
Amount of loss: $ 3,000,000 Attack method: Smart Contract Vulnerability
Description of the event: The Harmony Layer-1 blockchain was exploited, allowing an attacker to unauthorizedly mint approximately 4 billion ONE tokens (about 26% of the supply) via empty blocks and related flaws. Large amounts were quickly funneled to exchanges for sale, causing the token price to crash ~30-40%. The team confirmed the incident, paused the cross-chain bridge, released an emergency validator patch to stop further minting, coordinated with exchanges to freeze funds, and is evaluating a chain rollback.
Amount of loss: $ 3,200,000 Attack method: Protocol Logic Vulnerability
Description of the event: Oraichain (AI Layer 1) suffered from a vulnerability in its EVM cross-chain transfer path, enabling unauthorized minting of ORAI tokens. The network has been halted since 04:00 UTC on August 9, 2026, with bridges, cross-chain routes, and public interfaces restricted. The exploit path has been identified and addressed; the team is working with partners and CEXs to limit fund movements and is preparing to burn the unauthorized minted balances and reconcile protocol states to restore the canonical ORAI supply.
Amount of loss: - Attack method: Cross-Chain Bridge Exploit
Description of the event: The KITE Foundation detected abnormal KITE token transfers on Ethereum mainnet, confirming that some wallet addresses had been compromised by hackers. The team urgently paused ERC-20 transfers and related cross-chain channels, with no asset losses to users or the project. A new contract was later deployed, airdropping new tokens 1:1 to legitimate addresses based on the snapshot at block 25,692,498, excluding attacker-controlled addresses.
Amount of loss: 0 Attack method: Private Key Leakage
Description of the event: The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before being bridged out. The team has suspended bridges and related services while working with exchanges, security firms, and law enforcement to track the funds.
Amount of loss: $ 6,250,000 Attack method: Private Key Leakage
Description of the event: On June 19, 2026, approximately $600,000 in assets (ATOM, USDC, OSMO, TIA, NYM, etc.) were drained from Namada’s Multi-Asset Shielded Pool (MASP) through an IBC Transfer Logic Exploit. The loss initially went unnoticed because a stale indexer continued displaying funds as available, while live RPC queries showed zero balances on the chain. The attacker swept shielded IBC assets cross-chain. Namada confirmed the exploit and is investigating.
Amount of loss: $ 600,000 Attack method: Protocol Vulnerability
Description of the event: A spokesperson for Galaxy Digital disclosed that the company recently contained a cybersecurity incident. Unauthorized access was strictly limited to an isolated development and testing environment; production systems, trading platforms, and customer accounts remained unaffected. The company quickly detected and contained the intrusion. The affected area was a standalone R&D environment unrelated to core infrastructure, resulting in a loss of less than $10,000 in corporate testing funds. Following a review, it was confirmed that no customer funds or account information were accessed or at risk, and all platforms and services remain fully operational. Galaxy stated they will continue to review the incident and provide updates as appropriate.
Amount of loss: $ 10,000 Attack method: Unknown
Description of the event: Arbitrum has issued a security alert: The official X account for Arbitrum Governance (@arbitrumdao_gov) has been compromised. Do not click on any links posted by this account or engage with it. The team is working to restore access and will provide further updates soon.
Amount of loss: - Attack method: The X account was hacked
Description of the event: Solar, the official Solana Mandarin community, highly suspects its official X account (@Solana_zh) has been hacked. The team currently lacks access and is working urgently with X support to resolve the issue. Recovery time is TBD.
Amount of loss: - Attack method: Account Compromise
Description of the event: Scroll alerted on X that the X account of co-founder @shenhaichen has been compromised. They are actively working to recover the account and advise users not to interact with any links or direct messages.
Amount of loss: - Attack method: The X account was hacked
Description of the event: According to an official announcement from Saga, the SagaEVM chain has suffered an attack involving a series of malicious contract deployments, cross-chain operations, and liquidity withdrawals. The attacker transferred approximately $7 million worth of USDC, yUSD, ETH, and tBTC, which have since been consolidated into ETH and sent to the address 0x2044…6ecb. Following the incident, SagaEVM was halted at block height 6,593,800. The Saga team is currently working with exchanges and cross-chain bridge providers to block the attacker’s address. A comprehensive technical post-mortem will be released in due course. The Saga SSC mainnet and other chains remain unaffected.
Amount of loss: $ 7,000,000 Attack method: Smart Contract Vulnerability
Description of the event: The Flow Foundation announced that an attacker exploited a vulnerability in the Flow execution layer, transferring approximately $3.9 million in assets off the network before validators were able to coordinate and halt operations. The incident did not affect existing user balances, and all user deposits remain intact.
Amount of loss: $ 3,900,000 Attack method: Execution Layer Vulnerability
Description of the event: According to Arkham’s monitoring, an attacker allegedly carried out a deliberate exploit against HLP (Hyperliquidity Provider) on Hyperliquid. The attacker used 19 wallets and $3 million in principal to open a leveraged long position worth $20–30 million on POPCAT with 5× leverage, while placing large buy walls to support the price. Subsequently, the attacker suddenly removed the buy walls, causing a flash crash in POPCAT’s price and triggering the liquidation of their $3 million collateral to zero. Due to the lack of liquidity, HLP was forced to absorb the position, ultimately resulting in a bad debt loss of $4.9 million. Analyst @mlmabc noted that losing $3 million within seconds was not a mistake or negligence, but rather a deliberate attack targeting both HLP and Hyperliquid.
Amount of loss: $ 4,950,000 Attack method: Price Manipulation
Description of the event: Berachain announced that approximately USD 12.8 million in funds lost due to the BEX/Balancer v2 vulnerability have been fully returned to the Berachain Foundation’s deployer address, and the blockchain has now resumed normal operations.
Amount of loss: $ 12,800,000 Attack method: Contract Vulnerability
Description of the event: According to monitoring by Scam Sniffer, the official X account of Noble was compromised, and the attacker used it to post phishing tweets.
Amount of loss: - Attack method: Account Compromise
Description of the event: On October 1, BNB Chain officially announced that its English Twitter account had been compromised and was under emergency recovery, warning users not to click on any links.Subsequent investigation revealed that the incident involved a total of 10 phishing links, resulting in losses of approximately $8,000, with a single user losing as much as $6,500.The attacker deployed a phishing contract address, injected $17,800, and exchanged it for $22,000 worth of tokens. Following the incident, the team implemented additional security measures to prevent similar occurrences and further strengthened account protection.As of October 31, all user compensations related to this phishing incident have been completed, and transaction details are available on Etherscan. The root cause of the incident has been confirmed as phishing links, which have since been removed and brought under control.
Amount of loss: $ 8,000 Attack method: Phishing Attack
Description of the event: The official X account of @PlasmaFDN has been compromised. The attacker is posting phishing links using the X Bot UA spoofing trick—the URLs appear legitimate at first glance but redirect to a phishing site: https://vault-plasma[.]to. Do not click on any recent links or interact with the account until an official statement is released.
Amount of loss: - Attack method: Account Compromise