Back to Site

🔐 Smart Contract Incidents

Analysis of the latest 10 major incidents in DeFi and smart contracts

KelpDAO (rsETH) — LayerZero Bridge Exploit

April 2026
$292,000,000

On April 18, 2026, an attacker minted ~116,500 unbacked rsETH (~$292–293M, ~18% of supply) by abusing KelpDAO’s LayerZero bridge verification. Industry analysis points to RPC poisoning against a 1-of-1 DVN setup: the bridge accepted a forged burn message and released tokens with no real backing. The attacker immediately posted rsETH as collateral on Aave markets and borrowed large amounts of WETH, creating major bad debt before emergency freezes. DeFi TVL dropped sharply afterward. Preliminary attribution links the campaign to Lazarus/TraderTraitor. The incident shows DeFi risk shifting from Solidity bugs toward bridge ops and verifier configuration.

Vulnerability Type
Bridge / RPC Poisoning
Severity
Critical
Blockchain
Ethereum, Arbitrum

Drift Protocol — Administrative Key Compromise

April 2026
$285,000,000

On April 1, 2026, Solana-based Drift Protocol lost about $285M after attackers obtained administrative control. Public reporting describes a long-running social-engineering campaign; the contracts executed privileged actions that looked “authorized.” This is one of 2026’s largest losses driven by key/credential theft rather than a classic smart-contract bug. The case reinforces hardware multisigs, timelocks on admin actions, and strict privilege separation in DeFi ops.

Vulnerability Type
Key / Admin Compromise
Severity
Critical
Blockchain
Solana

Cetus Protocol — CLMM Integer Overflow

May 2025
$223,000,000

On May 22, 2025, Sui DEX Cetus lost ~$223M due to a flawed overflow check in its liquidity math library (checked_shlw). By manipulating tick/liquidity parameters, the attacker minted a massive LP position with a near-1-token deposit and drained pools. Sui validators froze ~$162M; Cetus later relaunched using recovered funds, treasury, and a Sui Foundation loan, restoring most LP liquidity. Remaining stolen assets were bridged/laundered off-chain. A textbook critical math bug in concentrated-liquidity contracts.

Vulnerability Type
Integer Overflow
Severity
Critical
Blockchain
Sui

Resolv Labs — Infrastructure Compromise

March 2026
$80,000,000

In March 2026, Resolv Labs suffered an ~$80M incident tied primarily to operational/key compromise rather than a classic public-contract reentrancy. It fits the broader 2026 pattern where stolen credentials and infrastructure attacks dominate dollar losses. Aftermath discussions focused on privileged-role monitoring, incident response playbooks, and reserve/insurance coverage for users.

Vulnerability Type
Operational / Key Compromise
Severity
Critical
Blockchain
Ethereum

Balancer V2 — Rounding Bug in Composable Stable Pools

November 2025
$128,000,000

On November 3, 2025, Balancer disclosed a multi-chain exploit against V2 Composable Stable pools. A rounding discrepancy in pool math let an attacker craft swaps that extracted value between internal accounting and real balances. Aggregate impact is estimated around $128M across affected networks. The case shows that even mature AMM contracts remain sensitive to precision bugs—and composability expands blast radius.

Vulnerability Type
Rounding / Pool Math
Severity
Critical
Blockchain
Ethereum + L2 / multi-chain

Euler Finance — Flash Loan & donateToReserves Logic Bug

March 2023
$197,000,000

On March 13, 2023, Ethereum lending protocol Euler lost about $197M. The attacker used a flash loan plus a logic gap around donateToReserves / liquidity checks to self-liquidate profitably and drain reserves. Nearly all funds were later returned after negotiations—a rare outcome at this scale. The incident became a reference case for lending-math audits and defenses against artificial insolvency.

Vulnerability Type
Flash Loan / Logic Bug
Severity
Critical
Blockchain
Ethereum

Multichain — Cross-Chain Infrastructure Compromise

July 2023
$126,000,000

In July 2023, cross-chain service Multichain saw mass asset withdrawals (~$125–130M+, with major losses on Fantom routes) amid a bridge halt and reports of operational key-control failures. The event coincided with the CEO’s arrest and concerns about centralized MPC/key custody. It destroyed trust in opaque bridge operators and accelerated migration toward transparent light-client / ZK bridges and stricter role separation.

Vulnerability Type
Bridge / Key Centralization
Severity
Critical
Blockchain
Multi-chain (Fantom et al.)

Curve Finance — Vyper Reentrancy Guard Compiler Bug

July 2023
$73,000,000

In July 2023, several Curve pools were drained because the reentrancy guard in Vyper compiler versions ~0.2.15–0.3.0 failed to protect as intended. Attackers extracted roughly $70–73M from affected pools; some funds returned via negotiations and bounties. The root cause was the toolchain, not Curve’s business logic—driving stricter compiler pinning and formal verification for critical pools.

Vulnerability Type
Compiler / Reentrancy
Severity
Critical
Blockchain
Ethereum

Orbit Chain — Bridge Multisig Compromise

January 2024
$81,000,000

In January 2024, Orbit Chain’s bridge was attacked for about $81M. Public analyses indicate attackers obtained enough signing power to authorize malicious withdrawals from the bridge vault—a classic weak/compromised cross-chain multisig scenario. Funds moved quickly through mixers and exchanges. The case reinforced higher signing thresholds, hardware keys, and real-time monitoring of anomalous bridge withdrawals.

Vulnerability Type
Bridge Multisig Compromise
Severity
Critical
Blockchain
Orbit / multi-chain

Radiant Capital — Malware Targeting Hardware Multisig

October 2024
$53,000,000

In October 2024, lending protocol Radiant Capital lost roughly $50–56M. Investigations pointed to malware that intercepted hardware-wallet multisig signing sessions: signers approved malicious transactions believing they were legitimate. This was operational compromise of privileged roles, not a classic Solidity bug. Aftermath guidance emphasized air-gapped processes, calldata verification off the infected host, and least-privilege policies.

Vulnerability Type
Malware / Multisig UX
Severity
Critical
Blockchain
Arbitrum / BSC / multi-chain

KyberSwap Elastic — CLMM Precision / Tick Exploit

November 2023
$48,000,000

In November 2023, KyberSwap Elastic suffered an ~$47–48M exploit tied to rounding/tick handling in concentrated liquidity. The attacker manipulated pool state to extract value during swaps/liquidity operations. It continues the CLMM incident pattern (later echoed by Cetus) and underscores differential testing of AMM math libraries and pool invariants.

Vulnerability Type
CLMM Precision Bug
Severity
Critical
Blockchain
Ethereum / multi-chain

Penpie (Magpie) — Pendle Yield Integration Exploit

September 2024
$27,000,000

In September 2024, Penpie (Magpie/Pendle ecosystem) lost about $27M due to a vulnerability in yield-position / pool logic. The attack shows how composite DeFi products can expose collateral and rewards through a single integration-layer flaw. The team worked on containment and user communication; the case is a key audit lesson for “overlay” protocols built on Pendle-like primitives.

Vulnerability Type
Yield / Integration Logic
Severity
Critical
Blockchain
Ethereum / Arbitrum

GMX — Perpetual DEX Exploit

2025
$42,000,000

In 2025, perpetual DEX GMX appeared among the year’s largest on-chain losses (~$42M in industry tallies). The attack touched position/liquidity economics typical of perp DEXs—pricing, open interest, or related contract pathways. It reinforces oracle design, OI limits, and liquidation stress testing on derivative DeFi venues.

Vulnerability Type
Perp DEX / Economic Exploit
Severity
Critical
Blockchain
Arbitrum / multi-chain

Poly Network — Cross-Chain Exploit (2021)

August 2021
$611,000,000

Poly Network, a cross-chain protocol, fell victim to one of the largest attacks in DeFi history. The attacker exploited a vulnerability in the cross-chain manager function, allowing them to gain control over private keys and withdraw funds from three blockchains: Ethereum, Binance Smart Chain, and Polygon. The attack was possible due to insufficient input validation in the function responsible for validating transactions between blockchains. The attacker was able to forge signatures and bypass the security system, leading to the theft of over 600 million dollars in various cryptocurrencies. After the attack, the Poly Network team appealed to the attacker to return the funds, and most of the funds were returned. The incident demonstrated the critical importance of security auditing for cross-chain protocols and the need for stricter checks in smart contract code.

Vulnerability Type
Reentrancy Attack
Severity
Critical
Blockchain
Ethereum, BSC, Polygon

Wormhole Bridge - Signature Exploitation

February 2022
$325,000,000

Wormhole, a popular bridge between blockchains, was attacked, resulting in the theft of 325 million dollars. The attacker exploited a vulnerability in the signature validation system, allowing them to create fake transactions and withdraw funds from the protocol. The problem was that the system did not properly verify the authenticity of validator signatures, allowing the attacker to bypass security mechanisms. The attack was particularly devastating because Wormhole is one of the main bridges between Ethereum and Solana, and many DeFi protocols rely on its security. After the incident, the Wormhole team received financial support from Jump Crypto to cover losses, but the reputational damage was significant. This case highlighted the importance of thorough auditing of validation systems and the need for stricter checks in cross-chain protocols.

Vulnerability Type
Signature Validation
Severity
Critical
Blockchain
Ethereum, Solana

Ronin Network - Private Key Compromise

March 2022
$625,000,000

Ronin Network, the blockchain for the game Axie Infinity, was attacked, resulting in the theft of 625 million dollars. The attackers gained access to the private keys of network validators, allowing them to sign fraudulent transactions and withdraw funds from the bridge between Ethereum and Ronin. The attack was possible due to insufficient infrastructure security and social engineering. The attackers were able to gain access to four of the nine network validators, giving them control over the majority of votes in the consensus system. This incident demonstrated the vulnerability of systems based on multisignature when security depends on human factors. After the attack, Ronin Network switched to a more secure validation system and increased the number of validators, but the damage to the Axie Infinity ecosystem was significant.

Vulnerability Type
Private Key Compromise
Severity
Critical
Blockchain
Ethereum, Ronin

Nomad Bridge - Message Validation Vulnerability

August 2022
$190,000,000

Nomad Bridge, a cross-chain protocol, was attacked, resulting in the theft of 190 million dollars. The attackers used a vulnerability in the message validation system, allowing them to create fake transactions and withdraw funds from the protocol. The problem was that the system did not properly verify message hashes and their signatures, making it possible to create fraudulent transactions. The attack was particularly devastating because many users lost their funds, and trust in cross-chain protocols was undermined. After the incident, Nomad Bridge suspended operations and began the recovery process, but many users were unable to recover their funds. This case highlighted the importance of thorough auditing of validation systems and the need for stricter checks in cross-chain protocols.

Vulnerability Type
Message Validation
Severity
Critical
Blockchain
Multiple

Beanstalk Farms - Flash Loan Attack

April 2022
$182,000,000

Beanstalk Farms, a DeFi protocol for stablecoins, was attacked, resulting in the theft of 182 million dollars. The attacker used a flash loan to gain temporary control over a large number of governance tokens, allowing them to vote for a malicious proposal that withdrew all funds from the protocol. The attack was possible due to shortcomings in the protocol governance system and lack of protection against flash loan attacks. The attacker was able to bypass security mechanisms and gain control over the protocol for a short time, but this was enough to steal all funds. After the attack, Beanstalk Farms suspended operations and began the recovery process, but many users lost their investments. This incident demonstrated the importance of protection against flash loan attacks in DeFi protocols.

Vulnerability Type
Flash Loan Attack
Severity
Critical
Blockchain
Ethereum

Harmony Bridge - Multisignature Compromise

June 2022
$100,000,000

Harmony Bridge, a cross-chain protocol, was attacked, resulting in the theft of 100 million dollars. The attackers gained access to the private keys of multisignature validators, allowing them to sign fraudulent transactions and withdraw funds from the bridge. The attack was possible due to insufficient infrastructure security and social engineering. The attackers were able to gain access to two of the five validators, giving them control over the multisignature system. This incident demonstrated the vulnerability of systems based on multisignature when security depends on human factors and physical infrastructure security. After the attack, Harmony Bridge suspended operations and began the recovery process, but many users lost their funds.

Vulnerability Type
Multisig Compromise
Severity
Critical
Blockchain
Ethereum, Harmony

Wintermute - Smart Contract Vulnerability

September 2022
$160,000,000

Wintermute, a major cryptocurrency trading firm, lost 160 million dollars due to a vulnerability in a smart contract. The problem was in the incorrect implementation of a function that allowed attackers to access funds without proper authorization. The vulnerability was that the smart contract did not properly verify access rights and allowed critical operations to be performed without necessary permissions. The attackers were able to exploit this vulnerability and withdraw funds from the contract. After discovering the attack, Wintermute suspended operations and began an investigation, but the damage was significant. This incident demonstrated the importance of thorough security auditing for all smart contracts, especially those managing large amounts of funds.

Vulnerability Type
Access Control
Severity
Critical
Blockchain
Ethereum

Mango Markets - Price Manipulation

October 2022
$117,000,000

Mango Markets, a DeFi protocol on Solana, was attacked, resulting in the theft of 117 million dollars. The attacker used price manipulation to exploit a vulnerability in the collateral system. The attacker was able to artificially inflate the price of the MNGO token, allowing them to obtain large loans against collateral and then withdraw funds from the protocol. The vulnerability was that the system did not have sufficient protection against price manipulation and allowed the use of inflated prices for obtaining loans. After the attack, the attacker offered to return some funds in exchange for immunity from prosecution, which caused controversy in the community. This incident demonstrated the importance of protection against price manipulation in DeFi protocols.

Vulnerability Type
Price Manipulation
Severity
Critical
Blockchain
Solana

Rari Capital - Reentrancy Attack

May 2021
$80,000,000

Rari Capital, a DeFi lending protocol, was attacked, resulting in the theft of 80 million dollars. The attacker exploited a vulnerability in the smart contract that allowed repeated function calls before the initial transaction was completed. This allowed the attacker to repeatedly withdraw funds from the protocol within a single transaction. The vulnerability was that the contract did not use the checks-effects-interactions pattern and did not check the state before performing critical operations. After the attack, Rari Capital suspended operations and began the recovery process, but many users lost their funds. This incident demonstrated the importance of protection against reentrancy attacks in smart contracts.

Vulnerability Type
Reentrancy Attack
Severity
Critical
Blockchain
Ethereum

Cream Finance - Flash Loan Attack

October 2021
$130,000,000

Cream Finance, a DeFi lending protocol, was attacked, resulting in the theft of 130 million dollars. The attacker used a flash loan to gain temporary control over a large number of tokens, allowing them to exploit a vulnerability in the protocol's pricing system. The attack was possible due to shortcomings in the price determination mechanism and lack of protection against liquidity manipulation. The attacker was able to artificially inflate the price of a specific token, allowing them to obtain large loans against collateral and then withdraw funds from the protocol. After the attack, Cream Finance suspended operations and began the recovery process, but many users lost their investments. This incident demonstrated the importance of protection against flash loan attacks and price manipulation in DeFi protocols.

Vulnerability Type
Flash Loan Attack
Severity
Critical
Blockchain
Ethereum