2265 hack event(s)
Description of the event: Cross-chain protocol Chainflip was exploited on its TRON USDT integration. The attacker abused TRON memo handling by attaching a custom memo to a transaction already signed by validators, causing the system to treat the same deposit as a separate failed swap and issue a duplicate refund. The attack was repeated eight times over about 90 minutes, producing six unauthorized payouts totaling 736,442.17 USDT. A pending user swap of 115,654.41 USDT remains safely in the vault. The network is paused, a fix is ready, restart is expected as early as Monday, and affected users will be made whole.
Amount of loss: $ 736,442.17 Attack method: Protocol logic vulnerability
Description of the event: Users of ether.fi Liquid (liquidETH) lost ~15.45 ETH after an attacker exploited missing access control in AtomicQueue.solve() on the caller-supplied solver parameter. The attacker crafted a malicious AtomicRequest, forced already-approved victim addresses to act as solver, and drained funds via existing ERC-20 allowances with transferFrom. About 11 users were affected.
Amount of loss: $ 38130 Attack method: Smart Contract Vulnerability
Description of the event: Ethereum ERC-404 token OMNI404 (O404) derived NFT mint/burn counts from integer balanceOf/units diffs in _transfer(). Its transfer() treated values ≤50 as ERC-721 IDs but still moved a fixed 1e18 units. Using flash loans and Uniswap V3 exact-output swaps (transfer(recipient, 1/2/.../21)), the attacker received full-unit tokens while the pool booked wei-level amounts, draining about 2.4 WETH.
Amount of loss: $ 5,923 Attack method: Smart Contract Vulnerability
Description of the event: Attackers exploited ORBToken’s receive() function (which auto-granted max allowance) and ORBCore’s whitelist tax exemption. The addPoolAndSell function lacked a reentrancy guard, enabling repeated tax-free sells. Combined with burnLP destroying large amounts of ORB in the LP and a subsequent sync() to manipulate reserves, the attacker extracted about $32,610.72.
Amount of loss: $ 32,610.72 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited Symbiosis’s Bitcoin Bridge (BridgeV2), minting about 2622^{62}2^{62} raw unbacked syBTC on BNB Chain (face value ~46.1 billion) and selling ~4.39 WBTC on Ethereum Uniswap V4 for about $336,000. The team paused native BTC routes, said it recovered ~15 BTC into a team multisig, and offered a 20% white-hat bounty.
Amount of loss: $ 336,000 Attack method: Smart Contract Vulnerability
Description of the event: Dominion Market’s Solana silver token $SILV suffered a treasury multisig compromise. With 3-of-5 keys, the attacker emptied the treasury and pulled SILV from loans, dumping about 46,909 tokens (face value ~$3 million) into thin DEX pools and realizing about $238,000 as the peg broke. The team pulled liquidity, rotated hardware, froze tokens bought in the incident window, and planned USDC refunds plus a repeg.
Amount of loss: $ 238,000 Attack method: Private Key Leakage
Description of the event: The old BNB Chain DeFi protocol Amnext (AMC), a no-loss lottery/prize-pool product, was exploited. The attacker mass-minted Ticket AMC and drained about 154.02 WBNB from the protocol via PancakeSwap, causing a loss of approximately $ 116,100.
Amount of loss: $ 116,100 Attack method: Smart Contract Vulnerability
Description of the event: An attacker exploited a bug in Nomic’s custom forwarding mechanism to double-spend nBTC and send unbacked vouchers to Osmosis. Osmosis and IBC themselves were not compromised. 39.84 nBTC of the minted supply sat in Alloyed BTC (~36% of its backing). Osmosis froze Nomic and Alloyed BTC flows, upgraded with validators, and froze 22.65 BTC in the attacker’s address. Governance will be asked to seize those funds and cover the rest from the community pool.
Amount of loss: $ 3,150,000 Attack method: Double-Spending Attack
Description of the event: On September 9, 2026, an attacker used a single transaction on Citrea mainnet and ~200,000 USDC.e of flash liquidity as temporary collateral to drain 140,000 ctUSD and 30 USDC.e from Zentra’s lending pool. The root cause was an accounting edge case in repayWithATokens: the debt path could complete while the matching aToken burn was reduced to zero. The operations multisig paused all markets about 17 minutes later; no second exploit occurred.
Amount of loss: $ 140,030 Attack method: Smart Contract Vulnerability
Description of the event: BeatXswap’s LiquidityVestingConvert used the Uniswap/Pancake V3 slot0() spot price as its only oracle, with no TWAP or deviation checks. An attacker flash-loaned 6,000,000 BTX, dumped it to crash the pool price, then called deposit() twice (10,000 + 2,000 USDT) to mint LP at the manipulated quote and drain 2,984,557 BTX (~$77,512).
Amount of loss: $ 77,512 Attack method: Price Manipulation
Description of the event: The WealthManagementV2 contract lost funds after owner privileges were suspected of being illegally transferred (possibly due to a leaked private key). The attacker-controlled owner instantly set extreme plan parameters (period=0, interestMultiplier/unlockMultiplier=528,300,000) via updatePlanConfig with no timelock or bounds, minted inflated interest by investing and redeeming in the same transaction, then unlocked and withdrew the funds via a second investment, resulting in a loss of 26,414 USDT.
Amount of loss: $ 26,414 Attack method: Private Key Leakage
Description of the event: DeFi protection protocol Cozy Finance on Optimism was exploited for about $160,000. The attacker first bought PTokens in the Aave v2 and Curve protection markets, then submitted undisputed YES answers to the UMA Optimistic Oracle. The trigger did not independently verify a real Aave/Curve hack, and PToken payout eligibility was not tied to a pre-proposal holder snapshot. After the markets moved to TRIGGERED, the attacker burned PTokens and claimed USDC.
Amount of loss: $ 160,000 Attack method: Smart Contract Vulnerability
Description of the event: An unnamed DEX router on BNB Chain was exploited because uniswapV3SwapCallback did not authenticate a real V3 pool. The attacker used a fake pool, set victims as payer, and drained existing token allowances via transferFrom, stealing about 62.28 WBNB from 29 wallets in one transaction.
Amount of loss: $ 46,070 Attack method: Smart Contract Vulnerability
Description of the event: Bitcoin sidechain Liquid Network was exploited via an Elements range-proof verification cache bug, allowing creation of about 4,000 unbacked LBTC. The actor then used SideSwap’s standard peg-out path to withdraw about 4,000 BTC ($320,000,000) from the federation reserve. Liquid said no private keys were compromised. The actor, claiming to be a white hat, returned 3,400 BTC on September 7 and still holds about 598.5 BTC ($47,000,000). The network remains paused.
Amount of loss: $ 320,000,000 Attack method: Elements Software Vulnerability
Description of the event: An attacker exploited a dormant, illiquid perpetual market on Rocket. Using a burner account, they posted orders at artificially inflated prices and traded against themselves to generate fake profits on one account while bankrupting the burner. The profitable account then withdrew approximately $287K in positive PnL from the Bridge, with the loss socialized across the platform. Deposits, withdrawals and trading were paused.
Amount of loss: $ 287,000 Attack method: Price Manipulation
Description of the event: Secured Finance’s fixed-rate lending protocol was exploited via an order-book accounting flaw that treated unfilled orders as filled and created invalid balances. Attackers used flash loans and self-trades to manipulate the current-block price and withdraw funds. Markets on Ethereum, Arbitrum, and Filecoin were paused. The team’s preliminary loss estimate is about $180,000; no recovery has been confirmed.
Amount of loss: $ 180000 Attack method: Flash Loan Price Manipulation
Description of the event: Reddio’s RedSonic Vault on Ethereum was exploited for about 9.25 ETH (~$22,800). After permissionlessly registering an stETH vault, the same stETH was counted in both the ETH vault and the stETH vault. The attacker used a flash loan to inflate the rsvETH share price, redeemed excess ETH, then redeemed rsvstETH to recover the same stETH.
Amount of loss: $ 22,800 Attack method: Smart Contract Vulnerability
Description of the event: Dream Health Chain’s staking/reward contracts on BSC were exploited for about 71,851 USDT. A broken award state machine allowed a claimed reward to be reset with a tiny or zero-effective DHC deposit, so the same fixed payout could be claimed repeatedly from the shared pool. The attacker looped pledge and claim, then sold about 542,070 DHC into the DHC-USDT pool.
Amount of loss: $ 71,851 Attack method: Smart Contract Vulnerability
Description of the event: Notional Finance’s legacy V1 Escrow contract was exploited. The attacker abused an unsafe uint128 cast in free-collateral valuation so that a fabricated liability of about 2^128 truncated to zero, bypassing solvency checks, minting fake fCash claims, and withdrawing about 69,257.37 DAI and 1,658,524.86 USDC (~$1.73M). The funds were swapped into roughly 689.2 ETH and deposited into Tornado Cash. The team paused the affected contract, said other user assets were not at risk, and is pursuing recovery.
Amount of loss: $ 1,730,000 Attack method: Smart Contract Vulnerability
Description of the event: On the evening of September 3, 2026, approximately 4,011 XRPH Wallet user accounts suffered unauthorized transactions involving XRPH, XRPHAI and other assets, with roughly $452,000 stolen. Funds were collected, bridged via NEAR Intents to Ethereum, and converted to about 445,198 DAI, which remains unmoved in one address. The project confirmed no issue with the XRP Ledger itself, took the app offline, and is investigating.
Amount of loss: $ 452,000 Attack method: Seed Phrase Leakage