Sign in

web3 is going just great

@web3isgoinggreat.com
22K followers 1 following 863 posts

tracking only some of the many disasters happening in crypto, defi, NFTs, and other blockchain-based projects since 2021 • created by @molly.wiki web3isgoinggreat.com

PostsRepliesMedia
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Single attacker steals $2.25 million from three crypto projects in the "Artificial Superintelligence Alliance" September 20, 2026 www.web3isgoinggreat.com/?id=fetcha…
Single attacker steals $2.25 million from three crypto projects in the "Artificial Superintelligence Alliance"
One attacker stole crypto tokens from three cryptocurrency projects that are part of what's called the "Artificial Superintelligence Alliance" — a group of crypto projects "dedicated to decentralized Artificial General Intelligence". The attack occurred within just one day, netting around $2.25 million in actual profits, though the stolen tokens were notionally priced considerably higher.
Most of the profits came from stolen FET tokens, which are linked to Fetch.ai. The attacker was also able to perform unauthorized mints of various tokens, crashing their prices but earning the attacker little in the way of profits. Security researchers noticed that attackers stole assets from sixteen wallets spanning the three companies, suggesting they had significant access to all three companies' systems. Almost $290,000 was taken from a contract used for company payroll.
38311
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Projects on the defunct Neutron chain lose $1.8 million to governance attack, Cosmos Hub halts chain September 22, 2026 www.web3isgoinggreat.com/?id=neutro…
Projects on the defunct Neutron chain lose $1.8 million to governance attack, Cosmos Hub halts chain
Neutron, a blockchain in the Cosmos ecosystem that entered maintenance mode in June, suffered a governance attack when someone spent $20,200 to acquire enough NTRN governance tokens to pass a vote allowing them to take control of the Neutron-based Astroport and Drop applications, whose contracts contained a combined $9.5 million in assets.
Neutron was paused shortly after the attack, and validators subsequently paused the entire Cosmos Hub network. Together, the pauses prevented the attacker from cashing out the entire amount, though they successfully made off with $1.8 million that they were able to bridge to Ethereum prior to the pause. Cosmos Hub remained paused for approximately 24 hours. During the pause, validators coordinated to move approximately 1.73 million ATOM from the attacker's wallet to a multi-signature wallet controlled by a group of companies operating network validato
0554
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit September 25, 2026 www.web3isgoinggreat.com/?id=magic-…
Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit
Exploiters took advantage of a legacy approvals bug in an old payment processor called Limit Break, which the platform had stopped using in late 2024. The bug affected listings on Magic Eden's EVM marketplace, which the company had shut down earlier this year. The attackers were able to steal numerous NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate Apewives. Attackers also subsequently stole 660 wETH (~$1.78 million).
 A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.
1766
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Meter token prices crash after unauthorized mint September 24, 2026 www.web3isgoinggreat.com/?id=meter-…
Meter token prices crash after unauthorized mint
An exploiter was able to mint unbacked wrapped MTR and MTRG tokens, notionally priced at more than $2.3 million. They sold some of the tokens on a decentralized exchange, crashing the MTRG price by more than 88%. The price of the project's MTR token — which is supposed to maintain a stable price based on the cost to produce 10 kWh of electricity — also plummeted by approximately the same percentage. Meter has attributed the exploit to a "block validation flaw".
Meter paused the blockchain and bridge, and has urged people not to trade the token. They have warned that "Transactions after block 100731417 may not be honored", suggesting they are considering a blockchain rollback.
Meter suffered another bridge attack in February 2022, which amounted to $4.3 million.
1493
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Payy Network bridge fully drained of $1.8 million September 24, 2026 www.web3isgoinggreat.com/?id=payy-n…
Payy Network bridge fully drained of $1.8 million
The Payy Network, a stablecoin infrastructure company, disclosed that a bridge contract had been fully drained of funds, netting attackers $1.8 million. They later stated that the theft was "NOT a compromised key, social engineering or exploit of our off-chain infrastructure," but has not disclosed what it was. They also announced that the stolen funds were "users' non-custodial deposits to Payy Network / Payy Wallet", which is somewhat of an oxymoron.
Payy Network has halted all activity following the attack.
2486
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Duelbits crypto casino goes offline after $7 million theft September 24, 2026 www.web3isgoinggreat.com/?id=duelbi…
Duelbits crypto casino goes offline after $7 million theft
The Duelbits crypto gambling site lost around $7 million to an apparent hot wallet compromise. The site went offline shortly after the attack, and the company has said the site will stay offline "until we have clarity". The Curaçao-based platform offers casino games and sportsbetting.
0596
web3 is going just great @web3isgoinggreat.com · 27/09/2026
Bitget crypto exchange hacked for $388 million, pauses withdrawals September 24, 2026 www.web3isgoinggreat.com/?id=bitget…
Bitget crypto exchange hacked for $388 million, pauses withdrawals
Attackers stole $387.5 million in crypto assets from Bitget, a cryptocurrency exchange originally founded in Singapore and headquartered out of the Seychelles. Centralized stablecoin issuers Circle and Tether (issuers of USDC and USDT) froze $318,000 in stolen assets, but the vast majority were swapped to decentralized cryptocurrencies and have not been frozen.
Bitget CEO Gracy Chen has said the company believes that a North Korean cybercrime group may be behind the theft. Bitget halted withdrawals shortly after the theft was noticed, citing the need to prevent attackers from stealing more assets. Bitget has said they have sufficient assets to cover the stolen funds.
710018
web3 is going just great @web3isgoinggreat.com · 07/09/2026
The attackers who took $320 million from Blockstream's Liquid Network have returned 90% (~$272 million), keeping 600 BTC ($48 million) likely as a "bug bounty". Unclear to what extent Blockstream okayed the 10% reward.
1588
web3 is going just great @web3isgoinggreat.com · 06/09/2026
Blockstream pauses Liquid Network after attackers claiming to be whitehats take 4,000 BTC (~$320 million) September 6, 2026 www.web3isgoinggreat.com/?id=liquid…
Blockstream pauses Liquid Network after attackers claiming to be whitehats take 4,000 BTC (~$320 million)
An unauthorized withdrawal of 3,998.5 BTC (~$320 million) from the Liquid Network, a bitcoin sidechain, prompted a network halt. By disabling nodes that bridge between Liquid and the bitcoin mainchain, attackers are limited in their ability to cash out via bridge. Blockstream, the developers of Liquid Network, also said they had contacted exchanges to ask them to pause LBTC deposits and withdrawals, cutting off another avenue.
The unauthorized transaction included a message reading "we are whitehats. contact us on chain", suggesting the possibility that the withdrawal was in fact well-intentioned security researchers aiming to "rescue" funds after discovering they were vulnerable and then return them to a secure wallet. However, as of the afternoon on September 6, Blockstream had only said that they were "working on contacting" the "purported white-hat hackers".
2899
web3 is going just great @web3isgoinggreat.com · 31/08/2026
More Markets exploited for $9.3 million August 31, 2026 www.web3isgoinggreat.com/?id=more-m…
More Markets exploited for $9.3 million
Defi lending project More Markets lost $9.3 million after an attacker was able to trick the lending protocol logic and empty the project's reserve. The attack was noticed by blockchain security researchers at Blockaid; More Labs later announced they were investigating. Oddly, while acknowledging that funds had been stolen, they wrote, "Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused." They claimed that only 5% of the assets were bridged out of the Flow blockchain, though did not explain how they planned to prevent the attacker from moving more tokens or collapsing the token price entirely.
0412
web3 is going just great @web3isgoinggreat.com · 31/08/2026
Crypto​.com-affiliated Cronos blockchain halted after Tectonic theft August 30, 2026 www.web3isgoinggreat.com/?id=tecton…
Crypto.com-affiliated Cronos blockchain halted after Tectonic theft
The ostensibly decentralized Cronos blockchain was halted after a price manipulation attack allowed an attacker to borrow more than $75 million against nearly worthless collateral from the Tectonic lending platform. The attacker pumped the price of the thinly traded TONIC token, the native token of Tectonic, then borrowed against it. The attacker cashed out approximately $6 million by bridging it to Ethereum before the Cronos chain was halted, limiting their profits. The blockchain was offline for almost 24 hours, during which time it was rolled back to a block prior to the hack — essentially undoing all the transactions that occurred after that block.
 Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain — though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.
0472
web3 is going just great @web3isgoinggreat.com · 30/08/2026
Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks August 28, 2026 www.web3isgoinggreat.com/?id=avici-…
Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks
A vulnerability in a smart contract belonging to Rain, a crypto payments infrastructure provider, resulted in $1.1 million in losses to various firms. Customers of the Avici cryptocurrency neobank, which offers a Visa credit card through which customers can spend crypto, suffered roughly $500,000 in losses. Customers of another neobank, Tria, lost more than $430,000.
The losses are somewhat unusual because the neobanks describe themselves as self-custodial, which normally means that customers have total control over their crypto assets rather than storing them on a third-party platform. Normally, self-custody is more resilient to exploits like this, given that assets remain in user wallets. However, because these neobanks require customers to load funds they want to be able to spend into a third-party contract, they were vulnerable to the theft.
0395
web3 is going just great @web3isgoinggreat.com · 27/08/2026
$1.76 million stolen from MAYAChain in attack exploiting six bugs August 18, 2026 www.web3isgoinggreat.com/?id=mayach…
$1.76 million stolen from MAYAChain in attack exploiting six bugs
The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.
1383
web3 is going just great @web3isgoinggreat.com · 27/08/2026
KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure August 22, 2026 www.web3isgoinggreat.com/?id=cosmos…
KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure
Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."
 KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.
0352
web3 is going just great @web3isgoinggreat.com · 27/08/2026
BounceBit exploited for $3 million, announces shutdown and migration August 20, 2026 www.web3isgoinggreat.com/?id=bounce…
BounceBit exploited for $3 million, announces shutdown and migration
An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.
BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.
0395
web3 is going just great @web3isgoinggreat.com · 27/08/2026
Moonwell loses $8.7 million to fourth exploit in less than a year August 27, 2026 www.web3isgoinggreat.com/?id=moonwe…
Moonwell loses $8.7 million to fourth exploit in less than a year
An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.
This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.
1475
web3 is going just great @web3isgoinggreat.com · 27/08/2026
Term Finance loses $8.5 million to governance attack August 23, 2026 www.web3isgoinggreat.com/?id=term-f…
Term Finance loses $8.5 million to governance attack
Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.
The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.
Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.
1383
web3 is going just great @web3isgoinggreat.com · 12/08/2026
Ravencoin rolls back blockchain after exploit August 11, 2026 www.web3isgoinggreat.com/?id=ravenc…
Ravencoin rolls back blockchain after exploit
Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.
Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.
1413
web3 is going just great @web3isgoinggreat.com · 12/08/2026
Harmony token plunges 40% after unauthorized mint August 11, 2026 www.web3isgoinggreat.com/?id=harmon…
Harmony token plunges 40% after unauthorized mint
An attacker was able to exploit the Harmony blockchain to mint 4 billion of the network's $ONE token. The massive increase in token supply caused the token price to plunge 40%.
Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback — that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.
This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North
1492
web3 is going just great @web3isgoinggreat.com · 11/08/2026
Proof of Attendance Protocol (POAP) shuts down August 3, 2026 www.web3isgoinggreat.com/?id=proof-…
Proof of Attendance Protocol (POAP) shuts down
Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.
 The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things. Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."
5614
web3 is going just great @web3isgoinggreat.com · 11/08/2026
Step App "move-to-earn" project shuts down August 5, 2026 www.web3isgoinggreat.com/?id=step-a…
Step App "move-to-earn" project shuts down
Step App, one of the last surviving "move-to-earn" projects from the 2022 crypto fitness fad, announced it will shut down all services on August 21. The project advertised itself as a "fitness app that pays you", and was essentially a step counter that paid crypto rewards. Users had to first buy the Step App's FITFI token to purchase an NFT representing sneakers, then were rewarded with the project's KCAL tokens for each minute they spent moving — although the number of minutes that would generate rewards were capped, often at just a few minutes, and required more NFTs to increase.
Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.
0382
web3 is going just great @web3isgoinggreat.com · 10/08/2026
Coinsbuy exploited for $8 milllion August 9, 2026 www.web3isgoinggreat.com/?id=coinsb…
Coinsbuy exploited for $8 milllion
The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.
Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.
2656
web3 is going just great @web3isgoinggreat.com · 02/08/2026
Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets July 31, 2026 www.web3isgoinggreat.com/?id=coldca…
Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets
Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to securHardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".
37210
web3 is going just great @web3isgoinggreat.com · 22/07/2026
Wanchain bridge on Cardano exploited for more than $9 million July 20, 2026 www.web3isgoinggreat.com/?id=cardan…
Wanchain bridge on Cardano exploited for more than $9 million
An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.
0353
web3 is going just great @web3isgoinggreat.com · 22/07/2026
42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft July 21, 2026 www.web3isgoinggreat.com/?id=balanc…
42DAO's Balance Coin algorithmic stablecoin crashes after $912,000 theft
Balance Coin, a small algorithmic stablecoin built on BNB Chain, lost its dollar peg and crashed to fractions of a cent after an attacker successfully exploited a flaw in its pricing logic. The attacker was able to trick the system into accepting an incorrectly low bitcoin price, which they then used to drain multiple vaults used by the project's lending protocol.
The attacker ultimately profited by about $912,000, consisting of funds stolen from 42DAO, the entity that runs the Balance protocol.
2483
web3 is going just great @web3isgoinggreat.com · 20/07/2026
Across Protocol exploited for $3.35 million July 17, 2026 www.web3isgoinggreat.com/?id=across…
Across Protocol exploited for $3.35 million
The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.
0302
web3 is going just great @web3isgoinggreat.com · 20/07/2026
Allbridge exploited for $1.66 million July 19, 2026 www.web3isgoinggreat.com/?id=allbri…
Allbridge exploited for $1.66 million
The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.
1381
web3 is going just great @web3isgoinggreat.com · 17/07/2026
Ostium loses at least $24 million to oracle exploit July 15, 2026 www.web3isgoinggreat.com/?id=ostium…
Ostium loses at least $24 million to oracle exploit
Decentralized perpetual futures exchange Ostium was drained of at least $24 million after an attacker manipulated its oracle system — a system that pulls in off-chain price data. After the attacker apparently gained access to the private key used to sign oracle messages, they were able to submit future-dated oracle reports that tricked the system into thinking trades were profitable.
The attacker siphoned at least $24 million USDC from the protocol, which they quickly swapped into ETH and laundered via Tornado Cash.
2495
web3 is going just great @web3isgoinggreat.com · 02/07/2026
Dutch Knaken crypto platform collapses June 30, 2026 www.web3isgoinggreat.com/?id=knaken…
Dutch Knaken crypto platform collapses
The Dutch cryptocurrency platform Knaken (not to be confused with the American Kraken platform) abruptly went offline in early June, leaving roughly 30,000 customers unable to access their funds. The company was unable to secure a license under the EU's MiCA regulations, which it said forced them to shut down. Though they claim to be winding down the company in an orderly fashion, they have reportedly stopped paying customer withdrawals, and have asked customers to stop filing claims.
Dutch prosecutors have asked courts to declare the platform bankrupt, which would install a court-appointed trustee to oversee the process of extracting assets from the company to return to customers. The country's Fiscal Information and Investigation Service has also opened a criminal investigation into the platform.
1569
web3 is going just great @web3isgoinggreat.com · 25/06/2026
Polymarket customers lose $2.97 million, company blames third-party vendor June 25, 2026 www.web3isgoinggreat.com/?id=polyma…
Polymarket customers lose $2.97 million, company blames third-party vendor
Polymarket customers have lost around $2.97 million to an attacker who then swapped stolen Polymarket USD (pUSD) to ETH.
Polymarket, a crypto-based prediction markets platform, quickly made an announcement to claim that a third-party vendor had been compromised to allow an attacker to inject a malicious script into the website frontend. Polymarket has said it will refund affected customers.
65811
web3 is going just great @web3isgoinggreat.com · 25/06/2026
Users of the SecondFi Cardano wallet lose $2.4 million in series of hacks June 23, 2026 www.web3isgoinggreat.com/?id=second…
Users of the SecondFi Cardano wallet lose $2.4 million in series of hacks
Users of the Cardano wallet SecondFi (formerly Yoroi) have lost a cumulative 16 million ADA (~$2.4 million) across three attacks targeting a vulnerability in the project's wallet generation code.
After the attacks commenced, SecondFi "rescued" another 129 million ADA (~$19.4 million) by moving the assets to a third party entity. They have announced that an external accounting firm will verify the funds and process user claims.
1405
web3 is going just great @web3isgoinggreat.com · 22/06/2026
Highly active MEV bot known as jaredfromsubway​.eth drained for $7.7 million June 20, 2026 www.web3isgoinggreat.com/?id=jaredf…
Highly active MEV bot known as jaredfromsubway.eth drained for $7.7 million
On blockchains like Ethereum, a strategy known as "MEV" (short for "maximal extractable value") allows intermediaries to profit from manipulating the structure of blocks added to the chain — often reordering or "sandwiching" transactions in ways that extract profits. Automated software known as MEV bots make a business out of this strategy, and one of the most active is a bot called jaredfromsubway.eth — likely so named after one-time Subway spokesman and convicted sex offender Jared Fogle because of its strategy of "sandwiching" transactions by placing trades on both sides, causing the original trader to pay more.
On June 20, an attacker used a series of contracts to cause the bot to grant token approvals that were later used to drain 4,427 ETH ($7.7 million). Some of the funds were then laundered through Tornado Cash.
0504
web3 is going just great @web3isgoinggreat.com · 22/06/2026
Secret bridge exploited for $4.67 million a week before anyone notices June 10, 2026 www.web3isgoinggreat.com/?id=secret…
Secret bridge exploited for $4.67 million a week before anyone notices
The bridge between the Cosmos-based Secret network and Axelar network was exploited via an infinite mint bug that went unnoticed for a week. An attacker exploited a smart contract in order to mint a large quantity of wrapped Axelar tokens on the Secret network, which they then redeeemed for around $4.67 million.
The exploit, which occurred on June 10, went unnoticed until June 17, when a transaction failed with a message suggesting that more tokens had been bridged out of the Secret network than had been bridged in.
Secret has warned, "If you hold Axelar-bridged saXXX tokens on Secret, please be aware their backing was affected and your funds may be lost."
0401
web3 is going just great @web3isgoinggreat.com · 22/06/2026
Main Street USD (msUSD) loses its dollar peg June 20, 2026 www.web3isgoinggreat.com/?id=main-s…
Main Street USD (msUSD) loses its dollar peg
Main Street USD, also known as msUSD, lost its dollar peg and crashed to around $0.25. At points, the token dipped as low as around $0.06. The asset, issued by Main Street Finance, is supposed to be redeemable 1:1 with Circle's USDC stablecoin. It's used as part of a yield strategy that is marketed as "democratizing the options box spread strategy through a stablecoin". Prior to the depeg, there was about $80 million msUSD in circulation.
On June 20, the verification provider Accountable announced that they had "terminated its service agreement with MainStreet, effective immediately. MainStreet was unable to meet our verification standards." The sudden loss of confidence in the token caused the price to plummet as holders rushed to withdraw funds.
Main Street issued a statement, claiming that "Mainstreet remains fully backed" and that "this is an infrastructure and reporting issue, not a solvency issue." However, they noted that "while our p
4385
web3 is going just great @web3isgoinggreat.com · 22/06/2026
Taiko bridge exploited June 22, 2026 www.web3isgoinggreat.com/?id=taiko-…
Taiko bridge exploited
The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.
0443
web3 is going just great @web3isgoinggreat.com · 18/06/2026
Thief steals remaining 7,200 unsold The Kiss NFTs in digital museum heist June 2, 2026 www.web3isgoinggreat.com/?id=thief-…
Thief steals remaining 7,200 unsold The Kiss NFTs in digital museum heist
Remember when Austria's otherwise respectable Belvedere Museum sold 10,000 NFTs representing postage-stamp sized sections of Gustav Klimt's The Kiss for like $2,000 a pop? No? Don't worry, I've got you.
 Only about a quarter of them ever sold, leaving about 7,200 of them on the digital shelves. That is, until they were stolen (or, as the museum put it, "transferred from the wallet without authorization"). If valued at their sale price the stolen NFTs would be worth €13.32 million (US$15.3 million), though it's hard to argue the thief could've ever sold them for that amount given the museum had failed to do so for several years. The stolen NFTs were soon made even less appealing to prospective buyers when the museum un-linked the image files from the digital assets, and OpenSea blocked them from trading.
913920
web3 is going just great @web3isgoinggreat.com · 18/06/2026
Aztec Connect hacked for a second time in less than a week June 18, 2026 www.web3isgoinggreat.com/?id=aztec-…
Aztec Connect hacked for a second time in less than a week
Three days after Aztec Labs' deprecated Aztec Connect blockchain bridge was exploited for $2.1 million, the project has been hacked again for the same amount. Aztec Labs confirmed the second exploit, again trying to emphasize that the code was deprecated four years ago.
The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.
2653
web3 is going just great @web3isgoinggreat.com · 16/06/2026
Pudgy Penguins shuts down Pudgy Party NFT game after losing millions in less than ten months June 15, 2026 www.web3isgoinggreat.com/?id=pudgy-…
Pudgy Penguins shuts down Pudgy Party NFT game after losing millions in less than ten months
The Pudgy Penguins NFT brand announced it would be shutting down its Pudgy Party NFT games less than ten months after its launch. The game was a mobile battle royale game, but built on crypto rails, with NFTs used for in-game items and characters that players could buy and sell. Pudgy Penguins seemed aware that the crypto aspect would be off-putting to many players, telling Decrypt in December 2025 that they were downplaying the crypto side of things "because the world is not ready for NFTs or crypto, or even blockchain en masse yet. But soon, very, very soon, we're going to use Pudgy Party as the glue between Web3 and Web2."
 Although Pudgy Penguins CEO Lucas Netz boasted on Twitter in December about "1M+ downloads today. 10M+ downloads soon." he later admitted interest in the game had quickly died off. In a community call to announce the game's shutdown, Netz acknowledged that within months of the launch, there were only 200–300 active players. The project had lost the company millions of dollars, he confessed.
920117
web3 is going just great @web3isgoinggreat.com · 15/06/2026
Humanity Protocol loses $36 million to employee laptop compromise June 9, 2026 www.web3isgoinggreat.com/?id=humani…
Humanity Protocol loses $36 million to employee laptop compromise
Humanity Protocol, a decentralized identity project that uses palm scans to try to prove that users are human, has suffered a $36 million loss after attackers compromised a laptop belonging to an employee. After the laptop was infected with malware, the malicious code gained root access, then stole seven private keys that were reportedly accidentally stored in a backup. Several of the keys were sufficient to satisfy multisignature requirements, which are intended to prevent private key leaks from allowing attackers to gain control over sensitive infrastructure like bridges. With multisignature wallets, keys are supposed to be stored separately across multiple individuals and devices; however, in this case, attackers only needed to compromise one laptop to gain control over multisig-protected contracts.
 With the keys, the attacker stole more than 6 million of Humanity's H token, then used other keys to upgrade a bridge and drain 141 million more tokens. With the bridge access, they also minted 300 million new H tokens. The attacker then quickly swapped the ill-gotten tokens for ETH, causing the H price to plummet by 80–90%. Humanity Protocol markets itself as a competitor to Sam Altman's World (formerly Worldcoin), a decentralized identity project that aims to use iris scans to prove that users are unique humans. Humanity raised $20 million in 2025 from Pantera Capital and Jump Crypto.
0745
web3 is going just great @web3isgoinggreat.com · 15/06/2026
Raydium users lose $1.34 million after legacy smart contract exploited June 10, 2026 www.web3isgoinggreat.com/?id=raydiu…
Raydium users lose $1.34 million after legacy smart contract exploited
An attacker exploited a legacy smart contract that had been used by the Raydium Solana DEX before it was deprecated in 2021. Though the contract was unused, there were still funds in the liquidity pools affected by the vulnerable contract. Using fake LP tokens, the exploiter was able to trick an old smart contract with insufficient validation into allowing them to withdraw assets.
Raydium has said it will compensate users who lost funds in the exploit.
1542
web3 is going just great @web3isgoinggreat.com · 15/06/2026
DxSale exploited for $7.3 million May 29, 2026 www.web3isgoinggreat.com/?id=dxsale…
DxSale exploited for $7.3 million
DxSale, a project that was popular in 2021 for launching new tokens and creating liquidity pools, suffered a $7.3 million exploit after ownership of a locker contract was transferred to a new address. Nine months later, the contract ownership was repeatedly moved between many new wallets — likely in an attempt to cover tracks — before $7.3 million was taken from old liquidity pools. The stolen assets were then swapped to BNB and routed through bridges and mixers to obscure the trail.
2415
web3 is going just great @web3isgoinggreat.com · 18/05/2026
Largest North American bitcoin ATM operator, Bitcoin Depot, files for bankruptcy May 18, 2026 www.web3isgoinggreat.com/?id=bitcoi…
Largest North American bitcoin ATM operator, Bitcoin Depot, files for bankruptcy
Bitcoin Depot has filed for Chapter 11 bankruptcy. The company operates a fleet of kiosks at retail locations that allow customers to purchase bitcoin with cash. Bitcoin Depot announced in a press release that its 9,700 kiosks – primarily located at gas stations and convenience stores – had already been taken offline.
The company's bankruptcy filing reports between $10 million and $50 million in both assets and liabilities. In a recent financial disclosure, the company had reported a 49% year-over-year reduction in revenue and a net loss of $9.5 million for the year. The company had also suffered a $3.67 million hack in April.
Bitcoin Depot has blamed a challenging state-level regulatory environment for its bankruptcy, pointing to a series of regulatory restrictions and outright bans on crypto ATMs, which are a major conduit for crypto scams. An FBI report on Internet crime in 2024 showed 11,000 reports of
1021355
web3 is going just great @web3isgoinggreat.com · 18/05/2026
Verus bridge hacked for $11.6 million May 17, 2026 www.web3isgoinggreat.com/?id=verus-…
Verus bridge hacked for $11.6 million
An attacker stole $11.6 million in various crypto assets from the Verus–Ethereum bridge, which allows users to use tokens from the Verus network on the Ethereum chain and vice versa. The attacker then swapped the tokens for ETH, limiting the ability for issuers of more centralized tokens to freeze the stolen assets.
Verus halted the entire Verus network after the exploit was detected in hopes of limiting further damage.
0462
web3 is going just great @web3isgoinggreat.com · 15/05/2026
THORchain exploited for $10.8 million May 15, 2026 www.web3isgoinggreat.com/?id=thorch…
THORchain exploited for $10.8 million
The THORchain cross-chain liquidity protocol was exploited for around $10.8 million across several blockchains: Bitcoin, Ethereum, BNB Chain, and Base. The protocol paused trading after observing the suspicious transactions. News of the hack caused the protocol's RUNE token to drop in price by more than 10%.
1515
web3 is going just great @web3isgoinggreat.com · 14/05/2026
Transit Finance hacked for $1.88 million May 13, 2026 www.web3isgoinggreat.com/?id=transi…
Transit Finance hacked for $1.88 million
Transit Finance was exploited for $1.88 million after an attacker exploited a "legacy contract" on the TRON blockchain that the project said was deprecated in 2022. "Historical vulnerabilities within it" were exploited, the project explained, allowing the attacker to steal $1.88 million.
Transit was previously exploited in 2022 for $21 million, although around 70% of the stolen assets were later returned.
0404
web3 is going just great @web3isgoinggreat.com · 14/05/2026
TAC bridge exploited for $2.8 million May 12, 2026 www.web3isgoinggreat.com/?id=tac-br…
TAC bridge exploited for $2.8 million
The TAC bridge, which bridges assets from the Ethereum blockchain to the Telegram-linked TON chain, was exploited for $2.8 million. The project paused the bridge and announced they were investigating.
The project has announced they intend to "restor[e] bridge liquidity through a legally structured sale of Foundation's TAC token treasury reserves."
0363
web3 is going just great @web3isgoinggreat.com · 07/05/2026
TrustedVolumes suffers $6.7 million exploit May 6, 2026 www.web3isgoinggreat.com/?id=truste…
TrustedVolumes suffers $6.7 million exploit
TrustedVolumes, a resolver and market maker used by 1inch and other defi platforms, suffered a $6.7 million exploit after an attacker was able to steal funds without proper validation. The thief then swapped the stolen wETH, USDT, wBTC, and USDC through ChangeNow and converted them to ETH to evade freezes.
Blockchain research firm Blockaid has linked the attacker to a similar exploit in March 2025 that saw $5 million drained from 1inch. This time, 1inch has asserted that although they use TrustedVolumes as a resolver, the exploit did not involve any of their systems.
1513
web3 is going just great @web3isgoinggreat.com · 06/05/2026
Ekubo exploited for $1.4 million May 5, 2026 www.web3isgoinggreat.com/?id=ekubo-…
Ekubo exploited for $1.4 million
The Ekubo automated market maker infrastructure project experienced a $1.4 million theft after attackers were able to take advantage of a smart contract that improperly verified permissions. They stole 17 wBTC ($1.4 million), which they swapped for ETH and laundered via Tornado Cash.
0413
web3 is going just great @web3isgoinggreat.com · 30/04/2026
Wasabi Protocol exploited for more than $5 million April 30, 2026 www.web3isgoinggreat.com/?id=wasabi…
Wasabi Protocol exploited for more than $5 million
The Wasabi Protocol defi derivatives platform has been exploited for more than $5 million across multiple blockchains. The attack has been attributed by blockchain security firms to a compromised admin key, which allowed the attacker to upgrade contracts to steal assets.
2587
web3 is going just great @web3isgoinggreat.com · 29/04/2026
Polish Zondacrypto exchange stops processing withdrawals amid possible insolvency April 25, 2026 www.web3isgoinggreat.com/?id=zondac…
Polish Zondacrypto exchange stops processing withdrawals amid possible insolvency
The Polish cryptocurrency exchange Zondacrypto faced complaints that withdrawals were not being processed as far back as December 2025, but the crisis seems to have escalated. CEO Przemysław Kral attempted to assuage insolvency fears by pointing to a cryptocurrency wallet containing around 4,500 BTC (~$330 million) as proof of assets, but he also admitted that the keys to the wallet were known only to the exchange's previous CEO and not transferred during the company's 2021 sale. The former CEO has been missing for four years.
Polish authorities have launched investigations into the apparent collapse. Losses have been estimated at 350 million zł (~$96 million).
Poland's Prime Minister Donald Tusk has also recently accused Zondacrypto of sponsoring conservative and right-wing politicians, including Polish President Karol Nawrocki. Nawrocki has repeatedly vetoed legislation aiming to regulate the crypto sec
0488