close

Continuously maintained research ledger

Hall of Hacks

Search the public record of major crypto exploits, compare losses and attack methods, and trace the phishing campaigns that follow a breach.

Updated · Nightly source refresh

Latest record

Harmony Bridge

Not reported

Technique
Infinite Mint
Coverage
Merged archive
Total recorded losses
$47.96B
Incident records
2,379
Incidents in 2026
175

Incident archive

Search the record

Full server-rendered archive. Filters enhance the existing HTML.

Showing 12 of 2,379 incidents

Harmony Bridge

Chains: Harmony

Token & Share Accounting

Infinite Mint

Not reported

Returned funds not reported

Coinsbuy

Chains: Ethereum, Tron

Access Control

Improper Access Control

$7.9M

Returned funds not reported

Coreum Bridge

Chains: XRPL, Coreum

Bridge & Cross-Chain

Bridge Logic Flaw

$200K

Returned funds not reported

USM

Chains: Ethereum

Token & Share Accounting

Arithmetic Error

$136K

Returned funds not reported

Atomic Green

Chains: Arbitrum

Input Validation

Signature Replay

$30K

Returned funds not reported

Oraichain

Chains: Oraichain

Bridge & Cross-Chain

Unbacked Cross-Chain Mint

Not reported

Returned funds not reported

Ravencoin

Chains: Ravencoin

Input Validation

Missing Input Validation

Not reported

Returned funds not reported

RRWallet

Chains: Bitcoin

Key Compromise

Weak Key Generation

$2M

Returned funds not reported

Panther Protocol

Chains: Base

Governance

Malicious Proposal

$7.6K

Returned funds not reported

Hyperliquid Malaysia

Chains: Solana

Key Compromise

Private Key Compromised

Not reported

Returned funds not reported

Unistreets

Chains: Ethereum

Access Control

Arbitrary External Call

$17.8K

Returned funds not reported

RISEx

Chains: RISE

Protocol Logic

Access Control Exploit

$673K

Returned funds not reported

Archive analysis

Where losses concentrate

Rankings are recalculated from the same merged records shown above.

Leading chains and categories

Most reported techniques

Methodology

One durable record, two source layers

Preserved history
The 1,971-record MistTrack archive remains the historical baseline. MistTrack-only incidents are never deleted.
Nightly freshness
The DefiLlama hacks API extends DeFi coverage and refreshes technique and returned-funds fields.
Conservative merge
Records match on normalized project name and incident date within three days. Historical conflicts retain MistTrack values.
Phishing correlation
93,753 post-incident impersonation domains are linked across 226 affected projects. Matches use flagged project brands and incident dates.

Data sources: DefiLlama Hacks API and the preserved MistTrack incident archive. PhishDestroy merges, validates, and enriches the public record; source-only incidents remain intact.

Related Research

Crypto Security Essentials
Essential protection against drainers, fake support, and common wallet traps.
$100K Malvertising Recovery
Wallet access restored and $100K+ returned after a malvertising and stealer attack.
Critical Action Guide
Emergency steps and trusted services for when you have been compromised.