Advertisement

Hacks

Taiko Bridge Drained $1.7M After SGX Signing Key Left Exposed on GitHub
Hacks

Taiko Bridge Drained $1.7M After SGX Signing Key Left Exposed on GitHub

An attacker forged withdrawal proofs using an RSA-3072 private key accidentally committed to Taiko’s public raiko GitHub repository, draining $1.7 million from L1 bridge contracts and forcing the protocol to halt block production and urge all users to exit.
Secret Network's Axelar Bridge Drained $4.67M via Infinite-Mint Flaw
Hacks

Secret Network's Axelar Bridge Drained $4.67M via Infinite-Mint Flaw

Secret Network's cross-chain bridge to Axelar has been suspended after an attacker exploited a years-old minting flaw in a CW20-ICS20 contract to drain $4.67 million in wrapped tokens over seven undetected days. The exploit ran from June 10 to June 17, drained seven Axelar-wrapped assets, and has sparked a dispute between the two teams over contract responsibility.
Jaredfromsubway.eth, Ethereum's Most Active Sandwich Bot, Drained for $7.5M Over the Weekend
Hacks

Jaredfromsubway.eth, Ethereum's Most Active Sandwich Bot, Drained for $7.5M Over the Weekend

An attacker drained more than $7.5 million from jaredfromsubway.eth, the Ethereum address tied to roughly 70% of sandwich attacks on the network, after a counter-MEV honeypot fed it 66 fake token contracts over several weeks. Blockaid disclosed the exploit Saturday.
Dormant Wallet Tied to HashFlare Fraud Moves 10,600 ETH Worth $18.5M
Hacks

Dormant Wallet Tied to HashFlare Fraud Moves 10,600 ETH Worth $18.5M

An Ethereum address tied to the HashFlare cloud-mining Ponzi moved 10,600 ETH worth about $18.5 million on Monday morning after sitting idle for roughly three and a half years. Onchain investigator ZachXBT, with help from security firm Cyvers, flagged the movement, the first activity from the address since the long-running scheme collapsed.
Aztec Connect Drained of $2.1M Through Deprecated Contract Three Years After Shutdown
Hacks

Aztec Connect Drained of $2.1M Through Deprecated Contract Three Years After Shutdown

An attacker exploited a proof-verification flaw in Aztec Connect's abandoned RollupProcessorV3 contract to withdraw roughly $2.1 million, including 909 ETH, from a privacy bridge that Aztec Labs shut down three years ago and can no longer control.
Thetanuts Finance: $2.1M Attack, Partial White-Hat Recovery
Hacks

Thetanuts Finance: $2.1M Attack, Partial White-Hat Recovery

The on-chain options and structured product protocol Thetanuts Finance was exploited for $2.1 million. Security firm Blockaid published the exploit transaction and exploiter address shortly after the attack.
Q2 2026 Sets All-Time High for DeFi Hack Count With ~70 Exploits, $746M Stolen
Hacks

Q2 2026 Sets All-Time High for DeFi Hack Count With ~70 Exploits, $746M Stolen

DeFi logged approximately 70 separate exploits in Q2 2026, roughly doubling the previous quarterly record, even as the $746 million dollar total remains a fraction of historical single-event peaks.
Attacker Mints 10 Billion TOP Tokens Through Governance Takeover, Drains $1.58M from Balancer Pool
Hacks

Attacker Mints 10 Billion TOP Tokens Through Governance Takeover, Drains $1.58M from Balancer Pool

An attacker exploited Token of Power's Aragon DAO on Tuesday to mint 10 billion TOP tokens via a malicious governance proposal, then swapped the supply for 944.2 WETH worth roughly $1.58 million.
Raydium Confirms $1.34M Drain on Deprecated AMM V3, Pledges Treasury Compensation
Hacks

Raydium Confirms $1.34M Drain on Deprecated AMM V3, Pledges Treasury Compensation

Raydium core contributor Infra confirmed Wednesday that an attacker drained ~$1.34M from the legacy AMM V3 program, a contract phased out in 2021. Current users were unaffected, the treasury will cover full compensation, and the root cause was a self-contained LP-mint validation flaw. PeckShield earlier traced the laundering across KuCoin, a Solana-to-Ethereum bridge, Tornado Cash and FixedFloat.
Humanity Protocol Traces $36M Hack to Single Malware-Infected Machine That Held Seven Keys
Hacks

Humanity Protocol Traces $36M Hack to Single Malware-Infected Machine That Held Seven Keys

A forensic report from Humanity Protocol found a single malware-infected developer machine held backups of seven private keys, giving an attacker full control over both its Ethereum and BNB Smart Chain infrastructure.