exploitsTriple-A's $11.8M Hot Wallet Drain: Seven Chains, and 31 Hours Nobody Closed the TapTriple-A's treasury wallets were swept across seven chains starting July 24, 2026. The theft took hours. Deposits kept arriving and kept being swept for 31.Dmitry Serdyuk·Jul 30, 20263m
exploitsB2 Network $3.86M Staking Drain: The Upgrade Key Did All the WorkB2 Network lost 8.59M B2 tokens, about $3.86M, when someone used the staking contract's upgrade authority. That privilege had sat on the same wallet since 2025.Dmitry Serdyuk·Jul 27, 20263m
exploitsAFX Trade $24.15M Bridge Exploit: Compromised Validator Keys Signed a Valid DrainAFX Trade's bridge lost $24.15M in USDC on Arbitrum. No contract bug: five operator-held validator keys signed a real quorum, and the bridge did exactly as told.Dmitry Serdyuk·Jul 24, 20263m
exploitsThe Fake Recruiter Repo That Hid Its Malware in a Tailwind ConfigA fake Web3 recruiter sends a GitHub repo to try before the interview. The malware hides as a 4 MB Tailwind plugin, fires on the dev command, and hunts wallets, SSH keys, and seed phrases.Dmitry Serdyuk·Jul 23, 20264m
exploitsThe TRAE Extension Backdoor That Ran Its C2 on an Ethereum ContractA fake Solidity plugin, juannegro.solidity, backdoors Windows, macOS, and Linux dev machines and reads its C2 address from an Ethereum contract the attacker updates on-chain.Dmitry Serdyuk·Jul 22, 20263m
exploitsAllbridge Core $1.65M Exploit: A 2023 Flash Loan Fix That Missed SolanaAllbridge Core lost $1.65M on Solana to the same flash loan trick it said it fixed in 2023. The one-pool promise held on BNB Chain and not on Solana.Dmitry Serdyuk·Jul 21, 20263m
exploitsDefiTuna Exploit: $580K Drained From Solana Lending PoolDefiTuna's USDC lending pool lost $580K to a July 2026 exploit on Solana, leaving it in bad debt. Inside the attack, the Sec3 audit gap, and the lessons.Aron Turner·Jul 20, 20263m
exploitsInjective npm SDK Backdoored to Steal Wallet Keys: Anatomy of a Near MissA compromised maintainer account backdoored 18 @injectivelabs npm packages on July 8, 2026, harvesting wallet seed phrases at key-derivation time. It failed by minutes. Here is how it nearly worked.Dmitry Serdyuk·Jul 14, 20263m
exploitsSummer.fi's $6M Lazy Summer Exploit: When a Donation Broke the Vault MathAn attacker donated an asset into a Summer.fi Lazy Summer vault, inflated its totalAssets() share price, and redeemed a flash loan for a $6M profit. No key was stolen. The accounting was the hole.Dmitry Serdyuk·Jul 8, 20264m
exploitsBonkDAO's $20M Governance Takeover: When Buying the Vote Beats Hacking the CodeAn attacker spent about $4M buying BONK, took a voting majority on BonkDAO's Realms governance, and passed one proposal that moved $20M out of the treasury. No contract was hacked. The rules were.Dmitry Serdyuk·Jul 7, 20264m
exploitsAztec Connect's $2.19M Exploit: A ZK-Rollup Settlement Bug in a Contract No One Could PatchA deprecated Aztec Connect contract was drained of $2.19M when its L1 settlement loop and its ZK proof disagreed on how many slots were real. Its keys were renounced, so no one could pause it.Dmitry Serdyuk·Jul 5, 20264m
exploitsJaredFromSubway MEV Bot Drained for $7.5M in a Counter-MEV HoneypotJaredFromSubway, Ethereum's most prolific MEV sandwich bot, was drained of $7.5M when an attacker turned its own logic into a counter-MEV honeypot. How the dangling-approval attack worked.Aron Turner·Jun 23, 20263m
exploitsHumanity Protocol's $36M Key Compromise: A Runbook for Wallets That Touch ContractsOne compromised laptop held seven keys and cleared two multisigs, draining $36M+ from Humanity Protocol. A runbook for segregating, monitoring, and revoking project wallets that touch contracts.Dmitry Serdyuk·Jun 10, 20263m
exploitsThe $3.2M SquidRouterModule Exploit: How a Public String Drained 86 Safe WalletsA third-party module named SquidRouterModule drained $3.2M from 86 Gnosis Safe wallets on Ethereum and Base. Full attack chain, the auth flaw, and the lesson.Aron Turner·May 26, 20263m
exploitsGitHub's 3,800-Repo Breach: How a Poisoned VS Code Extension Burned the World's Biggest Code HostOne poisoned VS Code extension on one GitHub employee's laptop cost the company ~3,800 internal repositories. Here is the attack chain, the Mini Shai-Hulud worm internals, and the rotate-everything checklist that follows.Aron Turner·May 21, 20264m
exploitsKelp DAO's $292M Hack and Aave's $6B Fallout: One Config Parameter Broke DeFiA 1-of-1 LayerZero DVN let attackers drain 116,500 rsETH ($292M) from Kelp DAO, loop it through Aave V3 for $266M in ETH, and wipe $6B in Aave TVL in 24 hours. No Solidity bug. One config parameter broke DeFi.Aron Turner·Apr 20, 20264m
exploitsDrift Protocol's $270M Exploit: How Solana's Durable Nonces Became a Social Engineering WeaponAn attacker drained $270M from Drift Protocol by abusing Solana's durable nonce feature to pre-sign malicious multisig transactions weeks before execution.Aron Turner·Apr 3, 20263m
exploitsAave's $27M Liquidation Incident: How a Stale Oracle Parameter Wiped Out 34 UsersA desynchronized oracle parameter caused Aave to undervalue wstETH by 2.85%, triggering $27M in wrongful liquidations across 34 users. Full technical breakdown.Aron Turner·Mar 12, 20263m