Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
A proposed class action filed September 3, 2026 in the Northern District of California (Dassanayake et al. v. Meta Platforms, Inc.) alleges that Meta's advertising infrastructure and generative-AI tools actively contributed to the creation and distribution of fraudulent crypto investment ads on Facebook and Instagram, funneling victims into WhatsApp-based pig-butchering schemes. The suit follows a Reuters investigation, published November 2025, in which internal Meta documents reportedly projected roughly $16 billion — approximately 10% of 2024 advertising revenue — from scam and banned-product ads. A separate civil prosecution was filed by Santa Clara County in May 2026, and bipartisan U.S. senators have called on the FTC and SEC to investigate Meta's alleged profiteering from fraudulent advertising. All allegations are at the complaint or pre-trial stage; no court has adjudicated Meta's liability.
avoid.net/bitmex-shutdown-september-2026→38/100[WARNING]HDR Global Trading Limited, operator of the cryptocurrency derivatives exchange BitMEX, announced on July 23, 2026 that it will permanently cease operations effective September 23, 2026 at 04:00 UTC, ending an 11-year run. The wind-down follows a multi-year U.S. law-enforcement history culminating in a $100 million Bank Secrecy Act fine and probation sentence for the company in January 2025, after its three founders pleaded guilty to related charges in 2022 (and were later pardoned by President Trump in March 2025). As of this writing (September 12, 2026) the shutdown has not yet occurred; BitMEX has stated customer assets exceed liabilities and this is a solvent wind-down rather than a bankruptcy, but users who fail to withdraw before the deadline face ongoing maintenance fees, and BitMEX itself has warned of phishing and impersonation schemes exploiting the closure.
avoid.net/kelp-dao-layerzero-292m-exploit→22/100[CRITICAL]On April 18, 2026, an attacker drained 116,500 rsETH (approximately $292 million) from Kelp DAO's LayerZero-powered cross-chain bridge, the largest single DeFi exploit reported in 2026. LayerZero and Chainalysis attributed the attack with preliminary confidence to North Korea's Lazarus Group, which allegedly compromised internal RPC nodes feeding a single-verifier (1-of-1) LayerZero DVN while DDoS-ing external nodes to force reliance on the compromised infrastructure. Responsibility for the vulnerable 1-of-1 configuration was initially disputed: LayerZero first blamed Kelp for a risky configuration choice, then reversed course in May 2026, publicly admitting it had allowed its DVN to operate in a 1-of-1 mode for high-value transactions.
avoid.net/xinbi-guarantee→0/100[CRITICAL]Xinbi Guarantee is a Chinese-language illicit online marketplace that operated via Telegram, functioning as an escrow service connecting transnational criminal syndicates with vendors selling scam infrastructure, money laundering services, stolen data, and human trafficking recruitment. On September 9, 2026, the U.S. Treasury's OFAC designated Xinbi Guarantee as a significant transnational criminal organization under Executive Order 13581, and the DOJ's Scam Center Strike Force seized two cryptocurrency wallets and obtained restraining orders covering 47 additional wallets, together freezing approximately $52.8 million. Blockchain analytics firms place the platform's total transaction throughput at between $24 billion and $36 billion since approximately 2022.
avoid.net/zondacrypto-collapse→2/100[CRITICAL]Zondacrypto (operated by BB Trade Estonia OÜ, formerly BitBay) was one of Poland's largest cryptocurrency exchanges before its 2026 collapse. On-chain analysis published in April 2026 showed the exchange's operational Bitcoin reserves had fallen by roughly 99.7% since mid-2024, the site went offline that month, and both the exchange's founder and its later CEO became unreachable. Estonia's financial regulator revoked the company's licence in June 2026, a Tallinn court declared it bankrupt on August 27, 2026, and Polish prosecutors opened a fraud investigation estimating customer losses near 350 million zloty (approximately $94-97 million) affecting an estimated 30,000 or more people.
avoid.net/coldcard-coinkite-firmware-exploit→22/100[CRITICAL]Coldcard is a Bitcoin-only hardware wallet produced by Toronto-based Coinkite Inc. A build configuration error introduced in firmware v4.0.1 (March 2021) caused seed generation to rely on a weak software pseudorandom number generator rather than the device's hardware true random number generator, reducing effective entropy to as little as 40 bits on older models. Beginning July 30, 2026, attackers exploited this flaw to drain an estimated 1,816+ BTC (approximately $116–$130 million, depending on source and wave count) from over 5,200 addresses across four coordinated attack waves, marking the largest hardware wallet compromise in recorded history.
avoid.net/fincen-fin-2026-alert005-overseas-scam-centers-12-7b→5/100[CRITICAL]On September 3, 2026, the U.S. Financial Crimes Enforcement Network (FinCEN) published alert FIN-2026-Alert005, identifying approximately $12.7 billion in financial activity linked to suspected digital asset investment scams flowing through the U.S. financial system between September 2023 and December 2025. The analysis covered 33,904 Bank Secrecy Act reports and represents the largest single-source U.S. government quantification of crypto fraud flows on record. The schemes — commonly known as 'pig butchering,' 'romance baiting,' or 'cryptocurrency confidence schemes' — were attributed primarily to transnational criminal organizations (TCOs) operating industrial-scale scam compounds in Southeast Asia, particularly Cambodia, Burma (Myanmar), and Laos.
avoid.net/tria→42/100[WARNING]Tria is a self-custodial Solana-based neobank founded in 2022 by Vijit Katta and Parth Bhalla that raised $12 million in pre-seed and strategic funding in October 2025. On August 28, 2026, an attacker exploited an authorization-bypass vulnerability in an outdated Rain Solana card contract shared across multiple neobank products, draining $431,945 from 636 Tria card users. Tria pledged full refunds plus a 10% bonus to affected users; its native token fell more than 10% following public disclosure. The incident did not affect user self-custodial wallets — only card-collateral balances staged for spending were compromised.
avoid.net/liquid-network→22/100[CRITICAL]Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.
avoid.net/kyiv-crypto-drainer-ring-fake-investment-platforms-september-2026→3/100[CRITICAL]In early September 2026, Ukraine's Security Service (SBU) and National Police announced the dismantling of a Kyiv-based network that allegedly ran fake cryptocurrency investment platforms and used a 'test transaction' approval-phishing technique to drain victims' wallets. Authorities said the operation, allegedly organized by a 25-year-old IT specialist and staffed by more than 46 Ukrainian citizens, generated turnover of up to $1 million a month at its peak and had identified at least 62 victims across more than 20 countries. As of the most recent reporting, no suspects had been named publicly and formal notices of suspicion had reportedly not yet been served, with the case proceeding under the Prosecutor General's Office.
avoid.net/cosmos-labs→28/100[WARNING]Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.
avoid.net/meta-platforms→38/100[WARNING]Meta Platforms, operator of Facebook, Instagram, and WhatsApp, faces multiple active lawsuits alleging its advertising systems — including generative AI ad-creation tools — actively facilitate cryptocurrency and investment scam advertisements that funnel users into fraudulent schemes. This dossier concerns Meta's alleged role as a distribution channel and profit beneficiary of crypto-fraud advertising, not an allegation that Meta itself operates a crypto scheme. The allegations below are drawn from active, unadjudicated litigation and an investigative news report based on leaked internal documents; Meta disputes characterizations of its motives and has argued for dismissal in several of the underlying cases.
avoid.net/coinkite→15/100[CRITICAL]Coinkite Inc. is a small, privately held Toronto-based Bitcoin hardware company that manufactures the Coldcard wallet. A firmware defect introduced into Coldcard seed generation in March 2021 went undetected for roughly five years — including, per public claims from the developer who flagged it, a specific warning to Coinkite in May 2025 that was dismissed — until attackers began draining wallets on July 30, 2026, ultimately taking an estimated 1,816 BTC (roughly $116–155 million) from more than 5,200 victims. Coinkite has publicly apologized and shipped fixed firmware, but now faces credible, still-unfiled class-action and product-liability litigation threats from law firms in Canada and the UK, alongside separate allegations — unconfirmed by the company — that its own CTO authored the flawed code.
avoid.net/cozy-finance→14/100[CRITICAL]Cozy Finance, a DeFi coverage/insurance protocol built on the Cozy V2 stack and deployed on Optimism, has suffered two confirmed exploits within roughly thirteen months: an alleged $427,000 loss in August 2025 tied to a missing caller-identity check in its withdrawal code, and an alleged $170,000 loss on September 7, 2026 whose root cause is disputed across secondary reporting. The recurrence of a fund-draining incident on the same chain, with no public post-mortem or protocol response identified for the second event as of this writing, indicates unresolved security and governance risk independent of which technical account of the second exploit is correct.
avoid.net/coldcard-coinkite→28/100[WARNING]Coinkite is a Toronto-based company founded in 2012 that manufactures Coldcard, a Bitcoin-only hardware wallet widely regarded before 2026 as one of the most secure consumer self-custody products available. Beginning July 30, 2026, attackers exploited a firmware vulnerability introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of hardware entropy, reducing effective key strength from 128 bits to as low as 40 bits. Across four documented attack waves through early August 2026, approximately 1,816 BTC valued at roughly $116 million was drained from more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026.
avoid.net/coinkite-coldcard→13/100[CRITICAL]Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.
avoid.net/kelp-dao→38/100[WARNING]Kelp DAO is an Ethereum liquid restaking protocol, founded in November 2023 by Amitej Gajjala and Dheeraj Borra, that issues rsETH as a non-rebasing liquid restaking token backed by EigenLayer positions. On April 18, 2026, attackers attributed by LayerZero and Chainalysis to North Korea's Lazarus Group (TraderTraitor subunit) exploited a single-verifier configuration on the protocol's LayerZero-powered cross-chain bridge, draining approximately 116,500 rsETH valued at roughly $292 million — the largest single DeFi exploit of 2026. The incident triggered a $10 billion DeFi-wide withdrawal wave and cascading bad debt on Aave; a coordinated industry recovery effort under the 'DeFi United' banner subsequently restored rsETH to full collateralization by late May 2026.
avoid.net/tac-chain→22/100[CRITICAL]TAC Chain (Telegram Application Chain) is a Cosmos EVM-compatible Layer 1 blockchain designed to bridge Ethereum DeFi with TON and Telegram's user base, which launched its mainnet in July 2025. On August 22, 2026, an attacker exploited a balance-synchronization integer underflow in the shared Cosmos EVM module, draining approximately 2.986 billion TAC tokens (28.6% of total supply, worth roughly $7.5 million at the time) from the network's staking pool; validators halted the chain at block 24,671,475. This was TAC's second significant security incident in 2026, following a $2.8 million bridge exploit in May 2026 that was ultimately classified as a white-hat recovery.
avoid.net/layerzero-dvn-single-verifier-configuration-risk→32/100[WARNING]LayerZero is a cross-chain messaging protocol whose permissive Decentralized Verifier Network (DVN) architecture allowed integrating protocols to deploy bridges secured by a single verifier. In April 2026, this design pattern was exploited by the DPRK-affiliated Lazarus Group (TraderTraitor unit), which compromised LayerZero Labs' own DVN infrastructure to forge cross-chain messages and drain approximately $292 million from KelpDAO's rsETH bridge — the largest DeFi exploit of 2026. LayerZero has since publicly admitted a mistake in allowing its DVN to operate as a 1-of-1 verifier for high-value transactions and has announced policy changes, but the incident triggered a $15 billion migration of secured value away from LayerZero to competing infrastructure. A separate August 2026 exploit of The Sandbox's LayerZero-powered bridge deepened concerns about systemic risk across LayerZero integrations.
avoid.net/radoslaw-piesiewicz→20/100[CRITICAL]Radoslaw Piesiewicz (born February 20, 1981) is a Polish sports administrator who has served as president of the Polish Olympic Committee (PKOl) since 2023. On August 27, 2026, he was detained by Poland's Central Bureau for Combating Cybercrime in connection with a criminal investigation into the collapsed cryptocurrency exchange Zondacrypto. A Polish court subsequently ordered him held for three months pending the investigation; as of the date of this report, formal charges had not been publicly filed and no conviction has been entered.
avoid.net/przemyslaw-kral→4/100[CRITICAL]Przemyslaw Kral is the former CEO of Zondacrypto (formerly BitBay), Poland's largest cryptocurrency exchange, which collapsed in April 2026 amid a criminal fraud investigation. Polish prosecutors charged Kral with alleged participation in large-scale fraud and money laundering in connection with estimated customer losses ranging from approximately 350 million zloty ($97 million) to as much as 2.4 billion zloty ($650 million) according to later prosecutor estimates, affecting approximately 30,000 users. Kral departed Poland for Israel in April 2026 and holds dual Polish-Israeli citizenship; as of September 2026 he has reportedly been cooperating with prosecutors, though his precise location and formal legal status remain subjects of conflicting and unconfirmed reporting.
avoid.net/lazarus-group-mach-o-man-clickfix-macos-campaign→0/100[CRITICAL]In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.
avoid.net/the-sandbox-sand-oft-exploit→34/100[WARNING]On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.
avoid.net/the-sandbox-sand-layerzero-bridge-exploit-august-2026→12/100[CRITICAL]On August 21–22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base by hijacking LayerZero delegate permissions through the approveAndCall function, enabling unauthorized minting of approximately 329.24 trillion unbacked SAND tokens across 703 events over five hours. Actual financial extraction was substantially lower than headline figures: roughly 14.75 million SAND drained from the Ethereum OFT Adapter yielded approximately 80 ETH (~$675,000), while The Sandbox estimated the incident affected less than 0.01% of the 3-billion total SAND supply. The exploit was the third major LayerZero bridge incident in five months and contributed to accelerating an industry-wide migration from LayerZero to Chainlink CCIP, with publicly announced moves totaling approximately $15 billion.
avoid.net/the-sandbox-sand→30/100[WARNING]The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.
avoid.net/trusteplusglobal-com→12/100[CRITICAL]trusteplusglobal.com is a domain registered in October 2025 whose name closely mimics 'Trustee Plus Global,' the branding used by the established Lithuanian crypto wallet operator Trustee Global UAB (trusteeglobal.com / trusteeglobal.eu). The domain has no public web presence indexed by search engines, carries privacy-protected WHOIS registration, and was registered for only a one-year term — structural patterns commonly associated with phishing or impersonation infrastructure. No Tier 1 or Tier 2 investigative reporting directly attributing confirmed fraud to this specific domain has been found as of September 2026.
avoid.net/brevo-email-marketing-platform-used-by-trezor-bitbox-cointracking-solana-mobile→32/100[WARNING]Brevo, a Paris-based email marketing and CRM platform (formerly Sendinblue) used by numerous crypto companies for newsletters, suffered a SAML single sign-on (SSO) authorization flaw that an attacker exploited around September 9-10, 2026 to access 138 customer accounts. Six of those accounts, including ones belonging to hardware wallet maker Trezor, hardware wallet maker BitBox, and portfolio tracker CoinTracking, were used to send convincing phishing emails to hundreds of thousands of real subscribers from the companies' legitimate domains, prompting some recipients to enter sensitive wallet information. Brevo says it closed the access path and issued a fix within hours, but the incident is a documented supply-chain risk for any crypto business or user relying on Brevo-delivered newsletters.
avoid.net/ukrainian-fake-crypto-investment-ring-kyiv-2026→0/100[CRITICAL]A Kyiv-based criminal network allegedly operated multiple fake cryptocurrency investment platforms that targeted victims across more than 20 countries, with an estimated peak monthly turnover of up to $1 million. Ukrainian law enforcement, including the National Police of Ukraine, the Security Service of Ukraine (SBU), and the Office of the Prosecutor General, dismantled the operation in early September 2026 through 34 coordinated raids. The alleged organizer, a 25-year-old IT specialist, recruited over 46 Ukrainian citizens to staff the ring, which combined fabricated investment dashboards, wallet-draining malware, and identity data harvesting.
avoid.net/malone-lam→2/100[CRITICAL]Malone Lam, a 22-year-old Singaporean national also known online as 'King Greavys,' pleaded guilty on September 9, 2026 in U.S. District Court in Washington, D.C. to one count of racketeering conspiracy for his role as the alleged ringleader of a social engineering enterprise that stole over $245 million in cryptocurrency from multiple victims beginning no later than October 2023. Lam faces a maximum sentence of 20 years in prison, with sentencing guidelines recommending at least 14 years; a status hearing is scheduled for December 8, 2026.
avoid.net/mantra-chain-august-2026-exploit→38/100[WARNING]On August 20, 2026, MANTRA Chain — an RWA-focused Cosmos-based Layer 1 — suffered an exploit of a critical vulnerability in its upstream Cosmos EVM module, forcing a full network halt of approximately 30 hours and causing its OM token to drop 18% to a record low of $0.004126. Approximately 720.9 million OM tokens worth roughly $3.6 million were drained across the incident, part of a coordinated attack pattern that ultimately affected six Cosmos EVM chains and converted approximately $5.72 million in stolen assets across the ecosystem. This page covers the August 2026 security incident; the April 2025 token price collapse is documented separately under the 'mantra-chain' entry.
avoid.net/harmony-protocol-2026-one-token-exploit-and-l1-shutdown→12/100[CRITICAL]In August 2026, Harmony's Layer 1 blockchain suffered a critical unauthorized-minting exploit that began with roughly 4 billion forged ONE tokens (about 26% of supply) and, as investigation continued, was disclosed to involve trillions of forged tokens across multiple transactions, crashing the ONE price roughly 40%. Harmony responded with a full blockchain rollback of its two shards to a pre-attack checkpoint — an action critics say undermines blockchain immutability and highlights centralized control by the core team and validators. On September 6, 2026, Harmony proposed fully shutting down its Layer 1 network and migrating the ONE token to Ethereum as an ERC-20 asset, citing threats from "state actors and AI agents," with users told to exit all smart-contract positions before a September 10, 2026 snapshot deadline or risk permanent loss of assets not eligible for automatic migration.
avoid.net/7uh2uvf8hpqjlduwr7gffjwjfymvcjvlvvc7j9tdcuvd→50/100[WARNING]7uh2UVF8hpQjLdUwr7gffJWJfymVcjVLVvC7j9tdCuvD is a Solana address with no publicly documented identity, ownership, or purpose. Direct Solana mainnet RPC queries show the account holds no lamports and has never been initialized with data (no token mint, program, or wallet content currently exists at this address), and no scam-tracking database, news outlet, or blockchain analytics writeup returned any results for it. In the absence of any negative or positive signal, this address should be treated as unverified rather than either trusted or flagged.
avoid.net/joaquin-diaz-orionx-co-founder→12/100[CRITICAL]Joaquín Díaz is a co-founder and former head of technology (CTO) of Orionx, a Chilean cryptocurrency exchange that permanently shut down in September 2026 after a forensic audit found more than $7 million in customer assets had been moved to wallets outside company control. Díaz and former general manager Roberto Zibert are named as the principal targets of a criminal complaint filed by Orionx with Chile's Public Ministry on September 2, 2026, which alleges an account linked to Díaz received over $1.5 million across 14 transfers, while a related wallet allegedly received 187 ETH, more than 4.1 million USDT, and 200,000 USDC diverted from customer custody between 2018 and 2021. Díaz denies wrongdoing and no charges have been proven in court; the matter is under active criminal investigation in Chile.
avoid.net/roberto-zibert→8/100[CRITICAL]Roberto Zibert is a Chilean entrepreneur and co-founder and former general manager of Orionx, a Tether-backed cryptocurrency exchange based in Chile that permanently shut down in September 2026 after a forensic audit found a custody gap of more than $6 million to $7 million in customer Bitcoin, Ethereum, XRP, and Polygon (POL) holdings. Orionx itself filed a criminal complaint naming Zibert and fellow co-founder Joaquín Díaz as suspects in the alleged diversion of client assets between 2018 and 2021, an accusation both men have categorically denied. No court has yet reached a verdict, and the case remains under active investigation by Chilean prosecutors.
avoid.net/liquid-network-elements-cache-bug-exploit-september-2026→18/100[CRITICAL]On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.
avoid.net/fbi-operation-level-up-crypto-fraud-victim-alert-program→92/100[VERIFIED]Operation Level Up is a joint FBI/U.S. Secret Service initiative, launched in January 2024, that proactively identifies and directly contacts victims of ongoing cryptocurrency investment fraud (commonly called "pig butchering") before they lose additional funds. As of an April 2026 U.S. Attorney's Office update, the program had alerted nearly 9,000 individuals and was credited with preventing an estimated $562 million in further losses. It is a legitimate U.S. government law-enforcement victim-protection program, not a risk entity, and is documented here as a reference resource for victims and researchers.
avoid.net/hunter-biden-laptop-token→22/100[CRITICAL]$LAPTOP is an ERC-20 memecoin launched on the Base blockchain on September 9, 2026 by Hunter Biden, son of former U.S. President Joe Biden. The token surged to a reported peak near $190–$225 shortly after launch before collapsing approximately 98–99% within hours, with an estimated four out of five buyers suffering losses. Biden disputes characterizations of the collapse as a rug pull, attributing the crash to insufficient liquidity and automated sniper-bot activity, while asserting that team tokens remained locked and unsold throughout.
avoid.net/aquifer-solana-amm→28/100[WARNING]Aquifer is a Solana-based automated market maker that suffered an exploit on August 31, 2026, resulting in the loss of approximately $2.5 million. The protocol published an on-chain bounty offer giving the suspected attacker until September 3, 2026 to return 80% of funds in exchange for keeping 20%, but no public confirmation of compliance or fund recovery exists as of the reporting date. The root cause has not been established by a public post-mortem; compromised wallet or upgrade authority key access is the leading hypothesis, as available evidence has not confirmed a smart contract vulnerability.
avoid.net/mantra-chain-upstream-exploit-august-2026→32/100[WARNING]On August 20-21, 2026, MANTRA Chain halted all block production after an attacker exploited a critical vulnerability (ASA-2026-002) in the shared Cosmos EVM ICS20 precompile, a component developed by Cosmos Labs and used by multiple chains. MANTRA's OM token fell 18.5% to an all-time low of $0.004126 during the approximately 30-hour outage, and the chain resumed on August 22 after deploying patched version 8.4.0. MANTRA stated no user funds were exploited and that only two project-managed wallets were affected, but the team has not published a technical post-mortem nor disclosed what, if anything, was extracted from those wallets, leaving the full financial scope of the incident unresolved as of August 27, 2026.
avoid.net/mantra-chain→10/100[CRITICAL]MANTRA Chain, a Cosmos-EVM layer-1 blockchain focused on real-world asset tokenization, halted all block production on August 20, 2026 after an attacker exploited a known vulnerability in the shared Cosmos EVM ICS20 precompile module. The network was offline for approximately 30 hours, the native OM token fell 18% to an all-time low of $0.004126, and South Korean exchanges Upbit, Bithumb, and Coinone placed OM on delisting watchlists. This is MANTRA's second major crisis in 2026, following the April 2025 collapse of OM by more than 90%, and occurs in the context of a broader Cosmos EVM security incident that also affected KiiChain and TAC.
avoid.net/rocketswap-base→22/100[CRITICAL]RocketSwap is a decentralized exchange (DEX) launched on the Coinbase Base Layer 2 network in mid-2023 that suffered a $865,000 private key compromise exploit just days after Base's public launch, making it one of the first major exploits on the network. The attack, confirmed by security firms PeckShield and Certik as a private key compromise, was compounded by a separate $69,000 social engineering loss one week prior, and the hacker subsequently laundered stolen funds through Tornado Cash, Binance, OKX, and a self-created memecoin called LoveRCKT. The project has been flagged by ZachXBT and community analysts, with some alleging that pre-exploit proxy contract modifications and the team's decision to silence communications point to possible insider involvement, though this has not been conclusively proven.
avoid.net/brevo→42/100[WARNING]Brevo (formerly Sendinblue) is a Paris-based email marketing and CRM platform serving over 600,000 customers globally. On September 10, 2026, an attacker exploited a critical authorization boundary flaw in Brevo's SAML SSO implementation to compromise 138 customer accounts, six of which were used to send phishing emails to hundreds of thousands of cryptocurrency users. The incident is a confirmed supply-chain risk event, with Brevo having issued a public post-mortem acknowledging the flaw and deploying a fix.
avoid.net/0x7c0db2791af5f7f71a125531b0902917ea0c2bc9→52/100[CAUTIONARY]0x7C0dB2791af5f7F71a125531b0902917EA0C2bC9 is an Ethereum address identified on Etherscan as a Safe (formerly Gnosis Safe) Smart Account proxy, created in May 2024. The address has no scam, phishing, or OFAC sanctions labels on any major blockchain intelligence platform reviewed, though it has been involved in very large ETH and stETH transfers that are consistent with sophisticated or institutional-scale operations. No verified reports of fraud or abuse were located; risk factors are limited to the unusual scale of outflows and the absence of a publicly identified owner.
avoid.net/poolin-technology→8/100[CRITICAL]Poolin Technology Pte. Ltd., once the world's largest Bitcoin mining pool, halted all mining and hosting operations on July 10, 2026 and filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of New Jersey on July 22, 2026, with roughly $173 million in total obligations against less than $10 million in assets. The largest liability, $163.7 million owed to approximately 11,700 wallet customers as unpaid "IOU" tokens issued after Poolin froze withdrawals in September 2022, is projected to recover only about 32 cents on the dollar through a court-supervised sale of the company's two remaining Texas mining sites, a process still underway as of this writing.
avoid.net/sideswap→38/100[WARNING]SideSwap is an open-source, non-custodial peer-to-peer trading platform and wallet built on Blockstream's Liquid Network, founded in 2020 by Scott Millar. On September 6, 2026, SideSwap's Peg-out Authorization Key (PAK) was the mechanism through which approximately 3,996 real BTC — worth roughly $320 million — was released from the Liquid federation reserve in a single transaction, following an Elements software vulnerability that allowed the minting of unbacked L-BTC. SideSwap's own post-mortem acknowledged operational oversights including keeping its PAK key connected to the internet at all times and running no size, velocity, or origin checks on peg-out orders, though the underlying vulnerability originated in the open-source Elements codebase maintained by Blockstream.
avoid.net/orionx→5/100[CRITICAL]Orionx was a Chilean cryptocurrency exchange backed by Tether (Series A, June 2025) that operated in Chile, Peru, Colombia, and Mexico. On or around September 3–8, 2026, the exchange began a permanent shutdown after a forensic audit found more than $7 million in customer assets had been moved to wallets outside the company's control, allegedly by two co-founders between 2018 and 2021. Chile's financial regulator, the CMF, had already rejected Orionx's license application in June 2026 and confirmed it has no authority to supervise the wind-down or compel restitution, leaving more than 100,000 registered users dependent on the company's own multi-stage closure process.
avoid.net/blockstream-liquid-network→32/100[WARNING]The Liquid Network is a Bitcoin sidechain operated by Blockstream via a federated multi-signature custody model, designed for fast, confidential BTC transfers between exchanges and financial institutions. On September 6, 2026, attackers exploited a cache-key collision vulnerability in the open-source Elements software to mint approximately 4,000 unbacked L-BTC and drain roughly $320 million from the federation reserve — one of the largest Bitcoin-adjacent security incidents on record. Attackers claiming to be white-hat researchers subsequently returned approximately 3,400 BTC while retaining ~598.5 BTC (~$47M) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft.
avoid.net/liquid-network-blockstream→28/100[WARNING]Liquid Network is a Bitcoin sidechain operated by Blockstream and a federation of member exchanges, launched in 2018 to enable fast inter-exchange BTC settlement via a pegged asset called L-BTC. On September 6, 2026, attackers exploited a range-proof cache collision vulnerability in the underlying Elements software to mint approximately 4,000 unbacked L-BTC tokens and redeem them for roughly $320 million in real Bitcoin from the federation reserve, representing one of the largest crypto hacks of 2026. Attackers returned approximately 85% of funds after the vulnerability was patched, but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft, not responsible disclosure.
avoid.net/stonk→32/100[WARNING]The name 'STONK' (and variants 'STONKS', '$STNK') is shared by at least four distinct and unrelated crypto tokens across different blockchains, creating significant investor confusion risk. The most prominent current entity is StonkFun (STONK), a Solana-based token launchpad whose native token surged over 250% in September 2026 following a Raydium integration. A separate and older project, Stonks (STNK), claims to be the first memecoin on Solana (launched April 2021) and was revived under community ownership in November 2024. Several phishing and impersonation domains using the StonkFun brand name have been flagged by security services. No formal smart contract audits, regulatory filings, or doxxed teams have been identified for any of these tokens.
avoid.net/phoenix-trade→72/100[CAUTIONARY]Phoenix Trade (phoenix.trade) is a fully on-chain, non-custodial decentralized exchange built on Solana by Ellipsis Labs, offering both spot and perpetual futures trading via a crankless central limit order book (CLOB) architecture. The protocol is backed by prominent venture investors including Paradigm and Haun Ventures, has processed over $75 billion in cumulative spot volume, and has been audited by OtterSec. No regulatory actions, fraud allegations, or confirmed exploits have been identified against the protocol as of September 2026, though the expansion into equity perpetual futures products raises unresolved regulatory questions in the United States.
avoid.net/taptaptap→50/100[WARNING]Extensive web research conducted in September 2026 found no verifiable crypto entity operating under the name 'Taptaptap' — no token, protocol, exchange, or blockchain game with that exact name could be identified on any major aggregator, DEX, regulatory record, or news outlet. The closest identifiable entities are unrelated projects with similar names (TapSwap, Tap Protocol, TapTap game store), none of which are the same entity. In the absence of verifiable identifying information, no trust score adjustment can be made and a score of 50 is assigned as a neutral placeholder pending further identification.
avoid.net/kylie-jenner-x-account-hack-kylie-solana-memecoin-scam→3/100[CRITICAL]On August 24, 2026, Kylie Jenner's verified X account (roughly 39.5 million followers) was reportedly hacked and used, without her knowledge or consent, to promote a Pump.fun-launched Solana memecoin called $KYLIE. The token's market cap spiked to roughly $1.2 million before collapsing 68-90% within minutes of the compromised posts being deleted. Kylie Jenner is the victim of this incident, not its perpetrator: this dossier concerns the account-hijacking campaign and the $KYLIE token, not any wrongdoing by Jenner, and evidence indicates the incident is one instance of a recurring scheme that has also hit the SpaceX/Starlink, Robinhood CEO Vlad Tenev, and 'Roaring Kitty' (Keith Gill) X accounts in 2026.
avoid.net/evmos-network→30/100[WARNING]Evmos was a Cosmos-based, EVM-compatible proof-of-stake blockchain developed by Tharsis Labs that launched on mainnet in April 2022 and raised $27 million in a token sale led by Polychain Capital. The network was formally shut down on approximately May 18, 2026, after Governance Proposal #331 passed with 99.8% approval, halting all block production at block height 37,318,000. Following discontinuation, an authorization vulnerability in the Evmos vesting and lockup module — left unpatched because the codebase was no longer maintained — was exploited in August 2026 to drain approximately $3 million from BounceBit Chain, a third-party network built on the Evmos stack.
avoid.net/wolf-capital-crypto-trading-llc→2/100[CRITICAL]Wolf Capital Crypto Trading LLC was an Oklahoma-based cryptocurrency investment firm whose founder and CEO Travis Ford pleaded guilty in January 2025 to conspiracy to commit wire fraud for operating a Ponzi scheme that defrauded approximately 2,800 investors of $9.4 million. Ford was sentenced on November 13, 2025, to 60 months in federal prison and ordered to pay over $1 million in forfeiture and more than $170,000 in restitution. The CFTC separately filed a civil enforcement complaint in December 2025 alleging the scheme ran from October 2022 through December 2024 and collected over $10 million from more than 3,000 investors.
avoid.net/lifi-finance→32/100[WARNING]LI.FI is a Berlin-based cross-chain bridge and DEX aggregation protocol founded in 2021 by Philipp Zentner and Max Klenk. The protocol has suffered two significant smart contract exploits — a $600,000 loss in March 2022 and an $11.6 million loss in July 2024 — both stemming from the same class of arbitrary-call vulnerability, prompting criticism from security researchers that lessons were not learned. Separately, blockchain investigator ZachXBT alleged in June 2025 that North Korean (DPRK) actors accounted for an estimated 15–25% of the protocol's volume during May 2025, using LI.FI to launder funds from the Bybit hack.
avoid.net/euler-v1→10/100[CRITICAL]Euler Finance V1 was a permissionless DeFi lending protocol on Ethereum that launched in December 2021 and was exploited for approximately $197 million on March 13, 2023, in what was the largest DeFi hack of that year. The attack exploited a missing health check in the donateToReserves function introduced in EIP-14, despite the codebase having undergone multiple external audits. In a highly unusual outcome, the pseudonymous attacker known as 'Jacob' returned all recoverable funds by April 3, 2023, with the total recovered value reaching approximately $240 million due to ETH price appreciation during the recovery period.
avoid.net/xbridge→12/100[CRITICAL]XBridge is a cross-chain bridge protocol built by SaitaChain (formerly Saitama Inu), designed to connect Ethereum Mainnet and BNB Chain. On April 24, 2024, the protocol suffered a $1.44 million exploit caused by a critical access-control vulnerability in its smart contracts, with stolen funds subsequently routed through Tornado Cash. The parent company, Saitama LLC, faces U.S. federal charges of wire fraud and market manipulation, with CEO Manpreet Kohli arrested in the UK in October 2024 and facing extradition proceedings.
avoid.net/ionic-protocol→18/100[CRITICAL]Ionic Protocol (also known as Ionic Money) is a decentralized non-custodial lending and borrowing protocol deployed on the Mode Network (OP Superchain). It is a rebrand of Midas Capital, which suffered two separate exploits in 2023 totaling approximately $1.26 million. In February 2025, Ionic itself was exploited via a social engineering attack involving a counterfeit LBTC token, resulting in losses estimated between $8.6 million and $12.3 million; funds were partially laundered through Tornado Cash and have not been recovered.
avoid.net/kiichain→32/100[WARNING]KiiChain, a Cosmos SDK Layer 1 chain built by Kii Global for FX and cross-border payment settlement, lost 148,326,583.15 KII tokens (nominally about $9.7 million, with an estimated $1.6 million actually realized by the attacker) on August 22, 2026, after an attacker exploited a shared, three-part integer underflow vulnerability in the Cosmos EVM precompile layer across 18 sequential transactions. The same underlying Cosmos EVM defect was used to attack MANTRA Chain and the TAC Protocol in the same window, and KiiChain has publicly disputed Cosmos Labs' disclosure and coordination timeline. The network halted at block 9,355,723 and resumed six days later; roughly 54% of the drained tokens remained on-chain and were frozen, while the rest were bridged to BNB Chain via Hyperlane and largely liquidated before the chain resumed.
avoid.net/m1llionz-richmilly666→3/100[CRITICAL]M1llionz, also known online as RichMilly666, is a French individual alleged by on-chain investigator ZachXBT to have laundered approximately $667,000 in cryptocurrency stolen during two violent home invasion robberies in France in April 2026. ZachXBT's tracing led Tether to freeze roughly $93,500 in USDT tied to an Ethereum address attributed to the suspect. No arrest, charge, or conviction has been publicly confirmed by law enforcement as of this report, and the suspect's real-world identity remains unverified; all claims below derive from open-source blockchain analysis and social-media self-exposure rather than a legal finding.
avoid.net/sol-strategies-inc-stke→42/100[WARNING]SOL Strategies Inc. (NASDAQ: STKE; CSE: HODL) is a publicly traded, SEC- and OSC-regulated Solana "digital asset treasury" and validator company that has disclosed significant financial stress: a C$101.7 million interim net loss tied to SOL price declines, more than half of its SOL treasury pledged as collateral to Kamino Finance with an automatic liquidation trigger, and current liabilities exceeding available cash by a wide margin. These are disclosed leverage and mark-to-market losses inherent to a highly volatile treasury strategy, not allegations of fraud or misconduct, and the company has taken public steps (equity raises, asset sales, disclosure) consistent with an operating, reporting entity rather than a defunct or fraudulent one.
avoid.net/teraswitch-solana-validator-hosting-concentration-incident→52/100[CAUTIONARY]Teraswitch is a data-center and network hosting provider whose autonomous system (AS20326) hosted roughly 27% of all staked SOL as of August 2026. A routing misconfiguration originating at Teraswitch's Miami facility on August 12, 2026 knocked out connectivity to its European and Asia-Pacific sites for about 33 minutes, simultaneously disconnecting approximately 90 Solana validators representing up to 28.83% of staked SOL and pushing the network to roughly 86% of the 33.34% delinquent-stake threshold at which Solana would lose transaction finality. This is documented as an infrastructure-concentration and availability incident, not an allegation of fraud or misconduct by Teraswitch; the network recovered fully and finality was never actually lost, but the event is treated by validators, delegators and the Solana Foundation as evidence of a systemic single-point-of-failure risk in the validator hosting landscape.
avoid.net/gurhan-kiziloz→0/100[CRITICAL]Gurhan Kiziloz is a Turkish-British entrepreneur who co-founded BlockDAG Network, a Layer-1 blockchain project that claimed to raise up to $442 million in a presale running from December 2023 to February 2026. His identity was concealed for over two years while a public-facing CEO served as the project's visible representative; Kiziloz confirmed his role in a December 2025 investor AMA. His prior UK fintech Lanistar received an FCA consumer warning in November 2020 and was liquidated by a UK High Court in September 2025. In May 2026, a Brazilian court ordered the freeze of approximately $213 million in USDT across 48 wallets linked to Kiziloz over alleged unpaid gambling taxes and unregistered crypto sales; a Brazilian federal appellate court subsequently narrowed the freeze in August 2026, with full adjudication ongoing.
avoid.net/kenneth-thom-k-money→2/100[CRITICAL]Kenneth Thom, operating under the aliases 'K Money' and 'K$,' was a FINRA-suspended broker who reinvented himself as a social media financial influencer and raised nearly $800,000 from approximately 67 investors beginning in late 2023. He diverted a substantial portion of those funds for personal use — including travel, dining, and luxury goods — while fabricating trading performance reports. On August 11, 2026, U.S. District Judge Edgardo Ramos sentenced Thom to two years in federal prison after he pleaded guilty to investment adviser fraud; he was also ordered to pay $724,756.09 each in forfeiture and restitution.
avoid.net/bald→4/100[CRITICAL]BALD was a memecoin launched on Coinbase's Base Layer 2 network on July 29, 2023, allegedly named as a reference to Coinbase CEO Brian Armstrong's appearance. After attracting over $66 million in ETH to its liquidity pool through aggressive liquidity additions and a price surge of approximately 4,000,000% within 24 hours, the anonymous deployer removed approximately $25.6 million in liquidity on July 31, 2023, causing the token price to collapse by roughly 90%. On-chain investigators linked the deployer's wallet to addresses with documented interactions with Alameda Research, with Wintermute's head of research publicly identifying former Alameda co-CEO Sam Trabucco as the most likely suspect — though no conclusive proof of identity was ever established.
avoid.net/alex→28/100[WARNING]ALEX (Automated Liquidity Exchange) is a decentralized finance protocol built on the Stacks blockchain, designed to bring DeFi capabilities to Bitcoin. The protocol has suffered two major security exploits: a $4.3 million hack in May 2024 attributed to North Korea's Lazarus Group via a private key compromise of its XLink bridge, and an $8.3 million exploit in June 2025 caused by a smart contract access control vulnerability. In both cases, ALEX Lab Foundation pledged full user reimbursement, though partial recovery of 2024 stolen funds remained ongoing as of mid-2025, and the native ALEX token has declined approximately 99.9% from its all-time high.
avoid.net/skr→48/100[WARNING]SKR is the governance and utility token of Seeker, the second-generation crypto smartphone produced by Solana Mobile, a subsidiary of Solana Labs. The token launched via airdrop in January 2026 and has since traded significantly below its all-time high, with notable concerns around token concentration, an unfixable hardware vulnerability in the Seeker device, inflation pressure, and the existence of at least one other unrelated token sharing the SKR ticker (Saakuru Protocol). No fraud, rug pull, or regulatory action has been documented against the Solana Mobile SKR token as of September 2026.
avoid.net/cat-in-a-dogs-world→62/100[CAUTIONARY]cat in a dogs world (MEW) is a cat-themed memecoin launched on the Solana blockchain in March 2024, positioned as an alternative to dog-themed memecoins such as Dogecoin and Shiba Inu. It is a widely traded, exchange-listed asset with no known history of fraud, rug-pull behavior, or regulatory action; the risks documented here are the structural risks common to all memecoins — extreme volatility, no cash flow or intrinsic value, and dependence on continued social/speculative interest — rather than allegations of misconduct. This page was surfaced by a routine AVOID.NET wallet exposure scan, not by any fraud complaint.
avoid.net/coinsbuy-exchange-august-2026-hot-wallet-drain→30/100[WARNING]On August 9, 2026, wallets associated with Coinsbuy — a B2B crypto payment processor and exchange — were drained of approximately $7.9 million across Ethereum and TRON in a coordinated attack completed within roughly one hour. The attacker linked both chains via cross-chain swapper Bridgers and subsequently laundered the majority of proceeds through FixedFloat and into Monero; ChangeNOW froze a six-figure portion. Coinsbuy stated it covered all client losses from company reserves and offered a $100,000 bounty for information leading to the perpetrators' identification.
avoid.net/irs-fake-digital-asset-compliance-portal-letter-campaign-2026→0/100[CRITICAL]A fraud campaign active as of late July 2026 in which unknown threat actors mail physically printed letters impersonating the IRS, instructing cryptocurrency holders to enroll in a nonexistent 'Digital Asset Compliance Portal' via an embedded QR code. The IRS Criminal Investigation division publicly confirmed on July 30, 2026 that it does not operate any such portal and did not send the letters. Infrastructure linked to the campaign was registered through a Hong Kong-based registrar and hosted on Romanian servers previously associated with financial phishing attacks.
avoid.net/irs-fake-digital-asset-compliance-portal-physical-mail-phishing→0/100[CRITICAL]Beginning in late July 2026, an unidentified threat actor began mailing counterfeit IRS letters to cryptocurrency holders in the United States, directing recipients to a nonexistent 'Digital Asset Compliance Portal' via embedded QR codes. IRS Criminal Investigation (IRS-CI) publicly confirmed on July 30, 2026, that the portal does not exist and that the agency did not send the letters. Cybersecurity firms Coinbase and DarkTower traced the campaign's infrastructure to a domain registered through a Hong Kong registrar and hosted on Romanian servers previously associated with financial-institution phishing.
avoid.net/irs-fake-digital-asset-compliance-portal-phishing-campaign-2026→0/100[CRITICAL]In late July 2026, an unidentified threat actor mailed counterfeit IRS letters to U.S. cryptocurrency holders directing them to a fictitious 'Digital Asset Compliance Portal' (DACP) at a lookalike domain. IRS Criminal Investigation (IRS-CI) issued a public warning on July 30, 2026, confirming no such portal exists and that the campaign was designed to harvest personal information, exchange credentials, and digital asset holdings. The phishing infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior history of financial phishing activity.
avoid.net/irs-digital-asset-compliance-portal-phishing-campaign-2026→0/100[CRITICAL]Beginning in late July 2026, an organized criminal operation mailed counterfeit IRS letters to US cryptocurrency holders directing them via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest credentials and drain digital asset accounts. IRS Criminal Investigation confirmed the campaign on July 30, 2026, stating no such portal exists; infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior phishing history.
avoid.net/dforce-network→32/100[WARNING]dForce Network is a China-founded DeFi protocol suite offering lending, stablecoin, and trading products, founded in late 2018 by Mindao Yang and Xin Xu. The protocol suffered two significant security incidents: a $25 million ERC-777 reentrancy exploit in April 2020 and a $3.65 million read-only reentrancy attack in February 2023, with funds returned in both cases. Despite recovering from both exploits and continuing to operate across multiple chains, the protocol's pattern of deploying code without fully auditing all integrated components remains a documented risk factor.
avoid.net/nishad-singh→12/100[CRITICAL]Nishad Singh is a former software engineer who served as Director of Engineering at FTX, the cryptocurrency exchange that collapsed in November 2022 following the misappropriation of more than $8 billion in customer funds. Singh pleaded guilty in February 2023 to six criminal charges including wire fraud, commodities fraud, securities fraud, money laundering conspiracy, and campaign finance violations, and was sentenced in October 2024 to time served with no prison after providing extensive cooperation against FTX founder Sam Bankman-Fried. A supplemental CFTC civil settlement was reached in April 2026, requiring Singh to disgorge $3.7 million and subjecting him to a five-year trading ban.
avoid.net/dforce-lending→28/100[WARNING]dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.
avoid.net/lendfme→30/100[WARNING]Lendf.me was a decentralized lending protocol built by dForce Network and launched in September 2019 as a fork of Compound v1. On April 19, 2020, an attacker exploited a reentrancy vulnerability involving ERC-777 tokens to drain approximately $25.2 million from the protocol — at the time representing 99.95% of its total value locked. The attacker returned nearly all funds within two days after inadvertently exposing identifying metadata, and the original Lendf.me contract was permanently deprecated following the incident.
avoid.net/ansem-ansem-black-bull-creator-coin-controversy→38/100[WARNING]In mid-to-late June 2026, an anonymous developer launched a Solana memecoin branded with the name of prominent crypto trader Ansem (Zion Thomas, @blknoiz06) and sent him 650 million tokens at no cost; Ansem's resulting holdings peaked at over $100 million in value before declining sharply. Ansem, who says he did not create or officially endorse the token, subsequently airdropped roughly $7 million of it to Solana wallets and publicly denied intending a rug pull amid community backlash over the concentration of supply in his wallet. No regulator, court, or on-chain investigator has established that investors suffered net losses attributable to Ansem's conduct, and Ansem has not sold his holdings as of the most recent reporting reviewed.
avoid.net/indonesia-pig-butchering-syndicate-live-model-operation-2025-2026→0/100[CRITICAL]An international online fraud syndicate operating out of Sukoharjo and Surakarta in Central Java, Indonesia from approximately July 2025 to May 2026, allegedly defrauding at least 133 U.S. victims of approximately US$2.33 million through romance manipulation and fake cryptocurrency investment platforms, a scheme known as 'pig butchering.' Indonesian police arrested 39 suspects in May 2026 and have engaged the FBI given the predominance of American victims. Charges are pending; no convictions have been entered as of the date of this investigation.
avoid.net/stake-com→38/100[WARNING]Stake.com is the world's largest crypto gambling platform by revenue, founded in 2017 by Australian entrepreneurs Ed Craven and Bijan Tehrani and operating under a Curacao gaming license. In September 2023, the platform suffered a $41 million hot wallet breach that the FBI formally attributed to North Korea's Lazarus Group (APT38). The platform faces mounting legal and regulatory pressure across multiple jurisdictions, including a landmark California civil suit filed by the Los Angeles City Attorney in 2025, multiple class action lawsuits, and a UK exit following a Gambling Commission investigation.
avoid.net/hundred-finance→8/100[CRITICAL]Hundred Finance was a multi-chain DeFi lending protocol forked from Compound V2 that suffered at least two major security exploits totaling approximately $13.6 million in direct losses, alongside a related $11 million joint attack with Agave Finance on Gnosis Chain. The protocol was unable to recover stolen funds and shut down in August 2023 following a governance vote, with remaining treasury funds allocated toward partial victim compensation. Stolen funds remained unrecovered as of 2024, with the April 2023 attacker moving assets through decentralized exchanges more than a year after the exploit.
avoid.net/leetswap→32/100[WARNING]LeetSwap was a decentralized exchange (DEX) launched on Coinbase's Base Layer 2 network in mid-2023 and briefly held the position of the network's largest DEX by trading volume and total value locked. On August 1, 2023, shortly after Base's mainnet opened to all users, an attacker exploited a publicly exposed smart contract function to drain approximately 342 ETH (~$630,000) from multiple liquidity pools. The protocol halted trading, partially recovered funds through white-hat rescue operations, and has since operated at a fraction of its pre-exploit TVL, with no public audit ever confirmed prior to the incident.
avoid.net/elephant-money→10/100[CRITICAL]Elephant Money is a Binance Smart Chain DeFi protocol offering the ELEPHANT reward token and TRUNK stablecoin that suffered a $22.2 million flash loan price-manipulation exploit in April 2022, with stolen funds laundered through Tornado Cash. Independent analysts have additionally alleged that the protocol's yield mechanics constitute a structurally unsustainable Ponzi scheme dependent on continuous new capital inflows.
avoid.net/fomo-token→18/100[CRITICAL]The name 'FOMO Token' and ticker '$FOMO' are shared by numerous unrelated crypto projects across multiple blockchains, the most prominent being FOMO Network (Ethereum, ERC-20), Fomo Lab (Ethereum, ERC-20), FomoFi (BNB Chain), and several unnamed meme coins on Solana and other chains. The dominant risk signal centers on FOMO Network, whose token collapsed from approximately $28 million in market capitalization to near zero on June 10, 2024 in an event investigators and community members described as a rug pull; the project's founder, Ashley Ward (also known as Ashley Keable and online as 'Toshi'), carries two prior UK fraud convictions and an October 2025 investigative report by Byline Times linked him to a pattern of serial scam activity. Separately, phishing operations impersonating the legitimate fomo.family trading app — including the typosquatted domains fomoo.family and claim-fomo.family — actively drain connected wallets and represent an ongoing third-party fraud risk unrelated to any specific FOMO-named token.
avoid.net/codexfield→12/100[CRITICAL]CodexField is a decentralized code-management and developer marketplace platform built on BNB Greenfield that won first place in BNB Chain's Hackvolution hackathon in September 2023. On July 9, 2026, on-chain researcher Specter alleged the project may be executing a rug pull, citing partially verified cross-chain fund movements totaling 17.3 million USDT and claiming total user funds at risk of approximately USD 85 million. As of the investigation date, CodexField and BNB Chain have not publicly responded to the allegations, and the USD 85 million figure lacks a complete published on-chain trace.
avoid.net/cronos-chain→26/100[WARNING]Cronos is an EVM-compatible blockchain developed by Crypto.com and operated by Cronos Labs, running a capped, invitation-only validator set. On August 30, 2026, validators halted block production and executed a full chain rollback after a price-manipulation exploit drained an estimated $75 million from Tectonic, the chain's dominant lending protocol; the rollback erased approximately two hours of transaction history network-wide and recovered most of the stolen funds on-chain, while roughly $6.29 million that had already been bridged to Ethereum was not recovered. The incident reignited longstanding debates about immutability, validator centralization, and the degree of operational control Crypto.com holds over the network.
avoid.net/more-markets→17/100[CRITICAL]More Markets is a DeFi lending protocol built on the Flow EVM blockchain by More Labs, operating as a fork of Aave V3. On August 31, 2026, an attacker exploited the protocol's E-Mode mechanism using Ankr's ankrFLOW liquid staking token as collateral to drain approximately 15.5 million WFLOW tokens, valued at roughly $9.3 million according to security firm Blockaid's initial estimate. The protocol subsequently paused operations and disputed the scale of losses reported by Blockaid, attributing the root vulnerability to a third party, though a post-mortem had not been published as of the date of this report.
avoid.net/sheldon-xia-bitmart-founder→10/100[CRITICAL]Sheldon Xia is the founder of BitMart, a cryptocurrency exchange he established in 2017 that served over 13 million users across 180 countries before announcing a wind-down on July 26, 2026. Since that announcement, Xia has become the primary target of accountability demands from users and employees who allege frozen withdrawals and unpaid salaries, while Xia has publicly dismissed calls for a third-party audit and wallet disclosure as fabricated rumors. As of August 20, 2026, Xia has released no proof-of-reserves, no repayment plan, and no independent accounting of user funds, while on-chain data tracked by Arkham Intelligence shows a significant decline in wallet balances attributable to exchange-linked addresses.
avoid.net/dean-daghita-cmdss-command-services-and-support→0/100[CRITICAL]Command Services and Support, Inc. (CMDSS) is a Haymarket, Virginia-based Service-Disabled Veteran-Owned Small Business led by president and CEO Dean Daghita that received a U.S. Marshals Service contract in October 2024 to manage and dispose of Class 2-4 seized cryptocurrency. In January 2026, blockchain investigator ZachXBT publicly alleged that Daghita's son, John Daghita (alias 'Lick'), had stolen over $46 million in digital assets from government-controlled USMS wallets by abusing insider access obtained through his father's company. John Daghita was arrested in Saint Martin on March 4, 2026, and was subsequently indicted on 15 federal counts; Dean Daghita himself had not been charged as of August 2026, though CMDSS's online presence was taken offline following the revelations and the company faces significant scrutiny over contract award process and oversight failures.
avoid.net/uniblock→64/100[CAUTIONARY]Uniblock is a Canadian Web3 infrastructure company founded in 2022 that provides a unified, multi-chain API aggregation platform for blockchain developers, connecting over 300 blockchains and 55 data providers through a single interface with patented auto-routing technology. The company is venture-backed with C$7.5 million in total funding from institutional investors including SBI Ven Capital, AllianceDAO, NGC Ventures, Alchemy, and MoonPay. No regulatory actions, fraud allegations, or significant security incidents have been identified; risk factors are principally commercial and operational rather than conduct-related.
avoid.net/jump-trading→42/100[WARNING]Jump Trading is a Chicago-based proprietary trading firm founded in 1999, operating one of the largest high-frequency trading operations globally across futures, equities, fixed income, FX, and cryptocurrency markets. Its crypto division, Jump Crypto, became a major force in DeFi infrastructure between 2021 and 2023, co-developing Wormhole, Pyth Network, and the Firedancer Solana validator client. The firm has faced significant regulatory and legal exposure: its subsidiary Tai Mo Shan settled with the SEC in December 2024 for $123 million over TerraUSD manipulation, the Terraform bankruptcy administrator filed a $4 billion civil lawsuit in December 2025 naming Jump and individual executives, and a separate CFTC investigation was reported in 2024 with no public resolution as of mid-2026.
avoid.net/euler-finance→58/100[CAUTIONARY]Euler Finance is an Ethereum-based non-custodial lending protocol founded in 2020 by Michael Bentley (PhD, Oxford) that pioneered permissionless lending for long-tail ERC-20 assets. On March 13, 2023, the protocol suffered a ~$197 million flash loan exploit — the largest DeFi hack of 2023 — caused by a missing health check in the donateToReserves() function. In an unusual outcome, the attacker, who communicated under the alias 'Jacob,' returned approximately $240 million in assets (including ETH price appreciation) over three weeks following on-chain negotiations, enabling full user restitution. The protocol relaunched as Euler V2 in September 2024 with a modular architecture, 45+ security audits, and subsequently grew TVL to over $1.5 billion by early 2025.
avoid.net/bzx-protocol→12/100[CRITICAL]bZx Protocol was an Ethereum-based decentralized margin trading and lending protocol founded in 2017 by Tom Bean and Kyle Kistner. The protocol suffered four separate security incidents between 2020 and 2021, culminating in a ~$55 million hack attributed to a phishing-induced private key compromise. Following a transfer of control to a DAO structure, the successor Ooki DAO was sued by the CFTC for operating an unregistered derivatives exchange, ultimately receiving a default judgment, trading bans, and a court-ordered shutdown in June 2023.
avoid.net/ooki→5/100[CRITICAL]Ooki Protocol (formerly bZx Protocol) is a decentralized margin trading and lending protocol on Ethereum that was the subject of the first-ever CFTC enforcement action against a DAO, resulting in a 2023 default judgment ordering the protocol to cease operations and pay $643,542 in penalties. The protocol suffered four separate security incidents between 2020 and 2021 totaling over $64 million in losses, including a $55 million phishing-based hack attributed by Kaspersky to the North Korean state-linked BlueNoroff group. Following the CFTC judgment, the Ooki DAO's website was ordered shut down and the protocol has been effectively defunct.
avoid.net/minterest→22/100[CRITICAL]Minterest (formerly using the MNT token, later rebranded to MINTY) was a cross-chain DeFi lending and borrowing protocol founded by Josh Rogers and incorporated as Minterest Labs OÜ in Estonia. The protocol suffered a $1.4 million reentrancy exploit on July 14, 2024 — in a market that went live without a completed security audit — and subsequently announced the sunsetting of all operations in November 2025, explicitly stating that hack victims would receive no refund or token compensation as part of the wind-down.
avoid.net/us-government-crypto-wallet→10/100[CRITICAL]The US government holds one of the largest concentrations of seized cryptocurrency in the world, accumulated through major law enforcement actions including the 2016 Bitfinex hack and the Silk Road darknet marketplace. In October 2024, a government-controlled wallet linked to Bitfinex seizure funds was drained of approximately $20 million in what was subsequently attributed to alleged insider theft by John Daghita, son of a US Marshals Service contractor, who was arrested in Saint Martin in March 2026 after a blockchain investigation by ZachXBT exposed the scheme.
avoid.net/typus-perp→28/100[WARNING]Typus Perp is a GMX-style perpetuals DEX operating on the Sui blockchain, developed by Typus Finance (founded by Tommy Chen). On October 15, 2025, the protocol suffered a $3.44 million oracle manipulation exploit that drained its TLP liquidity pool entirely — caused by an unaudited smart contract module that was excluded from the project's May 2025 MoveBit security audit. As of May 2026, the protocol has minimal TVL ($126K) and the stolen funds have not been recovered.
avoid.net/fake-gta-6-leak-wallet-drainer-campaign→2/100[CRITICAL]A live phishing campaign, first documented by Malwarebytes on September 1, 2026, impersonates a fan countdown site for Rockstar Games' Grand Theft Auto VI and offers a 'leaked' pre-release copy for $50 or 1 SOL. Behind the payment flow, the site runs two malicious wallet-drainer scripts — one built specifically for Solana and a separate multi-chain tool covering Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base and Fantom — that empty a connecting wallet down to fee-covering dust once a user approves a transaction. Rockstar Games and its parent Take-Two are impersonated brands and are not implicated in any wrongdoing; GTA 6's confirmed retail launch is November 19, 2026, meaning any offer of a playable 'leaked copy' before that date is fraudulent by definition.
avoid.net/ramil-ventura-palafox→0/100[CRITICAL]Ramil Ventura Palafox, a dual U.S.-Philippine citizen and founder of Praetorian Group International (PGI), was sentenced on February 12, 2026 to 20 years in federal prison after pleading guilty to wire fraud and money laundering for operating a Bitcoin Ponzi scheme that received over $201 million from more than 90,000 investors worldwide between December 2019 and October 2021. On April 6, 2026, he removed his GPS monitoring device and failed to report to prison, becoming a federal fugitive; the FBI placed him on its Most Wanted list, and he was arrested approximately 12 days later in Los Angeles, California, where he remains in federal custody.
avoid.net/asymmetric-research→77/100[VERIFIED]Asymmetric Research is a specialized blockchain security firm founded by Jonathan Claudius (formerly CSO at Jump Crypto) and Felix Wilhelm (formerly at Google Project Zero and Jump Crypto), with a team of 45+ researchers across North America, Europe, and Asia. The firm focuses on embedded, long-term security partnerships with L1/L2 blockchains and DeFi protocols, and has disclosed multiple high-severity vulnerabilities across Cosmos, Solana, Ethereum, and Circle infrastructure. No regulatory actions, fraud allegations, or client harm incidents have been identified in available sources.
avoid.net/superior-browser-extension-campaign-wallet-drainer→2/100[CRITICAL]The 'Superior' campaign is a coordinated supply-chain attack involving 19 malicious browser extensions for Chrome and Edge, identified and named by Socket Security in August 2026. The campaign reached approximately 80,000 users, deploys a modular multi-chain wallet-draining framework targeting EVM, Solana, and Tron wallets, and remained active as of late August 2026, with confirmed infrastructure rotation on August 14, 2026. No individual or group has been publicly named as the actor; the campaign name derives from tags found in the malicious JavaScript modules.
avoid.net/tectonic-cronos-august-2026-tonic-price-manipulation-exploit→18/100[CRITICAL]On August 30, 2026, an unknown attacker manipulated the price of TONIC — the thinly traded governance token of Tectonic, the dominant lending protocol on the Cronos blockchain — by approximately 100-fold in roughly 20 minutes, then deposited the artificially inflated tokens as collateral and borrowed an estimated $75 million in liquid assets from the protocol's pools. Cronos validators halted all block production network-wide within minutes, freezing approximately $68.7 million on-chain; roughly $6 million had already been bridged to Ethereum before the halt and could not be recovered by rollback. Validators subsequently rolled the chain back to its pre-attack state — discarding approximately 11,000 blocks and reversing nearly two hours of third-party transactions — and resumed block production at block 90,896,189 (23:49:01 UTC, August 30). As of September 1, 2026, no compensation plan, final loss figure, or formal post-mortem had been published by Tectonic or Cronos Labs.
avoid.net/ofac-operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-2026→0/100[CRITICAL]On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a sweeping sanctions campaign against Iran that, for the first time, designated Iran's entire digital assets sector as sanctionable under Executive Order 13902. The action named nearly 60 entities, individuals, and vessels and listed 30 crypto wallet addresses across Bitcoin, Ethereum, and TRON linked to the Mabna Institute and IRGC-Qods Force. The sectoral determination creates broad secondary sanctions exposure for any foreign crypto business — exchange, custodian, OTC desk, or DeFi protocol — that maintains material Iran-nexus counterparty relationships, regardless of whether those counterparties are individually listed.
avoid.net/gotbit-vortex-antier-contrarian-doj-crypto-market-maker-manipulation-ring→0/100[CRITICAL]Four cryptocurrency market-making firms — Gotbit Consulting, Vortex, Antier Solutions, and Contrarian — were the subjects of coordinated DOJ criminal indictments filed between October 2024 and September 2025 and publicly announced on March 30, 2026. Ten foreign nationals were charged across three separate federal indictments in the Northern District of California and the District of Massachusetts for conducting wash trading and pump-and-dump schemes affecting over 60 cryptocurrency tokens, resulting in the seizure of more than $25 million in digital assets. Gotbit founder Aleksei Andriunin pleaded guilty and was sentenced to eight months in federal prison in June 2025, and Gotbit was ordered to forfeit approximately $23 million in cryptocurrency and cease operations.
avoid.net/ctrl-wallet-security-exploit-and-forced-shutdown→22/100[CRITICAL]Ctrl Wallet, a multi-chain self-custodial wallet formerly known as XDEFI Wallet and supporting over 2,500 blockchain networks with approximately 650,000 monthly active users, permanently ceased operations on August 3, 2026 following an unrecovered June 2026 cryptographic exploit. The exploit targeted the Cardano integration layer operated by SecondFi (formerly Yoroi Wallet), a platform under the same EMURGO parent, draining approximately 16.1 million ADA (roughly $2.4–$2.6 million USD) from 374 wallet addresses via a signing flaw that allowed private key material to be reconstructed from public blockchain data. Users who did not export recovery phrases before the August 3 deadline may face permanent loss of access to remaining funds.
avoid.net/bonzo-finance→18/100[CRITICAL]Bonzo Finance is an open-source, non-custodial lending and borrowing protocol deployed on the Hedera network, developed by Bonzo Finance Labs and launched on mainnet on October 28, 2024. On July 11, 2026, an attacker exploited a BLS signature verification flaw in a Supra oracle contract to artificially inflate the price of the SAUCE token by approximately 12 orders of magnitude, draining approximately $9.05 million in USDC and wrapped HBAR from Bonzo Lend. The incident caused Bonzo Lend's total value locked to collapse 77% and Hedera's overall DeFi TVL to drop nearly 40% within 24 hours; Bonzo Lend and Bonzo Points were subsequently paused, with the Hedera Foundation committing backing for full user position recovery.
avoid.net/triple-a-treasury-hack-july-2026→22/100[CRITICAL]Triple-A, a Singapore-based crypto payment platform holding a Major Payment Institution license from the Monetary Authority of Singapore (MAS), suffered an unauthorized access event beginning approximately July 24, 2026, in which approximately $11.8 million in company treasury assets was drained across seven blockchain networks over roughly 31 hours. The attacker consolidated stolen funds as approximately 5,287 ETH at a single Ethereum address. Triple-A stated that client funds were entirely segregated and unaffected, and that the company remained solvent and able to meet all liabilities.
avoid.net/gotbit-vortex-antier-contrarian-market-manipulation-ring→2/100[CRITICAL]Gotbit, Vortex, Antier Solutions, and Contrarian are four cryptocurrency market-making firms whose executives and employees were charged by the U.S. Department of Justice as part of Operation Token Mirrors, an FBI-led undercover investigation into wash trading and pump-and-dump schemes. Between 2018 and 2025, the firms allegedly provided market manipulation as a service to dozens of crypto projects, generating artificial trading volume through algorithmic bots and coordinated self-dealing across hundreds of wallets. In total, more than $25 million in cryptocurrency was seized and 28 individuals and entities faced criminal or civil charges across two waves of enforcement in October 2024 and March 2026.
avoid.net/zondacrypto→2/100[CRITICAL]Zondacrypto (operating entity: BB Trade Estonia OÜ), formerly known as BitBay and once Poland's largest cryptocurrency exchange, was declared bankrupt by the Harju County Court in Tallinn on August 27, 2026 after CEO Przemyslaw Kral departed to Israel in April 2026 and an on-chain forensic analysis found the exchange's hot-wallet Bitcoin reserves had fallen by approximately 99.7 percent. Polish prosecutors have opened a criminal fraud investigation, with estimated customer losses of roughly 350 million PLN (approximately $82–97 million) affecting up to 30,000 users who cannot access their funds. The collapse also triggered the arrest of Polish Olympic Committee president Radoslaw Piesiewicz on bribery allegations and the bankruptcy of affiliated fintech Femion Technology.
avoid.net/zoth-protocol→8/100[CRITICAL]Zoth Protocol is an Ethereum-based real-world asset (RWA) re-staking and tokenization platform founded in 2023 by Pritam Dutta and Koushik Bhargav. In March 2025 the protocol suffered two separate security incidents within three weeks: an initial $285,000 logic-flaw exploit on March 1 and a far more damaging $8.4 million deployer-key compromise on March 21 that enabled a malicious proxy contract upgrade. The protocol has since launched a user compensation program, engaged Crystal Blockchain BV for fund recovery, and announced a security overhaul backed by a $15 million strategic token commitment from Bolts Capital.
avoid.net/dough-finance→12/100[CRITICAL]Dough Finance was an Ethereum-based DeFi lending and margin-trading protocol co-founded by Chase Herro and Zachary Folkman. On July 12, 2024, the protocol was exploited via a flash loan attack that drained approximately $2.1–2.5 million in user funds due to unvalidated calldata in its ConnectorDeleverageParaswap smart contract. The protocol's website is shut down, the vast majority of the approximately 2,700 affected users have received no meaningful compensation, and the co-founders have since launched World Liberty Financial alongside Donald Trump, earning an alleged $65 million in revenues from that new venture.
avoid.net/zoth-zeusd→28/100[WARNING]Zoth is a Dubai-based real-world asset (RWA) restaking protocol and the issuer of ZeUSD, a CDP-style stablecoin backed by tokenized fixed-income assets including U.S. T-Bills and ETFs. In March 2025, the protocol suffered two separate security incidents within three weeks: a $285,000 logic-flaw exploit on March 1 and a critical $8.4–8.85 million admin key compromise on March 21, the latter resulting in the theft of 8.85 million USD0++ tokens. The stolen funds remain largely unrecovered as of mid-2025, with Zoth offering a $500,000 bounty and engaging Crystal Blockchain BV for forensic investigation.
avoid.net/veil-cash→38/100[WARNING]Veil Cash is a zero-knowledge privacy protocol deployed on Coinbase's Base L2 network, enabling anonymous ETH and USDC transfers via zk-SNARK proofs and a UTXO model. In February 2026 the protocol's legacy pools were exploited due to an incomplete Groth16 trusted-setup ceremony, resulting in 2.9 ETH being drained before funds were returned by the exploiter. The incident attracted industry attention because the same misconfiguration pattern was subsequently replicated in a larger $2.26 million exploit of FoomCash, raising broader questions about cryptographic setup hygiene across ZK DeFi protocols.
avoid.net/resolv→22/100[CRITICAL]Resolv is a DeFi protocol issuing USR, a delta-neutral stablecoin backed by ETH with perpetual futures hedging, developed by Resolv Labs. On March 22, 2026, the protocol suffered a critical exploit in which an attacker compromised Resolv's AWS key management infrastructure to mint 80 million unbacked USR tokens, extracting approximately $23–25 million in ETH and triggering a severe stablecoin depeg. The protocol remains paused as of May 2026 while recovery and infrastructure remediation are underway.
avoid.net/the-sandbox-sand-bridge-exploit→38/100[WARNING]On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.
avoid.net/xtoken→10/100[CRITICAL]xToken (XTK) was a DeFi protocol offering wrapped staking tokens and liquidity management on Ethereum, founded by Michael J. Cohen in 2020. The protocol suffered two major flash loan exploits in 2021 — a $24.5 million attack in May and a $4.5 million attack in August — resulting in total losses exceeding $29 million and the permanent retirement of its flagship xSNX product. The XTK governance token subsequently lost approximately 99.84% of its value, and compensation paid to victims was significantly below the amounts stolen.
avoid.net/team-finance→28/100[WARNING]Team Finance is a DeFi token-locking and vesting platform operated by TrustSwap Inc. that suffered a critical $14.5 million exploit on October 27, 2022, when an attacker abused a validation flaw in its Uniswap V2-to-V3 migration function. The attacker ultimately returned approximately $7 million, retaining roughly 10% as a self-declared bug bounty; Team Finance subsequently switched auditors to CertiK and reported full user reimbursement by June 2023.
avoid.net/rivus-dao→8/100[CRITICAL]Rivus DAO was a Bittensor-focused liquid staking protocol on Ethereum that raised approximately $4.23 million in an April 2024 IDO before suffering a rugpull classified by DefiLlama as a Third-party Dev Backdoor Exploit on September 16, 2024. The incident effectively drained protocol TVL from its operational peak to under $2,500, and the RIVUS governance token lost more than 99.8% of its all-time high value. On-chain investigator ZachXBT has flagged this entity; the project attempted a relaunch in October 2024 but is currently listed as inactive with no trading activity.
avoid.net/heeboo→54/100[CAUTIONARY]HEEBOO is a Solana-based entertainment launchpad and parent company to the Claynosaurz NFT brand, operating under the legal entity HEEBOO GROUP Inc. (a Delaware corporation). The project launched a fair-sale ecosystem token ($HEEBOO) on Solana in 2026 and has secured a content deal with Amazon Prime Video for a Claynosaurz animated series. While the project has a credible creative team and verifiable mainstream partnerships, the $HEEBOO token sale raised standard risk flags around the absence of a published smart-contract audit and a 12.5% treasury allocation that is fully unlocked at the token generation event.
avoid.net/bitcoin-depot→0/100[CRITICAL]Bitcoin Depot was once the largest operator of cryptocurrency ATMs in North America, running approximately 9,700 kiosks at peak. Facing enforcement actions from at least 11 state agencies, a voluntary information request from the SEC, an FTC inquiry, and lawsuits from the attorneys general of Massachusetts and Iowa alleging the company knowingly facilitated hundreds of millions of dollars in consumer fraud, Bitcoin Depot filed for Chapter 11 bankruptcy on May 18, 2026, and immediately took its entire kiosk network offline. This page focuses specifically on the fraud facilitation angle — the mechanisms by which the ATM network was allegedly used to funnel scam proceeds, the regulatory responses that followed, and the consumer harm caused both by third-party scammers and by the abrupt bankruptcy shutdown itself.
avoid.net/web3port→5/100[CRITICAL]Web3Port is a Hong Kong-registered crypto market-making and incubation firm alleged to have orchestrated the dumping of 66 million MOVE tokens one day after the Movement Labs token launch in December 2024, generating approximately $38 million in downward price pressure. Binance subsequently banned and froze the profits of the market-making account it associated with Web3Port, citing misconduct. A U.S. Department of Justice grand jury investigation into the MOVE token launch is ongoing as of 2026, and movement Labs — the project whose token Web3Port allegedly manipulated — filed for Chapter 11 bankruptcy in July 2026.
avoid.net/avraham-eisenberg→2/100[CRITICAL]Avraham Eisenberg, also known as 'Avi Eisenberg,' is a crypto trader who in October 2022 executed an oracle manipulation attack against Mango Markets, a Solana-based DeFi protocol, extracting approximately $110–117 million in digital assets. He publicly claimed the scheme was a 'highly profitable trading strategy' and a legal use of the protocol, returned approximately $67 million after a DAO-mediated settlement, and was subsequently charged by the DOJ, SEC, and CFTC. A federal jury convicted him in April 2024, but a federal judge vacated all criminal convictions in May 2025 on grounds of improper venue and insufficient evidence of material misrepresentation; prosecutors have appealed. Eisenberg is currently serving a separate 52-month federal prison sentence for possession of child sexual abuse material.
avoid.net/seedify→28/100[WARNING]Seedify (Seedify.fund) is a blockchain gaming incubator and IDO/IGO launchpad founded in February 2021 by Levent Cem Aydan, operating on BNB Chain, Ethereum, and Avalanche with its native SFUND token. The platform suffered a critical $1.2–1.7 million bridge exploit in September 2025 attributed by ZachXBT and CZ (Binance) to the North Korean DPRK-affiliated 'Contagious Interview' hacking campaign, causing SFUND to collapse approximately 80–99% and affecting approximately 64,000 token holders. The platform's SFUND token has declined more than 99% from its November 2021 all-time high of approximately $17.67, and the project has been flagged by ZachXBT in connection with the on-chain forensics tying the exploit to state-sponsored theft infrastructure.
avoid.net/audia6-crypto-laundering-network→0/100[CRITICAL]AudiA6 was a professional cryptocurrency money laundering service allegedly operating from 2021 through 2025, accused of processing approximately $389.7 million (EUR 336 million) in illicit funds for ransomware gangs and other cybercriminals. The service also administered the Dark2Web dark web cybercrime forum. A US-led international law enforcement operation dismantled AudiA6's infrastructure on June 10, 2026, and two alleged operators were arrested in Batumi, Georgia and charged by the US Department of Justice.
avoid.net/maya-protocol-august-2026-six-bug-exploit→22/100[CRITICAL]On August 18, 2026, an attacker exploited MAYAChain—the decentralized cross-chain liquidity network operated by Maya Protocol—by chaining six distinct software bugs in a single 23-message transaction. The exploit allowed the attacker to inflate a liquidity pool by approximately 49.45 million CACAO tokens, gain near-total control of that pool, and extract roughly $1.65–1.7 million in Bitcoin and other assets. CACAO's price fell approximately 89% and total network pool value dropped by an estimated $11 million, prompting an emergency network halt. As of late August 2026, the attacker's Bitcoin wallet remained unspent and no patch timeline or LP compensation framework had been publicly confirmed.
avoid.net/faruk-fatih-ozer→0/100[CRITICAL]Faruk Fatih Ozer is the Turkish founder and CEO of Thodex, a cryptocurrency exchange that collapsed in April 2021 after he fled to Albania, leaving approximately 391,000 users unable to access an estimated $2 billion in funds. He was arrested in Albania in August 2022, extradited to Turkey in April 2023, and sentenced on September 7, 2023 to 11,196 years, 10 months, and 15 days in prison on charges of aggravated fraud, founding a criminal organization, and money laundering. He was found dead in Tekirdag F-Type High Security Prison on November 1, 2025, with Turkish authorities indicating initial findings pointed to suicide.
avoid.net/ruja-ignatova→0/100[CRITICAL]Ruja Ignatova, known as the 'Cryptoqueen,' is the Bulgaria-born German co-founder of OneCoin, a fraudulent pyramid scheme that defrauded approximately 3.5 million victims of more than $4 billion between 2014 and 2019. Indicted in 2017 by a U.S. grand jury on charges of wire fraud, money laundering, and securities fraud, she fled law enforcement in October 2017 and remains a fugitive. She is currently an FBI Ten Most Wanted Fugitive with a $5 million reward for information leading to her arrest.
avoid.net/hayden-davis→0/100[CRITICAL]Hayden Mark Davis (born November 27, 1996) is an American cryptocurrency marketer and CEO of Kelsier Ventures who orchestrated the launch of the $LIBRA token on February 14, 2025 — a memecoin promoted by Argentine President Javier Milei that collapsed 85–95% within hours, causing an estimated $251 million in losses across approximately 44,000 to 74,000 investors. On-chain analytics by Bubblemaps and Nansen identified insider wallets tied to Davis and associates extracting between $87 million and $107 million in liquidity during the price peak. Davis is subject to an Interpol Red Notice sought by Argentine prosecutors, a U.S. federal class action (Hurlock v. Kelsier, S.D.N.Y.), and parallel Argentine criminal proceedings; he denies fraud allegations, characterizing the collapse as 'a plan gone miserably wrong.'
avoid.net/harmony-one-august-2026-layer-1-mint-exploit→16/100[CRITICAL]On August 12, 2026, an unidentified attacker exploited two consensus-layer vulnerabilities in the Harmony ONE mainnet to mint approximately 4 billion unauthorized ONE tokens, inflating the circulating supply by roughly 26%. Approximately 97% of the minted tokens reached cryptocurrency exchange deposit wallets before freezes could be enacted. Harmony deployed an emergency patch within roughly five hours, suspended its cross-chain bridge, and subsequently executed a full blockchain rollback to the pre-exploit state of August 11, 2026, erasing more than 109,000 legitimate transactions in the process. This incident is distinct from the June 2022 Horizon bridge hack.
avoid.net/alpha-homora→20/100[CRITICAL]Alpha Homora is a leveraged yield farming protocol developed by Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) that allows users to take on leveraged positions in liquidity pools. On February 13, 2021, the protocol suffered a critical exploit in which an attacker drained approximately $37.5 million from Iron Bank (C.R.E.A.M. Finance) by exploiting multiple smart contract vulnerabilities in Alpha Homora V2, including a hidden undisclosed sUSD lending pool, a rounding miscalculation in the borrow function, and an unrestricted reserve function callable by anyone. The resulting bad debt between the two protocols remained largely unresolved for years, culminating in a public dispute in 2023 in which Iron Bank froze Alpha Homora user accounts, and Alpha Homora proposed surrendering approximately $32 million in user funds to satisfy the outstanding obligation.
avoid.net/coinhub-bitcoin-atm-fraud-facilitation-network→22/100[CRITICAL]Coinhub, operated by Nevada-based LSGT Services LLC, is one of the largest remaining Bitcoin ATM operators in the United States with approximately 2,000 machines following Bitcoin Depot's May 2026 bankruptcy. The company has faced confirmed regulatory enforcement actions in California and Connecticut, has been named in U.S. Senate correspondence over its role in facilitating elder fraud, and has been identified by the ICIJ as a major recipient of bitcoin liquidity from Kraken despite ongoing scam-related losses at its machines. Coinhub has not been charged with fraud or any crime; all regulatory findings to date relate to consumer-protection violations including excessive fees and missing disclosures.
avoid.net/trezor-shipmonk-data-breach→46/100[WARNING]On August 10, 2026, Trezor disclosed that its third-party fulfillment partner ShipMonk suffered a data breach that exposed personal data for 13,689 hardware wallet customers, including names, email addresses, phone numbers, and home shipping addresses. The breach originated from an unpatched critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a business-intelligence tool used by ShipMonk. Trezor's own systems, hardware wallet firmware, and customer private keys were not affected, but the exposure of verified hardware wallet owner home addresses raises direct physical safety concerns given a documented surge in violent crypto-targeted home invasions in 2026.
avoid.net/operation-economic-outcast-iran-digital-asset-sanctions→0/100[CRITICAL]Operation Economic Outcast is a U.S. Treasury-led sanctions campaign announced on August 24, 2026, that for the first time designated Iran's entire digital asset sector as a sanctionable segment of the Iranian economy under Executive Order 13902. The action designated nearly 60 entities, individuals, and vessels and issued five sectoral sanctions determinations — covering digital assets, technology, gold, aviation, and shipping — creating secondary sanctions exposure for any person or business globally that operates in or provides services to Iran's crypto sector. This page documents the regulatory framework, key designations, and compliance implications relevant to anyone interacting with Iran-adjacent protocols, wallets, or exchanges.
avoid.net/pickle→10/100[CRITICAL]Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.
avoid.net/allbridge→28/100[WARNING]Allbridge is a cross-chain bridging protocol founded in 2021 that operates Allbridge Classic and Allbridge Core, supporting stablecoin transfers across more than 20 blockchains. The protocol has suffered three separate security incidents since its launch: a $573K flash loan exploit on BNB Chain in April 2023, a $1.65M flash loan attack on its Solana deployment in July 2026, and a $191K CCTP router exploit on Base in August 2026 involving forged Circle attestation messages. The recurrence of similar vulnerability classes across deployments — and the failure to apply 2023 remediations to all active chains — raises systemic concerns about the protocol's security review and deployment practices.
avoid.net/coinw6→0/100[CRITICAL]CoinW6 is a fraudulent cryptocurrency trading platform at the center of the SEC's first-ever enforcement action targeting a pig butchering (relationship investment) scam, filed September 17, 2024 in the U.S. District Court for the Central District of California (Case No. 2:24-cv-07924). According to the SEC's complaint, operators of CoinW6 posed as wealthy professionals on LinkedIn and Instagram, cultivated romantic relationships with victims over WhatsApp, then directed at least 11 investors to a fake trading interface that displayed fabricated returns, stealing approximately $2.2 million between July 2022 and December 2023. As of mid-2026, the case remains pending, with the SEC seeking service by publication after defendants failed to appear.
avoid.net/ottersex→50/100[WARNING]No verifiable information about a cryptocurrency project, token, memecoin, or NFT collection named 'Ottersex' was found across public web sources, blockchain explorers, or market data aggregators as of September 2026. The entity may be an extremely obscure micro-cap or short-lived token that has left no indexed trace, or the name may be a variant spelling of another project. No risk signals, team information, or community activity could be confirmed.
avoid.net/avici→38/100[WARNING]Avici (ticker: AVICI) is a Solana-based, self-custodial neobank and crypto payment platform that launched its token via an on-chain MetaDAO sale in October 2025. On August 28–29, 2026, attackers exploited an outdated Solana card contract supplied by Avici's issuing partner Rain, draining an estimated $500,859 to over $1 million from approximately 1,685 user card accounts; Avici pledged full refunds, filed an FBI IC3 report, and the stolen funds were ultimately moved through Tornado Cash. Separately, third-party scammers created fake airdrop sites impersonating Avici to drain additional user wallets.
avoid.net/fogo→38/100[WARNING]Fogo is a Layer 1 blockchain built on the Solana Virtual Machine (SVM), designed for institutional-grade, low-latency trading and settlement. It launched its public mainnet in January 2026 after raising approximately $20.5 million across multiple funding rounds. On August 29, 2026, the Fogo Foundation disclosed a wallet breach in which an unknown actor transferred 400 million FOGO tokens (approximately 4% of total supply, valued at roughly $3.88 million at the time) to an external address, causing the token price to fall approximately 18–20%.
avoid.net/gary-wang→18/100[CRITICAL]Zixiao 'Gary' Wang is the co-founder and former Chief Technology Officer of FTX, the cryptocurrency exchange that collapsed in November 2022 following the discovery of an $8 billion shortfall caused by the misappropriation of customer funds to affiliated hedge fund Alameda Research. Wang pleaded guilty in December 2022 to four counts of wire fraud and conspiracy, served as a principal cooperating witness against former CEO Sam Bankman-Fried, and was sentenced in November 2024 to time served with three years of supervised release and $11 billion in forfeiture obligations.
avoid.net/qubit-finance→5/100[CRITICAL]Qubit Finance was a BSC-based DeFi lending and borrowing protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logical flaw in the protocol's Ethereum-BSC cross-chain bridge (QBridge), minting 77,162 qXETH without depositing any real ETH on Ethereum, ultimately draining approximately $80 million in user funds. No funds were recovered, the attacker's identity was never established, and the compensation plan announced by the team was never verifiably fulfilled.
avoid.net/prisma-fi→12/100[CRITICAL]Prisma Finance was an Ethereum-based collateralized debt position (CDP) protocol that issued stablecoins (mkUSD and ULTRA) backed by liquid staking and restaking tokens (LRTs/LSTs). On March 28, 2024, a critical input validation flaw in the MigrateTroveZap contract was exploited via flash loan, resulting in the theft of approximately 3,479 ETH (~$12 million) from user vaults. Following the exploit, the core team effectively abandoned the protocol, which was subsequently shut down via DAO governance (PIP-46) and succeeded by Resupply Finance.
avoid.net/gala-games→42/100[WARNING]Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer (co-founder of Zynga) and Wright Thurston, issuing the GALA utility and governance token. The company has been beset by a high-profile inter-founder legal dispute alleging $130 million in token theft, a May 2024 smart contract exploit in which 5 billion GALA tokens worth approximately $200–240 million were minted by a compromised admin wallet, and co-founder Wright Thurston's prior SEC lawsuit over an unrelated $18 million unregistered securities offering. These compounding governance failures, security incidents, and legal controversies place the platform among the more heavily scrutinized projects in the blockchain gaming sector.
avoid.net/term-finance→22/100[CRITICAL]Term Finance is an Ethereum-based DeFi fixed-rate lending protocol developed by Term Labs, Inc., which raised $8 million in funding from investors including Electric Capital and Maelstrom. On August 23, 2026, an attacker bootstrapped with 2 ETH sourced from Tornado Cash, acquired majority voting control of the protocol's sparsely held DAO governance token at a cost of approximately $951, and passed malicious proposals to drain an estimated $8.5 million (2,843 ETH and 1.68 million USDC) from Term's Meta Vaults. In response, Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles; as of the time of writing, no recovery of stolen funds has been confirmed and no concrete user compensation plan has been announced.
avoid.net/edward-zimbardi-the-crypto-program→2/100[CRITICAL]The Crypto Program was an alleged cryptocurrency investment fraud operated by Edward Zimbardi, 59, of Flowery Branch, Georgia between June 2022 and August 2023. Prosecutors allege the scheme collected more than $165 million from over 6,000 investors worldwide by promising guaranteed 25% monthly returns on fictitious digital advertising packages. A federal grand jury indicted Zimbardi on July 8, 2026 on 25 counts; he was deported from Fiji to U.S. custody on August 14, 2026 and the case is currently pending trial.
avoid.net/snowdog→5/100[CRITICAL]Snowdog (SDOG) was an Avalanche-based OlympusDAO fork launched in November 2021 as a self-described '8-day decentralized reserve meme coin experiment' by the anonymous team behind Snowbank DAO. The project accumulated a $44 million MIM treasury before a planned token buyback on November 25, 2021, collapsed the token price by over 90% within seconds, with alleged insiders exploiting a hidden 'challengeKey' mechanism to extract approximately $20 million in profits while ordinary holders were locked out. The team declined to acknowledge deliberate wrongdoing, characterizing the event as a 'game-theory experiment gone wrong,' and subsequently renounced ownership, leaving investors with near-total losses.
avoid.net/mango-markets-v3→10/100[CRITICAL]Mango Markets V3 was a Solana-based decentralized margin trading protocol that suffered a $116 million oracle manipulation attack in October 2022 executed by Avraham Eisenberg, who artificially inflated the MNGO token price to extract funds against fabricated collateral. The protocol subsequently reached a partial recovery settlement, faced SEC and CFTC enforcement actions, and formally wound down operations by January 2025.
avoid.net/cftc-crypto-atm-scam-warning→5/100[CRITICAL]On August 26–27, 2026, the U.S. Commodity Futures Trading Commission issued a formal consumer alert titled 'Pause Before You Pay: Unusual Money Transfer Instructions May Signal Fraud,' warning the public about a sharp rise in cryptocurrency ATM scams. The warning was grounded in FBI Internet Crime Complaint Center data showing that U.S. residents filed 13,460 complaints involving cryptocurrency kiosks in 2025, reporting $388,981,267 in losses — a 58% year-over-year increase. More than half of all complaints involved people over 50, who collectively reported losses exceeding $302 million, making this demographic the primary target of the attack pattern.
avoid.net/operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-2026→0/100[CRITICAL]On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a whole-of-government sanctions campaign against Iran and its enablers, issuing the first-ever sectoral sanctions determination covering Iran's digital assets sector under Executive Order 13902. The action designated 78 individuals, entities, and vessels across 13 jurisdictions and structurally expanded secondary sanctions exposure so that any foreign person anywhere in the world who operates in or provides support to Iran's digital asset sector may now be designated — without OFAC needing to name them in advance. This page documents the regulatory action itself, the named designees with crypto relevance, and the compliance implications for global exchanges, OTC desks, and DeFi infrastructure.
avoid.net/ivan-obukhov-foscom-fze→2/100[CRITICAL]Ivan Obukhov is a UAE-based Ukrainian national designated by OFAC on August 24, 2026, as part of Operation Economic Outcast. U.S. Treasury alleges that since 2023 he processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Qods Force, and that he has for years brokered Iranian shadow-fleet vessels. His UAE-registered company Foscom FZE, which he acquired in 2022, was simultaneously designated under Executive Order 13224 as an entity controlled by Obukhov.
avoid.net/maya-protocol→28/100[WARNING]Maya Protocol (MAYAChain) is a decentralized cross-chain liquidity network and friendly fork of THORChain that launched its mainnet in April 2023. On August 18, 2026, an attacker chained six software vulnerabilities in a single 23-message transaction to fabricate approximately 49.45 million CACAO tokens, drain roughly $1.36 million in Bitcoin and other assets off-chain, and trigger an 88.7% collapse in CACAO's price. The team halted the network globally in response; as of late August 2026, the attacker had not returned funds, no formal post-mortem had been published by the team, and no swap-resumption timeline had been announced.
avoid.net/maya-protocol-mayachain→12/100[CRITICAL]Maya Protocol is a permissionless, decentralized cross-chain liquidity network built on MAYAChain, a THORChain fork that launched mainnet in April 2023. On August 18, 2026, the protocol suffered its first documented loss-of-funds incident: an attacker chained six software vulnerabilities in a single 23-message transaction to extract approximately $1.36 million in hard assets (including 20.83 BTC) and trigger a broader pool-value impact estimated at $11 million, while CACAO crashed 89%. MAYAChain halted all operations on August 18, 2026, and has not resumed as of August 23, 2026; no funds have been returned.
avoid.net/kyle-davies→3/100[CRITICAL]Kyle Davies is the co-founder of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion in liabilities owed to 27 creditors. Following the collapse, Davies evaded liquidators, was sentenced in absentia to four months imprisonment in Singapore for failing to cooperate with court-ordered investigations, and received a nine-year ban from Singapore's Monetary Authority of Singapore (MAS) for regulatory violations including providing false information to regulators. He subsequently co-founded OPNX, a crypto bankruptcy claims exchange that also failed and shut down in early 2024.
avoid.net/su-zhu→3/100[CRITICAL]Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.
avoid.net/orbit-chain-bridge→8/100[CRITICAL]Orbit Bridge is the cross-chain bridging protocol of Orbit Chain, developed by South Korean blockchain company Ozys. On December 31, 2023, attackers compromised seven of ten multisig private keys and drained approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Ethereum vault in the largest crypto hack of New Year's Eve 2023. The attack has been attributed with medium-to-high confidence to North Korea's Lazarus Group, with an additional alleged insider-threat dimension involving Ozys' former chief information security officer, who allegedly sabotaged the company firewall weeks before the exploit.
avoid.net/superrare→45/100[WARNING]SuperRare is a curated Ethereum-based NFT art marketplace founded in 2018 by John Crain, Charles Crain, and Jonathan Perkins, operating as a high-end platform for 1-of-1 digital artworks with its own governance token RARE. On July 28, 2025, a critical access control vulnerability in the platform's RareStakingV1 staking contract was exploited, resulting in the theft of approximately 11.9 million RARE tokens worth roughly $731,000. SuperRare subsequently reimbursed the 61 affected wallets by August 5, 2025, and the RARE token recovered approximately 41% following the remediation announcement.
avoid.net/axiom-dex-insider-trading-2026→22/100[CRITICAL]In February 2026, blockchain investigator ZachXBT published findings alleging that employees of Axiom Exchange, a Y Combinator-backed Solana trading platform, abused internal customer support dashboards to track private user wallet activity and execute insider trades over approximately one year. The alleged scheme, centered on senior business development employee Broox Bauer, exploited the platform's lack of role-based access controls to compile non-public trading data on high-profile crypto traders, with a secondary layer of alleged front-running on Polymarket prediction markets using advance knowledge of ZachXBT's impending report. No formal criminal charges had been publicly announced as of the investigation's release.
avoid.net/novatech-ltd→2/100[CRITICAL]NovaTech Ltd. (also marketed as NovaTech FX) was a crypto trading and multi-level marketing program incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion from June 2019 through May 2023. The SEC alleges it raised more than $650 million from over 200,000 investors worldwide — largely from Haitian-American communities — while conducting only a small fraction of the promised trading. The scheme collapsed in May 2023; the SEC filed civil fraud charges in August 2024 and the Petions had not been served as of mid-2025, reportedly located in Panama.
avoid.net/curve-finance→62/100[CAUTIONARY]Curve Finance is a major decentralized exchange (DEX) on Ethereum optimized for stablecoin and pegged-asset trading, operating since January 2020. On July 30, 2023, a latent vulnerability in the Vyper smart-contract compiler (versions 0.2.15, 0.2.16, and 0.3.0) was exploited across multiple Curve liquidity pools, draining approximately $70 million and triggering a near-systemic crisis when the resulting CRV price drop threatened to cascade-liquidate founder Michael Egorov's heavily collateralized on-chain loans. Roughly 73% of stolen funds were ultimately recovered or returned, and in December 2023 the Curve DAO voted to disburse approximately $49 million in compensation to affected liquidity providers.
avoid.net/wormhole-bridge→63/100[CAUTIONARY]Wormhole Bridge is a cross-chain messaging and token bridge protocol originally developed by Certus One, later owned by Jump Crypto, enabling asset transfers between Solana, Ethereum, and other blockchains. On February 2, 2022, an attacker exploited a signature verification flaw in the Solana-side smart contract to fraudulently mint 120,000 wrapped ETH (wETH) worth approximately $320–326 million without posting collateral, making it the second-largest DeFi exploit in history at the time. Jump Crypto replenished the stolen ETH within 24 hours to prevent ecosystem collapse, and a court-authorized counter-exploit in February 2023 recovered approximately $140 million of the remaining stolen funds.
avoid.net/cetus-protocol→28/100[WARNING]Cetus Protocol is a concentrated liquidity market maker (CLMM) decentralized exchange deployed on the Sui and Aptos blockchains. On May 22, 2025, the protocol suffered one of the largest DeFi exploits in history when an attacker exploited an integer overflow vulnerability in its smart contract math library to drain approximately $223 million from liquidity pools. Roughly $162 million was frozen on-chain through emergency validator action by the Sui network, and following a governance vote the protocol relaunched in June 2025 with partial user compensation.
avoid.net/bitcoin-latinum-ltnm-donald-basile→2/100[CRITICAL]Bitcoin Latinum (LTNM) is a cryptocurrency token launched in 2020 by Donald G. Basile through his companies GIBF GP, Inc. and Monsoon Blockchain Corporation. In April 2026, the U.S. Securities and Exchange Commission charged Basile with orchestrating a $16 million investor fraud scheme, alleging he raised funds through Simple Agreements for Future Tokens (SAFTs) using fabricated insurance coverage claims and nonexistent asset-backing structures, then diverted millions to personal expenses. The token, which peaked near $9,336 in December 2021, has since collapsed to near zero, and multiple civil lawsuits from defrauded investors preceded the SEC action.
avoid.net/transit-finance→2/100[CRITICAL]Transit Finance (also known as Transit Swap) is a cross-chain DEX aggregator supporting over 122 decentralized exchanges across Ethereum, BNB Chain, TRON, Solana, Polygon, and other networks. The protocol has suffered two confirmed security exploits: a $28.9 million hack in October 2022 due to an arbitrary external call vulnerability in its routing contract, with approximately $18.9 million recovered; and a second $1.88 million exploit in May 2026 via a deprecated TRON smart contract that remained on-chain and exploitable years after official deprecation. ZachXBT flagged the protocol amid broader DeFi monitoring, and the 2022 attacker routed funds through OFAC-sanctioned Tornado Cash.
avoid.net/eminence→10/100[CRITICAL]Eminence Finance (EMN) was an unfinished, unaudited NFT gaming protocol being developed by Yearn Finance founder Andre Cronje that was exploited on September 29, 2020, resulting in the theft of approximately $15 million in DAI from its bonding curve contracts. The contracts had never been officially announced or released to the public, but community members discovered and deposited into them after Cronje's cryptic tweets; the attacker returned $8 million to Cronje's deployer address but $7 million was never recovered. The incident became a defining case study in DeFi's 'degen' culture and the risks of deploying unaudited smart contracts to Ethereum mainnet.
avoid.net/yearn-finance→58/100[CAUTIONARY]Yearn Finance is a decentralized yield aggregator on Ethereum that routes user deposits into lending protocols to maximize returns. Founded by Andre Cronje in 2020, the protocol has suffered at least four documented security exploits between 2021 and 2025, with aggregate losses exceeding $20 million, and its founder departed in 2022 citing sustained pressure from an SEC investigation. Governance concerns, an interconnected web of affiliated DeFi protocols implicated in their own major hacks, and repeated failures to deprecate vulnerable legacy code compound the protocol's risk profile.
avoid.net/vee-finance→12/100[CRITICAL]Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.
avoid.net/compound-v2→28/100[WARNING]Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.
avoid.net/pnetwork→12/100[CRITICAL]pNetwork is a cross-chain bridge and interoperability protocol built on the pTokens architecture, enabling assets to move between Bitcoin, Ethereum, BNB Chain, and other networks via wrapped synthetic tokens. The protocol has suffered two major security incidents — a September 2021 pBTC-on-BSC hack losing approximately $12 million, and a November 2022 pGALA incident that triggered a $28 million lawsuit by Gala Games and Huobi alleging pNetwork's own engineers caused the vulnerability through a leaked private key, then allegedly profited from a self-described 'white hat' rescue. As of 2025, the PNT governance token trades at a fraction of its 2021 peak and the protocol operates with negligible market capitalization and trading volume.
avoid.net/prismalst→10/100[CRITICAL]Prisma Finance is a Liquity-forked, Ethereum-based DeFi protocol that allowed users to mint overcollateralized stablecoins (mkUSD and ULTRA) against liquid staking tokens (LSTs) such as wstETH, rETH, sfrxETH, and cbETH. On March 28, 2024, a critical vulnerability in the protocol's MigrateTroveZap helper contract was exploited for approximately $11.6 million, with a total loss across all attacker wallets of roughly $12.3 million; the primary exploiter sent the majority of stolen funds through Tornado Cash while claiming a 'whitehat rescue,' and as of 2026 the protocol's TVL has collapsed from a pre-exploit peak of approximately $220 million to under $300K.
avoid.net/unibtc→32/100[WARNING]uniBTC is a synthetic Bitcoin liquid restaking token issued by Bedrock protocol, enabling wBTC holders to earn BTC-native yield via the Babylon staking protocol while retaining liquidity. In September 2024, a critical minting vulnerability in multiple uniBTC vault smart contracts across eight blockchains was exploited for approximately $2 million after a third-party security firm disclosed the flaw hours before the attack. Post-incident forensics by Fuzzland, disclosed in June 2025, attributed the exploit to an insider threat — a former employee who embedded malware into Fuzzland's internal codebase and used privileged access to execute the attack; Bedrock has since integrated Chainlink Proof of Reserve and expanded to multiple new chains.
avoid.net/kinto-bridge→28/100[WARNING]Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.
avoid.net/curve-llamalend→52/100[CAUTIONARY]Curve LlamaLend (also referred to as the crvUSD lending markets) is a decentralized, permissionless isolated lending protocol built by Curve Finance that allows users to borrow crvUSD against crypto collateral using the LLAMMA soft-liquidation mechanism. The protocol has experienced multiple distinct incidents since launch: a $10 million bad-debt event in June 2024 tied to the founder's oversized leveraged positions, an oracle-manipulation attack on the sDOLA market in March 2026 resulting in approximately $240,000 in borrower losses, an October 2025 market crash that left the CRV-long vault approximately $700,000 underbacked, and a May 2026 third-party exploit (Stake DAO) that forced the sunsetting of an associated Arbitrum LlamaLend market. The protocol's core contracts have not been directly compromised by a code-level hack, but recurring bad-debt events, oracle design flaws in permissionlessly created markets, and governance concentration risks have drawn sustained scrutiny including a flag from on-chain investigator ZachXBT.
avoid.net/axiom-exchange-employee-insider-trading-scandal→30/100[WARNING]Axiom Exchange is a Y Combinator-backed, non-custodial Solana trading terminal founded in 2024 that generated over $390 million in revenue within roughly a year of launch. On February 26, 2026, blockchain investigator ZachXBT published findings alleging that at least one senior employee, Broox Bauer, systematically abused internal customer support tools to access private wallet data and share it with outside parties for front-running purposes, a scheme alleged to have operated for approximately ten months. The company issued a statement expressing disappointment, revoked access to the affected tools, and pledged an internal investigation, but no formal regulatory or legal charges had been announced as of the time of this report.
avoid.net/pancakebunny→18/100[CRITICAL]PancakeBunny was a Binance Smart Chain yield aggregator and optimizer built by a team known as Mound, launched in December 2020. The protocol suffered two major flash loan exploits in 2021: a May 20, 2021 attack that caused the BUNNY token to crash over 95% and wiped out approximately $200 million in market capitalization, and a July 16, 2021 attack on its Polygon fork PolyBunny that resulted in $2.4 million in losses. Both exploits stemmed from oracle price manipulation vulnerabilities in the minting reward logic, and the protocol has never recovered to its pre-exploit state.
avoid.net/beanstalk-farms→28/100[WARNING]Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.
avoid.net/ranger-finance→22/100[CRITICAL]Ranger Finance was a Solana-based perpetual contract aggregator that raised $1.9M in seed funding in January 2025 and launched its RNGR token in January 2026. Within two months of token launch, community governance voted to liquidate the project treasury following allegations that the team made materially misleading claims about trading volume and revenue during its ICO. The project formally shut down in May 2026 after the treasury liquidation and approximately $900,000 in exposure from the DPRK-linked Drift Protocol exploit left operations unsustainable, with employees and vendors not fully compensated.
avoid.net/paid-network→12/100[CRITICAL]PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.
avoid.net/bunny→10/100[CRITICAL]PancakeBunny (Bunny Finance) was a Binance Smart Chain yield-optimizer developed by the anonymous team MOUND (Mound Inc.), which received a $1.6 million seed round led by Binance Labs in April 2021. The protocol suffered three separate exploits across 2021–2022 totaling over $127 million in losses, including a $45 million flash loan attack in May 2021, a $2.4 million polyBUNNY exploit on Polygon in July 2021, and an $80 million hack of its affiliated lending protocol Qubit Finance in January 2022. The BUNNY token has lost more than 99% of its all-time high value, the protocol transitioned to a DAO structure in early 2022, and no stolen funds from any exploit were publicly confirmed as recovered.
avoid.net/burgerswap→22/100[CRITICAL]BurgerSwap is a decentralized exchange (DEX) and automated market maker (AMM) protocol launched in September 2020 on Binance Smart Chain (BSC), built around the native BURGER governance token. On May 28, 2021, the protocol suffered a flash loan and reentrancy exploit that drained approximately $7.2 million in user funds across 14 transactions. Uniswap founder Hayden Adams publicly noted that a critical line of code enforcing the constant-product formula had been deliberately removed from BurgerSwap's fork of Uniswap v2, raising allegations of an intentional vulnerability or insider involvement by the anonymous development team.
avoid.net/aperocket→22/100[CRITICAL]ApeRocket is a DeFi yield farming aggregator and optimizer originally deployed on Binance Smart Chain (BSC) and Polygon in 2021. The protocol suffered two simultaneous flash loan exploits on July 14, 2021, resulting in combined losses of approximately $1.26 million and a 63% collapse in its native SPACE token price. The project attempted a V2 relaunch with improved security, but the SPACE token currently shows zero trading volume and effectively zero market capitalization, indicating the protocol is inactive.
avoid.net/bondly→22/100[CRITICAL]Bondly Finance is a DeFi and NFT protocol launched in September 2020 that suffered a major exploit on July 14-15, 2021, in which 373 million BONDLY tokens were minted via owner-level credentials and sold into liquidity pools, causing an 82% token price collapse and approximately $5.9-7.5 million in losses. The exploit originated from the protocol owner's address, prompting blockchain security firm PeckShield to allege a potential rug pull, though the team attributed it to compromised credentials belonging to CEO Brandon Smith. Following acquisition by Animoca Brands in September 2021 and a rebrand to Forj in May 2022, the project has undergone significant leadership changes; the original founder departed under a cloud of unresolved questions about the exploit's true origin.
avoid.net/qubit→10/100[CRITICAL]Qubit Finance was a Binance Smart Chain lending and cross-chain bridge protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logic error in the QBridge Ethereum-BSC bridge to mint approximately 77,162 qXETH tokens without depositing any ETH, then drained roughly $80 million in protocol assets; no funds were ever recovered and the attacker was never identified.
avoid.net/sudorare→2/100[CRITICAL]SudoRare was an anonymous NFT automated market maker (AMM) protocol launched on August 23, 2022, presented as a fork of SudoSwap and LooksRare. Approximately six hours after launch, the anonymous development team executed a premeditated rugpull via a backdoored smart contract, draining approximately 519 ETH (valued at $815,000–$852,000) from user deposits before deleting all online presence. Blockchain security firms PeckShield and CertiK traced a funding wallet to Kraken, but no public arrests or legal proceedings have been reported.
avoid.net/gmx-v1-perps→28/100[WARNING]GMX V1 was a decentralized perpetual exchange on Arbitrum and Avalanche that operated from September 2021 until July 2025, when a reentrancy exploit drained approximately $42 million from its GLP liquidity pool. The protocol has since disabled all V1 trading and GLP minting; it is no longer an active product, with users directed to GMX V2, which was unaffected by the exploit.
avoid.net/themis-protocol→32/100[WARNING]Themis Protocol is a DeFi lending and borrowing platform deployed on Arbitrum that allows users to collateralize Uniswap v3 LP positions and Balancer LP tokens to borrow stablecoins and blue-chip assets. On June 27, 2023, approximately eleven days after its beta launch, the protocol suffered a flash loan oracle manipulation exploit resulting in approximately $370,000 in losses. The attacker laundered the stolen funds via Tornado Cash, the protocol was suspended indefinitely, and TVL effectively dropped to near zero following the incident.
avoid.net/stakecom→28/100[WARNING]Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.
avoid.net/radiant-v2→10/100[CRITICAL]Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that suffered two significant security incidents in 2024: a $4.5 million flash loan exploit in January 2024 and a far more devastating $50 million multisig compromise in October 2024. The October hack, attributed by Mandiant with high confidence to North Korean state-sponsored group UNC4736 (Citrine Sleet / AppleJeus), involved a months-long social engineering campaign, macOS malware deployment on developer devices, and manipulation of hardware wallet signing interfaces to drain funds across BNB Chain and Arbitrum.
avoid.net/fixedfloat→10/100[CRITICAL]FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.
avoid.net/curio→10/100[CRITICAL]Curio (CurioDAO) is a multi-chain real-world asset (RWA) DeFi protocol that suffered a critical smart contract exploit on March 23, 2024, resulting in approximately $16 million in losses after an attacker exploited a voting-power privilege escalation vulnerability to mint approximately 1 billion unauthorized CGT governance tokens. The protocol had no known third-party security audits prior to the exploit and relied on internal reviews. Curio announced a recovery plan including a new CGT 2.0 token and a phased compensation program, though independent verification of full compensation delivery remains limited.
avoid.net/grand-base→5/100[CRITICAL]Grand Base was a decentralized real-world asset (RWA) synthetic trading protocol launched on Coinbase's Base layer-2 blockchain in early 2024. On April 15, 2024, the protocol suffered a critical security incident in which its deployer wallet was compromised, allowing an attacker to mint approximately 32.5 million unauthorized GB tokens and drain roughly $2 million in liquidity. The GB token subsequently lost over 99% of its value; no verified recovery or compensation plan has been confirmed, and the project's long-term operational status remains uncertain.
avoid.net/leadblocks-morpho-blue-market→38/100[WARNING]LeadBlock's Morpho Blue Market refers to a permissionless lending market and associated MetaMorpho vault curated by LeadBlock Partners on the Morpho Blue protocol. On October 13, 2024, an oracle misconfiguration in the LeadBlock-curated PAXG/USDC market enabled an opportunistic user to borrow approximately $230,000 in USDC against only $350 of PAXG collateral, exploiting an overvalued asset price of $2.6 trillion per unit of gold. The incident was attributed to an incorrectly configured SCALE_FACTOR by LeadBlock's oracle provider and raised questions about the adequacy of pre-launch testing and risk curation practices.
avoid.net/impermax-v3→32/100[WARNING]Impermax V3 is the third major iteration of Impermax Finance, a DeFi leveraged yield-farming and lending protocol that allows liquidity providers to use Uniswap V3 LP tokens as collateral. The protocol suffered two separate critical exploits in 2025 — a ~$300,000 flash-loan collateral valuation attack in April and a ~$380,000 liquidation logic exploit in November — both on the Base chain, resulting in cumulative losses exceeding $680,000 and leaving lenders with unresolved bad debt. These incidents follow a 2022 private key compromise affecting the IMX token, representing a recurring pattern of security failures across the protocol's history.
avoid.net/foom-cash→28/100[WARNING]FOOM Cash (foom.cash) is a pseudonymous, privacy-focused decentralized lottery protocol built on Ethereum and Base, marketed as an 'upgraded Tornado Cash' using zk-SNARKs cryptography. On February 26, 2026, the protocol suffered a $2.26 million exploit caused by a critical deployment error in its Groth16 trusted setup — a flaw publicly known from an identical exploit on Veil Cash days earlier that the team failed to patch. The team had been silent for approximately three months prior to the attack and was subsequently flagged as a notable risk by AVOID.NET due to compounding concerns: anonymous founders, serious operational negligence, misleading post-incident communications, and unverifiable audit claims.
avoid.net/socket-security-malicious-browser-extension-campaign-august-2026→2/100[CRITICAL]On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.
avoid.net/term-finance-governance-exploit-august-2026→10/100[CRITICAL]On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.
avoid.net/defi-governance-attack-wave-2026→0/100[CRITICAL]Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.
avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-2026→38/100[WARNING]On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.
avoid.net/h1-2026-crypto-hack-landscape-ai-agent-attack-vector-emerges→0/100[CRITICAL]The first half of 2026 established a new all-time record for cryptocurrency exploit frequency, with 207–212 verified incidents (varying by methodology) resulting in $972 million to $1.32 billion in losses depending on the reporting firm. North Korea's Lazarus Group (TraderTraitor subunit) was responsible for approximately 55–66% of total losses through two concentrated attacks in April 2026, while AI-powered autonomous agents emerged as a distinct and novel attack surface for the first time in widely documented crypto security history.
avoid.net/june-2026-cross-chain-bridge-exploit-127m-three-protocols→10/100[CRITICAL]An alleged coordinated cross-chain bridge exploit on June 14, 2026 is described as draining $127 million from three DeFi protocols — identified only as BridgeLink, CrossFlow, and Relay Protocol — across Ethereum, Arbitrum, and Polygon in under 12 minutes. This specific incident, including the protocol names, the $127M figure, and the 03:42 UTC timestamp, cannot be independently verified through any Tier 1 or Tier 2 source as of June 30, 2026; the sole primary source is a blog post by Nadcab Labs, an Indian blockchain development services company with a commercial interest in publishing DeFi security content. While a severe pattern of verified cross-chain bridge exploits across 2026 provides real context, the specific claims in this investigation request should be treated as unverified until corroborated by credible on-chain analysis or major news coverage.