Analysis of the latest 10 major incidents in DeFi and smart contracts
On April 18, 2026, an attacker minted ~116,500 unbacked rsETH (~$292–293M, ~18% of supply) by abusing KelpDAO’s LayerZero bridge verification. Industry analysis points to RPC poisoning against a 1-of-1 DVN setup: the bridge accepted a forged burn message and released tokens with no real backing. The attacker immediately posted rsETH as collateral on Aave markets and borrowed large amounts of WETH, creating major bad debt before emergency freezes. DeFi TVL dropped sharply afterward. Preliminary attribution links the campaign to Lazarus/TraderTraitor. The incident shows DeFi risk shifting from Solidity bugs toward bridge ops and verifier configuration.
On April 1, 2026, Solana-based Drift Protocol lost about $285M after attackers obtained administrative control. Public reporting describes a long-running social-engineering campaign; the contracts executed privileged actions that looked “authorized.” This is one of 2026’s largest losses driven by key/credential theft rather than a classic smart-contract bug. The case reinforces hardware multisigs, timelocks on admin actions, and strict privilege separation in DeFi ops.
On May 22, 2025, Sui DEX Cetus lost ~$223M due to a flawed overflow check in its liquidity math library (checked_shlw). By manipulating tick/liquidity parameters, the attacker minted a massive LP position with a near-1-token deposit and drained pools. Sui validators froze ~$162M; Cetus later relaunched using recovered funds, treasury, and a Sui Foundation loan, restoring most LP liquidity. Remaining stolen assets were bridged/laundered off-chain. A textbook critical math bug in concentrated-liquidity contracts.
In March 2026, Resolv Labs suffered an ~$80M incident tied primarily to operational/key compromise rather than a classic public-contract reentrancy. It fits the broader 2026 pattern where stolen credentials and infrastructure attacks dominate dollar losses. Aftermath discussions focused on privileged-role monitoring, incident response playbooks, and reserve/insurance coverage for users.
On November 3, 2025, Balancer disclosed a multi-chain exploit against V2 Composable Stable pools. A rounding discrepancy in pool math let an attacker craft swaps that extracted value between internal accounting and real balances. Aggregate impact is estimated around $128M across affected networks. The case shows that even mature AMM contracts remain sensitive to precision bugs—and composability expands blast radius.
On March 13, 2023, Ethereum lending protocol Euler lost about $197M. The attacker used a flash loan plus a logic gap around donateToReserves / liquidity checks to self-liquidate profitably and drain reserves. Nearly all funds were later returned after negotiations—a rare outcome at this scale. The incident became a reference case for lending-math audits and defenses against artificial insolvency.
In July 2023, cross-chain service Multichain saw mass asset withdrawals (~$125–130M+, with major losses on Fantom routes) amid a bridge halt and reports of operational key-control failures. The event coincided with the CEO’s arrest and concerns about centralized MPC/key custody. It destroyed trust in opaque bridge operators and accelerated migration toward transparent light-client / ZK bridges and stricter role separation.
In July 2023, several Curve pools were drained because the reentrancy guard in Vyper compiler versions ~0.2.15–0.3.0 failed to protect as intended. Attackers extracted roughly $70–73M from affected pools; some funds returned via negotiations and bounties. The root cause was the toolchain, not Curve’s business logic—driving stricter compiler pinning and formal verification for critical pools.
In January 2024, Orbit Chain’s bridge was attacked for about $81M. Public analyses indicate attackers obtained enough signing power to authorize malicious withdrawals from the bridge vault—a classic weak/compromised cross-chain multisig scenario. Funds moved quickly through mixers and exchanges. The case reinforced higher signing thresholds, hardware keys, and real-time monitoring of anomalous bridge withdrawals.
In October 2024, lending protocol Radiant Capital lost roughly $50–56M. Investigations pointed to malware that intercepted hardware-wallet multisig signing sessions: signers approved malicious transactions believing they were legitimate. This was operational compromise of privileged roles, not a classic Solidity bug. Aftermath guidance emphasized air-gapped processes, calldata verification off the infected host, and least-privilege policies.
In November 2023, KyberSwap Elastic suffered an ~$47–48M exploit tied to rounding/tick handling in concentrated liquidity. The attacker manipulated pool state to extract value during swaps/liquidity operations. It continues the CLMM incident pattern (later echoed by Cetus) and underscores differential testing of AMM math libraries and pool invariants.
In September 2024, Penpie (Magpie/Pendle ecosystem) lost about $27M due to a vulnerability in yield-position / pool logic. The attack shows how composite DeFi products can expose collateral and rewards through a single integration-layer flaw. The team worked on containment and user communication; the case is a key audit lesson for “overlay” protocols built on Pendle-like primitives.
In 2025, perpetual DEX GMX appeared among the year’s largest on-chain losses (~$42M in industry tallies). The attack touched position/liquidity economics typical of perp DEXs—pricing, open interest, or related contract pathways. It reinforces oracle design, OI limits, and liquidation stress testing on derivative DeFi venues.
Poly Network, a cross-chain protocol, fell victim to one of the largest attacks in DeFi history. The attacker exploited a vulnerability in the cross-chain manager function, allowing them to gain control over private keys and withdraw funds from three blockchains: Ethereum, Binance Smart Chain, and Polygon. The attack was possible due to insufficient input validation in the function responsible for validating transactions between blockchains. The attacker was able to forge signatures and bypass the security system, leading to the theft of over 600 million dollars in various cryptocurrencies. After the attack, the Poly Network team appealed to the attacker to return the funds, and most of the funds were returned. The incident demonstrated the critical importance of security auditing for cross-chain protocols and the need for stricter checks in smart contract code.
Wormhole, a popular bridge between blockchains, was attacked, resulting in the theft of 325 million dollars. The attacker exploited a vulnerability in the signature validation system, allowing them to create fake transactions and withdraw funds from the protocol. The problem was that the system did not properly verify the authenticity of validator signatures, allowing the attacker to bypass security mechanisms. The attack was particularly devastating because Wormhole is one of the main bridges between Ethereum and Solana, and many DeFi protocols rely on its security. After the incident, the Wormhole team received financial support from Jump Crypto to cover losses, but the reputational damage was significant. This case highlighted the importance of thorough auditing of validation systems and the need for stricter checks in cross-chain protocols.
Ronin Network, the blockchain for the game Axie Infinity, was attacked, resulting in the theft of 625 million dollars. The attackers gained access to the private keys of network validators, allowing them to sign fraudulent transactions and withdraw funds from the bridge between Ethereum and Ronin. The attack was possible due to insufficient infrastructure security and social engineering. The attackers were able to gain access to four of the nine network validators, giving them control over the majority of votes in the consensus system. This incident demonstrated the vulnerability of systems based on multisignature when security depends on human factors. After the attack, Ronin Network switched to a more secure validation system and increased the number of validators, but the damage to the Axie Infinity ecosystem was significant.
Nomad Bridge, a cross-chain protocol, was attacked, resulting in the theft of 190 million dollars. The attackers used a vulnerability in the message validation system, allowing them to create fake transactions and withdraw funds from the protocol. The problem was that the system did not properly verify message hashes and their signatures, making it possible to create fraudulent transactions. The attack was particularly devastating because many users lost their funds, and trust in cross-chain protocols was undermined. After the incident, Nomad Bridge suspended operations and began the recovery process, but many users were unable to recover their funds. This case highlighted the importance of thorough auditing of validation systems and the need for stricter checks in cross-chain protocols.
Beanstalk Farms, a DeFi protocol for stablecoins, was attacked, resulting in the theft of 182 million dollars. The attacker used a flash loan to gain temporary control over a large number of governance tokens, allowing them to vote for a malicious proposal that withdrew all funds from the protocol. The attack was possible due to shortcomings in the protocol governance system and lack of protection against flash loan attacks. The attacker was able to bypass security mechanisms and gain control over the protocol for a short time, but this was enough to steal all funds. After the attack, Beanstalk Farms suspended operations and began the recovery process, but many users lost their investments. This incident demonstrated the importance of protection against flash loan attacks in DeFi protocols.
Harmony Bridge, a cross-chain protocol, was attacked, resulting in the theft of 100 million dollars. The attackers gained access to the private keys of multisignature validators, allowing them to sign fraudulent transactions and withdraw funds from the bridge. The attack was possible due to insufficient infrastructure security and social engineering. The attackers were able to gain access to two of the five validators, giving them control over the multisignature system. This incident demonstrated the vulnerability of systems based on multisignature when security depends on human factors and physical infrastructure security. After the attack, Harmony Bridge suspended operations and began the recovery process, but many users lost their funds.
Wintermute, a major cryptocurrency trading firm, lost 160 million dollars due to a vulnerability in a smart contract. The problem was in the incorrect implementation of a function that allowed attackers to access funds without proper authorization. The vulnerability was that the smart contract did not properly verify access rights and allowed critical operations to be performed without necessary permissions. The attackers were able to exploit this vulnerability and withdraw funds from the contract. After discovering the attack, Wintermute suspended operations and began an investigation, but the damage was significant. This incident demonstrated the importance of thorough security auditing for all smart contracts, especially those managing large amounts of funds.
Mango Markets, a DeFi protocol on Solana, was attacked, resulting in the theft of 117 million dollars. The attacker used price manipulation to exploit a vulnerability in the collateral system. The attacker was able to artificially inflate the price of the MNGO token, allowing them to obtain large loans against collateral and then withdraw funds from the protocol. The vulnerability was that the system did not have sufficient protection against price manipulation and allowed the use of inflated prices for obtaining loans. After the attack, the attacker offered to return some funds in exchange for immunity from prosecution, which caused controversy in the community. This incident demonstrated the importance of protection against price manipulation in DeFi protocols.
Rari Capital, a DeFi lending protocol, was attacked, resulting in the theft of 80 million dollars. The attacker exploited a vulnerability in the smart contract that allowed repeated function calls before the initial transaction was completed. This allowed the attacker to repeatedly withdraw funds from the protocol within a single transaction. The vulnerability was that the contract did not use the checks-effects-interactions pattern and did not check the state before performing critical operations. After the attack, Rari Capital suspended operations and began the recovery process, but many users lost their funds. This incident demonstrated the importance of protection against reentrancy attacks in smart contracts.
Cream Finance, a DeFi lending protocol, was attacked, resulting in the theft of 130 million dollars. The attacker used a flash loan to gain temporary control over a large number of tokens, allowing them to exploit a vulnerability in the protocol's pricing system. The attack was possible due to shortcomings in the price determination mechanism and lack of protection against liquidity manipulation. The attacker was able to artificially inflate the price of a specific token, allowing them to obtain large loans against collateral and then withdraw funds from the protocol. After the attack, Cream Finance suspended operations and began the recovery process, but many users lost their investments. This incident demonstrated the importance of protection against flash loan attacks and price manipulation in DeFi protocols.