DeFi Incident Tracker
Methodology →Confirmed facts, reports under review and unresolved questions are kept separate. Records without verified sources are not presented as confirmed incidents.
Incident database
41 records match| Event | Date | Chain | Technique | Loss | Status | Confidence | |
|---|---|---|---|---|---|---|---|
| Whitehats move 52 bitcoin from the Coldcard hackAccording to Galaxy Digital, the good guys have moved 52 BTC to an address carrying an OP_RETURN message reading "claim:cryptorecoverytrust dot com." | 2026-09-22 | Bitcoin | Security incident | Unavailable | Confirmed | 80% | Open → |
| White hats outrun Coldcard hackers in 52-Bitcoin evacuationWhite hats secured about 40% of the Bitcoin moved in the Coldcard exploit’s second wave, transferring it to a Wyoming trust for victims. | 2026-09-22 | Bitcoin | Exploit | Unavailable | Under review | 55% | Open → |
| Ledger CTOTL;DR: Charles Guillemet, Chief Technology Officer at Ledger, issued a public alert on September 21, 2026, regarding the DarkSword exploit chain targeting Safari. The threat chains six iOS security flaws that compromise the JavaScriptCore engine, bypass sandbox isolation, and exploit the system kernel. Google confirmed that the original vulnerabilities in the chain were patched starting ... Read more | 2026-09-21 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| SlowMistSlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets. SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s… | 2026-09-21 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| Pragma flags 6 price feeds as critical riskThe September 18 assessment exposes a gap between oracle valuations and the liquidity lenders need to sell collateral. The post Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit appeared first on CryptoSlate . | 2026-09-22 | Not specified | Exploit | $3.5M | Under review | 55% | Open → |
| SlowMistSlowMist has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5 and extract private keys from self-custody crypto wallets. SlowMist Chief Information Security Officer 23pds said attackers are using Darksword to bypass Apple’s… | 2026-09-21 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| Google Admits Gemini AIGoogle learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks. | 2026-09-21 | Not specified | Security incident | Unavailable | Under review | 55% | Open → |
| Why Balancer’s $1.4M hack recovery won’t pay LPsThe pending plan uses attack-time losses and pre-exploit pool balances, but no V1 claim window is open. The post Why Balancer’s $1.4M hack recovery won’t pay LPs anytime soon appeared first on CryptoSlate . | 2026-09-21 | Not specified | Exploit | $1.4M | Under review | 55% | Open → |
| Why Balancer’s $1.4M hack recovery won’t pay LPsThe pending plan uses attack-time losses and pre-exploit pool balances, but no V1 claim window is open. The post Why Balancer’s $1.4M hack recovery won’t pay LPs anytime soon appeared first on CryptoSlate . | 2026-09-21 | Not specified | Exploit | $1.4M | Under review | 55% | Open → |
| One wallet links $1.55 million FetchAI theft toFetch.ai says its own contracts were unaffected, while shared bridge routes leave an unresolved NTX supply question. The post One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint appeared first on CryptoSlate . | 2026-09-21 | Not specified | Security incident | $1.6M | Under review | 55% | Open → |
| SecondFiSecondFi has warned holders of compromised wallets not to redeem upcoming NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address. According to SecondFi, some users affected by its June security incident… | 2026-09-21 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| X sues Bitcoin account operators over alleged $278KX alleges six Bitcoin-focused accounts coordinated posts and engagement to inflate creator payouts, with claimed and projected losses of at least $378,000. | 2026-09-21 | Bitcoin | Fraud or scam | $278.0K | Confirmed | 80% | Open → |
| SecondFiSecondFi has warned holders of compromised wallets not to redeem upcoming NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address. According to SecondFi, some users affected by its June security incident… | 2026-09-21 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| MultiversXMultiversX has come under formal trading review at Upbit after the South Korean exchange flagged EGLD on Sept. 21 following a mainnet security incident that forced the network to stop progressing. Upbit’s official notice designated EGLD/KRW, EGLD/BTC and EGLD/USDT as… | 2026-09-21 | Not specified | Exploit | Unavailable | Under review | 55% | Open → |
| Fetch.aiFetch.ai reports a security breach affecting SingularityNET contracts, revealing crucial operational updates. The post Fetch.ai Confirms SingularityNET Exploit appeared first on Coinfomania . | 2026-09-20 | Not specified | Exploit | Unavailable | Under review | 55% | Open → |
| Fetch.ai and NuNetThe same exploiter was linked to attacks involving Fetch.ai (FET) and NuNet (NTX), with roughly $2 million in assets involved. Security firms tied both events to the same wallet. NuNet’s token lost more than 70% of its value and touched an all-time low on September 20. How One Attacker Reached Two Protocols Blockaid said on The post Fetch.ai and NuNet Exploited for $2 Million by Same Attacker, NTX Hits All-Time Low appeared first on BeInCrypto . | 2026-09-20 | Not specified | Exploit | $2.0M | Under review | 55% | Open → |
| Blink Wallet pauses services after attacker drains custodialThe breach underscores the inherent risks of custodial crypto services, accelerating the shift towards self-custody amid regulatory pressures. The post Blink Wallet pauses services after attacker drains custodial accounts appeared first on Crypto Briefing . | 2026-09-19 | Not specified | Security incident | Unavailable | Under review | 55% | Open → |
| GoogleFour frontier AI labs have now confirmed that their models reached the open internet and then accessed the systems of real companies. Google joined that list on Friday, roughly four months after its own incidents happened. Gemini accessed three real companies during a May evaluation. Notably, the model stopped in all three cases. Google’s Gemini The post Google Confirms Gemini Hacked 3 Real Companies in May Safety Test appeared first on BeInCrypto . | 2026-09-19 | Not specified | Security incident | Unavailable | Confirmed | 80% | Open → |
| Investigadores ganan $6,500 tras hackear OpenAI con ClaudeEl propio modelo de IA de un competidor terminó haciendo la mayor parte del trabajo en un ataque contra OpenAI. Los investigadores de Hacktron AI usaron Claude, de Anthropic, para escribir código de exploit funcional. Toda la intrusión tomó menos de 72 horas. OpenAI terminó pagando una recompensa de 6,500 dólares cuando el equipo demostró El post Investigadores ganan $6,500 tras hackear OpenAI con Claude de Anthropic fue visto por primera vez en BeInCrypto . | 2026-09-18 | Not specified | Exploit | $6 | Confirmed | 80% | Open → |
| 7,000 Crypto Wallets Targeted as North Korean HackersTL;DR: Japan’s National Police Agency and the FBI confirmed the infection of over 30,000 devices and the theft of credentials from 7,000 wallets across more than 100 countries. Addresses controlled by the attackers received at least 1.7 billion yen (approximately $10.71 million) between December 2025 and July 2026. Law enforcement dismantled Japan’s first operational “laptop ... Read more | 2026-09-18 | Not specified | Credential compromise | $10.7M | Confirmed | 80% | Open → |
| North Korean hackers stole 7,000 crypto wallet records,North Korea linked hacking group WaterPlum has compromised more than 30,000 devices across over 100 countries and regions, stealing information from more than 7,000 cryptocurrency wallets while targeting developers through fake recruitment campaigns. Japan’s National Police Agency said on Sept.… | 2026-09-18 | Not specified | Credential compromise | Unavailable | Under review | 55% | Open → |
| Blockchain malware activity jumps 440% as AI lowersPublic chains preserve malware instructions beyond ordinary domain takedowns, shifting defense toward monitoring wallets, contracts and off-chain servers. The post Blockchain malware activity jumps 440% as AI lowers the barrier for North Korea and Iran-linked hackers appeared first on CryptoSlate . | 2026-09-18 | Not specified | Malware | Unavailable | Under review | 55% | Open → |
| Ethereum Founder Vitalik Buterin Says AI Won’t DoomThe Ethereum co-founder said AI could help developers mathematically verify entire software systems, turning the same technology powering new attacks into a tool for defense. | 2026-09-17 | Ethereum | Security incident | Unavailable | Under review | 55% | Open → |
| Cardano’s Splash fix patches the exploit, but leavesThe exploit drained 2.42 million ADA net, while OADA lacks protocol redemption and faces a thin-pool overhang. The post Cardano’s Splash fix patches the exploit, but leaves 2.4M ADA missing and holders trapped appeared first on CryptoSlate . | 2026-09-17 | Not specified | Exploit | Unavailable | Under review | 55% | Open → |
| Hacker turned 55 days of failed transactions into a $3 million master key thatLedger timestamps and SDK patches show why signed intent needed automatic checks before funds reached a bridge. The post Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets appeared first on CryptoSlate . | 2026-09-17 | Not specified | Security incident | $3.0M | Under review | 55% | Open → |
| State hackers drive 420% surge in onchain malware,North Korea-linked hackers used Tron, Aptos and BNB Chain to maintain malware infrastructure, while suspected Iran-linked actors embedded directions in Bitcoin transactions. | 2026-09-17 | Bitcoin | Malware | Unavailable | Under review | 55% | Open → |
| Chainflip to reset TRON USDT provider balances toProviders retain a separate on-chain record of what they are owed, but Chainflip has not disclosed repayment timing. The post Chainflip to reset TRON USDT provider balances to zero following $736,000 exploit appeared first on CryptoSlate . | 2026-09-17 | Tron | Exploit | $736 | Under review | 55% | Open → |
| Revolut says no direct contact after $3 millionRevolut says it received no direct contact despite separate ransom demands for $3 million in Monero and 10,000 Bitcoin from competing breach claimants. | 2026-09-17 | Bitcoin | Security incident | $3.0M | Confirmed | 80% | Open → |
| Chainflip to reset TRON USDT provider balances toProviders retain a separate on-chain record of what they are owed, but Chainflip has not disclosed repayment timing. The post Chainflip to reset TRON USDT provider balances to zero following $736,000 exploit appeared first on CryptoSlate . | 2026-09-17 | Tron | Exploit | $736 | Under review | 55% | Open → |
| ERA Launches Software Wallet, Turning Its Hardware DeviceThe companion app connects to the ERA hardware wallet to add portfolio management, swaps, and dApp access across 14 networks — while private keys never leave the device. The release follows a full independent security audit by Cure53, and lands alongside a major update to ERA Lens, ERA’s on-device scam-warning system, plus new hardware-side capabilities The post ERA Launches Software Wallet, Turning Its Hardware Device Into a Full Self-Custody Ecosystem appeared first on BeInCrypto . | 2026-09-16 | Multi-chain | Credential compromise | Unavailable | Under review | 55% | Open → |
| OpenAI's Rogue AI Agents Were Probing Hugging FaceAn independent researcher found the agents hijacked Hugging Face accounts and mapped the platform's defenses as early as May 13—activity OpenAI's own incident report never fully described. | 2026-09-16 | Not specified | Security incident | Unavailable | Under review | 55% | Open → |
| Hackers Hijack HBO Max’s Reddit Account to SpreadAttackers ran 108 malicious ads through the streaming service’s verified account, directing users to fake software downloads. | 2026-09-16 | Not specified | Malware | Unavailable | Confirmed | 80% | Open → |
| Celsius sues BitMEX for $495 million just 11Celsius Network’s bankruptcy estate has sued BitMEX over a 2020 liquidation cascade it says cost more than 6,360 Bitcoin. The complaint, filed Sept. 12 in the US Bankruptcy Court for the Southern District of New York, accuses entities behind the crypto derivatives exchange of fraud, market manipulation and wrongful liquidations during Bitcoin’s historic March 2020 […] The post Celsius sues BitMEX for $495 million just 11 days before exchange shutdown appeared first on CryptoSlate . | 2026-09-16 | Bitcoin | Fraud or scam | $495.0M | Under review | 55% | Open → |
| VymopayMost people searching for a no-kyc crypto exchange alternative are not looking for less compliance, they are looking for less exposure. Less counterparty risk. Less reliance on a custodian that could be hacked, frozen, or insolvent when they need their… | 2026-09-16 | Not specified | Security incident | Unavailable | Under review | 55% | Open → |
| KREMLIN malware uses Ethereum to update attack serversKREMLIN malware uses malicious Chrome and Edge extensions plus Ethereum smart contracts, with Elastic tracing 1,515 infected hosts, mostly in Brazil. | 2026-09-16 | Ethereum | Malware | Unavailable | Under review | 55% | Open → |
| Did crypto’s $20 Billion DeFi surge just getStablecoin growth stayed below 6% while ETH and SOL gained more than 32%, leaving the inflow picture unresolved. The post Did crypto’s $20 Billion DeFi surge just get stolen by price inflation? appeared first on CryptoSlate . | 2026-09-15 | Not specified | Security incident | $20.0B | Under review | 55% | Open → |
| Balancer proposes shutdown and treasury distribution to BALBalancer's shutdown highlights governance challenges in DeFi, emphasizing the need for adaptive strategies amid financial instability and exploits. The post Balancer proposes shutdown and treasury distribution to BAL holders appeared first on Crypto Briefing . | 2026-09-14 | Not specified | Exploit | Unavailable | Confirmed | 80% | Open → |
| MetaMask Adds New Wallet Protections Against Crypto ScamsMetaMask’s latest safeguards flag suspicious transfers and stop transactions that don’t match their previews. | 2026-09-14 | Not specified | Fraud or scam | Unavailable | Under review | 55% | Open → |
| AI Agents Just Slashed the Cost of aThe ECDSA.Fail challenge cut a resource benchmark for one component of a potential quantum attack by 86%. | 2026-09-10 | Bitcoin | Security incident | Unavailable | Under review | 55% | Open → |
| Anthropic Discloses Fourth Claude Hacking Incident as DebateThe company now says attacks during security tests exposed model behavior failures, after initially emphasizing errors in its testing infrastructure. | 2026-09-10 | Not specified | Security incident | Unavailable | Under review | 55% | Open → |
| Trezor, BitBoxBitBox said multiple Bitcoin companies appeared to have been targeted through a shared newsletter provider, while Trezor confirmed a breach at its email service. | 2026-09-10 | Multi-chain | Phishing | Unavailable | Under review | 55% | Open → |