Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
Cashio was a Solana-based algorithmic stablecoin protocol that issued the CASH token, collateralized by Saber LP tokens. On March 23, 2022, an attacker exploited a critical missing validation flaw in the smart contract to mint approximately 2 billion CASH tokens backed by worthless fake collateral, draining roughly $52 million in real assets and permanently destroying the token's USD peg. The protocol was unaudited, never compensated victims in full, and its pseudonymous creator later admitted the code was rushed and insecure.
avoid.net/elephant-money→10/100[CRITICAL]Elephant Money is a Binance Smart Chain DeFi protocol offering the ELEPHANT reward token and TRUNK stablecoin that suffered a $22.2 million flash loan price-manipulation exploit in April 2022, with stolen funds laundered through Tornado Cash. Independent analysts have additionally alleged that the protocol's yield mechanics constitute a structurally unsustainable Ponzi scheme dependent on continuous new capital inflows.
avoid.net/deus-finance→10/100[CRITICAL]DEUS Finance is a decentralized derivatives and synthetic asset protocol built primarily on Fantom, co-founded by Lafayette Tabor and Mohammad Abrishami. The protocol suffered three separate security exploits between March 2022 and May 2023, resulting in combined losses exceeding $22 million across flash loan oracle attacks and a smart contract implementation flaw, with stolen funds routed through Tornado Cash in the 2022 incidents. Repeated security failures across distinct vulnerability classes raise severe concerns about the protocol's security practices and long-term viability.
avoid.net/fortress-loans→18/100[CRITICAL]Fortress Loans (fortress.loans) was an algorithmic money market and lending protocol on BNB Chain (Binance Smart Chain), launched in April 2021 by the JetFuel Finance team. On May 8, 2022, the protocol was drained of all funds — approximately $2.98 million — through a combined governance manipulation and oracle price manipulation attack. The protocol has been effectively inactive since, with DefiLlama recording a TVL of approximately $1,168 as of 2024, and the FTS governance token has lost effectively all of its value.
avoid.net/blizz-finance→10/100[CRITICAL]Blizz Finance was a decentralized lending protocol on Avalanche, forked from Aave v2, that launched in November 2021 and was rendered insolvent in May 2022 when the Terra LUNA collapse triggered a Chainlink oracle circuit breaker that froze the LUNA price at $0.10 while the token's actual market price fell to near zero. Attackers exploited the stale price feed to borrow approximately $8.3 million in protocol assets using nearly worthless LUNA as collateral, draining the protocol entirely. The team announced permanent shutdown shortly after, recovering and distributing only approximately $1.5 million to affected users.
avoid.net/wintermute→38/100[WARNING]Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.
avoid.net/gym-network→12/100[CRITICAL]Gym Network (GYMNET) is a Binance Smart Chain-based DeFi protocol launched in March 2022 that operates an affiliate investment scheme with hallmarks of a Ponzi structure, requiring continuous recruitment to sustain promised returns of up to 250% annually. The project was founded by Claudio Catrini, who has prior involvement in the OneCoin fraud, and suffered a $2.1 million smart contract exploit in June 2022. The GYMNET token has declined approximately 99.8% from its all-time high of $1.90 to under $0.004 as of 2026.
avoid.net/harmony-bridge→10/100[CRITICAL]Harmony's Horizon Bridge is a cross-chain bridge connecting the Harmony (ONE) blockchain to Ethereum and Binance Smart Chain, launched in October 2020. In June 2022, it was exploited for approximately $100 million by the Lazarus Group, a North Korea-affiliated state-sponsored hacking collective, through compromise of a 2-of-5 multisig scheme controlling bridge funds. The FBI formally confirmed Lazarus Group attribution in January 2023; as of 2025, full victim restitution has not been achieved.
avoid.net/crema-finance→28/100[WARNING]Crema Finance is a Solana-based concentrated liquidity market maker (CLMM) DEX protocol that launched in January 2022. On July 2, 2022, the protocol suffered a critical exploit in which an attacker used a fake tick account and flash loans to drain approximately $8.78 million from multiple liquidity pools. Following on-chain negotiations, the attacker returned roughly $7.1 million and retained approximately $1.68 million as an agreed white-hat bounty; Crema subsequently issued a CRM token compensation plan for affected users and submitted a revised codebase for re-audit by SlowMist before reopening.
avoid.net/audius→58/100[CAUTIONARY]Audius is a decentralized music streaming protocol and its native AUDIO token, launched in 2020 on Ethereum and subsequently migrated to Solana. On July 23, 2022, an attacker exploited a critical re-initialization vulnerability in Audius governance smart contracts, draining 18.56 million AUDIO tokens (valued at approximately $6 million at the time) from the community treasury before swapping them for approximately $1.08 million in ETH via Uniswap and routing funds through Tornado Cash. The platform has continued to operate since the exploit, deploying patched contracts and expanding user and artist partnerships, but the AUDIO token has declined approximately 99.6% from its all-time high and the exploit raised serious questions about audit quality.
avoid.net/slope-wallet→28/100[WARNING]Slope Wallet (Slope Finance) was a Solana-based mobile cryptocurrency wallet that suffered a catastrophic security breach on August 2, 2022, in which over 9,200 wallets were drained of approximately $4–8 million in assets due to the app transmitting users' unencrypted seed phrases to a third-party telemetry service (Sentry). The root cause was a severe security misconfiguration by Slope Finance, in which the mobile application logged plaintext private key material without proper scrubbing. No formal victim compensation was established, the team declined to publicly accept responsibility, and founder Leal Cheung subsequently launched a new project (zkME) without resolution for affected users.
avoid.net/dragoma→3/100[CRITICAL]Dragoma was a move-to-earn GameFi project built on the Polygon network whose native DMA token collapsed 99.8% within hours of its MEXC exchange listing on August 8, 2022, in what blockchain security firm PeckShield identified as a rug pull. Approximately $3.5 million in investor funds were allegedly drained by the development team and deposited into centralized exchanges. The project's website and all social media channels were subsequently deleted, and no known recovery or law enforcement action against the responsible parties has been publicly confirmed.
avoid.net/sudorare→2/100[CRITICAL]SudoRare was an anonymous NFT automated market maker (AMM) protocol launched on August 23, 2022, presented as a fork of SudoSwap and LooksRare. Approximately six hours after launch, the anonymous development team executed a premeditated rugpull via a backdoored smart contract, draining approximately 519 ETH (valued at $815,000–$852,000) from user deposits before deleting all online presence. Blockchain security firms PeckShield and CertiK traced a funding wallet to Kraken, but no public arrests or legal proceedings have been reported.
avoid.net/gmx-v1-perps→28/100[WARNING]GMX V1 was a decentralized perpetual exchange on Arbitrum and Avalanche that operated from September 2021 until July 2025, when a reentrancy exploit drained approximately $42 million from its GLP liquidity pool. The protocol has since disabled all V1 trading and GLP minting; it is no longer an active product, with users directed to GMX V2, which was unaffected by the exploit.
avoid.net/transit-swap→18/100[CRITICAL]Transit Swap is a cross-chain DEX aggregator incubated by TokenPocket, supporting swaps across Ethereum, BNB Chain, Polygon, Tron, Solana, and other networks. On October 1–2, 2022, an attacker exploited an input validation vulnerability in the platform's swap contract, draining approximately $21–28.9 million in user funds across Ethereum and BNB Chain. The attacker subsequently returned roughly 70% of stolen assets after security firms identified the exploiter's IP address and email, though an estimated 30% of funds — including amounts routed through Tornado Cash — remain unrecovered.
avoid.net/moola-market→28/100[WARNING]Moola Market is a decentralized lending protocol built on the Celo blockchain, founded in 2020 by Patrick Baron and backed by Polychain Capital. In October 2022, the protocol suffered a price manipulation exploit draining approximately $9.1 million, making it one of the largest DeFi incidents on Celo; over 93% of funds were returned by the attacker within hours in exchange for a roughly $500,000 bounty. The protocol subsequently relaunched with reduced collateral thresholds, but its TVL and MOO token value have declined sharply since the incident.
avoid.net/team-finance→28/100[WARNING]Team Finance is a DeFi token-locking and vesting platform operated by TrustSwap Inc. that suffered a critical $14.5 million exploit on October 27, 2022, when an attacker abused a validation flaw in its Uniswap V2-to-V3 migration function. The attacker ultimately returned approximately $7 million, retaining roughly 10% as a self-declared bug bounty; Team Finance subsequently switched auditors to CertiK and reported full user reimbursement by June 2023.
avoid.net/deribit→72/100[CAUTIONARY]Deribit is a crypto options and futures exchange founded in 2016 in the Netherlands by John and Marius Jansen, historically operated through a Panama-registered entity and now licensed under Dubai's VARA framework as Deribit FZE. The exchange suffered a $28 million hot wallet compromise on November 1, 2022, covering the loss entirely from its own balance sheet. Coinbase completed the acquisition of Deribit for approximately $2.9 billion on August 14, 2025, making it a subsidiary of a publicly traded, NASDAQ-listed U.S. company.
avoid.net/save→38/100[WARNING]Save (formerly Solend) is a Solana-based algorithmic lending and borrowing protocol that has operated since 2021. The protocol has been flagged by ZachXBT and carries a history of two significant incidents: a controversial governance vote in June 2022 that briefly granted the team emergency powers to seize a user's wallet, and a $1.26 million oracle manipulation exploit in November 2022. The protocol rebranded from Solend to Save in late 2024 and continues to operate with approximately $74 million in total value locked as of mid-2026.
avoid.net/pando-rings→18/100[CRITICAL]Pando Rings is an algorithmic lending and borrowing protocol built on the Mixin Network by Fox One, modeled on Compound Finance. On November 5, 2022, an attacker exploited a price oracle vulnerability tied to the sBTC-WBTC LP token on 4swap to drain approximately $21.9 million in ETH, BTC, and EOS from the protocol; an additional ~$50 million remained frozen in the attacker's wallets. The protocol subsequently suffered further losses in the September 2023 Mixin Network infrastructure breach, and as of late 2023 remained in a limited operational state with interest accrual and liquidations suspended.
avoid.net/ankr→58/100[CAUTIONARY]Ankr is a Web3 infrastructure and liquid staking protocol founded in 2017, providing RPC endpoints for over 75 blockchains and BNB Chain-based liquid staking products. In December 2022, a former employee executed a supply chain attack that compromised Ankr's private deployer key, enabling unlimited minting of aBNBc tokens and resulting in approximately $5 million in direct losses, with cascading secondary losses of roughly $19 million through Helio Protocol's HAY stablecoin depeg. Ankr subsequently compensated affected users, implemented multi-signature controls, and continues to operate, though questions persist over the completeness of user reimbursement.
avoid.net/ratio-finance→22/100[CRITICAL]Ratio Finance is a defunct Solana-based collateralized debt position (CDP) protocol that allowed users to mint the USDr stablecoin against yield-bearing LP token collateral. The protocol raised $8.4 million across multiple rounds from investors including Alameda Research, Solana Ventures, and CMS Holdings, then launched its RATIO governance token in March 2022 at an all-time high near $2.24. The project suffered a private key compromise on or around December 3, 2022, after which the protocol's TVL fell to zero, the RATIO token lost over 99.9% of its value, and all social media activity ceased by December 2023.
avoid.net/rubic→28/100[WARNING]Rubic is a cross-chain DEX aggregator founded in 2020 by Vladimir Tikhomirov and Alexandra Korneva, supporting swaps across 90+ blockchains. The protocol suffered two significant security incidents within two months in late 2022: a private key compromise in November that drained approximately $1.2 million in RBC tokens, followed by a smart contract exploit on December 25, 2022 that stole roughly $1.4 million in user USDC. Both events caused severe token price collapses, though the platform subsequently implemented new security architecture and remained operational into 2025.
avoid.net/launchzone→18/100[CRITICAL]LaunchZone (LZ) was a Binance Smart Chain-based DeFi launchpad and IDO platform originally launched as BSCex in December 2020, later rebranded in March 2021. On February 27, 2023, the protocol suffered a critical smart contract exploit in its Bscex SwapX contract, resulting in approximately $700,000 drained from its liquidity pool and a total of nearly $7.8 million in cumulative losses as additional vulnerable contracts were identified. The platform ceased operations on March 26, 2023, with over 75,000 user wallets remaining exposed weeks after the initial attack. ZachXBT has flagged this entity as a risk.
avoid.net/myalgo→12/100[CRITICAL]MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.
avoid.net/euler-v1→10/100[CRITICAL]Euler Finance V1 was a permissionless DeFi lending protocol on Ethereum that launched in December 2021 and was exploited for approximately $197 million on March 13, 2023, in what was the largest DeFi hack of that year. The attack exploited a missing health check in the donateToReserves function introduced in EIP-14, despite the codebase having undergone multiple external audits. In a highly unusual outcome, the pseudonymous attacker known as 'Jacob' returned all recoverable funds by April 3, 2023, with the total recovered value reaching approximately $240 million due to ETH price appreciation during the recovery period.
avoid.net/paraspace-lending-v1→28/100[WARNING]ParaSpace Lending V1 was an Ethereum-based cross-margin NFT and fungible token lending protocol launched in December 2022. In March 2023, a price manipulation exploit targeting the AutoCompoundApe contract nearly drained $5 million (2,909 ETH) from the protocol; blockchain security firm BlockSec intervened in a white-hat operation to recover the funds. In May 2023, a separate internal governance crisis erupted when over 19 team members accused CEO Yubo Ruan of misappropriating approximately 1,454.5 ETH (~$2.7M) from the recovered funds, allegations Ruan denied. The protocol subsequently rebranded through a merger with Parallel Finance, forming ParaX in August 2023, while the original V1 contracts were wound down and remain at minimal TVL as of 2026.
avoid.net/sentiment→32/100[WARNING]Sentiment is an undercollateralized DeFi lending protocol originally deployed on Arbitrum, later migrating activity to HyperLiquid L1. On April 4, 2023, the protocol suffered a read-only reentrancy exploit resulting in approximately $1 million in losses, of which 90% was returned by the attacker following a negotiated $95,000 bounty. ZachXBT has flagged the entity for elevated risk; the protocol remains operational with a low TVL of roughly $518,000 as of 2025.
avoid.net/sushiswap→52/100[CAUTIONARY]SushiSwap is a decentralized exchange (DEX) and DeFi protocol launched in August 2020 as a fork of Uniswap, offering an automated market maker (AMM), governance token (SUSHI), and multi-chain liquidity pools. The protocol has endured a series of serious controversies spanning its entire history: a founding exit-scam attempt by anonymous creator Chef Nomi, early operational control handed to convicted fraudster Sam Bankman-Fried, an SEC subpoena issued to the protocol and its CEO in 2023, a $3.3 million smart contract exploit the same year, allegations that North Korean IT workers were embedded in its developer team, disputed DAO treasury centralization in 2024, and a governance process in late 2025 where a single wallet controlled 99.9% of a vote. TVL has declined approximately 98.7% from its 2022 peak of over $8 billion to roughly $100 million as of late 2025.
avoid.net/bitrue→18/100[CRITICAL]Bitrue is a Singapore-incorporated centralized cryptocurrency exchange founded in 2018 that suffered a confirmed $23 million hot wallet exploit in April 2023, with stolen funds subsequently laundered through Tornado Cash as recently as June 2025. The exchange holds no license from Singapore's Monetary Authority (MAS) and relies on a VASP registration in Lithuania — a lower-tier regulatory framework — while accumulating a persistent record of user complaints alleging unjustified account freezes and asset seizures.
avoid.net/level-perps→28/100[WARNING]Level Finance (also marketed as Level Perps) is a decentralized perpetual derivatives exchange that launched on BNB Chain in Q4 2022 and later expanded to Arbitrum. In May 2023 the protocol suffered a $1.1 million exploit caused by a logic bug in its referral reward contract that was missed by two prior security audits. The protocol's LVL token has declined approximately 99.9% from its all-time high, and as of 2025-2026 the protocol shows near-zero TVL ($32K), zero fees, and zero revenue, indicating effective dormancy.
avoid.net/jimbos-protocol→18/100[CRITICAL]Jimbos Protocol was an Arbitrum-based DeFi liquidity protocol designed to provide a semi-stable floor price for its native JIMBO token. On May 28, 2023, just three days after launching its V2, the protocol was exploited via a flash loan attack that drained approximately 4,090 ETH (~$7.5 million) by exploiting a lack of slippage control in the JimboController contract. The attacker rejected a $800,000 bounty offer, laundered the full amount through Tornado Cash, and remains unidentified; no funds have been recovered.
avoid.net/hector-lending→8/100[CRITICAL]Hector Lending is a defunct DeFi lending protocol built on the Fantom blockchain and operated by Hector Network (also known as Hector DAO). It was one of several products in an ecosystem whose treasury declined from approximately $110 million to near zero through a combination of alleged team mismanagement, three separate security incidents, and a court-ordered receivership. The broader Hector Network entered BVI receivership in February 2024 and subsequently obtained US Chapter 15 bankruptcy recognition — the first DAO ever to do so — in July 2024.
avoid.net/atlantis-loans→12/100[CRITICAL]Atlantis Loans was a decentralized lending and borrowing protocol built on BNB Chain (BSC) that was abandoned by its development team in April 2023 due to financial distress. Despite the abandonment, active smart contracts and unrevoked user approvals remained on-chain, which an attacker exploited in June 2023 through a malicious governance proposal, ultimately draining an estimated $2.5 million from users. The protocol is now defunct, its website is down, and its TVL has collapsed to near zero.
avoid.net/themis-protocol→32/100[WARNING]Themis Protocol is a DeFi lending and borrowing platform deployed on Arbitrum that allows users to collateralize Uniswap v3 LP positions and Balancer LP tokens to borrow stablecoins and blue-chip assets. On June 27, 2023, approximately eleven days after its beta launch, the protocol suffered a flash loan oracle manipulation exploit resulting in approximately $370,000 in losses. The attacker laundered the stolen funds via Tornado Cash, the protocol was suspended indefinitely, and TVL effectively dropped to near zero following the incident.
avoid.net/multichain→10/100[CRITICAL]Multichain (formerly AnySwap) was a cross-chain bridge protocol that collapsed in mid-2023 following the arrest of its CEO Zhaojun by Chinese police in May 2023, which resulted in the seizure of private keys controlling over $1.5 billion in user assets. On July 7, 2023, approximately $126–127 million was drained from Multichain bridge reserves in transfers widely attributed to Chinese authorities or insiders with access to the CEO's confiscated key material. The protocol formally ceased operations on July 14, 2023, leaving users with unrecoverable losses.
avoid.net/azukidao→28/100[WARNING]AzukiDAO is an informal decentralized autonomous organization formed in late June 2023 by a self-described group of 72 to 74 Azuki NFT holders in response to widespread community outrage over the Azuki Elementals NFT launch. Within days of its formation, AzukiDAO's BEAN governance token airdrop contract was exploited via a signature replay vulnerability, resulting in the theft of approximately 35 ETH ($68,000). On-chain investigator ZachXBT had previously flagged the Azuki project's founder Zagabond (Alex Xu) for alleged involvement in multiple prior abandoned NFT projects, and his findings were central to the community grievances that motivated AzukiDAO's creation.
avoid.net/eralend→28/100[WARNING]EraLend (formerly Nexon Finance) is a decentralized lending protocol on zkSync Era that suffered a $3.4 million read-only reentrancy exploit on July 25, 2023, draining its USDC pool due to a vulnerability in inherited SyncSwap oracle code. The protocol's pre-hack audit by PeckShield explicitly assumed a trusted price oracle, leaving the vulnerable oracle mechanism unexamined. EraLend relaunched post-hack with a fee-based compensation plan but has seen its TVL decline sharply to approximately $138,000 as of 2025-2026.
avoid.net/alphapo→10/100[CRITICAL]AlphaPo is a cryptocurrency payment processor incorporated in Panama and operating primarily in the online gambling sector, serving clients such as HypeDrop, Bovada, and Ignition. On July 22, 2023, attackers drained approximately $60 million in ETH, BTC, and TRX from its hot wallets via a private key compromise, disrupting withdrawals across multiple dependent platforms. On-chain investigator ZachXBT and subsequently the FBI attributed the attack to the DPRK-affiliated Lazarus Group (also designated TraderTraitor and APT38), placing the incident within a broader 2023 North Korean cryptocurrency theft campaign that totaled over $200 million.
avoid.net/leetswap→32/100[WARNING]LeetSwap was a decentralized exchange (DEX) launched on Coinbase's Base Layer 2 network in mid-2023 and briefly held the position of the network's largest DEX by trading volume and total value locked. On August 1, 2023, shortly after Base's mainnet opened to all users, an attacker exploited a publicly exposed smart contract function to drain approximately 342 ETH (~$630,000) from multiple liquidity pools. The protocol halted trading, partially recovered funds through white-hat rescue operations, and has since operated at a fraction of its pre-exploit TVL, with no public audit ever confirmed prior to the incident.
avoid.net/uwerx→12/100[CRITICAL]Uwerx (WERX) was a purported decentralized freelancing platform that conducted a multi-stage token presale in 2023 before suffering a flash loan exploit on August 2, 2023, one day after its Uniswap listing, resulting in the loss of approximately 176 ETH (~$324,000). Despite two prior smart contract audits by SolidProof and InterFi Network, neither audit identified the exploited vulnerability. The project subsequently relaunched on Polygon in October 2023 but has since been listed as abandoned on CoinSniper, with the token trading at effectively zero value and only six recorded holders as of early 2026.
avoid.net/bald→4/100[CRITICAL]BALD was a memecoin launched on Coinbase's Base Layer 2 network on July 29, 2023, allegedly named as a reference to Coinbase CEO Brian Armstrong's appearance. After attracting over $66 million in ETH to its liquidity pool through aggressive liquidity additions and a price surge of approximately 4,000,000% within 24 hours, the anonymous deployer removed approximately $25.6 million in liquidity on July 31, 2023, causing the token price to collapse by roughly 90%. On-chain investigators linked the deployer's wallet to addresses with documented interactions with Alameda Research, with Wintermute's head of research publicly identifying former Alameda co-CEO Sam Trabucco as the most likely suspect — though no conclusive proof of identity was ever established.
avoid.net/cypher→12/100[CRITICAL]Cypher Protocol was a Solana-based cross-margin decentralized exchange (DEX) and perpetuals trading platform that suffered a critical smart contract exploit in August 2023 resulting in approximately $1 million in losses. Following the exploit, an insider contributor known as 'Hoak' systematically drained over $314,000 from the community redemption fund established to reimburse hack victims, admitting publicly to gambling the funds away. The protocol appears effectively defunct, having failed to deliver meaningful restitution to users who received roughly 31 cents on the dollar from the original exploit fund before that fund itself was embezzled.
avoid.net/steadefi→35/100[WARNING]Steadefi is a decentralized leveraged yield farming protocol operating on Arbitrum and Avalanche. On August 7, 2023, an attacker exploited a compromised deployer private key to drain approximately $1.14 million from the protocol's lending vaults across both chains. The protocol subsequently relaunched with enhanced security measures and issued a token-based compensation plan for affected users, though roughly 70% of stolen funds were never recovered.
avoid.net/rocketswap-base→22/100[CRITICAL]RocketSwap is a decentralized exchange (DEX) launched on the Coinbase Base Layer 2 network in mid-2023 that suffered a $865,000 private key compromise exploit just days after Base's public launch, making it one of the first major exploits on the network. The attack, confirmed by security firms PeckShield and Certik as a private key compromise, was compounded by a separate $69,000 social engineering loss one week prior, and the hacker subsequently laundered stolen funds through Tornado Cash, Binance, OKX, and a self-created memecoin called LoveRCKT. The project has been flagged by ZachXBT and community analysts, with some alleging that pre-exploit proxy contract modifications and the team's decision to silence communications point to possible insider involvement, though this has not been conclusively proven.
avoid.net/exactly→32/100[WARNING]Exactly Protocol is a decentralized, non-custodial fixed-rate and variable-rate lending protocol deployed on the Optimism Layer 2 network. On August 18, 2023, the protocol suffered a critical exploit resulting in approximately $7.3–$12 million in ETH stolen from 117 user accounts due to insufficient input validation in its DebtManager periphery contract. The protocol has since resumed operations, engaged law enforcement, offered a $700,000 bounty, and passed a governance proposal to compensate affected users with EXA tokens.
avoid.net/harbor-protocol→28/100[WARNING]Harbor Protocol is a decentralized collateralized-debt-position (CDP) protocol built on the Comdex chain (Cosmos SDK / CosmWasm) that enabled users to mint the Composite stablecoin (CMST) against whitelisted collateral assets. The protocol suffered two distinct security incidents in 2023 — an oracle-manipulation liquidation event in June and a direct vault drain exploit in August — after which its total value locked collapsed to effectively zero. As of 2025 the protocol appears inactive, with the HARBOR governance token near worthless and no meaningful community or development activity detected.
avoid.net/balancer-v2→32/100[WARNING]Balancer V2 is a decentralized automated market maker (AMM) protocol launched in 2021 on Ethereum and multiple chains that separates AMM logic from token custody via a central Vault architecture. The protocol has experienced at least four documented security incidents across its V1 and V2 deployments, including a November 2025 exploit that drained approximately $128 million and directly led to the dissolution of Balancer Labs, the corporate entity behind the protocol, announced in March 2026.
avoid.net/gmblcomputer→38/100[WARNING]GMBL.COMPUTER is an Arbitrum-based DeFi gambling protocol that launched in September 2023 and was exploited within hours of going live, losing approximately 471 ETH (~$770,000) due to an off-chain server signature vulnerability and a flaw in its referral system. The exploiter returned roughly half of the stolen funds (235 ETH) after the team issued a conditional bug bounty offer. The protocol operates with an anonymous team, no disclosed security audits, no regulatory licensing, and as of 2025 shows near-zero trading volume and minimal on-chain activity.
avoid.net/remitano→28/100[WARNING]Remitano is a peer-to-peer cryptocurrency exchange operated by Babylon Solutions Limited, incorporated in Seychelles and active since 2015. The platform suffered a confirmed hot wallet hack in September 2023 resulting in approximately $2.7 million in losses, with the Lazarus Group (North Korea-linked) alleged as a probable suspect. Regulatory authorities in Malaysia, the United Kingdom, and Seychelles have issued warnings or taken enforcement actions against Remitano for operating without authorization, and the operating entity Babylon Solutions Limited was dissolved and struck off as of January 1, 2023.
avoid.net/mixin-network→10/100[CRITICAL]Mixin Network is a Hong Kong-based layer-2 cross-chain payment protocol that suffered the largest single crypto hack of 2023 when attackers compromised its cloud service provider's database and drained approximately $200 million in ETH, BTC, and USDT. The network remains operational but has only partially compensated users, the majority of stolen funds remain unrecovered, and a dormant attacker wallet moved funds to Tornado Cash in February 2026.
avoid.net/htx→28/100[WARNING]HTX (formerly Huobi Global) is one of the world's largest cryptocurrency exchanges, rebranded in September 2023 following the de facto acquisition of Huobi by interests linked to Justin Sun in late 2022. The exchange has suffered at least three significant security incidents totaling over $130 million in losses since September 2023, and in May 2026 was sanctioned by the UK government for alleged facilitation of Russian sanctions evasion — the first such crypto-exchange designation under the UK Russia sanctions framework. HTX also faces FCA legal proceedings over illegal financial promotions to UK consumers, has withdrawn its Hong Kong licensing applications twice, and has been publicly criticized for opaque reserve practices.
avoid.net/arena-socialfi→32/100[WARNING]Arena SocialFi (originally Stars Arena, rebranded to The Arena) is an Avalanche-based SocialFi platform launched September 2023. The platform suffered a critical reentrancy exploit on October 7, 2023, losing approximately $2.9 million in AVAX; it subsequently recovered ~90% of stolen funds via a bounty agreement. Following the hack, the original team dissolved and the platform was acquired and rebuilt under new leadership, launching the ARENA token in 2024 and raising $2 million in pre-seed funding.
avoid.net/maestro→47/100[WARNING]Maestro is a Telegram-based crypto trading bot developed by Gearlay Technologies Inc. (Canada) that enables sniping, copy-trading, and wallet management across 14 blockchains. On October 24, 2023, a critical access-control vulnerability in its MaestroRouter2 smart contract was exploited, draining approximately 280 ETH (~$500,000) from 106 user accounts; the team subsequently refunded all affected users with 610 ETH (~$1.1 million) sourced from its own revenue. The platform operates a partial-custody model in which user private keys are encrypted and stored on Maestro servers, representing a persistent systemic risk.
avoid.net/astrid-finance→38/100[WARNING]Astrid Finance is an Ethereum-based liquid restaking protocol built on EigenLayer, allowing users to deposit liquid staking tokens (stETH, rETH, cbETH) in exchange for liquid restaked tokens. On October 28, 2023, the protocol suffered a smart contract exploit due to a missing input validation check in its withdraw function, resulting in the theft of approximately $228,000 in assets. The attacker eventually returned 80% of stolen funds after an on-chain negotiation and legal threat by the team; all affected users received refunds, and the vulnerable contracts remain paused pending re-audit.
avoid.net/unibot→48/100[WARNING]Unibot is a Telegram-based cryptocurrency trading bot launched in May 2023 that enables users to trade on Uniswap and other decentralized exchanges directly within Telegram. On October 31, 2023, Unibot suffered a smart contract router exploit in which approximately $560,000–$640,000 in user tokens were stolen by an external attacker; the team subsequently reimbursed affected users. The platform operates with an anonymous founding team and involves inherent custodial risks because the bot manages user wallet interactions.
avoid.net/raft→22/100[CRITICAL]Raft is a decentralized Ethereum CDP lending protocol that issued the R stablecoin, collateralized by liquid staking tokens (stETH, rETH). On November 10, 2023, an attacker exploited a precision loss vulnerability to mint approximately $6.7 million in unbacked R tokens, draining 1,577 ETH from the protocol and causing the R stablecoin to depeg by up to 50%. Due to a coding error the attacker burned 1,570 of the stolen ETH to an inaccessible burn address, effectively losing money on the attack; the protocol subsequently implemented a partial recovery plan offering approximately 42% restitution to affected users and announced plans to phase out the current version.
avoid.net/kronos-research→28/100[WARNING]Kronos Research is a Taipei-based cryptocurrency quantitative trading firm and market maker founded in 2018 by Mark Pimentel and Jack Tan. The firm experienced two serious security incidents within months of each other in 2023: an insider sabotage case in which two disgruntled engineers tampered with trading code causing $1.4 million in losses, and an external hack in November 2023 where compromised API keys led to the theft of approximately $25–26 million. The November hack cascaded onto WOO X, an exchange Kronos incubated and served as primary liquidity provider, causing a temporary trading halt and liquidations for 227 users.
avoid.net/huobi→28/100[WARNING]Huobi, rebranded to HTX in September 2023, is a major centralized cryptocurrency exchange founded in 2013 that came under the de facto control of Tron founder Justin Sun in late 2022. The exchange has suffered three significant security incidents since September 2023, faces extensive regulatory non-compliance across multiple jurisdictions, and its proof-of-reserves methodology has been subject to credible allegations of double-counting and asset manipulation by investigative outlets.
avoid.net/okx-dex→18/100[CRITICAL]OKX DEX is the decentralized exchange aggregator operated by OKX (Aux Cayes FinTech Co. Ltd.), one of the world's largest centralized crypto exchanges. In December 2023, the DEX suffered a ~$2.7 million exploit caused by a suspected private key leak and a centralized proxy upgrade mechanism with no multi-signature protection. The broader OKX entity has faced severe regulatory sanctions including a $504 million U.S. DOJ settlement in February 2025 for operating an unlicensed money-transmitting business and facilitating over $5 billion in suspicious transactions, a €1.1 million Malta AML fine, and repeated scrutiny over its DEX aggregator being used by North Korea's Lazarus Group to launder stolen funds from the $1.5 billion Bybit hack in early 2025.
avoid.net/locus-finance→22/100[CRITICAL]Locus Finance is a DeFi yield-vault protocol launched in July 2023 by Iakov Levin, the founder of the defunct custodial crypto platform Midas Investments, which collapsed in December 2022 with a reported $63.3 million deficit. On December 30, 2023, Locus suffered a $320,964 exploit due to a developer private key leak during a CTO transition. The LOCUS token has declined over 99% from its all-time high, the protocol's TVL is near zero, and Levin is subject to regulatory enforcement actions in California and Wisconsin related to his prior venture.
avoid.net/orbit-bridge→10/100[CRITICAL]Orbit Bridge is a cross-chain interoperability protocol developed by South Korean blockchain firm Ozys that suffered one of the largest bridge exploits in crypto history on December 31, 2023, losing approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI. The attacker allegedly compromised seven of ten multisig signatories after a former chief information security officer allegedly weakened the company firewall before departing, and blockchain analysts have linked the attack's patterns to North Korea's Lazarus Group, though no formal attribution has been confirmed by authorities. As of 2025, the majority of stolen funds remain unrecovered, with the attacker having laundered over 17,000 ETH through Tornado Cash.
avoid.net/wise-lending-v1→22/100[CRITICAL]Wise Lending V1 is the first version of the Wise Lending decentralized lending and yield-aggregation protocol deployed on Ethereum, built from scratch by WiseSoft LLC and founded by Peter Girr. The V1 deployment suffered two confirmed on-chain exploits within approximately three months, losing an estimated $700,000+ in total user funds across both incidents, with no publicly documented recovery or compensation plan. ZachXBT has flagged the entity, and post-exploit TVL collapsed effectively to zero.
avoid.net/bungee→42/100[WARNING]Bungee Exchange is a cross-chain bridge aggregator and liquidity routing protocol developed by Socket (formerly SocketDotTech), founded in 2021 by Vaibhav Chellani and Rishabh Khurana. On January 16, 2024, the underlying Socket infrastructure was exploited via an inadequately validated smart contract route, resulting in approximately $3.3 million stolen from roughly 700 wallets with infinite token approvals. The protocol recovered approximately $2.23 million of the stolen funds one week later and resumed operations; it remains active as of 2026.
avoid.net/concentric→18/100[CRITICAL]Concentric (Concentric.fi) was an automated liquidity management protocol built on Camelot v3 on the Arbitrum network, offering vault-based yield optimization for concentrated liquidity positions. On January 22, 2024, the protocol suffered a critical security breach when a team member's deployer wallet was compromised through a targeted social engineering attack, resulting in approximately $1.85 million in losses and a 57% crash in the CONE token price. The protocol was subsequently halted entirely, and blockchain forensics firm CertiK linked the exploiter's wallets to prior incidents targeting OKX, UnoRe, and LunaFi, suggesting a sophisticated and recurring threat actor.
avoid.net/fixedfloat→10/100[CRITICAL]FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.
avoid.net/blueberry→32/100[WARNING]Blueberry Protocol is an Ethereum-based decentralized leveraged yield farming and prime brokerage protocol developed by Composable Corp. In February 2024, the protocol suffered a significant exploit caused by an oracle misconfiguration that allowed a flash loan attacker to drain approximately 457.7 ETH (~$1.35M) from three lending markets; most funds were rescued by white hat MEV operator c0ffeebabe.eth but ~91 ETH (~$265,000) was permanently lost to validator payments. Despite completing multiple Sherlock and Hacken audits and raising $2.5M in a June 2024 Series A, the protocol's security track record and history of audit findings raise material concerns for prospective users.
avoid.net/shido→22/100[CRITICAL]Shido Network (SHIDO) is a Layer-1 proof-of-stake blockchain project founded in Sweden in 2021. On February 29, 2024, an attacker exploited the Ethereum-based SHIDO staking contract by transferring ownership to a new address and upgrading it with a hidden token-withdrawal function, draining over 4.3 billion tokens and causing the price to collapse 94% within 30 minutes. On-chain investigator ZachXBT linked the exploit to a serial hacker responsible for the OKX (December 2023) and Concentric Finance (January 2024) hacks, with the attack vector in each case being private key compromise via social engineering.
avoid.net/woofi-swap→28/100[WARNING]WOOFi Swap is a decentralized exchange (DEX) built by WOO Network, operating on 12+ blockchain networks including Arbitrum, Avalanche, and Optimism, and using a proprietary synthetic Proactive Market Maker (sPMM) algorithm. On March 5, 2024, the protocol suffered a critical oracle manipulation exploit on Arbitrum in which an attacker used flash loans to manipulate WOO token pricing to near zero, stealing approximately $8.75 million; funds were not recovered. The parent platform WOO X also suffered a separate $14 million phishing-linked breach in July 2025 attributed to North Korean state-sponsored threat actors, compounding the ecosystem's security record.
avoid.net/super-sushi-samurai→28/100[WARNING]Super Sushi Samurai (SSS) is a Telegram-based blockchain game launched on the Blast layer-2 network in March 2024. On March 21, 2024 — four days after launch — a critical infinite-mint vulnerability in the SSS token contract was exploited, draining approximately $4.6–4.8 million (1,310 ETH) from its liquidity pool and causing the token to lose over 99% of its value. The attacker claimed to be a white-hat actor, and most funds were returned minus a 5% bounty; however, approximately 40 ETH were separately stolen by a distinct black-hat actor and the failed audit by Verichains raises material security governance concerns.
avoid.net/prismalst→10/100[CRITICAL]Prisma Finance is a Liquity-forked, Ethereum-based DeFi protocol that allowed users to mint overcollateralized stablecoins (mkUSD and ULTRA) against liquid staking tokens (LSTs) such as wstETH, rETH, sfrxETH, and cbETH. On March 28, 2024, a critical vulnerability in the protocol's MigrateTroveZap helper contract was exploited for approximately $11.6 million, with a total loss across all attacker wallets of roughly $12.3 million; the primary exploiter sent the majority of stolen funds through Tornado Cash while claiming a 'whitehat rescue,' and as of 2026 the protocol's TVL has collapsed from a pre-exploit peak of approximately $220 million to under $300K.
avoid.net/lava→42/100[WARNING]Lava (lavadefi.io) is a decentralized, non-custodial multichain lending and borrowing protocol deployed on Arbitrum and Base, operating since March 2024. The protocol suffered two documented exploit incidents in 2024 totaling approximately $470,000 in losses, both rooted in protocol logic vulnerabilities and flash loan abuse. The platform was flagged by on-chain investigator ZachXBT, and separately the lava.xyz Bitcoin lending product drew significant backlash in late 2025 after quietly switching users from a self-custodial DLC-based model to a fully custodial setup without adequate disclosure.
avoid.net/pike-v1→22/100[CRITICAL]Pike V1 (also known as Pike Beta) was a cross-chain DeFi lending protocol built by Nuts Finance that suffered two smart contract exploits within four days in April 2024, resulting in approximately $1.98 million in user losses. A vulnerability identified by auditing partner OtterSec prior to launch was never remediated, and a subsequent botched patch introduced even more severe vulnerabilities. The project's October 2024 token generation event further damaged investor trust after the team launched the $P token with only $10,000 in initial liquidity despite having raised $6.45 million in a presale.
avoid.net/dmm-bitcoin→52/100[CAUTIONARY]DMM Bitcoin was a licensed Japanese cryptocurrency exchange operated by DMM Group (DMM.com) that launched in January 2018. In May 2024 it suffered the eighth-largest crypto theft in history when North Korean state-sponsored hackers attributed to the TraderTraitor subgroup of Lazarus Group stole 4,502.9 BTC (approximately $305–308 million USD) through a sophisticated supply-chain attack targeting Ginco, a third-party wallet management provider. Following the hack, Japan's Financial Services Agency issued a business improvement order, the exchange restricted operations, and in December 2024 announced full closure with all customer assets transferred to SBI VC Trade by March 2025.
avoid.net/velocore-v2→12/100[CRITICAL]Velocore V2 was a ve(3,3) decentralized exchange (DEX) deployed on the Linea and zkSync Era layer-2 blockchains. On June 2, 2024, the protocol suffered a critical smart contract exploit that drained approximately $6.8 million in ETH from its volatile liquidity pools. The attacker laundered stolen funds through Tornado Cash, no recovery was achieved, and the team subsequently announced a treasury liquidation rather than a protocol relaunch.
avoid.net/uwu-lend→10/100[CRITICAL]UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave V2, launched in September 2022 and operated by Michael Patryn (known pseudonymously as 0xSifu), a co-founder of the collapsed Canadian crypto exchange QuadrigaCX and a convicted felon. In June 2024, the protocol was exploited twice by the same attacker — first for approximately $19.3 million on June 10 and again for $3.7 million on June 13 — via oracle price manipulation using flash loans, bringing combined losses to approximately $23 million.
avoid.net/yolo-games→28/100[WARNING]YOLO Games is an on-chain gambling platform built on the Blast Layer 2 network, offering high-risk games such as YOLO, Moon or Doom, and Poke the Bear, with a native $YOLO token as its reward mechanism. In June 2024, an access control vulnerability in a third-party Liquidity Bootstrapping Pool (LBP) contract was exploited, resulting in the extraction of approximately $1.387 million, of which 90% was subsequently returned by the attacker acting as a whitehat. The $YOLO token has since collapsed approximately 99.6% from its all-time high and the protocol shows near-zero fee activity as of 2025-2026, suggesting severe user attrition or effective abandonment.
avoid.net/holograph→28/100[WARNING]Holograph is an omnichain tokenization protocol that enables cross-chain asset transfers, launched in 2022 by CXIP Labs with $6.5 million in seed funding. On June 13, 2024, a former technical contractor exploited admin-level access to the protocol's operator contract to mint 1 billion unauthorized HLG tokens worth approximately $14.4 million, crashing the token price by over 80%. Four suspects were subsequently arrested in Italy and extradited to France, where criminal proceedings are ongoing; approximately 80% of stolen tokens were reported recovered by law enforcement.
avoid.net/coinstats→35/100[WARNING]CoinStats is an Armenian-founded cryptocurrency portfolio tracking application with approximately 1.5 million users, founded in 2017 by Narek Gevorgyan. On June 22, 2024, the platform suffered a significant security breach in which 1,590 internally-hosted wallets were compromised and approximately $2.2 million in cryptocurrency was stolen, with attribution pointing to North Korea's Lazarus Group. The platform has since rebuilt its infrastructure and restored operations, but no confirmed compensation program for affected users has been publicly documented.
avoid.net/dough-finance→12/100[CRITICAL]Dough Finance was an Ethereum-based DeFi lending and margin-trading protocol co-founded by Chase Herro and Zachary Folkman. On July 12, 2024, the protocol was exploited via a flash loan attack that drained approximately $2.1–2.5 million in user funds due to unvalidated calldata in its ConnectorDeleverageParaswap smart contract. The protocol's website is shut down, the vast majority of the approximately 2,700 affected users have received no meaningful compensation, and the co-founders have since launched World Liberty Financial alongside Donald Trump, earning an alleged $65 million in revenues from that new venture.
avoid.net/minterest→22/100[CRITICAL]Minterest (formerly using the MNT token, later rebranded to MINTY) was a cross-chain DeFi lending and borrowing protocol founded by Josh Rogers and incorporated as Minterest Labs OÜ in Estonia. The protocol suffered a $1.4 million reentrancy exploit on July 14, 2024 — in a market that went live without a completed security audit — and subsequently announced the sunsetting of all operations in November 2025, explicitly stating that hack victims would receive no refund or token compensation as part of the wind-down.
avoid.net/lifi-finance→32/100[WARNING]LI.FI is a Berlin-based cross-chain bridge and DEX aggregation protocol founded in 2021 by Philipp Zentner and Max Klenk. The protocol has suffered two significant smart contract exploits — a $600,000 loss in March 2022 and an $11.6 million loss in July 2024 — both stemming from the same class of arbitrary-call vulnerability, prompting criticism from security researchers that lessons were not learned. Separately, blockchain investigator ZachXBT alleged in June 2025 that North Korean (DPRK) actors accounted for an estimated 15–25% of the protocol's volume during May 2025, using LI.FI to launder funds from the Bybit hack.
avoid.net/monoswap→18/100[CRITICAL]MonoSwap is a decentralized exchange (DEX) and launchpad built on the Blast L2 network that launched in late February 2024. On July 24, 2024, the protocol was compromised via a social engineering attack in which a developer was tricked into installing infostealer malware disguised as a video conferencing app, allowing attackers to drain approximately $1.3 million in staked liquidity. The stolen funds were subsequently laundered through Tornado Cash, and the protocol has remained largely inactive with negligible TVL since the incident.
avoid.net/terra-20→7/100[CRITICAL]Terra 2.0 (LUNA) is a replacement blockchain launched in May 2022 by Terraform Labs following the catastrophic collapse of the original Terra network and its algorithmic stablecoin TerraUSD (UST), which erased approximately $40–60 billion in market value in one week. The project's founder, Do Kwon, was arrested in March 2023, found liable for securities fraud in a U.S. civil trial in April 2024, pleaded guilty to wire fraud and conspiracy in August 2025, and was sentenced to 15 years in federal prison in December 2025. Terraform Labs itself filed for Chapter 11 bankruptcy in January 2024 and received court approval to wind down operations by September 2024, leaving Terra 2.0 as a severely diminished chain with minimal developer activity and an approximately 79% year-over-year decline in token value.
avoid.net/penpie→10/100[CRITICAL]Penpie is a yield-boosting DeFi protocol built on Pendle Finance by the Magpie DAO ecosystem, allowing users to earn boosted yields on Pendle liquidity pools without directly locking PENDLE tokens. On September 3, 2024, an attacker exploited a reentrancy vulnerability in Penpie's staking contract to drain approximately $27.3 million across Ethereum and Arbitrum, subsequently laundering all stolen funds through Tornado Cash and ignoring recovery appeals. The protocol filed reports with the FBI and Singapore Police but recovered no funds; a partial community compensation plan was proposed but not fully executed.
avoid.net/indodax→28/100[WARNING]Indodax (formerly Bitcoin Indonesia) is Indonesia's largest licensed cryptocurrency exchange, founded in 2014 by Oscar Darmawan and William Sutanto and serving over 9.6 million users. In September 2024, the exchange suffered a major security breach attributed to North Korea's Lazarus Group, resulting in approximately $22–25 million in losses across multiple blockchains. The exchange pledged full reimbursement to affected users, resumed operations within roughly 80 hours, and has since undergone a leadership restructuring.
avoid.net/wxeta→22/100[CRITICAL]WXETA (Wrapped Xeta) is an ERC-20 token deployed on Ethereum using a Diamond (EIP-2535) upgradeable proxy architecture, associated with XETA Capital / XETA Genesis — a DeFi yield platform incorporated in Belize that claimed up to 20% monthly returns via high-frequency trading algorithms. The underlying XETA ecosystem is named as a co-defendant in a federal civil RICO lawsuit filed in January 2025 alleging tens of millions of dollars in investor fraud, and ZachXBT has flagged the entity. The platform ceased onboarding new members at end of 2023 and converted member positions into non-liquid NFTs, leaving the withdrawal status of the bulk of investor funds disputed.
avoid.net/rivus-dao→8/100[CRITICAL]Rivus DAO was a Bittensor-focused liquid staking protocol on Ethereum that raised approximately $4.23 million in an April 2024 IDO before suffering a rugpull classified by DefiLlama as a Third-party Dev Backdoor Exploit on September 16, 2024. The incident effectively drained protocol TVL from its operational peak to under $2,500, and the RIVUS governance token lost more than 99.8% of its all-time high value. On-chain investigator ZachXBT has flagged this entity; the project attempted a relaunch in October 2024 but is currently listed as inactive with no trading activity.
avoid.net/banana-gun→32/100[WARNING]Banana Gun is a Telegram-based crypto trading bot launched in 2023 that allows users to snipe token launches on EVM chains and Solana. The project has experienced two major security incidents: a smart contract bug at token launch in September 2023 that caused the BANANA token to crash 99.7%, and a $3 million exploit in September 2024 in which attackers leveraged a Telegram message oracle vulnerability to drain 11 users. Separate, unresolved allegations from on-chain researchers claim the team arranged an exclusive order flow deal with block builder Titan that funneled millions of dollars in user bribe payments away from Ethereum validators.
avoid.net/bingx→32/100[WARNING]BingX is a Singapore-headquartered centralized cryptocurrency exchange founded in 2018 (originally as Bingbon), operating across 160+ countries with over 10 million reported users. In September 2024, the exchange suffered a confirmed hot wallet breach totaling approximately $52 million across at least seven blockchain networks, with on-chain forensics subsequently linking the attack to North Korea's Lazarus Group. The exchange pledged full user compensation from reserves and resumed withdrawals within days, but independently unverified regulatory claims and initial opacity around the breach raise ongoing due-diligence concerns.
avoid.net/unibtc→32/100[WARNING]uniBTC is a synthetic Bitcoin liquid restaking token issued by Bedrock protocol, enabling wBTC holders to earn BTC-native yield via the Babylon staking protocol while retaining liquidity. In September 2024, a critical minting vulnerability in multiple uniBTC vault smart contracts across eight blockchains was exploited for approximately $2 million after a third-party security firm disclosed the flaw hours before the attack. Post-incident forensics by Fuzzland, disclosed in June 2025, attributed the exploit to an insider threat — a former employee who embedded malware into Fuzzland's internal codebase and used privileged access to execute the attack; Bedrock has since integrated Chainlink Proof of Reserve and expanded to multiple new chains.
avoid.net/leadblocks-morpho-blue-market→38/100[WARNING]LeadBlock's Morpho Blue Market refers to a permissionless lending market and associated MetaMorpho vault curated by LeadBlock Partners on the Morpho Blue protocol. On October 13, 2024, an oracle misconfiguration in the LeadBlock-curated PAXG/USDC market enabled an opportunistic user to borrow approximately $230,000 in USDC against only $350 of PAXG collateral, exploiting an overvalued asset price of $2.6 trillion per unit of gold. The incident was attributed to an incorrectly configured SCALE_FACTOR by LeadBlock's oracle provider and raised questions about the adequacy of pre-launch testing and risk curation practices.
avoid.net/ambient→42/100[WARNING]Ambient Finance (formerly CrocSwap, operated by Crocodile Labs) is a decentralized exchange protocol that runs an entire DEX inside a single smart contract, combining concentrated and ambient liquidity on Ethereum and several L2 networks. On October 17, 2024, the protocol's frontend suffered a DNS hijacking attack deploying Inferno Drainer malware to drain wallets of users who interacted with the compromised site; the underlying smart contracts were unaffected and the team reimbursed all affected users in ETH. ZachXBT has flagged this entity.
avoid.net/1inch→62/100[CAUTIONARY]1inch is a decentralized exchange (DEX) aggregator and liquidity protocol founded in 2019 by Sergej Kunz and Anton Bukov, operating across Ethereum and multiple EVM-compatible chains. The platform has experienced a series of security incidents between late 2024 and mid-2025, including a front-end supply chain attack, a private key compromise, a $5 million Fusion v1 resolver exploit, and a separate $5.87 million attack on a partner resolver — raising questions about operational security and smart contract lifecycle management. Additional concerns include alleged connections between co-founder Anton Bukov and the Russian FSS Academy, governance centralization risks, and sustained token value erosion since the 2021 peak.
avoid.net/xt-exchange→22/100[CRITICAL]XT Exchange (XT.com), founded in 2018 and registered in Seychelles, is a centralized cryptocurrency exchange that has been flagged by multiple regulatory authorities — including the UK FCA, Dubai VARA, Thailand SEC, and the Seychelles FSA — for operating without proper licensing. The exchange suffered a $1.7 million hot wallet exploit in November 2024 due to a compromised private key, and has accumulated substantial user complaints alleging unjustified account freezing, asset seizure, and blocked withdrawals. Independent analysis has also raised concerns about inflated trading volumes and inadequate proof-of-reserves transparency.
avoid.net/btc24h→18/100[CRITICAL]BTC24H is an ERC-20 token and associated DAO platform launched on Polygon in late 2024, marketed as a mechanism for continuous Bitcoin distribution through high-yield daily payouts. The platform's Lock contract suffered a critical access-control vulnerability in December 2024 that allowed any caller to drain tokens, resulting in an estimated $85,700 loss. Multiple independent scam-detection services rate associated BTC24H web domains as high-risk or outright malicious, and the project's tokenomics — 5% daily returns for 30 days via a multi-level referral structure — exhibit structural characteristics consistent with unsustainable high-yield investment programs.
avoid.net/gempad→28/100[WARNING]GemPad is a multi-chain no-code token launchpad and crowdfunding platform operating primarily on BNB Smart Chain, Ethereum, and Base, launched around 2021. On December 17, 2024, a reentrancy vulnerability in its LP Locker V2 smart contract was exploited across three chains, draining approximately $1.9–$2.2 million in locked liquidity from at least 27 dependent projects. Stolen funds were routed through Tornado Cash, and GemPad issued no public compensation plan for affected projects.
avoid.net/moby→38/100[WARNING]Moby Trade (moby.trade) is an on-chain options protocol built on Arbitrum and Berachain, launched in 2024 and backed by an Arbitrum Foundation grant. On January 8, 2025, the protocol suffered a critical security breach when a private key controlling proxy admin contracts was compromised, resulting in approximately $2.5 million in user funds being drained; roughly $1.5 million was subsequently recovered through an intervention by the SEAL911 security team. The protocol resumed operations after the incident and expanded to Berachain mainnet in February 2025, but the unrecovered ~$1 million in ETH and WBTC was routed through privacy mixers including Railgun and Tornado Cash, leaving those funds effectively unrecoverable.
avoid.net/dogwiftools→4/100[CRITICAL]DogWifTools is a Solana-based memecoin tooling platform that markets features explicitly designed to simulate artificial trading volume, conceal supply concentration across hundreds of wallets, and inflate engagement metrics on pump.fun — capabilities that security researchers and blockchain analysts characterize as enabling wash trading and coordinated pump-and-dump schemes. In January 2025, the platform suffered a supply-chain attack in which threat actors trojaned versions 1.6.3 through 1.6.6 with a Remote Access Trojan, draining an estimated $10 million from users' wallets; the attacker group framed the theft as vigilante justice against scammers. No known regulatory action has been taken against DogWifTools operators, who remain anonymous.
avoid.net/fourmeme→38/100[WARNING]four.meme is a permissionless meme token launchpad built on BNB Chain (BSC), operated under the Four (formerly BinaryX) ecosystem, that enables zero-KYC token creation with automatic bonding-curve-to-PancakeSwap liquidity migration. The platform suffered two confirmed smart contract exploits within six weeks in early 2025, losing a combined total of approximately $310,000 in user and pool funds. Repeat critical vulnerabilities, a phishing campaign that hijacked Google search results, and ecosystem-wide spam and token-pollution incidents raise substantial safety concerns for users.
avoid.net/cardex→28/100[WARNING]Cardex is an on-chain fantasy trading card game that launched on the Ethereum layer-2 network Abstract in February 2025, offering tokenized digital versions of collectible trading cards for competition in online tournaments. Within one week of launch, a critical operational security failure — the inadvertent exposure of a shared session signer private key on the application's frontend — allowed an attacker to drain approximately $400,000–$470,000 in ETH from roughly 9,000 user wallets over a seven-hour period. The project has been flagged by ZachXBT; user accusations of a rug pull circulated on Telegram, though Abstract core contributors attributed the incident to mishandled credentials rather than intentional fraud. No confirmed restitution fund or formal accountability measure had been publicly disclosed as of the most recent reporting.
avoid.net/infini→12/100[CRITICAL]Infini is a Hong Kong-based stablecoin neobank offering yield-bearing accounts and a global payment card. On February 24, 2025, a former developer who had covertly retained administrative privileges over Infini's smart contracts drained approximately $49.5 million in USDC from the Morpho MEVCapital vault, converting the funds to ETH and routing them through Tornado Cash. As of May 2026, no funds have been recovered, and the attacker's wallet remained active through at least February 2026.
avoid.net/berally→32/100[WARNING]Berally is a SocialFi and AI-agent social trading platform built on the Berachain blockchain, issuing the BRLY token via a public presale on Fjord Foundry in late 2024. In March 2025, the project suffered a significant security incident in which its deployer private key was alleged to have been leaked, resulting in all vesting tokens being dumped into its liquidity pool and approximately $90,000 drained from the pool. The BRLY token subsequently collapsed to roughly 99% below its all-time high, trading has effectively ceased, and community members have alleged the incident was an inside job, though this has not been formally substantiated.
avoid.net/tenderize-v2→37/100[WARNING]Tenderize V2 is a DeFi liquid staking protocol launched on January 29, 2024, enabling users to mint validator-specific liquid staked tokens (tTokens) for assets including MATIC, LPT, and GRT across Ethereum, Arbitrum, and Sei Network. The protocol suffered a protocol logic exploit on April 7, 2025, resulting in a loss of approximately $10,850 via a proxy upgrade skim technique on Ethereum; the incident was relatively small in dollar terms but raised concerns about smart contract integrity. ZachXBT has flagged this entity, and while the protocol holds multiple security audits including a Hacken audit scoring 9.8/10 and a Halborn audit, its current TVL of approximately $495,000 reflects limited adoption relative to the broader liquid staking market.
avoid.net/zksync→57/100[CAUTIONARY]ZKsync is an Ethereum Layer 2 scaling protocol built on zero-knowledge rollup technology, developed by Matter Labs, which has raised approximately $458 million in venture capital. The protocol has faced multiple significant controversies including a $5 million airdrop contract exploit in April 2025, a contentious 2024 token airdrop marred by sybil attack failures and community backlash, a South Korean regulatory probe into alleged price manipulation, compromised social media accounts spreading false SEC investigation claims, and an intellectual property theft lawsuit filed against Matter Labs by defunct firm BANKEX. User funds in the core protocol have not been directly compromised, but the pattern of incidents has substantially eroded community trust.
avoid.net/loopscale→38/100[WARNING]Loopscale is a Solana-based DeFi lending protocol (formerly Bridgesplit) launched on April 10, 2025, backed by Coinbase Ventures, Solana Labs, and CoinFund. On April 26, 2025 — just 16 days after launch — the protocol suffered a $5.8 million oracle pricing exploit affecting its Genesis Vaults, an attack vector that had been flagged in its pre-launch OShield security audit but was allegedly inadequately remediated. All stolen funds were ultimately recovered via negotiation with the exploiter, and user deposits suffered no permanent loss.
avoid.net/cetus-clmm→18/100[CRITICAL]Cetus Protocol is a concentrated liquidity market maker (CLMM) and the dominant decentralized exchange on the Sui Network, launched in 2023. On May 22, 2025, an arithmetic overflow vulnerability in its fixed-point math library enabled an attacker to drain approximately $223 million from liquidity pools in the largest DeFi exploit of 2025, of which roughly $162 million was subsequently frozen by Sui validators and later returned to affected users via an on-chain governance vote. The incident raised significant concerns about smart contract security, audit effectiveness, and the degree of decentralization on the Sui network.
avoid.net/forcebridge→20/100[CRITICAL]ForceBridge is a cross-chain bridge operated by Magickbase on the Nervos Network (CKB), enabling transfers between Nervos and Ethereum and BNB Chain. On June 2, 2025, the bridge was exploited via an access control vulnerability — likely a compromised private key — resulting in approximately $3.7–3.9 million in user funds being stolen and laundered through Tornado Cash. The exploit occurred just one day after Magickbase announced the bridge's sunset, raising questions about the timing and origin of the attack.
avoid.net/silo-finance→47/100[WARNING]Silo Finance V1 is a non-custodial isolated lending protocol launched on Ethereum mainnet in August 2022, enabling permissionless markets for long-tail crypto assets by confining risk to individual lending pools (Silos). The protocol experienced two security incidents in 2023: a critical interest rate manipulation vulnerability discovered by a white-hat researcher (no user funds lost) and a white-hat drain of approximately $45,000 in SILO incentive tokens due to a separate contract flaw. The deployed production version of V1 diverges from the audited codebase, a risk the team has publicly acknowledged but not fully remediated through re-audit.
avoid.net/kinto-bridge→28/100[WARNING]Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.
avoid.net/arcadia-v2→28/100[WARNING]Arcadia V2 is a non-custodial leverage farming and liquidity management protocol operating primarily on Base, developed by Belgium-based Arcadia Finance (founded 2021, backed by Coinbase Ventures). The protocol has suffered two serious security exploits: a July 2023 reentrancy attack on its V1 codebase draining approximately $455K across Ethereum and Optimism, and a more severe July 2025 arbitrary calldata exploit on V2's Rebalancer contract that drained approximately $3.6M on Base despite multiple prior audits. ZachXBT has flagged the protocol as a high-risk entity given this pattern of repeated critical security failures.
avoid.net/woo-x→38/100[WARNING]WOO X is a centralized cryptocurrency exchange founded in 2019 and incubated by Taiwanese quantitative trading firm Kronos Research, offering spot and derivatives trading with a focus on deep liquidity and low fees. The exchange has experienced two significant security events: a November 2023 liquidity crisis triggered by a $26 million hack of its primary market maker Kronos Research, and a July 2025 $14 million breach of nine user accounts attributed to a North Korean state-sponsored group (UNC4899/Lazarus) via phishing of a developer. Both incidents resulted in user compensation from company reserves, though the pattern of security failures and structural dependency on Kronos Research represent elevated counterparty and operational risk.
avoid.net/superrare→45/100[WARNING]SuperRare is a curated Ethereum-based NFT art marketplace founded in 2018 by John Crain, Charles Crain, and Jonathan Perkins, operating as a high-end platform for 1-of-1 digital artworks with its own governance token RARE. On July 28, 2025, a critical access control vulnerability in the platform's RareStakingV1 staking contract was exploited, resulting in the theft of approximately 11.9 million RARE tokens worth roughly $731,000. SuperRare subsequently reimbursed the 61 affected wallets by August 5, 2025, and the RARE token recovered approximately 41% following the remediation announcement.
avoid.net/texture→28/100[WARNING]Texture Finance is a Solana-based decentralized lending protocol founded in 2021 and backed by $5 million in venture funding from P2P Capital, Sino Global Capital, Wintermute, and Jane Street Capital. In July 2025, a missing ownership check in its USDC vault smart contract allowed an attacker to steal approximately $2.2 million in user funds; the protocol negotiated a 10% greyhat bounty and recovered roughly $1.98 million. User withdrawals remained disabled following the exploit, and a formal repayment timeline had not been published as of mid-2025.
avoid.net/shibarium→28/100[WARNING]Shibarium is a layer-2 blockchain built on Ethereum, launched in August 2023 as the scaling solution for the Shiba Inu (SHIB) ecosystem. The network has faced a series of significant incidents including a failed initial launch that trapped $1.7 million in bridged funds, a September 2025 flash loan exploit that drained approximately $4.1 million from its cross-chain bridge via validator key compromise, persistent rug pull activity on its DeFi layer, allegations of code plagiarism, and ongoing transparency concerns stemming from fully pseudonymous leadership. Shibarium initiated a novel NFT-based restitution program following the 2025 exploit but as of early 2026 the recovery path remained unresolved.
avoid.net/griffinai→28/100[WARNING]Griffin AI is a Web3 no-code AI agent builder on BNB Chain that launched its native GAIN token on Binance Alpha on September 24, 2025. Within hours of launch, an attacker exploited a misconfigured LayerZero cross-chain peer to mint 5 billion unauthorized GAIN tokens and dump approximately $3 million worth into the market, crashing the token 87-90% and erasing roughly $36 million in market capitalization. The team subsequently enacted a token migration, a $2.5 million recovery fund, and a re-launch on October 6, 2025, though GAIN continues to trade approximately 95% below its all-time high.
avoid.net/asterafi→38/100[WARNING]Astera.fi is a DeFi credit facility and lending protocol operating on Ethereum's Linea Layer-2 network, issuing the asUSD stablecoin through both over- and under-collateralized mechanisms. On October 9, 2025, the protocol suffered a flash loan exploit via a liquidity index inflation attack that drained approximately $821,856–$880,000 across three lending pools. The protocol has been flagged by ZachXBT and market data indicates near-zero trading activity for asUSD, with the token appearing to have effectively ceased normal operation post-exploit.
avoid.net/moonwell-lending→28/100[WARNING]Moonwell is a decentralized, non-custodial lending and borrowing protocol deployed on Base, Optimism, Moonbeam, and Moonriver, operating as a fork of Compound v2. The protocol has suffered at least five distinct security incidents between 2022 and 2026, resulting in combined losses and bad debt exceeding $5 million, including repeated oracle failures, a flash loan exploit, a near-successful governance attack, and an AI-assisted smart contract misconfiguration. Despite multiple audits by Halborn and Code4rena, the pattern of recurring vulnerabilities and the removal of its Immunefi bug bounty program in early 2025 have raised significant security concerns.
avoid.net/raga-finance→42/100[WARNING]Raga Finance is a DeFi yield optimization protocol launched in 2024 and deployed on Berachain and Hyperliquid, offering automated cross-chain vaults for earning yield on ETH, BTC, and stablecoins. A pre-launch security audit by QuillAudits uncovered 16 smart contract vulnerabilities — including critical flaws enabling permanent loss of user funds, a non-functional emergency panic function, and an open-access vault address setter — constituting the protocol logic incident flagged for review. The protocol has been flagged by ZachXBT, and while the development team reportedly remediated all identified vulnerabilities, the severity and breadth of pre-launch flaws raise meaningful questions about engineering process and ongoing risk.
avoid.net/ribbon→28/100[WARNING]Ribbon Finance is an Ethereum-based DeFi protocol that pioneered Theta Vaults (DeFi Options Vaults) for structured yield products, later expanding into the Aevo derivatives exchange. The protocol has experienced multiple serious incidents including a $2.7 million oracle exploit in December 2025 whose recovery plan drew widespread community condemnation, a 2021 Sybil attack on its token airdrop by a connected venture capital firm, and a DNS hijacking in 2022. Its native token RBN lost approximately 90% of its value in 2025 alone and sits more than 99% below its all-time high.
avoid.net/mars-perps→28/100[WARNING]Mars Perps was the perpetual futures product of Mars Protocol, deployed on the Neutron outpost of the Cosmos ecosystem. On December 14, 2025, the protocol suffered a mechanism design exploit that drained $973,079 USDC from lending depositors via skew-based same-block arbitrage. The exploit ultimately triggered a full protocol wind-down, which concluded in March 2026 with user funds returned and community channels closed.
avoid.net/blend-pools-v2→32/100[WARNING]Blend Pools V2 is a modular, permissionless lending protocol built on the Stellar blockchain by Script3, launched as an upgrade to Blend V1 with additions including flash loans and a reduced backstop threshold. In February 2026, a community-managed pool built on top of the protocol (YieldBlox DAO Pool) suffered a $10.8 million oracle manipulation exploit; Script3 stated the core V2 contracts were not at fault, attributing the incident to pool-operator misconfiguration of the Reflector VWAP oracle.
avoid.net/dgld→42/100[WARNING]DGLD (Digital Gold Token) is a physically-backed gold token originally launched in October 2019 by a consortium of CoinShares, Blockchain.com, and MKS PAMP SA on CommerceBlock's Ocean Bitcoin sidechain. The project went dormant by 2020 due to liquidity failure and market under-adoption, and the underlying infrastructure provider CommerceBlock later shut down entirely. MKS PAMP relaunched DGLD in late 2025 under full ownership of Gold Token SA, migrating to Ethereum and Base — but significant jurisdictional restrictions, minimal liquidity, contractual liability exclusions, and the project's history of abandonment remain concerns.
avoid.net/foom-cash→28/100[WARNING]FOOM Cash (foom.cash) is a pseudonymous, privacy-focused decentralized lottery protocol built on Ethereum and Base, marketed as an 'upgraded Tornado Cash' using zk-SNARKs cryptography. On February 26, 2026, the protocol suffered a $2.26 million exploit caused by a critical deployment error in its Groth16 trusted setup — a flaw publicly known from an identical exploit on Veil Cash days earlier that the team failed to patch. The team had been silent for approximately three months prior to the attack and was subsequently flagged as a notable risk by AVOID.NET due to compounding concerns: anonymous founders, serious operational negligence, misleading post-incident communications, and unverifiable audit claims.
avoid.net/curve-llamalend→52/100[CAUTIONARY]Curve LlamaLend (also referred to as the crvUSD lending markets) is a decentralized, permissionless isolated lending protocol built by Curve Finance that allows users to borrow crvUSD against crypto collateral using the LLAMMA soft-liquidation mechanism. The protocol has experienced multiple distinct incidents since launch: a $10 million bad-debt event in June 2024 tied to the founder's oversized leveraged positions, an oracle-manipulation attack on the sDOLA market in March 2026 resulting in approximately $240,000 in borrower losses, an October 2025 market crash that left the CRV-long vault approximately $700,000 underbacked, and a May 2026 third-party exploit (Stake DAO) that forced the sunsetting of an associated Arbitrum LlamaLend market. The protocol's core contracts have not been directly compromised by a code-level hack, but recurring bad-debt events, oracle design flaws in permissionlessly created markets, and governance concentration risks have drawn sustained scrutiny including a flag from on-chain investigator ZachXBT.
avoid.net/stake-dao→36/100[WARNING]Stake DAO is a non-custodial DeFi protocol built around liquid staking, yield aggregation, and governance participation via veToken mechanics. The protocol has suffered three documented security incidents since 2023, the most severe of which — a May 2026 deployer private key compromise — enabled the minting of 5.4 trillion fraudulent vsdCRV tokens on Arbitrum, resulting in roughly $91,000 in realized losses despite a nominally catastrophic exposure. Repeated operational security failures across a two-year span, including a March 2026 oracle exploit draining $176,000 from its Votemarket product, indicate a pattern of infrastructure risk that audited smart contracts alone have not resolved.
avoid.net/cyrus-finance→18/100[CRITICAL]Cyrus Finance is a decentralized yield-optimizer protocol operating on the BNB Smart Chain that markets itself as a high-yield DeFi platform utilizing PancakeSwap liquidity pairs and single-sided vaults. On March 22, 2026, the protocol suffered a $5 million flash loan exploit attributed to flawed pool-share accounting in its smart contracts, with no reported fund recovery. Multiple secondary domains (cyrusfinance.xyz) associated with the Cyrus Finance brand have been independently flagged as potentially malicious fake-broker sites that simulate trading activity and block user withdrawals.
avoid.net/silo-v2→44/100[WARNING]Silo V2 is a non-custodial, permissionless isolated lending market protocol operating across Ethereum, Arbitrum, Base, Optimism, and Sonic. On June 25, 2025, an unreleased peripheral leverage contract was exploited for approximately $545,000 (224 ETH) belonging to SiloDAO test funds; the team confirmed that all core markets and user deposits were unaffected. The incident revealed inadequate input validation and absent formal verification on pre-release code that had been deployed to mainnet, and the attacker subsequently laundered the stolen ETH through Tornado Cash.
avoid.net/aethir→36/100[WARNING]Aethir is a Singapore-based decentralized GPU cloud computing protocol operating as a Decentralized Physical Infrastructure Network (DePIN), founded in 2021 by Mark Rydon and Daniel Wang. The project raised approximately $109M across funding rounds and a $100M+ checker node sale, launched its ATH token in June 2024, and claims $147M+ ARR from enterprise AI and gaming clients. Risk factors include a 95% token price decline from its all-time high, a redirected Season 3 community airdrop, a cross-chain bridge exploit in April 2026 resulting in up to $400K in losses, heavy insider token allocation, and a ZachXBT flag whose specific basis has not been publicly detailed.
avoid.net/subquery-network→38/100[WARNING]SubQuery Network is a Web3 data indexing protocol originally built for the Polkadot ecosystem, founded by Sam Zou and James Bayly out of New Zealand-based OnFinality. The project raised $10.8M in seed and Series A funding, launched its mainnet and SQT token in February 2024, and suffered a significant smart-contract exploit on April 12, 2026 in which a missing access-control modifier allowed an attacker to drain approximately 382 million SQT tokens (~$134,000 USD) from staker and delegator wallets across five transactions. ZachXBT flagged the entity in connection with this incident; the team published a full disclosure report and executed on-chain compensation for all affected wallets.
avoid.net/kelp→18/100[CRITICAL]Kelp (also known as Kelp DAO) is a liquid restaking protocol built on Ethereum and EigenLayer that issues rsETH, a liquid restaked token. In April 2026 the protocol suffered the largest DeFi exploit of 2026 to date when attackers, attributed to North Korea's Lazarus Group, drained approximately $292 million in rsETH through a compromised LayerZero cross-chain bridge configuration. The protocol and an industry coalition dubbed DeFi United are actively working to restore collateral and resume operations as of May 2026.
avoid.net/nemo-yield-trading→28/100[WARNING]Nemo Protocol is a Sui-based DeFi yield trading platform that suffered a $2.6 million exploit on September 7, 2025, caused by an unnamed developer who deployed unaudited code to mainnet while bypassing internal review processes. A security auditor had flagged a related vulnerability 27 days before the attack, which the team acknowledged it failed to address in time. The protocol's TVL has since collapsed to zero and it has been flagged as high-risk by trust intelligence sources.
avoid.net/panoptic-v11→37/100[WARNING]Panoptic V1.1 is a permissionless, oracle-free perpetual options protocol built on Uniswap V3 liquidity positions, developed by Panoptic Labs and incubated by Advanced Blockchain AG. On August 25, 2025, a Cantina researcher disclosed a critical position-spoofing vulnerability rooted in the protocol's XOR-based fingerprinting system, placing approximately $4–5 million in user funds at risk. A coordinated whitehat rescue secured over 98% of remaining at-risk funds, and ZachXBT flagged the incident, contributing to reduced community trust in the V1.1 deployment.
avoid.net/seedify→28/100[WARNING]Seedify (Seedify.fund) is a blockchain gaming incubator and IDO/IGO launchpad founded in February 2021 by Levent Cem Aydan, operating on BNB Chain, Ethereum, and Avalanche with its native SFUND token. The platform suffered a critical $1.2–1.7 million bridge exploit in September 2025 attributed by ZachXBT and CZ (Binance) to the North Korean DPRK-affiliated 'Contagious Interview' hacking campaign, causing SFUND to collapse approximately 80–99% and affecting approximately 64,000 token holders. The platform's SFUND token has declined more than 99% from its November 2021 all-time high of approximately $17.67, and the project has been flagged by ZachXBT in connection with the on-chain forensics tying the exploit to state-sponsored theft infrastructure.
avoid.net/kame-aggregator→32/100[WARNING]Kame Aggregator is a decentralized exchange (DEX) aggregator protocol built on the Sei blockchain, launched in late May 2025, designed to route token swaps across multiple liquidity sources for optimal pricing. On September 13, 2025, the protocol suffered a critical smart contract exploit in which approximately $1.325 million was drained from 830 user wallets via an arbitrary external call vulnerability in its swap() function. The primary exploiter returned approximately $946,000 after negotiations, while secondary exploiters retained approximately $357,000; the team initiated a compensation program that reached over $1 million USDC in distributions by November 2025.
avoid.net/hyperdrive-hl→35/100[WARNING]Hyperdrive HL (formerly Ambit Finance) is a stablecoin lending and liquid-staking protocol deployed on Hyperliquid EVM, which raised a $6 million Series A in May 2025 led by Hack VC and Arrington Capital. On September 27, 2025, an attacker exploited an arbitrary-call vulnerability in the protocol's router contract, draining approximately $782,000 in USDT0 and thBILL tokens across two markets. The team paused operations, patched the vulnerability, and compensated affected users before resuming, though the incident occurred within a broader wave of security breaches across the Hyperliquid ecosystem.
avoid.net/port3-network→38/100[WARNING]Port3 Network is a Web3 social data protocol and AI data layer founded in 2022, backed by KuCoin Ventures and Jump Crypto, with products including SoQuest, SoSignal, and SoPush targeting Web3 community engagement and data aggregation. In November 2025 the project suffered a critical exploit in which an attacker leveraged a boundary-condition vulnerability in the third-party CATERC20 cross-chain standard to mint approximately 1 billion unauthorized PORT3 tokens valued at roughly $13 million, triggering an 80% token price collapse and full contract migration. ZachXBT has flagged the entity, and the token has been delisted from at least one major exchange (Coinone) following the incident.
avoid.net/us-permissionless-dollar→28/100[WARNING]US Permissionless Dollar (USPD) is a decentralized, over-collateralized stablecoin protocol built on Ethereum by Permissionless Technologies, the team behind the Morpher trading platform. In December 2025, the protocol suffered a critical exploit via a clandestine proxy deployment attack — later dubbed CPIMP — that had silently compromised admin privileges since September 2025, resulting in approximately $1 million in losses. The project has undergone audits by Nethermind and Resonance Security but the exploit bypassed audited code by targeting the deployment layer, raising unresolved questions about operational security and the viability of the planned V2 relaunch.
avoid.net/0g-labs→43/100[WARNING]0G Labs (Zero Gravity Labs) is a Web3 AI infrastructure company building a modular, AI-first layer-1 blockchain and decentralized AI operating system, having raised $325 million across multiple funding rounds since March 2024. The project has faced a protocol-level smart contract exploit in December 2025 ($516K lost), a separate compromise of its official social media account in October 2025, and significant community criticism over alleged funding misrepresentation, undisclosed insider token allocations, and concerns that two co-founders departing from Conflux Network constituted a reputational 'soft rug' of that project. No regulatory actions have been identified as of May 2026.
avoid.net/unleash-protocol→18/100[CRITICAL]Unleash Protocol is a decentralized intellectual property finance (IPFi) platform built on the Story Protocol blockchain, launched in early 2024. On December 30, 2025, the protocol suffered a confirmed $3.9 million exploit in which an attacker gained unauthorized administrative control through its multisignature governance system, executed an unauthorized smart contract upgrade, and laundered 1,337 ETH through Tornado Cash. The protocol subsequently paused all operations; as of early 2026 no recovery or user compensation plan has been publicly confirmed.
avoid.net/makina→35/100[WARNING]Makina Finance is a non-custodial DeFi execution engine that launched in late 2025 on Ethereum, enabling automated yield strategies via tokenized vaults called Machines. On January 20, 2026, the protocol suffered a $4.13 million oracle manipulation exploit targeting its DUSD/USDC Curve stableswap pool, despite having completed six independent security audits in the months prior. The team recovered approximately $3.65 million (89% of user losses) within one week and resumed operations on January 26, 2026, though a residual 11% shortfall remained subject to a revenue-share restitution plan.
avoid.net/ploutos-money→12/100[CRITICAL]Ploutos Money was a multi-chain DeFi lending and leveraged farming protocol, forked from Aave v3.0.2, that operated across Ethereum, Arbitrum, Hemi, Hyperliquid, Avalanche, Polygon, Base, Plasma, and Katana. On February 26, 2026, the protocol lost approximately $388,000 (187.36 ETH) after its USDC price oracle was misconfigured to reference Chainlink's BTC/USD feed instead of the correct USDC/USD feed. Immediately following the exploit, the team deleted its website, GitHub repository, and all social media accounts without issuing any warning or post-mortem, prompting on-chain security firms CertiK and BlockSec to conclude that the incident was an inside job rather than an external attack.
avoid.net/iotex→38/100[WARNING]IoTeX is a Layer 1 blockchain and DePIN (Decentralized Physical Infrastructure Network) platform founded in 2017 by Raullen Chai, Qevan Guo, Jing Sun, and Xinxin Fan, with its native IOTX token launched via ICO in 2018. In February 2026 the project suffered a significant security incident when a compromised private key on the Ethereum side of its ioTube cross-chain bridge allowed an attacker to drain approximately $4.3–$4.4 million in assets and mint 410 million unauthorized CIOTX tokens, with total estimated damages disputed between $4.4 million (official) and $8.8 million (PeckShield). Additional concerns include a prior market-maker-linked near-zero price anomaly on Binance in October 2025, governance centralization risks from its 36-delegate Roll-DPoS consensus model, and on-chain analyst reports alleging the attacker's wallet was funded by the same entity behind the $49 million Infini Finance hack of 2025.
avoid.net/solvbtc→38/100[WARNING]SolvBTC is the flagship wrapped Bitcoin product of Solv Protocol, designed to represent Bitcoin in DeFi systems across multiple chains. In March 2026, the BRO vault component of the protocol suffered a $2.7 million exploit due to a double-mint logic flaw in the BitcoinReserveOffering smart contract. Separately, in January 2025, the protocol faced credible public allegations of TVL manipulation prior to its SOLV token launch.
avoid.net/aave-v3→58/100[CAUTIONARY]Aave V3 is the third major iteration of the Aave decentralized lending protocol, one of the largest in DeFi with over $14 billion in total value locked across 21 chains as of May 2026. The protocol's core smart contracts have not been directly exploited; however, in April 2026, a $292 million bridge exploit targeting integrated asset KelpDAO's rsETH generated significant bad debt on Aave V3 markets, an event flagged by on-chain investigator ZachXBT. The protocol demonstrated institutional resilience by coordinating a cross-industry recovery fund (DeFi United) that ultimately raised over $327 million, with full rsETH operations restored by May 25, 2026.
avoid.net/goose-finance→32/100[WARNING]Goose Finance is an anonymous-team yield farming and decentralized exchange protocol launched on Binance Smart Chain in February 2021, best known for its EGG governance and reward token. The protocol achieved rapid early traction, reaching third-most-popular DeFi app on BSC within one month, before its EGG token collapsed more than 99% from an all-time high near $172. A post-audit smart contract exploit in March 2026 drained approximately $8,000 via a share accounting flaw, and independent analysts have flagged the layered farming tokenomics as structurally unsustainable.
avoid.net/zerion-wallet→43/100[WARNING]Zerion is a non-custodial DeFi portfolio tracker and multi-chain wallet founded in 2016, supporting 50+ blockchains including Ethereum and Solana. The platform has experienced multiple security incidents over its history, including a 2026 social engineering attack attributed to North Korean threat actors that resulted in approximately $100,000 in company internal wallet losses, though user funds were unaffected in each incident. Zerion also shut down its ZERO Layer-2 network in May 2026 after 1.5 years due to low adoption, with assets bridgeable until July 31, 2026.
avoid.net/mona→38/100[WARNING]MONA is the native ERC-20 governance and utility token of DIGITALAX, a Web3 digital fashion NFT platform founded by Emma-Jane MacKinnon-Lee and launched in November 2020. The token reached an all-time high of approximately $5,980 in November 2021 before collapsing more than 99% to trade below $50, with a total market capitalisation under $500,000 as of mid-2026. Third-party security assessors flag critically low liquidity, extreme holder concentration, a below-average security score, and a near-total absence of trading activity, collectively indicating a project in terminal decline.
avoid.net/ola-finance→28/100[WARNING]Ola Finance is a multi-chain decentralized lending protocol offering a 'lending-as-a-service' platform that allows third parties to deploy isolated Compound-style lending pools across multiple blockchains. On March 31, 2022, the protocol's deployment on the Fuse Network was exploited via a reentrancy vulnerability in ERC677 token logic, resulting in approximately $4.67 million in stolen assets. The attacker used Tornado Cash to obscure initial funding, laundered proceeds through Ethereum and BNB Chain wallets, and was never publicly identified; a partial compensation plan was offered but fell materially short of full victim restitution.
avoid.net/beanstalk→12/100[CRITICAL]Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.
avoid.net/saddle-finance→10/100[CRITICAL]Saddle Finance was an Ethereum-based automated market maker (AMM) optimized for pegged-value assets such as stablecoins and wrapped BTC, founded in 2020 and launched in January 2021. The protocol suffered a critical exploit on April 30, 2022, when an attacker leveraged an unpatched MetaSwapUtils library bug to drain approximately $11 million via flash-loan-assisted price manipulation, with $3.8 million subsequently rescued by security firm BlockSec. The protocol formally wound down in September 2023 following a DAO vote (SIP-54) triggered in part by the broader DeFi security climate after the Curve Finance hack.
avoid.net/mm-finance-cronos→28/100[WARNING]MM Finance (also known as Mad Meerkat Finance) was the largest decentralized exchange on the Cronos blockchain. On May 4, 2022, the protocol suffered a frontend compromise in which an attacker injected a malicious router contract address, redirecting approximately $2 million in user funds to the attacker's wallet over roughly three hours. The stolen funds were laundered via Tornado Cash and routed through OKX; the team pledged reimbursement via trading fee airdrops, though full recovery of stolen assets was not confirmed. The MMF token subsequently lost approximately 99.9% of its value from its April 2022 all-time high.
avoid.net/nomad→10/100[CRITICAL]Nomad was a cross-chain messaging bridge operated by Illusory Systems, Inc. that suffered one of the largest DeFi exploits in history on August 1–2, 2022, when a smart contract initialization bug allowed approximately $190 million in user funds to be drained in a chaotic free-for-all involving over 300 wallet addresses. The protocol never recovered meaningful user adoption after a December 2022 relaunch, faced a class action lawsuit and an FTC enforcement action, and in December 2025 agreed to a settlement requiring repayment of $37.5 million to affected users.
avoid.net/binance-bridge→10/100[CRITICAL]Binance Bridge (BSC Token Hub) was the official cross-chain bridge connecting the BNB Beacon Chain (BEP2) and BNB Smart Chain (BEP20), operated by Binance. On October 6-7, 2022, an attacker exploited a critical flaw in the bridge's IAVL Merkle proof verification logic inherited from Cosmos SDK, forging deposit proofs to mint 2 million BNB (approximately $586 million at time of exploit). Although the BNB Chain was halted by validators to contain the damage — trapping roughly $430 million on-chain — approximately $110–137 million escaped to other networks before the halt took effect.
avoid.net/templedao→32/100[WARNING]TempleDAO is a DeFi yield protocol launched on Ethereum in August 2021, designed to offer low-volatility, fractionally backed yields on deposited assets. On October 11, 2022, an associated staking product, STAX Finance, suffered a smart contract exploit due to missing access control on the migrateStake() function, resulting in approximately $2.34 million in stolen funds that were subsequently laundered through Tornado Cash. The core TempleDAO vaults were not directly compromised, but the team's anonymous structure and the unrecovered stolen funds remain notable risk factors.
avoid.net/skyward-finance→18/100[CRITICAL]Skyward Finance was a permissionless token launchpad built on the NEAR Protocol, launched in June 2021. On November 2, 2022, a smart contract vulnerability in its treasury redemption function was exploited, resulting in the loss of approximately 1.1 million NEAR tokens (~$3.2 million USD). The exploit rendered the SKYWARD token and protocol treasury effectively worthless, and the team publicly advised users to withdraw all remaining funds and cease interacting with the platform.
avoid.net/defrost→18/100[CRITICAL]Defrost Finance was an Avalanche-based CDP (Collateralized Debt Position) DeFi protocol that allowed users to collateralize yield-bearing tokens to mint an H2O USD-pegged stablecoin. In December 2022 the protocol suffered a two-stage exploit resulting in approximately $12 million in losses; multiple blockchain security firms — including CertiK, PeckShield, and De.Fi Security — alleged the attack constituted an insider rug pull enabled by admin key access, a conclusion the team denied. Funds were subsequently returned and a refund contract was deployed in January 2023, but the protocol has since effectively ceased meaningful operations with under $100,000 in TVL, and the MELT governance token has lost nearly all of its value.
avoid.net/midas-capital→32/100[WARNING]Midas Capital is a multichain DeFi isolated lending protocol that forked its codebase from Rari Capital's Fuse implementation. The protocol suffered two separate security exploits in 2023 totaling approximately $1.26 million in losses, with both incidents attributed to known smart contract vulnerabilities that had previously affected other Compound V2 forks. ZachXBT flagged the protocol, and the second exploit resulted in laundered funds routed through Tornado Cash.
avoid.net/gdac→10/100[CRITICAL]GDAC was a South Korean cryptocurrency exchange operated by Peertec Co., Ltd. that launched in May 2018 and was registered as a Virtual Asset Service Provider (VASP) with Korea's Financial Intelligence Unit (KoFIU). On April 9, 2023, attackers drained approximately $13–14 million from its hot wallets — representing 23% of total custodial assets — causing the exchange to permanently shut down with no compensation offered to affected users.
avoid.net/merlin-dex→5/100[CRITICAL]Merlin DEX was a decentralized exchange built on zkSync Era that suffered a confirmed insider rug pull on April 26-27, 2023, during its MAGE token Liquidity Generation Event. Rogue backend developers exploited excessive smart contract permissions granted to a privileged 'Feeto' address to drain approximately $1.82 million in user funds. Despite a prior CertiK audit, centralization risks flagged during review were not effectively remediated; CertiK subsequently acknowledged partial responsibility and launched a compensation plan, recovering only $160,000 of the stolen amount.
avoid.net/kannagi→3/100[CRITICAL]Kannagi Finance was a decentralized yield aggregation protocol launched on zkSync Era in June 2023. On July 29, 2023, the project's anonymous team executed an exit scam, draining approximately $2.13 million in user funds and reducing TVL from $2.13 million to $0.17. The stolen funds were subsequently laundered through the Tornado Cash crypto mixer, and all project infrastructure — website, Twitter, and GitHub repositories — was deleted.
avoid.net/zunami-protocol→10/100[CRITICAL]Zunami Protocol is an Ethereum-based DeFi yield aggregator and stablecoin issuer (UZD, zETH) that suffered at least four separate security incidents between January 2023 and May 2025, losing a combined estimated $2.86 million or more in user funds. The protocol is notable for ignoring a prior warning from SlowMist before its largest smart contract exploit, and for a May 2025 incident in which an admin key compromise allegedly drained $500,000, with the team subsequently going silent for weeks and development activity having ceased months prior.
avoid.net/sharedstake→28/100[WARNING]SharedStake is an Ethereum liquid staking protocol launched in January 2021 that allowed users to deposit ETH in exchange for the vETH2 liquid staking token. In June 2021, a co-founder using the pseudonym 'Kairos' exploited a critical timelock bypass vulnerability in the protocol's vesting contracts — a bug that had been disclosed to the team two months prior — draining approximately $128,000 from liquidity providers and sending 100 ETH through Tornado Cash. The protocol subsequently relaunched as SharedDeposit v2 under remaining team members, though the SGT governance token never recovered.
avoid.net/onyx-protocol→22/100[CRITICAL]Onyx Protocol is a DeFi lending protocol forked from Compound Finance v2, operating on Ethereum and issuing the XCN (Onyxcoin) token. The protocol suffered two major exploits in under twelve months — $2.1 million in October/November 2023 and $3.8 million in September 2024 — both stemming from the same known precision vulnerability in the Compound v2 codebase that the team had been warned about by auditor CertiK in February 2023 and chose not to remediate. Following the second hack the Ethereum-based lending market was shut down and the protocol relaunched as Onyx Core.
avoid.net/poloniex→10/100[CRITICAL]Poloniex is a cryptocurrency exchange founded in 2014 and acquired in 2019 by an investor group led by Tron founder Justin Sun. On November 10, 2023, the exchange suffered one of the largest hot wallet compromises in crypto history, with attackers draining approximately $126 million across Ethereum, TRON, and Bitcoin networks in an attack attributed by multiple blockchain security firms to North Korea's Lazarus Group. The exchange has also faced significant regulatory enforcement actions, including a $7.59 million OFAC sanctions settlement and a $10.4 million SEC settlement for operating an unregistered national securities exchange.
avoid.net/kyberswap-elastic→10/100[CRITICAL]KyberSwap Elastic is the concentrated liquidity automated market maker (AMM) component of Kyber Network, a decentralized exchange protocol deployed across more than a dozen EVM-compatible blockchains. On November 22–23, 2023, it suffered the largest DeFi exploit of that year — approximately $48–56 million drained via a precision rounding bug in its tick-crossing swap logic — after which the alleged attacker issued an on-chain ultimatum demanding full executive control of the company. Canadian national Andean Medjedovic was indicted by U.S. prosecutors in February 2025 on charges including wire fraud, computer hacking, and extortion; he remains a fugitive as of mid-2026.
avoid.net/heco-bridge→5/100[CRITICAL]Heco Bridge was the official cross-chain bridge connecting the HECO Chain (HTX Eco Chain) to Ethereum, operated by HTX (formerly Huobi) and associated with Justin Sun. On November 22, 2023, the bridge operator's private key was compromised, resulting in the theft of approximately $86.6 million in crypto assets; combined with a simultaneous HTX hot wallet breach, total losses reached approximately $99 million. Blockchain analytics firm Elliptic attributed the attack to North Korea's Lazarus Group, which subsequently laundered over $100 million of the proceeds through Tornado Cash. The HECO Network was permanently shut down on January 15, 2025.
avoid.net/abracadabra-spell→10/100[CRITICAL]Abracadabra.money is a multi-chain DeFi lending protocol that allows users to mint the MIM (Magic Internet Money) USD-pegged stablecoin using interest-bearing tokens as collateral. The protocol has been compromised three times since January 2024, losing a combined total of over $21 million, and its founding ecosystem was shaken in January 2022 when co-founder Daniele Sestagalli's associate — Wonderland's pseudonymous treasury manager known as 0xSifu — was publicly identified as Michael Patryn, a convicted felon and co-founder of the fraudulent exchange QuadrigaCX. The SPELL token has declined approximately 99.5% from its November 2021 all-time high, and the protocol's total value locked has collapsed from over $776 million to under $30 million.
avoid.net/tectonic→42/100[WARNING]Tectonic is a decentralized money market protocol on the Cronos blockchain, operating as a fork of Compound, that allows users to lend and borrow cryptocurrency assets. Launched in December 2021 by Gary Or (former CTO of Crypto.com) and incubated by Particle B and Cronos Labs, the protocol reached approximately $1 billion TVL at peak in early 2022 before collapsing over 95% alongside the broader crypto bear market. A disclosed reentrancy vulnerability in the staking contract was reported in March 2024 allowing potential extraction of millions in a single transaction, and a separate flash loan exploit in February 2024 resulted in approximately $250,000 in losses.
avoid.net/dolomite→32/100[WARNING]Dolomite is a decentralized money market and trading protocol originally launched on Ethereum in 2019 and migrated to Arbitrum in 2022. The protocol suffered a $1.8 million exploit in March 2024 due to a reentrancy vulnerability in a legacy 2019 Ethereum contract. The platform drew significant controversy in 2026 when Trump-affiliated World Liberty Financial (WLFI) used 5 billion WLFI tokens as collateral to borrow $75 million on Dolomite — a platform co-founded by WLFI's own chief technology officer — driving USD1 pool utilization to 93% and trapping ordinary depositors.
avoid.net/munchables→10/100[CRITICAL]Munchables is a Blast-chain NFT game that suffered a $62.5 million exploit on March 26, 2024, when a contractor later attributed to North Korea exploited a backdoor they had embedded in the project's upgradeable smart contracts before launch. The developer surrendered private keys and the full sum was recovered within approximately 24 hours, but the incident exposed fundamental failures in contractor due diligence and smart contract architecture.
avoid.net/solareum→12/100[CRITICAL]Solareum was a Solana-based Telegram trading bot that shut down on March 30, 2024 following a security exploit that drained approximately $523,000 (2,800+ SOL) from over 300 user wallets. Prosecutors later revealed in a January 2025 court filing that the Solareum team had unknowingly hired a North Korean (DPRK) developer in December 2023, who subsequently facilitated the theft of 6,045 SOL worth roughly $1.4 million; the FBI seized approximately $950,000 in USDT two months after the hack. The project offered no compensation to victims, deleted its website and community channels, and is no longer operational.
avoid.net/grand-base→5/100[CRITICAL]Grand Base was a decentralized real-world asset (RWA) synthetic trading protocol launched on Coinbase's Base layer-2 blockchain in early 2024. On April 15, 2024, the protocol suffered a critical security incident in which its deployer wallet was compromised, allowing an attacker to mint approximately 32.5 million unauthorized GB tokens and drain roughly $2 million in liquidity. The GB token subsequently lost over 99% of its value; no verified recovery or compensation plan has been confirmed, and the project's long-term operational status remains uncertain.
avoid.net/hedgey→18/100[CRITICAL]Hedgey is a token vesting, lockup, and claims protocol that served over 100 on-chain projects before suffering a critical smart contract exploit on April 19, 2024, resulting in the theft of approximately $44.7 million across Ethereum and Arbitrum. The vulnerability — a missing input validation check in the ClaimCampaigns.sol contract — was present despite two prior audits by ConsenSys Diligence. No confirmed recovery of stolen funds has been reported; Hedgey was subsequently acquired by Anchorage Digital in late 2025.
avoid.net/xbridge→12/100[CRITICAL]XBridge is a cross-chain bridge protocol built by SaitaChain (formerly Saitama Inu), designed to connect Ethereum Mainnet and BNB Chain. On April 24, 2024, the protocol suffered a $1.44 million exploit caused by a critical access-control vulnerability in its smart contracts, with stolen funds subsequently routed through Tornado Cash. The parent company, Saitama LLC, faces U.S. federal charges of wire fraud and market manipulation, with CEO Manpreet Kohli arrested in the UK in October 2024 and facing extradition proceedings.
avoid.net/yield-protocol→38/100[WARNING]Yield Protocol was a decentralized finance protocol offering fixed-rate, fixed-term borrowing and lending on Ethereum and Arbitrum, launched in October 2020 and funded by Paradigm. It suffered multiple security incidents including collateral damage from the March 2023 Euler Finance hack and a critical smart contract vulnerability patched via Immunefi in April 2023, before announcing a full wind-down in October 2023 citing insufficient demand and regulatory pressure. After official operations ceased in December 2023, abandoned smart contracts on Arbitrum were exploited in April 2024 for approximately $181,000 via a flash loan attack on pool balance discrepancies.
avoid.net/geniusai→28/100[WARNING]GNUS.AI (Genius Ventures, Inc.) is a decentralized AI computing platform that issues the GNUS token across Ethereum, Polygon, and Fantom networks. On May 5, 2024, the project suffered a $1.27 million exploit in which an attacker leveraged a Discord breach to steal private key material, mint 100 million counterfeit GNUS tokens, and sell them into live liquidity pools — causing the token price to collapse. The token has traded 98-99% below its all-time high and ZachXBT has flagged the entity as a concern in the crypto community.
avoid.net/alex→28/100[WARNING]ALEX (Automated Liquidity Exchange) is a decentralized finance protocol built on the Stacks blockchain, designed to bring DeFi capabilities to Bitcoin. The protocol has suffered two major security exploits: a $4.3 million hack in May 2024 attributed to North Korea's Lazarus Group via a private key compromise of its XLink bridge, and an $8.3 million exploit in June 2025 caused by a smart contract access control vulnerability. In both cases, ALEX Lab Foundation pledged full user reimbursement, though partial recovery of 2024 stolen funds remained ongoing as of mid-2025, and the native ALEX token has declined approximately 99.9% from its all-time high.
avoid.net/gala→28/100[WARNING]Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer and Wright Thurston whose GALA token has been at the center of two major controversies: a 2023 civil lawsuit alleging Thurston stole 8.6 billion GALA tokens (~$130M) from company wallets, and a separate May 2024 smart contract exploit in which an unauthorized minter minted 5 billion tokens worth approximately $200M. Both co-founders have filed competing civil suits alleging misappropriation of hundreds of millions of dollars, while Thurston also faces an unrelated SEC fraud action over a separate crypto mining venture.
avoid.net/okx-nft-aggregator→30/100[WARNING]OKX NFT Aggregator is the NFT marketplace and aggregation layer of OKX, one of the world's largest crypto exchanges, supporting over 21 blockchains and 32 aggregated markets. The product has been implicated in a smart contract storage-collision exploit (June 2024), operates within an exchange that pleaded guilty to U.S. AML violations and agreed to a $504 million DOJ settlement (February 2025), and saw its parent DEX aggregator suspended in March 2025 after North Korea's Lazarus Group used the broader OKX Web3 infrastructure to launder approximately $100 million from the Bybit hack. ZachXBT has flagged the entity in the context of these broader OKX platform concerns.
avoid.net/rho-markets→38/100[WARNING]Rho Markets is a DeFi lending protocol (Compound V2 fork) deployed on Scroll, an Ethereum Layer 2 ZK-rollup network. On July 19, 2024, a misconfigured price oracle allowed an MEV bot to extract approximately $7.6 million in user funds; the operator voluntarily returned all funds after demanding a public acknowledgment of the misconfiguration. Despite full fund recovery, the protocol's TVL collapsed to near-zero and remains essentially inactive as of 2026.
avoid.net/deltaprime→22/100[CRITICAL]DeltaPrime is a decentralized leveraged farming and lending protocol deployed on Arbitrum and Avalanche. The protocol suffered two major security exploits in 2024 — a $5.98 million private key compromise in September and a $4.8 million smart contract vulnerability in November — totaling over $10.7 million in losses. On-chain investigator ZachXBT alleged that DeltaPrime had previously employed North Korean IT workers with alleged ties to the DPRK-linked Lazarus Group, raising concerns about insider access as a contributing factor to the first exploit.
avoid.net/convergence→18/100[CRITICAL]Convergence (CVG) is an Ethereum-based DeFi yield-aggregation protocol built on top of Curve and Convex Finance. On August 1, 2024, an attacker exploited a missing input-validation check in the CvxRewardDistributor contract — introduced by a post-audit gas-optimization change — to mint 58 million CVG tokens and sell them for approximately $212,000, collapsing the token price by 99%. The protocol never recovered; following a community DAO vote, the team pivoted operations to a successor project called Tangent Finance (TGN).
avoid.net/onyx-v2→22/100[CRITICAL]Onyx Protocol is a Compound Finance fork and DeFi lending platform on Ethereum that launched a V2 iteration in 2024 following two devastating exploits — one in November 2023 ($2.1M) and a second in September 2024 ($3.8M) — both exploiting the same known vulnerability in the Compound V2 codebase. After the second hack, the community voted to shut down the Ethereum lending market and relaunch as Onyx Core; V2 targeting compliance with the U.S. CLARITY Act launched in Q3 2025 on a new XCN Ledger infrastructure. Total confirmed losses across both exploits exceed $5.9 million.
avoid.net/us-government-crypto-wallet→10/100[CRITICAL]The US government holds one of the largest concentrations of seized cryptocurrency in the world, accumulated through major law enforcement actions including the 2016 Bitfinex hack and the Silk Road darknet marketplace. In October 2024, a government-controlled wallet linked to Bitfinex seizure funds was drained of approximately $20 million in what was subsequently attributed to alleged insider theft by John Daghita, son of a US Marshals Service contractor, who was arrested in Saint Martin in March 2026 after a blockchain investigation by ZachXBT exposed the scheme.
avoid.net/thalaswap→62/100[CAUTIONARY]ThalaSwap is the decentralized exchange component of Thala Labs, an Aptos-based DeFi protocol offering an AMM, the Move Dollar (MOD) overcollateralized stablecoin, liquid staking, and a launchpad. On November 15, 2024, an input-validation bug introduced in a two-line patch to the v1 farming contract allowed an attacker to drain $25.5 million in liquidity pool tokens; funds were fully recovered within hours after SEAL 911 identified the exploiter via on-chain evidence and the attacker returned assets in exchange for a $300,000 bounty.
avoid.net/dexx→10/100[CRITICAL]DEXX is a Solana-based on-chain memecoin trading terminal that suffered a catastrophic private key compromise on November 16, 2024, resulting in approximately $30 million in user losses across more than 8,600 wallets. Despite marketing itself as non-custodial, DEXX stored user private keys in plaintext on its own servers — a centralization risk that CertiK had flagged as unresolved prior to the breach. A partial compensation initiative led by LBank was announced in early 2025, but full recovery of stolen funds remains unlikely as the attacker laundered substantial ETH through Tornado Cash.
avoid.net/spectral-labs→42/100[WARNING]Spectral Labs (spectrallabs.xyz) is a U.S.-based Web3 protocol founded in 2021 that pivoted from an on-chain credit scoring product (MACRO Score) to an autonomous AI agent economy platform. The project has raised approximately $30 million from institutional investors including General Catalyst, Social Capital, and Jump Capital. Its governance token SPEC reached an all-time high of approximately $18.48 in November 2024 before collapsing more than 99% to under $0.10 by mid-2026, with Bybit delisting the token from both spot and futures markets, raising significant concerns around tokenomics, unlock-driven selling pressure, and product-market fit.
avoid.net/vestra-dao→32/100[WARNING]Vestra DAO is an Ethereum-based DeFi and SocialFi protocol operating the VSTR token, launched in late 2024. On December 4, 2024, the protocol suffered a critical smart contract exploit in its staking contract that drained approximately $480,000–$500,000 worth of VSTR tokens — an attack that occurred less than one month after the token began trading. Stolen funds were laundered through Tornado Cash, the token price collapsed by roughly 50%, and the project's ability to fully compensate affected users remains unresolved.
avoid.net/fegex→22/100[CRITICAL]FEGex is a decentralized exchange (DEX) and DeFi launchpad built around the FEG (Feed Every Gorilla) token ecosystem, operating on Ethereum and BNB Chain. The protocol has suffered three separate security exploits between 2022 and 2024, resulting in cumulative losses exceeding $3.6 million and a near-total collapse of token value following the most recent incident. The team operates anonymously and the protocol has demonstrated a repeated inability to prevent critical smart contract vulnerabilities despite multiple third-party audits.
avoid.net/moonhacker→18/100[CRITICAL]MoonHacker is an independently deployed DeFi vault protocol built on Optimism that was designed to interact with the Moonwell lending protocol. On December 23, 2024, MoonHacker vault contracts suffered a flash loan exploit due to improper input validation and absent access controls in the executeOperation function, resulting in the loss of approximately $320,000 USDC. The Moonwell team confirmed no affiliation with MoonHacker, the vault deployers remain anonymous, and stolen funds were converted to DAI and routed through Tornado Cash, complicating recovery efforts.
avoid.net/hedera→55/100[CAUTIONARY]Hedera is a public distributed ledger technology platform using a patented hashgraph consensus mechanism, launched to mainnet in September 2019. In March 2023, the network suffered a protocol-level exploit in its Smart Contract Service that drained approximately $600,000 in liquidity pool tokens from three decentralized exchanges, requiring a full mainnet proxy shutdown for 41 hours. The platform operates under a council governance model comprising up to 39 global enterprises, which provides institutional stability but draws criticism for centralization relative to permissionless blockchains.
avoid.net/orange-finance→28/100[WARNING]Orange Finance is an Arbitrum-based automated liquidity management protocol designed for LPDfi (liquidity provider DeFi), enabling users to earn swap fees and options premiums via concentrated AMM vaults. On January 8, 2025, the protocol suffered a critical security breach in which an attacker compromised the admin private key, exploited a misconfigured multi-signature wallet that required only a single signature to execute, and drained approximately $843,556 across all active vaults. The protocol was flagged by ZachXBT and has not resumed normal operations since the incident.
avoid.net/unilend-v2→38/100[WARNING]UniLend V2 is a permissionless DeFi lending and borrowing protocol deployed on Ethereum mainnet in February 2024, designed to support all ERC-20 tokens via isolated dual-asset pools. On January 12, 2025, the protocol suffered a smart contract exploit that drained approximately $197,000 from its stETH pool due to a logic flaw in health factor calculations during the asset redemption process. Despite having been audited by PeckShield and SlowMist prior to launch, the exploited vulnerability was not caught or fully remediated, and as of the last available reporting the attacker's 20% bounty offer had not yielded a fund recovery.
avoid.net/zoth-zeusd→28/100[WARNING]Zoth is a Dubai-based real-world asset (RWA) restaking protocol and the issuer of ZeUSD, a CDP-style stablecoin backed by tokenized fixed-income assets including U.S. T-Bills and ETFs. In March 2025, the protocol suffered two separate security incidents within three weeks: a $285,000 logic-flaw exploit on March 1 and a critical $8.4–8.85 million admin key compromise on March 21, the latter resulting in the theft of 8.85 million USD0++ tokens. The stolen funds remain largely unrecovered as of mid-2025, with Zoth offering a $500,000 bounty and engaging Crystal Blockchain BV for forensic investigation.
avoid.net/sir→38/100[WARNING]SIR (Synthetics Implemented Right), operating as SIR.trading, is an Ethereum-based DeFi protocol offering non-liquidating leveraged tokens and synthetic assets. On March 30, 2025, just 39 days after its February 20 mainnet launch, the protocol's Vault contract was completely drained of its entire $355,000 TVL through an exploit targeting a novel misuse of Ethereum's transient storage (EIP-1153) introduced in the Dencun upgrade. The attacker laundered proceeds through Railgun; the founder publicly pleaded for a partial return of funds; the protocol subsequently relaunched after completing four additional security audits.
avoid.net/upcx→28/100[WARNING]UPCX is a blockchain payment protocol that suffered a $70 million exploit on April 1, 2025, when an attacker compromised an administrative private key and used it to push a malicious smart contract upgrade, draining 18.4 million UPC tokens from management accounts. The attack was enabled by the absence of multisig controls on privileged protocol functions, despite having undergone CertiK and Cyberscope audits that did not catch the operational key management risk. Despite listing on a Japanese FSA-licensed exchange just 11 days prior, no recovery of stolen funds was reported.
avoid.net/impermax-v3→32/100[WARNING]Impermax V3 is the third major iteration of Impermax Finance, a DeFi leveraged yield-farming and lending protocol that allows liquidity providers to use Uniswap V3 LP tokens as collateral. The protocol suffered two separate critical exploits in 2025 — a ~$300,000 flash-loan collateral valuation attack in April and a ~$380,000 liquidation logic exploit in November — both on the Base chain, resulting in cumulative losses exceeding $680,000 and leaving lenders with unresolved bad debt. These incidents follow a 2022 private key compromise affecting the IMX token, representing a recurring pattern of security failures across the protocol's history.
avoid.net/kalax→5/100[CRITICAL]Kalax (ticker: KALA) was a non-custodial yield aggregator deployed on the Blast and Scroll blockchains in 2024 that marketed itself as an auto-compounding protocol for DEXs and lending markets. Despite commissioning a Beosin security audit and publishing promotional security guarantees, the project's founders are alleged to have executed an exit scam on October 14, 2024, abandoning the protocol and deleting all official social media accounts after draining user funds from protocol vaults. The kalax.io domain subsequently redirected to an unrelated gambling site, with no team communications issued to affected depositors.