Web3 Hacks & DeFi Exploit Intelligence
- $104B+Lost
- 3836Incidents
- 124Chains
- 16Classes
| # | Project | Date | Amount Lost | Chain | Technique | Links |
|---|---|---|---|---|---|---|
| 511 | OpenOcean Other | $22K | — | Other | ||
| 512 | zkLend Empty Market Exploit / First Depositor Attack | $9.6M | starknet | Empty Market Exploit / First Depositor Attack | ||
| 513 | four.meme Liquidity Pool Exploit / Swap Logic Flaw | $183K | bsc | Liquidity Pool Exploit / Swap Logic Flaw | ||
| 514 | Peapods Finance Other | $4K | — | Other | ||
| 515 | Ionic Other | $12.3M | — | Other | ||
| 516 | Ionic Protocol Phishing Attacks | $8.6M | mode | Fake Collateral Exploit / Impersonation Scam | ||
| 517 | Sirio Finance Flash Loan Attacks | $2.0M | hedera | Flashloan Exploit / Spot Price Manipulation | ||
| 518 | phishing Phishing Attacks | $394K | — | Phishing | ||
| 519 | DogWifTools Access Control Attacks | $10.0M | solana | Private Key Compromised (Malware) / Key Stored Publicly | ||
| 520 | Phemex Access Control Attacks | $85.0M | arbitrum, avalanche… | Private Key Compromised (Unknown Method) / Hot Wallet Key Compromised | ||
| 521 | AST Token Other | $65K | — | Other | ||
| 522 | Fake LAYER Rugpull | $465K | — | Rugpull | ||
| 523 | MELANIA Other | $200M | — | Other | ||
| 524 | BIGO Other | $18K | — | Other | ||
| 525 | The Idols NFT Reward Logic Flaw | $340K | ethereum | Reward Logic Flaw | ||
| 526 | Mosca2 Incorrect Share Accounting | $38K | bsc | Incorrect Share Accounting | ||
| 527 | Unilend V2 Redeem Process Exploit / Redeem Logic Flaw | $200K | ethereum | Redeem Process Exploit / Redeem Logic Flaw | ||
| 528 | FortuneWheel Other | $21.0M | — | Other | ||
| 529 | Moby Trade Access Control Attacks | $2.5M | — | Access Control | ||
| 530 | LAURA Other | $48K | — | Other | ||
| 531 | Mosca Other | $20K | — | Other | ||
| 532 | Moby Access Control Attacks | $1.5M | arbitrum | Private Key Compromised (Unknown Method) / Private Key Compromised | ||
| 533 | Orange Finance Access Control Attacks | $840K | arbitrum | Private Key Compromised (Unknown Method) / Access Control / Private Key Compromised | ||
| 534 | IPC AI Swap Logic Flaw | $590K | binance | Swap Logic Flaw | ||
| 535 | Mosca Incorrect Share Accounting | $38K | binance | Incorrect Share Accounting | ||
| 536 | Sorra Finance Reward Logic Flaw | $41K | ethereum | Reward Logic Flaw | ||
| 537 | MoonHacker Access Control Attacks | $300K | optimism | Unchecked FlashLoan Approve Exploit / Token Approval Abuse | ||
| 538 | NoOnes Cross-Chain Message Spoofing | $7.9M | binance, ethereum… | Cross-Chain Message Spoofing | ||
| 539 | FEG (Feed Every Gorilla) Other | $900K | — | Other | ||
| 540 | Fegex Access Control Attacks | $1.1M | base, bsc… | Missing Access Control / Cross-Chain Message Spoofing |
Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.
Hack Radar
Fresh DeFi incidents the moment they land in our database. Verified by trusted sources; auto-ingested entries are flagged for review.
Explore by Attack Type
Access Control Attacks
Arithmetic Overflow & Underflow Attacks
Delegatecall & Call Injection Attacks
Flash Loan Attacks
Oracle Manipulation & Price Manipulation
Reentrancy
DAO Governance Attacks
Frontrunning & Sandwich Attacks
Phishing Attacks
DOS Attacks
Replay Attacks
Self-Destruct Attacks
Sensitive On-Chain Data
Weak Randomness Attacks
Unchecked Return Value Attacks
Timestamp Manipulation Attacks
Understanding Smart Contract Vulnerabilities
Smart contract vulnerabilities remain the leading cause of DeFi protocol losses, with over $10 billion stolen since 2016. Understanding attack vectors like reentrancy, flash loans, and oracle manipulation is essential for every blockchain developer and security researcher.
Each incident in our database is categorized by attack class and linked to our in-depth vulnerability guides, making this the most educational Web3 hacks tracker available. Want a quick ranking? See the most expensive crypto hacks leaderboard.
Learn how these hacks actually worked
Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.