Cross-Layer Protocol Private Key Leak Compromises User Funds and Contract Ownership
Server-side private key storage for admin functions enabled immediate contract ownership transfer, draining 227 user wallets.
Aerodrome Velodrome DNS Hijacking Compromises User Token Approvals
Centralized DNS registrar vulnerability enabled front-end hijacking, exposing user wallets to malicious token approval transactions.
Cork Protocol Drained Twelve Million Exploiting Dual Smart Contract Flaws
A sophisticated attacker leveraged two distinct, unpatched contract vulnerabilities to drain collateral and expose systemic audit failures.
Lending Protocol Drained Exploiting Collateral Price Oracle Glitch
An external oracle mispriced a wrapped staked asset by 29,000,000%, allowing an attacker to over-collateralize and drain $1M.
Lending Protocol Rho Markets Drained via Oracle Price Manipulation on Scroll
The Rho Markets lending protocol was drained of $7.6 million by a compromised oracle, proving external data dependency remains a critical attack surface.
Moonwell Protocol Drained via Collateral Oracle Price Manipulation Flaw
Critical oracle mispricing of wrstETH collateral allowed an attacker to over-borrow, resulting in a $1.1M liquidity drain.
Hyperliquid Users Liquidated by Coordinated Perpetual Exchange Price Manipulation
Market manipulation exploiting thin liquidity and high leverage is the fastest vector for mass user liquidation, circumventing smart contract security.
Abracadabra Lending Protocol Drained Exploiting Deprecated Smart Contract Logic
A critical logic error in the cook function of deprecated cauldrons permitted unauthorized debt minting, bypassing core solvency checks.
Balancer V2 Stable Pools Drained via Faulty Smart Contract Access Control
A logic flaw in the V2 vault's `manageUserBalance` function allowed unauthorized internal withdrawals, compromising cross-chain liquidity.
