Attack Type Dataset
Real Delegatecall & Call Injection Hacks
Real incidents mapped to delegatecall & call injection. Start with the records, open the source, then use the attack guide when an incident matches the code you are reviewing.
Incident records
Sorted by known reported loss first, then recency. Open the source before treating any summary as final.
| Links | ||||||
|---|---|---|---|---|---|---|
| 1 | UXLINK | $48.0M | arbitrum, ethereum | Access Control Attacks | Details Source | |
| 2 | Furucombo | $14.0M | ethereum | Delegatecall & Call Injection Attacks | Details Source | |
| 3 | Punk Protocol | $8.9M | ethereum | Delegatecall & Call Injection Attacks | Details Source | |
| 4 | Unizen | $2.1M | ethereum | Delegatecall & Call Injection Attacks | Details Source | |
| 5 | Dexible V2 | $2.0M | arbitrum, ethereum | Delegatecall & Call Injection Attacks | Details Source | |
| 6 | Dough Finance | $2.0M | ethereum | Access Control Attacks | Details Source | |
| 7 | Maestro | $465K | ethereum | Delegatecall & Call Injection Attacks | Details Source | |
| 8 | Bond Protocol | $300K | ethereum | Delegatecall & Call Injection Attacks | Details Source |
Notes
Loss totals use parsed USD values only; unknown or unparseable losses are not guessed. Attack-class links are added only when the root cause is clear enough to map.