Some originally feared that the theft was enabled by an exploit on Hyperliquid itself, shortly after another Hyperliquid-based project was compromised, but the theft appears to have been a key leak rather than an exploit on the protocol.
Hyperliquid user loses $21 million to private key leak
Abracadabra loses more "Magic Internet Money" to third hack in two years
The project disclosed the theft, describing the exploit as affecting "some deprecated contracts". They downplayed the theft, saying they'd bought back the stolen assets using treasury funds.
Abracadabra previously suffered a $13 million theft in March 2025, and a $6.5 million theft in January 2024.
Futureverse announces restructuring two years after raising $54 million
As recently as this year, Futureverse was earning spots on "most innovative company" lists. In April, they announced they'd be acquiring Candy Digital, an NFT company created by Mike Novogratz, Gary Vaynerchuk, and others (which itself had raised a $100 million series A in 2021, and another funding round in 2023). "NFTs will be back in a big way one of these days", wrote Axios, covering the sale in April 2025.
But now, Futureverse has announced they've "made the difficult decision to begin a restructuring of the business". Focusing only on the AI portion of their business, and conspicuously omitting any mention of blockchains, NFTs, or metaverses, the company says they "recognize that adjustments are needed to ensure the long-term sustainability of our vision."
Futureverse locked comments on the post, likely to try to dodge angry community members who accused the company of stealing from them or rug-pulling.
Hyperdrive lending protocol exploited for $782,000
Hyperdrive paused all markets while investigating the vulnerability, and patched the bug. They also compensated those who had lost money in the exploit.
Hypervault rug pulls for $3.6 million
The project had attracted customers by advertising yields of 76–95%.
SBI Crypto likely suffers $21 million theft
SBI Crypto has not made any public statements addressing the apparent theft.
Griffin AI exploited for $3 million one day after launch
Griffin AI promises to allow customers to "build, deploy, and scale autonomous AI agents for crypto finance". These are essentially AI-powered bots that perform various functions — some of Griffin's advertised examples include a "robo-adviser" to provide "tailored investment strategies", and bots to do arbitrage trading or manage staked assets.
Seedify launchpad project suffers bridge exploit
Seedify has been a launchpad for blockchain games, NFT projects, and other web3 products. The team recently has embraced "vibe coding" — a practice in which people rely heavily on AI to generate code.
UXLINK exploited for around $28 million, then hacker gets phished
Shortly after the hack, the attacker apparently approved a phishing contract, perhaps in their rush to swap tokens before the price crashed further or before exchanges could freeze the tokens. Around 542 million of the UXLINK tokens were sent to a phishing address as a result, though it doesn't appear the phishing wallet has been able to sell the tokens.
Yala stablecoin depegs after $7.6 million theft
Despite the project's attempted reassurances, the YU stablecoin lost its $1 peg, plummeting as low as around $0.20. As of writing, about a day later, the stablecoin is still well below its peg, at around $0.94.
Shibarium bridge hit with $2.4 million flash loan attack
The project has paused staking on the network, freezing the BONE tokens borrowed by the attacker, which may limit the attacker's profits.
Thorchain founder exploited for $1.35 million
Later that week, Thorbjornsen apparently suffered another loss — this one confirmed on-chain to be around $1.35 million.
According to crypto sleuth zachxbt, the attackers appeared to be a part of North Korean crypto hacking operations. "JP is one of the people whose has greatly benefited financially from the laundering of DPRK hacks/exploits. So it’s a bit poetic he got rekt here by DPRK," he wrote.
$41.5 million stolen from SwissBorg in Kiln API exploit
SwissBorg announced that they would be reimbursing impacted customers using treasury funds, and working with security firms and law enforcement to try to recover the stolen assets.
Massive NPM supply chain attack puts crypto transactions at risk
strip-ansi
or determine if a variable is-arrayish
. Altogether, the packages get around two billion downloads per week, and the compromise is being called the "largest supply chain attack in history".Once the malicious code is injected, it then intercepts network traffic and API calls, scanning for cryptocurrency transactions across numerous blockchains. When a network request is made to transfer crypto, the malicious code intercepts it and replaces the destination with wallets controlled by the attackers.
Various prominent people in crypto have warned about the attack, with Ledger CTO Charles Guillemet tweeting: "If you use a hardware wallet, pay attention to every transaction before signing and you're safe. If you don't use a hardware wallet, refrain from making any on-chain transactions for now."
Ultimately, the exploit was not very financially successful, with reports that less than $1,000 was stolen.
Nemo Protocol exploited for $2.4 million
Venus Protocol user exploited for $13.5 million; most funds later recovered
Venus paused the protocol as they investigated the theft. The project then proposed a vote to force liquidation of the attacker's wallet and recover the stolen funds.
Bunni decentralized exchange exploited for $8.4 million
Reddit shuts down its NFT avatars project
Reddit has ended submissions for new avatars, and will shut down its avatar shop, collection display on profiles, and NFT wallet feature.
The feature is apparently so unused that the shutdown announcement garnered zero comments in the r/CollectibleAvatars subreddit. Besides posts relating to the shutdown, the most recent post in the subreddit was a year old.
This is the second blockchain-based feature Reddit has sunset, following the October 2023 decision to end their "Community Points" feature.
- "Closing up (the) Shop", post on r/CollectibleAvatars [archive]
BetterBank exploited, some funds returned
The vulnerable smart contract had been audited by cybersecurity firm Zokyo, which claimed they had flagged the issue during an audit. BetterBank responded by claiming that the auditors had either not identified or failed to communicate the true severity of the flaw.
Bitcoiner socially engineered out of $91 million
BtcTurk apparently hacked again, for $49 million
This is the second BtcTurk exploit, following an approximately $55 million theft in June 2024.