DeFi & exchange archive

The biggest DeFi & crypto hacks of the last 10 years

A chronological record of major DeFi exploits, bridge hacks, oracle attacks, and centralized-exchange compromises from 2016 through 2026 — with loss amounts, attack vector, and outcome.

37
Incidents tracked
~$8.0B
Total stolen
$1.5B (Bybit)
Biggest hack
2016–2026
Years covered

All hacks, latest first

MediumPrivate Key Compromise

AFX Trade

Chain:Arbitrum
Date:July 23, 2026
Loss:~$24.2M

A fake recruiter from a non-existent firm got an AFX Trade developer to clone a malicious repository on July 9; a hidden payload gave the attacker the developer's machine and, with it, the protocol's bridge keys.

Outcome
AFX Trade publicly offered the attacker a cut of the funds to return the rest and recovered most of the loss.
MediumOracle Manipulation

Ostium

Chain:Arbitrum
Date:July 16, 2026
Loss:~$18–24M

The largest oracle attack of 2026: stale and spoofed price timestamps were fed to Ostium's perpetuals engine, letting the attacker open and settle positions at prices that never existed.

Outcome
Arbitrum's base layer was unaffected. Ostium paused markets and published a post-mortem.
MediumSmart Contract Bug

Cork Protocol

Chain:Ethereum
Date:May 25, 2026
Loss:~$12M

A flaw in Cork's depeg-swap accounting allowed an attacker to extract wstETH from the protocol's pools.

Outcome
Protocol paused. Partial white-hat recovery.
HighBridge Exploit

Kelp DAO (rsETH)

Chain:Ethereum + LayerZero (~20 chains)
Date:April 18, 2026
Loss:~$292M

A compromise of Kelp DAO's bridging and messaging infrastructure let attackers mint and drain rsETH liquidity across roughly twenty LayerZero-connected chains — the largest crypto theft of 2026 so far.

Outcome
Attributed to North Korea-linked actors. Funds laundered through mixers; largely unrecovered.
HighPrivate Key Compromise

Drift Protocol

Chain:Solana
Date:April 1, 2026
Loss:~$285M

Months of patient social engineering gave attackers control of privileged Drift infrastructure, which they used to drain protocol funds and bridge them to Ethereum.

Outcome
Attributed to DPRK. On-chain trackers followed $44.4M into Tornado Cash before the wallet was emptied.
MediumPrivate Key Compromise

Step Finance

Chain:Solana
Date:January 31, 2026
Loss:~$27M

Attackers obtained privileged keys and drained treasury and user funds from Step Finance contracts.

Outcome
Investigation ongoing; funds not recovered.
HighSmart Contract Bug

Balancer V2

Chain:Ethereum + multi-chain
Date:November 3, 2025
Loss:~$128M

A rounding-error bug in Balancer's composable stable pool math let crafted swaps extract value from the gap between internal accounting and real pool balances, across several chains at once.

Outcome
Vulnerable pools disabled; tens of millions recovered by white hats and distributed back to LPs.
MediumPrivate Key Compromise

BtcTurk

Chain:Multi-chain
Date:August 14, 2025
Loss:~$48M

Turkey's oldest exchange reported unusual hot-wallet outflows consistent with compromised private keys; cold-storage reserves were untouched.

Outcome
Deposits and withdrawals halted, wallets rotated. Binance froze part of the stolen funds.
MediumPrivate Key Compromise

CoinDCX

Chain:Multi-chain
Date:July 19, 2025
Loss:~$44.2M

A server-side breach gave an attacker access to CoinDCX's internal systems and its operational hot wallets.

Outcome
Exchange covered the loss from treasury; customer funds unaffected.
MediumSmart Contract Bug

GMX V1

Chain:Arbitrum
Date:July 9, 2025
Loss:~$42M

A reentrancy-style flaw in a contract connected to the GLP liquidity pool let the attacker repeatedly withdraw more than their share.

Outcome
The exploiter returned the bulk of the funds in exchange for a bounty. GMX V1 was wound down.
MediumPrivate Key Compromise

Nobitex

Chain:Multi-chain
Date:June 18, 2025
Loss:~$80–90M

Iran's largest exchange had its hot wallets drained during the Israel–Iran conflict. The politically motivated attackers burned much of the loot to vanity addresses rather than cashing out.

Outcome
Service gradually restored; wallet infrastructure rotated. Funds not recoverable.
HighSmart Contract Bug

Cetus

Chain:Sui
Date:May 22, 2025
Loss:~$223M

An overflow check flaw in Cetus's concentrated-liquidity math let an attacker mint near-worthless positions and drain roughly $223M of liquidity from the largest DEX on Sui.

Outcome
Sui validators froze ~$162M of the stolen funds; most was later returned to users.
MediumSmart Contract Bug

Infini

Chain:Ethereum
Date:February 24, 2025
Loss:~$49.5M

An overlooked developer privilege left in Infini's contracts was used to drain protocol-controlled stablecoin reserves.

Outcome
Operations paused; access controls rebuilt. Partial clawback discussions with white hats.
CriticalPrivate Key Compromise

Bybit

Chain:Ethereum
Date:February 21, 2025
Loss:~$1.5B

North Korea's Lazarus Group compromised a Safe{Wallet} signer's machine and tricked Bybit's cold-wallet signers into approving a malicious upgrade, draining ~401K ETH in the largest crypto theft ever recorded.

Outcome
Bybit covered user losses from its treasury. FBI attributed to TraderTraitor / Lazarus.
MediumPrivate Key Compromise

Phemex

Chain:Multi-chain
Date:January 23, 2025
Loss:~$85M

Attackers drained BTC, ETH and stablecoins from Phemex hot wallets in rapid succession, in an incident security firms linked to North Korean groups.

Outcome
Exchange covered user balances and rebuilt key management. Stolen funds routed through mixers.
HighPrivate Key Compromise

WazirX

Chain:Ethereum
Date:July 18, 2024
Loss:~$235M

Attackers (linked to Lazarus Group) compromised WazirX's Liminal multi-sig and drained the exchange's hot wallet.

Outcome
Exchange paused withdrawals; restructuring scheme proposed to repay users.
HighPrivate Key Compromise

DMM Bitcoin

Chain:Bitcoin
Date:May 31, 2024
Loss:~$305M

Japanese exchange DMM Bitcoin lost 4,502.9 BTC in an unauthorized withdrawal later attributed to North Korean actors.

Outcome
DMM borrowed funds to make customers whole, then wound down the exchange in late 2024.
HighPrivate Key Compromise

Poloniex

Chain:Multi-chain
Date:November 22, 2023
Loss:~$125M

Justin Sun-owned Poloniex saw its hot wallets drained across Ethereum, Tron and Bitcoin networks after a private-key compromise.

Outcome
Sun committed to full reimbursement; partial on-chain recovery via bounty offer.
HighBridge Exploit

HTX / Heco Bridge

Chain:Heco / Ethereum
Date:November 9, 2023
Loss:~$113M

HTX (formerly Huobi) and the Heco cross-chain bridge were drained in coordinated exploits affecting hot wallets and bridge contracts.

Outcome
HTX pledged user reimbursement. Bridge paused.
HighPrivate Key Compromise

Mixin Network

Chain:Multi-chain
Date:September 22, 2023
Loss:~$200M

A cloud-service provider used by Mixin was breached, exposing keys to the network's main deposit/withdrawal wallet.

Outcome
Mixin offered partial repayment via tokenized debt; service paused.
MediumSmart Contract Bug

Curve Finance

Chain:Ethereum
Date:July 30, 2023
Loss:~$73.5M

A Vyper compiler bug broke the reentrancy locks in several Curve stablepools (alETH, msETH, pETH, CRV/ETH), enabling reentrancy drains.

Outcome
White-hats recovered ~73% of funds. Vyper patched; Curve compensated remaining LPs.
HighSmart Contract Bug

Euler Finance

Chain:Ethereum
Date:March 13, 2023
Loss:~$197M

A missing health check in the donateToReserves function allowed the attacker to push accounts into a self-liquidatable state and drain lending pools.

Outcome
After negotiations the attacker returned essentially all funds — among the largest white-hat-style returns ever.
HighOracle Manipulation

BonqDAO

Chain:Polygon
Date:February 2, 2023
Loss:~$120M

The attacker manipulated the Tellor oracle price feed for AllianceBlock's ALBT token to mint BEUR stablecoin against worthless collateral.

Outcome
Most stolen tokens proved illiquid; protocol effectively wound down.
HighOracle Manipulation

Mango Markets

Chain:Solana
Date:October 11, 2022
Loss:~$117M

Avraham Eisenberg pumped the MNGO perp price on thin spot liquidity, used the inflated collateral to borrow out the treasury.

Outcome
Eisenberg arrested by the FBI in December 2022 and convicted of fraud and market manipulation in 2024.
CriticalBridge Exploit

BNB Chain Token Hub Bridge

Chain:BNB Chain
Date:October 6, 2022
Loss:~$569M

Attacker forged a fake Merkle proof in the Token Hub bridge and minted 2M BNB. Validators halted the chain mid-attack.

Outcome
BNB Chain stopped block production; ~$430M frozen. Net stolen ~$100–140M.
HighBridge Exploit

Nomad Bridge

Chain:Multi-chain
Date:August 2, 2022
Loss:~$190M

A misconfigured initialization let any address spoof valid messages. Once one wallet started draining, hundreds copy-pasted the exploit calldata — the first 'free-for-all' bridge hack.

Outcome
Nomad recovered ~20% from white-hats; bridge effectively defunct.
HighBridge Exploit

Harmony Horizon Bridge

Chain:Harmony / Ethereum
Date:June 24, 2022
Loss:~$100M

Lazarus Group compromised two of five multi-sig signers (held with insufficient separation) and drained the bridge.

Outcome
Attributed to North Korea by the FBI. Funds laundered via Tornado Cash.
HighGovernance Attack

Beanstalk Farms

Chain:Ethereum
Date:April 17, 2022
Loss:~$182M

Attacker took a flash loan to obtain a supermajority of governance stalk and instantly executed a malicious proposal that sent the treasury to themselves.

Outcome
Protocol redeployed months later via community-funded restart.
CriticalBridge Exploit

Ronin Bridge (Axie Infinity)

Chain:Ronin / Ethereum
Date:March 23, 2022
Loss:~$624M

Lazarus Group socially engineered a Sky Mavis engineer via a fake LinkedIn job offer, compromising 5 of 9 bridge validator keys and draining 173,600 ETH + 25.5M USDC.

Outcome
Sky Mavis and Binance reimbursed users; OFAC sanctioned the laundering addresses.
HighBridge Exploit

Wormhole Bridge

Chain:Solana / Ethereum
Date:February 2, 2022
Loss:~$326M

Attacker forged signatures via a flawed signature-verification routine and minted 120K wETH on Solana without backing.

Outcome
Jump Crypto refilled the bridge from its own funds within 24 hours.
HighPrivate Key Compromise

BitMart

Chain:Multi-chain
Date:December 5, 2021
Loss:~$196M

Hot-wallet private keys for BitMart's Ethereum and BNB Chain wallets were stolen and drained.

Outcome
BitMart pledged to use its own funds to reimburse affected users.
CriticalBridge Exploit

Poly Network

Chain:Multi-chain
Date:August 10, 2021
Loss:~$611M

Attacker exploited a privileged cross-chain function (EthCrossChainManager) to mint and withdraw assets across Ethereum, BSC and Polygon.

Outcome
Attacker ("Mr White Hat") returned virtually all funds within two weeks.
HighFlash Loan

PancakeBunny

Chain:BNB Chain
Date:May 19, 2021
Loss:~$200M

Flash-loan attack manipulated the BUNNY/BNB pool, minting ~7M BUNNY and crashing the token from $146 to near zero.

Outcome
Token never recovered; compensation plan via vBUNNY released later.
MediumSmart Contract Bug

Uranium Finance

Chain:BNB Chain
Date:April 28, 2021
Loss:~$50M

A migration to v2.1 contained an off-by-one math error in the swap fee logic, letting the attacker drain pool reserves in a single swap.

Outcome
Protocol shut down. Funds laundered via Tornado Cash.
MediumFlash Loan

bZx

Chain:Ethereum
Date:February 4, 2020
Loss:~$954K (combined)

Two back-to-back attacks pioneered the 'DeFi flash loan' playbook by manipulating oracle prices using uncollateralized loans from dYdX.

Outcome
First widely cited proof that flash loans break naive on-chain oracle designs. Catalyst for TWAP/Chainlink adoption.
CriticalPrivate Key Compromise

Coincheck

Chain:NEM
Date:April 19, 2018
Loss:~$534M

Coincheck's NEM hot wallet was drained of 523M XEM after attackers planted malware via spear-phishing on employee machines.

Outcome
Coincheck reimbursed users from its own funds; later acquired by Monex Group. Catalyzed FSA regulation in Japan.
MediumSmart Contract Bug

The DAO

Chain:Ethereum
Date:June 17, 2016
Loss:~$60M (at the time)

A reentrancy bug in the split-DAO function let the attacker recursively drain 3.6M ETH from the largest crowdfunded smart contract.

Outcome
Ethereum hard-forked to reverse the theft, creating Ethereum Classic. Reshaped smart-contract security forever.

What 10 years of hacks tell us

  • Bridges and centralized custodians dominate the losses. Ronin, Poly, Wormhole, Nomad, BNB Chain, Bybit, Coincheck — the largest single events have all been custody or cross-chain trust failures, not pure smart-contract bugs.
  • North Korea (Lazarus / TraderTraitor) is the single biggest threat actor. Ronin, Harmony, DMM Bitcoin, WazirX and Bybit alone account for over $2.5B attributed to DPRK-linked groups.
  • Self-custody with a hardware wallet sidesteps almost every entry on this list. Exchange and bridge hacks only affect funds you've handed to those operators.
  • DeFi has matured but new vectors keep appearing. From reentrancy (The DAO) to flash loans (bZx) to compiler bugs (Curve/Vyper) to signer phishing (Bybit) — the attack surface evolves faster than audits cover.

Move funds off exchanges

Our hardware wallet comparison ranks devices by Secure Element design, air-gap, open-source status and supply-chain practices.

See the full comparison →

Loss figures use values reported at the time of each incident from Chainalysis, Rekt.news, Elliptic, TRM Labs, official post-mortems and major-outlet reporting. This page tracks publicly disclosed incidents and is not exhaustive.

VaultRank

VaultRank is reader-supported. Some outbound links are referral links — they fund the site at no cost to you. © 2026 vaultrank.xyz.