News
Coverage of crypto exploits, drains and scams, alongside reports filed by people who lost funds. Every item names the addresses involved and what PublicAML sees on them.
Investigations
- Where Amir Capital’s money went: a four-chain trace
- Finiko: what the chain says, and why the published totals conflict
- Finiko’s FNK token: the $14 million taken from its pool two years after the collapse
- FomoPeek: the App Store app that read wallet keys off the phone
- Term Labs: all of the stolen ETH went to Tornado Cash, and the DAI went to Robinhood Chain
- Nesa: the "$50 million" exploit that cashed out at about 109 ETH, into KuCoin
- Nomic and Osmosis allBTC: the 40.65 BTC nobody noticed for 74 days
- Tectonic: the branch that skipped Tornado — 232 XMR1 still sitting on Hyperliquid
- Liquid Network hack: the 598.5 BTC has not moved
Items marked Report are filings from readers, published as they were filed. Most have not been checked by anyone, and an unchecked report puts no risk label on any address. File a report.
- News
Nostra Faces $3.5 Million Loss from Rigged Oracle Pool
Nostra experienced a significant loss due to a manipulated oracle price feed. The incident involved a fake NSTR price that was 8,306 times the actual value, leading to unauthorized borrowing.
- News
Astroport Suffers $4.9 Million Loss from Malicious Proposal
Astroport experienced a significant security incident resulting in a loss of $4.9 million. The incident was triggered by a malicious proposal that compromised the platform.
- News
Drop suffers $4.4 million loss from malicious proposal
Drop experienced a significant financial loss due to a malicious proposal. The incident resulted in a loss of $4.4 million.
- Report · Theftethereum2 addressesInvestigator
Other blackmail report VR-0E90FB07
Second violent robbery in the same ZachXBT investigation, published 24 August 2026. On 20 April 2026 multiple attackers targeted a victim in France, tied them up and threatened them until they surrendered ~$110K in crypto. The stolen funds went to 0x3000d2A2ef9Bd8b614b368408768a6e25Bf4dE0F. Laundering path per ZachXBT: the funds were bridged to Ethereum and ~46 ETH (~$107K) was laundered through a Kucoin deposit address. Timing analysis on the matching Kucoin withdrawal identified 0x5fb7194CC893CdC8339fA1bD7E8B52cDB3d3d075, which then consolidated with proceeds from the first robbery. Both addresses in this report belong to the same operation: - 0x3000d2A2ef9Bd8b614b368408768a6e25Bf4dE0F — theft address, received the stolen funds directly - 0x5fb7194CC893CdC8339fA1bD7E8B52cDB3d3d075 — received the Kucoin withdrawal after laundering The investigation attributes both April 2026 robberies to a French actor operating as M1llionz / RichMilly666, $667K taken across the two incidents. The first robbery (17 April, ~7.2 BTC) is filed separately as VR-5B01D18E. ZachXBT's work led to a $93K Tether freeze tied to the case. Category note: physical coercion, not an online scam. The form has no category for robbery or extortion under physical threat, so this is filed under the closest available option (other blackmail). Source: ZachXBT thread, https://x.com/zachxbt/status/2091858014236295170 (posts 4/ and 5/ name these addresses). Filed by PublicAML from public reporting, not by a victim.
- News
DoinGud NFT Platform Exploited for $35,486 via Bug
The NFT platform DoinGud was exploited for $35,486 due to a bug in its bidding contract.
- News
Authorization Flaw in GaslessReservoirEnabler Leads to $23,000 Loss
An authorization flaw in the GaslessReservoirEnabler contract allowed an attacker to drain funds from multiple token-holder addresses. The incident affected approximately 997 addresses, resulting in a total loss of $23,000.
- News
Internet Token DAO Exploited for $265,000 in LiquidityUnifier Incident
Internet Token DAO's LiquidityUnifier was exploited, resulting in a significant loss. The attacker manipulated a Uniswap V3 pool address to mint a large amount of INT tokens.
- News
RWC Token Exploited on BSC via Flash Loan Attack
The RWC token on the BNB Smart Chain was exploited through a flash loan, resulting in a loss of approximately 109,460.85 USDT. The attack involved an unprotected burn function that allowed the attacker to manipulate token reserves.
- News
The Internet Token suffers loss due to arbitrary external call
The Internet Token experienced a loss of $16,380 due to an arbitrary external call. The incident highlights vulnerabilities in the token's smart contract interactions.
- News
Where Amir Capital's money went: a three-chain trace
An on-chain trace of the Amir Capital investment scheme across Bitcoin, Tron and Ethereum. 4,262 BTC and $51.1M in USDT passed through wallets that are empty today, but one Aave position worth roughly $17.8M is still live — and it moved to a new address on 11 August 2026.
- News
Blink Wallet Pauses Services After Security Incident
Blink Wallet has paused its services to investigate a security incident involving custodial accounts. An attacker accessed a limited number of these accounts and withdrew funds, but most funds remain secure.
- News
Fetch.ai Suffers $1.53 Million Loss Due to Private Key Compromise
Fetch.ai experienced a significant security incident resulting in a loss of $1.53 million. The breach was attributed to a compromised private key.
- News
MultiversX Network Paused Due to Exploit Attempt
An exploit attempt on the MultiversX mainnet led to invalid on-chain state changes. The network was paused to prevent further impact while engineers worked on a fix.
- News
NuNet Suffers Loss Due to Private Key Compromise
NuNet experienced a significant security incident resulting from a compromised private key. The incident led to a loss of $462,730.
- News
Likwid Exploited for $55,721 Due to Contract Bug
The BNB Chain DeFi protocol Likwid suffered an exploit resulting in a loss of $55,721. The incident involved a bug in the margin-borrow contract that allowed the attacker to drain funds from the vault.
- News
Nomic Flaw Leads to $3.15 Million Loss for Osmosis
A flaw in Nomic's forwarding logic resulted in a significant loss for Osmosis. The incident involved the minting of unbacked nBTC and the subsequent movement of funds to Tornado Cash.
- News
Nostra DeFi Protocol Exploit Results in $3.5 Million Loss
Nostra, a DeFi lending protocol, experienced an exploit due to oracle price manipulation. An attacker borrowed approximately $3.5 million in various cryptocurrencies using inflated collateral.
- News
Nostra Money Market Suffers $3.5 Million Loss from Price Manipulation
Nostra Money Market experienced a significant loss due to spot price manipulation. The incident resulted in a total loss of $3.5 million.
- News
Bonfiretoken Incident Involves $50,000 Loss Due to Access Control Flaw
An access control vulnerability in the BonfireSwap router led to a loss of approximately $50,000. The incident affected around 41 approved holders of the token.
- News
Flamincome Exploited for $345,900 Due to Unsafe Asset Accounting
Flamincome, associated with Flamingo Finance, suffered an exploit resulting in a loss of $345,900. The incident involved unsafe asset accounting and valuation techniques.
- News
Liquid Network Exploit Results in $320 Million Loss
An exploit in the Liquid Network led to a significant loss of funds. The incident involved the minting of unbacked L-BTC through a cache-key collision.
- News
Nimiq Targeted by Meta-Transaction Auth Flaw Exploit
An attacker exploited a vulnerability in OpenGSN meta-transactions affecting Nimiq. The incident resulted in a loss of approximately $50,463.
- News
Startale Suffers Loss Due to Improper Access Control
Startale experienced a security incident resulting in a loss of $2,876. The incident was attributed to improper access control mechanisms.
- News
Bonfire Suffers $47,400 Loss Due to Improper Access Control
Bonfire experienced a security incident resulting in a loss of $47,400. The incident was attributed to improper access control mechanisms.
- News
DCENT Wallet Issues Urgent Security Alert Over Abnormal Transfers
DCENT Wallet reported abnormal asset transfers in its mobile App Wallet, prompting an investigation. Users are advised to transfer funds to secure wallets immediately.
- News
Exploitation of Liquid Network Results in $320 Million Loss
An actor exploited a vulnerability in Elements to mint unbacked L-BTC, draining $320 million from Liquid Network. The actor returned a majority of the funds but retained a portion, leading to ongoing disputes.
- News
Long Bridge Incident Involves Fabricated Withdrawals
Long Bridge experienced a security incident where funds were released due to fabricated events. The issue was resolved the same day without user losses.
- News
Spiral Suffers Loss from Uniswap V4 Pool Manipulation
Spiral experienced a loss of approximately $26,800 due to a manipulation of the Uniswap V4 pool spot price. The attack involved bypassing a guard mechanism to borrow against inflated collateral.
- News
Tectonic Suffers $120.4 Million Loss from Token Manipulation
An attacker inflated Tectonic's TONIC token and borrowed against it, leading to significant losses. A rollback recovered most of the funds, but a portion remains unrecovered.
- News
Chainflip Exploited on TRON USDT Integration, Leading to Significant Loss
Chainflip lost 736,442.17 USDT on its TRON USDT integration to duplicated refunds. PublicAML traced the exploiter, its funding wallet and a 749,000 USDT consolidation that is moving to a Binance deposit address.
- News
Dominion Market's $SILV Treasury Compromised, $238K Lost
Dominion Market's Solana silver token $SILV experienced a treasury multisig compromise, resulting in a loss of $238,000. The attacker exploited a 3-of-5 key mechanism to deplete the treasury and manipulate token liquidity.
- News
Ether.fi Liquid Users Lose Funds Due to Access Control Exploit
Users of ether.fi Liquid lost approximately 15.45 ETH due to an exploit. The incident affected around 11 users.
- News
$50 million bridged from Nesa to Ethereum in security incident
An attacker bridged 257.7 million NES from Nesa to Ethereum, resulting in a loss of approximately $50 million. The incident is linked to a known bug chain affecting multiple platforms.
- News
OMNI404 Token Exploit Results in Loss of $5,923
An exploit involving the OMNI404 token led to a loss of $5,923. The attack utilized flash loans and Uniswap V3 swaps to drain funds from the pool.
- News
ORBToken Exploited for $32,610.72 on BSC
ORBToken suffered an exploit resulting in a loss of $32,610.72. The attack involved exploiting vulnerabilities in the token's functions and mechanisms.
- News
Symbiosis Bitcoin Bridge Exploit Results in $336,000 Loss
An exploit of Symbiosis's Bitcoin Bridge led to a significant loss of funds. The attacker minted unbacked syBTC and sold WBTC on Ethereum.
- News
Private Key Compromise at Dominion
Dominion experienced a security incident involving a compromised private key. The details regarding the mechanism and financial loss are not specified.
- News
Symbiosis Suffers $336,000 Loss from Unbacked Cross-Chain Mint
Symbiosis experienced a loss of $336,000 due to an unbacked cross-chain mint incident.
- Report · Phishingethereum1 addressInvestigator
Tech support phishing report VR-F1AD2F0C
Wallet attributed to Veer Chetal ("Wiz"/"Swag") in the $243M social-engineering theft of 19 August 2024, published by ZachXBT on 19 September 2024. The case: three actors — Malone Iam ("Greavys"), Veer Chetal ("Wiz"/"Swag") and Jeandiel Serrano ("Box"/"John") — socially engineered a single victim out of 4,064.3769 BTC (~$238M at the time, $243M across all assets). ZachXBT's investigation contributed to multiple arrests and to millions being frozen; a later superseding indictment confirmed the arrest of a further participant in Dubai. This address appears in ZachXBT's OSINT chart labelled "Wallet Address" for Veer Chetal. PublicAML read it out of that chart and verified it on-chain: an externally owned account, 109 transactions, activity clustered in early September 2024 — days after the theft — and our engine already scored it 40 on indirect exposure, tracing an inbound path from a mixer two hops out. Two other addresses in the same chart were deliberately NOT reported. PublicAML's own data classifies 0x6ef702810a1A221682FdEBCbd353e6E249e4248e and 0xe8Bde8169a2f6eD6855201AFcAc7Be05a5639B25 as centralised-exchange hubs. They are labelled "Wallet address" in the chart, but flagging an exchange hub would brand an intermediary rather than an actor. The seizure address published in a later update (0xb37d617716e46511E56FE07b885fBdD70119f768) is likewise excluded — it belongs to the authorities holding recovered funds. Category note: filed under tech-support phishing as the closest available label; the actual method was voice-based social engineering impersonating exchange and platform support. Source: https://x.com/zachxbt/status/1836752923830702392. Filed by PublicAML from public reporting plus our own verification, not by a victim of the incident.
- Report · Hackbsc6 addressesInvestigator
Contract exploit report VR-4690757D
LULA exploit on BNB Smart Chain, 29 July 2026, ~$578K lost. Reported by CertiK Alert; PublicAML read the addresses out of their call-trace screenshot and verified the contract types on-chain. Mechanism visible in the trace: a chain of contracts calls claimTeamReward() and claimReferralReward() on the LULA contract, which triggers recycle(amount = 5,466,425,413,399,659,914,651) and then LULA.transfer() payouts back to the callers. The privileged recycle() path is abused to mint rewards repeatedly. Addresses reported here, all with the same role — callers that received the drained LULA: 0x2a6Cf8592D1CC22BEd916481bb745ccAf80aE6F1 (received 5,335,604,142,729,676,918,919 LULA) 0xF60F0895301fdEF5f4795A8A6b57f5cb2A664E3c 0xFE2554A23b352dEC8A93aFD2DD463A453d8eE0CE 0xfD7eaBd41D826ADBA28Ef982BcC75AB1C679E4FA 0x6222155a9010Ec62dDe38e8E1606c7Bcd4Ce5897 0x296f885d55Fd78482e2bE4BC660518BE7E4d4481 (received 280,821,270,669,982,995,732 LULA) Verified via eth_getCode on BNB Smart Chain: the first five are minimal-proxy clones (48 bytes of code each) — disposable contracts deployed to repeat the reward claim. The last is an externally owned account. Deliberately NOT reported: 0x377a015f44C3FDf71060e94648EDC9e0316C7f1a appears in the same trace, but it carries 43,764 bytes of code and does not respond to name(). It may be protocol infrastructure rather than attacker-controlled, and we do not flag an address we cannot place with confidence. Source: https://x.com/CertiKAlert/status/2082309959484911845. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Hackethereum2 addressesInvestigator
Contract exploit report VR-56B95658
Verus Ethereum Bridge exploit, 23 July 2026, ~$7.53M drained. Reported by CertiK Alert; PublicAML recovered the full addresses from their screenshot and verified everything on-chain. Root cause per CertiK: the "hashOfTransfers" value calculated from "serializedTransfers" decoded to draining transfers, letting the caller push forged imports through the bridge. 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c — the caller. Verified on-chain: submitImports on the Verus bridge contract 0x71518580f36FeCEFfE0721F06bA4703218cD7F63 in block 25592836 at 03:45:59 UTC on 23 July 2026, transaction 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099. The same address had called setLatestData twice in the minutes before. 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 — the recipient of the drained assets. All seven ERC-20 transfers in that transaction went here: 71.5 tBTC ($4.69M), 220,357 DAI, 149,275 USDC, 78,300 USDT, 92,784 scrvUSD, 31,475 EURC and 59.43 MKR, plus 1,137.45 ETH ($2.19M) as an internal transfer. Our enrich already flagged it as mixer-interaction before this report. Both are externally owned accounts, not contracts. The bridge contract itself is the victim and is not reported here. Source: https://x.com/CertiKAlert/status/2080153763332174170. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Hackethereum2 addressesInvestigator
Contract exploit report VR-99A3B8E7
Addresses laundering the proceeds of the Term Labs exploit (23 August 2026, ~$8.5M lost), reported by PeckShieldAlert on 4 September 2026. PeckShield's alert referenced the exploiter address only inside a screenshot. PublicAML recovered the full addresses from the block numbers visible in that screenshot and verified every movement on-chain. 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e — deposits into Tornado Cash. Verified on-chain: four deposits of 100 ETH each into the Tornado Router in blocks 25904455, 25904456, 25904457 and 25904460 on 4 September 2026 between 14:08:35 and 14:09:35 UTC. PeckShield reported 960 ETH (~$2.35M) deposited in total. Our own enrich already flagged this address as mixer-interaction before this report. 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 — the funding address that supplied it. Verified on-chain: 100 ETH on 24 August, 400 ETH on 4 September 13:58, 100 ETH and 400 ETH on 4 September 19:10-19:12, then 2,000 ETH and 41.48 ETH on 5 September 05:03-05:16. Both are externally owned accounts, not contracts, and both are now effectively empty. Note on roles: PeckShield labels the first address the "Term Labs exploiter". The second is upstream of it and is recorded here as the source of the laundered funds, not as a separately confirmed exploiter. Source: https://x.com/PeckShieldAlert/status/2095881691017646109. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Phishingethereum1 addressInvestigator
Tech support phishing report VR-B373F58A
Ethereum leg of the same support-impersonation theft, exposed by ZachXBT on 10 August 2026. In June 2026 a victim lost $1.2M in Bitcoin and Ethereum after the group drained their Trezor wallet, following a spoofed BitcoinIRA email sent under the alias "Patricia Massie". ZachXBT names this address alongside the bitcoin address in post 3/ of the thread. The bitcoin leg (6.9944 BTC, moved 19 June 2026) is filed separately as a Bitcoin report — this form accepts one chain per report. Method: the actor phones victims posing as exchange or hardware-wallet support and talks them into surrendering access to their funds. ZachXBT published recordings of her taunting victims after draining them. A second actor using the aliases "bled" and "harm" appears to have supplied the phishing panel infrastructure. The investigation names Tiffany Milanovich, a US-based threat actor tied to at least $5M in thefts of this type. Amount note: the $1.2M figure is the total loss across both chains as reported by ZachXBT; he does not break it down per chain. The 46 ETH entered here is the largest single movement observed on this address on-chain (11 August 2026), not a confirmed split of the stolen total. The address is now effectively empty. Source: ZachXBT thread, https://x.com/zachxbt/status/2086785488149774411. Filed by PublicAML from public reporting, not by a victim of the incident.
- Report · Phishingbitcoin1 addressInvestigator
Tech support phishing report VR-9FD8D72C
Theft address from a support-impersonation ("caller") operation exposed by ZachXBT on 10 August 2026. In June 2026 a victim lost $1.2M in Bitcoin and Ethereum. The group drained the victim's Trezor wallet after a spoofed BitcoinIRA email sent under the alias "Patricia Massie". The bitcoin leg of the theft went to this address: 6.9944 BTC arrived and left on 19 June 2026 across two transactions, and the address is now empty. Method: the actor phones victims posing as exchange or hardware-wallet support and talks them into surrendering access. ZachXBT published call recordings in which she taunts victims after draining them. Another actor operating as "bled"/"harm" appears to have supplied the phishing panel infrastructure. The investigation names Tiffany Milanovich, a US-based threat actor tied to at least $5M in thefts from hardware-wallet and centralised-exchange support impersonation. The Ethereum leg of the same June 2026 theft is 0x491333E8EA6f4fC2a2475DB01b649e1E4602ec3c, filed separately because this form takes one chain per report. Source: ZachXBT thread, https://x.com/zachxbt/status/2086785488149774411 (post 3/ names this address). Filed by PublicAML from public reporting, not by a victim of the incident.
- Report · Theftbitcoin1 addressInvestigator
Other blackmail report VR-5B01D18E
Theft address from a violent home invasion robbery in France, published by ZachXBT on 24 August 2026. On 17 April 2026 five attackers carried out a home invasion robbery against a victim in France and took ~7.2 BTC (~$557K). Several people were hospitalised. The stolen bitcoin was sent to this address. Laundering path per ZachXBT: the funds were bridged from Bitcoin to Ethereum via Chainflip, and $317K was then laundered through three Kucoin deposit addresses. He performed timing analysis on the matching withdrawals to link them to the same actor. The investigation attributes this and a second robbery (20 April 2026) to a French actor operating as M1llionz / RichMilly666, with $667K taken across both incidents. ZachXBT's work led to a $93K Tether freeze tied to the case. Category note: this was physical coercion, not an online scam. PublicAML's report form has no category for robbery or extortion under physical threat, so this is filed under the closest available option (other blackmail). The correct label would be theft under coercion. Source: ZachXBT thread, https://x.com/zachxbt/status/2091858014236295170 (post 2/ names this address). Filed by PublicAML from public reporting, not by a victim of the incident.
- News
Amnext Exploited for $116,100 via Mass Minting
The Amnext protocol on BSC was exploited, resulting in a loss of $116,100. An attacker mass-minted Ticket AMC and drained funds through PancakeSwap.
- News
BeatSwap Exploit Results in $77,512 Loss on BSC
BeatSwap was exploited on the BSC chain, leading to a loss of $77,512. The attack involved manipulating the price oracle used by the platform.
- News
BeatXswap Suffers Loss from Spot Price Manipulation
BeatXswap experienced a loss due to spot price manipulation. The incident resulted in a financial impact of $77,512.
- News
Nomic nBTC Bridge Exploit Results in $3.15 Million Loss
A bug in Nomic's forwarding mechanism allowed an attacker to double-spend nBTC. The incident led to the freezing of funds and a governance proposal to recover losses.
- News
Zentra Finance Exploited for $140,030 via Flash Loan Attack
Zentra Finance suffered a loss of $140,030 due to a single transaction exploit. The attack involved using flash liquidity to drain funds from the lending pool.
Archive
- Website phishing report VR-B11FE031
- Website phishing report VR-F1D5B63D
- Protocol attack report VR-717BCCC5
- $50 million bridged from Nesa to Ethereum in security incident
- $50 million NES bridged from Nesa to Ethereum in security incident
- WealthManagementV2 Contract Exploited for 26,414 USDT Loss
- Cozy Finance Exploit Results in $170,000 Loss
- DEX Router Exploit on BSC Results in Loss of $46,070
- Liquid Network Exploit Results in $320 Million Loss
- Dream Health Chain Suffers $71,800 Loss Due to Reward Logic Flaw
- Reddio's RedSonic Vault Exploited for $22,940 on Ethereum
- Reddio RedSonic Suffers Loss Due to Incorrect Share Accounting
- Rocket Suffers $287K Loss from Exploit of Dormant Market
- Secured Finance Ethereum Lending Market Drained
- Notional Finance Exploited for $1.73M in Legacy Contract Attack
- Arithmetic Error Leads to Loss for Notional V2
- Unauthorized Transactions Affect XRPH Wallet Users
- GebProxyActions Contract Exploited for $14,000
- KiiChain Loses $9.7 Million in Cosmos EVM Exploit
- TAC Loses $7.5M Due to Cosmos EVM Underflow Bug
- Ankr Suffers $410,000 Loss from Unbacked Mint Incident
- Aquifer Exploited for $2.5 Million in Funds
- Balancer V1 Exploit Results in $234,000 Loss
- Float Protocol Suffers $28,000 Loss from Spot Price Manipulation
- Mantra suffers $3.6 million loss from Cosmos EVM underflow bug
- MORE Markets Suffers $9.3 Million Loss Due to Borrow Logic Flaw
- Radix Suffers $1.25 Million Loss Due to Improper Access Control
- Rounding Error Leads to $234,000 Loss on Balancer V1
- Tectonic Suffers $75 Million Loss from Spot Price Manipulation
- Spot Price Manipulation Incident at Weft V2
- Fogo Foundation Compromised, 400 Million Tokens Sent to Bad Actor
- Oracle Misconfiguration Affects Full Sail
- Security Incident Involving Permapod
- Other report VR-1AC08533
- Ajna V2 Suffers $775,400 Loss Due to Liquidation Logic Flaw
- Withdrawal Logic Flaw Leads to Significant Loss for Avici
- Fogo Foundation Suffers $3 Million Loss from Private Key Compromise
- Mantra Suffers $3.6 Million Loss Due to Cosmos EVM Underflow Bug
- Oracle Misconfiguration Leads to Significant Loss for Virtue
- CashCowCoin suffers $117,400 loss due to flawed trading router
- CCC Suffers $117,000 Loss Due to Swap Logic Flaw
- Moonwell DeFi Protocol Suffers $8.79 Million Attack
- FH Token Exploit on BSC Results in $20,000 Loss
- Term Labs Vaults Drained Due to Governance Exploit
- CometDEX Suffers $717,000 Loss Due to Incorrect Share Accounting
- Enjin Suffers Ownership Takeover Incident
- FH Token Suffers $20,000 Loss Due to Swap Logic Flaw
- Steakhouse Financial Suffers $920,000 Loss Due to Risk Parameter Abuse
- Arithmetic Error Leads to $50 Million Loss for Nesa
- Arithmetic Error Leads to $90,750 Loss at PacaSwap DEX
- Spot Price Manipulation Incident on Arrakis V1
- Surf Lending Suffers Private Key Compromise
- Malicious Proposal Targets TermFinance Vaults, Causing $8.5M Loss
- Warp.green ERC-20 Bridge Exploit Results in $93,000 Loss
- KiiChain Suffers $9.7 Million Loss Due to Arithmetic Error
- Withdrawal Logic Flaw Leads to $7.5M Loss for TAC
- Improper Access Control Incident at The Sandbox
- Improper Access Control Incident on MANTRA Chain
- The Sandbox SAND Bridge Exploited for $675,000
- MANTRA Chain exploited for 720.9 million tokens due to vulnerability
- Allbridge Suffers $191,000 Loss Due to Logic Flaw
- BounceBit Suffers $3 Million Loss Due to Improper Access Control
- Harmony Suffers $3.2 Million Loss Due to Replay Attack
- Maya Protocol Suffers $1.7 Million Loss Due to Withdrawal Logic Flaw
- FoxMarket Exploit Results in $118,700 Loss
- Bodega Market Suffers Security Incident
- $8.07 Million Lost from Coinsbuy in Under an Hour
- Cold Card Firmware Vulnerability Leads to $130 Million Theft
- Infinite Mint Incident on Harmony Bridge
- Harmony Protocol Exploited, 4 Billion ONE Tokens Minted Unauthorized
- USM Protocol Exploit Results in $136,000 Loss
- Coinsbuy Loses Over $7.9 Million in Crypto Drain
- Coreum Bridge Suffers $200,000 Loss Due to Logic Flaw
- Unbacked Cross-Chain Mint Incident at Oraichain
- Atomic Green Suffers $29,984 Loss from Signature Replay Exploit
- Unbacked Cross-Chain Mint Incident Affects Oraichain
- Security incident involving Ravencoin confirmed
- Private Key Compromise at Hyperliquid Malaysia
- KITE Foundation Pauses Transfers After Token Compromise
- Malicious Proposal Targets Panther Protocol
- RRWallet Suffers $2 Million Loss Due to Weak Key Generation
- Unistreets LaunchpadFactoryAuto Contract Exploited
- Unistreets Suffers $17,750 Loss Due to Arbitrary External Call
- ZEUS Infrastructure Experiences Cybersecurity Incident
- Access Control Exploit on RISEx Results in $673,000 Loss
- LOOPSDAO Exploited for $690,000 on BSC
- MOKE Token Exploit on BNB Chain Results in Significant Loss
- Critical Entropy Vulnerability in Coldcard Wallet Leads to $70.2 Million Loss
- Set Protocol Exploited Due to Smart Contract Vulnerability
- Private Key Compromise at Swan Treasury Results in Significant Loss
- VerusCoin Ethereum Bridge Exploit Results in $7.54 Million Loss
- Crypto DAO Exploit Results in $52,000 Loss
- LULA Token Exploited on BSC Leading to Significant Loss
- AFX Trade Loses $24.15 Million Due to Compromised Validator Signatures
- ChainConnect EVM Integration Compromised, $650,000 Lost
- Garden Finance Exploit Results in $450,000 Loss
- WEMIX Smart Contract Compromised, $6.25 Million Lost
- Social Account Takeover Incident at Bankr
- Bankrbot X Account Compromised, Wallet Drained
- Projekt reward vault exploited on Ethereum
- DeBond Suffers $542,000 Loss Due to Accounting Error
- Lien Finance Exploited for $542K in USDC
- Triple-A Suffers Unauthorized Access to Hot Wallets
- Solido Cash Exploited Due to Oracle Misassignment
- Verus Ethereum Bridge Exploited for $7.54 Million
- 42DAO Exploit Leads to Significant Losses
- AFX Bridge Exploited for $24.15 Million USDC
- Zilliqa Suffers Hidden Number Problem Exploit
- Unauthorized Withdrawal Detected at FlashTrade
- Ostium Loses $23.75 Million Due to Price Manipulation
- Wanchain Cardano-BNB Chain Bridge Exploited for $10 Million
- Allbridge Core Exploited for $1.65 Million
- Zilliqa Cold Wallet Theft Linked to Ledger App Vulnerability
- Attack on Across Cross-Chain Bridge Protocol
- FlyCow Suffers $65,300 Loss Due to Incorrect Share Accounting
- DefiTuna Lending Exploit Results in $580K Loss
- BarnBridge Suffers Governance Attack Resulting in $776,000 Loss
- Cascade Platform Suffers $1.34 Million Attack on Arbitrum
- Price Oracle Manipulation Incident at Cascade Liquidity Strategy
- Ostium Suffers $18 Million Oracle Manipulation Exploit
- TeleSwap Cross-Chain Bridge Exploited with $735,000 Loss
- Bonzo Finance Loses $9.05 Million Due to Oracle Verifier Error
- Drips Network Exploited for $24,900 Due to Integer Vulnerability
- Chi Protocol Exploited for $8,500 Due to Logic Error
- Lumi Finance Exploit Results in $270,000 Loss
- BlueMove DEX Suffers $529,000 Loss Due to LP-share Inflation
- Bonzo Lend Exploited for $9.05 Million via Oracle Vulnerability
- $19.3 Million Drained from BonkDAO in Governance Attack
- $6.04 Million Stolen from Summer Finance's Lazy Summer Depositors
- BonkDAO Governance Attack Results in $20M Loss
- Lazy Summer Protocol Exploit Results in $6.04M Loss
