OceanAltOceanAlt

Public incident archive · updated weekly

1,265 public crypto incidents, broken down by technique

Together they lost $20.64B. By technique, frontend/domain hijacks and social engineering happen at the moment of payment: screening the payee address and the payment URL first can stop the share already on a list or phishing feed before money leaves; rugpulls show warning signals such as a new contract with no history. Key compromise, contract bugs, oracle manipulation and bridge flaws happen inside wallets and contracts and need other controls, such as key management and code audits. Each class is marked below.

Incidents

1,265

all from a public dataset

Total lost

$20.64B

latest 2026-09-11

Pre-payment screening applies

197

$4.43B lost

By technique: where pre-payment screening applies

“Partly applies” means pre-payment screening covers part of that class — what is already on a list or phishing feed, or shows warning signals — not every incident in it.

TechniqueCountLostPre-payment screening
Access Control221$1.96BNeeds other controls

Broken contract permissions are a code-audit matter that pre-payment screening cannot see.

Protocol Logic168$251.5MNeeds other controls

Protocol logic flaws call for audits and formal verification.

Oracle Manipulation158$888.0MNeeds other controls

Oracle manipulation is a price-feed design problem.

Token & Share Accounting157$1.44BNeeds other controls

Accounting and share-math bugs are contract-layer problems for code audits.

Key Compromise153$8.55BNeeds other controls

Key compromise is a wallet and key-security matter; screening the counterparty or endpoint does not touch it.

Frontend & Infrastructure95$1.04BPartly applies

When a frontend or domain is hijacked the payee address is freshly generated and on no list, but the hijacked host is often already in public phishing feeds, so endpoint screening catches part of this class.

Input Validation69$755.4MNeeds other controls

Missing input validation is a contract code defect for code audits.

Reentrancy63$458.1MNeeds other controls

Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.

Social Engineering60$3.11BPartly applies

Phishing and fake-airdrop hosts show up in public domain feeds, and some payee addresses are already listed. Screening the endpoint and the counterparty before paying catches part of this class.

Bridge & Cross-Chain50$1.53BNeeds other controls

Bridge mint/verification flaws happen inside the bridge and are addressed by its own security design and audits.

Rugpull42$284.7MPartly applies

Rugpull contracts are usually new, with no history and no audit — visible warning signals before paying, used as signals only, never as proof.

Governance18$235.9MNeeds other controls

Governance attacks are countered by voting design and timelocks.

Market Manipulation11$135.1MNeeds other controls

Market manipulation is a liquidity and market-design problem.

How pre-payment screening addresses these

Endpoint screening

When a frontend is hijacked or a domain spoofed, the payee address shown is freshly generated — no address list has ever seen it. The hijacked host, however, is often already in public phishing feeds. This class can only be caught at the endpoint layer.

GET /api/endpoint?url=…

Counterparty screening

Addresses that received stolen funds, and payee addresses of known scams, are often already on community lists. Screening before settlement stops the known share before the money leaves.

GET /api/risk?addr=…

They answer different questions: address screening catches known-bad payees, endpoint screening catches spoofed payment URLs — use both.

The last 40

2026-09-11ether.fi Liquid$43KAccess Control· Ethereum
2026-09-10Symbiosis$336KBridge & Cross-Chain· BSC, Ethereum
2026-09-10Dominion$0Key Compromise· Solana
2026-09-09BeatXswap$78KOracle Manipulation· BSC
2026-09-09Zentra Finance$140KToken & Share Accounting· Citrea
2026-09-09Nomic$3.1MBridge & Cross-Chain· Nomic
2026-09-08WealthManagementV2$26KKey Compromise· BSC
2026-09-07Cozy V2$163KProtocol Logic· Optimism
2026-09-06Liquid Network$320.0MBridge & Cross-Chain· Liquid
2026-09-05Reddio RedSonic$23KToken & Share Accounting· Ethereum
2026-09-05Secured Finance Lending$104KOracle Manipulation· Ethereum
2026-09-05Dream Health Chain$72KProtocol Logic· BSC
2026-09-04Notional V2$1.7MToken & Share Accounting· Ethereum
2026-08-31Float Protocol$28KOracle Manipulation· Ethereum
2026-08-31Radix$1.2MAccess Control· Radix
2026-08-31Ankr$410KToken & Share Accounting· Flow
2026-08-31Aquifer$2.5MAccess Control· Solana
2026-08-30Tectonic$124.5MToken & Share Accounting· Cronos
2026-08-30Balancer V1$234KToken & Share Accounting· Ethereum
2026-08-30Weft V2$47KOracle Manipulation· Radix
2026-08-29Permapod$0Protocol Logic· ZIGChain
2026-08-29Full Sail$0Oracle Manipulation· Sui
2026-08-28Fogo Foundation$3.0MKey Compromise· Fogo
2026-08-28Avici$501KProtocol Logic· Solana
2026-08-28Virtue$895KOracle Manipulation· Iota
2026-08-28Ajna V2$775KProtocol Logic· Ethereum
2026-08-27CCC$117KProtocol Logic· BSC
2026-08-27Moonwell Lending$8.7MOracle Manipulation· Base
2026-08-25Enjin$162KAccess Control· Ethereum
2026-08-25FH Token$20KProtocol Logic· BSC
2026-08-25CometDEX$717KToken & Share Accounting· Stellar
2026-08-24Nesa$50.0MToken & Share Accounting· Nesa
2026-08-23Arrakis V1$7KOracle Manipulation· Ethereum
2026-08-23TermFinance Vaults$8.5MGovernance· Ethereum
2026-08-23warp.green$93KBridge & Cross-Chain· Chia, Ethereum
2026-08-22KiiChain$9.7MToken & Share Accounting· KiiChain
2026-08-22The Sandbox$675KAccess Control· Base, BSC, Ethereum
2026-08-22TAC$7.5MProtocol Logic· TAC
2026-08-21MANTRA Chain$0Access Control· MANTRA
2026-08-19Allbridge$191KBridge & Cross-Chain· Base

Source and notes

  • All incidents come from the public dataset DefiLlama Hacks. We carry it as published — amounts and classifications unchanged.
  • Class counts are computed from the data on every render and follow the upstream dataset as it updates.
  • The upstream dataset has no per-incident press links, so attribution is at the dataset level.
  • The “partly applies / needs other controls” column is our own judgement about the class of incident. It is not a conclusion about any specific event and assigns responsibility to no one.
  • We add no speculation and name no unconfirmed parties.