2188 hack event(s)
Description of the event: FlashTrade (a Solana perps protocol) detected an unauthorized $98,000 withdrawal from its ephemeral instance. As a precaution, trading, deposits, and withdrawals were paused. Thanks to the newly rolled-out withdrawal batching and monitoring system, the incident was detected quickly and contained. The team will fully cover the amount, with all user funds safe.
Amount of loss: $ 98,000 Attack method: Unknown
Description of the event: Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $1.65 million. The team paused the protocol, urged affected LPs to withdraw funds immediately, and asked arbitrage profiteers to return funds for LP compensation.
Amount of loss: $ 1,650,000 Attack method: Flash Loan Price Manipulation
Description of the event: Cross-chain bridge protocol Across was attacked on its Solana deployment on July 17, 2026. The attacker exploited a gap in Solana’s event system to spoof deposit signals, tricking relayers into paying out on fake deposits. User funds remained completely safe with zero losses; all transactions were completed or fully refunded. Losses were contained to the Risk Labs-operated relayer. The team paused Solana deposits and restored operations the next day, with a full post-mortem planned.
Amount of loss: 0 Attack method: Deposit signal spoofing
Description of the event: The Solana-based DeFi protocol DefiTuna's lending pools were exploited by an attacker who drained approximately $580K, creating a matching deficit in the USDC lending pool. The attack vector has been identified and patched; the team is investigating and working on fund recovery.
Amount of loss: $ 580,000 Attack method: Smart Contract Vulnerability
Description of the event: Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draining approximately $18 million USDC from the liquidity vault. The protocol has halted trading and is investigating.
Amount of loss: $ 18,000,000 Attack method: Private Key Leakage
Description of the event: The cross-chain bridge protocol TeleSwap was suspected of being exploited on July 15, 2026. Suspicious outflows of over $735,000 occurred from its Bitcoin hot wallet, which then stopped processing transactions. Five days later, the project has still not publicly disclosed the incident, and the attacker has moved funds toward Tornado Cash for laundering.
Amount of loss: $ 735,000 Attack method: Unknown
Description of the event: DeFi protocol BarnBridge suffered a governance attack on July 15, 2026. The attacker gained control of the DAO via a malicious governance proposal, upgraded the proxy contract to a malicious implementation, and drained approximately $776,000 USDC by exploiting pre-existing approvals from around 50 user addresses.
Amount of loss: $ 776,000 Attack method: Governance Attack
Description of the event: DeFi streaming payments protocol Drips Network was exploited on July 14, 2026. The attacker used an unsafe integer cast vulnerability (uint128 to int128) in the DaiDripsHub.give() function on Ethereum, causing a negative value to flip positive and reverse the transfer direction, draining 24,882.99 DAI (~$24,900) from the DaiReserve.
Amount of loss: $ 24,900 Attack method: Smart Contract Vulnerability
Description of the event: The DeFi protocol Lumi Finance on Arbitrum suffered an exploit where attackers leveraged Sodium smart accounts that performed token approvals as a side effect during UserOp validation. This allowed a malicious Paymaster to gain allowances from multiple accounts and drain funds, resulting in approximately $270,000 in losses.
Amount of loss: $ 270,000 Attack method: Smart Contract Logic Vulnerability
Description of the event: Chi Protocol (a DeFi stablecoin protocol issuing $USC backed by LSTs/LRTs on Ethereum) was exploited due to a logic error in the ArbitrageV5 contract’s burn() function. The attacker used a flash loan to buy heavily depegged $USC cheaply on a thin Uniswap V2 pool and burned it to redeem full-value collateral (weETH/stETH/WETH) at the hardcoded $1 peg, without the burn function checking the actual peg (unlike the mint function). This resulted in approximately $8,500 loss, nearly draining the protocol’s reserves.
Amount of loss: $ 8,500 Attack method: Smart Contract Logic Vulnerability
Description of the event: Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The borrowed funds were subsequently swapped on SaucerSwap and bridged to Ethereum via LayerZero (over $5M tracked on-chain). Bonzo Lend paused the protocol shortly after detecting abnormal activity.
Amount of loss: $ 9,050,000 Attack method: Oracle Price Manipulation
Description of the event: Lazy Summer Protocol (under Summer.fi) USDC vaults were exploited due to NAV/share price calculation flaw. The attacker used flash loans and pre-accumulated overvalued Silo tokens to inflate vault NAV (~9.5%), redeeming at inflated price and extracting ~$6.04M from other depositors.
Amount of loss: $ 6,040,000 Attack method: Smart Contract Vulnerability
Description of the event: BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contract exploit; used the DAO's own voting system.
Amount of loss: $ 20,000,000 Attack method: Governance Attack
Description of the event: Hinkal privacy DeFi protocol's Ethereum contract was exploited. The attacker used a "proofless deposit" vulnerability to drain approximately $820K USDC, then converted it to ETH and laundered via Tornado Cash and THORChain. The team paused contracts, limited the incident to one Ethereum pool, and committed to 1:1 user compensation.
Amount of loss: $ 820,000 Attack method: Smart Contract Vulnerability
Description of the event: Edel Finance lending protocol was exploited via wGOOGLx wrapped token exchange rate manipulation. The attacker used flash loans in repeated deposit/borrow loops to inflate wGOOGLx collateral value ~78x, then borrowed assets, creating ~$403K bad debt.
Amount of loss: $ 403,000 Attack method: Smart Contract Vulnerability
Description of the event: AIDC token on BSC was exploited due to a flaw in _sellTransfer()/burn logic. The attacker manipulated the PancakeSwap LP pool, causing burn fees to accumulate without properly deducting from sender balance, draining ~$121K WBNB.
Amount of loss: $ 121,000 Attack method: Smart Contract Vulnerability
Description of the event: Polymarket suffered a third-party supply chain attack where hackers injected a malicious script into the platform's frontend, draining approximately $3.1 million in PUSD from 11 user wallets. Funds were moved from Polygon to Ethereum. Polymarket contained the incident, removed the affected dependency, and promised full refunds to impacted users.
Amount of loss: $ 3,100,000 Attack method: Supply Chain Attack
Description of the event: Lixir Finance's vault tokens (lv_* wrappers over Uniswap V3 LP positions) were exploited due to a broken EIP-2612 permit signature verification. The attacker reused a single dummy signature to bypass checks, granting approval to their contract over dozens of holders' tokens, then drained underlying assets (WETH, USDC, USDT, LIX) via withdrawFrom/withdrawETHFrom, resulting in ~$12,300 loss.
Amount of loss: $ 12,300 Attack method: Smart Contract Vulnerability
Description of the event: According to security firm Blockaid, Yield Yak suffered a frontend attack. Its subdomain vote.yieldyak.com was injected with Eleven Drainer malicious code, posing risks of asset theft upon access. This mirrors a similar frontend attack previously experienced by Gitcoin.
Amount of loss: - Attack method: Frontend Attack
Description of the event: SecondFi (formerly Yoroi) Cardano wallet suffered an exploit due to a vulnerability in its proprietary web wallet generation software, exposing private keys at the address level. Attackers drained ~16 million ADA ($2.4M) from 374 affected wallets across three attacks. The project secured ~129 million ADA (~$19.4M) through emergency rescue; affected users must wait for official recovery and are advised to use hardware wallets for migration.
Amount of loss: $ 2,400,000 Attack method: Predictable Private Key Exploit