2239 hack event(s)
Description of the event: Venus Protocol’s Core Pool THE (Thena) market was exploited. The attacker accumulated THE tokens over 9 months, used a donation attack (direct transfer bypassing supply cap and mint) to inflate the vTHE exchange rate, combined with price manipulation borrow loops, extracted ~$3.7M in assets and left ~$2.15M in bad debt for the protocol.
Amount of loss: $ 3,700,000 Attack method: Donation Attack
Description of the event: Goose Finance, a yield farming protocol on BNB Chain, was exploited due to a share accounting flaw in the StrategyGooseEgg contract. The attacker repeatedly looped deposit() and withdraw() to mint inflated shares before rewards were settled, then redeemed them at higher value after harvest, profiting ~$8,435.
Amount of loss: $ 8,435 Attack method: Smart Contract Vulnerability
Description of the event: The AM/USDT pool on the BSC chain was exploited several hours ago, with estimated losses of approximately $131,000. The root cause lies in a vulnerability within the burn mechanism, which was exploited to manipulate the AM reserves in the pool and artificially inflate the token price. The attacker first manipulated the toBurnAmount and then triggered the burn logic after the AM balance in the pool had been adjusted. This drove the AM reserves down to an unnaturally low level, allowing the attacker to sell AM back to the pool at an inflated price to realize a profit.
Amount of loss: $ 131,000 Attack method: Reserve Manipulation Attack
Description of the event: Stake DAO’s Votemarket module was exploited. The attacker used a vulnerability in the L1BlockOracleUpdater peripheral contract to inject fabricated L1 block data via the LaPoste cross-chain bridge, poisoning the oracle and forging vote proofs to drain ~$176,000 in campaign incentive rewards across 54 campaigns. The incident was later resolved as a white-hat event with most funds recovered.
Amount of loss: $ 176,000 Attack method: Smart Contract Vulnerability
Description of the event: Aave V3 suffered a CAPO (Capped Asset Price Oracle) misconfiguration by Chaos Labs, which undervalued wstETH by ~2.85%. This triggered wrongful liquidations on 34 healthy positions, resulting in ~$862,000 in losses. Aave DAO fully compensated affected users; no protocol funds were stolen.
Amount of loss: $ 862,000 Attack method: Oracle Misconfiguration
Description of the event: BONKfun announced on X that its official website fell victim to a malicious social engineering attack on March 11. The attacker hijacked the BONKfun domain via the Domain Name Service (DNS) provider and transferred it to an external registrar. The team confirmed that the incident was not caused by a breach of BONK or BONKfun’s internal systems, codebases, or team accounts. Following the incident, the team took immediate action: shutting down the website, coordinating with wallet service providers to flag the domain as malicious, and containing the impact on users. The attack resulted in approximately $30,000 in customer losses; the team will compensate affected users at 110% to cover potential opportunity costs. Control over the BONKfun domain and registration was fully restored around 5 PM ET on March 18. Major wallet provider functionalities were restored by the evening of March 19, and the website is now securely back online. As some antivirus software still flags the main domain as a risk, the team is actively addressing the issue. For users unable to access the official site due to antivirus blocks, a backup domain with identical functionality is now live and available for use.
Amount of loss: $ 30,000 Attack method: Domain Hijacking
Description of the event: According to monitoring by BlockSec Phalcon, the DBXen contract was attacked this morning, with estimated losses of approximately $150,000.The root cause lies in a sender identity inconsistency within the ERC-2771 meta-transaction mechanism.
Amount of loss: $ 150,000 Attack method: Smart Contract Vulnerability
Description of the event: According to BlockSec Phalcon's monitoring, a suspicious transaction targeting the MT-WBNB liquidity pool on BSC was detected several hours ago, resulting in an estimated loss of approximately $242,000. The root cause lies in a flaw within the buyer restriction mechanism: under deflationary mode, normal buy orders were reverted; however, the router and pair addresses were whitelisted. The attacker bypassed these restrictions by swapping and removing liquidity through the router to acquire MT tokens from the pair. Subsequently, the attacker sold MT to accumulate a pendingBurnAmount and invoked the distributeFees() function to directly burn MT from the trading pair, artificially inflating the price. This allowed the attacker to swap MT back for WBNB to realize a profit. Furthermore, a referral rule that allowed the transfer of the first 0.2 MT to bypass buyer restrictions enabled the attacker to initiate the exploit.
Amount of loss: $ 242,000 Attack method: Reserve Manipulation Attack
Description of the event: Gondi V3 NFT lending protocol’s “Sell & Repay” contract (Purchase Bundler feature) was exploited. The attacker bypassed ownership checks due to an access control flaw and stole escrowed NFTs (approximately 78 NFTs) worth ~$230,000. The team disabled the vulnerable contract and committed to compensating affected users; other platform functions remained unaffected.
Amount of loss: $ 230,000 Attack method: Smart Contract Vulnerability
Description of the event: Molt EVM, an experimental self-replicating ERC-20 token protocol on Base, was exploited due to a weak access control flaw. The attacker deployed a malicious contract to bypass the onlySpawnerToken modifier, minted large amounts of tokens via mintFromSpawner(), and dumped them through liquidity pools for profit.
Amount of loss: $ 127,000 Attack method: Smart Contract Vulnerability
Description of the event: The Bitcoin staking protocol Solv Protocol stated on X that its BRO Vault experienced a limited exploit. Fewer than 10 users were affected, with a loss of 38.0474 SolvBTC (approximately $2.7 million). Other vaults and user funds were not impacted, and mitigation measures have already been implemented to prevent similar incidents. The team has committed to fully covering the losses of the affected users. They also told the attacker that a 10% white-hat bounty will be offered if the funds are returned promptly. The attacker can contact the team via direct message or by sending an on-chain message to a designated address.
Amount of loss: $ 2,700,000 Attack method: Smart Contract Vulnerability
Description of the event: According to BlockSec Phalcon’s monitoring, its system detected a suspicious transaction targeting an Inverse Finance contract on Ethereum several hours ago, resulting in a loss of approximately $240,000. The incident appears to involve DOLA price manipulation, which forced multiple users to liquidate their positions.
Amount of loss: $ 240,000 Attack method: Price Manipulation
Description of the event: On March 2, 2026, Curve Finance’s LlamaLend sDOLA/crvUSD market suffered a flash-loan + donation attack. The attacker first used a massive LLAMMA exchange to push all positions into soft liquidation, then inflated the sDOLA oracle price by 13.79% (1.189 → 1.353) via DolaSavings.stake() donation. This hard-liquidated 27 borrowers (~$10.9M debt). Attacker profited ~$240K; borrowers lost ~$822K equity (Curve DAO later proposed full compensation). Lenders and core protocol unaffected.
Amount of loss: $ 240,000 Attack method: Donation Attack
Description of the event: Bitcoin payment service provider Bitrefill disclosed on X that it suffered a cyberattack on March 1, 2026, resulting in a customer data breach. The attack originated from a compromised employee laptop, which allowed the attacker to access parts of the company’s databases and cryptocurrency wallets.The investigation indicates that the attack methods closely resemble those previously used by the North Korean DPRK Lazarus Group / Bluenoroff hacking organization in targeting crypto companies.Approximately 18,500 purchase records were affected, involving limited customer information such as email addresses, crypto payment addresses, and IP metadata. Among these, around 1,000 records contained customer names stored in encrypted form, which may also have been accessed.Bitrefill stated that customers do not need to take specific action but are advised to remain vigilant for any suspicious communications.The company added that the affected systems have been shut down and isolated, and it is working with security experts, on-chain analysts, and law enforcement agencies. Operations have now largely returned to normal.Bitrefill emphasized that it remains financially strong and profitable, capable of absorbing the losses from this incident, and will continue strengthening its cybersecurity measures, including internal access controls, monitoring, and incident response mechanisms.
Amount of loss: - Attack method: APT Endpoint Compromise Attack
Description of the event: The DeFi lending protocol Wise Lending V2 was exploited via a flash loan attack. The attacker drained approximately $66,000 from the protocol’s pools by exploiting logic vulnerabilities. The incident affected deployments on Ethereum and Arbitrum.
Amount of loss: $ 66,000 Attack method: Flash Loan Attack
Description of the event: Stake Nova suffered a loss of approximately $137,014, representing about 95% of user deposits. The root cause was an unchecked validation issue in the RedeemNovaSol() function, which led to a flash-loan exploit that drained the liquidity pool. The vulnerability has now been fixed, the dApp has been taken offline, and the website is currently under maintenance. The team is offering a 10% on-chain bounty to the attacker; otherwise, they stated they will continue to pursue accountability.
Amount of loss: $ 137,014 Attack method: Flash Loan Attack
Description of the event: The privacy gaming platform FOOMCASH was attacked on Base and Ethereum, resulting in a loss of 24,283,773,519,600 $FOOM (approximately $2.26 million). The vulnerability was caused by a misconfiguration of the verification key, which the attacker exploited to forge zkSNARK proofs and subsequently extract a massive amount of $FOOM from the compromised contracts.
Amount of loss: $ 2,260,000 Attack method: Smart Contract Vulnerability
Description of the event: The DeFi lending protocol Ploutos Money suffered an exploit due to a misconfigured price oracle (using Chainlink’s BTC/USD feed for USDC price), allowing an attacker to deposit minimal USDC collateral and borrow ~187.36 ETH, draining approximately $390K. The project’s website and social accounts were deleted shortly after, raising strong suspicions of an inside job or exit scam.
Amount of loss: $ 390,000 Attack method: Oracle Misconfiguration
Description of the event: the Holdstation team confirmed that its DeFAI Smart Wallet product suffered a supply chain attack targeting the application distribution infrastructure. This resulted in unauthorized transactions in some user wallets, with a confirmed loss of approximately $462,000 USDT. Smart contracts were not directly exploited. The team committed to 100% compensation for affected users and is reinforcing security measures.
Amount of loss: $ 462,000 Attack method: Supply Chain Attack
Description of the event: WLFI announced on X that USD1 experienced an organized attack this morning. The attackers reportedly compromised the accounts of several WLFI co-founders, paying influencers to spread FUD (Fear, Uncertainty, and Doubt) and heavily shorting $WLFI in an attempt to profit from artificially created market chaos. WLFI stated that the operation failed. Thanks to USD1’s robust minting and redemption mechanisms and its 100% 1:1 asset backing, USD1 remains stable and is currently trading near its par value. The team emphasized that no bad actors can shake their long-term commitment to USD1. Meanwhile, WLFI reminded users to obtain accurate information only through officially verified channels and to be wary of misleading content.
Amount of loss: - Attack method: Social Engineering