Cryptocurrency 1086 incidents

Cryptocurrency, DeFi, and Web3 security incidents including exchange hacks, bridge exploits, and smart contract vulnerabilities

Cryptocurrency

SEC Form 8-K

2026-04-06 [vendor] Bitcoin Depot [loss] $4M [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin ATM operator Bitcoin Depot has disclosed a March 23 hack in which attackers stole 50.903 BTC (~$3.67 million) from company wallets. According to the company's disclosure …

Cryptocurrency

Tweet by Solv Protocol

2026-03-05 [vendor] Solv Protocol [loss] $3M [chain] bitcoin
Vector: Smart contract exploit / hack

The Solv Protocol bitcoin defi lending and staking platform disclosed an exploit that they said affected fewer than ten users, but nevertheless netted the attacker 38 SolvBTC (a …

Cryptocurrency

Tweet by Step Finance

2026-02-23 [vendor] Step Finance [chain] solana
Vector: Protocol collapse / insolvency

Step Finance announced that, following a $30 million theft in late January, the project would be shutting down. Along with it, they will shut down SolanaFloor — a Solana-focused …

Cryptocurrency

Tweet by CertiK

2026-01-31 [vendor] Step Finance theft [loss] $29M [chain] solana
Vector: Smart contract exploit / hack

The Solana-based defi portfolio tracker Step Finance lost 261,854 SOL (~$28.7 million) when a thief gained access to treasury and fee wallets. It's not yet clear how the attacker …

Cryptocurrency

Tweet thread by Aperture Finance

2026-01-25 [vendor] Aperture Finance [loss] $3M [chain] ethereum, polygon, bsc, avalanche
Vector: Smart contract exploit / hack

An attacker exploited a bug in an Aperture Finance smart contract to steal at least $3.4 million from users who had enabled "instant liquidity management" features. Aperture …

Cryptocurrency

"SwapNet Incident Post Mortem"

2026-01-25 [vendor] Matcha Meta [loss] $13M [chain] ethereum
Vector: Smart contract exploit / hack

Some users of Matcha Meta, a decentralized exchange aggregator on the Base blockchain, suffered losses after a thief exploited a vulnerability in its SwapNet integration. SwapNet …

Cryptocurrency

Tweet by Saga

2026-01-21 [vendor] Saga [loss] $7M [chain] ethereum
Vector: Private key compromise

The Saga project halted its blockchain after acknowledging that $7 million had been stolen. An attacker was evidently able to mint a large quantity of Saga Dollar tokens, though …

Cryptocurrency

Tweet by RuneCrypto_

2026-01-12 [vendor] NYC Token crash [loss] $1M [chain] solana
Vector: Exit scam / rug pull

Shortly after losing his campaign for re-election as mayor of New York City, Eric Adams announced he would be launching "NYC Token". He's pitched the project as a fundraising tool …

Cryptocurrency

Tweet by zachxbt

2026-01-10 [vendor] Trezor support [loss] $281M [chain] bitcoin, monero, litecoin
Vector: On-chain theft (attributed by zachxbt)

A crypto holder has lost $282 million in bitcoin and litecoin after a scammer impersonating a customer support employee for the Trezor hardware wallet manufacturer successfully …

Cryptocurrency

Tweet by Truebit

2026-01-08 [vendor] Truebit [loss] $27M [chain] ethereum
Vector: Smart contract exploit / hack

A bug in a smart contract belonging to the Ethereum-based Truebit project allowed an attacker to steal 8,535 ETH (~$26.4 million). The thief targeted one of the project's older …

Cryptocurrency

Tweet by PeckShield

2025-12-16 [vendor] Yearn Finance [loss] $304,400 [chain] ethereum
Vector: Flash loan attack on smart contract

Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH …

Cryptocurrency

Tweet by Aevo (fka Ribbon Finance)

2025-12-12 [vendor] Ribbon Finance [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

Ribbon Finance, which has partially rebranded to Aevo, has lost $2.7 million after attackers exploited a vulnerability in the smart contract for legacy Ribbon vaults that enabled …

Cryptocurrency

"Fusaka Mainnet Prysm Incident"

2025-12-04 [vendor] Prysm consensus client bug [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

Ethereum validators running the Prysm consensus client lost around 382 ETH ($1.18 million) after a bug resulted in delays that caused validators to miss blocks and attestations. …

Cryptocurrency

Tweet thread by Homer J

2025-11-21 [vendor] Cardano [chain] cardano
Vector: AI-assisted attack or AI-generated exploit

On November 21, the Cardano blockchain suffered a major chainsplit after someone created a transaction that exploited an old bug in Cardano node software, causing the chain to …

Cryptocurrency

Telegram post by zachxbt

2025-11-20 [vendor] GANA Payment [loss] $3M [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

An attacker stole approximately $3.1 million from the BNB chain-based GANA Payment project. The thief laundered about $1 million of the stolen funds through Tornado Cash shortly …

Cryptocurrency

Tweet thread by Elixir

2025-11-06 [vendor] Elixir [chain] ethereum
Vector: Protocol collapse / insolvency

After the defi yield platform Stream Finance announced a $93 million loss, Elixir announced it would be discontinuing its deUSD synthetic stablecoin. Stream Finance owes $68 …

Cryptocurrency

wrsETH Oracle Malfunction 11/4/25

2025-11-04 [vendor] Moonwell oracle malfunction [loss] $4M [chain] ethereum
Vector: Oracle price manipulation

The Moonwell lending protocol, built on the Base Ethereum L2, wound up with $3.7 million in bad debt after an attacker took advantage of an oracle malfunction that caused the price …

Cryptocurrency

Tweet by Whale Alert

2025-10-15 [vendor] Paxos accidental mint [chain] ethereum
Vector: Software bug / unintentional loss

Paxos, the issuer of PayPal's PYUSD stablecoin, accidentally minted 300 trillion of the supposedly dollar-pegged token. For context, this is approximately 2.5x the global GDP, and …

Cryptocurrency

Tweet by Meta Alchemist

2025-09-23 [vendor] Seedify bridge [loss] $2M [chain] bsc, polygon, ethereum
Vector: Smart contract exploit / hack

An attacker exploited bridges for SFUND, the token issued by the Seedify launchpad and incubator. It appears the exploiter has profited around $1.7 million from the theft. Seedify …

Cryptocurrency

Tweet by Yala

2025-09-14 [vendor] Yala stablecoin depegs [loss] $8M [chain] bitcoin

The YU bitcoin-backed stablecoin lost its intended dollar peg after what they described as "an attempted attack", later writing that there was an "unauthorized transfer of funds". …

Cryptocurrency

"Closing up (the) Shop"

2025-08-28 [vendor] Reddit [chain] polygon

Three years after launching "Collectible Avatars", the NFT project they didn't want to call "NFTs" because they were already becoming kind of cringe, Reddit has decided to pull the …

Cryptocurrency

Tweet by zachxbt

2025-08-19 [vendor] Bitcoiner socially engineered out of $91 million [loss] $91M [chain] bitcoin
Vector: Social engineering attack

A bitcoin holder reportedly fell for a social engineering attack after receiving communications from scammers posing as customer support for a crypto exchange and hardware wallet …

Cryptocurrency

Tweet by BobBodily

2025-08-12 [vendor] Odin.fun [loss] $7M [chain] bitcoin
Vector: Smart contract exploit / hack

Odin.fun, a bitcoin-based memecoin launchpad sort of like the popular pump.fun, was exploited for 58.2 BTC (~$7 million). The attacker had apparently manipulated the price of …

Cryptocurrency

Tweet by CyversAlerts

2025-07-28 [vendor] SuperRare [loss] $731,000 [chain] ethereum
Vector: Smart contract exploit / hack

A hacker stole RARE tokens priced at around $731,000 after exploiting a vulnerability in a staking contract for the SuperRare NFT platform. The attacker funded the exploiter wallet …

Cryptocurrency

Tweet thread by CertiK

2025-07-15 [vendor] Arcadia Finance [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

The Arcadia Finance defi margin protocol was exploited for $3.5 million after an attacker found a vulnerability in a project smart contract. The attacker quickly swapped the stolen …

Cryptocurrency

Tweet by Ramon | Kinto

2025-07-10 [vendor] Kinto token crashes [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The price of Kinto's $K token suddenly crashed 90%, sparking accusations of a rug pull. A tranche of investor tokens had just been unlocked recently, leading some to speculate that …

Cryptocurrency

Tweet by PeckShield

2025-07-09 [vendor] GMX [loss] $42M [chain] ethereum
Vector: Smart contract exploit / hack

The decentralized perpetual exchange GMX has been exploited for $42 million. The exploit involved a vulnerability in one version of the exchange's price calculation smart contract. …

Cryptocurrency

Tweet by Texture

2025-07-09 [vendor] Texture [loss] $2M [chain] solana
Vector: Smart contract exploit / hack

An attacker exploited the Solana-based lending protocol Texture, stealing $2.2 million in user funds from one of the project's vaults.Shortly after the attack, Texture sent a …

Cryptocurrency

Tweet thread by deeberiroz

2025-07-09 [vendor] VennBuild discloses bug [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

On July 9, security researchers at VennBuild and other firms disclosed a "critical backdoor" affecting thousands of smart contracts, which one of the researchers said left "over …

Cryptocurrency

Tweet by Cetus

2025-05-22 [vendor] Cetus [loss] $60M [chain] sui
Vector: Smart contract exploit / hack

An attacker stole $223 million from the Sui-based Cetus Protocol. The project announced shortly after that $163 million of the funds had been frozen, leaving around $60 million …

Cryptocurrency

Tweet by zachxbt

2025-04-27 [vendor] $330 million in Bitcoin apparently stolen; laundering spikes Monero [loss] $331M [chain] monero, bitcoin
Vector: On-chain theft (attributed by zachxbt)

3,250 BTC (~$330 million) were apparently stolen from a bitcoin holder and then quickly moved through multiple exchanges and swapped for the Monero privacycoin. Such a massive swap …

Cryptocurrency

Tweet by Term Labs

2025-04-26 [vendor] Term Finance misconfiguration [loss] $600,000 [chain] ethereum
Vector: Software bug / unintentional loss

The Ethereum-based lending project Term Finance lost $1.6 million when an oracle misconfiguration resulted in unintended liquidations. The team later announced that they had …

Cryptocurrency

Tweet by KiloEx

2025-04-14 [vendor] KiloEx [loss] $750,000 [chain] ethereum, bsc
Vector: Oracle price manipulation

KiloEx, a decentralized perpetual futures exchange, was exploited for $7.5 million. An attacker executed an oracle manipulation attack on KiloEx's pricing smart contracts to steal …

Cryptocurrency

On-chain messages

2025-03-31 [vendor] zkLend [chain] ethereum
Vector: Phishing attack

The zkLend lending platform was hoping they could secure the return of stolen funds from the attacker who stole 3,667 ETH (~$9.5 million at the time) from the platform in …

Cryptocurrency

Telegram post

2025-03-28 [vendor] bc1qvl theft [loss] $46M [chain] bitcoin
Vector: On-chain theft (attributed by zachxbt)

A Coinbase customer reportedly lost 400 BTC (~$35 million) in a scam identified by blockchain sleuth zachxbt. While investigating the massive theft from the single customer, he …

Cryptocurrency

Tweet by 1inch

2025-03-05 [vendor] 1inch [loss] $5M [chain] ethereum
Vector: Smart contract exploit / hack

An attacker exploited a smart contract belonging to the 1inch DEX aggregator, stealing $5 million in the USDC stablecoin and wETH. According to the platform, the vulnerability …

Cryptocurrency

Complaint

2025-02-27 [vendor] Mirashi [loss] $40M [chain] bitcoin
Vector: Phishing attack

A plaintiff named Mandar Mirashi has filed a lawsuit against an unknown defendant accused of stealing around $40 million in bitcoin through a sophisticated phishing attack and/or …

Cryptocurrency

Tweet by Suji Yan

2025-02-27 [vendor] Suji Yan wallet [loss] $4M [chain] ethereum
Vector: Private key compromise

Suji Yan, the founder of the Mask Network, suffered the loss of more than $4 million in various cryptocurrency assets to an apparent wallet hack. According to Yan, the theft …

Cryptocurrency

"0xInfini Incident Analysis"

2025-02-24 [vendor] Almost $50 million stolen from Infini "stablecoin neobank" [loss] $50M [chain] ethereum
Vector: Smart contract exploit / hack

Around $49.5 million in the USDC stablecoin was stolen from the Infini crypto-focused "stablecoin neobank", a fintech company that promises "financial freedom" by "democratizing …

Cryptocurrency

Tweet by Ben Zhou

2025-02-21 [vendor] Bybit [loss] $1.5B [chain] ethereum
Vector: Phishing attack

In what is looking like largest ever theft from a cryptocurrency exchange, attackers took control of a hot wallet belonging to the Bybit cryptocurrency exchange and moved a massive …

Cryptocurrency

Tweet by 0xCygaar

2025-02-18 [vendor] Abstract Cardex [loss] $400,000 [chain] ethereum
Vector: Smart contract exploit / hack

Around $400,000 in ETH was stolen from around 9,000 wallets on the Abstract layer-2 network, which is built by the same company that makes the Pudgy Penguins NFTs. It appears that …

Cryptocurrency

Tweet by Lookonchain

2025-02-14 [vendor] Milei memecoin promotion [loss] $107M [chain] solana

A tweet from Argentina's president Javier Milei promoted a memecoin called Libra, which he described as a "private project [that] will [be] dedicated to encouraging the growth of …

Cryptocurrency

Tweet by Four.Meme

2025-02-11 [vendor] Four.Meme [loss] $183,000 [chain] bsc
Vector: Smart contract exploit / hack

A BNB Chain memecoin platform, Four.Meme, announced on Twitter that they were "currently experiencing a malicious attack". The team briefly paused a portion of the service while …

Cryptocurrency

"AlleyCat - The Gambling Deployer!"

2025-02-01 [vendor] AlleyCat project developer takes presale money to fund gambling habit [loss] $130,000 [chain] solana
Vector: Exit scam / rug pull

The creator of the AlleyCat Solana-based cryptocurrency project has reportedly taken about 600 SOL (~$130,000) raised during the project's presale and transferred it to gambling …

Cryptocurrency

"Poetic Justice"

2025-01-31 [vendor] Rugpuller tool [loss] $10M [chain] solana
Vector: Exit scam / rug pull

A suite of software tools called DogWifTools was popular among memecoin creators looking to rug pull unsuspecting traders. By helping token creators mask supply control and fake …

Cryptocurrency

Tweet by Ether Strategy

2025-01-30 [vendor] Ether Strategy destroys over $500,000 of ETH [loss] $535,850 [chain] ethereum

A Ethereum-based project promising to duplicate the bitcoin leveraged investment strategy used by MicroStrategy has announced that, prior to even launching, 165 ETH (~$535,850) was …

Cryptocurrency

Tweet thread by Arkham

2025-01-30 [vendor] Ross Ulbricht memecoin mistake [chain] solana
Vector: MEV / sandwich attack

Ross Ulbricht, the founder of the Silk Road darknet market place, earned a presidential pardon on January 21 as an apparent thank you by President Trump to the Libertarian Party. …

Cryptocurrency

Tweet by SlowMist

2025-01-21 [vendor] Fake Trump Twitter account memecoins [loss] $1M [chain] solana
Vector: Smart contract exploit / hack

A Twitter account called @TrumpDailyPosts has more than 1.3 million followers on Twitter. While the account does automatically crosspost to Twitter any posts Donald Trump makes on …

Cryptocurrency

Tweet by Melania Trump

2025-01-19 [vendor] Melania Trump's tweet announcing the memecoin [chain] solana

Before people had a chance to process the fact that the incoming president of the United States had just launched his own transparent crypto cash-grab, the soon-to-be First Lady …

Cryptocurrency

Tweet by Donald Trump

2025-01-17 [vendor] Trump memecoin promo image [chain] solana

In what is likely a preview of the levels of grift about to come — levels previously not thought possible — Trump has launched a Solana memecoin two days before his inauguration. …

Cryptocurrency

"The Idols NFT"

2025-01-14 [vendor] The Idols NFT [loss] $324,000 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker noticed a vulnerability in a smart contract for The Idols, an NFT project that also incorporates ETH staking functionality. They discovered that a function used to …

Cryptocurrency

Tweet by SlowMist

2025-01-12 [vendor] UniLend [loss] $197,600 [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

The UniLend project, which advertises itself as a "unified platform for all things AI and defi", was exploited for almost $200,000. An attacker was able to take advantage of a bug …

Cryptocurrency

"Moby Post-Mortem Report / Growth Plan"

2025-01-08 [vendor] Moby Trade theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

The Moby Trade defi options protocol suffered a $1 million loss, narrowly avoiding the loss of another nearly $1.5 million. The project team stated that a hacker had "identified …

Cryptocurrency

Tweet by Orange Finance

2025-01-08 [vendor] Orange Finance [loss] $840,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Arbitrum-based liquidity management project Orange Finance suffered at least $840,000 in losses after hackers compromised the project's admin address, then used it to upgrade …

Cryptocurrency

Telegram post

2025-01-01 [vendor] NoOnes [loss] $8M [chain] solana
Vector: On-chain theft (attributed by zachxbt)

After crypto sleuth zachxbt noticed an apparent theft from the NoOnes peer-to-peer crypto trading platform on January 1, CEO Ray Youssef was forced to acknowledge the theft. He …

Cryptocurrency

Indictment

2024-12-18 [vendor] Hay and Mayo [loss] $22M [chain] ethereum, solana
Vector: Exit scam / rug pull

Gabriel Hay and Gavin Mayo, two LA-based NFT creators, have been charged for defrauding investors of more than $22.4 million through a series of NFT rug pulls and other crypto …

Cryptocurrency

Tweet by Anchor Drops

2024-12-12 [vendor] Crypto holder [loss] $2M [chain] ethereum, bitcoin
Vector: Seed phrase / wallet compromise

A crypto holder tweeted at the Ledger hardware wallet manufacturer to report that 10 BTC (~$1 million) and "~1.5m of NFTs" had been stolen from a Ledger wallet they were using. …

Cryptocurrency

"Clober Dex Incident Analysis"

2024-12-11 [vendor] Clober DEX [loss] $501,000 [chain] ethereum
Vector: Smart contract exploit / hack

Clober, a DEX built on Coinbase's Base Ethereum layer-2, suffered an exploit only about a week after its launch. A re-entrancy bug in the project allowed an attacker to siphon …

Cryptocurrency

"False prophet"

2024-12-10 [vendor] Alpaca Finance oracle issue [loss] $3M [chain] bsc
Vector: Software bug / unintentional loss

Users of the Alpaca Finance lending protocol suffered losses when the protocol's sloppy oracle implementation finally resulted in consequences. Although many had warned the project …

Cryptocurrency

Tweet by Clipper DEX

2024-12-01 [vendor] Clipper DEX [loss] $450,000 [chain] ethereum
Vector: Private key compromise

The Clipper decentralized exchange suffered a $450,000 exploit across two Ethereum layer-2 chains. Although some speculated that the issue may have been a private key leak, Clipper …

Cryptocurrency

Tweet by DeltaPrime

2024-11-11 [vendor] DeltaPrime [loss] $5M [chain] avalanche, ethereum
Vector: Smart contract exploit / hack

The DeltaPrime defi protocol was hacked for the second time in two months, losing $4.8 million in Arbitrum and Avalanche tokens. The attacker appeared to have exploited a flaw in …

Cryptocurrency

Tweet by CyversAlerts

2024-11-08 [vendor] CoinPoker [chain] bsc, ethereum, polygon
Vector: Smart contract exploit / hack

Crypto-powered poker website CoinPoker was apparently exploited for around $2 million when an attacker was able to compromise a hot wallet controlled by the platform. The attacker …

Cryptocurrency

"Security Update"

2024-10-31 [vendor] M2 [loss] $14M [chain] ethereum, bitcoin, solana
Vector: Smart contract exploit / hack

The UAE-based M2 cryptocurrency exchange was hacked for $13.7 million in bitcoin, ether, and Solana tokens. The exploiter compromised several of the exchange's hot wallets to take …

Cryptocurrency

Tweet by Tapioca DAO

2024-10-18 [vendor] Tapioca DAO [loss] $4M [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The defi lending protocol Tapioca DAO was exploited after an attacker reportedly socially engineered the DAO's co-founder and gain access to their private key. The attacker then …

Cryptocurrency

"On the LSM Module"

2024-10-15 [vendor] Cosmos LSM [chain] cosmos
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Cosmos creator Jae Kwon has raised concerns about a portion of the Cosmos protocol called the "Liquid Staking Module" after learning it was developed by North Korean agents. …

Cryptocurrency

Tweet by Scam Sniffer

2024-10-13 [vendor] PEPE token permit phishing [loss] $1M [chain] ethereum
Vector: Phishing attack

An attacker using the permit phishing technique stole $1.39 million in tokens from an unsuspecting holder. The victim unknowingly signed a "Permit2" signature — a function intended …

Cryptocurrency

Tweet thread by CertiK

2024-09-10 [vendor] CUT token [loss] $1M [chain] bsc
Vector: Flash loan attack on smart contract

An attacker exploited a bug in the smart contract for a BSC-based token called CUT, draining a PancakeSwap liquidity pool of almost $1.45 million in the BSC-USD stablecoin. Total …

Cryptocurrency

"Penpie Post-Mortem Report"

2024-09-03 [vendor] Penpie [loss] $27M [chain] ethereum
Vector: Smart contract vulnerability exploit

The defi protocol Penpie was exploited for 11,113.6 ETH (~$27.3 million) by an attacker who exploited a flaw allowing them to withdraw unearned "rewards". Although the protocol …

Cryptocurrency

Tweet by ValidatorK

2024-08-24 [vendor] Users [loss] $140,000 [chain] polygon
Vector: Smart contract exploit / hack

Some fans of the Polygon blockchain, or those looking for help with using it, suffered losses after hackers successfully compromised the project's Discord server. Discord hacks …

Cryptocurrency

Tweet by Lookonchain

2024-08-20 [vendor] Crypto holder [loss] $55M [chain] ethereum
Vector: Phishing attack

Someone holding almost $55.5 million in the DAI stablecoin was apparently phished, signing a transaction to reassign ownership of their DAI stash to a phishing address. The victim …

Cryptocurrency

"Community Update on the Future of Reignmakers"

2024-07-30 [vendor] DraftKings Reignmakers shutdown [chain] ethereum, polygon
Vector: Regulatory / legal action

American sports gambling behemoth DraftKings announced the shutdown of its Reignmakers NFT game and NFT marketplace, effective immediately. Reignmakers was a fantasy sports game …

Cryptocurrency

ETHTrustFund

2024-07-20 [vendor] ETHTrustFund [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

The operators of a project called ETHTrustFund on Coinbase's Base layer-2 Ethereum blockchain have apparently rug-pulled the project. The ETHTrustFund project was a fork of the …

Cryptocurrency

Tweet by zachxbt

2024-07-19 [vendor] Rho loss [chain] ethereum
Vector: MEV / sandwich attack

An apparent misconfiguration by the RHO Markets lending protocol allowed operators of an MEV bot to take $7.6 million from the project's users across multiple chains.In a stroke of …

Cryptocurrency

Tweet by Trekki

2024-07-17 [vendor] Trekki NFT shutdown [chain] ethereum

Travel company Trip.com has some perturbed crypto holders on its hands, after shutting down the "Trekki" NFT project it launched in June 2023. The company's dolphin-themed NFTs had …

Cryptocurrency

Tweet by LI.FI

2024-07-16 [vendor] LI.FI [loss] $10M [chain] ethereum, solana
Vector: Smart contract exploit / hack

Users of the cross-chain swapping API LI.FI Protocol, and of projects that build on top of it, suffered wallet drains amounting to at least $10 million (and counting). An attacker …

Cryptocurrency

Tweet by Chaofan Shou

2024-07-14 [vendor] Minterest [loss] $1M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker stole $1.4 million from the defi lending project Minterest. Using a flash loan attack, they manipulated the exchange rate calculated by the project, allowing them to …

Cryptocurrency

"Dough Finance loses $1.8M in flash loan attack"

2024-07-12 [vendor] Dough Finance [loss] $2M [chain] ethereum
Vector: Flash loan attack on smart contract

Defi platform Dough Finance was hacked for 608 ETH ($1.8 million) by a hacker using a flash loan attack funded through the Railgun privacy service.Dough Finance sent an on-chain …

Cryptocurrency

Tweet thread by Scam Sniffer

2024-06-23 [vendor] 0xfb94d theft [loss] $11M [chain] ethereum
Vector: Phishing attack

A victim lost $11 million in Aave Ethereum (aEthMK) and Pendle USDe tokens after signing several permit phishing signatures. Permit phishing is a technique in which scammers …

Cryptocurrency

Tweet by CertiKAlert

2024-06-23 [vendor] Farcana token plunge [loss] $164,000 [chain] polygon
Vector: Smart contract vulnerability exploit

The token for the Farcana blockchain shooting game plummeted in value by around 60%. First, the project team announced that one of the project wallets had been compromised. …

Cryptocurrency

Instagram post by 50 Cent

2024-06-22 [vendor] 50 Cent account compromise [loss] $1M [chain] solana
Vector: Smart contract exploit / hack

50 Cent has claimed his Twitter account and website were hacked to promote a memecoin called $GUNIT. "I have no association with this crypto," the rapper wrote on Instagram.50 Cent …

Cryptocurrency

Telegram message

2024-06-22 [vendor] Sportsbet.io [loss] $4M [chain] tron
Vector: Smart contract exploit / hack

It appears that the online crypto sports betting platform Sportsbet.io suffered a theft of around $3.5 million in USDT and Tron's TRX tokens. The theft was observed by crypto …

Cryptocurrency

Twitter thread by CertiK

2024-06-19 [vendor] CertiK and Kraken bug dispute [loss] $3M [chain] polygon
Vector: Smart contract exploit / hack

Prominent blockchain security firm CertiK has accused American cryptocurrency exchange Kraken of threatening them after they reported a bug. According to CertiK, they discovered a …

Cryptocurrency

"Pharma Bro's Trump Card"

2024-06-18 [vendor] Martin Shkreli claims to have been behind a Donald Trump memecoin [chain] solana
Vector: On-chain theft (attributed by zachxbt)

After Arkham Intelligence announced a $150,000 bounty for anyone who could prove the identity of the person behind a Donald Trump memecoin called $DJT, blockchain sleuth zachxbt …

Cryptocurrency

Tweet by Cyvers

2024-06-13 [vendor] UwU Lend [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

After suffering a $20 million loss in a June 10 hack, the UwU Lend defi lending protocol has now seen another $3.7 million in suspicious outflows only days later. Although UwU Lend …

Cryptocurrency

Tweet by UwU Lend

2024-06-10 [vendor] UwU Lend [loss] $20M [chain] ethereum
Vector: Flash loan attack on smart contract

The defi lending protocol UwU Lend was hacked for around $20 million. After various blockchain security firms observed suspicious outflows of funds, the protocol acknowledged there …

Cryptocurrency

Tweet by br1an.eth

2024-06-05 [vendor] br1an.eth private key compromise [loss] $48,630 [chain] cosmos
Vector: Smart contract exploit / hack

A blockchain developer posted on Twitter that he had lost almost $50,000 after his cryptocurrency wallet was drained. He explained that he had been working on a software project on …

Cryptocurrency

"Velocore Incident Post-Mortem"

2024-06-02 [vendor] Velocore [loss] $7M [chain] ethereum
Vector: Flash loan attack on smart contract

The Velocore DEX, built on the Linea Ethereum layer-2 blockchain, was exploited for around $6.8 million in ETH. The hacker was able to take advantage of a bug in the project's …

Cryptocurrency

Tweet thread by zachxbt

2024-05-27 [vendor] CAT memecoin team [loss] $30,500 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

According to crypto sleuth zachxbt, the team behind the Solana-based $CAT memecoin hacked the Twitter account of "Gigantic-Cassocked-Rebirth" (@GCRClassic) crypto influencer.First, …

Cryptocurrency

"Normie Incident Analysis"

2024-05-26 [vendor] NORMIE [loss] $882,000 [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker perpetrated a flash loan attack on the "Normie" memecoin on the Base layer-2 blockchain to drain millions of NORMIE tokens. The vulnerability was evidently discovered …

Cryptocurrency

Thief wallet

2024-05-20 [vendor] Gala Games [loss] $21M [chain] ethereum
Vector: Smart contract exploit / hack

Someone was able to mint 5 billion $GALA tokens, the native token of the Gala Games blockchain gaming project. The tokens would be notionally worth around $200 million based on …

Cryptocurrency

"Alex Bridge Incident Anlaysis"

2024-05-14 [vendor] ALEX XLink bridge theft [loss] $6M [chain] bitcoin, bsc, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

An attacker tried to pull off what could have been a ~$12 million heist from ALEX Lab's XLink bridge after a private key was compromised. However, the sloppy work by the attacker …

Cryptocurrency

Tweet by CyversAlert

2024-05-14 [vendor] Sonne Finance [loss] $20M [chain] ethereum
Vector: Smart contract exploit / hack

The Sonne Finance lending protocol was exploited for at least $20 million as an attacker was able to exploit a vulnerability in some of their smart contracts. Sonne is a fork of …

Cryptocurrency

"Public statement"

2024-05-13 [vendor] Cypher contributor theft [loss] $316,294 [chain] solana
Vector: Smart contract exploit / hack

After the founder of the Solana-based Cypher futures trading protocol publicly accused a core contributor of stealing funds, the contributor — publicly known only as "hoak" — has …

Cryptocurrency

Tweet by Cyvers Alerts

2024-05-05 [vendor] GNUS.ai exploi [loss] $1M [chain] ethereum, fantom, polygon
Vector: AI-assisted attack or AI-generated exploit

An exploiter was able to create a fake version of the $GNUS token on the Fantom blockchain, then bridge the tokens to Ethereum and Polygon where they were then sold as though they …

Cryptocurrency

Tweet by Cyvers Alerts

2024-05-03 [vendor] 0x1E227 address poisoning [loss] $7M [chain] bitcoin, ethereum
Vector: Address poisoning attack

An Ethereum wallet was apparently drained of 1,155 wrapped bitcoin (~$72.7 million) when they transferred it to a malicious address that had been operating an address poisoning …

Cryptocurrency

"Early Bitcoin Investor Charged with Tax Fraud"

2024-04-30 [vendor] Roger Ver arrested for $50 million tax fraud [chain] bitcoin
Vector: Regulatory / legal action

Roger Ver, an early bitcoin investor who later became an outspoken evangelist for the fork Bitcoin Cash, has been arrested on tax fraud charges. According to the Department of …

Cryptocurrency

Telegram post by zachxbt

2024-04-29 [vendor] Rain [loss] $15M [chain] bitcoin, ethereum, ripple, solana
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Bahrain-based cryptocurrency exchange Rain was exploited for around $16.13 million dollars on April 29. The exchange did not publicly disclose the hack until the suspicious …

Cryptocurrency

Tweet by Hedgey Finance

2024-04-19 [vendor] Hedgey Finance [loss] $45M [chain] ethereum
Vector: Flash loan attack on smart contract

Hedgey Finance, a platform used to manage token claims, lockups, and vesting, was hit with a flash loan attack that drained $44.7 million of customer funds from the platform.The …

Cryptocurrency

Tweet thread by CertikAlert

2024-04-15 [vendor] Grand Base theft [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

Grand Base, a real world assets platform built on the Base layer-2 blockchain, has seen $2 million exit the platform in a hack or rug pull.The team behind the project claimed that …

Cryptocurrency

Tweet by Long Beach County

2024-04-07 [vendor] Bored & Hungry [chain] ethereum
Vector: Protocol collapse / insolvency

It's hard to believe that the hamburger joint themed around the owner's Bored Ape NFT failed to take off. Although there was novelty value in the themed restaurant, which for a …

Cryptocurrency

Web3 Is Going Great

2024-04-03 [vendor] Rug pull token [loss] $28,878 [chain] ethereum
Vector: Exit scam / rug pull

A project describing itself as "The world's first memecoin pre-announced as a rugpull" was explicit in its marketing: "do not buy this coin, as it will go to zero."Despite that, …

Cryptocurrency

Tweet by FixedFloat

2024-04-01 [vendor] FixedFloat [chain] ethereum
Vector: Smart contract exploit / hack

The FixedFloat cryptocurrency exchange was exploited again, this time for around $2.8 million. This follows shortly after a February 18 hack in which attackers made off with $26 …

Cryptocurrency

Tweet by Solareum Project

2024-03-30 [vendor] Solana drain attacks [loss] $500,000 [chain] solana
Vector: Smart contract exploit / hack

The Solana ecosystem is grappling with a spate of drained wallets. A cause has yet to be definitively determined, but some of the thefts were linked to the use of trading bots like …

Cryptocurrency

On-chain messages

2024-03-28 [vendor] Prisma Finance [loss] $12M [chain] ethereum
Vector: Smart contract exploit / hack

The defi protocol Prisma Finance was hacked for 3,257 ETH ($11.5 million). An attacker was able to take advantage of a flaw in the project's smart contracts, allowing them to …

Cryptocurrency

Tweet by CertiK

2024-03-22 [vendor] Lucky Star Currency [loss] $297,000 [chain] bsc
Vector: Exit scam / rug pull

The astrology-based Lucky Star Currency project rug-pulled for $1.1 million in October 2023. You'd think that might be the end of it, but on March 22, 2024, ownership of the …

Cryptocurrency

Web3 Is Going Great

2024-03-22 [vendor] Solana racist memecoins [chain] solana

Solana memecoin trading has been booming lately, with people making money by speculating on tokens themed around various memes and jokes. Amid an explosion in trading …

Cryptocurrency

On-chain message

2024-03-21 [vendor] Super Sushi Samurai [loss] $345,000 [chain] ethereum
Vector: Smart contract vulnerability exploit

Super Sushi Samurai, a new blockchain game on the Blast layer-2 blockchain was exploited for $4.6 million when an attacker discovered a vulnerability in its smart contract. A bug …

Cryptocurrency

Tweet thread by zachxbt

2024-03-21 [vendor] TICKER [loss] $900,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A developer brought on to run a presale for the $TICKER token stole $900,000 from the project. 15% of the token supply was sent to the developer to distribute via an airdrop, but …

Cryptocurrency

Tweet thread by Slerf

2024-03-18 [vendor] Slerf memecoin meltdown only adds to mania [loss] $10M [chain] solana

People have gotten really into memecoin trading on Solana recently. Like really into it. Someone decided they'd hop on the bandwagon with "Slerf", a sloth-themed memecoin they said …

Cryptocurrency

Tweet by zachxbt

2024-03-16 [vendor] Ansem Twitter impersonator [loss] $3M [chain] solana
Vector: On-chain theft (attributed by zachxbt)

Someone impersonating Ansem, an influential crypto trader, was able to scam people out of more than $2.6 million simply by replying to the real Ansem's tweets. Using an account …

Cryptocurrency

Tweet by Dumpster DAO

2024-03-16 [vendor] Remilia Collective reports multi-million dollar [loss] $6M [chain] ethereum
Vector: Smart contract exploit / hack

"Charlotte Fang", the leader of the controversial Remilia project (known for its Milady NFTs), claimed he was hacked and drained of ETH and NFTs potentially worth several million …

Cryptocurrency

"March' Major Private Key Compromises"

2024-03-16 [vendor] Wilder World theft [loss] $2M [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

Wilder World is a blockchain-based racing game that uses all the buzzwords: blockchains, artificial intelligence, and metaverse. On March 16, someone with access to the project …

Cryptocurrency

Tweet by CertiK Alert

2024-03-15 [vendor] Mozaic [loss] $200,000 [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

The "AI-optimized" defi project Mozaic Fi was exploited by an attacker who drained around $2 million in funds from the project.According to MozaicFi, the theft had been perpetrated …

Cryptocurrency

Tweet thread by ScamSniffer

2024-03-13 [vendor] ether.fi phishing [loss] $2M [chain] ethereum
Vector: Phishing attack

An Ethereum holder who had been staking their ETH through a liquid restaking protocol called Ether.fi suffered a 501 ETH (~$2.025 million) loss when they fell victim to a phishing …

Cryptocurrency

Crypto4Winners Telegram announcement

2024-03-09 [vendor] Crypto4Winners theft [chain] bitcoin, ethereum
Vector: Smart contract exploit / hack

A investment firm called Crypto4Winners announced in their Telegram channel that "Our investigations lead us to suspect an individual of committing fraudulent acts that may have …

Cryptocurrency

Tweet by SlowMist

2024-03-08 [vendor] Unizen [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Unizen defi platform lost around $2.1 million in the Tether stablecoin in an attack that took advantage of a vulnerability an external call from the project smart contract.The …

Cryptocurrency

Woofi

2024-03-05 [vendor] WOOFi [loss] $9M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to use a flash loan attack to manipulate an oracle on the WooFi DEX implementation on the Arbitrum network. By manipulating the price of $WOO, they were able …

Cryptocurrency

Tweet by zachxbt

2024-03-01 [vendor] AI Protocol theft and burn [loss] $4M [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

Someone who held over 111.6 million ALI tokens from a project called The AI Protocol was phished by someone using a wallet drainer service using a permit phishing technique. The …

Cryptocurrency

Tweet by Spreekaway

2024-02-28 [vendor] Seneca Protocol bug [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A bug in Seneca Protocol's smart contract has allowed attackers to steal funds from users who had approved the contract. So far, around $3 million has been stolen across the …

Cryptocurrency

Tweet

2024-02-27 [vendor] Serenity Shield [loss] $586,000 [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

Serenity Shield, a project aiming to solve "crypto inheritence", has been hacked. Although the project prominently claims to help "ensur[e] your financial and personal security", …

Cryptocurrency

Tweet by zachxbt

2024-02-26 [vendor] Dechat token launch error [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

The user experience in crypto is apparently so bad that platforms can't even keep their own tokens straight. A web3 messaging project, Dechat, announced with some fanfare that the …

Cryptocurrency

Tweet by CertiK

2024-02-22 [vendor] Blueberry Protocol narrowly avoids $1.3 million [loss] $265,000 [chain] ethereum
Vector: MEV / sandwich attack

The Blueberry defi leverage project had a bug in their lending contract, where improper decimal handling allowed for an exploit. An attacker tried to exploit the vulnerability, but …

Cryptocurrency

Tweet by Jihoz

2024-02-22 [vendor] Jihoz Zirlin wallet [loss] $10M [chain] ethereum
Vector: Smart contract exploit / hack

Jeff "Jihoz" Zirlin, a co-founder of the Axie Infinity blockchain game, lost around $9.5 million as two of his crypto wallets were compromised. The thief stole 3,248 ETH ($9.5 …

Cryptocurrency

"Farcaster"

2024-02-15 [vendor] Farcaster name controversy [chain] ethereum

One of the promises made by proponents of crypto-focused decentralized social networks like Farcaster is that you can't be de-platformed by centralized companies, and you maintain …

Cryptocurrency

Tweet thread by HashBastardsNFT

2024-02-14 [vendor] Creator of "Robotos" NFT project, once collaborating on a TV series with TIME studios, accused of [chain] ethereum

Pablo Stanley, an artist who created the "Robotos" generative NFT collection, posted two final messages from the Robotos Twitter account. First, "it was a good run! thank u, all!", …

Cryptocurrency

Tweet by CertiK Alert

2024-02-13 [vendor] Duelbits [loss] $5M [chain] ethereum, bsc
Vector: Private key compromise

The Duelbits crypto casino and sports betting website was drained of around $4.6 million on both the Ethereum and BNB Chain blockchains. The funds were quickly bridged or exchanged …

Cryptocurrency

Tweet thread by zachxbt

2024-01-31 [vendor] Chris Larsen XRP theft [loss] $108M [chain] ripple
Vector: On-chain theft (attributed by zachxbt)

Blockchain sleuth zachxbt noticed the strange movement of around 213 million XRP, the native token for the Ripple project. These tokens were priced at around $112.5 million at the …

Cryptocurrency

Tweet by CertiK

2024-01-28 [vendor] Goledo Finance [loss] $2M [chain] ethereum
Vector: Flash loan attack on smart contract

Goledo Finance, an Aave-based lending protocol, was exploited through a flash loan attack. The attacker stole assets estimated by CertiK at around $1.7 million.Goledo Finance …

Cryptocurrency

WSM exploiter wallets

2024-01-25 [vendor] WallStreetMemes [loss] $6M [chain] bsc
Vector: Smart contract exploit / hack

Hackers were able to exploit a vulnerability in the staking contract for WallStreetMemes ($WSM), a memecoin and online casino project targeted at the "meme warriors" who frequent …

Cryptocurrency

Tweet by ConcentricFi

2024-01-22 [vendor] Concentric Finance [loss] $2M [chain] ethereum
Vector: Social engineering attack

The Concentric Finance yield aggregator project issued a statement that the protocol had been exploited after a social engineering attack on a team member that had access to the …

Cryptocurrency

Chapter 11 petition

2024-01-21 [vendor] Terraform Labs files for bankruptcy [chain] terra
Vector: Regulatory / legal action

Terraform Labs, the company behind the Terra blockchain, has filed for bankruptcy. Its flagship product, the Terra stablecoin and associated LUNA token, failed spectacularly in May …

Cryptocurrency

Tweet by the SEC

2024-01-09 [vendor] SEC Twitter account compromised [chain] bitcoin
Vector: Smart contract exploit / hack

As the crypto industry collectively turns blue holding its breath for a decision on a raft of bitcoin spot ETFs currently in front of the SEC, the SEC Twitter account was hacked. …

Cryptocurrency

Web3 Is Going Great

2024-01-08 [vendor] "Undead Apes" [loss] $128,000 [chain] solana
Vector: Exit scam / rug pull

The creator of a Solana-based NFT project called Undead Apes Society has been charged with money laundering conspiracy and making false statements to investigators after …

Cryptocurrency

"XKingdom Incident Analysis"

2024-01-06 [vendor] xKingdom [loss] $1M [chain] ethereum

The xKingdom project promised users a way to "build your kingdom" on Twitter, earning tokens by interacting with tweets and doing "quests". Users had to borrow XKING tokens in …

Cryptocurrency

"Post-Mortem & Remediation Plan"

2024-01-04 [vendor] Gamma Strategies [loss] $6M [chain] ethereum
Vector: Smart contract exploit / hack

The Gamma Strategies defi protocol suffered an exploit when an attacker targeted their vaults on several projects across the Arbitrum layer-2 network. The attacker successfully …

Cryptocurrency

Tweet thread by Bill Lou

2024-01-02 [vendor] Bill Lou [loss] $125,000 [chain] ethereum
Vector: Phishing attack

Bill Lou, the co-founder of a cryptocurrency wallet that claims to "revolutionize wallet security", was scammed out of 52 stETH (~$125,000) when he clicked a link promising an …

Cryptocurrency

Tweet thread by Radiant Capital

2024-01-02 [vendor] Radiant Capital [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

Radiant Capital, a cross-chain lending protocol built on the Arbitrum layer-2 network, was hacked for 1,900 ETH (~$4.5 million). The exploit relied on a flaw in the underlying …

Cryptocurrency

Memorandum & Opinion

2023-12-28 [vendor] UST and LUNA deemed securities [chain] terra
Vector: Regulatory / legal action

The federal judge overseeing the SEC v. Terraform Labs case has determined that Terra's UST stablecoin, LUNA token, and related tokens were securities. "There is no genuine dispute …

Cryptocurrency

"Levana exploit postmortem"

2023-12-26 [vendor] Levana Protocol [loss] $1M [chain] cosmos
Vector: Smart contract exploit / hack

An attacker successfully manipulated an oracle to drain around 10% of the liquidity pool for the Levana Protocol, an Osmosis-based perpetual futures project. This amounted to …

Cryptocurrency

Tweet by Telcoin

2023-12-26 [vendor] Telcoin [loss] $1M [chain] polygon
Vector: Smart contract exploit / hack

$TEL, the token associated with the Telcoin remittances project, plunged 40% as an exploiter was able to steal around $1.25 million from the project. The company later disclosed …

Cryptocurrency

Tweet by CertiK

2023-12-25 [vendor] Megabot exit [chain] solana, ethereum, bsc
Vector: AI-assisted attack or AI-generated exploit

The Megabot project rug pulled, stealing $742,000 from those who bought in to the project's presale. The majority of the money — around $692,000 — was stolen on the Solana …

Cryptocurrency

"Incident disclosure - 2023-12-11"

2023-12-11 [vendor] Yearn treasury swap [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

Periodically, Yearn Finance converts a small quantity of its treasury tokens into stablecoins to spend on operations. However, something went terribly wrong during this process …

Cryptocurrency

Tweet thread by zachxbt

2023-12-07 [vendor] Uranium Finance [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

In April 2021, an attacker stole $50 million from the defi exchange Uranium Finance. Blockchain investigator zachxbt now says that he believes this attacker has been able to cash …

Cryptocurrency

"Smart contract security vulnerability 12/4"

2023-12-04 [vendor] ThirdWeb vulnerability [chain] ethereum, polygon
Vector: Software bug / unintentional loss

Projects using the suite of pre-built smart contracts from crypto development platform ThirdWeb have been racing to migrate to patched versions as ThirdWeb has disclosed a …

Cryptocurrency

Tweet by PeckShieldAlert

2023-11-30 [vendor] Florence Finance theft [loss] $1M [chain] ethereum
Vector: Address poisoning attack

An apparent address poisoning attack on the Florence Finance real-world asset lending protocol led to the loss of $1.45 million in the USDC stablecoin.As of December 4, Florence …

Cryptocurrency

"Randstorm: You Can’t Patch a House of Cards"

2023-11-14 [vendor] randstorm [chain] bitcoin, litecoin
Vector: Software bug / unintentional loss

While trying to help a Bitcoin holder who lost their password, researchers at Unciphered discovered a major flaw in the way early Bitcoin wallets had been created. Thanks to a flaw …

Cryptocurrency

Tweet by CyversAlerts

2023-11-10 [vendor] Samudai treasury drained [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

The treasury of the Samudai DAO was apparently drained as an attacker compromised the project's multisignature wallets and the wallet belonging to the project's founder, Kushagra …

Cryptocurrency

Tweet by CyversAlerts

2023-11-08 [vendor] CoinSpot [loss] $2M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Australian cryptocurrency exchange CoinSpot appears to have been hacked for around 1,283 ETH (~$2.4 million). In two separate transactions, the ETH was transferred out of …

Cryptocurrency

Tweet thread by CertiK Alert

2023-11-07 [vendor] MEV bot 0x05f01 [loss] $2M [chain] ethereum, bitcoin
Vector: Flash loan attack on smart contract

An MEV bot was exploited after an attacker discovered a vulnerability in its code that allowed anyone to call one of its functions that sold wBTC for wETH. Using a flash loan to …

Cryptocurrency

Tweet by NGBxShpend

2023-11-05 [vendor] Yuga Labs' social media lead resigns [chain] ethereum

One might think that a social media lead might have a grasp on his own social media accounts, and might have scrubbed damning tweets made only shortly before they began their …

Cryptocurrency

Tweet by Bored Ape Yacht Club

2023-11-04 [vendor] ApeFest photokeratitis [chain] ethereum

Bored Ape collectors attending an ApeFest party in Hong Kong have now been subjected to the kind of eye pain the rest of us have felt for years having to look at their hideous, …

Cryptocurrency

CCS Wallet Incident

2023-11-01 [vendor] Monero community wallet [loss] $460,895 [chain] monero
Vector: Seed phrase / wallet compromise

Monero's Community Crowdfunding System (CCS) funds projects that aim to improve the ecosystem of Monero, a privacycoin. The CCS is funded by donations, and up until September 1, …

Cryptocurrency

Findings of Fact & Conclusions of Law

2023-10-25 [vendor] Ryder Ripps [chain] ethereum
Vector: Regulatory / legal action

A judge has ordered Ryder Ripps and his co-defendant Jeremy Cahen to pay almost $1.6 million in disgorgement and damages after they created a collection of identical NFTs to the …

Cryptocurrency

Reddit announcement

2023-10-17 [vendor] Reddit abandons blockchain-based Community Points [chain] ethereum
Vector: Exit scam / rug pull

Reddit's attempt to blockchainify their signature Reddit karma has come to an end as the company has decided to pull the plug on the feature. The idea was that users could "own a …

Cryptocurrency

Tweet thread by ChainArgos

2023-10-16 [vendor] TrueUSD TEURO announcement [chain] ethereum
Vector: Private key compromise

A new, Euro-pegged stablecoin called $TEURO emerged on October 13, with an initial supply of around €70 million. However, TrueUSD subsequently tweeted that "we have zero …

Cryptocurrency

Tweet thread by PeckShield

2023-10-11 [vendor] Black Hole Token [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The Black Hole Token project suffered a $1.28 million apparent exploit, according to security firm PeckShield, though it's hard not to wonder if it might have been a rug pull.Black …

Cryptocurrency

"Lucky Star Currency, FSL"

2023-10-10 [vendor] FSL [loss] $2M [chain] bsc
Vector: Exit scam / rug pull

The BNB Chain-based FSL token rug pulled within 24 hours of launching, with developers draining $1.68 million of liquidity they had amassed. Total loss estimated at $1,680,000.

Cryptocurrency

Tweet by BigWhale

2023-10-03 [vendor] BigWhale [loss] $2M [chain] bsc
Vector: Private key compromise

The defi staking and lending project BigWhale announced that the private key to one of their crypto wallets had been leaked, and 7,200 BNB (~$1.5 million) had been stolen.In a long …

Cryptocurrency

Tweet thread by Justin Sun

2023-09-24 [vendor] Huobi exchange [chain] ethereum
Vector: Smart contract exploit / hack

Justin Sun confirmed on September 25 that his crypto exchange Huobi (recently rebranded to "HTX") had been hacked for 5,000 ETH ($8 million) the prior day. He reassured customers …

Cryptocurrency

Tweet by Balancer

2023-09-19 [vendor] Balancer frontend compromise [loss] $237,932 [chain] ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

Balancer issued an urgent warning to stop using its web interface, as it was evidently compromised by malicious actors who redirected the funds to themselves. Within 30 minutes of …

Cryptocurrency

SEC order

2023-09-13 [vendor] SEC charges Stoner Cats NFT project [chain] ethereum
Vector: Regulatory / legal action

In a rather amusing press release, the SEC announced they had charged "Stoner Cats 2 LLC" with conducting an unregistered securities offering when they raised $8.2 million selling …

Cryptocurrency

Tweet by Banana Gun

2023-09-11 [vendor] Banana Gun bot flubbed token launch [chain] ethereum
Vector: Exit scam / rug pull

The team behind Banana Gun, a Telegram bot to help "snipe" token launches, launched a token associated with the project on September 11. Only hours later, they announced in a tweet …

Cryptocurrency

Tweet by Charlotte Fang

2023-09-11 [vendor] Remilia theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A developer working on an NFT project spearheaded by Remilia, the DAO behind the Milady NFT project, stole around $1 million from the group by diverting fees generated by their new …

Cryptocurrency

Bitcoin transaction

2023-09-10 [vendor] Paxos fee overpayment [chain] bitcoin
Vector: Software bug / unintentional loss

A wallet on the Bitcoin blockchain paid a 19.82 BTC ($499,171) fee to transfer 0.074 BTC ($1,865). Put another way, they spent 270x the transaction value to pay the fee. Bitcoin …

Cryptocurrency

Attacker wallet

2023-09-09 [vendor] Vitalik Buterin's Twitter account [loss] $691,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Twitter account belonging to Vitalik Buterin, inventor and effective leader of the Ethereum project, was hacked to promote a crypto scam. A tweet posted to his compromised …

Cryptocurrency

Tweet thread by ScamSniffer

2023-09-06 [vendor] 0x13e38 phished [loss] $24M [chain] ethereum
Vector: Phishing attack

A crypto phisher hit it big today when they lured in a victim with a massive wallet balance. The victim wallet was drained of 4,851 rETH and 9,579 stETH, both wrapped versions of …

Cryptocurrency

Tweets by PeckShield

2023-09-05 [vendor] GMBL.COMPUTER [loss] $770,000 [chain] ethereum
Vector: Smart contract exploit / hack

The brand new Arbitrum-based defi casino GMBL.COMPUTER was exploited for around 471 ETH (~$770,000). The project, which promises to "generate yield from casino games", had …

Cryptocurrency

Tweet by zachxbt

2023-09-04 [vendor] Stake [loss] $41M [chain] bsc, polygon, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Attackers managed to make transactions from hot wallets operated by the Stake betting platform, stealing approximately $15.7 million from their Ethereum wallet and around $25.6 …

Cryptocurrency

Tweet by Balancer

2023-08-27 [vendor] Balancer [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

After warning users several days prior that a critical vulnerability had been discovered in their protocol, the Balancer defi project has been drained of around more than $2.1 …

Cryptocurrency

Tweet thread by Nick Garfield

2023-08-27 [vendor] Clockwork project to [chain] solana
Vector: Protocol collapse / insolvency

A year after raising $4 million in a seed round joined by Multicoin Capital, Solana Ventures, and Asymmetric, Clockwork co-founder Nick Garfield announced that the Solana-based …

Cryptocurrency

Tweet thread by zachxbt

2023-08-25 [vendor] Magnate Finance [loss] $5M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Magnate Finance, a lending protocol built on the new Base layer-2 blockchain, rug pulled within hours of a warning from crypto sleuth zachxbt. Zachxbt had discovered that a wallet …

Cryptocurrency

Tweet thread by SOLBigBrain

2023-08-25 [vendor] SOL Big Brain phishing attack [loss] $1M [chain] ethereum
Vector: Phishing attack

The NFT collector SOL Big Brain lost around $1.5 million in ETH, stablecoins, and the Gearbox token after being targeted in a phishing scam. The attacker apparently compromised a …

Cryptocurrency

Tweet thread by ScamSniffer

2023-08-21 [vendor] Celer Bridge Google Ad phishing [loss] $900,000 [chain] ethereum
Vector: Phishing attack

Google Ad phishing is the practice of taking out a Google advertisement to promote a malicious website impersonating a legitimate project. By taking out the ad, the result is …

Cryptocurrency

Tweet thread by PeckShield

2023-08-16 [vendor] SwirlLend [loss] $460,000 [chain] ethereum

Despite the fact that Coinbase's Base blockchain was only officially launched a week ago, and a relatively small amount of funds are locked on the chain, it's already racking up …

Cryptocurrency

Tweet by PeckShield

2023-08-14 [vendor] RocketSwap [loss] $857,257 [chain] ethereum
Vector: Smart contract exploit / hack

Exploiters stole around 471 ETH (~$857,000) from the RocketSwap project on the Base Ethereum layer-2 blockchain. According to RocketSwap, the project had stored private keys on a …

Cryptocurrency

Tweet by Hayden Adams

2023-08-12 [vendor] FrensTech [loss] $25,900 [chain] ethereum
Vector: Exit scam / rug pull

After pulling off a rug pull that only netted 14 ETH (~$25,900), Allen Lin (known as AzFlin) lost his day job for the company that maintains the Uniswap DEX. Hope it was worth …

Cryptocurrency

"April 2023 Exploit Response Vote"

2023-08-09 [vendor] Hundred Finance [chain] ethereum
Vector: Protocol collapse / insolvency

Hundred Finance is a lending protocol that was exploited in April 2023 for around $7 million, and in March for over $6 million. Since then, they've worked with law enforcement and …

Cryptocurrency

Tweet by FTM Ecologist

2023-08-09 [vendor] SpiritSwap to [chain] fantom
Vector: Protocol collapse / insolvency

SpiritSwap announced on its Discord that the project will be shutting down on September 1 unless they can find a new team to take over the project by that time. SpiritSwap lost …

Cryptocurrency

Tweet by Pau Bonet

2023-08-08 [vendor] Scammers target victims via web3 job search boards [loss] $1,172 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Scammers are constantly coming up with creative new ways to pull off their scams, and the latest seems to be targeting web3-interested individuals via dedicated web3 jobs portals. …

Cryptocurrency

Tweet by Spreek

2023-08-07 [vendor] Steadefi [loss] $1M [chain] ethereum
Vector: Private key compromise

"NOTICE: Steadefi has been exploited and all funds are currently at risk," wrote Steadefi on Twitter after an attacker was able to change the contract owner to their own address — …

Cryptocurrency

Tweet by PeckShield

2023-08-02 [vendor] Uwerx [loss] $324,000 [chain] ethereum
Vector: Flash loan attack on smart contract

Uwerx is a nascent project intending to build a blockchain-based freelancer marketplace, because what better concepts to combine than blockchains and the gig economy? Sadly for …

Cryptocurrency

Tweet thread by SlowMist

2023-08-01 [vendor] LeetSwap [loss] $624,000 [chain] ethereum
Vector: Smart contract exploit / hack

Although Coinbase's Base blockchain is at this stage intended for testing only, people have begun bridging substantial assets to the platform and using various services in …

Cryptocurrency

Tweet by Chaofan Shou

2023-07-30 [vendor] Vyper vulnerability affecting Curve [loss] $36M [chain] ethereum
Vector: Smart contract exploit / hack

Some types of Curve factory pools, including one operated by AlchemixFi and one by JPEG'd, were exploited. The attack stemmed from an issue in the Vyper language, a smart contract …

Cryptocurrency

"DeFiLabs"

2023-07-27 [vendor] DeFiLabs [loss] $2M [chain] bsc
Vector: Exit scam / rug pull

A defi project called DeFiLabs was able to rug pull for $1.6 million thanks to a backdoor written into the smart contract. After traders bought into the project, its creator was …

Cryptocurrency

Tweet by Jameson Lopp

2023-07-25 [vendor] CoinsPaid [loss] $37M [chain] bitcoin
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The CoinsPaid crypto payment platform, which provides payment services to various online casinos, reportedly suspended withdrawals under mysterious circumstances. The company later …

Cryptocurrency

Tweet thread by EraLend

2023-07-25 [vendor] EraLend [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

The EraLend crypto lending platform was exploited for around $3.4 million after an attacker took advantage of a re-entrancy vulnerability to manipulate token prices and drain funds …

Cryptocurrency

Tweet thread by Conic Finance

2023-07-21 [vendor] Conic Finance [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

A re-entrancy vulnerability in the Conic Finance defi project enabled an attacker to steal 1,700 ETH (~$3.22 million) from the project's ETH pool.Conic Finance announced that they …

Cryptocurrency

Tweet thread by Beosin Alert

2023-07-18 [vendor] GMETA [loss] $4M [chain] bsc

The GMETA project on BNB Chain saw its price plummet to near zero as the project creators drained the funds from the project. The contract creator was able to transfer large …

Cryptocurrency

Tweet thread by Geist Finance

2023-07-14 [vendor] Geist Finance [chain] ethereum, fantom
Vector: Protocol collapse / insolvency

Defi lending project Geist Finance announced they would be shutting down after more than $200 million was drained from the Multichain project in two separate events in early July. …

Cryptocurrency

"OptyFi Project Update"

2023-07-11 [vendor] OptyFi [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

OptyFi, a so-called "AI-powered defi" project, announced it would be shutting down for a variety of reasons. First, they blamed their recent failed token sale, in which they had …

Cryptocurrency

Tweet by PeckShield

2023-07-11 [vendor] Platypus Finance [loss] $157,000 [chain] avalanche
Vector: Flash loan attack on smart contract

Platypus Finance paused their pools after they were alerted to what they described as "suspicious activities". Security firm PeckShield was apparently the first to notice the …

Cryptocurrency

Tweet by BarnBridge

2023-07-06 [vendor] "Decentralized" BarnBridge closes up shop after claiming they are under SEC investigation [chain] ethereum
Vector: Regulatory / legal action

A small and rather unknown project called BarnBridge aimed to build a variety of defi yield projects. BarnBridge claimed to be decentralized and governed by a DAO. On July 6, an …

Cryptocurrency

Tweet by nftperp.xyz

2023-07-06 [vendor] NFTPerp blows up [chain] ethereum

A project called NFTPerp was, as the name suggests, a perpetual futures exchange for NFTs, allowing people to take long or short positions against NFTs. It relied on a vAMM — …

Cryptocurrency

Tweet thread by LoveMake.eth

2023-07-03 [vendor] LoveMake.eth wallet drain [loss] $213,000 [chain] ethereum
Vector: Phishing attack

Crypto personality LoveMake.eth wrote a Twitter thread about how they fell victim to a phishing scam in which an account appearing to belong to the cofounder of the popular Doodles …

Cryptocurrency

Tweet thread by Cardinal Labs

2023-06-28 [vendor] Cardinal Labs [chain] solana
Vector: Protocol collapse / insolvency

A little less than a year after raising $4.4 million in seed funding to build a Solana NFT protocol that allowed for NFT rentals and other such things, Cardinal Labs has announced …

Cryptocurrency

Tweet by PeckShield

2023-06-27 [vendor] Themis Protocol [loss] $368,000 [chain] ethereum
Vector: Flash loan attack on smart contract

Themis Protocol is a lending platform that has had somewhat of an excruciating rollout, with users waiting ever longer for the platform to finally go live as they endured …

Cryptocurrency

Tweet by Elena

2023-06-21 [vendor] Elena stolen art [chain] bitcoin

Web3 influencer Elena announced she would be launching an NFT collection titled "Atomic Ordinals", which would be inscribed on the Bitcoin blockchain. She claimed that the 200 …

Cryptocurrency

Tweet by zachxbt

2023-06-06 [vendor] Binance Discord compromise [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

Adding insult to injury in Binance's tough couple of days, someone has managed to hijack the Discord vanity URL used by BNB Chain, the blockchain project associated with Binance. …

Cryptocurrency

<i>SEC v. Binance</i>

2023-06-05 [vendor] SEC files complaint against Binance [chain] bsc, polygon, solana, cosmos, cardano
Vector: Regulatory / legal action

The SEC has filed a complaint against Binance, various related companies, and Binance CEO Changpeng "CZ" Zhao. They allege that the company has been acting with "blatant disregard" …

Cryptocurrency

Tweet by unshETH

2023-06-01 [vendor] unshETH [loss] $375,000 [chain] ethereum
Vector: Smart contract exploit / hack

After a developer leaked private keys to GitHub, someone used them to drain $375,000 from the unshETH defi project. The project emergency paused withdrawals of unshETH ether to …

Cryptocurrency

Tweet thread by zachxbt

2023-05-30 [vendor] Hopeexist1 NFT [loss] $117,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A person claiming to be battling cancer created a "charity NFT project" ostensibly to help with her treatment. She convinced some crypto influencers to promote the project, …

Cryptocurrency

Tweet thread by PeckShield

2023-05-29 [vendor] El Dorado Exchange [chain] ethereum, bsc
Vector: Smart contract exploit / hack

The new Arbitrum-based El Dorado Exchange (EDE) was exploited for around $580,000. In an interesting twist, the attacker claimed to be a whitehat who was exposing that the …

Cryptocurrency

Tweet thread by Arkham

2023-05-27 [vendor] Malfunctioning MEV bot [loss] $440,000 [chain] ethereum
Vector: MEV / sandwich attack

Some traders hoping to snipe new tokens launched by Poo Finance (yes, really) decided to try to use a MEV bot to snag priority ordering compared to other pending blockchain …

Cryptocurrency

Tweet thread by zachxbt

2023-05-25 [vendor] Steve Aoki Twitter compromise [loss] $170,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Twitter account compromises remain a lucrative way to scam crypto enthusiasts. Someone was able to compromise the Twitter account belonging to electronic musician and crypto …

Cryptocurrency

Tweet by PeckShieldAlert

2023-05-23 [vendor] CS token [loss] $689,400 [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker exploited the brand new $CS token for almost $700,000 using a flash loan exploit. They then swapped the funds into around 383 ETH ($689,400) and laundered them through …

Cryptocurrency

Etherscan transactions

2023-05-20 [vendor] Tornado Cash DAO governance attack [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A proposal ostensibly to penalize cheating network participants in the Tornado Cash crypto tumbler project successfully passed by DAO vote. However, the proposer had added an extra …

Cryptocurrency

Grumpy Cat cease and desist NFT

2023-05-18 [vendor] Grumpy Cat cease and desist [chain] ethereum

A Grumpy Cat Coin memecoin emerged in May, with a website using illustrations of the late real-life Grumpy Cat to promote the coin. Crypto influencers, including the "SlumDoge …

Cryptocurrency

<i>United States of America v. Nevin Shetty</i>

2023-05-17 [vendor] Fabric CFO funds misappropriation [loss] $35M [chain] terra
Vector: Regulatory / legal action

Nevin Shetty, the former chief financial officer of the Fabric e-commerce platform, was federally indicted for wire fraud after allegedly misappropriating $35 million from Fabric …

Cryptocurrency

Tweet thread by MistTrack

2023-05-15 [vendor] HitBTC phishing website [loss] $15M [chain] ethereum, bitcoin
Vector: Phishing attack

Blockchain security firm SlowMist has reported that a phishing website appearing to be the real cryptocurrency exchange HitBTC has stolen more than $15 million worth of Bitcoin, …

Cryptocurrency

Tweet thread by Andy Chorlian

2023-05-12 [vendor] Fractional NFT ownership platform Tessera [chain] ethereum

If you've found yourself thinking "man, I wish I could buy a hundredth of an NFT", you now have one fewer options. Andy Chorlian, co-founder and CEO of fractional NFT platform …

Cryptocurrency

Tweet by Aragon

2023-05-11 [vendor] Aragon DAO faces governance crisis [chain] ethereum
Vector: Social engineering attack

As the Aragon Association took steps to "progressively decentralize" their centralized project by assigning more control to the Aragon DAO, they encountered some challenges. …

Cryptocurrency

Tweet by Whale Alert

2023-05-07 [vendor] Ethereum user pays more than $100,000 in fees [chain] ethereum

A recent surge in memecoin popularity has caused Ethereum transaction fees to skyrocket. One trader paid the price, eating a 64 ETH ($118,000) transaction fee just to perform a …

Cryptocurrency

Tweet thread by zachxbt

2023-05-03 [vendor] WallStreetBets coin rugpull [loss] $635,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

WallStreetBets is a subreddit that became popular during the pandemic-fueled everyone-should-become-a-daytrader era, and is known for its memestocks and its users who often make …

Cryptocurrency

Tweet by CZ

2023-05-01 [vendor] CZ smacks down Justin Sun for trying to game SUI airdrop [chain] sui

"Binance LaunchPool are meant as air drops for our retail users, not just for a few whales," tweeted Changpeng "CZ" Zhao, the CEO of Binance, after seeing an alert showing that …

Cryptocurrency

Tweet by Level Finance

2023-05-01 [vendor] Level Finance [loss] $1M [chain] bsc
Vector: Smart contract exploit / hack

The Level Finance decentralized perpetual exchange was exploited after an attacker discovered a vulnerability in one of the project's smart contracts. They were able to drain …

Cryptocurrency

Tweets about "permit phishing" by ScamSniffer

2023-04-30 [vendor] "Permit phishing" [loss] $8M [chain] ethereum
Vector: Smart contract exploit / hack

Between March and April 2023, the Scam Sniffer organization has identified at least $7.7 million stolen by so-called "permit phishers". These attackers convince their victims to …

Cryptocurrency

Tweet by TheMerlinDEX

2023-04-26 [vendor] Merlin theft [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

The brand new Merlin DEX had only just launched on the zkSync Ethereum layer-2, with a public token sale beginning on April 25. The following day, they suddenly asked users to …

Cryptocurrency

Tweet by CertiKAlert

2023-04-24 [vendor] Ordinals Finance [loss] $1M [chain] ethereum, bitcoin

Ordinals Finance was a short-lived project, emerging in late February with promises to help build out a defi ecosystem on the Bitcoin blockchain.On April 24, the project developer …

Cryptocurrency

Tweet thread by 0xQuit

2023-04-21 [vendor] Blur bid acceptance bug [chain] ethereum
Vector: Software bug / unintentional loss

The Blur NFT marketplace appeared to become vulnerable to a bug in which old, canceled bids could still be accepted. This meant that people who had placed bids on NFTs when they …

Cryptocurrency

<i>Krzysztof Gagacki v. Edmond Truong</i>

2023-04-17 [vendor] Rebase co-founders lawsuit [chain] ethereum
Vector: Regulatory / legal action

Krzysztof Gagacki and Edmond Truong are co-founders of Rebase.gg, some sort of augmented reality app where people go hunting for NFTs. They're best known for helping to create a …

Cryptocurrency

Tweet thread by CertiKAlert

2023-04-15 [vendor] Hundred Finance [loss] $7M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to manipulate the exchange rate between tokens and their interest-bearing equivalents on the Hundred Finance system on the Optimism layer-2 network, ultimately …

Cryptocurrency

Post

2023-04-14 [vendor] Bitrue [loss] $23M [chain] ethereum
Vector: Smart contract exploit / hack

The Singapore-based Bitrue crypto exchange suffered a hack on April 14 in which attackers siphoned tokens including Ethereum, Shiba Inu, and MATIC (the token for the Polygon …

Cryptocurrency

Tweet by franklinisbored

2023-04-13 [vendor] Franklin claims to have been [loss] $4M [chain] ethereum
Vector: Exit scam / rug pull

Franklin, aka franklinisbored, has come to be known as one of the most prolific collectors of Bored Apes. At times, he's held more than fifty of the NFTs, and he can often be …

Cryptocurrency

Tweet thread by NicoleBehnam

2023-04-12 [vendor] Nicole Behnam pumps and dumps [loss] $38,000 [chain] ethereum

New passive voice Hall of Fame contender just dropped: "There were mistakes made in a wallet that I controlled." You would think someone who got their start as a writer might know …

Cryptocurrency

Trading Post shutdown announcement

2023-04-10 [vendor] Niantic shutters its web3 project [chain] polygon

Niantic, the creator of the popular Ingress and Pokémon Go augmented reality games, announced it will be shutting down its "Trading Post" product for NFT trading cards that it had …

Cryptocurrency

Tweet by PeckShieldAlert

2023-04-09 [vendor] Trader [loss] $61,000 [chain] ethereum

The former owner of Bored Ape #7810 presumably intended to agree to sell the ape to another buyer for 70 ETH (~$130,900). However, it's unlikely they intended for that buyer to …

Cryptocurrency

Tweet thread by PeckShield

2023-04-08 [vendor] 0xSifu [loss] $3M [chain] ethereum, polygon, avalanche, bsc
Vector: Smart contract exploit / hack

0xSifu, also known as Michael Patryn, also known as Omar Dahani, is the once-pseudonymous chief developer of the Wonderland protocol. His identity was discovered by zachxbt in …

Cryptocurrency

dez.eth

2023-04-07 [vendor] Dez Bryant's Bored Ape stolen [loss] $138,800 [chain] ethereum
Vector: Smart contract exploit / hack

The latest ape escape has affected Dez Bryant, a former NFL player now turned "web3 innovator". Bryant was the proud owner of Bored Ape #2902, an ape with leopard print skin …

Cryptocurrency

<i>Sphere 3D Corp. v. Gryphon Digital Mining, Inc.</i>

2023-04-07 [vendor] Sphere 3D and Gryphon Digital Mining dispute [loss] $500,000 [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin mining firm Sphere 3D has filed a biting lawsuit against its partner, Gryphon Digital Mining. According to Sphere 3D, Gryphon's CEO was fooled by multiple spoofing attacks …

Cryptocurrency

Tweet by Eden Au

2023-04-06 [vendor] Gemholic gets funds stuck [chain] ethereum

The Gemholic project raised 921 ETH (~$1.7 million) in a token sale only to discover there was no way for them to transfer those funds out of the smart contract. The project is …

Cryptocurrency

Tweet thread by Spreek

2023-04-04 [vendor] Sentiment [loss] $95,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Sentiment liquidity protocol on the Arbitrum blockchain was attacked on April 4 for almost $1 million in various tokens, including wrapped Bitcoin and Ether, and several …

Cryptocurrency

Tweet by PeckShield

2023-04-01 [vendor] Allbridge [loss] $573,757 [chain] bsc
Vector: Smart contract exploit / hack

The Allbridge cross-chain bridge project was exploited for around 283,000 BUSD and 291,000 USDT (~$574,000). The thief was able to manipulate a vulnerability in the project's smart …

Cryptocurrency

"Kokomo Finance"

2023-03-26 [vendor] Kokomo Finance [loss] $4M [chain] ethereum
Vector: Phishing attack

The Kokomo Finance project on the Optimism Ethereum layer-2 network rug pulled for $4.5 million in assets. The project positioned itself as a non-custodial lending platform.After …

Cryptocurrency

Tweet thread by NFTstatistics.eth

2023-03-24 [vendor] Collector accidentally burns their $123,000 NFT [chain] ethereum

The new owner of a CryptoPunk, one of the most popular early NFT projects, accidentally burned the NFT they had only just purchased. After spending 77 ETH ($123,434) on the NFT, …

Cryptocurrency

Thread by PeopleDAO

2023-03-11 [vendor] PeopleDAO theft [loss] $120,000 [chain] ethereum
Vector: Smart contract exploit / hack

PeopleDAO is the successor to ConstitutionDAO, a group that made an ill-fated attempt to buy a copy of the US Constitution in November 2021. When the accounting lead for PeopleDAO …

Cryptocurrency

Tweet by Spreekaway

2023-03-10 [vendor] Kyber bug [loss] $2M [chain] ethereum
Vector: MEV / sandwich attack

Someone tried to swap around 2.03 million 3CRV tokens (priced at around $1.97 million) for stablecoins using the KyberSwap decentralized exchange protocol. However, due to an …

Cryptocurrency

Web3 Is Going Great

2023-03-10 [vendor] USDC [chain] ethereum

The major stablecoin USDC lost its peg to the US dollar on March 10. Earlier that day, the collapse of the Silicon Valley Bank sent shockwaves through the financial system, and …

Cryptocurrency

"Togg to sell pre-order rights with NFTs"

2023-03-08 [vendor] Togg announces and then cancels NFT presale [chain] avalanche

Turkish electric vehicle startup Togg announced that interested customers would be able to buy obtain pre-order rights for the limited run of their "100 Year Special Series" cars …

Cryptocurrency

Tweets by HideYoApes

2023-02-26 [vendor] hideyoapes wallet drain [loss] $208,000 [chain] ethereum
Vector: Smart contract exploit / hack

"I still don't quite understand what happened here", wrote hideyoapes.eth after their wallet was drained of around 30 NFTs. They had previously owned several pricey NFTs from the …

Cryptocurrency

Community notice

2023-02-23 [vendor] Metroverse blockchain game implodes [chain] ethereum
Vector: Exit scam / rug pull

The Metroverse NFT-based game caught the end of the 2021–22 crypto bull market, minting the Genesis collection in January 2022. The project sold out quickly, netting the project …

Cryptocurrency

Tweet thread by WazirXNFT

2023-02-22 [vendor] WazirX closes NFT marketplace [chain] bsc

Indian cryptocurrency exchange WazirX abruptly closed their NFT marketplace on February 22, giving its users no warning. In an announcement on Twitter, they wrote that they had …

Cryptocurrency

Tweet thread by DexibleApp

2023-02-17 [vendor] Dexible [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Decentralized exchange aggregator Dexible disclosed that they had suffered an exploit of one of their smart contracts, which allowed an attacker to steal funds from customer …

Cryptocurrency

"Loyalist: $4m stolen from over 400 victims"

2023-02-16 [vendor] "Loyalist" phishing [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has released research indicating that a cryptocurrency and NFT phishing scammer who goes by Loyalist/Lukas/Shibango has stolen more than $4 million of various …

Cryptocurrency

Inscription 2042

2023-02-15 [vendor] Fart noise reportedly sells for $280,000 [chain] bitcoin

You thought NFTs were dead? Think again. Perhaps longing for the halcyon days when you could mint an NFT on Ethereum and smile in satisfaction at the carbon emissions you just …

Cryptocurrency

DForce Network

2023-02-13 [vendor] dForce Network [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker using flash loans to exploit a common re-entrancy vulnerability siphoned $3.65 million from the dForce defi project on both Arbitrum and Optimism, which are Ethereum …

Cryptocurrency

LocalBitcoins will discontinue its service

2023-02-09 [vendor] LocalBitcoins to [chain] bitcoin
Vector: Protocol collapse / insolvency

LocalBitcoins, a Finnish platform that allows individuals to trade Bitcoins with one another peer-to-peer, will be shutting down. The exchange is one of the longest running …

Cryptocurrency

Webaverse theft statement

2023-02-06 [vendor] Webaverse theft [loss] $4M [chain] ethereum
Vector: Social engineering attack

The metaverse gaming company Webaverse disclosed on February 6 that they had suffered a $4 million theft several months earlier. They outlined what appeared to be a complex scam in …

Cryptocurrency

<i>Holland v. CryptoZoo, Inc.</i>

2023-02-03 [vendor] Logan Paul slapped with a class action over CryptoZoo rugpull [chain] ethereum
Vector: Regulatory / legal action

Logan Paul is now facing a class action lawsuit over his CryptoZoo project, a planned NFT game that Paul apparently lost interest in and abandoned — after profiting handsomely, of …

Cryptocurrency

Tweet by PeckShield

2023-02-02 [vendor] Orion Protocol [loss] $3M [chain] ethereum
Vector: Reentrancy attack on smart contract

The decentralized exchange Orion Protocol suffered a loss of 1,757 ETH (about $2.9 million) from the company treasury funds thanks to a reentrancy attack.Orion Protocol CEO Alexey …

Cryptocurrency

Tweet by LukeDashjr

2023-01-31 [vendor] Ordinals launch [chain] bitcoin

A recent project called "Ordinals" has the Bitcoin community up in arms. The project is the latest attempt to introduce NFTs to the Bitcoin blockchain, a controversial subject …

Cryptocurrency

Tweet showing email to users

2023-01-31 [vendor] Rally sidechain [chain] ethereum

Rally is an Ethereum sidechain built to support "social tokens" — typically, tokens intended for fans of various celebrities or groups.Fans of creators including Felicia Day …

Cryptocurrency

One of the attacker wallets

2023-01-27 [vendor] Azuki Twitter [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Hackers were able to compromise the Twitter account belonging to the popular Azuki NFT project, which they then used to promote a fake NFT drop to its 334,000 followers. Users who …

Cryptocurrency

Tweet by Kevin Rose

2023-01-25 [vendor] Kevin Rose wallet [loss] $831,000 [chain] ethereum
Vector: Smart contract exploit / hack

Kevin Rose, perhaps best known as the founder of Digg, but also a prominent crypto investor and entrepreneur, lost a substantial number of pricey NFTs when he apparently signed a …

Cryptocurrency

Tweet thread by NFT GOD

2023-01-13 [vendor] NFT GOD wallet drain [loss] $25,800 [chain] ethereum
Vector: Phishing attack

According to NFT GOD, his computer was infected with malware when he clicked a sponsored link in a Google search when he went to download the streaming software OBS. This is …

Cryptocurrency

Tweet by Magic Eden

2023-01-04 [vendor] Magic Eden lists fake NFTs [loss] $5,000 [chain] solana
Vector: Smart contract exploit / hack

Magic Eden, as with many NFT marketplaces, has a verification layer that shows popular projects as "verified" to reduce the chances of people being tricked by NFTs with the same …

Cryptocurrency

"Nike's RTFKT COO Loses His NFTs in Massive Hack"

2023-01-02 [vendor] Nikhil Gopalani NFT theft [loss] $159,300 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker drained the wallet of Nikhil Gopalani, the COO of the Nike-owned crypto organization RTFKT. Most of the stolen NFTs were RTFKT NFTs, and the priciest were the nineteen …

Cryptocurrency

Tweet by PeckShieldAlert

2022-12-26 [vendor] BitKeep [loss] $8M [chain] bsc
Vector: Malicious code injection / supply chain

BitKeep, a popular cryptocurrency wallet in Asia, suffered a hack in which at least $8 million in various cryptocurrencies were stolen from user accounts.BitKeep has claimed that …

Cryptocurrency

Tweet by PeckShieldAlert

2022-12-23 [vendor] Defrost Finance [chain] avalanche
Vector: Flash loan attack on smart contract

Defrost Finance, a defi trading platform built on the Avalanche Network, apparently tried and failed to rug pull its users. The project claimed on December 23 that they were "sad …

Cryptocurrency

Tweet by Ray Youssef

2022-12-21 [vendor] Paxful delists ether [chain] bitcoin, ethereum

Peer-to-peer crypto marketplace Paxful announced that it will be delisting ether, citing "scams that have robbed people of billions".So close. You're almost there.Paxful CEO Ray …

Cryptocurrency

Tweet by Swan Bitcoin

2022-12-21 [vendor] Swan Bitcoin releases home equity Bitcoin product [chain] bitcoin

"Convert home equity into Bitcoin", Swan Bitcoin advertises with their new home equity product. Relatively few details are available on the new loan product they're offering, but …

Cryptocurrency

Tweet thread by _sevenseason_

2022-12-17 [vendor] sevenseason NFT theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A scammer spent a month setting up a con in which they stole fourteen Bored Ape NFTs belonging to one individual. Posing as a casting director at a real film production …

Cryptocurrency

"QuadrigaCX Has Had an Improbable Week"

2022-12-16 [vendor] QuadrigaCX "unauthorized" transfer [loss] $2M [chain] bitcoin
Vector: Exit scam / rug pull

QuadrigaCX was a Canadian crypto exchange that shut down and filed for bankruptcy in early 2019, with hundreds of millions more in liabilities than in assets. It later became …

Cryptocurrency

<i>Adonis Real v. Yuga Labs, Inc.</i>

2022-12-08 [vendor] Celebrity class action filed [chain] ethereum
Vector: Regulatory / legal action

A class action lawsuit against the company behind Bored Apes and its executives, those on the board of "Ape DAO", a whole host of celebrity promoters and brands, and the MoonPay …

Cryptocurrency

Tweet thread by OKHotshot

2022-12-08 [vendor] Vanessa Sierra [loss] $316,320 [chain] ethereum
Vector: Exit scam / rug pull

After a stint on Season 2 of Love Island Australia, Vanessa Sierra has made a career as a successful OnlyFans performer. In 2021, she also began offering crypto trading tips in a …

Cryptocurrency

Tweet by jac0xb.sol

2022-12-07 [vendor] FTX NFTs break [chain] ethereum, solana

After FTX declared bankruptcy, the entire FTX.us domain was redirected to a page providing information on the bankruptcy proceedings.However, NFTs that had been minted on the FTX …

Cryptocurrency

Tweet by Ankr

2022-12-01 [vendor] Ankr [loss] $5M [chain] bsc
Vector: Malicious code injection / supply chain

The BNB Chain-based Ankr defi protocol suffered an exploit of their aBNBc token. "We are currently working with exchanges to immediately halt trading," they wrote. However, the …

Cryptocurrency

Web3 Is Going Great

2022-11-26 [vendor] Elon statue fails to impress [chain] ethereum

A shitcoin project desperate for the kind of pump that sometimes occurs when Elon Musk tweets about a cryptocurrency has gone to new lengths to get his attention. The group spent …

Cryptocurrency

Tweet by PeckShield

2022-11-13 [vendor] Flare token [loss] $17M [chain] bsc
Vector: Exit scam / rug pull

Exploits and rug pulls of random tokens on BNB Chain are fairly commonplace, but typically the amount of money lost is fairly minimal. In this case, exploiters or insiders were …

Cryptocurrency

Tweet by jconorgrogan

2022-11-12 [vendor] Crypto.com admits erroneous transfer [chain] ethereum

A Twitter user posted Etherscan screenshots showing a massive flow of crypto from the Crypto.com cryptocurrency exchange to another exchange, Gate.io. "Anyone know why Crypto.com …

Cryptocurrency

Tweet by DeFiAI

2022-11-12 [vendor] DeFiAI [loss] $4M [chain] bsc
Vector: Smart contract exploit / hack

"Our contract has been hacked and has caused a lot of losses," wrote DeFiAI simply in their announcement. That same day, the project had announced the launch of a new website for …

Cryptocurrency

Tweet thread by CertiKAlert

2022-11-10 [vendor] DFX Finance attack [loss] $5M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to use a flash loan to exploit a vulnerability in the smart contract for DFX Finance, a decentralized forex trading platform. The platform suffered a loss …

Cryptocurrency

Tweet thread by zachxbt

2022-11-04 [vendor] Monkey Drainer phishing attack [loss] $867,042 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The "Monkey Drainer" NFT phishing scammer first identified by blockchain detective zachxbt has struck again. They successfully emptied 7 CryptoPunks and 20 Otherside NFTs, which …

Cryptocurrency

"Financing and Bitmain Prepayment Update"

2022-11-02 [vendor] Iris Energy close to defaulting on loans [chain] bitcoin
Vector: Protocol collapse / insolvency

Iris Energy, an Australian "sustainable Bitcoin mining company", has announced that they are close to defaulting on loans used to purchase $103 million of Bitcoin mining rigs. …

Cryptocurrency

Tweet thread by Rubic

2022-11-02 [vendor] Rubic [loss] $814,000 [chain] bsc, ethereum
Vector: Smart contract exploit / hack

An attacker was able to compromise the private key of an admin wallet for the Rubic crypto exchange, transferring around 34 million Rubic tokens. The attacker then sold the tokens …

Cryptocurrency

Tweet by Solend

2022-11-02 [vendor] Solend attack [loss] $1M [chain] solana
Vector: Oracle price manipulation

Solend announced that an exploiter had manipulated the oracle price of an asset on their platform, allowing them to take out a loan that left the platform with $1.26 million in bad …

Cryptocurrency

friesDAO

2022-10-27 [vendor] friesDAO attack [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

friesDAO describes itself as a "a decentralized social experiment where a crypto community builds and governs a fast food franchise empire via wisdom of the crowd". Welcome to the …

Cryptocurrency

Tweet thread by zachxbt

2022-10-25 [vendor] Monkey Drainer phishing [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A phishing scammer called "Monkey Drainer" stole around 700 ETH (~$940,000) in 24 hours on October 25, according to blockchain sleuth zachxbt. The scammer used malicious phishing …

Cryptocurrency

Tweet thread by Layer2DAO

2022-10-23 [vendor] Layer2DAO [loss] $87,000 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker was able to siphon nearly 50 million L2DAO tokens from a multi-sig wallet on the Optimism protocol. These tokens would nominally have been valued at around $400,000 at …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-10-23 [vendor] QuickSwap attack [loss] $188,260 [chain] polygon
Vector: Oracle price manipulation

Adding to the recent string of oracle manipulation attacks is an attack on the miMATIC ($MAI) market on the QuickSwap decentralized exchange. An exploiter was able to manipulate …

Cryptocurrency

Tweets by Wu Blockchain

2022-10-22 [vendor] 3Commas [loss] $6M [chain] bitcoin
Vector: Phishing attack

Several users of the automated trading bot 3Commas reported losing over a million dollars each in a hack or phishing scam affecting users who had connected it to their FTX …

Cryptocurrency

Tweet thread by Lee Bousfield

2022-10-18 [vendor] BitBTC vulnerability [chain] bitcoin, ethereum
Vector: Smart contract exploit / hack

A security researcher published a frustrated Twitter thread reporting that "BitBTC's Optimism bridge is trivially vulnerable. Their team has ignored my messages, so I'm going to …

Cryptocurrency

Tweet thread by Moola Market

2022-10-18 [vendor] Moola Market attack [loss] $588,000 [chain] celo
Vector: Oracle price manipulation

The Celo-based borrowing and lending platform, Moola Market, suffered a major exploit when an attacker manipulated collateral prices to steal a collection of assets notionally …

Cryptocurrency

Tweet by Rusty Bill

2022-10-18 [vendor] Roofstock claims to have sold house as NFT [chain] ethereum

If you've ever wished you could put the same amount of thought into buying a $100,000+ home as you do ordering another bag of dog food from your online retailer of choice, you're …

Cryptocurrency

"Why we’re no longer offering .coin"

2022-10-18 [vendor] Unstoppable Domains disables .coin extensions [chain] ethereum

Unstoppable Domains is in the business of selling "domains" — at least that's what they call them, but they're not the kind of domain that you can plug into your web browser. …

Cryptocurrency

Tweet thread by BitKeep Wallet

2022-10-17 [vendor] BitKeep Swap [loss] $100,000 [chain] bsc
Vector: Smart contract exploit / hack

The Swap feature of the BitKeep crypto wallet suffered an exploit that landed a hacker more than $1 million worth of BNB. The project acknowledged the hack, and promised to …

Cryptocurrency

Tweet thread by Syntropy

2022-10-15 [vendor] Syntropy theft [chain] ethereum
Vector: Smart contract exploit / hack

The web3 company Syntropy suffered the loss of 15 million of their $NOIA tokens when they attempted to transfer them to a venture capital firm, but instead they ended up with a …

Cryptocurrency

Tweet by MevRefund

2022-10-14 [vendor] Earning.Farm attack [loss] $971,248 [chain] ethereum
Vector: Flash loan attack on smart contract

The defi project Earning.Farm lost 748 ETH (~$971,000) to a hacker using a flash loan attack. The project contract was missing a check that a flash loan was initiated by the …

Cryptocurrency

Twitter thread by Cami

2022-10-13 [vendor] Blu3DAO accusations [chain] ethereum

Blu3DAO is a DAO that describes itself as "focused on empowering women, non-binary people, and allies to learn, earn, and play in web3 towards financial freedom". The group was the …

Cryptocurrency

Tweet by Vault by CNN

2022-10-11 [vendor] CNN abandons Vault NFT project [chain] flow
Vector: Exit scam / rug pull

In June 2021, CNN launched "Vault": a project to "make moments from history available for purchase". The project involved minting as NFTs various clips of CNN footage and …

Cryptocurrency

Web3 Is Going Great

2022-10-11 [vendor] Harassment at Ethereum conference [chain] ethereum

A Black woman attending the major Devcon Ethereum community event in Bogotá posted to Twitter a photograph of a man at the conference, writing, "Day 1 of Devcon and a group of us …

Cryptocurrency

Attacker's account

2022-10-11 [vendor] Mango Markets [loss] $50M [chain] solana
Vector: Oracle price manipulation

Mango Markets, a Solana-based defi project offering borrowing, lending, and leverage trading, was exploited for $116 million. An attacker manipulated the supposed value of their …

Cryptocurrency

Tweet thread by Rabby Wallet

2022-10-11 [vendor] Rabby Wallet [loss] $194,500 [chain] ethereum
Vector: Smart contract exploit / hack

Rabby Swap, a feature of the Rabby crypto wallet, was exploited a month after it was first rolled out. An attacker discovered an apparent vulnerability in the Rabby Swap smart …

Cryptocurrency

"DeFi Protocol Temple DAO Struck by $2.3M Exploit"

2022-10-11 [vendor] STAX Finance [loss] $2M [chain] ethereum
Vector: Smart contract access control vulnerability

A hacker discovered a vulnerability in the smart contract for the STAX project, which is built on the TempleDAO defi protocol. STAX is a liquidity provider for $TEMPLE/$FRAX.Poor …

Cryptocurrency

Tweet thread by OxQuit

2022-10-08 [vendor] Laszlo_btc NFT theft [loss] $2M [chain] ethereum
Vector: Phishing attack

In an incredible display of misfortune and perhaps ineptitude, an NFT collector was scammed out of a Bored Ape and then scammed out of six more Bored Apes when he tried to revoke …

Cryptocurrency

Tweet by Laine

2022-09-30 [vendor] Solana outage [chain] solana

In the latest illustration of our marvelous new decentralized, resilient blockchain future, one single Solana node apparently was able to take down the entire Solana network. …

Cryptocurrency

"RIP MEV BOT"

2022-09-28 [vendor] 0xbadc0de MEV bot [loss] $1M [chain] ethereum
Vector: MEV / sandwich attack

MEV bots are a controversial category of bots who frontrun transactions in ways that are often detrimental to users. One such bot, known as 0xbadc0de, earned a windfall when a …

Cryptocurrency

Tweet thread by Jason Falovitch

2022-09-25 [vendor] Jason Falovitch NFT theft [loss] $150,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Sports manager turned crypto entrepreneur Jason Falovitch is now perhaps best known for his influence in the NFT space. He co-founded the Leverage Game Media company along with …

Cryptocurrency

Tweet thread by Evgeny Gaevoy

2022-09-20 [vendor] Wintermute [loss] $160M [chain] ethereum
Vector: Smart contract exploit / hack

The algorithmic market maker Wintermute suffered a major hack, according to their CEO. He estimated the loss at around $160 million, also writing that the company is "solvent with …

Cryptocurrency

Tweet by LakeShowTJ

2022-09-18 [vendor] LakeShowTJ NFT theft [loss] $17,515 [chain] ethereum
Vector: Smart contract exploit / hack

The owner of Mutant Ape #21080 was approached with an offer to trade their ape for another Mutant Ape (#55) and an extra 0.5 ETH ($675) to sweeten the deal. The trader agreed, and …

Cryptocurrency

Tweet thread by CryptoCondom

2022-09-17 [vendor] AVAX chart [loss] $400,000 [chain] avalanche
Vector: Software bug / unintentional loss

GMX is a decentralized cryptocurrency exchange that boasts zero price impact trades. On most exchanges, users have to contend with slippage: a difference between the price of a …

Cryptocurrency

Tweet by Molly White

2022-09-14 [vendor] Ethereum merge double-your-money [loss] $314,307 [chain] ethereum
Vector: Smart contract exploit / hack

If it seems like you've been seeing a lot of Ethereum co-founder and figurehead Vitalik Buterin around Twitter lately, it may be due to the influx of hacked verified Twitter …

Cryptocurrency

Tweet by CertiKAlert

2022-09-06 [vendor] Avalanche flash loan attacks [loss] $370,000 [chain] avalanche
Vector: Flash loan attack on smart contract

An attacker using the Avalanche blockchain successfully executed a flash loan attack impacting one contract and several other liquidity providers. The attacker made around $370,000 …

Cryptocurrency

Tweet by DavidBowieReal

2022-09-06 [vendor] David Bowie NFT announcement [chain] ethereum

The latest entry in "group launches NFTs, fans hate it" comes from the David Bowie estate, who decided that "Bowie on the Blockchain" would be a cool idea to raise money for …

Cryptocurrency

Tweet thread by Rug Pull Finder

2022-09-02 [vendor] Bad Guys promotional artwork [loss] $4,000 [chain] ethereum
Vector: Exit scam / rug pull

The group Rug Pull Finder aims to combat fraud, scams, and hacks in the NFT space, often investigating crypto rug pulls and offering audits for projects and smart contracts. They …

Cryptocurrency

Tweet by CertiKAlert

2022-09-01 [vendor] ShadowFi [loss] $298,200 [chain] bsc
Vector: Smart contract exploit / hack

An attacker discovered that anyone could call the burn function on the liquidity pool contract for the ShadowFi project. They were able to exploit this vulnerability by calling the …

Cryptocurrency

"Babylon Finance is shutting down"

2022-08-31 [vendor] Babylon Finance [loss] $3M [chain] ethereum
Vector: Protocol collapse / insolvency

In April, an attacker exploited vulnerabilities in the defi lending project Rari Capital to steal $80 million. The asset management project Babylon Finance was a major lending pool …

Cryptocurrency

"From Fanfaron"

2022-08-26 [vendor] Ragnarok treasury mismanagement [loss] $2M [chain] ethereum

Ragnarok is a metaverse role-playing game that launched its character NFTs in April 2022. The project received $1.75 million in seed funding, plus another $17.5 million from NFT …

Cryptocurrency

Tweet thread by ENS DAO

2022-08-25 [vendor] eth.link domain at risk [chain] ethereum
Vector: Phishing attack

Some people might be familiar with ENS, the "Ethereum Name Service", which seeks to be a web3 equivalent of DNS. If you've seen people with usernames ending in .eth, that's an ENS …

Cryptocurrency

Tweet by CertikAlert

2022-08-24 [vendor] PokemonFi [loss] $708,000 [chain] bsc

It's not much compared to at least three separate crypto Pokémon ripoffs since February that have each taken millions, but apparently the love of Pokémon still drew people in to …

Cryptocurrency

Tweet by zachxbt

2022-08-20 [vendor] 0x47dF5 NFT theft [loss] $116,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

In what might be a new record, someone bought a Bored Ape NFT for 70.69 ETH (~$116,000) and had it stolen from them less than two hours later. The scammer quickly flipped the NFT …

Cryptocurrency

Tweet by penguin_curator

2022-08-20 [vendor] OpenSea listing bug [chain] ethereum
Vector: Software bug / unintentional loss

The same issue that led to OpenSea paying out $1.8 million to users who lost their NFTs is apparently still alive and well (despite OpenSea's introduction of an "Inactive listings" …

Cryptocurrency

"Magic Eden Response to Degen Town"

2022-08-18 [vendor] DegenTown [loss] $923,000 [chain] solana
Vector: Exit scam / rug pull

DegenTown, a collection of brightly-colored cel shaded humanoid figures, launched with much promotion from Magic Eden on their Launchpad minting service. Magic Eden aims to provide …

Cryptocurrency

HUSD on CoinMarketCap

2022-08-17 [vendor] HUSD [chain] ethereum

HUSD, a stablecoin linked to the Huobi crypto exchange, lost its peg and dropped to around $0.85. HUSD is a cash-backed stablecoin intended to be pegged to the US dollar, but the …

Cryptocurrency

Tweet by zachxbt

2022-08-14 [vendor] ASEC_APE NFT theft [loss] $546,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

An NFT collector who goes by ASEC_APE lost four Bored Ape Yacht Club NFTs to a phishing attack. The attacker quickly flipped three of the four NFTs for a total of around 200 ETH …

Cryptocurrency

Tweet thread by Philneeds

2022-08-13 [vendor] Fake Apecoin [loss] $163,770 [chain] ethereum
Vector: Smart contract exploit / hack

A scammer created a fake ApeCoin contract on the NFT Trader service, with tokens that appeared identical to the true ApeCoins but were actually worthless. After "chatt[ing] for a …

Cryptocurrency

Tweet by Velodrome

2022-08-13 [vendor] Velodrome theft by team member [chain] ethereum
Vector: Smart contract exploit / hack

On August 4, the team behind the Velodrome exchange and liquidity marketplace noticed that $350,000 had been taken from a team-operated wallet that was normally used for …

Cryptocurrency

Tweet by takenstheorem

2022-08-11 [vendor] Ethermine blocks Tornado transactions [chain] ethereum

The Ethermine mining pool is responsible for over a quarter of all Ethereum mining, making them the largest miner for that blockchain. On August 11, three days after OFAC added the …

Cryptocurrency

Tweet by Curve Finance

2022-08-09 [vendor] Curve Finance [chain] ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

Curve Finance's frontend at curve.fi was compromised, prompting users to give token approval to a malicious smart contract. Stolen funds were then transferred out to the FixedFloat …

Cryptocurrency

"Scammers In Paris"

2022-08-08 [vendor] Bored Ape animation [loss] $2M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has uncovered a French scam duo, Mathys and Camille, who he believes were behind the March "turn your BAYC animated" phishing scam in which they stole a …

Cryptocurrency

Riot Blockchain press release

2022-08-08 [vendor] Riot blockchain curtailment [chain] bitcoin

The Bitcoin mining firm Riot Blockchain produced 318 BTC in July, valued at around $6.88 million, from its mining operations located in central Texas. The firm also received $9.5 …

Cryptocurrency

Tweet by CertiK Alert

2022-08-07 [vendor] "Saxon James Musk" coin [loss] $442,000 [chain] bsc
Vector: Exit scam / rug pull

Who could have predicted that the shitcoin named after one of Elon Musk's 16-year-old sons could turn out to be a scam? Well, besides the people who fell for previous rug pulls of …

Cryptocurrency

Tweet by Steven Galanis

2022-08-06 [vendor] Steven Galanis wallet compromise [loss] $231,000 [chain] ethereum
Vector: Seed phrase / wallet compromise

A hacker compromised the wallet belonging to Steven Galanis, the CEO of Cameo, an app that allows people to pay various celebrities to record short messages for them. The hacker …

Cryptocurrency

Tweet thread by 0xfoobar

2022-08-02 [vendor] Slope wallet attack [loss] $6M [chain] solana
Vector: Smart contract exploit / hack

Nearly 8,000 Solana wallets were drained for at least $6 million worth of assets, including native SOL tokens and SPL tokens like USDC. The attack went on for nearly a day before …

Cryptocurrency

"Multi-Strategy Vault Post-Mortem"

2022-08-01 [vendor] Reaper Farm [loss] $2M [chain] fantom
Vector: Smart contract exploit / hack

Yield farming project Reaper Farm suffered an exploit that resulted in a $1.7 million loss. The attackers discovered a vulnerability that allowed them to withdraw anyone else's …

Cryptocurrency

"Audius Governance Takeover Post-Mortem 7/23/22"

2022-07-23 [vendor] Audius governance attack [loss] $1M [chain] ethereum
Vector: Governance attack / malicious on-chain proposal

An attacker was able to create and pass a governance proposal to transfer out 18.5 million AUDIO tokens from the community treasury. They then successfully swapped these for 705 …

Cryptocurrency

"Falling Man"

2022-07-23 [vendor] Gamestop NFT platform hosts 9/11 NFT [chain] ethereum

GameStop's brand new NFT platform, which launched on July 12, is off to a less than promising start. Unlike some other NFT platforms like OpenSea, Gamestop does not allow just …

Cryptocurrency

Tweet by franklinisbored

2022-07-20 [vendor] Franklin joke loss [loss] $150,646 [chain] ethereum

Bored Ape aficionado franklinisbored has apparently found a new source of entertainment by placing high bids on his own ENS domains with amusing names, causing a Twitter bot that …

Cryptocurrency

Tweet by PeckShieldAlert

2022-07-19 [vendor] Raccoon Network and Freedom Protocol [loss] $21M [chain] bsc

20.8 million BUSD, a dollar-pegged stablecoin on BNB Chain, was transferred from Raccoon Network and the Freedom Protocol on July 19. Security firm PeckShield identified the …

Cryptocurrency

Tweet by 0xQuit

2022-07-17 [vendor] PREMINT [loss] $680,800 [chain] ethereum
Vector: Smart contract exploit / hack

PREMINT is an NFT service intended to help project creators build access lists for new NFT projects based on various qualifications. The project was compromised on July 17, and …

Cryptocurrency

Tweet thread by zachxbt

2022-07-14 [vendor] Boneheads [loss] $3M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has accused the NFT project "Boneheads" of rug pulling only weeks after the project minted in August 2021. Although they promised physical collectibles, more …

Cryptocurrency

Tweet by PeckShieldAlert

2022-07-11 [vendor] Citizen Finance [loss] $94,300 [chain] polygon, bsc
Vector: Exit scam / rug pull

Citizen Finance, a multichain platform that has something to do with NFTs and blockchain gaming, claimed to have suffered an attack by an outside party who obtained access to a …

Cryptocurrency

Tweet by CZ

2022-07-11 [vendor] Uniswap phishing attack [loss] $8M [chain] ethereum
Vector: Phishing attack

In a successful, broadly-targeted phishing campaign, more than 70,000 addresses connected to Uniswap were airdropped tokens that baited users into approving transactions that …

Cryptocurrency

Tweet thread by Crema Finance

2022-07-02 [vendor] Crema Finance [loss] $2M [chain] solana
Vector: Smart contract exploit / hack

Solana liquidity protocol Crema Finance was exploited for around 69,500 SOL (~$2.3 million) and around $6.5 million worth of stablecoins for a total loss of around $8.8 million. …

Cryptocurrency

"Two Polygon, Fantom Front Ends Hit by DNS Attack"

2022-07-01 [vendor] Ankr [chain] polygon, fantom
Vector: DNS hijacking / domain takeover (front-end compromise)

The Ankr public RPC gateways (basically an API for dApps and other services to communicate with the blockchain) for Polygon and Fantom were impacted when attackers compromised the …

Cryptocurrency

"Voyager Digital Provides Market Update"

2022-07-01 [vendor] Voyager Digital suspends withdrawals [chain] bitcoin
Vector: Withdrawal halt / insolvency

Voyager Digital announced that they had suspended trading, deposits, withdrawals, and loyalty rewards. This came after it was revealed that Voyager had issued a notice of default …

Cryptocurrency

Web3 Is Going Great

2022-06-30 [vendor] Coca-Cola Pride Bottle #8 [chain] polygon

If it wasn't already nauseating to watch a huge corporation like Coca-Cola use LGBTQ Pride Month to market their products and pay lip service to supporting LGBTQ rights while …

Cryptocurrency

Tweet thread by Harmony

2022-06-23 [vendor] Horizon Bridge [loss] $100M [chain] bsc, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The Horizon Bridge is a blockchain bridge allowing assets to be used across Ethereum, BNB, and Harmony blockchains. The bridge is run by the Harmony blockchain project.On June 23, …

Cryptocurrency

Tweet by Daniel Hong

2022-06-20 [vendor] Terraforms Labs employees banned from leaving Korea [chain] terra
Vector: Regulatory / legal action

A former employee of Terraform Labs, the company behind the Terra project that collapsed in May, found that he was banned from leaving the country. According to the former …

Cryptocurrency

Tweet by OKHotshot

2022-06-19 [vendor] Lacoste Discord [chain] ethereum
Vector: Smart contract exploit / hack

So, apparently polo shirts have NFTs now. Fashion brand Lacoste's NFT project is titled "Undw3", which is apparently supposed to be pronounced "underwater" — I guess if you say the …

Cryptocurrency

"SLND1: Mitigate Risk From Whale"

2022-06-19 [vendor] Solend DAO passes proposal to take over account [chain] solana

Solend DAO, the DAO behind the Solend lending protocol on Solana, just passed its first ever governance proposal. A whale used their platform to take out an enormous margin …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-06-16 [vendor] Inverse Finance [loss] $6M [chain] ethereum
Vector: Flash loan attack on smart contract

A hacker was able to perform an oracle manipulation attack enabled by flash loans to siphon crypto worth around $1.26 million from Inverse Finance. The loss to the protocol was …

Cryptocurrency

Tweet by Flip McBot

2022-06-13 [vendor] NFT collector sells at huge loss [chain] ethereum

In October 2021, an NFT collector dropped 300 ETH (then $1.05 million) on CrypToadz #2155, a pixel art image of a blue toad skeleton on a blue background. On June 13, they sold the …

Cryptocurrency

Tweet thread by SmallCapScience

2022-06-12 [vendor] stETH [chain] ethereum

Lido-staked ETH, a project that offers to allow users to stake ETH for the purposes of securing it after the Ethereum "merge" — that is, the ever-delayed move to proof-of-stake. …

Cryptocurrency

Tweet by NFTherder

2022-06-09 [vendor] El Universal Twitter account [loss] $30,000 [chain] ethereum
Vector: Smart contract exploit / hack

Scammers successfully compromised the Twitter account for El Universal, a Venezuelan newspaper. The account is verified, and has five million followers. The scammers used the …

Cryptocurrency

Tweets by Offline Cash

2022-06-09 [vendor] Offline Cash project announcement [chain] bitcoin

Some crypto advocates have long promoted crypto as a proper digital equivalent to cash. Physical dollars have a lot of benefits, including that you don't need a bank account to use …

Cryptocurrency

Tweet by ApolloX

2022-06-08 [vendor] ApolloX exchange attack [loss] $2M [chain] bsc
Vector: Smart contract exploit / hack

The ApolloX exchange suffered an exploit where an attacker was able to withdraw around 40 million $APX, which they were able to swap for around $1.5 million. This also caused the …

Cryptocurrency

Tweet by PeckShieldAlert

2022-06-08 [vendor] Baby Elon coin [loss] $178,994 [chain] bsc
Vector: Exit scam / rug pull

The Baby Elon project on BNBChain rug pulled on June 8, with the token price plummeting 98% as the team withdrew 623 BNB (~$179,000) from the project. They quickly moved the funds …

Cryptocurrency

Tweet by PeckShield Inc.

2022-06-08 [vendor] GYM Network [loss] $2M [chain] bsc
Vector: Software bug / unintentional loss

Attackers stole around $2.1 million from the GYM Network defi project after exploiting a bug in a recently-deployed contract that failed to check the identity of the caller. The …

Cryptocurrency

"Republican Rep. Madison Cawthorn failed to properly disclose 2-dozen more cryptocurrency trades, including 'Let's Go Brandon' coin, bitcoin, and ethereum"

2022-06-08 [vendor] Madison Cawthorn belatedly reports trades [chain] ethereum, bitcoin, solana
Vector: Regulatory / legal action

Representative Madison Cawthorn (R-NC) is facing an ethics investigation pertaining to his involvement with the Let's Go Brandon coin, which includes allegations of insider trading …

Cryptocurrency

Thread by zachxbt

2022-06-08 [vendor] Players Only NFT [loss] $1M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto-sleuth zachxbt reported on June 8 that Players Only, and NFT project created by a group of NBA players including Michael Carter-Williams and Jerami Grant, appears to be a …

Cryptocurrency

Tweet by Yung Ape Squad

2022-06-06 [vendor] Early June 2022 Discord compromises [loss] $243,000 [chain] ethereum
Vector: Phishing attack

The June 4 compromise of the Bored Apes Discord was only one of several Discord hacks in a several-day period. All the attacks appeared to involve user accounts of individual …

Cryptocurrency

Thread by CertiK Alert

2022-06-04 [vendor] Bored Apes Discord compromise [loss] $250,000 [chain] ethereum
Vector: Smart contract exploit / hack

Scammers were able to compromise the Discord account of a Bored Apes community manager, then use it to post an announcement of an "exclusive giveaway" to anyone who held a Bored …

Cryptocurrency

Tweet by topshotkief

2022-06-04 [vendor] topshotkief NFT theft [loss] $365,000 [chain] ethereum
Vector: Smart contract exploit / hack

An NFT collector hoping to claim NFTs from the Goblintown collection was phished, resulting in ten of their NFTs being stolen from them. The scammers took two Mutant Ape NFTs and …

Cryptocurrency

Tweet thread by zachxbt

2022-06-02 [vendor] Animoon [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Animoon is yet another Pokémon rip-off NFT project, with artwork that was ripped directly from Pokémon artwork and recolored. They claim to have a "signed NDA" with Pokémon …

Cryptocurrency

Tweet thread by FedorLinnik

2022-06-02 [vendor] Goblin Asses project preempted [chain] ethereum

Hoping to riff off the popularity of the recent and weird Goblintown NFT project, some NFT enthusiasts decided to make their own "Goblin Asses" project, which is exactly what it …

Cryptocurrency

OpenSea transaction history

2022-06-01 [vendor] Bored Ape typo [chain] ethereum

NFT collector onekiller purchased Bored Ape #7256 for 188 ETH a month ago — at the time worth about $513,000. On June 1, they sold the ape for 0.088 ETH, or $161.It's not quite …

Cryptocurrency

Tweet by CryptoWhale

2022-06-01 [vendor] Solana outage [chain] solana

Solana is one of the more popular proof-of-stake blockchains, and is often trotted out as an alternative to Ethereum when people bring up Ethereum's environmental impact, slowness, …

Cryptocurrency

Tweet by nftmetaman.eth

2022-05-30 [vendor] Bored Ape typo [loss] $181,000 [chain] ethereum

An NFT collector trying to list their Bored Ape NFT for sale on OpenSea made a typo, and accidentally listed it for sale for 10 ETH (around $19,000) instead of 105 ETH (around …

Cryptocurrency

Tweet thread by FatMan

2022-05-30 [vendor] Mirror Protocol [loss] $2M [chain] terra
Vector: Software bug / unintentional loss

Someone has been able to drain more than $2 million from the Mirror Protocol in the Terra ecosystem. It appears they are exploiting an issue with the price oracle for "Luna …

Cryptocurrency

Tweet by RugPull Finder

2022-05-30 [vendor] Superlative Apes [loss] $3M [chain] ethereum
Vector: Exit scam / rug pull

The Superlative Apes NFTs are a collection of Bored Apes derivative NFTs that feature colorful pastels. The project amassed a large following (including, apparently, the rapper …

Cryptocurrency

Tweet by PINKCATNFT

2022-05-30 [vendor] Toronto Comic Arts Festival NFT artist controversy [chain] ethereum

The Toronto Comic Arts Festival angered artists and fans alike when they invited Saba Moeel, the artist behind the Pink Cat NFT collection, to attend as a featured guest. This was …

Cryptocurrency

Tweet thread by FatMan

2022-05-28 [vendor] Luna 2.0 [chain] terra

All holders of Luna, who saw their holdings crash to nothing in the Terra collapse, received an airdrop of the new Luna tokens with the release of Terra 2.0 (electric boogaloo). …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-27 [vendor] PokeMoney [loss] $4M [chain] bsc
Vector: Exit scam / rug pull

The token associated with yet another crypto Pokémon rip-off, PokeMoney, suddenly crashed in price when around 11,800 BNB ($3.5 million) worth of it was pulled out of the project. …

Cryptocurrency

Thread by FatMan

2022-05-26 [vendor] Mirror Protocol vulnerability [loss] $88M [chain] terra
Vector: Smart contract exploit / hack

A crypto researcher who goes by "FatMan" discovered that the Mirror Protocol in the Terra ecosystem contained a serious vulnerability, that was quietly patched with no announcement …

Cryptocurrency

Tweet thread by Terra

2022-05-25 [vendor] Terra 2.0 announcement [chain] terra

Following the dramatic collapse of Terra earlier this month, the Terra ecosystem voted to pass a proposal by Do Kwon to create "Terra 2.0". The project intends to "effectively …

Cryptocurrency

Tweet by CertiK Alert

2022-05-24 [vendor] DecentraWorld [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The creators of the Decentraworld project, and its associated $DEWO token, rug pulled for 3127 BNB, valued at just over $1 million. The project promised an "ecosystem of dapps with …

Cryptocurrency

Tweet by CirrusNFT

2022-05-24 [vendor] Digital Ornithologist NFT theft [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

A scammer was able to trick a prolific NFT collector into signing a transaction on a fake trading website, which then allowed them to maliciously transfer 29 pricey Moonbirds NFTs …

Cryptocurrency

Tweet thread by sniko

2022-05-22 [vendor] Beeple Twitter [loss] $438,000 [chain] ethereum
Vector: Smart contract exploit / hack

Attackers gained control of the Twitter account belonging to Beeple, an artist known for "selling" an NFT for $69 million in March 2021 and for his recent horror-inducing NFT …

Cryptocurrency

Tweet thread by TheJonnyReid

2022-05-22 [vendor] Johnny Reid wallet [loss] $203,000 [chain] ethereum
Vector: Phishing attack

Crypto speculator Jonny Reid wrote on May 22 that his crypto wallet had been hacked and drained of approximately $203,000. He wrote that he had never owned a hardware wallet before …

Cryptocurrency

Tweet thread by 0xngmi

2022-05-22 [vendor] Milady founders controversy [chain] ethereum

The founder of the Remilia Collective and its popular "Milady Maker" NFT project, "Charlotte Fang", was discovered to have been a key player in a white supremacist cult known as …

Cryptocurrency

Reptilian Renegade Twitter account

2022-05-19 [vendor] Reptilian Renegades [chain] solana
Vector: Exit scam / rug pull

The serial rug-puller who was behind the Balloonsville rug pull in February and Doodled Dragons rug pull in January has popped up once again, this time with a Solana NFT project …

Cryptocurrency

Tweet thread by FatMan

2022-05-19 [vendor] Stablegains [loss] $44M [chain] terra
Vector: Regulatory / legal action

A class action law firm sent a letter to the yield generation project Stablegains, demanding records on customer accounts, marketing and advertising strategies, and communications …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-18 [vendor] "Feminist Metaverse" token [loss] $533,000 [chain] bsc
Vector: Smart contract exploit / hack

The "Feminist Metaverse" ($FM) token suddenly plunged in value by 99.7% after an attacker stole 1,838 BNB ($533,000). The hacker quickly transferred the stolen funds to the Tornado …

Cryptocurrency

Tweet by Seth Green

2022-05-17 [vendor] Seth Green NFT theft [loss] $300,000 [chain] ethereum
Vector: Phishing attack

Actor Seth Green tweeted that he had been targeted with a phishing attack that resulted in the theft of four pricey NFTs: a Bored Ape, two Mutant Apes, and a Doodle. The thief …

Cryptocurrency

Tweet thread by CZ

2022-05-16 [vendor] CZ tweets about Binance's Terra/Luna holdings [chain] terra

On May 15, Binance CEO Changpeng Zhao (widely known as CZ) created a tweet thread in which he attempted to speak nonchalantly about questions that had "just occurred to [him]" …

Cryptocurrency

Tweet thread by CertiKAlert

2022-05-15 [vendor] "Feed Every Gorilla" token [loss] $2M [chain] ethereum, bsc
Vector: Flash loan attack on smart contract

A flash loan attack on the "Feed Every Gorilla" (FEG) token swap contracts pulled $1.3 million from the project, also tanking the token price by 80%. The project operates on both …

Cryptocurrency

"LUNA Trading Incident on Crypto.com App"

2022-05-13 [vendor] Crypto.com reverses Luna trades [chain] terra
Vector: Oracle price manipulation

One of the features of crypto that its proponents sometimes highlight is that transactions can't be reversed. This, of course, is not true when making trades on exchanges like …

Cryptocurrency

Tweet thread by Spirit Swap

2022-05-13 [vendor] SpiritSwap domain hijacking attack [loss] $18,000 [chain] fantom
Vector: DNS hijacking / domain takeover (front-end compromise)

In what is beginning to become a pattern, SpiritSwap was the latest project where attackers gained control of their domain and were able to modify the frontend to divert funds to a …

Cryptocurrency

Tweet by Terra

2022-05-12 [vendor] Terra blockchain halted [chain] terra
Vector: Governance attack / malicious on-chain proposal

After $LUNA dropped below $0.01, Terra announced that they halted the Terra blockchain. "Terra validators have decided to halt the Terra chain to prevent governance attacks …

Cryptocurrency

"Venus Protocol Official Statement regarding LUNA"

2022-05-12 [vendor] Terra oracle attacks [loss] $22M [chain] terra, avalanche, bsc
Vector: Smart contract exploit / hack

Earlier today, Terra halted their blockchain after a devastating few days. Subsequently, Chainlink's oracle paused the price feed, causing it to fall out of sync with the apparent …

Cryptocurrency

Luna/USD

2022-05-11 [vendor] Terra ($LUNA) to USD from April 11–May 11 [chain] terra
Vector: Protocol collapse / insolvency

Terraform Labs develops two cryptocurrencies: TerraUSD ($UST), an algorithmic stablecoin meant to be pegged to the U.S. dollar, and $LUNA, a crypto asset used both for speculation …

Cryptocurrency

"A Builder’s Journey"

2022-05-09 [vendor] Azuki #2821 [chain] ethereum
Vector: Exit scam / rug pull

In a blog post titled "A Builder's Journey", the founder of the popular Azuki NFT project admitted that he had also been behind the NFT projects CryptoPhunks (note the "h"), …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-09 [vendor] G.O.A.T. token [loss] $260,956 [chain] ethereum

The G.O.A.T. ("Greatest of all Tokens") project claimed to be "the new standard in cryptocurrency", with vague claims that it would "add value by addressing scalability and risk …

Cryptocurrency

TerraUSD/USD on CoinMarketCap

2022-05-09 [vendor] Terra/Luna [loss] $40.0B [chain] terra
Vector: Protocol collapse / insolvency

It's been a rough few days for TerraUSD, one of several popular stablecoins pegged to the US dollar. Unlike many stablecoins like Tether or USDC, Terra is an algorithmic …

Cryptocurrency

Archived Cashera website

2022-05-08 [vendor] Cashera [loss] $89,200 [chain] bsc

Cashera was a project claiming to provide a "banking revolution" with its CSR crypto token. The project did many things to try to appear legitimate, including linking to government …

Cryptocurrency

Tweet thread by Jetfuel Finance

2022-05-08 [vendor] Fortress Protocol [loss] $3M [chain] ethereum
Vector: Oracle price manipulation

An attacker was able to steal 1,048 ETH (~$2.65 million) and 400,000 DAI from the Fortress Protocol borrowing and lending platform in what appears to have been an oracle …

Cryptocurrency

Tweet thread by CertiKAlert

2022-05-08 [vendor] Hunter [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

Under the pretense of a contract upgrade, the Hunter defi project team drained the liquidity from the project, swapping the tokens for assets worth around $1.2 million. The team …

Cryptocurrency

Tweet by Rug Pull Finder

2022-05-07 [vendor] Fury of the Fur [loss] $303,000 [chain] ethereum

The Fury of the Fur NFT project was a collection of 3D models that sort of resembled bears. The project advertised that the models were "metaverse and game-ready", and the roadmap …

Cryptocurrency

Thread by CertiKAlert

2022-05-06 [vendor] Day of Defeat [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The token associated with the Day of Defeat project, which describes itself as a "radical social experiment token mathematically designed to give holders 10,000,000X PRICE …

Cryptocurrency

Tweet by CertiK Alert

2022-05-05 [vendor] Pragma [loss] $2M [chain] fantom
Vector: Exit scam / rug pull

The Pragma defi project on the Fantom blockchain announced that their treasury and project wallets had been drained for around $1.5 million in $FTM.The rug pull appeared to have …

Cryptocurrency

Tweet by MM.Finance

2022-05-04 [vendor] MM.Finance [loss] $2M [chain] cosmos, ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

MM.Finance, a group of crypto projects based on the Cronos blockchain, suffered an attack that allowed a hacker to redirect more than $2 million worth of crypto assets that were …

Cryptocurrency

Tweet thread by BlockSec

2022-04-30 [vendor] Fei Protocol [loss] $80M [chain] ethereum
Vector: Smart contract exploit / hack

A hacker attacked multiple Rari liquidity pools relating to the Fei Protocol, exploiting a known re-entrancy vulnerability that exists on forks of the Compound protocol. The …

Cryptocurrency

Tweet thread by Molly White

2022-04-30 [vendor] Otherside launch spikes gas fees [chain] ethereum

The much-awaited Bored Ape Yacht Club "Otherside" metaverse land sale began, and its popularity just about wrecked Ethereum for everyone else. Gas fees, which increase based on …

Cryptocurrency

Tweet thread by zachxbt

2022-04-30 [vendor] Otherside phishing sites [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

In what should surprise nobody, some of the historically phishing-prone fans of the pricey Bored Apes project fell for scams that pretended to be the Bored Apes' new land project, …

Cryptocurrency

Tweet thread by PeckShield

2022-04-30 [vendor] Saddle Finance [loss] $11M [chain] ethereum
Vector: Flash loan attack on smart contract

An exploiter used a flash loan attack to pull 3,933 ETH (~$11 million) from the "decentralized automated market maker" Saddle Finance. Shortly after the attack, the hacker began …

Cryptocurrency

Tweet thread by Solana Status

2022-04-30 [vendor] Solana outage [chain] solana

On April 30, NFT minting bots began flooding the Solana network with 4 million transactions per second, causing the network to lose consensus. The project tweeted that "Engineers …

Cryptocurrency

Tweet by OxQuit

2022-04-30 [vendor] Teenage Mutant Ninja Turtles project buys forged contract [chain] ethereum
Vector: Exit scam / rug pull

A project to create Teenage Mutant Ninja Turtles NFTs stirred up a lot of excitement, garnering more than 100,000 Twitter followers on a verified Twitter account that described …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-04-28 [vendor] Deus Finance [loss] $13M [chain] fantom
Vector: Flash loan attack on smart contract

The defi project Deus Finance was hit with a flash loan attack that netted the hacker $13.4 million. The loss to the protocol was likely larger than what the hacker was able to …

Cryptocurrency

Twitter thread by JennieCuteCat

2022-04-27 [vendor] Fake Louis Vuitton project [chain] ethereum
Vector: Smart contract exploit / hack

Scammers created a project on OpenSea with Louis Vuitton branding, which invited individuals to visit an external site to mint exclusive NFTs. They placed a blue checkmark on the …

Cryptocurrency

Tweet by Bored Ape Yacht Club

2022-04-25 [vendor] Bored Apes Instagram [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Bored Ape Yacht Club's Instagram account was compromised and used to advertised a fake airdrop for metaverse land. This was particularly believable, as the much-anticipated …

Cryptocurrency

Tweet thread by 0xfoobar

2022-04-22 [vendor] AkuDreams bug [loss] $34M [chain] ethereum
Vector: Software bug / unintentional loss

Micah Johnson, an artist and former professional baseball player, launched an astronaut-themed NFT project called AkuDreams. The auction was based around a Dutch auction, with the …

Cryptocurrency

Tweet thread by Molly White

2022-04-22 [vendor] Epoch Times writers send crypto mailer [chain] bitcoin

Bob Byrne and Tim Collins, two prolific contributors to the far-right Epoch Times, have expanded their grift to crypto. A twenty-page-long "newspaper" titled Wall Street Today …

Cryptocurrency

Web3 Is Going Great

2022-04-20 [vendor] Binance Twitter branded hashtag looks like a swastika [chain] bsc

Binance, the world's largest crypto exchange, used Twitter's branded hashtag feature to add a custom emoji to Twitter when people use the hashtags #Binance or #BNB. The hashtag …

Cryptocurrency

Tweet thread by zachxbt

2022-04-20 [vendor] Rogue Society [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Rogue Society NFT project launched in September, with an ambitious roadmap that included a theme song, comic book series, 3D figurines, an augmented reality app, and an …

Cryptocurrency

Tweet thread by SlowMist

2022-04-20 [vendor] Terra Google ad phishing [loss] $4M [chain] terra
Vector: Seed phrase / wallet compromise

Scammers ran Google ads for popular search queries relating to the Terra ecosystem. When users searched for things like "Anchor protocol" or "Astroport", the first result was …

Cryptocurrency

Tweet thread by 0x_fxnction

2022-04-19 [vendor] 0x_fxnction wallet compromise [loss] $240,000 [chain] solana
Vector: Smart contract exploit / hack

NFT influencer 0x_fxnction reported that his wallet had been compromised, and 2349 SOL (~$240,000) had been stolen. The money had primarily been profit from the DeGods project, he …

Cryptocurrency

Tweet thread by zachxbt

2022-04-19 [vendor] Rich Bulls Club [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt researched the Rich Bulls Club, an NFT project that launched in December with NFTs priced at 0.3 ETH (~$1,350) a pop. The project included a clause where …

Cryptocurrency

Tweet by CertiKAlert

2022-04-18 [vendor] 2omb and Redemption [loss] $189,625 [chain] fantom
Vector: Flash loan attack on smart contract

Redemption provides the liquidity pools for 2omb, a Fantom-based algorithmic stablecoin project with big promises: "What if you could invest in a golden goose? Something you can …

Cryptocurrency

Tweet thread by Domenic Iacovone

2022-04-18 [vendor] MetaMask iCloud backup vulnerability [loss] $650,000 [chain] ethereum
Vector: Phishing attack

Some MetaMask users using iOS were shocked to discover that their MetaMask credentials were automatically being stored to iCloud today, after MetaMask acknowledged this was the …

Cryptocurrency

Tweet thread by CertiK Alert

2022-04-17 [vendor] Beanstalk Farms [loss] $182M [chain] ethereum
Vector: Flash loan attack on smart contract

All my magic beans gone. An attacker successfully used a flash loan attack to exploit a flaw in Beanstalk Farms' stablecoin protocol, which allowed them to make off with 24,830 ETH …

Cryptocurrency

Tweet thread by zachxbt

2022-04-16 [vendor] Moonbirds Sybil attack [chain] ethereum

The NFT project "Moonbirds" generated so much hype that they implemented a raffle system for the many people who hoped to get on the project's allowlist, hoping to make it more …

Cryptocurrency

Tweet by PeckShield

2022-04-15 [vendor] Rikkei Finance [loss] $1M [chain] bsc
Vector: Smart contract exploit / hack

Rikkei Finance, which describes itself as a metaverse defi project, was apparently exploited. 2,571 BNB, priced at around $1.07 million, was transferred out of the protocol and …

Cryptocurrency

Announcement tweet

2022-04-14 [vendor] Archieverse NFT announcement [chain] ethereum

Archie Comics announced they would be launching an NFT project called "Archieverse", which centers around their spooky "Madam Satan" character and invites people to "unlock the …

Cryptocurrency

Tweet thread by zachxbt

2022-04-14 [vendor] The Real Tarzann [loss] $700,000 [chain] ethereum
Vector: Exit scam / rug pull

Influencer, conservationist, and exotic animal whisperer "The Real Tarzann" (a.k.a. Mike Holston) announced in October 2021 his plans for an NFT project called "Tribes of Ogun". …

Cryptocurrency

Tweet thread by TheBreadMakerr

2022-04-14 [vendor] Unicorn Nodes [loss] $129,000 [chain] avalanche
Vector: Exit scam / rug pull

Unicorn Nodes claimed to be a "defi-as-a-service" project. It launched its $RNBW token on April 14, despite warnings from "TheBreadmaker", who rates various protocols. Only hours …

Cryptocurrency

Tweet by Tim Beiko

2022-04-13 [vendor] Ethereum delays proof-of-stake [chain] ethereum

For years now, Ethereum has been talking about a transition from its energy-intensive, expensive proof-of-work consensus model to a proof-of-stake consensus model, which sports a …

Cryptocurrency

Tweet thread by Tanner Woodworth

2022-04-13 [vendor] Fake SkyVerse project [loss] $153,050 [chain] ethereum
Vector: Smart contract exploit / hack

A scammer recreated the Twitter account for SkyVerse, a much-anticipated NFT land project due to launch in "mid-April". More than 250 NFT collectors eager to get in on a mint that …

Cryptocurrency

Tweet by PeckShieldAlert

2022-04-12 [vendor] Elephant Money [loss] $22M [chain] bsc
Vector: Flash loan attack on smart contract

A person was able to use a flash loan attack to drain the Elephant Money project, crashing the token price to 0 while cashing out 27,416 BNB ($11 million). Losses to the project …

Cryptocurrency

Tweet by Casper

2022-04-11 [vendor] Casper NFT theft [loss] $600,000 [chain] ethereum
Vector: Smart contract exploit / hack

NFT collector "Casper" discovered their wallet had been compromised, and an attacker had stolen around 114 NFTs worth around $600,000. The collector took to Twitter to urge people …

Cryptocurrency

Tweet by PeckShield

2022-04-11 [vendor] Creat Future [loss] $2M [chain] bsc
Vector: Smart contract exploit / hack

An attacker stole about $1.9 million after exploiting a bug in the smart contract for the Creat Future token. The contract's transfer function was defined as public, with no …

Cryptocurrency

Instagram video of $APE transaction

2022-04-09 [vendor] Bored & Hungry restaurant opens [chain] ethereum

A restaurateur opened "Bored & Hungry", a Bored Ape-themed restaurant in Long Beach, California that offers a simple menu of hamburgers or plant-based burgers (with or without …

Cryptocurrency

"NFTs Are Here to Ruin D&amp;D"

2022-04-08 [vendor] Gripnr announcement [chain] polygon

Because, really, what is even the point of playing Dungeons & Dragons if you're not buying a premade character from a limited set of options, playing premade adventures with …

Cryptocurrency

Tweet thread by CertiK Alert

2022-04-07 [vendor] Starstream [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

Starstream, a defi project built on the Andromeda layer 2 Ethereum protocol, had its treasury drained. Blockchain security company CertiK reported that the treasury appeared to …

Cryptocurrency

Tweet thread by Kevin Homiak

2022-04-07 [vendor] Tyler Gaye alleged misappropriation [loss] $400,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Attorney Kevin Homiak tweeted that his firm would be representing several individuals who contributed money to a developer, Tyler Gaye, who promised to be working on an NFT …

Cryptocurrency

Scam wallet

2022-04-06 [vendor] Fake Revoke.cash site [loss] $16,000 [chain] ethereum
Vector: Smart contract exploit / hack

It's not exactly straightforward to revoke wallet permissions once they've been granted, and so many users use a site called revoke.cash to remove permissions in the case of …

Cryptocurrency

Tweet by cr0ss.eth

2022-04-05 [vendor] VaynerSports gas fee issue [chain] ethereum

AJ Vaynerchuk, brother of prominent NFT personality Gary Vaynerchuk (aka Gary Vee), launched his VaynerSports NFT collection. The popularity of the project resulted in surging gas …

Cryptocurrency

Tweet thread by 0xQuit

2022-04-04 [vendor] s27 NFT theft [loss] $587,000 [chain] ethereum
Vector: Smart contract exploit / hack

A trader who owned a Bored Ape and two Mutant Ape NFTs apparently reached a deal to trade them for three different Bored Ape NFTs. Because OpenSea doesn't support swapping NFTs …

Cryptocurrency

"I fell victim to the Trezor phishing scam"

2022-04-03 [vendor] Trezor phishing attack [loss] $72,000 [chain] bitcoin
Vector: Seed phrase / wallet compromise

A Bitcoin holder using a Trezor hardware wallet fell victim to a phishing scam after attackers stole email lists from a third-party vendor use by Trezor. The user wrote on Reddit …

Cryptocurrency

Tweet by PeckShieldAlert

2022-04-02 [vendor] Inverse Finance [loss] $16M [chain] ethereum
Vector: Oracle price manipulation

An attacker targeting the defi project Inverse Finance was able to manipulate the price oracle of INV/ETH, artificially inflating the apparent price of INV and allowing the …

Cryptocurrency

Tweet by BoredApeYC

2022-04-01 [vendor] Multiple Discord compromises [chain] ethereum
Vector: Smart contract exploit / hack

Another day, another Discord compromise — or in this case, many Discord compromises. Bored Apes wrote on their Twitter account in the early hours of the morning, "STAY SAFE. Do not …

Cryptocurrency

Tweet by Dirty Bubble Media

2022-03-31 [vendor] Cosmic Cowgirls [loss] $1M [chain] ethereum

The former head moderator of the Cosmic Cowgirls NFT project Discord, Esh, wrote on Twitter that that the project team had fired all moderators and scrapped all of their roadmaps. …

Cryptocurrency

"Community Alert: Ronin Validators Compromised"

2022-03-29 [vendor] Axie Infinity bridge [loss] $619M [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

One of the most popular play-to-earn games, Axie Infinity, suffered an enormous hack to the Ronin network on which it runs. The project announced that a majority of Ronin validator …

Cryptocurrency

Tweet thread by zachxbt

2022-03-29 [vendor] Bored Bunny [loss] $21M [chain] ethereum
Vector: Exit scam / rug pull

Many had written off the Bored Bunny NFT project (and its subsequent spin-off NFT collections) as a rug pull. After releasing several new NFT collections that appeared to be little …

Cryptocurrency

Tweet thread by Phillip Lietz

2022-03-28 [vendor] Andrew Yang stiffs artist [chain] ethereum

In February, perennial political candidate Andrew Yang announced he had created "Lobby3", a DAO which he says will push for crypto-friendly regulation and "eradicate poverty". The …

Cryptocurrency

Tweet by Cameron Moulène

2022-03-28 [vendor] Cameron Moulène NFT theft [loss] $368,660 [chain] ethereum
Vector: Smart contract exploit / hack

NFT collector Cameron Moulène was excited to see a link promising a merch drop in the bio of an account with the same branding as Bored Ape Yacht Club, but with the handle …

Cryptocurrency

Web3 Is Going Great

2022-03-28 [vendor] MkLeo Twitter account [chain] ethereum
Vector: Smart contract exploit / hack

MkLeo, who is widely considered to be the best Smash Ultimate player in the world, had his 217,000-follower Twitter account hacked and repurposed for NFT shilling. The scammers …

Cryptocurrency

Tweet thread by manifold.xyz

2022-03-28 [vendor] Pak NFT transaction failures [chain] ethereum

Collectors were excited for a chance to obtain NFTs from the artist Pak's upcoming collection, "Ash Chapter II: Metamorphosis". Pak is an extremely popular digital artist, and his …

Cryptocurrency

"Revest Protocol Exploit Recovery Plan"

2022-03-27 [vendor] Revest Finance [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Revest protocol was targeted with an attack that stole $BLOCKS, $ECO, and $RENA tokens from their vault. The protocol wrote that the attacker used a "highly sophisticated …

Cryptocurrency

Tweet by 0xQuit

2022-03-27 [vendor] taylorRichie.eth NFT theft [loss] $73,585 [chain] ethereum
Vector: Smart contract exploit / hack

A trader known by taylorRichie.eth agreed to swap their Morie NFT for a Doodle, in a trade they'd coordinated with a user on Discord. Because OpenSea doesn't support trading one …

Cryptocurrency

Tweet by PeckShieldAlert

2022-03-24 [vendor] Pye [loss] $3M [chain] bsc
Vector: Flash loan attack on smart contract

The security firm PeckShield reported that the Pye ecosystem had been targeted with a flash loan attack, which drained around $2.6 million from the protocol. Pye is a group of defi …

Cryptocurrency

Ronin Network / Axie Infinity Lazarus Group Hack ($625M, Largest Crypto Theft)

2022-03-23 [vendor] Ronin Network (Ethereum sidechain bridge) [chain] ethereum
Vector: North Korea's Lazarus Group targeted Sky Mavis (Axie Infinity developer) employees with fake LinkedIn job offers; a senior engineer downloaded a malicious PDF 'job offer' that installed macOS spyware; Lazarus used this foothold to compromise 5 of the 9 Ronin validator private keys

On March 23, 2022, the Lazarus Group (North Korea, DPRK Bureau 121) stole 173,600 ETH and 25.5 million USDC ($625 million at the time) from the Ronin Network — the Ethereum …

Cryptocurrency

Tweet by Arthur_0x

2022-03-21 [vendor] Arthur_0x NFT theft [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Arthur_0x, a crypto investor and NFT whale, had two of their hot wallets compromised. The attacker stole ETH and transferred some big-ticket NFTs out of the wallets, including at …

Cryptocurrency

Tweet by Zachxbt

2022-03-21 [vendor] Bored Apes animation [loss] $900,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

An NFT collector fell for a scam website promising to "turn your BAYC animated". After connecting their wallet, the attacker transferred their three pricey Bored Ape NFTs to their …

Cryptocurrency

Winamp Twitter thread

2022-03-16 [vendor] Winamp announces NFT plans [chain] ethereum

A week after LimeWire emerged from cryostasis to announce it would become an NFT platform, Winamp decided to jump in as well. Winamp was a Windows media player that first launched …

Cryptocurrency

Tweet thread by Tiffany Hutchinson

2022-03-15 [vendor] NFTBOOKS token distribution chart [chain] bsc

A project called NFTBOOKS has cropped up, promising to "transform the world of book-readings" by creating an NFT economy of authors, book-lenders, readers, translators, and, of …

Cryptocurrency

Twitter thread by Louis Nel

2022-03-14 [vendor] Clipboard malware [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin wallet addresses look something like bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq, and so it's not always obvious at a glance if one string of random characters might have …

Cryptocurrency

Twitter thread by SerpentAU

2022-03-14 [vendor] Wizard Pass Discord [loss] $169,000 [chain] ethereum
Vector: Smart contract exploit / hack

Wizard Pass is an NFT trading community and package of various software tools that can be joined for a price: a collection of 3,000 NFTs gates access to the community. The NFTs had …

Cryptocurrency

Tweet by Rob Freund

2022-03-12 [vendor] Rare Pepes lawsuit [chain] ethereum, bitcoin
Vector: Regulatory / legal action

Matt Furie is the original creator of the Pepe the Frog cartoon that was later co-opted as an alt-right hate symbol, and which has also been popular among crypto enthusiasts and …

Cryptocurrency

"An Update on Our NFT..."

2022-03-11 [vendor] MeUndies' modified Bored Ape illustration [chain] ethereum

Believe me, I was as shocked as you were to discover that the MeUndies underwear brand has a "community". But that community apparently objected to the brand's purchase of a Bored …

Cryptocurrency

Tweet by dino_dealer

2022-03-10 [vendor] EtherRock typo [chain] ethereum

The owner of EtherRock #44 tried to list their NFT for sale for 444 ETH (almost $1.2 million), but erroneously listed it for 444 wei — the fractional unit of ETH typically used for …

Cryptocurrency

Tweet thread by Bored Ape Yacht Club

2022-03-10 [vendor] Yuga Labs requests KYC [chain] ethereum

Yuga Labs, the company behind the Bored Ape Yacht Club (BAYC) project, announced a new project in partnership with blockchain gaming group Animoca Brands. The signup required KYC — …

Cryptocurrency

Tweet thread by rifftrader

2022-03-09 [vendor] Crypto exchange glitch costs user [chain] bitcoin, litecoin

Something apparently went terribly wrong on the trading platform that Twitter user rifftrader was using (though they didn't say which) when 10 BTC (~$385,000) was erroneously …

Cryptocurrency

Tweet by Fantasm Finance

2022-03-09 [vendor] Fantasm Finance [loss] $3M [chain] fantom
Vector: Software bug / unintentional loss

An exploiter was able to use a bug in the Fantasm Mint contract to drain more than 1,000 ETH ($2,640,000) from Fantasm Finance. Fantasm urged their users to redeem their tokens …

Cryptocurrency

Tweet thread by BlockSecTeam

2022-03-09 [vendor] Pirate X Pirate [loss] $78,000 [chain] bsc
Vector: Smart contract exploit / hack

The Pirate X Pirate blockchain gaming platform was exploited, with an attacker selling of more than 9.6 million $PXP. They were able to dump the tokens into the market for a profit …

Cryptocurrency

"Exposing Jake Paul's Scams"

2022-03-07 [vendor] Jake Paul undisclosed promotion accusations [chain] ethereum

Jake Paul, who is already in hot water after being named in the class-action lawsuit against SafeMoon, has now been implicated by YouTube detective CoffeeZilla in $2.2 million …

Cryptocurrency

Tweet thread by Bacon Protocol

2022-03-05 [vendor] Bacon Protocol [loss] $1M [chain] ethereum
Vector: Reentrancy attack on smart contract

Bacon Protocol, a defi project seeking to provide NFT mortgage liens (yes, really) was hacked. A reentrancy bug in their smart contract enabled attackers to get more lending …

Cryptocurrency

Tweet by danvee.eth

2022-03-05 [vendor] BattleCatsArena [loss] $54,943 [chain] ethereum
Vector: Exit scam / rug pull

The NFT project BattleCatsArena appears to have rug pulled on March 5, about three weeks after its launch. The project had been announced late last year, with a post from its …

Cryptocurrency

Tweet by Frooxius

2022-03-04 [vendor] NeosVR abandons crypto [chain] ethereum

NeosVR, a virtual reality project originally released in 2018, introduced "Neos Credits" (NCR) in 2018 with the idea that it could enable in-game transactions. The crypto component …

Cryptocurrency

Nemus Earth whitepaper

2022-03-03 [vendor] Nemus Earth NFT [chain] ethereum

A project called Nemus Earth has emerged, offering to sell you an Ethereum NFT to become a "Guardian" of the Brazilian Amazon rainforest. The project has lofty plans to create a …

Cryptocurrency

Brian Rose

2022-03-02 [vendor] Brian Rose and David Icke [chain] ethereum

Conspiracy theorists Brian Rose and David Icke are together known for their April 7, 2020 interview where Icke attempted to draw unsubstantiated links between the rollout of 5G …

Cryptocurrency

Tweet by KeyboardMonkey3

2022-03-02 [vendor] Treasure NFT marketplace bug [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

The Treasure NFT marketplace on Arbitrum (a layer 2 network built atop Ethereum) apparently experienced a bug that allowed someone to "buy" NFTs in transactions where they sent 0 …

Cryptocurrency

Thread by zachxbt

2022-03-01 [vendor] Malicious Fiverr developer [loss] $580,325 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A developer offering his services on the freelancer marketplace Fiverr was hired by 32 different NFT projects, for which he wrote and deployed the smart contracts. The first …

Cryptocurrency

Tweet by Memofrogwell

2022-02-28 [vendor] Elexir Finance [loss] $1M [chain] avalanche
Vector: Exit scam / rug pull

Elexir Finance promised a platform where users could build passive income via "yield bearing NFTs". They drew in more than $1.3 million in investments since the project's launch on …

Cryptocurrency

GenomesDAO Docs

2022-02-28 [vendor] GenomesDAO launch [chain] ethereum

GenomesDAO has created a platform which they promise will allow people who wish to sell their genetic data to have more control over it. They write that genetic data is "data that …

Cryptocurrency

Armijo v. Ozone Networks, Inc. d/b/a Opensea

2022-02-28 [vendor] Robert Armijo NFT theft [loss] $300,000 [chain] ethereum
Vector: Phishing attack

Robert Armijo is the former owner of three valuable NFTs — one Bored Ape and two Mutant Apes — which he bought for a total of around $300,000 between November 2021 and January …

Cryptocurrency

Thread by HOWLERZNFT

2022-02-26 [vendor] Howlerz fake contract [loss] $675,000 [chain] ethereum
Vector: Smart contract exploit / hack

A heavily-hyped NFT project called "Howlerz" released its project via "secret mint" with no allowlist, and it went very, very poorly. Would-be buyers who were excitedly waiting for …

Cryptocurrency

Tweet thread by MetaMehdee

2022-02-26 [vendor] Starcatchers insider trading [loss] $140,000 [chain] ethereum

The Starcatchers NFT project sold NFTs which did not immediately show the image associated with them, but would instead be revealed at a later date. An observant collector noticed …

Cryptocurrency

Tweet by molly0xfff

2022-02-25 [vendor] Associated Press mishandles controversy [chain] polygon

After the fiasco the previous day in which some group of people at the Associated Press apparently decided turning an image of human suffering into an NFT was a brilliant idea, …

Cryptocurrency

Tweet thread by zachxbt

2022-02-25 [vendor] Pixelmon [loss] $70M [chain] ethereum
Vector: Smart contract exploit / hack

The Pixelmon project promised an ambitious roadmap including a Pokémon-like game where the pixelized Pokémon could be caught and traded, a land project, and rewards to buyers of …

Cryptocurrency

Archived tweet by the Associated Press

2022-02-24 [vendor] Associated Press releases NFT of migrants [chain] polygon

The Associated Press announced they would be dropping a new NFT on the platform they launched in January, which notably doesn't allow users to sell their NFTs off-platform or …

Cryptocurrency

Project contract

2022-02-23 [vendor] De'Aaron Fox [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

Sacramento Kings player De'Aaron Fox announced his "SwipaTheFox" NFT project in mid-December, and the "high utility NFT collection" went live on January 15. The project roadmap …

Cryptocurrency

Space Crypto (SPE) to USD Chart

2022-02-23 [vendor] Space Crypto tokenomics flop [chain] bsc

Space Crypto, a play-to-earn game that launched on February 15, announced on February 23 that users wouldn't be able to withdraw all their reward tokens, as expected. Without …

Cryptocurrency

Tweet by schniggie

2022-02-22 [vendor] Ocean Protocol vulnerability [chain] ethereum
Vector: Software bug / unintentional loss

Ocean Protocol is a web3 project promising to help people "publish, discover, and consume data in a secure, privacy-preserving fashion". Recently, they've been promoting the ALGA …

Cryptocurrency

Tweet by Jon_HQ

2022-02-19 [vendor] OpenSea phishing attacks [loss] $3M [chain] ethereum
Vector: Phishing attack

Panic erupted on February 19 as a few users saw their wallets emptied of valuable NFTs without knowing why, and many others feared the same could happen to them. Early explanations …

Cryptocurrency

Tweet thread by dcsilver

2022-02-18 [vendor] Bitconnect lawsuit continues [chain] bitcoin
Vector: Ponzi / pyramid scheme

An appeals court found that a legal claim could continue to be pursued against some of the major voices that promoted Bitconnect online. Bitconnect was a Ponzi scheme that …

Cryptocurrency

Tweet by NFTCryptoChicks

2022-02-18 [vendor] Crypto.Chicks art theft controversy [chain] ethereum

Polly, a member of the popular Crypto.Chicks NFT team, apologized for "drawing inspiration from" artists and "inadvertently cop[ying]" their work, after it is discovered that she …

Cryptocurrency

<i>McKimmy v. OpenSea</i>

2022-02-18 [vendor] Timothy McKimmy NFT theft [loss] $300,000 [chain] ethereum
Vector: Regulatory / legal action

Businessman Timothy McKimmy is the former owner of Bored Ape #3475, an NFT he purchased in December for 55 ETH (then about $232,000). In a lawsuit against OpenSea, McKimmy alleged …

Cryptocurrency

Tweet from MetaDeckz

2022-02-16 [vendor] MetaDecks unauthorized NFTs [chain] ethereum
Vector: Regulatory / legal action

An artist creating and selling trading cards of various streamers without asking their permission claims he was "just trying to do something cool for the community". He originally …

Cryptocurrency

Tweet by katienotopoulos

2022-02-16 [vendor] Robness harasses journalist [chain] ethereum

"Robness", an NFT artist who is somewhat known for selling a photograph of a trashcan for more than $250,000, apparently took issue with BuzzFeed News journalist Katie Notopoulos, …

Cryptocurrency

Tweet thread by CertiKCommunity

2022-02-15 [vendor] BNB42 [loss] $3M [chain] bsc

BNB42 was a "100% decentralized investment platform" that promised investors a 20% daily return on their investments. Unsurprisingly, that turned out to be too good to be true when …

Cryptocurrency

Tweet thready by zachxbt

2022-02-15 [vendor] helloimmorgan fails to disclose paid promotions [chain] ethereum

More shadiness emerges around the Jacked Ape Club as it's discovered that the popular NFT influencer account Morgan (aka @helloimmorgan and morgan.eth) failed to disclose being …

Cryptocurrency

The Kiss NFT website

2022-02-14 [vendor] Belvedere Museum auctions scraps of painting [chain] ethereum

In a Valentine's Day-themed stunt, the otherwise reputable Belvedere Museum in Austria decided to sell Gustav Klimt's The Kiss as NFTs. But making one NFT was apparently not enough …

Cryptocurrency

Tweet by finance_build

2022-02-14 [vendor] BuildFinance governance attack [loss] $470,000 [chain] ethereum
Vector: Smart contract exploit / hack

A person managed to submit a proposal to the DAO that governs BuildFinance, a "decentralized venture builder", that would allow them to take over the project contract. The attacker …

Cryptocurrency

Tweet by Hantao

2022-02-13 [vendor] Jacked Ape Club team melts down [chain] ethereum
Vector: Exit scam / rug pull

The team behind Jacked Ape Club, another NFT project featuring computer-generated apes, briefly erupted in chaos, shaking the confidence of many in the project. Several days prior, …

Cryptocurrency

Tweet thread by thomasg.eth

2022-02-12 [vendor] Air taxi DAO founder narrowly escapes [chain] ethereum
Vector: Smart contract exploit / hack

thomasg.eth is the founder of Arrow, a DAO that is working to create "open-source VTOL [vertical take-off and landing] aircraft and air taxi protocol". In a long Twitter thread, he …

Cryptocurrency

Tweet by JackedApeClub

2022-02-11 [vendor] Jacked Ape Club deception [chain] ethereum

The Jacked Ape Club launched their public sale on February 10, offering 8,888 NFTs of illustrated apes much like the Bored Apes, but muscular. The following day they tweeted that, …

Cryptocurrency

Tweet by Coffeezilla

2022-02-11 [vendor] Lana Rhoades [loss] $2M [chain] ethereum

Lana Rhoades put her celebrity status behind the "CryptoSis" NFT project, which launched on January 22 and raised about $1.8 million. The project featured a detailed roadmap, …

Cryptocurrency

Tweet thread by mtgDAO

2022-02-10 [vendor] mtgDAO legal notice [chain] ethereum
Vector: Regulatory / legal action

The fledgling mtgDAO promised to deliver a "crypto NFT card economy" based around the Magic: The Gathering card game published by Wizards of the Coast. Needless to say, WotC sent …

Cryptocurrency

Tweet by PeckShieldAlert

2022-02-09 [vendor] Dego Finance [loss] $10M [chain] bsc
Vector: Smart contract exploit / hack

Hackers drained more than $10 million from the project Dego Finance. This also plunged the value of the project's $DEGO token by about 78%. Dego claims that the hackers compromised …

Cryptocurrency

"Ira Financial and Gemini"

2022-02-08 [vendor] IRA Financial [loss] $36M [chain] bitcoin
Vector: Smart contract exploit / hack

IRA Financial, a platform for managing retirement investments, boasts of being "the first self-directed IRA company to allow their clients to invest in cryptocurrencies, such as …

Cryptocurrency

"Superfluid - REKT"

2022-02-08 [vendor] Superfluid [loss] $9M [chain] polygon
Vector: Software bug / unintentional loss

A vulnerability in the Superfluid crypto streaming protocol allowed an attacker to drain $8.7 million, affecting projects including Mai Finance, Stacker Ventures, Stake DAO, and …

Cryptocurrency

Tweet from earnhubBSC

2022-02-07 [vendor] EarnHub [loss] $284,000 [chain] bsc
Vector: Exit scam / rug pull

EarnHub, a DeFi platform with its own rap song, suddenly saw 660 wBNB (around $284,000) disappear from their project. EarnHub wrote on Twitter that "A hacker was able to exploit …

Cryptocurrency

Tweet by Zilverk

2022-02-06 [vendor] Ratz Club [loss] $140,000 [chain] solana
Vector: Smart contract exploit / hack

Mexican VTuber Zilverk created an NFT project called Ratz Club, built on the Solana blockchain. On February 6, the project announced that a developer they had contracted drained …

Cryptocurrency

Tweet by damedoteth

2022-02-05 [vendor] ENS leadership controversy [chain] ethereum

Brantly Millegan is the director of operations for the Ethereum Name Service, which is basically a blockchain version of DNS, and is also how some people get their wallet to show …

Cryptocurrency

Tweet by wormholecrypto

2022-02-02 [vendor] Wormhole bridge [loss] $180M [chain] solana
Vector: Smart contract exploit / hack

The Wormhole Network is a blockchain bridge between Solana and various other blockchains, allowing assets to be traded across the different and not otherwise interoperable chains. …

Cryptocurrency

Tweet by Choke Chain

2022-02-01 [vendor] HitPiece unauthorized marketplace [chain] ethereum

The industrial band Choke Chain tweeted, "Yo a bunch of industrial scene acts (including me) have NFTs for sale on the site hitpiece.com I did not put it online and I assume you …

Cryptocurrency

WWF NFT website

2022-01-31 [vendor] WWF NFT announcement [chain] polygon, ethereum

The UK branch of the World Wildlife Fund (WWF) announced their upcoming "Tokens For Nature" NFT project, which is meant to support endangered species. The WWF was quick to tout …

Cryptocurrency

Twitter thread by Omar Farooq

2022-01-30 [vendor] Colors NFTs [chain] ethereum

As the NFT gold rush continues and people attempt to slap price tags on everything in sight, Omar Farooq detailed his plans to sell colors on the blockchain. He said he will then …

Cryptocurrency

Twitter feed of Qubit Finance

2022-01-30 [vendor] Qubit bounty negotiation [chain] bsc
Vector: Smart contract exploit / hack

After a bug in their code allowed an attacker to make off with $80 million, Qubit immediately began trying to contact the exploiter and convince them to return the money. First …

Cryptocurrency

Tweet thread by smlundberg

2022-01-28 [vendor] Khan Academy wash trading controversy [chain] ethereum

Khan Academy, an otherwise excellent non-profit offering online educational tools, announced they would be participating in an NFT charity auction on January 19. The auction …

Cryptocurrency

Tweet thread by NFT Ethics

2022-01-28 [vendor] Lazy Lion Ape Club [loss] $125,000 [chain] ethereum

Lazy Lion Ape Club, an NFT project in somewhat resembling the mega-popular Bored Apes, listed their NFTs on OpenSea on January 26. In addition to the NFTs, the project promised to …

Cryptocurrency

Tweet by cr0ssETH

2022-01-28 [vendor] OpenSea listing bug continues [chain] ethereum
Vector: Software bug / unintentional loss

OpenSea began reimbursing users who lost money earlier this month through what some have described as a bug with the platform, but which others argue is just a misunderstanding on …

Cryptocurrency

Tweet by Qubit Finance

2022-01-27 [vendor] Qubit Finance [loss] $80M [chain] bsc
Vector: Software bug / unintentional loss

An attacker exploited a bug in Qubit Finance, a decentralized lending platform. The bug allowed them to call the "deposit" function without actually depositing any funds. This …

Cryptocurrency

Tweet by PeckShieldAlert

2022-01-26 [vendor] WeGro [loss] $378,000 [chain] bsc
Vector: Exit scam / rug pull

WeGro, a project to allow "everyone to safely participate in the hemp and cannabis industry through the supply chain", saw its token tank in price as the deployer drained 1,000 BNB …

Cryptocurrency

Tweet by NFT Ethics

2022-01-25 [vendor] Blockverse [loss] $1M [chain] ethereum
Vector: Exit scam / rug pull

Blockverse, a project that promised to build a play-to-earn game on top of Minecraft, rug pulled two days after launch. The initial NFT collection sold out in only eight minutes, …

Cryptocurrency

Tweet by Nayib Bukele

2022-01-24 [vendor] Nayib Bukele insults [chain] bitcoin

El Salvadoran president Nayib Bukele gives us Americans a painful reminder of having a president who truly cannot be trusted with the reins of a country, much less a Twitter …

Cryptocurrency

Tweet thread by NFTethics

2022-01-23 [vendor] Cryptopunks insider trading [chain] ethereum

The enormously popular Cryptopunks project, created by the LarvaLabs group, is actually on its second version. A bug in the original smart contract allowed users to retrieve their …

Cryptocurrency

Tweet by GeorgeBTurner

2022-01-22 [vendor] NFT Conservation Fund announcement [chain] ethereum

Conservationist and wildlife photographer George Benjamin tweeted about his new project, "The NFT Conservation Fund". "Over the last decade I've seen first-hand the devastation …

Cryptocurrency

Tweet from PeckShieldAlert

2022-01-19 [vendor] Kingfund Finance [loss] $141,000 [chain] bsc
Vector: Exit scam / rug pull

Kingfund Finance suddenly drained more than 300 WBNB (about $141,000) from their project. This happened a few days after users began to report being blocked by the project's …

Cryptocurrency

PeckShieldAlert tweet

2022-01-18 [vendor] BNB Heroes [loss] $190,000 [chain] bsc
Vector: Exit scam / rug pull

The BNB Heroes play-to-earn game apparently rug pulled after a period of inactivity from the development team. The developer drained almost $200,000 from the token pool, plummeting …

Cryptocurrency

Tweet from MastercardNews

2022-01-18 [vendor] Mastercard partners with Coinbase [chain] ethereum

Apparently the real issue with crypto grifts all along has been that it's just too dang hard to put your money into them. Mastercard has shown up to fix that, announcing a new …

Cryptocurrency

PeckShield tweet

2022-01-16 [vendor] CryptoBurgers [loss] $770,000 [chain] bsc
Vector: Flash loan attack on smart contract

The value of the $BURG token associated with the CryptoBurgers game suddenly plummeted after being hacked shortly after launching earlier that day. The game allowed users to earn …

Cryptocurrency

Tweet by Pranksy

2022-01-16 [vendor] NotASecretNFT project [chain] ethereum
Vector: Exit scam / rug pull

Enthusiasts rushed to buy NFTs from a project called NotASecretNFT after seeing NFT mega-whale Pranksy buy in, even though the OpenSea description was simply, "1000 secrets, …

Cryptocurrency

Tweet by codenamehugs

2022-01-12 [vendor] Global Game Jam sponsorship controversy [chain] ethereum

Global Game Jam, an annual event where people collaborate to make video games, proudly plugged The Sandbox as their "primary headline sponsor" on Twitter. The Sandbox is a platform …

Cryptocurrency

Tweet thread by SolRarity_

2022-01-11 [vendor] Big Daddy Ape Club [loss] $1M [chain] solana
Vector: Exit scam / rug pull

The creators of "Big Daddy Ape Club" rug pulled shortly after mint, deleting their social media and website and making off with around $1.2 million. The project's creators were …

Cryptocurrency

Tweet thread by questauthority

2022-01-10 [vendor] Associated Press NFT marketplace announcement [chain] polygon

I can safely describe most NFT marketplaces as bizarre, but the AP is really trying to top the bunch. The marketplace will provide a place for trading the NFTs they plan to create …

Cryptocurrency

Tweet by CoinersTakingLs

2022-01-09 [vendor] Doodled Dragons [loss] $30,000 [chain] solana

A SolSea-verified NFT project on the Solana blockchain, Doodled Dragons, touted that they would distribute all profits "straight to charities protecting animals on the brink of …

Cryptocurrency

Tweet thread by zachxbt

2022-01-09 [vendor] Rich Dwarves Tribe [loss] $3M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Rich Dwarves Tribe was an NFT project announced in December 2021, which minted in January 2022. The project had been heavily promoted by musicians including NeYo, Jason Derulo, …

Cryptocurrency

<i>SEC v. Crowd Machine, Inc.</i>

2022-01-06 [vendor] CrowdMachine SEC lawsuit [chain] ethereum
Vector: Regulatory / legal action

The SEC alleged that Craig Sproule, founder of companies CrowdMachine and Metavine, ran a fraudulent and unregistered ICO when he launched "Crowd Machine Compute Tokens" (CMCTs). …

Cryptocurrency

Tweet thread by 9x9x9

2022-01-05 [vendor] Pudgy Penguin attempted [chain] ethereum

Pudgy Penguins, a popular NFT project that somehow warranted a full-length New York Times article by Kevin Roose, apparently is trying something pretty shady. This was revealed by …

Cryptocurrency

Tweet thread by ElectionDayMad1

2022-01-04 [vendor] Franklin exposed for undisclosed shilling [chain] ethereum
Vector: Exit scam / rug pull

NFT collector and influencer Franklin posted a tweet thread about how he had hyped a project that later rugpulled. He was paid about 18 ETH (about $63,000) to promote the …

Cryptocurrency

Tweet by PeckShieldAlert

2022-01-03 [vendor] ArbixFinance [loss] $10M [chain] bsc
Vector: Exit scam / rug pull

Yield farming platform ArbixFinance was drained of at least $10 million, with some reporting amounts up to $32 million. Some optimistic users hoped it was a glitch, but the fact …

Cryptocurrency

"CryptoBike showing signs of scam"

2022-01-01 [vendor] CryptoBike [loss] $1M [chain] bsc

A Vietnamese play-to-earn game called CryptoBike became popular shortly after its December 25 launch, soaring to around $41.6 million in daily trading volume. However, on January …

Cryptocurrency

Tweet by NFTtheft

2021-12-29 [vendor] Fake Baby Ape Social Club NFTs [loss] $52,000 [chain] polygon
Vector: Smart contract exploit / hack

A clone of Solana's popular "Baby Ape Social Club" project popped up on OpenSea, using the Polygon blockchain. The project enjoyed 14.3 ETH in trading volume (about $52,000) before …

Cryptocurrency

Tweet from WakaFlocka

2021-12-28 [vendor] Waka Flocka NFT theft [loss] $19,000 [chain] ethereum
Vector: Smart contract exploit / hack

Waka Flocka Flame posted to Twitter: "@opensea One of me wallets was hacked wtf man". In a video, he showed NFTs in his OpenSea wallet, saying "This is fake, this is fake, this is …

Cryptocurrency

"MetaDAO Makes Off With $3.2M in Rug Pull"

2021-12-27 [vendor] MetaDAO [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

A project that promised to be "the DAO of DAOs" managed to accumulate and then make off with 800 ETH, which was worth around $3.2 million at the time of the scam. The project …

Cryptocurrency

Tweet by jilliancyork

2021-12-26 [vendor] Cipher Punks NFTs created without permission [chain] ethereum

The "Cipher Punks" NFT project tried to sell NFTs with illustrations of various cypherpunks, or at least the ones that were listed on Wikipedia. The project said that it intended …

Cryptocurrency

"OpenSea freezes $2.2M of stolen Bored Apes"

2021-12-25 [vendor] bergpay.eth NFT theft [loss] $41,100 [chain] ethereum
Vector: Smart contract exploit / hack

bergpay.eth checked his MetaMask wallet on the day after Christmas only to discover that all his NFTs had been stolen, including five from the popular "Jungle Freaks" collection …

Cryptocurrency

Tweet by Fr0zenBuffal0

2021-12-23 [vendor] Fr0zenBuffal0 NFT theft [loss] $290,000 [chain] ethereum
Vector: Smart contract exploit / hack

An NFT collector lost his Bored Ape NFT to a scammer impersonating the well-known NFT collector Jeffrey Huang, aka "Machi Big Brother". The real Huang did eventually buy the NFT …

Cryptocurrency

Tweet thread by Kris Nóva

2021-12-22 [vendor] Open source NFTs made without permission [chain] ethereum

Some prominent open source advocates and contributors were surprised to find that their likenesses were turned into NFTs by an artist who photographed them in 2018. Kris Nóva …

Cryptocurrency

Tweet by commenstar

2021-12-21 [vendor] Monkey Kingdom Discord [loss] $1M [chain] solana
Vector: Phishing attack

An NFT trader hoping to get in on the "Monkey Kingdom" NFT collection was duped by a scam link in the project's official Discord channel, and sent 650 SOL (about $116,000) to a …

Cryptocurrency

Tweet thread by _elcomisionado_

2021-12-18 [vendor] Chivo Wallet bug [loss] $96,224 [chain] bitcoin

A Twitter thread showed dozens of people reporting amounts from hundreds to tens of thousands of dollars disappearing from their Chivo Wallets, the Bitcoin wallet backed by El …

Cryptocurrency

Tweet from NFTtheft

2021-12-17 [vendor] OpenSea ignores stolen artwork reports [chain] ethereum

Artists going through the greuling process of reporting individual NFTs created without permission from their work reported tickets being automatically rejected. Artists were also …

Cryptocurrency

Tweet by Molly White

2021-12-16 [vendor] Bored Ape owner messages [chain] ethereum

The apparent owner of Bored Ape #5262, of which this site header is a derivative work, contacted me on Twitter to say "I believe you are using my ape on your website without my …

Cryptocurrency

Tweet from NFT_Shady

2021-12-15 [vendor] Doodles typo [chain] ethereum

A misplaced decimal point caused an NFT trader to sell their "beloved" Doodle NFT for 0.37 ETH (about $1,500) instead of their intended 3.7 ETH (about $15,000). The trader tried …

Cryptocurrency

Tweet thread by zachxbt

2021-12-14 [vendor] Laurent Correia [loss] $960,000 [chain] ethereum

Laurent Correia, a French influencer and the creator of "Billionaire Tips" sports betting app, launched an NFT project called "Billionaire Dogs" in December. Promising perks …

Cryptocurrency

Tweet thread by Loish

2021-12-13 [vendor] Loish art thefts [chain] ethereum

Digital artist Loish discovered more than one hundred instances where people had created NFTs from her art without her permission, and had to spend hours reporting each individual …

Cryptocurrency

Tweet by @BadWritingTakes

2021-12-02 [vendor] CODEX launches [chain] flow

A platform called "CODEX" announced that they intend to "upgrade the digital book market industry to Web3". This, apparently, involves artificially limiting the number of copies of …

Cryptocurrency

Cryptoland pitch video

2021-11-06 [vendor] Cryptoland video [chain] ethereum

Signs unfortunately point to this being an actual, real project rather than satire, but the video purporting to advertise it dunks on cryptobros harder than most satirists have …

Cryptocurrency

Tweet from Becerra announcing the theft

2021-10-31 [vendor] Calvin Becerra NFT theft [loss] $1M [chain] ethereum
Vector: Social engineering attack

NFT collector Calvin Becerra fell for some social engineering on Discord: "Guys posing as buyers in Discord were helping me troubleshoot a problem we thought was happening... They …

Cryptocurrency

"Inside the Realms of Ruin"

2021-10-21 [vendor] Realms of Ruin fails to launch [chain] solana

Six popular young-adult fiction writers attempted to launch an NFT project where they created a base universe, and participants would contribute their own stories (which they would …

Cryptocurrency

Tweet by PeckShieldAlert

2021-08-12 [vendor] DAO Maker [loss] $7M [chain] ethereum
Vector: Smart contract exploit / hack

The DAO Maker project (not to be confused with the well-known MakerDAO) is a launchpad that claims to be "building the future of venture capital". Its website boasts that users who …

Cryptocurrency

"Saddle Finance"

2021-01-19 [vendor] Saddle Finance [loss] $275,000 [chain] bitcoin
Vector: Smart contract exploit / hack

The Saddle Finance defi project, a fork of the Curve Finance project, launched on January 20. It promised it would "eliminate slippage".The project was exploited only hours later, …