Web3 Hacks & DeFi Exploit Intelligence
- $104B+Lost
- 3836Incidents
- 124Chains
- 16Classes
| # | Project | Date | Amount Lost | Chain | Technique | Links |
|---|---|---|---|---|---|---|
| 181 | Transit Finance Access Control Attacks | $1.9M | tron | Improper Access Control | ||
| 182 | SQ Protocol Access Control Attacks | $346K | bsc | Improper Access Control | ||
| 183 | BoostHook Oracle Manipulation & Price Manipulation | $187K | ethereum | Spot Price Manipulation | ||
| 184 | IEXCBP Oracle Manipulation & Price Manipulation | $97K | bsc | Spot Price Manipulation | ||
| 185 | Aurellion Access Control Attacks | $456K | arbitrum | Access Control / Uninitialized Proxy | ||
| 186 | Huma Finance V2 Access Control Attacks | $101K | polygon | Improper Access Control | ||
| 187 | TAC Protocol Proof Verifier Bug | $2.9M | tac, ton | Proof Verifier Bug | ||
| 188 | Ink Finance Access Control Attacks | $140K | polygon | Access Control / Caller Impersonation | ||
| 189 | Renegade Access Control Attacks | $209K | arbitrum | Access Control / Uninitialized Proxy | ||
| 190 | TrustedVolumes Access Control Attacks | $6.7M | ethereum | Caller Impersonation | ||
| 191 | Ekubo Access Control Attacks | $1.4M | ethereum | Token Approval Abuse | ||
| 192 | Ekubo Protocol Access Control Attacks | $1.4M | — | Access Control | ||
| 193 | SquidRouterModule Access Control Attacks | $3.2M | base, ethereum | Improper Access Control | ||
| 194 | SmartCredit Unknown | $72K | ethereum | Unknown | ||
| 195 | Wasabi Protocol | $5.9M | — | — | ||
| 196 | Bisq Other | $850K | — | Other | ||
| 197 | Bisq Missing Input Validation | $550K | bitcoin | Missing Input Validation | ||
| 198 | Sharwa.Finance Oracle Manipulation & Price Manipulation | $33K | arbitrum | Spot Price Manipulation | ||
| 199 | Wasabi Access Control Attacks | $5.5M | base, berachain… | Access Control / Deployer Key Compromised | ||
| 200 | Sweat Foundation Withdrawal Logic Flaw | $3.5M | near | Withdrawal Logic Flaw | ||
| 201 | Aftermath Perps Withdrawal Logic Flaw | $1.1M | sui | Withdrawal Logic Flaw | ||
| 202 | Syndicate Access Control Attacks | $400K | base | Access Control / Bridge Logic Flaw | ||
| 203 | JUDAO Arithmetic Error | $228K | bsc | Arithmetic Error | ||
| 204 | YieldCore Access Control Attacks | $399K | ethereum | Improper Access Control | ||
| 205 | Quant Access Control Attacks | $138K | ethereum | Arbitrary External Call | ||
| 206 | Volo | $3.5M | — | — | ||
| 207 | Singularity Finance Oracle Manipulation & Price Manipulation | $413K | base | Oracle Misconfiguration | ||
| 208 | ZetaChain Access Control Attacks | $334K | arbitrum, avalanche… | Access Control / Token Approval Abuse | ||
| 209 | Litecoin Missing Input Validation | — | litecoin | Missing Input Validation | ||
| 210 | Scallop Lend Reward Logic Flaw | $142K | sui | Reward Logic Flaw |
Data sourced from DefiLlama & SunWeb3Sec/DeFiHackLabs . Thank you for keeping Web3 security data open.
Hack Radar
Fresh DeFi incidents the moment they land in our database. Verified by trusted sources; auto-ingested entries are flagged for review.
Explore by Attack Type
Access Control Attacks
Arithmetic Overflow & Underflow Attacks
Delegatecall & Call Injection Attacks
Flash Loan Attacks
Oracle Manipulation & Price Manipulation
Reentrancy
DAO Governance Attacks
Frontrunning & Sandwich Attacks
Phishing Attacks
DOS Attacks
Replay Attacks
Self-Destruct Attacks
Sensitive On-Chain Data
Weak Randomness Attacks
Unchecked Return Value Attacks
Timestamp Manipulation Attacks
Understanding Smart Contract Vulnerabilities
Smart contract vulnerabilities remain the leading cause of DeFi protocol losses, with over $10 billion stolen since 2016. Understanding attack vectors like reentrancy, flash loans, and oracle manipulation is essential for every blockchain developer and security researcher.
Each incident in our database is categorized by attack class and linked to our in-depth vulnerability guides, making this the most educational Web3 hacks tracker available. Want a quick ranking? See the most expensive crypto hacks leaderboard.
Learn how these hacks actually worked
Study the exploit patterns behind the incidents in this database, then practice finding them before attackers do.