Loading prices…
Security

Exploits

Smart-contract and DeFi vulnerabilities — oracle manipulation, reentrancy, flash-loan attacks, and governance exploits.

Exploits covers the technical failures and adversarial transactions that put smart contracts, DeFi markets, bridges, wallets and onchain governance systems at risk. The beat includes reentrancy, oracle manipulation, flash-loan-assisted attacks, signature and verification flaws, access-control failures and malicious governance proposals. These incidents matter beyond the protocol directly affected: a compromised price feed can trigger bad debt, a bridge flaw can threaten assets across networks, and a treasury raid can expose weaknesses in voting participation, quorum rules or execution delays. For holders of ETH, USDC, BTC, ADA and ecosystem tokens such as BONK and HBAR, the key questions are not only how much was taken, but which assumptions failed and whether connected markets remain exposed.

Zipp follows exploit reports from the first suspicious transaction through containment, post-mortems and recovery efforts. Day-to-day coverage examines transaction traces, attacker funding, oracle inputs, contract permissions, governance votes, validator or sequencer responses, bridge withdrawal guidance and changes to protocol operations. Recent reporting themes include low-turnout treasury attacks against DAOs, flash-loan exploits in lending systems, oracle and signature failures on Arbitrum and Hedera, verification problems affecting Taiko infrastructure, wallet compromises in the Cardano ecosystem and severe dislocations in Morpho-linked markets. We also track whether teams pause contracts or block production, move assets into security infrastructure such as Chainlink CCIP, negotiate with attackers, compensate users or leave unresolved liabilities. The aim is to separate the exploit mechanism from its market impact and show readers what evidence confirms a loss, what remains uncertain and which follow-on risks deserve attention.

Related tokens

Frequently asked questions

  1. What is a smart contract exploit?

    A smart contract exploit is the use of a coding flaw, faulty assumption or unsafe permission to produce an outcome the protocol did not intend. Not every exploit requires hacked private keys; some attackers interact with deployed contracts exactly as their code permits.

  2. How does an oracle manipulation attack work?

    An attacker distorts or exploits the price data a protocol uses for lending, trading or collateral checks. If the protocol relies on a thin market, a single source or a poorly configured update mechanism, the false price can enable excessive borrowing, unfair liquidations or asset withdrawals.

  3. Why are flash loans used in DeFi exploits?

    Flash loans provide large amounts of temporary capital that must be borrowed and repaid within one transaction. They are legitimate tools, but attackers can use them to amplify oracle manipulation, governance power or accounting flaws without committing substantial capital beforehand.

  4. How can I verify that a reported DeFi exploit happened?

    Check the affected protocol’s official notices, relevant contract addresses and transaction records on a block explorer. Confirm whether independent security researchers identify the same mechanism, and distinguish the attacker’s gross transfers from the protocol’s final net loss.