
Bonzo Lend Loses $9.05 Million in Hedera Oracle Exploit
Lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a verification flaw in a Supra oracle contract on the Hedera network.

Lending protocol Bonzo Lend lost approximately $9.05 million after an attacker exploited a verification flaw in a Supra oracle contract on the Hedera network.

Secret Network has cited AI exploit risks and outdated code as significant security concerns regarding its proposed move to the Arbitrum ecosystem.

Crypto wallet provider Ctrl Wallet is set to cease operations, urging users to withdraw assets by August 3, 2026, after a June 23 security exploit.

A crypto trader lost $2 million in a "same-block backrun extraction" exploit, highlighting the critical need for transaction route review.

Memecoin project BONK has suffered a **$20 million** treasury drain after an attacker exploited its governance mechanism by purchasing **$4 million** in tokens.

BonkDAO, the entity behind the memecoin project, has reported a $20 million theft resulting from a malicious governance proposal.

DeFi protocol Summer.fi halted its Lazy Summer vaults after a $6 million exploit, causing its SUMR token to fall over 18%.

Taiko has reopened its cross-chain bridge after an 11-day network disruption caused by a $1.7 million exploit, confirming all users were made whole.

An attacker inflated a tokenized Google share by 7,700% to borrow funds, resulting in $403,000 in bad debt.

SecondFi aims for a two-week recovery, having completed forensic investigations and taken a balance snapshot after a Cardano wallet exploit.

SecondFi, a Cardano-based platform, lost $2.4 million in a wallet exploit stemming from a flaw in its generation software, though 129 million ADA was secured.

THORChain has fully resumed network activity over a month after a $10.7 million exploit was addressed through security upgrades and vault migration.

The Secret Network experienced a $4.7 million exploit involving an "infinite mint" bug, with funds moving to Ethereum and exchanges.

Ethereum's largest 'sandwich' bot, Jaredfromsubway.eth, was reportedly exploited for $7.5 million by an attacker using fake trading routes, Blockaid confirmed.

The notorious MEV bot Jaredfromsubway.eth, responsible for 70% of Ethereum sandwich attacks, has been exploited for $7.5 million.

Aztec Network was hit by its second $2.1 million exploit in a week, prompting security experts to warn about vulnerable deprecated smart contracts.

A deprecated smart contract associated with the privacy-focused Aztec Connect platform has been exploited, leading to a loss of approximately $2.1 million in crypto assets.

An attacker exploited Aztec Connect's deprecated smart contract, siphoning off $2.1 million in crypto assets, highlighting risks of immutable code.

Decentralized exchange Raydium, built on the Solana blockchain, has committed to using its treasury to reimburse users affected by a recent $1.34 million exploit.

Humanity Protocol's recent $36 million bridge exploit has been linked to compromised multisignature keys, potentially due to an accidental backup on an infected device.

A critical security lapse involving a compromised laptop led to a $36 million exploit on Humanity Protocol, impacting its cross-chain bridges.

The Humanity Protocol decentralized identity project lost $36 million and saw its token crash by 73% after an employee's laptop compromise led to private key theft.

Humanity Protocol's H token plummeted over 80% after a reported $32 million hack, stemming from a compromised private key of a foundation member.

Yuga Labs, the creator of Bored Ape Yacht Club, has recovered more than 60 Ethereum NFTs from recent exploits, holding them for return to their owners.

Ethical hackers successfully recovered **$500,000** worth of NFTs following a **Flooring exploit**, highlighting ongoing security challenges in a cooling market where **CryptoPunks** and **BAYC** maintain dominance.

A critical counterfeiting bug, present in Zcash for four years and discovered with AI assistance, has raised concerns about illicit token creation and network integrity.

Gnosis Pay is addressing an exploit within its delay module, with co-founder Martin Köppelmann committing to fully reimburse all affected users.