Incident archive

Intelligence overview

DCI-2026-288

Notional V1 Escrow arithmetic truncation exploit caused about $1.73 million in losses

Ethereum

Incident overview

Notional confirmed that a legacy V1 contract was exploited. An integer truncation in the free-collateral path allowed checks to be bypassed, leading to withdrawals of about 69,257 DAI and 1,658,525 USDC that were converted into roughly 689.2 ETH.

Text incident index

Expand the chronological list of incident titles, summaries, and primary sources.212 records
  1. DCI-2026-288

    Notional V1 Escrow arithmetic truncation exploit caused about $1.73 million in losses

    Notional confirmed that a legacy V1 contract was exploited. An integer truncation in the free-collateral path allowed checks to be bypassed, leading to withdrawals of about 69,257 DAI and 1,658,525 USDC that were converted into roughly 689.2 ETH.

    Primary source:Notional official incident confirmation
  2. DCI-2026-289

    GebProxyActions access-control flaw enabled the theft of about 5.94 ETH

    Several historical SAFEs registered the shared GebProxyActions contract as owner. An attacker directly called the unauthenticated quitSystem helper and withdrew residual collateral from four SAFEs, totaling about 5.9436 ETH.

    Primary source:SlowMist technical alert
  3. DCI-2026-287

    Two phishing approvals from 2024 enabled about $187,000 in theft

    Two Ethereum users had not revoked malicious approvals signed in 2024. After SYN and USDC reached the wallets, the old approvals were used to transfer assets worth a reported total of $187,046.

    Primary source:Scam Sniffer original alert
  4. DCI-2026-286

    Float Protocol lost about $28,000 to spot-price manipulation

    An attacker used flash loans to distort a Uniswap V3 spot price, causing Float Protocol Hypervisors to misprice shares and allowing about 10.71 ETH to be extracted through repeated deposits and withdrawals.

    Primary source:SlowMist technical alert
  5. DCI-2026-285

    Ankr ankrFLOW exploit affected MORE Markets reserves

    A flaw in Ankr's ankrFLOW contract allowed about 8.6 million unbacked tokens to be created and deposited into MORE Markets, where roughly 15.5 million WFLOW was borrowed. Flow corrected the spot-value reserve impact to about $410,000.

    Primary source:Flow official incident statement
  6. DCI-2026-284

    Aquifer one-sided swap flaw drained about $2.47 million

    Aquifer's Solana swap program accepted attacker-controlled token accounts and a fake token program, completing 212 swaps with real output and no real input. About $2.47 million was converted to SOL and bridged to Ethereum.

    Primary source:Bitquery on-chain reconstruction
  7. DCI-2026-276

    Balancer V1 BPool reserve-compression rounding exploit

    SlowMist reported that after compressing a Balancer V1 BPool's WBTC reserve, rounding in joinswapPoolAmountOut allowed the attacker to mint BPT with minimal input and exit with multiple assets, for an estimated loss of about $234,000.

    Primary source:SlowMist Balancer V1 alert
  8. DCI-2026-275

    Tectonic Cronos TONIC price manipulation and chain halt

    Tectonic on Cronos was exploited after the attacker inflated the price of thinly traded TONIC and borrowed liquid assets. Security researchers estimated $66 million to $75 million, with about $6 million bridged to Ethereum and most remaining on Cronos after the halt.

    Primary source:Cronos Network official halt notice
  9. DCI-2026-274

    Ajna v2 multi-pool liquidation accounting exploit on Ethereum

    Internal liquidation accounting across several Ajna v2 lending pools on Ethereum was manipulated through repeated liquidation paths. Ajna told users to withdraw and stop interacting; external monitoring estimated about $775,000 in losses.

    Primary source:Ajna official risk disclosure
  10. DCI-2026-270

    Fogo Foundation wallet compromise moved 400 million FOGO

    Fogo Foundation confirmed that an unknown actor moved 400 million FOGO from assets under foundation control, about 4% of total supply. The chain continued operating; the token amount was valued at about $3.88 million, while complete addresses and transaction hashes remain unpublished.

    Primary source:Fogo official notice
  11. DCI-2026-269

    Avici / Rain Solana card-balance contract authorization exploit

    An outdated Rain Solana card-balance contract was exploited through its authorization path, allowing batch withdrawals after crafted signature and administrator calls. Avici confirmed 1,685 users and $500,859.22 in affected card balances and announced refunds; a broader on-chain estimate of about $1.02 million is not additive.

    Primary source:Avici initial official disclosure
  12. DCI-2026-273

    Moonwell Base MAMO thin-liquidity price manipulation exploit

    The price of thinly traded MAMO collateral in Moonwell's Base lending markets was inflated, allowing the attacker to borrow real assets such as cbBTC and USDC. Security researchers estimated about $8.79 million, and Moonwell restricted the affected markets.

    Primary source:Moonwell official response
  13. DCI-2026-272

    CCC Token LP accounting exploit on BNB Chain

    A CCC Token sell path on BNB Chain could alter the token reserve held by its LP. The attacker used the accounting behavior to create a price anomaly and extract liquidity; TenArmor estimated about $117,000 at stake.

    Primary source:TenArmor CCC alert
  14. DCI-2026-271

    TRON address-poisoning campaign affected 15 victims

    Specter disclosed a four-week TRON address-poisoning campaign affecting 15 victims with an aggregate loss of about $9.4 million. Verifiable in-window USDD inflows totaled about 3,191,402.34, but cannot be treated as new net loss for the window.

    Primary source:Specter campaign analysis
  15. DCI-2026-265

    Enjin Managed Delegate Proxy storage collision enabled an administrative takeover

    An Enjin Managed Delegate Proxy on Ethereum was taken over through a DELEGATECALL storage collision and an unprotected initializer. The attacker registered a malicious adapter and transferred assets; SlowMist estimated about $162,000 in losses.

    Primary source:SlowMist Enjin technical alert
  16. DCI-2026-268

    CometDEX BLND-USDC pool exploited on Stellar

    CometDEX's BLND-USDC pool on Stellar was exploited through a reserve-accounting flaw involving repeated USDC-to-USDC swaps. SlowMist reported about $717,518.92; Blend's ordinary deposit pools were unaffected, while backstop depositors were impacted.

    Primary source:Blend initial warning
  17. DCI-2026-267

    PacaSwap SWAP / DAG pools drained through a metagraph vulnerability

    PacaSwap confirmed that its SWAP / DAG liquidity pools were drained through a metagraph vulnerability and paused the Bridge. The project said it would cover affected LP losses, but disclosed no USD amount, attacker address, or transaction hash.

    Primary source:PacaSwap initial security notice
  18. DCI-2026-266

    Trezor confirms a new phishing wave using data leaked from multiple crypto services

    Trezor confirmed a new targeted phishing wave using data leaked from multiple crypto services. No new on-chain loss has been publicly confirmed, but the campaign is an active malicious distribution threat to multi-chain wallet users.

    Primary source:Trezor official phishing response
  19. DCI-2026-264

    FH / FHToken PancakeSwap V2 sell-tax logic exploit

    The FH / USDT PancakeSwap V2 pool on BNB Chain was exploited through repeated buy-and-sell calls. A FHToken sell-tax flaw corrupted pool reserves, with security researchers estimating about $20,000 in losses.

    Primary source:SlowMist FH technical alert
  20. DCI-2026-263

    Realio / realio.fund custody wallets drained across multiple chains

    Realio-controlled realio.fund wallets showed continuing anomalous outflows across five chains from August 25. A community ledger recorded 127,918,788 RIO and about $263,596 in liquid assets; Realio confirmed an attack and paused the affected WebApp.

    Primary source:Realio official incident notice
  21. DCI-2026-256

    Arrakis V1 G-UNI vault suffered an atomic liquidity-sandwich attack

    An attacker exploited state-dependent Uniswap V3 mint/burn accounting in a 2021 legacy G-UNI ENS–WETH vault, extracting about 2.94 WETH valued near $7,100 through atomic liquidity operations. Arrakis Pro vaults were unaffected.

    Primary source:SlowMist Arrakis alert
  22. DCI-2026-255

    Term Labs / Term Meta Vaults governance attack drained about $8.5 million

    An attacker used a low-cost tmvETH / gtmvETH voting-power path to influence Term Vault governance and drain about $8.5 million, including about 2,843 ETH and $1.68 million in stablecoins. Term closed Meta Vaults, revoked DAO roles, and blocked new deposits while withdrawals remain available.

    Primary source:Term Labs initial confirmation
  23. DCI-2026-254

    The Sandbox SAND OFT suffered delegate hijacking and unauthorized minting

    The Base SAND OFT approveAndCall / LayerZero delegate path was abused to mint large amounts of unbacked SAND. The Sandbox confirmed containment; SAND on Ethereum and Polygon was unaffected. GoPlus estimated actual loss constrained by liquidity and reserves at about $670,000.

    Primary source:Blockaid SAND OFT initial report
  24. DCI-2026-253

    Bofur Capital-labeled address lost about $2 million USDC to address poisoning

    Dust transfers and look-alike addresses polluted transaction history. After a Bofur Capital-labeled Ethereum address withdrew from Compound, it mis-sent 2,000,000 USDC to the poisoned address, which was later swapped into about 1,999,939.4763 DAI.

    Primary source:ScamSniffer Bofur alert
  25. DCI-2026-252

    MANTRA Chain Cosmos-EVM vulnerability exploitation caused a mainnet pause

    MANTRA confirmed exploitation of an upstream Cosmos-EVM module vulnerability. The mainnet paused near block 17,449,398 and two MANTRA management wallets were affected. MANTRA said user, exchange, and partner funds were not directly affected; the chain later resumed block production with v8.4.0.

    Primary source:MANTRA initial announcement
  26. DCI-2026-251

    Malicious Rust crates.io packages compromised the developer supply chain

    Rust security response confirmed malicious versions of arrayref, internment, and append-only-vec were published and could execute a malicious dependency during builds. The versions were removed and the account was locked; no specific crypto project or on-chain loss was confirmed.

    Primary source:Rust official security response
  27. DCI-2026-246

    Solidity Pro VS Code extension poisoning targeted Web3 developers

    SlowMist disclosed malicious activity in historical Solidity Pro VS Code extension versions, exposing browser wallets, local private keys and seed phrases, API keys, SSH keys, and source-control credentials. It is a disclosed malicious developer-tool supply-chain campaign, but no single on-chain victim transaction has been confirmed.

    Primary source:SlowMist Solidity Pro X alert
  28. DCI-2026-245

    MAYAChain false-subsidy accounting and composable cross-chain liquidity attack

    MAYAChain suffered a composable protocol attack in which false-subsidy and accounting-validation flaws created unsupported internal ARB.LINK balances. The attacker extracted CACAO and LINK through liquidity operations and moved value to Bitcoin, Ethereum, Arbitrum, and THORChain. Confirmed L1 outflows were about $1,356,218, while total attacker-held value was estimated at about $1,647,599.

    Primary source:Aaluxx MAYA incident statement
  29. DCI-2026-238

    BitMart Chinese official X account was taken over

    A BitMart-linked executive confirmed that the Chinese official X account was compromised and that the abnormal content was not posted by a current employee. The original malicious post is unavailable, and no verifiable on-chain theft or user-asset loss was found.

    Primary source:BitMart Chinese-account takeover confirmation
  30. DCI-2026-237

    New Solana wallet was drained of about 6.209 SOL

    An on-chain transaction shows a Solana wallet sending 6.209202768 SOL to a receiving address. The private key had been imported into a trading bot, but public evidence does not identify the bot, clipboard, endpoint malware, or social engineering as the specific leak path.

    Primary source:Solana wallet-drain source post
  31. DCI-2026-234

    SafePal order-tracking plugin data breach affected about 39,798 customers

    SafePal disclosed unauthorized access in its order-tracking plugin, affecting information for about 39,798 historical customers, including names, emails, delivery addresses, phone numbers, and purchase details. Seeds, private keys, wallet passwords, payment cards, and government IDs were not involved.

    Primary source:SafePal official disclosure
  32. DCI-2026-233

    FoxLpBondsPool spot-price manipulation and stale accounting caused about $118,700 in loss

    On BNB Chain, FoxLpBondsPool read a manipulable PancakePair spot price and reused a stale _stakeAmount, causing Treasury to mint excessive Fox rewards. The attacker sold the new Fox in the same transaction for an estimated $118,700 gain.

    Primary source:SlowMist Fox root-cause analysis
  33. DCI-2026-232

    Trezor logistics provider ShipMonk data breach affected 13,689 customers

    Trezor disclosed unauthorized access in a third-party ShipMonk logistics environment. Full names, emails, phone numbers, and delivery addresses were exposed for 11,742 customers, while names, cities, and emails were exposed for another 1,947. Wallets, devices, and backup words were not identified as compromised.

    Primary source:Trezor official disclosure
  34. DCI-2026-231

    Malicious increaseAllowance approval drained about $550,000 in USDC on Arbitrum

    After a victim signed an effectively unlimited increaseAllowance, the attacker used multicall to execute three transferFrom calls six seconds later and moved about 550,019.146870 USDC. The alert rounded the amount to 549,744 USDC; the on-chain Transfer sum is retained as the precise basis.

    Primary source:ScamSniffer Arbitrum approval-theft alert
  35. DCI-2026-230

    TLBL whale wallets were likely compromised through private-key exposure, losing about $25–25.6 million

    Two public Ethereum wallets were drained within approximately 15 minutes, after which the assets were swapped into about 20 million DAI and 3,000 ETH. Security researchers favor likely private-key exposure, but the victim has not published endpoint forensics; $25–25.6 million is a valuation range from different reporting points.

    Primary source:ScamSniffer TLBL initial alert
  36. DCI-2026-228

    Harmony cross-shard receipt replay caused unauthorized minting

    Harmony's forensic update placed the first anomalous activity at Shard 0 block 92,730,036 on August 12, 2026 at 07:25:41. The first wave minted 4 billion ONE in two empty blocks, while a six-transaction, four-wallet reconstruction totals 3,010,000,100,000 ONE. Cross-shard receipt replay is the confirmed primary flaw; the empty-signature quorum issue remains a secondary attribution under review. No final freeze or net USD loss was public.

    Primary source:Harmony initial response, patch, and rollback options
  37. DCI-2026-229

    Solana address poisoning caused an approximately $100,000 USDT mis-transfer

    Cyvers disclosed an address-poisoning incident in which a victim copied an impersonating address from transaction history and mis-sent approximately 100,012.89 USDT. The attacker then swapped the USDT for about 52.8 ETH. The attacker, victim, and loss-transaction identifiers were truncated in the source image and are not guessed.

    Primary source:Cyvers address-poisoning alert
  38. DCI-2026-225

    Oraichain EVM cross-chain transfer flaw enabled unauthorized ORAI minting

    SlowMist Hacked Zone and Oraichain’s official notice describe an EVM cross-chain transfer flaw that enabled unauthorized ORAI minting. The network was paused for remediation, burning, and reconciliation; no verifiable loss amount was disclosed.

    Primary source:Oraichain official security notice
  39. DCI-2026-224

    Bifrost shared Guardian Vault exploited across three farming pools

    Bifrost confirmed exploitation of a shared Guardian Vault across three farming pools involving 881,150 DOT, publicly valued at about $720,000. The underlying vDOT reserve remained 1:1 backed, and complete attack identifiers were not disclosed.

    Primary source:Bifrost initial official notice
  40. DCI-2026-222

    USM / FUM defund pricing logic exploited through flash loans and split calls

    USM / FUM on Ethereum was exploited through flash loans and about 64 split defund calls, with an estimate of 70.83 ETH and a disclosed USD value of about $136,000.

    Primary source:CertiK technical alert
  41. DCI-2026-221

    Coinsbuy-linked hot wallets drained across Ethereum and TRON for about $7.9 million

    Coinsbuy-linked hot wallets suffered concentrated outflows on Ethereum and TRON with a public estimate of about $7.9 million. Some funds moved through ChangeNOW, FixedFloat, and BingX; the root cause and final aggregation route remain incomplete.

    Primary source:DarkWebInformer addresses and initial route
  42. DCI-2026-223

    Ongoing sponsored-search phishing activity impersonating Trezor and Ledger

    The same phishing activity placed sponsored ads in Trezor and Ledger searches and directed users to imitation pages for high-risk wallet actions. Cross-window losses were estimated above $3 million, while the strict-window increment cannot be isolated.

    Primary source:CoinDesk Trezor sponsored-ad alert
  43. DCI-2026-214

    BTCPay Server flaw exposed Lightning credentials and enabled wallet theft

    BTCPay Server / LND nodes were affected by a server flaw or credential exposure, and operators including Foundation and Citadel21 reported Lightning funds being drained. Public reporting has not established a unified victim set or total loss.

    Primary source:BTCPay flaw and affected-entity leads
  44. DCI-2026-213

    Base phishing authorization theft of approximately 500,000 USDC

    A personal wallet on Base lost approximately 500,000 USDC after phishing or malicious authorization. The attacker then swapped through a low-liquidity Uniswap V4 pool and ended with about 67 WETH; most value was captured by MEV and was not returned to the victim.

    Primary source:PeckShield alert
  45. DCI-2026-215

    ZEUS Bitcoin Lightning infrastructure compromise with no customer-fund loss

    SlowMist recorded a compromise of ZEUS Bitcoin Lightning wallet and LSP infrastructure. The incident was mitigated, customer funds were not lost or at risk, and services were temporarily offline.

    Primary source:SlowMist Hacked Zone ZEUS record
  46. DCI-2026-212

    Keyv / Cacheable npm supply-chain compromise

    The Keyv / Cacheable npm release chain was hijacked, allowing malicious versions to target CI/CD and developer credentials. Multiple security teams corroborated the compromise, but no unified direct on-chain loss amount was confirmed by the report cutoff.

    Primary source:SlowMist Web3 supply-chain alert
  47. DCI-2026-211

    RISEx RWA strategy unauthorized withdrawal of 673,011.56 USDC

    An RISEx-linked RWA strategy suffered an unauthorized withdrawal of 673,011.56 USDC. SlowMist records the incident date as August 3; the project said it patched the issue and fully compensated XLP depositors, which is not the same as recovering attacker funds.

    Primary source:SlowMist Hacked Zone RISEx record
  48. DCI-2026-204

    KRON PEPE pool indexing and accounting were disrupted with no confirmed fund loss

    KRON said that re-importing an internal token caused an indexing and accounting mismatch around the PEPE pool. Trading was unavailable for about two hours and LP access was paused longer; the team restored from backup, blocked the path, and said no funds were stolen, drained, or moved.

    Primary source:KRON transparency report
  49. DCI-2026-203

    MOKE: a complex BSC transaction triggered an estimated $907,700 attack alert

    TenArmor flagged a successful transaction with multiple assets and protocol calls and estimated approximately $907,700 at risk. The transaction and tokens are verifiable on BNB Smart Chain, but the root cause, affected-contract boundary, and final net loss require independent analysis.

    Primary source:TenArmor original alert
  50. DCI-2026-210

    LOOPSDAO / LpdFi spot-oracle manipulation on BNB Chain

    ExVul, Backward Labs, and on-chain researchers documented a LpdFi oracle-manipulation attack on BNB Chain. The attacker used flash-loan and spot-price manipulation to remove LP assets; public estimates put the loss at approximately $696,952.81.

    Primary source:ExVul initial report and attack transaction
  51. DCI-2026-205

    Twenty-two OKX Web3 extension wallets were reportedly drained after a suspected endpoint compromise

    A user reported that assets from 22 OKX Web3 extension wallets were moved after downloading several untrusted VPN tools, with about 1,000 USDT reported lost and about 300 USDT moved to safety. Public evidence supports a personal-wallet compromise lead, but no malware sample, complete transaction path, or independent forensic conclusion was available.

    Primary source:Victim’s original X post
  52. DCI-2026-199

    Swan Treasury off-chain signer key compromise

    The attacker used a compromised off-chain signer key to set the discount parameter to 1, bought roughly 687,000 STY for about 19,700 USDT, and sold the tokens for approximately 625,000 USDT in net proceeds. Defimon reported that repeated ecrecover calls resolved to the same hardcoded signer, supporting a key-compromise finding.

    Primary source:Defimon Alerts exploit analysis
  53. DCI-2026-208

    Base unverified contract exploit drained 16.623 WETH through an unrestricted low-level call

    An attacker used an unrestricted low-level CALL in an unverified Base contract to abuse an existing WETH approval and transfer 16.623029776956898128 WETH from a victim. The exploit occurred on July 30 and was disclosed by SlowMist on August 1, making it a prior-case technical disclosure during the window.

    Primary source:SlowMist technical alert
  54. DCI-2026-198

    Set Protocol ExchangeIssuance state-inflation exploit

    An attacker used a malicious SetToken, pre-issue hook, and fake valuer to inflate component units by approximately 93.66 times after quotation, causing ExchangeIssuance to transfer excess real assets. SlowMist estimated the loss at about $9,600.

    Primary source:SlowMist full exploit analysis
  55. DCI-2026-197

    COLDCARD weak-entropy flaw linked to multistage BTC theft

    Coinkite confirmed a weak-entropy flaw in seed generation on older COLDCARD firmware. The first three waves confirmed approximately 1,367.05 BTC; on August 12, 2026, SlowMist disclosed a cross-wave cumulative total of at least 1,719 BTC, about $111M, across more than 5,200 addresses. The initial 388.92748828 BTC fourth-wave figure from August 3 remains under review and is not added again.

    Primary source:Coinkite seed-generation security warning
  56. DCI-2026-194

    Relay AI meeting-tool recruitment malware campaign

    SlowMist MistEye disclosed a recruitment-scam campaign targeting Web3 professionals. Attackers impersonated recruiters and induced targets to install malware disguised as the Relay AI meeting tool on macOS or Windows in order to steal endpoint credentials.

    Primary source:SlowMist recruitment-malware alert
  57. DCI-2026-193

    LULA recycle() reserve-manipulation exploit

    The privileged recycle() function in the LULA Rental contract could move LULA directly from a PancakeSwap V2 pool and call sync(). The attacker combined flash liquidity, reward claims, and reserve updates to obtain 578,295.907588061 USDT.

    Primary source:BlockSec Phalcon analysis
  58. DCI-2026-191

    TheIndexFi former-member delegated-access incident

    TheIndexFi’s X account published abnormal wallet-connection content. The project said this was not an external takeover: a former member still retained delegated access. The team removed the content and revoked access. No victim transaction or loss has been confirmed.

    Primary source:TheIndexFi abnormal post
  59. DCI-2026-190

    CryptoDAO Global / PRO access-control exploit

    In CryptoDAO Global’s previous PRO implementation, exec() lacked a caller check. The attacker repeatedly invoked the function through an attack contract and distorted the PRO/USDT price, earning approximately $52,000. The proxy was later upgraded to an implementation with caller validation.

    Primary source:GoPlus attack analysis
  60. DCI-2026-196

    ChainConnect bridge suffered unauthorized access

    SlowMist recorded approximately $650,000 drained from ChainConnect bridge contracts across Ethereum, BNB Chain, Avalanche, and Polygon in 23 transactions. Venom Foundation later confirmed a bridge security incident and the suspension of all bridge operations.

    Primary source:SlowMist Hacked Zone incident record
  61. DCI-2026-114

    Malicious multicall concealed an unlimited approval and drained alphaUSDCDeltaV2

    After the victim signed a transaction presented as multicall, an inner call granted an attacker unlimited approval. About 36 seconds later, the attacker used transferFrom to remove 332,787 alphaUSDCDeltaV2, valued at approximately $340,463.

    Primary source:Scam Sniffer primary alert
  62. DCI-2026-111

    Garden Finance HTLC and solver infrastructure exploitation

    An independent Garden Finance solver’s off-chain database was compromised and populated with fraudulent records, causing HTLC flows on Ethereum, Base, Arbitrum, and BNB Chain to release approximately 450,000 USDT improperly. The project said its core protocol and smart contracts were not compromised and took the application offline.

    Primary source:Blockaid primary alert
  63. DCI-2026-110

    WEMIX$ contract authority compromise and unauthorized minting

    WEMIX confirmed that ownership of a WEMIX$-related contract was compromised. The attacker minted approximately 5.2255 million WEMIX$ without authorization and swapped it into 30,736 WEMIX and 724,198.27 USDC.e. Reported loss uses an approximately $730,000 realized-value basis and does not add nominal minted value.

    Primary source:Initial WEMIX security notice
  64. DCI-2026-189

    Projekt reward-allocation logic exploit

    Projekt’s GREEN/GOLD reward vault used permissionless trackPurchase() to allocate rewards from token-balance changes without verifying real ETH expenditure. The attacker used flash liquidity and skim() to create fake purchase records, then withdrew approximately 301.7 ETH, valued near $560,000, through massWithdraw().

    Primary source:Defimon technical analysis
  65. DCI-2026-188

    Bankrbot X account and project wallet compromise

    Bankrbot’s X account was taken over despite an on-device passkey and used to publish fake airdrop links. In the same incident window, a project wallet without multifactor authentication was drained of approximately 1.5 billion BNKR. SlowMist Hacked Zone records a loss of about $479,885.

    Primary source:Bankrbot team account-compromise notice
  66. DCI-2026-112

    Triple-A multi-chain hot-wallet outflow

    Triple-A confirmed unauthorized access to company hot wallets across multiple chains and a final loss of approximately $11.8 million. Client and merchant funds were unaffected. Assets were swapped, bridged, and consolidated on Ethereum, and services resumed after security checks.

    Primary source:PeckShieldAlert multi-chain outflow alert
  67. DCI-2026-186

    Solido Cash oracle misassignment and excess minting

    After the SOLID collateral feed failed, Solido Cash incorrectly fell back to a CASH price near $1 and severely overvalued low-priced SOLID. The attacker minted 809,051.55 CASH and obtained approximately 293,705,544.97 SUPRA.

    Primary source:Solido forensic-report announcement
  68. DCI-2026-113

    Lien Finance multiset-integrity validation exploit

    Lien Finance’s exchangeEquivalentBonds compared only aggregate anomaly counts and did not verify each bondID multiplicity. The attacker duplicated a bondID in the output, minted undercollateralized BondToken, and redeemed 542,144.63 USDC through preapproved endpoints.

    Primary source:SlowMist TI alert and root-cause analysis
  69. DCI-2026-058

    Evan Jawad reports PC and account compromise with cryptocurrency and NFT losses

    Evan Jawad said an unknown file led to compromise of his PC, multiple accounts, and X account, followed by the transfer of more than $600 in wallet assets and NFTs, for a total loss exceeding $1,000. This is a first-party report without public addresses, transaction IDs, sample, or independent forensics.

    Primary source:Evan Jawad first-party statement
  70. DCI-2026-056

    Robinhood CEO Vlad Tenev’s X account was taken over to promote a fake VLAD token

    Robinhood confirmed that Vlad Tenev’s X account was compromised and used to promote a fake VLAD token before access was restored. GoPlus associated address 0xd70627fd9ee5b70906620a6f2001ba74457b438d with the token deployment and an estimated $1.2 million to $1.3 million in attacker profit; that profit is not confirmed victim net loss.

    Primary source:Robinhood Comms confirmation
  71. DCI-2026-187

    Second Verus–Ethereum Bridge exploit of the same flaw

    The attacker exploited different handling of duplicate proofRoots on Verus and Ethereum, allowing a malicious state root to overwrite the genuine root. A fabricated import proof based on a 0.01 VRSC export then released approximately $7.44 million from bridge reserves.

    Primary source:BlockSec Phalcon root-cause update
  72. DCI-2026-051

    Unauthorized access to B² Network staking-contract upgrade authority

    B² Network confirmed unauthorized access to its staking-contract upgrade authority. Approximately 8.591 million B2 was withdrawn; nominal value was about $3.86 million and realized proceeds were about 5,409 BNB, or $3.01 million.

    Primary source:x.com source
  73. DCI-2026-050

    AFX Trade custodial bridge exploited for approximately 24.15 million USDC

    Approximately 24.15 million USDC left the AFX custodial bridge and was converted into about 12,467.44 ETH. On July 25, 2026, monitoring showed 655.4 ETH converted through THORChain into 18.86 BTC, while about 11,812 ETH remained at related addresses; no freeze, return, or recovery was confirmed.

    Primary source:x.com source
  74. DCI-2026-044

    Repeat theft through a 183-day-old malicious Permit

    An unrevoked Permit was reused to steal 75,780 USDC; the two known thefts total about 77,405 USDC.

    Primary source:x.com source
  75. DCI-2026-043

    42DAO / Balance Coin oracle liquidation attack

    An abnormally low BTCB oracle price triggered immediate liquidations, causing an estimated $912,000-$915,000 loss.

    Primary source:x.com source
  76. DCI-2026-185

    FlashTrade ephemeral-instance unauthorized withdrawal

    FlashTrade confirmed an unauthorized $98,000 withdrawal from an ephemeral instance. Newly deployed withdrawal batching and monitoring detected and contained the event quickly. The team said it would cover the amount in full and that user funds were unaffected.

    Primary source:FlashTrade initial announcement
  77. DCI-2026-041

    Wanchain Cardano-BNB Chain NIGHT bridge incident

    About 515 million NIGHT tokens were exposed; realized swaps and the reported nominal $9-13 million exposure are recorded separately.

    Primary source:x.com source
  78. DCI-2026-040

    Malicious TRAE IDE extension

    A malicious IDE extension targeted developer credentials and wallet material through the software supply chain.

    Primary source:x.com source
  79. DCI-2026-039

    Zilliqa partner exchange cold-wallet theft

    A cold wallet operated by a Zilliqa partner exchange was compromised; the cited sources did not establish one USD loss figure.

    Primary source:x.com source
  80. DCI-2026-038

    Delayed theft from a year-old malicious approval

    An approval granted about a year earlier was used to steal approximately $84,000 after funds returned to the victim wallet.

    Primary source:x.com source
  81. DCI-2026-037

    RWT protocol exploit

    A protocol weakness caused approximately $118,100 in reported losses.

    Primary source:bscscan.com source
  82. DCI-2026-036

    Allbridge Core bridge exploit

    A bridge weakness caused approximately $1.65 million in reported losses.

    Primary source:x.com source
  83. DCI-2026-033

    Fake Web3 recruitment GitHub malware

    Fraudulent recruiting workflows delivered malware through GitHub repositories, creating credential and wallet-theft risk.

    Primary source:x.com source
  84. DCI-2026-032

    CrowdRingCircle protocol incident

    A smart-contract weakness caused approximately $201,400 in reported losses.

    Primary source:bscscan.com source
  85. DCI-2026-031

    FCOW protocol exploit

    A protocol weakness caused approximately $61,300 in reported losses.

    Primary source:bscscan.com source
  86. DCI-2026-030

    Across Protocol / Risk Labs relayer forged-deposit incident

    Across confirmed that a Solana off-chain event-reading defect caused a Risk Labs relayer to advance real assets against forged deposits, with reported loss of approximately $3.6 million. On July 28, 2026, a labeled attacker address returned 331.8 ETH to the Across Hub Pool Owner Multisig, valued at about $623,900 when disclosed.

    Primary source:x.com source
  87. DCI-2026-028

    DeFiTuna oracle manipulation

    A pricing weakness enabled abnormal liquidations and approximately $580,000 in reported losses.

    Primary source:certik.com source
  88. DCI-2026-027

    Chi Protocol exploit

    A protocol weakness was exploited for approximately $8,500.

    Primary source:x.com source
  89. DCI-2026-026

    Cascade CLS Vault exploit

    A vault weakness caused approximately $1.34 million in reported losses.

    Primary source:x.com source
  90. DCI-2026-047

    macOS infostealer hijacks Telegram and swaps hardware-wallet apps

    Malware replaced Telegram and Ledger/Trezor software while stealing local credentials; aggregate on-chain loss remains unknown.

    Primary source:slowmist.medium.com source
  91. DCI-2026-024

    Ostium oracle manipulation incident

    An oracle and pricing weakness caused approximately $23.75 million in reported losses.

    Primary source:x.com source
  92. DCI-2026-022

    Drips Network protocol incident

    A protocol incident led to approximately $24,883 in reported losses.

    Primary source:x.com source
  93. DCI-2026-021

    VECAndETH protocol exploit

    A contract-level weakness was exploited for approximately $109,600.

    Primary source:bscscan.com source
  94. DCI-2026-020

    Lumi Finance smart-account authorization flaw

    An authorization weakness affecting smart accounts enabled approximately $270,000 in unauthorized asset transfers.

    Primary source:x.com source
  95. DCI-2026-048

    PHX Pancake LP drain on BNB Chain

    Liquidity was removed from a PHX Pancake pool, causing approximately $89,600 in reported losses.

    Primary source:x.com source
  96. DCI-2026-019

    Solana OG personal wallet theft

    A long-time Solana holder lost assets estimated at about $14.2 million after a personal wallet compromise.

    Primary source:x.com source
  97. DCI-2026-018

    Bonzo Lend oracle manipulation

    A pricing and liquidation weakness caused approximately $9.05 million in reported losses.

    Primary source:x.com source
  98. DCI-2026-023

    BarnBridge SMART Yield governance attack

    A malicious governance path was used to extract approximately 776,600 USDC.

    Primary source:x.com source
  99. DCI-2026-015

    BONK DAO malicious governance proposal

    A malicious governance action created an exposure estimated at about $20 million and triggered emergency community response.

    Primary source:x.com source
  100. DCI-2026-007

    Summer.fi shared-accounting price manipulation

    An attacker manipulated shared vault accounting and price calculations, causing approximately $6.04 million in reported losses.

    Primary source:x.com source
  101. DCI-2026-046

    Gate user account-takeover dispute involving $1.7 million

    A Gate user reported an account takeover and approximately $1.7 million in disputed losses; responsibility remains contested.

    Primary source:etherscan.io source
  102. DCI-2026-012

    Hinkal Protocol exploit

    A protocol weakness was exploited for approximately $820,000, according to the cited on-chain security disclosures.

    Primary source:x.com source
  103. DCI-2026-045

    Alkanes / DIESEL indexer attack

    An indexer-level attack disrupted data integrity, but the cited sources did not identify a direct asset loss.

    Primary source:x.com source
  104. DCI-2026-009

    Malicious npm package supply-chain campaign

    At least 30 lookalike Web3 packages carried credential-stealing code; aggregate wallet losses were not publicly established.

    Primary source:x.com source
  105. DCI-2026-008

    Edel Finance ERC-4626 donation attack

    Attackers manipulated an ERC-4626 share price used as collateral, extracting about $353,000 and leaving roughly $403,000 in bad debt.

    Primary source:x.com source
  106. DCI-2026-106

    Unnamed Base ERC-4626 vault exploit

    Public sources identify Unnamed Base ERC-4626 vault exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.

    Primary source:Public security alert or project statement
  107. DCI-2026-105

    AIDC — on-chain smart-contract exploit

    Public sources identify AIDC — on-chain smart-contract exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.

    Primary source:Public security alert or project statement
  108. DCI-2026-104

    Cook Finance Issuance — on-chain smart-contract exploit

    Public sources report Cook Finance Issuance — on-chain smart-contract exploit, with a loss of approximately $50,000.

    Primary source:Public security alert or project statement
  109. DCI-2026-103

    Mini Shai-Hulud, Miasma and Hades malware expands into Go modules

    Mini Shai-Hulud, Miasma, and Hades malware expanded into Go modules in a documented supply-chain campaign; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  110. DCI-2026-102

    czirker developer account compromise contaminates 23 npm packages

    Compromise of the czirker developer account contaminated 23 npm packages; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  111. DCI-2026-101

    Polymarket International — Front-end Vulnerability

    Public sources report Polymarket International — Front-end Vulnerability, with a loss of approximately $3,000,000.

    Primary source:Public security alert or project statement
  112. DCI-2026-100

    Ocean Protocol BPool/SideStaking — on-chain smart-contract exploit

    Public sources identify Ocean Protocol BPool/SideStaking — on-chain smart-contract exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.

    Primary source:Public security alert or project statement
  113. DCI-2026-099

    Lixir Finance forged Permit signature theft

    Public sources report Lixir Finance forged Permit signature theft, with a loss of approximately $12,300.

    Primary source:Public security alert or project statement
  114. DCI-2026-098

    Wallet drainer injected into Yield Yak voting subdomain

    A wallet drainer was injected into the Yield Yak voting subdomain; no verified aggregate loss amount was published.

    Primary source:cryptopolitan.com public source
  115. DCI-2026-097

    DLMC — on-chain smart-contract exploit

    Public sources report DLMC — on-chain smart-contract exploit, with a loss of approximately $222,560.

    Primary source:Public security alert or project statement
  116. DCI-2026-096

    Royal.io/Royal Royalties — on-chain smart-contract exploit

    Public sources report Royal.io/Royal Royalties — on-chain smart-contract exploit, with a loss of approximately $261,163.

    Primary source:Public security alert or project statement
  117. DCI-2026-095

    Wallet drainer injected into a Gitcoin voting subdomain

    A wallet drainer was injected into a Gitcoin voting subdomain; no verified aggregate loss amount was published.

    Primary source:cryptopolitan.com public source
  118. DCI-2026-005

    SecondFi — Predictable Private Key Exploit

    A deterministic nonce-derivation flaw in the SecondFi web-wallet software signer made some Cardano private keys derivable from public signatures. Public reporting confirms about 16 million ADA, worth roughly $2.4 million, was stolen.

    Primary source:Public security alert or project statement
  119. DCI-2026-094

    ATM liquidity-pool transfer front-run by a burn transaction

    Public sources identify ATM liquidity-pool transfer front-run by a burn transaction as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.

    Primary source:Public security alert or project statement
  120. DCI-2026-093

    Taiko Bridge — Fake Proof Exploit

    Public sources report Taiko Bridge — Fake Proof Exploit, with a loss of approximately $1,700,000.

    Primary source:Public security alert or project statement
  121. DCI-2026-092

    Quicksilver Zone — Unchecked Proof Minting

    Public sources report Quicksilver Zone — Unchecked Proof Minting, with a loss of approximately $3,500.

    Primary source:DeFiLlama Hacks database
  122. DCI-2026-091

    OLPC/LABUBU — on-chain smart-contract exploit

    Public sources report OLPC/LABUBU — on-chain smart-contract exploit, with a loss of approximately $1,115,904.

    Primary source:Public security alert or project statement
  123. DCI-2026-090

    JaredFromSubway MEV Bot — Reverse MEV Honeypot

    Public sources report JaredFromSubway MEV Bot — Reverse MEV Honeypot, with a loss of approximately $7,500,000.

    Primary source:Public security alert or project statement
  124. DCI-2026-089

    mySwap CL — CL Pool Accounting Hack

    Public sources report mySwap CL — CL Pool Accounting Hack, with a loss of approximately $300,000.

    Primary source:DeFiLlama Hacks database
  125. DCI-2026-088

    Secret Network — Unbacked Mint via ICS-20

    Public sources report Secret Network — Unbacked Mint via ICS-20, with a loss of approximately $4,670,000.

    Primary source:ourcryptotalk.com public source
  126. DCI-2026-087

    Namada Shielded Pools — IBC Transfer Logic Exploit

    Public sources report Namada Shielded Pools — IBC Transfer Logic Exploit, with a loss of approximately $600,000.

    Primary source:DeFiLlama Hacks database
  127. DCI-2026-086

    JB — on-chain smart-contract exploit

    Public sources report JB — on-chain smart-contract exploit, with a loss of approximately $49,958.

    Primary source:Public security alert or project statement
  128. DCI-2026-085

    WHALE — on-chain smart-contract exploit

    Public sources report WHALE — on-chain smart-contract exploit, with a loss of approximately $3,460.

    Primary source:Public security alert or project statement
  129. DCI-2026-084

    Malicious dependency inserted across more than 140 Mastra packages

    A malicious dependency was inserted across more than 140 Mastra packages; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  130. DCI-2026-083

    Little Boy Plus/LBP — on-chain smart-contract exploit

    Public sources report Little Boy Plus/LBP — on-chain smart-contract exploit, with a loss of approximately $367,000.

    Primary source:Public security alert or project statement
  131. DCI-2026-082

    Aztec V1 EscapeHatch — on-chain smart-contract exploit

    Public sources report Aztec V1 EscapeHatch — on-chain smart-contract exploit, with a loss of approximately $2,200,000.

    Primary source:DeFiHackLabs on-chain reproduction
  132. DCI-2026-081

    RetoSwap — ACK Frontrun Attack

    Public sources report RetoSwap — ACK Frontrun Attack, with a loss of approximately $2,700,000.

    Primary source:DeFiLlama Hacks database
  133. DCI-2026-080

    DIP — on-chain smart-contract exploit

    Public sources report DIP — on-chain smart-contract exploit, with a loss of approximately $111,098.

    Primary source:Public security alert or project statement
  134. DCI-2026-109

    Thetanuts Finance — on-chain smart-contract exploit

    Public sources report Thetanuts Finance — on-chain smart-contract exploit, with a loss of approximately $105,000.

    Primary source:Public security alert or project statement
  135. DCI-2026-079

    SStar Agent fake Web3 AI project malware campaign

    The fake SStar Agent Web3 AI project distributed malware; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  136. DCI-2026-078

    Aztec Connect — on-chain smart-contract exploit

    Public sources report Aztec Connect — on-chain smart-contract exploit, with a loss of approximately $2,190,000.

    Primary source:Public security alert or project statement
  137. DCI-2026-077

    Malicious PyPI packages including openai_mcp

    Malicious PyPI packages including openai_mcp formed a software-supply-chain campaign; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  138. DCI-2026-075

    Raydium AMM — Fake LP Mint Attack

    Public sources report Raydium AMM — Fake LP Mint Attack, with a loss of approximately $1,340,000.

    Primary source:Public security alert or project statement
  139. DCI-2026-074

    Token of Power/TOP — on-chain smart-contract exploit

    Public sources report Token of Power/TOP — on-chain smart-contract exploit, with a loss of approximately $1,580,000.

    Primary source:Public security alert or project statement
  140. DCI-2026-073

    NovaBox — on-chain smart-contract exploit

    Public sources report NovaBox — on-chain smart-contract exploit, with a loss of approximately $107,000.

    Primary source:Public security alert or project statement
  141. DCI-2026-072

    Asterix — DN404 Forge Loop

    Public sources report Asterix — DN404 Forge Loop, with a loss of approximately $40,000.

    Primary source:DeFiLlama Hacks database
  142. DCI-2026-071

    Flooring Protocol — DN404 Forge Loop

    Public sources identify Flooring Protocol — DN404 Forge Loop as a DN404 Forge Loop incident. No single verifiable USD loss amount was published.

    Primary source:DeFiLlama Hacks database
  143. DCI-2026-004

    Humanity Protocol key compromise and unauthorized $H mint

    Humanity Protocol’s investigation says phishing and remote-access malware enabled the theft of project keys used for unauthorized transfers, minting, and sales of $H on Ethereum and BNB Chain; the aggregate uses the later loss estimate of approximately $36 million.

    Primary source:Humanity Protocol official investigation summary
  144. DCI-2026-070

    Syscoin Bridge — Fake Proof Exploit

    Public sources report Syscoin Bridge — Fake Proof Exploit, with a loss of approximately $8,000,000.

    Primary source:halborn.com public source
  145. DCI-2026-069

    Ambient CrocSwapDex — on-chain smart-contract exploit

    Public sources report Ambient CrocSwapDex — on-chain smart-contract exploit, with a loss of approximately $110,000.

    Primary source:Public security alert or project statement
  146. DCI-2026-068

    ATOHook — token-pool smart-contract exploit

    Public sources report ATOHook — token-pool smart-contract exploit, with a loss of approximately $2,100,000.

    Primary source:Public security alert or project statement
  147. DCI-2026-067

    BOSS — on-chain smart-contract exploit

    Public sources report BOSS — on-chain smart-contract exploit, with a loss of approximately $10,208.

    Primary source:Public security alert or project statement
  148. DCI-2026-066

    DTXT — on-chain smart-contract exploit

    Public sources report DTXT — on-chain smart-contract exploit, with a loss of approximately $35,041.

    Primary source:Public security alert or project statement
  149. DCI-2026-065

    AISO Presale — on-chain smart-contract exploit

    Public sources report AISO Presale — on-chain smart-contract exploit, with a loss of approximately $30,315.

    Primary source:Public security alert or project statement
  150. DCI-2026-064

    BY Token — on-chain smart-contract exploit

    Public sources report BY Token — on-chain smart-contract exploit, with a loss of approximately $87,402.

    Primary source:DeFiHackLabs on-chain reproduction
  151. DCI-2026-063

    ATM Token — on-chain smart-contract exploit

    Public sources report ATM Token — on-chain smart-contract exploit, with a loss of approximately $243,543.

    Primary source:DeFiHackLabs on-chain reproduction
  152. DCI-2026-062

    GPU.NET — Social Engineering

    Public sources report GPU.NET — Social Engineering, with a loss of approximately $10,600.

    Primary source:DeFiLlama Hacks database
  153. DCI-2026-061

    Red Hat Cloud Services npm supply-chain compromise

    The Red Hat Cloud Services npm publishing chain was compromised; no verified aggregate loss amount was published.

    Primary source:Public security alert or project statement
  154. DCI-2026-060

    TSR — Infinite Mint and Dump

    Public sources report TSR — Infinite Mint and Dump, with a loss of approximately $2,500,000.

    Primary source:Public security alert or project statement
  155. DCI-2026-059

    Gnosis Pay — Zodiac Delay Module Exploit

    Public sources identify Gnosis Pay — Zodiac Delay Module Exploit as a Zodiac Delay Module Exploit incident. No single verifiable USD loss amount was published.

    Primary source:DeFiLlama Hacks database
  156. DCI-2026-177

    Fluid Lending reward-list operational-key compromise

    Fluid Lending reward-list operational-key compromise was reported on 2026-05-31. Evidence indicates that an operational key controlling the reward list was compromised. Reported loss is approximately $215,000.

    Primary source:fluid.io public source
  157. DCI-2026-176

    AFI Protocol afiUSD Vault theft

    AFI Protocol afiUSD Vault theft was reported on 2026-05-31. Evidence indicates that afiUSD Vault authority was used to transfer assets without authorization. Reported loss is approximately $480,000.

    Primary source:x.com official statement
  158. DCI-2026-174

    AROS price-manipulation incident

    AROS price-manipulation incident was reported on 2026-05-31. Evidence indicates that the AROS market was manipulated through a pricing or liquidity path. Reported loss is approximately $295,000.

    Primary source:defillama.com public source
  159. DCI-2026-123

    Gravity Bridge compromise

    Gravity Bridge compromise was reported on 2026-05-30. Evidence indicates that the bridge validator or signing path was compromised. Reported loss is approximately $5,400,000.

    Primary source:x.com public source
  160. DCI-2026-180

    YSDAO reserve manipulation

    YSDAO reserve manipulation was reported on 2026-05-29. Evidence indicates that reserve accounting was manipulated to extract value. Reported loss is approximately $19,500.00.

    Primary source:hacked.slowmist.io public source
  161. DCI-2026-179

    MoneyMon signature-validation bypass

    MoneyMon signature-validation bypass was reported on 2026-05-29. Evidence indicates that a signature-validation bypass allowed unauthorized execution. Reported loss is approximately $85,519.47.

    Primary source:hacked.slowmist.io public source
  162. DCI-2026-003

    Alephium TokenBridge off-chain guardian exploit

    Alephium TokenBridge off-chain guardian exploit was reported on 2026-05-29. Evidence indicates that false off-chain bridge messages bypassed guardian validation. Reported loss is approximately $815,000.

    Primary source:x.com public source
  163. DCI-2026-182

    ONTR zero-address ownership and hidden-balance exploit

    ONTR zero-address ownership and hidden-balance exploit was reported on 2026-05-28. Evidence indicates that zero-address ownership and hidden-balance logic enabled unauthorized control. Reported loss is approximately $98,200.00.

    Primary source:hacked.slowmist.io public source
  164. DCI-2026-181

    Joe Agent reentrancy exploit

    Joe Agent reentrancy exploit was reported on 2026-05-28. Evidence indicates that a reentrancy weakness allowed repeated execution. Reported loss is approximately $45,000.00.

    Primary source:hacked.slowmist.io public source
  165. DCI-2026-155

    JINX-0164 macOS malware campaign

    JINX-0164 macOS malware campaign was reported on 2026-05-28. Evidence indicates that a macOS information-stealing malware family targeted credentials and wallet material. No stable verified USD loss amount was published.

    Primary source:x.com public source
  166. DCI-2026-121

    DxSale legacy LP-locker compromise

    DxSale legacy LP-locker compromise was reported on 2026-05-28. Evidence indicates that legacy administrative authority over the LP-locker path was compromised. Reported loss is approximately $7,300,000.

    Primary source:x.com public source
  167. DCI-2026-163

    AI and search-poisoning mining-malware campaign

    AI and search-poisoning mining-malware campaign was reported on 2026-05-27. Evidence indicates that search and AI-answer poisoning redirected users to mining malware. No stable verified USD loss amount was published.

    Primary source:x.com public source
  168. DCI-2026-151

    StakeDAO vsdCRV unauthorized mint

    StakeDAO vsdCRV unauthorized mint was reported on 2026-05-27. Evidence indicates that unauthorized authority was used to mint vsdCRV. Reported loss is approximately $91,170.00.

    Primary source:x.com public source
  169. DCI-2026-136

    SKP Token liquidity-pool exploit

    SKP Token liquidity-pool exploit was reported on 2026-05-27. Evidence indicates that an abnormal liquidity-pool operation affected SKP Token. Reported loss is approximately $213,000.

    Primary source:x.com public source
  170. DCI-2026-119

    SUPERFORTUNE AI multisig transaction-target substitution

    SUPERFORTUNE AI multisig transaction-target substitution was reported on 2026-05-27. Evidence indicates that a multisig transaction target was replaced with a lookalike recipient during transaction construction. Reported loss is approximately $15,180,000.

    Primary source:x.com public source
  171. DCI-2026-006

    Ill Bloom weak-randomness wallet vulnerability

    Weak randomness in wallet seed generation enabled private-key enumeration, with more than $5 million in reported multi-chain losses.

  172. DCI-2026-175

    Bitmor DCA approval theft

    Bitmor DCA approval theft was reported on 2026-05-25. Evidence indicates that a malicious approval was used to steal assets from a Bitmor DCA user. Reported loss is approximately $10,000.00.

    Primary source:revoke.cash public source
  173. DCI-2026-156

    Lazarus RemotePE in-memory RAT campaign

    Lazarus RemotePE in-memory RAT campaign was reported on 2026-05-25. Evidence indicates that Lazarus-linked RemotePE malware executed an in-memory remote-access payload. No stable verified USD loss amount was published.

    Primary source:x.com public source
  174. DCI-2026-150

    New Market Trading security incident

    New Market Trading security incident was reported on 2026-05-25. Evidence indicates that an executed trading-platform incident moved assets without authorization. Reported loss is approximately $3,980,000.

    Primary source:x.com public source
  175. DCI-2026-135

    WUSD / GLOVE exploit

    WUSD / GLOVE exploit was reported on 2026-05-25. Evidence indicates that a smart-contract weakness affected WUSD / GLOVE liquidity. Reported loss is approximately $207,000.

    Primary source:x.com public source
  176. DCI-2026-134

    Fake Uniswap Google Ads phishing campaign

    Fake Uniswap Google Ads phishing campaign was reported on 2026-05-25. Evidence indicates that a paid-search advertisement led users to a fake Uniswap phishing page. Reported loss is approximately $400,000.

    Primary source:x.com public source
  177. DCI-2026-124

    SquidRouterModule third-party module compromise

    SquidRouterModule third-party module compromise was reported on 2026-05-25. Evidence indicates that a third-party router module was compromised and used against connected liquidity. Reported loss is approximately $3,100,000.

    Primary source:x.com public source
  178. DCI-2026-154

    TrapDoor supply-chain campaign

    TrapDoor supply-chain campaign was reported on 2026-05-24. Evidence indicates that malicious code was distributed through a software supply-chain campaign. No stable verified USD loss amount was published.

    Primary source:x.com public source
  179. DCI-2026-149

    Fractal Protocol security incident

    Fractal Protocol security incident was reported on 2026-05-24. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $13,700.00.

    Primary source:x.com public source
  180. DCI-2026-148

    Mure security incident

    Mure security incident was reported on 2026-05-23. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $11,700.00.

    Primary source:x.com public source
  181. DCI-2026-125

    StablR stablecoin mint-authority compromise

    StablR stablecoin mint-authority compromise was reported on 2026-05-23. Evidence indicates that stablecoin mint authority was used without authorization. Reported loss is approximately $2,800,000.

    Primary source:x.com public source
  182. DCI-2026-160

    Based Apparel website wallet-drainer injection

    Based Apparel website wallet-drainer injection was reported on 2026-05-22. Evidence indicates that wallet-draining code was injected into the Based Apparel website. No stable verified USD loss amount was published.

    Primary source:x.com public source
  183. DCI-2026-131

    Polymarket UMA CTF Adapter operational-key compromise

    Polymarket UMA CTF Adapter operational-key compromise was reported on 2026-05-22. Evidence indicates that an operational key used by the UMA CTF Adapter was compromised. Reported loss is approximately $520,000.

    Primary source:x.com public source
  184. DCI-2026-140

    MAP / Butter Bridge exploit

    MAP / Butter Bridge exploit was reported on 2026-05-20. Evidence indicates that a bridge contract or message-validation path was exploited. Reported loss is approximately $110,000.

    Primary source:x.com public source
  185. DCI-2026-127

    RetoSwap / Haveno multisig-path exploit

    RetoSwap / Haveno multisig-path exploit was reported on 2026-05-20. Evidence indicates that the RetoSwap / Haveno multisig path was exploited. Reported loss is approximately $2,700,000.

    Primary source:x.com public source
  186. DCI-2026-147

    HermesVault security incident

    HermesVault security incident was reported on 2026-05-19. Evidence indicates that a vault weakness was exploited before most assets were returned. Reported loss is approximately $4,000.00.

    Primary source:x.com public source
  187. DCI-2026-141

    Echo Protocol / eBTC admin-key compromise

    Echo Protocol / eBTC admin-key compromise was reported on 2026-05-19. Evidence indicates that administrative signing authority was compromised. Reported loss is approximately $5,130,000.

    Primary source:x.com public source
  188. DCI-2026-052

    First Verus–Ethereum Bridge value-conservation exploit

    On May 18, 2026, Verus–Ethereum Bridge validation failed to enforce value equality between source-side input and destination-side output, allowing low-value input to release high-value reserves. Initial exposure was approximately $11.58 million, and about 4,052.4 ETH, publicly valued near $8.5 million, was later returned.

    Primary source:x.com public source
  189. DCI-2026-159

    Ledger physical-letter seed phishing campaign

    Ledger physical-letter seed phishing campaign was reported on 2026-05-17. Evidence indicates that physical letters impersonating Ledger attempted to steal wallet seed phrases. No stable verified USD loss amount was published.

    Primary source:x.com public source
  190. DCI-2026-146

    SEA Token security incident

    SEA Token security incident was reported on 2026-05-17. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $153,000.

    Primary source:x.com public source
  191. DCI-2026-132

    Adshares Bridge exploit

    Adshares Bridge exploit was reported on 2026-05-17. Evidence indicates that the Adshares bridge validation path was exploited. Reported loss is approximately $88,000.00.

    Primary source:x.com public source
  192. DCI-2026-120

    THORChain multichain vault theft

    THORChain multichain vault theft was reported on 2026-05-15. Evidence indicates that a malicious validator used threshold-signing interactions to recover vault signing material. Reported loss is approximately $10,350,000.

    Primary source:x.com public source
  193. DCI-2026-161

    Fake job-interview JobStealer campaign

    Fake job-interview JobStealer campaign was reported on 2026-05-14. Evidence indicates that fake job interviews delivered credential and wallet-stealing malware. No stable verified USD loss amount was published.

    Primary source:x.com public source
  194. DCI-2026-139

    ShapeShift Colony meta-transaction exploit

    ShapeShift Colony meta-transaction exploit was reported on 2026-05-13. Evidence indicates that a meta-transaction validation weakness allowed unauthorized execution. Reported loss is approximately $132,000.

    Primary source:x.com public source
  195. DCI-2026-128

    Transit Finance legacy-contract exploit

    Transit Finance legacy-contract exploit was reported on 2026-05-13. Evidence indicates that a legacy Transit Finance contract path remained exploitable. Reported loss is approximately $1,880,000.

    Primary source:x.com public source
  196. DCI-2026-145

    SQ Protocol ownership compromise

    SQ Protocol ownership compromise was reported on 2026-05-12. Evidence indicates that contract ownership was taken over and used against the staking contract. Reported loss is approximately $346,100.

    Primary source:x.com public source
  197. DCI-2026-133

    Aurellion Labs Diamond-proxy malicious-facet exploit

    Aurellion Labs Diamond-proxy malicious-facet exploit was reported on 2026-05-12. Evidence indicates that a malicious Diamond proxy facet was installed through administrative authority. Reported loss is approximately $456,000.

    Primary source:halborn.com public source
  198. DCI-2026-126

    TAC Protocol TON–EVM bridge incident

    TAC Protocol TON–EVM bridge incident was reported on 2026-05-12. Evidence indicates that a TON–EVM bridge path was exploited and later handled through a negotiated return. Reported loss is approximately $280,000.

    Primary source:x.com public source
  199. DCI-2026-183

    Huma Finance V1 BaseCreditPool legacy-contract exploit

    Huma Finance V1 BaseCreditPool legacy-contract exploit was reported on 2026-05-11. Evidence indicates that a legacy BaseCreditPool contract path remained exploitable. Reported loss is approximately $101,400.

    Primary source:hacked.slowmist.io public source
  200. DCI-2026-157

    TrickMo Android malware variant

    TrickMo Android malware variant was reported on 2026-05-11. Evidence indicates that a TrickMo Android malware variant targeted financial and authentication data. No stable verified USD loss amount was published.

    Primary source:x.com public source
  201. DCI-2026-138

    INK Finance treasury privilege compromise

    INK Finance treasury privilege compromise was reported on 2026-05-11. Evidence indicates that treasury privileges were used without authorization. Reported loss is approximately $140,000.

    Primary source:x.com public source
  202. DCI-2026-144

    Renegade security incident

    Renegade security incident was reported on 2026-05-10. Evidence indicates that public monitoring confirmed an executed protocol exploit and later reported returned funds. Reported loss is approximately $209,000.

    Primary source:x.com public source
  203. DCI-2026-122

    TrustedVolumes RFQ proxy exploit

    TrustedVolumes RFQ proxy exploit was reported on 2026-05-07. Evidence indicates that an RFQ proxy authorization path allowed unauthorized asset movement. Reported loss is approximately $6,300,000.

    Primary source:x.com public source
  204. DCI-2026-162

    ClickFix fake macOS tool campaign

    ClickFix fake macOS tool campaign was reported on 2026-05-06. Evidence indicates that a ClickFix social-engineering flow delivered a fake macOS tool. No stable verified USD loss amount was published.

    Primary source:x.com public source
  205. DCI-2026-129

    Ekubo Protocol extension callback exploit

    Ekubo Protocol extension callback exploit was reported on 2026-05-05. Evidence indicates that an extension callback path allowed reentrant or unauthorized execution. Reported loss is approximately $1,400,000.

    Primary source:x.com public source
  206. DCI-2026-143

    SmartCredit security incident

    SmartCredit security incident was reported on 2026-05-04. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $72,000.00.

    Primary source:x.com public source
  207. DCI-2026-137

    Bankr / Grok wallet AI-agent attack

    Bankr / Grok wallet AI-agent attack was reported on 2026-05-04. Evidence indicates that an AI-agent wallet workflow was manipulated to authorize asset movement. Reported loss is approximately $175,000.

    Primary source:x.com public source
  208. DCI-2026-158

    FEMITBOT Telegram Mini Apps malware campaign

    FEMITBOT Telegram Mini Apps malware campaign was reported on 2026-05-03. Evidence indicates that malicious Telegram Mini Apps distributed the FEMITBOT payload. No stable verified USD loss amount was published.

    Primary source:x.com public source
  209. DCI-2026-142

    Sharwa Finance security incident

    Sharwa Finance security incident was reported on 2026-05-01. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $32,850.00.

    Primary source:x.com public source
  210. DCI-2026-130

    Bisq v1 client attack

    Bisq v1 client attack was reported on 2026-05-01. Evidence indicates that a weakness in the Bisq v1 client or trade workflow enabled theft. Reported loss is approximately $858,000.

    Primary source:halborn.com public source
  211. DCI-2026-002

    KelpDAO rsETH bridge RPC infrastructure compromise

    LayerZero’s final report says compromised RPC infrastructure enabled a forged cross-chain message, resulting in the loss of 116,500 rsETH, approximately $292 million; KelpDAO’s single-DVN configuration allowed the destination contract to accept the attestation. May litigation and asset-restriction developments are attached to the same incident.

    Primary source:LayerZero final incident report
  212. DCI-2024-001

    Radiant Capital multisig operations compromise

    Attackers compromised multisig operators and tampered with the Safe Wallet transaction interface, causing about $50 million in reported losses.

    Primary source:Public incident post-mortem

Data snapshot Not real-time or complete coverage