83 hack event(s)
Description of the event: On August 19, 2026, the cross-chain bridge Allbridge was attacked. The attacker had prepared on July 26 by calling Circle’s MessageTransmitterV2.sendMessage on Polygon to forge a CCTP-style message claiming a 1M USDC transfer (with no actual burn) and obtained a valid attestation. On Aug 19, after a real CCTP deposit brought the Base Router balance to ~191k USDC, the attacker used the forged message via receiveCctpMessage (which lacked proper verification and credited it as a real deposit), flash-loaned ~809k USDC from Aave to match the claimed amount, and withdrew ~999k USDC, netting ~$189,800.
Amount of loss: $ 190,000 Attack method: Bridge Logic Flaw
Description of the event: On August 9, 2026, the cross-chain bridge connecting the XRP Ledger and Coreum (now tx) was exploited. The attacker abused a flaw in the deposit-verification/relayer logic by creating fake deposits (self-transfers of the bridge’s own wrapped tokens with valid memos), tricking the relayers into authorizing real XRP withdrawals from the bridge’s reserve. Nearly 200,000 XRP (~$200,000) was drained in 94 multisig transactions over 97 minutes.
Amount of loss: $ 200,000 Attack method: Bridge Logic Vulnerability
Description of the event: ChainConnect’s EVM integration was compromised through unauthorized access. Approximately $650,000 in tokens was drained from the bridge contracts across Ethereum, BNB Chain, Avalanche C-Chain and Polygon in 23 transactions; bridge operations were paused immediately.
Amount of loss: $ 650,000 Attack method: Unauthorized Access
Description of the event: Security firm Blockaid detected an ongoing exploit targeting Garden Finance’s HTLC contracts, draining about $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Chain. The project stated that an independent solver’s off-chain database was compromised and fraudulent records were inserted, causing improper fund releases; the protocol and smart contracts themselves were not compromised, and the app has been temporarily taken offline.
Amount of loss: $ 450,000 Attack method: Supply Chain Attack
Description of the event: The Verus Ethereum Bridge was exploited again. The attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, draining approximately $7.54 million in assets (ETH, tBTC, USDC, etc.) from the bridge reserves. This is the second exploit of the same flaw from May. The project has not issued a detailed official statement yet.
Amount of loss: $ 7,540,000 Attack method: Smart Contract Vulnerability
Description of the event: The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for ETH. Arbitrum’s native bridge was unaffected, and AFX’s core trading infrastructure remained secure. The team suspended bridge operations and is investigating with security partners.
Amount of loss: $ 24,150,000 Attack method: Private Key Leakage
Description of the event: Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspended the bridge; Midnight’s core network was unaffected. Multiple exchanges froze related funds, and NIGHT price dropped sharply before partial recovery.
Amount of loss: $10,000,000 Attack method: Smart Contract Vulnerability
Description of the event: Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $1.65 million. The team paused the protocol, urged affected LPs to withdraw funds immediately, and asked arbitrage profiteers to return funds for LP compensation.
Amount of loss: $ 1,650,000 Attack method: Flash Loan Price Manipulation
Description of the event: Cross-chain bridge protocol Across was attacked on its Solana deployment on July 17, 2026. The attacker exploited a gap in Solana’s event system to spoof deposit signals, tricking relayers into paying out on fake deposits. User funds remained completely safe with zero losses; all transactions were completed or fully refunded. Losses were contained to the Risk Labs-operated relayer. The team paused Solana deposits and restored operations the next day, with a full post-mortem planned.
Amount of loss: 0 Attack method: Deposit signal spoofing
Description of the event: The cross-chain bridge protocol TeleSwap was suspected of being exploited on July 15, 2026. Suspicious outflows of over $735,000 occurred from its Bitcoin hot wallet, which then stopped processing transactions. Five days later, the project has still not publicly disclosed the incident, and the attacker has moved funds toward Tornado Cash for laundering.
Amount of loss: $ 735,000 Attack method: Unknown
Description of the event: On June 21-22, 2026, Taiko (an Ethereum L2) suffered a bridge exploit targeting its ERC20 Vault. Attackers exploited a compromise in the chain state verification mechanism by forging SGX proofs to register a malicious prover, bypassing verification to submit fake bridge messages and drain approximately $1.7 million in assets (including USDC, ETH, and TAIKO tokens). Taiko quickly confirmed the verification compromise, paused the bridge and block production, initially urged users to withdraw funds, and later contained the incident while coordinating with exchanges to freeze attacker assets. A full post-mortem is forthcoming.
Amount of loss: $ 1,700,000 Attack method: Private Key Leakage
Description of the event: On June 17, 2026, attackers exploited Aztec’s deprecated Private Rollup Bridge (launched in 2021 and shut down in 2022). They abused an immutable escape-hatch function that lacked proper ownership checks, using manipulated or fake rollup proofs to withdraw assets without corresponding deposits. Approximately $2.16 million (1,158 ETH, 150,000 DAI, and 0.47 renBTC) was drained. Aztec Labs confirmed the affected contract is unrelated to the current Aztec Network or the AZTEC ERC-20 token and that they have no control over the immutable old contracts.
Amount of loss: $ 2,160,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a vulnerability in Secret Network’s modified CW20-ICS20 contract used for the Axelar IBC bridge. By creating a fake Cosmos chain and sending forged IBC deposit packets (the contract had critical source-channel verification checks commented out), the attacker minted approximately $4.67 million in unbacked “saTokens” (Secret-wrapped versions of Axelar-bridged assets). These were redeemed through the legitimate bridge channel, draining real assets from Axelar’s escrow in about 18 minutes. Funds were then bridged out via Osmosis to Ethereum and mostly cashed out on exchanges. The incident was detected on June 17 and publicly disclosed on June 19. Axelar paused the Secret bridge routes; its core protocol and other chains were unaffected. No funds have been recovered.
Amount of loss: $ 4,670,000 Attack method: Smart Contract Vulnerability
Description of the event: Syscoin Bridge was exploited. The attacker leveraged a validation issue in the bridge flow, resulting in an unauthorized creation of approximately 5 billion SYS on the UTXO side. The funds were subsequently moved and split. The team has paused the bridge, is actively tracing the tainted outputs, coordinating with exchanges for blacklisting/monitoring, and working on a fix and remediation.
Amount of loss: $ 10,000,000 Attack method: Bridge Verification Flaw
Description of the event: Alephium TokenBridge was exploited. The attacker used a backend vulnerability in the bridge to forge messages, draining approximately $815K assets from Ethereum and BNB Chain within about 7 minutes, while minting a large amount of unbacked wrapped ALPH. The team quickly shut down the bridge, pledged to compensate users, and advised users to withdraw ALPH liquidity.
Amount of loss: $ 815,000 Attack method: Off-Chain Vulnerability in the Bridge Backend
Description of the event: Gravity Bridge, a cross-chain bridge connecting Ethereum and the Cosmos ecosystem, was exploited likely due to a compromised contract key or signing authorization. The attacker drained approximately $5.4M in assets (primarily USDC, ETH, and USDT). The exploiter has begun laundering funds via exchanges and mixers, with a significant portion (~2,102 ETH) still under their control.
Amount of loss: $ 5,400,000 Attack method: Private Key Leakage
Description of the event: The Butter Bridge V3.1 (part of MAP Protocol and Butter Network) was exploited. An attacker used a vulnerability in the OmniServiceProxy contract’s retry message verification logic, specifically an abi.encodePacked hash collision with dynamic-bytes fields. This allowed forging a cross-chain retry message that bypassed authentication, resulting in the minting of approximately 1 quadrillion (10^15) MAPO tokens (about 4.8 million times the legitimate ~208 million circulating supply). The attacker dumped ~1 billion fake MAPO into the Uniswap V4 ETH/MAPO pool, extracting roughly $180,000 in liquidity (≈52.21 ETH). The teams immediately paused the bridge and related swaps. User funds in pending swaps are safe, and a patch/audit/redeployment is in progress. The remaining ~999 trillion fake tokens stay in the attacker’s wallet, posing ongoing dilution risk.
Amount of loss: $ 180,000 Attack method: Smart Contract Vulnerability
Description of the event: Blockaid detected an ongoing exploit on the Verus-Ethereum Bridge. The attacker drained approximately $11.58 million in assets (including ~1,625 ETH, ~103.6 tBTC, and ~147k USDC). The funds were swapped and consolidated into a drainer wallet (e.g., 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9). This is a cross-chain bridge incident affecting the bridge infrastructure, not the core Verus blockchain. The project had recently issued an urgent update, but the exploit still occurred. Funds remain in the attacker's control as of the latest reports. On May 22, PeckShield's monitoring revealed that the exploiter of the Verus cross-chain bridge has returned 4,052.4 ETH (valued at around $8.5 million) to the team's designated address. This recovery accounts for 75% of the total plundered funds, while the remaining 25% (approximately 1,350 ETH) is being retained in the hacker's wallet as a bug bounty.
Amount of loss: $ 11,580,000 Attack method: Smart Contract Vulnerability
Description of the event: Adshares Bridge was exploited on Ethereum around May 15, 2026. The attacker used the bridge-minter EOA to sign three wrapTo() calls with non-existent native-chain transaction IDs on the Adshares canonical chain. This allowed minting large amounts of fake wrapped ADS (wADS: 99,999.93 ×2 + 999,999.94). The fake tokens were then dumped via Uniswap V4 UniversalRouter, draining roughly $628K in ETH and USDC from liquidity pools. Security researchers flagged it quickly, and the project posted an on-chain whitehat message offering a 10% bounty for return of 90% of funds.
Amount of loss: $ 628,000 Attack method: Bridge Verification Bypass
Description of the event: Decentralized cross-chain aggregation protocol Transit Finance suffered an exploit on its deprecated (2022-era) TRON smart contract, resulting in approximately $1.88 million in DAI being drained. The stolen funds were transferred to an Ethereum address. The team confirmed it was isolated to legacy code, stated that current contracts are secure, completed remediation on May 12, and promised full user compensation. They sent an on-chain message to the attacker offering a bug bounty for return within 48 hours, or they would pursue legal action.
Amount of loss: $ 1,880,000 Attack method: Smart Contract Vulnerability