A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.
Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit
Meter token prices crash after unauthorized mint
Meter paused the blockchain and bridge, and has urged people not to trade the token. They have warned that "Transactions after block 100731417 may not be honored", suggesting they are considering a blockchain rollback.
Meter suffered another bridge attack in February 2022, which amounted to $4.3 million.
Payy Network bridge fully drained of $1.8 million
Payy Network has halted all activity following the attack.
Duelbits crypto casino goes offline after $7 million theft
Bitget crypto exchange hacked for $388 million, pauses withdrawals
Bitget CEO Gracy Chen has said the company believes that a North Korean cybercrime group may be behind the theft. Bitget halted withdrawals shortly after the theft was noticed, citing the need to prevent attackers from stealing more assets. Bitget has said they have sufficient assets to cover the stolen funds.
Projects on the defunct Neutron chain lose $1.8 million to governance attack, Cosmos Hub halts chain
Neutron was paused shortly after the attack, and validators subsequently paused the entire Cosmos Hub network. Together, the pauses prevented the attacker from cashing out the entire amount, though they successfully made off with $1.8 million that they were able to bridge to Ethereum prior to the pause. Cosmos Hub remained paused for approximately 24 hours. During the pause, validators coordinated to move approximately 1.73 million ATOM from the attacker's wallet to a multi-signature wallet controlled by a group of companies operating network validators.
Single attacker steals $2.25 million from three crypto projects in the "Artificial Superintelligence Alliance"
Most of the profits came from stolen FET tokens, which are linked to Fetch.ai. The attacker was also able to perform unauthorized mints of various tokens, crashing their prices but earning the attacker little in the way of profits. Security researchers noticed that attackers stole assets from sixteen wallets spanning the three companies, suggesting they had significant access to all three companies' systems. Almost $290,000 was taken from a contract used for company payroll.
4,000 BTC (~$320 million) stolen from Liquid Network by claimed whitehats, 90% returned
The unauthorized transaction included a message reading "we are whitehats. contact us on chain", suggesting the possibility that the withdrawal was in fact well-intentioned security researchers aiming to "rescue" funds after discovering they were vulnerable and then return them to a secure wallet. After some back and forth, the attacker returned 3,400 BTC (~$272 million) keeping 600 BTC (~$48 million), likely as a "bounty".
More Markets exploited for $9.3 million
Crypto.com-affiliated Cronos blockchain halted after Tectonic theft
Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain — though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.
Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks
The losses are somewhat unusual because the neobanks describe themselves as self-custodial, which normally means that customers have total control over their crypto assets rather than storing them on a third-party platform. Normally, self-custody is more resilient to exploits like this, given that assets remain in user wallets. However, because these neobanks require customers to load funds they want to be able to spend into a third-party contract, they were vulnerable to the theft.
Moonwell loses $8.7 million to fourth exploit in less than a year
This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.
Term Finance loses $8.5 million to governance attack
The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.
Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.
KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure
KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.
BounceBit exploited for $3 million, announces shutdown and migration
BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.















