2292 hack event(s)
Description of the event: An attacker exploited Limit Break’s Payment Processor V2 on Ethereum by impersonating holders who had approved the contract as an NFT operator, buying those NFTs at a zero price. About $1.7 million in user-approved NFTs were drained across a few transactions while the attack was still ongoing. A whitehat rescued a portion of the assets and said they would be returned once no longer at risk.
Amount of loss: $ 1,700,000 Attack method: Smart Contract Vulnerability
Description of the event: Crypto casino Duelbits’ multi-chain hot wallets (Ethereum, BSC, Tron and Bitcoin) suffered a suspected private key compromise, with about $4.9 million transferred to newly created addresses; most funds were swapped to ETH, and the site was taken offline for investigation.
Amount of loss: $ 4,900,000 Attack method: Private Key Leakage
Description of the event: Blockaid reported an ongoing exploit of Meter.io’s Meter Passport bridge on BNB Chain. An attacker minted a large amount of unbacked wrapped MTRG through the bridge and sold part of it on PancakeSwap. About $2,300,000 of unbacked wMTRG had been minted in roughly two transactions when the alert went out, and the attack was still ongoing.
Amount of loss: $ 2,300,000 Attack method: Smart Contract Vulnerability
Description of the event: At 18:31 UTC on September 24, 2026, Bitget detected unauthorized transfers from some hot and warm wallets, with about $351.6 million affected; cold wallets remained secure. Withdrawals were paused, and the exchange said its $464 million+ User Protection Fund covers the loss. Preliminary findings say attackers compromised a core wallet-backend system, spoofed transfer data, and triggered Bitget’s own authorization/signing process. A direct private-key leak has been ruled out.
Amount of loss: $ 351,600,000 Attack method: Internal System Compromise
Description of the event: Payy’s Ethereum bridge contract was exploited and fully drained, with about 1,832,149 USDC leaving the contract. Payy said the stolen funds were users’ non-custodial deposits to Payy Network / Payy Wallet, paused all transactions, and said it is working on fund retrieval and a root-cause analysis.
Amount of loss: $ 1,832,149 Attack method: Smart Contract Vulnerability
Description of the event: The personal X account of Nano Labs founder Jack Kong was compromised. Attackers used it to promote a fake AI trading token called Binance World Assets ($BWA), claiming it would use trading fees on BNB Chain to trade bStocks and share profits with holders. Nano Labs’ official account later stated that the posts were unauthorized, that the company had not issued or endorsed any such token, and warned users not to click links or send funds to any contracts.
Amount of loss: - Attack method: The X account was hacked
Description of the event: The Drop project suffered an attack via a malicious governance proposal, through which the attacker transferred treasury funds, resulting in a loss of approximately $4.4 million.
Amount of loss: $ 4,400,000 Attack method: Governance Attack
Description of the event: Astroport (a Cosmos ecosystem DEX) announced a security incident on the Neutron chain that may have resulted in the theft of admin privileges for its contracts. Neutron has halted chain operations for investigation, and the project advised users to immediately withdraw liquidity from all Astroport pools across chains. Terra-side contracts were unaffected.
Amount of loss: $ 4,900,000 Attack method: Compromised administrator privileges
Description of the event: Internet Token DAO’s LiquidityUnifier on Base was exploited after it trusted a caller-supplied Uniswap V3 pool address. A fake pool callback minted about 925 million INT out of thin air. The attacker drained 5.847 WETH (about $16,033.55) from the official INT/WETH pool and kept about 764 million INT. The mint role was not revoked in time, copycat exploits inflated supply to about 156 billion, and the attacker submitted a governance proposal aiming to move treasury funds.
Amount of loss: $ 265,000 Attack method: Smart Contract Vulnerability
Description of the event: The RWC token on BNB Smart Chain was exploited with a flash loan. An unprotected burn function let the attacker destroy RWC sitting in the PancakeSwap RWC/USDT pair and call sync() to rewrite reserves, inflating the price before selling back. The pool lost about 109,460.85 USDT in one transaction. The attacker kept about 39,964.07 USDT; the remaining about 69,496.78 USDT was routed to the project’s company and platform wallets by the token’s fee logic.
Amount of loss: $ 109,460.85 Attack method: Smart Contract Vulnerability
Description of the event: The Polygon contract GaslessReservoirEnabler had an authorization flaw: erc20WithTransfersAndExecute → _executeInternal checked module addresses but did not bind ERC-20 transferFrom calls to an authorized asset owner. An attacker could therefore spend victims’ existing allowances on whitelisted tokens (WETH and ZED). About 997 token-holder addresses were drained for roughly $23,000. The proceeds were consolidated and deposited into a bridge on Polygon.
Amount of loss: $ 23,000 Attack method: Smart Contract Vulnerability
Description of the event: The dormant NFT platform DoinGud was exploited on Polygon via a bug in its Diamond bidding contract: acceptBid paid out but never cleared the bid record, so the same bid could be reused. An attacker flash-loaned USDC equal to the contract balance, bid on themselves, accepted the bid twice, and drained about $35,486 USDC.e on September 21, 2026.
Amount of loss: $ 35,486 Attack method: Smart Contract Vulnerability
Description of the event: Bitcoin Lightning wallet Blink Wallet paused services to investigate a security incident. The team said an attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds remain secure, and non-custodial wallets were not affected. The team is currently conducting an in-depth investigation and emergency response to this vulnerability. Further details of the investigation and recovery arrangements will be announced later.
Amount of loss: - Attack method: Unauthorized access to custodial accounts
Description of the event: An attacker attempted to exploit a virtual-machine-level atomicity issue on the MultiversX mainnet, causing invalid on-chain state changes. The network was paused to contain further impact. Engineers prepared a fix for validation on a shadow fork and are evaluating a targeted recovery that would keep finalized history and legitimate user state while reversing only incident-related invalid changes. Users were told not to submit or rebroadcast transactions and not to deposit or withdraw EGLD or ESDT via exchanges or bridges.
Amount of loss: - Attack method: VM-level atomicity vulnerability
Description of the event: An attacker used a leaked conversion-authorizer / bridge backend signing key to call conversionIn() on Fetch.ai’s Ethereum token-conversion contract and drain about 8,721,530 FET (~$1.53 million). The same wallet cluster then minted about 408.5 million unauthorized NTX via a NuNet deployer key and later expanded the attack to related ASI Alliance bridge/converter infrastructure.
Amount of loss: $ 1,530,000 Attack method: Private Key Leakage
Description of the event: An attacker gained control of NuNet’s Ethereum deployer/minting private key and called mint() on the NTX token contract, issuing 408,532,878.13 NTX to the attacker’s address. The mint function had no supply-cap check, so possession of the key was enough to create new tokens. PeckShield valued the unauthorized mint at approximately $462,730 at the time of the incident.
Amount of loss: $ 462,730 Attack method: Private Key Leakage
Description of the event: The BNB Chain DeFi protocol Likwid was exploited due to a margin-borrow contract bug. In the leverage=0 path of LikwidMarginPosition, pair reserves were not updated, so each borrow reused the same quote. The attacker first pumped a thin meme pool, then repeated the collateral/borrow cycle and drained 74.31 BNB (~$ 55,721) from the vault. The funds were later sent to Tornado Cash.
Amount of loss: $ 55,721 Attack method: Smart Contract Vulnerability
Description of the event: Nostra, a DeFi lending protocol on Starknet, suffered an exploit after the NSTR oracle price was manipulated. An attacker used inflated NSTR as collateral to borrow about $3.5 million in ETH, STRK, USDC, USDT, WBTC and DAI from the money market. The market has been paused while the team traces funds; about $1.92 million has already been bridged to Ethereum, and the final loss and recoveries are not yet confirmed.
Amount of loss: $ 3,500,000 Attack method: Oracle Manipulation
Description of the event: The BonfireSwap router’s transfer lacked access control: it did not require msg.sender == from or check the caller’s allowance on from. An attacker set approved holders as from and themselves as to, drained TOKEN via existing victim→router allowances, then forwarded funds through a same-token pool swap. About 41 approved holders were hit; loss ~$50,000.
Amount of loss: $ 50,000 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome (legacy contracts of Flamingo Finance) was exploited due to unsafe asset accounting and valuation. The attacker flash-loaned ~$18M USDT, injected USDP/3CRV LP into the Strategy (treating a permissionlessly injectable Convex BaseRewardPool balance as its own assets and overvaluing it via Curve’s get_virtual_price() in a depegged pool), inflated the VaultYUSDT share price, and redeemed real Aave aUSDT liquidity for ~$345.9K profit.
Amount of loss: $ 345,900 Attack method: Smart Contract Vulnerability