Bitcoin Depot is the largest operator of crypto ATMs globally and in the United States, with approximately 8,700 kiosks in the US and 9,200 worldwide.
Bitcoin Depot hacked for $3.67 million
- SEC Form 8-K filed by Bitcoin Depot Inc. on April 6, 2026
- Top Crypto ATM Operators, Coin ATM Radar
Drift exploited for $285 million
The project later described the exploit as "a novel attack involving durable nonces, resulting in a rapid takeover of Drift's Security Council administrative powers." Once the attacker had access to admin capabilities, they quickly eliminated risk management limits on the protocol and drained huge quantities of tokens, which they swapped to USDC and then ETH. The attack was attributed to extremely sophisticated social engineering, likely by North Korean hackers.
Some have criticized USDC's issuer, Circle, for not freezing the stolen funds during the six hours they were held in USDC. Unlike ETH, USDC is controlled by a centralized company that can, and regularly does, freeze assets determined to have been stolen or connected to illicit activity.
The theft is among the largest in defi history.
Moonwell faces $1 million governance attack
Ultimately, facing being outvoted, the attacker dumped their MFAM holdings and the proposal was canceled as their balance had fallen below the proposal threshold.
This was only the most recent of Moonwell's troubles after the protocol suffered a $1.78 million loss in February due to an oracle misconfiguration and a $3.7 million loss in November 2025.
- Attack proposal, Moonwell governance [archive]
- Tweet thread by Blockful [archive]
Balancer Labs shuts down after $110 million hack
Balancer co-founder Fernando Martinelli has said he strongly considered shutting down the protocol entirely, but ultimately decided to continue the project as it generates a relatively small amount of revenue. Instead, the project will move to being operated by a DAO and operating company, which Martinelli hopes will allow them to dodge "real and ongoing legal exposure" and "the liability of past security incidents".
Although another Balancer co-founder has optimistically presented this as "the start of a better chapter" for Balancer, it remains to be seen whether a skeleton crew will be able to revive the project.
USR stablecoin depegs in $24 million exploit
An exploiter took advantage of a flaw in USR's minting code to create tens of millions of USR tokens without depositing any assets to back them. The attacker then sold the unbacked USR, crashing the stablecoin's price to as low as $0.14. The attacker has profited at least 11,400 ETH (~$24 million), though they are still selling.
Some defi protocols paused USR-exposed strategies to avoid downstream impacts. Resolv issued a statement that the token's collateral pool was unaffected, though this is likely little comfort for those who purchased the unbacked USR.
Venus Protocol accumulates $2.15 million in bad debt after exploit
While the exploit left the Venus Protocol with over $2 million in bad debt, it's not clear if the attacker even made money from the exploit. The exploiter's position was ultimately liquidated, collapsing the increase in THE price. However, it's possible the exploiter took advantage of the price discrepancy elsewhere to profit.
The Venus Protocol has had a number of issues in the past — notably in June 2023, when the team developing the BNB Chain had to intervene when the a thief borrowed $150 million on Venus against stolen tokens and then faced liquidation.
BlockFills goes bankrupt
BlockFills was backed by investors including Susquehanna and CME Ventures.
- Chapter 11 Voluntary Petition, Reliz Technology Group Holdings Inc.
Trader loses almost $50 million in Aave swap gone wrong
The Aave founder offered to refund the user the $600,000 in fees collected from the transaction, and acknowledged "there are additional guardrails the industry can build to better protect users".
$26.9 million erroneously liquidated on Aave after Chaos Labs oracle bug
Chaos Labs, presumably embarrassed to have lived up to its name, promised to reimburse users whose positions were improperly liquidated.
Thief pilfers NFTs priced at $230,000 from Gondi
According to Gondi, the exploiter took advantage of functionality that allowed users to sell their NFTs to automatically repay loans.
Gondi has said it has reimbursed customers by buying them "comparable items" from the same collections as their stolen NFTs, although it seems questionable that this will satisfy customers who purchased products whose whole selling point is that they aren't interchangeable.
Solv Protocol exploited for $2.7 million
Returned crypto stolen again from Korean authorities
Crypto stolen from Korean authorities after they post wallet seed phrase
The blunder was likely due to the authorities' lack of knowledge about cryptocurrency. The move was somewhat akin to authorities publicly posting a username and password for a criminal's bank account — though that would likely be an easier mistake to unwind.
- "$4.8M in crypto stolen after Korean tax agency exposes wallet seed", Bleeping Computer [archive]
Step Finance, SolanaFloor, and Remora Markets shut down after January hack
According to Step Finance, "we explored every possible path forward, including financing and acquisition opportunities. Unfortunately, we were unable to secure a viable outcome and have made the difficult decision to end all operations effective immediately."
In reply to Step Finance's announcement, crypto investor Mike Dudas claimed that the project had contacted him about bridge financing, but that Step had never responded to his request for more information about the hack. "i responded: 'would need to see the security post mortem before i could consider investing here' <crickets>"
YieldBlox lending pool drained of $10.2 million
The attacker was able to manipulate the oracle price to show that USTRY was priced at $100 (rather than its actual trading price of around $1.05). Then, they borrowed against the overvalued asset, withdrawing XLM and USDC priced at $10.2 million. However, around 48 million of the stolen XLM (~$7.2 million) were frozen.
IoTeX bridge exploited for $2 million after private key compromise
Blockchain security researcher Specter has suggested there may be links between this attack and a $50 million theft from the Infini "stablecoin neobank" a year ago.
Goliath Ventures CEO charged with running $328 million Ponzi scheme
- Goliath Ventures - United States v. Christopher Alexander Delgado, US Attorney's Office for the Middle District of Florida
South Korean prosecutors lose $22 million of seized crypto to the wallet inspector, later recover it
On February 19, the office announced they had recovered the stolen assets and identified the thief.
Moonwell lending protocol suffers $1.78 million loss after second oracle misconfiguration in four months
This is the second time Moonwell has suffered a loss thanks to an oracle misconfiguration. In November 2025, the platform was left with almost $3.7 million in bad debt after a different asset was mispriced.
Although the vulnerable pull requests were at least partially developed by an AI tool, the security auditor who initially attributed the vulnerability to Claude Opus 4.6 later softened his criticism, noting that even senior developers could have made the same mistake. He did, however, criticize the project for a lack of sufficiently rigorous testing that should have caught the issue.
BlockFills crypto lender halts withdrawals
Platforms limiting or halting withdrawals — particularly lending platforms — is reminiscient of the 2022 crypto crash, when falling crypto prices exposed crypto firms that had been engaging in highly risky or sometimes illegal behavior. As crypto prices fell, firms were unable to meet their loan obligations or faced margin calls, and the tightly interconnected web of lending within the crypto ecosystem often meant that one company failure cascaded into multiple more. It remains to be seen whether this is an isolated incident or the beginning of a trend as crypto prices hit revisit price lows not seen in over a year.
BlockFills claims to have more than 2,000 institutional clients globally, and boasted of facilitating more than $61 billion in transactions in 2025. The company's backers include Susquehanna Capital and CME Ventures.
Bithumb accidentally gives away $44 billion to customers
The exchange announced that they had recovered 99.7% of the erroneously awarded tokens, leaving around 1,860 BTC (~$130 million) unaccounted for.
The incident has drawn further scrutiny from Korean regulators, who said that the error "has exposed the vulnerabilities and risks of virtual assets." Regulatory agencies in the country had already been cracking down on crypto firms following a $30 million hack of the Upbit crypto exchange in November 2025.
Gemini crypto exchange fires 25% of staff, blames AI
As many companies do these days, the Winklevosses tried to pin the layoffs on AI, claiming that the engineers using AI are ten times more productive. "A smaller organization, leveraging the right tools, isn't just more efficient, it's actually faster," they wrote — in a blog post that itself reeks of AI.
CrossCurve users exploited for around $3 million
CrossCurve took a conciliatory tone in on-chain messages sent to the thief, writing, "These tokens were wrongfully taken from users due to a smart contract exploit. We do not believe this was intentional on your part, and there is no indication of malicious intent." (Who among us hasn't accidentally stolen millions of dollars?) However, they warned, they planned to escalate to working with law enforcement and blockchain security firms to investigate and prosecute the theft if the funds were not returned within 72 hours.
$29 million stolen from from Step Finance treasury wallets
Aperture Finance users lose at least $3.4 million
Aperture has said they disabled portions of their web app impacted by the bug, and are working to try to trace and recover stolen funds.
$13.43 million stolen from Matcha Meta users in SwapNet exploit
Most of the lost funds came from a single user, who lost $13.34 million in assets. Other users lost a combined $90,000.
- "SwapNet Incident Post Mortem", Matcha Meta
Thief of millions in seized U.S.-controlled crypto alleged to be government crypto contractor's son
zachxbt has alleged that "Lick" is a man named John Daghita. After reporting Daghita's identity, "Lick" appeared to try to scrub his Telegram account, then dusted zachxbt's public crypto wallet from one of the theft addresses.
Daghitia is reportedly the son of Dean Daghita, the owner of Command Services & Support (CMDSS). In October 2024, CMDSS landed a contract with the US Marshals to manage seized crypto assets, which is still active. After zachxbt linked the younger Daghita to his father and CMDSS, CMDSS also scrubbed its online presence. Around that time, Lick began trolling zachxbt again, and later sent 0.6767 ETH (~$1,900) of the stolen funds to zachxbt.
CMDSS' website boasts that they are "a proven provider of mission-critical services to the Department of Defense and Department of Justice".
Saga halts blockchain after $7 million theft
The Saga Dollar token lost its peg and fell to around $0.75 after the attack.
Former NYC Mayor Eric Adams accused of rug pull as NYC Token crashes
He launched the project on January 12, and buyers piled in in hopes of being early to a high-profile crypto token endorsed by a public figure. However, within hours, the team began pulling liquidity as the price peaked, extracting around $2.5 million. As the price began to fall, the team added back around $1.5 million, leaving around $1 million unaccounted for.
Additionally, on-chain researchers observed at least one wallet that spent almost $750,000 to purchase around 1.5 million $NYC around 10 minutes before the token was publicly announced, leading to speculation around insider trading. However, because of the token price crash after the team began pulling liquidity, the apparent insider ultimately lost around $500,000.
People were quick to accuse Adams, or his unidentified crypto team, of rug-pulling buyers. Adams and the project's social media account have claimed that the team was simply moving or "rebalanc[ing]" liquidity, though they have not yet offered any explanation as to where the missing $1 million went.
- Tweet by RuneCrypto_ [archive]
- Tweet thread by Bubblemaps [archive]
- Tweet by NYC Token [archive]
- Tweet thread by Bubblemaps [archive]
- Wallet on Solscan [archive]
- "Pitching Crypto and Needling Mamdani: Adams’s Post-Mayoralty Takes Shape", New York Times [archive]
- "Former 'bitcoin mayor' Eric Adams faces $3 million rugpull allegation after issuing NYC Token", CoinDesk [archive]
Crypto holder loses $283 million to scammer impersonating wallet support
Around $700,000 of the stolen assets were frozen thanks to intervention by a security firm called ZeroShadow, although this represents only 0.2% of the total loss.
Truebit exploited for over $26 million
Truebit acknowledged the hack and urged users not to interact with the vulnerable smart contract.






















