Web3 Hacks & DeFi Exploit Intelligence

Security trends
  • $91B+Lost
  • 3595Incidents
  • 141Chains
  • 19Classes
# Project Date Amount Lost Chain Technique Links
721 ALP $10K bsc Improper Access Control
722 TGBS $151K — Pool-burn price manipulation
723 HGM, AGSC $75K — Phishing
724 OrdiZK $1.4M — Rugpull
725 WOOFi Swap $8.8M arbitrum Price Oracle Manipulation / Flash Loan Attack / Spot Price Manipulation
726 AI Protocol $4.3M — Phishing
727 Shido $3.3M ethereum Private Key Compromised / Access Control
728 Serenity Shield $586K ethereum Phishing
729 Smoofs — polygon Reentrancy
730 Seneca $6.5M arbitrum, ethereum Token approval exploit / Access Control / Token Approval Abuse
731 Ore $243K — Rugpull
732 RiskOnBlast $1.3M blast Rugpull / Exit Scam
733 ZoomerCoin $41K ethereum Flashloan Governance Attack
734 BlueBerry $1.4M ethereum Flashloan Price Oracle Attack / Spot Price Manipulation / Other
735 BitForex $56.0M — Rugpull
736 Jeffrey Zirlin $9.7M — Personal wallet-key compromise
737 Tectonic $250K cronos Flashloan New Market Exploit / Unknown
738 Gain $3.0M ethereum Infinite Mint
739 DeezNutz_404 $174K ethereum Flash Loan Attack / Infinite Mint
740 RuggedArt — ethereum Reentrancy
741 FixedFloat $26.1M bitcoin, ethereum Private Key Compromised / Key Leaked via Infrastructure / Access Control
742 xPet $257K — Other
743 User $48K — Phishing
744 DualPools $41K bsc Flash Loan Attack / Rounding Error
745 Particle Trade $142K ethereum Missing Input Validation
746 BEAM $5.2M — Phishing
747 MINER $467K ethereum Missing Input Validation
748 DuelBits $4.6M ethereum Suspected wallet-access compromise
749 GAME $50K — Reentrancy
750 PlayDapp $290M ethereum Access Control / Hot Wallet Key Compromised

Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.

Understanding Smart Contract Vulnerabilities

Explore the technical causes behind reentrancy, flash loan attacks, and oracle manipulation in our attack guides.

Learn how these hacks actually worked

Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.