Crypto scammers created a counterfeit version of the Upbit-backed GIWA blockchain and tricked DYORSWAP into integrating it, leading to the theft of approximately 767 ETH (about $2 million) from over 1,300 wallets that bridged funds to the fake Layer 2 network. DYORSWAP has paid over 200 ETH in compensation to affected users.
THORChain declined Bitget's formal request to block addresses linked to the $387.5 million hack, stating it 'doesn't censor by design' and comparing itself to Bitcoin's permissionless nature, while approximately $6 million in stolen funds moved through the protocol.
Bitget announced on September 26, 2026 that withdrawals would restart in phases after its September 24 wallet security incident, beginning with BTC on September 28, then ETH, USDT and other assets on later scheduled dates. Availability should be checked on the platform as each phase begins.
Crypto casino and sports betting platform Duelbits confirmed a hack that drained approximately $7 million from its hot wallets across multiple blockchain networks including Ethereum, BNB Chain, Tron, and Bitcoin. The platform took its site offline following the suspected private key compromise, though it stated user funds remain safe.
A vulnerability in Limit Break's Payment Processor V2 left NFTs listed on Magic Eden's now-closed EVM marketplace between February and October 2024 exposed to potential theft. Whitehat researchers rescued 23,155 NFTs worth more than $5.7 million before malicious actors could exploit the flaw.
Evercrest Technologies, developer of KelpDAO, filed a civil claim in British Columbia against LayerZero Labs, its Canadian entity, and CEO Bryan Pellegrino over the April 2026 rsETH bridge exploit that caused roughly $292 million in losses. The lawsuit alleges LayerZero failed to disclose technical vulnerabilities and endorsed the setup used in the exploit.
Crypto exchange Bitget confirmed unauthorized transfers affecting approximately $351.6 million in assets from hot wallets on September 24, temporarily suspending withdrawals across all assets while investigating the security breach.
Brooklyn man Ronald Spektor, 23, was sentenced to four to 12 years in prison after pleading guilty to all 31 counts related to a phishing operation that stole nearly $16 million from approximately 100 Coinbase users.
Cosmos Hub validators stopped block production for nearly 25 hours following a governance attack on Neutron that initially led to losses of approximately $9.5 million, moving 1.23 million ATOM from attacker wallets after restart.
A joint operation between Microsoft, Coinbase, and law enforcement has taken down EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 email inboxes across more than 10,000 organizations and traced $1.1 million in crypto theft.
A group claiming responsibility for a Revolut data breach is demanding 6,000 XMR (roughly $3 million) within 24 hours, threatening to sell stolen customer data including passport information and Bitcoin transaction histories. The breach reportedly exposed data on at least 680 customers.
Polish prosecutors charged a fifth person in the Zondacrypto exchange investigation, with a Katowice court ordering pretrial detention. The probe involves an estimated $94-100 million in losses related to alleged fraud and organized crime at the exchange.
XRP Healthcare disclosed that approximately 4,011 XRPH Wallet accounts were affected by unauthorized transactions beginning September 3, 2026, resulting in the theft of around $452,000 in XRP and related assets, including 267,664 XRP and 23.2 million XRPH tokens that have been traced on-chain.
Malone Lam, 22, is expected to plead guilty in federal court to orchestrating a $240-245 million Bitcoin theft by impersonating Google and Gemini staff to trick a Washington investor. A Singaporean co-conspirator also pleaded guilty.
Blockstream's Liquid Network disabled its bridge nodes after approximately 4,000 BTC ($320 million) were withdrawn from the federation wallet to a single address. The withdrawer left an on-chain message stating "we are whitehats."
Chilean crypto exchange Orionx, backed by Tether, is permanently closing after a forensic audit uncovered more than $7 million in customer assets moved to wallets outside the exchange's control. The company announced it is beginning a permanent shutdown process.
Hardware wallet manufacturer Trezor disclosed on September 4 that an additional 67,000 US customers were affected by the ShipMonk shipping partner data breach, bringing the total to approximately 80,700. The breach exposed names, addresses, and phone numbers of customers who ordered between November 2019 and August 2021.
The Financial Crimes Enforcement Network analyzed 33,904 suspicious activity reports and identified $12.7 billion in crypto transactions linked to pig butchering and other scams operated from Asian compounds.
DeFi protocol Notional Finance suffered a $1.7 million exploit on September 4, with an attacker draining approximately $69,000 in DAI and $1.66 million in USDC from a legacy escrow contract through an integer overflow bug. The stolen funds were reportedly moved to Tornado Cash.
Wallets linked to North Korea's Lazarus Group moved more than $30 million in Bitcoin through decentralized exchange Hyperliquid over three weeks, raising sanctions compliance questions as the platform pursues US market entry through talks with Kraken parent Payward.
Blockchain security firm CertiK reported that crypto losses reached approximately $215 million in August 2026, with DeFi exploits accounting for $144.6 million. Major incidents included a $75 million price manipulation attack on Tectonic protocol that halted the Cronos Network and a $9.3 million exploit of More Markets on Flow EVM.
The Cronos blockchain halted block production on Sunday after an attacker exploited Tectonic, its largest lending protocol, by artificially inflating the TONIC token price roughly 100-fold and using it as collateral to borrow approximately $75 million in assets. Validators paused the network, stranding most of the stolen funds.
DeFi lending protocol Moonwell suffered an $8.7 million exploit after an attacker manipulated the price of MAMO token to borrow real assets against inflated collateral, prompting the protocol to set borrow caps to 1 wei across Base markets.
HumidiFi, one of Solana's busiest decentralized exchanges, suspended all trading on August 22 after an internal network incident compromised a portion of its own systems. The platform clarified that customer assets were not affected, only platform funds.
The Sandbox contained a vulnerability in its SAND cross-chain bridge on Base and BNB Smart Chain after an attacker minted approximately 500 million unbacked tokens. The project stated the impact was under $1 million, though the full extent of damage remains unclear.
MANTRA Chain, a Layer 1 blockchain focused on real-world asset tokenization, halted network operations following an unspecified security incident. The native token dropped 18.5% to an all-time low before partially recovering.
Coinkite released new firmware for Coldcard hardware wallets following a randomness vulnerability that enabled attackers to steal $114 million in Bitcoin, adding user-supplied entropy and stricter transaction checks.
Cross-chain decentralized exchange Maya Protocol suspended its network after an attacker exploited multiple software vulnerabilities to steal approximately $1.7 million in Bitcoin and other cryptocurrencies. The exploit caused the protocol's native CACAO token to plummet 89%.
Bitcoin hardware wallet manufacturer BitBox released firmware version 9.26.5 to address severe security vulnerabilities discovered during internal security reviews that utilized AI models. The company confirmed no funds were stolen but urged users to update their devices.
People claiming to be BitMart employees took control of the exchange's Chinese X account, demanding the CEO provide answers by August 19 about frozen user funds and unpaid wages after the exchange shut down.
Cryptocurrency wallet provider SafePal disclosed a security breach that exposed names, physical addresses, and contact details of 39,798 customers. The breach follows a similar incident at Trezor days earlier that affected 13,689 users.
DeFiLlama founder 0xngmi downloaded a fake DeFiLlama app from Apple's App Store, funded a wallet, and let the scam app steal the funds as proof of the scam. Apple removed the fake listing days later after months of inaction on reports.
An unknown crypto whale lost $25.6 million after an attacker drained their wallet on August 12. The hacker swapped the stolen assets into DAI and ETH. The same wallet had previously lost $24 million in a phishing attack two years ago.
A demonstrated consensus flaw let invalid blocks onto Ravencoin starting at block height 4,487,776 on August 7. Pools controlling majority hashpower are mining a replacement chain, putting deposits and withdrawals made since then at risk.
BTCPay Server disclosed a critical vulnerability that allowed attackers to remotely hijack Lightning Network nodes and drain bitcoin payment servers. Supporters have committed to a recovery bounty of 10% of any stolen funds recovered, capped at 3 BTC (approximately $190,000).
Crypto payment processor Coinsbuy was hit by a security breach on August 9, 2026, draining over $7.9 million from wallets across Ethereum and TRON networks. The attacker converted stolen assets into Monero, a privacy-focused cryptocurrency that complicates transaction tracing.
Following $3.4 billion in crypto thefts in 2025 and over $1 billion stolen in the first half of 2026, investigators reveal hackers have approximately 45 days to launder stolen assets before trails go cold. The Bybit exchange has recovered $48.4 million after suing North Korea's Lazarus Group, with a US court freezing $30.5 million in related assets.
BTCPay Server disclosed a critical vulnerability being actively exploited and urged users to immediately update to version 2.4.2 or shut down their servers. Foundation and Citadel21 reported their Lightning nodes were drained, in some cases hours before the public alert.
Crypto exchange Bybit filed a civil lawsuit against North Korea, its intelligence agency, and the Lazarus Group over the February 2026 hack. A U.S. federal judge granted Bybit's request to trace stolen assets.
Non-custodial Bitcoin bridge Boltz halted all swap services indefinitely after a surge of AI-assisted hacking attempts over recent months outpaced the team's ability to patch vulnerabilities. The service connects Bitcoin's main chain with Lightning Network and Liquid sidechain.
An attacker exploited a publicly accessible vault function in Crypto DAO on July 28, draining $8.2 million in USDT from the protocol. Security firm Blockaid flagged the exploit involving the access-control bug.
An attacker exploited a missing eight-byte check in Across Protocol's offchain code to fabricate $41.7 million in Solana deposit events, draining approximately $4 million from a Risk Labs-operated relayer on July 17, 2026. The attack was part of a broader wave of cross-chain bridge exploits that drained over $35 million across multiple protocols within hours.
Two unrelated bridge exploits hit AFX Trade and Verus Protocol within seven hours, draining approximately $24 million and $7.5 million respectively through compromised bridge infrastructure on Arbitrum and other chains.
Decentralized derivatives protocol AFX Trade on Arbitrum suffered a $24.15 million USDC loss on July 22 after an attacker compromised its cross-chain bridge validator signing keys. The stolen funds were converted to approximately 12,467 ETH on Ethereum.
A security breach in Wanchain's bridge connecting Cardano to BNB Chain resulted in the theft of between 290-515 million NIGHT tokens (valued at approximately $10M), causing the Midnight privacy network token to plunge 43% to a record low of $0.01524 before rebounding 19%. Seven major exchanges have frozen stolen funds.
Cross-chain bridge protocol Allbridge Core has paused operations following a flash loan exploit that drained approximately $1.65 million from its Solana stablecoin liquidity pools. The attacker used a $1.12 million flash loan from Kamino to manipulate pool ratios before bridging funds to Ethereum.
Hedera-based lending protocol Bonzo Lend (also referred to as Sauce Protocol) suffered approximately $9 million in losses after an attacker manipulated the price oracle for SAUCE collateral, allowing them to borrow assets far beyond deposited value. The stolen funds were bridged from Hedera to Ethereum.
Cryptocurrency projects lost approximately $972 million across 207 hack incidents in the first half of 2026, marking the highest number of attacks ever recorded despite total losses remaining below the $1 billion threshold, according to Immunefi's report.
Summer Finance (Summer.fi) suffered a $6 million exploit on July 6, with attackers draining funds from its USDC vault through a flash loan attack. The vault's advertised yield briefly spiked past 2 million percent before the breach.
Security researchers from Hexens identified and reported a significant security flaw in the Aptos blockchain using a $3,000 server. The vulnerability has since been patched, preventing potential risk to approximately $70 billion in cryptocurrency.
North Korean cybercriminals stole $643 million in cryptocurrency during the first six months of 2026, representing two-thirds of all crypto lost to theft and exploits globally during that period. The theft occurred amid a record number of heists but reduced overall losses compared to previous periods.
DeFi lending protocol Edel Finance halted its version-one protocol after an attacker exploited the wrapping mechanism for tokenized Alphabet stock, artificially inflating collateral values by 7,700% and extracting $403,000. The team stated no depositors would bear losses.
Ethereum-based rollup Taiko confirmed a compromise of its chain state verification mechanism, halting block production and urging users to withdraw funds. The exploit resulted in approximately $1.7 million in losses.
Attackers exploited TOP token's governance system by gaining over 50% voting power with minimal token supply, using Aragon DAO to create, vote on, and execute a malicious proposal in a single transaction that minted tokens worth $1.58 million.
Attackers compromised private keys of a Humanity Protocol foundation member through an employee laptop breach, draining over $32-36 million worth of H tokens from multiple wallets. The decentralized identity project's token plunged between 73-89% as attackers dumped stolen tokens for ether.
Syscoin halted its bridge after an attacker exploited a validation issue to mint approximately 5 billion unauthorized SYS tokens on the network's UTXO chain. The project is tracing the unauthorized tokens and investigating the breach.
DeFi protocol losses from exploits fell from $2.62 billion in 2022 to $680.3 million in 2025, according to Immunefi, even as Chainalysis reports attackers are increasingly targeting unverified smart contracts, which accounted for $36.7 million in losses across four exploits in the past six months.
Aave published an official postmortem tracing a $230 million exploit to a LayerZero bridge verification failure and announced a sweeping overhaul of its asset-listing standards as DeFi risks shift beyond smart contract bugs.
Gravity Bridge, the cross-chain bridge connecting Ethereum and Cosmos, was exploited for approximately $5.4 million in digital assets including $4.3 million in USDC and 274 ETH, with investigators pointing to a compromised signing key rather than a smart contract vulnerability.
European stablecoin issuer StablR suffered a contract exploit draining between $3-10 million, causing EURR and USDR to crash over 20% below their pegs. On-chain investigator ZachXBT flagged the incident as a live hack affecting StablR-linked contracts.
Echo Protocol suffered a bridge exploit where an attacker minted 1,000 eBTC (worth approximately $76.64 million) on Monad using a compromised admin key, then used the fake eBTC to borrow real crypto assets. The protocol suspended all cross-chain transactions.
The Verus-Ethereum cross-chain bridge was drained of approximately $11.5 million on May 18 through a forged Merkle proof exploit. The attack adds to May 2026's growing tally of DeFi exploits and brings the year's total bridge hack losses to $329 million.
Following a $292 million KelpDAO exploit, crypto projects with over $3 billion in total value locked migrated their cross-chain infrastructure from LayerZero to Chainlink's CCIP. Solv Protocol moved $700 million in tokenized Bitcoin infrastructure as part of the migration.
Aave LLC filed an emergency motion in U.S. federal court to lift a restraining order freezing approximately $73 million in Ether recovered after the Kelp DAO exploit, as a law firm attempts to seize the funds claiming links to North Korean hackers.
TRM Labs reports that North Korean state-backed hackers stole $577 million in two April exploits (including the $285 million Drift hack), representing 76% of all crypto losses in 2026. The regime has now stolen over $6 billion in cryptocurrency since 2017.
A coalition of DeFi protocols including Aave, Compound, and others unveiled a detailed technical plan to eliminate bad debt and restore full backing for exploited rsETH tokens following the $290 million Kelp DAO hack, with pledges totaling over $300 million in recovery funds.
Sui-based liquid staking platform Volo Protocol was exploited for approximately $3.5 million from its WBTC, XAUm, and USDC vaults. The team has pledged to absorb losses and frozen affected assets while conducting an investigation.
The Arbitrum Security Council froze $71 million worth of ETH stolen in the $292 million Kelp DAO exploit, with funds only movable through further governance action. Kelp DAO and LayerZero continue to dispute responsibility for the bridge vulnerability.
A coalition of DeFi protocols deployed a joint emergency mechanism to help Aave ETH lenders and loopers exit positions after the Kelp DAO bridge exploit created systemic risk across lending markets. The response demonstrates DeFi's architectural openness can produce rapid crisis solutions.
Attackers drained approximately 116,500 rsETH (roughly $292-293 million) from Kelp DAO's LayerZero-powered bridge, causing emergency freezes across multiple DeFi protocols including Aave, SparkLend, Fluid, and Upshift. The exploit represents 2026's largest crypto hack to date and impacted at least nine protocols.