Cronos Halts Its Own Chain After $75M Tectonic Oracle Exploit
An attacker pumped a thinly-traded governance token 100x in 20 minutes and used it as inflated collateral to drain Cronos's largest lending market — forcing validators to freeze the entire chain.
Moonwell's Fourth Exploit in a Year: $8.7M Lost to a MAMO Price Manipulation
An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.
BonkDAO's $20M Governance Attack: The Contracts Worked Exactly as Coded
An attacker spent roughly $4.4M buying BONK to clear a 1% quorum, then pushed a malicious treasury proposal through a near-empty vote — no exploit, no bug, just governance math.
Step App Shuts Down: What a Silent Move-to-Earn Exit Teaches About Crypto Risk
One of the last surviving move-to-earn projects is closing on 21 August with no explanation for users — a pattern worth understanding if you hold tokens in any similarly structured app.
Wanchain Bridge Exploit Drains $9M in NIGHT Tokens: A Signature-Reuse Lesson
A flawed message-encoding scheme in Wanchain's Cardano–BNB bridge let an attacker reuse a legitimate signature to drain 515 million NIGHT tokens — a reminder that bridge validators, not the chains they connect, remain the weakest link.
Allbridge Core Loses $1.65M to a Flash Loan Pricing Bug It Fixed in 2023
A flash loan against Allbridge Core's Solana stablecoin pools distorted internal pricing and let an attacker drain roughly $1.65 million — the same class of bug the protocol says it patched on BNB Chain three years ago.
Across Protocol's Solana Bridge Hit for $3.35M — Relayer, Not Users, Took the Loss
A July 17 attack on Across Protocol's Solana deployment drained roughly $3.35 million from the project's own relayer, not from bridge users — a result that says as much about bridge architecture as it does about the exploit itself.
Summer Finance's $6M Vault Accounting Bug Ends in Full Shutdown
A flash-loan attacker exploited how Summer Finance's Fleet Commander vault priced its underlying strategies, extracting $6 million in a single transaction — and the protocol has now wound down entirely.
Summer.fi's $6M Vault Exploit Is a Playbook for Donation-Based Share Manipulation
A three-month-old attacker wallet used a $65M flash loan and a donation to a strategy adapter pending removal to skew vault share pricing, draining $6.04M from two Lazy Summer USDC vaults before guardians could react.
Aztec Connect: $2.1M Stolen From a Bridge With No One Left to Fix It
A proof-verification flaw let an attacker drain a DeFi privacy bridge that Aztec Labs deprecated three years ago and can no longer patch, pause, or upgrade — a case study in what "immutable" really costs.
Counter-MEV Honeypot Drains jaredfromsubway.eth of $7.5 Million
Ethereum's most-active sandwich-attack bot was beaten at its own game — tricked by 66 fake token contracts into handing over real WETH, USDC, and USDT in a single sweep transaction.