Balancer V2 Composable Pools Drained via Faulty Smart Contract Access Control
Faulty V2 access control logic permitted unauthorized internal withdrawals, draining over $120 million in pooled assets across multiple chains.
Decentralized Exchange Cetus Drained $223 Million Exploiting Smart Contract Overflow Flaw
A critical integer overflow vulnerability in the DEX's forked code allowed a malicious actor to manipulate liquidity checks, resulting in a $223 million asset drain.
Lending Protocol Drained via Oracle Collateral Price Manipulation
A Chainlink oracle glitch mispriced `wrstETH` collateral, allowing an attacker to execute a systemic under-collateralized borrowing exploit, draining $1.1M.
Lending Protocol Drained via Oracle Price Feed Manipulation on Base
Critical oracle failure on Base allowed asset mispricing, enabling immediate, under-collateralized fund extraction from the lending pool.
Web3 Social Platform UXLINK Drained $41 Million via Multi-Sig Key Compromise
A multi-sig wallet's private key compromise enabled an attacker to weaponize a `delegatecall` function, resulting in unauthorized token minting and a $41M capital drain.
Lending Protocol Drained by External Oracle Price Feed Manipulation Flaw
A critical misconfiguration in the external price oracle allowed for collateral overvaluation, creating an immediate, systemic risk of protocol insolvency.
Bedrock Staking Drained Two Million via Unaudited Infinite-Mint Contract Flaw
A critical, unaudited smart contract logic flaw enabled token infinite-minting, compromising liquidity and resulting in a $2M asset drain.
Major DeFi Lending Protocol Drained $50 Million via Oracle Manipulation
A $50M drain confirms that unaudited oracle input validation remains a critical systemic risk for all interconnected DeFi lending platforms.
Moonwell Lending Protocol Exploited via External Oracle Price Manipulation
A temporary oracle malfunction on the Base network mispriced a collateral token, enabling a $1 million uncollateralized asset drain via systemic lending protocol logic.
