Notional V1 Escrow arithmetic truncation exploit caused about $1.73 million in losses
Ethereum
Incident overview
Notional confirmed that a legacy V1 contract was exploited. An integer truncation in the free-collateral path allowed checks to be bypassed, leading to withdrawals of about 69,257 DAI and 1,658,525 USDC that were converted into roughly 689.2 ETH.
Text incident index
Expand the chronological list of incident titles, summaries, and primary sources.212 records
Notional confirmed that a legacy V1 contract was exploited. An integer truncation in the free-collateral path allowed checks to be bypassed, leading to withdrawals of about 69,257 DAI and 1,658,525 USDC that were converted into roughly 689.2 ETH.
Several historical SAFEs registered the shared GebProxyActions contract as owner. An attacker directly called the unauthenticated quitSystem helper and withdrew residual collateral from four SAFEs, totaling about 5.9436 ETH.
Two Ethereum users had not revoked malicious approvals signed in 2024. After SYN and USDC reached the wallets, the old approvals were used to transfer assets worth a reported total of $187,046.
An attacker used flash loans to distort a Uniswap V3 spot price, causing Float Protocol Hypervisors to misprice shares and allowing about 10.71 ETH to be extracted through repeated deposits and withdrawals.
A flaw in Ankr's ankrFLOW contract allowed about 8.6 million unbacked tokens to be created and deposited into MORE Markets, where roughly 15.5 million WFLOW was borrowed. Flow corrected the spot-value reserve impact to about $410,000.
Aquifer's Solana swap program accepted attacker-controlled token accounts and a fake token program, completing 212 swaps with real output and no real input. About $2.47 million was converted to SOL and bridged to Ethereum.
SlowMist reported that after compressing a Balancer V1 BPool's WBTC reserve, rounding in joinswapPoolAmountOut allowed the attacker to mint BPT with minimal input and exit with multiple assets, for an estimated loss of about $234,000.
Tectonic on Cronos was exploited after the attacker inflated the price of thinly traded TONIC and borrowed liquid assets. Security researchers estimated $66 million to $75 million, with about $6 million bridged to Ethereum and most remaining on Cronos after the halt.
Internal liquidation accounting across several Ajna v2 lending pools on Ethereum was manipulated through repeated liquidation paths. Ajna told users to withdraw and stop interacting; external monitoring estimated about $775,000 in losses.
Fogo Foundation confirmed that an unknown actor moved 400 million FOGO from assets under foundation control, about 4% of total supply. The chain continued operating; the token amount was valued at about $3.88 million, while complete addresses and transaction hashes remain unpublished.
An outdated Rain Solana card-balance contract was exploited through its authorization path, allowing batch withdrawals after crafted signature and administrator calls. Avici confirmed 1,685 users and $500,859.22 in affected card balances and announced refunds; a broader on-chain estimate of about $1.02 million is not additive.
The price of thinly traded MAMO collateral in Moonwell's Base lending markets was inflated, allowing the attacker to borrow real assets such as cbBTC and USDC. Security researchers estimated about $8.79 million, and Moonwell restricted the affected markets.
A CCC Token sell path on BNB Chain could alter the token reserve held by its LP. The attacker used the accounting behavior to create a price anomaly and extract liquidity; TenArmor estimated about $117,000 at stake.
Specter disclosed a four-week TRON address-poisoning campaign affecting 15 victims with an aggregate loss of about $9.4 million. Verifiable in-window USDD inflows totaled about 3,191,402.34, but cannot be treated as new net loss for the window.
An Enjin Managed Delegate Proxy on Ethereum was taken over through a DELEGATECALL storage collision and an unprotected initializer. The attacker registered a malicious adapter and transferred assets; SlowMist estimated about $162,000 in losses.
CometDEX's BLND-USDC pool on Stellar was exploited through a reserve-accounting flaw involving repeated USDC-to-USDC swaps. SlowMist reported about $717,518.92; Blend's ordinary deposit pools were unaffected, while backstop depositors were impacted.
PacaSwap confirmed that its SWAP / DAG liquidity pools were drained through a metagraph vulnerability and paused the Bridge. The project said it would cover affected LP losses, but disclosed no USD amount, attacker address, or transaction hash.
Trezor confirmed a new targeted phishing wave using data leaked from multiple crypto services. No new on-chain loss has been publicly confirmed, but the campaign is an active malicious distribution threat to multi-chain wallet users.
The FH / USDT PancakeSwap V2 pool on BNB Chain was exploited through repeated buy-and-sell calls. A FHToken sell-tax flaw corrupted pool reserves, with security researchers estimating about $20,000 in losses.
Realio-controlled realio.fund wallets showed continuing anomalous outflows across five chains from August 25. A community ledger recorded 127,918,788 RIO and about $263,596 in liquid assets; Realio confirmed an attack and paused the affected WebApp.
An attacker exploited state-dependent Uniswap V3 mint/burn accounting in a 2021 legacy G-UNI ENS–WETH vault, extracting about 2.94 WETH valued near $7,100 through atomic liquidity operations. Arrakis Pro vaults were unaffected.
An attacker used a low-cost tmvETH / gtmvETH voting-power path to influence Term Vault governance and drain about $8.5 million, including about 2,843 ETH and $1.68 million in stablecoins. Term closed Meta Vaults, revoked DAO roles, and blocked new deposits while withdrawals remain available.
The Base SAND OFT approveAndCall / LayerZero delegate path was abused to mint large amounts of unbacked SAND. The Sandbox confirmed containment; SAND on Ethereum and Polygon was unaffected. GoPlus estimated actual loss constrained by liquidity and reserves at about $670,000.
Dust transfers and look-alike addresses polluted transaction history. After a Bofur Capital-labeled Ethereum address withdrew from Compound, it mis-sent 2,000,000 USDC to the poisoned address, which was later swapped into about 1,999,939.4763 DAI.
MANTRA confirmed exploitation of an upstream Cosmos-EVM module vulnerability. The mainnet paused near block 17,449,398 and two MANTRA management wallets were affected. MANTRA said user, exchange, and partner funds were not directly affected; the chain later resumed block production with v8.4.0.
Rust security response confirmed malicious versions of arrayref, internment, and append-only-vec were published and could execute a malicious dependency during builds. The versions were removed and the account was locked; no specific crypto project or on-chain loss was confirmed.
SlowMist disclosed malicious activity in historical Solidity Pro VS Code extension versions, exposing browser wallets, local private keys and seed phrases, API keys, SSH keys, and source-control credentials. It is a disclosed malicious developer-tool supply-chain campaign, but no single on-chain victim transaction has been confirmed.
MAYAChain suffered a composable protocol attack in which false-subsidy and accounting-validation flaws created unsupported internal ARB.LINK balances. The attacker extracted CACAO and LINK through liquidity operations and moved value to Bitcoin, Ethereum, Arbitrum, and THORChain. Confirmed L1 outflows were about $1,356,218, while total attacker-held value was estimated at about $1,647,599.
A BitMart-linked executive confirmed that the Chinese official X account was compromised and that the abnormal content was not posted by a current employee. The original malicious post is unavailable, and no verifiable on-chain theft or user-asset loss was found.
An on-chain transaction shows a Solana wallet sending 6.209202768 SOL to a receiving address. The private key had been imported into a trading bot, but public evidence does not identify the bot, clipboard, endpoint malware, or social engineering as the specific leak path.
SafePal disclosed unauthorized access in its order-tracking plugin, affecting information for about 39,798 historical customers, including names, emails, delivery addresses, phone numbers, and purchase details. Seeds, private keys, wallet passwords, payment cards, and government IDs were not involved.
On BNB Chain, FoxLpBondsPool read a manipulable PancakePair spot price and reused a stale _stakeAmount, causing Treasury to mint excessive Fox rewards. The attacker sold the new Fox in the same transaction for an estimated $118,700 gain.
Trezor disclosed unauthorized access in a third-party ShipMonk logistics environment. Full names, emails, phone numbers, and delivery addresses were exposed for 11,742 customers, while names, cities, and emails were exposed for another 1,947. Wallets, devices, and backup words were not identified as compromised.
After a victim signed an effectively unlimited increaseAllowance, the attacker used multicall to execute three transferFrom calls six seconds later and moved about 550,019.146870 USDC. The alert rounded the amount to 549,744 USDC; the on-chain Transfer sum is retained as the precise basis.
Two public Ethereum wallets were drained within approximately 15 minutes, after which the assets were swapped into about 20 million DAI and 3,000 ETH. Security researchers favor likely private-key exposure, but the victim has not published endpoint forensics; $25–25.6 million is a valuation range from different reporting points.
Harmony's forensic update placed the first anomalous activity at Shard 0 block 92,730,036 on August 12, 2026 at 07:25:41. The first wave minted 4 billion ONE in two empty blocks, while a six-transaction, four-wallet reconstruction totals 3,010,000,100,000 ONE. Cross-shard receipt replay is the confirmed primary flaw; the empty-signature quorum issue remains a secondary attribution under review. No final freeze or net USD loss was public.
Cyvers disclosed an address-poisoning incident in which a victim copied an impersonating address from transaction history and mis-sent approximately 100,012.89 USDT. The attacker then swapped the USDT for about 52.8 ETH. The attacker, victim, and loss-transaction identifiers were truncated in the source image and are not guessed.
SlowMist Hacked Zone and Oraichain’s official notice describe an EVM cross-chain transfer flaw that enabled unauthorized ORAI minting. The network was paused for remediation, burning, and reconciliation; no verifiable loss amount was disclosed.
Bifrost confirmed exploitation of a shared Guardian Vault across three farming pools involving 881,150 DOT, publicly valued at about $720,000. The underlying vDOT reserve remained 1:1 backed, and complete attack identifiers were not disclosed.
USM / FUM on Ethereum was exploited through flash loans and about 64 split defund calls, with an estimate of 70.83 ETH and a disclosed USD value of about $136,000.
Coinsbuy-linked hot wallets suffered concentrated outflows on Ethereum and TRON with a public estimate of about $7.9 million. Some funds moved through ChangeNOW, FixedFloat, and BingX; the root cause and final aggregation route remain incomplete.
The same phishing activity placed sponsored ads in Trezor and Ledger searches and directed users to imitation pages for high-risk wallet actions. Cross-window losses were estimated above $3 million, while the strict-window increment cannot be isolated.
BTCPay Server / LND nodes were affected by a server flaw or credential exposure, and operators including Foundation and Citadel21 reported Lightning funds being drained. Public reporting has not established a unified victim set or total loss.
A personal wallet on Base lost approximately 500,000 USDC after phishing or malicious authorization. The attacker then swapped through a low-liquidity Uniswap V4 pool and ended with about 67 WETH; most value was captured by MEV and was not returned to the victim.
SlowMist recorded a compromise of ZEUS Bitcoin Lightning wallet and LSP infrastructure. The incident was mitigated, customer funds were not lost or at risk, and services were temporarily offline.
The Keyv / Cacheable npm release chain was hijacked, allowing malicious versions to target CI/CD and developer credentials. Multiple security teams corroborated the compromise, but no unified direct on-chain loss amount was confirmed by the report cutoff.
An RISEx-linked RWA strategy suffered an unauthorized withdrawal of 673,011.56 USDC. SlowMist records the incident date as August 3; the project said it patched the issue and fully compensated XLP depositors, which is not the same as recovering attacker funds.
KRON said that re-importing an internal token caused an indexing and accounting mismatch around the PEPE pool. Trading was unavailable for about two hours and LP access was paused longer; the team restored from backup, blocked the path, and said no funds were stolen, drained, or moved.
TenArmor flagged a successful transaction with multiple assets and protocol calls and estimated approximately $907,700 at risk. The transaction and tokens are verifiable on BNB Smart Chain, but the root cause, affected-contract boundary, and final net loss require independent analysis.
ExVul, Backward Labs, and on-chain researchers documented a LpdFi oracle-manipulation attack on BNB Chain. The attacker used flash-loan and spot-price manipulation to remove LP assets; public estimates put the loss at approximately $696,952.81.
A user reported that assets from 22 OKX Web3 extension wallets were moved after downloading several untrusted VPN tools, with about 1,000 USDT reported lost and about 300 USDT moved to safety. Public evidence supports a personal-wallet compromise lead, but no malware sample, complete transaction path, or independent forensic conclusion was available.
The attacker used a compromised off-chain signer key to set the discount parameter to 1, bought roughly 687,000 STY for about 19,700 USDT, and sold the tokens for approximately 625,000 USDT in net proceeds. Defimon reported that repeated ecrecover calls resolved to the same hardcoded signer, supporting a key-compromise finding.
An attacker used an unrestricted low-level CALL in an unverified Base contract to abuse an existing WETH approval and transfer 16.623029776956898128 WETH from a victim. The exploit occurred on July 30 and was disclosed by SlowMist on August 1, making it a prior-case technical disclosure during the window.
An attacker used a malicious SetToken, pre-issue hook, and fake valuer to inflate component units by approximately 93.66 times after quotation, causing ExchangeIssuance to transfer excess real assets. SlowMist estimated the loss at about $9,600.
Coinkite confirmed a weak-entropy flaw in seed generation on older COLDCARD firmware. The first three waves confirmed approximately 1,367.05 BTC; on August 12, 2026, SlowMist disclosed a cross-wave cumulative total of at least 1,719 BTC, about $111M, across more than 5,200 addresses. The initial 388.92748828 BTC fourth-wave figure from August 3 remains under review and is not added again.
SlowMist MistEye disclosed a recruitment-scam campaign targeting Web3 professionals. Attackers impersonated recruiters and induced targets to install malware disguised as the Relay AI meeting tool on macOS or Windows in order to steal endpoint credentials.
The privileged recycle() function in the LULA Rental contract could move LULA directly from a PancakeSwap V2 pool and call sync(). The attacker combined flash liquidity, reward claims, and reserve updates to obtain 578,295.907588061 USDT.
TheIndexFi’s X account published abnormal wallet-connection content. The project said this was not an external takeover: a former member still retained delegated access. The team removed the content and revoked access. No victim transaction or loss has been confirmed.
In CryptoDAO Global’s previous PRO implementation, exec() lacked a caller check. The attacker repeatedly invoked the function through an attack contract and distorted the PRO/USDT price, earning approximately $52,000. The proxy was later upgraded to an implementation with caller validation.
SlowMist recorded approximately $650,000 drained from ChainConnect bridge contracts across Ethereum, BNB Chain, Avalanche, and Polygon in 23 transactions. Venom Foundation later confirmed a bridge security incident and the suspension of all bridge operations.
After the victim signed a transaction presented as multicall, an inner call granted an attacker unlimited approval. About 36 seconds later, the attacker used transferFrom to remove 332,787 alphaUSDCDeltaV2, valued at approximately $340,463.
An independent Garden Finance solver’s off-chain database was compromised and populated with fraudulent records, causing HTLC flows on Ethereum, Base, Arbitrum, and BNB Chain to release approximately 450,000 USDT improperly. The project said its core protocol and smart contracts were not compromised and took the application offline.
WEMIX confirmed that ownership of a WEMIX$-related contract was compromised. The attacker minted approximately 5.2255 million WEMIX$ without authorization and swapped it into 30,736 WEMIX and 724,198.27 USDC.e. Reported loss uses an approximately $730,000 realized-value basis and does not add nominal minted value.
Projekt’s GREEN/GOLD reward vault used permissionless trackPurchase() to allocate rewards from token-balance changes without verifying real ETH expenditure. The attacker used flash liquidity and skim() to create fake purchase records, then withdrew approximately 301.7 ETH, valued near $560,000, through massWithdraw().
Bankrbot’s X account was taken over despite an on-device passkey and used to publish fake airdrop links. In the same incident window, a project wallet without multifactor authentication was drained of approximately 1.5 billion BNKR. SlowMist Hacked Zone records a loss of about $479,885.
Triple-A confirmed unauthorized access to company hot wallets across multiple chains and a final loss of approximately $11.8 million. Client and merchant funds were unaffected. Assets were swapped, bridged, and consolidated on Ethereum, and services resumed after security checks.
After the SOLID collateral feed failed, Solido Cash incorrectly fell back to a CASH price near $1 and severely overvalued low-priced SOLID. The attacker minted 809,051.55 CASH and obtained approximately 293,705,544.97 SUPRA.
Lien Finance’s exchangeEquivalentBonds compared only aggregate anomaly counts and did not verify each bondID multiplicity. The attacker duplicated a bondID in the output, minted undercollateralized BondToken, and redeemed 542,144.63 USDC through preapproved endpoints.
Evan Jawad said an unknown file led to compromise of his PC, multiple accounts, and X account, followed by the transfer of more than $600 in wallet assets and NFTs, for a total loss exceeding $1,000. This is a first-party report without public addresses, transaction IDs, sample, or independent forensics.
Robinhood confirmed that Vlad Tenev’s X account was compromised and used to promote a fake VLAD token before access was restored. GoPlus associated address 0xd70627fd9ee5b70906620a6f2001ba74457b438d with the token deployment and an estimated $1.2 million to $1.3 million in attacker profit; that profit is not confirmed victim net loss.
The attacker exploited different handling of duplicate proofRoots on Verus and Ethereum, allowing a malicious state root to overwrite the genuine root. A fabricated import proof based on a 0.01 VRSC export then released approximately $7.44 million from bridge reserves.
B² Network confirmed unauthorized access to its staking-contract upgrade authority. Approximately 8.591 million B2 was withdrawn; nominal value was about $3.86 million and realized proceeds were about 5,409 BNB, or $3.01 million.
Approximately 24.15 million USDC left the AFX custodial bridge and was converted into about 12,467.44 ETH. On July 25, 2026, monitoring showed 655.4 ETH converted through THORChain into 18.86 BTC, while about 11,812 ETH remained at related addresses; no freeze, return, or recovery was confirmed.
FlashTrade confirmed an unauthorized $98,000 withdrawal from an ephemeral instance. Newly deployed withdrawal batching and monitoring detected and contained the event quickly. The team said it would cover the amount in full and that user funds were unaffected.
Across confirmed that a Solana off-chain event-reading defect caused a Risk Labs relayer to advance real assets against forged deposits, with reported loss of approximately $3.6 million. On July 28, 2026, a labeled attacker address returned 331.8 ETH to the Across Hub Pool Owner Multisig, valued at about $623,900 when disclosed.
Public sources identify Unnamed Base ERC-4626 vault exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.
Public sources identify AIDC — on-chain smart-contract exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.
Mini Shai-Hulud, Miasma, and Hades malware expanded into Go modules in a documented supply-chain campaign; no verified aggregate loss amount was published.
Public sources identify Ocean Protocol BPool/SideStaking — on-chain smart-contract exploit as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.
A deterministic nonce-derivation flaw in the SecondFi web-wallet software signer made some Cardano private keys derivable from public signatures. Public reporting confirms about 16 million ADA, worth roughly $2.4 million, was stolen.
Public sources identify ATM liquidity-pool transfer front-run by a burn transaction as a on-chain smart-contract exploit incident. No single verifiable USD loss amount was published.
Humanity Protocol’s investigation says phishing and remote-access malware enabled the theft of project keys used for unauthorized transfers, minting, and sales of $H on Ethereum and BNB Chain; the aggregate uses the later loss estimate of approximately $36 million.
Public sources identify Gnosis Pay — Zodiac Delay Module Exploit as a Zodiac Delay Module Exploit incident. No single verifiable USD loss amount was published.
Fluid Lending reward-list operational-key compromise was reported on 2026-05-31. Evidence indicates that an operational key controlling the reward list was compromised. Reported loss is approximately $215,000.
AFI Protocol afiUSD Vault theft was reported on 2026-05-31. Evidence indicates that afiUSD Vault authority was used to transfer assets without authorization. Reported loss is approximately $480,000.
AROS price-manipulation incident was reported on 2026-05-31. Evidence indicates that the AROS market was manipulated through a pricing or liquidity path. Reported loss is approximately $295,000.
Gravity Bridge compromise was reported on 2026-05-30. Evidence indicates that the bridge validator or signing path was compromised. Reported loss is approximately $5,400,000.
YSDAO reserve manipulation was reported on 2026-05-29. Evidence indicates that reserve accounting was manipulated to extract value. Reported loss is approximately $19,500.00.
MoneyMon signature-validation bypass was reported on 2026-05-29. Evidence indicates that a signature-validation bypass allowed unauthorized execution. Reported loss is approximately $85,519.47.
Alephium TokenBridge off-chain guardian exploit was reported on 2026-05-29. Evidence indicates that false off-chain bridge messages bypassed guardian validation. Reported loss is approximately $815,000.
ONTR zero-address ownership and hidden-balance exploit was reported on 2026-05-28. Evidence indicates that zero-address ownership and hidden-balance logic enabled unauthorized control. Reported loss is approximately $98,200.00.
Joe Agent reentrancy exploit was reported on 2026-05-28. Evidence indicates that a reentrancy weakness allowed repeated execution. Reported loss is approximately $45,000.00.
JINX-0164 macOS malware campaign was reported on 2026-05-28. Evidence indicates that a macOS information-stealing malware family targeted credentials and wallet material. No stable verified USD loss amount was published.
DxSale legacy LP-locker compromise was reported on 2026-05-28. Evidence indicates that legacy administrative authority over the LP-locker path was compromised. Reported loss is approximately $7,300,000.
AI and search-poisoning mining-malware campaign was reported on 2026-05-27. Evidence indicates that search and AI-answer poisoning redirected users to mining malware. No stable verified USD loss amount was published.
StakeDAO vsdCRV unauthorized mint was reported on 2026-05-27. Evidence indicates that unauthorized authority was used to mint vsdCRV. Reported loss is approximately $91,170.00.
SKP Token liquidity-pool exploit was reported on 2026-05-27. Evidence indicates that an abnormal liquidity-pool operation affected SKP Token. Reported loss is approximately $213,000.
SUPERFORTUNE AI multisig transaction-target substitution was reported on 2026-05-27. Evidence indicates that a multisig transaction target was replaced with a lookalike recipient during transaction construction. Reported loss is approximately $15,180,000.
Bitmor DCA approval theft was reported on 2026-05-25. Evidence indicates that a malicious approval was used to steal assets from a Bitmor DCA user. Reported loss is approximately $10,000.00.
Lazarus RemotePE in-memory RAT campaign was reported on 2026-05-25. Evidence indicates that Lazarus-linked RemotePE malware executed an in-memory remote-access payload. No stable verified USD loss amount was published.
New Market Trading security incident was reported on 2026-05-25. Evidence indicates that an executed trading-platform incident moved assets without authorization. Reported loss is approximately $3,980,000.
WUSD / GLOVE exploit was reported on 2026-05-25. Evidence indicates that a smart-contract weakness affected WUSD / GLOVE liquidity. Reported loss is approximately $207,000.
Fake Uniswap Google Ads phishing campaign was reported on 2026-05-25. Evidence indicates that a paid-search advertisement led users to a fake Uniswap phishing page. Reported loss is approximately $400,000.
SquidRouterModule third-party module compromise was reported on 2026-05-25. Evidence indicates that a third-party router module was compromised and used against connected liquidity. Reported loss is approximately $3,100,000.
TrapDoor supply-chain campaign was reported on 2026-05-24. Evidence indicates that malicious code was distributed through a software supply-chain campaign. No stable verified USD loss amount was published.
Fractal Protocol security incident was reported on 2026-05-24. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $13,700.00.
Mure security incident was reported on 2026-05-23. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $11,700.00.
StablR stablecoin mint-authority compromise was reported on 2026-05-23. Evidence indicates that stablecoin mint authority was used without authorization. Reported loss is approximately $2,800,000.
Based Apparel website wallet-drainer injection was reported on 2026-05-22. Evidence indicates that wallet-draining code was injected into the Based Apparel website. No stable verified USD loss amount was published.
Polymarket UMA CTF Adapter operational-key compromise was reported on 2026-05-22. Evidence indicates that an operational key used by the UMA CTF Adapter was compromised. Reported loss is approximately $520,000.
MAP / Butter Bridge exploit was reported on 2026-05-20. Evidence indicates that a bridge contract or message-validation path was exploited. Reported loss is approximately $110,000.
RetoSwap / Haveno multisig-path exploit was reported on 2026-05-20. Evidence indicates that the RetoSwap / Haveno multisig path was exploited. Reported loss is approximately $2,700,000.
HermesVault security incident was reported on 2026-05-19. Evidence indicates that a vault weakness was exploited before most assets were returned. Reported loss is approximately $4,000.00.
Echo Protocol / eBTC admin-key compromise was reported on 2026-05-19. Evidence indicates that administrative signing authority was compromised. Reported loss is approximately $5,130,000.
On May 18, 2026, Verus–Ethereum Bridge validation failed to enforce value equality between source-side input and destination-side output, allowing low-value input to release high-value reserves. Initial exposure was approximately $11.58 million, and about 4,052.4 ETH, publicly valued near $8.5 million, was later returned.
Ledger physical-letter seed phishing campaign was reported on 2026-05-17. Evidence indicates that physical letters impersonating Ledger attempted to steal wallet seed phrases. No stable verified USD loss amount was published.
SEA Token security incident was reported on 2026-05-17. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $153,000.
Adshares Bridge exploit was reported on 2026-05-17. Evidence indicates that the Adshares bridge validation path was exploited. Reported loss is approximately $88,000.00.
THORChain multichain vault theft was reported on 2026-05-15. Evidence indicates that a malicious validator used threshold-signing interactions to recover vault signing material. Reported loss is approximately $10,350,000.
Fake job-interview JobStealer campaign was reported on 2026-05-14. Evidence indicates that fake job interviews delivered credential and wallet-stealing malware. No stable verified USD loss amount was published.
ShapeShift Colony meta-transaction exploit was reported on 2026-05-13. Evidence indicates that a meta-transaction validation weakness allowed unauthorized execution. Reported loss is approximately $132,000.
Transit Finance legacy-contract exploit was reported on 2026-05-13. Evidence indicates that a legacy Transit Finance contract path remained exploitable. Reported loss is approximately $1,880,000.
SQ Protocol ownership compromise was reported on 2026-05-12. Evidence indicates that contract ownership was taken over and used against the staking contract. Reported loss is approximately $346,100.
Aurellion Labs Diamond-proxy malicious-facet exploit was reported on 2026-05-12. Evidence indicates that a malicious Diamond proxy facet was installed through administrative authority. Reported loss is approximately $456,000.
TAC Protocol TON–EVM bridge incident was reported on 2026-05-12. Evidence indicates that a TON–EVM bridge path was exploited and later handled through a negotiated return. Reported loss is approximately $280,000.
Huma Finance V1 BaseCreditPool legacy-contract exploit was reported on 2026-05-11. Evidence indicates that a legacy BaseCreditPool contract path remained exploitable. Reported loss is approximately $101,400.
TrickMo Android malware variant was reported on 2026-05-11. Evidence indicates that a TrickMo Android malware variant targeted financial and authentication data. No stable verified USD loss amount was published.
INK Finance treasury privilege compromise was reported on 2026-05-11. Evidence indicates that treasury privileges were used without authorization. Reported loss is approximately $140,000.
Renegade security incident was reported on 2026-05-10. Evidence indicates that public monitoring confirmed an executed protocol exploit and later reported returned funds. Reported loss is approximately $209,000.
TrustedVolumes RFQ proxy exploit was reported on 2026-05-07. Evidence indicates that an RFQ proxy authorization path allowed unauthorized asset movement. Reported loss is approximately $6,300,000.
ClickFix fake macOS tool campaign was reported on 2026-05-06. Evidence indicates that a ClickFix social-engineering flow delivered a fake macOS tool. No stable verified USD loss amount was published.
Ekubo Protocol extension callback exploit was reported on 2026-05-05. Evidence indicates that an extension callback path allowed reentrant or unauthorized execution. Reported loss is approximately $1,400,000.
SmartCredit security incident was reported on 2026-05-04. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $72,000.00.
Bankr / Grok wallet AI-agent attack was reported on 2026-05-04. Evidence indicates that an AI-agent wallet workflow was manipulated to authorize asset movement. Reported loss is approximately $175,000.
FEMITBOT Telegram Mini Apps malware campaign was reported on 2026-05-03. Evidence indicates that malicious Telegram Mini Apps distributed the FEMITBOT payload. No stable verified USD loss amount was published.
Sharwa Finance security incident was reported on 2026-05-01. Evidence indicates that public monitoring confirmed an executed protocol exploit but did not establish a complete root cause. Reported loss is approximately $32,850.00.
Bisq v1 client attack was reported on 2026-05-01. Evidence indicates that a weakness in the Bisq v1 client or trade workflow enabled theft. Reported loss is approximately $858,000.
LayerZero’s final report says compromised RPC infrastructure enabled a forged cross-chain message, resulting in the loss of 116,500 rsETH, approximately $292 million; KelpDAO’s single-DVN configuration allowed the destination contract to accept the attestation. May litigation and asset-restriction developments are attached to the same incident.