Hedgey Finance Token Locker Drained via Unrevoked Smart Contract Approval
A critical business logic flaw failed to revoke token approvals, allowing unauthorized `transferFrom` calls to drain $44.7 million in locked assets.
Orange Finance Drained $843k Exploiting Misconfigured Multi-Signature Access Control
Misconfigured multi-signature access enabled a single-signature contract upgrade, bypassing governance to facilitate complete asset extraction.
DeFi Lender CrediX Drained via Compromised Admin Key Unbacked Token Minting
A compromised admin key allowed the attacker to mint unbacked collateral tokens, bypassing solvency checks and draining the protocol's liquidity.
Typus Finance Drained $3.4 Million Exploiting Custom Oracle Access Flaw
Unaudited custom oracle code with a missing authorization check enabled a $3.4M price manipulation attack on the TLP contract.
Exchange Solana Hot Wallet Compromise Drains Thirty-Seven Million Assets
A failure in centralized access controls allowed the coordinated, unauthorized withdrawal of $37M in Solana-based assets, underscoring systemic key management risk.
Decentralized Social Protocol Suffers Multisig Wallet Delegate Call Exploit
A critical delegate call vulnerability in the protocol's administrative multisig allowed arbitrary code execution, leading to unauthorized token minting.
Centralized Exchange Hot Wallet Compromise Drains Thirty-Seven Million Solana Assets
A critical failure in key management or access control allowed unauthorized transfers, exposing the systemic risk of CEX hot wallet custody.
Cross-Layer Protocol Private Key Leak Compromises User Funds and Contract Ownership
Server-side private key storage for admin functions enabled immediate contract ownership transfer, draining 227 user wallets.
Yearn Legacy Pool Drained by Infinite Token Minting Logic Flaw
A critical logic flaw in a legacy stableswap contract allowed an attacker to mint unauthorized yETH, compromising $9M in deposited assets.
