🔥 Security incidents
Documented hacks, exploits, and security events with disclosure timelines.
Summary
Attacker exploited a reentrancy vulnerability in the staking contract to drain approximately $47 million worth of assets across three chains.
The vulnerability was introduced in contract upgrade v2.1.0 deployed 45 days ago. The attacker used flash loans to amplify the attack.
Quick facts
Affected
Affected accounts
📋 Disclosure timeline
Attacker deploys malicious contract and initiates flash loan on Ethereum.
Attacker bridges to Arbitrum and Polygon, drains additional $24M.
X user @SecurityResearcher posts warning thread.
DeFiProtocol team acknowledges incident, pauses remaining contracts.
Team working with security firms and law enforcement.
Recent incidents
Private key for Project Alpha's deployer wallet was accidentally committed to a public GitHub repo. Contract admin access is at risk. White hat researchers are attempting rescue.
Security researcher discovered critical vulnerability in marketplace contract. Funds rescued via white hat operation. Bounty of $250K paid.
Anonymous team behind MoonRocket token drained liquidity pool after 3 months of operation. Multiple warning signs were present from launch.
Attacker manipulated on-chain oracle to perform undercollateralized borrows. Protocol treasury covered losses. Oracle upgraded to Chainlink.