A Case for Critical Thinking


AI keeps getting trusted before anyone checks if it should be. The bill is landing. Essays nobody can quote, wrongful arrests, insurance denials reversed 90% of the time, and data centers draining local water. The tool isn't the failure. Trusting it blind is.

MÁS

Ostium - Rekt


An attacker used a trusted price forwarder to feed the vault a fake $60K Bitcoin quote to drain $23.75 million from Ostium on Arbitrum, then collected the payout on trades that were never real.

MÁS

BonkDAO - Rekt


$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.

MÁS

Summer Finance - Rekt


$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.

MÁS

Digging for Gold


Multi-strategy yield protocol Altura, raised $39 million for a gold-backed strategy, moved funds through Tron, relied on a verifier tied to the COO's own project, ran a dashboard that admitted it verified nothing, closed the vault, and left depositors waiting.

MÁS

SecondFi - Rekt


A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already there.

MÁS

Secret Network - Rekt


$4.67 million lost from Secret Network’s bridge connection to Axelar Network after a forked Secret-side IBC contract minted unbacked tokens from thin air. 2 missing validation checks let an attacker forge deposits with a fake Cosmos chain. Drain went undetected for 7 days.

MÁS

Aztec Bridge - Rekt


One deprecated contract, one flawed escape hatch circuit, and a verifier that should have been retired years earlier. Aztec’s legacy rollup contract lost roughly $2.198 million after a ZK proof passed a broken root-binding check.

MÁS

Aztec Connect - Rekt


$2.28 million drained from Aztec Connect on June 14th, a deprecated ZK-rollup built by Aztec Labs, across two consecutive days. The ZK proof and settlement layer processed different transaction sets, attackers exploited the gap to mint unbacked balances and drain real funds.

MÁS

Humanity Protocol - Rekt


Seven keys on one laptop handed an attacker $36.4 million from Humanity Protocol across Ethereum and BSC. Rare for its kind, the owner of the compromised device was publicly named. The code wasn't broken. The key management was, and nobody's been held accountable for either.

MÁS