| | Upstream dependency vulnerability — Cosmos-EVM stack authorization bypass (bank-layer debit via staking precompile), n | Resolved | | $0 | >10 | | Aug 20, 2026 | | 3 | Sign in |
| | Supply chain attack — malicious dependency injection (typosquat build-script malware, 86-107 minute exposure window) | Contained | | $0 | >10 | | Aug 19, 2026 | | 2 | Sign in |
| | Protocol-level authorization flaw — Evmos native module trusted-input bypass (no key compromise) | Closed | | $3.3M | 9 | | Aug 18, 2026 | | 0 | Sign in |
| | Protocol logic flaw — chained six-bug accounting exploit (uncapped slash subsidy) | Paused | | $1.4M | >10 | | Aug 17, 2026 | | 1 | Sign in |
| | Third-party data breach — authorization flaw in an order-tracking plugin (no wallet or fund compromise) | Resolved | | $0 | 39798 | | Aug 15, 2026 | | 1 | Sign in |
| | Third-party/supply chain data breach — unauthorized access to an external analytics/support system (no custody or trad | Contained | | $0 | 200000 | | Aug 15, 2026 | | 0 | Sign in |
| | Flash-loan attack — stale AMM spot-price oracle manipulation (time-of-check/time-of-use) | Closed | | $118.7K | >10 | | Aug 14, 2026 | | 0 | Sign in |
| | Supply chain attack — third-party data breach (Metabase SQL injection zero-day) | Contained | | $0 | 13689 | | Aug 12, 2026 | | 7 | Sign in |
| | Private key compromise — systematic DeFi position unwinding | Active | | $25.6M | 1 | | Aug 11, 2026 | | 2 | Sign in |
| | Phishing campaign — Tornado Cash-themed fake frontend (entry vector unconfirmed: expired-domain takeover alleged by co | Active | | $1.9M | 1 | | Aug 11, 2026 | | 2 | Sign in |
| | Protocol exploit — KAWPOW PoW consensus input validation flaw (chain rollback) | Active | | $0 | >10 | | Aug 10, 2026 | | 2 | Sign in |
| | Protocol exploit — Unauthorized ONE token mint via cross-shard receipt replay + quorum bypass | Recovering | | $3.2M | >10 | | Aug 10, 2026 | | 1 | Sign in |
| | Social engineering — Address poisoning (82-day lookalike preparation) | Active | | $100.0K | 1 | | Aug 10, 2026 | | 1 | Sign in |
| | Social engineering — Support impersonation phone fraud network | Active | | $5M | >10 | | Aug 9, 2026 | | 3 | Sign in |
| | Smart contract exploit — Arithmetic split-invariance violation | Contained | | $136K | >10 | | Aug 8, 2026 | | 3 | Sign in |
| | Hot wallet drain — multi-chain access compromise | Resolved | | $7.9M | >10 | | Aug 8, 2026 | | 2 | Sign in |
| | Bridge exploit — relayer deposit verification logic flaw | Paused | | $200K | >10 | | Aug 8, 2026 | | 1 | Sign in |
| | Cross-chain exploit — Unauthorized mint via ICS-20 EVM precompile | Recovering | | $0 | >10 | | Aug 7, 2026 | | 5 | Sign in |
| | Smart contract exploit — Signature replay | Contained | | $30.0K | >10 | | Aug 7, 2026 | | 1 | Sign in |
| | Firmware vulnerability / weak entropy | Active | | $111M | 7300 | | Aug 6, 2026 | | 4 | Sign in |
| | Critical vulnerability — active exploitation | Active | | $0 | 2 | | Aug 6, 2026 | | 5 | Sign in |
| | Phishing campaign | Active | | $1.6M | 1 | | Aug 5, 2026 | | 3 | Sign in |
| | Detected & contained attack | Contained | | $0 | >10 | | Aug 5, 2026 | | 4 | Sign in |
| | Governance attack (optimistic oracle) | Resolved | | $14.3K | >10 | | Aug 5, 2026 | | 4 | Sign in |
| | Phishing / wallet compromise | Closed | | $501.7K | 1 | | Aug 5, 2026 | | 2 | Sign in |