Storyline
DeFi exploit wave 2026
A relentless wave of DeFi exploits—spanning smart contracts, bridges, oracles, and MEV bots—is draining hundreds of millions and pushing 2026 toward record hack losses.
Timeline
- Thu, Jul 23Latest
Ostium DEX Reopens Trading After $23.8 Million Oracle Exploit
Ostium announced it would reopen trading on July 23 following the $23.75–$23.8 million oracle manipulation exploit confirmed in prior periods, with a recovery plan for affected liquidity providers under development. Separate reporting clarified the exploit drained funds through Ostium directly and was not a hack of the Arbitrum bridge.
- Sun, Jul 19
Ostium Exploit Confirmed at $23.75 Million Via False Oracle Prices; Platform Cooperates With Investigators
Ostium confirmed the total losses from its perpetual DEX exploit reached $23.75 million, caused by the injection of false oracle prices that unlocked trader positions. The platform issued an incident update stating it is cooperating with multiple investigative parties and will provide 24 hours notice before resuming trading. The exploit originated from oracle price data compromise, while Ostium stated traders' collateral and positions were separately unaffected.
- Thu, Jul 16
Supra Oracle Patched 11 Other Chains Before $9 Million Hedera Exploit
New reporting disclosed that Supra patched its oracle on 11 other blockchain networks before the $9 million Hedera exploit became public. The sequence adds detail to the previously documented Bonzo Lend oracle manipulation attack and extends the current period's documented oracle attack wave.
- Thu, Jul 16
Ostium $18M Oracle Exploit
The Ostium perpetual DEX suffered an $18 million exploit attributed to an oracle key compromise, forcing the platform to pause all trading. Blockaid identified and disclosed the attack. The incident is the latest in a documented wave of oracle attacks targeting DeFi infrastructure.
- Sun, Jul 12
Bonzo Lend on Hedera Loses $9 Million After Supra Oracle Accepts Manipulated Price Feed
The Bonzo Lend protocol on the Hedera network was exploited for $9 million after a Supra oracle verifier accepted a manipulated price update. The attack caused Bonzo Lend to lose approximately 77% of its total value locked.
- Wed, Jul 8
Lazy Summer Protocol Drained of $6M in Vault Exploit; Months of Preparation Disclosed in Post-Mortem
Summer.fi published a post-mortem revealing that the $6 million Lazy Summer Protocol vault exploit involved months of preparation by the attacker before execution. The incident, previously reported as a cross-chain vault vulnerability, prompted the protocol to suspend all vaults and set deposit caps to zero.
- Wed, Jul 8
Lido stETH Leverage Loops Carry Hidden Liquidation Risk; Ethereum Trader Loses $2M in Single-Block Backrun
Analysis flagged hidden liquidation risk embedded in Lido stETH leverage loop strategies, where cascading liquidations could create DeFi contagion. Separately, an Ethereum trader lost $2 million in a single-block MEV backrun exploit, documenting an on-chain execution risk for active DeFi participants.
- Tue, Jul 7
Summer Finance Loses $6M in Vault Exploit; Protocol Suspends All Vaults
Summer Finance's Lazy Summer Protocol suffered an active vulnerability resulting in approximately $6 million in losses, prompting the team to suspend all vaults and set deposit caps to zero. The exploit was attributed to a cross-chain vulnerability in the vault infrastructure.
- Sat, Jul 4
North Korea-Linked Hackers Steal $643M in Crypto in H1 2026
North Korea-linked hackers were attributed with $643 million in cryptocurrency theft in the first half of 2026. This figure was reported alongside the broader crypto sector record of 207 attacks in H1 2026 with aggregate losses declining overall, indicating a concentration of large-scale losses in state-actor activity.
- Wed, Jul 1
BackedFi Suffers ~$204K Exploit on Ethereum
Ethereum-based RWA and DeFi project BackedFi suffered a suspicious attack resulting in losses of approximately $204,200.
- Mon, Jun 29
AIDC Token on BSC Suffers ~$121K Exploit
The AIDC token on Binance Smart Chain suffered a suspicious attack resulting in losses of approximately $121,100.
- Mon, Jun 29
Etherlink Cross-Chain Bridge Suspended After Attack Attempt
The Etherlink EVM cross-chain bridge suspended transfers after officials detected and began investigating a suspected attack attempt.
- Mon, Jun 29
Q2 2026 Becomes Worst Quarter on Record for Crypto Hacks
Q2 2026 was reported as the worst quarter on record for crypto hacks, with cumulative losses across exploits and breaches exceeding all prior quarterly totals.
- Thu, Jun 25
DLMC Token on BSC Chain Suffers $222,600 Exploit
The DLMC token on the Binance Smart Chain suffered a suspicious attack resulting in losses of approximately $222,600. The incident was identified as a small-scale exploit separate from larger DeFi security events.
- Thu, Jun 25
THORChain Resumes Trading After $10.7M Exploit; Unveils Monero Swap Roadmap
THORChain resumed trading operations following a month-long halt caused by a $10.7 million exploit and simultaneously published a roadmap for adding Monero swap functionality to the protocol. The Monero swap roadmap represents a planned expansion of privacy-coin liquidity access through THORChain's cross-chain infrastructure.
- Wed, Jun 24
THORChain Resumes Trading After $10.7M Exploit and Month-Long Halt
THORChain resumed trading operations after a month-long trading halt that followed a $10.7 million exploit of the protocol. No specific recovery or remediation details were disclosed alongside the resumption announcement. The incident was counted as part of the record 83 security breaches recorded in Q2 2026.
- Mon, Jun 22
Taiko Chain Proof-of-State Mechanism Compromised; $1.7M Lost in Bridge Exploit
Taiko's Proof-of-State verification mechanism was compromised, with PeckShield confirming approximately $1.7 million in losses from the exploit. Users were advised to immediately withdraw funds from Taiko's cross-chain bridge, and the incident was counted among more than 20 crypto hacks recorded in June 2026.
- Sun, Jun 21
Tornado Cash Used in JaredFromSubway Exploit Fund Laundering
The attacker responsible for a reversal attack on the prominent MEV bot jaredfromsubway.eth, which resulted in losses exceeding $7.5 million, transferred a portion of the stolen funds into Tornado Cash. The exploit and subsequent laundering activity were tracked via on-chain monitoring tools.
- Sun, Jun 21
Namada Privacy Chain Exploited; 228,000 ATOM Drained via Cross-Chain Bridge
The Namada privacy-focused blockchain was exploited, with approximately 228,000 ATOM transferred out via a cross-chain bridge. Namada had earlier issued a security alert stating its protocol was under active attack with an investigation underway. The incident is separate from the previously reported $4.67 million Axelar-Secret Network bridge exploit.
- Sat, Jun 20
Axelar Disables Secret Network Bridge After $4.67M Exploit; IBC-Linked Assets Affected
Axelar disabled its bridge connection to the Secret Network following an exploit that resulted in approximately $4.67 million in token losses from IBC-linked assets. The attack affected cross-chain privacy infrastructure and prompted Axelar to shut down the affected bridge routes. The Secret Network exploit highlights vulnerability in cross-chain privacy protocol infrastructure.
- Thu, Jun 18
Aztec Suffers Second Exploit in Under a Week for $2.1M
SlowMist confirmed that Aztec suffered a second exploit within less than one week of its first attack, with losses in the second incident totaling approximately $2.1 million. Both exploits were attributed to vulnerabilities in deprecated Aztec smart contracts, with the first incident involving a ZK proof and Layer 1 settlement mismatch.
- Mon, Jun 15
Aztec Network Exploited for $2.15M via ZK Proof–L1 Settlement Mismatch
Aztec Network suffered an exploit resulting in losses of over $2.15 million, with the root cause identified as a mismatch between ZK proof verification and Layer 1 settlement. A separate report attributed approximately $2.1 million in losses to exploitation of an abandoned Aztec Connect smart contract.
- Fri, Jun 12
AI Accelerating Discovery of DeFi and Smart Contract Exploits; Legacy Contracts Flagged as Ongoing Risk
A report found that AI is accelerating the discovery of DeFi and smart contract attack vectors and exploits. Separately, analysis warned that legacy DeFi contracts that have been largely forgotten remain a persistent source of vulnerability risk.
- Thu, Jun 11
DeFi Exploits Drain $36M+ Via Unverified Contracts; Governance Attack Drains Balancer Pool
Crypto hackers drained over $36 million from protocols using unverified contracts across multiple incidents. A separate governance takeover attack resulted in the minting of 10 billion TOP tokens and the draining of $1.58 million from a Balancer pool. A NovaBox rewards pool was also exploited for 56.73 ETH through a vulnerability in its distribution mechanism.