Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
Genesis Global Capital, LLC was the crypto lending arm of Digital Currency Group (DCG), founded in 2013 as the first institutional OTC bitcoin trading desk. Following catastrophic loan exposures to Three Arrows Capital and FTX in 2022, Genesis suspended customer withdrawals in November 2022 and filed for Chapter 11 bankruptcy in January 2023, owing approximately $3.4 billion to creditors. The company subsequently settled with the SEC for $21 million and with the New York Attorney General for $2 billion, completed a $4 billion restructuring distribution in August 2024, and in May 2025 its post-bankruptcy Litigation Oversight Committee filed dual lawsuits totaling $3.3 billion against parent DCG and CEO Barry Silbert alleging fraud and concealment of insolvency.
avoid.net/nexo→34/100[WARNING]Nexo is a crypto lending and yield platform founded in 2018 by Antoni Trenchev and Kosta Kantchev, incorporated in the Cayman Islands, that grew to over $11 billion in assets under management. The company paid a $45 million settlement to the SEC and a multistate coalition of regulators in January 2023 over the unregistered offer and sale of its Earn Interest Product, and exited the US market in late 2022. A Bulgarian criminal investigation launched simultaneously was closed in December 2023 for lack of evidence, after which Nexo filed a $3 billion ICSID arbitration claim against Bulgaria; Nexo formally reentered the US market in February 2026 in partnership with Bakkt.
avoid.net/ripple-labs→47/100[WARNING]Ripple Labs is a San Francisco-based financial technology company founded in 2012 that developed the XRP Ledger and issues the XRP token for cross-border payments. The company was the subject of a landmark five-year SEC enforcement action alleging a $1.3 billion unregistered securities offering, which concluded in August 2025 via joint dismissal of appeals following a 2024 court-imposed $125 million civil penalty. A 2023 federal court split ruling established that institutional XRP sales constituted unregistered securities while secondary market sales did not, making the case the first significant federal court ruling to distinguish token sale contexts under securities law.
avoid.net/wirecard-ag→0/100[CRITICAL]Wirecard AG was a German payment processor and financial services company headquartered in Munich that collapsed in June 2020 after revealing that approximately €1.9 billion in cash held in purported escrow accounts in the Philippines almost certainly did not exist. The scandal, described as the largest corporate fraud in postwar German history, implicated the company's senior leadership, exposed systemic failures by auditor Ernst & Young and German financial regulator BaFin, and revealed intelligence connections through fugitive COO Jan Marsalek, who is alleged to have been a Russian intelligence asset. Criminal proceedings against former CEO Markus Braun and co-defendants were ongoing in Munich as of early 2026, with no verdict yet reached.
avoid.net/bitfinex-hack→10/100[CRITICAL]On August 2, 2016, the Hong Kong-based cryptocurrency exchange Bitfinex was breached by Ilya Lichtenstein, who fraudulently authorized more than 2,000 transactions to steal 119,756 BTC valued at approximately $72 million at the time. The exchange socialized losses across all customers and issued BFX recovery tokens, redeeming them fully by April 2017. In February 2022, the U.S. Department of Justice arrested Lichtenstein and his wife Heather Morgan, seizing over $3.6 billion in Bitcoin in what was then the largest financial seizure in DOJ history; both pleaded guilty in August 2023 and were sentenced in November 2024.
avoid.net/celsius-network→0/100[CRITICAL]Celsius Network was a centralized crypto lending platform founded in 2017 that attracted over 1.7 million users and $20 billion in assets under management by offering yields of up to 18% on deposited cryptocurrency. In June 2022 the platform froze all withdrawals, subsequently filed for Chapter 11 bankruptcy in July 2022, and exposed a $1.2 billion balance sheet deficit. Founder and CEO Alex Mashinsky was arrested in July 2023, pleaded guilty to commodities fraud and securities fraud in December 2024, and was sentenced to 12 years in federal prison in May 2025.
avoid.net/terraform-labs→0/100[CRITICAL]Terraform Labs Pte. Ltd. was a Singapore-based blockchain company founded in 2018 by Do Kwon and Daniel Shin, best known for developing the Terra blockchain, the algorithmic stablecoin TerraUSD (UST), and the associated LUNA cryptocurrency. In May 2022, UST lost its dollar peg, triggering a collapse that wiped out approximately $40–45 billion in market capitalization within days. Following SEC civil fraud proceedings, a unanimous jury verdict in April 2024, and a $4.47 billion settlement, the company filed for Chapter 11 bankruptcy in January 2024 and received court approval to wind down operations in September 2024. Co-founder Do Kwon was sentenced to 15 years in federal prison in December 2025.
avoid.net/alex-mashinsky→0/100[CRITICAL]Alexander Mashinsky is the founder and former CEO of Celsius Network, a cryptocurrency lending platform that collapsed in July 2022 after freezing approximately $4.7 billion in customer assets. In December 2024, Mashinsky pleaded guilty to commodities fraud and a scheme to manipulate the price of Celsius's CEL token; he was sentenced to 12 years in federal prison in May 2025. Regulatory actions were brought by the DOJ, SEC, CFTC, and FTC.
avoid.net/quadrigacx→0/100[CRITICAL]QuadrigaCX was a Canadian cryptocurrency exchange founded in 2013 that collapsed in early 2019 following the death of its CEO Gerald Cotten in India in December 2018. The Ontario Securities Commission concluded in June 2020 that the exchange had operated as a fraud and Ponzi scheme, with Cotten using fictitious balances and customer funds for personal enrichment, causing losses of at least C$169 million across approximately 76,000 affected users.
avoid.net/voyager-digital→0/100[CRITICAL]Voyager Digital was a US-based cryptocurrency brokerage and lending platform founded in 2018 that grew to 3.5 million users and $5.9 billion in assets before filing for Chapter 11 bankruptcy on July 5, 2022, following a $650 million loan default by Three Arrows Capital. The company's collapse resulted in customers losing access to funds, multiple federal regulatory actions against the firm and its CEO Stephen Ehrlich, and the failure of two successive acquisition deals by FTX and Binance.US. After a court-approved liquidation plan in May 2023, creditors received partial distributions estimated at approximately 70% of claims across multiple tranches through 2024.
avoid.net/blockfi→38/100[WARNING]BlockFi was a cryptocurrency lending platform founded in 2017 by Zac Prince and Flori Marquez, once valued at $3 billion. The company faced a $100 million SEC and state regulator settlement in February 2022 for offering unregistered securities, then collapsed in November 2022 following the implosion of FTX, which had extended BlockFi a $400 million credit facility. After filing Chapter 11 bankruptcy, BlockFi achieved a notable outcome: all creditors received 100% recovery of allowed claims, funded largely by a $874.5 million settlement with FTX/Alameda Research.
avoid.net/three-arrows-capital→2/100[CRITICAL]Three Arrows Capital (3AC) was a Singapore-based cryptocurrency hedge fund founded in 2012 by Su Zhu and Kyle Davies that, at its peak in early 2022, managed an estimated $10 billion in assets. Severe losses from the Terra/LUNA ecosystem collapse in May 2022 triggered cascading margin calls and a liquidity crisis that led to court-ordered liquidation in the British Virgin Islands on June 27, 2022, leaving more than $3.5 billion in creditor claims. The founders subsequently faced arrest warrants, prison sentences for non-cooperation with liquidators, a nine-year regulatory ban by Singapore's Monetary Authority, and fines from Dubai's virtual asset regulator over a failed post-collapse exchange venture.
avoid.net/do-kwon→2/100[CRITICAL]Do Hyeong Kwon (born 1991) is a South Korean software engineer and former CEO of Terraform Labs, the company behind the Terra blockchain ecosystem, including the TerraUSD (UST) algorithmic stablecoin and the LUNA cryptocurrency. In May 2022, the Terra ecosystem collapsed, wiping out an estimated $40–45 billion in market capitalization within a week. Kwon was subsequently charged with fraud by U.S. federal prosecutors and the SEC, arrested in Montenegro in March 2023, extradited to the United States in December 2024, pleaded guilty in August 2025, and was sentenced to 15 years in federal prison in December 2025.
avoid.net/sam-bankman-fried→0/100[CRITICAL]Sam Bankman-Fried (SBF) is the co-founder and former CEO of FTX, a now-bankrupt cryptocurrency exchange, and Alameda Research, a crypto trading firm. In November 2022, FTX collapsed after it was revealed that approximately $8 billion in customer funds had been misappropriated and transferred to Alameda Research without customer consent. Bankman-Fried was convicted on all seven criminal counts on November 2, 2023, and sentenced to 25 years in federal prison on March 28, 2024.
avoid.net/mt-gox→2/100[CRITICAL]Mt. Gox was a Tokyo-based Bitcoin exchange that, at its peak in 2013–2014, handled approximately 70% of all global Bitcoin transactions. In February 2014 it suspended trading and filed for bankruptcy after disclosing the loss of approximately 850,000 BTC — later revised to approximately 650,000 BTC net — due to theft that investigators determined began as early as late 2011. Creditor repayment proceedings under civil rehabilitation law have been ongoing since 2018, with partial distributions commencing in July 2024 and a current deadline of October 31, 2026.
avoid.net/paintswap→57/100[CAUTIONARY]PaintSwap is a decentralized NFT marketplace and DeFi protocol originally launched on the Fantom Opera blockchain in May 2021, which migrated to the Sonic chain (formerly Fantom) in late 2024. The platform operates an open NFT marketplace, an AMM DEX, yield farming, and an on-chain idle MMORPG called Estfor Kingdom, all powered by its native BRUSH token. No confirmed rug pull, hack, or regulatory action has been identified; the primary documented incident is a domain hijacking by a third-party registrar in October 2025.
avoid.net/aave→74/100[CAUTIONARY]Aave is a decentralized, non-custodial liquidity protocol built on Ethereum and multiple other blockchains, enabling users to supply assets to earn interest or borrow against overcollateralized positions. Founded in 2017 as ETHLend by Finnish lawyer Stani Kulechov, it rebranded to Aave in 2020 and grew into the largest DeFi lending platform by total value locked, holding roughly 60% market share in DeFi lending. A multi-year SEC investigation into the AAVE token closed without enforcement in December 2025. In April 2026 Aave was a downstream victim of the $292 million Kelp DAO rsETH bridge exploit (attributed to North Korea's Lazarus Group): the attacker used now-unbacked rsETH as collateral to borrow roughly $190 million, leaving Aave with bad debt and triggering an $8.45 billion, 48-hour deposit run that cut TVL from ~$45.8B to ~$28.6B. Aave's own smart contracts were not exploited — the loss stemmed from accepting compromised external collateral. The protocol led the industry-wide 'DeFi United' restitution coalition (raising over $300 million in ETH), pursued recovery of roughly $71 million in frozen attacker funds in U.S. court, and restored rsETH operations by late May 2026. Residual concerns are the bad-debt overhang from the April incident and ongoing governance tensions between token holders and Aave Labs, but the protocol remains a fundamentally legitimate blue-chip lending platform.
avoid.net/bitconnect→0/100[CRITICAL]BitConnect was a cryptocurrency lending platform and exchange that operated from February 2016 until January 2018. It raised an estimated \$2.4 billion from investors worldwide through a fraudulent lending program that falsely claimed to use a proprietary volatility trading bot to generate daily returns of up to 1%. Subsequent U.S. federal investigations confirmed it operated as a classic Ponzi scheme; its founder Satish Kumbhani remains a fugitive as of 2025, while lead U.S. promoter Glenn Arcaro was sentenced to 38 months in federal prison.
avoid.net/axiom→32/100[WARNING]Axiom (axiom.trade) is a Y Combinator-backed Solana trading terminal launched in January 2025 by co-founders Henry Zhang and Preston Ellis. The platform grew rapidly to become the dominant Solana memecoin trading interface, generating over $300 million in fees within 263 days. In February 2026, crypto investigator ZachXBT published an exposé alleging that multiple Axiom employees abused internal 'admin dashboard' access controls to surveil private user wallet data and conduct insider trading over a period of approximately 13 months.
avoid.net/alameda-research→0/100[CRITICAL]Alameda Research LLC was a quantitative cryptocurrency trading firm founded in November 2017 by Sam Bankman-Fried that served as the primary vehicle for one of the largest financial frauds in U.S. history. Alongside FTX, which Bankman-Fried founded in 2019, Alameda secretly borrowed and misappropriated approximately $8 billion in FTX customer deposits, using the funds for risky trading, venture investments, real estate, and political donations. The collapse of FTX and Alameda in November 2022 triggered criminal convictions for multiple executives, a 25-year prison sentence for Bankman-Fried, and a $12.7 billion CFTC judgment.
avoid.net/pump-fun→0/100[CRITICAL]Pump.fun (operated by Baton Corporation Ltd.) is a Solana-based memecoin launchpad that launched on January 19, 2024, enabling users to create and trade tokens within seconds for a fraction of a cent. Despite generating over $1 billion in cumulative platform revenue by late 2025, the platform faces a consolidated federal class-action lawsuit alleging operation of an unregistered securities exchange, insider exploitation of MEV infrastructure, and a whistleblower-sourced cache of 5,000+ internal messages alleged to show coordinated market manipulation. Third-party research classifies 98.6% of tokens launched on the platform as rug pulls or pump-and-dump schemes, and North Korea's Lazarus Group has been linked by on-chain investigator ZachXBT to laundering attempts through the platform using fake memecoins after the February 2025 Bybit hack.
avoid.net/africrypt→0/100[CRITICAL]Africrypt was a South African cryptocurrency investment platform founded in 2019 by brothers Raees and Ameer Cajee. In April 2021, the platform abruptly shut down following an alleged hack, after which the founders fled South Africa with investor funds. The case became one of the most prominent alleged cryptocurrency exit scams in African history, though the exact amount lost remains disputed.
avoid.net/alameda→0/100[CRITICAL]Alameda Research was a cryptocurrency trading firm co-founded by Sam Bankman-Fried in 2017 that became central to one of the largest financial frauds in US history. The firm secretly used billions in [[ftx|FTX]] customer funds for trading and investments, leading to both companies filing for bankruptcy in November 2022.
avoid.net/coindash→28/100[WARNING]CoinDash was an Israeli-founded cryptocurrency portfolio management and social trading platform that conducted an ICO in July 2017. Thirteen minutes into its token sale, an attacker compromised the company's website and substituted a fraudulent Ethereum address, diverting approximately 43,500 ETH (valued at roughly $7-10 million at the time) from over 2,000 investors before the sale was halted. The company later rebranded as Blox and has since ceased operations; the CDT token retains minimal trading volume.
avoid.net/trinity-wallet→28/100[WARNING]Trinity Wallet was the official desktop and mobile software wallet for the IOTA cryptocurrency, developed and maintained by the IOTA Foundation. In February 2020, a supply chain attack exploiting a compromised MoonPay SDK delivered via CDN resulted in the theft of approximately 8.55 Ti (teraIOTA) worth roughly $2 million from 50 user seeds, forcing the IOTA Foundation to shut down the entire IOTA network for 27 days. Trinity was subsequently deprecated in April 2021 following the Chrysalis protocol upgrade, with the Firefly wallet introduced as its replacement.
avoid.net/origin-protocol→38/100[WARNING]Origin Protocol is a San Francisco-based DeFi and NFT platform founded in 2017 by Josh Fraser and Matthew Liu, best known for its yield-bearing stablecoin Origin Dollar (OUSD) and Origin Ether (OETH). In November 2020, before completing any security audit, OUSD was exploited via a reentrancy flash-loan attack resulting in approximately $7.7 million in losses including over $1 million from the team's own treasury. The protocol subsequently completed multiple audits, compensated affected users, and relaunched; it has continued operating with expanded DeFi yield products through 2025, though the OGN token trades at a fraction of its 2021 all-time high.
avoid.net/warp-protocol→22/100[CRITICAL]Warp Protocol refers to two distinct but both risk-flagged entities: (1) Terraform Labs' Cosmos-based on-chain automation protocol, shut down by December 2024 following the $40 billion Terra/Luna collapse and a $4.47 billion SEC settlement against Do Kwon and Terraform Labs; and (2) Warp Finance, an Ethereum DeFi lending protocol that suffered a $7.76 million flash loan exploit in December 2020, which ZachXBT linked to Omar Zaki, a Yale graduate who had previously settled SEC fraud charges for $25,000 in 2019 while operating an unregistered hedge fund. ZachXBT's February 2022 investigation alleged that Zaki operated both Warp Finance and Force DAO under the pseudonym '0xbrainjar' while concealing his SEC enforcement history from the Composable Finance community.
avoid.net/growth-defi→28/100[WARNING]Growth DeFi is a Binance Smart Chain (BSC) yield aggregator and DeFi ecosystem founded in 2020, offering the GRO governance token, the WHEAT yield optimizer, and the MOR overcollateralized stablecoin. On February 8, 2021, the protocol suffered a flashloan price oracle exploit targeting its stkGRO/rAAVE staking contract, resulting in approximately $1.3–1.4 million in stolen funds with no full recovery. As of 2026, the protocol has an extremely low TVL of roughly $22,000 and the GRO token trades at near-zero valuations, indicating near-complete abandonment.
avoid.net/dodo-amm→42/100[WARNING]DODO is a decentralized exchange (DEX) protocol launched in 2020, operating across 14 EVM-compatible chains, and known for its proprietary Proactive Market Maker (PMM) algorithm that concentrates liquidity near market price. On March 8, 2021, an attacker exploited a critical initialization vulnerability in DODO's V2 Crowdpooling smart contracts, draining approximately $3.8 million across four pools; roughly $3.1 million was subsequently recovered through voluntary restitution and frontrunning bot operator cooperation. The protocol continues to operate and has undergone multiple third-party security audits post-exploit, though it has lost significant market share and TVL since its 2021 peak.
avoid.net/turtle-dex→2/100[CRITICAL]TurtleDex (TTDX) was a Binance Smart Chain decentralized file-storage protocol that conducted a confirmed exit scam on March 19, 2021, approximately 72 hours after its presale closed. The anonymous development team drained 9,000 BNB (approximately $2.5 million) from liquidity pools on PancakeSwap and ApeSwap, converted the proceeds to ETH split across nine wallets, and routed the funds to Binance exchange addresses before deleting all official channels. No funds are known to have been recovered and no perpetrators have been publicly identified.
avoid.net/autoshark→14/100[CRITICAL]AutoShark Finance was a Binance Smart Chain-based yield optimizer and AMM that suffered two separate economic exploits in 2021, resulting in total losses exceeding $1.4 million in BNB across its SHARK and JAWS tokens. The protocol underwent multiple failed recovery attempts — including token migrations from SHARK to JAWS and a new reserve-currency token ATLAS — before formally shutting down in March 2022 after all three tokens had lost 97–99.75% of their peak value. AutoShark has been flagged by ZachXBT in the context of the wider BSC flash loan attack wave that targeted PancakeBunny forks.
avoid.net/merlin→4/100[CRITICAL]Merlin DEX was a decentralized exchange built on zkSync Era that was drained of approximately $1.82 million on April 26, 2023, during its public MAGE token liquidity generation event. Security investigators, including auditor CertiK, concluded the incident was an insider rug pull executed by the protocol's own back-end development team, who had embedded a backdoor granting themselves unlimited withdrawal rights over all liquidity pools. The rogue developers, allegedly a group of Serbian nationals, have never been publicly identified or prosecuted, and no meaningful recovery of stolen funds has been confirmed. This entity is distinct from Merlin Chain, an unrelated Bitcoin Layer 2 protocol.
avoid.net/alchemix-v2→48/100[WARNING]Alchemix V2 is a DeFi self-repaying loan protocol on Ethereum that allows users to borrow synthetic assets (alUSD, alETH) against yield-bearing collateral, with loans auto-repaid by yield generated from underlying deposits. The protocol experienced two notable security incidents: a June 2021 smart contract bug in the alETH vault that allowed users to withdraw collateral without repaying loans (the 'reverse rug pull,' ~$6.5M shortfall), and an indirect July 2023 exploit via a Vyper compiler vulnerability in a Curve liquidity pool (~$13.6M drained, later fully returned). In both cases, the Alchemix team responded promptly and took active steps to restore protocol solvency, distinguishing it from many exploited DeFi protocols.
avoid.net/eleven-finance→32/100[WARNING]Eleven Finance is a yield optimizer and leveraged yield farming protocol deployed on Binance Smart Chain (BSC) and Polygon. On June 22, 2021, attackers exploited a critical smart contract vulnerability in the protocol's Nerve-partnership vaults, draining approximately $4.5–4.8 million. The team published a recovery plan, repaid an initial 25% tranche from personal debt, and later announced full principal recovery; however, the ELE token has since lost over 99% of its value from its all-time high, and the protocol appears largely inactive.
avoid.net/safe-dollar→4/100[CRITICAL]Safe Dollar (SDO) was an algorithmic stablecoin launched on the Polygon network in June 2021 that collapsed to zero within two weeks of its initial DEX offering. The protocol suffered two separate exploits in rapid succession, with the second draining approximately $248,000 in USDC and USDT from its liquidity pools by exploiting a reward-calculation flaw that allowed unlimited SDO minting. The project was flagged as a high-risk entity by on-chain investigators and DeFi security researchers, and its stablecoin peg was never restored.
avoid.net/thorchain-dex→28/100[WARNING]THORChain is a decentralized cross-chain liquidity protocol that enables native asset swaps across blockchains without wrapped tokens, using its RUNE token as settlement collateral. Since its mainnet launch, the protocol has suffered three significant exploit events totaling over $25 million in losses, became the primary laundering conduit for North Korea's Lazarus Group following the 2025 Bybit hack ($1.2 billion routed through the network), and its THORFi lending product collapsed in January 2025 with approximately $200 million in user funds frozen. The protocol faces ongoing legal action from creditors, has lost key developers over ethical disputes about blocking illicit transactions, and experienced a further $10.8 million vault breach in May 2026.
avoid.net/surgebnb→22/100[CRITICAL]SurgeBNB was a BEP-20 yield token on Binance Smart Chain operated by the XSurge DeFi project. On August 16–17, 2021, an attacker exploited a reentrancy vulnerability in the contract's sell() function via a flash loan, draining approximately 13,111 BNB (~$5 million USD) from the protocol. The project had publicly claimed to be 'rug-proof' prior to the exploit; post-hack, the team launched a 'SurgeFund' compensation scheme, though the extent and completion of repayment to victims remains unclear.
avoid.net/siren→18/100[CRITICAL]SIREN is a BNB Chain-based token launched in early 2025, marketed as an on-chain AI agent analyst. In March 2026, blockchain investigator ZachXBT and analytics firm Bubblemaps identified that a single wallet cluster controlled nearly 50% of the circulating supply and linked those wallets on-chain to DWF Labs, alleging coordinated market manipulation. The token subsequently crashed over 70% from its all-time high within 24 hours. The SIREN name is also shared by a separate, earlier Ethereum-based DeFi options protocol (Siren Markets) that suffered a $3.5 million reentrancy exploit in September 2021.
avoid.net/zabu-finance→52/100[CAUTIONARY]Zabu Finance was an Avalanche-based yield farming protocol that suffered a $3.2 million flash loan exploit on September 12, 2021, marking what was widely described as the first major DeFi hack on the Avalanche blockchain. The vulnerability — a known deflationary token accounting flaw that had already been exploited on Polygon two months prior — drained the protocol's SPORE staking pool and caused the ZABU token to collapse from approximately $0.004 to near-zero. The protocol attempted a v2 token relaunch but has since gone effectively dormant, with a TVL of approximately $5,000 and a website SSL certificate that expired in August 2022.
avoid.net/jaypegs-automart→38/100[WARNING]JayPegs Automart (also styled Jay Pegs Auto Mart) is an Ethereum-based NFT and token project launched in September 2021 by the anonymous team behind NGMI.global, themed as a satirical used-car dealership selling 2007 Kia Sedona NFTs. On September 17, 2021, a contractor injected malicious code into the SushiSwap MISO auction front end during the project's DONA token sale, redirecting approximately $3.1 million (864.8 ETH) to the attacker's wallet. Funds were fully recovered within 24 hours following public identification of the alleged attacker and threat of FBI referral.
avoid.net/8ightdao→18/100[CRITICAL]8ight Finance (also referred to as 8ightDAO) was an OHM fork launched on the Harmony blockchain in October 2021, positioning itself as a relief project for victims of the Snowdog DAO rug pull. In December 2021, approximately $1.75 million in treasury stablecoins was drained after the team admitted to transmitting private keys through Facebook group chat and Google Drive. The incident is disputed: community members alleged an intentional rug pull while the team claimed external compromise, but funds were sent to Tornado Cash making attribution impossible.
avoid.net/gamma→28/100[WARNING]Gamma Strategies is a DeFi active liquidity management (ALM) protocol built on Uniswap v3 and other concentrated-liquidity DEXs, formerly known as Visor Finance. The protocol suffered a significant flash loan exploit on January 4, 2024, resulting in losses of approximately $6.18 million across four vaults on Arbitrum; the attacker laundered the majority of stolen funds through Tornado Cash. This was not the protocol's first security incident: its predecessor Visor Finance lost approximately $8.2 million to an infinite mint vulnerability in December 2021, leading to a rebrand.
avoid.net/fantasm-finance→18/100[CRITICAL]Fantasm Finance was a fractional-algorithmic synthetic token protocol on the Fantom Opera blockchain, designed to maintain a synthetic FTM token (XFTM) backed partially by FTM collateral and partially by the protocol's native FSM token. On March 9, 2022, within days of its public launch, the protocol suffered a critical smart contract exploit that drained approximately $2.62 million from its collateral reserve pool. The attacker laundered the stolen funds through Tornado Cash and was never publicly identified; the protocol has since ceased operations with zero TVL remaining.
avoid.net/paraluni-masterchef→18/100[CRITICAL]Paraluni is a metaverse DeFi yield-farming protocol deployed on Binance Smart Chain (BSC). On March 13, 2022, its MasterChef smart contract was exploited via a reentrancy vulnerability in the depositByAddLiquidity function, resulting in approximately $1.7 million in losses. The attacker laundered the proceeds through Tornado Cash and never returned funds despite a public appeal from the Paraluni team.
avoid.net/revest-finance→28/100[WARNING]Revest Finance is an Ethereum DeFi protocol that tokenizes ERC-20 assets into Financial NFTs (FNFTs) using the ERC-1155 standard, allowing users to lock and manage assets with programmable release conditions. On March 27, 2022, the protocol suffered a reentrancy attack that resulted in approximately $2 million in user funds stolen, with the team publicly acknowledging it lacked the resources to fully reimburse victims. The protocol remains technically active with extremely low TVL and a token (RVST) that has declined over 99% from its all-time high.
avoid.net/nirvana-v1→5/100[CRITICAL]Nirvana V1 was a Solana-based algorithmic stablecoin and yield protocol that operated twin tokens: ANA (an algorithmic metastable wealth token) and NIRV (a decentralized stablecoin). On July 28, 2022, the protocol was catastrophically exploited via a flash loan attack that drained approximately $3.5 million — representing nearly all protocol reserves — causing both tokens to collapse and forcing a permanent shutdown. The attacker, Shakeeb Ahmed, was later identified, arrested, and convicted in the first-ever U.S. criminal prosecution for hacking a smart contract, and was sentenced to three years in prison in April 2024.
avoid.net/blur-finance→2/100[CRITICAL]Blur Finance (ticker: BLR) was a yield aggregator DeFi protocol that operated on BNB Chain and Polygon in mid-2022. In August 2022, developers allegedly executed a textbook rug pull, withdrawing approximately $600,000 from user-deposited funds before deleting all social media channels and abandoning the project. The BLR token collapsed 99%, and the protocol's smart contracts on both chains have since been formally flagged on BscScan and PolygonScan as rug pull addresses.
avoid.net/kyberswap-classic→28/100[WARNING]KyberSwap is a decentralized exchange (DEX) and liquidity protocol operated by Kyber Network. In November 2023, KyberSwap Elastic — the protocol's concentrated liquidity layer — suffered one of the largest DEX exploits of the year, with approximately $48.9 million drained across thirteen chains via a sophisticated tick-manipulation and rounding-error attack. The alleged attacker, Canadian national Andean Medjedovic, was subsequently indicted by U.S. federal prosecutors on five felony counts and remains a fugitive as of mid-2026.
avoid.net/bond-protocol→42/100[WARNING]Bond Protocol is a permissionless bonds-as-a-service platform for DeFi, spun out of OlympusDAO's Olympus Pro product via a governance vote in mid-2022. In October 2022 — just weeks after its public launch — the protocol's Fixed-Expiry Teller smart contract was exploited for approximately $300,000 in OHM tokens due to a missing input validation vulnerability that had evaded three prior independent audits. The attacker ultimately returned all funds, the team underwent re-auditing with Zellic and Sherlock, and the protocol raised $2.5M in seed funding, though its TVL has since declined to minimal levels.
avoid.net/lodestar-v0→22/100[CRITICAL]Lodestar V0 is the original deployment of Lodestar Finance, an algorithmic money market lending protocol on Arbitrum. On December 10, 2022, the protocol suffered a critical flash loan exploit in which an attacker manipulated the plvGLP price oracle to drain approximately $6.9 million in user funds. The protocol was subsequently relaunched as Lodestar V1 in July 2023; V0 remains abandoned with negligible TVL (~$95K) and the attacker was never publicly identified.
avoid.net/elasticswap→22/100[CRITICAL]ElasticSwap was an Avalanche-first AMM protocol specializing in elastic supply tokens, which launched in May 2022 and was exploited in December 2022 for approximately $854,000 via flash loan attacks that exploited an accounting inconsistency between its addLiquidity and removeLiquidity functions. The vulnerability class that enabled the exploit had been identified in a Code4rena security audit conducted ten months earlier but was not adequately remediated before deployment. The protocol recovered approximately 55% of user funds through a bounty program and community vote, but the TIC governance token lost over 70% of its value and the protocol appears to have ceased meaningful activity.
avoid.net/raydium-amm→62/100[CAUTIONARY]Raydium is a leading Solana-based automated market maker (AMM) and decentralized exchange (DEX) launched in February 2021 by a pseudonymous team. On December 16, 2022, a compromise of the protocol's admin private key enabled an attacker to drain approximately $4.4 million from eight liquidity pools; the stolen funds were subsequently laundered through Tornado Cash in January 2023. The team implemented a phased compensation plan and post-incident security upgrades, including migration of admin authority to a Squads multisig, but the incident exposed significant centralization risks that were not apparent prior to the exploit.
avoid.net/amun→38/100[WARNING]Amun refers to two related but distinct entities: Amun AG, a Swiss ETP issuer that rebranded to 21Shares in 2020 and lists regulated crypto exchange-traded products on the SIX Swiss Exchange; and Amun Ltd / Amun DeFi Tokens, a separate DeFi arm that issued leveraged tokens and on-chain index products on Ethereum and Polygon. The DeFi arm experienced a critical smart contract exploit on December 26, 2022 resulting in approximately $300,000 in losses, followed by the termination of multiple product lines. On-chain investigator ZachXBT has been cited in connection with flagging Amun, though a specific, verifiable public post could not be independently confirmed at the time of this investigation.
avoid.net/roe-finance→28/100[WARNING]Roe Finance is a decentralized lending protocol built on Ethereum that allows Uniswap v2 liquidity providers to lend LP tokens for additional yield. On January 11, 2023, the protocol suffered a flash loan-driven price oracle manipulation exploit that drained approximately $80,000 from its pools, with the majority of profits captured by a front-running MEV bot rather than the original attacker. The protocol issued no official post-mortem or public response to the incident, raising concerns about transparency and operational accountability.
avoid.net/lendhub→18/100[CRITICAL]LendHub was a decentralized cross-chain lending protocol operating primarily on the Huobi Eco Chain (HECO) and Binance Smart Chain (BSC). On January 12, 2023, the protocol suffered an approximately $6 million exploit caused by an operational failure to remove a deprecated IBSV cToken from its market, allowing an attacker to drain funds by arbitraging the two coexisting token versions. The protocol's TVL collapsed to near zero following the exploit, stolen funds were laundered through Tornado Cash, and the protocol is no longer considered operational.
avoid.net/dfx-v2→28/100[WARNING]DFX Finance is a decentralized foreign exchange protocol optimized for trading fiat-backed stablecoins such as CADC, EURS, and XSGD, backed by investors including Polychain Capital. On November 10, 2022, the V2 smart contracts were exploited via a reentrancy vulnerability in the flash loan function, resulting in approximately $7.5 million in total losses split between a primary attacker (~$4.3M) and an MEV front-running bot (~$3.2M). The stolen funds were funneled into Tornado Cash; the protocol subsequently paused all contracts, launched a DFX-token reimbursement plan, and later released V3, but TVL remains near zero as of 2024.
avoid.net/omm→28/100[WARNING]Omm (Open Money Market) is a decentralized lending and borrowing protocol built on the ICON blockchain, launched in August 2021 by Lydia Labs (formerly ICX Station), co-founded by Scott Smiley and Daeki Lee. On January 21, 2023, the protocol suffered a smart contract exploit in which an attacker deployed a malicious contract to drain approximately $1.9 million in user collateral across 18 transactions, exploiting a critical flaw in the Redeem function. Following the exploit, the protocol pivoted away from its money market model toward a liquid staking product, which launched in January 2024, though TVL and market activity remain minimal.
avoid.net/bonqdao→18/100[CRITICAL]BonqDAO was a Polygon-based decentralized lending protocol that launched in December 2022, offering zero-interest borrowing against crypto collateral with a native euro-pegged stablecoin (BEUR). On February 1, 2023, the protocol suffered a critical oracle manipulation exploit in which an attacker staked approximately $175 worth of TRB tokens to manipulate the Tellor price feed for the WALBT collateral token, minting 100 million BEUR against near-zero collateral and liquidating other users for an additional 113 million WALBT, resulting in nominal losses of approximately $120 million. BonqDAO's TVL fell by over 99% following the attack; a successor protocol (3A DAO) was subsequently launched by the team but BonqDAO itself remains effectively defunct.
avoid.net/platypus-finance→28/100[WARNING]Platypus Finance is an Avalanche-based stablecoin automated market maker (AMM) and issuer of the USP stablecoin that suffered three separate exploits in 2023, losing a combined total of approximately $11.75 million. The first and most severe attack in February 2023 exploited a logic flaw in the protocol's emergency withdrawal function, draining roughly $8.5–9.1 million and causing the USP stablecoin to lose its dollar peg. Two French brothers identified by blockchain investigator ZachXBT were arrested and later acquitted on criminal charges after one argued he was an 'ethical hacker'; as of 2024 the protocol's total value locked had collapsed from over $200 million at peak to below $100,000.
avoid.net/hope-finance→4/100[CRITICAL]Hope Finance was an Arbitrum-based DeFi protocol that launched in January 2023, positioning itself around an algorithmic stablecoin pegged to 0.001 ETH. On February 20, 2023 — the same day the platform went live — approximately $2 million (1,095 ETH) was drained from its Genesis Rewards Pool in what blockchain security firms CertiK and PeckShield assessed as an insider-orchestrated exit scam, making it the largest exit scam recorded on Arbitrum at that time. Stolen funds were bridged to Ethereum and routed through Tornado Cash; the protocol's website subsequently went offline and the team became unreachable.
avoid.net/dexible-v2→18/100[CRITICAL]Dexible V2 is a multichain DEX aggregator that suffered a critical smart contract exploit on February 17, 2023, resulting in approximately $2 million in user funds stolen across Ethereum and Arbitrum. The attack exploited an unvalidated router address in the selfSwap function of the v2 contracts, which had never undergone a formal third-party security audit. Stolen funds were laundered through Tornado Cash and have not been recovered; the protocol has since ceased operations.
avoid.net/arbiswap→2/100[CRITICAL]ArbiSwap was a decentralized exchange (DEX) launched on the Arbitrum network in February 2023 that executed a rug pull on March 2, 2023, approximately six days after launch, stealing roughly 84 ETH (over $100,000) from users and moving the proceeds through Tornado Cash. The anonymous developer exploited a hidden 'recoverToken' function in a swapped smart contract to drain liquidity pools while the ARBI governance token collapsed more than 99% in value. The project attracted $4.4 million in total value locked by advertising unsustainable yields above 1,000% APY before abandoning the protocol and going silent.
avoid.net/tender-finance→32/100[WARNING]Tender Finance (tender.fi) was an Arbitrum-based decentralized lending and borrowing protocol that suffered a $1.59 million oracle misconfiguration exploit on March 7, 2023. A white hat hacker exploited a decimal precision error in the GMX price oracle, depositing one GMX token worth approximately $71 to borrow nearly $1.6 million in assets. The hacker returned funds in exchange for a $97,000 bounty, and the project subsequently rebranded to GLend under the Gemach DAO umbrella, migrating its TND token to GLEND and later to GMAC.
avoid.net/zircon-gamma→32/100[WARNING]Zircon Gamma was a Moonriver-deployed automated market maker (AMM) built by Zircon Labs that pioneered single-sided liquidity provision via its Pylon risk-tranching mechanism. On March 18, 2023, an attacker exploited a vulnerability in the protocol's modified Uniswap V2 core across both its Moonriver and BNB Chain deployments, draining approximately $350,000 in user funds. Following the exploit, the ZRG token lost essentially all market value, development activity ceased by mid-2023, and the promised relaunch and debt-repayment plan have not been publicly demonstrated as fulfilled.
avoid.net/safemoon→0/100[CRITICAL]SafeMoon was a BNB Chain-based DeFi token launched in March 2021 that rapidly attracted retail investors through celebrity endorsements and social media hype, reaching a peak market capitalization of approximately $17 billion. Federal prosecutors and the SEC charged the project's founders and executives in November 2023 with securities fraud, wire fraud, and money laundering, alleging they secretly misappropriated over $200 million from the liquidity pool for personal enrichment. CEO Braden John Karony was convicted on all counts in May 2025 and sentenced to 100 months in prison in February 2026; CTO Thomas Smith pleaded guilty in February 2025; founder Kyle Nagy remained a fugitive as of early 2026.
avoid.net/allbridge-core→42/100[WARNING]Allbridge Core is a cross-chain stablecoin bridge protocol operating across EVM-compatible chains, Solana, Tron, and Stellar. On April 1-2, 2023, the protocol suffered a flash loan price-manipulation exploit on BNB Chain that drained approximately $570,000 from its BUSD and USDT liquidity pools. The attacker was subsequently identified via on-chain analysis by BNB Chain and AvengerDAO, and ultimately returned roughly $465,000 of the stolen funds after Allbridge offered a white hat bounty with immunity from legal action.
avoid.net/0vix→28/100[WARNING]0VIX was a DeFi lending protocol built on Polygon PoS and Polygon zkEVM, forked from the Compound v2 codebase, that launched as one of Polygon zkEVM's inaugural partners. On April 28, 2023, an attacker exploited a price oracle vulnerability in the protocol's vGHST market using a flash loan, draining approximately $2 million in user funds from a total TVL of $6.4 million. Stolen funds were bridged to Ethereum via Stargate Finance and deposited into Tornado Cash; the attacker did not respond to a $125,000 bounty offer. The protocol subsequently rebranded as Keom in August 2023.
avoid.net/swaprum→2/100[CRITICAL]Swaprum was an Arbitrum-based decentralized exchange (DEX) that launched in early 2023 and operated briefly before its anonymous development team executed a deliberate exit scam on May 18, 2023. The team exploited a backdoor function embedded in an upgraded smart contract to drain approximately 1,628 ETH (roughly $3 million) from user liquidity pools, then laundered the proceeds through Tornado Cash and deleted all official communication channels. No funds have been recovered and no arrests have been publicly reported.
avoid.net/local-traders→22/100[CRITICAL]Local Traders (localtraders.finance) is a peer-to-peer cryptocurrency exchange and native token (LCT) project launched in 2021, headquartered in Chile and targeting Latin American and African markets. On May 23, 2023, the platform's smart contract was exploited due to a missing access-control check, resulting in approximately 379 BNB (~$119,000) stolen from its liquidity pool. The LCT token has since declined approximately 99.9% from its all-time high, the platform has shown limited trading volume, unverified team credentials, and a lack of regulatory registration, and the project was flagged by on-chain investigator ZachXBT.
avoid.net/keep3r-network→42/100[WARNING]Keep3r Network (KP3R) is a decentralized keeper-job matching protocol launched in October 2020 by Andre Cronje, the creator of Yearn Finance. The protocol has experienced multiple security incidents including a $211k exploit in June 2023, a latent two-year-old vulnerability in its GaugeProxyV2 contract discovered in September 2022, and its oracle was implicated in the $15.6M Inverse Finance hack of April 2022. ZachXBT has flagged the protocol in the context of broader DeFi security concerns, and the project has been surrounded by scam forks, impersonator accounts, and fraudulent staking services operated by unaffiliated parties.
avoid.net/tropykus-rsk→44/100[WARNING]Tropykus is a DeFi lending and borrowing protocol deployed on the Rootstock (RSK) Bitcoin sidechain, founded in 2021 by a Colombian team targeting Latin American underbanked communities. On June 14, 2023, the protocol suffered an exploit in its rBTC micro-market due to a redeem rounding error and exchange rate manipulation, resulting in losses of approximately $150,000 — roughly 10% of total value locked at the time. The team committed to full reimbursement of affected users and subsequently reverted to Compound Finance's original codebase, but the incident highlighted unresolved smart contract risks in a customized fork.
avoid.net/ara-finance→14/100[CRITICAL]ARA Finance is an Avalanche-based DeFi project that launched in December 2021, combining a yield farm (Goose/Masterchef fork) with a decentralized reserve currency protocol modeled on Olympus DAO (OHM). The project underwent a failed v1 launch, published a postmortem acknowledging market collapse, and pivoted to a v2 with minimal transparency. As of 2026, the protocol is effectively defunct with a TVL of approximately $1,500, a token classified as a dead coin, and an anonymous team that ceased meaningful communication.
avoid.net/rodeo→12/100[CRITICAL]Rodeo Finance was an Arbitrum-based leveraged yield protocol that allowed users to open leveraged positions in DeFi yield strategies using borrowed USDC from an integrated lending pool. The protocol suffered two separate security exploits in July 2023 within six days of each other, with the second — a TWAP oracle manipulation attack — draining approximately 472 ETH (roughly $888,000 net) and collapsing its total value locked from $20 million to under $500. The attacker bridged stolen funds to Ethereum, routed 150 ETH through Tornado Cash, and the protocol never fully recovered operationally.
avoid.net/arcadia-v1→22/100[CRITICAL]Arcadia Finance v1 was a decentralized margin lending protocol deployed on Ethereum and Optimism that suffered a critical reentrancy exploit on July 10, 2023, resulting in the loss of approximately $459,030 across both chains. The attack exploited a missing reentrancy guard in the vault liquidation function combined with absent untrusted-input validation, allowing the attacker to bypass collateral health checks and drain darcWETH and darcUSDC vaults. The stolen funds on Optimism were largely laundered through Tornado Cash; the protocol subsequently paused all contracts and issued a bounty ultimatum to the attacker that went unanswered.
avoid.net/conic-finance→22/100[CRITICAL]Conic Finance was a DeFi liquidity-diversification protocol built on Curve Finance that allowed users to deposit assets into Omnipools across multiple Curve pools. On July 21, 2023, the protocol suffered two separate exploits totaling approximately $4.2 million — a $3.26 million read-only reentrancy attack on its ETH Omnipool and a subsequent $300,000 sandwich attack on its crvUSD Omnipool — after which TVL never recovered. In March 2025, the team formally shut down the protocol, citing an inability to fix critical security issues in a planned v2 upgrade.
avoid.net/palmswap→22/100[CRITICAL]Palmswap was a decentralized perpetual futures exchange built on BNB Chain (Binance Smart Chain), launched in 2022 and offering up to 50x leverage trading via its PALM governance token and PLP liquidity provider token. On July 24–25, 2023, the protocol suffered a flash loan price manipulation exploit that drained approximately $901,455 USDT from its liquidity vault due to a critical smart contract logic flaw in the PlpManager contract. The exploiter ultimately returned $721,450 of the stolen funds after bounty negotiations, but the protocol's liquidity partner Gotbit was subsequently indicted and convicted by US federal prosecutors for market manipulation and wire fraud, raising additional integrity concerns about the project's ecosystem.
avoid.net/dydx-v3→30/100[WARNING]dYdX V3 was a decentralized perpetual futures exchange built on Ethereum using StarkWare's StarkEx Layer-2 technology, operated by dYdX Trading Inc. The platform suffered a $9 million insurance fund drain in November 2023 due to an alleged coordinated market manipulation attack targeting YFI and SUSHI markets, a DNS hijacking attack in July 2024, and a software supply chain compromise in September 2022. The V3 product was formally sunset on October 28, 2024, with trading migrated to the dYdX Chain (V4) on Cosmos.
avoid.net/florence-finance→28/100[WARNING]Florence Finance is a DeFi real-world asset (RWA) lending protocol built on Arbitrum that tokenizes euro-denominated loans to European small and medium enterprises (SMEs). In November 2023 the protocol lost $1.45 million in USDC to an address poisoning attack, and notably failed to publicly acknowledge the theft for at least five days after it was reported by security firms. As of 2025-2026 the protocol's TVL has collapsed to approximately zero and the official website indicates the project is shutting down.
avoid.net/levana-perps→32/100[WARNING]Levana Perps is a decentralized perpetual-swap protocol originally deployed on Osmosis (Cosmos ecosystem) and later expanded to Sei and Injective. In December 2023, the protocol suffered a confirmed oracle-manipulation exploit spanning 13 days that drained approximately $1.14 million (roughly 10% of liquidity provider funds). The protocol subsequently underwent a strategic rebrand and token migration into the Rujira (RUJI) ecosystem in 2025, effectively sunsetting the standalone LVN token.
avoid.net/mangofarmsol→2/100[CRITICAL]MangoFarmSOL was a purported yield-farming protocol on the Solana blockchain that executed an exit scam in January 2024, draining approximately $1.32 million from users who had deposited SOL tokens in anticipation of a promised MANGO token airdrop. The perpetrators deployed a malicious frontend under the guise of an 'emergency migration,' bridged stolen funds to Ethereum, and laundered proceeds through privacy tools including Railgun and instant exchanges before all social media accounts, the project website, and the Telegram channel were abandoned. No perpetrators have been publicly identified and no regulatory or law enforcement actions are known to have followed.
avoid.net/duelbits→32/100[WARNING]DuelBits is a Curacao-licensed crypto casino and sportsbook operated by Liquid Entertainment N.V., launched in 2020. The platform suffered a confirmed $4.6 million private key compromise on February 13, 2024, affecting wallets on both the Ethereum and BNB Chain networks. DuelBits has also been flagged in broader contexts related to unlicensed gambling promotion, Twitch's 2022 ban on unlicensed gambling streams, and mixed user reports of withdrawal delays and account-closure disputes.
avoid.net/riskonblast→2/100[CRITICAL]RiskOnBlast was a GambleFi (gambling and exchange) platform launched on the Blast Layer-2 network in February 2024. Its anonymous team executed an exit scam (rug pull) on February 24, 2024, draining approximately 420 ETH (~$1.3 million) from over 750 investor wallets immediately after the IDO cap was reached. The project is linked by on-chain evidence to a serial fraud group responsible for more than $20 million in losses across multiple DeFi protocols.
avoid.net/seneca→22/100[CRITICAL]Seneca is a decentralized stablecoin lending protocol that allowed users to mint senUSD against collateral. On February 28, 2024, attackers exploited a critical arbitrary external-call vulnerability in its Chamber contract, draining approximately $6.4 million from user wallets across Ethereum and Arbitrum. Approximately 80% of stolen funds were recovered after an on-chain bounty offer; however, the vulnerability had been publicly identified months before the exploit and the team proceeded to launch without patching it.
avoid.net/unizen→32/100[WARNING]Unizen is a cross-chain DEX aggregator and smart exchange ecosystem operating on Ethereum and multiple other networks, with a native utility token ZCX. On March 8, 2024, the platform suffered a $2.1 million exploit caused by an unsafe external call vulnerability introduced during a smart contract upgrade; the attacker subsequently laundered the stolen funds through Tornado Cash in August 2024. Despite a CEO-funded reimbursement covering approximately 99% of affected users, the incident raised significant questions about upgrade security practices given that two prior audits (Halborn, Verichain 2022) had not caught the flaw.
avoid.net/uxlink→32/100[WARNING]UXLINK is a Web3 social infrastructure platform founded in 2022 and headquartered in Singapore, claiming over 54 million registered users as of mid-2025. On September 22, 2025, the protocol suffered a critical multi-signature wallet exploit via a delegateCall vulnerability that resulted in over $11.3 million in direct losses and the fraudulent minting of approximately 10 trillion tokens. As of June 2026, the exploiter had laundered a cumulative $19.1 million through Tornado Cash, with an estimated $16 million in stolen funds still unrecovered.
avoid.net/step-finance→22/100[CRITICAL]Step Finance was a Solana-based DeFi portfolio tracker and analytics dashboard founded in 2021, often described as the 'front page of Solana,' with approximately 300,000–350,000 monthly active users at its peak. On January 31, 2026, attackers compromised devices belonging to members of the executive team, gaining access to treasury and fee wallets and draining an estimated $27–40 million in digital assets. Unable to secure refinancing or an acquisition, the team announced a permanent shutdown on February 23, 2026, alongside affiliated projects SolanaFloor and Remora Markets.
avoid.net/drift-trade→0/100[CRITICAL][MERGED] This page has been consolidated into the canonical 'drift' investigation. Original content preserved in investigation_logs. Merged on 2026-05-10.
avoid.net/judao→18/100[CRITICAL]JUDAO is a deflationary BEP-20 token deployed on BNB Smart Chain and trading primarily on PancakeSwap, with a self-described 'T3 JUDAO' iteration launched in January 2026 and a separate 'JUDAO 3.0' variant announced as part of the JuCoin ecosystem via NordCore Labs. On April 28, 2026, the token's liquidity pool was drained of approximately $228,000 through a flash loan exploit that exploited a double-reserve-sync vulnerability in its custom transfer logic. The project's parent exchange JuCoin was independently flagged by on-chain investigator ZachXBT as 'sketchy' in March 2025, and JUDAO 3.0 has no verifiable audit, no identified founding team, and no smart contract security review on record.
avoid.net/drift→52/100[CAUTIONARY]Drift Protocol is a decentralized perpetual futures exchange built on the Solana blockchain, founded in 2021 by Cindy Leow, David Lu, and co-founders. The protocol has experienced two significant security incidents: a $14.5 million PnL accounting bug in May 2022 triggered by the LUNA collapse (fully reimbursed), and a catastrophic $285–286 million exploit on April 1, 2026, attributed with medium-high confidence to the North Korean state-sponsored threat actor UNC4736 (also tracked as Lazarus Group, AppleJeus, and Citrine Sleet), which constituted the largest DeFi hack of 2026. A $295 million recovery plan involving Tether-led financing and user-issued recovery tokens was announced in May 2026; a class action lawsuit was simultaneously filed against Circle Internet Financial.
avoid.net/titan-exchange→58/100[CAUTIONARY]Titan Exchange is a Solana-based meta-DEX aggregator founded in 2024 that routes swaps across multiple aggregators, including its own proprietary routing engine, to deliver competitive pricing. The platform raised $10.5M in venture funding and publicly launched in September 2025, positioning itself as the primary competitor to Jupiter, the dominant Solana DEX aggregator. While no verified fraud or regulatory action has been found against Titan itself, the investigation surfaces several concerns: self-reported and inconsistent performance benchmarks, an unconfirmed token/airdrop creating speculative user activity, an API-blocking dispute with major incumbent aggregators, and the context of Titan capitalizing on a reputational controversy surrounding Jupiter's founder.
avoid.net/zachxbt→82/100[VERIFIED]ZachXBT (legal name Zachary Wolk, revealed through 2023 court filings) is a pseudonymous American blockchain investigator and OSINT researcher who has operated since 2021, publishing forensic investigations into cryptocurrency fraud, scams, and large-scale thefts. He is widely regarded as one of the most consequential independent crypto investigators, credited with helping recover over $350 million in stolen assets and contributing evidence that has led to multiple arrests across several countries. He maintains strict anonymity and has no formal law enforcement affiliation, though he joined Paradigm as an incident response advisor in February 2025.
avoid.net/zetachain→42/100[WARNING]ZetaChain is a San Francisco-based omnichain Layer 1 blockchain that enables native cross-chain smart contracts connecting Bitcoin, Ethereum, and other networks. The protocol has been flagged by community investigators and crypto-security observers following a premeditated $334,000 exploit of its GatewayEVM smart contract in April 2026, which the team's own earlier bug-bounty review had dismissed as intended behavior. Additional concerns include a controversial airdrop policy that rewarded sybil actors, persistent token unlock sell pressure, and structural centralization risks inherent to its Threshold Signature Scheme validator design.
avoid.net/luna→5/100[CRITICAL]<cite index="4-7,1-2">Terra was a blockchain protocol created in 2018 that collapsed in May 2022, wiping out almost $45 billion in market capitalization within one week</cite>. <cite index="11-1,13-5,15-15">The project was founded by Do Kwon, who was charged with securities fraud by the SEC in February 2023, found liable for defrauding investors in April 2024, and sentenced to 15 years in prison in December 2025</cite>. <cite index="3-1,7-1">At its peak, Terra was the third largest cryptocurrency ecosystem after Bitcoin and Ethereum before collapsing in three days in May 2022</cite>.
avoid.net/scallop-lend→32/100[WARNING]Scallop Lend is a DeFi lending and borrowing protocol deployed on the Sui blockchain, and the first DeFi project to receive an official grant from the Sui Foundation. On April 26, 2026, the protocol suffered a flash-loan exploit that drained approximately 150,000 SUI (roughly $142,000) from a deprecated rewards contract that had remained callable on-chain for approximately 17 months despite no longer being in active use. The protocol covered 100% of user losses from treasury reserves and resumed operations within two hours, though the incident raised questions about legacy contract hygiene and the completeness of prior audits by OtterSec, MoveBit, and Zellic.
avoid.net/pokemon→85/100[VERIFIED]Pokemon itself is a legitimate intellectual property owned by The Pokemon Company International, Nintendo, and Game Freak. However, the brand has been extensively exploited in various scam operations including fraudulent NFT projects, trading card fraud schemes, counterfeit merchandise sales, and cryptocurrency investment scams that have collectively resulted in millions of dollars in losses.
avoid.net/jupiter-exchange→62/100[CAUTIONARY]Jupiter Exchange (jup.ag) is the dominant DEX aggregator on Solana, founded in October 2021 by pseudonymous co-founder Meow and Siong Ong. It handles an estimated 95% of Solana aggregator volume and has expanded into perpetuals trading, lending, liquid staking, and a native stablecoin, positioning itself as a 'DeFi superapp.' While the platform is legitimate and widely used with over $2.2 trillion in cumulative swap volume, it has accumulated a series of documented controversies including a co-founder racial slur incident, misleading lending risk disclosures, a governance crisis over team voting power, an X account hack that caused user losses, and community concerns about ecosystem monopolization through acquisitions.
avoid.net/amazon-web-services→65/100[CAUTIONARY]Amazon Web Services is a leading cloud computing platform that controls 38% of the cloud infrastructure market. While generally reliable and secure, AWS has experienced multiple significant outages and faces ongoing privacy lawsuits, though no major regulatory sanctions have been identified in recent searches.
avoid.net/onecoin→0/100[CRITICAL]OneCoin was a fraudulent cryptocurrency scheme founded in 2014 by Ruja Ignatova ('Cryptoqueen') and Karl Sebastian Greenwood, which defrauded approximately 3.5 million investors worldwide of over $4 billion. The scheme operated through a fake private blockchain and multilevel marketing network before collapsing in 2017. Greenwood was sentenced to 20 years in prison in 2023; Ignatova remains a fugitive on the FBI Ten Most Wanted list with a $5 million reward for information leading to her arrest.
avoid.net/mev→5/100[CRITICAL]MEV bot scams represent a sophisticated category of cryptocurrency fraud that exploits legitimate blockchain concepts to steal millions from users. While legitimate MEV (Maximum Extractable Value) bots are automated trading programs that extract value through transaction ordering on blockchains, scammers create fake MEV bot tutorials and investment schemes that promise guaranteed returns but actually drain victims' wallets.
avoid.net/polymarket→25/100[CRITICAL]Polymarket is a cryptocurrency-based prediction market platform that allows users to bet on real-world events. Despite being the world's largest prediction market with accurate election forecasting, the platform faces significant concerns including regulatory violations, market manipulation allegations, and insider trading issues.
avoid.net/altria→25/100[CRITICAL]Altria Group, one of the largest tobacco companies in the U.S., faces significant legal and regulatory challenges primarily related to its $12.8 billion investment in Juul Labs and alleged conspiracy to target youth with vaping products. The company has been subject to multiple securities fraud class actions, antitrust litigation, and regulatory violations totaling over $1.2 billion in penalties since 2000.
avoid.net/litecoin→64/100[CAUTIONARY]Litecoin (LTC) is one of the oldest proof-of-work cryptocurrencies, created in October 2011 by former Google engineer Charlie Lee as a Bitcoin fork with faster block times and the Scrypt hashing algorithm. The protocol itself has a long operating history and has been formally classified as a digital commodity by U.S. regulators as of 2026. ZachXBT flagged Litecoin in connection with a January 2026 social engineering theft in which a single victim lost approximately $282 million in BTC and LTC — the largest individual crypto theft of that year — though the attack targeted a holder rather than representing any flaw in the Litecoin protocol or its development team.
avoid.net/singularity-finance→28/100[WARNING]Singularity Finance (SFI) is an EVM-compatible Layer 2 blockchain protocol that emerged in late 2024 from a three-way token merger involving SingularityDAO, Cogito Finance, and SelfKey, positioning itself as a DeFAI (decentralized finance plus AI) platform within the Artificial Superintelligence Alliance ecosystem. The SFI token launched at an ICO price of approximately $0.123 in February 2025, reached an all-time high near $0.20 on launch day, and had declined approximately 97-98% to around $0.004 by May 2026. On-chain investigator ZachXBT has flagged Singularity Finance as a concern; independently verifiable risk indicators include a catastrophic post-ICO price collapse, an undelivered Q1 2025 mainnet promise, an unaudited smart contract, a reported CertiK Skynet score of 3.6 out of 10, and significant token supply overhang with only 31% of the 500 million maximum supply in circulation.
avoid.net/fomo-fomo-family→52/100[CAUTIONARY]Fomo (fomo.family) is a consumer social crypto trading app developed by FOMO Labs, Inc. of San Francisco, co-founded by former dYdX employees Paul Erlanger and Se Yong Park. Launched in May 2025 and backed by $19 million in funding led by Benchmark Capital, the platform operates on Solana, Base, and BNB Chain with a non-custodial wallet architecture. The platform is explicitly unregulated, has no publicly disclosed security audits, charges flat per-trade fees that disadvantage small traders, and has spawned at least one active phishing/wallet-drainer scam site impersonating its brand.
avoid.net/solana→62/100[CAUTIONARY]Solana is a high-performance blockchain platform that has experienced significant technical instability, ecosystem fraud, and regulatory challenges since its 2020 launch. While positioned as an "Ethereum killer," the network has suffered from multiple outages, massive meme coin scams, and legal scrutiny regarding its centralization and potential securities classification.
avoid.net/madlads→65/100[CAUTIONARY]Mad Lads is a Solana-based NFT collection launched in April 2023 by Coral, the development company behind Backpack wallet. Created by former Alameda Research and FTX employees Armani Ferrante and Tristan Yver, the project gained significant attention for its innovative mint process that used honeypot tactics to deter bots and for being the first major xNFT collection.
avoid.net/chads-nft→38/100[WARNING]Chads (chads.wtf) is a Solana-based PFP/avatar NFT collection of 5,565 algorithmically generated pixel-art characters that minted on April 20, 2023 via the Elixir launchpad. The project positioned itself as a meme-culture social club with utility promises including ChadOS tooling, a YesDAO community treasury, and a YES token reward system. No formal fraud or rug pull allegations have been found in credible sources, but the collection has experienced a significant value decline of approximately 97.5% from its December 2023 all-time high, several roadmap deliverables remain unverified as shipped, and the founding team has not publicly doxxed their identities.
avoid.net/kraken→62/100[CAUTIONARY]Kraken (operated by Payward, Inc.) is one of the largest and longest-running cryptocurrency exchanges in the world, founded in 2011 and publicly launched in 2013 in San Francisco. The exchange holds a Wyoming special purpose depository institution bank charter and serves approximately 15 million users across 190+ countries. While Kraken is a legitimate, operating business and has not been the subject of exit-scam or market-manipulation allegations, it has accumulated a substantial regulatory enforcement record across multiple jurisdictions, experienced a zero-day security exploit in 2024, and faced an active extortion attempt in April 2026 tied to insider-related data access incidents.
avoid.net/phantom-wallet→63/100[CAUTIONARY]Phantom Wallet is a self-custody, non-custodial cryptocurrency wallet developed by Phantom Technologies, Inc., headquartered in San Francisco. Originally launched in 2021 as a Solana-focused browser extension, it has expanded to support Ethereum, Bitcoin, Polygon, Base, and Sui across browser extensions and mobile apps, with approximately 15 million monthly active users and $25 billion in self-custodied assets as of early 2025. The company is well-funded and has engaged constructively with US regulators, though it faces an active civil lawsuit alleging a browser-extension security flaw, and its users have been materially targeted by phishing impersonators and fake app-store clones.
avoid.net/amazon→65/100[CAUTIONARY]Amazon is a major e-commerce and technology company that has faced significant regulatory challenges and consumer protection issues. While not itself a scam, Amazon's scale has made it a frequent target for impersonation scams and has led to multiple regulatory actions including a $2.5 billion FTC settlement for deceptive Prime subscription practices.
avoid.net/zombies→25/100[CRITICAL]"Zombies" in cryptocurrency refers to a broad classification of dormant or abandoned blockchain projects rather than a specific single entity. The term encompasses thousands of tokens that maintain blockchain presence and trading activity despite ceased development, minimal utility, or failed missions.
avoid.net/wallet-drainers→5/100[CRITICAL]Wallet drainers are malicious phishing tools specifically designed for the Web3 ecosystem that trick users into authorizing fraudulent transactions that empty their cryptocurrency wallets. These sophisticated scam-as-a-service operations have stolen over $500 million in 2024 alone from hundreds of thousands of victims through fake websites masquerading as legitimate crypto projects.
avoid.net/hyperliquid→62/100[CAUTIONARY]Hyperliquid suffered a documented ecosystem incident with reported losses of $37K on Arbitrum. This page tracks DeFiLlama's record of the event.
avoid.net/binance→45/100[WARNING]Binance is the world's largest cryptocurrency exchange by trading volume, founded in 2017 by Changpeng Zhao (CZ). In November 2023, Binance and CZ pleaded guilty to U.S. federal charges and agreed to pay $4.3 billion in combined penalties for Bank Secrecy Act violations, unlicensed money transmission, and sanctions evasion — the largest financial penalty ever imposed on a cryptocurrency company. CZ resigned as CEO, served a four-month prison sentence in 2024, and was controversially pardoned by President Trump in October 2025. Under CEO Richard Teng, Binance has pursued an aggressive global licensing strategy while remaining subject to ongoing compliance monitoring and new civil litigation tied to terrorist financing allegations.
avoid.net/axiom-exchange→4/100[CRITICAL]<cite index="11-3,27-15">Axiom Exchange is a crypto trading platform founded in 2024 by Henry Zhang (Mist) and Preston Ellis (Cal), backed by Y Combinator</cite>. <cite index="11-1,21-3">In February 2026, blockchain investigator ZachXBT alleged that senior employees misused internal access controls to conduct insider trading using sensitive user wallet data</cite>. <cite index="11-5,27-17">Despite generating over $390 million in revenue to date, the platform now faces serious allegations of internal data abuse and trading misconduct</cite>.
avoid.net/td-bank→52/100[CAUTIONARY]TD Bank is a major North American financial institution formed in 1955 from the merger of two Canadian banks. In October 2024, the bank faced historic penalties totaling over $3 billion after pleading guilty to money laundering conspiracy charges, resulting in severe business restrictions and regulatory oversight.
avoid.net/binancelife→28/100[WARNING]BinanceLife (币安人生, ticker 币安人生/BINANCELIFE) is a Chinese-language meme token launched on the BNB Smart Chain via the Four.meme launchpad on October 4, 2025. It has no affiliation with the Binance exchange, Binance founder Changpeng Zhao (CZ), or CZ's memoir of the same Chinese title, despite its name and branding closely evoking Binance. The token operated for months with no official website, no verified team, and heavily concentrated token holdings, yet was nonetheless listed on Binance Alpha and later Binance's spot market, raising concerns about the risk of retail investors mistaking it for an official Binance-affiliated asset.
avoid.net/bonkdao→30/100[WARNING]BonkDAO is the decentralized governance body overseeing the community treasury of BONK, a Solana-based dog-themed memecoin launched in December 2022. On July 6, 2026, BonkDAO's treasury was drained of approximately $20 million in BONK tokens after an attacker accumulated enough BONK on the open market (roughly $4-4.4 million worth) to win a governance vote (Realms proposal BIP #76) and authorize the transfer of about 4.426 trillion BONK to a wallet under their control. This was a governance/voting-power exploit rather than a smart-contract hack, and it was widely reported by mainstream and crypto-native outlets, giving the core facts high confidence; the identity of the attacker, ultimate fund recovery, and any compensation for the DAO remain unresolved as of the most recent reporting.
avoid.net/circle-usyc→78/100[VERIFIED]USYC (US Yield Coin) is a tokenized money market fund representing shares in the Hashnote International Short Duration Yield Fund Ltd., a Cayman Islands-regulated fund investing primarily in short-duration U.S. Treasury securities and reverse repurchase agreements. Originally issued by Hashnote, USYC and its issuer were acquired by Circle Internet Group in January 2025; the token is now issued by Circle International Bermuda Limited, a Bermuda Monetary Authority-licensed entity, and has grown to become the largest tokenized U.S. Treasury product on-chain by assets under management. The product carries genuine institutional-grade structure and disclosure, but access is restricted to non-U.S. persons and KYC'd institutional entities, redemption ultimately depends on centralized allowlisting and issuer-controlled smart contracts, and the fund itself was not directly implicated in the January 2025 Usual/USD0++ depeg despite serving as collateral for that episode.
avoid.net/zeus-network→37/100[WARNING]Zeus Network is a Solana-based protocol (token ticker ZEUS, mint ZEUS1aR7aX8DFFJf5QjWj2ftDDdNTroMNGo8YoQm3Gq) that markets itself as a permissionless Bitcoin-to-Solana bridge, minting a 1:1 Bitcoin-pegged asset called zBTC via its APOLLO application and Zeus Program Library (ZPL). The project raised roughly $8 million from named venture funds and angel investors, including Solana co-founder Anatoly Yakovenko, and its ZEUS token has fallen approximately 99.7% from its April 2024 all-time high, trading at fractions of a cent as of July 2026. A set of specific abandonment allegations attributed to a social-media watchdog account (deleted Discord, an unconfirmed Astarter "acquisition," an unreachable team, disabled comments) could not be independently corroborated from verifiable sources at the time of this review; on the contrary, available evidence points to an active, if commercially struggling, project rather than a confirmed rug pull or exit scam.
avoid.net/vlad→4/100[CRITICAL]"$VLAD" is not a single token but a ticker that has been used by at least three distinct, unrelated crypto projects on Robinhood's new "Robinhood Chain" blockchain during its permissionless memecoin boom in July 2026, plus unrelated pre-existing tokens with the same ticker on other chains (a Solana pump.fun token called Vladcoin and a low-volume Ethereum token called Vlad Finance). The most notable and highest-signal use of the ticker is "Vladhood ($VLAD)", a fraudulent token promoted via a confirmed unauthorized post from the compromised X account of Robinhood CEO Vlad Tenev, which falsely claimed official Robinhood affiliation. Separately, an opportunistic copycat memecoin called "The Green Bull (VLAD)" and unverified speculation about a "$VLAD" token tied to the (subsequently halted) Vlad.fun launchpad have also circulated. No project using the $VLAD ticker has any confirmed official affiliation with Robinhood Markets or Vlad Tenev, and the ticker has become a recurring vector for impersonation and copycat-token schemes.
avoid.net/janus-henderson-anemoy-aaa-clo-fund-jaaa→72/100[CAUTIONARY]The Janus Henderson Anemoy AAA CLO Fund (JAAA) is a tokenized real-world asset fund providing on-chain exposure to AAA-rated tranches of Collateralized Loan Obligations (CLOs), actively managed by Janus Henderson Investors U.S. LLC as sub-advisor and issued by Anemoy Capital SPC Limited, a British Virgin Islands regulated professional fund. Launched in June 2025 with a $1 billion seed allocation from the Sky/MakerDAO ecosystem via the Grove DeFi protocol, the tokenized fund had approximately $686 million in assets under management as of June 2026. The fund is restricted to non-US qualified institutional investors who pass KYC/AML onboarding via the Centrifuge platform, and carries inherent risks from CLO market credit spreads, smart contract infrastructure, cross-jurisdictional regulatory uncertainty, and stablecoin dependency.
avoid.net/invesco-short-duration-us-government-securities-fund-ustb→78/100[VERIFIED]USTB is a tokenized short-duration U.S. Treasury fund originally launched by Superstate in February 2024 and transitioned to Invesco Advisers, Inc. as investment manager in mid-2026. As of July 2026, the fund holds approximately $682 million in AUM, is deployed on Ethereum, Solana, and Plume, and is restricted to accredited investors and qualified purchasers. It operates as a private Section 3(c)(7) fund under a Regulation D Rule 506(c) exemption and has no record of regulatory enforcement actions, fraud allegations, or security incidents.
avoid.net/spiko-amundi-overnight-swap-fund-eur→78/100[VERIFIED]The Spiko Amundi Overnight Swap Fund EUR (ticker: eurSAFO) is a tokenized UCITS money market fund launched in March 2026, co-developed by French fintech Spiko and Amundi, Europe's largest asset manager with approximately €2.4 trillion under management. The EUR share class is regulated by France's Autorité des Marchés Financiers (AMF) and operates as a sub-fund of SPIKO SICAV, using fully collateralized total return swaps with Tier 1 bank counterparties to deliver yields above overnight benchmarks. As of mid-2026, eurSAFO had approximately $830 million in total asset value across five blockchain networks, ranking among the largest tokenized RWA funds globally.
avoid.net/janus-henderson-anemoy-treasury-fund-jtrsy→82/100[VERIFIED]The Janus Henderson Anemoy Treasury Fund (JTRSY) is a tokenized British Virgin Islands professional fund that invests exclusively in short-term U.S. Treasury Bills with maturities under six months, issued on-chain via the Centrifuge protocol. The fund is regulated by the BVI Financial Services Commission, managed by Anemoy Asset Management with Janus Henderson Investors as sub-investment manager, and has received top-tier credit ratings including AA+f/S1+ from S&P Global Ratings as of March 2025. Access is restricted to non-U.S. professional investors and qualified crypto institutions, with subscriptions and redemptions settled in USDC.
avoid.net/usdgo→74/100[CAUTIONARY]USDGO is a USD-pegged enterprise stablecoin launched in February 2026, issued by Anchorage Digital Bank N.A. (the first federally chartered crypto bank in the United States) and branded and distributed by Hong Kong-listed OSL Group. As of July 2026 its circulating supply surpassed $1 billion, placing it among the top six regulated stablecoins globally. No fraud allegations, regulatory actions, or enforcement proceedings have been identified against the issuer or distributor in connection with USDGO.
avoid.net/spiko-eu-t-bills-money-market-fund→78/100[VERIFIED]Spiko EU T-Bills Money Market Fund (ticker: EUTBL) is a tokenized money market fund structured as a UCITS sub-fund of the Spiko SICAV, investing exclusively in short-term Eurozone sovereign Treasury Bills. It is regulated by the French Autorité des marchés financiers (AMF), managed by Twenty First Capital, and custodied by CACEIS Bank (a Credit Agricole subsidiary). As of July 2026 it ranks approximately #64 by market capitalization on CoinGecko with over $1 billion in assets under management, making it one of the largest tokenized real-world asset (RWA) products in Europe. No fraud, hack, or regulatory enforcement actions have been identified against Spiko or the fund.
avoid.net/usx→62/100[CAUTIONARY]USX is a Solana-native synthetic stablecoin issued by Solstice Finance, a DeFi protocol incubated by Deus X Capital, a $1 billion institutional digital-asset investment firm. Launched on September 30, 2025 with $160 million in TVL, USX is backed 1:1 by a diversified reserve of USDC, USDT, tokenized Treasuries, and delta-neutral hedged positions, with reserves attested in real time via Chainlink and Accountable. In December 2025, USX briefly depegged to $0.10 on secondary Solana DEX markets due to a liquidity crunch; the issuer attributed the event to secondary-market illiquidity rather than collateral failure, and USX subsequently restabilized near $1.00.
avoid.net/ylds→68/100[CAUTIONARY]YLDS is a yield-bearing, SEC-registered debt security issued as a tokenized face-amount certificate by Figure Certificate Company (FCC), a wholly owned subsidiary of Figure Technology Solutions, Inc. (Nasdaq: FIGR). It is the first interest-bearing transferable stablecoin to be registered under the U.S. Investment Company Act of 1940, and as of mid-2026 has approximately $540 million in circulation across Provenance Blockchain, Solana, Stellar, and Sui. While the product carries legitimate regulatory backing, parent company Figure Technology Solutions faces outstanding short-seller allegations regarding blockchain misrepresentation, lending quality, and a significant 2026 data breach affecting nearly one million customers.
avoid.net/audiera-beat→32/100[WARNING]Audiera is a BNB Chain-based Web3 gaming and music platform that markets itself as the blockchain evolution of the Audition rhythm game franchise, issuing the BEAT token at TGE in November 2025. The project has attracted significant speculative trading volume, reaching a market cap briefly exceeding $2 billion in June 2026 before collapsing approximately 88% within days, raising pump-and-dump concerns among analysts. Key risk factors include anonymous or undisclosed founding team, unverified IP licensing claims relating to the original Audition game IP owned by T3 Entertainment, concentrated token distribution, and derivative-driven price action disconnected from measurable user adoption.
avoid.net/adi→52/100[CAUTIONARY]ADI is the native utility token of ADI Chain, an Ethereum-compatible Layer 2 blockchain developed by Abu Dhabi-based ADI Foundation, a unit of Sirius International Holding — the digital arm of International Holding Company (IHC), a $240 billion UAE conglomerate chaired by Sheikh Tahnoon bin Zayed Al Nahyan, brother of the UAE president. Mainnet launched December 9, 2025, with the token listing simultaneously on Kraken, KuCoin, and Crypto.com; as of July 2026 it ranked approximately #69–#74 by market cap with a valuation near $840 million. The project carries meaningful institutional backing and regulatory legitimacy through a UAE Central Bank-approved dirham stablecoin and MoUs with BlackRock, Mastercard, and Franklin Templeton, but is offset by governance opacity in its parent conglomerate, an associated prediction-market subsidiary whose CEO has documented ties to the Qatargate corruption scandal, a principal executive who settled insider-trading charges with India's SEBI in 2025, and undisclosed investors in a July 2026 $50 million fundraise.
avoid.net/united-stables-u→48/100[WARNING]United Stables is a USD-pegged stablecoin issued by United Stables Limited (registered in the British Virgin Islands), operating under the ticker symbol U. Launched in December 2025 on BNB Chain and Ethereum, it reached approximately $1 billion in circulating supply by mid-2026, ranking among the top-100 cryptocurrencies by market cap. The issuer explicitly states it holds no regulatory licenses under MiCA, Hong Kong stablecoin law, or the US GENIUS Act, and the public leadership profile is extremely limited, with the CEO identified only as 'Athena Y.'
avoid.net/bfusd→52/100[CAUTIONARY]BFUSD is a reward-bearing margin asset launched by Binance Futures in November 2024, designed exclusively for use as collateral in USDT-M Futures trading. It is not a blockchain token, cannot be withdrawn from Binance, and generates yield through delta-neutral funding-fee strategies and ETH staking. While Binance maintains a reserve fund and transparency dashboard, the product carries significant concentrated counterparty risk tied to Binance's centralized custody model and its operator's prior criminal guilty plea on AML charges in 2023.
avoid.net/pax-gold-paxg→72/100[CAUTIONARY]PAX Gold (PAXG) is a regulated, gold-backed ERC-20 token issued by Paxos Trust Company, launched in September 2019, where each token represents one fine troy ounce of physical gold stored in Brink's vaults in London. Paxos holds a national trust charter from the U.S. Office of the Comptroller of the Currency (OCC) as of December 2025, and publishes monthly third-party attestation reports via KPMG. The issuing entity, Paxos Trust Company, entered a $48.5 million settlement with the New York Department of Financial Services (NYDFS) in August 2025 over anti-money laundering failures tied to its prior BUSD stablecoin business, which does not directly implicate PAXG but reflects compliance weaknesses at the parent firm.
avoid.net/ondo-us-dollar-yield-usdy→72/100[CAUTIONARY]Ondo US Dollar Yield (USDY) is a tokenized yield-bearing note issued by Ondo USDY LLC, a Delaware bankruptcy-remote special purpose vehicle affiliated with Ondo Finance, and backed by short-duration U.S. Treasuries, iShares Short Treasury Bond ETF shares, and bank demand deposits. The token is offered exclusively to non-U.S. persons under a Regulation S exemption, accrues yield through a rising token price or daily rebasing, and had grown to approximately $740 million in supply across ten blockchains as of early 2026. A two-year SEC investigation into Ondo Finance was closed without charges in December 2025, though ongoing risks include centralized price-setting infrastructure, limited FDIC deposit coverage on a portion of reserves, and access and composability constraints imposed by the token's on-chain allowlist system.
avoid.net/tether-gold-xaut→44/100[WARNING]Tether Gold (XAUT) is a commodity-backed digital token issued by TG Commodities, S.A. de C.V., a subsidiary of Tether Holdings, where each token represents one troy fine ounce of physical gold stored in LBMA-certified Swiss vaults. The product ranks among the top tokenized gold assets by market capitalization, with approximately 375,000 troy ounces of gold backing circulation as of mid-2025. Its parent company, Tether Limited, has settled enforcement actions with the CFTC and the New York Attorney General over misrepresentation of its USDT stablecoin reserves, and remained under an active DOJ probe as of late 2024 into alleged sanctions and anti-money laundering violations.
avoid.net/falcon-usd-usdf→42/100[WARNING]Falcon USD (USDf) is a synthetic overcollateralized dollar token issued by Falcon Finance, a protocol incubated and backed by DWF Labs, launched publicly on April 30, 2025. As of mid-2026, USDf holds a market capitalization of approximately $1.4 billion, ranking it among the top synthetic stablecoins. The protocol has attracted significant scrutiny due to its parent firm DWF Labs facing alleged market manipulation and wash trading charges, a notable depeg event in July 2025, opaque off-chain reserve management, and concerns raised by independent DeFi risk researchers over collateral quality and centralized control.
avoid.net/ripple-usd-rlusd→74/100[CAUTIONARY]Ripple USD (RLUSD) is a U.S. dollar-pegged stablecoin issued by Standard Custody & Trust Company, LLC, a wholly owned subsidiary of Ripple Labs, under a limited-purpose trust company charter granted by the New York Department of Financial Services (NYDFS). It launched on December 17, 2024, following formal regulatory approval, and had grown to approximately $1.5 billion in circulating supply as of July 2026. RLUSD carries standard centralization and counterparty risks inherent to issuer-controlled fiat-backed stablecoins, including administrative freeze and blacklist capabilities, but is backed by monthly Deloitte attestations, BNY Mellon custody of reserves, and a clear regulatory framework.
avoid.net/blackrock-usd-institutional-digital-liquidity-fund→82/100[VERIFIED]BUIDL is a tokenized U.S. dollar money market fund managed by BlackRock and issued on public blockchains through tokenization platform and transfer agent Securitize. Launched on Ethereum in March 2024, it holds cash, U.S. Treasury bills, and repurchase agreements, is custodied by Bank of New York Mellon, and is offered as a private placement restricted to accredited/qualified institutional investors rather than as a retail SEC-registered security. It has grown into the largest tokenized U.S. Treasury fund by assets under management, but access, redemption, and transfer are gated by centralized whitelisting and freeze controls typical of permissioned real-world-asset (RWA) tokens.
avoid.net/paypal-usd→68/100[CAUTIONARY]PayPal USD (PYUSD) is a US dollar-pegged stablecoin issued by Paxos Trust Company, a New York-chartered limited purpose trust company regulated by the NYDFS, and marketed by PayPal. Reserves are attested monthly by an independent accounting firm and are held in cash and short-term US Treasuries, with redemption rights subject to Paxos and PayPal compliance review. PYUSD carries the same centralization risks common to bank-issued stablecoins (issuer freeze and address-wipe functions) and its issuer, Paxos, has a prior NYDFS enforcement history tied to its Binance-branded BUSD stablecoin, though PYUSD itself has not been the subject of a depeg event, and a 2023 SEC subpoena into PYUSD was closed in February 2025 without enforcement action.
avoid.net/global-dollar→68/100[CAUTIONARY]Global Dollar (USDG) is a fiat-backed stablecoin issued by Paxos Digital Singapore Pte. Ltd. and regulated by the Monetary Authority of Singapore, launched in November 2024 to anchor the Global Dollar Network (GDN), a consortium of exchanges and fintechs including Robinhood, Kraken, Galaxy Digital, Anchorage Digital, Bullish, Nuvei, and Visa. USDG differentiates itself from USDT and USDC by sharing reserve yield with network partners rather than retaining it at the issuer, and publishes monthly third-party reserve attestations. The stablecoin itself has no confirmed depeg incidents or direct regulatory enforcement action to date, but its issuer, Paxos, has a documented history of AML/KYC compliance failures tied to the BUSD stablecoin, and USDG's yield-distribution model sits in a regulatory gray area under the GENIUS Act's interest-payment prohibitions that lawmakers and banking groups are actively seeking to close.
avoid.net/lighter→62/100[CAUTIONARY]Lighter is a venture-backed, zero-fee perpetual futures decentralized exchange built as a custom zero-knowledge rollup on Ethereum, founded by former Citadel engineer Vladimir Novakovski. It has raised roughly $89 million from high-profile investors including Founders Fund, Ribbit Capital, Haun Ventures, Craft Ventures, Dragonfly and Robinhood Markets, reaching a $1.5 billion valuation, and briefly ranked among the top perpetuals DEXs by volume. The platform has drawn scrutiny over post-token-launch withdrawal delays, a front-end chart-manipulation controversy following a bot-driven price spike, heavy team/investor token allocation, and a sharp decline in trading volume and user activity after its December 2025 airdrop.
avoid.net/gho→61/100[CAUTIONARY]GHO is a decentralized, crypto-collateralized stablecoin native to the Aave protocol, launched in July 2023 and minted through governance-approved 'Facilitators.' The token suffered a prolonged sub-$1 depeg for roughly seven months after launch and a sharper flash depeg during the July 2023 Curve Finance exploit, before stabilizing near $1.00 in 2024–2026 following the introduction of a Peg Stability Module-style mechanism. As of mid-2026, GHO's peg is largely stable and its supply has grown to roughly $500–650 million, but the protocol carries residual risks tied to collateral concentration, stablecoin-backed peg defenses, and recent turmoil in Aave DAO governance following the exit of the Aave Chan Initiative, a delegate that had driven much of GHO's growth.
avoid.net/usds→63/100[CAUTIONARY]USDS is the primary stablecoin of Sky (formerly MakerDAO), launched in September 2024 as the successor to DAI within Sky's product line, with holders able to convert 1:1 between the two tokens. USDS is over-collateralized by a mix of crypto assets, USDC held via peg stability modules, and tokenized real-world assets including U.S. Treasuries, but it has drawn recurring criticism over a wallet-freezing capability, a custody arrangement for hundreds of millions of dollars in reserves that relied on a single externally-owned wallet, and rising governance complexity under Sky's 'Endgame' restructuring. No confirmed hack or sustained depeg of USDS itself has been documented as of this writing, though it inherits pass-through depeg risk from its USDC backing.
avoid.net/usdd→28/100[WARNING]USDD is a stablecoin issued by the TRON DAO Reserve, launched in May 2022 and marketed as an over-collateralized, algorithmically-assisted alternative to Terra's failed UST. USDD de-pegged from its $1.00 target within weeks of launch and again during the November 2022 FTX collapse, and has since faced sustained criticism over opaque, shifting reserve composition, a defunct governance structure, and the concentration of control and collateral around TRON founder Justin Sun and his exchange HTX. Independent stablecoin rating firm Bluechip assigned USDD the lowest grade ('F') among stablecoins it assessed, citing commingled reserves and an absence of functioning decentralized governance.
avoid.net/usd1→38/100[WARNING]USD1 is a U.S. dollar-pegged stablecoin launched in March 2025 by World Liberty Financial (WLFI), a DeFi project with direct financial ties to the Trump family. Reserves are custodied by BitGo Trust Company and attested to monthly by Crowe LLP, but the coin has drawn scrutiny for delayed attestation reports, heavy offshore concentration, an unresolved conflict-of-interest controversy tied to a $2 billion MGX-Binance transaction, a June 2026 exchange delisting following an address freeze, and open questions about whether its issuance structure complies with the GENIUS Act. As of July 2026 it ranks among the largest stablecoins by market capitalization, though its governance is entangled with the political and business interests of a sitting U.S. president's family.
avoid.net/world-liberty-financial-wlfi→22/100[CRITICAL]World Liberty Financial (WLFI) is a DeFi protocol and stablecoin issuer co-founded in 2024 by members of the Trump family and the Witkoff family, along with crypto entrepreneurs Chase Herro and Zachary Folkman. The project has raised approximately $550 million through governance token sales and issued the USD1 stablecoin, which reached roughly $4.6 billion in circulating supply by mid-2026. The project has attracted sustained congressional scrutiny, multiple Senate-requested federal probes, a high-profile lawsuit from one of its largest investors, allegations of token sales to sanctioned entities, and documented conflicts of interest tied to the sitting U.S. president's direct financial stake in the venture.
avoid.net/teleswap→32/100[WARNING]TeleSwap (formerly TeleportDAO) is a cross-chain bridge protocol that lets users move Bitcoin and Runes to EVM chains, TON, and Solana using light-client and "Locker"/"Teleporter" custodian architecture, funded by a $2.5M 2023 seed round and a 2024 public token sale. On July 15, 2026, on-chain investigator ZachXBT and the SlowMist Hacked incident database reported suspicious outflows of roughly $735,000 from TeleSwap's Bitcoin hot wallet followed by laundering through Tornado Cash; as of this writing TeleSwap has not issued a public confirmation, technical postmortem, or the underlying transaction details, which is itself a notable transparency concern. Overall reporting quality on the incident is thin — it traces back mainly to one investigator's claim and aggregator write-ups rather than a project statement, a named security-firm root-cause report, or Tier-1 news coverage, so key facts (attack vector, exact amount, affected users) remain unverified.
avoid.net/barnbridge→12/100[CRITICAL]BarnBridge was an Ethereum-based DeFi protocol, structured as a DAO, best known for its SMART Yield product, which tranched variable-rate yield from lending markets like Compound and Aave into fixed and variable risk classes. The protocol halted operations in mid-2023 after founders disclosed an SEC investigation, and BarnBridge DAO and its two founders settled with the SEC in December 2023 for $1.7 million over unregistered offer and sale of crypto asset securities and unregistered investment company violations. On July 15, 2026, despite being effectively defunct, BarnBridge's SMART Yield governance and legacy token approvals were exploited in a governance-takeover attack that drained approximately $776,000 in USDC from roughly 50 wallets; the attacker reportedly spent only about $600 to acquire enough BOND voting power to pass a malicious upgrade proposal through an inactive DAO. The scout flag characterizing this as a governance-attack incident is substantiated: the event is corroborated across multiple independent crypto-news outlets and an on-chain security firm, though as of this writing it lacks coverage from top-tier wire/legal press specific to the 2026 incident itself (the 2023 SEC action is Tier 1 sourced).
avoid.net/zilliqa→61/100[CAUTIONARY]Zilliqa is a Singapore-founded, sharded layer-1 blockchain launched in 2017 out of National University of Singapore research, with a track record of independent smart-contract audits and no history of SEC or DOJ enforcement action against the project itself. Its trust profile is weighed down by two distinct security incidents: a February 2025 exploit of Zilliqa's own X-Bridge token-manager contracts (protocol-level fault, roughly $42,000 realized loss) and a July 2026 theft of ZIL tokens from an exchange partner's cold wallet, which Zilliqa's own preliminary findings attribute to a technical flaw in legacy ZIL1 wallet transaction-signing rather than to the exchange's custody practices — a claim that as of this writing is corroborated by only one secondary source and remains unconfirmed by Zilliqa's promised full post-mortem.
avoid.net/ledger-live→58/100[CAUTIONARY]Ledger Live is the official companion application published by Ledger SAS for managing Ledger hardware wallets. The genuine application itself has no documented vulnerabilities that have led to direct fund loss, but the "Ledger Live" name and branding have been repeatedly and successfully counterfeited on major app marketplaces (Apple App Store, Microsoft Store, Google Play, Chrome Web Store), resulting in tens of millions of dollars in alleged theft from users who mistook fake listings for the real app. Separately, a genuine Ledger-published software component in the same ecosystem (the Ledger Connect Kit library) was compromised in a December 2023 supply-chain attack that briefly redirected funds from users of dApps integrating with Ledger hardware wallets.
avoid.net/gmgn-ai→58/100[CAUTIONARY]GMGN.ai is a Singapore-based, primarily Chinese-run multi-chain memecoin trading terminal and Telegram trading bot, launched in mid-2023, focused on Solana, Ethereum, Base, and BNB Chain token discovery, smart-money wallet tracking, and copy trading. The platform states it is non-custodial and cannot move user wallet balances itself, but it carries a poor Trustpilot rating driven by complaints about copy-trading losses and unclear fees, and it has been the target of extensive phishing and impersonation campaigns — including fake mobile apps and cloned websites — that have drained victims' wallets. No confirmed breach of GMGN's own infrastructure or misappropriation of user funds by the company has been documented in available sources.
avoid.net/cavepay→18/100[CRITICAL]Cavepay (marketed at the domain cavepay.app and via a Telegram channel) presented itself as a multi-cryptocurrency wallet service. Independent, credible reporting on the project is essentially nonexistent: no Tier 1 or Tier 2 news coverage, regulatory action, or court records were found. The only substantive third-party assessment located is an automated scam-detection aggregator that flags the site for phishing and gives it the lowest possible trust rating, and the domain no longer resolves. Given the near-total absence of verifiable information, this page should be treated as low confidence — it documents red flags and an information vacuum rather than a confirmed fraud finding or a confirmed clean bill of health.
avoid.net/peter-stokes-scattered-spider→3/100[CRITICAL]Peter Stokes, 19, a dual U.S.-Estonian national, was arrested in Finland in April 2026 on an Interpol Red Notice and extradited to the United States on July 1, 2026 to face federal charges in the Northern District of Illinois for alleged membership in the Scattered Spider cybercrime collective. Prosecutors allege Stokes participated in a May 2025 social-engineering breach of an unnamed luxury jewelry retailer in which attackers reset an employee's two-factor authentication credentials via the company help desk, stole data, and demanded roughly $8 million in cryptocurrency. All allegations against Stokes are pending trial and unproven in court; Scattered Spider as a network has been linked by U.S. authorities to more than 100 corporate intrusions and over $100 million in crypto-denominated ransom and extortion payments.
avoid.net/knaken→4/100[CRITICAL]Knaken (Knaken Cryptohandel B.V.), a Rotterdam-based Dutch cryptocurrency exchange founded in 2017, was declared bankrupt by a Rotterdam court on July 16, 2026 after roughly €7 million in customer funds could not be accounted for. The platform, which had roughly 30,000 customers, went offline in early June 2026 after failing to obtain the license required under the EU's Markets in Crypto-Assets (MiCA) regulation, and is now the subject of a Dutch Public Prosecution Service (OM) criminal investigation into the missing funds.
avoid.net/benjamin-paul-wiener→8/100[CRITICAL]Benjamin Paul Wiener is a 43-year-old Sioux Falls, South Dakota resident and founder of the Benaiah group of investment entities who was indicted by a federal grand jury in June 2026 on 29 counts including wire fraud, bank fraud, money laundering, and aggravated identity theft, in connection with an alleged Ponzi-style scheme that solicited roughly $20-25 million from investors in cash and cryptocurrency. Wiener pleaded not guilty at his arraignment on July 10, 2026, and is scheduled for trial on September 15, 2026; the case is a pending criminal matter and Wiener is presumed innocent unless and until convicted. A separate, earlier-filed civil lawsuit and court-ordered asset freeze/receivership against Wiener's Benaiah entities alleges similar conduct and predates the criminal indictment.
avoid.net/summer-fi-lazy-summer-protocol→22/100[CRITICAL]Summer.fi, a DeFi yield-optimization platform formerly known as Oasis.app that spun out of the Maker Foundation in 2021, operated the DAO-governed Lazy Summer Protocol until a July 6, 2026 exploit drained roughly $6.04 million from two of its USDC vaults via a flash-loan-funded share-price manipulation of the Fleet Commander accounting contract. Summer.fi's own post-mortem attributes the loss to an operational oversight — an old, capped strategy that was never fully removed from vault net-asset-value calculations — rather than a smart-contract bug or compromised keys. The Summer.fi Labs company announced on July 15, 2026 that it would wind down and shut off its app by August 31, 2026, leaving user compensation and the fate of roughly $4 million in illiquid affected-vault holdings to a future Lazy Summer DAO governance vote.
avoid.net/injective-npm-sdk-supply-chain-attack→62/100[CAUTIONARY]On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.
avoid.net/wanchain→32/100[WARNING]Wanchain is a blockchain interoperability project founded in 2017 by Jack Lu that operates cross-chain bridges connecting networks such as Ethereum, BNB Chain, and Cardano. On July 21, 2026, Wanchain's Cardano-to-BNB Chain bridge was exploited for approximately $10 million (515.2 million NIGHT tokens) due to a signature-reuse flaw in its TreasuryCheck validator, one of the larger cross-chain bridge exploits of 2026. The incident caused a 30-40% intraday crash in the price of NIGHT (the token of the Cardano-affiliated Midnight blockchain) and prompted Wanchain to take its bridge offline while the Midnight Foundation publicly distanced its core network from the breach.
avoid.net/ostium→32/100[WARNING]Ostium is an Arbitrum-based decentralized perpetuals exchange, founded by Harvard alumni Kaledora Kiernan-Linn and Marco Antonio Ribeiro, that offers leveraged exposure to real-world assets such as commodities, FX, and indices. On July 15, 2026, the protocol lost an estimated $18-24 million after an attacker compromised an oracle signer's private key and pushed forged, future-dated BTC/USD price reports through a component (PriceUpKeep) that Ostium's own bug bounty program had explicitly excluded from scrutiny. Ostium halted trading within roughly an hour of detection, but as of the most recent reporting the protocol had not published a final loss figure, root-cause postmortem, or reimbursement plan for affected liquidity providers.
avoid.net/philippines-sec-multi-exchange-unlicensed-operations-enforcement→20/100[CRITICAL]In August 2025, the Philippine Securities and Exchange Commission (SEC) issued public advisories naming ten major global cryptocurrency exchanges — OKX, Bybit, KuCoin, Kraken, MEXC, Bitget, Phemex, CoinEx, BitMart, and Poloniex — as operating without mandatory Crypto Asset Service Provider (CASP) registration, and directed the National Telecommunications Commission (NTC) to instruct ISPs PLDT and Smart Communications to block access to these platforms. The action follows the July 5, 2025 effectivity of SEC Memorandum Circulars No. 4 and No. 5 (Series of 2025) which established the CASP regulatory framework. Filipino users of these platforms face inability to access funds through local ISPs, no legal recourse in Philippine courts, and exposure to fraud without regulatory protection.
avoid.net/north-korea-lazarus-group-h1-2026-systematic-crypto-theft-campaign→0/100[CRITICAL]North Korea-linked threat actors, operating under cluster names including Lazarus Group and TraderTraitor (UNC4736), are alleged to have stolen approximately $643 million in cryptocurrency during the first half of 2026 — representing roughly 66% of the $972 million stolen across 207 documented incidents globally in that period, according to blockchain intelligence firm TRM Labs. Two anchor attacks, the $285 million Drift Protocol exploit on April 1 and the $292 million KelpDAO bridge exploit on April 18, together accounted for approximately 59% of all H1 2026 crypto hack losses. Cumulative DPRK-attributed crypto theft since 2017 has now exceeded $6 billion across an estimated 270+ incidents, according to multiple blockchain intelligence firms.
avoid.net/trump-memecoin-presidential-conflict-of-interest-and-retail-losses→8/100[CRITICAL]The $TRUMP token is a Solana-based memecoin launched on January 17, 2025 — three days before President Donald Trump's inauguration — by two Trump-affiliated entities, CIC Digital LLC and Fight Fight Fight LLC, which collectively retained 80% of the 1-billion-token supply under a multi-year vesting schedule. Trump's June 2026 Office of Government Ethics financial disclosure reported $635 million in royalties from the token, funneled through a licensing agreement with an entity called 'Celebration Coins' for which no public digital footprint could be found. As the token collapsed more than 97% from its January 2025 peak of approximately $74, on-chain analysis by Chainalysis attributed losses of over $700 million to retail buyers across more than 764,000 wallets, while legal experts, Senate investigators, and ethics watchdogs raised alarms that the token's anonymous purchase mechanism created an untraceable channel for gifts and influence payments to a sitting president.
avoid.net/blockfills-reliz-technology-group-holdings→4/100[CRITICAL]BlockFills, a Chicago-based institutional crypto trading and lending firm operating through parent entity Reliz Technology Group Holdings, Inc., filed Chapter 11 bankruptcy on March 15, 2026 in the U.S. Bankruptcy Court for the District of Delaware, reporting $50–100M in assets against $100–500M in liabilities. A central allegation — confirmed by debtors' own counsel at the first-day hearing — is that client funds were never segregated but were commingled with company funds on a single balance sheet, producing an estimated $77M deficit that renders clients unsecured creditors. In June 2026, Brussels-based market maker Keyrock agreed to acquire substantially all BlockFills assets for $3.25M, a figure that represents a fraction of total liabilities and raises serious doubts about meaningful client recovery.
avoid.net/mica-eu-mass-non-compliance-83-unlicensed-platform-risk→18/100[CRITICAL]The European Union's Markets in Crypto-Assets Regulation (MiCA) transitional grace period expired on July 1, 2026. Of approximately 1,200+ crypto firms that previously operated under national VASP registrations, only roughly 210–244 obtained full Crypto Asset Service Provider (CASP) authorization — a conversion rate of approximately 17–20%, leaving an estimated 83% operating in breach of EU law. ESMA confirmed on April 17, 2026 that no extensions would be granted and that unlicensed firms must cease EU services immediately; affected major exchanges include Binance (withdrew Greek application June 24, 2026), MEXC, Bitget, CoinEx, and others serving millions of European users.
avoid.net/wasabi-protocol→18/100[CRITICAL]Wasabi Protocol is a decentralized perpetual futures trading platform backed by Electric Capital, offering leveraged trading on long-tail assets including memecoins and NFTs across Ethereum, Base, Berachain, and Blast. On April 30, 2026, the protocol suffered an estimated $5–5.9 million exploit after an attacker compromised the sole deployer wallet (wasabideployer.eth), which held unchecked ADMIN_ROLE permissions across all upgradeable vault contracts with no multisig or timelock protections. The attacker drained all pool balances within approximately three minutes via UUPS proxy upgrades, subsequently routing the majority of funds through Tornado Cash.
avoid.net/trenton-johnston-crypto-social-engineering-theft-ring→2/100[CRITICAL]Trenton Richard David Johnston, a 20-year-old Canadian national, pleaded guilty on June 10, 2026 in U.S. District Court (Southern District of Florida) to conspiracy to commit money laundering in connection with a social engineering scheme that caused losses exceeding $13 million in cryptocurrency. Johnston operated as part of a broader theft ring — connected to 'The Com' hacker network — alongside co-conspirators including Miami resident Brandon Michael Tardibone and an uncharged individual identified by blockchain investigator ZachXBT as Dritan Kapllani Jr., who is alleged to be linked to approximately $19 million in total social engineering thefts. The scheme involved impersonating support representatives from Google, Trezor, and other crypto companies to trick victims into surrendering access to their digital wallets.
avoid.net/doj-global-pig-butchering-takedown-ko-thet-sanduo-giant-company→0/100[CRITICAL]In April and May 2026, the U.S. Department of Justice's Scam Center Strike Force, in coordination with the FBI, Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police, announced charges against six individuals operating three named cryptocurrency investment fraud organizations — Ko Thet Company, Sanduo Group, and Giant Company — as part of a coordinated global takedown that resulted in at least 276 arrests, dismantlement of nine scam centers, and restraint of over $701 million in cryptocurrency linked to money laundering. The operations are part of a broader law enforcement campaign against Southeast Asian pig-butchering fraud compounds that have been estimated to defraud Americans of billions of dollars annually, and are intertwined with human trafficking and forced labor.
avoid.net/polygon-zkevm→38/100[WARNING]Polygon zkEVM was a zero-knowledge rollup network launched in March 2023 by Polygon Labs, built upon the 2021 acquisition of Hermez Network for approximately $250 million in MATIC tokens. Despite early promise — including Vitalik Buterin processing the first transaction — the chain never achieved meaningful adoption, reportedly failed to implement the cost-reducing EIP-4844 blobs upgrade, and was shut down on July 1, 2026. Assets locked in DeFi smart contracts at the time of shutdown cannot be auto-migrated and may be permanently inaccessible.
avoid.net/zero-network-zerion-l2→38/100[WARNING]Zero Network was an Ethereum Layer 2 rollup launched in November 2024 by Zerion, a crypto wallet company, offering gas-free transactions via a ZK Stack architecture deployed through Caldera's rollup-as-a-service platform. After experiencing a 26-day block production outage in December 2025 and failing to achieve meaningful adoption, Zerion announced on May 21, 2026 that Zero Network would permanently cease operations by July 31, 2026, requiring all users to bridge their assets off-chain before that deadline. Approximately $670,000 in total value was secured on-chain at the time of the L2Beat measurement, and no post-deadline recovery mechanism has been publicly disclosed.
avoid.net/wojtek-kulisz-merry-sim-swap-crypto-theft-ring→2/100[CRITICAL]Wojtek Kulisz, known online as 'Merry', is a Polish national alleged by blockchain investigator ZachXBT to be among four individuals arrested in Poland on June 25, 2026, as part of a joint CBZC-FBI-HSI operation targeting an organized SIM swap crypto theft ring. The group is accused of breaching telecommunications infrastructure, hijacking victims' phone numbers, and draining cryptocurrency exchange accounts, with prosecutors estimating laundered funds in excess of tens of millions of Polish zlotys (approximately $5–$15 million USD). Polish authorities placed all four suspects in pretrial detention facing charges of participation in an organized criminal group, unauthorized computer system access, and money laundering, each carrying a maximum sentence of 25 years.
avoid.net/aztec-connect-deprecated-bridge-double-exploit-june-2026→20/100[CRITICAL]In June 2026, two separate deprecated Aztec infrastructure contracts on Ethereum were exploited within one week, draining a combined total of approximately $4.25 million. The first exploit, on June 14, targeted the legacy Aztec Connect rollup contract via a proof verification mismatch; a follow-on second attack on June 15 drained residual funds. A third, separate exploit on June 17-18 hit the deprecated Aztec Private Rollup Bridge's escapeHatch function. Aztec Labs stated it had renounced all admin keys over the affected contracts in April 2024 and that the incidents had no connection to the current Aztec Network or AZTEC ERC-20 token.
ZachXBT Intelligence · Backfilled
28Chris Larsen is the co-founder and Executive Chairman of Ripple, one of the most prominent figures in the XRP ecosystem. On January 30, 2024, attackers drained an estimated 213–283 million XRP (valued at $112.5–$150 million) from his personal cryptocurrency accounts — not Ripple corporate wallets — in what became the largest individual crypto theft of 2024. A U.S. government forfeiture complaint filed in March 2025 linked the breach to the 2022 LastPass password manager hack, alleging that private keys had been stored in an online vault subsequently compromised by attackers.
avoid.net/tornado-cash→0/100[CRITICAL]Tornado Cash is a decentralized, non-custodial cryptocurrency mixing protocol deployed on Ethereum in December 2019, co-founded by Roman Storm, Roman Semenov, and Alexey Pertsev. It was sanctioned by the U.S. Treasury's Office of Foreign Assets Control (OFAC) in August 2022 for allegedly laundering over $7 billion in virtual currency, including hundreds of millions stolen by North Korea's Lazarus Group; the sanctions were later lifted in March 2025 following a Fifth Circuit ruling that immutable smart contracts do not constitute sanctionable 'property' under IEEPA. All three co-founders face or have faced criminal proceedings: Pertsev was convicted in the Netherlands in May 2024 and sentenced to 64 months in prison, Storm was convicted on one of three counts in the U.S. in August 2025, and Semenov remains at large.
avoid.net/pink-drainer→0/100[CRITICAL]Pink Drainer was a Drainer-as-a-Service (DaaS) phishing toolkit that operated from approximately July 2023 to May 2024, facilitating the theft of over $85.3 million in cryptocurrency from more than 21,000 victims across Ethereum and other networks. The operators ran the service by licensing a sophisticated wallet-draining script to affiliate phishers for a 20-30% cut of stolen proceeds, then announced a voluntary shutdown on May 17, 2024, citing their goal as 'accomplished.'
avoid.net/inferno-drainer→0/100[CRITICAL]Inferno Drainer is a scam-as-a-service (drainer-as-a-service) platform that provided phishing infrastructure and malicious wallet-draining scripts to criminal affiliates in exchange for a percentage of stolen funds. Active from November 2022 through at least early 2025, it is attributed to stealing over $80 million from approximately 137,000 victims during its initial operational phase, with operators claiming a cumulative total exceeding $250 million across all periods including a covert post-shutdown phase. It operates by luring victims to phishing websites impersonating legitimate crypto brands, tricking users into signing malicious transactions that drain wallets across multiple EVM-compatible blockchains.
avoid.net/lazarus-group→0/100[CRITICAL]Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor, also tracked as APT38, TraderTraitor, BlueNorOff, Hidden Cobra, and ZINC, operating under the Reconnaissance General Bureau (RGB) of the Korean People's Army. Active since approximately 2009, the group has stolen an estimated $6.75 billion in cryptocurrency through targeted attacks on exchanges, bridges, and blockchain companies, using stolen funds to finance North Korea's weapons programs and circumvent international sanctions. The U.S. Department of Justice has indicted three named members, and OFAC placed the group on the Specially Designated Nationals (SDN) list in April 2022.
avoid.net/veer-chetal→2/100[CRITICAL]Veer Chetal, known online as 'Wiz,' is a 19-year-old from Danbury, Connecticut who pleaded guilty in November 2024 to conspiracy to commit wire fraud and conspiracy to launder monetary instruments in connection with a $243–245 million Bitcoin theft targeting a single Genesis creditor via social engineering. He was identified and exposed by blockchain investigator ZachXBT, who traced stolen funds on-chain and publicly named the perpetrators before law enforcement arrests were made. Chetal was re-arrested in early 2025 after committing additional crypto thefts while released on bond and faces a federal sentencing guideline range of 19–24 years imprisonment.
avoid.net/wiz-khalifa-pump-fun→2/100[CRITICAL]On November 3, 2024, unidentified scammers compromised the X (Twitter) account of rapper Wiz Khalifa (35.7 million followers) and used it to promote two fraudulent Solana meme coins — $WIZ and $WIZZLE — launched on pump.fun. The $WIZ token reached a peak market cap of approximately $2.5 million within 15 minutes before collapsing over 95% in under one hour, with at least two insider wallets extracting a combined $160,000 in profit. Blockchain investigator ZachXBT linked the incident to a broader campaign of celebrity account takeovers that allegedly stole over $3.5 million in total, and subsequently accused a former professional Fortnite player known as 'Serpent' of involvement in the coordinated scheme.
avoid.net/tradeogre→4/100[CRITICAL]TradeOgre was an unregistered, no-KYC cryptocurrency exchange founded around 2018 and known for listing privacy coins including Monero (XMR) and Pirate Chain. On September 18, 2025, the RCMP executed Canada's largest-ever cryptocurrency seizure, dismantling the platform and seizing over CAD $56 million (approximately USD $40 million) in digital assets. Investigators determined that the majority of funds transacted on the platform came from criminal sources, including ransomware proceeds, darknet market activity, hacking exploits, and fraud schemes.
avoid.net/jelly→5/100[CRITICAL]JELLY (JellyJelly / JELLYJELLY) is a Solana memecoin launched in January 2025 by Venmo co-founder Iqram Magdon-Ismail that became the center of a major market manipulation incident on Hyperliquid on March 26, 2025. A coordinated trader used a self-liquidation strategy — opening large opposing long and short positions — to force Hyperliquid's HLP liquidity vault to absorb a toxic short, causing up to $13.5 million in unrealized losses before validators emergency-delisted the token and force-settled all positions at a fixed price. The incident triggered widespread criticism of Hyperliquid's decentralization claims and raised systemic questions about perpetuals DEX risk management.
avoid.net/pumpdotfun→8/100[CRITICAL]pump.fun (operated by Baton Corporation Ltd., also listed on AVOID.NET as 'pumpdotfun') is a Solana-based meme token launchpad that launched in January 2024 and rapidly became one of the most-used token creation platforms in crypto, generating over $800 million in cumulative revenue and more than 11.9 million tokens. The platform is subject to an active RICO class action lawsuit in the SDNY alleging up to $5.5 billion in retail losses, a UK FCA regulatory ban, a $1.9 million insider flash loan exploit, documented use by North Korea's Lazarus Group for money laundering, and independent research classifying 98.6% of its tokens as rug pulls or fraud.
avoid.net/bitcoindepot→18/100[CRITICAL]Bitcoin Depot was once the largest Bitcoin ATM operator in North America, operating more than 9,000 kiosks before filing for Chapter 11 bankruptcy on May 18, 2026. The company faces lawsuits from the attorneys general of Iowa and Massachusetts alleging it knowingly facilitated crypto scams, with one state finding that more than 80% of high-value transactions at its kiosks were linked to fraud. Multiple data breaches, a $3.6 million wallet theft, regulatory enforcement in California, and on-chain evidence flagged by ZachXBT further document systemic compliance and security failures.
avoid.net/kelpdao→28/100[WARNING]KelpDAO is a liquid restaking protocol built on EigenLayer, founded in 2023, that issues rsETH as a yield-bearing liquid restaking token. On April 18, 2026, attackers attributed to North Korea's Lazarus Group (TraderTraitor / UNC4899) exploited a single-point-of-failure DVN configuration on KelpDAO's LayerZero bridge to drain 116,500 rsETH worth approximately $292 million — the largest single DeFi exploit of 2026. The attack triggered $13.21 billion in DeFi TVL outflows within 48 hours and precipitated an industry-wide bailout coalition called DeFi United, which ultimately restored rsETH to full backing by May 25, 2026.
avoid.net/nexera→32/100[WARNING]Nexera (formerly AllianceBlock) is a blockchain infrastructure protocol focused on compliant real-world asset tokenization, operating primarily on Ethereum. In August 2024, a threat actor later attributed to North Korea's Lazarus Group used social engineering and BeaverTail malware to steal smart contract management credentials, enabling unauthorized transfer of 47.24 million NXRA tokens valued at approximately $1.9 million. The team mitigated further losses by zeroing out and subsequently burning the 32.5 million tokens that remained in the attacker's wallet, limiting confirmed liquidated losses to roughly $449,000.
avoid.net/kiln→35/100[WARNING]Kiln is an institutional-grade, non-custodial staking infrastructure provider that manages over $14 billion in staked assets across 50+ proof-of-stake networks, including approximately 6% of the entire Ethereum validator set. In September 2025, Kiln suffered a sophisticated supply chain attack in which a threat actor compromised a GitHub access token belonging to a Kiln infrastructure engineer, injected malicious code into the Kiln Connect API, and caused the theft of approximately 192,600 SOL (~$41 million) from enterprise customer SwissBorg. The incident prompted Kiln to exit all 1.6 million ETH worth of its Ethereum validators as a precautionary measure, triggering the longest Ethereum exit queue backlog in the network's history.
avoid.net/bonad→38/100[WARNING]BONAD.fun is a permissionless meme token launchpad operating on the Monad blockchain, positioned as BONK's community-driven expansion from Solana into the EVM ecosystem via Monad. The platform is an independent community project not officially endorsed or vetted by the BONK Foundation, and no public smart contract audit has been documented. The platform shares brand identity and fee-recycling mechanics with Bonk.fun, the Solana-based predecessor that suffered a domain hijacking and wallet-drainer attack in March 2026 — a front-end attack vector that is directly relevant to BONAD.fun's risk surface as a structurally similar deployment.
avoid.net/nelly→40/100[WARNING]Rapper Nelly (Cornell Iral Haynes Jr.) is flagged here not as a perpetrator of crypto fraud, but as a victim of an account compromise. In October 2023, an X (formerly Twitter) account associated with Nelly — handle @NellioETH — was hacked by an unknown third party who then used it to run a social engineering phishing campaign against crypto users. Blockchain investigator ZachXBT first identified and publicized the incident; specific amounts stolen from victims and detailed on-chain forensics have not been publicly confirmed.
avoid.net/hypurr-nfts→42/100[WARNING]Hypurr NFTs are a 4,600-piece cat-themed NFT collection airdropped by the Hyper Foundation on September 28, 2025, to early Hyperliquid users who participated in the November 2024 Genesis Event. On the day of launch, blockchain investigator ZachXBT flagged the theft of eight Hypurr NFTs from compromised HyperEVM wallets, yielding approximately $400,000 in profit for the attacker. The collection itself is a legitimate product of the Hyper Foundation, but the incident exposed wallet security vulnerabilities in the HyperEVM ecosystem and coincided with a broader pattern of exploits across Hyperliquid-based protocols in late September 2025.
avoid.net/bittensor→52/100[CAUTIONARY]Bittensor is a decentralized blockchain protocol functioning as a peer-to-peer marketplace for machine intelligence, using the TAO token to reward AI model contributors. In July 2024, the protocol was the target of a supply chain attack via a malicious version of its official PyPI package, resulting in the theft of approximately $28 million in TAO tokens from 32 wallets. A civil lawsuit filed in January 2025 alleges that former Opentensor Foundation employees orchestrated the attack, and on-chain investigator ZachXBT identified a key suspect through NFT wash-trade analysis and Railgun de-mixing.
avoid.net/ledger→53/100[CAUTIONARY]Ledger SAS is a Paris-based hardware cryptocurrency wallet manufacturer founded in 2014, producing the Nano S and Nano X devices used by millions worldwide. Despite its status as a legitimate and established company, Ledger has been involved in two major security incidents: a 2020 customer database breach exposing over 1 million email addresses and 272,000 physical addresses, and a December 2023 supply chain attack on its @ledgerhq/connect-kit npm package that drained approximately $600,000–$850,000 from users of multiple DeFi protocols via the Angel Drainer malware-as-a-service. A third-party data breach via payment processor Global-e was disclosed in January 2026.
avoid.net/ton-blockchain→55/100[CAUTIONARY]TON (The Open Network) is a layer-1 blockchain originally developed by Telegram, abandoned in 2020 following an SEC enforcement action that compelled a $18.5 million penalty and $1.22 billion investor return, and subsequently revived by an independent TON Foundation. By 2024, rapid ecosystem growth attracted a significant wave of phishing campaigns, wallet drainer toolkits, pyramid schemes, and rug pull activity, with over 1,200 fraud cases reported in H1 2024 alone. In May 2026, Pavel Durov announced Telegram would reassume control as the network's largest validator, reintroducing centralization risk to a network already under scrutiny for facilitating illicit marketplaces.
avoid.net/trezor→57/100[CAUTIONARY]Trezor is a legitimate Prague-based hardware wallet manufacturer (SatoshiLabs) and one of the oldest in the industry, but it has accumulated a significant threat ecosystem around its brand. A January 2024 breach of its third-party support portal exposed contact data for approximately 66,000 users, which subsequently fueled targeted phishing campaigns delivered via email, physical mail, and fake apps. Trezor hardware devices have also been subject to disclosed physical attack vectors, including an alleged unpatchable flaw in the STM32 microcontroller used in the Trezor T model.
avoid.net/eigenlayer→58/100[CAUTIONARY]EigenLayer is a legitimate Ethereum restaking protocol operated by Eigen Labs that became a high-value target for phishing campaigns, wallet drainer attacks, and social engineering in 2024 following the launch of its EIGEN token. In October 2024 alone, the protocol's official X account was compromised to promote a fake airdrop resulting in at least $800,000 lost by one victim, and a separate email-based social engineering attack redirected approximately $5.7 million in locked investor tokens to an attacker's wallet. EIGEN holders and restakers face an elevated and persistent threat surface from impersonation sites, fake airdrop claims, and token-approval drainer schemes that exploit the protocol's name and brand recognition.
avoid.net/velodrome→62/100[CAUTIONARY]Velodrome Finance is an automated market maker (AMM) and decentralized exchange (DEX) launched on June 2, 2022, on the Optimism Layer 2 network. It is a fork and improvement of Andre Cronje's Solidly Exchange, implementing a ve(3,3) governance and liquidity incentive model. The protocol has experienced three documented security incidents: an insider theft of $350,000 by a team member in August 2022, a DNS/frontend social-engineering attack in November–December 2023 resulting in approximately $250,000 in user losses, and a second DNS hijacking in November 2025 attributed to a NameSilo registrar insider, resulting in estimated losses of $700,000–$1,000,000. Smart contracts have not been directly exploited; all monetary losses have stemmed from front-end and operational security failures.
avoid.net/porkbun→62/100[CAUTIONARY]Porkbun LLC is a legitimate ICANN-accredited domain registrar founded circa 2014-2015, headquartered in Sherwood, Oregon, and managing over 3.45 million domains. While the company is not itself a scam operation, it has attracted scrutiny from the crypto security community — including on-chain investigator ZachXBT — for hosting phishing infrastructure linked to Angel Drainer and Inferno Drainer wallet-draining services, including fake Ledger sites. Third-party tracking platforms document hundreds of flagged phishing domains registered through Porkbun and allege that the company's abuse-response enforcement has been inadequate, with a majority of reported domains remaining active after formal abuse reports.
avoid.net/compound-finance→62/100[CAUTIONARY]Compound Finance is an Ethereum-based decentralized lending protocol founded in 2017 by Robert Leshner and Geoffrey Hayes that allows users to lend and borrow cryptocurrencies algorithmically. The protocol has been subject to multiple significant security and governance incidents, including a 2021 smart contract bug that placed up to ~280,000 COMP tokens (approximately $80–90 million) at risk, a 2024 alleged governance takeover by a whale known as 'Humpy,' and a July 2024 front-end DNS hijacking attack tied to the Squarespace registrar migration. Despite these incidents, the core smart contract protocol has not been exploited; the recurring issues have primarily affected token distribution, governance integrity, and front-end infrastructure.
avoid.net/coinspot→62/100[CAUTIONARY]CoinSpot is an Australian cryptocurrency exchange founded in 2013 by Russell Wilson and headquartered in Melbourne. It is registered with AUSTRAC as a Digital Currency Exchange (since May 2018) and holds ISO 27001 certification. On November 8, 2023, the platform suffered a suspected private key compromise resulting in the loss of approximately 1,283 ETH (~$2.4 million USD), with stolen funds bridged to Bitcoin via THORChain and Wan Bridge. No customer funds were reported lost in the incident.
avoid.net/ninamo→71/100[CAUTIONARY]Ninamo is a purported crypto entity whose name was submitted for investigation on AVOID.NET. Exhaustive searches across regulatory databases, blockchain explorers, crypto news outlets, scam trackers, social media platforms, domain registries, and the Wayback Machine returned no verifiable information about any crypto project, exchange, token, or DeFi protocol operating under the name Ninamo. No wallet addresses, enforcement actions, community reports, or archived web presence could be located.
avoid.net/bybit→72/100[CAUTIONARY]Bybit is a Dubai-headquartered cryptocurrency derivatives and spot exchange founded in 2018 by Ben Zhou, serving over 80 million registered users globally. On February 21, 2025, the exchange suffered the largest cryptocurrency theft in recorded history when North Korean state-sponsored hackers attributed to the Lazarus Group (TraderTraitor) stole approximately $1.46 billion in Ethereum via a supply chain compromise of Safe{Wallet}'s frontend infrastructure. Separately, Bybit accounts have been cited in the ICIJ's 2025 Coin Laundry investigation into crypto exchanges facilitating international criminal money flows.