Ostium - Rekt
An attacker used a trusted price forwarder to feed the vault a fake $60K Bitcoin quote to drain $23.75 million from Ostium on Arbitrum, then collected the payout on trades that were never real.
An attacker used a trusted price forwarder to feed the vault a fake $60K Bitcoin quote to drain $23.75 million from Ostium on Arbitrum, then collected the payout on trades that were never real.
Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still moving in 2026.
Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.
$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.
$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.
Multi-strategy yield protocol Altura, raised $39 million for a gold-backed strategy, moved funds through Tron, relied on a verifier tied to the COO's own project, ran a dashboard that admitted it verified nothing, closed the vault, and left depositors waiting.
A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already there.
$4.67 million lost from Secret Network’s bridge connection to Axelar Network after a forked Secret-side IBC contract minted unbacked tokens from thin air. 2 missing validation checks let an attacker forge deposits with a fake Cosmos chain. Drain went undetected for 7 days.
One deprecated contract, one flawed escape hatch circuit, and a verifier that should have been retired years earlier. Aztec’s legacy rollup contract lost roughly $2.198 million after a ZK proof passed a broken root-binding check.
$2.28 million drained from Aztec Connect on June 14th, a deprecated ZK-rollup built by Aztec Labs, across two consecutive days. The ZK proof and settlement layer processed different transaction sets, attackers exploited the gap to mint unbacked balances and drain real funds.
Seven keys on one laptop handed an attacker $36.4 million from Humanity Protocol across Ethereum and BSC. Rare for its kind, the owner of the compromised device was publicly named. The code wasn't broken. The key management was, and nobody's been held accountable for either.
5 billion SYS minted from a malformed SPV proof that slipped past Syscoin’s bridge relay parser. The team published the receipts, coordinated a whitehat recovery, and the funds came back. No public audit record for the relay path that failed.