Security incident · 2026-05-01
Bisq
According to the public DefiLlama incident dataset, Bisq (Bitcoin) suffered a security incident on 2026-05-01, with about $550K reported lost.
| Date | 2026-05-01 |
|---|---|
| Reported loss | $550K |
| Chain | Bitcoin |
| Target type | DeFi Protocol |
| Technique class | Input Validation |
| Technique | Missing Input Validation |
| Bridge incident | No |
| Within 2026 | #136 by loss that year, 0.0% of all reported losses that year |
How this kind of attack works
The contract did not check the parameters it received, and the attacker passed crafted data that made it do something it should not.
Would a pre-payment check have helped
Missing input validation is a contract code defect for code audits.
Other incidents with the same technique
- Portal2022-02-02 · $326.0M
- Orbit Bridge2023-12-31 · $81.7M
- Qubit2022-01-28 · $80.0M
- Cashio2022-03-23 · $52.8M
- Hedgey2024-04-19 · $44.7M
- Transit Swap2022-10-02 · $28.9M

