DeFi & exchange archive

The biggest DeFi & crypto hacks of the last 10 years

A chronological record of major DeFi exploits, bridge hacks, oracle attacks, and centralized-exchange compromises from 2016 through 2026 — with loss amounts, attack vector, and outcome.

23
Incidents tracked
~$6.6B
Total stolen
$1.5B (Bybit)
Biggest hack
2016–2026
Years covered

All hacks, latest first

CriticalPrivate Key Compromise

Bybit

Chain:Ethereum
Date:February 21, 2025
Loss:~$1.5B

North Korea's Lazarus Group compromised a Safe{Wallet} signer's machine and tricked Bybit's cold-wallet signers into approving a malicious upgrade, draining ~401K ETH in the largest crypto theft ever recorded.

Outcome
Bybit covered user losses from its treasury. FBI attributed to TraderTraitor / Lazarus.
HighPrivate Key Compromise

WazirX

Chain:Ethereum
Date:July 18, 2024
Loss:~$235M

Attackers (linked to Lazarus Group) compromised WazirX's Liminal multi-sig and drained the exchange's hot wallet.

Outcome
Exchange paused withdrawals; restructuring scheme proposed to repay users.
HighPrivate Key Compromise

DMM Bitcoin

Chain:Bitcoin
Date:May 31, 2024
Loss:~$305M

Japanese exchange DMM Bitcoin lost 4,502.9 BTC in an unauthorized withdrawal later attributed to North Korean actors.

Outcome
DMM borrowed funds to make customers whole, then wound down the exchange in late 2024.
HighPrivate Key Compromise

Poloniex

Chain:Multi-chain
Date:November 22, 2023
Loss:~$125M

Justin Sun-owned Poloniex saw its hot wallets drained across Ethereum, Tron and Bitcoin networks after a private-key compromise.

Outcome
Sun committed to full reimbursement; partial on-chain recovery via bounty offer.
HighBridge Exploit

HTX / Heco Bridge

Chain:Heco / Ethereum
Date:November 9, 2023
Loss:~$113M

HTX (formerly Huobi) and the Heco cross-chain bridge were drained in coordinated exploits affecting hot wallets and bridge contracts.

Outcome
HTX pledged user reimbursement. Bridge paused.
HighPrivate Key Compromise

Mixin Network

Chain:Multi-chain
Date:September 22, 2023
Loss:~$200M

A cloud-service provider used by Mixin was breached, exposing keys to the network's main deposit/withdrawal wallet.

Outcome
Mixin offered partial repayment via tokenized debt; service paused.
MediumSmart Contract Bug

Curve Finance

Chain:Ethereum
Date:July 30, 2023
Loss:~$73.5M

A Vyper compiler bug broke the reentrancy locks in several Curve stablepools (alETH, msETH, pETH, CRV/ETH), enabling reentrancy drains.

Outcome
White-hats recovered ~73% of funds. Vyper patched; Curve compensated remaining LPs.
HighSmart Contract Bug

Euler Finance

Chain:Ethereum
Date:March 13, 2023
Loss:~$197M

A missing health check in the donateToReserves function allowed the attacker to push accounts into a self-liquidatable state and drain lending pools.

Outcome
After negotiations the attacker returned essentially all funds — among the largest white-hat-style returns ever.
HighOracle Manipulation

BonqDAO

Chain:Polygon
Date:February 2, 2023
Loss:~$120M

The attacker manipulated the Tellor oracle price feed for AllianceBlock's ALBT token to mint BEUR stablecoin against worthless collateral.

Outcome
Most stolen tokens proved illiquid; protocol effectively wound down.
HighOracle Manipulation

Mango Markets

Chain:Solana
Date:October 11, 2022
Loss:~$117M

Avraham Eisenberg pumped the MNGO perp price on thin spot liquidity, used the inflated collateral to borrow out the treasury.

Outcome
Eisenberg arrested by the FBI in December 2022 and convicted of fraud and market manipulation in 2024.
CriticalBridge Exploit

BNB Chain Token Hub Bridge

Chain:BNB Chain
Date:October 6, 2022
Loss:~$569M

Attacker forged a fake Merkle proof in the Token Hub bridge and minted 2M BNB. Validators halted the chain mid-attack.

Outcome
BNB Chain stopped block production; ~$430M frozen. Net stolen ~$100–140M.
HighBridge Exploit

Nomad Bridge

Chain:Multi-chain
Date:August 2, 2022
Loss:~$190M

A misconfigured initialization let any address spoof valid messages. Once one wallet started draining, hundreds copy-pasted the exploit calldata — the first 'free-for-all' bridge hack.

Outcome
Nomad recovered ~20% from white-hats; bridge effectively defunct.
HighBridge Exploit

Harmony Horizon Bridge

Chain:Harmony / Ethereum
Date:June 24, 2022
Loss:~$100M

Lazarus Group compromised two of five multi-sig signers (held with insufficient separation) and drained the bridge.

Outcome
Attributed to North Korea by the FBI. Funds laundered via Tornado Cash.
HighGovernance Attack

Beanstalk Farms

Chain:Ethereum
Date:April 17, 2022
Loss:~$182M

Attacker took a flash loan to obtain a supermajority of governance stalk and instantly executed a malicious proposal that sent the treasury to themselves.

Outcome
Protocol redeployed months later via community-funded restart.
CriticalBridge Exploit

Ronin Bridge (Axie Infinity)

Chain:Ronin / Ethereum
Date:March 23, 2022
Loss:~$624M

Lazarus Group socially engineered a Sky Mavis engineer via a fake LinkedIn job offer, compromising 5 of 9 bridge validator keys and draining 173,600 ETH + 25.5M USDC.

Outcome
Sky Mavis and Binance reimbursed users; OFAC sanctioned the laundering addresses.
HighBridge Exploit

Wormhole Bridge

Chain:Solana / Ethereum
Date:February 2, 2022
Loss:~$326M

Attacker forged signatures via a flawed signature-verification routine and minted 120K wETH on Solana without backing.

Outcome
Jump Crypto refilled the bridge from its own funds within 24 hours.
HighPrivate Key Compromise

BitMart

Chain:Multi-chain
Date:December 5, 2021
Loss:~$196M

Hot-wallet private keys for BitMart's Ethereum and BNB Chain wallets were stolen and drained.

Outcome
BitMart pledged to use its own funds to reimburse affected users.
CriticalBridge Exploit

Poly Network

Chain:Multi-chain
Date:August 10, 2021
Loss:~$611M

Attacker exploited a privileged cross-chain function (EthCrossChainManager) to mint and withdraw assets across Ethereum, BSC and Polygon.

Outcome
Attacker ("Mr White Hat") returned virtually all funds within two weeks.
HighFlash Loan

PancakeBunny

Chain:BNB Chain
Date:May 19, 2021
Loss:~$200M

Flash-loan attack manipulated the BUNNY/BNB pool, minting ~7M BUNNY and crashing the token from $146 to near zero.

Outcome
Token never recovered; compensation plan via vBUNNY released later.
MediumSmart Contract Bug

Uranium Finance

Chain:BNB Chain
Date:April 28, 2021
Loss:~$50M

A migration to v2.1 contained an off-by-one math error in the swap fee logic, letting the attacker drain pool reserves in a single swap.

Outcome
Protocol shut down. Funds laundered via Tornado Cash.
MediumFlash Loan

bZx

Chain:Ethereum
Date:February 4, 2020
Loss:~$954K (combined)

Two back-to-back attacks pioneered the 'DeFi flash loan' playbook by manipulating oracle prices using uncollateralized loans from dYdX.

Outcome
First widely cited proof that flash loans break naive on-chain oracle designs. Catalyst for TWAP/Chainlink adoption.
CriticalPrivate Key Compromise

Coincheck

Chain:NEM
Date:April 19, 2018
Loss:~$534M

Coincheck's NEM hot wallet was drained of 523M XEM after attackers planted malware via spear-phishing on employee machines.

Outcome
Coincheck reimbursed users from its own funds; later acquired by Monex Group. Catalyzed FSA regulation in Japan.
MediumSmart Contract Bug

The DAO

Chain:Ethereum
Date:June 17, 2016
Loss:~$60M (at the time)

A reentrancy bug in the split-DAO function let the attacker recursively drain 3.6M ETH from the largest crowdfunded smart contract.

Outcome
Ethereum hard-forked to reverse the theft, creating Ethereum Classic. Reshaped smart-contract security forever.

What 10 years of hacks tell us

  • Bridges and centralized custodians dominate the losses. Ronin, Poly, Wormhole, Nomad, BNB Chain, Bybit, Coincheck — the largest single events have all been custody or cross-chain trust failures, not pure smart-contract bugs.
  • North Korea (Lazarus / TraderTraitor) is the single biggest threat actor. Ronin, Harmony, DMM Bitcoin, WazirX and Bybit alone account for over $2.5B attributed to DPRK-linked groups.
  • Self-custody with a hardware wallet sidesteps almost every entry on this list. Exchange and bridge hacks only affect funds you've handed to those operators.
  • DeFi has matured but new vectors keep appearing. From reentrancy (The DAO) to flash loans (bZx) to compiler bugs (Curve/Vyper) to signer phishing (Bybit) — the attack surface evolves faster than audits cover.

Move funds off exchanges

Our hardware wallet comparison ranks devices by Secure Element design, air-gap, open-source status and supply-chain practices.

See the full comparison →

Loss figures use values reported at the time of each incident from Chainalysis, Rekt.news, Elliptic, TRM Labs, official post-mortems and major-outlet reporting. This page tracks publicly disclosed incidents and is not exhaustive.