| Date | Incident | Loss (USD) |
|---|---|---|
| 2025-05-22 |
Math overflow in Cetus AMM's tick-math allowed minting of liquidity positions claiming many orders of magnitude more value than collateral.
|
$223M |
| 2025-02-21 |
Malicious JavaScript injected into Safe.global UI rewrote the multisig payload between the browser and hardware wallet, overwriting the proxy implementation slot.
|
$1.46B |
| 2024-07-18 |
Lazarus-attributed compromise of WazirX-Liminal multisig signing flow drained approximately $235M of users' Ethereum and ERC-20 holdings.
|
$235M |
| 2023-07-30 |
Vyper compiler 0.2.15-0.3.0 emitted broken @nonreentrant decorators, allowing reentrancy across multiple Curve stable pools.
|
$73M |
| 2023-03-13 |
donateToReserves omitted the post-call solvency check, enabling a flash-loan, mint-leverage, donate-collateral, self-liquidate sequence; funds were later returned in full.
|
$197M |
| 2022-11-11 |
FTX commingled customer deposits with Alameda Research's working capital under a sister-company prime-brokerage arrangement; a CoinDesk leak and CZ tweet triggered a five-day run that exposed the shortfall.
|
$8B+ |
| 2022-05-12 |
UST's Luna-burn arbitrage failed reflexively when depeg pressure exceeded Luna's market depth; Anchor's 19.5% yield concentrated 75% of UST in a single yield-aggregator that turned depeg into instant exit-flow.
|
$40B+ |
| 2022-04-17 |
Attacker submitted a malicious BIP titled as Ukraine relief, then in one transaction flash-loaned $1B from Aave to mint majority Stalk voting power, passed the proposal, and drained the silo.
|
$182M |
| 2022-03-23 |
Lazarus spear-phished a Sky Mavis engineer to capture 4 of 9 validator keys, plus a dormant Axie DAO permission for a 5th, breaching the 5-of-9 multisig.
|
$620M |
| 2022-02-02 |
Solana-side verify_signatures used a deprecated function that didn't validate account ownership, letting the attacker forge a synthetic sysvar account vouching for an empty guardian set.
|
$326M |