2289 hack event(s)
Description of the event: Crypto casino Duelbits’ multi-chain hot wallets (Ethereum, BSC, Tron and Bitcoin) suffered a suspected private key compromise, with about $4.9 million transferred to newly created addresses; most funds were swapped to ETH, and the site was taken offline for investigation.
Amount of loss: $ 4,900,000 Attack method: Private Key Leakage
Description of the event: Blockaid reported an ongoing exploit of Meter.io’s Meter Passport bridge on BNB Chain. An attacker minted a large amount of unbacked wrapped MTRG through the bridge and sold part of it on PancakeSwap. About $2,300,000 of unbacked wMTRG had been minted in roughly two transactions when the alert went out, and the attack was still ongoing.
Amount of loss: $ 2,300,000 Attack method: Smart Contract Vulnerability
Description of the event: The personal X account of Nano Labs founder Jack Kong was compromised. Attackers used it to promote a fake AI trading token called Binance World Assets ($BWA), claiming it would use trading fees on BNB Chain to trade bStocks and share profits with holders. Nano Labs’ official account later stated that the posts were unauthorized, that the company had not issued or endorsed any such token, and warned users not to click links or send funds to any contracts.
Amount of loss: - Attack method: The X account was hacked
Description of the event: The Drop project suffered an attack via a malicious governance proposal, through which the attacker transferred treasury funds, resulting in a loss of approximately $4.4 million.
Amount of loss: $ 4,400,000 Attack method: Governance Attack
Description of the event: Astroport (a Cosmos ecosystem DEX) announced a security incident on the Neutron chain that may have resulted in the theft of admin privileges for its contracts. Neutron has halted chain operations for investigation, and the project advised users to immediately withdraw liquidity from all Astroport pools across chains. Terra-side contracts were unaffected.
Amount of loss: $ 4,900,000 Attack method: Compromised administrator privileges
Description of the event: Internet Token DAO’s LiquidityUnifier on Base was exploited after it trusted a caller-supplied Uniswap V3 pool address. A fake pool callback minted about 925 million INT out of thin air. The attacker drained 5.847 WETH (about $16,033.55) from the official INT/WETH pool and kept about 764 million INT. The mint role was not revoked in time, copycat exploits inflated supply to about 156 billion, and the attacker submitted a governance proposal aiming to move treasury funds.
Amount of loss: $ 265,000 Attack method: Smart Contract Vulnerability
Description of the event: The RWC token on BNB Smart Chain was exploited with a flash loan. An unprotected burn function let the attacker destroy RWC sitting in the PancakeSwap RWC/USDT pair and call sync() to rewrite reserves, inflating the price before selling back. The pool lost about 109,460.85 USDT in one transaction. The attacker kept about 39,964.07 USDT; the remaining about 69,496.78 USDT was routed to the project’s company and platform wallets by the token’s fee logic.
Amount of loss: $ 109,460.85 Attack method: Smart Contract Vulnerability
Description of the event: The Polygon contract GaslessReservoirEnabler had an authorization flaw: erc20WithTransfersAndExecute → _executeInternal checked module addresses but did not bind ERC-20 transferFrom calls to an authorized asset owner. An attacker could therefore spend victims’ existing allowances on whitelisted tokens (WETH and ZED). About 997 token-holder addresses were drained for roughly $23,000. The proceeds were consolidated and deposited into a bridge on Polygon.
Amount of loss: $ 23,000 Attack method: Smart Contract Vulnerability
Description of the event: The dormant NFT platform DoinGud was exploited on Polygon via a bug in its Diamond bidding contract: acceptBid paid out but never cleared the bid record, so the same bid could be reused. An attacker flash-loaned USDC equal to the contract balance, bid on themselves, accepted the bid twice, and drained about $35,486 USDC.e on September 21, 2026.
Amount of loss: $ 35,486 Attack method: Smart Contract Vulnerability
Description of the event: Bitcoin Lightning wallet Blink Wallet paused services to investigate a security incident. The team said an attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds remain secure, and non-custodial wallets were not affected. The team is currently conducting an in-depth investigation and emergency response to this vulnerability. Further details of the investigation and recovery arrangements will be announced later.
Amount of loss: - Attack method: Unauthorized access to custodial accounts
Description of the event: An attacker attempted to exploit a virtual-machine-level atomicity issue on the MultiversX mainnet, causing invalid on-chain state changes. The network was paused to contain further impact. Engineers prepared a fix for validation on a shadow fork and are evaluating a targeted recovery that would keep finalized history and legitimate user state while reversing only incident-related invalid changes. Users were told not to submit or rebroadcast transactions and not to deposit or withdraw EGLD or ESDT via exchanges or bridges.
Amount of loss: - Attack method: VM-level atomicity vulnerability
Description of the event: An attacker used a leaked conversion-authorizer / bridge backend signing key to call conversionIn() on Fetch.ai’s Ethereum token-conversion contract and drain about 8,721,530 FET (~$1.53 million). The same wallet cluster then minted about 408.5 million unauthorized NTX via a NuNet deployer key and later expanded the attack to related ASI Alliance bridge/converter infrastructure.
Amount of loss: $ 1,530,000 Attack method: Private Key Leakage
Description of the event: An attacker gained control of NuNet’s Ethereum deployer/minting private key and called mint() on the NTX token contract, issuing 408,532,878.13 NTX to the attacker’s address. The mint function had no supply-cap check, so possession of the key was enough to create new tokens. PeckShield valued the unauthorized mint at approximately $462,730 at the time of the incident.
Amount of loss: $ 462,730 Attack method: Private Key Leakage
Description of the event: The BNB Chain DeFi protocol Likwid was exploited due to a margin-borrow contract bug. In the leverage=0 path of LikwidMarginPosition, pair reserves were not updated, so each borrow reused the same quote. The attacker first pumped a thin meme pool, then repeated the collateral/borrow cycle and drained 74.31 BNB (~$ 55,721) from the vault. The funds were later sent to Tornado Cash.
Amount of loss: $ 55,721 Attack method: Smart Contract Vulnerability
Description of the event: Nostra, a DeFi lending protocol on Starknet, suffered an exploit after the NSTR oracle price was manipulated. An attacker used inflated NSTR as collateral to borrow about $3.5 million in ETH, STRK, USDC, USDT, WBTC and DAI from the money market. The market has been paused while the team traces funds; about $1.92 million has already been bridged to Ethereum, and the final loss and recoveries are not yet confirmed.
Amount of loss: $ 3,500,000 Attack method: Oracle Manipulation
Description of the event: The BonfireSwap router’s transfer lacked access control: it did not require msg.sender == from or check the caller’s allowance on from. An attacker set approved holders as from and themselves as to, drained TOKEN via existing victim→router allowances, then forwarded funds through a same-token pool swap. About 41 approved holders were hit; loss ~$50,000.
Amount of loss: $ 50,000 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome (legacy contracts of Flamingo Finance) was exploited due to unsafe asset accounting and valuation. The attacker flash-loaned ~$18M USDT, injected USDP/3CRV LP into the Strategy (treating a permissionlessly injectable Convex BaseRewardPool balance as its own assets and overvaluing it via Curve’s get_virtual_price() in a depegged pool), inflated the VaultYUSDT share price, and redeemed real Aave aUSDT liquidity for ~$345.9K profit.
Amount of loss: $ 345,900 Attack method: Smart Contract Vulnerability
Description of the event: Startale’s ERC-7579 smart accounts on Ethereum were exploited. The attacker abused a transient-storage initialization flag in initializeAccount that persists for the entire transaction, allowing re-initialization with a malicious bootstrap in the same tx after factory deployment. This enabled draining ~330 pre-funded counterfactual accounts (no signatures or capital required) for a total of ~$2,876. The Soneium network itself was unaffected.
Amount of loss: $ 2,876 Attack method: Smart Contract Vulnerability
Description of the event: An attacker abused an OpenGSN meta-transaction auth flaw on Polygon HTLC contracts: open/execute accepted a spoofed from without a real user signature. Posing as liquidity wallet 0x24cb…6773, they used leftover near-unlimited ERC-20 allowances to lock 26,130.64171 USDC, 24,332.489269 USDT0 and 0.661117 USDC.e into HTLCs with attacker-chosen recipient and secretHash=sha256(1), then redeemed via a CREATE2 contract with secret=1. Single-tx loss was about $50,463.
Amount of loss: $ 50,463 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome’s legacy USDT strategy (VaultYUSDT) was exploited. The attacker took an ~$18 million USDT flash loan via Morpho, staked manipulated Curve USDP LP into the Strategy to inflate the vault share price, then redeemed aUSDT for about $345,900 in profit.4.
Amount of loss: $ 345,900 Attack method: Flash Loan Price Manipulation