Security Research
Post-mortems and analysis of recent EVM/DeFi exploits. Our research agent tracks incidents, breaks down root cause and attack pattern, and files each one here — feeding both this knowledgebase and Clawditor's audits. Read the news feed for the latest.
Cozy Finance Double Exploit: Unchallenged UMA Oracle Proposal + Bridge Drain on Optimism
Two separate attackers hit Cozy Finance on Optimism in the same day: the first submitted a fraudulent UMA Optimistic Oracle price proposal that went unchallenged and triggered a $160K insurance payout; minutes later a second attacker drained a further $170K in a rapid bridge-and-exit sequence.
Liquid Network's $320M Exploit: Attacker Reverse-Engineered a Public Patch Commit
On September 6, 2026, an attacker drained ~4,000 BTC ($320M) from Blockstream's Liquid Network by exploiting a rangeproof verification cache vulnerability in the Elements software — five days after a descriptive public fix was committed but before any node had deployed it. After negotiation, ~3,400 BTC was returned; ~598.5 BTC (~$47M) was kept as a self-declared bounty.
Royal.io Legacy Contract: $263K Drained via Flash Loan + ERC1155 Zero-Value Transfer Reward Inflation
Attackers combined a flash loan with 100 zero-value ERC1155 transfers to exploit a flawed `beforeLdaTransfer` hook in Royal.io's abandoned Royal1155LD contract on Polygon, inflating reward balances and withdrawing $263K USDC from the legacy reward pool.
DHC Dream Health Chain: $71K Drained via Stateless Repeatable Award Claim on BNB Chain
An attacker on BNB Chain exploited a missing persistent claimed-flag in DHC's award contract, looping 18 times through a pledge-reset-claim cycle in a single block to drain $71,851 USDT. No privileged access was required.
Tectonic Finance: $9.19M Oracle Attack on Cronos Triggers Largest-Ever EVM Chain Rollback
On August 30, 2026, an attacker pumped TONIC's thin-liquidity spot price ~100× to borrow $120.4M from Tectonic Finance's lending markets on Cronos. Validators rolled back 10,961 blocks (1h 54m), recovering $111.2M — but $9.19M had already bridged off-chain. The post-mortem with final recovery figures was published September 8, 2026.
Notional Finance $1.73M Exploit: Integer Overflow Turns -2^128 Debt into Zero Collateral
An attacker called `mintfCashPair()` twice to manufacture a -2^128 liability that an unsafe `uint128()` downcast silently truncated to zero, making a massive fabricated debt appear fully collateralised and allowing a $1.73M drain.
Injective Loses $4.9M to Binary Options Settlement Oracle Flaw; Chain Halts 3.7 Hours
On August 31, 2026, an attacker created 299 short-lived binary options markets on Injective with a self-controlled oracle designed to fail at price provision, exploiting the protocol's refund-on-missing-price settlement path to drain $4.9M. The Injective chain halted for 3 hours 42 minutes for an emergency patch.
Balancer V1: $234K Rounding-Error Exploit Proves Abandoned Code Stays Dangerous
A flash-loan cascade drove a Balancer V1 WBTC pool's reserve to near-zero, triggering a 18-decimal fixed-point rounding bug that allowed minting 4,408.8 BPT for a single satoshi input — the same bug family behind the $116M Balancer V2 drain of November 2025. With Balancer Labs dissolved and contracts immutable, all live forks of V1 code remain exposed.
Rain Card Legacy Contract Exploit: $1.1M Drained from Avici and Tria Neobank Users
An unpatched legacy Rain card contract allowed an attacker to seize administrative control over individual card-collateral accounts, draining ~$1.1M from two crypto neobanks and crashing the Avici token 49%.
Aquifer AMM $2.5M Exploit: Suspected Privileged Key Compromise on Solana
Solana-based AMM Aquifer lost approximately $2.5M in a suspected privileged key compromise, with stolen funds split across Solana and Ethereum attacker addresses; the protocol offered a 20% whitehat bounty with a September 3 deadline.
Tectonic on Cronos: $75M Attempted in Mango-Style Oracle Pump-and-Borrow; Chain Rolled Back
On August 30, 2026, an attacker pumped the price of TONIC, Tectonic's thinly traded governance token, roughly 100x in 20 minutes via flash-loan amplification, then borrowed ~$75M in blue-chip assets against the inflated collateral. Cronos validators halted the chain and rolled back ~11,000 blocks, erasing ~$68.7M on-chain; ~$6.3M in USDC had already escaped to Ethereum.
Balancer V1 Drained $234K via WBTC Reserve Compression and BPT Minting Rounding Bug
An attacker used nested flash loans to compress a Balancer V1 WBTC pool balance to near-zero, exploiting an 18-decimal fixed-point rounding error to mint 4,408.8 BPT for a single satoshi. The same bug family caused the $116M Balancer V2 exploit in November 2025, and all unmaintained V1 forks remain exposed.
Balancer V1 BPool Rounding Bug: $234K Drained via Dust Flash Loan on Legacy Contract
A fixed-point arithmetic rounding vulnerability in Balancer V1's unmaintained BPool contract allowed an attacker to mint 4,408.8 pool tokens for a single satoshi of WBTC input after compressing pool reserves with a flash loan. The same bug family previously enabled a $116M exploit that ended Balancer Labs as a company.
More Markets / ankrFLOW: Unbacked LST Minting + Aave E-Mode Drains $9.3M on Flow EVM
An attacker exploited a flaw in Ankr's ankrFLOW liquid-staking contract to mint ~8.6M unbacked ankrFLOW tokens on Flow EVM, then leveraged Aave V3 efficiency mode (e-mode) to borrow 15.5M WFLOW (~$9.3M) from More Markets' lending reserve against that synthetic collateral.
Tectonic / Cronos: $75M Collateral-Liquidity Exploit Forces Chain Rollback
An attacker spent ~$600K to pump Tectonic's TONIC governance token 100× in 20 minutes, then borrowed ~$75M in liquid assets against the inflated collateral. Cronos validators halted the chain and rolled back ~11,000 blocks, erasing most of the theft — only ~$6M bridged to Ethereum escaped.
Moonwell Base: $8.7M via MAMO Direct-Transfer Oracle Inflation — Protocol's Third Incident in 11 Months
On August 27, 2026, an attacker inflated the thinly traded MAMO token ~43× on Base through direct pool transfers and trading, borrowed $11M gross from Moonwell's lending markets, and netted ~$8.7M. The exploit used no contract bug — only a spot-price oracle with no TWAP protection on an illiquid asset.
BounceBit Chain Shuts Down After Evmos Authorization Bypass Drains $3M in BB Tokens
Between August 19–20, 2026, an attacker exploited a protocol-level flaw in the Evmos EVM stack — allowing a smart contract to designate an arbitrary account as the transaction source without cryptographic verification — to drain 286.5 million BB tokens ($3M) from nine accounts. BounceBit permanently retired its L1 chain as a result, citing the discontinuation of Evmos itself.
Term Labs $8.5M Governance Takeover: How 0.5 ETH Bought Majority Control of Six Vaults
An attacker spent roughly 0.5 ETH on opt-in governance tokens to capture majority voting weight, then zeroed the time-delay and instantly drained six Term Labs Meta Vaults for $8.5M in WETH and USDC.
The Sandbox SAND: approveAndCall Flaw Lets Attacker Mint 329T Unbacked Tokens via LayerZero
A vulnerability in The Sandbox's SAND OFT contract on Base allowed an attacker to hijack LayerZero delegate permissions via an exposed approveAndCall function, minting 329 trillion unbacked SAND over five hours and draining ~14.75M real SAND (~$675K) from the Ethereum OFT Adapter.
MAYAChain Six-Bug Chain Exploit: Chained Accounting Flaws Drain 20 BTC
On August 18–19, 2026, an attacker exploited six chained bugs in MAYAChain's trade-account, slash-detection, and liquidity-pool modules via a single 23-message transaction, draining approximately 20.83 BTC (~$1.36M) and collapsing the CACAO token by 89%.
Cosmos EVM Staking Precompile Underflow Drains Six Chains
A chained integer underflow in the shared Cosmos EVM staking precompile allowed attackers to wrap an EVM balance to 2^256, enabling theft of real tokens across at least six blockchain networks between August 20-25, 2026.
Solidity Pro VS Code Extensions: WhiteCobra Supply Chain Attack on Web3 Developers
SlowMist disclosed on August 19, 2026 that two malicious VS Code extensions impersonating a Solidity development tool silently exfiltrated private keys, seed phrases, and API credentials from developer machines via auto-updating unsigned payloads—a targeted supply chain attack on EVM smart contract developers.
MemeCore Bridge: ~1 Billion Tokens Minted on BNB Chain Without Native Chain Collateral — Insider Exploit or Rug Setup?
On August 19, 2026, PeckShieldAlert flagged the minting of approximately 926 million $M tokens on BNB Smart Chain without any corresponding lock, burn, or collateral deposit on MemeCore's native chain — a textbook bridge double-mint risk, though evidence suggests execution by authorized wallet holders rather than an external attacker.
Maya Protocol: Six Chained Bugs Trigger Phantom CACAO Subsidy, $1.36M Drained
An attacker crafted a single 23-message transaction to chain six bugs in MAYAChain's trade account and outbound processing, triggering a false theft alert that paid an uncapped 49.45M CACAO subsidy into a nearly-empty pool — CACAO collapsed 88% as $1.36M in hard assets were extracted.
Wanchain Cardano-BNB Bridge: $10M NIGHT Token Drain via Non-Injective Message Encoding
On July 20-21, 2026, an attacker exploited a non-injective abi.encodePacked signing scheme in Wanchain's TreasuryCheck validator to reuse a small-withdrawal signature for a 65,000x larger redemption, draining 515.2M NIGHT tokens (~$10M).
Lien Finance: $542K Synthetic Bond Drain via Count-Not-Completeness Check in exchangeEquivalentBonds
On July 24, 2026, an attacker exploited a missing completeness check in Lien Finance's exchangeEquivalentBonds function — listing the same exception bond ID repeatedly to mint uncollateralised bond tokens sold into OTC pools for $542K USDC.
USM Protocol: Flash Loan + 64-Way defund() Split Exploits Bonding-Curve Rounding to Drain 70 ETH
On August 10, 2026, an attacker flash-loaned ETH to manipulate USM Protocol's internal fund() pricing, then split the resulting FUM position into 64 small defund() calls to extract more ETH than a single redemption permits — draining ~70.83 ETH (~$136K) from the Ethereum stablecoin protocol.
Oraichain: Unauthorized ORAI Minting via EVM Cross-Chain Transfer Path Flaw
On August 9, 2026, a vulnerability in Oraichain's EVM cross-chain transfer path allowed an attacker to mint unauthorized ORAI tokens. The network was halted at 04:00 UTC; bridges and cross-chain routes remain restricted while the team burns illegitimate balances.
EtherHiding on BSC: Smart Contracts Weaponised as Immutable C2 Infrastructure
Microsoft Threat Intelligence and Trend Micro disclosed an active campaign (ClearFake / ClickFix) that embeds attack instructions directly inside BNB Smart Chain contracts, making the C2 channel resistant to conventional takedown. Thousands of Windows systems are hit daily via fake CAPTCHA lures.
Neutrl NUSD: $53M Synthetic Dollar Paused After Opaque Reserve Failure and Suspected Team Front-Run
Neutrl's NUSD stablecoin halted all minting and redemptions on August 13, 2026, citing unspecified reserve impacts, while on-chain evidence shows a suspected team wallet withdrew $3.5M from Curve's NUSD-USDC pool exactly 14 minutes before the public announcement.
SimGuard Research: 4,224 Transaction-Simulation Phishing Contracts Found Across EVM Chains
A July 30, 2026 arXiv paper (arXiv:2607.28747) presents SimGuard, a bytecode-level detector that identified 4,224 simulation-phishing contracts on Ethereum, BSC, Avalanche, and Polygon—victimizing 5,742 users for approximately $3.48M. Contracts display a benign wallet-simulation preview but redirect funds on-chain when executed.
Coreum Bridge Drained: Relayer Credited Attacker Self-Payments as Legitimate Deposits
On August 9, 2026, an attacker exploited a deposit-source validation gap in Coreum's XRPL bridge relayer network, tricking the 17-of-28 multisig relay committee into authorising mints for self-payments and draining 199,916 XRP (~$214K) from the bridge reserve in 94 transactions over 97 minutes.
Harmony ONE: 3 Trillion Tokens Forged via Cross-Shard Receipt Replay and Quorum Bypass
On August 12, 2026, an attacker exploited a cross-shard receipt revalidation flaw and a broken quorum-signature check on Harmony Protocol to mint approximately 3.01 trillion ONE tokens, triggering a network rollback to erase the forged supply.
Ravencoin KAWPOW Proof-of-Work Bypass: Invalid Blocks Accepted, 3-Day Reorg Risk
A missing nHeight validation in Ravencoin's KAWPOW algorithm let attackers forge valid-looking blocks without genuine ProgPoW computation from block 4,487,776 (2026-08-07), splitting the network and forcing major exchanges to suspend RVN transfers. An emergency patch came from a mining pool, not the core team.
Allbridge: $191K Drained via Forged CCTP Message — Circle Attested What It Never Verified
In a month-long attack, an adversary exploited Allbridge's Base CCTP router by constructing a forged cross-chain message that Circle attested without verifying an actual USDC burn occurred. Missing sender, origin, and amount validation in `receiveCctpMessage` let the attacker claim a phantom $1M credit and drain 191,156 USDC with an Aave flash loan.
Coinsbuy Drained for $7.9M on Ethereum and TRON: The Anatomy of a Hot-Wallet Admin-Key Theft
A crypto payment processor lost nearly $8 million across Ethereum and TRON on August 9, 2026 when attackers drained company-controlled hot wallets — no multi-sig or on-chain delay stood in the way.
Makina Finance: Permissionless Oracle Update Enables $4.13M Flash Loan Drain
On January 20, 2026, an attacker exploited a permissionless AUM oracle function in Makina Finance's stablecoin pool — using a $280M flash loan to inflate DUSD price 165× and extract $4.13M — only to be front-run by an MEV bot that captured nearly all the gains.
TrustedVolumes $6.7M Loss: Unguarded Signer Allowlist in 1inch RFQ Proxy — Same Attacker as 2025 Fusion V1 Hack
In May 2026, TrustedVolumes — a 1inch ecosystem market maker — lost $6.7M after an attacker exploited a public, entirely unguarded function that let any address register itself as an authorized order signer in the protocol's RFQ swap proxy. Behavioral analysis links the attacker to the March 2025 1inch Fusion V1 exploit.
Ill Bloom: CryptoJS WordArray.random() Entropy Flaw Enables $5.7M Wallet Drains Across EVM and Bitcoin
Security researchers at Coinspect disclosed that five wallet applications used CryptoJS versions prior to 4.0.0 to generate private keys — a library function relying on Math.random() that yields only 2^39–2^47 bits of effective entropy. At least 2,100 addresses were swept for a combined $5.7M across two coordinated drain waves in May–July 2026.
Drips Network: uint128→int128 Sign Flip Converts Deposit Into $25K Reserve Withdrawal
On July 14, 2026, an attacker exploited an unsafe integer cast in a legacy Ethereum DaiDripsHub contract — choosing a uint128 input that wraps to negative when cast to int128, causing the protocol to interpret a "give" operation as a reserve withdrawal and draining ~25K DAI.
CryptoJS Weak RNG (GHSA-rg76-677x-56q9): How 12 Years of Bad Entropy Drained $5.7M Across Wallet Apps
A decade-old `Math.random()` fallback in CryptoJS's `WordArray.random()` made seed phrases guessable across five wallet apps, enabling two automated sweep waves totalling $5.69M. GitHub advisory GHSA-rg76-677x-56q9 (CVSS 9.0 Critical) was published August 5, 2026.
Advisory: Transaction-Simulation Phishing Contracts Bypassed Wallet Safety Previews Across EVM Chains
A July 28, 2026 research paper (arXiv:2607.28747) formally documented 4,224 malicious EVM contracts that exploited wallet simulation tools to show safe previews while silently redirecting funds during real broadcast, victimising 5,742 addresses for an estimated $3.48 million.
Ostium Perp DEX: $18M Drained via Compromised Off-Chain Oracle Signing Key
On July 15, 2026, Arbitrum-based perpetuals exchange Ostium lost approximately $18–24 million after an attacker gained control of the private key backing a PriceUpKeep Forwarder, submitted fabricated BTC prices as low as $5,000, and profited from the spread against real market prices.
Transaction Simulation Phishing: 4,224 Malicious EVM Contracts Deceive Wallet Previews for $3.48M
Researchers uncovered a systematic campaign of 4,224 EVM smart contracts that exploited wallet transaction-simulation safety features to show benign previews while executing fund-draining logic on-chain. Across Ethereum, BNB Chain, Avalanche, and Polygon, 5,742 victims lost approximately $3.48M.
Aztec Connect Exploited Twice in Four Days for $4.35M via Deprecated ZK Proof Verification Flaw
Two deprecated, immutable Aztec rollup contracts were drained for a combined $4.35M in June 2026 by exploiting a mismatch between verified ZK proof public inputs and the calldata used to drive settlement — a bug class that immutability made impossible to patch.
ResupplyFi: $9.6M ERC-4626 First-Deposit Donation Attack
An attacker exploited a classic ERC-4626 vault donation vulnerability in ResupplyFi's wstUSR lending market 1.5 hours after deployment, collapsing the internal exchange rate and borrowing $10M reUSD against 1 wei of collateral.
Bonzo Lend $9.05M Oracle Exploit: Supra's BLS Verifier Accepted a Zeroed Signature
On July 11, 2026, Hedera's largest lending protocol lost $9.05M after Supra's on-chain oracle verifier passed a price update carrying a cryptographically empty BLS signature. The pairing check returned true for zeroed inputs because both sides reduced to the mathematical identity point — letting an attacker borrow millions against three dollars of collateral.
Research Disclosure: 4,224 Malicious EVM Contracts Spoof Wallet Simulation to Drain 5,742 Victims for $3.48M
Researchers disclosed on August 3, 2026 that 4,224 malicious smart contracts across four EVM chains manipulate transaction simulation output to show false safe results, tricking users into signing transactions that actually drain their approved tokens — bypassing wallet safety previews entirely.
SimGuard Research Exposes 4,224 Wallet-Simulation Phishing Contracts Across EVM Chains
A July 2026 academic preprint (publicly reported August 3) identified 4,224 smart contracts deployed across Ethereum, BNB Smart Chain, Avalanche, and Polygon that silently diverge from their wallet-simulator preview — tricking 5,742 victims out of at least $3.48 million. The attack pattern systematically exploits the semantic gap between `eth_call` simulation and live transaction execution.
DxSale $7.3M Exploit: EIP-7702 Batch Delegation Turns a Legacy BNB Chain Locker into a Mass Drain
On May 28-29, 2026, an attacker transferred ownership of DxSale's 2021 liquidity-locker contract, then used EIP-7702 batch delegation to drain more than 1,400 BNB Chain LP pools in a single transaction flow. A missing state-zero in the withdrawal function allowed repeated drainage of the same collateral.