Web3 Hacks & DeFi Exploit Intelligence

Security trends
  • $91B+Lost
  • 3595Incidents
  • 141Chains
  • 19Classes
# Project Date Amount Lost Chain Technique Links
61 Virtue $894K iota Oracle Misconfiguration
62 Ajna V2 $775K ethereum Liquidation Logic Flaw
63 Avici $501K solana Signature Validation / Authorization Flaw
64 CCC $117K bsc Swap Logic Flaw
65 Moonwell Lending $8.7M base Spot Price Manipulation / Oracle Issue
66 CometDEX $718K stellar Incorrect Share Accounting
67 Enjin $162K ethereum Unprotected Initialization and Ownership Takeover
68 FH Token $20K bsc Reserve Desynchronization
69 Nesa $50.0M nesa Arithmetic Error
70 PacaSwap DEX $91K constellation Arithmetic Error
71 Surf Lending — cardano Private Key Compromised
72 warp.green $93K chia, ethereum Bridge Logic Flaw
73 Term Labs $8.5M ethereum Malicious Proposal
74 Arrakis V1 $7K ethereum Spot Price Manipulation
75 KiiChain $9.7M kiichain Arithmetic Error
76 TAC — tac Integer Underflow / Overflow
77 MANTRA Chain $3.6M mantra Unsigned Integer Underflow
78 The Sandbox $675K base, bsc, ethereum Access Control / Improper Access Control
79 Blockchain Intelligence Hunger Games $94.6M — —
80 BounceBit $3.0M bouncebit Improper Access Control
81 Allbridge $191K base Cross-Chain Message Validation Flaw
82 Maya Protocol $1.7M mayachain Withdrawal Logic Flaw
83 Fox Market $120K bsc Spot Price Manipulation / Flash Loan Attack
84 Whale Wallet Drain $25.6M — Phishing
85 Harmony $300K — Other
86 USM $136K ethereum Flash-Loan-Funded Accounting Exploit
87 Coreum $200K coreum, xrpl Deposit Verification Flaw
88 Coinsbuy $8.1M ethereum, tron Access Control / Improper Access Control
89 Oraichain $1.0M oraichain EVM Cross-Chain Unauthorized Mint
90 Atomic Green $30K arbitrum Signature Replay

Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.

Understanding Smart Contract Vulnerabilities

Explore the technical causes behind reentrancy, flash loan attacks, and oracle manipulation in our attack guides.

Learn how these hacks actually worked

Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.