Advertisement

Hacks

Spotlighting security breaches, exploits and unauthorized access incidents within the cryptocurrency ecosystem.

Top Stories

Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault

Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault

Blockaid says an attacker used a registered price-feed forwarder and future-dated oracle reports to book fake trading profits, in the latest exploit to target the automated infrastructure DeFi protocols lean on for pricing.

Recent articles

Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault

Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault

Blockaid says an attacker used a registered price-feed forwarder and future-dated oracle reports to book fake trading profits, in the latest exploit to target the automated infrastructure DeFi protocols lean on for pricing.
Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees

Prism Relaunches on New Contract After Exploit Diverted Nearly 40% of Fees

A pseudonymous team is redeploying the Uniswap v4 token that pays fees to everyone who holds it, after a bad actor created 2,500 'phantom' fee positions. The original token has crashed more than 90% in a day.
Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit

Bonzo Lend Loses $9M on Hedera in Supra Oracle Exploit

A single manipulated price feed let an attacker turn 250 SAUCE tokens worth a few dollars into $9.05 million in borrowed USDC and wrapped HBAR in eight seconds.
Summer.fi Hacker Moves $1.35M Into Tornado Cash

Summer.fi Hacker Moves $1.35M Into Tornado Cash

Summer.fi's own post-mortem confirms the attacker began laundering the $6M haul through the mixer, calling it a sign of "limited intent to return the funds voluntarily."
BonkDAO Attacker Moves $19M Loot Into New 'BONK 2.0' DAO

BonkDAO Attacker Moves $19M Loot Into New 'BONK 2.0' DAO

The wallet behind BonkDAO's $20 million governance attack has parked most of the stolen BONK in a multisig controlled by a newly created shadow DAO, Chainalysis said in a post on its official X account Tuesday.
EMURGO Says Hacked Cardano Wallet SecondFi Won't Reopen

EMURGO Says Hacked Cardano Wallet SecondFi Won't Reopen

EMURGO, the Cardano-founding entity behind SecondFi, said Monday the hacked wallet service will not resume normal operations even after ongoing security audits conclude, telling all users to migrate away using its official recovery process. "Although we believe unaffected users remain safe,…
BonkDAO Treasury Drained of $20M via Malicious Proposal

BonkDAO Treasury Drained of $20M via Malicious Proposal

BonkDAO, the decentralized autonomous organization tied to the Solana-based memecoin BONK, said Monday it was the target of a malicious governance proposal that drained an estimated $20 million worth of BONK tokens from its treasury, according to a post on its official X account. The DAO said the…
Summer Finance Drained of $6M in Flash Loan Exploit

Summer Finance Drained of $6M in Flash Loan Exploit

DeFi vault platform Summer Finance was drained of roughly $6 million on Monday in an exploit that security firm Blockaid said its detection system flagged as it was unfolding. Blockaid posted the exploit transaction, the attacker's address and the affected Lazy Summer contracts within minutes of…
Chinese Exile Miles Guo Sentenced to 30 Years for $1B Crypto Fraud Scheme

Chinese Exile Miles Guo Sentenced to 30 Years for $1B Crypto Fraud Scheme

A federal judge ordered Guo to forfeit $889 million after a jury convicted him of running a scheme that raised over $1 billion partly through the fake Himalaya Coin cryptocurrency.
AMLBot Puts Polymarket Phishing Toll at $3.1M Across 11 Wallets, Funds Traced to Ethereum

AMLBot Puts Polymarket Phishing Toll at $3.1M Across 11 Wallets, Funds Traced to Ethereum

Blockchain intelligence firm AMLBot has confirmed the Polymarket supply-chain attack total at approximately $3.1 million in PUSD across 11 user wallets, with funds bridged from Polygon to Ethereum and converted to ETH. Polymarket has pledged full refunds but has not named the compromised vendor.