Skip to content

Major Hacks & Bad Actors

Documented crypto hacks, exploits, sanctioned actors, and frauds — 58 cases across exchange collapses, DeFi exploits, state-sponsored theft, and Ponzi schemes. Searchable and filterable. Loss figures are estimates and vary by source.

About this reference
These are documented cases drawn from public sources (DOJ, OFAC, SEC, exchange post-mortems, reputable news). Loss figures are estimates and vary by methodology — treat them as orders of magnitude. For the chronological context, see the History Timeline and the Policy Timeline (sanctions and enforcement milestones). For the tracing techniques behind attribution, see the Tracing module.

58 of 58 cases

  • Mt. Gox

    Feb 2014 · ~$450M (≈850K BTC)

    Exchange hack

    Target: Mt. Gox exchange (Japan)
    Perpetrator: Unknown (slowly drained over years; some recovered)

    Japan-based Mt. Gox handled the majority of Bitcoin trading until it filed for bankruptcy in 2014 after revealing the loss of roughly 850,000 BTC to theft accumulated over years. It was the first defining exchange-collapse in crypto history and scarred the industry’s early reputation.

    Root cause
    Inadequate internal controls, a hot-wallet security failure, and a long-unnoticed slow drain. The exchange commingled customer funds with operational funds, so theft went undetected.
    Aftermath
    Birthed the "not your keys, not your coins" self-custody ethos; pushed Japan to regulate exchanges under the FSA (2017 Payment Services Act revision); a decade-long civil rehabilitation returned a fraction of funds to creditors.

    Repayments in BTC and BCH began in July 2024 and continued through 2025, with the trustee extending the repayment deadline from October 2024 to October 2025 and then again to October 2026 — one of the longest-running bankruptcy proceedings in crypto.

    Sources:

  • BitClub Network

    2014–2019 · ~$722M

    Fraud / Ponzi

    Target: BitClub Network ("Bitcoin mining pool" investment scheme)
    Perpetrator: Operators (DOJ indicted; sentenced 2020–2021)

    BitClub Network ran for five years as a "Bitcoin mining investment" pool, taking ~$722M from investors worldwide while misleading them about mining returns and paying recruiters with new-member funds. The DOJ indicted the operators in 2019 and secured sentences through 2020–2021.

    Root cause
    A long-running Ponzi disguised as a mining pool: returns were fabricated/paid from new deposits, and a multi-level referral structure drove recruitment. The "mining" framing lent false legitimacy.
    Aftermath
    Operators sentenced to years in federal prison; one of the longest-running crypto Ponzis. Cited in scam-education content alongside BitConnect and OneCoin as a "fake yield / fake operation" pattern.

    Sources:

  • Bitfinex hack

    Aug 2016 · ~$72M (≈119K BTC)

    Exchange hack

    Target: Bitfinex exchange (Hong Kong)
    Perpetrator: Ilya Lichtenstein and Heather Morgan (DOJ, 2022)

    Bitfinex was hacked for ~119,756 BTC in August 2016. The DOJ finally charged a couple in 2022 with conspiring to launder the stolen funds over years, in what was then the largest crypto-seizure in DOJ history.

    Root cause
    A vulnerability in Bitfinex’s multi-signature wallet architecture (with BitGo) was exploited; funds were moved out despite the multi-sig design.
    Aftermath
    Bitfinex socialized losses across all customers via a BFX token that was later redeemed; the 2022 arrests demonstrated that even years-old crypto thefts can lead to prosecution. DOJ recovered most of the stolen BTC.

    Sources:

  • The DAO hack

    Jun 2016 · ~$60M (ETH)

    DeFi exploit

    Target: The DAO (Ethereum smart contract)
    Perpetrator: Unknown attacker exploiting a reentrancy bug

    The DAO, a decentralized investment fund built on Ethereum, raised ~$150M then was drained of ~$60M by an attacker exploiting a reentrancy bug. It was the first crisis of smart-contract security and split the community over what to do about it.

    Root cause
    A classic reentrancy: the attacker’s contract re-entered the DAO’s splitDAO function before state updates settled, draining the same funds repeatedly. No audit had caught it.
    Aftermath
    Ethereum executed a hard fork to reverse the theft and return funds — the most famous schism in crypto history. The minority that refused the fork continued the original chain as Ethereum Classic (ETC). "Code is law" vs. human intervention became a defining debate.

    Covered as the canonical reentrancy example in the Smart Contracts module.

    Sources:

  • Parity multi-sig freeze

    Nov 2017 · ~$280M (frozen)

    DeFi exploit

    Target: Parity multi-sig wallets (Ethereum)
    Perpetrator: Accidental — a developer using the handle "devops199" deleted the library contract

    A bug in Parity’s multi-sig wallet contract let a developer using the handle "devops199" accidentally delete the library it depended on, permanently freezing ~$280M of user funds. It became a textbook example of smart-contract fragility and irreversible failure.

    Root cause
    The multi-sig wallet logic was in a shared library contract; an earlier fix had left the library’s init function unprotected. A user called it, took ownership, then "killed" the library — bricking every wallet that depended on it.
    Aftermath
    A hard lesson on shared-library risk, access control, and the irreversibility of smart-contract failure. Some affected funds remain frozen. Cited in upgradable-proxy and access-control debates.

    Sources:

  • OneCoin

    Oct 2017 · ~$4B

    Fraud / Ponzi

    Target: OneCoin "cryptocurrency" (not actually on a blockchain)
    Perpetrator: Ruja Ignatova ("Cryptoqueen") and co-conspirators

    OneCoin was a $4B Ponzi marketed as a cryptocurrency that never actually had a blockchain — it was purely a database the operators controlled. Founder Ruja Ignatova disappeared in 2017 and was added to the FBI Ten Most Wanted list in 2022.

    Root cause
    A pure fraud: no blockchain, no coin, no trading — just a multi-level-marketing structure selling "educational packages" that paid recruiters with new-member funds.
    Aftermath
    Ignatova remains a fugitive (FBI Ten Most Wanted); several co-conspirators convicted. OneCoin is the canonical example of a "fake crypto" — it didn’t even use the technology it claimed to.

    Sources:

  • Coincheck hack

    Jan 2018 · ~$530M (NEM)

    Exchange hack

    Target: Coincheck exchange (Japan)
    Perpetrator: Unknown (suspected DPRK-linked)

    Japan-based Coincheck lost ~$530M in NEM to hackers — then the largest exchange theft since Mt. Gox. It pushed Japan to tighten exchange regulation and revived the self-custody debate.

    Root cause
    NEM funds were held in a hot wallet connected to the internet rather than cold storage, and the exchange lacked the FSA registration that post-Mt. Gox rules would have required.
    Aftermath
    The FSA issued administrative orders against Coincheck and tightened oversight; accelerated Japan’s shift to the licensed-exchange regime; Coincheck later paid out affected customers.

    Sources:

  • BitConnect

    Jan 2018 · ~$2.4B

    Fraud / Ponzi

    Target: BitConnect "trading bot" + BCC token
    Perpetrator: Founder Satish Kumbhani and promoters (DOJ-charged)

    BitConnect promised daily returns from a "trading bot" that didn’t exist, paid early investors with later deposits, and collapsed in 2018. The DOJ charged the founder in 2022 with a $2.4B fraud — one of the largest crypto Ponzis on record.

    Root cause
    A textbook Ponzi: returns funded by new deposits, with no real trading bot. The BCC token’s price was manipulated by the scheme’s own demand and collapsed when withdrawals halted.
    Aftermath
    Founder charged (2022); a defining cautionary tale about "guaranteed returns" in crypto. Frequently referenced in scam-education content; the Security module’s "Scam or Legit?" game uses BitConnect-style red flags.

    Sources:

  • Bitgrail

    Feb 2018 · ~$195M (Nano/XRB)

    Exchange hack

    Target: Bitgrail exchange (Italy)
    Perpetrator: Operator insolvency (founder Francesco Firano)

    Italian exchange Bitgrail announced the loss of ~$195M of Nano (XRB), but investigations and the Nano team concluded Bitgrail had likely been insolvent for months — the "missing" funds reflected accounting losses, not a single theft. A smaller-scale Mt. Gox parallel of commingled and misreported funds.

    Root cause
    Suspicious transaction behavior on the exchange ledger; founder Firano allegedly knew of the shortfall. Like Mt. Gox, the line between external theft and internal insolvency blurred.
    Aftermath
    An Italian bankruptcy proceeding; a cautionary tale on exchange solvency and the risks of exchange-listed, low-cap tokens. Reinforces "not your keys, not your coins" alongside Mt. Gox and QuadrigaCX.

    Sources:

  • QuadrigaCX

    Jan 2019 · ~$190M (customer funds)

    Exchange hack

    Target: QuadrigaCX exchange (Canada)
    Perpetrator: Operator failure (CEO Gerald Cotten died with sole keys)

    Canadian exchange QuadrigaCX collapsed after its CEO died reportedly holding the only keys to the cold wallet holding ~$190M of customer funds. The court-appointed monitor later found the exchange had been operating like a Ponzi scheme, with funds moved to trading losses and personal accounts.

    Root cause
    Extreme single-point-of-failure: one person held sole control of the cold-wallet keys, with no succession plan. The monitor’s report also revealed the exchange had been insolvent for years and misused customer funds.
    Aftermath
    A textbook case for institutional custody controls, key-management policies, and succession planning. Cited in custody-regulation debates; the cold wallet was later found to be largely empty.

    The "what happens to your keys when you die?" question is covered in the Cold Storage Walkthrough lab.

    Sources:

  • Plus Token

    Jun 2019 · ~$5.8B (claimed)

    Fraud / Ponzi

    Target: Plus Token wallet app (China/South Korea)
    Perpetrator: Chinese operators (sentenced 2020)

    Plus Token was a massive crypto Ponzi disguised as a wallet with "yield-generating AI," defrauding millions of users across Asia for ~$5.8B before Chinese authorities shut it down and sentenced the operators. The scale made it one of the largest crypto frauds ever.

    Root cause
    A classic Ponzi with a crypto wrapper: high promised returns funded by new deposits, with the operators eventually moving funds through mixers and cashing out.
    Aftermath
    Chinese courts sentenced 27 operators (2020); the case is cited in Ponzi-vs-crypto education and cross-border laundering discussions. The funds were moved through significant mixer/OTC laundering.

    Categorized as Fraud / Ponzi: the operators were Chinese and no credible public source ties the laundering to a state actor.

    Sources:

  • Upbit hack

    Nov 2019 · ~$50M (≈342K ETH)

    Exchange hack

    Target: Upbit exchange (South Korea, hot wallet)
    Perpetrator: Unknown (funds laundered through ETH swaps)

    South Korea's Upbit lost ~342K ETH (~$50M) in a single hot-wallet transfer that the exchange identified as an abnormal withdrawal. The stolen ETH was laundered through swaps and remained partially untraced, a clean example of how hot-wallet drainage is laundered.

    Root cause
    A hot-wallet compromise; Upbit had reportedly moved most funds to cold storage shortly before, limiting damage. The vector itself was not disclosed.
    Aftermath
    Upbit reimbursed users and tightened hot-wallet limits; the case is cited in hot-wallet-limits and laundering-path discussions. One of the larger pre-2022 South Korean exchange incidents.

    Sources:

  • KuCoin hack

    Sep 2020 · ~$281M (≈$150M net after recovery)

    Exchange hack

    Target: KuCoin exchange (hot wallets)
    Perpetrator: DPRK / Lazarus-linked (per Chainalysis attribution)

    Singapore-based exchange KuCoin's hot wallets were compromised for ~$281M across many assets — at the time one of the largest exchange thefts. KuCoin covered user losses via its insurance fund, on-chain freezes by partner projects recovered ~$150M, and Chainalysis later linked the attackers to DPRK actors.

    Root cause
    A hot-wallet private-key compromise; the specific vector was not fully disclosed. The wide asset list (BTC, ETH, ERC-20 tokens) let KuCoin and token teams coordinate freezes on a portion of the stolen funds.
    Aftermath
    KuCoin reimbursed affected users and continued operating — a notable recovery case. Cited in hot-vs-cold-wallet risk and the DPRK exchange-targeting pattern that intensified through 2024.

    Sources:

  • Mirror Trading International (MTI)

    Dec 2020 · ~$1.2B (claimed up to ~$1.8B BTC)

    Fraud / Ponzi

    Target: MTI (South Africa-based "Bitcoin trading" pool)
    Perpetrator: CEO Johann Steynberg (fled to Brazil; never extradited — reportedly died in custody 2024)

    MTI ran South Africa's largest crypto Ponzi, promising daily returns from an "AI trading bot" that didn't exist and paying early members with new deposits. After it collapsed in 2020, founder Johann Steynberg fled to Brazil, was arrested there in December 2021, and was charged with fraud by the US CFTC in June 2022 — but he was never extradited, reportedly dying in Brazilian custody in 2024.

    Root cause
    Classic Ponzi with a crypto wrapper: fabricated trading returns, a fake bot, and a multi-level-marketing referral structure funding withdrawals from new deposits.
    Aftermath
    South African regulators placed MTI in liquidation; The CFTC charged Steynberg with fraud in June 2022 and US courts later imposed a record ~$3.4B judgment against him (2023), but he reportedly died in Brazilian custody in 2024 while fighting extradition. A flagship South African case and a near-exact structural twin of BitConnect.

    Sources:

  • Thodex

    Apr 2021 · ~$2B (customer funds)

    Exchange hack

    Target: Thodex exchange (Turkey)
    Perpetrator: Operator fraud (CEO Faruk Fatih Özer, fled)

    Turkish exchange Thodex halted withdrawals and its CEO fled the country with ~$2B of customer funds, triggering an Interpol red notice and mass arrests. It was one of the largest retail-facing crypto-exit scams by value.

    Root cause
    Operator fraud and an exit scam; the exchange appears to have been a Ponzi that promised unusually high returns and collapsed when new deposits stopped covering withdrawals.
    Aftermath
    Özer was arrested in Albania in 2022 and extradited to Turkey; sentenced to 11,196 years (Turkey’s aggregate sentencing). A stark reminder that unregulated exchanges can be pure fraud.

    Sources:

  • Poly Network

    Aug 2021 · ~$610M

    DeFi exploit

    Target: Poly Network cross-chain bridge
    Perpetrator: Unknown attacker — later returned nearly all funds

    An attacker exploited a cross-chain bridge flaw to steal ~$610M from Poly Network — the largest DeFi theft to that point. After public negotiations and the attacker framing themselves as a "white hat," nearly all funds were returned.

    Root cause
    A flaw in the bridge’s EthCrossChainManager contract let the attacker forge a message that called the bridge’s own contract to unlock assets, without needing private keys.
    Aftermath
    Became the canonical example of bridge risk (bridges remain the riskiest link in crypto) and an unusual "white-hat" recovery story. Bridges have since been the most-exploited category by value.

    Sources:

  • BadgerDAO

    Dec 2021 · ~$120M

    DeFi exploit

    Target: BadgerDAO frontend / user wallets (Ethereum)
    Perpetrator: Unknown attacker via a compromised frontend

    BadgerDAO was drained of ~$120M not through a smart-contract bug but through its frontend: an attacker compromised Badger's Cloudflare/email infrastructure and injected a malicious script that prompted users to approve a drainer contract, signing away their tokens. The contract itself was never broken.

    Root cause
    A supply-chain compromise of the frontend (Cloudflare and a team email account) — a reminder that the user-facing layer, not just the on-chain code, is part of the attack surface. Users were socially engineered into signing approvals.
    Aftermath
    Badger paused contracts, engaged chain-analysis and recovery specialists, and eventually reached a settlement reimbursing victims via a remunerative token. Cited as a flagship case for frontend/infrastructure risk and the "don't trust the UI" principle.

    Sources:

  • Cream Finance

    Oct 2021 · ~$130M

    DeFi exploit

    Target: Cream Finance (Ethereum lending protocol, yearn fork)
    Perpetrator: Unknown attacker (flash-loan price manipulation)

    Cream Finance was drained of ~$130M when an attacker manipulated the price of a LP token that Cream used as collateral, then borrowed real assets against the inflated collateral. It was one of several Cream incidents in 2021 and a textbook flash-loan/oracle-manipulation case.

    Root cause
    Cream's price oracle valued an illiquid LP token using a spot price the attacker could move with a flash loan, then borrowed against the inflated value. The protocol hadn't guarded the oracle against flash-loan manipulation.
    Aftermath
    Cited alongside Polter Finance as a canonical oracle-manipulation case — the recurring "don't use thin/spot prices as collateral oracles" lesson. Cream paused operations and compensated some users.

    Sources:

  • Liquid hack

    Aug 2021 · ~$97M

    Exchange hack

    Target: Liquid exchange (Japan-licensed, operated by Quoine)
    Perpetrator: DPRK-linked (per on-chain analysis)

    Japan-licensed exchange Liquid was compromised for ~$97M in crypto from its hot wallets. On-chain analysts linked the laundering to DPRK actors, making it a Japan-regulatory counterpart to Coincheck and a precursor to the DMM Bitcoin social-engineering pattern.

    Root cause
    A hot-wallet key compromise; the attacker moved funds through DPRK-consistent laundering infrastructure (swaps and bridges).
    Aftermath
    Liquid suspended withdrawals and was later acquired by FTX (pre-collapse). Cited in Japan's exchange-security trajectory alongside Coincheck, Mt. Gox, and DMM Bitcoin.

    Sources:

  • Suex / Chatex / Bitzlato

    Sep 2021 · N/A (sanctioned laundering venues)

    State-sponsored

    Target: Suex, Chatex, Bitzlato (Russia-linked OTC exchanges)
    Perpetrator: Sanctions evasion / ransomware laundering

    OFAC's September 2021 designation of Suex was the first time a crypto exchange was sanctioned outright, targeting an OTC desk laundering ransomware proceeds. Chatex followed later in 2021, and Bitzlato was charged and sanctioned in 2023, together defining the "first sanctioned exchanges" tier.

    Root cause
    Non-compliant OTC desks willing to convert illicit crypto to fiat for ransomware actors and other criminals; the structural difficulty of enforcing sanctions against offshore, non-cooperative venues.
    Aftermath
    Established the precedent for sanctioning exchanges (later Garantex, Hydra). A flagship case for the crypto-sanctions toolkit and a natural lead-in to the Garantex entry.

    Sources:

  • Squid Game token

    Nov 2021 · ~$3.4M

    Fraud / Ponzi

    Target: Squid Game (SQUID) memecoin (Binance Smart Chain)
    Perpetrator: Anonymous developers (rug pull)

    A memecoin piggybacking on the "Squid Game" TV show pumped thousands of percent before its developers pulled liquidity and vanished with ~$3.4M. Despite anti-dump tokenomics (a built-in "anti-dump" mechanism), buyers couldn't sell — only the developers could.

    Root cause
    A classic rug pull: developers retained the ability to sell while holders couldn't (the tokenomics literally prevented selling), then drained the liquidity pool. The pop-culture name drew in buyers who didn't read the contract.
    Aftermath
    Small in dollar terms but culturally defining — the canonical "pop-culture memecoin rug pull." Cited in scam-education as the example of why celebrity/media-hype tokens and "you can't sell" mechanics are red flags.

    Included for its educational notability despite the small loss — a clean anti-rug teaching case.

    Sources:

  • FTX collapse

    Nov 2022 · ~$8B (customer funds)

    Exchange hack

    Target: FTX exchange (Bahamas)
    Perpetrator: Operator fraud (SBF, Alameda, et al.)

    Giant exchange FTX collapsed after revelations that sister trading firm Alameda had misused customer funds. Founder Sam Bankman-Fried was arrested, convicted of fraud and conspiracy, and sentenced to 25 years — a defining cautionary tale about centralized custody and unchecked founders.

    Root cause
    Commingling of customer funds with Alameda (a sister firm), fraudulent financials, absence of independent oversight, and a bank-run triggered by public revelations of the relationship.
    Aftermath
    SBF convicted (2023) and sentenced (2024); intensified scrutiny of exchange custody, "proof of reserves" campaigns, and the push for qualified-custody rules. The collapse accelerated the 2022 crypto winter.

    Sources:

  • Wormhole bridge hack

    Feb 2022 · ~$320M

    DeFi exploit

    Target: Wormhole bridge (Solana ↔ Ethereum)
    Perpetrator: Unknown (never publicly attributed)

    The Wormhole cross-chain bridge was exploited for ~$320M by forging a "guardian" signature to mint wrapped SOL on Ethereum and withdraw it. It was one of the largest bridge exploits of 2022 — a year defined by bridge attacks.

    Root cause
    A signature-verification flaw: the attacker bypassed the bridge’s guardian set and minted wrapped assets without the corresponding deposits, then redeemed them for real assets.
    Aftermath
    Jump Crypto (Wormhole’s backer) reimbursed users; accelerated the focus on bridge security and multi-signature guardian structures. Bridges remain the most-exploited DeFi category.

    Sources:

  • Ronin Bridge hack

    Mar 2022 · ~$620M

    DeFi exploit

    Target: Ronin bridge (Axie Infinity / Sky Mavis)
    Perpetrator: Lazarus Group (DPRK) — OFAC-designated

    The Ronin bridge backing Axie Infinity was drained of ~$620M by North Korea’s Lazarus Group — the largest crypto theft on record at the time, until the Bybit hack of February 2025. OFAC designated the Lazarus Group and associated addresses over the exploit.

    Root cause
    The attacker compromised 5 of 9 validator signing keys (a quorum the bridge required), then approved fraudulent withdrawals. Sky Mavis didn’t detect the breach until a user reported being unable to withdraw — six days later.
    Aftermath
    OFAC designated the Lazarus Group; a defining case for state-sponsored crypto theft and validator-key security. The UN Panel of Experts has since documented DPRK crypto theft as a weapons-funding revenue stream.

    See the DPRK jurisdiction card on the Regulation by Country page for the sanctions angle.

    Sources:

  • Beanstalk governance capture

    Apr 2022 · ~$182M

    DeFi exploit

    Target: Beanstalk protocol (Ethereum)
    Perpetrator: Unknown attacker using a flash loan

    The Beanstalk stablecoin protocol was drained of ~$182M when an attacker used a flash loan to acquire enough voting power to pass a malicious governance proposal — executed in a single block. The DAO had no voting delay.

    Root cause
    A flash-loan governance capture: the attacker borrowed enough BEAN voting power for one transaction, passed a proposal that granted them control of the Comptroller, and drained funds — all in one block.
    Aftermath
    The textbook case for governance delays, quorum/supermajority requirements, and flash-loan-resistant voting. Covered in the DAOs module as the canonical flash-loan-capture example.

    Sources:

  • Nomad bridge exploit

    Aug 2022 · ~$190M

    DeFi exploit

    Target: Nomad bridge
    Perpetrator: Many copycat attackers (a "crowd-sourced" exploit)

    The Nomad bridge was drained of ~$190M in a chaotic exploit where, once the initial vulnerability was found, many copycat attackers simply replicated the exploit transaction with their own addresses. It became a rare "crowd-sourced" hack.

    Root cause
    A routine code update initialized the bridge’s "committedRoot" to 0x00, which made every message hash valid — so anyone could send a transaction claiming to withdraw any amount.
    Aftermath
    A stark lesson on initialization bugs and the "millions of attackers at once" failure mode. Nomad published a post-mortem and coordinated partial recovery; the case is cited in bridge-security discussions.

    Sources:

  • Lazarus Group (DPRK)

    Apr 2022 · ~$620M (Ronin) + billions cumulative

    State-sponsored

    Target: Ronin Bridge and others (cross-chain bridges, exchanges)
    Perpetrator: Lazarus Group / DPRK state actors

    North Korea’s Lazarus Group is the most prolific state-sponsored crypto thief, linked to the Ronin Bridge exploit and an estimated billions in cumulative theft. OFAC has designated the group and associated wallet addresses, and the UN Panel of Experts has documented the activity as a weapons-funding revenue stream.

    Root cause
    State capacity: APT-style intrusion (social engineering of employees, compromised validator keys), combined with the irreversibility of crypto and the anonymity of laundering through mixers and bridges.
    Aftermath
    OFAC designation; global sanctions-screening obligations on VASPs; a flagship case for the intersection of crypto, sanctions, and weapons proliferation. The DPRK is treated as a sanctioned jurisdiction on the Regulation by Country page.

    The Tracing module covers the chain-analysis techniques used to attribute DPRK activity.

    Sources:

  • Garantex exchange

    Apr 2022 · N/A (sanctions evasion venue)

    State-sponsored

    Target: Garantex (Russia-based exchange)
    Perpetrator: Sanctions evasion (Russian illicit finance)

    OFAC designated Garantex, a Russia-based exchange, alongside Hydra marketplace, for facilitating ransomware and illicit-finance flows. It kept operating for nearly three years despite the designation — until March 2025, when US authorities seized the exchange and the DOJ charged two of its administrators with money laundering, closing a years-long enforcement gap against non-compliant venues.

    Root cause
    A non-compliant venue willing to process sanctioned and illicit flows; the difficulty of enforcing sanctions against offshore/non-cooperative exchanges.
    Aftermath
    A flagship case for crypto-sanctions enforcement: designated in 2022 but only taken down in March 2025, when US authorities seized the exchange and the DOJ charged two administrators with money laundering. Pairs with the Tornado Cash case to show the spectrum of crypto-sanctions targets.

    Sources:

  • Terra / Luna collapse

    May 2022 · ~$40B (market cap destroyed)

    Fraud / Ponzi

    Target: TerraUSD (UST) algorithmic stablecoin + Luna
    Perpetrator: Design failure; SEC charges against Do Kwon (fraud)

    The algorithmic stablecoin TerraUSD (UST) lost its peg and its sister token Luna collapsed to zero, wiping out ~$40B in days and triggering contagion (Celsius, BlockFi, 3AC). The SEC later charged Terraform Labs and Do Kwon with defrauding investors.

    Root cause
    The algorithmic-peg design was inherently fragile: UST’s peg depended on arbitrage against Luna, which collapsed under selling pressure. The SEC alleges Do Kwon also misrepresented reserves and risks.
    Aftermath
    A defining DeFi failure that ended the "algorithmic stablecoin" thesis for most observers. SEC charges (2023); Do Kwon arrested in Montenegro. Accelerated the 2022 contagion and the push for stablecoin reserve rules (MiCA, US proposals).

    Categorized as Fraud/Ponzi due to the SEC fraud charges; the primary failure was a design collapse, but the operator misrepresented reserves and risks.

    Sources:

  • Celsius Network

    Jul 2022 · ~$1.2B (customer shortfall)

    Fraud / Ponzi

    Target: Celsius lending platform
    Perpetrator: Operator fraud (SEC charges against Alex Mashinsky)

    Crypto lender Celsius filed for bankruptcy in 2022 after halting withdrawals, revealing a ~$1.2B shortfall. The SEC charged founder Alex Mashinsky with fraud and misrepresenting the platform’s financial health.

    Root cause
    Celsius deployed customer funds into risky positions (including leveraged DeFi and illiquid assets) while promising "safe" returns; when the market turned, the shortfall was exposed. The SEC alleges Mashinsky misled customers about the risks.
    Aftermath
    Chapter 11 bankruptcy; SEC charges (2023); part of the 2022 contagion alongside BlockFi and 3AC. Cited in CeFi-lending-risk and custody debates.

    Sources:

  • Harmony Bridge hack

    Jun 2022 · ~$100M

    DeFi exploit

    Target: Harmony Horizon bridge (Ethereum ↔ BSC)
    Perpetrator: Lazarus Group / "TraderTraitor" (DPRK) — FBI attributed

    Harmony's Horizon cross-chain bridge was drained of ~$100M when the attacker compromised two of the five multi-sig keys needed to authorize withdrawals, then approved fraudulent transfer transactions. The FBI and Harmony later attributed the theft to DPRK's Lazarus/TraderTraitor actors.

    Root cause
    The bridge required only a 2-of-5 multi-sig quorum to authorize transactions; the attacker compromised two signing keys, giving them enough authority to approve withdrawals. Detection lagged until after the funds had moved.
    Aftermath
    Harmony reimbursed affected users with its own (printable) ONE tokens, diluting existing holders. Funds were laundered through Tornado Cash and later mingled with Ronin/Lazarus proceeds — a defining case in the DPRK bridge-attack pattern alongside Ronin.

    Pairs with Wormhole (Feb 2022) and Ronin (Mar 2022) as the trio of major 2022 bridge exploits; Harmony and Ronin were attributed to the same DPRK actor cluster, while Wormhole was never publicly attributed.

    Sources:

  • Tornado Cash

    Aug 2022 · N/A (mixing service)

    State-sponsored

    Target: Tornado Cash (Ethereum privacy mixer)
    Perpetrator: Sanctioned mixer; developers prosecuted

    OFAC sanctioned the Tornado Cash mixing contracts in August 2022, treating the immutable smart contracts themselves as sanctioned property — an unprecedented step. The case split the crypto-privacy debate and culminated in a November 2024 Fifth Circuit ruling that immutable smart contracts are not "property" and can't be sanctioned, leading Treasury to delist the contracts in March 2025.

    Root cause
    Tornado Cash was used (not exclusively) to launder billions in stolen crypto, including DPRK-linked proceeds. The policy question: can code itself be sanctioned, or only the people and entities who operate it?
    Aftermath
    Developer Roman Storm was indicted (2023) and convicted in August 2025 on one of the three counts against him — conspiracy to operate an unlicensed money transmitting business — while Alexey Pertsev was convicted in the Netherlands (2024); the November 2024 Van Loon v. Treasury ruling and the March 2025 OFAC delisting marked a partial walk-back. A landmark case at the intersection of privacy, sanctions, and code-as-speech. Covered in the Privacy module and a dedicated deep dive.

    Has a dedicated deep-dive page; this entry anchors it in the consolidated bad-actors listing.

    Sources:

  • Hydra Market

    Apr 2022 · N/A (~$5B lifetime transaction volume)

    State-sponsored

    Target: Hydra Market (Russia-based darknet market)
    Perpetrator: Sanctioned / seized (German-led takedown + OFAC)

    Hydra, Russia's largest darknet market and a major crypto-laundering venue for ransomware and narcotics, was seized by German authorities and concurrently sanctioned by OFAC in April 2022. Its lifetime transaction volume was estimated at ~$5B.

    Root cause
    A non-compliant, offshore marketplace operating with apparent Russian tolerance; crypto was the settlement layer enabling global illicit trade.
    Aftermath
    A flagship crypto-sanctions action alongside the Garantex designation. Cited in darknet-market and ransomware-laundering discussions; a broader "bad-actor infrastructure" case than a single hack.

    Sources:

  • Three Arrows Capital (3AC)

    Jun 2022 · ~$10B (collapsed AUM)

    Fraud / Ponzi

    Target: Three Arrows Capital (Singapore-based crypto hedge fund)
    Perpetrator: Operator mismanagement (Su Zhu, Kyle Davies)

    Crypto hedge fund Three Arrows Capital collapsed in 2022 after over-leveraged bets (GBTC, Luna) turned against it, wiping out an estimated ~$10B and triggering contagion across Voyager, BlockFi, and Genesis. Founders Su Zhu and Kyle Davies were later banned from Singapore and pursued by liquidators.

    Root cause
    Extreme leverage on directional crypto bets, opaque counterparty exposure, and no meaningful risk management; the Luna collapse (3AC held large Luna positions) was the proximate trigger.
    Aftermath
    A key node in the 2022 contagion chain — 3AC's default pushed Voyager and BlockFi toward bankruptcy and left Genesis exposed. Liquidators seized assets; Zhu and Davies faced contempt findings. Cited as the defining non-exchange collapse of 2022.

    Not a Ponzi per se, but categorized with frauds for the contagion context; the primary failure was reckless leverage and opacity.

    Sources:

  • Voyager Digital

    Jul 2022 · ~$670M (3AC exposure) + customer losses

    Fraud / Ponzi

    Target: Voyager Digital (crypto broker/lender)
    Perpetrator: Counterparty exposure (3AC default) + marketing misconduct

    Crypto lender Voyager filed for Chapter 11 days after 3AC defaulted on a ~$670M loan, exposing Voyager's heavy concentration risk. Voyager had also marketed its USD deposits as FDIC-insured in a way regulators and courts later scrutinized — the contagion case for the 3AC collapse.

    Root cause
    Massive unsecured exposure to a single counterparty (3AC), combined with misleading "FDIC-insured" marketing of crypto deposits. When 3AC defaulted, Voyager was insolvent.
    Aftermath
    Bankruptcy; assets later acquired by Binance.US (which fell through) then by creditors. A defining contagion-and-custody case tying 3AC to the broader 2022 lending collapse alongside BlockFi and Celsius.

    Categorized with frauds for the marketing-misconduct angle; the immediate trigger was counterparty (3AC) risk.

    Sources:

  • BlockFi

    Nov 2022 · Bankruptcy (FTX/Alameda exposure)

    Fraud / Ponzi

    Target: BlockFi (crypto lending platform)
    Perpetrator: Counterparty exposure (FTX/Alameda collapse)

    Crypto lender BlockFi filed for Chapter 11 weeks after FTX collapsed, having depended on FTX/Alameda for both a rescue loan and custody — the FTX collapse made BlockFi insolvent. It had earlier settled SEC charges over its interest-bearing lending product.

    Root cause
    Dependence on FTX (rescue financing and asset custody) layered on an earlier SEC enforcement over unregistered lending. When FTX fell, BlockFi had neither a lender nor clear title to its assets.
    Aftermath
    Bankruptcy completed in 2024 with creditor recoveries. Completes the 2022 contagion chain (Luna → 3AC → Voyager/Celsius → FTX → BlockFi) and is cited in CeFi-lending and qualified-custody debates.

    Sources:

  • Satish Kumbhani

    2022 · ~$2.4B (BitConnect)

    Fraud / Ponzi

    Target: BitConnect founder (fugitive)
    Perpetrator: Satish Kumbhani (DOJ-indicted, at large)

    BitConnect founder Satish Kumbhani was indicted by the DOJ in February 2022 for orchestrating the ~$2.4B BitConnect Ponzi (see the BitConnect entry) and remained at large — a named-individual bad actor in the BitConnect fraud, distinct from the scheme's mechanics.

    Root cause
    A founder who allegedly built and profited from a Ponzi while a network of promoters sold it to retail investors; the DOJ charged him with securities fraud and conspiracy.
    Aftermath
    Kumbhani remained a fugitive after the 2022 indictment; several promoters were separately charged. Cited alongside Ruja Ignatova (OneCoin) as a "crypto-Ponzi founder on the run" bad-actor profile.

    An actor-style entry cross-referencing the BitConnect case; see the BitConnect entry for the scheme itself.

    Sources:

  • Curve exploit

    Jul 2023 · ~$70M

    DeFi exploit

    Target: Curve Finance pools (Ethereum)
    Perpetrator: Unknown attacker exploiting a Vyper compiler bug

    A Vyper compiler bug let an attacker drain ~$70M from Curve pools using the vulnerable compiler version. It triggered a broader DeFi contagion scare and showed that even battle-tested protocols can be undone by dependencies few people scrutinize.

    Root cause
    A reentrancy lock bug in the Vyper compiler (specific version) — the lock was supposed to prevent re-entry but failed, allowing the attacker to re-enter Curve pool functions and drain them.
    Aftermath
    Showed that compiler/dependency risk is as real as contract risk. Some funds were recovered via white-hat returns; the case reshaped how Curve and other protocols vet their compiler version pinning.

    Sources:

  • Euler Finance exploit

    Mar 2023 · ~$197M

    DeFi exploit

    Target: Euler Finance (Ethereum lending protocol)
    Perpetrator: Unknown attacker — later returned most funds

    Euler Finance was drained of ~$197M via a flash-loan-enabled exploit of a donation/liquidation logic flaw. After negotiations, the attacker returned most of the funds — another rare white-hat outcome.

    Root cause
    A logic flaw in Euler’s donation function, combined with a liquidation mis-pricing, let the attacker use a flash loan to create a self-referential debt position and extract funds.
    Aftermath
    Most funds were returned after on-chain negotiation. The case is cited in liquidation-design and flash-loan-risk discussions; Euler published a detailed post-mortem.

    Sources:

  • Orbit Bridge

    Dec 2023 · ~$81.5M

    DeFi exploit

    Target: Orbit Bridge (cross-chain bridge by Orbit Chain)
    Perpetrator: Suspected DPRK/Lazarus (developer firm later alleged a former CISO)

    Orbit Bridge was drained of ~$81.5M in the final hours of 2023, spilling into January 2024. The attack compromised the bridge's multisig; the developer firm later alleged a former CISO had "abruptly made the firewall vulnerable" before departing.

    Root cause
    A multisig compromise — the attacker obtained enough signing authority to approve fraudulent withdrawals. Transaction-replay bugs were also considered. The insider-CISO allegation, if true, points to insider-enabled compromise.
    Aftermath
    A late-2023 bridge exploit that bookended a year of bridge attacks and set the stage for 2024's signing-layer focus. Pairs with Wormhole/Ronin/Poly in the bridge-risk pattern.

    Categorized by event date (Dec 31, 2023) but included here as a 2023/2024 boundary case relevant to recent trends.

    Sources:

  • KyberSwap

    Nov 2023 · ~$49M

    DeFi exploit

    Target: KyberSwap Elastic (concentrated-liquidity AMM)
    Perpetrator: Unknown attacker exploiting a tick-math precision bug

    KyberSwap's Elastic concentrated-liquidity pools were drained of ~$49M through a novel precision/tick-math bug that let the attacker extract value from liquidity positions by manipulating the tick boundaries. The attacker posted an on-chain "negotiation" message and later returned a small portion.

    Root cause
    A subtle precision bug in Kyber's concentrated-liquidity math — the kind of flaw unique to tick-based AMMs (cf. Uniswap v3 forks). The exploit was sophisticated enough that pools on other AMMs were paused as a precaution.
    Aftermath
    KyberNetwork proposed a recovery plan and bounty; the case reshaped how concentrated-liquidity forks audit their tick math. A reminder that AMM innovation (concentrated liquidity) brings new, subtle attack classes.

    Sources:

  • Atomic Wallet

    Jun 2023 · ~$100M+

    Exchange hack

    Target: Atomic Wallet (non-custodial wallet users)
    Perpetrator: DPRK / "TraderTraitor" (Elliptic/Chainalysis attribution)

    Thousands of Atomic Wallet users lost >$100M in a mass compromise of the popular non-custodial wallet — a rare case where users of a self-custody product were drained directly. Chainalysis and Elliptic attributed the laundering to DPRK's TraderTraitor actors.

    Root cause
    The exact vector was not definitively disclosed; suspected supply-chain compromise of an Atomic Wallet update or a dependency. Distinct from exchange hacks because users held their own keys but the wallet software itself was poisoned.
    Aftermath
    A defining case for non-custodial-wallet supply-chain risk: self-custody protects against exchange failure but not against compromised wallet software. Reinforces the Tracing module's DPRK laundering-path coverage.

    Categorized as Exchange hack for filter convenience; technically a non-custodial-wallet compromise.

    Sources:

  • BALD token

    Jul 2023 · ~$25M+

    Fraud / Ponzi

    Target: BALD memecoin (Base L2 launch)
    Perpetrator: Anonymous developer ("Bald")

    BALD, a memecoin that launched on the then-new Coinbase Base L2, surged dramatically on hype around the chain's launch before its anonymous developer pulled liquidity, costing holders ~$25M+. The developer later returned some funds after backlash.

    Root cause
    A rug pull by an anonymous developer on a brand-new L2: concentrated holdings and add-only liquidity let the deployer extract value. The L2-launch hype drew buyers who assumed the chain's launch implied project legitimacy.
    Aftermath
    A defining case for L2-launch and anonymous-developer risk: a new chain's debut does not vet its tokens. Cited alongside the Squid Game token as an "anon-dev rug" teaching example.

    Sources:

  • Justin Sun / TRON

    Mar 2023 · N/A (fraud/market-manipulation charges)

    Fraud / Ponzi

    Target: TRX, BTT and the TRON ecosystem; Poloniex/HTX exchanges
    Perpetrator: Justin Sun (SEC fraud/manipulation charges)

    The SEC charged Justin Sun and his companies with fraud and market manipulation for orchestrating unregistered offers of TRX and BTT, wash-trading to inflate volume, and paying celebrities to promote the tokens. Sun's exchanges (Poloniex, later HTX) were also hit by large hacks — Poloniex lost ~$114M in Nov 2023.

    Root cause
    Alleged wash-trading and a paid-promotion scheme to manufacture demand, layered on unregistered token sales. The case treats on-chain market manipulation as securities fraud — paralleling the Eisenberg conviction.
    Aftermath
    The SEC dropped the case in February 2025, shortly after the change in US administration. A named-individual fraud/manipulation case alongside FTX/SBF and Celsius/Mashinsky, and the TRON-ecosystem counterpart to those collapses. Cited in market-manipulation and celebrity-endorsement-risk discussions.

    A bad-actor entry (named individual) — the TRON counterpart to the SBF and Mashinsky entries.

    Sources:

  • DMM Bitcoin

    May 2024 · ~$304M (≈4,503 BTC)

    State-sponsored

    Target: DMM Bitcoin exchange (Japan)
    Perpetrator: DPRK / TraderTraitor (Japan NPA attribution)

    Japan-based DMM Bitcoin lost ~$304M in BTC — the largest Japanese exchange theft since Mt. Gox. Japan's National Police Agency later attributed it to DPRK's TraderTraitor group, via a fake LinkedIn recruiter who sent a malicious "pre-employment test" to an employee at a wallet-software vendor.

    Root cause
    Social engineering: a malicious file delivered via a fake recruiter compromised a vendor employee's machine, which was then used to manipulate a legitimate transaction and drain the exchange wallet. Classic DPRK APT tradecraft applied to crypto.
    Aftermath
    DMM Bitcoin suspended withdrawals and sought capital injection to make customers whole. Reinforced the pattern of DPRK targeting exchanges via social engineering of staff and vendors; cited in AML/tracing discussions alongside the Ronin and Bybit cases.

    Sources:

  • WazirX

    Jul 2024 · ~$235M

    Exchange hack

    Target: WazirX exchange (India, Safe multisig at Liminal Custody)
    Perpetrator: Unconfirmed (analysts suggested DPRK-linked)

    Indian exchange WazirX was drained of ~$235M from a Safe multisig wallet held at Liminal Custody. The attackers compromised 2 of 4 required keys and signature-phished the other 2, tricking signers into approving a malicious wallet upgrade that bypassed Liminal's checks.

    Root cause
    A multisig compromise combining key theft and signature phishing: the signers believed they were approving a routine upgrade, but the payload bypassed the custodian's verification. The exact entry point for the key theft was not fully disclosed.
    Aftermath
    WazirX halted withdrawals and entered a restructuring; India's largest crypto hack at the time. A case study in custodial multisig risk and the failure of the verifier layer (Liminal) to catch the malicious payload.

    Sources:

  • Radiant Capital (Oct 2024)

    Oct 2024 · ~$53M

    DeFi exploit

    Target: Radiant Capital (cross-chain lending protocol)
    Perpetrator: Suspected DPRK-linked (malware-injected signer devices)

    Radiant Capital was drained of ~$53M when malware was injected into the private-key signer devices of its operators, enabling a malicious transfer of ownership and drainage. The attack bypassed the protocol's own audits by compromising the human signing layer rather than the contract code.

    Root cause
    Malware on the physical signer devices let attackers capture signing keys and push a malicious ownership-transfer and drain transaction that the operators unknowingly signed. A 2024-defining case for "the human signing layer is now the target."
    Aftermath
    Radiant published a post-mortem emphasizing hardware-signer malware and the limits of contract-level audits. Pairs with Bybit and WazirX as a year where the signing/operational layer, not the smart contract, was the primary attack surface.

    A smaller Radiant incident also occurred in Jan 2024 (~$4.5M) via a known bug in forked Aave V2 code; this entry covers the larger October incident.

    Sources:

  • Penpie

    Sep 2024 · ~$27M

    DeFi exploit

    Target: Penpie (yield-farming protocol on Pendle)
    Perpetrator: Unknown (anonymous Ethereum addresses)

    Penpie was drained of ~$27M via a reentrancy bug in its batchHarvestMarketRewards() function, exploited through a fake Pendle market that inflated the attacker's staking balance and let them claim unearned rewards.

    Root cause
    A classic reentrancy: a fake market contract re-entered the harvest function before state settled, letting the attacker claim rewards repeatedly. The integration with Pendle introduced the reentrancy surface that Penpie's own code didn't guard against.
    Aftermath
    A reminder that reentrancy — the original 2016 DAO bug class — is still finding victims in 2024 through integration surfaces, not just standalone contracts. Covered alongside the Smart Contracts module's reentrancy teaching.

    Sources:

  • BingX

    Sep 2024 · ~$45M

    Exchange hack

    Target: BingX exchange (hot wallet)
    Perpetrator: Unconfirmed (analysts noted Lazarus-consistent behavior)

    BingX's hot wallet was compromised for ~$45M; the exchange cited "abnormal network access." Exact attribution and vulnerability were not publicly confirmed, though on-chain analysts noted patterns consistent with DPRK-linked actors.

    Root cause
    A hot-wallet compromise; the specific vector was not disclosed. Consistent with the pattern of 2024 exchange attacks targeting the operational/hot-wallet layer.
    Aftermath
    BingX suspended withdrawals and reported working to recover funds. One of several 2024 exchange hot-wallet compromises; reinforces the hot-vs-cold-wallet risk distinction in the Wallets module.

    Sources:

  • Polter Finance

    Nov 2024 · ~$8.7M

    DeFi exploit

    Target: Polter Finance (lending protocol on Fantom)
    Perpetrator: Unknown (flash-loan oracle manipulator)

    Polter Finance was drained of ~$8.7M via flash-loan price manipulation: the protocol used a low-liquidity SpookySwap pool as its BOO-token oracle, so the attacker flash-borrowed BOO to inflate its price, then borrowed against the inflated collateral.

    Root cause
    An oracle manipulation: relying on a low-liquidity DEX pool for pricing let a flash loan move the price arbitrarily in one transaction. The code reportedly relied on a Geist audit report but was not independently audited for this oracle design.
    Aftermath
    A textbook oracle-manipulation case (a recurring DeFi failure class). Cited in oracle-risk and "don't use thin pools as oracles" guidance; reinforces the DeFi and Smart Contracts modules' oracle-manipulation coverage.

    Sources:

  • Munchables

    Mar 2024 · ~$62.5M (recovered)

    DeFi exploit

    Target: Munchables (NFT game on Blast L2)
    Perpetrator: Insider — a rogue developer (funds returned)

    Munchables, an NFT game on the Blast L2, was drained of ~$62.5M by an insider: a rogue developer who had hidden a backdoor in an upgradeable proxy, manipulating storage slots to assign himself a huge ETH balance. After on-chain sleuth ZachXBT exposed the developer, the funds were returned.

    Root cause
    An insider backdoor in an upgradeable proxy contract — the developer manually manipulated storage slots to grant a huge balance. Four "distinct" developers were likely the same person, a classic insider-threat pattern.
    Aftermath
    Funds were returned after the developer was identified. A defining case for insider-risk in NFT/game contracts, upgradeable-proxy storage manipulation, and the role of on-chain sleuths (ZachXBT) in attribution and recovery.

    A rare "insider attack then refund" — pairs with Poly Network and Euler as cases where funds came back.

    Sources:

  • Kraken

    Jun 2024 · ~$3M (recovered)

    Exchange hack

    Target: Kraken exchange
    Perpetrator: Security researcher (disputed as theft by Kraken)

    A security researcher exploited a zero-day that let them post fake account balances and withdraw real funds past daily limits, netting ~$3M. Kraken treated it as theft rather than a bug-bounty report and recovered the funds; the incident raised questions about responsible-disclosure norms in crypto.

    Root cause
    A zero-day in balance/withdrawal logic allowed artificially-inflated balances to be withdrawn. The researcher disclosed the exploit but had already withdrawn the funds, which Kraken argued crossed from disclosure into theft.
    Aftermath
    Funds recovered; the case sparked debate about bug-bounty norms, when disclosure becomes extortion, and how exchanges handle researchers who exploit before reporting. Cited in security/bug-bounty-policy discussions.

    A gray-area case — neither a typical hack nor a clean bug-bounty. Useful for teaching responsible-disclosure norms.

    Sources:

  • Mango Markets / Eisenberg

    Apr 2024 · ~$110M (2022 exploit; 2024 conviction)

    Fraud / Ponzi

    Target: Mango Markets (Solana DEX)
    Perpetrator: Avraham Eisenberg (self-described "legal arbitrage"; convicted 2024)

    Avraham Eisenberg manipulated Mango Protocol's oracle/swap mechanism with two accounts to inflate the MNGO token price and borrow ~$110M against it (Oct 2022). He publicly described it as "legal arbitrage," but a SDNY jury convicted him of commodities fraud and manipulation in April 2024 — a landmark "on-chain manipulation is still fraud" case.

    Root cause
    Oracle manipulation: the attacker controlled both sides of a thin market to move MNGO's price, then used the inflated collateral value to borrow real assets from Mango. The protocol's design relied on a manipulable price feed.
    Aftermath
    Conviction (April 2024) established that on-chain manipulation framed as "arbitrage" can be prosecuted as fraud. Sentencing in 2025. A defining case for DeFi market-manipulation law and the "code is law" defense's limits.

    Sources:

  • Sonne Finance

    May 2024 · ~$20M

    DeFi exploit

    Target: Sonne Finance (Compound-fork lending protocol)
    Perpetrator: Unknown attacker (reentrancy in a forked market)

    Sonne Finance, a Compound v2 fork, was drained of ~$20M through a reentrancy bug exposed via a newly listed market — the classic reentrancy-against-an-integration-surface pattern. The flaw traced to forked, unaudited listing logic.

    Root cause
    A reentrancy in Sonne's market redemption path — the same bug class as The DAO (2016) and Penpie (2024), this time through a forked Compound market's redeem flow that didn't guard against re-entry.
    Aftermath
    A 2024 reminder that "fork a battle-tested protocol" is not the same as "inherit its security," and that reentrancy keeps finding victims through integration/listing surfaces. Covered alongside the Smart Contracts module's reentrancy teaching.

    Sources:

  • Hyperverse / HyperFund

    2024 · ~$1.3B

    Fraud / Ponzi

    Target: HyperVerse / HyperFund ("metaverse ROI" investment platform)
    Perpetrator: Operators (DOJ indicted 2024)

    HyperFund and its rebrand "HyperVerse" promised guaranteed daily returns from "metaverse" investments and crypto mining, drawing ~$1.3B from investors globally before collapsing. The DOJ indicted operators in 2024, describing a Ponzi paying early investors with new deposits and a celebrity-backed promotion network.

    Root cause
    A Ponzi wrapped in "metaverse" and mining hype: fabricated returns funded by new deposits, with paid celebrity endorsements (Chuck Norris and others appeared at events) lending false legitimacy.
    Aftermath
    DOJ indictments (2024); a recent large-scale Ponzi still in active prosecution. Cited as a 2020s successor to BitConnect and OneCoin in the "fake-yield + celebrity endorsement" pattern.

    Sources:

  • Bybit hack

    Feb 2025 · ~$1.46B (≈400K ETH)

    State-sponsored

    Target: Bybit exchange (Ethereum cold wallet via Safe{Wallet})
    Perpetrator: DPRK / Lazarus Group — FBI attributed as "TraderTraitor"

    Bybit was drained of ~$1.46B in ETH — the largest crypto heist on record — when attackers compromised the Safe{Wallet} multisig interface, presenting a malicious transaction payload that Bybit signers approved as routine. The FBI publicly attributed the attack to DPRK state actors ("TraderTraitor").

    Root cause
    A supply-chain compromise of the third-party multisig UI: the signers saw a normal-looking withdrawal but signed a transaction that transferred control of the cold wallet to the attacker. The base-chain transaction was valid; the deception happened at the signing layer.
    Aftermath
    Bybit covered the loss and processing resumed within days; the FBI and on-chain analysts traced laundering through mixers and bridges. A defining case for supply-chain and signing-UI security, and for DPRK state-sponsored crypto theft scale. Reinforced the Tracing and Privacy modules' point that the on/off-ramp and laundering path are where attribution happens.

    Surpassed Ronin (~$620M, 2022) as the largest single crypto theft. The signing-UI deception, not a smart-contract bug, was the root cause.

    Sources:

  • Coinbase data breach

    May 2025 · No direct fund loss (~$400M remediation est.)

    Exchange hack

    Target: Coinbase (customer PII via bribed support agents)
    Perpetrator: Cybercriminals who bribed overseas support agents

    Coinbase disclosed that bribed overseas support agents exfiltrated customer personal data (no passwords, private keys, or direct fund theft). The attackers demanded a $20M ransom, which Coinbase refused, estimating up to ~$400M in remediation and customer reimbursement. A data-breach case rather than a fund theft.

    Root cause
    An insider threat: support agents were bribed to exfiltrate customer PII for use in social-engineering attacks. The breach was of personal data, not custodial funds — but enables downstream theft via phishing.
    Aftermath
    Coinbase disclosed via 8-K, refused to pay the extortion, and budgeted for customer reimbursement. A reminder that the threat surface includes PII and insider access, not just smart contracts and hot wallets. Pairs with the Security module's phishing/social-engineering coverage.

    Included despite no direct fund loss because it is a major 2025 incident and a different attack class (PII/insider) relevant to the Security module.

    Sources:

  • $LIBRA (Viva La Libertad)

    Feb 2025 · ~$4.5B market cap destroyed (~$250M+ user losses)

    Fraud / Ponzi

    Target: $LIBRA memecoin (Solana)
    Perpetrator: Hayden Davis and associates; promoted by President Milei

    A Solana memecoin branded "Viva La Libertad" briefly surged after Argentine President Javier Milei promoted it on social media, then collapsed when he deleted the post, wiping out ~$4.5B of market cap and leaving retail holders with ~$250M+ in losses. Milei denied wrongdoing and fired an advisor; the affair prompted fraud probes.

    Root cause
    A politically-endorsed memecoin rug: concentrated insider holdings and liquidity were extracted after the presidential promotion pumped the price. The scheme depended entirely on the credibility signal from a head of state.
    Aftermath
    Argentine and international fraud investigations; political fallout for Milei; a defining case for politically-endorsed memecoins and the "head-of-state pump" as a new rug-pull vector. Cited in scam-education as a 2025 escalation of celebrity-endorsed tokens.

    Politically and jurisdictionally unique — the most notable 2025 fraud not already on the page.

    Sources:

Educational only, not financial or legal advice.