2239 hack event(s)
Description of the event: Solana-based proprietary AMM Aquifer was exploited for about $2.5 million. Public reporting points to compromised protocol-linked wallets or admin credentials rather than a confirmed smart-contract bug. The attacker operated addresses on both Solana and Ethereum. The same day, Aquifer’s Solana upgrade authority posted an on-chain white-hat offer: return at least 80% of stolen assets by September 3, 2026, 14:00 UTC to designated recovery addresses, and keep up to 20% as a bounty, in exchange for no civil claims by the project.
Amount of loss: $ 2,500,000 Attack method: Wallet Credential Compromise
Description of the event: An attacker exploited a vulnerability in Ankr’s ankrFLOW liquid staking contract to mint approximately 8.6 million unbacked ankrFLOW tokens, then used them as collateral with More Markets’ E-mode to drain about 15.5 million WFLOW (~$410,000 at spot) from the lending reserve. The attacker realized roughly $246,000 after slippage. The Flow Foundation stated the root cause was in Ankr’s Solidity contract, not Flow EVM or More Markets.
Amount of loss: $ 410,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker used a flash loan to execute large swaps on a Uniswap V3 pool and manipulate the spot price (slot0). This caused Float Protocol’s Hypervisor contracts to misprice LP shares. Because critical functions lacked TWAP/oracle validation and slippage protection, the attacker repeatedly deposited and withdrew at inflated share values, extracting about $28,000 (10.71 ETH).
Amount of loss: $ 28,000 Attack method: Flash Loan Price Manipulation
Description of the event: An attacker exploited a rounding/precision vulnerability in legacy Balancer V1 contracts. Using flash loans to compress WBTC reserves to near-zero, they minted a large amount of BPT with only 1 satoshi of WBTC and then proportionally exited to drain DPI, USDC, WETH and WBTC from the pool.
Amount of loss: $ 234,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker inflated the price of the thinly traded TONIC governance token by about 100x in roughly 20 minutes and used it as collateral to borrow high-value assets from Tectonic (a Mango Markets-style price manipulation attack). Cronos halted the chain and later rolled it back to contain most of the damage.
Amount of loss: $ 75,000,000 Attack method: Price Manipulation
Description of the event: An attacker exploited a vulnerability in Switchboard’s production code to add a controlled key to a live oracle, published false prices roughly 100 times below market, deposited into Full Sail vaults at distorted values, then restored prices and withdrew more than deposited.
Amount of loss: $ 91,000 Attack method: Oracle Manipulation
Description of the event: Attackers exploited a vulnerability in an outdated version of Rain’s Solana card contract used by Avici (and a few other programs). By submitting crafted signature bundles to gain unauthorized admin rights via AddCollateralAdmin and then withdrawing collateral, they drained $500,859.22 from 1,685 users’ card balances. Self-custodial wallets were unaffected. The contract was upgraded across all programs, and full refunds were promised.
Amount of loss: $ 500,859.22 Attack method: Smart Contract Vulnerability
Description of the event: Base-based DeFi lending protocol Moonwell was attacked. The attacker inflated the price of the low-liquidity token MAMO, posted it as collateral, and borrowed real assets such as cbBTC and USDC from markets including mCBTC and mUSDC. Blockaid first reported about 50.6 cbBTC (over $4,000,000) drained, later updating observed outflows to about $8,790,000.
Amount of loss: $ 8,790,000 Attack method: Price Manipulation
Description of the event: FH Token on the BSC chain was exploited in its FH/USDT liquidity pool on PancakeSwap V2. A flaw in the token’s _transfer function and isSell logic caused incorrect token burns during sells, allowing the attacker to drain funds from the pool through repeated buy-and-sell loops, resulting in a loss of approximately $20,000.
Amount of loss: $ 20,000 Attack method: Smart Contract Vulnerability
Description of the event: The BLND-USDC liquidity pool of CometDEX (Comet AMM) on the Stellar network was exploited due to an accounting bug that allowed same-asset swaps (USDC→USDC), corrupting reserve calculations. The attacker used flash loans from a Blend pool and repeated the process about 36 times to extract excess funds, resulting in a loss of approximately $717,518.92 USDC. Funds were subsequently moved.
Amount of loss: $ 717,518.92 Attack method: Smart Contract Vulnerability
Description of the event: Enjin’s legacy ERC-1155 Crypto Items platform on Ethereum was exploited. The attacker used a storage-layout mismatch in delegate-call adapters plus an unprotected initialize function to take over the Managed Delegate Proxy via DELEGATECALL. After gaining manager privileges, they registered a malicious adapter, transferred NFTs from about 52 wallets without approval, and melted them to redeem the backing ENJ from the reserve, draining approximately 5.24 million ENJ .
Amount of loss: $ 162,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 23, 2026, Term Finance’s Strategy Vaults (Ethereum-based fixed-rate lending protocol by Term Labs) suffered a governance exploit. The attacker acquired majority voting power (100% on several USDC vaults, ~91% on the ETH Meta Vault), passed malicious proposals to disable the timelock and drain ~2,843 ETH and 1.68M USDC (later swapped to DAI), resulting in ~$8.5 million losses (about 68% of the vaults’ then-TVL).
Amount of loss: $ 8,500,000 Attack method: Governance Attack
Description of the event: On August 23, 2026, the Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was drained via Uniswap V3 spot-price manipulation. The attacker flash-loaned 1,800 WETH from Morpho Blue, skewed the pool’s instantaneous spot price, minted vault shares at the distorted valuation, restored the price, and burned the shares for a richer token mix, netting ≈2.94 WETH. Root cause: mint()/burn() valued the Uniswap V3 position off pool.slot0() with no TWAP or deviation guard (TWAP only protected rebalance()).
Amount of loss: $ 7,018 Attack method: Flashloan Price Manipulation
Description of the event: The ERC-20 bridge of warp.green (a cross-chain messaging protocol between Chia and EVM chains) suffered an exploit due to a vulnerability in the Chia-side Chialisp puzzle. The attacker minted worthless CAT tokens, presented them as burned wUSDC, obtained validator signatures, and drained ~$93,000 USDC from the Base and Ethereum bridge contracts, later converting the funds to ETH. The CAT bridge (securing assets like wXCH) appears unaffected.
Amount of loss: $ 93,000 Attack method: Smart Contract Vulnerability
Description of the event: Layer 1 blockchain TAC was exploited when an attacker used a vulnerability in the shared Cosmos EVM precompile layer to drain approximately 2.985 billion TAC tokens (valued at around $7.5 million) from a single account. The project confirmed it was a drain (not a mint), total supply unchanged, only $TAC affected, and the flaw is not in TAC-specific code. The chain was halted at block 24,671,475; the team is coordinating with SEAL 911 and exchanges to track funds and plans to release a post-mortem and relaunch plan.
Amount of loss: $ 7,500,000 Attack method: Contract Vulnerability
Description of the event: The Sandbox’s SAND cross-chain bridge (LayerZero OFT on Base and BNB Chain) was exploited. The attacker used a configuration function to gain sole verifier rights, minting large amounts of unbacked SAND and draining approximately 14.74 million real SAND (~$675,000) from the Ethereum vault. The project quickly halted affected bridging; Ethereum and Polygon assets remained unaffected.
Amount of loss: $ 675,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 19, 2026, the cross-chain bridge Allbridge was attacked. The attacker had prepared on July 26 by calling Circle’s MessageTransmitterV2.sendMessage on Polygon to forge a CCTP-style message claiming a 1M USDC transfer (with no actual burn) and obtained a valid attestation. On Aug 19, after a real CCTP deposit brought the Base Router balance to ~191k USDC, the attacker used the forged message via receiveCctpMessage (which lacked proper verification and credited it as a real deposit), flash-loaned ~809k USDC from Aave to match the claimed amount, and withdrew ~999k USDC, netting ~$189,800.
Amount of loss: $ 190,000 Attack method: Bridge Logic Flaw
Description of the event: Maya Protocol (MAYAChain) suffered a security vulnerability attack. The attacker exploited 6 chained edge-case bugs in Trade Account, outbound handling, and pool math, inflating accounting via false subsidy (e.g., ARB.LINK pool), then added/removed liquidity to extract ~48.87M CACAO and convert to ~20.83 BTC plus other assets, causing ~$1.7 million loss. The team paused global operations to fix the issues and seeks fund recovery.
Amount of loss: $ 1,700,000 Attack method: Smart Contract Vulnerability
Description of the event: FoxMarket (a DeFi project on BSC) had its FoxLpBondsPool.stake() function calculate and fix _stakeAmount from a manipulable Pancake AMM spot quote before a large USDT→Fox swap. The attacker used flash loans to skew pair reserves, then addLiquidity used a mismatched ratio; Treasury.lpBonds() trusted the stale value, minted excess Fox tokens, and sent inviter rewards to an attacker-controlled address, which were sold in the same transaction.
Amount of loss: $ 118,700 Attack method: Flash Loan Attack
Description of the event: The Harmony Layer-1 blockchain was exploited, allowing an attacker to unauthorizedly mint approximately 4 billion ONE tokens (about 26% of the supply) via empty blocks and related flaws. Large amounts were quickly funneled to exchanges for sale, causing the token price to crash ~30-40%. The team confirmed the incident, paused the cross-chain bridge, released an emergency validator patch to stop further minting, coordinated with exchanges to freeze funds, and is evaluating a chain rollback.
Amount of loss: $ 3,200,000 Attack method: Protocol Logic Vulnerability