Level Finance Referral Contract Exploited for $1.1 Million in LVL Tokens
A critical business logic flaw in Level Finance's referral contract enabled an attacker to repeatedly claim rewards, underscoring the severe risk of inadequate precondition checks in DeFi protocols.
UXLINK Multi-Signature Wallet Compromised via DelegateCall Vulnerability
A delegateCall vulnerability in a multi-signature wallet enabled unauthorized administrative control, leading to significant asset drain and token inflation.
UXLINK Multi-Signature Wallet Compromised, Billions of Tokens Minted
A delegate call vulnerability in UXLINK's multi-signature wallet granted administrative control, enabling unauthorized token minting and significant financial loss.
NPM `debug` Package Compromised by Phishing, Malicious Code Redirects Crypto
A compromised npm package account enabled malicious code injection, posing an immediate risk of cryptocurrency theft for browser-based application users.
BtcTurk Hot Wallets Drained by Private Key Compromise
A critical private key compromise enabled attackers to exfiltrate $48 million from BtcTurk's hot wallets across seven distinct blockchains.
Cetus Protocol on Sui Suffers $223 Million Arithmetic Overflow Exploit
An arithmetic overflow vulnerability in a third-party library allowed an attacker to manipulate asset calculations, leading to a catastrophic $223 million drain from the Cetus Protocol.
Yala Protocol Suffers Bridge Exploit via Compromised Deployment Key
An exploited temporary deployment key facilitated an unauthorized cross-chain bridge, leading to the overissuance of tokens and a significant asset drain.
Shibarium Bridge Suffers $2.3 Million Validator Key Compromise
A flash loan attack exploited Shibarium's validator system, compromising signing keys and enabling unauthorized asset withdrawals, directly impacting user funds.
Bedrock uniBTC Minting Logic Flaw Drains $2 Million in DeFi Exploit
A critical logic flaw in the uniBTC minting mechanism allowed attackers to exploit disparate asset valuations, leading to a significant capital drain.
Nemo Protocol Suffers $2.6 Million Exploit Due to Unaudited Code
A critical lapse in code review and governance allowed a developer to deploy unaudited smart contracts, creating an exploitable vector for significant asset drain.
Onyx Protocol Suffers $3.8 Million Exploit via NFT Liquidation Contract
A critical flaw in Onyx Protocol's NFT liquidation contract enabled an attacker to drain $3.8 million, compromising stablecoin peg integrity.
PlayDapp Suffers $290 Million Private Key Compromise, Token Minting Exploit
A compromised private key enabled unauthorized token minting, leading to a severe $290 million loss and critical supply inflation for PlayDapp.
Shibarium Bridge Drained by Flash Loan and Validator Key Exploit
A sophisticated flash loan attack exploited Shibarium's validator key management, compromising network consensus and enabling significant asset exfiltration.
BtcTurk Suffers $48 Million Private Key Compromise across Seven Blockchains
A critical private key compromise enabled attackers to drain $48 million from BtcTurk hot wallets, exposing systemic risks in centralized exchange key management.
SwissBorg Earnings Program Breached via Partner API
An external API compromise allowed attackers to drain $41 million in Solana tokens, highlighting critical third-party integration risks.
Nemo Protocol Developer Deployed Unaudited Code, Enabling $2.6m Exploit
An unaudited code deployment enabled a flash loan and state manipulation attack, compromising Nemo Protocol and jeopardizing user assets.
Shibarium Bridge Suffers Flash Loan Validator Key Compromise
A flash loan attack manipulated Shibarium's validator consensus, enabling unauthorized asset siphoning and exposing critical governance vulnerabilities.
SwissBorg Solana Earn Compromised by Kiln API Manipulation
A compromised third-party staking API enabled attackers to siphon $41 million in Solana, exposing critical supply chain risks.
SwissBorg Solana Earn API Compromise Drains $41 Million
A third-party API vulnerability allowed unauthorized access to SwissBorg's SOL Earn program, resulting in significant asset loss for users.
