420 hack event(s)
Description of the event: Crypto casino Duelbits’ multi-chain hot wallets (Ethereum, BSC, Tron and Bitcoin) suffered a suspected private key compromise, with about $4.9 million transferred to newly created addresses; most funds were swapped to ETH, and the site was taken offline for investigation.
Amount of loss: $ 4,900,000 Attack method: Private Key Leakage
Description of the event: The personal X account of Nano Labs founder Jack Kong was compromised. Attackers used it to promote a fake AI trading token called Binance World Assets ($BWA), claiming it would use trading fees on BNB Chain to trade bStocks and share profits with holders. Nano Labs’ official account later stated that the posts were unauthorized, that the company had not issued or endorsed any such token, and warned users not to click links or send funds to any contracts.
Amount of loss: - Attack method: The X account was hacked
Description of the event: The Drop project suffered an attack via a malicious governance proposal, through which the attacker transferred treasury funds, resulting in a loss of approximately $4.4 million.
Amount of loss: $ 4,400,000 Attack method: Governance Attack
Description of the event: Astroport (a Cosmos ecosystem DEX) announced a security incident on the Neutron chain that may have resulted in the theft of admin privileges for its contracts. Neutron has halted chain operations for investigation, and the project advised users to immediately withdraw liquidity from all Astroport pools across chains. Terra-side contracts were unaffected.
Amount of loss: $ 4,900,000 Attack method: Compromised administrator privileges
Description of the event: On September 9, 2026, an attacker used a single transaction on Citrea mainnet and ~200,000 USDC.e of flash liquidity as temporary collateral to drain 140,000 ctUSD and 30 USDC.e from Zentra’s lending pool. The root cause was an accounting edge case in repayWithATokens: the debt path could complete while the matching aToken burn was reduced to zero. The operations multisig paused all markets about 17 minutes later; no second exploit occurred.
Amount of loss: $ 140,030 Attack method: Smart Contract Vulnerability
Description of the event: Bitcoin sidechain Liquid Network was exploited via an Elements range-proof verification cache bug, allowing creation of about 4,000 unbacked LBTC. The actor then used SideSwap’s standard peg-out path to withdraw about 4,000 BTC ($320,000,000) from the federation reserve. Liquid said no private keys were compromised. The actor, claiming to be a white hat, returned 3,400 BTC on September 7 and still holds about 598.5 BTC ($47,000,000). The network remains paused.
Amount of loss: $ 320,000,000 Attack method: Elements Software Vulnerability
Description of the event: An attacker exploited a vulnerability in Ankr’s ankrFLOW liquid staking contract to mint approximately 8.6 million unbacked ankrFLOW tokens, then used them as collateral with More Markets’ E-mode to drain about 15.5 million WFLOW (~$410,000 at spot) from the lending reserve. The attacker realized roughly $246,000 after slippage. The Flow Foundation stated the root cause was in Ankr’s Solidity contract, not Flow EVM or More Markets.
Amount of loss: $ 410,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 30, 2026, an attacker looped borrowing and re-supplying Tectonic’s governance token TONIC as collateral while manipulating its price by ~195x, then borrowed about $120.4 million from multiple Tectonic lending markets in one transaction. Cronos halted and rolled back the chain, restoring on-chain assets to the pre-exploit state; approximately $9.19 million that left Cronos before the halt remains unrecovered. Supply and borrow remain paused.
Amount of loss: $ 120,400,000 Attack method: Price Manipulation
Description of the event: An attacker exploited a vulnerability in Switchboard’s production code to add a controlled key to a live oracle, published false prices roughly 100 times below market, deposited into Full Sail vaults at distorted values, then restored prices and withdrew more than deposited.
Amount of loss: $ 91,000 Attack method: Oracle Manipulation
Description of the event: The BLND-USDC liquidity pool of CometDEX (Comet AMM) on the Stellar network was exploited due to an accounting bug that allowed same-asset swaps (USDC→USDC), corrupting reserve calculations. The attacker used flash loans from a Blend pool and repeated the process about 36 times to extract excess funds, resulting in a loss of approximately $717,518.92 USDC. Funds were subsequently moved.
Amount of loss: $ 717,518.92 Attack method: Smart Contract Vulnerability
Description of the event: Maya Protocol (MAYAChain) suffered a security vulnerability attack. The attacker exploited 6 chained edge-case bugs in Trade Account, outbound handling, and pool math, inflating accounting via false subsidy (e.g., ARB.LINK pool), then added/removed liquidity to extract ~48.87M CACAO and convert to ~20.83 BTC plus other assets, causing ~$1.7 million loss. The team paused global operations to fix the issues and seeks fund recovery.
Amount of loss: $ 1,700,000 Attack method: Smart Contract Vulnerability
Description of the event: Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/consolidated to a single Ethereum address. Client funds remained unaffected in separate trust accounts; services were briefly paused for security checks and have been fully restored.
Amount of loss: $ 11,800,000 Attack method: Hot Wallet Compromise
Description of the event: Solido Cash (the largest DeFi protocol on Supra) was exploited due to an oracle misassignment on SOLID collateral (stale feed fallback to CASH oracle, severely overvaluing collateral). The attacker, in two waves (one atomic tx + one multi-wallet manual), deposited cheap collateral, minted excess CASH, and sold it on DEXs for SUPRA, netting ~293.7M SUPRA. No user funds were affected; losses primarily hit LPs (mostly the foundation) and protocol reserves. The protocol paused relevant functions and released a forensic report.
Amount of loss: $ 73,400 Attack method: Oracle Misassignment
Description of the event: Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The borrowed funds were subsequently swapped on SaucerSwap and bridged to Ethereum via LayerZero (over $5M tracked on-chain). Bonzo Lend paused the protocol shortly after detecting abnormal activity.
Amount of loss: $ 9,050,000 Attack method: Oracle Price Manipulation
Description of the event: Quicksilver Zone (Cosmos Liquid Staking protocol) was exploited via Unchecked Proof Minting vulnerability. The attacker forged proofs to mint large amounts of unbacked qATOM (~505K) and qOSMO (~10M). The chain was halted; actual drained loss was limited (~$3,500). The team is working with Cosmos Hub and Osmosis to burn fake tokens and recover.
Amount of loss: $ 3,500 Attack method: Smart Contract Vulnerability
Description of the event: Haedal Protocol’s Vault pools on Sui suffered an exploit due to a hidden cross-version logic flaw from a 2025 upgrade. The attacker used deprecated old deposit paths to mint inflated LP shares and redeemed them via new paths for excess underlying assets, causing ~$915k in direct losses. Haedal has paused the affected contracts, will fully compensate users, and is preparing a patched upgrade.
Amount of loss: $ 915,179 Attack method: Smart Contract Vulnerability
Description of the event: On June 8, 2026, OpenMonero's P2P trading platform server was breached. The hacker gained root access and stole approximately 200 XMR. The project owner announced on Telegram that all funds were lost; the attack was not at the application layer.
Amount of loss: $ 62,900 Attack method: Supply Chain Attack
Description of the event: GoPlus issued a security alert stating that the X account of crypto KOL Jadoodoo (@jadoodoo_ ) has been hacked. The attacker is sending phishing links via direct messages to fans under the guise of collaboration offers. Multiple KOLs have already fallen victim, with total losses of around $5,000.
Amount of loss: $ 5000 Attack method: Social Engineering
Description of the event: A vulnerability in the Phala Cloud API endpoint allowed unauthorized modifications to some Offchain KMS CVMs. The attacker deployed a malicious pre-launch script to affected CVMs, which may have accessed decrypted environment variables after boot. The issue was identified, patched, and contained on June 1, 2026. Affected users/CVMs have been directly notified via email.
Amount of loss: 0 Attack method: API endpoint vulnerability
Description of the event: HermesVault, an Algorand-based privacy protocol using zero-knowledge proofs for private transactions, was exploited. The attacker exploited a flaw in the key reset defense logic within the withdrawal verification script. This allowed bypassing the zero-knowledge (zk) verification process and unauthorized withdrawal of funds. The protocol permanently shut down operations following the incident. Lead engineer Giulio Pizzini confirmed that the core zk circuit remained secure, but the auxiliary withdrawal script had a vulnerability. The team patched the issue, refunded a large portion of the funds, and initiated a full refund process for affected users.
Amount of loss: $ 29,466 Attack method: Smart Contract Vulnerability