2204 hack event(s)
Description of the event: Stake Nova suffered a loss of approximately $137,014, representing about 95% of user deposits. The root cause was an unchecked validation issue in the RedeemNovaSol() function, which led to a flash-loan exploit that drained the liquidity pool. The vulnerability has now been fixed, the dApp has been taken offline, and the website is currently under maintenance. The team is offering a 10% on-chain bounty to the attacker; otherwise, they stated they will continue to pursue accountability.
Amount of loss: $ 137,014 Attack method: Flash Loan Attack
Description of the event: The privacy gaming platform FOOMCASH was attacked on Base and Ethereum, resulting in a loss of 24,283,773,519,600 $FOOM (approximately $2.26 million). The vulnerability was caused by a misconfiguration of the verification key, which the attacker exploited to forge zkSNARK proofs and subsequently extract a massive amount of $FOOM from the compromised contracts.
Amount of loss: $ 2,260,000 Attack method: Smart Contract Vulnerability
Description of the event: The DeFi lending protocol Ploutos Money suffered an exploit due to a misconfigured price oracle (using Chainlink’s BTC/USD feed for USDC price), allowing an attacker to deposit minimal USDC collateral and borrow ~187.36 ETH, draining approximately $390K. The project’s website and social accounts were deleted shortly after, raising strong suspicions of an inside job or exit scam.
Amount of loss: $ 390,000 Attack method: Oracle Misconfiguration
Description of the event: the Holdstation team confirmed that its DeFAI Smart Wallet product suffered a supply chain attack targeting the application distribution infrastructure. This resulted in unauthorized transactions in some user wallets, with a confirmed loss of approximately $462,000 USDT. Smart contracts were not directly exploited. The team committed to 100% compensation for affected users and is reinforcing security measures.
Amount of loss: $ 462,000 Attack method: Supply Chain Attack
Description of the event: WLFI announced on X that USD1 experienced an organized attack this morning. The attackers reportedly compromised the accounts of several WLFI co-founders, paying influencers to spread FUD (Fear, Uncertainty, and Doubt) and heavily shorting $WLFI in an attempt to profit from artificially created market chaos. WLFI stated that the operation failed. Thanks to USD1’s robust minting and redemption mechanisms and its 100% 1:1 asset backing, USD1 remains stable and is currently trading near its par value. The team emphasized that no bad actors can shake their long-term commitment to USD1. Meanwhile, WLFI reminded users to obtain accurate information only through officially verified channels and to be wary of misleading content.
Amount of loss: - Attack method: Social Engineering
Description of the event: DGLD (Swiss physical gold-backed tokenized asset) was exploited due to a legacy edge case in the Ethereum contract’s transferFrom behavior. Attackers minted large amounts of unbacked fake DGLD on Base and dumped them on DEXes. The team promptly paused contracts, froze illicit tokens, and contained the incident. Physical gold was never at risk, all pre-exploit holders retained their backed tokens, with ~$250k economic impact mostly borne by the project.
Amount of loss: $ 250,000 Attack method: Smart Contract Vulnerability
Description of the event: Blend Pools V2 (specifically the YieldBlox DAO-managed lending pool on Stellar) was exploited. The attacker manipulated the price of the low-liquidity asset USTRY ~100x higher in a single trade on Stellar DEX (SDEX). This manipulated the Reflector oracle price feed. The attacker then deposited the overvalued USTRY as collateral into the Blend Pools V2 lending pool and borrowed approximately $10.2M–$10.97M worth of XLM and USDC. Stellar validators and Blockaid responded quickly, freezing a large portion (~48M XLM / ~$7.3M) of the funds. Most of the stolen assets were contained, though some USDC was bridged out.
Amount of loss: $ 10,200,000 Attack method: Oracle Manipulation Attack
Description of the event: The IoT-focused public chain IoTeX suffered a professional hacker attack caused by a private key compromise of the ioTube bridge’s Ethereum-side validator owner. This allowed the attacker to gain administrative privileges and illicitly extract assets from the token safe. According to the official confirmation on February 24, the incident resulted in approximately $4.4 million in asset losses (including USDC, USDT, IOTX, and WBTC). The hacker converted most of the stolen funds into roughly 2,183 ETH and bridged them to the Bitcoin network via THORChain (with approximately 66.6 BTC currently tracked). The IoTeX team has implemented security enhancements and address blacklisting via the v2.3.4 mainnet upgrade. They have also issued an on-chain ultimatum: the attacker can receive a 10% white-hat bounty (approx. $440,000) and be exempted from legal liability if the funds are returned within 48 hours. A compensation plan for affected users is currently being finalized.
Amount of loss: $ 4,400,000 Attack method: Private Key Leakage
Description of the event: Veil.Cash (a zk-SNARK privacy protocol on Base, forked from Tornado Cash) suffered an exploit on its legacy fixed-denomination privacy pools. Due to a misconfigured Groth16 zk-SNARK verifier (where delta2 equaled gamma2), an attacker was able to forge valid zero-knowledge proofs and drain approximately 2.9 ETH (~$5,000) in a single transaction by making multiple fraudulent withdrawals without corresponding deposits. Whitehat interveners and the exploiter voluntarily returned the funds, resulting in 100% recovery. The project’s newer/live pools were unaffected.
Amount of loss: $ 5,000 Attack method: Smart Contract Vulnerability
Description of the event: According to Decrypt, the DeFi lending protocol Moonwell incurred approximately $1.78 million in bad debt due to an oracle configuration error.
Amount of loss: $ 1,780,000 Attack method: Oracle Misconfiguration
Description of the event: Arbitrum has issued a security alert: The official X account for Arbitrum Governance (@arbitrumdao_gov) has been compromised. Do not click on any links posted by this account or engage with it. The team is working to restore access and will provide further updates soon.
Amount of loss: - Attack method: The X account was hacked
Description of the event: The cross-chain liquidity protocol CrossCurve (formerly EYWA) has confirmed that its cross-chain bridge protocol is under attack, due to a vulnerability in its smart contract that was exploited, resulting in the theft of approximately USD 3 million across multiple networks. Blockchain security firm Defimon Alerts identified that the attack vector exploited a gateway verification bypass vulnerability in CrossCurve’s ReceiverAxelar contract. Analysis shows that anyone could use a forged cross-chain message to call the contract’s expressExecute function, thereby bypassing the intended gateway verification and triggering unauthorized token unlocks on the protocol’s PortalV2 contract. Subsequently, CrossCurve issued a security update regarding the $EYWA token, stating that the exploitation has been successfully contained.
Amount of loss: $ 3,000,000 Attack method: Smart Contract Vulnerability
Description of the event: Step Finance has issued a statement on X regarding a recent exploit, disclosing that approximately $40 million was stolen from its treasury due to a compromise of an executive's device. Upon detecting the vulnerability, Step Finance launched an investigation in collaboration with cybersecurity researchers and relevant authorities, and has notified law enforcement. While certain operations were temporarily suspended during this period, the team has successfully recovered approximately $3.7 million in Remora assets and $1 million in other positions.
Amount of loss: $ 40,000,000 Attack method: Private Key Leakage
Description of the event: Revert Finance’s newly launched Aerodrome Lend vault on Base was exploited for $50,101. The attacker used a flash loan from Morpho to mint an Aerodrome concentrated liquidity NFT, deposited it as collateral, borrowed USDC, and then exploited a missing safety check in the GaugeManager contract. This allowed unstaking and withdrawing all liquidity from the debt-backed position, leaving the vault with a worthless NFT shell. A second attacker replicated it shortly after. User funds were safe; losses were mostly from Revert’s own seeded USDC. The team disabled deposits and published a post-mortem.
Amount of loss: $ 50,101 Attack method: Smart Contract Vulnerability
Description of the event: According to BlockSec monitoring, an unknown contract on the BSC network was exploited. The attacker leveraged a design flaw in the “burn pair” mechanism to execute two reverse swaps, resulting in losses of approximately $100,000. The attacker first drained PGNLZ tokens, then triggered PGNLP burns and price manipulation, ultimately siphoning off most of the USDT from the liquidity pool.
Amount of loss: $100,000 Attack method: Smart Contract Vulnerability
Description of the event: Solar, the official Solana Mandarin community, highly suspects its official X account (@Solana_zh) has been hacked. The team currently lacks access and is working urgently with X support to resolve the issue. Recovery time is TBD.
Amount of loss: - Attack method: Account Compromise
Description of the event: SwapNet’s closed-source aggregator contracts were exploited via an arbitrary-call vulnerability due to insufficient input validation on user-controlled parameters. This allowed attackers to abuse existing token approvals (especially from users who disabled Matcha Meta’s One-Time Approval) to execute unauthorized transferFrom calls, draining ~$13.43M across Base, Ethereum, Arbitrum, and BSC. The attacker swapped large amounts of USDC to ETH on Base and bridged funds. Matcha Meta and 0x core contracts were unaffected.
Amount of loss: $ 13,430,000 Attack method: Smart Contract Vulnerability
Description of the event: Scroll alerted on X that the X account of co-founder @shenhaichen has been compromised. They are actively working to recover the account and advise users not to interact with any links or direct messages.
Amount of loss: - Attack method: The X account was hacked
Description of the event: Aperture Finance (Aperture LM) was exploited for approximately $3.67 million across Ethereum, Base, Arbitrum, and BSC. The root cause was an arbitrary-call vulnerability in its closed-source V3/V4 contracts due to insufficient input validation on low-level calls. Attackers abused existing user token and Uniswap V3 LP NFT approvals to drain funds via transferFrom operations. The team paused affected features, urged users to revoke approvals, and published a security incident analysis.
Amount of loss: $ 3,670,000 Attack method: Smart Contract Vulnerability
Description of the event: According to an official announcement from Saga, the SagaEVM chain has suffered an attack involving a series of malicious contract deployments, cross-chain operations, and liquidity withdrawals. The attacker transferred approximately $7 million worth of USDC, yUSD, ETH, and tBTC, which have since been consolidated into ETH and sent to the address 0x2044…6ecb. Following the incident, SagaEVM was halted at block height 6,593,800. The Saga team is currently working with exchanges and cross-chain bridge providers to block the attacker’s address. A comprehensive technical post-mortem will be released in due course. The Saga SSC mainnet and other chains remain unaffected.
Amount of loss: $ 7,000,000 Attack method: Smart Contract Vulnerability