Web3 Hacks & DeFi Exploit Intelligence
- $104B+Lost
- 3836Incidents
- 124Chains
- 16Classes
| # | Project | Date | Amount Lost | Chain | Technique | Links |
|---|---|---|---|---|---|---|
| 721 | GeniusAI Access Control Attacks | $1.3M | ethereum, fantom | Private Key Compromised (Discord Hack) / Social Account Takeover | ||
| 722 | NovaMind Rugpull | $70K | — | Rugpull | ||
| 723 | Pike Finance Other | $1.6M | — | Other | ||
| 724 | Pike V1 Access Control Attacks | $1.6M | arbitrum, ethereum… | Storage Misalignment Exploit / Proxy Upgrade Hijack | ||
| 725 | Yield Protocol Balance Disparity Exploit / Incorrect Share Accounting | $181K | arbitrum | Balance Disparity Exploit / Incorrect Share Accounting | ||
| 726 | Rain Access Control Attacks | $14.8M | bitcoin, ethereum… | Private Key Compromised | ||
| 727 | BNBX Arithmetic Error | — | bsc | Arithmetic Error | ||
| 728 | Pike Finance Other | $300K | — | Other | ||
| 729 | YIEDL Missing Input Validation | $150K | bsc | Missing Input Validation | ||
| 730 | FENGSHOU Token Access Control Attacks | $191K | bsc | Access Control / Improper Access Control | ||
| 731 | XBridge Access Control Attacks | $1.9M | bsc, ethereum | Access Control / Improper Access Control | ||
| 732 | Magpie Protocol Router Exploit / Missing Input Validation | $129K | arbitrum, avalanche… | Router Exploit / Missing Input Validation | ||
| 733 | Z123 Oracle Manipulation & Price Manipulation | $136K | bsc | Spot Price Manipulation | ||
| 734 | Rico Access Control Attacks | — | arbitrum | Arbitrary External Call | ||
| 735 | Hedgey Flash Loan Attacks | $44.7M | arbitrum, ethereum | Claim Contract Flashloan Exploit / Flash Loan Attack / Missing Input Validation | ||
| 736 | Wilder Access Control Attacks | $1.4M | — | Access Control | ||
| 737 | Chainge Finance Access Control Attacks | $716K | bsc | Arbitrary External Call | ||
| 738 | Grand Base Access Control Attacks | $1.7M | base | Private Key Compromised (Unknown Method) / Access Control / Phishing | ||
| 739 | Zest Oracle Manipulation & Price Manipulation | $1.0M | stacks | Spot Price Manipulation | ||
| 740 | Sumer Reentrancy | — | base | Reentrancy | ||
| 741 | Sumer.Money Flash Loan Attacks | $350K | — | Flash Loan Attack | ||
| 742 | Empower AI Rugpull | $230K | — | Rugpull | ||
| 743 | xBlast Hot Wallet Key Compromised | $84K | ethereum | Hot Wallet Key Compromised | ||
| 744 | SQUID Swap Logic Flaw | $87K | bsc | Swap Logic Flaw | ||
| 745 | SAGA (Fake) Rugpull | $1.6M | — | Rugpull | ||
| 746 | DegenFox Rugpull | $150K | — | Rugpull | ||
| 747 | Condom Rugpull | $900K | — | Rugpull | ||
| 748 | Solareum Other | $523K | — | Other | ||
| 749 | OpenLeverage Unknown | $236K | bsc | Unknown | ||
| 750 | FixedFloat Key Leaked via Infrastructure | $3.0M | — | Key Leaked via Infrastructure |
Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.
Hack Radar
Fresh DeFi incidents the moment they land in our database. Verified by trusted sources; auto-ingested entries are flagged for review.
Explore by Attack Type
Access Control Attacks
Arithmetic Overflow & Underflow Attacks
Delegatecall & Call Injection Attacks
Flash Loan Attacks
Oracle Manipulation & Price Manipulation
Reentrancy
DAO Governance Attacks
Frontrunning & Sandwich Attacks
Phishing Attacks
DOS Attacks
Replay Attacks
Self-Destruct Attacks
Sensitive On-Chain Data
Weak Randomness Attacks
Unchecked Return Value Attacks
Timestamp Manipulation Attacks
Understanding Smart Contract Vulnerabilities
Smart contract vulnerabilities remain the leading cause of DeFi protocol losses, with over $10 billion stolen since 2016. Understanding attack vectors like reentrancy, flash loans, and oracle manipulation is essential for every blockchain developer and security researcher.
Each incident in our database is categorized by attack class and linked to our in-depth vulnerability guides, making this the most educational Web3 hacks tracker available. Want a quick ranking? See the most expensive crypto hacks leaderboard.
Learn how these hacks actually worked
Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.