⚠️Top 10 Security Incidents (January–June 2026)
1:KelpDAO, April 18, loss of approximately $292 million. The attacker exploited a verification flaw in the LayerZero-related cross-chain bridge validation flow, released a large amount of unbacked rsETH, and rapidly supplied it to protocols including Aave, Compound, Euler, and Fluid for borrowing and cashing out, ultimately evolving into a cross-protocol bad debt contagion event.
2:Drift Protocol, April 1, loss of approximately $285 million. The attacker obtained protocol administrative control by leveraging durable nonce, social engineering, and weaknesses in multisig governance, then introduced forged collateral assets and manipulated protocol parameters to drain a large amount of real assets from the protocol.
3:Step Finance, January 31, loss of approximately $40 million. The compromise of high-privilege devices and the treasury private key system resulted in significant asset losses. On February 24, the project announced it would cease operations.
4:Humanity Protocol, June 9, loss of approximately $31 million to $36 million. The root cause was improper management of private keys and multisig keys. After compromising critical devices, the attacker took over bridge administrative privileges and carried out fund transfers and abnormal minting across multiple chains.
5:Truebit, January 8, loss of approximately $26.6 million. The attacker exploited an integer overflow/pricing logic flaw in a legacy contract to mint a large amount of TRU at low cost and dump the tokens on the market, causing the token price to collapse rapidly.
6:Resolv Labs, March 22, loss of approximately $25 million. After obtaining high-privilege signing capabilities, the attacker exploited the lack of supply caps and ratio validation in the minting logic to mint approximately 80 million unbacked USR and cash them out.
7:SwapNet, January 25, loss of approximately $13.4 million. Its closed-source contract contained arbitrary-call / approval abuse risks. The attacker leveraged users' existing approved allowances to trigger malicious transferFrom calls and drained users' assets at scale.
8:Verus-Ethereum Bridge, May 18, loss of approximately $11.58 million. The cross-chain bridge failed to strictly verify whether the source-chain input amount matched the destination-chain release amount during the validation process. The attacker exploited this flaw to forge valid payloads and withdraw assets.
9:YieldBlox, February 22, loss of approximately $10.97 million. The attacker manipulated the price of USTRY in a low-liquidity market, causing the oracle to overestimate the collateral value, and then executed excessive borrowing from the Stellar lending pool.
10:THORChain, May 15, loss of approximately $10.7 million. A newly joined node operator exploited weaknesses in the GG20 threshold signature scheme, compromised a single vault, and withdrew assets across multiple chains, exposing the systemic risks of cross-chain signing infrastructure.
더 보기