Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

Term Finance loses $8.5 million to governance attack

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

BounceBit exploited for $3 million, announces shutdown and migration

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

Coinsbuy exploited for $8 milllion

The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.

Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.

Proof of Attendance Protocol (POAP) shuts down

Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.

The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.

Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."

MVMT Labs files for bankruptcy

MVMT Labs, the company behind the Movement blockchain, has filed for bankruptcy, reporting assets of between $100,001 and $500,000 against liabilities of between $1 million and $10 million. The largest unsecured claim, at more than $1.6 million, belongs to co-founder Rushi Manche — whom the company fired in May 2025 after an investigation into the MOVE token launch.

Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.

The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.

Taiko bridge exploited

The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.

Highly active MEV bot known as jaredfromsubway.eth drained for $7.7 million

On blockchains like Ethereum, a strategy known as "MEV" (short for "maximal extractable value") allows intermediaries to profit from manipulating the structure of blocks added to the chain — often reordering or "sandwiching" transactions in ways that extract profits. Automated software known as MEV bots make a business out of this strategy, and one of the most active is a bot called jaredfromsubway.eth — likely so named after one-time Subway spokesman and convicted sex offender Jared Fogle because of its strategy of "sandwiching" transactions by placing trades on both sides, causing the original trader to pay more.

On June 20, an attacker used a series of contracts to cause the bot to grant token approvals that were later used to drain 4,427 ETH ($7.7 million). Some of the funds were then laundered through Tornado Cash.

Aztec Connect hacked for a second time in less than a week

Three days after Aztec Labs' deprecated Aztec Connect blockchain bridge was exploited for $2.1 million, the project has been hacked again for the same amount. Aztec Labs confirmed the second exploit, again trying to emphasize that the code was deprecated four years ago.

The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.

Deprecated project Aztec Connect exploited for $2.1 million

Aztec Connect, an abandoned defi privacy bridge from Aztec Labs, was drained of $2.1 million after an attacker exploited a bug in the project's smart contracts. Although the project was deprecated three years ago, funds remained in the legacy system. "Aztec Labs holds no admin keys or control over the system; it cannot be paused or upgraded by us," the project posted on social media.

The theft is only the latest in a string of attacks targeting vulnerable legacy smart contracts, many of which cannot be deleted, paused, or changed due to blockchains' immutable nature. Raydium and DxSale are two other platforms that have recently suffered losses due to old, insecure code.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.