TOPIC ARCHIVE

Web3

Selected Web3 developments from public primary sources.

P0
SlowMist Hacked

AFX Bridge hacked — $24.15M lost

The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for…

P0
SlowMist Hacked

Ostium hacked — $18.00M lost

Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draini…

P0
SlowMist Hacked

BonkDAO hacked — $20.00M lost

BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contr…

P0
SlowMist Hacked

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P0
SlowMist Hacked

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P0
SlowMist Hacked

Wanchain Cardano-BNB Chain Bridge hacked — $10.00M lost

Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspe…

P1
SlowMist Hacked

Bonzo Lend hacked — $9.05M lost

Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The bo…

P1
SlowMist Hacked

WEMIX hacked — $6.25M lost

The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before be…

P1
Rekt News

BonkDAO - Rekt

$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighte…

P1
SlowMist Hacked

Verus Ethereum Bridge hacked — $7.54M lost

The Verus Ethereum Bridge was exploited again. The attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, draining approximately $7.54 million in assets (ETH, tBTC, USDC, etc.) from the bridge reserves.…

P1
Rekt News

Bonzo Finance - Rekt

Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.

P1
Rekt News

Summer Finance - Rekt

$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.

P1
SlowMist Hacked

Lazy Summer Protocol hacked — $6.04M lost

Lazy Summer Protocol (under Summer.fi) USDC vaults were exploited due to NAV/share price calculation flaw. The attacker used flash loans and pre-accumulated overvalued Silo tokens to inflate vault NAV (~9.5%), redeeming at inflated price a…

P1
SlowMist Hacked

Allbridge Core hacked — $1.65M lost

Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $…

P1
Rekt News

SecondFi - Rekt

A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already…

P1
SlowMist Hacked

SecondFi hacked — $2.40M lost

SecondFi (formerly Yoroi) Cardano wallet suffered an exploit due to a vulnerability in its proprietary web wallet generation software, exposing private keys at the address level. Attackers drained ~16 million ADA ($2.4M) from 374 affected…

P1
SlowMist Hacked

Taiko Bridge hacked — $1.70M lost

On June 21-22, 2026, Taiko (an Ethereum L2) suffered a bridge exploit targeting its ERC20 Vault. Attackers exploited a compromise in the chain state verification mechanism by forging SGX proofs to register a malicious prover, bypassing ver…

P1
SlowMist Hacked

MEV Bot hacked — $7.50M lost

The MEV bot operated by JaredFromSubway.eth was drained of approximately $7.5 million. Attackers deployed fake token wrappers and liquidity pools to trick the bot’s automated MEV execution system into granting token approvals to attacker-c…

P1
Rekt News

Secret Network - Rekt

$4.67 million lost from Secret Network’s bridge connection to Axelar Network after a forked Secret-side IBC contract minted unbacked tokens from thin air. 2 missing validation checks let an attacker forge deposits with a fake Cosmos chain.…

P1
Rekt News

AFX Trade - Rekt

Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.

P1
SlowMist Hacked

Polymarket hacked — $3.10M lost

Polymarket suffered a third-party supply chain attack where hackers injected a malicious script into the platform's frontend, draining approximately $3.1 million in PUSD from 11 user wallets. Funds were moved from Polygon to Ethereum. Poly…

P1
Rekt News

Aztec Connect - Rekt

$2.28 million drained from Aztec Connect on June 14th, a deprecated ZK-rollup built by Aztec Labs, across two consecutive days. The ZK proof and settlement layer processed different transaction sets, attackers exploited the gap to mint unb…

P1
Rekt News

Aztec Bridge - Rekt

One deprecated contract, one flawed escape hatch circuit, and a verifier that should have been retired years earlier. Aztec’s legacy rollup contract lost roughly $2.198 million after a ZK proof passed a broken root-binding check.

P1
SlowMist Hacked

LABUBU/OLPC hacked — $1.10M lost

The OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited, resulting in approximately $1.1 million in losses. The attacker exploited a logic vulnerability in the OLPC token contract’s _update function. Approximately 46 day…

P1
Rekt News

Zunami Protocol - Case File

Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still movi…

P1
Rekt News

Humanity Protocol - Rekt

Seven keys on one laptop handed an attacker $36.4 million from Humanity Protocol across Ethereum and BSC. Rare for its kind, the owner of the compromised device was publicly named. The code wasn't broken. The key management was, and nobody…