Web3 Hacks in 2018

2018 incident records, sorted by known loss. The strongest mapped pattern is Access Control (14 rows); the largest tracked chain bucket is Nem ($534.0M).

Incident records

Sorted by known reported loss first, then recency. Open the source before treating any summary as final.

Links
1 BitConnect $2.0B Rugpull
2 Coincheck $534M nem Access Control Attacks
3 Gate $235M Access Control Attacks
4 BitGrail $170M nano Access Control Attacks
5 Zaif $60.0M bitcoin Access Control Attacks
6 Blockchain.com $50.0M Access Control Attacks
7 Coinrail $40.0M ethereum Access Control Attacks
8 Bithumb $31.0M ethereum Access Control Attacks
9 Bancor $23.5M ethereum Other / Hot Wallet Key Compromised
10 Bitcoin Gold $18.0M bitcoin gold Forged Proof
11 Trade.io $9.0M Access Control Attacks
12 KICKICO $7.7M ethereum Hot Wallet Key Compromised
13 MapleChange $5.9M Other
14 Coinsecure $3.3M bitcoin Access Control Attacks
15 Verge $1.8M verge Withdrawal Logic Flaw
16 Taylor $1.6M Access Control Attacks
17 Electrum $949K Access Control Attacks
18 ZenCash $550K zencash Forged Proof
19 AurumCoin $500K aurumcoin Risk Parameter Abuse
20 BlackWallet $400K Access Control Attacks
21 EOSBet $338K eos Donation Attack
22 EOSBet $200K eos Infinite Mint
23 MyEtherWallet $150K Access Control Attacks
24 Vertcoin $100K vertcoin Risk Parameter Abuse
25 MonaCoin $90K monacoin Forged Proof
26 EOSCast $73K eos Infinite Mint
27 EosRoyale $60K eos Unknown
28 NewDex $58K eos Infinite Mint
29 SpankChain $38K ethereum Reentrancy
30 EOSDice $25K eos Unknown
31 HireVibes AirDropsDAC $14K eos Access Control Attacks
32 EOS.WIN $9K eos Unknown
33 FFGame $7K eos Unknown
34 ToBet eos Unknown
35 EOS Max eos Unknown
36 EOS Lelego eos Unknown
37 Gate bitcoin, ethereum Supply Chain Attack
38 BlockVest ethereum Honeypot
39 Coinseed Token ethereum Honeypot
40 Blockchain Terminal Token ethereum Honeypot
41 SmartMesh ethereum Infinite Mint
42 BeautyChain ethereum Infinite Mint

Notes

Loss totals use parsed USD values only; unknown or unparseable losses are not guessed. Attack-class links are added only when the root cause is clear enough to map.