Incidents
707 worked examples, each mapped to the OAK Techniques it demonstrates.
2026 (122)
- Solana PermanentDelegate burn-on-buy, 2026 continuation — the operators started revoking every authority the checkers look at and keeping the one they don't — Solana / Token-2022 — 2026 Q1
- Q1–Q2 2026 Sub-Million Exploit Cohort — 36 Incidents Across 13 Chains — Aggregate ~$10.1M
- Q1–Q2 2026 Oracle and Price-Manipulation Cohort — Blend Pools V2, Makina, Moonwell, BSC TMM/USDT — Aggregate ~$18.6M
- Q1–Q2 2026 Mint and Tokenomics Exploit Cohort — Truebit, Saga, SolvBTC, FOOM Cash, TMX TRIBE — Aggregate ~$40.1M
- Q1–Q2 2026 Key Compromise Cohort — Step Finance, IoTeX, Grinex, Gravity Bridge, Polymarket UMA — Aggregate ~$68.7M
- Q1–Q2 2026 Flash-Loan, Approval and Slippage Exploit Cohort — Matcha, Cyrus Finance, YO Protocol, Aperture LM — Aggregate ~$24.4M
- Q1–Q2 2026 Cross-Chain, Bridge and OTC Exploit Cohort — CrossCurve, Purrlend, Transit Finance, Meteora DAMM V2, TAC Protocol, Alephium — Aggregate ~$11.4M
- Q1–Q2 2026 Access-Control and Authorisation-Gap Cohort — Sweat Foundation, Ekubo, Giddy, Aftermath Perps — Aggregate ~$7.3M
- NFT marketplace wash-trade and fake-mint cohort — 2026 Q1
- EIP-7702 Delegation Phishing — Continued 2026 CrimeEnjoyor Cluster Operations — 2026 — ~$3M+
- CoWSwap $50M Institutional Trade MEV Routing / Liquidity Fragmentation Event — 2026 — ~$50M price impact
- Bybit $1.5B Hack Laundering Continuation into 2026 — DPRK / Lazarus — 2026
- XRPH Wallet — a self-custody wallet sent the user's seed phrase to the vendor's own server every time someone staked, and 4,011 accounts were emptied — XRP Healthcare (XRPH Wallet) / XRP Ledger — 2026-09-03
- Symbiosis — a bridge accepted a message it should have rejected and minted 2^62 raw units of synthetic Bitcoin, of which the market let the attacker keep a third of a million — Symbiosis / BNB Chain + Ethereum — 2026-09-11
- RedSonic Vault — anyone could register the same collateral a second time, so one pool of stETH backed two share classes and both of them were redeemed — RedSonic / Ethereum — 2026-09-05
- Notional Finance — a deprecated V1 escrow nobody had swept was drained through a debt of −2^128 that an unsafe cast rounded to zero — Notional Finance / Ethereum — 2026-09-04
- Liquid Network — unbacked L-BTC passed consensus, so the federation's 11-of-15 signers approved a peg-out that was valid in every way they were built to check — Liquid Network (Blockstream) / Bitcoin sidechain — 2026-09-06
- Hemi Network — an airdrop contract created the lock before it updated the ledger, so 63 recursive claims emptied every allocation nobody had collected yet — Hemi Network — 2026-09-07
- ether.fi — a deprecated withdrawal queue let anyone name someone else as the solver, and eleven wallets' un-revoked approvals paid the bill — ether.fi / Veda AtomicQueue / Ethereum — 2026-09-11
- Dream Health Chain — awards were recorded without locking the funds to pay them, and a claimed award could be reset and claimed again — Dream Health Chain / BNB Chain — 2026-09-05
- USM — redeeming the same position in 64 slices paid more than redeeming it once, because the redemption price was an arithmetic mean over the path rather than a function of the position — USM Protocol (Ethereum) — 2026-08-10
- Term Finance — $951 bought 90.66% of a vault's voting power, because voting required opt-in staking and almost nobody had opted in — Term Labs / Ethereum — 2026-08-23
- Tectonic — a lending market accepted its own thinly-traded token as collateral, and when the price was pumped the chain itself had to be rewound to contain the loss — Tectonic / Cronos — 2026-08-30
- TAC — the upstream fix was three days old and the attack method had been published two days earlier, so the chain was drained through a bug it could have patched and then froze for ten days — TAC (Cosmos EVM / TON-connected L1) — 2026-08-22
- The Sandbox — hijacked LayerZero OFT delegate permissions minted $49B of face-value SAND across 400+ transactions, and the pools could only pay out $675K of it — The Sandbox / Base + BNB Smart Chain — 2026-08-22
- Repeat-victim whale — the same address that lost $24.2M to approval phishing in 2023 was drained again for $25.6M three years later, and this time nothing came back — unidentified individual (Ethereum) — 2026-08-12 (first drain 2023-09)
- Oraichain — an EVM cross-chain transfer path allowed ORAI to be minted without a backing deposit, and the team stopped the entire chain four hours in rather than let the supply keep moving — Oraichain (Cosmos SDK / OraichainEVM) — 2026-08-09
- OAK field-collects a live fake-recruiter lure to check its own T15.001 page against a real specimen — and finds the page wrong on two points: the trigger is npm prepare, and the repository carries no payload at all — OnChainAttack, first-party collection — 2026-08-27
- Moonwell — the same protocol lost money to its price feed for the second time in six months, this time by listing a token thin enough to move by hand — Moonwell / Base — 2026-08-27
- Maya Protocol — one deposit carrying 23 messages overwrote the chain's own observed-transaction voter, so a safety mechanism paid a 49.45M CACAO "compensation" into a pool holding 0.11 LINK — MAYAChain — 2026-08-18
- Harmony — a committee verifier that counted the roster instead of the signers accepted an all-zero signature mask, and unauthenticated receipt-proof fields let spent cross-shard receipts be credited again — Harmony Mainnet (ONE) — 2026-08-12
- Coreum–XRPL bridge — relayers verified that a deposit message was well-formed and never that the XRP had arrived, so self-transfers carrying a forged memo released 199,916 real XRP — Coreum / XRP Ledger — 2026-08-09
- Coinsbuy — a B2B payment processor's Ethereum and TRON wallets emptied in the same hour, the signature of one signing infrastructure rather than two compromises — Coinsbuy (Ethereum, TRON) — 2026-08-09
- BounceBit — an inherited Evmos authorisation flaw let a caller name any account as the source of funds, and the chain was retired rather than patched — BounceBit Chain — 2026-08-19
- Allbridge — a forged CCTP attestation was minted on 26 July, left to sit for 24 days, and redeemed on 19 August the moment the target router had a balance worth taking — Allbridge / Polygon → Base — 2026-08-19
- WEMIX — an attacker takes administrator privileges over the WEMIX$ stablecoin contract and mints 5.2M units out of nothing, forcing the network to shut its own bridges, DEX, and marketplace — WEMIX (Wemix3.0) — 2026-07-26
- Wanchain Cardano bridge — 14 variable-length fields concatenated without separators make the signed message non-injective, so a signature for 3,110 NIGHT authorises 203,001,692 — Wanchain / Midnight NIGHT (Cardano ⇄ BNB Chain) — 2026-07-20/21
- Verus ⇄ Ethereum Bridge, second time — the May attacker returns the funds, the team redeposits them into the unfixed contract, and a different attacker takes them out through the same import path — Verus / Ethereum — 2026-07-23
- Triple-A — a licensed payment processor's hot wallets are swept for 31 hours because pausing the service never disabled the on-chain deposit addresses still receiving merchant settlements — Triple-A (Singapore) — 2026-07-24/25
- Summer.fi (Lazy Summer Protocol) — a market capped for offboarding stays priced into vault NAV, so a donation of stale Stream-Finance-era tokens inflates the share price for an atomic redemption — Summer.fi / Lazy Summer (Ethereum) — 2026-07-06
- Solido Cash — a stale price feed on the backstop collateral token trips fallback logic that values it far above market, and 809,052 CASH are minted against it — Solido Money (SUPRA) — 2026-07-23
- Ostium — an authorised price-report path settles a BTC long opened at $5,000 and closed at ~$60,000 in one transaction, draining the OLP vault — Ostium (Arbitrum) — 2026-07-15
- Lien Finance — an internal rate function prices attacker-crafted bonds far above the collateral actually backing them — Lien Finance (Ethereum) — 2026-07-24
- LayerZero Executor — hot wallets for the message-execution role drain simultaneously across eight chains, the signature of co-located key material — LayerZero (cross-chain) — 2026-07-15
- Injective Labs SDK — a commit from a trusted maintainer account rides the OIDC auto-publish pipeline into 18 npm packages that exfiltrate seed phrases at key-derivation time — Injective Labs / npm (chain-agnostic) — 2026-07-08
- DPRK state banks breached from the inside — former military operators are reported arrested for diverting state funds into overseas crypto wallets and structuring them out through Chinese border brokers — Central Bank of the DPRK / Foreign Trade Bank — 2026-07-12 (reported 2026-07-25)
- DeFiTuna — concentrated liquidity, lending, and 5x leverage in one protocol, and the attack landed on the seams between them rather than inside any of them — DeFiTuna (Solana) — 2026-07-16
- Coldcard — a 2021 library migration left an RNG config check that tested whether a setting existed but not whether it was on, silently dropping seed entropy from 128 bits to 40, and five years of seeds were swept — Coldcard / Coinkite (Bitcoin) — 2026-07-30/31 onward, ongoing
- Cascade — pre-launch depositors farming reward points had their USDC locked until mainnet, so when the CLS vault was drained none of them could have withdrawn first — Cascade (Arbitrum) — 2026-07-16
- Bonzo Lend — an all-zero signature satisfies Supra's oracle verifier trivially, inflating SAUCE by ~12 orders of magnitude to borrow $9.05M against 250 tokens — Bonzo Lend / Supra (Hedera) — 2026-07-12
- BonkDAO — an attacker buys just over 1% of supply on KYC exchanges, meets a low quorum in a 2.9%-turnout ballot, and votes the treasury to itself — BonkDAO / Realms (Solana) — 2026-07-06
- B² Network — an attacker takes the staking contract's upgrade authority, rewrites what the contract does, and sells 8.59M B2 into the market — B² Network (Bitcoin Layer 2) — 2026-07-23
- Allbridge Core — a $1.12M Kamino flash loan skews the USDC/USDT pool ratio, liquidity is withdrawn at the distorted valuation, and the loan repays in the same transaction — Allbridge Core (Solana) — 2026-07-19
- AFX Trade — five compromised hot-validator keys meet the bridge's two-thirds quorum, and a 200-second dispute window passes with nobody watching it — AFX Trade (Arbitrum) — 2026-07-22
- Across Protocol — a missing 8-byte Anchor discriminator check lets an attacker forge Solana deposit events that never moved funds, and the relayer fills 581 of them — Across / Risk Labs (Solana) — 2026-07-17
- 42DAO / Balance Protocol — the attacker pokes an abnormally low BTCB price into the vault-health contract, making solvent vaults look insolvent, and liquidates them — 42DAO / Balance Coin (BNB Chain) — 2026-07-22
- Zcash Orchard counterfeiting vulnerability — under-constrained halo2 scalar-mul gadget (AI-discovered responsible disclosure) — 2026-05-29 / 2026-06-02
- Token of Power ($TOP) — low-float governance takeover mints 10B TOP in one block — Ethereum — 2026-06-09
- TesseraDAO ($TSR) — admin-key compromise → unauthorised mint-and-dump — 2026-06-01
- Taiko bridge — a leaked SGX prover signing key forges L2-state proofs to drain the L1 bridge — Ethereum L1 ⇄ Taiko Alethia L2 — 2026-06-21
- Syscoin bridge — SPV-proof-parsing flaw mints ~5B SYS without a burn — Syscoin UTXO ⇄ NEVM — 2026-06-07
- Steam Workshop / Wallpaper Engine malicious wallpapers — Lumma + Vidar infostealers harvesting Steam sessions and crypto wallets — Windows / cross-chain — disclosed 2026-06-16
- Secret Network — a forked CW20-ICS20 bridge contract skips source-channel and escrow checks, minting unbacked tokens redeemed over the real Axelar route — Secret Network / Axelar (Cosmos IBC) — 2026-06-10
- SecondFi — predictable web-wallet key generation drains Cardano (ADA) wallets — Cardano — 2026-06-23
- Rust crypto-clipper — fake-reputation "Ghost Network" distribution of trojanised trading tools — Windows + macOS / cross-chain — disclosed 2026-06-17
- Polymarket — a compromised third-party frontend vendor injects wallet-draining JavaScript into the live site — Polygon / Ethereum — 2026-06-25
- OpenMonero — server misconfiguration exposes wallet-RPC, hot wallet drained — Monero — 2026-06-08
- Namada — an IBC transfer-logic flaw drains the Multi-Asset Shielded Pool while a stale indexer masks the loss — Namada (Cosmos / IBC) — 2026-06-19
- mySwap CL — a fake "EVIL" token abuses shared-vault concentrated-liquidity accounting to drain residual LP — Starknet — 2026-06-19
- Joe Agent ($JOE) — _removeLiquidityViaContract single-function reentrancy — 2026-06
- jaredfromsubway.eth — a counter-MEV honeypot lures the sandwich bot into leaving standing token allowances, then sweeps them — Ethereum — 2026-06-20
- Humanity Protocol ($H) — single developer-machine compromise defeats two multisig quorums across two chains — Ethereum + BNB Chain — 2026-06-08/09
- Gnosis Pay — Zodiac Delay/Roles modifier fallback-handler bypass — 2026-06-01
- Flooring Protocol — a crafted high-bit token-ID alias made an ownership check pass for a token the caller did not own, and the balance update behind it underflowed, turning a little WETH into effectively unlimited fpTokens — Flooring Protocol V2 / BitmapPunks (Ethereum) — 2026-06-08
- "Eleven drainer" injected into legitimate project subdomains — Gitcoin and Yield Yak — Ethereum / Avalanche — 2026-06 (June 21 and 24)
- CryptoBandits — USB-worm crypto-clipper with Tor C2 and clipboard secret-harvesting — Windows / cross-chain — disclosed 2026-06-17
- Aztec deprecated rollup infrastructure — forged rollup proofs drain two immutable, abandoned bridges within a week — Ethereum — 2026-06 (≈06-14 and ≈06-17) (cohort)
- Verus ⇄ Ethereum Bridge — missing source-amount validation (checkCCEValues) — 2026-05-18
- TrustedVolumes RFQ Authorization-Boundary Failure — Ethereum — 2026-05-07
- THORChain Router — Ethereum / BSC / Base / Bitcoin — 2026-05-15
- Superfortune ($GUA) — multisig airdrop-transfer destination tampering to a lookalike address — 2026-05-27
- Stake DAO — deployer-key compromise → LayerZero OFT peer redirect → 5.4T vsdCRV mint — 2026-05-27
- SquidRouterModule — counterfeit Safe module with public-constant-string "authorization" — 2026-05-25
- Roaring Kitty (@TheRoaringKitty) — verified X-account compromise → $RKC Pump.fun memecoin — 2026-05-11
- RetoSwap / Haveno — unauthenticated ACK → arbitrator impersonation → 2-of-3 multisig instantiation hijack — 2026-05-21
- Nx Console VS Code extension — trojanised release (nrwl.angular-console v18.95.0) credential stealer — 2026-05-18
- MAP Protocol — Butter Bridge abi.encodePacked hash-collision + retry-message replay — 2026-05-20
- LABtrade — Insider OTC/Vesting/Supply Manipulation — 2026-05-14
- LAB and the Bitget market-maker cohort — four launches where insiders held almost the whole supply and one venue sat in the middle of all of them — LAB / RAVE / RIVER / SIREN — 2026-03 → 2026-07
- Kraken / Coinbase users — coordinated physical-coercion + wallet-compromise theft — 2026-05
- Ill Bloom — recovery phrases from less-common mobile wallets were generated by an insecure PRNG, and 431 accounts across five chains were swept in one coordinated action — multi-wallet cohort (multi-chain) — first sweep 2026-05-27, disclosed July 2026, root cause named 2026-08-05 as CryptoJS.lib.WordArray.random() (CVE-2026-71851)
- EchoProtocol eBTC Bridge Signature-Verification Bypass and Unbounded Mint — Monad — 2026-05-19
- DxSale — legacy BNB-Chain liquidity-locker backdoor (setFee→1 wei + obscured ownership) — 2026-05-29
- DSJ Exchange (DSJEX) — Ponzi Collapse — 2026-04/05
- Dritan Kapllani Jr — Social Engineering Theft — 2024–2026
- Zondacrypto Exchange CEO-Transition Custody Failure and Alleged Russian Mafia Takeover — Apr 2026 — ~$96M
- Wasabi Protocol UUPS Proxy-Upgrade Admin-Key Exploit — Apr 2026 — $5.9M
- Volo Admin-Key Social-Engineering Compromise — Sui — 2026-04-21
- Rhea Finance Margin-Parser Exploit — Apr 2026 — $18.4M
- RaveDAO ($RAVE) insider OTC distribution and coordinated dump — Multi-CEX (Binance / Bitget / Gate) — 2026-04
- RAVE Token — -95% Market Manipulation / CEX Intervention — 2026-04
- Polymarket UMA vote capture — US-Iran ceasefire market — 2026-04
- KelpDao rsETH Bridge Hack via LayerZero Infrastructure Compromise — Apr 2026 — $290M
- Hyperbridge Merkle-proof forgery and counterfeit-DOT mint — Polkadot ⇄ Ethereum / Base / BNB / Arbitrum — 2026-04-13
- ERC-4337 paymaster mass-griefing campaign — EVM mainnets — 2026
- Drift Protocol durable-nonce admin-takeover and fictitious-collateral drain — Solana — 2026-04-01
- Venus Protocol Supply-Cap Donation-Attack Exploit — BNB Chain — 2026-03-15
- Solana permissioned tokens — since March 2026 a regulated fund and a honeypot have the same on-chain shape, and only the freeze authority's owner separates them — Token ACL (sRFC-37) / Solana — 2026-03-06 onward
- Resolv Labs Private-Key Compromise and Unlimited USR Mint — Mar 2026 — $25M
- Polymarket Iran-strike market — physical coercion of resolution source — 2026-03
- Panic-Account Farm — $0 Direct Loss / Scam Traffic Funnel via Doomposting — 2026-03
- Lido — six validators from a permissionless operator were slashed, and the loss stopped at that operator's bond instead of reaching stakers — Lido Community Staking Module / Ethereum — 2026-03-13
- Gondi — a bundler released three weeks earlier never checked who was calling it, and 78 NFTs left wallets whose loans had already closed — Gondi V3 / Ethereum — 2026-03-09
- Aave wstETH Oracle Misconfiguration Liquidation Cascade — Mar 2026 — $27.78M
- Veil Cash — the verifying key set delta equal to gamma, so the pairing equation accepted proofs nobody had to compute — Veil Cash / Base — 2026-02-20
- Polymarket Iran-strike timing market — operational-insider trading by IDF Air Force reservist — 2026-02
- "120 Hours" — the creator told a livestream audience he had five days to live, waited for the token to reach Raydium, and pulled the liquidity while still on camera — pump.fun / Solana — 2026-02-09
- Polymarket Venezuela / Maduro-capture market — operational-insider trading by US Special Forces NCO — 2026-01
- Polymarket trader-tooling supply-chain compromise — npm + GitHub — 2026-01
- Polycule trading bot — third-party brand-impersonation soft rug — 2026-01
- IPOR Fusion — the admin account had delegated itself to a contract that would call anything, and a legacy vault would run any module it was handed — IPOR Fusion PlasmaVault / Arbitrum — 2026-01-06
- Hardware Wallet Social Engineering — LTC/BTC — 2026-01-10
2025 (78)
- 2025 Rekt.Uncovered Incidents Cohort — 23 Incidents — Aggregate ~$14.2B (incl. Lubian $14.8B legacy) / ~$297M excl. Lubian
- Axiom Exchange — Employee Insider Trading via Internal Data Access — 2025
- Trezor-impersonating physical-mail seed-phrase phishing campaign — 2025–2026
- Tangem card physical-access disclosures (Ledger Donjon) — hardware — 2025-09 → 2026-07
- Prediction-Market Resolution-Source Harassment Cohort — 2025–2026
- Polymarket Subjective-Oracle Resolution Manipulation Cohort — 2025–2026
- USPD CPIMP "Clandestine Proxy In the Middle of Proxy" stablecoin exploit — Ethereum — admin-frontrun 2025-09-16; mint event 2025-12
- Unleash Protocol multisig governance hijack — Story Protocol — 2025-12-30
- Polymarket UFO Declassification UMA Vote-Capture Dispute — 2025-12
- HNUT (Holly The Squirrel) bundled-rug Pull — Solana / Pump.fun — 2025-12-30
- Polymarket comment-section phishing campaign — Polygon — 2025-11
- Hyperliquid POPCAT spoofed-buy-wall + cancel-flood manipulation — Hyperliquid (HyperEVM L1) — 2025-11-12 to 2025-11-13
- Balancer V2 ComposableStablePool rounding-error exploit — multi-chain — 2025-11-03
- Polymarket POLY pre-token brand-anticipation phishing — EVM — 2025-10 onward
- Huione Group / Prince Group Southeast Asia compound-operated investment-fraud cohort — multi-chain (BTC / ETH / USDT on Tron dominant) — 2020–2025
- Garden Finance solver-key compromise — multi-chain — 2025-10-30
- Polymarket filter-bypass manipulation — Polygon — 2025-10
- UXLINK multisig delegate-call hijack — Ethereum / Arbitrum — 2025-09-22
- SwissBorg SOL-Earn third-party-API supply-chain compromise — Solana — 2025-09-08
- SSV Network correlated mass-slashing event — Ethereum Beacon Chain — 2025-09-10
- Shibarium bridge validator-key + flash-loan-amplified PoS-bridge exploit — Ethereum ↔ Shibarium — 2025-09-12
- SBI Crypto mining-pool drain — Bitcoin / multi-chain — 2025-09-24
- ERC-4337 EntryPoint griefing-vector responsible disclosure (TrustSec / HackenProof / Ethereum Foundation) — coordinated disclosure 2025-09 → patched in v0.9 — 2025
- Hypervault Finance exit scam via fake-audit-claims — Hyperliquid / Ethereum — 2025-08
- ERC-4337 paymaster exploit cohort — EVM mainnets — 2025-08
- BtcTurk hot-wallet drain (recurrence) — multi-chain — 2025-08-14
- Polymarket Zelenskyy-suit market — UMA resolution-spec ambiguity — 2025-07
- Lido stETH / Aave validator-exit-queue and looped-leverage depeg cascade — Ethereum L1 — 2025-07
- GMX V1 GLP global-short-tracking exploit — Arbitrum — 2025-07-09
- ALT Token — Influencer Insider Dump — 2025-07-14
- CoinDCX operational-wallet drain — Solana — 2025-07-19
- Central Bank of Brazil — Service Provider Breach → Crypto Conversion — 2025-07
- Resupply Finance wstUSR empty-market donation exploit — Ethereum — 2025-06-26
- Pepe Creator (Matt Furie) NFT contract hijack via fake-IT-worker social engineering — Ethereum — 2025-06-18 to 2025-06-25
- Nobitex — multi-chain hot-wallet key compromise drains Iran's largest exchange — EVM chains + Tron — 2025-06-18
- Force Bridge admin-key drainage — Ethereum / BNB Chain — 2025-06-01
- Inferno Drainer "Reloaded" — encrypted on-chain config + single-use smart contracts + fake CollabLand Discord phishing — multi-chain — September 2024 to March 2025 (Check Point disclosure 2025-05)
- EIP-7702 CrimeEnjoyor delegation-phishing cohort — Ethereum mainnet — 2025-05 onward
- Cetus Protocol concentrated-liquidity overflow exploit — Sui — 2025-05-22
- ZKsync unclaimed-airdrop pool drain — Ethereum / ZKsync Era — 2025-04-15
- Meteora M3M3 launch class-action and MET airdrop controversy — Solana — 2024-12 to 2025-10
- Mango Markets MNGO governance-token expiry and protocol wind-down — Solana — 2025-01 to 2025-04
- Loopscale RateX-token-pricing exploit — Solana — 2025-04-26
- KiloEx oracle-feed manipulation — multi-chain (BNB Chain, Base, Manta, Taiko) — 2025-04-14
- eXch instant-exchange shutdown — Bybit-laundering substrate sanctions response — 2025-04 to 2025-05
- ERC-4337 paymaster compromise cohort — EVM mainnets — 2024–2025 (April 2025 anchor)
- EigenLayer Mainnet Slashing Launch and AVS Slashing-Condition Activation — Ethereum L1 — 2025-04-17
- 3520 BTC — Instant Exchange → Monero Laundering — 2025-04
- zkLend precision-loss collateral-accounting exploit — Starknet — 2025-02-12
- Uniswap routing-manipulation frontend phishing cohort — EVM — 2025
- SushiSwap delegation-cluster governance takeover — Ethereum — 2025-03 to 2025-04
- Solflare base-x library homograph-attack vulnerability (CVE-2025-27611) — Solana — 2025-03
- Polymarket UMA governance attack — Ukraine mineral deal market — 2025-03
- Hyperliquid Whale — Illicit Trading via Highly Leveraged Positions — 2025-03
- Hyperliquid JELLY self-liquidation + cross-venue spot-pump cascade — Hyperliquid (HyperEVM L1) + Solana spot — 2025-03-26
- 1inch resolver-contract patch-not-propagated exploit — Ethereum + BNB Chain — 2025-03-05
- zkLend empty-market rounding-error exploit — Starknet — 2025-02-12
- WEMIX — a developer uploads NFT-platform monitoring keys to a shared repository for convenience, and two months later 13 of 15 withdrawals empty the Play Bridge Vault — WEMIX / Wemade (Play Bridge Vault) — 2025-02-28
- Solana brand-X-account compromise cohort (Jupiter / Pump.fun / DogWifCoin) — Solana — 2024-11 to 2025-02
- $LIBRA / Milei presidential-endorsement pump-and-dump — Solana — 2025-02
- Infini neobank treasury drain — Ethereum / multi-chain — 2025-02-24
- Cardex session-signer-key frontend leak — Abstract Chain — 2025-02-18
- Bybit cold-wallet theft — Ethereum — 2025-02-21
- Bybit aftermath — $1.4B THORChain laundering — Ethereum → BTC / DAI — 2025-02 to 2025-03
- $TRUMP and $MELANIA presidential / first-spouse memecoin launches — Solana — 2025-01
- Solana NFT X-account-compromise fake-mint drainer cohort — Solana — 2025-Q1
- Prediction-market journalist safety / resolution-source intimidation cohort — global — 2025–2026
- Polymarket US election operational-insider trading cohort — multi-chain — 2025
- Phemex hot-wallet theft — multi-chain — 2025-01-23
- MEV-Boost relay censorship and OFAC-compliance validator concentration — Ethereum — 2025
- Mango Markets SEC settlement and protocol shutdown — Solana — 2024-09 to 2025-01
- David Balland (Ledger co-founder) kidnapping — crypto ransom, France — 2025-01
- Hyperliquid trading-bot malware campaign — Arbitrum / Hyperliquid — 2025
- Hyperliquid / DEX brand-impersonation custodial soft-rug cohort — multi-chain (Arbitrum, EVM) — 2025
- Huione Guarantee fake-CEX / pig-butchering platform — Southeast Asia / multi-chain — 2025
- Hayden Davis / Kelsier Ventures memecoin operator-cluster cohort — Solana — 2025-Q1
- Counterfeit Ledger Nano S Plus hardware-wallet supply-chain compromise cohort — multi-chain — 2025 (cohort surfacing)
- BullX / Solana token-launch MEV sandwich cohort — Solana — 2025
2024 (152)
- Sonne Finance 14-month fork-vulnerability exposure — Optimism — 2024-05-14
- Honeypot token cohort — cross-chain — 2024 Q4
- Post-Tornado-Cash DeFi yield-protocol laundering shift — cross-chain — 2024
- Onyx Protocol year-plus fork-vulnerability exposure — Ethereum — 2024
- Murad — $24M Meme Coin Insider Wallet Cluster — 2024
- Fake Ledger Live — Microsoft App Store — 2023-11
- EigenLayer token-anticipation phishing campaign — 2024
- EigenLayer restaking airdrop — AVS slashing and cascading-risk context — 2024
- Curio DAO MakerDAO fork-chain governance exploit — Ethereum — 2024-03
- Chainalysis laundering report — stablecoin issuer-selection laundering — 2024
- Chainalysis laundering report — DEX aggregator routing cohort — 2024
- Bittensor — Insider-Linked Exploit / Whitehat Recovery — 2024 / 2025-10
- Solana / multi-chain npm trader-tooling supply-chain key exfiltration cohort — Solana / EVM — 2024–2026
- NFT Marketplace Insider Trading and Wash-Trading Infrastructure — 2024–2026 — structural
- Embedded-Wallet and Trader-Tooling Supply-Chain Compromise Cohort — 2024–2026
- Cross-Chain Bridge Observer Signature Scope Audit — 2024–2026
- US Treasury OFAC/IRS-CI blockchain analytics deployment — chain-agnostic — 2024–2025
- Uniswap Permit2 Phishing Cohort — Ethereum / multi-chain EVM — 2024–2025
- Solana Token-2022 transfer-hook class vulnerability and ZK-ElGamal proof zero-day — Solana — 2024-2025
- SwapKit router impersonator phishing cohort — EVM — 2024–2025
- Solana Token-2022 Multi-Extension Scam Token Cohort — 2024–2025 — Aggregate $150M+
- Safe {Wallet} ERC-4337 Module Integration Security Issues — 2024–2025 — $0 (audit disclosures)
- Rocket Pool fake-staking-frontend phishing campaigns — Ethereum — 2024–2025
- Pump.fun / Solana token-launch MEV sniping cohort — Solana — 2024–2025
- Pump.fun bonding-curve memecoin rug-pull cohort — Solana — 2024-2025
- Polymarket Spec-Ambiguity Resolution Dispute Cohort — 2024–2025
- Jupiter DCA TWAP oracle manipulation on Solana — Solana — 2024–2025
- John Daghita ("Lick") — US Government Seizure Address Theft — 2024–2025
- EIP-7702 delegation abuse research and advisory cohort — Ethereum / multi-chain — 2024–2025 (pre-deployment and post-deployment advisory class)
- EigenLayer Restaking Deposit Caps and LRT NAV Dilution — Ethereum L1 — 2024–2025
- EigenLayer restaking-frontend phishing cohort — Ethereum — 2024–2025
- DOJ/SEC Pig-Butchering Platform Enforcement Cohort — 2024–2025
- Organization-Targeted Phishing — 15+ X Accounts Compromised via Email Phishing — 2024-12
- @solana/web3.js npm supply-chain compromise — Solana — 2024-12-03
- Pudgy Penguins Google-Ads NFT-drainer phishing campaign — multi-chain (Ethereum-NFT-centric) — 2024-12
- Pimlico ERC-20 Paymaster EIP-2612 Permit Cross-Chain Replay — Late 2024 — $0 (patched)
- Movement Network ($MOVE) market-maker insider dump — Binance / Coinbase — 2024-12
- $HAWK / Hawk Tuah celebrity-memecoin sniper-distribution pump-and-dump — Solana — 2024-12
- Thala Labs farming-contract Move-language flaw — Aptos — 2024-11-15
- MakerDAO Endgame Snapshot governance legitimacy dispute — off-chain signal-vote treated as binding for multi-billion-dollar protocol restructuring — Ethereum — 2024-11
- Tapioca DAO DSO logic flaw + key compromise — Arbitrum — 2024-10-18
- $SHAR / Sharpei Solana memecoin funnel-collapse rug — Solana — 2024-10-23/24
- Radiant Capital cross-chain lending compromise — Arbitrum / BNB Chain — 2024-10-16
- Operation Token Mirrors — FBI NexFundAI sting against crypto market-maker wash-trading-as-pump cohort — multi-CEX (centred on FBI-deployed token, NexFundAI on Ethereum) — initial charges 2024-10-09; guilty pleas + sentencings through 2025–2026
- Inferno Drainer service ecosystem — multi-chain — operating ~2022 through November 2023 (Telegram-announced shutdown; affiliate / kit re-emergence under successor branding)
- Ethereum block-proposer griefing via targeted missed-slot campaign — Ethereum L1 — 2024-10
- WalletConnect-impersonating Google Play mobile drainer — Android/multi-chain — 2024-03 to 2024-09
- Solana Token-2022 PermanentDelegate malicious-exercise cohort — Solana — 2024–2025
- Solana Token-2022 PermanentDelegate burn-on-buy cohort — Solana — 2024-09 onward
- Polymarket account takeover via third-party auth — Polygon — 2024-09
- Penpie Finance reward-claim exploit — Ethereum + Arbitrum — 2024-09-03
- Onyx Protocol empty-market rounding exploit — Ethereum — 2024-09-26
- Indodax hot-wallet drain — multi-chain — 2024-09-11
- ENS DAO delegation-concentration governance dynamics — delegate voting-weight accumulation and proposal-outcome influence — Ethereum — 2023–2024
- DEXX trading-bot platform compromise cohort — Solana + EVM — 2024-09 to 2024-11
- DeltaPrime admin-key compromise + malicious upgrade — Arbitrum + Avalanche — 2024-09-16/17
- BingX hot-wallet drain — multi-chain — 2024-09-20
- Banana Gun oracle-messenger information leak — Ethereum — 2024-09-19
- Ronin Bridge upgrade-function misconfiguration — Ronin / Ethereum — 2024-08-06
- Ronin Bridge whitehat MEV-bot rescue — Ronin / Ethereum — 2024-08-06
- Rocket Pool node-operator infrastructure-concentration downtime event — AWS/Hetzner correlated outage induced material inactivity-leak penalties across concentrated validator set — Ethereum — 2024-08
- Penpie Finance yield-optimizer reward-accounting exploit — Ethereum + Arbitrum — 2024-09-03
- Nexera (formerly AllianceBlock) NXRA proxy-admin compromise — Ethereum — 2024-08-06
- Genesis Creditor — Multi-Stage Impersonation Social Engineering — 2024-08-19
- ERC-4337 paymaster validation-bypass disclosure cohort — EVM — 2024
- DPRK IT Worker Crypto Team Infiltration — Multi-Protocol — 2024-08
- Discord bookmark-phishing drainer campaign via server-boost mechanic — EVM/Solana — 2024-08 to 2024-10
- Bittensor PyPI compromise — coldkey-cohort impact — Bittensor / TAO — 2024-07 to 2024-08 (cohort)
- 4064 BTC — Instant Exchange + Cross-Chain Bridge Laundering — 2024-08
- WazirX — Ethereum — 2024-07-18
- Puffer pufETH LRT depeg event — EigenLayer restaking withdrawal-cap constraint — Ethereum — 2024-07
- $NEIRO Solana memecoin bundled-launch concentration rug — Solana — 2024-07-27
- Li.Fi cross-chain aggregator facet exploit — multi-chain — 2024-07-16
- Gurvinder Bhangu (Gurv) — Celebrity X Account Compromise → Meme Coin Scams — 2024-07
- GMX-brand-impersonation Telegram copy-trading bot soft rug — Arbitrum — 2024-07 to 2024-09
- Compound DAO Proposal 289 attempted governance takeover — Ethereum — 2024-07-28
- Compound cross-chain governance relay misconfiguration — Ethereum / multi-chain — 2023–2024 (audit-finding class)
- WalletConnect multisig-drain via fake MEV-bot session — EVM/multi-chain — 2024-06
- Velocore CPMM fee-rate underflow exploit — zkSync Era / Linea — 2024-06-02
- UwU Lend sUSDe oracle thin-input manipulation — Ethereum — 2024-06-10
- Bittensor bittensor PyPI supply-chain coldkey-exfiltration compromise — Bittensor / TAO — 2024-07-02
- Uplift DAO malicious proxy-upgrade treasury drain — Ethereum — 2024-06-18
- Solana validator-coordinated sandwich-attack MEV cohort and Foundation delegation-program removal — Solana — 2024-06
- Polymarket Barron Trump / DJT memecoin oracle-override dispute — 2024
- OpenSea creator-royalty enforcement sunset — EVM NFT marketplaces — 2024-06 to 2025-01
- Mark Cuban — Public Figure Wallet Social Engineering Compromise — 2024-06
- Loopring Smart Wallet 2FA-bypass guardian-recovery exploit — Ethereum — 2024-06-09
- Loopring Smart Wallet guardian-recovery exploit — Ethereum — 2024-06-09
- Kelp rsETH liquid-restaking-token depeg — Ethereum L1 — 2024-06
- Holograph deployer-key compromise unlimited-mint-and-dump — Ethereum — 2024-06-13
- ERC-4337 bundler MEV extraction on Polygon — specific operator-level bundler front-running incident — 2024-06
- CoinStats MetaMask-Snap-related compromise — Ethereum + multi-chain — 2024-06-22
- BtcTurk hot-wallet drain (first incident) — multi-chain — 2024-06-22
- BeraChain fake-airdrop token-metadata-spoofing wave — BeraChain EVM — 2024-06 to 2024-09
- Uniswap DAO delegation governance concentration — delegate voting-weight accumulation and community governance dynamics — Ethereum — 2023–2025
- Sonne Finance empty-market rounding-error exploit — Optimism — 2024-05-14
- GCR Classic Hack → $3.3M Insider Longs on Hyperliquid — 2024-05
- Gala Games admin-key compromise emergency-recovery — Ethereum — 2024-05-20
- Ether.fi weETH liquid-restaking-token discount-to-NAV event — Ethereum L1 — 2024-05
- EigenLayer withdrawal slippage sandwich — Ethereum — 2024-05
- EigenLayer restaking airdrop dispute and AVS slashing-condition cohort — Ethereum L1 — 2024-05 onward
- DMM Bitcoin exchange hack — Bitcoin — 2024-05-31
- Cypher Protocol Hoak insider theft from redemption fund — Solana — 2024-05
- Address Poisoning — Ethereum — 2024-05-03 ($68M WBTC, returned)
- ZKasino gambling-platform bridge-exit — Ethereum / L2s — 2024-04-20 onward
- Renzo ezETH liquid-restaking-token depeg and looped-leverage liquidation cascade — Ethereum L1 + multi-chain — 2024-04-24
- Pike Finance Wormhole-NTT cross-chain message-handling exploit — multi-chain — 2024-04-30 / 2024-05-05
- NFT wrapper / fractionalisation protocol royalty circumvention cohort — NFTX / FloorDAO / Sudoswap — Ethereum — 2022–2025
- Hedgey Finance claim-function input-validation exploit — multi-chain — 2024-04-19
- Change Healthcare data-leak re-extortion — Bitcoin / RansomHub brand — 2024-04
- WOOFi Pro sPMM curve flash-loan manipulation — Arbitrum — 2024-03-05
- Prisma Finance MigrateTroveZap delegatecall exploit — Ethereum — 2024-03-28
- Munchables — Blast L2 — 2024-03-26
- Kyle DeGods — Fake Hack / Insider Theft from Nuddies NFT Project — 2024-03
- Jolan Lacroix — $900K Presale Theft / Gambling on Meme Coins and Milady NFTs — 2024-03
- Profanity vanity-address entropy cohort tail — Ethereum — 2023–2024 (cohort-extended case)
- Cygnus Finance read-only reentrancy via LP-token oracle — EVM — 2024-03
- Curio DAO governance attack — Ethereum + multi-chain — 2024-03-23
- Coinbase Smart Wallet pre-launch audit disclosure (H-01 ownership-recovery loss-of-funds) — Base — 2024-03
- @blknoiz06 Impersonation — $2.6M Meme Coin Reply Phishing — 2024-03
- Arbitrum ARB team-and-investor vesting-cliff unlock and coordinated sell-pressure — Ethereum — 2024-03-16
- Stader ETHx LST secondary-market discount to ETH NAV — DEX liquidity pool pricing divergence during LRT-season liquidity migration — Ethereum — 2024-02
- PlayDapp $290M Private Key Compromise — Gaming Platform Exploit — 2024-02
- MINER — the transfer function checked that neither address was null but not that they were different, so sending tokens to yourself doubled your balance — MINER (ERC-X) / Ethereum — 2024-02
- LockBit Operation Cronos disruption — multi-jurisdiction takedown — 2024-02-19 to 2024-02-20
- Honeypot-by-design token cohort — Ethereum / BNB Chain / Base — 2024-02 onward
- FixedFloat instant-swap hot-wallet drain — multi-chain — 2024-02-16
- EigenLayer pre-token anticipation phishing — Ethereum — early 2024
- dYdX DYDX token vesting-cliff unlock and investor sell-pressure — Ethereum — 2024-02-01
- Change Healthcare ransom payment — Bitcoin — 2024-02-21 to 2024-03-05
- Blur points-farming wash-trading ring — coordinated circular NFT trades across linked wallet clusters — Ethereum — 2023–2024
- BitForex hot-wallet drain (operator-driven exit-scam pattern) — multi-chain — 2024-02-23
- Socket/Bungee bridge exploit — Ethereum — 2024-01-16
- Socket / Bungee bridge infinite-approval call-injection exploit — Ethereum — 2024-01-16
- U.S. SEC verified X-account compromise and fake Bitcoin ETF approval — chain-agnostic — 2024-01-09
- Ripple — Private Key Compromise — 2024-01-31
- Post-Tornado-Cash DeFi yield-protocol laundering shift — cross-chain — 2024 onward
- Orbit Bridge — Ethereum ↔ multi-chain — 2024-01-01
- NFT marketplace royalty-enforcement sunset and creator-revenue bypass — multi-chain (Ethereum, Solana, Bitcoin ordinals) — 2024
- KK Park compound-operated investment-fraud takedown — Myanmar/Thailand border — 2024
- iOS WhatsApp iCloud-backup wallet-seed exfiltration cohort — multi-chain — 2024
- HyperVerse / HyperFund — Sam Lee / Ryan Xu fake-asset-manager Ponzi (HyperTech ecosystem) — global — 2020-06 to 2022-11 (operating) / DOJ + SEC charges 2024-01
- Gamma Strategies $3.4M Flash Loan Price Manipulation — 2024-01
- Fake Trezor Suite download phishing campaign — multi-chain — 2024
- Fake MetaMask Chrome extension campaign — EVM/multi-chain — 2024-01 to 2024-06
- DPRK-attributed multi-stage chain-hop laundering via privacy-chain conversions — cross-chain — 2024
- Blue-chip DeFi yield-protocol laundering via LST and lending-market cover — Ethereum — 2024
- Concentric Finance multisig signing-key social-engineering compromise — Arbitrum — 2024-01-22
- Email Impersonation Phishing Wave — CoinTelegraph/WalletConnect/Token Terminal Impersonation — 2024-01
- CoinsPaid $37M Lazarus Group Attack — Payment Processor Exploit — 2024-01
- Astaria reinitialization vulnerability disclosure — EVM — 2024
- 1Password encrypted-note seed-storage cohort — multi-chain — 2024–2025
2023 (102)
- Tornado Cash → Magic: The Gathering Cards — $25M Collectibles Laundering — 2023
- SIM Swap Wave — Multi-Victim Telecom Attack — 2023
- MEV-Boost relay equivocation attack surface — Ethereum — 2023
- Jaredfromsubway MEV sandwich bot — Ethereum — 2023
- Hundred Finance Compound V2 fork exploit — multi-chain — 2023-04-15
- Fake hardware-wallet firmware-update / recovery-app phishing cohort — Ledger / Trezor user base — 2023 onward (multi-year cohort)
- Fake DEX / clone-frontend distribution cohort — multi-chain — 2023 onward (multi-year cohort)
- ERC-4337 Paymaster Griefing and DoS Attack Surface Cohort — 2023–2026
- Coinbase Support Impersonation — Multi-Victim Social Engineering — 2023–2026
- WalletConnect session-hijack phishing campaigns — multi-chain — 2023–2025
- Kraken and Coinbase Staking-as-a-Service SEC Enforcement and Validator-Set Disruption — 2023–2025
- Multi-block MEV TWAP oracle grinding via proposer-builder coordination — Ethereum L1 — 2023–2025
- Fee-on-Transfer Token Accounting Exploit Cohort — multi-chain (EVM, BNB Chain, Polygon, Arbitrum) — 2023–2025
- Fake Revoke.cash / Wallet-Security Browser-Extension Phishing — 2023–2025
- Fake Crypto Wallet App Google Play / App Store Phishing — 2023–2025
- DPRK post-Tornado-Cash DEX aggregator routing laundering — 2023–2025
- DPRK IT-worker program exchange-account farming — multi-chain — 2023–2025
- DeFi yield-strategy laundering via liquidity-provision and staking-as-rail — multi-chain — 2023–2025
- Cloud-Document / Email-Draft Seed-Phrase Storage Compromise Cohort — 2023–2025
- Akira Ransomware-as-a-Service — 2023–2025
- zkSync airdrop-anticipation phishing campaign — 2023–2024
- UK Scammer @ape_31 — Fake PNL Screenshot Funnel to Paid Scam Services — 2023-2024
- StarkNet STRK Pre-Token Anticipation Phishing — 2023–2024
- Squeeth volatility auction slippage sandwich — Ethereum — 2023–2024
- LayerZero OFT governance relay misconfiguration audit-finding cohort — cross-chain — 2023–2024
- TeufeurS Kidnapping — $2M Crypto Ransom / $800K Frozen — 2023
- ERC-4337 Bundler MEV Extraction Cohort — Ethereum / Polygon / Arbitrum / Optimism / Base — 2023–2025
- ERC-4337 bundler MEV extraction cohort — Ethereum / EVM L2s — 2023–2025 (cohort)
- DAO governance proposal-snowballing cohort — multi-proposal submission to overwhelm voter attention and divide quorum — multi-chain — 2023–2024
- Counterfeit-token dust-attack-lure cohort — EVM — 2022–2024 (cohort)
- Balancer veBAL delegation-cluster vote takeover — Ethereum — 2023–2024
- Argent Smart Wallet Escape-Guardian Recovery-Flow Exploitation — 2023–2024 — $0 (patched)
- Tellor (TRB) spot-perpetual manipulation and liquidation cascade — Ethereum / CEX — 2023-12-31
- Orbit Chain $81M Cross-Chain Bridge Exploit — 2023-12
- Ledger Connect Kit npm supply-chain compromise — multi-chain (EVM) — 2023-12-14
- Ledger Connect Kit Library Supply-Chain Compromise — multi-chain (EVM dApps) — 2023-12-14
- Galxe frontend DNS hijack pair — Ethereum / multi-chain — 2023-10-06 + 2023-12
- Solana Jito relayer eclipse griefing — Solana — November 2023
- Snowdog DAO cross-chain locked-liquidity spoof — Avalanche / Ethereum — 2023-11 to 2023-12
- SafeMoon (SFM) — BNB Chain — federal action 2023-11-01
- PulseChain ecosystem fake-audit-claim token launches — PulseChain — 2023-11 to 2024-02
- Poloniex hot-wallet drain — multi-chain — 2023-11-10
- KyberSwap Elastic tick-state-manipulation exploit — multi-chain — 2023-11-22
- ICBC Financial Services LockBit intrusion — U.S. Treasury market disruption — 2023-11-09
- HTX hot wallet + HECO Bridge — Ethereum ↔ HECO — 2023-11-22
- dYdX V3 SUSHI/YFI targeted market manipulation and insurance-fund drain — dYdX V3 (StarkEx L2) — 2023-10-29 to 2023-11-18
- LastPass Breach → Crypto Drain — Multi-Victim Seed Phrase Exposure — 2023-10
- Stargate / LayerZero cross-chain governance relay multisig configuration — bridge parameter update relay path — multi-chain — 2023–2024
- Stake.com hot-wallet theft — multi-chain — 2023-09-04
- Nouns DAO rage-quit fork arbitrage — Ethereum — 2023-09-15
- Mixin Network — multi-chain — 2023-09-23
- MGM Resorts ransomware intrusion — ALPHV / Scattered Spider — 2023-09-10
- JPEX Hong Kong unlicensed-exchange fraud — Hong Kong — 2023-09-13 onward
- Gitcoin DAO Snapshot Off-Chain Governance Attack — Ethereum — 2023-09
- CoinEx exchange hot-wallet compromise — Multi-chain (ETH, TRON, Polygon) — 2023-09-12
- Caesar's Ransomware — $12M Seized / Multi-Agency Recovery — 2023-09
- Caesars Entertainment ransom payment — ALPHV / Scattered Spider — 2023-09
- Zunami Protocol price-manipulation drain via Curve pool — Ethereum — 2023-08-13
- Verified Organization Phishing — Fake Verified Org Account Farms on X/Twitter — 2023-08
- Steadefi deployer-key compromise and malicious-upgrade extraction — Arbitrum — 2023-08-07
- OpenSea Operator Filter Registry sunset — Ethereum + multi-chain — 2023-08-17 (announcement) to 2024-02-29 (grace-period end)
- Milk Sad — bx seed documents 128–256 bits of entropy and delivers 32, because Mersenne Twister is seeded on the system clock: same second, same "random" wallet — Libbitcoin Explorer (CVE-2023-39910) — theft 2023-07-12, disclosed 2023-08-08
- Magnate Finance / Solfire / Kokomo deployer-cluster exit-scam cohort — Solana / BNB Chain / Base — 2022-01 → 2023-08
- Exactly Protocol — a periphery contract took the market address as an argument and never checked it, so a fake market reentered and spent 117 users' approvals — Exactly Protocol / Optimism — 2023-08-18
- Cypher Protocol sub-account isolation flaw — Solana — 2023-08-07
- Balancer V2 Boosted Pools exploitation — Ethereum + multi-chain — 2023-08-22
- Multichain — cross-chain bridge protocol — 2023-07-06
- Multichain MPC bridge verification-model collapse — multi-chain — 2023-07-06/07
- Italian Government Email Compromise — Twitter Legal Request Portal Hijack — 2023-07
- Curve Finance Vyper compiler-level reentrancy — Ethereum — 2023-07-30
- Curve Finance Exploit Freeze Coordination — Multi-Exchange Compliance Response — 2023-07
- Alphapo payment-processor hot-wallet compromise — Multi-chain (BTC, ETH, TRON) — 2023-07-23
- MOVEit Transfer mass-extortion campaign — Cl0p — 2023-05-27 onward
- Chibi Finance panic / onlyGov residual-authority exit-scam — Arbitrum — 2023-06-27
- Atomic Wallet — multi-chain — 2023-06-03
- Atlantis Loans audit-bytecode-mismatch exploit — BNB Chain — 2023-06-10
- Tornado Cash governance attack — Ethereum — 2023-05-20
- Tornado Cash DAO Snapshot off-chain voting exploitation via governance-token Sybil deployment — chain-agnostic — 2023-05
- Sudoswap wash-trade laundering pools — Ethereum — 2023-05 to 2023-10
- Mango Markets orderbook spoofing via fake-liquidity deployment — Solana — 2023-05 to 2023-08
- Ledger Recover seed-recovery service trust-substrate-shift event — Ledger hardware-wallet ecosystem — 2023-05-16
- Ethereum Beacon Chain finality loss event — Ethereum — 2023-05-11 to 2023-05-12
- Sentiment Protocol read-only reentrancy via Balancer LP integration — Arbitrum — 2023-04-04
- Paribus diamond-facet exploit — EVM — 2023-04
- Optimism Goerli Testnet Governance Replay — Optimism — 2023-04
- MEV-Boost relay equivocation / unbundling — Ethereum mainnet — 2023-04-03
- Hundred Finance empty-market rounding-error exploit — Gnosis Chain — 2023-04-15
- Cross-chain bridge signature replay across shared-validator-set instances — multi-chain — 2022–2024
- Arbitrum Foundation governance bypass and treasury transfer — Ethereum — 2023-03/04
- Allbridge stable-pool virtual-price manipulation — BNB Chain — 2023-04-01
- Rocket Pool node operator slashing — Ethereum — 2023-03
- ParaSpace whitehat rescue by BlockSec — an attacker inflates cAPE collateral value via a rebasingIndex manipulation, fails on gas, and BlockSec redeploys the attack to rescue the funds first — Ethereum — 2023-03-17
- Euler Finance lending exploit — Ethereum — 2023-03-13
- Yearn iearnUSDT v1 deprecated-vault misconfiguration — Ethereum — 2023-02-02
- Platypus Finance emergency-withdrawal logic flaw — Avalanche — 2023-02-16
- MetaBirkins (Hermès vs Mason Rothschild) — Ethereum + civil-court judgment — minted 2021-12; verdict 2023-02-08
- jaredfromsubway.eth sandwich-MEV operator — Ethereum — operating since 2023-02-27
- Hope Finance router-rerouting rug pull — Arbitrum — 2023-02-21
- BonqDAO Tellor oracle manipulation — Polygon — 2023-02-01
- Blur airdrop incentive-wash cohort — Ethereum — 2022-10-19 through 2024 (cohort case)
- Magic Eden y00ts indexer-bug counterfeit-listing exploit — Solana — 2023-01-04
- Ledger Donjon side-channel seed-extraction research — hardware — 2023
2022 (99)
- Post-Tornado-Cash USDC/USDT freeze-policy asymmetry laundering — 2022
- Hydra Marketplace German server-seizure takedown — 2022
- Circle USDC — $420M+ Compliance Failures / Stablecoin Issuer Inaction — 2022-2026
- Validator liveness-fault griefing cohort — Ethereum L1 (primary), Solana, Cosmos — 2022–2025
- Travel Rule Gap Exploitation — Sub-Threshold Structuring and VASP-Avoidant Routing — 2022–2025
- OFAC-compliance builder censorship of Tornado Cash transactions — Ethereum — 2022–2025 (ongoing)
- Stablecoin Issuer Freeze-Asymmetry and Optimistic Bridge Fraud-Proof Gap Cohort — 2022–2025
- Social-Engineering Entry-Vector Cohort — 2022–2025
- Smart-Contract Architecture Exploit Cohort — 2022–2025
- Seed-Phrase At-Rest Exfiltration Cohort — 2022–2025
- Optimistic-bridge fraud-proof gap cohort — multi-chain — 2022–2025 (cohort)
- Optimism L1-to-L2 cross-chain governance relay gap — Ethereum / Optimism — 2022–2025 (architecture-review)
- NFT Marketplace Wash-Trading and Royalty-Bypass Infrastructure — 2022–2025 — Aggregate Revenue Loss in Hundreds of Millions
- MEV-Boost Relay Operator Trust-Surface and MEV Theft Risk — Ethereum — 2022–2025
- MEV-Boost Relay Bid Withholding and Builder Auction Gaming — Ethereum L1 — 2022–2025
- Fake browser-extension phishing cohort — cross-chain — 2022–2025
- Ethereum Validator DDoS Extortion and Liveness-Fault Griefing Campaigns — 2022–2025
- Ethereum Block Builder Exclusive Order-Flow Centralization and Censorship — 2022–2025
- Ethereum Beacon Chain Inactivity-Leak Griefing and Correlation-Penalty Economics — 2022–2025
- ERC-20 transferFrom return-value spoofing cohort — EVM — 2022–2025
- DAO Governance Exploitation Cohort — 2022–2025 — Aggregate $30M+ Attempted, ~$8M Realised
- Custody Infrastructure Compromise Cohort — 2022–2025
- Cross-chain replay vulnerability cohort — multi-chain — 2022–2025 (cohort)
- Cross-Chain Locked-Liquidity and Token Metadata Spoofing Cohort — 2022–2025 — Aggregate $20M+
- Cross-chain locked-liquidity spoof via split-chain lock-receipt claims — multi-chain — 2022–2025
- Cross-chain locked-liquidity spoof cohort — multi-chain — 2022–2025 (cohort)
- Cosmos-SDK Validator Downtime Jailing and Slashing-Evasion Patterns — 2022–2025
- Coinbase cbETH Structural Discount and Liquid Staking Token Pricing Surface — Ethereum — 2022–2025
- Arbitrum One optimistic bridge validator-set gap — Ethereum / Arbitrum One — 2022–2025 (architecture-review)
- Snapshot off-chain voting exploitation via flash-loaned and delegated voting power — Ethereum — 2022–2024
- Flash-Loan Governance Attack Cohort — 2022–2024 — Aggregate $200M+ Nominal, ~$190M+ Realised
- Black Basta Ransomware-as-a-Service — 2022–2024
- Android Google-Drive Wallet-Backup Seed Exfiltration Cohort — 2022–2024
- Lido stETH staking-interface phishing cohort — Ethereum — 2022-2023
- LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort — multi-chain — 2022-12 (breach) / 2023-2025 (drains)
- Defrost Finance exit scam — Avalanche — 2022-12-23
- Ankr deployer-key compromise and malicious upgrade — BNB Chain — 2022-12-01
- Ankr aBNBc Liquid Staking Token Exploit via Unlimited Mint — BNB Chain — 2022-12-02
- X2Y2 + LooksRare royalty-optional shift — Ethereum — 2022-08 through 2023 (cohort case)
- FTX exchange collapse — multi-chain (CEX) — 2022-11-11 (Chapter 11 filing)
- Transit Swap DEX aggregator exploit — Multi-chain (Ethereum, BNB Chain) — 2022-10-02
- Team Finance liquidity-locker migrate() exploit — Ethereum / BNB Chain — 2022-10-27
- Market.xyz — a lending market prices Curve LP collateral through get_virtual_price() and is drained by re-entering the pool's view during remove_liquidity — Market.xyz / QuickSwap (Polygon) — 2022-10-24
- Mango Markets oracle manipulation — Solana — 2022-10-11
- BSC Token Hub (BNB Bridge) — Beacon Chain ↔ BSC — 2022-10-06
- Wintermute DeFi vault drain — Ethereum — 2022-09-20
- Profanity vanity-address cohort — Ethereum — 2022-09-15 to 2022-12 (cohort case)
- Snapshot.org off-chain voting Sybil-attack cohort — chain-agnostic — 2022–2025 (cohort)
- Ethereum PoW fork cross-chain replay — Ethereum / ETHPoW — September 2022
- CryptoFX / Mauricio Chavez fake-asset-manager Ponzi targeting Latino community — Houston, Texas + ten-state US footprint + two foreign countries — 2020-05 onward / SEC emergency action 2022-09
- Yuga Labs Otherside Discord-phishing wave — Ethereum + multi-chain — 2022-08-04
- Tornado Cash OFAC sanctions — trust-substrate shift via regulatory action — Ethereum — 2022-08-08
- Slope Wallet (Solana) — 2022-08-02
- OptiFi accidental program closure — Solana — 2022-08-29
- Nomad Bridge — Ethereum / Moonbeam / Avalanche / Evmos — 2022-08-01
- Curve Finance frontend DNS hijack — Ethereum — 2022-08
- Premint NFT-allowlist platform front-end JavaScript injection — Ethereum — 2022-07-17
- Omni Protocol — handing an NFT back with safeTransferFrom calls the borrower's code mid-transition, and two unguarded functions turned that callback into a double reentrancy — Omni Protocol (Ethereum) — 2022-07-10
- Nomad optimistic bridge challenger-network gap — EVM — 2022 (architecture-review)
- Nirvana Finance flash-loan-driven price manipulation — Solana — 2022-07-28
- Li.Fi v1 diamond-facet vulnerability — EVM — 2022-07
- Crema Finance fake-tick-array exploit — Solana — 2022-07-02
- Audius governance storage-collision attack — Ethereum — 2022-07-23
- XCarnival — the borrow path checked that a pledge order existed, never that the Ape was still in the vault, so one BAYC backed loan after loan — XCarnival (Ethereum) — 2022-06-26/27
- OpenSea insider trading — Nate Chastain — Ethereum — 2021-09 to 2022-06
- Lido stETH depeg and Aave / Curve looped-leverage liquidation cascade — Ethereum L1 — 2022-05 to 2022-06
- Harmony Horizon Bridge — Ethereum ↔ Harmony — 2022-06-23/24
- Harmony Horizon Bridge validator economic-incentive gap — Ethereum / BSC / Harmony — 2022-06-23/24
- Harmony Horizon Bridge light-client verification economic-security gap — Ethereum / Harmony — 2022-06-23/24
- Terra/Luna / UST algorithmic-stablecoin collapse — Terra — 2022-05-07 to 2022-05-13
- Pixelmon NFT reveal-rug — Ethereum — 2022-02 mint, 2022-05 reveal
- Fortress Protocol flash-loan governance attack — BNB Chain — 2022-05-08
- Saddle Finance virtual-price manipulation — Ethereum — 2022-04-30
- Ronin Bridge Discord-impersonation followups — Axie Infinity / Ronin community — 2022-04 (cohort)
- Rari Fuse TWAP Oracle Window-Manipulation Lending Exploit — Ethereum — 2022-04-30
- Inverse Finance recurring oracle exploits — Ethereum — 2022-04-02 and 2022-06-16
- Inverse Finance TWAP-oracle window-manipulation lending exploit — Ethereum — 2022-04-02
- iCloud-backup MetaMask seed-phrase cohort — multi-chain (EVM-dominant) — 2022-04 (canonical Iacovone case) onward
- Elephant Money flash-loan governance attack — BNB Chain — 2022-04-12
- Bored Ape Yacht Club / Yuga Labs operator-side credential-compromise wave — Ethereum — 2022-04 → 2024-08
- Beanstalk Farms flash-loan governance attack — Ethereum — 2022-04-17
- Ronin Bridge — Ethereum ↔ Ronin sidechain — 2022-03-23
- Paraluni flash-loan exploit — BNB Chain — 2022-03-13
- NFT collection proxy-upgrade rug cohort — upgradeable contracts without timelock executed within same block — Ethereum — 2021–2023
- Cashio infinite-mint via missing input validation — Solana — 2022-03-23
- BSC yield-farm single-sided liquidity-plant cohort — Binance Smart Chain — 2022-Q1 through 2022-Q3
- Agave / Hundred Finance reentrancy exploit — Gnosis Chain — 2022-03-15
- X2Y2 marketplace-incentive wash-trade cohort — Ethereum — 2022-02-15 onward
- Wormhole Bridge — Ethereum ↔ Solana — 2022-02-02
- Meter.io Passport Bridge — Ethereum ↔ BNB Smart Chain ↔ Moonriver — 2022-02-05
- Build Finance DAO hostile-takeover — Ethereum — 2022-02-09 to 2022-02-14
- Akutar NFT influencer-backed rug — Ethereum — 2022-02 to 2022-04
- Wonderland Money — concealed-pseudonym treasury operator (Sifu / Michael Patryn) — Avalanche / multi-chain — 2022-01-27
- Qubit Bridge — BNB Smart Chain ↔ Ethereum — 2022-01-27
- LooksRare / X2Y2 wash-trading reward-farming cohort — Ethereum — 2022
- LooksRare wash-trading launch incentive — Ethereum — 2022-01-10 onward
- Frosties NFT rug pull — Solana — 2022-01-09
- Big Daddy Ape Club NFT rug pull — Solana — 2022-01-10
- Arbix Finance audit-scope-mismatch rug pull — Binance Smart Chain — 2022-01-04
2021 (47)
- PancakeSwap token-impersonation wave — BSC — 2021
- Bitcoin Fog Roman Sterlingov exchange-funding de-anonymization — 2021
- Vesting-Cliff Dump and Brand-Impersonation Custodial Soft-Rug Cohort — 2021–2026
- Influencer-amplified non-memecoin promotion-and-dump cohort — multi-chain — 2021 onward (multi-year cohort)
- Fake Audit Claims and Audit-Pending Marketing Cohort — 2021–2026 — Aggregate ~$50M+
- Slippage-manipulation sandwich MEV cohort — EVM (primary), Solana — 2021–2025
- PancakeSwap token-launch MEV sandwich cohort — BSC — 2021–2025
- Multi-block MEV TWAP oracle manipulation cohort — EVM — 2021–2025
- Karakurt encryption-free data-theft extortion operation — 2021–2025
- Initial-Liquidity Backdoor and Locked-Liquidity Spoof Cohort — 2021–2025 — Aggregate $100M+
- Governance Timelock Design Anti-Pattern Cohort — 2021–2025 — Amplification Factor Across Multiple Technique Classes
- DeFi and NFT Laundering-Infrastructure Cohort — 2021–2025
- BlackByte Ransomware-as-a-Service — 2021–2025
- 2021–2024 Rekt.Uncovered Incidents Cohort
- Magnate/Kokomo/Lendora/Solfire — Cross-Project Repeat Rug Pull Operation — 2021-2024
- Andariel Maui ransomware — healthcare-sector targeting — 2021–2024
- Uranium Finance — Smart Contract Exploit / $31M Seized — 2021 / 2025-02
- Vulcan Forged wallet-server compromise — Polygon/Ethereum — December 2021
- Visor Finance Uniswap V3 TWAP oracle manipulation — Ethereum — 2021-12-21
- BitMart hot-wallet compromise — Ethereum/BNB Chain — 2021-12-05
- BadgerDAO frontend compromise via Cloudflare Workers — Ethereum — 2021-12
- AscendEX hot-wallet compromise — multi-chain (Ethereum, BSC, Polygon) — 2021-12-11
- SQUID (Squid Game token) — BNB Chain — 2021-10 / 2021-11-01
- Cream Finance oracle manipulation — Ethereum — 2021-10-27
- AnubisDAO (ANKH) — Ethereum — 2021-10-28 / 2021-10-29
- Vee Finance oracle manipulation — Avalanche — 2021-09-21
- Evolved Apes NFT rug pull — Ethereum — 2021-09-24 / 2021-10-05
- Compound Comptroller distribution bug — Ethereum — 2021-09-30
- Poly Network — Cross-Chain Bridge — 2021-08-10
- Liquid Global warm-wallet compromise — multi-chain — 2021-08-19
- THORChain — Bifröst module — 2021-07-15, 2021-07-23, 2021-08-12 (cluster)
- ChainSwap bridge token-deployment exploit — multi-chain (Ethereum, BSC, Polygon) — 2021-07-02 and 2021-07-11
- StableMagnet — the explorer verified the contract but not the library it called, so the published source and the deployed behaviour were different programs — StableMagnet (SMAG) / BNB Chain — 2021-06-23
- Iron Finance (IRON / TITAN) — Polygon — collapse 2021-06-16
- Spartan Protocol AMM-LP-pricing exploit — BNB Smart Chain — 2021-05-02
- PancakeBunny yield-aggregator mint-pricing exploit — BNB Smart Chain — 2021-05-19
- Meebits — the mint told you what you got before you had to keep it, and an archived attribute file told you what it was worth, so a contract minted and reverted until a rare one came out — Meebits / Larva Labs (Ethereum) — 2021-05-08
- DFINITY Internet Computer (ICP) insider vesting-cliff token dump — Ethereum — 2021-05-10 onward
- Colonial Pipeline ransomware extortion payment — 2021-05
- Bogged Finance flash-loan governance attack — BNB Chain — 2021-05-22
- Uranium Finance migration-pair arithmetic error — BSC — 2021-04-28
- EasyFi admin-key compromise — Polygon — 2021-04-19
- True Seigniorage Dollar (TSD) hostile-vote mint flooding — Binance Smart Chain — 2021-03-13
- SafeMoon (SFM) token-launch mechanics — BNB Chain — 2021-03
- Meerkat Finance deployer-drain exit scam — BSC — 2021-03-04
- McAfee / Watson digital-asset pump-and-dump CFTC + DOJ enforcement — multi-CEX (Twitter-amplified) — 2017-12 / 2018-01 conduct; charges 2021-03-05
- Furucombo proxy-authority exploit — Ethereum — 2021-02-27
2020 (30)
- MEV Sandwich Attack Cohort — 2020–2025
- Initial liquidity sandwich MEV cohort — EVM / multi-chain — 2020–2025 (ongoing)
- Landmark Ransomware Extortion Cohort — 2020–2024 — 12 Incidents — Aggregate ~$225M+
- Lazarus Group — $200M Fiat Cash-Out from 25+ Hacks — 2020-2023
- Uniswap V2/V3 fake-token impersonation wave — Ethereum — 2020-2021
- DeFi "move fast" era timelock-free protocol upgrade cohort — EVM — 2020–2021
- Uniswap honeypot-token wave and serial deployer cluster — Ethereum — 2020 (cohort)
- Warp Finance flash-loan oracle exploit — Ethereum — 2020-12-17
- Livecoin exchange infrastructure seizure and hot-wallet drain — Bitcoin / Ethereum / multi-asset (CEX) — 2020-12-23
- Cover Protocol Blacksmith infinite-mint exploit — Ethereum — 2020-12-28
- Compounder Finance strategy-swap LP drain — Ethereum — 2020-11-30 to 2020-12-02
- Pickle Finance Evil Jar exploit — Ethereum — 2020-11-21
- Origin Dollar (OUSD) flash-loan-funded reentrancy — Ethereum — 2020-11-17
- Cred Inc. custodial-fraud / counterparty-risk insolvency — multi-chain (custodial) — 2020-11-07
- Akropolis Delphi flash-loan-funded reentrancy — Ethereum — 2020-11-12
- UniCats yield-farm approval backdoor — Ethereum — 2020-10-05
- Harvest Finance flash-loan-funded oracle manipulation — Ethereum — 2020-10-26
- Yfdexf.Finance liquidity-mining exit scam — Ethereum — 2020-09-08 to 2020-09-10
- SushiSwap dev-fund T5.005 + vampire-attack launch — Ethereum — 2020-08-26 to 2020-09-11
- KuCoin exchange hot-wallet theft — multi-chain — 2020-09-25
- Eminence DeFi flash-loan exploit — Ethereum — 2020-09-28 to 2020-09-29
- Yam Finance rebase-bug governance-capture — Ethereum — 2020-08-12 to 2020-08-13
- Twitter internal-tool compromise and Bitcoin scam campaign — 2020-07-15
- Ledger customer-data breach and follow-on phishing campaign — e-commerce / multi-chain — 2020-07 (disclosed 2020-07-29)
- Evil Corp WastedLocker ransomware — Garmin incident — 2020-07
- Bancor v0.6 upgrade pool-drain exploit — Ethereum — 2020-06-18
- Lendf.me reentrancy via ERC-777 callback chain — Ethereum — 2020-04-19
- MakerDAO Black Thursday liquidation-cascade zero-bid auctions — Ethereum — 2020-03-12
- bZx Protocol flash-loan-funded exploits — Ethereum — 2020-02-15 and 2020-02-18
- Trezor One / Model T RDP-downgrade voltage-glitch seed extraction (Kraken Security Labs disclosure) — hardware wallets — 2020-01-31
2019 (10)
- Crypto Exchange Orderbook Spoofing and Wash-Trading Cohort — 2019–2025
- Upbit exchange hack — Ethereum — 2019-11-27
- Wallet.fail Trezor / KeepKey Hardware-Side Seed Extraction Disclosure — 35C3 — 2018-12-27
- Bitpoint exchange hack — Multi-asset (BTC, ETH, XRP, LTC, BCH) — 2019-07-11
- PlusToken (Plus Token) Ponzi — multi-chain — collapse 2019-06
- Binance KYC data leak — Binance (CEX) via third-party KYC vendor — 2019-06 (breach date) / 2019-08-06 (public disclosure)
- Binance hot-wallet compromise — Bitcoin — 2019-05-07
- DragonEx exchange compromise — multi-asset cross-chain — 2019-03-24
- QuadrigaCX exchange collapse — multi-chain (BTC, ETH, LTC, BCH) — 2019-01 to 2019-04
- Cryptopia exchange sustained drain — Ethereum and ERC-20 tokens — 2019-01-14 to 2019-01-28
2018 (12)
- Welcome to Video Son Jong-woo cross-layer de-anonymization — 2018
- Iranian state-aligned financially-motivated cyber operations — 2018–2025
- DPRK IT worker exchange account farming — 2018–2025
- APT43 / Kimsuky crypto-funded espionage — 2018–2025
- Zaif exchange hack — Multi-asset (BTC, BCH, MONA) — 2018-09-14
- Bancor — Ethereum DEX — 2018-07-09
- Coinrail exchange compromise — multi-asset (ERC-20 token portfolio) — 2018-06-09 / 2018-06-10
- Bithumb exchange hack — Multi-asset (BTC, ETH, XRP, others) — 2018-06-20
- Binance API-key phishing campaign — Binance (CEX) — 2018-03-07
- BitGrail exchange compromise — Nano (XRB / NANO) — 2017-10 to 2018-02-08 (disclosure)
- Coincheck exchange hot-wallet theft — NEM / XEM — 2018-01-26
- BitConnect Ponzi collapse — Bitcoin / BitConnect — 2018-01-16
2017 (10)
- Hardware-Wallet Physical Compromise Cohort — 2017–2025
- Cross-exchange account farming infrastructure — chain-agnostic (exchange-side) — 2017–2025
- Early Ledger Nano S Counterfeit Cohort — 2017–2019
- NiceHash mining-marketplace wallet compromise — Bitcoin — 2017-12-06
- Tether treasury hack — Bitcoin (Omni Layer) — 2017-11-19
- Parity Multisig Wallet — Ethereum — 2017-07-19 and 2017-11-06
- BTC-e exchange seizure and Alexander Vinnik arrest — Bitcoin — 2017-07-25 to 2017-07-26
- Bithumb employee-laptop compromise + downstream phishing wave — multi-asset / Korean exchange — 2017-06 to 2017-09
- Yapizon (Youbit) exchange hack — Bitcoin — 2017-04-22
- Big Pump Signal Telegram / Discord coordinated pump-and-dump cohort — multi-CEX (Binance / Cryptopia / Bittrex) — 2017–2018 (canonical academic anchor); cohort recurs through 2024
2016 (5)
2015 (6)
- Bitfinex hot-wallet compromise — Bitcoin — 2015-05-22
- Evolution Darknet Market Exit Scam — 2015-03
- BTER hot-wallet drain — Bitcoin — 2015-02-14
- LocalBitcoins social-engineering compromise — Bitcoin — 2015-01-27
- Coin.mx first US federal criminal prosecution of unlicensed Bitcoin exchange — Bitcoin — 2015-01-26 (indictment unsealed)
- Bitstamp hot-wallet compromise — Bitcoin — 2015-01-04
2014 (8)
- Chainalysis founding and Silk Road tracing — 2014
- OneCoin — Ruja Ignatova / Karl Sebastian Greenwood multi-level fake-cryptocurrency Ponzi — global — 2014-2017 (operating) / 2017-onward (federal action)
- Moolah / Alex Green (Ryan Kennedy) Exchange Fraud — 2014-10
- MintPal hot-wallet compromise + operator-fraud collapse — multi-asset / UK altcoin exchange — 2014-09 to 2014-10
- Poloniex hot-wallet compromise — Bitcoin — 2014-03-06
- Flexcoin Bitcoin bank closure after hot-wallet hack — Bitcoin — 2014-03-02 to 2014-03-04
- Mt. Gox exchange collapse — Bitcoin — 2011-09 to 2014-02 (filing); recovery through 2024–2025
- Cryptsy multi-asset hot-wallet drain + operator-fraud collapse — multi-asset / US altcoin exchange — 2014-01 (drained); 2016-01 (publicly disclosed); 2016 (Florida bankruptcy and civil judgement)
2013 (10)
- Silk Road "altoid" handle cross-layer de-anonymization — 2013
- Meiklejohn Bitcoin address clustering research — 2013
- On-Chain De-Anonymization and Exchange Account-Farming Cohort — 2013–2025
- Illicit-Purpose and Designated-Entity Financing Cohort — 2013–2025
- Off-chain opsec failure cohort enabling attribution — chain-agnostic (off-chain attribution surface) — 2013–2024
- Emergence of blockchain transaction-graph forensics — Bitcoin — 2013–2015
- GBL Bitcoin Exchange Ponzi / Exit Scam — 2013-12
- Sheep Marketplace exit scam — Bitcoin — 2013-11 to 2013-12
- Inputs.io web-wallet hack — Bitcoin — 2013-10
- Atlas DNS Bitcoin-domain hijack phishing campaign — Bitcoin — April 2013
2012 (5)
- GLBSE (Global Bitcoin Stock Exchange) operator shutdown — Bitcoin — 2012-09
- Bitcoin Savings & Trust Ponzi — Bitcoin — 2011-11 to 2012-08
- Bitfloor exchange hot-wallet compromise — Bitcoin — 2012-05-02
- Linode Server Compromise — Bitcoin Service Infrastructure Attacks — 2012-03-01/02
- Bitcoinica exchange server compromise — Bitcoin — 2012-03-01
2011 (7)
- Darknet Marketplace Operations and Takedowns Cohort — 2011–2025 — 9 Landmarks
- BTC-e exchange account farming and sybil infrastructure — 2011–2017
- Silk Road darknet marketplace — Bitcoin — 2011-02 to 2013-10
- MyBitcoin wallet-service collapse — Bitcoin — 2011-07 to 2011-08
- Bitcoinica First Server-Side Hot-Wallet Compromise — 2011-07-29
- Mt. Gox auditor account compromise — Bitcoin — 2011-06-19
- Allinvain first major Bitcoin theft — Bitcoin — 2011-06-13