{
  "schema_version": "1.0",
  "title": "DeFi hacks H1 2026: audit coverage and incident data",
  "version": "1.0",
  "generated": "2026-07-01",
  "window": {
    "from": "2026-01-01",
    "to": "2026-06-29"
  },
  "record_count": 135,
  "total_lost_usd": 939855058,
  "incidents": [
    {
      "id": "H001",
      "protocol": "PRXVT",
      "hack_date": "2026-01-01",
      "amount_usd": 97000,
      "chains": [
        "Base"
      ],
      "victim_type": "token",
      "attack_type": "Sybil Attack via CREATE2 addresses on staking contract",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "BlockThreat (Peter Kacherginsky)",
          "kind": "security_firm",
          "url": "https://blockthreat.com/blockthreat-week-1-2026/"
        },
        {
          "publisher": "@AndreaPN (named X user)",
          "kind": "x",
          "url": "https://x.com/AndreaPN/status/2006741203480621182"
        }
      ]
    },
    {
      "id": "H002",
      "protocol": "TMX Tribe (TMXTribe)",
      "hack_date": "2026-01-05",
      "amount_usd": 1400000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "perp-dex",
      "attack_type": "Protocol logic / accounting flaw — mint-stake-swap-redeem loop (inflated AUM / GLP price)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "Rekt News",
          "kind": "rekt",
          "url": "https://rekt.news/tmztribe-rekt"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/tmx-tribe/"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://x.com/QuillAudits_AI/status/2008459614711386457"
        },
        {
          "publisher": "CertiK (CertiKAlert)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2008360565010559045"
        },
        {
          "publisher": "Bitcoin Ethereum News",
          "kind": "news",
          "url": "https://bitcoinethereumnews.com/finance/certik-flags-1-4m-exploit-linked-to-tmx-tribe-on-arbitrum/"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "news",
          "url": "https://smartcontractshacking.com/hacks/tmx-tribe-hack-2026"
        }
      ]
    },
    {
      "id": "H003",
      "protocol": "Fusion by IPOR",
      "hack_date": "2026-01-06",
      "amount_usd": 336000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "EIP-7702 delegation exploit combined with missing fuse validation",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "BlockSec",
          "audit_date": "2025/02/28",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1iqhAszOmUNUIuXuuAcwIHjL96de1zME5/view"
        },
        {
          "firm": "Protofire",
          "audit_date": "2024/09/06",
          "scope": "probable",
          "source_url": "https://drive.google.com/file/d/1UZE7J-pTfHY-XtgZtVYMAOh4tHXTCCN2/view"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "Fusion by IPOR (official X account)",
          "kind": "protocol",
          "url": "https://x.com/ipor_io/status/2008728627190321480"
        },
        {
          "publisher": "IPOR Labs (official post-mortem)",
          "kind": "protocol",
          "url": "https://blog.ipor.io/post-mortem-ipor-usdc-optimizer-arbitrum-vault-exploit-aff11fd01b62"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/01/07/ipors-fusion-plasmavault-hit-by-336k-exploit-via-eip-7702-flaw/"
        },
        {
          "publisher": "CryptoNews",
          "kind": "news",
          "url": "https://cryptonews.com/news/ipor-labs-loses-336k-in-arbitrum-vault-exploit-vows-full-refund/"
        }
      ]
    },
    {
      "id": "H004",
      "protocol": "Polycule (PCULE)",
      "hack_date": "2026-01-07",
      "amount_usd": 230000,
      "chains": [
        "Polygon"
      ],
      "victim_type": "other",
      "attack_type": "custodial exit scam / rug pull (claimed as 'hack' by team)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/polycule"
        },
        {
          "publisher": "@oxandrein (X)",
          "kind": "x",
          "url": "https://x.com/oxandrein/status/2026229652910727496"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/polycule-polymarket-bot-goes-offline/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/polycule-tg-bot-hacked-230000-in-user-funds-compromised-52040"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/polycule-users-unable-to-withdraw-funds-after-suspected-rug-pull-52868"
        },
        {
          "publisher": "KuCoin News",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/telegram-trading-bot-polycule-on-polymarket-hacked-230k-stolen"
        },
        {
          "publisher": "Odaily",
          "kind": "news",
          "url": "https://www.odaily.news/en/post/5208756"
        },
        {
          "publisher": "WEEX Crypto News",
          "kind": "news",
          "url": "https://www.weex.com/news/detail/polycule-suspected-rug-pull-team-previously-claimed-hack-attack-305023"
        }
      ]
    },
    {
      "id": "H005",
      "protocol": "Truebit Protocol",
      "hack_date": "2026-01-08",
      "amount_usd": 26440000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Integer overflow (unchecked addition) in bonding-curve mint pricing",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DeFi Planet (reporting SlowMist analysis)",
          "kind": "security_firm",
          "url": "https://defi-planet.com/2026/01/slowmist-gives-analysis-on-truebit-26m-exploit/"
        },
        {
          "publisher": "Olympix",
          "kind": "security_firm",
          "url": "https://olympixai.medium.com/truebit-26-6m-exploit-integer-overflow-and-the-cost-of-abandoned-code-84ed3aa64e43"
        },
        {
          "publisher": "KuCoin (reporting ExVul analysis)",
          "kind": "security_firm",
          "url": "https://www.kucoin.com/news/flash/truebit-protocol-hacked-for-26-44m-due-to-integer-overflow-vulnerability"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-truebit-hack-january-2026"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/markets/2026/01/09/truebit-token-tru-crashes-99-9-after-usd26-6m-exploit-drains-8-535-eth"
        },
        {
          "publisher": "Cointelegraph (cites CertiK & PeckShield)",
          "kind": "news",
          "url": "https://cointelegraph.com/news/26m-truebit-hack-smart-contract-vulnerability"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/truebit-hack-first-major-crypto-exploit-of-2026"
        },
        {
          "publisher": "DefiLlama (hacks dataset)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "Lookonchain (X)",
          "kind": "x",
          "url": "https://x.com/lookonchain/status/2009303499927154909"
        }
      ]
    },
    {
      "id": "H008",
      "protocol": "Makina (Makina Finance)",
      "hack_date": "2026-01-20",
      "amount_usd": 4130000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Flash-loan price/oracle manipulation",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "ChainSecurity",
          "audit_date": "2026/05/06",
          "scope": "confirmed",
          "source_url": "https://reports.chainsecurity.com/Makina/ChainSecurity_Makina_MakinaCoreSmartContracts_Audit.pdf"
        },
        {
          "firm": "OtterSec",
          "audit_date": "2025/10/29",
          "scope": "probable",
          "source_url": "https://github.com/MakinaHQ/makina-core/blob/main/audits/OtterSec_Makina_Report.pdf"
        },
        {
          "firm": "Sigma Prime",
          "audit_date": "2025/08",
          "scope": "probable",
          "source_url": "https://github.com/sigp/public-audits/blob/master/reports/makina/review.pdf"
        },
        {
          "firm": "Enigma Dark",
          "audit_date": "2025/07",
          "scope": "probable",
          "source_url": "https://github.com/Enigma-Dark/security-review-reports/blob/main/2025-07_Invariant_Testing_Engagement_Makina_Finance_Makina_Core.pdf"
        },
        {
          "firm": "Cantina",
          "audit_date": "2025/10/15",
          "scope": "out",
          "source_url": "https://cantina.xyz/competitions/2adf7150-27ba-4cba-86a2-bd8ea175e7da"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/makina-rekt"
        },
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://www.certik.com/resources/blog/makina-incident-analysis"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/analyzing-the-4m-makina-finance-exploit"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth"
        },
        {
          "publisher": "CryptoPotato",
          "kind": "news",
          "url": "https://cryptopotato.com/makina-finance-loses-4-13m-in-flash-loan-exploit-on-curve-pool/"
        },
        {
          "publisher": "Makina (official docs)",
          "kind": "protocol",
          "url": "https://docs.makina.finance/concepts/security/audits"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/makina"
        },
        {
          "publisher": "PeckShieldAlert",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2013468943193645085"
        },
        {
          "publisher": "CertiKAlert",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2013473512116363734"
        },
        {
          "publisher": "SlowMist_Team",
          "kind": "x",
          "url": "https://x.com/SlowMist_Team/status/2013506241776230897"
        }
      ]
    },
    {
      "id": "H170",
      "protocol": "SynapLogic",
      "hack_date": "2026-01-20",
      "amount_usd": 88000,
      "chains": [
        "Base"
      ],
      "victim_type": "token",
      "attack_type": "Input validation bypass with flash loan in token purchase contract",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "SlowMist (named security firm, original X post)",
          "kind": "security_firm",
          "url": "https://x.com/SlowMist_Team/status/2013448818365473101"
        },
        {
          "publisher": "CryptoNews.net",
          "kind": "news",
          "url": "https://cryptonews.net/news/security/32305318/"
        },
        {
          "publisher": "Phemex News (sourcing CertiK)",
          "kind": "news",
          "url": "https://phemex.com/news/article/certik-identifies-193-suspicious-transactions-in-synaplogic-contract-54596"
        }
      ]
    },
    {
      "id": "H131",
      "protocol": "SagaEVM (Saga / @Sagaxyz__) precompile bridge exploit",
      "hack_date": "2026-01-21",
      "amount_usd": 7000000,
      "chains": [
        "SagaEVM",
        "Ethereum"
      ],
      "victim_type": "other",
      "attack_type": "infinite mint via EVM precompile bridge (fake IBC messages / ICS20 precompile state-handling flaw)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena (Zenith / C4 Zenith)",
          "audit_date": "2024/12",
          "scope": "out",
          "source_url": "https://github.com/zenith-security/reports/blob/main/reports/Sage%20-%20Zenith%20Audit%20Report.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/saga-rekt"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-sagaevm-hack-january-2026"
        },
        {
          "publisher": "Cosmos / cosmos-evm GitHub Security Advisory (ASA-2026-002)",
          "kind": "explorer",
          "url": "https://github.com/cosmos/evm/security/advisories/GHSA-54gx-3cgr-7mfm"
        },
        {
          "publisher": "Saga (Sagaxyz Medium)",
          "kind": "protocol",
          "url": "https://medium.com/sagaxyz/sagaevm-security-incident-investigation-update-29a1d2a6b0cd"
        },
        {
          "publisher": "Saga (@Sagaxyz__)",
          "kind": "protocol",
          "url": "https://x.com/Sagaxyz__/status/2014144936631738532"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/saga-pauses-sagaevm-after-7m-exploit"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/saga-evm-chain-paused-after-7m-contract-exploit-2026/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/saga-exploit-land-on-tornado-cash/"
        },
        {
          "publisher": "CryptoRank (audit attribution)",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/4cfc0-saga-launches-mainnet-2-0-partners-with-uniswap"
        },
        {
          "publisher": "CertiKAlert",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2014163278839337207"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/386638/sagaevm-suffers-exploit"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/saga-becomes-latest-victim-in-defi-hacking-spree/"
        },
        {
          "publisher": "Web3 is Going Great",
          "kind": "news",
          "url": "https://www.web3isgoinggreat.com/single/saga-exploit"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        }
      ]
    },
    {
      "id": "H011",
      "protocol": "Aperture Finance (Aperture LM)",
      "hack_date": "2026-01-25",
      "amount_usd": 3670000,
      "chains": [
        "Ethereum",
        "Arbitrum",
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Arbitrary external call abusing pre-existing ERC20/ERC721 token approvals",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Veridise",
          "audit_date": "2023/10/04",
          "scope": "out",
          "source_url": "https://veridise.com/audits-archive/company/aperture-finance/uniswap-v3-manta-pacific-deployment-2023-10-04/"
        },
        {
          "firm": "Narya.ai",
          "audit_date": "2023/07/03",
          "scope": "out",
          "source_url": "https://github.com/Aperture-Finance/uniswap-v3-automan/blob/main/audits/Narya.ai%20UniV3Automan%20Report%20July%203rd%202023.pdf"
        },
        {
          "firm": "Oak Security",
          "audit_date": "2022/06/27",
          "scope": "out",
          "source_url": "https://github.com/oak-security/audit-reports/blob/master/Aperture/2022-06-27%20Audit%20Report%20-%20Aperture%202%20v1.0.pdf"
        },
        {
          "firm": "Solidified",
          "audit_date": "2022/09/24",
          "scope": "out",
          "source_url": "https://github.com/solidified-platform/audits/blob/master/Audit%20Report%20-%20Aperture%20Finance.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "SolidityScan",
          "kind": "security_firm",
          "url": "https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33/"
        },
        {
          "publisher": "AMLBot",
          "kind": "security_firm",
          "url": "https://blog.amlbot.com/13-5m-lost-in-aperture-finance-swapnet-exploit-full-on-chain-breakdown/"
        },
        {
          "publisher": "Coinpedia",
          "kind": "news",
          "url": "https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/aperture-finance-hack-funds-tornado-cash/"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/aperture-finance-reports-v3-v4-contract-exploit-halts-front-end-functions/"
        },
        {
          "publisher": "KuCoin News",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/aperture-finance-and-swapnet-smart-contracts-hacked-17m-stolen"
        },
        {
          "publisher": "Aperture Finance (official docs)",
          "kind": "protocol",
          "url": "https://docs.aperture.finance/docs/transparency/security-audit"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/aperture-lm"
        }
      ]
    },
    {
      "id": "H142",
      "protocol": "SwapNet (DEX aggregator integrated into Matcha Meta / 0x)",
      "hack_date": "2026-01-25",
      "amount_usd": 16800000,
      "chains": [
        "Base",
        "BSC",
        "Arbitrum"
      ],
      "victim_type": "other",
      "attack_type": "arbitrary external call / approvals abuse (unvalidated call target -> transferFrom of pre-approved user funds)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/swapnet-exploit-analysis"
        },
        {
          "publisher": "Matcha Meta (official SwapNet incident post-mortem)",
          "kind": "protocol",
          "url": "https://meta.matcha.xyz/SwapNet-Incident-Post-Mortem"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/386986/matcha-meta-swapnet-incident"
        },
        {
          "publisher": "DL News",
          "kind": "news",
          "url": "https://www.dlnews.com/articles/defi/matcha-meta-users-lose-millions-after-security-breach-at-integrated-protocol/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/matcha-meta-swapnet-defi-exploit-loss/"
        },
        {
          "publisher": "@Harvesto12 (original candidate lead)",
          "kind": "x",
          "url": "https://x.com/Harvesto12/status/2017178965320884349"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/matcha"
        },
        {
          "publisher": "CoinGecko (X)",
          "kind": "x",
          "url": "https://x.com/coingecko/status/2015744320419070166"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2015608261119217671"
        },
        {
          "publisher": "SolidityScan",
          "kind": "security_firm",
          "url": "https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33/"
        },
        {
          "publisher": "AMLBot",
          "kind": "security_firm",
          "url": "https://blog.amlbot.com/13-5m-lost-in-aperture-finance-swapnet-exploit-full-on-chain-breakdown/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/matcha-meta-security-breach-16-8m-drained/"
        },
        {
          "publisher": "BlockThreat",
          "kind": "security_firm",
          "url": "https://blockthreat.com/blockthreat-week-4-2026/"
        },
        {
          "publisher": "SwapNet",
          "kind": "protocol",
          "url": "https://www.swap-net.xyz/"
        }
      ]
    },
    {
      "id": "H161",
      "protocol": "PGNLZ",
      "hack_date": "2026-01-27",
      "amount_usd": 100000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Burn mechanism exploit / price manipulation — attacker triggered a flawed burn function to drain PGNLZ from the PancakeSwap V2 pool, creating a reserve imbalance, then swapped to extract USDT",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-jan-25-feb-1-2026"
        },
        {
          "publisher": "CertiKAlert",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2016152047356121307"
        },
        {
          "publisher": "egw.news",
          "kind": "news",
          "url": "https://egw.news/crypto/news/32207/x-player-hit-with-717k-attack-similar-to-pgnlz-qMG8Zl10x"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/crypto-hacks-and-scams-january-2026/"
        }
      ]
    },
    {
      "id": "H138",
      "protocol": "XPlayer_Media",
      "hack_date": "2026-01-28",
      "amount_usd": 717000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Burn mechanism exploit — attacker called the privileged DynamicBurnPool() function to burn XPL directly from the PancakeSwap V2 liquidity pair, reducing reserves to near-zero, then drained USDT",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-jan-25-feb-1-2026"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/x-player-exploit-results-in-717000-theft-via-contract-burn-mechanism-56631"
        },
        {
          "publisher": "CertiKAlert",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2016533331257503824"
        },
        {
          "publisher": "egw.news",
          "kind": "news",
          "url": "https://egw.news/crypto/news/32207/x-player-hit-with-717k-attack-similar-to-pgnlz-qMG8Zl10x"
        }
      ]
    },
    {
      "id": "H012",
      "protocol": "Revert Lend",
      "hack_date": "2026-01-29",
      "amount_usd": 50000,
      "chains": [
        "Base"
      ],
      "victim_type": "lending",
      "attack_type": "Staked collateral exploit — attacker flash-loaned funds, minted an Aerodrome Slipstream NFT position as collateral, borrowed USDC against it, then exploited GaugeManager's execution path to unstake and drain the NFT while the loan remained active",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "PeckShield",
          "audit_date": "2024/08/16",
          "scope": "out",
          "source_url": "https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Revert-Lend-v1.0.pdf"
        },
        {
          "firm": "Hydn Security",
          "audit_date": "2024/02/28",
          "scope": "out",
          "source_url": "https://github.com/hydnsec/audits/blob/main/Revert%20Finance%20-%20Lend/HYDN%20-%20Revert%20Finance%20Lend%20Audit%20Report.pdf"
        },
        {
          "firm": "Code4rena",
          "audit_date": "2024/05/22",
          "scope": "out",
          "source_url": "https://code4rena.com/reports/2024-03-revert-lend"
        },
        {
          "firm": "Cantina",
          "audit_date": "2026/06/04",
          "scope": "out",
          "source_url": "https://github.com/revert-finance/lend/blob/aerodrome-slipstream/report_cli_cantina_efb6f308_f13b_4110_aff8_0d67181608dd_revert_finance.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "news",
          "url": "https://smartcontractshacking.com/hacks/revert-lend-hack-2026"
        },
        {
          "publisher": "Revert Finance",
          "kind": "protocol",
          "url": "https://docs.revert.finance/revert/resources/security"
        }
      ]
    },
    {
      "id": "H171",
      "protocol": "Gyroscope",
      "hack_date": "2026-01-30",
      "amount_usd": 807000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "stablecoin",
      "attack_type": "Arbitrary input / cross-chain bridge exploit — attacker called BridgeToken() bridging 1 wei GYD to the token contract address itself with malicious calldata, triggering approve() to grant themselves unlimited GYD approval, then used transferFrom() to drain 6M GYD",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Nethermind",
          "audit_date": "2024/06/25",
          "scope": "probable",
          "source_url": "https://raw.githubusercontent.com/gyrostable/audit-reports/main/Nethermind/NM0255_GYROSCOPE%20_FINAL.pdf"
        },
        {
          "firm": "Trail of Bits",
          "audit_date": "2022/09/15",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/gyrostable/audit-reports/main/Trail%20of%20Bits/Summary%20Report%20%26%20Fix%20Review%20-%20Gyroscope.pdf"
        },
        {
          "firm": "Runtime Verification",
          "audit_date": "2022/04/27",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/gyrostable/audit-reports/main/Runtime%20Verification/Gyroscope_Protocol_Audit_Report.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "GyroStable (protocol)",
          "kind": "protocol",
          "url": "https://x.com/GyroStable/status/2017546048114250219"
        },
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://www.certik.com/skynet-report/gyroscope-incident-analysis"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/gyroscope-governance-floats-resolution-path-after-gyd-contract-incident/"
        },
        {
          "publisher": "Gyroscope (GitHub)",
          "kind": "protocol",
          "url": "https://github.com/gyrostable/audit-reports"
        }
      ]
    },
    {
      "id": "H013",
      "protocol": "Step Finance",
      "hack_date": "2026-01-31",
      "amount_usd": 40000000,
      "chains": [
        "Solana"
      ],
      "victim_type": "other",
      "attack_type": "Private key / treasury wallet compromise (off-chain signing infrastructure)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-step-finance-hack-january-2026"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters"
        },
        {
          "publisher": "BleepingComputer",
          "kind": "news",
          "url": "https://www.bleepingcomputer.com/news/security/step-finance-says-compromised-execs-devices-led-to-40m-crypto-theft/"
        },
        {
          "publisher": "CryptoPotato",
          "kind": "news",
          "url": "https://cryptopotato.com/the-end-of-step-finance-how-a-wallet-compromise-killed-the-solana-defi-aggregator/"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/step-finance-shutdown-solana-january-hack-2026/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/step-finance"
        },
        {
          "publisher": "CertiK (CertiKAlert)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2017610781660217643"
        }
      ]
    },
    {
      "id": "H014",
      "protocol": "CrossCurve (formerly EYWA)",
      "hack_date": "2026-02-01",
      "amount_usd": 3000000,
      "chains": [
        "Ethereum",
        "Arbitrum"
      ],
      "victim_type": "bridge",
      "attack_type": "spoofed cross-chain message / missing source validation (access control)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "MixBytes",
          "audit_date": "2024/10/10",
          "scope": "out",
          "source_url": "https://github.com/mixbytes/audits_public/tree/master/EYWA/CLP"
        },
        {
          "firm": "Hexens",
          "audit_date": "2026/03/19",
          "scope": "out",
          "source_url": "https://hexens.io/audit-reports/eywa-crosscurve-oft-protocol-mar-2026"
        },
        {
          "firm": "SmartState",
          "audit_date": "2025/08/29",
          "scope": "out",
          "source_url": "https://smartstate.tech/sites/default/files/reports/crosscurve_metalayer_clp_smart_contract_audit_report_ver_1_2_august-2.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "Cantina",
          "kind": "security_firm",
          "url": "https://cantina.xyz/blog/crosscurve-bridge-hack-axelar-expressexecute"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-crosscurve-hack-february-2026"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/cross-curve-exploit"
        },
        {
          "publisher": "Olympix",
          "kind": "security_firm",
          "url": "https://olympixai.medium.com/crosscurve-exploit-post-mortem-1-4m-lost-to-a-missing-access-control-check-c128e0aeb360"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/387939/crosscurve-bridge-exploited-for-approximately-3-million-across-multiple-chains-via-spoofed-messages"
        },
        {
          "publisher": "CCN",
          "kind": "news",
          "url": "https://www.ccn.com/news/crypto/crosscurve-bridge-exploit-3m-cross-chain-risk-hack/"
        },
        {
          "publisher": "The Cyber Express",
          "kind": "news",
          "url": "https://thecyberexpress.com/crosscurve-bridge-3m-cyberattack/"
        },
        {
          "publisher": "CrossCurve (EYWA)",
          "kind": "protocol",
          "url": "https://crosscurve.medium.com/eywa-clp-security-audit-by-mixbytes-c4e966070103"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/crosscurve"
        }
      ]
    },
    {
      "id": "H127",
      "protocol": "SOF Token",
      "hack_date": "2026-02-14",
      "amount_usd": 248000,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "token",
      "attack_type": "Burn-before-sync flaw with flash loan price manipulation",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://www.certik.com/blog/sof-laxo-incident-analysis"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/02/27/flash-loan-attack-drains-438k-from-sof-and-laxo-on-bnb-chain/"
        },
        {
          "publisher": "CertiK",
          "kind": "x",
          "url": "https://x.com/CertiK/status/2027481668961874077"
        }
      ]
    },
    {
      "id": "H015",
      "protocol": "Moonwell Lending",
      "hack_date": "2026-02-15",
      "amount_usd": 1779045,
      "chains": [
        "Base",
        "Optimism"
      ],
      "victim_type": "lending",
      "attack_type": "Oracle misconfiguration / mispricing (price manipulation via faulty cbETH/USD feed) exploited by liquidation MEV bots",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Halborn",
          "audit_date": "2022/02/01",
          "scope": "out",
          "source_url": "https://github.com/HalbornSecurity/PublicReports/blob/master/Solidity%20Smart%20Contract%20Audits/Moonwell_Finance_Smart_Contract_Security_Audit_Report_Halborn_Final.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "Moonwell Governance Forum (official post-mortem)",
          "kind": "protocol",
          "url": "https://forum.moonwell.fi/t/mip-x43-cbeth-oracle-incident-summary/2068"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/390302/defi-lending-protocol-moonwell-hit-with-1-8-million-bad-debt-after-oracle-misconfiguration"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/moonwell-exploit-cbeth-oracle-misprice-ai-commits-testing-audits"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/02/18/ether-briefly-priced-at-usd1-on-defi-app-moonwell-glitch-triggering-usd1-8m-in-bad-debt"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/358374/oracle-error-leaves-defi-lender-moonwell-1-8-million-bad-debt"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/moonwell-lending"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/defi-meet-claude-moonwells-vibe-coded-oracle-in-1-8m-blowup/"
        }
      ]
    },
    {
      "id": "H017",
      "protocol": "Veil Cash",
      "hack_date": "2026-02-20",
      "amount_usd": 5690,
      "chains": [
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Misconfigured Groth16 verifier — forged zkSNARK proofs enabling unauthorized withdrawals",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2025/02/15",
          "scope": "out",
          "source_url": "https://github.com/pashov/audits/blob/master/team/pdf/VeilCash-security-review_2025-02-12.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/veil-cash-groth16-forgery/"
        },
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/default-settings"
        },
        {
          "publisher": "Pashov Audit Group",
          "kind": "x",
          "url": "https://x.com/PashovAuditGrp/status/2025598503255167195"
        },
        {
          "publisher": "DK27ss (community PoC)",
          "kind": "other",
          "url": "https://github.com/DK27ss/VeilCash-5K-PoC"
        }
      ]
    },
    {
      "id": "H016",
      "protocol": "IoTeX ioTube Bridge",
      "hack_date": "2026-02-21",
      "amount_usd": 8000000,
      "chains": [
        "Ethereum",
        "IoTeX"
      ],
      "victim_type": "bridge",
      "attack_type": "compromised private key (validator-owner key); malicious Validator contract upgrade bypassing signature/validation checks to control MintPool/TokenSafe",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2025161252620955965"
        },
        {
          "publisher": "Beosin",
          "kind": "security_firm",
          "url": "https://x.com/BeosinAlert/status/2025521268733485103"
        },
        {
          "publisher": "Forta Network",
          "kind": "security_firm",
          "url": "https://x.com/FortaNetwork/status/2027746788598313283"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/business/2026/02/23/iotex-bridge-exploit-sparks-debate-over-losses-and-recovery-prospects"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/02/22/iotex-confirms-4-3m-iotube-bridge-breach-validator-key-compromised/"
        },
        {
          "publisher": "IoTeX (official)",
          "kind": "protocol",
          "url": "https://x.com/iotex_io/status/2025824807120412842"
        },
        {
          "publisher": "Coinpedia",
          "kind": "news",
          "url": "https://coinpedia.org/news/iotex-suffers-8-million-hack-after-private-key-compromise/"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/iotex-hack-2026"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/iotex"
        }
      ]
    },
    {
      "id": "H018",
      "protocol": "YieldBlox (Blend V2 lending pool, Stellar)",
      "hack_date": "2026-02-22",
      "amount_usd": 10970000,
      "chains": [
        "Stellar"
      ],
      "victim_type": "lending",
      "attack_type": "Price oracle manipulation of a near-zero-liquidity collateral asset (USTRY) to overvalue collateral and drain a lending pool",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena",
          "audit_date": "2025/03/17",
          "scope": "out",
          "source_url": "https://github.com/blend-capital/blend-contracts-v2/blob/main/audits/Code4rena%20x%20Blend%20V2%20audit%20report.pdf"
        },
        {
          "firm": "Certora (engaged with Script3)",
          "audit_date": "2025/04",
          "scope": "out",
          "source_url": "https://github.com/blend-capital/blend-contracts-v2/blob/main/audits/Script3%20-%20Certora%20-%20Blend%20v2%20-%20Security%20Assessment%20Draft%20v3%20Report%20-%20April%202025.pdf"
        },
        {
          "firm": "Certora",
          "audit_date": "2025/06",
          "scope": "out",
          "source_url": "https://github.com/blend-capital/blend-contracts-v2/tree/main/audits"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/yieldblox-rekt"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/"
        },
        {
          "publisher": "Bankless",
          "kind": "news",
          "url": "https://www.bankless.com/read/news/lending-market-blend-suffers-10m-exploit"
        },
        {
          "publisher": "The Block (citing PeckShield)",
          "kind": "security_firm",
          "url": "https://www.theblock.co/post/391725/crypto-hack-losses-fell-to-26-5-million-in-february-amid-sharp-monthly-and-annual-declines-peckshield"
        },
        {
          "publisher": "Blend Capital (protocol docs)",
          "kind": "protocol",
          "url": "https://docs.blend.capital/users/general-faq"
        },
        {
          "publisher": "Blend Capital GitHub",
          "kind": "protocol",
          "url": "https://github.com/blend-capital/blend-contracts-v2/tree/main/audits"
        },
        {
          "publisher": "Code4rena",
          "kind": "security_firm",
          "url": "https://code4rena.com/audits/2025-02-blend-v2-audit-certora-formal-verification"
        },
        {
          "publisher": "MarcinRedStone (RedStone) on X",
          "kind": "x",
          "url": "https://x.com/MarcinRedStone/status/2026034195232182494"
        },
        {
          "publisher": "pashov on X",
          "kind": "x",
          "url": "https://x.com/pashov/status/2025938184903721015"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained"
        },
        {
          "publisher": "RektHQ (X)",
          "kind": "x",
          "url": "https://x.com/RektHQ/status/2027443286521319793"
        }
      ]
    },
    {
      "id": "H128",
      "protocol": "LAXO Token",
      "hack_date": "2026-02-22",
      "amount_usd": 190000,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "token",
      "attack_type": "Burn-before-sync flaw with flash loan price manipulation",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://www.certik.com/blog/sof-laxo-incident-analysis"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/laxo-token-exploit-amm-reserve-manipulation"
        },
        {
          "publisher": "Olympix",
          "kind": "security_firm",
          "url": "https://olympixai.medium.com/the-190k-laxo-token-exploit-how-a-flawed-burn-mechanism-drained-a-liquidity-pool-and-how-olympix-132d76cd013a"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/02/27/flash-loan-attack-drains-438k-from-sof-and-laxo-on-bnb-chain/"
        }
      ]
    },
    {
      "id": "H019",
      "protocol": "DGLD",
      "hack_date": "2026-02-23",
      "amount_usd": 250000,
      "chains": [
        "Base",
        "Ethereum"
      ],
      "victim_type": "token",
      "attack_type": "Infinite mint via phantom L1 deposit exploiting non-standard transferFrom return value in L1↔L2 bridge",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2026/03/12",
          "scope": "out",
          "source_url": "https://s3.eu-central-1.amazonaws.com/gtsa.s8/dgld/Hacken_DGLD_ETH_AuditMar2026.pdf"
        },
        {
          "firm": "Halborn",
          "audit_date": "2026/03/16",
          "scope": "out",
          "source_url": "https://s3.eu-central-1.amazonaws.com/gtsa.s8/dgld/Halborn_DGLD_ETH_AuditMar2026.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DGLD (protocol official)",
          "kind": "protocol",
          "url": "https://dgld.ch/news/post-incident-report-february-2026-exploit"
        },
        {
          "publisher": "DGLD (protocol official)",
          "kind": "protocol",
          "url": "https://dgld.ch/legal/smart-contract-audits"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        }
      ]
    },
    {
      "id": "H151",
      "protocol": "Holdstation",
      "hack_date": "2026-02-25",
      "amount_usd": 462000,
      "chains": [
        "World Chain",
        "BSC",
        "Berachain",
        "zkSync"
      ],
      "victim_type": "wallet",
      "attack_type": "Supply chain attack — attacker stole developer session token, bypassed 2FA, injected malicious code into application update",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Verichains",
          "audit_date": "2022/10/21",
          "scope": "out",
          "source_url": "https://github.com/verichains/public-audit-reports/blob/main/Verichains%20Public%20Audit%20Report%20-%20Holdstation%20Mobile%20Wallet%20-%20v1.0.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/holdstation-security-breach-462000-usdt-confirmed-stolen/"
        },
        {
          "publisher": "Bitget News",
          "kind": "news",
          "url": "https://www.bitget.com/amp/news/detail/12560605224859"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/february-2026-crypto-security-report-23-63-million-lost-across-12-reported-incidents/"
        },
        {
          "publisher": "HoldstationW (protocol)",
          "kind": "protocol",
          "url": "https://x.com/HoldstationW/status/2026691403305333124"
        }
      ]
    },
    {
      "id": "H023",
      "protocol": "FOOM Cash (Foom.Cash)",
      "hack_date": "2026-02-26",
      "amount_usd": 2260000,
      "chains": [
        "Ethereum",
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Forged zkSNARK (Groth16) withdrawal proofs via misconfigured verifier (delta2 == gamma2)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/the-unfinished-proof"
        },
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2026935120943526178"
        },
        {
          "publisher": "Beosin",
          "kind": "security_firm",
          "url": "https://x.com/BeosinAlert/status/2026949474065809838"
        },
        {
          "publisher": "SolidityScan",
          "kind": "security_firm",
          "url": "https://x.com/SolidityScan/status/2027889027274199186"
        },
        {
          "publisher": "Defimon Alerts (white-hat rescue coordination)",
          "kind": "x",
          "url": "https://x.com/DefimonAlerts/status/2027761569262682591"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/foom-cash-faces-2-3m-loss-in-exploit/"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/02/26/foomcash-loses-2-26m-in-copycat-zksnark-exploit/"
        },
        {
          "publisher": "DefiLlama (protocol id 6908; audits: 0, no audit_links)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/foom-cash"
        },
        {
          "publisher": "BaseScan (Foom Club: FOOM.Cash Lottery contract; 'No Contract Security Audit Submitted')",
          "kind": "explorer",
          "url": "https://basescan.org/address/0xdb203504ba1fea79164af3ceffba88c59ee8aafd"
        }
      ]
    },
    {
      "id": "H020",
      "protocol": "Ploutos Money",
      "hack_date": "2026-02-26",
      "amount_usd": 388000,
      "chains": [
        "Ethereum",
        "Hemi",
        "Arbitrum",
        "Hyperliquid",
        "Avalanche"
      ],
      "victim_type": "lending",
      "attack_type": "price oracle misconfiguration (BTC/USD Chainlink feed used to price USDC); admin/deployment config exploited 1 block after the misconfig tx",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CredShields",
          "audit_date": "2026/02/12",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/Credshields/audit-reports/dd56467855ab269df6884adec251e6a7d40c84c6/Ploutos_Final_Audit_Report.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "CertiK (CertiKAlert)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2026963490695487960"
        },
        {
          "publisher": "BlockSec Phalcon",
          "kind": "security_firm",
          "url": "https://x.com/Phalcon_xyz/status/2026943448734114011"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/defi-exploiter-targets-lending-protocols-with-oracle-tricks/"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/02/26/ploutos-money-supposedly-pulls-an-exit-scam-with-188-eth-exploit/"
        },
        {
          "publisher": "Live Bitcoin News (citing Hemi official incident blog)",
          "kind": "news",
          "url": "https://www.livebitcoinnews.com/hemi-confirms-ploutos-exploit-388k-gone-across-five-chains/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/ploutus-protocol-loses-390000-due-to-oracle-misconfiguration-62815"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/ploutos-money"
        },
        {
          "publisher": "CredShields",
          "kind": "security_firm",
          "url": "https://github.com/Credshields/audit-reports/blob/dd56467855ab269df6884adec251e6a7d40c84c6/Ploutos_Final_Audit_Report.pdf"
        }
      ]
    },
    {
      "id": "H160",
      "protocol": "Stake Nova",
      "hack_date": "2026-02-26",
      "amount_usd": 137014,
      "chains": [
        "Solana"
      ],
      "victim_type": "protocol",
      "attack_type": "Flash-loan exploit via unchecked validation in RedeemNovaSol() function",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/?c=Solana&page=1"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/february-2026-crypto-security-report-23-63-million-lost-across-12-reported-incidents/"
        },
        {
          "publisher": "SolidityScan",
          "kind": "security_firm",
          "url": "https://x.com/SolidityScan/status/2027805825058713942"
        }
      ]
    },
    {
      "id": "H021",
      "protocol": "Wise Lending V2",
      "hack_date": "2026-02-28",
      "amount_usd": 66000,
      "chains": [
        "Arbitrum",
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "Flashloan exploit — Protocol Logic",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena",
          "audit_date": "2024/03/11",
          "scope": "unknown",
          "source_url": "https://code4rena.com/audits/2024-02-wise-lending"
        },
        {
          "firm": "Hats Finance",
          "audit_date": "2024/02/19",
          "scope": "unknown",
          "source_url": "https://github.com/hats-finance/Wise-Lending-0xa2ca45d6e249641e595d50d1d9c69c9e3cd22573/blob/master/report.md"
        }
      ],
      "verification": "likely",
      "independent_source_count": 1,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/wise-lending-v2"
        }
      ]
    },
    {
      "id": "H022",
      "protocol": "Curve LlamaLend (sDOLA-long2)",
      "hack_date": "2026-03-02",
      "amount_usd": 240567,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "Oracle manipulation via donation attack (flash loan + DolaSavings.stake() to inflate sDOLA spot price, triggering hard liquidations)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Statemind",
          "audit_date": "2024/02/02",
          "scope": "out",
          "source_url": "https://github.com/statemindio/public-audits/blob/main/Curve/2024-02-02_Curve_Lending.pdf"
        },
        {
          "firm": "MixBytes",
          "audit_date": "2024/09/02",
          "scope": "out",
          "source_url": "https://github.com/mixbytes/audits_public/blob/master/Curve%20Finance/Curve%20Lending/Curve%20Lending%20Security%20Audit%20Report.pdf"
        },
        {
          "firm": "ChainSecurity",
          "audit_date": "2025/02/21",
          "scope": "out",
          "source_url": "https://www.chainsecurity.com/reports/Curve/ChainSecurity_Curve_CurveStablecoin_Audit.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Curve Finance Governance (official post-mortem)",
          "kind": "protocol",
          "url": "https://gov.curve.finance/t/llamalend-sdola-long2-post-mortem/11020"
        },
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/sdola-llamalend-oracle-manipulation/"
        },
        {
          "publisher": "CryptoRank",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/b396e-dola-price-manipulation-causes-240k-llamalend-users-loss-inverse-finance-unaffected"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/curve-investigates-attack-on-sdola-llamalend-market-63826"
        }
      ]
    },
    {
      "id": "H024",
      "protocol": "Solv Protocol (SolvBTC BRO Vault)",
      "hack_date": "2026-03-05",
      "amount_usd": 2700000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Self-reentrancy double-mint via ERC-3525/ERC-721 onERC721Received callback (missing nonReentrant)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/solv-rekt"
        },
        {
          "publisher": "Verichains (LCD)",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/solv-protocol-hack-analysis"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/solv-bro-double-mint/"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-solv-hack-march-2026"
        },
        {
          "publisher": "Hypernative",
          "kind": "security_firm",
          "url": "https://www.hypernative.io/blog/how-hypernatives-alert-saved-10m-in-the-solv-protocol-exploit"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/392492/solv-protocol-says-exploit-drained-2-7-million-from-bitcoin-yield-vault"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/hacker-steals-nearly-3-million-from-solv-protocol"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/solv-protocol-exploit-drains-2-7m-in-solvbtc-10-bounty-offered/"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/solvbtc-hack-2026"
        },
        {
          "publisher": "NomosLabs",
          "kind": "other",
          "url": "https://nomoslabs.io/archive/solv-protocol-2026"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/solvbtc"
        },
        {
          "publisher": "Solv Finance Audit repo (GitHub)",
          "kind": "protocol",
          "url": "https://github.com/solv-finance/Audit"
        }
      ]
    },
    {
      "id": "H025",
      "protocol": "Molt EVM (mEVM)",
      "hack_date": "2026-03-08",
      "amount_usd": 101000,
      "chains": [
        "Base"
      ],
      "victim_type": "token",
      "attack_type": "Access control bypass: onlySpawnerToken modifier trivially bypassed by deploying a stub contract whose initialized() returns true, enabling unlimited minting",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "NomosLabs",
          "kind": "security_firm",
          "url": "https://nomoslabs.io/archive/molt-evm-2026"
        },
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/molt-evm-weak-spawner-access-control/"
        }
      ]
    },
    {
      "id": "H026",
      "protocol": "Gondi V3 (PurchaseBundler)",
      "hack_date": "2026-03-09",
      "amount_usd": 230000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Access control bypass in PurchaseBundler.executeSell(): missing borrower identity check allowed attacker to drain NFTs using victim approvals",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena",
          "audit_date": "2024/04/16",
          "scope": "out",
          "source_url": "https://github.com/code-423n4/2024-04-gondi (scope README) / final report https://code4rena.com/reports/2024-04-gondi"
        },
        {
          "firm": "Code4rena (Mitigation Review)",
          "audit_date": "2024/05/24",
          "scope": "out",
          "source_url": "https://code4rena.com/audits/2024-05-gondi-mitigation-review"
        },
        {
          "firm": "Halborn",
          "audit_date": "2024/05/03",
          "scope": "out",
          "source_url": "https://docs.gondi.xyz/gondi-v3/security-and-audits — Halborn report PDF https://drive.google.com/file/d/1w_o5mZkJL0AItg1MbWzx8tevgONm_Yte/view"
        },
        {
          "firm": "Zenith",
          "audit_date": "2025/02/04",
          "scope": "probable",
          "source_url": "https://drive.google.com/file/d/140tc97VA_-YdPmJ1aH606fzVtOIMy7a_/view (Zenith 'Gondi Sell & Repay' report, published Feb 4 2025) — note also a separate Zenith V3.1 report https://github.com/zenith-security/reports/blob/main/reports/Gondi%20-%20Zenith%20Audit%20Report.pdf which is a different, NON-covering scope"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/gondi-purchasebundler-drain/"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/392909/nft-platform-gondi-moves-users-whole-230000-contract-exploit"
        },
        {
          "publisher": "DEV Community (cryip)",
          "kind": "other",
          "url": "https://dev.to/cryip/gondi-nft-lending-platform-hack-a-detailed-report-489c"
        },
        {
          "publisher": "NoSmokeSport",
          "kind": "news",
          "url": "https://nosmokesport.com/crypto-news/gondi-nft-protocol-exploit-restitution/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/gondi-v3"
        }
      ]
    },
    {
      "id": "H027",
      "protocol": "Aave V3",
      "hack_date": "2026-03-10",
      "amount_usd": 862000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "CAPO Oracle Misconfiguration (configuration error by Chaos Labs risk oracle operator; not a deliberate external exploit)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Certora",
          "audit_date": "2024/03",
          "scope": "probable",
          "source_url": "https://github.com/aave-dao/aave-price-feeds/blob/main/security/Certora/CAPO%20report.pdf"
        },
        {
          "firm": "Trail of Bits",
          "audit_date": "2021/11/29",
          "scope": "out",
          "source_url": "https://github.com/aave/aave-v3-core/blob/master/audits/07-01-2022_TrailOfBits_AaveV3.pdf"
        },
        {
          "firm": "OpenZeppelin",
          "audit_date": "2020/01/15",
          "scope": "out",
          "source_url": "https://www.openzeppelin.com/news/aave-protocol-audit"
        },
        {
          "firm": "Oxorio",
          "audit_date": "2025/01/29",
          "scope": "out",
          "source_url": "https://oxor-io.github.io/public_audits/Aave/Aave-v3.3.0-Audit-Report.pdf"
        },
        {
          "firm": "Sherlock",
          "audit_date": "2025/01/22",
          "scope": "out",
          "source_url": "https://github.com/sherlock-audit/2025-01-aave-v3-3"
        },
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2025/11/29",
          "scope": "out",
          "source_url": "https://github.com/pashov/audits/blob/master/team/md/Aave-security-review_2025-11-29.md"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "Aave Governance",
          "kind": "protocol",
          "url": "https://governance.aave.com/t/post-mortem-exchange-rate-misallignment-on-wsteth-core-and-prime-instances/24269"
        },
        {
          "publisher": "Rekt News",
          "kind": "rekt",
          "url": "https://rekt.news/aave-rekt"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/amp/post/393121/aave-oracle-glitch-wsteth"
        },
        {
          "publisher": "Yahoo Finance / CryptoNews",
          "kind": "news",
          "url": "https://finance.yahoo.com/news/aave-oracle-glitch-causes-27m-123639335.html"
        }
      ]
    },
    {
      "id": "H028",
      "protocol": "Stake DAO (Votemarket peripheral oracle)",
      "hack_date": "2026-03-12",
      "amount_usd": 176000,
      "chains": [
        "Arbitrum",
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Oracle Message Spoofing — peripheral oracle update contract exploited to drain rewards",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "ChainSecurity",
          "audit_date": "2023/01/17",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/stake-dao/audits/main/votemarket/v1/2023-01-01_chainsecurity_votemarket_v1.pdf"
        },
        {
          "firm": "Trust Security",
          "audit_date": "2024/09/10",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/stake-dao/audits/main/votemarket/v2/2024-09-01_trust_security_votemarket_v2.pdf"
        },
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2024/10/24",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/stake-dao/audits/main/votemarket/v2/laposte/2024-10-01_pashov_laposte.pdf"
        },
        {
          "firm": "Zach Obront (independent)",
          "audit_date": "2023/05/26",
          "scope": "out",
          "source_url": "https://github.com/zobront/audits/blob/main/reports/stakedao.md"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Stake DAO (official account)",
          "kind": "protocol",
          "url": "https://x.com/StakeDAOHQ/status/2032489716629578004"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/stake-dao-hit-by-hack-as-defi-security-confidence-hits-new-low/"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/stake-dao-hack-2026"
        }
      ]
    },
    {
      "id": "H029",
      "protocol": "Goose Finance",
      "hack_date": "2026-03-14",
      "amount_usd": 8435,
      "chains": [
        "BSC"
      ],
      "victim_type": "protocol",
      "attack_type": "Share Accounting Flaw",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2021/02/21",
          "scope": "out",
          "source_url": "https://www.goosedefi.com/files/hackenAudit.pdf"
        },
        {
          "firm": "CertiK",
          "audit_date": "2021/10/12",
          "scope": "out",
          "source_url": "https://skynet.certik.com/projects/goose-finance"
        }
      ],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/goose-finance"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/goose-finance-hack-2026"
        },
        {
          "publisher": "DefimonAlerts on X",
          "kind": "x",
          "url": "https://x.com/DefimonAlerts/status/2032836162046316868"
        }
      ]
    },
    {
      "id": "H030",
      "protocol": "Venus Protocol (Core Pool) — THE/Thena market donation attack",
      "hack_date": "2026-03-15",
      "amount_usd": 3700000,
      "chains": [
        "BSC"
      ],
      "victim_type": "lending",
      "attack_type": "Donation attack / vToken exchange-rate inflation (supply-cap bypass via direct token transfer to vTHE; getCashPrior reads raw balanceOf)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "PeckShield",
          "audit_date": "2023/07/18",
          "scope": "out",
          "source_url": "https://docs-v4.venus.io/links/security-and-audits"
        },
        {
          "firm": "CertiK",
          "audit_date": "2023/08/03",
          "scope": "out",
          "source_url": "https://docs-v4.venus.io/links/security-and-audits"
        },
        {
          "firm": "OpenZeppelin",
          "audit_date": "2023/08/17",
          "scope": "out",
          "source_url": "https://www.openzeppelin.com/news/venus-protocol-diamond-comptroller-audit"
        },
        {
          "firm": "Quantstamp",
          "audit_date": "2023/09/18",
          "scope": "out",
          "source_url": "https://docs-v4.venus.io/links/security-and-audits"
        },
        {
          "firm": "Fairyproof",
          "audit_date": "2023/06/25",
          "scope": "out",
          "source_url": "https://docs-v4.venus.io/links/security-and-audits"
        },
        {
          "firm": "Code4rena",
          "audit_date": "2023/08/09",
          "scope": "out",
          "source_url": "https://code4rena.com/reports/2023-05-venus"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/venus-protocol-rekt4"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/venus-thena-donation-attack"
        },
        {
          "publisher": "Venus Protocol (official governance)",
          "kind": "protocol",
          "url": "https://community.venus.io/t/the-market-incident-post-mortem/5712"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/venus-5m-exploit"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/03/16/venus-protocol-hit-by-3-7m-supply-cap-attack-key-markets-paused/"
        },
        {
          "publisher": "Code4rena",
          "kind": "security_firm",
          "url": "https://code4rena.com/reports/2023-05-venus"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/venus-core-pool"
        }
      ]
    },
    {
      "id": "H031",
      "protocol": "dTRINITY dLEND",
      "hack_date": "2026-03-17",
      "amount_usd": 257328,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "liquidity-index inflation via flash-loan premium accrual on an empty reserve (Aave V3 fork)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Verichains",
          "audit_date": "2024/06/17",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1Q58ewyXYxWTpbUoGct6Rdl4PuvJQD1N9/view"
        },
        {
          "firm": "Halborn",
          "audit_date": "2024/10/04",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1WJSIYMoLZLeQ5ix9gxKYqRrzePowU2BO/view"
        },
        {
          "firm": "Cyberscope",
          "audit_date": "2024/10/21",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/13K-vwkwb3NJKhSa3eaBf1rVeSscHxAxY/view"
        },
        {
          "firm": "Hats Finance",
          "audit_date": "2025/08/22",
          "scope": "out",
          "source_url": "https://github.com/hats-finance/dTRINITY-0xee5c6f15e8d0b55a5eff84bb66beeee0e6140ffe/blob/report-update-20250822T111243728Z/report.md"
        },
        {
          "firm": "Hashlock",
          "audit_date": "2025/10",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1iVIOl8xwNr__d9J_gArV-xZlHidBDst3/view"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "dTRINITY (official docs)",
          "kind": "protocol",
          "url": "https://docs.dtrinity.org/developer-guide/audits-and-security"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/deep-dive-into-the-dtribity-cbbtc"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/dtrinity-dlend-index-manipulation/"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026"
        },
        {
          "publisher": "NomosLabs",
          "kind": "security_firm",
          "url": "https://nomoslabs.io/archive/dtrinity-2026"
        },
        {
          "publisher": "dTRINITY (official X)",
          "kind": "protocol",
          "url": "https://x.com/dTRINITY_DeFi/status/2036267791733477788"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/defi-lending-protocol-dtrinity-suffers-260000-exploit-67152"
        },
        {
          "publisher": "KuCoin News",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/dtrinity-dlend-on-ethereum-hit-by-deposit-inflation-attack-causing-257-000-bad-debt"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/dtrinity-dlend"
        }
      ]
    },
    {
      "id": "H032",
      "protocol": "Neutrl",
      "hack_date": "2026-03-18",
      "amount_usd": null,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "stablecoin",
      "attack_type": "DNS / frontend hijack (Permit2 wallet-approval phishing via redirected domain)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Spearbit",
          "audit_date": "2025/08/04",
          "scope": "out",
          "source_url": "https://docs.neutrl.finance/pdf/report-cantinacode-neutrl-2407.pdf"
        },
        {
          "firm": "Cantina",
          "audit_date": "2025/07/17",
          "scope": "out",
          "source_url": "https://cantina.xyz/portfolio/8595495c-8763-42d2-baaa-d2b9bc7d7ab0"
        },
        {
          "firm": "Sherlock",
          "audit_date": "2025/09/12",
          "scope": "out",
          "source_url": "https://audits.sherlock.xyz/contests/1065"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "Smart Contract Hacking",
          "kind": "rekt",
          "url": "https://smartcontractshacking.com/hacks/neutrl-hack-2026"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/03/19/neutrl-defi-pauses-smart-contracts-amid-suspected-dns-frontend-hijack/"
        },
        {
          "publisher": "CryptoNewsZ",
          "kind": "news",
          "url": "https://www.cryptonewsz.com/neutrl-front-end-attack-update-urgent-security/"
        },
        {
          "publisher": "PANews",
          "kind": "news",
          "url": "https://www.panewslab.com/en/articles/019d0f98-33ac-76cd-9ed3-35fdc6ef1292"
        },
        {
          "publisher": "DefiLlama (hacks API)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "Neutrl (official docs - audits)",
          "kind": "protocol",
          "url": "https://docs.neutrl.finance/resources-and-ecosystem/audits"
        },
        {
          "publisher": "bitcoinearly (X)",
          "kind": "x",
          "url": "https://x.com/bitcoinearly/status/2034893837190246614"
        },
        {
          "publisher": "AnchoredFi (X)",
          "kind": "x",
          "url": "https://x.com/AnchoredFi/status/2039089299484778738"
        }
      ]
    },
    {
      "id": "H168",
      "protocol": "ShiMamaProtocol",
      "hack_date": "2026-03-18",
      "amount_usd": 30000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Missing Access Control",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://x.com/SlowMist_Team/status/2034473400081813877"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026"
        }
      ]
    },
    {
      "id": "H033",
      "protocol": "Resolv Labs (USR stablecoin)",
      "hack_date": "2026-03-22",
      "amount_usd": 24500000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "stablecoin",
      "attack_type": "Compromised privileged signing key (SERVICE_ROLE held in AWS KMS, controlled by a single EOA) obtained via a software supply-chain attack; attacker called completeSwap() with inflated mint amounts. The on-chain minting/Counter contract enforced no maximum-mint limit, no oracle check, and no deposit-to-mint ratio validation, so ~80M unbacked USR were minted from ~$100-200K USDC deposits.",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2024/12/09",
          "scope": "out",
          "source_url": "https://github.com/pashov/audits/blob/master/team/md/Resolv-security-review_2024-12-09.md"
        },
        {
          "firm": "Sherlock",
          "audit_date": "2024/12/02",
          "scope": "out",
          "source_url": "https://github.com/sherlock-protocol/sherlock-reports/blob/main/audits/2024.12.02%20-%20Final%20-%20Resolv%20Core%20Audit%20Report.pdf"
        },
        {
          "firm": "MixBytes",
          "audit_date": "2024/12/20",
          "scope": "out",
          "source_url": "https://github.com/mixbytes/audits_public/blob/master/Resolv/PoR%20Oracles/README.md"
        },
        {
          "firm": "Pessimistic",
          "audit_date": "2024/06",
          "scope": "out",
          "source_url": "https://docs.resolv.xyz/litepaper/resources/security"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/resolv-labs-rekt"
        },
        {
          "publisher": "Chainalysis",
          "kind": "security_firm",
          "url": "https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/361984/resolv-labs-stablecoin-depegs-plunges-74-after-25m-exploit"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/394582/resolvs-usr-stablecoin-depegs-after-attacker-mints-80-million-unbacked-tokens-extracts-roughly-25-million"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/resolv-says-no-assets-lost-as-defi-partners-respond-to-usr-depeg"
        },
        {
          "publisher": "Resolv Labs",
          "kind": "protocol",
          "url": "https://docs.resolv.xyz/litepaper/resources/security.md"
        },
        {
          "publisher": "Pashov Audit Group",
          "kind": "security_firm",
          "url": "https://github.com/pashov/audits/blob/master/team/md/Resolv-security-review-October.md"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/resolv"
        },
        {
          "publisher": "Cyvers",
          "kind": "x",
          "url": "https://x.com/CyversAlerts/status/2035640521524146636"
        }
      ]
    },
    {
      "id": "H034",
      "protocol": "Cyrus Finance (CyrusTreasury)",
      "hack_date": "2026-03-22",
      "amount_usd": 5000000,
      "chains": [
        "BSC"
      ],
      "victim_type": "protocol",
      "attack_type": "Oracle/price manipulation via flash loan (PancakeSwap V3 spot-price, no TWAP)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CertiK",
          "audit_date": "2025/11/17",
          "scope": "unknown",
          "source_url": "https://skynet.certik.com/projects/cyrus-finance"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/cyrus-price-manipulation/"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/cyrus-finance-hack-2026"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/peckshield/status/2035820631711744478"
        },
        {
          "publisher": "CertiK Skynet",
          "kind": "security_firm",
          "url": "https://skynet.certik.com/projects/cyrus-finance"
        },
        {
          "publisher": "Cyrus Finance",
          "kind": "protocol",
          "url": "https://www.cyrusfinance.net/"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/how-cyrus-finance-is-positioning-itself-as-the-best-usdt-yield-platform/"
        }
      ]
    },
    {
      "id": "H035",
      "protocol": "GoonFi",
      "hack_date": "2026-03-28",
      "amount_usd": 254000,
      "chains": [
        "Solana"
      ],
      "victim_type": "protocol",
      "attack_type": "Mispricing Arbitrage (Protocol Logic Bug)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/goonfi"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/?c=Solana&page=1"
        },
        {
          "publisher": "SmartContractHacking.com",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/goonfi-hack-2026"
        }
      ]
    },
    {
      "id": "H037",
      "protocol": "Drift Protocol",
      "hack_date": "2026-04-01",
      "amount_usd": 285000000,
      "chains": [
        "Solana"
      ],
      "victim_type": "perp-dex",
      "attack_type": "Admin/multisig private key compromise via months-long DPRK social engineering (durable-nonce abuse to obtain pre-signed multisig txns), followed by fake-token (CVT) listing with attacker-controlled oracle and parameter/withdrawal-limit changes to drain vaults",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Trail of Bits",
          "audit_date": "2023/02/15",
          "scope": "out",
          "source_url": "https://docs.drift.trade/security/audits"
        },
        {
          "firm": "Neodyme",
          "audit_date": "2024/05/10",
          "scope": "out",
          "source_url": "https://cdn.prod.website-files.com/6310e7dee49f0866da8eed4c/6686bbdfe7c6e5a997cc51bc_Neodyme%20-%20Drift%20Security%20Audit.pdf"
        },
        {
          "firm": "Zellic",
          "audit_date": "2022/02/16",
          "scope": "out",
          "source_url": "https://github.com/Zellic/publications/blob/master/Drift%20Protocol%20Audit%20Report.pdf"
        },
        {
          "firm": "OtterSec",
          "audit_date": "2023/08/04",
          "scope": "out",
          "source_url": "https://docs.drift.trade/security/audits"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "Chainalysis",
          "kind": "security_firm",
          "url": "https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"
        },
        {
          "publisher": "TRM Labs",
          "kind": "security_firm",
          "url": "https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"
        },
        {
          "publisher": "Elliptic",
          "kind": "security_firm",
          "url": "https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"
        },
        {
          "publisher": "QuillAudits",
          "kind": "security_firm",
          "url": "https://www.quillaudits.com/blog/hack-analysis/drift-protocol-multisig-exploit"
        },
        {
          "publisher": "Bloomberg",
          "kind": "news",
          "url": "https://www.bloomberg.com/news/articles/2026-04-01/solana-based-defi-project-drift-hit-by-285-million-exploit"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/04/02/how-a-solana-feature-designed-for-convenience-let-an-attacker-drain-usd270-million-from-drift"
        },
        {
          "publisher": "Unchained",
          "kind": "news",
          "url": "https://unchainedcrypto.com/drift-protocol-suffers-285-million-exploit-after-admin-key-compromise-and-oracle-manipulation-unchained/"
        },
        {
          "publisher": "Drift Protocol (official docs)",
          "kind": "protocol",
          "url": "https://docs.drift.trade/protocol/risk-and-safety/audits"
        },
        {
          "publisher": "Drift Protocol (Trail of Bits audit page)",
          "kind": "protocol",
          "url": "https://www.drift.trade/audit"
        },
        {
          "publisher": "DefiLlama (id 970, Drift Trade)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/drift"
        },
        {
          "publisher": "PeckShieldAlert",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2039546185120387169"
        }
      ]
    },
    {
      "id": "H135",
      "protocol": "LML/USDT Staking Protocol",
      "hack_date": "2026-04-01",
      "amount_usd": 950000,
      "chains": [
        "BSC"
      ],
      "victim_type": "protocol",
      "attack_type": "price manipulation via flash loan",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/"
        },
        {
          "publisher": "PANews (citing BlockSec)",
          "kind": "security_firm",
          "url": "https://www.panewslab.com/en/articles/019d478c-6698-7558-9ba6-fcded9dc4486"
        },
        {
          "publisher": "KuCoin",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/bsc-chain-lml-usdt-staking-protocol-suffers-price-manipulation-attack-losses-reach-950-000"
        },
        {
          "publisher": "Bitget (citing BlockSec)",
          "kind": "news",
          "url": "https://www.bitget.com/news/detail/12560605325066"
        },
        {
          "publisher": "MrBreadSmith",
          "kind": "x",
          "url": "https://x.com/MrBreadSmith/status/2049517575827267848"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-30-apr-5-2026"
        }
      ]
    },
    {
      "id": "H130",
      "protocol": "Silo V2",
      "hack_date": "2026-04-03",
      "amount_usd": 392000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "lending",
      "attack_type": "Oracle misconfiguration (immutable wstUSR oracle at stale price ~1.133 vs market ~0.12) combined with supply cap bypass via receiver parameter and totalAssets() accounting flaw that counted externally credited bUSDC shares without minting corresponding soUSDC shares",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Certora",
          "audit_date": "2025/04",
          "scope": "confirmed",
          "source_url": "https://docs.silo.finance/assets/files/Certora_Silo_Vault_Audit_Report-18f189172bc797604545b1fed1f44cfd.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-30-apr-5-2026"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/attacks/oracle-manipulation-attacks"
        },
        {
          "publisher": "Global Ledger",
          "kind": "news",
          "url": "https://blog.globalledger.io/research-investigations/hackers-steal-642m-in-april-set-2026-record"
        },
        {
          "publisher": "EvanLuthra (X)",
          "kind": "x",
          "url": "https://x.com/EvanLuthra/status/2045669602282422317"
        }
      ]
    },
    {
      "id": "H038",
      "protocol": "TMM/USDT (BSC) reserve manipulation exploit",
      "hack_date": "2026-04-04",
      "amount_usd": 1665000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "reserve/price manipulation via flash loans (constant-product AMM reserve donation/burn)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "ExVul (exvulsec)",
          "kind": "security_firm",
          "url": "https://x.com/exvulsec/status/2040649377803546859"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-tmm-hack-april-2026"
        },
        {
          "publisher": "SlowMist Hacked database",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/?c=BSC&page=1"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/bsc-network-hit-by-tmmusdt-reserve-manipulation-attack-1665-million-lost-71016"
        },
        {
          "publisher": "Bitget News / Foresight News",
          "kind": "news",
          "url": "https://www.bitget.com/news/detail/12560605337534"
        },
        {
          "publisher": "CoinCentral",
          "kind": "news",
          "url": "https://coincentral.com/crypto-hacks-surge-over-a-dozen-defi-protocols-attacked-since-280m-drift-protocol-exploit/"
        }
      ]
    },
    {
      "id": "H039",
      "protocol": "Aethir (AethirOFTAdapter bridge exploit)",
      "hack_date": "2026-04-09",
      "amount_usd": 423000,
      "chains": [
        "BNB Chain",
        "TRON",
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "Access control exploit (unprotected transferOwnership ownership takeover on cross-chain OFT adapter)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2042441698559868970"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/aethir-bridge-exploit-halt-user-compensation-90k-loss"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/10/aethir-adapter-hack-drains-400k-funds-moved-to-tron/"
        },
        {
          "publisher": "DEV Community (technical postmortem)",
          "kind": "other",
          "url": "https://dev.to/cryip/aethir-adapter-exploit-complete-technical-postmortem-report-1001"
        },
        {
          "publisher": "Traders Union",
          "kind": "news",
          "url": "https://tradersunion.com/news/cryptocurrency-news/show/1909527-aethir-slides-7-14percent-to-usd0-006/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/aethir"
        }
      ]
    },
    {
      "id": "H040",
      "protocol": "SubQuery Network",
      "hack_date": "2026-04-12",
      "amount_usd": 131000,
      "chains": [
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "access control",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2022/04/06",
          "scope": "probable",
          "source_url": "https://raw.githubusercontent.com/subquery/network-contracts/develop/audits/SubQuery_Pte_Ltd_16022022SCAudit_Report.pdf"
        },
        {
          "firm": "SlowMist",
          "audit_date": "2024/02/29",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/subquery/network-contracts/develop/audits/SlowMist%20Audit%20Report%20-%20subquery-network-contracts.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "SubQuery Network (protocol disclosure)",
          "kind": "protocol",
          "url": "https://subquery.ghost.io/subquery-network-security-incident-report/"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/subquery-settings-access-control-staking-drain/"
        },
        {
          "publisher": "pashov (auditor, X)",
          "kind": "x",
          "url": "https://x.com/pashov/status/2043354433686237679"
        },
        {
          "publisher": "Defi Nerd (X)",
          "kind": "x",
          "url": "https://x.com/Defi_Nerd_sec/status/2043522897084629484"
        },
        {
          "publisher": "EvanLuthra (X, candidate evidence)",
          "kind": "x",
          "url": "https://x.com/EvanLuthra/status/2045669602282422317"
        }
      ]
    },
    {
      "id": "H041",
      "protocol": "Hyperbridge (Polytope Labs) Token Gateway / MMR Verifier exploit",
      "hack_date": "2026-04-13",
      "amount_usd": 2500000,
      "chains": [
        "Ethereum",
        "Base",
        "BNB Chain",
        "Arbitrum"
      ],
      "victim_type": "bridge",
      "attack_type": "cross-chain message forgery via forged Merkle Mountain Range (MMR) state proof -> admin takeover of bridged DOT token contract -> infinite mint of 1B fake DOT -> dumped into DEX liquidity",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Security Research Labs (SRLabs)",
          "audit_date": "2026/05/12",
          "scope": "out",
          "source_url": "https://github.com/srlabs/audit-reports/blob/master/Polkadot/SRL-Polytope-Solidity-MMR_audit-v1.2.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Hyperbridge / Polytope Labs (official post-mortem)",
          "kind": "protocol",
          "url": "https://blog.hyperbridge.network/april-13-post-mortem/"
        },
        {
          "publisher": "Hyperbridge / Polytope Labs (official security update)",
          "kind": "protocol",
          "url": "https://blog.hyperbridge.network/security-update-forged-proofs/"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/04/13/attacker-mints-usd1-billion-polkadot-tokens-on-ethereum-ends-up-stealing-just-usd250-000"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/397773/polkadot-hyperbridge-exploit-losses-2-5-million-ten-times-initial-estimate"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/polkadot-hyperbridge-ethereum-gateway-exploit-sjb0ql"
        },
        {
          "publisher": "Verichains (security firm root-cause analysis)",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/how-a-missing-bounds-check-led-to"
        },
        {
          "publisher": "CoinMarketCap / CertiK alert",
          "kind": "security_firm",
          "url": "https://coinmarketcap.com/academy/article/hyperbridge-exploit-mints-1b-dot-tokens-in-attack-certik-reports"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/hyperbridge-exploit-losses-revised-25m/"
        },
        {
          "publisher": "Wikipedia",
          "kind": "other",
          "url": "https://en.wikipedia.org/wiki/Hyperbridge"
        },
        {
          "publisher": "@hyperbridge (official X disclosure)",
          "kind": "x",
          "url": "https://x.com/hyperbridge/status/2047271354047594620"
        },
        {
          "publisher": "@CertiKAlert",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2043557571609731268"
        }
      ]
    },
    {
      "id": "H043",
      "protocol": "Dango Perps",
      "hack_date": "2026-04-13",
      "amount_usd": 410000,
      "chains": [
        "Dango Mainnet",
        "Ethereum"
      ],
      "victim_type": "perp-dex",
      "attack_type": "Protocol logic flaw — insurance fund donation function did not validate amount > 0 (negative/sign error); attacker 'donated' a negative amount to reverse fund flow and drain USDC collateral from the perps contract",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Sherlock",
          "audit_date": "2025/09/29",
          "scope": "out",
          "source_url": "https://audits.sherlock.xyz/contests/1066"
        },
        {
          "firm": "Zellic",
          "audit_date": "2025/04/07",
          "scope": "out",
          "source_url": "https://docs.dango.exchange/audits/20241025-zellic-jmt.pdf"
        },
        {
          "firm": "Informal Systems",
          "audit_date": "2025/03/05",
          "scope": "out",
          "source_url": "https://informal.systems/blog/jellyfish-merkle-tree-quint-2025"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CryptoIntegrat",
          "kind": "news",
          "url": "https://www.cryptointegrat.com/p/dango-perps-protocol-exploited-for"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/dango-exploit-resolved-after-white-hat-returns-funds-users-unaffected/"
        },
        {
          "publisher": "PANews",
          "kind": "news",
          "url": "https://www.panewslab.com/en/articles/019d898e-f42a-739c-ab2a-3e26b912bbdf"
        },
        {
          "publisher": "Live Bitcoin News",
          "kind": "news",
          "url": "https://www.livebitcoinnews.com/april-2026-crypto-hacks-hit-620m-as-bridge-failures-and-admin-exploits-dominate-attacks/"
        },
        {
          "publisher": "TheStreet",
          "kind": "news",
          "url": "https://www.thestreet.com/crypto/markets/major-defi-hack-becomes-the-largest-of-2026-yet"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/dango-perps"
        },
        {
          "publisher": "Dango (official docs)",
          "kind": "protocol",
          "url": "https://dango-4.gitbook.io/dango-docs/audits"
        },
        {
          "publisher": "Sherlock",
          "kind": "security_firm",
          "url": "https://audits.sherlock.xyz/contests/1066"
        },
        {
          "publisher": "EvanLuthra (X)",
          "kind": "x",
          "url": "https://x.com/EvanLuthra/status/2045669602282422317"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H044",
      "protocol": "Zerion",
      "hack_date": "2026-04-14",
      "amount_usd": 100000,
      "chains": [
        "Unknown"
      ],
      "victim_type": "wallet",
      "attack_type": "Social engineering / employee device & credential compromise (hot wallet drain). AI-enabled spear-phishing attributed to DPRK threat actor UNC1069; attacker obtained logged-in sessions, credentials, and private keys to internal testing/operational hot wallets.",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Trail of Bits",
          "audit_date": "2020/12/18",
          "scope": "out",
          "source_url": "https://github.com/zeriontech/defi-sdk/blob/master/audits/Zerion%20DeFi%20SDK%20Trail%20of%20Bits%20Audit%20Report.pdf"
        },
        {
          "firm": "PeckShield",
          "audit_date": "2020/08/31",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/158GG-J681xAc4d8pMibpP_SFJikX4HPM/view?usp=sharing"
        },
        {
          "firm": "Cube53",
          "audit_date": null,
          "scope": "out",
          "source_url": "https://zerion.io/security"
        },
        {
          "firm": "Secfault Security",
          "audit_date": null,
          "scope": "out",
          "source_url": "https://zerion.io/security"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "Zerion (official security page)",
          "kind": "protocol",
          "url": "https://zerion.io/security"
        },
        {
          "publisher": "FinanceFeeds",
          "kind": "news",
          "url": "https://financefeeds.com/north-korean-hackers-behind-100k-zerion-exploit/"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/15/north-korean-hackers-target-zerion-in-ai-driven-attack-steal-100k/"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/zerion-hit-by-ai-enabled-social-engineering-as-north-korean-hackers-target-human-layer/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/zerion-claims-no-user-funds-were-affected-as-employee-loses-100k-in-social-engineering-attack/"
        },
        {
          "publisher": "Coin Edition",
          "kind": "news",
          "url": "https://coinedition.com/zerion-disables-web-app-after-100k-internal-wallet-breach/"
        },
        {
          "publisher": "Crypto Economy",
          "kind": "news",
          "url": "https://crypto-economy.com/zerion-says-user-funds-are-safe-after-employee-loses-100k-in-social-engineering-attack/"
        },
        {
          "publisher": "DefiLlama (protocol metadata, id 4049 'Zerion Wallet', category Wallets, audits=0)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/zerion"
        },
        {
          "publisher": "@EvanLuthra (X lead)",
          "kind": "x",
          "url": "https://x.com/EvanLuthra/status/2045669602282422317"
        },
        {
          "publisher": "@grok (X lead)",
          "kind": "x",
          "url": "https://x.com/grok/status/2045738258299072546"
        }
      ]
    },
    {
      "id": "H148",
      "protocol": "CoW Swap (CoW Protocol) cow.fi domain hijack",
      "hack_date": "2026-04-14",
      "amount_usd": 1200000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "other",
      "attack_type": "DNS / domain hijack (registrar-level) leading to frontend phishing / wallet-drainer; NOT a smart-contract exploit",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Gnosis / G0 Group",
          "audit_date": "2021/05",
          "scope": "out",
          "source_url": "https://github.com/cowprotocol/contracts/blob/main/audits/GnosisProtocolV2May2021.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "CoW Swap / CoW DAO (official post-mortem)",
          "kind": "protocol",
          "url": "https://x.com/CoWSwap/article/2044924940886163780"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/397432/cow-swap-pauses-protocol-amid-domain-hijacking"
        },
        {
          "publisher": "The Cryptonomist",
          "kind": "news",
          "url": "https://en.cryptonomist.ch/2026/04/17/cow-swap-domain-hijack/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/cow-swap-experienced-dns-hijacking/"
        },
        {
          "publisher": "Domain Name Wire",
          "kind": "news",
          "url": "https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/"
        },
        {
          "publisher": "CryptoRank",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/264ca-cow-swap-domain-hijacking-attack-loss"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/cow-swap-frontend-flagged-in-potential-attack-users-warned-to-avoid-platform/"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H042",
      "protocol": "MONA (BurnAddress deferred-LP-burn token, BSC)",
      "hack_date": "2026-04-14",
      "amount_usd": 60950,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "accounting bug / deferred burn LP reserve manipulation",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/burnaddress-mona-deferred-lp-burn/"
        },
        {
          "publisher": "MEXC News",
          "kind": "news",
          "url": "https://www.mexc.com/news/1031060"
        },
        {
          "publisher": "jussy_world (X)",
          "kind": "x",
          "url": "https://x.com/jussy_world/status/2044684951891898473"
        },
        {
          "publisher": "grok (X)",
          "kind": "x",
          "url": "https://x.com/grok/status/2045738258299072546"
        }
      ]
    },
    {
      "id": "H045",
      "protocol": "Grinex",
      "hack_date": "2026-04-16",
      "amount_usd": 15000000,
      "chains": [
        "Tron",
        "Ethereum"
      ],
      "victim_type": "cex",
      "attack_type": "Hot wallet breach / exchange infrastructure compromise (private key or operational compromise of internet-connected wallets)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "TRM Labs",
          "kind": "security_firm",
          "url": "https://www.trmlabs.com/resources/blog/sanctioned-russian-exchange-grinex-and-kyrgyzstani-exchange-tokenspot-hit-in-usd-15-million-theft"
        },
        {
          "publisher": "Chainalysis",
          "kind": "security_firm",
          "url": "https://www.chainalysis.com/blog/sanctioned-grinex-exchange-suspends-operations/"
        },
        {
          "publisher": "Elliptic",
          "kind": "security_firm",
          "url": "https://www.elliptic.co/blog/sanctioned-russia-linked-crypto-exchange-grinex-halts-operations-following-alleged-hack"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/397814/russia-linked-grinex-exchange-suspends-operations-15-million-hack-hostile-states"
        },
        {
          "publisher": "The Hacker News",
          "kind": "news",
          "url": "https://thehackernews.com/2026/04/1374m-hack-shuts-down-sanctioned-grinex.html"
        },
        {
          "publisher": "Crowdfund Insider",
          "kind": "news",
          "url": "https://www.crowdfundinsider.com/2026/04/273911-sanctioned-crypto-platform-grinex-hit-by-15-million-cyber-theft-with-ties-to-kyrgyz-exchange-tokenspot/"
        },
        {
          "publisher": "DefiLlama (hacks dataset)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        }
      ]
    },
    {
      "id": "H046",
      "protocol": "Rhea Finance (Burrowland / Rhea Lend)",
      "hack_date": "2026-04-16",
      "amount_usd": 18400000,
      "chains": [
        "Near"
      ],
      "victim_type": "lending",
      "attack_type": "protocol logic bug — margin-trading slippage/open-position validation flaw exploited via fake token pools (fake collateral)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "BlockSec",
          "audit_date": "2024/05/22",
          "scope": "out",
          "source_url": "https://guide.rhea.finance/developers/audits (BlockSec 'Margin Trading' report, dated April 2 2025, GitBook file id bRauJPLPLTkMvauBoRD3, artifact 'burrow_margin_trading_v1.0')"
        },
        {
          "firm": "Trail of Bits",
          "audit_date": "2025/02/19",
          "scope": "out",
          "source_url": "https://guide.rhea.finance/developers/audits (Trail of Bits 'Smart Contract' report, February 19 2025, GitBook file id uhyvS5HhlEhebmyT7bQJ)"
        },
        {
          "firm": "Resonance",
          "audit_date": "2025/10/09",
          "scope": "out",
          "source_url": "https://github.com/ResonanceCybersecurity/audits"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Rekt News",
          "kind": "rekt",
          "url": "https://rekt.news/rhea-finance-rekt"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/397961/rhea-finance-post-mortem-exploit-losses-18-4-million-double-initial-estimates"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/rhea-finance-revises-exploit-losses-to-18-4m-confirms-slippage-flaw-as-funds-partially-recovered/"
        },
        {
          "publisher": "CoinEdition",
          "kind": "news",
          "url": "https://coinedition.com/18-4m-rhea-finance-hack-built-over-two-days-post-mortem-reveals/"
        },
        {
          "publisher": "Rhea Finance (official post-mortem)",
          "kind": "protocol",
          "url": "https://rhea-finance.medium.com/a-post-mortem-on-the-ref-finance-exploit-what-happened-9f6140bafde6"
        },
        {
          "publisher": "CryptoTimes / CertiK Alert",
          "kind": "security_firm",
          "url": "https://www.cryptotimes.io/2026/04/16/rhea-finance-loses-7-6m-in-exploit-says-certik/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/rhea-lend"
        },
        {
          "publisher": "Rhea Finance (audits page)",
          "kind": "protocol",
          "url": "https://guide.rhea.finance/developers/audits"
        }
      ]
    },
    {
      "id": "H047",
      "protocol": "Kelp DAO (rsETH) LayerZero bridge exploit",
      "hack_date": "2026-04-18",
      "amount_usd": 292000000,
      "chains": [
        "Ethereum",
        "Unichain",
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "Cross-chain bridge exploit via forged LayerZero v2 message (compromised 1-of-1 DVN / off-chain RPC infrastructure)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Sigma Prime",
          "audit_date": "2024/11",
          "scope": "out",
          "source_url": "https://kerneldao.com/kelp/audits/smartcontracts/Sigma_Prime_hgETH.pdf"
        },
        {
          "firm": "Code4rena",
          "audit_date": "2023/11/15",
          "scope": "out",
          "source_url": "https://code4rena.com/audits/2023-11-kelp-dao-rseth (scope via https://github.com/code-423n4/2023-11-kelp README)"
        },
        {
          "firm": "BailSec",
          "audit_date": "2026/05",
          "scope": "out",
          "source_url": "https://www.banklesstimes.com/articles/2026/05/13/kelp-dao-aave-restart-rseth-operations-after-292m-exploit/"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Chainalysis",
          "kind": "security_firm",
          "url": "https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"
        },
        {
          "publisher": "LayerZero (incident statement)",
          "kind": "protocol",
          "url": "https://layerzero.network/blog/kelpdao-incident-statement"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"
        },
        {
          "publisher": "DL News",
          "kind": "news",
          "url": "https://www.dlnews.com/articles/defi/why-crypto-bridges-are-defis-weakest-link-after-293m-kelp-dao-hack/"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/401060/kelp-dao-aave-resume-rseth"
        },
        {
          "publisher": "rekt.news (leaderboard #10)",
          "kind": "rekt",
          "url": "https://rekt.news/leaderboard"
        },
        {
          "publisher": "DefiLlama Hacks API (id 3946)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "Sigma Prime (rsETH Adapter report)",
          "kind": "security_firm",
          "url": "https://kerneldao.com/kelp/audits/smartcontracts/Sigma_Prime_hgETH.pdf"
        },
        {
          "publisher": "Code4rena",
          "kind": "security_firm",
          "url": "https://code4rena.com/audits/2023-11-kelp-dao-rseth"
        },
        {
          "publisher": "Hypernative",
          "kind": "security_firm",
          "url": "https://hypernative.io/insights/blog/the-kelpdao-observation-layer-exploit-291m-released-on-a-message-that-never-existed"
        }
      ]
    },
    {
      "id": "H048",
      "protocol": "Thetanuts Finance",
      "hack_date": "2026-04-20",
      "amount_usd": 50000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "First Depositor Attack on vault initialization — attacker mints 1 share, donates large amount directly to contract to manipulate asset-to-share ratio, then redeems inflated share when next depositor interacts",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Halborn",
          "audit_date": "2023/11",
          "scope": "unknown",
          "source_url": "https://docs.thetanuts.finance/contracts-and-security/security"
        },
        {
          "firm": "Consensys Diligence",
          "audit_date": "2023/11",
          "scope": "out",
          "source_url": "https://docs.thetanuts.finance/contracts-and-security/security"
        },
        {
          "firm": "PeckShield",
          "audit_date": "2022/05/28",
          "scope": "out",
          "source_url": "https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Thetanuts-v1.0.pdf"
        },
        {
          "firm": "Zokyo",
          "audit_date": "2022/03",
          "scope": "unknown",
          "source_url": "https://docs.thetanuts.finance/contracts-and-security/security"
        },
        {
          "firm": "X41 D-Sec",
          "audit_date": "2021/12/14",
          "scope": "out",
          "source_url": "https://www.x41-dsec.de/static/reports/X41-Audit-Thetanuts-2021-11-Public-Report.pdf"
        },
        {
          "firm": "Akira Tech",
          "audit_date": "2022/03",
          "scope": "unknown",
          "source_url": "https://docs.thetanuts.finance/contracts-and-security/security"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/thetanuts-finance"
        },
        {
          "publisher": "TeleSwap Academy",
          "kind": "news",
          "url": "https://academy.teleswap.xyz/defi-protocol-hacks-april-2026-exploits-analyzed/"
        },
        {
          "publisher": "ChainSec",
          "kind": "other",
          "url": "https://www.chainsec.io/defi-hacks"
        },
        {
          "publisher": "Thetanuts Finance (protocol docs)",
          "kind": "protocol",
          "url": "https://docs.thetanuts.finance/contracts-and-security/security"
        },
        {
          "publisher": "stacy_muur",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        }
      ]
    },
    {
      "id": "H165",
      "protocol": "Juicebox V3",
      "hack_date": "2026-04-20",
      "amount_usd": 52000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "borrowFrom spoof / unregistered accounting source (REVLoans extension on Juicebox V3)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CertiK",
          "audit_date": "2022/03/29",
          "scope": "out",
          "source_url": "https://docs.juicebox.money/assets/files/certik-audit-report-12b48328d22ac38207dad74162cac1db.pdf"
        },
        {
          "firm": "PeckShield",
          "audit_date": "2022/04/08",
          "scope": "out",
          "source_url": "https://docs.juicebox.money/assets/files/peckshield-audit-report-ab36ee2b5dfb2a387410b4d64276f6ba.pdf"
        },
        {
          "firm": "Code4rena (Juicebox V3 NFT Delegate, Oct 2022)",
          "audit_date": "2022/10/23",
          "scope": "out",
          "source_url": "https://code4rena.com/reports/2022-10-juicebox"
        },
        {
          "firm": "Bernd Artmueller (independent — V3 Migration: JBV3Token, JBV3TokenDeployer only)",
          "audit_date": "2023/01",
          "scope": "out",
          "source_url": "https://hackmd.io/@berndartmueller/2023-01-juice-v3-migration"
        },
        {
          "firm": "Code4rena",
          "audit_date": "2022/10/23",
          "scope": "out",
          "source_url": "https://code4rena.com/reports/2022-10-juicebox"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/juicebox-v3"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-roundup-2026-04-26"
        },
        {
          "publisher": "TeleSwap Academy",
          "kind": "news",
          "url": "https://academy.teleswap.xyz/defi-protocol-hacks-april-2026-exploits-analyzed/"
        },
        {
          "publisher": "stacy_muur",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        }
      ]
    },
    {
      "id": "H050",
      "protocol": "Volo (Volo Protocol / Volo Vault) — Sui vault exploit",
      "hack_date": "2026-04-21",
      "amount_usd": 3500000,
      "chains": [
        "Sui",
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "private key compromise (privileged admin/operator key)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2023/09/22",
          "scope": "out",
          "source_url": "https://hacken.io/audits/volo/"
        },
        {
          "firm": "MoveBit",
          "audit_date": "2023/09/07",
          "scope": "out",
          "source_url": "https://movebit.xyz/reports/Volo-Smart-Contract-Audit-Report.pdf"
        },
        {
          "firm": "OtterSec",
          "audit_date": "2023/10/20",
          "scope": "out",
          "source_url": "https://www.volosui.com/volo-audit-final.pdf"
        },
        {
          "firm": "Veridise",
          "audit_date": "2025/05/02",
          "scope": "out",
          "source_url": "https://github.com/Sui-Volo/volo-smart-contracts/blob/main/audit/Volo_V2_Increment_Veridise_2025.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "Rekt News",
          "kind": "rekt",
          "url": "https://rekt.news/volo-rekt"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/398393/sui-volo-protocol-exploited"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/markets/2026/04/22/another-defi-protocol-loses-millions-in-hack-days-after-kelpdao-breach"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/volo-protocol-sui-vault-exploit/"
        },
        {
          "publisher": "Blockonomi",
          "kind": "news",
          "url": "https://blockonomi.com/volo-protocol-security-breach-3-5m-drained-from-sui-based-liquid-staking-platform/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/volo-vault"
        },
        {
          "publisher": "Volo (official docs)",
          "kind": "protocol",
          "url": "https://volosui.gitbook.io/volo/introduction/contract-audits"
        },
        {
          "publisher": "MrBreadSmith (X)",
          "kind": "x",
          "url": "https://x.com/MrBreadSmith/status/2049517575827267848"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H163",
      "protocol": "Kipseli",
      "hack_date": "2026-04-22",
      "amount_usd": 72350,
      "chains": [
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Output token validation failure / decimals mismatch (USDC 6-decimal quote used as raw cbBTC 8-decimal transfer amount)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-roundup-2026-04-26"
        },
        {
          "publisher": "TeleSwap Academy",
          "kind": "news",
          "url": "https://academy.teleswap.xyz/defi-protocol-hacks-april-2026-exploits-analyzed/"
        },
        {
          "publisher": "Kipseli (protocol docs)",
          "kind": "protocol",
          "url": "https://docs.kipseli.capital/"
        },
        {
          "publisher": "stacy_muur",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        },
        {
          "publisher": "ChainSec",
          "kind": "other",
          "url": "https://www.chainsec.io/defi-hacks"
        },
        {
          "publisher": "0xD4N0 (X)",
          "kind": "x",
          "url": "https://x.com/D4NOGOTHACKED/status/2046883409906040858"
        }
      ]
    },
    {
      "id": "H134",
      "protocol": "Giddy (GiddyVaultV3)",
      "hack_date": "2026-04-23",
      "amount_usd": 1300000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "smart contract exploit — authorization bypass / signature replay",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-roundup-2026-04-26"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/when-signing-is-not-secure"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/giddyvaultv3-signature-replay/"
        },
        {
          "publisher": "SlowMist (Hacked DB)",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/en/?c=ETH"
        },
        {
          "publisher": "DefiLlama Hacks DB",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "TeleSwap Academy",
          "kind": "news",
          "url": "https://academy.teleswap.xyz/defi-protocol-hacks-april-2026-exploits-analyzed/"
        },
        {
          "publisher": "Giddy (official site — now shows 'Giddy Shutdown')",
          "kind": "protocol",
          "url": "https://giddy.co/"
        },
        {
          "publisher": "@MrBreadSmith (X)",
          "kind": "x",
          "url": "https://x.com/MrBreadSmith/status/2049517575827267848"
        },
        {
          "publisher": "@FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        },
        {
          "publisher": "DefiLlama (hacks API)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        }
      ]
    },
    {
      "id": "H053",
      "protocol": "Purrlend",
      "hack_date": "2026-04-25",
      "amount_usd": 1520000,
      "chains": [
        "Hyperliquid L1",
        "MegaETH"
      ],
      "victim_type": "lending",
      "attack_type": "access control / privileged-role abuse (admin multisig takeover -> BRIDGE_ROLE granted to attacker EOA -> mintUnbacked of unbacked pUSDm/pUSDC used as collateral to borrow real assets)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CD Security",
          "audit_date": "2026/02",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/CDSecurity/audits/main/audit%20reports/Purrlend.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/purrlend"
        },
        {
          "publisher": "Purrlend (official audit repo)",
          "kind": "protocol",
          "url": "https://github.com/Purrlend/Purrlend-AUDIT"
        },
        {
          "publisher": "CD Security",
          "kind": "security_firm",
          "url": "https://github.com/CDSecurity/audits"
        },
        {
          "publisher": "LiveBitcoinNews / Blockonomi",
          "kind": "news",
          "url": "https://www.livebitcoinnews.com/purrlend-exploit-steals-1-5m-on-hyperevm-and-megaeth/"
        },
        {
          "publisher": "MEXC News",
          "kind": "news",
          "url": "https://www.mexc.com/news/1053473"
        },
        {
          "publisher": "OurCryptoTalk",
          "kind": "news",
          "url": "https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit"
        },
        {
          "publisher": "Bitget News / Odaily",
          "kind": "news",
          "url": "https://www.bitget.com/asia/news/detail/12560605393515"
        },
        {
          "publisher": "Yahoo Finance / TheStreet",
          "kind": "news",
          "url": "https://finance.yahoo.com/markets/crypto/articles/another-defi-platform-just-got-122925586.html"
        },
        {
          "publisher": "AInvest",
          "kind": "news",
          "url": "https://www.ainvest.com/news/purrlend-exploit-1-5m-drain-l2s-part-800m-april-defi-bloodbath-2604/"
        },
        {
          "publisher": "MrBreadSmith (X)",
          "kind": "x",
          "url": "https://x.com/MrBreadSmith/status/2049517575827267848"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H054",
      "protocol": "Scallop (Scallop Lend)",
      "hack_date": "2026-04-26",
      "amount_usd": 142000,
      "chains": [
        "Sui"
      ],
      "victim_type": "lending",
      "attack_type": "smart contract exploit (flash-loan-assisted reward drain + oracle/price-feed manipulation)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "OtterSec",
          "audit_date": "2023/07/15",
          "scope": "out",
          "source_url": "https://docs.scallop.io/protocol/auditing (PDF: en/.gitbook/assets/Scallop_Audit.pdf in github.com/scallop-io/docs)"
        },
        {
          "firm": "MoveBit",
          "audit_date": "2023/06/30",
          "scope": "out",
          "source_url": "https://docs.scallop.io/protocol/auditing (PDF: en/.gitbook/assets/Scallop Smart Contract Audit Report.pdf in github.com/scallop-io/docs)"
        },
        {
          "firm": "Zellic",
          "audit_date": "2024/04/19",
          "scope": "out",
          "source_url": "https://docs.scallop.io/protocol/auditing (PDF: en/.gitbook/assets/Scallop - Zellic Audit Report.pdf in github.com/scallop-io/docs)"
        },
        {
          "firm": "Asymptotic",
          "audit_date": "2025/12/02",
          "scope": "out",
          "source_url": "https://docs.scallop.io/protocol/auditing (GitBook file /files/c4DaB94au2v6LbyVgMSK)"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/sui-based-scallop-hit-by-flash-loan-attack-142k-lost/"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/27/scallop-loses-142k-in-flash-loan-attack-on-deprecated-contract/"
        },
        {
          "publisher": "Blockonomi",
          "kind": "news",
          "url": "https://blockonomi.com/scallop-defi-exploit-exposes-deprecated-contract-risk-amid-april-2026s-606m-loss-streak"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/scallop-sui-defi-exploit-150k/"
        },
        {
          "publisher": "MoneyCheck",
          "kind": "news",
          "url": "https://moneycheck.com/scallop-protocol-suffers-142k-loss-after-exploiter-drains-deprecated-sui-contract"
        },
        {
          "publisher": "Grafa",
          "kind": "news",
          "url": "https://grafa.com/en/news/crypto/scallop-sui-exploit-150k-loss"
        },
        {
          "publisher": "TronWeekly",
          "kind": "news",
          "url": "https://www.tronweekly.com/scallop-resumes-after-270k-ssul-exploit/"
        },
        {
          "publisher": "Scallop (official docs)",
          "kind": "protocol",
          "url": "https://docs.scallop.io/protocol/auditing"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/scallop-lend"
        },
        {
          "publisher": "awesome-move-security (GitHub)",
          "kind": "other",
          "url": "https://github.com/Monethic/awesome-move-security"
        },
        {
          "publisher": "stacy_muur (X)",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        },
        {
          "publisher": "MrBreadSmith (X)",
          "kind": "x",
          "url": "https://x.com/MrBreadSmith/status/2049517575827267848"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H057",
      "protocol": "ZetaChain GatewayEVM/GatewayZEVM cross-chain exploit",
      "hack_date": "2026-04-26",
      "amount_usd": 333868,
      "chains": [
        "Ethereum",
        "BSC",
        "Base",
        "Arbitrum"
      ],
      "victim_type": "bridge",
      "attack_type": "smart contract logic flaw (chained access-control + arbitrary-call + unrevoked ERC20 approvals); NOT a private key compromise",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Cantina",
          "audit_date": "2025/04/15",
          "scope": "probable",
          "source_url": "https://github.com/zeta-chain/audit-reports/blob/main/15-04-2025%20Cantina%20Protocol%20Audit%20Report.pdf"
        },
        {
          "firm": "Sherlock",
          "audit_date": "2025/07/11",
          "scope": "out",
          "source_url": "https://github.com/zeta-chain/audit-reports/blob/main/2025-07-11%20-%20%20Sherlock%20Zetachain%20Public%20Audit%20Contest.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "SolidityScan",
          "kind": "security_firm",
          "url": "https://blog.solidityscan.com/zetachain-gateway-hack-analysis/"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/29/how-a-perfect-storm-of-3-bugs-led-to-zetachains-333k-gatewayevm-exploit/"
        },
        {
          "publisher": "MEXC News",
          "kind": "news",
          "url": "https://www.mexc.com/news/1061680"
        },
        {
          "publisher": "BanklessTimes",
          "kind": "news",
          "url": "https://www.banklesstimes.com/articles/2026/04/28/zetachain-halts-cross-chain-transfers-after-300k-gatewayevm-exploit/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/did-zetachain-ignore-a-bug-report-that-could-have-prevented-334k-exploit/"
        },
        {
          "publisher": "TodayQ News",
          "kind": "protocol",
          "url": "https://news.todayq.com/zetachain-blocks-gatewayevm-attack-launches-investigation/"
        },
        {
          "publisher": "ZetaChain (official audit-reports repo)",
          "kind": "protocol",
          "url": "https://github.com/zeta-chain/audit-reports"
        },
        {
          "publisher": "Cantina",
          "kind": "security_firm",
          "url": "https://cantina.xyz/competitions/80a33cf0-ad69-4163-a269-d27756aacb5e"
        },
        {
          "publisher": "Sherlock",
          "kind": "security_firm",
          "url": "https://audits.sherlock.xyz/contests/857"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/zetachain"
        },
        {
          "publisher": "stacy_muur (X)",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        },
        {
          "publisher": "FabianoSolana (X)",
          "kind": "x",
          "url": "https://x.com/FabianoSolana/status/2049825541352509929"
        }
      ]
    },
    {
      "id": "H055",
      "protocol": "Litecoin",
      "hack_date": "2026-04-26",
      "amount_usd": null,
      "chains": [
        "Litecoin"
      ],
      "victim_type": "other",
      "attack_type": "zero-day vulnerability exploitation and DoS/DDoS",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "The Cyber Express",
          "kind": "news",
          "url": "https://thecyberexpress.com/litecoin-network-zero-day-bug/"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/markets/2026/04/26/litecoin-says-its-13-block-reorg-was-not-a-zero-day-but-github-commit-history-shows-otherwise"
        },
        {
          "publisher": "CybersecurityNews",
          "kind": "news",
          "url": "https://cybersecuritynews.com/litecoin-zero-day-vulnerability-exploited/"
        },
        {
          "publisher": "Security Boulevard",
          "kind": "news",
          "url": "https://securityboulevard.com/2026/04/litecoin-zero-day-vulnerability-exploited-in-dos-attack-disrupts-major-mining-pools/"
        }
      ]
    },
    {
      "id": "H152",
      "protocol": "Singularity Finance",
      "hack_date": "2026-04-27",
      "amount_usd": 413000,
      "chains": [
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Oracle Misconfiguration Exploit",
      "audit_status": "unknown",
      "auditors": [
        {
          "firm": "Paladin Blockchain Security",
          "audit_date": "2025/05/30",
          "scope": "out",
          "source_url": "https://paladinsec.co/assets/audits/20250529_Paladin_SingularityDAODynaVaults_Final_Report.pdf"
        },
        {
          "firm": "Hacken",
          "audit_date": "2024/05/08",
          "scope": "out",
          "source_url": "https://hacken.io/audits/singularitydao/"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/weekly-web3-security-roundup-2026-04-26"
        },
        {
          "publisher": "ChainSec",
          "kind": "other",
          "url": "https://www.chainsec.io/defi-hacks"
        },
        {
          "publisher": "stacy_muur (X)",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "TeleSwap Academy",
          "kind": "news",
          "url": "https://academy.teleswap.xyz/defi-protocol-hacks-april-2026-exploits-analyzed/"
        }
      ]
    },
    {
      "id": "H158",
      "protocol": "Judao",
      "hack_date": "2026-04-28",
      "amount_usd": 228000,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "token",
      "attack_type": "Flash loan + reserve manipulation (sell-burn reserve manipulation via double sync() in custom _update function)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Verichains (LCD)",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/judao-hack-analysic"
        },
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/judao-sell-burn-reserve-manipulation/"
        },
        {
          "publisher": "ExVul",
          "kind": "security_firm",
          "url": "https://x.com/exvulsec/status/2048947737568432328"
        },
        {
          "publisher": "stacy_muur",
          "kind": "x",
          "url": "https://x.com/stacy_muur/status/2049470260672430548"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        }
      ]
    },
    {
      "id": "H058",
      "protocol": "Quant (DeFi protocol, Ethereum)",
      "hack_date": "2026-04-28",
      "amount_usd": 138000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Access control exploit enabling unauthorized privileged actions",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "ChainSec",
          "kind": "other",
          "url": "https://www.chainsec.io/defi-hacks"
        }
      ]
    },
    {
      "id": "H153",
      "protocol": "YieldCore-3rd-deal (RWAVault)",
      "hack_date": "2026-04-28",
      "amount_usd": 398700,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Missing ERC4626 caller authorization check — withdraw()/redeem() overrides stripped the standard _spendAllowance() call, allowing any caller to drain depositor funds",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/yieldcore-rwavault-unauthorized-withdrawal/"
        },
        {
          "publisher": "PeckShield",
          "kind": "x",
          "url": "https://x.com/peckshield/status/2049167005148721535"
        },
        {
          "publisher": "Trading Strategy",
          "kind": "other",
          "url": "https://tradingstrategy.ai/trading-view/vaults/yieldcore-3rd-deal"
        }
      ]
    },
    {
      "id": "H060",
      "protocol": "Aftermath Finance (Aftermath Perps)",
      "hack_date": "2026-04-29",
      "amount_usd": 1140000,
      "chains": [
        "Sui"
      ],
      "victim_type": "perp-dex",
      "attack_type": "Fee-accounting logic flaw (signed-integer underflow in integrator/builder-code fee accounting); attacker self-registered as integrator and set a negative taker fee to mint synthetic collateral and withdraw it as real USDC",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "OtterSec",
          "audit_date": "2025/11",
          "scope": "probable",
          "source_url": "https://www.livebitcoinnews.com/sui-perps-exploit-victims-get-a-sheet-a-warning-and-a-monday-deadline/"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/29/aftermath-finance-perps-on-sui-exploited-for-1-14m/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/aftermath-finance-exploit-perpetual-futures/"
        },
        {
          "publisher": "Live Bitcoin News",
          "kind": "news",
          "url": "https://www.livebitcoinnews.com/sui-perps-exploit-victims-get-a-sheet-a-warning-and-a-monday-deadline/"
        },
        {
          "publisher": "MEXC News",
          "kind": "news",
          "url": "https://www.mexc.com/news/1062692"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/aftermath-finance-loses-11m-usdc-in-sui-network-exploit-77259"
        },
        {
          "publisher": "Startup Fortune",
          "kind": "news",
          "url": "https://startupfortune.com/aftermath-finances-sui-exploit-shows-how-fast-a-small-accounting-bug-can-become-a-real-defi-run/"
        },
        {
          "publisher": "SQ Magazine",
          "kind": "news",
          "url": "https://sqmagazine.co.uk/aftermath-finance-1m-usdc-exploit-sui/"
        },
        {
          "publisher": "Odaily",
          "kind": "news",
          "url": "https://www.odaily.news/en/newsflash/478809"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/aftermath-perps"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/aftermathfi-perpetuals-negative-integrator-fee-collateral-inflation/"
        },
        {
          "publisher": "CertiKAlert (@CertiKAlert)",
          "kind": "x",
          "url": "https://x.com/CertiKAlert/status/2049428250359648528"
        }
      ]
    },
    {
      "id": "H061",
      "protocol": "Sweat Economy (Sweat Foundation / $SWEAT)",
      "hack_date": "2026-04-29",
      "amount_usd": 3500000,
      "chains": [
        "Near"
      ],
      "victim_type": "token",
      "attack_type": "Access-control / refund-logic exploit: ungated NEP-141 ft_resolve_transfer callback weaponized via empty-bytes noop to trigger full-balance 'refund' to attacker",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2024/01/19",
          "scope": "out",
          "source_url": "https://hacken.io/audits/the-sweat-foundation-ltd/sca-sweatco-claim-dec2023/"
        },
        {
          "firm": "Guvenkaya",
          "audit_date": "2024/01/29",
          "scope": "out",
          "source_url": "https://github.com/Guvenkaya/public-reports"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Fireblocks",
          "kind": "security_firm",
          "url": "https://www.fireblocks.com/blog/near-zero-day-sweat-hot-token-exploit"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/399498/sweat-protocol-thwarts-multi-million-dollar-exploit-restores-user-balances"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/30/sweat-economy-tokens-worth-over-2m-drained-in-reported-attack/"
        },
        {
          "publisher": "Tekedia",
          "kind": "news",
          "url": "https://www.tekedia.com/sweat-economy-on-near-protocol-exploited-draining-13-71b-sweat-tokens/"
        },
        {
          "publisher": "BSCN",
          "kind": "news",
          "url": "https://bsc.news/news/sweat-economy-recovers-funds-near-exploit"
        },
        {
          "publisher": "CoinCentral",
          "kind": "news",
          "url": "https://coincentral.com/sweat-protocol-restores-balances-after-exploit-drains-13-7-billion-tokens/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/sweateconomy-suffers-major-attack-65-of-sweat-tokens-stolen-77473"
        },
        {
          "publisher": "NEARBuilders audits (GitHub)",
          "kind": "security_firm",
          "url": "https://github.com/NEARBuilders/audits/blob/main/README.md"
        },
        {
          "publisher": "Guvenkaya public-reports (GitHub)",
          "kind": "security_firm",
          "url": "https://github.com/Guvenkaya/public-reports"
        },
        {
          "publisher": "@tangentcash (X)",
          "kind": "x",
          "url": "https://x.com/tangentcash/status/2049614168211554656"
        }
      ]
    },
    {
      "id": "H062",
      "protocol": "Syndicate (Commons cross-chain bridge)",
      "hack_date": "2026-04-29",
      "amount_usd": 380000,
      "chains": [
        "Base",
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "Bridge contract compromise via leaked upgrade private key (malicious contract upgrade)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Softstack (softstack GmbH; formerly Chainsulting)",
          "audit_date": "2025/07/09",
          "scope": "probable",
          "source_url": "https://raw.githubusercontent.com/SyndicateProtocol/syndicate-appchains/main/audits/Syndicate%20SYND%20Audit.pdf"
        },
        {
          "firm": "Softstack",
          "audit_date": "2025/07/09",
          "scope": "out",
          "source_url": "https://raw.githubusercontent.com/SyndicateProtocol/syndicate-appchains/main/audits/Syndicate%20SYND%20Audit.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CertiK (CertiKAlert)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2049378233410613647"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/399318/syndicate-exploit"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/syndicate-labs-suffers-380k-synd-bridge-exploit-pledges-full-user-compensation/"
        },
        {
          "publisher": "Invezz (Syndicate Labs official confirmation)",
          "kind": "news",
          "url": "https://invezz.com/news/2026/04/30/syndicate-labs-confirms-commons-cross-chain-bridge-attack-pledges-full-compensation/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/syndicate-synd-crashes-34-bridge-exploit/"
        },
        {
          "publisher": "AUTOSEC.DEV (security analysis)",
          "kind": "other",
          "url": "https://blog.autosec.dev/security-events/Syndicate-Commons-Bridge-exploit/"
        },
        {
          "publisher": "Gate News",
          "kind": "news",
          "url": "https://www.gate.com/news/detail/syndicate-loses-330k-after-commons-cross-chain-bridge-exploit-185m-synd-20675409"
        },
        {
          "publisher": "CryptoEconomyEN",
          "kind": "x",
          "url": "https://x.com/CryptoEconomyEN/status/2049546880149774781"
        },
        {
          "publisher": "Syndicate Protocol (GitHub audits directory)",
          "kind": "protocol",
          "url": "https://github.com/SyndicateProtocol/syndicate-appchains/tree/main/audits"
        }
      ]
    },
    {
      "id": "H164",
      "protocol": "QNT Reserve Pool (EIP-7702 exploit)",
      "hack_date": "2026-04-29",
      "amount_usd": 55000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "EIP-7702 arbitrary call vulnerability — admin EOA delegated code to BatchExecutor which authorized a permissionless BatchCall contract; attacker called BatchCall.batch() without any permission checks to drain reserve pool",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "x",
          "url": "https://x.com/SlowMist_Team/status/2049333031371210854"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/qnt-pool-drain-via-eip-7702-admin-eoa-delegation/"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/eip7702-vulnerability-leads-to-theft-of-19885-qnt-77145"
        },
        {
          "publisher": "Bitget News",
          "kind": "news",
          "url": "https://www.bitget.com/amp/news/detail/12560605389679"
        }
      ]
    },
    {
      "id": "H150",
      "protocol": "Alchemix yvWETH user position drained via malicious unverified-contract approval (~$1M)",
      "hack_date": "2026-04-29",
      "amount_usd": 1000000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "wallet",
      "attack_type": "malicious-contract approval / arbitrary call execution (wallet drainer)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 1,
      "sources": [
        {
          "publisher": "PeckShield (X)",
          "kind": "security_firm",
          "url": "https://x.com/peckshield/status/2049296116177322491"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/alchemix-yvvault-user-loses-1m-in-unauthorized-contract-attack-77100"
        },
        {
          "publisher": "DefiLlama (Alchemix V2 audit metadata)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/alchemix-v2"
        },
        {
          "publisher": "Runtime Verification (Alchemix protocol audit — NOT the exploited code)",
          "kind": "security_firm",
          "url": "https://github.com/runtimeverification/publications/blob/main/reports/smart-contracts/Alchemix_v2.pdf"
        }
      ]
    },
    {
      "id": "H132",
      "protocol": "Wasabi Protocol (Wasabi Perps)",
      "hack_date": "2026-04-30",
      "amount_usd": 5500000,
      "chains": [
        "Ethereum",
        "Base",
        "Berachain",
        "Blast"
      ],
      "victim_type": "perp-dex",
      "attack_type": "admin key compromise (compromised deployer EOA with sole ADMIN_ROLE -> grantRole delay=0 -> malicious UUPS upgrade of perp vaults)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Zellic",
          "audit_date": "2024/01/09",
          "scope": "probable",
          "source_url": "https://wasabi-public.s3.us-east-1.amazonaws.com/audits/v1/Wasabi+Perps+-+Zellic+Audit+Report.pdf"
        },
        {
          "firm": "Narya.ai",
          "audit_date": "2023/04/21",
          "scope": "out",
          "source_url": "https://dkoda-public.s3.amazonaws.com/Narya.ai_Wasabi_Smart_Contract_Audit.pdf"
        },
        {
          "firm": "Sherlock",
          "audit_date": "2024/11/28",
          "scope": "probable",
          "source_url": "https://wasabi-public.s3.us-east-1.amazonaws.com/audits/v1/Wasabi_Perps_EVM_Audit_Sherlock.pdf"
        },
        {
          "firm": "Foobar (0xfoobar)",
          "audit_date": "2023/12/17",
          "scope": "probable",
          "source_url": "https://wasabi-public.s3.amazonaws.com/audits/v1/WasabiPerps+Security+Assessment-1+(2).pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "DefiLlama (hacks DB, id 2900: Wasabi Perps, $5.5M, Admin Key Compromised, date 2026-04-30)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/wasabi-protocol-rekt"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/04/30/wasabi-protocol-drained-for-usd4-5-million-in-apparent-admin-key-compromise"
        },
        {
          "publisher": "Crowdfund Insider",
          "kind": "news",
          "url": "https://www.crowdfundinsider.com/2026/05/276724-decentralized-perpetual-futures-platform-wasabi-protocol-loses-millions-in-deployer-key-compromise/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/wasabi-protocol-exploit-tied-to-admin-key-breach-5m-drained-across-chains/"
        },
        {
          "publisher": "Coin Edition",
          "kind": "news",
          "url": "https://coinedition.com/wasabi-protocol-suffers-over-5m-loss-in-multi-chain-exploit/"
        },
        {
          "publisher": "CoinCentral",
          "kind": "news",
          "url": "https://coincentral.com/wasabi-protocol-exploited-for-over-5m-after-admin-key-compromise/"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-wasabi-protocol-hack-april-2026"
        },
        {
          "publisher": "Zellic",
          "kind": "security_firm",
          "url": "https://dkoda-public.s3.amazonaws.com/Zellic_Wasabi_Smart_Contract_Audit.pdf"
        },
        {
          "publisher": "Narya.ai",
          "kind": "security_firm",
          "url": "https://dkoda-public.s3.amazonaws.com/Narya.ai_Wasabi_Smart_Contract_Audit.pdf"
        },
        {
          "publisher": "PeckShield (X, reporter/attribution - not an auditor)",
          "kind": "x",
          "url": "https://x.com/peckshield/status/2049935172674425250"
        },
        {
          "publisher": "Wasabi Protocol (official docs)",
          "kind": "protocol",
          "url": "https://docs.wasabi.xyz/_/overview/technical-documentation/audits"
        },
        {
          "publisher": "Zellic",
          "kind": "security_firm",
          "url": "https://reports.zellic.io/publications/wasabi-perps/"
        },
        {
          "publisher": "Hypernative Labs",
          "kind": "x",
          "url": "https://x.com/HypernativeLabs/status/2052373450912673805"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/wasabi-protocol-hack"
        }
      ]
    },
    {
      "id": "H065",
      "protocol": "Bisq",
      "hack_date": "2026-05-01",
      "amount_usd": 858000,
      "chains": [
        "Bitcoin"
      ],
      "victim_type": "protocol",
      "attack_type": "Protocol Logic — negative miner-fee validation bypass via modified client",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Bisq Network (official)",
          "kind": "protocol",
          "url": "https://bisq.network/blog/security-incident-post-mortem/"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/en/?c=&page=4"
        },
        {
          "publisher": "Bisq Network (official follow-up)",
          "kind": "protocol",
          "url": "https://bisq.network/blog/where-bisq-stands-after-security-incident/"
        },
        {
          "publisher": "CryptoRank",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/9b496-bisq-plans-refund-suspected-ai-exploit"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/bisq-plans-refund-suspected-ai-exploit/"
        }
      ]
    },
    {
      "id": "H064",
      "protocol": "Sharwa.Finance",
      "hack_date": "2026-05-01",
      "amount_usd": 32850,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "Oracle Price Manipulation via flash loan",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2024/06/23",
          "scope": "out",
          "source_url": "https://github.com/pashov/audits/blob/master/team/md/SharwaFinance-security-review.md"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/vulnerability-analysis-deconstructing"
        },
        {
          "publisher": "Cryptonomist",
          "kind": "news",
          "url": "https://en.cryptonomist.ch/2026/05/08/new-defi-hack-on-ethereum-over-6-7-million-drained-from-the-market-maker-linked-to-1inch/"
        }
      ]
    },
    {
      "id": "H066",
      "protocol": "SmartCredit",
      "hack_date": "2026-05-04",
      "amount_usd": 72000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "Flash Loan Exploit",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Pessimistic.io",
          "audit_date": "2022/01/21",
          "scope": "out",
          "source_url": "https://github.com/pessimistic-io/audits/blob/ca048cb8eaba4f7959fb83c1c6f5cb4803c85718/SmartCredit%20Security%20Analysis%20by%20Pessimistic.pdf"
        },
        {
          "firm": "ImmuneBytes",
          "audit_date": "2024",
          "scope": "probable",
          "source_url": "https://github.com/ImmuneBytes-Security-Audit/Smart-Contract-Audit-Reports/tree/main/SmartCredit"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/en/?c=Ethereum&page=4"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "Cryptonomist",
          "kind": "news",
          "url": "https://en.cryptonomist.ch/2026/05/08/new-defi-hack-on-ethereum-over-6-7-million-drained-from-the-market-maker-linked-to-1inch/"
        }
      ]
    },
    {
      "id": "H067",
      "protocol": "Ekubo Protocol",
      "hack_date": "2026-05-05",
      "amount_usd": 1400000,
      "chains": [
        "Ethereum",
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "improper access control / unauthorized transferFrom via unvalidated payment callback",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena",
          "audit_date": "2025/12/10",
          "scope": "confirmed",
          "source_url": "https://code4rena.com/reports/2025-11-ekubo"
        },
        {
          "firm": "ABDK",
          "audit_date": "2025/04/01",
          "scope": "confirmed",
          "source_url": "https://315464330-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTLfgXtzlwI2fzDVFEifT%2Fuploads%2FIEez2iqmq6I9MoOf6tQE%2FABDK_Ekubo_EkuboProtocol_v_1_0.pdf (linked from https://docs.ekubo.org/integration-guides/reference/audits)"
        },
        {
          "firm": "Plainshift",
          "audit_date": "2025/03/17",
          "scope": "confirmed",
          "source_url": "https://315464330-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTLfgXtzlwI2fzDVFEifT%2Fuploads%2FwOLy0F8Kln2qG2ZFyc3V%2FEkubo%20EVM%20Deployment%20Plainshift%20Audit.pdf (linked from https://docs.ekubo.org/integration-guides/reference/audits)"
        },
        {
          "firm": "Nethermind Security",
          "audit_date": "2024/03/22",
          "scope": "out",
          "source_url": "https://315464330-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTLfgXtzlwI2fzDVFEifT%2Fuploads%2FQRpaG8UbUhVThiOUpCEo%2FNM0123_EKUBO_FINAL_PUBLIC.pdf (linked from https://docs.ekubo.org/integration-guides/reference/audits)"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/400189/attackers-drain-1-4m-in-wrapped-bitcoin-from-defi-protocol-ekubo-in-approval-based-exploit"
        },
        {
          "publisher": "Bankless",
          "kind": "news",
          "url": "https://www.bankless.com/read/news/ekubo-dex-users-drained-for-1-4m-in-token-approval-exploit"
        },
        {
          "publisher": "Web3 Is Going Great (Molly White)",
          "kind": "news",
          "url": "https://www.web3isgoinggreat.com/single/ekubo-exploit"
        },
        {
          "publisher": "Crypto Economy (cites Blockaid analysis)",
          "kind": "security_firm",
          "url": "https://crypto-economy.com/ekubo-protocol-loses-1-4m-in-wbtc/"
        },
        {
          "publisher": "FinanceFeeds",
          "kind": "news",
          "url": "https://financefeeds.com/ekubo-loses-1-4-million-after-attackers-exploit-evm-swap-router-flaw/"
        },
        {
          "publisher": "Ekubo Protocol (official)",
          "kind": "protocol",
          "url": "https://x.com/EkuboProtocol/status/2051754481465856038"
        },
        {
          "publisher": "OurCryptoTalk",
          "kind": "news",
          "url": "https://ourcryptotalk.com/news/ekubo-protocol-exploit-evm-swap-router"
        },
        {
          "publisher": "Revoke.cash",
          "kind": "other",
          "url": "https://revoke.cash/exploits"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/ekubo"
        }
      ]
    },
    {
      "id": "H068",
      "protocol": "TrustedVolumes",
      "hack_date": "2026-05-07",
      "amount_usd": 6700000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "other",
      "attack_type": "Access control / authorization bypass (permissionless signer registration in custom RFQ swap proxy)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/trustedvolumes-rekt"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-trustedvolumes-hack-may-2026"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/trustedvolumes-exploit-analysis"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/367070/defi-platform-trustedvolumes-hit-by-6-7m-exploit"
        },
        {
          "publisher": "NewsBTC",
          "kind": "news",
          "url": "https://www.newsbtc.com/news/defi-trustedvolumes-6-7m-hack-2026-exploits/"
        },
        {
          "publisher": "CryptoPotato",
          "kind": "news",
          "url": "https://cryptopotato.com/hacker-drains-5-9m-from-ethereum-liquidity-provider-trustedvolumes/"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/trustedvolumes-rfq-proxy-drain/"
        }
      ]
    },
    {
      "id": "H069",
      "protocol": "Renegade",
      "hack_date": "2026-05-10",
      "amount_usd": 209000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "perp-dex",
      "attack_type": "Unprotected Initializer Exploit — proxy delegatecall drain",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "ZK Security",
          "audit_date": "2026/01/30",
          "scope": "out",
          "source_url": "https://github.com/renegade-fi/renegade/tree/main/audits"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/en/?c=&page=4"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/renegade-dark-pool-unprotected-initializer/"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/renegade-recovers-190k-in-swift-whitehat-resolution-after-209k-arbitrum-dark-pool-exploit/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/how-a-basic-proxy-oversight-cost-renegade-fi-nearly-209k/"
        },
        {
          "publisher": "Blockaid (security firm)",
          "kind": "x",
          "url": "https://x.com/blockaid_/status/2053395937708384587"
        }
      ]
    },
    {
      "id": "H070",
      "protocol": "INK Finance",
      "hack_date": "2026-05-11",
      "amount_usd": 140000,
      "chains": [
        "Polygon"
      ],
      "victim_type": "protocol",
      "attack_type": "Whitelisted Address Impersonation via logic flaw in Workspace Treasury Proxy authentication; attacker deployed a malicious contract mimicking a whitelisted claimer, used a ~$25K Balancer V2 flash loan to inflate balance, and triggered an authorized treasury transfer",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Salus Security",
          "audit_date": "2023/08/15",
          "scope": "out",
          "source_url": "https://github.com/Ink-Finance-Inc/contract-audit/tree/main/salus-security"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/11/ink-finance-exploited-on-polygon-140k-usdt-drained-in-flash-loan-attack/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/ink-finance-loses-140k-as-whitelist-bypass-exploit-targets-treasury-infrastructure-details/"
        },
        {
          "publisher": "KuCoin (citing Blockaid alert)",
          "kind": "news",
          "url": "https://www.kucoin.com/news/insight/POL/6a01d7fad064730007b4dfd2"
        },
        {
          "publisher": "PANews",
          "kind": "news",
          "url": "https://www.panewslab.com/en/articles/019e161a-c19d-71db-b6b8-56c49ad72eaa"
        }
      ]
    },
    {
      "id": "C-TAC",
      "protocol": "TAC Protocol (TON-EVM cross-chain bridge)",
      "hack_date": "2026-05-12",
      "amount_usd": 2800000,
      "chains": [
        "TON",
        "TAC"
      ],
      "victim_type": "bridge",
      "attack_type": "cross-chain bridge exploit (TON side)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/tac-white-hat-incident-hacker-refund/"
        },
        {
          "publisher": "Global Ledger (May 2026 recap)",
          "kind": "security_firm",
          "url": "https://blog.globalledger.io/research-investigations/crypto-hacks-may-2026"
        },
        {
          "publisher": "PeckShield via Bitcoin.com",
          "kind": "security_firm",
          "url": "https://news.bitcoin.com/crypto-bridge-exploits-328-million-may-2026-peckshield/"
        }
      ]
    },
    {
      "id": "H071",
      "protocol": "Aurellion Labs",
      "hack_date": "2026-05-12",
      "amount_usd": 456000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "Uninitialized Diamond Proxy (EIP-2535) exploit — attacker called initialize() on an unprotected SafeOwnable facet, seized ownership, injected a malicious pullERC20 facet, and drained outstanding USDC approvals",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "VeriChains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/aurellion-labs-hack-analysis-diamond"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/12/aurellion-labs-drained-of-455k-usdc-in-diamond-proxy-exploit/"
        },
        {
          "publisher": "Blockaid",
          "kind": "x",
          "url": "https://x.com/blockaid_/status/2054154334326190288"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/aurellion-labs-exploit-drains-456k-after-diamond-proxy-initialization-flaw/"
        }
      ]
    },
    {
      "id": "H073",
      "protocol": "Transit Finance (Transit Swap)",
      "hack_date": "2026-05-13",
      "amount_usd": 1880000,
      "chains": [
        "Tron",
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "deprecated/legacy smart contract exploit (dormant historical vulnerability in a 2022 contract still live on-chain)",
      "audit_status": "unaudited",
      "auditors": [
        {
          "firm": "PeckShield",
          "audit_date": null,
          "scope": "out",
          "source_url": "https://github.com/peckshield/publications/tree/master/audit_reports"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/transit-finance-hack-drains-1-88m-from-cross-chain-protocol/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/transit-finance-to-refund-hack-may-losses/"
        },
        {
          "publisher": "news.bitcoin.com (PeckShield May 2026 roundup)",
          "kind": "security_firm",
          "url": "https://news.bitcoin.com/crypto-bridge-exploits-328-million-may-2026-peckshield/"
        },
        {
          "publisher": "MEXC News / PeckShield",
          "kind": "security_firm",
          "url": "https://www.mexc.com/news/1087384"
        },
        {
          "publisher": "NullTX",
          "kind": "news",
          "url": "https://nulltx.com/1-88m-reportedly-drained-in-transitfinance-exploit-that-exposes-hidden-risks-of-legacy-smart-contracts/"
        },
        {
          "publisher": "BSCN on X",
          "kind": "x",
          "url": "https://x.com/BSCNews/status/2054613633460777265"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/transit-finance-to-compensate-users-after-tron-smart-contract-exploit-80916"
        },
        {
          "publisher": "CertiK (2022 incident, audit-scope context)",
          "kind": "security_firm",
          "url": "https://www.certik.com/resources/blog/transit-swap-incident-report"
        }
      ]
    },
    {
      "id": "H074",
      "protocol": "THORChain",
      "hack_date": "2026-05-15",
      "amount_usd": 10700000,
      "chains": [
        "Bitcoin",
        "Ethereum",
        "BSC",
        "Base",
        "Avalanche",
        "Dogecoin",
        "Litecoin",
        "Bitcoin Cash",
        "XRP"
      ],
      "victim_type": "bridge",
      "attack_type": "rogue/malicious node exploiting GG20 threshold signature scheme (TSS) to reconstruct an Asgard vault private key and make unauthorized outbound transfers",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Kudelski Security",
          "audit_date": "2020/06/19",
          "scope": "probable",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain-Kudelski-TSS-Audit-June2020.pdf"
        },
        {
          "firm": "Halborn",
          "audit_date": "2021/09/30",
          "scope": "probable",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/Halborn-TSS-Audit-Sep2021.pdf"
        },
        {
          "firm": "Trail of Bits",
          "audit_date": "2021/08/23",
          "scope": "probable",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain-TrailOfBits-FullAudit-Aug2021.pdf"
        },
        {
          "firm": "Certik",
          "audit_date": "2020/04/20",
          "scope": "out",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain-Certik-CodeReview-Mar2020.pdf"
        },
        {
          "firm": "Gauntlet",
          "audit_date": "2020/06",
          "scope": "out",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain-Gauntlet-EconomicSecurityReview-May2020.pdf"
        },
        {
          "firm": "IOActive",
          "audit_date": "2020/11/16",
          "scope": "out",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain-IOActive-PenetrationTest-Nov2020.pdf"
        },
        {
          "firm": "Zellic",
          "audit_date": "2025/01/27",
          "scope": "out",
          "source_url": "https://github.com/thorchain/Resources/blob/master/Audits/THORChain%20Bifrost%20UTXO%20Client%20-%20Zellic%20Audit%20Report.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 9,
      "sources": [
        {
          "publisher": "The Crypto Times (covering THORChain official Exploit Report #1)",
          "kind": "protocol",
          "url": "https://www.cryptotimes.io/2026/05/21/thorchain-shares-exploit-report-revealing-10-7m-vault-breach-by-new-node/"
        },
        {
          "publisher": "TRM Labs",
          "kind": "security_firm",
          "url": "https://www.trmlabs.com/resources/blog/thorchain-exploit-drains-usd-11m-across-at-least-nine-chains-what-trm-knows-now"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/05/15/thorchain-halts-trading-after-usd10-million-cross-chain-exploit-rune-token-drops-12"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/thorchain-trading-resumes-after-10-7m-exploit-and-month-long-halt/"
        },
        {
          "publisher": "The Open Source Press",
          "kind": "news",
          "url": "https://www.theopensourcepress.com/thorchain-vault-exploit-may-2026/"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2055226411125027171"
        },
        {
          "publisher": "Beosin",
          "kind": "security_firm",
          "url": "https://x.com/BeosinAlert/status/2055236899644826024"
        },
        {
          "publisher": "Cyvers",
          "kind": "security_firm",
          "url": "https://x.com/CyversAlerts/status/2055223952453074987"
        },
        {
          "publisher": "THORChain (official audit repository)",
          "kind": "protocol",
          "url": "https://github.com/thorchain/Resources/tree/master/Audits"
        },
        {
          "publisher": "Verichains (TSSHOCK GG20 vulnerability research, related root-cause class)",
          "kind": "security_firm",
          "url": "https://verichains.io/tsshock/"
        },
        {
          "publisher": "DefiLlama (protocol id 412, slug thorchain-dex)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/thorchain-dex"
        }
      ]
    },
    {
      "id": "H140",
      "protocol": "ShapeShift FOX Colony",
      "hack_date": "2026-05-15",
      "amount_usd": 132705,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "Meta-transaction DSAuth self-call authorization flaw — attacker exploited a semantic conflict between executeMetaTransaction (no filtering on functionSignature) and DSAuth automatic self-call authorization (src == address(this)) to call setResolver() without authorization, redirect the EtherRouter fallback delegatecall to a malicious contract, and drain USDC and FOX tokens",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://slowmist.medium.com/analysis-of-the-exploit-trust-chain-flaw-in-shapeshift-fox-colony-authorization-mechanism-b35a61865a80"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/13/shapeshift-fox-colony-loses-132k-in-smart-contract-exploit-on-arbitrum/"
        },
        {
          "publisher": "SlowMist (X)",
          "kind": "x",
          "url": "https://x.com/SlowMist_Team/status/2055225790032441785"
        }
      ]
    },
    {
      "id": "H075",
      "protocol": "Adshares (WrappedADS / ADS cross-chain bridge)",
      "hack_date": "2026-05-16",
      "amount_usd": 628000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "bridge exploit",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/wrappedads-privileged-wrapto-mint/"
        },
        {
          "publisher": "PANews (citing PeckShield)",
          "kind": "news",
          "url": "https://www.panewslab.com/en/articles/019e3ae3-2795-761d-9fbc-5b1b3cdb86c7"
        },
        {
          "publisher": "MEXC News (citing PeckShield)",
          "kind": "news",
          "url": "https://www.mexc.com/news/1100734"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/adshares-bridge-exploiter-returns-256-eth-after-628k-incident/"
        },
        {
          "publisher": "PeckShieldAlert (X)",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2056335190709223428"
        },
        {
          "publisher": "chrisdior777 (X)",
          "kind": "x",
          "url": "https://x.com/chrisdior777/status/2055752668262375665"
        }
      ]
    },
    {
      "id": "H076",
      "protocol": "MetaSea (SEA Token)",
      "hack_date": "2026-05-17",
      "amount_usd": 110000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "token",
      "attack_type": "Flash Loan + Reward Inflation (Logic Error)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/sea-settlement-adapter-round-redemption-inflation/"
        },
        {
          "publisher": "anomly.rs",
          "kind": "other",
          "url": "https://anomly.rs/metasea-redeemposition-distributor-drain-arb-2026-05-17"
        }
      ]
    },
    {
      "id": "H077",
      "protocol": "Verus-Ethereum Bridge",
      "hack_date": "2026-05-18",
      "amount_usd": 11500000,
      "chains": [
        "Ethereum",
        "Verus"
      ],
      "victim_type": "bridge",
      "attack_type": "bridge hack",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-verus-ethereum-bridge-hack-may-2026"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/web3-security-verus-bridge-retoswap-more"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/verus-ethereum-bridge-drained-of-11-5m-in-forged-transfer-exploit/"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/verus-ethereum-bridge-exploit-11-5-million-ri18bt"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/verus-ethereum-bridge-hack-drains-11-58m-why-defi-trust-is-eroding/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/verus-suffers-11-5m-hack-as-bridge-related-exploits-hit-329m-in-2026/"
        },
        {
          "publisher": "Crypto Times (recovery / bounty return)",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/22/verus-hacker-returns-8-5m-after-bridge-exploit-deal/"
        },
        {
          "publisher": "Verus (official Ethereum bridge page + verus.io 'no audits needed' positioning)",
          "kind": "protocol",
          "url": "https://verus.io/ethereum-bridge"
        },
        {
          "publisher": "VerusCoin GitHub (exploited Ethereum-side contracts; no audit folder/report)",
          "kind": "other",
          "url": "https://github.com/VerusCoin/Verus-Ethereum-Contracts"
        },
        {
          "publisher": "CryptoPatel (candidate lead; corroboration only)",
          "kind": "x",
          "url": "https://x.com/CryptoPatel/status/2056985522904731729"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/402319/verus-bridge-exploiter-returns-4052-eth"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/bridge-hacks-back-in-vogue-as-verus-exploit-brings-2026-total-to-329m/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/verus-bridge-exploit-may-defi-hacks/"
        },
        {
          "publisher": "PeckShield (PeckShieldAlert)",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2056194168385642881"
        },
        {
          "publisher": "CertiK (CertiKAlert)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2056189590000763371"
        },
        {
          "publisher": "Verus (protocol)",
          "kind": "protocol",
          "url": "https://www.verus.io/ethereum-bridge"
        },
        {
          "publisher": "Verus (protocol)",
          "kind": "protocol",
          "url": "https://www.verus.io/"
        }
      ]
    },
    {
      "id": "H078",
      "protocol": "Echo Protocol (eBTC) Monad exploit",
      "hack_date": "2026-05-18",
      "amount_usd": 821000,
      "chains": [
        "Monad"
      ],
      "victim_type": "protocol",
      "attack_type": "private key / admin-role compromise enabling unauthorized (infinite) token mint",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Hacken",
          "audit_date": "2025/08/28",
          "scope": "out",
          "source_url": "https://github.com/echo-proto/audit-report/blob/HEAD/Echo-IOTA-Bridge-Smart-Contract-Audit-Report-Hacken.pdf"
        },
        {
          "firm": "MoveBit",
          "audit_date": "2024/07/24",
          "scope": "out",
          "source_url": "https://movebit.xyz/reports/20240726-Echo-Bridge-Smart-Contract-Final-Audit-Report.pdf"
        },
        {
          "firm": "OtterSec",
          "audit_date": null,
          "scope": "out",
          "source_url": "https://github.com/echo-proto/audit-report"
        },
        {
          "firm": "Zellic",
          "audit_date": null,
          "scope": "out",
          "source_url": "https://github.com/Zellic/publications"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/business/2026/05/19/echo-protocol-suffers-usd76-million-exploit-in-ebtc-minting-attack-on-monad"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/368315/bitcoin-defi-platform-echo-protocol-hit-by-76m-monad-exploit"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/401771/echo-protocol-monad-exploit"
        },
        {
          "publisher": "Cointelegraph (PeckShield analysis cited)",
          "kind": "security_firm",
          "url": "https://www.tradingview.com/news/cointelegraph:d46cc4652094b:0-echo-protocol-s-ebtc-exploited-for-77m-in-admin-key-compromise/"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/echo-protocol-pauses-bridge-after-attacker-mints-76m-ebtc/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/autopsy-of-the-echo-protocol-hack/"
        },
        {
          "publisher": "Hacken (audit report)",
          "kind": "security_firm",
          "url": "https://hacken.io/audits/echo-protocol/sca-echo-protocol-bridge-iota-jul2025/"
        },
        {
          "publisher": "Beosin (X)",
          "kind": "x",
          "url": "https://x.com/BeosinAlert/status/2056581173510607329"
        },
        {
          "publisher": "CryptoPatel (X)",
          "kind": "x",
          "url": "https://x.com/CryptoPatel/status/2056985522904731729"
        }
      ]
    },
    {
      "id": "H080",
      "protocol": "Bankr (May 19 wallet breach)",
      "hack_date": "2026-05-19",
      "amount_usd": 170000,
      "chains": [
        "Base"
      ],
      "victim_type": "wallet",
      "attack_type": "AI Agent Prompt Injection / Session Permission Abuse",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/20/bankr-breach-exposes-ai-crypto-wallet-after-attacker-accessed-14-wallets/"
        },
        {
          "publisher": "Yahoo Finance",
          "kind": "news",
          "url": "https://finance.yahoo.com/markets/crypto/articles/bankr-joins-may-hack-wave-041512042.html"
        },
        {
          "publisher": "Bitcoinist",
          "kind": "news",
          "url": "https://bitcoinist.com/crypto-ai-platform-bankr-locks-down-system-after-hacker-breaches-14-crypto-wallets/"
        },
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"
        }
      ]
    },
    {
      "id": "H082",
      "protocol": "RetoSwap (Haveno-fork Monero P2P DEX) — ACK message arbitrator-hijack exploit",
      "hack_date": "2026-05-20",
      "amount_usd": 2700000,
      "chains": [
        "Monero"
      ],
      "victim_type": "dex",
      "attack_type": "protocol-logic / authentication flaw (forged out-of-order ACK message frontrunning multisig setup; arbitrator address hijack)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-retoswap-hack-may-2026"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/web3-security-verus-bridge-retoswap-more"
        },
        {
          "publisher": "Sam Bent (technical writeup, cites TradeProtocol.java fix)",
          "kind": "other",
          "url": "https://www.sambent.com/haveno-brought-back-the-arbitrator-multisig-and-attackers-just-hijacked-it/"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/21/monero-dex-retoswap-suspends-trading-after-2-7m-exploit-in-haveno-protocol/"
        },
        {
          "publisher": "Gate News",
          "kind": "news",
          "url": "https://www.gate.com/news/detail/haveno-protocol-hacked-retoswap-loses-7000-xmr-and-suspends-trading-21261649"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/retoswap-hacked-7000-xmr-stolen-via-haveno-protocol-vulnerability-84519"
        },
        {
          "publisher": "Smart Contract Hacking",
          "kind": "other",
          "url": "https://smartcontractshacking.com/hacks/retoswap-hack-2026"
        },
        {
          "publisher": "PeckShieldAlert (X)",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2057279916165693841"
        },
        {
          "publisher": "Haveno (project FAQ — no audit mentioned)",
          "kind": "protocol",
          "url": "https://haveno.exchange/faq/"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/retoswap-suspends-trading-after-second-haveno-protocol-exploit/"
        },
        {
          "publisher": "xgram.io",
          "kind": "news",
          "url": "https://xgram.io/blog/2-7m-drained"
        },
        {
          "publisher": "RetoSwap / Haveno-reto GitHub",
          "kind": "protocol",
          "url": "https://github.com/retoaccess1/haveno-reto"
        }
      ]
    },
    {
      "id": "H081",
      "protocol": "MAP Protocol / Butter Bridge V3.1",
      "hack_date": "2026-05-20",
      "amount_usd": 110000,
      "chains": [
        "Ethereum",
        "BSC"
      ],
      "victim_type": "bridge",
      "attack_type": "Infinite Mint via abi.encodePacked Hash Collision",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CertiK",
          "audit_date": "2023/01/05",
          "scope": "out",
          "source_url": "https://skynet.certik.com/projects/map-protocol"
        },
        {
          "firm": "DeHacker",
          "audit_date": "2024/11/15",
          "scope": "out",
          "source_url": "https://medium.com/@dehacker_security/map-protocol-swap-audit-by-dehacker-1b19a90400b5"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/21/map-bridge-exploit-1-quadrillion-mapo-minted-in-cross-chain-attack/"
        },
        {
          "publisher": "CryptoBriefing",
          "kind": "news",
          "url": "https://cryptobriefing.com/mapo-token-plunges-96-bridge-exploit/"
        },
        {
          "publisher": "CoinTelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/map-protocol-loses-96-of-its-value-after-quadrillion-token-mint-exploit"
        },
        {
          "publisher": "The Currency Analytics",
          "kind": "news",
          "url": "https://thecurrencyanalytics.com/defi/butter-bridge-hack-mints-1-quadrillion-mapo-tokens-wiping-out-nearly-a-third-of-token-value-259299"
        }
      ]
    },
    {
      "id": "H083",
      "protocol": "Polymarket (UMA CTF Adapter internal top-up wallet)",
      "hack_date": "2026-05-22",
      "amount_usd": 700000,
      "chains": [
        "Polygon"
      ],
      "victim_type": "other",
      "attack_type": "private key compromise (internal operations/top-up wallet drain)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "OpenZeppelin",
          "audit_date": "2023/08/16",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/uma-ctf-adapter/blob/main/audit/Polymarket_UMA_Optimistic_Oracle_Adapter_Audit.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "PeckShieldAlert",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2057745696674218049"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/402327/zachxbt-flags-suspected-exploit-involving-polymarkets-uma-adapter-contract-on-polygon"
        },
        {
          "publisher": "Decrypt",
          "kind": "news",
          "url": "https://decrypt.co/368740/polymarket-hit-by-internal-top-up-wallet-exploit-700k-drained"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/polymarket-exploit-with-520000-in-losses/"
        },
        {
          "publisher": "Bitcoin.com",
          "kind": "news",
          "url": "https://news.bitcoin.com/polymarket-suffers-700k-breach-after-internal-admin-wallet-is-compromised/"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/polymarket-uma-adapter-appears-exploited-520k-zachxbt"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/polymarkets-700k-exploit-targets-usdc-pol-are-user-funds-safe/"
        },
        {
          "publisher": "Polymarket GitHub",
          "kind": "protocol",
          "url": "https://github.com/Polymarket/uma-ctf-adapter"
        },
        {
          "publisher": "PolygonScan",
          "kind": "explorer",
          "url": "https://polygonscan.com/address/0x6A9D222616C90FcA5754cd1333cFD9b7fb6a4F74"
        }
      ]
    },
    {
      "id": "H084",
      "protocol": "StablR (EURR / USDR) minting multisig compromise",
      "hack_date": "2026-05-23",
      "amount_usd": 2800000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "stablecoin",
      "attack_type": "private key compromise / multisig misconfiguration (threshold 1) leading to unauthorized minting",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/402429/stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/stablr-stablecoins-exploited-eurr-and-usdr-depeg-after-minting-key-compromise"
        },
        {
          "publisher": "CCN",
          "kind": "news",
          "url": "https://www.ccn.com/education/crypto/stablr-hack-eurr-usdr-collapse-mica-compliance/"
        },
        {
          "publisher": "Bitrace",
          "kind": "security_firm",
          "url": "https://blog.bitrace.io/stablr-governance-crisis-how-attackers-hijacked-eurr-and-usdr/"
        },
        {
          "publisher": "Crypto Briefing (cites ZachXBT)",
          "kind": "news",
          "url": "https://cryptobriefing.com/stablecoin-issuer-stablr-hit-suspected-3m-smart-contract-exploit-zachxbt/"
        },
        {
          "publisher": "GoPlus Security",
          "kind": "x",
          "url": "https://x.com/GoPlusSecurity/status/2059177851321303214"
        },
        {
          "publisher": "StablR (official site)",
          "kind": "protocol",
          "url": "https://stablr.com/"
        }
      ]
    },
    {
      "id": "H133",
      "protocol": "SquidRouterModule (third-party Gnosis Safe module impersonating Squid)",
      "hack_date": "2026-05-25",
      "amount_usd": 3200000,
      "chains": [
        "Ethereum",
        "Base"
      ],
      "victim_type": "wallet",
      "attack_type": "Access-control / authorization bypass in a malicious third-party Gnosis Safe module (executeSameChainActions accepted a publicly-visible hardcoded constant string as proof of authorization), letting the attacker impersonate a trusted caller and execute arbitrary calldata to drain wallets that had approved the module; stolen assets routed through attacker-controlled Uniswap V3 pools into DAI.",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "Squid (official @squidrouter)",
          "kind": "protocol",
          "url": "https://x.com/squidrouter/status/2058890710611276238"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-squidroutermodule-hack-may-2026"
        },
        {
          "publisher": "crypto.news (citing Blockaid)",
          "kind": "news",
          "url": "https://crypto.news/blockaid-flags-3m-squidroutermodule-exploit-across-86-safes/"
        },
        {
          "publisher": "Cryptopolitan (citing Blockaid + PeckShield)",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/3-2m-drained-gnosis-safes-hack-base-ethereum/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/squid-disowns-3-2m-squidroutermodule-exploit/"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2058887446268645747"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/squid-rushes-to-separate-brand-from-3-million-gnosis-safe-module-exploit/"
        },
        {
          "publisher": "Coin Edition",
          "kind": "news",
          "url": "https://coinedition.com/hackers-drain-3-million-from-86-gnosis-safes-in-squidroutermodule-exploit/"
        },
        {
          "publisher": "Yahoo Finance / CoinDesk",
          "kind": "news",
          "url": "https://finance.yahoo.com/markets/crypto/articles/squid-distances-itself-3-2-044207127.html"
        }
      ]
    },
    {
      "id": "H159",
      "protocol": "WUSD.fi / GLOVE",
      "hack_date": "2026-05-25",
      "amount_usd": 207000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Sybil Reward Abuse + Flashloan",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "PeckShieldAlert",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2058865446984802630"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/25/wusd-fi-glove-incentive-abuse-drains-200k-from-uniswap-v3-pools/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        }
      ]
    },
    {
      "id": "H089",
      "protocol": "Bitmor",
      "hack_date": "2026-05-26",
      "amount_usd": 6000,
      "chains": [
        "Base"
      ],
      "victim_type": "protocol",
      "attack_type": "Access Control Exploit (compromised executor wallet draining DCA contract approvals)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "FailSafe",
          "audit_date": "2026/03/08",
          "scope": "out",
          "source_url": "https://getfailsafe.com/bitmor-agentic-security-review"
        }
      ],
      "verification": "likely",
      "independent_source_count": 1,
      "sources": [
        {
          "publisher": "Revoke.cash",
          "kind": "other",
          "url": "https://revoke.cash/exploits"
        }
      ]
    },
    {
      "id": "H090",
      "protocol": "Stake DAO (vsdCRV LayerZero OFT exploit)",
      "hack_date": "2026-05-27",
      "amount_usd": 91000,
      "chains": [
        "Arbitrum"
      ],
      "victim_type": "protocol",
      "attack_type": "deployer private key compromise / cross-chain OFT peer reconfiguration leading to unbacked token mint",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "ChainSecurity",
          "audit_date": "2023/01/17",
          "scope": "out",
          "source_url": "https://github.com/stake-dao/audits/blob/HEAD/votemarket/v1/2023-01-01_chainsecurity_votemarket_v1.pdf"
        },
        {
          "firm": "Trust Security",
          "audit_date": "2026/04/10",
          "scope": "out",
          "source_url": "https://github.com/stake-dao/audits/blob/HEAD/vlsdt/2026_03_26_trust_security_vlsdt.pdf"
        },
        {
          "firm": "Omniscia",
          "audit_date": "2025/09/03",
          "scope": "out",
          "source_url": "https://github.com/stake-dao/audits/blob/HEAD/staking-v2/2025-09-03_omniscia_staking_v2.pdf"
        },
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2025/08/08",
          "scope": "out",
          "source_url": "https://github.com/stake-dao/audits/blob/HEAD/staking-v2/2025-08-08_pashov_staking_v2_morpho_support.pdf"
        },
        {
          "firm": "Zach Obront",
          "audit_date": "2023/11/22",
          "scope": "out",
          "source_url": "https://github.com/stake-dao/audits/blob/HEAD/onlyboost/2023-11-22_zachobront_onlyboost.md"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/402719/security-researchers-flag-ongoing-stakedao-exploit-vsdcrv"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/defi-exploit-hits-stake-dao-as-attacker-swaps-vsdcrv-for-eth/"
        },
        {
          "publisher": "BeInCrypto (also syndicated to Yahoo Finance)",
          "kind": "news",
          "url": "https://beincrypto.com/stake-dao-exploit-deployer-key-vsdcrv/"
        },
        {
          "publisher": "The Crypto Times (Stake DAO post-mortem coverage)",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/09/trillions-of-tokens-91k-gone-stake-dao-details-arbitrum-exploit/"
        },
        {
          "publisher": "Crypto Briefing",
          "kind": "news",
          "url": "https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/"
        },
        {
          "publisher": "WEEX (Stake DAO official response)",
          "kind": "protocol",
          "url": "https://www.weex.com/news/detail/stake-dao-responds-to-the-security-incident-do-not-interact-with-vsdcrv-at-this-time-j6cjr8vus09rkzekk89a806g"
        },
        {
          "publisher": "Stake DAO (official audit repository)",
          "kind": "protocol",
          "url": "https://github.com/stake-dao/audits"
        },
        {
          "publisher": "Stake DAO Docs (security partners + audits)",
          "kind": "protocol",
          "url": "https://docs.stakedao.org/audits"
        },
        {
          "publisher": "DefiLlama (protocol id 249, audits=2, audit_links=docs.stakedao.org/audits)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/stake-dao"
        },
        {
          "publisher": "TruebieMarkets (X, candidate lead)",
          "kind": "x",
          "url": "https://x.com/TruebieMarkets/status/2061233749845758084"
        }
      ]
    },
    {
      "id": "H096",
      "protocol": "Fluid (Instadapp) — off-chain merkle rewards infrastructure compromise",
      "hack_date": "2026-05-27",
      "amount_usd": 215000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "lending",
      "attack_type": "off-chain operational/private key compromise of merkle rewards distribution infrastructure (fraudulent merkle root / empty-proof reward claims)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "PeckShield",
          "audit_date": "2023/11/10",
          "scope": "out",
          "source_url": "https://docs.fluid.instadapp.io/Peckshield_Fluid_Audit.pdf"
        },
        {
          "firm": "StateMind",
          "audit_date": "2023/12/29",
          "scope": "out",
          "source_url": "https://docs.fluid.instadapp.io/Statemind_Fluid_Audit.pdf"
        },
        {
          "firm": "MixBytes",
          "audit_date": "2024/06/21",
          "scope": "out",
          "source_url": "https://github.com/mixbytes/audits_public/tree/master/Instadapp/Fluid"
        },
        {
          "firm": "Cantina",
          "audit_date": "2025/01/07",
          "scope": "out",
          "source_url": "https://docs.fluid.instadapp.io/cantina-audit-dex.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "Bitget News (relaying Fluid's official @0xfluid X disclosure)",
          "kind": "protocol",
          "url": "https://www.bitget.com/amp/news/detail/12560605437313"
        },
        {
          "publisher": "Fluid (@0xfluid) official X account",
          "kind": "protocol",
          "url": "https://x.com/0xfluid/status/2061124908277538827"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/31/fluid-protocol-loses-125k-fluid-51-9k-gho-in-key-compromise-attack/"
        },
        {
          "publisher": "CryptoRank (citing BlackHart DeFi risk intelligence analysis)",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/0bcbc-fluid-loses-215k-reward-system-exploit-key-compromise"
        },
        {
          "publisher": "ETH Daily",
          "kind": "news",
          "url": "https://ethdaily.io/958"
        },
        {
          "publisher": "Today in DeFi",
          "kind": "news",
          "url": "https://news.todayindefi.com/p/exponent-launches-v2-fluid-incentives"
        },
        {
          "publisher": "Fluid / Instadapp official docs (audit list)",
          "kind": "protocol",
          "url": "https://docs.fluid.instadapp.io/audits-and-security.html"
        },
        {
          "publisher": "DefiLlama Hacks database",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        }
      ]
    },
    {
      "id": "H154",
      "protocol": "Joe Agent",
      "hack_date": "2026-05-27",
      "amount_usd": 290000,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "protocol",
      "attack_type": "Single-function reentrancy",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/joe-agent-liquidity-removal-reentrancy/"
        },
        {
          "publisher": "SlowMist Hacked DB",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/?c=BSC"
        },
        {
          "publisher": "SpectraAudit",
          "kind": "x",
          "url": "https://x.com/SpectraAudit/status/2060804433886240827"
        }
      ]
    },
    {
      "id": "H091",
      "protocol": "DxSale",
      "hack_date": "2026-05-28",
      "amount_usd": 7300000,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "protocol",
      "attack_type": "Access control / owner-privilege abuse of an unaudited legacy liquidity-locker contract (deployer-key compromise + EIP-7702 batch delegation, setFee fee reset to 1 wei, unlock-timestamp reset, batch withdrawal across 1,400+ LP positions)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CertiK",
          "audit_date": "2022/08/18",
          "scope": "out",
          "source_url": "https://skynet.certik.com/projects/dxsale"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "Rekt News",
          "kind": "rekt",
          "url": "https://rekt.news/dxsale-rekt"
        },
        {
          "publisher": "BlockSec",
          "kind": "security_firm",
          "url": "https://blocksec.com/blog/web3-security-dxsale-squidrouter-more"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2060188553079054351"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/old-dxsale-lockers-drained-for-7-3m-across-1-400-bnb-chain-pools-as-owner-privil"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/dxsale-exploit-drains-7-3m-in-bnb-through-hidden-contract-backdoor/"
        },
        {
          "publisher": "CryptoPotato",
          "kind": "news",
          "url": "https://cryptopotato.com/over-1400-liquidity-providers-hit-in-7-3-million-dxsale-exploit/"
        },
        {
          "publisher": "Invezz",
          "kind": "news",
          "url": "https://invezz.com/news/2026/05/29/dxsale-loses-7-3m-in-bnb-chain-liquidity-providers-lps-hack/"
        },
        {
          "publisher": "OneKey (relaying DxSale statement)",
          "kind": "protocol",
          "url": "https://onekey.so/blog/ecosystem/dxsale-releases-incident-clarification-v2-and-later-liquidity-lock-contracts-remain-unaffected-20260531045105/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/dxsale"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/29/hackers-drain-7-3m-from-dxsales-old-bnb-chain-liquidity-lockers/"
        }
      ]
    },
    {
      "id": "H139",
      "protocol": "ONTR Token",
      "hack_date": "2026-05-28",
      "amount_usd": 98315,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "token",
      "attack_type": "Uninitialized / zero-address owner backdoor (access control exploit)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://x.com/SlowMist_Team/status/2060208317574906076"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/how-renouncing-ownership-opened-a"
        },
        {
          "publisher": "Olympix",
          "kind": "security_firm",
          "url": "https://olympixai.medium.com/ontr-token-lost-98-3k-because-its-safety-signal-was-a-lie-in-the-code-5037c1da119f"
        },
        {
          "publisher": "SpectraAudit",
          "kind": "x",
          "url": "https://x.com/SpectraAudit/status/2060804433886240827"
        },
        {
          "publisher": "Bloomingbit (SlowMist relay)",
          "kind": "news",
          "url": "https://en.bloomingbit.io/feed/news/113125"
        }
      ]
    },
    {
      "id": "H094",
      "protocol": "Gravity Bridge",
      "hack_date": "2026-05-29",
      "amount_usd": 5400000,
      "chains": [
        "Ethereum",
        "Cosmos"
      ],
      "victim_type": "bridge",
      "attack_type": "denom mapping poisoning (permissionless deployERC20 + missing denom-to-ERC20 collision check) -> bridge custody drain",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Code4rena",
          "audit_date": "2021/11/05",
          "scope": "confirmed",
          "source_url": "https://code4rena.com/reports/2021-08-gravitybridge"
        },
        {
          "firm": "Least Authority",
          "audit_date": "2022/04/11",
          "scope": "confirmed",
          "source_url": "https://leastauthority.com/static/publications/LeastAuthority_Althea_Gravity%20Bridge_Final_Audit_Report.pdf"
        },
        {
          "firm": "Informal Systems",
          "audit_date": "2021",
          "scope": "probable",
          "source_url": "https://github.com/althea-net/cosmos-gravity-bridge/issues/206"
        },
        {
          "firm": "Certik",
          "audit_date": null,
          "scope": "unknown",
          "source_url": "https://github.com/Gravity-Bridge/Gravity-Docs/blob/main/docs/security.md"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/gravity-bridge-rekt"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/403108/cosmos-based-gravity-bridge-drained-of-5-4-million-in-suspected-key-compromise-researchers-say"
        },
        {
          "publisher": "Security4Web3",
          "kind": "security_firm",
          "url": "https://security4web3.com/blogposts/post22-gravity-bridge-exploit"
        },
        {
          "publisher": "news.bitcoin.com",
          "kind": "news",
          "url": "https://news.bitcoin.com/gravity-bridge-exploit-5-4-million-binance-changenow-2026/"
        },
        {
          "publisher": "Gravity Bridge (official docs)",
          "kind": "protocol",
          "url": "https://github.com/Gravity-Bridge/Gravity-Docs/blob/main/docs/security.md"
        },
        {
          "publisher": "Code4rena",
          "kind": "security_firm",
          "url": "https://code4rena.com/reports/2021-08-gravitybridge"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/gravity-bridge"
        },
        {
          "publisher": "Cyvers (CyversAlerts)",
          "kind": "x",
          "url": "https://x.com/CyversAlerts/status/2060639281354260555"
        },
        {
          "publisher": "QuillAudits",
          "kind": "x",
          "url": "https://x.com/QuillAudits_AI/status/2060654689126154700"
        }
      ]
    },
    {
      "id": "H092",
      "protocol": "Alephium Bridge (Token Bridge)",
      "hack_date": "2026-05-30",
      "amount_usd": 815000,
      "chains": [
        "Ethereum",
        "BNB Chain",
        "Alephium"
      ],
      "victim_type": "bridge",
      "attack_type": "Off-chain backend exploit / forged guardian messages (forged Wormhole VAAs)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "Alephium (official on-chain incident report)",
          "kind": "protocol",
          "url": "https://alephium.org/news/post/the-alephium-bridge-exploit-on-chain-report/"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/alephium-bridge-815k-forged-guardian-messages"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/alephium-bridge-exploit-forged-messages/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/815k-gone-in-7-minutes-inside-ethereums-alephium-tokenbridge-exploit/"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/05/30/alephium-reveals-cause-of-815k-bridge-exploit-promises-compensation/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/alephium-tokenbridge-hacked-815000-in-assets-stolen-86934"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/alephium-bridge"
        },
        {
          "publisher": "Alephium GitHub (wormhole-fork)",
          "kind": "explorer",
          "url": "https://github.com/alephium/wormhole-fork"
        },
        {
          "publisher": "Trueo_ (X)",
          "kind": "x",
          "url": "https://x.com/Trueo_/status/2060906971675672843"
        },
        {
          "publisher": "TruebieMarkets (X)",
          "kind": "x",
          "url": "https://x.com/TruebieMarkets/status/2061233749845758084"
        }
      ]
    },
    {
      "id": "H093",
      "protocol": "AFI Protocol",
      "hack_date": "2026-05-30",
      "amount_usd": 480000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "stablecoin",
      "attack_type": "Protocol Logic / Vault Exploit",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Cantina",
          "audit_date": "2025/07/30",
          "scope": "probable",
          "source_url": "https://cantina.xyz/portfolio/49c4ad16-2ab3-49f0-bcee-356ebf628020"
        },
        {
          "firm": "Quantstamp",
          "audit_date": "2025/11/18",
          "scope": "out",
          "source_url": "https://certificate.quantstamp.com/full/afi-vault/dc8a68ae-e72b-4b63-bef2-544c709f6fda/index.html"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/09/afi-protocol-shares-incident-update-after-480k-exploit-begins-recovery/"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/afiusd-vault-exploit-drains-480k-as-june-hack-run-continues/"
        },
        {
          "publisher": "AFI Protocol Docs",
          "kind": "protocol",
          "url": "https://docs.afiprotocol.xyz/risks/audits-and-bug-bounty"
        }
      ]
    },
    {
      "id": "H095",
      "protocol": "AROS",
      "hack_date": "2026-05-30",
      "amount_usd": 295000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Flash Loan / Price Manipulation",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "Bitget News (relaying TenArmor / Foresight News)",
          "kind": "news",
          "url": "https://www.bitget.com/news/detail/12560605437772"
        },
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/aros-attack-on-bnb-chain-adds-295k-loss-as-june-opens-with-defi-exploits/"
        },
        {
          "publisher": "DeFiHackLabs (SunWeb3Sec)",
          "kind": "other",
          "url": "https://github.com/SunWeb3Sec/DeFiHackLabs"
        },
        {
          "publisher": "BSCScan",
          "kind": "explorer",
          "url": "https://bscscan.com/tx/0xe89fe640ec5241edfca7d8dcae77a0a4270dee15e4bbd043fc60e393aabf41e1"
        }
      ]
    },
    {
      "id": "H098",
      "protocol": "Gnosis Pay",
      "hack_date": "2026-06-01",
      "amount_usd": 265000,
      "chains": [
        "Gnosis Chain"
      ],
      "victim_type": "wallet",
      "attack_type": "smart contract exploit — ERC-1271 / EIP-1271 signature verification bypass in Zodiac Delay Modifier (missing success check on contract-signature staticcall)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "G0 Group",
          "audit_date": "2021/09",
          "scope": "out",
          "source_url": "https://github.com/gnosisguild/zodiac-modifier-delay/blob/main/audits/ZodiacDelayModuleSep2021.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://www.certik.com/blog/gnosispay-incident-analysis"
        },
        {
          "publisher": "Verichains",
          "kind": "security_firm",
          "url": "https://blog.verichains.io/p/gnosis-pay-exploit-the-devs-discovered"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/403147/gnosis-will-cover-all-user-losses-amid-exploit-related-to-gnosis-pay-co-founder-koppelmann-says"
        },
        {
          "publisher": "Cointelegraph",
          "kind": "news",
          "url": "https://cointelegraph.com/news/gnosis-hit-by-fresh-exploit-team-vows-to-fully-cover-user-losses"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/gnosis-pay-exploit-tied-to-zodiac-delay-module-as-users-exit/"
        },
        {
          "publisher": "The Crypto Times (Zodiac/Gnosis Guild disclosure)",
          "kind": "protocol",
          "url": "https://www.cryptotimes.io/2026/06/03/zodiac-reveals-flaw-behind-gnosis-pay-exploit-safe-unaffected/"
        },
        {
          "publisher": "PeckShield",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2061372084589371581"
        },
        {
          "publisher": "Gnosis Guild (zodiac-modifier-delay repo, G0 Group audit)",
          "kind": "explorer",
          "url": "https://github.com/gnosisguild/zodiac-modifier-delay"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/gnosis-pay"
        }
      ]
    },
    {
      "id": "H097",
      "protocol": "TesseraDAO (TSR)",
      "hack_date": "2026-06-01",
      "amount_usd": 2500000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Admin-key / ownership takeover -> unauthorized infinite mint and dump",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 4,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/tesseradao-rekt"
        },
        {
          "publisher": "PeckShield (via Bloomingbit)",
          "kind": "security_firm",
          "url": "https://en.bloomingbit.io/feed/news/113373"
        },
        {
          "publisher": "QuillAudits (incident analysis, X; quoted by rekt.news)",
          "kind": "security_firm",
          "url": "https://x.com/QuillAudits_AI/status/2061742276976824659"
        },
        {
          "publisher": "Coinpedia",
          "kind": "news",
          "url": "https://coinpedia.org/crypto-live-news/tessera-dao-token-crashes-after-99m-tsr-minted-and-sold/"
        },
        {
          "publisher": "Cryptopolitan / Bitget News",
          "kind": "news",
          "url": "https://www.bitget.com/amp/news/detail/12560605440181"
        },
        {
          "publisher": "ChainCatcher",
          "kind": "news",
          "url": "https://www.chaincatcher.com/en/article/2268696"
        },
        {
          "publisher": "CertiK Skynet (project status page)",
          "kind": "explorer",
          "url": "https://skynet.certik.com/projects/tessera"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2061713210210988434"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/exploit-hits-gnosis-pay-tesseradao-june/"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/02/tesseradao-tsr-plunges-99-after-attacker-mints-99m-tokens/"
        },
        {
          "publisher": "Crypto Economy",
          "kind": "news",
          "url": "https://crypto-economy.com/tesseradao-suffers-2-5-million-exploit-following-ownership-takeover-attack/"
        }
      ]
    },
    {
      "id": "H100",
      "protocol": "ATM",
      "hack_date": "2026-06-03",
      "amount_usd": 243500,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Protocol Logic / Tax-on-Transfer Exploit",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/04/atm-token-exploit-drains-243k-through-hidden-swap-loophole/"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/atm-token-exploited-on-bnb-chain-243500-drained-via-hidden-swap-loophole/"
        }
      ]
    },
    {
      "id": "H167",
      "protocol": "DTXT",
      "hack_date": "2026-06-05",
      "amount_usd": 35041,
      "chains": [
        "BNB Chain"
      ],
      "victim_type": "token",
      "attack_type": "Spoofable Liquidity-Addition Detection Logic",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://x.com/SlowMist_Team/status/2062876917045608594"
        },
        {
          "publisher": "Bitget News / Foresight News",
          "kind": "news",
          "url": "https://www.bitget.com/news/detail/12560605446055"
        }
      ]
    },
    {
      "id": "H101",
      "protocol": "Syscoin Bridge",
      "hack_date": "2026-06-07",
      "amount_usd": 8000000,
      "chains": [
        "Syscoin"
      ],
      "victim_type": "bridge",
      "attack_type": "malformed SPV proof / proof-validation parsing flaw (unauthorized mint)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "rekt.news",
          "kind": "rekt",
          "url": "https://rekt.news/syscoin-rekt"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-syscoin-bridge-hack-june-2026"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/syscoin-bridge-paused-exploit-project/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/syscoin-how-a-validation-flaw-enabled-5-billion-unauthorized-sys/"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/08/syscoin-halts-bridge-after-exploit-mints-5-billion-sys-tokens/"
        },
        {
          "publisher": "Syscoin (incident report, via KuCoin)",
          "kind": "protocol",
          "url": "https://www.kucoin.com/news/flash/syscoin-releases-bridge-security-incident-report-unauthorized-funds-destroyed"
        },
        {
          "publisher": "Cyrex",
          "kind": "security_firm",
          "url": "https://cyrex.tech/case-study/pali-wallet"
        },
        {
          "publisher": "Syscoin Community Wiki",
          "kind": "protocol",
          "url": "https://support.syscoin.org/t/pali-wallet-security-audit/886"
        },
        {
          "publisher": "PricePredictions",
          "kind": "news",
          "url": "https://pricepredictions.com/news/syscoin-bridge-exploit-5-billion-sys-tokens-minted-proof-validation-flaw-br7jyfk9"
        }
      ]
    },
    {
      "id": "H102",
      "protocol": "Ambient Finance",
      "hack_date": "2026-06-07",
      "amount_usd": 110000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Flashloan Accounting Logic Exploit",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Zellic",
          "audit_date": "2022/08/24",
          "scope": "probable",
          "source_url": "https://github.com/Zellic/publications/blob/master/CrocSwap%20-%20Zellic%20Audit%20Report.pdf"
        },
        {
          "firm": "Quantstamp",
          "audit_date": "2023/04/25",
          "scope": "probable",
          "source_url": "https://certificate.quantstamp.com/full/croc-swap-v-2/95abbeb4-b253-49f8-9ddb-bb2a5e0495fa/index.html"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        },
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/08/ethereum-defi-protocol-ambient-finance-suffers-110k-drain/"
        },
        {
          "publisher": "Zellic",
          "kind": "security_firm",
          "url": "https://github.com/Zellic/publications/blob/master/CrocSwap%20-%20Zellic%20Audit%20Report.pdf"
        },
        {
          "publisher": "Quantstamp",
          "kind": "security_firm",
          "url": "https://raw.githubusercontent.com/CrocSwap/CrocSwap-protocol/main/audits/QuantstampV1.pdf"
        }
      ]
    },
    {
      "id": "H104",
      "protocol": "Humanity Protocol",
      "hack_date": "2026-06-08",
      "amount_usd": 32000000,
      "chains": [
        "Ethereum",
        "BNB Chain"
      ],
      "victim_type": "protocol",
      "attack_type": "private key / multisig compromise (bridge ProxyAdmin takeover + unauthorized mint)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "PeckShield (PeckShieldAlert)",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2064171043489726484"
        },
        {
          "publisher": "Cyvers (CyversAlerts)",
          "kind": "security_firm",
          "url": "https://x.com/CyversAlerts/status/2064250350995919135"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/06/09/humanity-protocol-token-crashes-more-than-80-after-a-usd32-million-private-key-hack"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/404053/humanity-protocol-exploit"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/humanity-protocol-post-mortem-malware-developer-machine-seven-keys"
        },
        {
          "publisher": "Crypto Adventure (re: Quantstamp incident report)",
          "kind": "security_firm",
          "url": "https://cryptoadventure.com/humanity-publishes-quantstamp-report-after-h-token-compromise/"
        },
        {
          "publisher": "Halborn (incident analysis, not auditor)",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-humanity-protocol-hack-june-2026"
        },
        {
          "publisher": "crypto.news (protocol post-mortem)",
          "kind": "news",
          "url": "https://crypto.news/humanity-protocol-says-attacker-stole-seven-keys-from-one-device/"
        },
        {
          "publisher": "Bitcoin.com News (ZachXBT investigation)",
          "kind": "news",
          "url": "https://news.bitcoin.com/humanity-protocol-exploit-zachxbt-staged/"
        },
        {
          "publisher": "CertiK Skynet (no audit on record)",
          "kind": "security_firm",
          "url": "https://skynet.certik.com/projects/humanity-protocol"
        },
        {
          "publisher": "DefiLlama (id 7848, audits=0)",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/humanity"
        }
      ]
    },
    {
      "id": "H103",
      "protocol": "Flooring Protocol",
      "hack_date": "2026-06-08",
      "amount_usd": null,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "DN404/BT404 Ghost Ownership / fpToken Infinite Mint",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Halborn",
          "audit_date": "2023/09/08",
          "scope": "out",
          "source_url": "https://docs.fp.io/security/audit-by-halborn"
        },
        {
          "firm": "OtterSec",
          "audit_date": "2023/10/04",
          "scope": "out",
          "source_url": "https://docs.fp.io/security/audit-by-ottersec"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/08/yuga-labs-rescues-68-blue-chip-nfts-from-flooring-protocol-exploit/"
        },
        {
          "publisher": "NFTEvening",
          "kind": "news",
          "url": "https://nftevening.com/white-hats-rescue-500k-nfts-flooring-protocol-exploit/"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/floor-protocol-exploited-bored-apes-and-pudgy-penguins-gone/"
        },
        {
          "publisher": "Floor Protocol Docs",
          "kind": "protocol",
          "url": "https://docs.fp.io/security/audit-by-halborn"
        },
        {
          "publisher": "Floor Protocol Docs",
          "kind": "protocol",
          "url": "https://docs.fp.io/security/audit-by-ottersec"
        }
      ]
    },
    {
      "id": "H107",
      "protocol": "Token of Power (TOP)",
      "hack_date": "2026-06-09",
      "amount_usd": 1580000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "token",
      "attack_type": "Governance takeover via malicious Aragon DAO proposal (no-timelock single-tx mint), drained TOP/WETH Balancer V1 pool",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "Cyvers (CyversAlerts)",
          "kind": "security_firm",
          "url": "https://x.com/CyversAlerts/status/2064335152440844753"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/token-of-power-exploit-drains-1-58m-from-balancer-pool/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/token-of-power-top-aragon-dao-exploit/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/governance-takeover-lets-attacker-mint-10b-top-tokens-in-1-5m-exploit/"
        },
        {
          "publisher": "TRM Labs",
          "kind": "security_firm",
          "url": "https://www.trmlabs.com/resources/blog/the-top-takeover-tornado-cashs-latest-chapter"
        },
        {
          "publisher": "The Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/10/one-vote-1-58m-gone-top-token-hit-by-alleged-governance-attack/"
        },
        {
          "publisher": "Bitcoinist",
          "kind": "news",
          "url": "https://bitcoinist.com/token-of-power-governance-exploit-drains-1-58-million-in-weth-trm-says/"
        },
        {
          "publisher": "KuCoin News",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/token-of-power-governance-attack-drains-1-58m-via-balancer-pool"
        }
      ]
    },
    {
      "id": "H105",
      "protocol": "Asterix",
      "hack_date": "2026-06-09",
      "amount_usd": 40000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "token",
      "attack_type": "DN404 Forge Loop (ghost ownership — token ID approval reuse in BT404-style accounting)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "CryptoNews",
          "kind": "news",
          "url": "https://cryptonews.net/news/security/32987389/"
        },
        {
          "publisher": "Bitget News (SlowMist analysis)",
          "kind": "security_firm",
          "url": "https://www.bitget.com/amp/news/detail/12560605450521"
        },
        {
          "publisher": "Bitget News",
          "kind": "news",
          "url": "https://www.bitget.com/amp/news/detail/12560605451484"
        }
      ]
    },
    {
      "id": "H106",
      "protocol": "NovaBox",
      "hack_date": "2026-06-09",
      "amount_usd": 107000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Dividend Snapshot Exploit / Flash Loan",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "CryptoTimes",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/10/novabox-loses-nearly-99-86-eth-reward-pool-in-flash-loan-exploit/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/hacks"
        }
      ]
    },
    {
      "id": "H108",
      "protocol": "Raydium (legacy AMM V3 / order-book AMM liquidity pools)",
      "hack_date": "2026-06-10",
      "amount_usd": 1340000,
      "chains": [
        "Solana"
      ],
      "victim_type": "protocol",
      "attack_type": "Fake LP token mint / remove-liquidity validation bypass (logic flaw in deprecated AMM program)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Kudelski Security",
          "audit_date": "2021/05/11",
          "scope": "out",
          "source_url": "https://github.com/raydium-io/raydium-docs/raw/master/audit/Kudelski%20Q2%202021/Raydium_Audit.pdf"
        },
        {
          "firm": "OtterSec",
          "audit_date": "2022/11/11",
          "scope": "out",
          "source_url": "https://github.com/raydium-io/raydium-docs/raw/master/audit/OtterSec%20Q3%202022/Raydium%20updated%20order-book%20AMM%20program.pdf"
        },
        {
          "firm": "MadShield (now OShield)",
          "audit_date": "2023/06/10",
          "scope": "out",
          "source_url": "https://github.com/raydium-io/raydium-docs/raw/master/audit/MadSheild%20Q2%202023/Raydium%20updated%20orderbook%20AMM%20program%20%26%20OpenBook%20migration.pdf"
        },
        {
          "firm": "Halborn",
          "audit_date": "2024/11/11",
          "scope": "out",
          "source_url": "https://github.com/raydium-io/raydium-docs/raw/master/audit/Halborn%20Q4%202024/raydium_liquidity_locking.pdf"
        },
        {
          "firm": "Sec3",
          "audit_date": "2026/04/21",
          "scope": "out",
          "source_url": "https://github.com/raydium-io/raydium-docs/raw/master/audit/Sec3%20Q2%202026/raydium_clmm_limitorder_dynamicfee.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 7,
      "sources": [
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/raydium-promises-full-refund-after-1-3m-solana-pool-exploit/"
        },
        {
          "publisher": "CCN",
          "kind": "news",
          "url": "https://www.ccn.com/news/crypto/raydium-exploit-legacy-pools-solana/"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/raydiums-old-liquidity-pools-exploited-for-1-3-million/"
        },
        {
          "publisher": "Yahoo Finance / Decrypt",
          "kind": "news",
          "url": "https://finance.yahoo.com/markets/crypto/articles/fake-token-exploit-bleeds-raydium-120715548.html"
        },
        {
          "publisher": "Cryptonews",
          "kind": "news",
          "url": "https://cryptonews.com/news/raydium-exploit-fake-lp-tokens-deprecated-solana-pools/"
        },
        {
          "publisher": "DARKNAVY (technical post-mortem)",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/raydium-legacy-remove-liquidity-lp-mint-validation/"
        },
        {
          "publisher": "Crypto Times (citing GoPlus analysis)",
          "kind": "security_firm",
          "url": "https://www.cryptotimes.io/2026/06/11/raydium-exploit-update-goplus-reveals-how-hacker-stole-1-34m/"
        },
        {
          "publisher": "99Bitcoins",
          "kind": "news",
          "url": "https://99bitcoins.com/news/altcoins/raydium-dex-hack-134m-dormant-pools/"
        },
        {
          "publisher": "PeckShieldAlert",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2064729285894852609"
        },
        {
          "publisher": "Raydium (official audit repository)",
          "kind": "protocol",
          "url": "https://github.com/raydium-io/raydium-docs/tree/master/audit"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/raydium"
        }
      ]
    },
    {
      "id": "H118",
      "protocol": "Secret Network (Axelar IBC bridge / modified CW20-ICS20 contract)",
      "hack_date": "2026-06-10",
      "amount_usd": 4670000,
      "chains": [
        "Secret",
        "Axelar",
        "Cosmos",
        "Osmosis",
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "Unbacked/infinite mint via forged IBC packets",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/405459/secret-networks-axelar-bridge-drained-for-4-67-million-in-infinite-mint-exploit-that-went-unnoticed-for-seven-days"
        },
        {
          "publisher": "Cointelegraph (via TradingView)",
          "kind": "news",
          "url": "https://www.tradingview.com/news/cointelegraph:e52a8055f094b:0-secret-network-bridge-exploited-for-4-7m-with-infinite-mint-bug/"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/axelar-bridged-tokens-worth-4-67-million-drained-in-secret-network-contract-exploit/"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/axelar-shuts-down-secret-network-bridge-routes-after-4-7m-exploit/"
        },
        {
          "publisher": "KuCoin News (Axelar clarification)",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/axelar-clarifies-4-67m-secret-network-bridge-exploit-origin"
        },
        {
          "publisher": "Bitcoinist",
          "kind": "news",
          "url": "https://bitcoinist.com/secret-network-axelar-bridge-suspended-after-4-67m-infinite-mint-exploit/"
        }
      ]
    },
    {
      "id": "H110",
      "protocol": "Thetanuts Finance",
      "hack_date": "2026-06-15",
      "amount_usd": 105000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Low-supply share-price / index-token mint manipulation via flash loan (integer-division truncation in mint/claim math)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "PeckShield",
          "audit_date": "2022/05/28",
          "scope": "out",
          "source_url": "https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Thetanuts-v1.0.pdf"
        },
        {
          "firm": "Zokyo",
          "audit_date": "2022/03/16",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1MS_2CmNzIpOoSfjogLRVPubZOC5zmpvd/view"
        },
        {
          "firm": "Akira Tech",
          "audit_date": "2022/03",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1yOHxBlbZI_qoNgTRZeT-3g5syWP6w3sd/view"
        },
        {
          "firm": "X41 D-Sec",
          "audit_date": "2021/12/14",
          "scope": "out",
          "source_url": "https://x41-dsec.de/static/reports/X41-Audit-Thetanuts-2021-11-Public-Report.pdf"
        },
        {
          "firm": "Consensys Diligence",
          "audit_date": "2023/11",
          "scope": "out",
          "source_url": "https://consensys.io/diligence/audits/private/f2sb58y9uhrao9/"
        },
        {
          "firm": "Halborn",
          "audit_date": "2024/02/12",
          "scope": "out",
          "source_url": "https://drive.google.com/file/d/1X0zRpY7WgWjoEEEChIiJRdxFOXKpW-tL/"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://x.com/SlowMist_Team/status/2066548856138162628"
        },
        {
          "publisher": "Cryptopolitan",
          "kind": "news",
          "url": "https://www.cryptopolitan.com/hack-deprecated-thetanuts-vault/"
        },
        {
          "publisher": "Crypto Economy",
          "kind": "news",
          "url": "https://crypto-economy.com/thetanutsfi-suffers-2-1-million-exploit-white-hat-recovers-most-funds/"
        },
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/15/2-1m-exploit-hits-thetanuts-inside-the-latest-defi-flash-loan/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/thetanuts-deprecated-vault-exploit-defi/"
        },
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://coindesk.cc/deprecated-thetanuts-vault-exploited-for-2-1-million-in-latest-defi-attack-64541.html"
        },
        {
          "publisher": "Thetanuts Finance (docs)",
          "kind": "protocol",
          "url": "https://docs.thetanuts.finance/contracts-and-security/security"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/thetanuts-finance"
        }
      ]
    },
    {
      "id": "H114",
      "protocol": "Aztec Connect Private Rollup Bridge (RollupProcessor escapeHatch) exploit",
      "hack_date": "2026-06-17",
      "amount_usd": 2190000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "escapeHatch function exploit (missing access control + unverified rollup proof / public-input binding) on deprecated immutable bridge",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Solidified",
          "audit_date": "2022/04/10",
          "scope": "probable",
          "source_url": "https://github.com/solidified-platform/audits/blob/master/Audit%20Report%20-%20Aztec%20.pdf"
        },
        {
          "firm": "Sentnl",
          "audit_date": "2022/03/26",
          "scope": "out",
          "source_url": "https://aztec.network/blog/layer-by-layer-a-guide-to-aztecs-security-approach"
        },
        {
          "firm": "Sentnl (Sentnlio Ltd)",
          "audit_date": "2022/03/26",
          "scope": "out",
          "source_url": "https://github.com/AztecProtocol/aztec-connect/blob/master/audits/Security%20Audit%20%20Results%20-%20Aztec%20Protocol.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "PeckShieldAlert",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2067502440044437871"
        },
        {
          "publisher": "CertiKAlert",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2067497629127410058"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/aztec-private-rollup-bridge-escape-hatch-claim-proof-drain/"
        },
        {
          "publisher": "Protos (citing BlockSec; flagged by researcher Vishal Singh)",
          "kind": "news",
          "url": "https://protos.com/aztec-network-hit-by-second-hack-this-week-as-escapehatch-drained-of-2m/"
        },
        {
          "publisher": "The Crypto Times (citing SlowMist)",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/18/aztec-networks-rollupprocessor-exploited-for-2-21-million/"
        },
        {
          "publisher": "AMBCrypto (citing SlowMist)",
          "kind": "news",
          "url": "https://ambcrypto.com/aztec-network-attacked-twice-in-3-days-hacker-drains-2-21m-in-digital-assets/"
        },
        {
          "publisher": "TronWeekly",
          "kind": "news",
          "url": "https://www.tronweekly.com/aztec-network-exploit-2-16m-drained-from/"
        },
        {
          "publisher": "Halborn",
          "kind": "security_firm",
          "url": "https://www.halborn.com/blog/post/explained-the-aztec-connect-hack-june-2026"
        },
        {
          "publisher": "CoinJournal",
          "kind": "news",
          "url": "https://coinjournal.net/news/aztec-network-loses-over-4-million-in-three-days-to-two-subsequent-hacks/"
        },
        {
          "publisher": "Aztec Labs (audit history)",
          "kind": "protocol",
          "url": "https://aztec.network/blog/layer-by-layer-a-guide-to-aztecs-security-approach"
        },
        {
          "publisher": "SlowMist",
          "kind": "security_firm",
          "url": "https://slowmist.medium.com/analysis-of-the-2-19-million-asset-theft-from-aztec-connect-d867c59b1fc6"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/aztec-connect-deprecated-contract-exploit-2-1m-zk-proof"
        },
        {
          "publisher": "KuCoin News",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/aztec-connect-hacked-for-2-19m-via-zk-rollup-vulnerability"
        },
        {
          "publisher": "Aztec Labs (official X)",
          "kind": "protocol",
          "url": "https://x.com/AztecLabs_/status/2067511785637163354"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/aztec-connect"
        },
        {
          "publisher": "Aztec Protocol / Sentnl",
          "kind": "security_firm",
          "url": "https://github.com/AztecProtocol/aztec-connect/blob/master/audits/Security%20Audit%20%20Results%20-%20Aztec%20Protocol.pdf"
        }
      ]
    },
    {
      "id": "H112",
      "protocol": "DIP",
      "hack_date": "2026-06-17",
      "amount_usd": 111000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Transfer/Sell Logic Exploit — missing return statement causes double-execution of transfer logic, enabling skim()/sync() reserve manipulation",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/dip-token-double-transfer-reserve-manipulation/"
        },
        {
          "publisher": "Bitcoin.com (SlowMist)",
          "kind": "security_firm",
          "url": "https://news.bitcoin.com/dip-token-exploit-slowmist-usdc/"
        },
        {
          "publisher": "GnCrypto News",
          "kind": "news",
          "url": "https://www.gncrypto.news/news/missing-return-attacker-drain-111098-dip-token/"
        },
        {
          "publisher": "WEEX (TenArmorAlert)",
          "kind": "other",
          "url": "https://www.weex.com/news/detail/data-dip-tokens-on-the-bsc-chain-were-attacked-resulting-in-a-loss-of-approximately-111100-kf1qqk7xn4ordkf9njrbrmmy"
        }
      ]
    },
    {
      "id": "H113",
      "protocol": "Little Boy Plus",
      "hack_date": "2026-06-17",
      "amount_usd": 367000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Unauthorized minting via zero-value transferFrom bypass (logic exploit in LBPHashrate._update())",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/18/little-boy-plus-loses-377k-after-exploit-targets-minting-bug/"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        }
      ]
    },
    {
      "id": "H117",
      "protocol": "Namada Shielded Pools",
      "hack_date": "2026-06-19",
      "amount_usd": 600000,
      "chains": [
        "Namada"
      ],
      "victim_type": "protocol",
      "attack_type": "IBC Transfer Logic Exploit — shielded cross-chain asset sweep from Multi-Asset Shielded Pool (MASP)",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "Informal Systems",
          "audit_date": "2024/08/16",
          "scope": "probable",
          "source_url": "https://github.com/informalsystems/audits/blob/main/Anoma/2024-08-16%20IBC%20and%20MASP%20integrations%20Final%20Report.pdf"
        },
        {
          "firm": "Least Authority",
          "audit_date": "2023/07/03",
          "scope": "out",
          "source_url": "https://leastauthority.com/wp-content/uploads/2025/07/Least-Authority-Heliax-Namada-Interface-Final-Audit-Report.pdf"
        },
        {
          "firm": "Oak Security",
          "audit_date": "2023/03/28",
          "scope": "out",
          "source_url": "https://github.com/oak-security/audit-reports/blob/main/Anoma/2023-03-28%20Audit%20Report%20-%20Namada%20Ethereum%20Bridge%20v1.0.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "Crypto Times",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/20/namadas-600k-masp-drain-goes-unnoticed-as-stale-indexer-masks-the-loss/"
        },
        {
          "publisher": "BingX News",
          "kind": "news",
          "url": "https://bingx.com/en/news/post/namada-confirms-exploit-as-masp-tvl-drops-to-on-june"
        },
        {
          "publisher": "CoinTrust",
          "kind": "news",
          "url": "https://www.cointrust.com/market-news/namada-investigates-protocol-exploit-amid-security-review"
        },
        {
          "publisher": "CryptoRank",
          "kind": "news",
          "url": "https://cryptorank.io/news/feed/54d1e-namada-protocol-exploit"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        },
        {
          "publisher": "Namada (official security page)",
          "kind": "protocol",
          "url": "https://namada.net/security"
        }
      ]
    },
    {
      "id": "H116",
      "protocol": "mySwap CL",
      "hack_date": "2026-06-19",
      "amount_usd": 305000,
      "chains": [
        "Starknet"
      ],
      "victim_type": "protocol",
      "attack_type": "CL Pool Accounting Manipulation via Fake Token",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "CryptoAdventure",
          "kind": "news",
          "url": "https://cryptoadventure.com/myswap-loses-305k-on-starknet-after-fake-evil-token-abuses-cl-pool-accounting/"
        },
        {
          "publisher": "Phemex News",
          "kind": "news",
          "url": "https://phemex.com/news/article/starknets-myswap-protocol-exploited-300000-drained-90069"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/myswap-cl"
        }
      ]
    },
    {
      "id": "H120",
      "protocol": "jaredfromsubway.eth MEV bot",
      "hack_date": "2026-06-20",
      "amount_usd": 7500000,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "other",
      "attack_type": "reverse/counter-MEV honeypot — fake-token approval drain",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 6,
      "sources": [
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/405464/notorious-jaredfromsubway-mev-bot-drained-for-roughly-7-5-million-in-counter-mev-honeypot"
        },
        {
          "publisher": "Chainalysis",
          "kind": "security_firm",
          "url": "https://www.chainalysis.com/blog/sandwich-attack-jaredfromsubway-hack/"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/jaredfromsubway-eth-mev-bot-drained-7-5-million-counter-mev-honeypot"
        },
        {
          "publisher": "Protos",
          "kind": "news",
          "url": "https://protos.com/mev-bot-jaredfromsubway-eth-loses-7-5m-to-approvals-honeypot/"
        },
        {
          "publisher": "BeInCrypto",
          "kind": "news",
          "url": "https://beincrypto.com/jaredfromsubway-mev-bot-honeypot-exploit/"
        },
        {
          "publisher": "Gizmodo",
          "kind": "news",
          "url": "https://gizmodo.com/infamous-front-running-crypto-bot-jaredfromsubway-gets-tricked-and-drained-for-7-5m-2000774984"
        },
        {
          "publisher": "crypto.news",
          "kind": "news",
          "url": "https://crypto.news/jaredfromsubway-mev-bot-gets-drained-in-7-5m-approval-trap/"
        },
        {
          "publisher": "BleepingComputer",
          "kind": "news",
          "url": "https://www.bleepingcomputer.com/news/security/jaredfromsubway-mev-bot-hacked-in-15-million-crypto-theft/"
        },
        {
          "publisher": "Incrypted",
          "kind": "news",
          "url": "https://incrypted.com/en/predator-became-prey-well-known-ethereum-mev-bot/"
        },
        {
          "publisher": "@DishitaInCrypto (X, candidate lead)",
          "kind": "x",
          "url": "https://x.com/DishitaInCrypto/status/2071530388435157099"
        }
      ]
    },
    {
      "id": "H119",
      "protocol": "PancakeSwap OLPC/LABUBU pool exploit (BSC)",
      "hack_date": "2026-06-20",
      "amount_usd": 1100000,
      "chains": [
        "BSC"
      ],
      "victim_type": "token",
      "attack_type": "Malicious token logic / deflationary burn reserve manipulation (rug time-bomb)",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "DefiLlama (hacks API)",
          "kind": "defillama",
          "url": "https://api.llama.fi/hacks"
        },
        {
          "publisher": "ExVul (@exvulsec) security firm",
          "kind": "security_firm",
          "url": "https://x.com/exvulsec/status/2068308334512365924"
        },
        {
          "publisher": "AMBCrypto (cites @evilcos/SlowMist + @exvulsec)",
          "kind": "news",
          "url": "https://ambcrypto.com/bnblabubu-exploit-drains-1-1mln-after-olpc-reserve-mismatch-details/"
        },
        {
          "publisher": "Crypto Times (cites PeckShield, ExVul, SlowMist)",
          "kind": "news",
          "url": "https://www.cryptotimes.io/2026/06/20/pancakeswap-labubu-pool-exploited-for-1-1m-what-went-wrong/"
        },
        {
          "publisher": "Bloomingbit (PancakeSwap official statement + PeckShield)",
          "kind": "news",
          "url": "https://en.bloomingbit.io/feed/news/114666"
        },
        {
          "publisher": "PeckShield via BingX flash news",
          "kind": "security_firm",
          "url": "https://bingx.com/en/flash-news/post/peckshield-pancakeswap-olpc-labubu-pool-on-bnb-chain-hacked-about-m-taken-and-eth-sent-to-tornado-cash"
        },
        {
          "publisher": "CryptoNews",
          "kind": "news",
          "url": "https://cryptonews.net/news/security/33038552/"
        },
        {
          "publisher": "ChainCatcher",
          "kind": "news",
          "url": "https://www.chaincatcher.com/en/article/2272571"
        },
        {
          "publisher": "DEXTools News ('46-day time bomb' analysis)",
          "kind": "news",
          "url": "https://www.dextools.io/news/pancakeswap-labubi-olpc-exploit-time-bomb-2026"
        },
        {
          "publisher": "PeckShield",
          "kind": "security_firm",
          "url": "https://x.com/PeckShieldAlert/status/2068314444422402515"
        },
        {
          "publisher": "KuCoin",
          "kind": "news",
          "url": "https://www.kucoin.com/news/flash/pancakeswap-olpc-labubu-pool-on-bsc-hacked-1-1m-stolen-and-converted-to-633-4-eth"
        },
        {
          "publisher": "Bitcoin World",
          "kind": "protocol",
          "url": "https://bitcoinworld.co.in/pancakeswap-smart-contracts-not-at-fault-hack/"
        },
        {
          "publisher": "PancakeSwap Docs",
          "kind": "protocol",
          "url": "https://docs.pancakeswap.finance/welcome-to-pancakeswap/audits"
        }
      ]
    },
    {
      "id": "H123",
      "protocol": "SecondFi (formerly Yoroi Wallet)",
      "hack_date": "2026-06-21",
      "amount_usd": 2400000,
      "chains": [
        "Cardano"
      ],
      "victim_type": "wallet",
      "attack_type": "predictable-private-key / deterministic-nonce signing flaw (Ed25519 secret nonce unset) enabling private-key reconstruction from on-chain signatures",
      "audit_status": "unaudited",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/business/2026/06/24/secondfi-loses-usd2-4-million-in-cardano-wallet-exploit-with-up-to-usd20-million-at-risk"
        },
        {
          "publisher": "The Block",
          "kind": "news",
          "url": "https://www.theblock.co/post/406457/secondfi-maps-recovery-path-after-2-4-million-cardano-wallet-exploit-aims-to-return-funds-within-two-weeks"
        },
        {
          "publisher": "Crypto Briefing",
          "kind": "news",
          "url": "https://cryptobriefing.com/secondfi-exploit-drains-cardano-users/"
        },
        {
          "publisher": "AMBCrypto",
          "kind": "news",
          "url": "https://ambcrypto.com/cardano-wallet-exploit-secondfi-traces-attack-to-private-key-flaw-warns-users-not-to-restore-seed-phrases/"
        },
        {
          "publisher": "Bitquery (on-chain investigation)",
          "kind": "explorer",
          "url": "https://bitquery.io/investigations/cardano-secondfi-129m-drain"
        },
        {
          "publisher": "SecondFi (official, @secondfiapp)",
          "kind": "protocol",
          "url": "https://x.com/secondfiapp/status/2069306133337227382"
        },
        {
          "publisher": "SecondFi (official, @secondfiapp)",
          "kind": "protocol",
          "url": "https://x.com/secondfiapp/status/2069651138933346807"
        },
        {
          "publisher": "Blockonomi",
          "kind": "news",
          "url": "https://blockonomi.com/secondfi-exploit-drains-374-cardano-wallets-over-16-million-ada-stolen-in-coordinated-attack/"
        },
        {
          "publisher": "DishitaInCrypto (X)",
          "kind": "x",
          "url": "https://x.com/DishitaInCrypto/status/2071530388435157099"
        },
        {
          "publisher": "Abdulkarim2 (X)",
          "kind": "x",
          "url": "https://x.com/Abdulkarim2/status/2071519711423017466"
        }
      ]
    },
    {
      "id": "H122",
      "protocol": "Taiko Bridge",
      "hack_date": "2026-06-22",
      "amount_usd": 1700000,
      "chains": [
        "Taiko",
        "Ethereum"
      ],
      "victim_type": "bridge",
      "attack_type": "Forged cross-chain withdrawal proofs via leaked SGX prover signing key",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "OpenZeppelin",
          "audit_date": "2024/06/26",
          "scope": "out",
          "source_url": "https://www.openzeppelin.com/news/taiko-protocol-audit"
        },
        {
          "firm": "QuillAudits",
          "audit_date": "2024/02",
          "scope": "out",
          "source_url": "https://www.quillaudits.com/case-studies/taiko-protocol-security-audit"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 5,
      "sources": [
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/tech/2026/06/22/taiko-halts-its-ethereum-layer-2-network-after-a-bridge-exploit-token-dives-10"
        },
        {
          "publisher": "DARKNAVY",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/taiko-bridge-source-signal-proof-forgery/"
        },
        {
          "publisher": "Incrypted (citing PeckShield, BlockSec/Phalcon, and Taiko official statement)",
          "kind": "news",
          "url": "https://incrypted.com/en/taiko-suffers-nearly-2m-exploit-urges-users-to-withdraw-funds/"
        },
        {
          "publisher": "The Defiant",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/taiko-bridge-exploit-sgx-signing-key-github-1-7m"
        },
        {
          "publisher": "thirdweb",
          "kind": "news",
          "url": "https://blog.thirdweb.com/taiko-bridge-exploit-explained-how-a-leaked-key-led-to-1-7m-in-forged-withdrawals/"
        },
        {
          "publisher": "CertiK Alert (X)",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2068947256309596293"
        },
        {
          "publisher": "soladrome (X)",
          "kind": "x",
          "url": "https://x.com/soladrome/status/2071360549305421980"
        },
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://api.llama.fi/protocol/taiko-bridge"
        }
      ]
    },
    {
      "id": "H155",
      "protocol": "Royalties (Royal.io)",
      "hack_date": "2026-06-23",
      "amount_usd": 261200,
      "chains": [
        "Polygon"
      ],
      "victim_type": "protocol",
      "attack_type": "ERC1155 zero-amount batch transfer inflates custom tier balance, enabling 100x royalty overclaim (flawed settlement / accounting inflation)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "confirmed",
      "independent_source_count": 3,
      "sources": [
        {
          "publisher": "CertiKAlert",
          "kind": "security_firm",
          "url": "https://x.com/CertiKAlert/status/2069625284790505723"
        },
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/old-royalties-contract-on-polygon-attacked-261200-lost/"
        },
        {
          "publisher": "DarkNavy",
          "kind": "security_firm",
          "url": "https://www.darknavy.org/web3/exploits/royal-royalties-zero-amount-erc1155-accounting-inflation/"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        }
      ]
    },
    {
      "id": "H124",
      "protocol": "Royal.io",
      "hack_date": "2026-06-23",
      "amount_usd": 261200,
      "chains": [
        "Polygon"
      ],
      "victim_type": "other",
      "attack_type": "Reward Record Stacking via Zero-Value Transfers (Hook/Settlement Logic Manipulation)",
      "audit_status": "unknown",
      "auditors": [],
      "verification": "likely",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "Cryip",
          "kind": "news",
          "url": "https://cryip.co/old-royalties-contract-on-polygon-attacked-261200-lost/"
        },
        {
          "publisher": "CertiK",
          "kind": "security_firm",
          "url": "https://x.com/CertiK/status/2050243749972689267"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        }
      ]
    },
    {
      "id": "H125",
      "protocol": "Polymarket (front-end supply-chain / phishing drain)",
      "hack_date": "2026-06-25",
      "amount_usd": 3100000,
      "chains": [
        "Polygon",
        "Ethereum"
      ],
      "victim_type": "other",
      "attack_type": "Front-end supply-chain attack (compromised third-party JS dependency) leading to wallet-drainer phishing",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "ChainSecurity",
          "audit_date": "2024/04/11",
          "scope": "out",
          "source_url": "https://www.chainsecurity.com/security-audit/polymarket-exchange-smart-contracts"
        },
        {
          "firm": "OpenZeppelin",
          "audit_date": "2023/08/16",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/oz_neg_risk_adapter.pdf"
        },
        {
          "firm": "Cantina",
          "audit_date": "2026/06/03",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/Polymarket%20V2%20Diff%20Review%20-%20Cantina%20-%20June%202026.pdf"
        },
        {
          "firm": "Certora",
          "audit_date": "2026/04/17",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/Polymarket%20V2%20-%20Certora%20-%20April%202026.pdf"
        },
        {
          "firm": "Quantstamp",
          "audit_date": "2026/05/26",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/Polymarket%20V2%20-%20Quantstamp%20-%20May%202026.pdf"
        },
        {
          "firm": "Pashov Audit Group",
          "audit_date": "2026/05/03",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/Polymarket%20V2%20-%20Pashov%20-%20May%202026.pdf"
        },
        {
          "firm": "Zellic",
          "audit_date": "2026/03/13",
          "scope": "out",
          "source_url": "https://github.com/Polymarket/contract-security/blob/main/audit-reports/DepositWallet%20-%20Zellic%20-%20March%202026.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 8,
      "sources": [
        {
          "publisher": "CoinDesk",
          "kind": "news",
          "url": "https://www.coindesk.com/markets/2026/06/27/polymarket-hack-updated-to-usd3-1-million-days-after-the-platform-promised-users-full-refunds"
        },
        {
          "publisher": "SecurityWeek",
          "kind": "news",
          "url": "https://www.securityweek.com/3-million-reportedly-stolen-in-polymarket-hack/"
        },
        {
          "publisher": "BleepingComputer",
          "kind": "news",
          "url": "https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/"
        },
        {
          "publisher": "CyberInsider",
          "kind": "news",
          "url": "https://cyberinsider.com/polymarket-suffers-supply-chain-attack-leading-to-3-million-crypto-theft/"
        },
        {
          "publisher": "The Defiant (citing AMLBot/Specter)",
          "kind": "news",
          "url": "https://thedefiant.io/news/hacks/amlbot-polymarket-phishing-3-1-million-11-wallets-ethereum"
        },
        {
          "publisher": "Bitcoin.com News",
          "kind": "news",
          "url": "https://news.bitcoin.com/polymarket-3-million-third-party-breach/"
        },
        {
          "publisher": "crypto.news (citing PeckShield)",
          "kind": "security_firm",
          "url": "https://crypto.news/polymarket-hack-losses-rise-to-3-1m-as-refund-pledge-faces-scrutiny/"
        },
        {
          "publisher": "PeckShieldAlert",
          "kind": "x",
          "url": "https://x.com/PeckShieldAlert/status/2070157742514618443"
        },
        {
          "publisher": "Rescana",
          "kind": "security_firm",
          "url": "https://www.rescana.com/post/polymarket-supply-chain-attack-analysis-3-million-cryptocurrency-theft-via-compromised-third-party-dependency"
        },
        {
          "publisher": "Polymarket (official audit repo)",
          "kind": "protocol",
          "url": "https://github.com/Polymarket/contract-security"
        }
      ]
    },
    {
      "id": "H126",
      "protocol": "Lixir Finance",
      "hack_date": "2026-06-25",
      "amount_usd": 12300,
      "chains": [
        "Ethereum"
      ],
      "victim_type": "protocol",
      "attack_type": "Broken EIP-2612 permit signature verification — attacker reused dummy/invalid signature to bypass authorization and drain vault token underlying assets",
      "audit_status": "audited",
      "auditors": [
        {
          "firm": "CertiK",
          "audit_date": "2021/09/12",
          "scope": "out",
          "source_url": "https://github.com/LIXIR-FINANCE/audits/blob/main/REP-Lixir-Finance-2021-09-12.pdf"
        },
        {
          "firm": "Haechi",
          "audit_date": "2021/10/27",
          "scope": "probable",
          "source_url": "https://github.com/LIXIR-FINANCE/audits/blob/main/HAECHI_AUDIT_Lixir_Finance_Smart_Contract_Audit_Report_ver_1_3.pdf"
        }
      ],
      "verification": "confirmed",
      "independent_source_count": 2,
      "sources": [
        {
          "publisher": "DefiLlama",
          "kind": "defillama",
          "url": "https://defillama.com/protocol/lixir-finance"
        },
        {
          "publisher": "SlowMist Hacked",
          "kind": "security_firm",
          "url": "https://hacked.slowmist.io/"
        },
        {
          "publisher": "Lixir Finance (GitBook)",
          "kind": "protocol",
          "url": "https://lixir-finance.gitbook.io/lixir-doc/resources/security/audits"
        },
        {
          "publisher": "Lixir Finance GitHub",
          "kind": "other",
          "url": "https://github.com/LIXIR-FINANCE/audits"
        }
      ]
    }
  ]
}
