Back to Blog

Defi

8 articles on this topic.

Web3 & Smart Contract Security27 September 2026

Magic Eden's Retired Payment Processor Bled $1.8M via Zombie Approvals

A bug in a payment processor Magic Eden stopped using in 2024 let attackers drain NFTs and wETH from old wallet approvals — even after the marketplace itself was shut down.

web3-securitynft-securitytoken-approvals
4 min readRead
Web3 & DeFi Security1 September 2026

Cronos Halts Its Entire Chain to Reverse a $75M Tectonic Exploit

An attacker pumped Tectonic's governance token 100x in 20 minutes to borrow against phantom collateral. Cronos validators froze the whole chain and rolled it back to claw the funds back — trading decentralization for recovery.

defiweb3-securitysmart-contracts
4 min readRead
Web3 & Smart Contract Security29 August 2026

BounceBit's $3M Authorization Bug Forces It to Kill Its Own Layer 1

An unverified-account flaw in BounceBit's Evmos-based chain let an attacker drain 286.5 million BB from nine wallets — and because the underlying chain client is itself discontinued, BounceBit is retiring the L1 rather than patching it.

web3-securitysmart-contract-securityblockchain
4 min readRead
Web3 & Smart-Contract Security15 August 2026

BonkDAO's $20M Governance Attack: The Contracts Worked Exactly as Coded

An attacker spent roughly $4.4M buying BONK to clear a 1% quorum, then pushed a malicious treasury proposal through a near-empty vote — no exploit, no bug, just governance math.

dao-securitygovernance-attackdefi
4 min readRead
Web3 & Exchange Security10 August 2026

Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem

An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.

web3-securityexchange-securitycross-chain
4 min readRead
Web3 & Smart Contract Security22 July 2026

Wanchain Bridge Exploit Drains $9M in NIGHT Tokens: A Signature-Reuse Lesson

A flawed message-encoding scheme in Wanchain's Cardano–BNB bridge let an attacker reuse a legitimate signature to drain 515 million NIGHT tokens — a reminder that bridge validators, not the chains they connect, remain the weakest link.

bridge securityweb3cardano
4 min readRead
Web3 & Bridge Security20 July 2026

Across Protocol's Solana Bridge Hit for $3.35M — Relayer, Not Users, Took the Loss

A July 17 attack on Across Protocol's Solana deployment drained roughly $3.35 million from the project's own relayer, not from bridge users — a result that says as much about bridge architecture as it does about the exploit itself.

web3bridge-securitysolana
4 min readRead
DeFi Security29 June 2026

Counter-MEV Honeypot Drains jaredfromsubway.eth of $7.5 Million

Ethereum's most-active sandwich-attack bot was beaten at its own game — tricked by 66 fake token contracts into handing over real WETH, USDC, and USDT in a single sweep transaction.

mevdefiethereum
4 min readRead