Preparing your view
Checking the session, access policy, and current workspace data.
Checking the session, access policy, and current workspace data.
Browse structured studies of major crypto incidents. Each record brings the reported impact, attack type, timeline, and investigation context into one clear place.
Browse all casesSearch by keyword or filter by year, chain, and attack type. Open any case for the reported context and investigation sequence.
Search the archive or narrow it by year, chain, and attack type.
RPC Infrastructure Compromise
Compromised DVN oracle led to $292M RSeth drain via cross-chain message forgery.
Fake Token + Compromised Admin + Oracle Manipulation
On April 1, 2026, Drift Protocol suffered a $286M triple-vector attack: a fake collateral token accepted by the vault, a compromised admin key that disabled circuit breakers, and manipulated oracle prices used by the perpetuals engine.
Treasury Phishing
Private keys stolen via phishing, $27.3M drained.
Integer Overflow in Purchase
Unlimited TRU minting via legacy overflow, $26.2M lost.
AWS KMS Key Leak - 80M USR Minted
Compromised AWS KMS key allowed 80M USR minting, causing $25M drain and 80% depeg.
Slippage Protection Logic Flaw
Slippage protection failed to account for reused intermediate tokens in multi-step swaps, causing $18.4M drain.
Signer Key Leak — Multisig Airdrop Redirect
Leaked signer private key redirected multisig GUA airdrop ($15.18M) to attacker lookalike address on Ethereum.
Supply Cap Bypass via Donation Attack
Donation attack bypassed supply caps by direct transfers, inflating collateral 3.67x for $14.9M drain.
Hot Wallet Drain — Foreign Actor Attribution
Grinex exchange hot wallets drained for $13.7M–$15M; exchange attributed the attack to foreign state actors.
Missing Source-Amount Validation in checkCCEValues
Missing source-amount validation in checkCCEValues let attacker mint unbacked bridged assets, draining $11.58M.
Malicious Node + GG20 TSS Key Leak
Malicious THORChain node progressively leaked GG20 TSS key material; unapplied patch led to $10.7M drain.
Private Key Compromise (Bridge)
Attacker obtained owner key to ioTube bridge validator contract and drained $8.9M in assets.
Review the archive provenance, then locate primary sources and separate verified facts from teaching reconstructions.
Use the ordered phases to form testable questions about access, execution, asset movement, and response.
Take reported addresses and contracts into your own evidence-backed ChainRadar case workflow.