Clawditor
knowledge base

Security Research

Post-mortems and analysis of recent EVM/DeFi exploits. Our research agent tracks incidents, breaks down root cause and attack pattern, and files each one here — feeding both this knowledgebase and Clawditor's audits. Read the news feed for the latest.

post-mortemhigh$330K lost

Cozy Finance Double Exploit: Unchallenged UMA Oracle Proposal + Bridge Drain on Optimism

Two separate attackers hit Cozy Finance on Optimism in the same day: the first submitted a fraudulent UMA Optimistic Oracle price proposal that went unchallenged and triggered a $160K insurance payout; minutes later a second attacker drained a further $170K in a rapid bridge-and-exit sequence.

oraclesdefi-lendingbridges
Sep 9, 2026
post-mortemcritical$47.0M lost

Liquid Network's $320M Exploit: Attacker Reverse-Engineered a Public Patch Commit

On September 6, 2026, an attacker drained ~4,000 BTC ($320M) from Blockstream's Liquid Network by exploiting a rangeproof verification cache vulnerability in the Elements software — five days after a descriptive public fix was committed but before any node had deployed it. After negotiation, ~3,400 BTC was returned; ~598.5 BTC (~$47M) was kept as a self-declared bounty.

bridgeschain-specificliquid-networkcache-invalidation+2
Sep 8, 2026
post-mortemmedium$263K lost

Royal.io Legacy Contract: $263K Drained via Flash Loan + ERC1155 Zero-Value Transfer Reward Inflation

Attackers combined a flash loan with 100 zero-value ERC1155 transfers to exploit a flawed `beforeLdaTransfer` hook in Royal.io's abandoned Royal1155LD contract on Polygon, inflating reward balances and withdrawing $263K USDC from the legacy reward pool.

flashloanserc721precision-matherc20
Sep 7, 2026
post-mortemhigh$72K lost

DHC Dream Health Chain: $71K Drained via Stateless Repeatable Award Claim on BNB Chain

An attacker on BNB Chain exploited a missing persistent claimed-flag in DHC's award contract, looping 18 times through a pledge-reset-claim cycle in a single block to drain $71,851 USDT. No privileged access was required.

defi-stakingaccess-controllogic-bugbnb-chain+2
Sep 6, 2026
post-mortemhigh$9.2M lost

Tectonic Finance: $9.19M Oracle Attack on Cronos Triggers Largest-Ever EVM Chain Rollback

On August 30, 2026, an attacker pumped TONIC's thin-liquidity spot price ~100× to borrow $120.4M from Tectonic Finance's lending markets on Cronos. Validators rolled back 10,961 blocks (1h 54m), recovering $111.2M — but $9.19M had already bridged off-chain. The post-mortem with final recovery figures was published September 8, 2026.

oraclesdefi-lendingchain-specificprice-manipulation+3
Sep 5, 2026
post-mortemhigh$1.7M lost

Notional Finance $1.73M Exploit: Integer Overflow Turns -2^128 Debt into Zero Collateral

An attacker called `mintfCashPair()` twice to manufacture a -2^128 liability that an unsafe `uint128()` downcast silently truncated to zero, making a massive fabricated debt appear fully collateralised and allowing a $1.73M drain.

precision-mathdefi-lendingerc20
Sep 5, 2026
post-mortemhigh$4.9M lost

Injective Loses $4.9M to Binary Options Settlement Oracle Flaw; Chain Halts 3.7 Hours

On August 31, 2026, an attacker created 299 short-lived binary options markets on Injective with a self-controlled oracle designed to fail at price provision, exploiting the protocol's refund-on-missing-price settlement path to drain $4.9M. The Injective chain halted for 3 hours 42 minutes for an emergency patch.

oraclesdefi-ammaccess-controlchain-specific
Sep 5, 2026
analysismedium$234K lost

Balancer V1: $234K Rounding-Error Exploit Proves Abandoned Code Stays Dangerous

A flash-loan cascade drove a Balancer V1 WBTC pool's reserve to near-zero, triggering a 18-decimal fixed-point rounding bug that allowed minting 4,408.8 BPT for a single satoshi input — the same bug family behind the $116M Balancer V2 drain of November 2025. With Balancer Labs dissolved and contracts immutable, all live forks of V1 code remain exposed.

precision-mathdefi-ammflashloanserc20
Sep 3, 2026
post-mortemhigh$1.1M lost

Rain Card Legacy Contract Exploit: $1.1M Drained from Avici and Tria Neobank Users

An unpatched legacy Rain card contract allowed an attacker to seize administrative control over individual card-collateral accounts, draining ~$1.1M from two crypto neobanks and crashing the Avici token 49%.

access-controlchain-specificsolanalegacy-contract+1
Sep 3, 2026
post-mortemhigh$2.5M lost

Aquifer AMM $2.5M Exploit: Suspected Privileged Key Compromise on Solana

Solana-based AMM Aquifer lost approximately $2.5M in a suspected privileged key compromise, with stolen funds split across Solana and Ethereum attacker addresses; the protocol offered a 20% whitehat bounty with a September 3 deadline.

defi-ammaccess-controlchain-specificsolana+2
Sep 3, 2026
post-mortemcritical$6.3M lost

Tectonic on Cronos: $75M Attempted in Mango-Style Oracle Pump-and-Borrow; Chain Rolled Back

On August 30, 2026, an attacker pumped the price of TONIC, Tectonic's thinly traded governance token, roughly 100x in 20 minutes via flash-loan amplification, then borrowed ~$75M in blue-chip assets against the inflated collateral. Cronos validators halted the chain and rolled back ~11,000 blocks, erasing ~$68.7M on-chain; ~$6.3M in USDC had already escaped to Ethereum.

oraclesflashloansdefi-lending
Sep 2, 2026
post-mortemhigh$234K lost

Balancer V1 Drained $234K via WBTC Reserve Compression and BPT Minting Rounding Bug

An attacker used nested flash loans to compress a Balancer V1 WBTC pool balance to near-zero, exploiting an 18-decimal fixed-point rounding error to mint 4,408.8 BPT for a single satoshi. The same bug family caused the $116M Balancer V2 exploit in November 2025, and all unmaintained V1 forks remain exposed.

precision-mathdefi-ammflashloans
Sep 2, 2026
post-mortemhigh$234K lost

Balancer V1 BPool Rounding Bug: $234K Drained via Dust Flash Loan on Legacy Contract

A fixed-point arithmetic rounding vulnerability in Balancer V1's unmaintained BPool contract allowed an attacker to mint 4,408.8 pool tokens for a single satoshi of WBTC input after compressing pool reserves with a flash loan. The same bug family previously enabled a $116M exploit that ended Balancer Labs as a company.

defi-ammprecision-mathflashloanslegacy-code+1
Aug 31, 2026
analysishigh$9.3M lost

More Markets / ankrFLOW: Unbacked LST Minting + Aave E-Mode Drains $9.3M on Flow EVM

An attacker exploited a flaw in Ankr's ankrFLOW liquid-staking contract to mint ~8.6M unbacked ankrFLOW tokens on Flow EVM, then leveraged Aave V3 efficiency mode (e-mode) to borrow 15.5M WFLOW (~$9.3M) from More Markets' lending reserve against that synthetic collateral.

defi-lendingerc20oraclesdefi-staking+1
Aug 31, 2026
post-mortemcritical$6.0M lost

Tectonic / Cronos: $75M Collateral-Liquidity Exploit Forces Chain Rollback

An attacker spent ~$600K to pump Tectonic's TONIC governance token 100× in 20 minutes, then borrowed ~$75M in liquid assets against the inflated collateral. Cronos validators halted the chain and rolled back ~11,000 blocks, erasing most of the theft — only ~$6M bridged to Ethereum escaped.

oraclesdefi-lendingchain-specificprice-manipulation+3
Aug 31, 2026
post-mortemhigh$8.7M lost

Moonwell Base: $8.7M via MAMO Direct-Transfer Oracle Inflation — Protocol's Third Incident in 11 Months

On August 27, 2026, an attacker inflated the thinly traded MAMO token ~43× on Base through direct pool transfers and trading, borrowed $11M gross from Moonwell's lending markets, and netted ~$8.7M. The exploit used no contract bug — only a spot-price oracle with no TWAP protection on an illiquid asset.

oraclesdefi-lendingerc20
Aug 27, 2026
post-mortemhigh$3.0M lost

BounceBit Chain Shuts Down After Evmos Authorization Bypass Drains $3M in BB Tokens

Between August 19–20, 2026, an attacker exploited a protocol-level flaw in the Evmos EVM stack — allowing a smart contract to designate an arbitrary account as the transaction source without cryptographic verification — to drain 286.5 million BB tokens ($3M) from nine accounts. BounceBit permanently retired its L1 chain as a result, citing the discontinuation of Evmos itself.

chain-specificaccess-controlerc20
Aug 24, 2026
post-mortemcritical$8.5M lost

Term Labs $8.5M Governance Takeover: How 0.5 ETH Bought Majority Control of Six Vaults

An attacker spent roughly 0.5 ETH on opt-in governance tokens to capture majority voting weight, then zeroed the time-delay and instantly drained six Term Labs Meta Vaults for $8.5M in WETH and USDC.

governancedefi-lendingaccess-control
Aug 23, 2026
post-mortemhigh$675K lost

The Sandbox SAND: approveAndCall Flaw Lets Attacker Mint 329T Unbacked Tokens via LayerZero

A vulnerability in The Sandbox's SAND OFT contract on Base allowed an attacker to hijack LayerZero delegate permissions via an exposed approveAndCall function, minting 329 trillion unbacked SAND over five hours and draining ~14.75M real SAND (~$675K) from the Ethereum OFT Adapter.

bridgeserc20access-controlsandbox+4
Aug 23, 2026
post-mortemhigh$1.4M lost

MAYAChain Six-Bug Chain Exploit: Chained Accounting Flaws Drain 20 BTC

On August 18–19, 2026, an attacker exploited six chained bugs in MAYAChain's trade-account, slash-detection, and liquidity-pool modules via a single 23-message transaction, draining approximately 20.83 BTC (~$1.36M) and collapsing the CACAO token by 89%.

defi-ammprecision-mathbridgesmayachain+4
Aug 23, 2026
post-mortemcritical$9.7M lost

Cosmos EVM Staking Precompile Underflow Drains Six Chains

A chained integer underflow in the shared Cosmos EVM staking precompile allowed attackers to wrap an EVM balance to 2^256, enabling theft of real tokens across at least six blockchain networks between August 20-25, 2026.

chain-specificdefi-stakingprecision-mathassembly
Aug 22, 2026
advisoryhigh

Solidity Pro VS Code Extensions: WhiteCobra Supply Chain Attack on Web3 Developers

SlowMist disclosed on August 19, 2026 that two malicious VS Code extensions impersonating a Solidity development tool silently exfiltrated private keys, seed phrases, and API credentials from developer machines via auto-updating unsigned payloads—a targeted supply chain attack on EVM smart contract developers.

access-controlchain-specificsupply-chaindeveloper-toolchain+2
Aug 21, 2026
advisoryhigh

MemeCore Bridge: ~1 Billion Tokens Minted on BNB Chain Without Native Chain Collateral — Insider Exploit or Rug Setup?

On August 19, 2026, PeckShieldAlert flagged the minting of approximately 926 million $M tokens on BNB Smart Chain without any corresponding lock, burn, or collateral deposit on MemeCore's native chain — a textbook bridge double-mint risk, though evidence suggests execution by authorized wallet holders rather than an external attacker.

bridgesaccess-controlerc20chain-specific+4
Aug 19, 2026
post-mortemcritical$1.4M lost

Maya Protocol: Six Chained Bugs Trigger Phantom CACAO Subsidy, $1.36M Drained

An attacker crafted a single 23-message transaction to chain six bugs in MAYAChain's trade account and outbound processing, triggering a false theft alert that paid an uncapped 49.45M CACAO subsidy into a nearly-empty pool — CACAO collapsed 88% as $1.36M in hard assets were extracted.

chain-specificprecision-mathdefi-ammoracles+3
Aug 19, 2026
post-mortemcritical$10.0M lost

Wanchain Cardano-BNB Bridge: $10M NIGHT Token Drain via Non-Injective Message Encoding

On July 20-21, 2026, an attacker exploited a non-injective abi.encodePacked signing scheme in Wanchain's TreasuryCheck validator to reuse a small-withdrawal signature for a 65,000x larger redemption, draining 515.2M NIGHT tokens (~$10M).

bridgessignatureschain-specificaccess-control
Aug 18, 2026
post-mortemmedium$542K lost

Lien Finance: $542K Synthetic Bond Drain via Count-Not-Completeness Check in exchangeEquivalentBonds

On July 24, 2026, an attacker exploited a missing completeness check in Lien Finance's exchangeEquivalentBonds function — listing the same exception bond ID repeatedly to mint uncollateralised bond tokens sold into OTC pools for $542K USDC.

erc20defi-lendingaccess-controlprecision-math
Aug 18, 2026
post-mortemmedium$136K lost

USM Protocol: Flash Loan + 64-Way defund() Split Exploits Bonding-Curve Rounding to Drain 70 ETH

On August 10, 2026, an attacker flash-loaned ETH to manipulate USM Protocol's internal fund() pricing, then split the resulting FUM position into 64 small defund() calls to extract more ETH than a single redemption permits — draining ~70.83 ETH (~$136K) from the Ethereum stablecoin protocol.

flashloansprecision-mathdefi-lendingerc20
Aug 17, 2026
post-mortemhigh

Oraichain: Unauthorized ORAI Minting via EVM Cross-Chain Transfer Path Flaw

On August 9, 2026, a vulnerability in Oraichain's EVM cross-chain transfer path allowed an attacker to mint unauthorized ORAI tokens. The network was halted at 04:00 UTC; bridges and cross-chain routes remain restricted while the team burns illegitimate balances.

bridgeserc20chain-specificaccess-control
Aug 16, 2026
advisoryhigh

EtherHiding on BSC: Smart Contracts Weaponised as Immutable C2 Infrastructure

Microsoft Threat Intelligence and Trend Micro disclosed an active campaign (ClearFake / ClickFix) that embeds attack instructions directly inside BNB Smart Chain contracts, making the C2 channel resistant to conventional takedown. Thousands of Windows systems are hit daily via fake CAPTCHA lures.

chain-specificerc20assemblyaccess-control
Aug 15, 2026
post-mortemhigh

Neutrl NUSD: $53M Synthetic Dollar Paused After Opaque Reserve Failure and Suspected Team Front-Run

Neutrl's NUSD stablecoin halted all minting and redemptions on August 13, 2026, citing unspecified reserve impacts, while on-chain evidence shows a suspected team wallet withdrew $3.5M from Curve's NUSD-USDC pool exactly 14 minutes before the public announcement.

access-controldefi-stakingdefi-amm
Aug 15, 2026
advisoryhigh$3.5M lost

SimGuard Research: 4,224 Transaction-Simulation Phishing Contracts Found Across EVM Chains

A July 30, 2026 arXiv paper (arXiv:2607.28747) presents SimGuard, a bytecode-level detector that identified 4,224 simulation-phishing contracts on Ethereum, BSC, Avalanche, and Polygon—victimizing 5,742 users for approximately $3.48M. Contracts display a benign wallet-simulation preview but redirect funds on-chain when executed.

signatureserc20erc721assembly+1
Aug 14, 2026
post-mortemmedium$214K lost

Coreum Bridge Drained: Relayer Credited Attacker Self-Payments as Legitimate Deposits

On August 9, 2026, an attacker exploited a deposit-source validation gap in Coreum's XRPL bridge relayer network, tricking the 17-of-28 multisig relay committee into authorising mints for self-payments and draining 199,916 XRP (~$214K) from the bridge reserve in 94 transactions over 97 minutes.

bridgessignaturesaccess-control
Aug 12, 2026
post-mortemcritical

Harmony ONE: 3 Trillion Tokens Forged via Cross-Shard Receipt Replay and Quorum Bypass

On August 12, 2026, an attacker exploited a cross-shard receipt revalidation flaw and a broken quorum-signature check on Harmony Protocol to mint approximately 3.01 trillion ONE tokens, triggering a network rollback to erase the forged supply.

chain-specificsignaturesaccess-control
Aug 12, 2026
post-mortemcritical

Ravencoin KAWPOW Proof-of-Work Bypass: Invalid Blocks Accepted, 3-Day Reorg Risk

A missing nHeight validation in Ravencoin's KAWPOW algorithm let attackers forge valid-looking blocks without genuine ProgPoW computation from block 4,487,776 (2026-08-07), splitting the network and forcing major exchanges to suspend RVN transfers. An emergency patch came from a mining pool, not the core team.

chain-specificconsensusproof-of-workreorg+1
Aug 11, 2026
post-mortemmedium$191K lost

Allbridge: $191K Drained via Forged CCTP Message — Circle Attested What It Never Verified

In a month-long attack, an adversary exploited Allbridge's Base CCTP router by constructing a forged cross-chain message that Circle attested without verifying an actual USDC burn occurred. Missing sender, origin, and amount validation in `receiveCctpMessage` let the attacker claim a phantom $1M credit and drain 191,156 USDC with an Aave flash loan.

bridgessignaturesflashloanserc20+2
Aug 11, 2026
post-mortemhigh$7.9M lost

Coinsbuy Drained for $7.9M on Ethereum and TRON: The Anatomy of a Hot-Wallet Admin-Key Theft

A crypto payment processor lost nearly $8 million across Ethereum and TRON on August 9, 2026 when attackers drained company-controlled hot wallets — no multi-sig or on-chain delay stood in the way.

access-controlerc20
Aug 11, 2026
post-mortemcritical$4.1M lost

Makina Finance: Permissionless Oracle Update Enables $4.13M Flash Loan Drain

On January 20, 2026, an attacker exploited a permissionless AUM oracle function in Makina Finance's stablecoin pool — using a $280M flash loan to inflate DUSD price 165× and extract $4.13M — only to be front-run by an MEV bot that captured nearly all the gains.

flashloansoraclesaccess-controldefi-amm+1
Aug 10, 2026
post-mortemhigh$6.7M lost

TrustedVolumes $6.7M Loss: Unguarded Signer Allowlist in 1inch RFQ Proxy — Same Attacker as 2025 Fusion V1 Hack

In May 2026, TrustedVolumes — a 1inch ecosystem market maker — lost $6.7M after an attacker exploited a public, entirely unguarded function that let any address register itself as an authorized order signer in the protocol's RFQ swap proxy. Behavioral analysis links the attacker to the March 2025 1inch Fusion V1 exploit.

access-controlsignatureserc20rfq+1
Aug 9, 2026
advisorycritical$5.7M lost

Ill Bloom: CryptoJS WordArray.random() Entropy Flaw Enables $5.7M Wallet Drains Across EVM and Bitcoin

Security researchers at Coinspect disclosed that five wallet applications used CryptoJS versions prior to 4.0.0 to generate private keys — a library function relying on Math.random() that yields only 2^39–2^47 bits of effective entropy. At least 2,100 addresses were swept for a combined $5.7M across two coordinated drain waves in May–July 2026.

chain-specificerc20supply-chainweak-randomness+1
Aug 9, 2026
post-mortemmedium$25K lost

Drips Network: uint128→int128 Sign Flip Converts Deposit Into $25K Reserve Withdrawal

On July 14, 2026, an attacker exploited an unsafe integer cast in a legacy Ethereum DaiDripsHub contract — choosing a uint128 input that wraps to negative when cast to int128, causing the protocol to interpret a "give" operation as a reserve withdrawal and draining ~25K DAI.

precision-matherc20defi-staking
Aug 8, 2026
advisorycritical$5.7M lost

CryptoJS Weak RNG (GHSA-rg76-677x-56q9): How 12 Years of Bad Entropy Drained $5.7M Across Wallet Apps

A decade-old `Math.random()` fallback in CryptoJS's `WordArray.random()` made seed phrases guessable across five wallet apps, enabling two automated sweep waves totalling $5.69M. GitHub advisory GHSA-rg76-677x-56q9 (CVSS 9.0 Critical) was published August 5, 2026.

signatureschain-specific
Aug 7, 2026
advisorymedium$3.5M lost

Advisory: Transaction-Simulation Phishing Contracts Bypassed Wallet Safety Previews Across EVM Chains

A July 28, 2026 research paper (arXiv:2607.28747) formally documented 4,224 malicious EVM contracts that exploited wallet simulation tools to show safe previews while silently redirecting funds during real broadcast, victimising 5,742 addresses for an estimated $3.48 million.

erc20signatureschain-specific
Aug 7, 2026
post-mortemhigh$18.0M lost

Ostium Perp DEX: $18M Drained via Compromised Off-Chain Oracle Signing Key

On July 15, 2026, Arbitrum-based perpetuals exchange Ostium lost approximately $18–24 million after an attacker gained control of the private key backing a PriceUpKeep Forwarder, submitted fabricated BTC prices as low as $5,000, and profited from the spread against real market prices.

oraclesdefi-ammaccess-controlarbitrum+2
Aug 6, 2026
analysishigh$3.5M lost

Transaction Simulation Phishing: 4,224 Malicious EVM Contracts Deceive Wallet Previews for $3.48M

Researchers uncovered a systematic campaign of 4,224 EVM smart contracts that exploited wallet transaction-simulation safety features to show benign previews while executing fund-draining logic on-chain. Across Ethereum, BNB Chain, Avalanche, and Polygon, 5,742 victims lost approximately $3.48M.

erc20assemblychain-specific
Aug 6, 2026
post-mortemhigh$4.3M lost

Aztec Connect Exploited Twice in Four Days for $4.35M via Deprecated ZK Proof Verification Flaw

Two deprecated, immutable Aztec rollup contracts were drained for a combined $4.35M in June 2026 by exploiting a mismatch between verified ZK proof public inputs and the calldata used to drive settlement — a bug class that immutability made impossible to patch.

signatureschain-specificaccess-controlzk-rollup+1
Aug 6, 2026
post-mortemcritical$9.6M lost

ResupplyFi: $9.6M ERC-4626 First-Deposit Donation Attack

An attacker exploited a classic ERC-4626 vault donation vulnerability in ResupplyFi's wstUSR lending market 1.5 hours after deployment, collapsing the internal exchange rate and borrowing $10M reUSD against 1 wei of collateral.

erc4626flashloansdefi-lendingprecision-math+2
Aug 5, 2026
post-mortemcritical$9.1M lost

Bonzo Lend $9.05M Oracle Exploit: Supra's BLS Verifier Accepted a Zeroed Signature

On July 11, 2026, Hedera's largest lending protocol lost $9.05M after Supra's on-chain oracle verifier passed a price update carrying a cryptographically empty BLS signature. The pairing check returned true for zeroed inputs because both sides reduced to the mathematical identity point — letting an attacker borrow millions against three dollars of collateral.

oraclesdefi-lendingsignaturesprecision-math
Aug 4, 2026
advisoryhigh$3.5M lost

Research Disclosure: 4,224 Malicious EVM Contracts Spoof Wallet Simulation to Drain 5,742 Victims for $3.48M

Researchers disclosed on August 3, 2026 that 4,224 malicious smart contracts across four EVM chains manipulate transaction simulation output to show false safe results, tricking users into signing transactions that actually drain their approved tokens — bypassing wallet safety previews entirely.

erc20signatureschain-specific
Aug 4, 2026
advisoryhigh$3.5M lost

SimGuard Research Exposes 4,224 Wallet-Simulation Phishing Contracts Across EVM Chains

A July 2026 academic preprint (publicly reported August 3) identified 4,224 smart contracts deployed across Ethereum, BNB Smart Chain, Avalanche, and Polygon that silently diverge from their wallet-simulator preview — tricking 5,742 victims out of at least $3.48 million. The attack pattern systematically exploits the semantic gap between `eth_call` simulation and live transaction execution.

erc20signaturesaccess-controlsimulation-phishing+2
Aug 4, 2026
post-mortemhigh$7.3M lost

DxSale $7.3M Exploit: EIP-7702 Batch Delegation Turns a Legacy BNB Chain Locker into a Mass Drain

On May 28-29, 2026, an attacker transferred ownership of DxSale's 2021 liquidity-locker contract, then used EIP-7702 batch delegation to drain more than 1,400 BNB Chain LP pools in a single transaction flow. A missing state-zero in the withdrawal function allowed repeated drainage of the same collateral.

access-controlerc20chain-specificproxies
Aug 4, 2026