A $292M DeFi hack just exposed the protocol layer's deepest weak spots — insiders say the fixes are overdue.
A single exploit drained $292 million from DeFi protocols, reigniting a debate that the industry has deferred too long…
Exchange, bridge, and protocol breaches where funds were stolen — incident reports and post-mortems.
A single exploit drained $292 million from DeFi protocols, reigniting a debate that the industry has deferred too long…
The scale — 500+ wallets, some untouched for years — suggests something beyond a single-point exploit; the on-chain trail points to a shared compromise vector still under investigation.
Over 500 long-idle wallets — some four to eight years cold — were swept into a tagged phishing address, and the compromise path remains unresolved as April's $635M exploit tally closes.
Hundreds of dormant Ethereum mainnet wallets moved to a single address in a coordinated drain, while ETH trades below every short-term moving average and the 200-day at $2,755 flashes a sell signal.
The record counts both raw dollars and incident count, and the dollar figure only excludes the February 2025 Bybit event — context that frames the month as the worst stretch for protocol security…
The first-ever 9-of-12 emergency multi-sig execution on a major L2 sets a precedent the rest of DeFi will now have to argue about.
Wasabi Protocol has suffered a $4.5 million loss in what appears to be an admin key compromise, allowing an attacker to…
The criticism pits Tether's freeze track record against Circle's silence in a public call to action — and raises the question of whether selling USDC is the lever that moves a $60B stablecoin issuer.
Recovery pace is the story: the largest exchange heist on record was neutralised inside the fiscal year, with revenue continuing to grow through the aftermath.
Internal team wallets were the only target — no user funds hit — but the pause puts a hold on every cross-chain message until the post-mortem lands.
Industry leaders have committed hundreds of millions of dollars to a rescue plan for Aave users following a significant…
The contracts held — the bridge didn't. Aave V3 lost $4B of usable liquidity in 29 hours, and WETH utilization hit 100% in under 90 minutes before the Protocol Guardian stepped in.
The KelpDAO rsETH exploit pulled $12B+ from Aave, and a cross-chain rescue — Solana lending USDT, AAVE going multi-chain — is now the recovery's defining bet.
No user funds were lost and a patch is already live, but a 13-block reorg on a top-20 PoW chain is the kind of event miners, exchanges, and custody providers will be reading closely for weeks.
About 4,500 BTC are reportedly inaccessible after private keys vanished with the missing co-founder, withdrawals are halted, and losses could top $100M as Polish authorities open criminal probes.
GitHub commit logs show the consensus bug was privately fixed four weeks before the attack; the Foundation's 'zero-day' framing is now in dispute, and the LTC moved during the 32-minute invalid…
Five months after a ~$120M exploit, the Balancer attacker is back on-chain, swapping 1,100 ETH into BTC through THORChain's cross-chain router in under an hour.