High-Value Hyperliquid User Wallet Drained by Private Key Compromise
The compromise of a single EOA's private key allowed a $21M asset drain, underscoring the catastrophic risk of centralized key management failure.
Balancer V2 Boosted Pools Drained by Faulty Access Control Logic
A flawed access control implementation in V2 pools allowed unauthorized asset withdrawals, bypassing invariant checks and risking systemic DeFi capital.
Balancer Protocol Drained by Multi-Chain Smart Contract Logic Flaw
A critical access control vulnerability within boosted pools allowed unauthorized asset withdrawals, proving complex contract logic magnifies systemic risk.
Balancer V2 Boosted Pools Drained across Six Chains by Access Control Flaw
A critical logic error in V2's boosted pool access control allowed unauthorized withdrawal, compromising $128M and proving access control is the paramount smart contract risk.
Arcadia Finance Drained via Rebalancer Contract Input Validation Flaw
A critical smart contract logic error allowed unvalidated `swapData` input to execute unauthorized rebalance calls, resulting in $3.6M in asset theft.
Credit Market Protocol Exploited via Smart Contract Vulnerability on Optimism
An internal contract flaw on the Optimism credit market allowed an attacker to siphon assets, underscoring systemic DeFi risk.
Lending Protocol Moonwell Exploited via External Oracle Price Manipulation
A critical oracle failure mispriced collateral, enabling the attacker to leverage a minimal deposit into a $1.1 million insolvency event.
Threat Actor LARVA-208 Targets Web3 Developers via Fake AI Platform Malware
Sophisticated spearphishing campaign delivers the Fickle infostealer via malicious 'audio driver' download, compromising developer credentials and project supply chains.
Stream Finance Stablecoin Depegs Following External Asset Manager Loss
Custodial failure by a third-party asset manager triggered a $93M loss, exposing systemic counterparty risk in yield-bearing stablecoins.
