Magic Eden's Retired Payment Processor Bled $1.8M via Zombie Approvals
A bug in a payment processor Magic Eden stopped using in 2024 let attackers drain NFTs and wETH from old wallet approvals — even after the marketplace itself was shut down.
Cronos Halts Its Entire Chain to Reverse a $75M Tectonic Exploit
An attacker pumped Tectonic's governance token 100x in 20 minutes to borrow against phantom collateral. Cronos validators froze the whole chain and rolled it back to claw the funds back — trading decentralization for recovery.
Rain Contract Bug Drains $1.1M From 'Self-Custodial' Crypto Cards
An outdated Solana smart contract at payments processor Rain let an attacker seize admin control of card-collateral accounts, draining funds from Avici and Tria customers who believed their crypto stayed under their own control.
BounceBit's $3M Authorization Bug Forces It to Kill Its Own Layer 1
An unverified-account flaw in BounceBit's Evmos-based chain let an attacker drain 286.5 million BB from nine wallets — and because the underlying chain client is itself discontinued, BounceBit is retiring the L1 rather than patching it.
Cosmos EVM Bug Drains Three Chains After Early Public Disclosure
A shared underflow in the Cosmos EVM module let an attacker drain KiiChain, TAC, and Nesa Chain within days of Cosmos Labs publishing the fix — before telling the chains that ran the vulnerable code.
Term Finance's $8.5M Governance Takeover: When a Timelock Doesn't Trigger
An attacker bought up Term Finance's thinly-held governance token and voted itself control of the protocol's vaults, draining roughly 68% of assets — with the on-paper timelock and veto safeguards never firing.
Fake Flare Network Staking Site Drains $8.5M in XRP, Two Arrested
A cloned staking site, a fabricated Wikipedia entry, and a paid actor were enough to convince 71 investors to hand over 3.4 million XRP — a reminder that brand impersonation, not smart-contract exploits, remains crypto's most reliable attack surface.
Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem
An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.
Coldcard's 2021 Firmware Bug Drains $89M in Bitcoin — A Five-Year Blind Spot
A silent 2021 configuration error swapped Coldcard's hardware RNG for a predictable software fallback, and five years later attackers used it to drain more than $89 million in Bitcoin.
Taiko Bridge Drained $1.7M After SGX Signing Key Exposed on GitHub
An attacker leveraged a publicly committed SGX enclave key to forge withdrawal proofs on Taiko's Ethereum L2 bridge, draining $1.7 million before block production was halted on 22 June 2026.