498 hack event(s)
Description of the event: The DeFi protocol Neutrl announced on platform X that its frontend appears to have been compromised and that the team is conducting an urgent investigation. Out of an abundance of caution, the official advisory recommends that users refrain from interacting with the website until further updates are released. Additionally, Neutrl urged users to immediately revoke Permit2 approvals for relevant addresses via Revoke.cash. Users were also reminded to check and revoke approvals granted to other suspicious addresses to mitigate potential asset risks.Subsequently, Neutrl's preliminary investigation revealed that the DNS provider hosting the application's domain was subjected to a social engineering attack, resulting in the redirection of the domain by the attackers.
Amount of loss: 0 Attack method: Supply Chain Attack
Description of the event: dTRINITY disclosed on X that yesterday, the dLEND deployment on Ethereum suffered its first deposit inflation attack. This incident drained the dUSD liquidity in the lending pool, resulting in approximately $257,000 in bad debt.The protocol has been temporarily paused, and the team is actively working on remediation measures. They have committed to covering 100% of the losses using internal funds. Repayment of the bad debt will begin within 24 hours of the announcement, after which dLEND is expected to resume operations.Deployments of dTRINITY on Fraxtal and Katana were not affected, and user funds remain safe. Each deployment maintains isolated reserves, collateral, and lending pools across different chains.
Amount of loss: $ 257,000 Attack method: First Deposit Inflation Attack
Description of the event: Aave V3 suffered a CAPO (Capped Asset Price Oracle) misconfiguration by Chaos Labs, which undervalued wstETH by ~2.85%. This triggered wrongful liquidations on 34 healthy positions, resulting in ~$862,000 in losses. Aave DAO fully compensated affected users; no protocol funds were stolen.
Amount of loss: $ 862,000 Attack method: Oracle Misconfiguration
Description of the event: According to monitoring by BlockSec Phalcon, the DBXen contract was attacked this morning, with estimated losses of approximately $150,000.The root cause lies in a sender identity inconsistency within the ERC-2771 meta-transaction mechanism.
Amount of loss: $ 150,000 Attack method: Smart Contract Vulnerability
Description of the event: Gondi V3 NFT lending protocol’s “Sell & Repay” contract (Purchase Bundler feature) was exploited. The attacker bypassed ownership checks due to an access control flaw and stole escrowed NFTs (approximately 78 NFTs) worth ~$230,000. The team disabled the vulnerable contract and committed to compensating affected users; other platform functions remained unaffected.
Amount of loss: $ 230,000 Attack method: Smart Contract Vulnerability
Description of the event: The Bitcoin staking protocol Solv Protocol stated on X that its BRO Vault experienced a limited exploit. Fewer than 10 users were affected, with a loss of 38.0474 SolvBTC (approximately $2.7 million). Other vaults and user funds were not impacted, and mitigation measures have already been implemented to prevent similar incidents. The team has committed to fully covering the losses of the affected users. They also told the attacker that a 10% white-hat bounty will be offered if the funds are returned promptly. The attacker can contact the team via direct message or by sending an on-chain message to a designated address.
Amount of loss: $ 2,700,000 Attack method: Smart Contract Vulnerability
Description of the event: According to BlockSec Phalcon’s monitoring, its system detected a suspicious transaction targeting an Inverse Finance contract on Ethereum several hours ago, resulting in a loss of approximately $240,000. The incident appears to involve DOLA price manipulation, which forced multiple users to liquidate their positions.
Amount of loss: $ 240,000 Attack method: Price Manipulation
Description of the event: On March 2, 2026, Curve Finance’s LlamaLend sDOLA/crvUSD market suffered a flash-loan + donation attack. The attacker first used a massive LLAMMA exchange to push all positions into soft liquidation, then inflated the sDOLA oracle price by 13.79% (1.189 → 1.353) via DolaSavings.stake() donation. This hard-liquidated 27 borrowers (~$10.9M debt). Attacker profited ~$240K; borrowers lost ~$822K equity (Curve DAO later proposed full compensation). Lenders and core protocol unaffected.
Amount of loss: $ 240,000 Attack method: Donation Attack
Description of the event: The DeFi lending protocol Wise Lending V2 was exploited via a flash loan attack. The attacker drained approximately $66,000 from the protocol’s pools by exploiting logic vulnerabilities. The incident affected deployments on Ethereum and Arbitrum.
Amount of loss: $ 66,000 Attack method: Flash Loan Attack
Description of the event: The DeFi lending protocol Ploutos Money suffered an exploit due to a misconfigured price oracle (using Chainlink’s BTC/USD feed for USDC price), allowing an attacker to deposit minimal USDC collateral and borrow ~187.36 ETH, draining approximately $390K. The project’s website and social accounts were deleted shortly after, raising strong suspicions of an inside job or exit scam.
Amount of loss: $ 390,000 Attack method: Oracle Misconfiguration
Description of the event: WLFI announced on X that USD1 experienced an organized attack this morning. The attackers reportedly compromised the accounts of several WLFI co-founders, paying influencers to spread FUD (Fear, Uncertainty, and Doubt) and heavily shorting $WLFI in an attempt to profit from artificially created market chaos. WLFI stated that the operation failed. Thanks to USD1’s robust minting and redemption mechanisms and its 100% 1:1 asset backing, USD1 remains stable and is currently trading near its par value. The team emphasized that no bad actors can shake their long-term commitment to USD1. Meanwhile, WLFI reminded users to obtain accurate information only through officially verified channels and to be wary of misleading content.
Amount of loss: - Attack method: Social Engineering
Description of the event: Aperture Finance (Aperture LM) was exploited for approximately $3.67 million across Ethereum, Base, Arbitrum, and BSC. The root cause was an arbitrary-call vulnerability in its closed-source V3/V4 contracts due to insufficient input validation on low-level calls. Attackers abused existing user token and Uniswap V3 LP NFT approvals to drain funds via transferFrom operations. The team paused affected features, urged users to revoke approvals, and published a security incident analysis.
Amount of loss: $ 3,670,000 Attack method: Smart Contract Vulnerability
Description of the event: According to PeckShieldAlert monitoring, the Makinafi protocol was exploited by hackers, resulting in a loss of approximately 1,299 ETH (about $4.13 million). The stolen funds are currently held in two addresses: 0xbed2...dE25 (around $3.3 million) and 0x573d...910e (around $880,000). News on January 23: Makina, a DeFi execution engine, posted on X stating that at 21:15 on January 22, the MEV Builder returned funds according to the SEAL Safe Harbor, deducting a 10% bounty. Approximately 920 ETH (out of 1,023 ETH collected) was returned, accounting for a portion of the total ~1,299 ETH stolen. The funds have been transferred to the recovery multi-sig address 0xc22F...8AB9. The team is continuing to pursue the remaining funds and is seeking to contact the RocketPool validator address 0x573D...910E, which received approximately 276 ETH.
Amount of loss: $ 4,130,000 Attack method: Smart Contract Vulnerability
Description of the event: The blockchain verification protocol Truebit was suspected to have been hacked, losing 8,535 ETH, valued at approximately $26.44 million.
Amount of loss: $ 26,440,000 Attack method: Smart Contract Vulnerability
Description of the event: According to monitoring by Paidun, Yearn Finance V1 suffered a hacker attack, resulting in a total loss of approximately USD 300,000. The attacker has converted the stolen funds into 103 ETH, which are currently held at the address: 0x0F21...4066.
Amount of loss: $ 300,000 Attack method: Unknown
Description of the event: On December 14, Aevo announced that a vulnerability introduced during a smart contract upgrade led to an attack on the legacy Ribbon DOV vault on December 12, resulting in losses of approximately $2.7 million.
Amount of loss: $ 2,700,000 Attack method: contract vulnerability
Description of the event: According to PeckShieldAlert, the stablecoin project USPD has suffered a major security breach, resulting in approximately $1 million in losses. The USPD team later confirmed that the protocol had been exploited, with the attacker minting tokens without authorization and draining liquidity. The official team has urgently advised users to revoke all token approvals granted to the USPD contract. According to the project’s confirmation, the incident was identified as a “CPIMP” attack. During the deployment phase, the attacker used Multicall3 to preemptively initialize the proxy and seize administrator privileges, while disguising the malicious implementation as an audited contract. The hidden logic remained dormant for several months before being activated, allowing the attacker to upgrade the proxy, mint approximately 98 million USPD tokens, and transfer around 232 stETH. The USPD team has disclosed the attacker addresses (Infector: 0x7C97…9d83, Drainer: 0x0833…215A) and stated that they are working with law enforcement and white-hat partners to trace the funds. The team has also offered a 10% bounty if the attacker returns the stolen assets.
Amount of loss: $ 1,000,000 Attack method: "CPIMP" (Clandestine Proxy In the Middle of Proxy) attack
Description of the event: The on-chain private fund Goldfinch’s old contract on Ethereum (0x0689) contained a vulnerability. Because the user deltatiger.eth did not revoke the authorization in time, they were exploited and lost approximately USD 330,000. The attacker has already sent 118 ETH (around USD 329,000) into the privacy mixer Tornado Cash.
Amount of loss: $ 330,000 Attack method: contract vulnerability
Description of the event: According to PeckShieldAlert on X, Yearn Finance suffered an attack in which the hacker drained the liquidity pool by infinitely minting yETH, causing losses of roughly $9 million. Approximately 1,000 ETH (about $3 million) was transferred to Tornado Cash, while the attacker’s address still holds around $6 million worth of crypto assets. On December 1, according to PeckShield’s monitoring, Yearn recovered 2.4 million USD by burning the pxETH held by the hacker. An equivalent amount of pxETH has been re-minted and returned to the Redacted Cartel multisig wallet.
Amount of loss: $ 9,000,000 Attack method: Contract Vulnerability
Description of the event: The DeFi protocol Balancer V2 suffered a vulnerability exploit that affected its Composable Stable Pools. The root cause of the incident was an incorrect rounding direction in the Stable Pool’s “exact-out” swap path. This flaw was amplified under conditions of precision errors introduced by rate providers and extremely low liquidity, allowing the attacker to manipulate the invariant and distort the BPT price calculation. As a result, the attacker was able to withdraw large amounts of assets from the pool at a cost far below their real value.The attack caused a total loss of $121.1 million across Ethereum, Arbitrum, Base, Optimism, and Polygon. As of November 19, coordinated mitigation efforts enabled several security measures to be deployed promptly after the issue was discovered, resulting in approximately $45.7 million in user funds being protected or recovered.
Amount of loss: $ 121,100,000 Attack method: Business Logic Flaw