On-chain Data Suggests Crypto Hacks and DeFi Exploits are on … – Securities.io
More than $320 million was lost to bad actors within the crypto space in the first quarter of the year as per data compiled by smart contract security platform CertiK. The figure represented a significant decline from that in the preceding quarter (Q4 2022) and from a similar period in the previous year. The blockchain security firm attributed this decrease to distressing incidents that rocked the industry across the three months.
Notable among them, an upheaval in the stablecoin markets and a banking crisis extending into the digital assets space. These and other unfortunate incidents prompted investors to move their funds to the sidelines while also putting off potential entrants and inflows as a result. Barely halfway into Q2, more exploit incidents have been reported with attributable losses headed to equal the figure reported in Q1.
In March, about $211 million was stolen in crypto, dominated by a $197 million hack on Euler Finance. The amount siphoned last month was slightly less than half of this, with blockchain security firm Certified Kernel Tech (CertiK) estimating a figure of $103.7 million in losses to exploits, hacks, and scams.
April and March numbers brought the total amount stolen by malicious actors in the first four months to $429.7 million year-to-date. Another major incident in April was the Ethereum Maximal Extractable Value (MEV) bot sandwich attack which resulted in a $25.4 million loss. Bitrue exchange also reportedly had $23 million in Ether and other currencies drained from one of its hot wallets.
Decentralized finance aggregator, Yearn Finance led in flash loan attacks last month, with only users running on an older version of the protocol affected. PeckShield reported on April 13 that a hacker targeted a bug to mint an extremely huge amount of yUSDT 1.3 quadrillion tokens, worth about $11.6 million from just 10,000 USDT. In a series of swaps that ensued afterward, the attacker was able to obtain 61,000 USDP, 1.5 million TUSD, 1.79 million BUSD, 1.2 million USDT, 2.58 million USDC, and 3 million DAI.
Multi-chain lending pool Hundred Finance lost $7.4 million on April 15 after suffering a security breach involving flash loaning WBTC on Ethereum layer two Optimism. The protocol has since placed a $500,00 bounty on the hacker after efforts to negotiate seemingly bore no fruits. Hundred Finance was previously hit to the tune of $6.5 million in a reentrancy attack in March 2022. The blockchain security firm further showed that total funds lost to exit scams increased to $9.4 million in April, heralded by the decentralized exchange Merlin.
zkSync decentralized exchange Merlin's loss of $1.82 million came on April 25, during the three-day public sale of its MAGE tokens, despite brandishing an audit by CertiK. The DEX, whose popularity stems from the attractive yield offered on deposits, confirmed the attack advising all users to disengage their wallet permissions. CertiK meanwhile termed it a private key management issue.
In a thread addressing the incident, the blockchain security firm later highlighted that it had pointed out centralization risk under Decentralization Efforts in its audit report of Merlin. Some, however, question the quality of work done by the firm. Meanwhile, the malicious code that allegedly caused the loss of funds was identified by eZKalibur, a decentralized exchange, and launchpad also built on zkSync. eZKalibur pointed out that the initialize function created a backdoor of sorts, allowing an unlimited amount of tokens to be transferred from the contract's address to the feeTo address.
CertiK said on April 26 that it was exploring a compensation plan for the affected while still urging the responsible individuals to return 80% of the funds and keep the rest as a white hat bounty. It further said that rather than an attack, Merlin was a victim of rogue developers which explains why the entity was able to siphon the liquidity pool with such ease. The blockchain security team said the perpetrators are believed to be in Europe and that it is working with law enforcement agencies to bring them to justice should direct negotiations hit a brick wall.
In an update on the situation on Friday, CertiK insisted that all this was a rug pull by Merlin developers who took advantage of their wallet privileges to defraud users. It added that attempts to collaborate with the remaining Merlin team were plagued by challenges as certain core members were unwilling to verify their identities, making validation and eventual assistance of the victims difficult. CertiK has frozen $160,000 of the stolen funds so far and is closely monitoring the remaining amount in hopes of recovery. It is working with law enforcement agencies in the US and UK towards these efforts and also pledged $2 million to help the victims and fight exit scams.
A price oracle manipulation hack struck lending protocol 0VIX at the end of April, causing it to lose more than $2 million following an exploit on the vGHST token, a staked token of blockchain gaming initiative inspired by the popular Tamagotchi game. Blockchain security company PeckShield revealed that the hackers behind the 0VIX Protocol attack utilized a flash loan worth $6.12 million in stablecoins to open vGSHT lending positions.
The attacker(s) afterward manipulated the protocol's price oracle and the vGSHT lending pool in extension they manufactured a spike in the price of GHST, which made the vGHST lending pool insolvent, enabling them to liquidate the pools and walk away with the collateral from the pools. The protocol's core team suspended Polygon POS and zkEVM operations (its token lending markets), adding that it had initiated efforts to manage the situation.
In a subsequent update, the 0VIX Protocol Association said it resumed operations on the zkEVM, allowing users of the 0VIX Polygon zkEVM market unrestricted access to their funds. It asked all users to verify their positions and health factor and repay any outstanding debts. The update further clarified that the pause on 0VIX zkEVM had only been a preventive measure, as the exploit did not affect it. The Association, however, didnt divulge any further details to protect the integrity of ongoing investigations, adding that it, along with its security partners, remained dedicated to recovering the compromised funds.
This week, Level Finance was hacked for $1 million worth of its native LVL token. The BNB Chain-native non-custodial spot and perpetual contracts exchange confirmed on May 1 that the attacker targeted its LevelReferralControllerV2 referral contract that enables repeated claims, making away with more than 214 LVLs which they exchanged for 3,345 BNB.
Blockchain security company PeckShield said that the hack resulted from a bug that allowed repeated referral claims (in the same epoch), which Level Finance confirmed was from a recent update to its incentive mechanism. The platform temporarily halted its referral program to end the attack, though the event did not affect its liquidity pools or linked DAOs.
In a more recent incident, DeFi protocol Deus Finance confirmed over the weekend that it was the victim of a hack on its BNB Smart Chain and Arbitrum deployments. Though not confirmed yet, the manipulation saw it lose more than $6 million in crypto assets. The attack was front run by a bot according to PeckShield, allowing the hacker to make away with 1,337,375 BUSD from DEI/BUSD pools, and a further $5 million on the ARB/ETH pools. Deus paused all contracts and DEI tokens on-chain burned in response to mitigate against more losses. The protocol team added that it actively evaluating the underlying collateral of the DEI, and will devise a comprehensive recovery and redemption plan depending on pre-burn DEI balances.
Recognizing that some individuals may have taken part in arbitrage endeavors following the breach and gotten stuck while at it, Deus said it was actively assessing to see whether these transactions can be reversed expeditiously to resolve the matter. The DeFi platform pointed out that the Deus v3 system, currently in use, is isolated from DEI and therefore was unaffected by the events. It has also urged the attacker to relinquish 80% of the proceeds and consider the rest a white hat bounty. In a tweet earlier today, the DEI stablecoin issuer Deus Finance said the exploiter(s) had complied and sent back 2,023 ETH to a recovery multi-sig wallet address managed by trusted members of Yearn Finance.
Excerpt from:
On-chain Data Suggests Crypto Hacks and DeFi Exploits are on ... - Securities.io
- Smart Contracts Under the Microscope: What Recent Audits Are Revealing - vocal.media - February 1st, 2026 [February 1st, 2026]
- REVOX joins TOYUSD1 to boost decentralized gaming via smart contracts - MSN - January 20th, 2026 [January 20th, 2026]
- Polygon smart contracts under attack, but the real danger may be just starting! - AMBCrypto - January 18th, 2026 [January 18th, 2026]
- Melento and Forrester reveal how smart contracts drive risk, compliance, and revenue insights - Mediabrief.com - January 18th, 2026 [January 18th, 2026]
- The father of smart contracts: supports X revoking access permissions to InfoFi application APIs; Kaito and other incentive-based content platforms... - January 18th, 2026 [January 18th, 2026]
- HIP-1249: Enhanced smart contracts on Hedera with precise throttling - Hedera - January 16th, 2026 [January 16th, 2026]
- 'Imagination the limit': DeadLock ransomware gang using smart contracts to hide their work - theregister.com - January 16th, 2026 [January 16th, 2026]
- Caixin: Digital RMB smart contracts differ from Ethereum smart contracts and are not built on a blockchain network. - Bitget - January 9th, 2026 [January 9th, 2026]
- Ethereum developer activity hits record high, with 8.7 million smart contracts deployed in Q4 2025 - Bitget - January 9th, 2026 [January 9th, 2026]
- Ethereum Deploys Record 8.7 Million Smart Contracts In Q4 2025, Breaking 2021 High - Yellow.com - January 4th, 2026 [January 4th, 2026]
- Ethereum Smart Contracts Shatter Records: 8.7M Deploy in Q4 - Live Bitcoin News - December 31st, 2025 [December 31st, 2025]
- What Are Smart Contracts? Transforming Digital Industries & Trust - Outlook India - December 31st, 2025 [December 31st, 2025]
- What Are Smart Contracts and How Do They Work? - Blockchain Council - December 27th, 2025 [December 27th, 2025]
- The Mechanics of Smart Contracts: From Conditions to Automatic Execution - vocal.media - December 22nd, 2025 [December 22nd, 2025]
- Understanding Ethereums Role in Creating and Deploying Smart Contracts - aberdeennews.com - December 18th, 2025 [December 18th, 2025]
- Interpreting and vetting smart contracts: utilising blockchain manipulations and crypto currency fraud - Penningtons Manches Cooper - December 10th, 2025 [December 10th, 2025]
- Smart Contracts: Enhancing Security, Trust, and Automation in Modern Digital Platforms - vocal.media - December 5th, 2025 [December 5th, 2025]
- AI has successfully simulated the theft of $4.6 million and has learned to autonomously attack smart contracts. - PANews - December 5th, 2025 [December 5th, 2025]
- AI-Native Smart Contracts Are No Longer TheoryThey Just Became Real - Hackernoon - December 5th, 2025 [December 5th, 2025]
- How Do Smart Contracts Work And Why Are They Critical For Secure Blockchain Systems? - Outlook India - December 5th, 2025 [December 5th, 2025]
- How automation, smart contracts and AI are reshaping property law - lawnews.nz - December 2nd, 2025 [December 2nd, 2025]
- TBC: Revolutionizing Bitcoin With UTXO Smart Contracts and Cross-Chain Innovation - Bitcoin.com News - December 2nd, 2025 [December 2nd, 2025]
- What Are Smart Contracts In Crypto: Uses, Risks, And Benefits - Traders Union - December 2nd, 2025 [December 2nd, 2025]
- Blockchain and Smart Contracts Are Reshaping the Future of Online Casinos in Australia - Australian Manufacturing Forum - November 30th, 2025 [November 30th, 2025]
- DataVault AI licenses smart contracts tech to Wellgistics Health - Investing.com - November 26th, 2025 [November 26th, 2025]
- How Blockchain Security and Smart Contracts Are Helping Reduce Fraud and Increase Trust in Online Casinos - BlockchainReporter - November 23rd, 2025 [November 23rd, 2025]
- Certora Launches the First Safe AI Coding Platform for Smart Contracts By Chainwire - Investing.com - November 23rd, 2025 [November 23rd, 2025]
- AgriFi Democratizes Farming Profits through Tokenized Agriculture and Smart Contracts - StreetInsider - November 11th, 2025 [November 11th, 2025]
- Smart Contracts on Tron vs. Smart Contracts on Ethereum: Which Is the Best Choice? - The Gila Herald - November 11th, 2025 [November 11th, 2025]
- Game Changer For Crypto Smart Contracts - Sovereign Wealth Fund Institute | SWFI - November 11th, 2025 [November 11th, 2025]
- AI & Crypto 2025: Machine Learning, DeFi Innovation, and Smart Contracts with AI - Bitcoinsensus - November 11th, 2025 [November 11th, 2025]
- Klever Blockchain Update: KVM Becomes the New Execution Layer for Smart Contracts - The Defiant - November 3rd, 2025 [November 3rd, 2025]
- Noomez vs Other Presales: The Clear Advantages of $NNZs Audited Smart Contracts and Price Progression - Live Bitcoin News - November 3rd, 2025 [November 3rd, 2025]
- North Korean Hackers Are Using BNB And Ethereum Smart Contracts To 'Bulletproof' Crypto-Stealing Malware, Google Says - Yahoo Finance - October 28th, 2025 [October 28th, 2025]
- How Banks Can Fend Off the Twin Threat of Stablecoins and Smart Contracts to Business Payments - The Financial Brand - October 28th, 2025 [October 28th, 2025]
- Klever Blockchain Update: KVM Becomes the New Execution Layer for Smart Contracts - Brave New Coin - October 28th, 2025 [October 28th, 2025]
- Giggle Academy: Has never issued any tokens or smart contracts - Bitget - October 26th, 2025 [October 26th, 2025]
- AI-powered digital arbitration framework leveraging smart contracts and electronic evidence authentication - Nature - October 24th, 2025 [October 24th, 2025]
- Smart Contracts in Blockchain: What They Are and How They Work - Crypto.com - October 23rd, 2025 [October 23rd, 2025]
- North Korean hackers embedded malware in Ethereum and BNB smart contracts - Invezz - October 23rd, 2025 [October 23rd, 2025]
- Rewriting Blockchain Privacy: The Dawn of Private Smart Contracts with Zero Knowledge Proof - Digital Journal - October 21st, 2025 [October 21st, 2025]
- DPRK and EtherHiding: UNC5342 hides malware in smart contracts on Ethereum and BNB Smart Chain - Bitcoinsensus - October 19th, 2025 [October 19th, 2025]
- Smart Contracts on the Blockchain: What They Are, How They Work, and Examples - Nasscom - October 19th, 2025 [October 19th, 2025]
- What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts - Cointelegraph - October 19th, 2025 [October 19th, 2025]
- UNC5142 Exploits Blockchain Smart Contracts to Distribute Info-Stealing Malware Across Windows and macOS - CXO Digitalpulse - October 19th, 2025 [October 19th, 2025]
- Nexchain Nears Final Integration Phase Before Testnet 2.0 Launch: Backend, Smart Contracts, Airdrop & More - Crypto Economy - October 17th, 2025 [October 17th, 2025]
- Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites - The Hacker News - October 17th, 2025 [October 17th, 2025]
- North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts - The Hacker News - October 17th, 2025 [October 17th, 2025]
- Introducing Smart Contracts to Federated Learning: How Flock is Reshaping AI Production Relationships? - Bitget - October 17th, 2025 [October 17th, 2025]
- Private Smart Contracts at Scale: Zero Knowledge Proof Is the dApp Platform You'll Wish You Saw Earlier - openPR.com - October 15th, 2025 [October 15th, 2025]
- DHS, CBP award $4.5B in new contracts under OBBB for Smart Wall construction along southwest border - The Gila Herald - October 15th, 2025 [October 15th, 2025]
- Bay Miner Unveils Innovative App with AI and Smart Contracts Driving Daily BTC and XRP Earnings - openPR.com - October 13th, 2025 [October 13th, 2025]
- How Ethereum Smart Contracts Work and Why They Matter - vocal.media - October 11th, 2025 [October 11th, 2025]
- *Ethereum is still the king of smart contracts and crypto tech.* --- Let me know if you want this - Binance - October 9th, 2025 [October 9th, 2025]
- Smart Contracts and the Crypto Economy Safeguarding Your Investments - OneSafe - October 7th, 2025 [October 7th, 2025]
- How is Avalanche Changing the Game with Smart Contracts? - OneSafe - October 7th, 2025 [October 7th, 2025]
- AI and Smart Contracts Drive Bay Miner Cloud Mining App for More Efficient Daily BTC and ETH Earnings - Azat TV - October 7th, 2025 [October 7th, 2025]
- The Avalanche ecosystem is growing rapidly the number of smart contracts has tripled! - Pintu - October 7th, 2025 [October 7th, 2025]
- Blockchain and Smart Contracts: Redefining Transparency in Online Gaming Platforms - Techloy - October 4th, 2025 [October 4th, 2025]
- Smart Contracts Software Market to Reach USD 21.4 billion - openPR.com - October 4th, 2025 [October 4th, 2025]
- Red Wings smart contracts just aged beautifully thanks to Wild - Octopus Thrower - October 2nd, 2025 [October 2nd, 2025]
- How Smart Contracts and Blockchain Transactions Are Revolutionizing Industries: Insights from Machi - OKX - September 28th, 2025 [September 28th, 2025]
- From Surfboards to Smart Contracts: The Relentless Rise of Juan Mari - Block Telegraph - September 23rd, 2025 [September 23rd, 2025]
- Hackers Just Found A Way To Hide Malware In Ethereum Smart Contracts And Your Crypto Wallet Could Be Next - Yahoo Finance - September 17th, 2025 [September 17th, 2025]
- Green Computing Power + Smart Contracts: EARN Mining Mobile Cloud Mining Ensures Sustainable Daily Settlement for BTC and XRP - Nation Thailand - September 13th, 2025 [September 13th, 2025]
- How Are Smart Contracts Transforming Decentralized Autonomous Organizations? - Nasscom - September 9th, 2025 [September 9th, 2025]
- Ethereum Smart Contracts Become Latest Hiding Spot For Malware - Mitrade - September 9th, 2025 [September 9th, 2025]
- Cybercriminals are trolling developers by hiding malware in Ethereum smart contracts - Cybernews - September 6th, 2025 [September 6th, 2025]
- How Hackers Use Ethereum Smart Contracts to Hide Malware in Plain Sight - Cointribune - September 6th, 2025 [September 6th, 2025]
- Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers - The Hacker News - September 5th, 2025 [September 5th, 2025]
- Ethereum Smart Contracts Abused to Hide npm Malware - Bitcoinsensus - September 5th, 2025 [September 5th, 2025]
- Hackers Use Ethereum Smart Contracts to Hide Malware in npm Packages - CoinCentral - September 5th, 2025 [September 5th, 2025]
- Hackers find new way to hide malware in Ethereum smart contracts - Cointelegraph - September 5th, 2025 [September 5th, 2025]
- AI, Blockchain, and smart contracts: Why Utah businesses cant afford to wait - Utah Business - September 5th, 2025 [September 5th, 2025]
- A Blockchain Framework Using Proof of Authority and Smart Contracts for Ethical and Secure Healthcare Asset Management - Frontiers - September 5th, 2025 [September 5th, 2025]
- Ethereum (ETH) News: Attackers Are Now Using Ether Smart Contracts to Mask Malware - CoinDesk - September 5th, 2025 [September 5th, 2025]
- News Explorer ReversingLabs Uncovered NPM Packages Using Ethereum Smart Contracts to Disseminate Malware in a GitHub Campaign - Decrypt - September 5th, 2025 [September 5th, 2025]
- Researchers Find Ethereum Smart Contracts Used to Deliver Malware - Crypto Economy - September 5th, 2025 [September 5th, 2025]
- Ethereum News Today: Malware Hiding in Ethereum Smart Contracts Rears Its Head - AInvest - September 5th, 2025 [September 5th, 2025]
- New Way to Hide Hacking Software in Ethereum Smart Contracts - Happy Coin News - September 5th, 2025 [September 5th, 2025]