Payy Network's Ethereum bridge drained of $1.83M USDC: what is confirmed
Payy says its Ethereum bridge contract was drained of its full balance and that the cause was not a compromised key, social engineering or its off-chain infrastructure. The root cause is still undisclosed, so here is what the public record supports and what bridge teams should check.
Cronos Halts Its Own Chain After $75M Tectonic Oracle Exploit
An attacker pumped a thinly-traded governance token 100x in 20 minutes and used it as inflated collateral to drain Cronos's largest lending market — forcing validators to freeze the entire chain.
Cronos Halts Its Entire Chain to Reverse a $75M Tectonic Exploit
An attacker pumped Tectonic's governance token 100x in 20 minutes to borrow against phantom collateral. Cronos validators froze the whole chain and rolled it back to claw the funds back — trading decentralization for recovery.
Rain Contract Bug Drains $1.1M From 'Self-Custodial' Crypto Cards
An outdated Solana smart contract at payments processor Rain let an attacker seize admin control of card-collateral accounts, draining funds from Avici and Tria customers who believed their crypto stayed under their own control.
Moonwell's Fourth Exploit in a Year: $8.7M Lost to a MAMO Price Manipulation
An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.
Term Finance's $8.5M Governance Takeover: When a Timelock Doesn't Trigger
An attacker bought up Term Finance's thinly-held governance token and voted itself control of the protocol's vaults, draining roughly 68% of assets — with the on-paper timelock and veto safeguards never firing.
Wanchain Bridge Exploit Drains $9M in NIGHT Tokens: A Signature-Reuse Lesson
A flawed message-encoding scheme in Wanchain's Cardano–BNB bridge let an attacker reuse a legitimate signature to drain 515 million NIGHT tokens — a reminder that bridge validators, not the chains they connect, remain the weakest link.
Across Protocol's Solana Bridge Hit for $3.35M — Relayer, Not Users, Took the Loss
A July 17 attack on Across Protocol's Solana deployment drained roughly $3.35 million from the project's own relayer, not from bridge users — a result that says as much about bridge architecture as it does about the exploit itself.
Aztec Connect: $2.1M Stolen From a Bridge With No One Left to Fix It
A proof-verification flaw let an attacker drain a DeFi privacy bridge that Aztec Labs deprecated three years ago and can no longer patch, pause, or upgrade — a case study in what "immutable" really costs.