2282 hack event(s)
Description of the event: Internet Token DAO’s LiquidityUnifier on Base was exploited after it trusted a caller-supplied Uniswap V3 pool address. A fake pool callback minted about 925 million INT out of thin air. The attacker drained 5.847 WETH (about $16,033.55) from the official INT/WETH pool and kept about 764 million INT. The mint role was not revoked in time, copycat exploits inflated supply to about 156 billion, and the attacker submitted a governance proposal aiming to move treasury funds.
Amount of loss: $ 265,000 Attack method: Smart Contract Vulnerability
Description of the event: The RWC token on BNB Smart Chain was exploited with a flash loan. An unprotected burn function let the attacker destroy RWC sitting in the PancakeSwap RWC/USDT pair and call sync() to rewrite reserves, inflating the price before selling back. The pool lost about 109,460.85 USDT in one transaction. The attacker kept about 39,964.07 USDT; the remaining about 69,496.78 USDT was routed to the project’s company and platform wallets by the token’s fee logic.
Amount of loss: $ 109,460.85 Attack method: Smart Contract Vulnerability
Description of the event: Bitcoin Lightning wallet Blink Wallet paused services to investigate a security incident. The team said an attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds remain secure, and non-custodial wallets were not affected. The team is currently conducting an in-depth investigation and emergency response to this vulnerability. Further details of the investigation and recovery arrangements will be announced later.
Amount of loss: - Attack method: Unauthorized access to custodial accounts
Description of the event: An attacker attempted to exploit a virtual-machine-level atomicity issue on the MultiversX mainnet, causing invalid on-chain state changes. The network was paused to contain further impact. Engineers prepared a fix for validation on a shadow fork and are evaluating a targeted recovery that would keep finalized history and legitimate user state while reversing only incident-related invalid changes. Users were told not to submit or rebroadcast transactions and not to deposit or withdraw EGLD or ESDT via exchanges or bridges.
Amount of loss: - Attack method: VM-level atomicity vulnerability
Description of the event: An attacker used a leaked conversion-authorizer / bridge backend signing key to call conversionIn() on Fetch.ai’s Ethereum token-conversion contract and drain about 8,721,530 FET (~$1.53 million). The same wallet cluster then minted about 408.5 million unauthorized NTX via a NuNet deployer key and later expanded the attack to related ASI Alliance bridge/converter infrastructure.
Amount of loss: $ 1,530,000 Attack method: Private Key Leakage
Description of the event: An attacker gained control of NuNet’s Ethereum deployer/minting private key and called mint() on the NTX token contract, issuing 408,532,878.13 NTX to the attacker’s address. The mint function had no supply-cap check, so possession of the key was enough to create new tokens. PeckShield valued the unauthorized mint at approximately $462,730 at the time of the incident.
Amount of loss: $ 462,730 Attack method: Private Key Leakage
Description of the event: The BNB Chain DeFi protocol Likwid was exploited due to a margin-borrow contract bug. In the leverage=0 path of LikwidMarginPosition, pair reserves were not updated, so each borrow reused the same quote. The attacker first pumped a thin meme pool, then repeated the collateral/borrow cycle and drained 74.31 BNB (~$ 55,721) from the vault. The funds were later sent to Tornado Cash.
Amount of loss: $ 55,721 Attack method: Smart Contract Vulnerability
Description of the event: Nostra, a DeFi lending protocol on Starknet, suffered an exploit after the NSTR oracle price was manipulated. An attacker used inflated NSTR as collateral to borrow about $3.5 million in ETH, STRK, USDC, USDT, WBTC and DAI from the money market. The market has been paused while the team traces funds; about $1.92 million has already been bridged to Ethereum, and the final loss and recoveries are not yet confirmed.
Amount of loss: $ 3,500,000 Attack method: Oracle Manipulation
Description of the event: The BonfireSwap router’s transfer lacked access control: it did not require msg.sender == from or check the caller’s allowance on from. An attacker set approved holders as from and themselves as to, drained TOKEN via existing victim→router allowances, then forwarded funds through a same-token pool swap. About 41 approved holders were hit; loss ~$50,000.
Amount of loss: $ 50,000 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome (legacy contracts of Flamingo Finance) was exploited due to unsafe asset accounting and valuation. The attacker flash-loaned ~$18M USDT, injected USDP/3CRV LP into the Strategy (treating a permissionlessly injectable Convex BaseRewardPool balance as its own assets and overvaluing it via Curve’s get_virtual_price() in a depegged pool), inflated the VaultYUSDT share price, and redeemed real Aave aUSDT liquidity for ~$345.9K profit.
Amount of loss: $ 345,900 Attack method: Smart Contract Vulnerability
Description of the event: Startale’s ERC-7579 smart accounts on Ethereum were exploited. The attacker abused a transient-storage initialization flag in initializeAccount that persists for the entire transaction, allowing re-initialization with a malicious bootstrap in the same tx after factory deployment. This enabled draining ~330 pre-funded counterfactual accounts (no signatures or capital required) for a total of ~$2,876. The Soneium network itself was unaffected.
Amount of loss: $ 2,876 Attack method: Smart Contract Vulnerability
Description of the event: An attacker abused an OpenGSN meta-transaction auth flaw on Polygon HTLC contracts: open/execute accepted a spoofed from without a real user signature. Posing as liquidity wallet 0x24cb…6773, they used leftover near-unlimited ERC-20 allowances to lock 26,130.64171 USDC, 24,332.489269 USDT0 and 0.661117 USDC.e into HTLCs with attacker-chosen recipient and secretHash=sha256(1), then redeemed via a CREATE2 contract with secret=1. Single-tx loss was about $50,463.
Amount of loss: $ 50,463 Attack method: Smart Contract Vulnerability
Description of the event: Flamincome’s legacy USDT strategy (VaultYUSDT) was exploited. The attacker took an ~$18 million USDT flash loan via Morpho, staked manipulated Curve USDP LP into the Strategy to inflate the vault share price, then redeemed aUSDT for about $345,900 in profit.4.
Amount of loss: $ 345,900 Attack method: Flash Loan Price Manipulation
Description of the event: An unidentified user’s Gnosis Safe wallet on Ethereum was drained of about $7,730,000. The attacker exploited an authorization bypass in a Router multicall function, used the victim Safe module to DelegateCall attacker-crafted data, injected aEthrsETH into a malicious Uniswap V4 hooked pool, then swapped and redeemed it as rsETH. Kelp later placed a 24-hour pause on an address that received the stolen rsETH.
Amount of loss: $ 7,730,000 Attack method: Smart Contract Vulnerability
Description of the event: On September 16, 2026, DCENT (formerly D'CENT) issued an urgent security alert stating that abnormal asset transfers had been detected in its mobile App Wallet (software wallet) and that an emergency investigation was underway. Initial findings indicate the issue is limited to the App Wallet, with no confirmed impact on hardware wallets themselves. Users holding assets in the App Wallet, or using the same mnemonic for both the App Wallet and a hardware wallet, are strongly advised to immediately transfer funds to a secure hardware wallet or other trusted address, and to remain vigilant against scams.
Amount of loss: $ 6,570,000 Attack method: Unknown
Description of the event: The attacker manipulated the Uniswap V4 pool spot price. SpiralHookV2.borrow() valued collateral using poolManager.getSlot0() without TWAP or price-change limits. The noSameBlockSwap guard (keyed by tx.origin) was bypassed via 6 different EOAs, allowing borrowing against inflated collateral in the same block as the pump, resulting in a loss of ~10.7 ETH.
Amount of loss: $ 26,800 Attack method: Price Manipulation
Description of the event: Long’s custodial bridge released 46.7928 WETH (about $118,000) from its Robinhood Chain vault after a third-party RPC fed the keeper fabricated Arc withdrawal events. No on-chain contract or key was breached. The team halted the keeper, rebuilt verification, and refilled the vault the same day from platform revenue. Users did not lose funds.
Amount of loss: $ 118,000 Attack method: Supply Chain Attack
Description of the event: Cross-chain protocol Chainflip was exploited on its TRON USDT integration. The attacker abused TRON memo handling by attaching a custom memo to a transaction already signed by validators, causing the system to treat the same deposit as a separate failed swap and issue a duplicate refund. The attack was repeated eight times over about 90 minutes, producing six unauthorized payouts totaling 736,442.17 USDT. A pending user swap of 115,654.41 USDT remains safely in the vault. The network is paused, a fix is ready, restart is expected as early as Monday, and affected users will be made whole.
Amount of loss: $ 736,442.17 Attack method: Protocol logic vulnerability
Description of the event: Users of ether.fi Liquid (liquidETH) lost ~15.45 ETH after an attacker exploited missing access control in AtomicQueue.solve() on the caller-supplied solver parameter. The attacker crafted a malicious AtomicRequest, forced already-approved victim addresses to act as solver, and drained funds via existing ERC-20 allowances with transferFrom. About 11 users were affected.
Amount of loss: $ 38130 Attack method: Smart Contract Vulnerability
Description of the event: Ethereum ERC-404 token OMNI404 (O404) derived NFT mint/burn counts from integer balanceOf/units diffs in _transfer(). Its transfer() treated values ≤50 as ERC-721 IDs but still moved a fixed 1e18 units. Using flash loans and Uniswap V3 exact-output swaps (transfer(recipient, 1/2/.../21)), the attacker received full-unit tokens while the pool booked wei-level amounts, draining about 2.4 WETH.
Amount of loss: $ 5,923 Attack method: Smart Contract Vulnerability