Estimated amount: $0
<$10KLive fundsKITE Foundation Token Attack — Detected and Contained
Aug 5, 20264 viewsEthereumDetected & contained attackContained
Discover active investigations, estimated exposure, and whether funds are still moving — then open a full incident page.
Estimated amount: $0
<$10KLive fundsAug 5, 20264 viewsEthereumDetected & contained attackContained
Estimated amount: $14.3K
<$100KLive fundsAug 5, 20264 viewsBaseGovernance attack (optimistic oracle)Resolved
Estimated amount: $501.7K
<$1MLive fundsAug 5, 20262 viewsBasePhishing / wallet compromiseClosed
Estimated amount: $0
<$10KLive fundsAug 5, 20260 viewsChain-agnostic (Web3 developer toolingsupply chain)Supply chain attack — malicious IDE extension (credential/seed harvesting, remote payload execution)Contained
Estimated amount: $111M
$10M+Live fundsAug 6, 20264 viewsBitcoinFirmware vulnerability / weak entropyActive
Estimated amount: $0
<$10KLive fundsAug 6, 20265 viewsBitcoinLightning NetworkCritical vulnerability — active exploitationActive
Estimated amount: $0
<$10KLive fundsAug 7, 20265 viewsOraichain L1Cross-chain exploit — Unauthorized mint via ICS-20 EVM precompileRecovering
Estimated amount: $30.0K
<$100KLive fundsAug 7, 20261 viewsArbitrumSmart contract exploit — Signature replayContained
Estimated amount: $136K
<$1MLive fundsAug 8, 20263 viewsEthereum L1Smart contract exploit — Arithmetic split-invariance violationContained
Estimated amount: $7.9M
<$10MLive fundsAug 8, 20262 viewsEthereumTRONHot wallet drain — multi-chain access compromiseResolved
Estimated amount: $200K
<$1MLive fundsAug 8, 20261 viewsXRP LedgerCoreumtxBridge exploit — relayer deposit verification logic flawPaused
Estimated amount: $5M
<$10MLive fundsAug 9, 20263 viewsBitcoinEthereumCoinbaseSocial engineering — Support impersonation phone fraud networkActive
Estimated amount: $0
<$10KLive fundsAug 10, 20262 viewsRavencoin (RVN) — Bitcoin codebase forkKAWPOW PoWProtocol exploit — KAWPOW PoW consensus input validation flaw (chain rollback)Active
Estimated amount: $3.2M
<$10MLive fundsAug 10, 20261 viewsHarmony L1 (Shard 0Shard 1)Protocol exploit — Unauthorized ONE token mint via cross-shard receipt replay + quorum bypassRecovering
Estimated amount: $100.0K
<$1MLive fundsAug 10, 20261 viewsEthereum L1Social engineering — Address poisoning (82-day lookalike preparation)Active
Estimated amount: $25.6M
$10M+Live fundsAug 11, 20262 viewsEthereum L1Private key compromise — systematic DeFi position unwindingActive
Estimated amount: $1.9M
<$10MLive fundsAug 11, 20262 viewsEthereumPhishing campaign — Tornado Cash-themed fake frontend (entry vector unconfirmed: expired-domain takeover alleged by coActive
Estimated amount: $0
<$10KLive fundsAug 12, 20267 viewsOff-chainSupply chain attack — third-party data breach (Metabase SQL injection zero-day)Contained
Estimated amount: $118.7K
<$1MLive fundsAug 14, 20260 viewsBNB Smart ChainFlash-loan attack — stale AMM spot-price oracle manipulation (time-of-check/time-of-use)Closed
Estimated amount: $0
<$10KLive fundsAug 15, 20261 viewsNot applicable (Web2 e-commerceorder-tracking system; SafePal is a hardwaresoftware wallet provider)Third-party data breach — authorization flaw in an order-tracking plugin (no wallet or fund compromise)Resolved
Estimated amount: $0
<$10KLive fundsAug 15, 20260 viewsNot applicable (CEXregulated crypto brokerIsrael; Web2 third-party analytics system)Third-party/supply chain data breach — unauthorized access to an external analytics/support system (no custody or tradContained
Estimated amount: $1.4M
<$10MLive fundsAug 17, 20261 viewsMAYAChainBitcoinArbitrumProtocol logic flaw — chained six-bug accounting exploit (uncapped slash subsidy)Paused
Estimated amount: $3.3M
<$10MLive fundsAug 18, 20260 viewsBounceBit Chainreissued as BEP-20 on BNB ChainProtocol-level authorization flaw — Evmos native module trusted-input bypass (no key compromise)Closed
Estimated amount: $0
<$10KLive fundsAug 19, 20262 viewsChain-agnostic (Rustcrates.io ecosystemheavily used in Solana and broader Web3 tooling)Supply chain attack — malicious dependency injection (typosquat build-script malware, 86-107 minute exposure window)Contained
Estimated amount: $0
<$10KLive fundsAug 20, 20263 viewsMANTRA ChainUpstream dependency vulnerability — Cosmos-EVM stack authorization bypass (bank-layer debit via staking precompile), nResolved
| Chain | Title | Type | Status | Severity | Amount | Victims | Progress | Occurred | Live | Views | Watch |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Detected & contained attack | Contained | <$10K | $0 | >10 | 100% | Aug 5, 2026 | 4 | Sign in | |||
| Governance attack (optimistic oracle) | Resolved | <$100K | $14.3K | >10 | 100% | Aug 5, 2026 | 4 | Sign in | |||
| Phishing / wallet compromise | Closed | <$1M | $501.7K | 1 | 90% | Aug 5, 2026 | 2 | Sign in | |||
Solidity Pro VS Code Extension — Web3 Developer Credential StealerChain-agnostic (Web3 developer tooling / supply chain) | Supply chain attack — malicious IDE extension (credential/seed harvesting, remote payload execution) | Contained | <$10K | $0 | >10 | 100% | Aug 5, 2026 | 0 | Sign in | ||
| Firmware vulnerability / weak entropy | Active | $10M+ | $111M | 7300 | 75% | Aug 6, 2026 | 4 | Sign in | |||
BTCPay Server LND Macaroon Credential Exposure — Active ExploitationBitcoin / Lightning Network | Critical vulnerability — active exploitation | Active | <$10K | $0 | 2 | 40% | Aug 6, 2026 | 5 | Sign in | ||
| Cross-chain exploit — Unauthorized mint via ICS-20 EVM precompile | Recovering | <$10K | $0 | >10 | 50% | Aug 7, 2026 | 5 | Sign in | |||
| Smart contract exploit — Signature replay | Contained | <$100K | $30.0K | >10 | 50% | Aug 7, 2026 | 1 | Sign in | |||
| Smart contract exploit — Arithmetic split-invariance violation | Contained | <$1M | $136K | >10 | 75% | Aug 8, 2026 | 3 | Sign in | |||
Coinsbuy — Coordinated Multi-Chain Hot Wallet DrainEthereum / TRON | Hot wallet drain — multi-chain access compromise | Resolved | <$10M | $7.9M | >10 | 75% | Aug 8, 2026 | 2 | Sign in | ||
Coreum/tx XRPL Bridge — Fake Deposit Relayer Logic ExploitXRP Ledger / Coreum / tx | Bridge exploit — relayer deposit verification logic flaw | Paused | <$1M | $200K | >10 | 50% | Aug 8, 2026 | 1 | Sign in | ||
Tiffany Milanovich — Crypto Support Impersonation Fraud NetworkBitcoin / Ethereum / Coinbase | Social engineering — Support impersonation phone fraud network | Active | <$10M | $5M | >10 | 75% | Aug 9, 2026 | 3 | Sign in | ||
Ravencoin — KAWPOW PoW Consensus Flaw & Chain RollbackRavencoin (RVN) — Bitcoin codebase fork / KAWPOW PoW | Protocol exploit — KAWPOW PoW consensus input validation flaw (chain rollback) | Active | <$10K | $0 | >10 | 50% | Aug 10, 2026 | 2 | Sign in | ||
Harmony Protocol — Unauthorized 4B ONE Mint via Cross-Shard Receipt ReplayHarmony L1 (Shard 0 / Shard 1) | Protocol exploit — Unauthorized ONE token mint via cross-shard receipt replay + quorum bypass | Recovering | <$10M | $3.2M | >10 | 75% | Aug 10, 2026 | 1 | Sign in | ||
| Social engineering — Address poisoning (82-day lookalike preparation) | Active | <$1M | $100.0K | 1 | 75% | Aug 10, 2026 | 1 | Sign in | |||
| Private key compromise — systematic DeFi position unwinding | Active | $10M+ | $25.6M | 1 | 50% | Aug 11, 2026 | 2 | Sign in | |||
| Phishing campaign — Tornado Cash-themed fake frontend (entry vector unconfirmed: expired-domain takeover alleged by co | Active | <$10M | $1.9M | 1 | 75% | Aug 11, 2026 | 2 | Sign in | |||
| Supply chain attack — third-party data breach (Metabase SQL injection zero-day) | Contained | <$10K | $0 | 13689 | 75% | Aug 12, 2026 | 7 | Sign in | |||
FoxMarket Flash-Loan Stale Spot-Price Bond Mint ExploitBNB Smart Chain | Flash-loan attack — stale AMM spot-price oracle manipulation (time-of-check/time-of-use) | Closed | <$1M | $118.7K | >10 | 75% | Aug 14, 2026 | 0 | Sign in | ||
SafePal Order-Tracking Plugin Data Breach — 39,798 Customers ExposedNot applicable (Web2 e-commerce / order-tracking system; SafePal is a hardware / software wallet provider) | Third-party data breach — authorization flaw in an order-tracking plugin (no wallet or fund compromise) | Resolved | <$10K | $0 | 39798 | 100% | Aug 15, 2026 | 1 | Sign in | ||
Bits of Gold Third-Party Analytics Breach — ~200,000 Customers ExposedNot applicable (CEX / regulated crypto broker / Israel; Web2 third-party analytics system) | Third-party/supply chain data breach — unauthorized access to an external analytics/support system (no custody or trad | Contained | <$10K | $0 | 200000 | 75% | Aug 15, 2026 | 0 | Sign in | ||
Maya Protocol Six-Bug MAYAChain Exploit — Uncapped Slash Subsidy DrainMAYAChain / Bitcoin / Arbitrum | Protocol logic flaw — chained six-bug accounting exploit (uncapped slash subsidy) | Paused | <$10M | $1.4M | >10 | 75% | Aug 17, 2026 | 1 | Sign in | ||
BounceBit Chain Evmos Authorization Flaw — Permanent L1 SunsetBounceBit Chain / reissued as BEP-20 on BNB Chain | Protocol-level authorization flaw — Evmos native module trusted-input bypass (no key compromise) | Closed | <$10M | $3.3M | 9 | 75% | Aug 18, 2026 | 0 | Sign in | ||
Rust Crates Supply Chain Attack — arrayref, internment, append-only-vecChain-agnostic (Rust / crates.io ecosystem / heavily used in Solana and broader Web3 tooling) | Supply chain attack — malicious dependency injection (typosquat build-script malware, 86-107 minute exposure window) | Contained | <$10K | $0 | >10 | 100% | Aug 19, 2026 | 2 | Sign in | ||
| Upstream dependency vulnerability — Cosmos-EVM stack authorization bypass (bank-layer debit via staking precompile), n | Resolved | <$10K | $0 | >10 | 100% | Aug 20, 2026 | 3 | Sign in |
Page 8 of 8, showing 25 of 200 incidents
← Back to home