Web3 Hacks & DeFi Exploit Intelligence
- $104B+Lost
- 3844Incidents
- 126Chains
- 16Classes
| # | Project | Date | Amount Lost | Chain | Technique | Links |
|---|---|---|---|---|---|---|
| 1831 | Inverse Finance Frontier Oracle Manipulation & Price Manipulation | $15.6M | ethereum | Price Oracle Attack / Oracle Issue / Spot Price Manipulation | ||
| 1832 | GHOSTP2E Rugpull | $346K | — | Rugpull | ||
| 1833 | Ola Finance Reentrancy | $4.7M | fuse | Reentrancy / Other | ||
| 1834 | BasketDAO Access Control Attacks | $1.2M | ethereum | Arbitrary External Call | ||
| 1835 | Ronin Access Control Attacks | $625M | — | Access Control | ||
| 1836 | Cryptovoxels Phishing Attacks | $171K | ethereum | Phishing | ||
| 1837 | Revest Other | $2.0M | — | Other | ||
| 1838 | Revest Finance Reentrancy | $2.0M | ethereum | Reentrancy | ||
| 1839 | Auctus Access Control Attacks | $726K | ethereum | Arbitrary External Call | ||
| 1840 | PYE Other | $2.6M | — | Other | ||
| 1841 | Doodle Monkey Rugpull | $76K | — | Rugpull | ||
| 1842 | Ronin Bridge Phishing Attacks | $624M | ethereum | Private Key Compromised (Social Engineering) / Validator Key Compromised | ||
| 1843 | Cashio Collateral Validation Exploit / Missing Input Validation | $52.8M | solana | Collateral Validation Exploit / Missing Input Validation | ||
| 1844 | REALSWAK Rugpull | $527K | — | Rugpull | ||
| 1845 | OneRing Flash Loan Attacks | $1.5M | — | Flash Loan Attack | ||
| 1846 | One Ring Finance Access Control Attacks | $1.4M | ethereum | Improper Access Control | ||
| 1847 | LI.FI Access Control Attacks | $600K | ethereum | Token Approval Abuse | ||
| 1848 | Umbrella Network Access Control Attacks | $700K | bsc, ethereum | Improper Access Control | ||
| 1849 | Rare Bears Access Control Attacks | $206K | — | Access Control | ||
| 1850 | ApeCoin Flash Loan Attacks | $820K | ethereum | Flashloan Governance Attack | ||
| 1851 | DEUS Finance Flash Loan Attacks | $3.0M | fantom | Flash Loan Attack / Spot Price Manipulation | ||
| 1852 | Agave Flash Loan Attacks | $5.5M | gnosis chain | Flashloan Reentrancy Attack / Reentrancy | ||
| 1853 | Hundred Finance Flash Loan Attacks | $6.2M | gnosis chain | Flashloan Reentrancy Attack / Reentrancy | ||
| 1854 | NFTflow Rugpull | $216K | — | Rugpull | ||
| 1855 | PARALUNI Other | $1.7M | — | Other | ||
| 1856 | Paraluni Masterchef Flash Loan Attacks | $1.7M | bsc | Flashloan Reentrancy Attack / Reentrancy | ||
| 1857 | Fantasm Finance Missing Condition Check / Missing Input Validation | $2.6M | fantom | Missing Condition Check / Missing Input Validation | ||
| 1858 | Pirate x Pirate Access Control Attacks | $78K | bsc | Access Control / Improper Access Control | ||
| 1859 | Ebuy Finance Honeypot | — | binance | Honeypot | ||
| 1860 | Ormeus Coin Other | $124M | — | Other |
Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.
Hack Radar
Fresh DeFi incidents the moment they land in our database. Verified by trusted sources; auto-ingested entries are flagged for review.
Explore by Attack Type
Access Control Attacks
Arithmetic Overflow & Underflow Attacks
Delegatecall & Call Injection Attacks
Flash Loan Attacks
Oracle Manipulation & Price Manipulation
Reentrancy
DAO Governance Attacks
Frontrunning & Sandwich Attacks
Phishing Attacks
DOS Attacks
Replay Attacks
Self-Destruct Attacks
Sensitive On-Chain Data
Weak Randomness Attacks
Unchecked Return Value Attacks
Timestamp Manipulation Attacks
Understanding Smart Contract Vulnerabilities
Smart contract vulnerabilities remain the leading cause of DeFi protocol losses, with over $10 billion stolen since 2016. Understanding attack vectors like reentrancy, flash loans, and oracle manipulation is essential for every blockchain developer and security researcher.
Each incident in our database is categorized by attack class and linked to our in-depth vulnerability guides, making this the most educational Web3 hacks tracker available. Want a quick ranking? See the most expensive crypto hacks leaderboard.
Learn how these hacks actually worked
Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.