Skip to main content
Sign in

Avoid your next
big mistake

Crowdsourced due diligence for crypto

Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis

Browse investigationsSubmit evidenceHow it works

Featured Investigations

195·
sort:
avoid.net/asymmetric-research77/100[VERIFIED]

Asymmetric Research is a specialized blockchain security firm founded by Jonathan Claudius (formerly CSO at Jump Crypto) and Felix Wilhelm (formerly at Google Project Zero and Jump Crypto), with a team of 45+ researchers across North America, Europe, and Asia. The firm focuses on embedded, long-term security partnerships with L1/L2 blockchains and DeFi protocols, and has disclosed multiple high-severity vulnerabilities across Cosmos, Solana, Ethereum, and Circle infrastructure. No regulatory actions, fraud allegations, or client harm incidents have been identified in available sources.

avoid.net/audia6-crypto-laundering-network0/100[CRITICAL]

AudiA6 was a professional cryptocurrency money laundering service allegedly operating from 2021 through 2025, accused of processing approximately $389.7 million (EUR 336 million) in illicit funds for ransomware gangs and other cybercriminals. The service also administered the Dark2Web dark web cybercrime forum. A US-led international law enforcement operation dismantled AudiA6's infrastructure on June 10, 2026, and two alleged operators were arrested in Batumi, Georgia and charged by the US Department of Justice.

avoid.net/superior-browser-extension-campaign-wallet-drainer0/100[CRITICAL]

The 'Superior' campaign is a coordinated browser extension supply-chain attack identified by Socket Security in August 2026. Nineteen malicious Chrome and Edge extensions — collectively reaching approximately 80,000 users — deliver a multi-module malware framework capable of draining EVM, Solana, and Tron wallets, harvesting hardware-wallet seed phrases, and stealing credentials from major exchanges. The threat actor remains unidentified but has operated since at least February 2024, with confirmed infrastructure updates as recently as August 14, 2026.

avoid.net/coinsbuy-exchange-august-2026-hot-wallet-drain30/100[WARNING]

On August 9, 2026, wallets associated with Coinsbuy — a B2B crypto payment processor and exchange — were drained of approximately $7.9 million across Ethereum and TRON in a coordinated attack completed within roughly one hour. The attacker linked both chains via cross-chain swapper Bridgers and subsequently laundered the majority of proceeds through FixedFloat and into Monero; ChangeNOW froze a six-figure portion. Coinsbuy stated it covered all client losses from company reserves and offered a $100,000 bounty for information leading to the perpetrators' identification.

avoid.net/tectonic-cronos-august-2026-tonic-price-manipulation-exploit18/100[CRITICAL]

On August 30, 2026, an unknown attacker manipulated the price of TONIC — the thinly traded governance token of Tectonic, the dominant lending protocol on the Cronos blockchain — by approximately 100-fold in roughly 20 minutes, then deposited the artificially inflated tokens as collateral and borrowed an estimated $75 million in liquid assets from the protocol's pools. Cronos validators halted all block production network-wide within minutes, freezing approximately $68.7 million on-chain; roughly $6 million had already been bridged to Ethereum before the halt and could not be recovered by rollback. Validators subsequently rolled the chain back to its pre-attack state — discarding approximately 11,000 blocks and reversing nearly two hours of third-party transactions — and resumed block production at block 90,896,189 (23:49:01 UTC, August 30). As of September 1, 2026, no compensation plan, final loss figure, or formal post-mortem had been published by Tectonic or Cronos Labs.

avoid.net/cronos-chain26/100[WARNING]

Cronos is an EVM-compatible blockchain developed by Crypto.com and operated by Cronos Labs, running a capped, invitation-only validator set. On August 30, 2026, validators halted block production and executed a full chain rollback after a price-manipulation exploit drained an estimated $75 million from Tectonic, the chain's dominant lending protocol; the rollback erased approximately two hours of transaction history network-wide and recovered most of the stolen funds on-chain, while roughly $6.29 million that had already been bridged to Ethereum was not recovered. The incident reignited longstanding debates about immutability, validator centralization, and the degree of operational control Crypto.com holds over the network.

avoid.net/maya-protocol-august-2026-six-bug-exploit22/100[CRITICAL]

On August 18, 2026, an attacker exploited MAYAChain—the decentralized cross-chain liquidity network operated by Maya Protocol—by chaining six distinct software bugs in a single 23-message transaction. The exploit allowed the attacker to inflate a liquidity pool by approximately 49.45 million CACAO tokens, gain near-total control of that pool, and extract roughly $1.65–1.7 million in Bitcoin and other assets. CACAO's price fell approximately 89% and total network pool value dropped by an estimated $11 million, prompting an emergency network halt. As of late August 2026, the attacker's Bitcoin wallet remained unspent and no patch timeline or LP compensation framework had been publicly confirmed.

avoid.net/bitcoin-depot0/100[CRITICAL]

Bitcoin Depot was once the largest operator of cryptocurrency ATMs in North America, running approximately 9,700 kiosks at peak. Facing enforcement actions from at least 11 state agencies, a voluntary information request from the SEC, an FTC inquiry, and lawsuits from the attorneys general of Massachusetts and Iowa alleging the company knowingly facilitated hundreds of millions of dollars in consumer fraud, Bitcoin Depot filed for Chapter 11 bankruptcy on May 18, 2026, and immediately took its entire kiosk network offline. This page focuses specifically on the fraud facilitation angle — the mechanisms by which the ATM network was allegedly used to funnel scam proceeds, the regulatory responses that followed, and the consumer harm caused both by third-party scammers and by the abrupt bankruptcy shutdown itself.

avoid.net/more-markets17/100[CRITICAL]

More Markets is a DeFi lending protocol built on the Flow EVM blockchain by More Labs, operating as a fork of Aave V3. On August 31, 2026, an attacker exploited the protocol's E-Mode mechanism using Ankr's ankrFLOW liquid staking token as collateral to drain approximately 15.5 million WFLOW tokens, valued at roughly $9.3 million according to security firm Blockaid's initial estimate. The protocol subsequently paused operations and disputed the scale of losses reported by Blockaid, attributing the root vulnerability to a third party, though a post-mortem had not been published as of the date of this report.

avoid.net/the-sandbox-sand-oft-exploit34/100[WARNING]

On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.

avoid.net/faruk-fatih-ozer0/100[CRITICAL]

Faruk Fatih Ozer is the Turkish founder and CEO of Thodex, a cryptocurrency exchange that collapsed in April 2021 after he fled to Albania, leaving approximately 391,000 users unable to access an estimated $2 billion in funds. He was arrested in Albania in August 2022, extradited to Turkey in April 2023, and sentenced on September 7, 2023 to 11,196 years, 10 months, and 15 days in prison on charges of aggravated fraud, founding a criminal organization, and money laundering. He was found dead in Tekirdag F-Type High Security Prison on November 1, 2025, with Turkish authorities indicating initial findings pointed to suicide.

avoid.net/ruja-ignatova0/100[CRITICAL]

Ruja Ignatova, known as the 'Cryptoqueen,' is the Bulgaria-born German co-founder of OneCoin, a fraudulent pyramid scheme that defrauded approximately 3.5 million victims of more than $4 billion between 2014 and 2019. Indicted in 2017 by a U.S. grand jury on charges of wire fraud, money laundering, and securities fraud, she fled law enforcement in October 2017 and remains a fugitive. She is currently an FBI Ten Most Wanted Fugitive with a $5 million reward for information leading to her arrest.

avoid.net/hayden-davis0/100[CRITICAL]

Hayden Mark Davis (born November 27, 1996) is an American cryptocurrency marketer and CEO of Kelsier Ventures who orchestrated the launch of the $LIBRA token on February 14, 2025 — a memecoin promoted by Argentine President Javier Milei that collapsed 85–95% within hours, causing an estimated $251 million in losses across approximately 44,000 to 74,000 investors. On-chain analytics by Bubblemaps and Nansen identified insider wallets tied to Davis and associates extracting between $87 million and $107 million in liquidity during the price peak. Davis is subject to an Interpol Red Notice sought by Argentine prosecutors, a U.S. federal class action (Hurlock v. Kelsier, S.D.N.Y.), and parallel Argentine criminal proceedings; he denies fraud allegations, characterizing the collapse as 'a plan gone miserably wrong.'

avoid.net/harmony-one-august-2026-layer-1-mint-exploit16/100[CRITICAL]

On August 12, 2026, an unidentified attacker exploited two consensus-layer vulnerabilities in the Harmony ONE mainnet to mint approximately 4 billion unauthorized ONE tokens, inflating the circulating supply by roughly 26%. Approximately 97% of the minted tokens reached cryptocurrency exchange deposit wallets before freezes could be enacted. Harmony deployed an emergency patch within roughly five hours, suspended its cross-chain bridge, and subsequently executed a full blockchain rollback to the pre-exploit state of August 11, 2026, erasing more than 109,000 legitimate transactions in the process. This incident is distinct from the June 2022 Horizon bridge hack.

avoid.net/alpha-homora20/100[CRITICAL]

Alpha Homora is a leveraged yield farming protocol developed by Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) that allows users to take on leveraged positions in liquidity pools. On February 13, 2021, the protocol suffered a critical exploit in which an attacker drained approximately $37.5 million from Iron Bank (C.R.E.A.M. Finance) by exploiting multiple smart contract vulnerabilities in Alpha Homora V2, including a hidden undisclosed sUSD lending pool, a rounding miscalculation in the borrow function, and an unrestricted reserve function callable by anyone. The resulting bad debt between the two protocols remained largely unresolved for years, culminating in a public dispute in 2023 in which Iron Bank froze Alpha Homora user accounts, and Alpha Homora proposed surrendering approximately $32 million in user funds to satisfy the outstanding obligation.

avoid.net/coinhub-bitcoin-atm-fraud-facilitation-network22/100[CRITICAL]

Coinhub, operated by Nevada-based LSGT Services LLC, is one of the largest remaining Bitcoin ATM operators in the United States with approximately 2,000 machines following Bitcoin Depot's May 2026 bankruptcy. The company has faced confirmed regulatory enforcement actions in California and Connecticut, has been named in U.S. Senate correspondence over its role in facilitating elder fraud, and has been identified by the ICIJ as a major recipient of bitcoin liquidity from Kraken despite ongoing scam-related losses at its machines. Coinhub has not been charged with fraud or any crime; all regulatory findings to date relate to consumer-protection violations including excessive fees and missing disclosures.

avoid.net/lazarus-group-mach-o-man-clickfix-macos-campaign0/100[CRITICAL]

In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.

avoid.net/trezor-shipmonk-data-breach46/100[WARNING]

On August 10, 2026, Trezor disclosed that its third-party fulfillment partner ShipMonk suffered a data breach that exposed personal data for 13,689 hardware wallet customers, including names, email addresses, phone numbers, and home shipping addresses. The breach originated from an unpatched critical SQL injection vulnerability (CVE-2026-72898) in Metabase, a business-intelligence tool used by ShipMonk. Trezor's own systems, hardware wallet firmware, and customer private keys were not affected, but the exposure of verified hardware wallet owner home addresses raises direct physical safety concerns given a documented surge in violent crypto-targeted home invasions in 2026.

avoid.net/operation-economic-outcast-iran-digital-asset-sanctions0/100[CRITICAL]

Operation Economic Outcast is a U.S. Treasury-led sanctions campaign announced on August 24, 2026, that for the first time designated Iran's entire digital asset sector as a sanctionable segment of the Iranian economy under Executive Order 13902. The action designated nearly 60 entities, individuals, and vessels and issued five sectoral sanctions determinations — covering digital assets, technology, gold, aviation, and shipping — creating secondary sanctions exposure for any person or business globally that operates in or provides services to Iran's crypto sector. This page documents the regulatory framework, key designations, and compliance implications relevant to anyone interacting with Iran-adjacent protocols, wallets, or exchanges.

avoid.net/heeboo54/100[CAUTIONARY]

HEEBOO is a Solana-based entertainment launchpad and parent company to the Claynosaurz NFT brand, operating under the legal entity HEEBOO GROUP Inc. (a Delaware corporation). The project launched a fair-sale ecosystem token ($HEEBOO) on Solana in 2026 and has secured a content deal with Amazon Prime Video for a Claynosaurz animated series. While the project has a credible creative team and verifiable mainstream partnerships, the $HEEBOO token sale raised standard risk flags around the absence of a published smart-contract audit and a 12.5% treasury allocation that is fully unlocked at the token generation event.

avoid.net/pickle10/100[CRITICAL]

Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.

avoid.net/allbridge28/100[WARNING]

Allbridge is a cross-chain bridging protocol founded in 2021 that operates Allbridge Classic and Allbridge Core, supporting stablecoin transfers across more than 20 blockchains. The protocol has suffered three separate security incidents since its launch: a $573K flash loan exploit on BNB Chain in April 2023, a $1.65M flash loan attack on its Solana deployment in July 2026, and a $191K CCTP router exploit on Base in August 2026 involving forged Circle attestation messages. The recurrence of similar vulnerability classes across deployments — and the failure to apply 2023 remediations to all active chains — raises systemic concerns about the protocol's security review and deployment practices.

avoid.net/coinw60/100[CRITICAL]

CoinW6 is a fraudulent cryptocurrency trading platform at the center of the SEC's first-ever enforcement action targeting a pig butchering (relationship investment) scam, filed September 17, 2024 in the U.S. District Court for the Central District of California (Case No. 2:24-cv-07924). According to the SEC's complaint, operators of CoinW6 posed as wealthy professionals on LinkedIn and Instagram, cultivated romantic relationships with victims over WhatsApp, then directed at least 11 investors to a fake trading interface that displayed fabricated returns, stealing approximately $2.2 million between July 2022 and December 2023. As of mid-2026, the case remains pending, with the SEC seeking service by publication after defendants failed to appear.

avoid.net/web3port5/100[CRITICAL]

Web3Port is a Hong Kong-registered crypto market-making and incubation firm alleged to have orchestrated the dumping of 66 million MOVE tokens one day after the Movement Labs token launch in December 2024, generating approximately $38 million in downward price pressure. Binance subsequently banned and froze the profits of the market-making account it associated with Web3Port, citing misconduct. A U.S. Department of Justice grand jury investigation into the MOVE token launch is ongoing as of 2026, and movement Labs — the project whose token Web3Port allegedly manipulated — filed for Chapter 11 bankruptcy in July 2026.

avoid.net/ottersex50/100[WARNING]

No verifiable information about a cryptocurrency project, token, memecoin, or NFT collection named 'Ottersex' was found across public web sources, blockchain explorers, or market data aggregators as of September 2026. The entity may be an extremely obscure micro-cap or short-lived token that has left no indexed trace, or the name may be a variant spelling of another project. No risk signals, team information, or community activity could be confirmed.

avoid.net/avici38/100[WARNING]

Avici (ticker: AVICI) is a Solana-based, self-custodial neobank and crypto payment platform that launched its token via an on-chain MetaDAO sale in October 2025. On August 28–29, 2026, attackers exploited an outdated Solana card contract supplied by Avici's issuing partner Rain, draining an estimated $500,859 to over $1 million from approximately 1,685 user card accounts; Avici pledged full refunds, filed an FBI IC3 report, and the stolen funds were ultimately moved through Tornado Cash. Separately, third-party scammers created fake airdrop sites impersonating Avici to drain additional user wallets.

avoid.net/fogo38/100[WARNING]

Fogo is a Layer 1 blockchain built on the Solana Virtual Machine (SVM), designed for institutional-grade, low-latency trading and settlement. It launched its public mainnet in January 2026 after raising approximately $20.5 million across multiple funding rounds. On August 29, 2026, the Fogo Foundation disclosed a wallet breach in which an unknown actor transferred 400 million FOGO tokens (approximately 4% of total supply, valued at roughly $3.88 million at the time) to an external address, causing the token price to fall approximately 18–20%.

avoid.net/gary-wang18/100[CRITICAL]

Zixiao 'Gary' Wang is the co-founder and former Chief Technology Officer of FTX, the cryptocurrency exchange that collapsed in November 2022 following the discovery of an $8 billion shortfall caused by the misappropriation of customer funds to affiliated hedge fund Alameda Research. Wang pleaded guilty in December 2022 to four counts of wire fraud and conspiracy, served as a principal cooperating witness against former CEO Sam Bankman-Fried, and was sentenced in November 2024 to time served with three years of supervised release and $11 billion in forfeiture obligations.

avoid.net/qubit-finance5/100[CRITICAL]

Qubit Finance was a BSC-based DeFi lending and borrowing protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logical flaw in the protocol's Ethereum-BSC cross-chain bridge (QBridge), minting 77,162 qXETH without depositing any real ETH on Ethereum, ultimately draining approximately $80 million in user funds. No funds were recovered, the attacker's identity was never established, and the compensation plan announced by the team was never verifiably fulfilled.

avoid.net/prisma-fi12/100[CRITICAL]

Prisma Finance was an Ethereum-based collateralized debt position (CDP) protocol that issued stablecoins (mkUSD and ULTRA) backed by liquid staking and restaking tokens (LRTs/LSTs). On March 28, 2024, a critical input validation flaw in the MigrateTroveZap contract was exploited via flash loan, resulting in the theft of approximately 3,479 ETH (~$12 million) from user vaults. Following the exploit, the core team effectively abandoned the protocol, which was subsequently shut down via DAO governance (PIP-46) and succeeded by Resupply Finance.

avoid.net/gala-games42/100[WARNING]

Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer (co-founder of Zynga) and Wright Thurston, issuing the GALA utility and governance token. The company has been beset by a high-profile inter-founder legal dispute alleging $130 million in token theft, a May 2024 smart contract exploit in which 5 billion GALA tokens worth approximately $200–240 million were minted by a compromised admin wallet, and co-founder Wright Thurston's prior SEC lawsuit over an unrelated $18 million unregistered securities offering. These compounding governance failures, security incidents, and legal controversies place the platform among the more heavily scrutinized projects in the blockchain gaming sector.

avoid.net/euler-finance58/100[CAUTIONARY]

Euler Finance is an Ethereum-based non-custodial lending protocol founded in 2020 by Michael Bentley (PhD, Oxford) that pioneered permissionless lending for long-tail ERC-20 assets. On March 13, 2023, the protocol suffered a ~$197 million flash loan exploit — the largest DeFi hack of 2023 — caused by a missing health check in the donateToReserves() function. In an unusual outcome, the attacker, who communicated under the alias 'Jacob,' returned approximately $240 million in assets (including ETH price appreciation) over three weeks following on-chain negotiations, enabling full user restitution. The protocol relaunched as Euler V2 in September 2024 with a modular architecture, 45+ security audits, and subsequently grew TVL to over $1.5 billion by early 2025.

avoid.net/term-finance22/100[CRITICAL]

Term Finance is an Ethereum-based DeFi fixed-rate lending protocol developed by Term Labs, Inc., which raised $8 million in funding from investors including Electric Capital and Maelstrom. On August 23, 2026, an attacker bootstrapped with 2 ETH sourced from Tornado Cash, acquired majority voting control of the protocol's sparsely held DAO governance token at a cost of approximately $951, and passed malicious proposals to drain an estimated $8.5 million (2,843 ETH and 1.68 million USDC) from Term's Meta Vaults. In response, Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles; as of the time of writing, no recovery of stolen funds has been confirmed and no concrete user compensation plan has been announced.

avoid.net/coldcard-coinkite28/100[WARNING]

Coinkite is a Toronto-based company founded in 2012 that manufactures Coldcard, a Bitcoin-only hardware wallet widely regarded before 2026 as one of the most secure consumer self-custody products available. Beginning July 30, 2026, attackers exploited a firmware vulnerability introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of hardware entropy, reducing effective key strength from 128 bits to as low as 40 bits. Across four documented attack waves through early August 2026, approximately 1,816 BTC valued at roughly $116 million was drained from more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026.

avoid.net/edward-zimbardi-the-crypto-program2/100[CRITICAL]

The Crypto Program was an alleged cryptocurrency investment fraud operated by Edward Zimbardi, 59, of Flowery Branch, Georgia between June 2022 and August 2023. Prosecutors allege the scheme collected more than $165 million from over 6,000 investors worldwide by promising guaranteed 25% monthly returns on fictitious digital advertising packages. A federal grand jury indicted Zimbardi on July 8, 2026 on 25 counts; he was deported from Fiji to U.S. custody on August 14, 2026 and the case is currently pending trial.

avoid.net/snowdog5/100[CRITICAL]

Snowdog (SDOG) was an Avalanche-based OlympusDAO fork launched in November 2021 as a self-described '8-day decentralized reserve meme coin experiment' by the anonymous team behind Snowbank DAO. The project accumulated a $44 million MIM treasury before a planned token buyback on November 25, 2021, collapsed the token price by over 90% within seconds, with alleged insiders exploiting a hidden 'challengeKey' mechanism to extract approximately $20 million in profits while ordinary holders were locked out. The team declined to acknowledge deliberate wrongdoing, characterizing the event as a 'game-theory experiment gone wrong,' and subsequently renounced ownership, leaving investors with near-total losses.

avoid.net/mango-markets-v310/100[CRITICAL]

Mango Markets V3 was a Solana-based decentralized margin trading protocol that suffered a $116 million oracle manipulation attack in October 2022 executed by Avraham Eisenberg, who artificially inflated the MNGO token price to extract funds against fabricated collateral. The protocol subsequently reached a partial recovery settlement, faced SEC and CFTC enforcement actions, and formally wound down operations by January 2025.

avoid.net/cftc-crypto-atm-scam-warning5/100[CRITICAL]

On August 26–27, 2026, the U.S. Commodity Futures Trading Commission issued a formal consumer alert titled 'Pause Before You Pay: Unusual Money Transfer Instructions May Signal Fraud,' warning the public about a sharp rise in cryptocurrency ATM scams. The warning was grounded in FBI Internet Crime Complaint Center data showing that U.S. residents filed 13,460 complaints involving cryptocurrency kiosks in 2025, reporting $388,981,267 in losses — a 58% year-over-year increase. More than half of all complaints involved people over 50, who collectively reported losses exceeding $302 million, making this demographic the primary target of the attack pattern.

avoid.net/operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-20260/100[CRITICAL]

On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a whole-of-government sanctions campaign against Iran and its enablers, issuing the first-ever sectoral sanctions determination covering Iran's digital assets sector under Executive Order 13902. The action designated 78 individuals, entities, and vessels across 13 jurisdictions and structurally expanded secondary sanctions exposure so that any foreign person anywhere in the world who operates in or provides support to Iran's digital asset sector may now be designated — without OFAC needing to name them in advance. This page documents the regulatory action itself, the named designees with crypto relevance, and the compliance implications for global exchanges, OTC desks, and DeFi infrastructure.

avoid.net/ivan-obukhov-foscom-fze2/100[CRITICAL]

Ivan Obukhov is a UAE-based Ukrainian national designated by OFAC on August 24, 2026, as part of Operation Economic Outcast. U.S. Treasury alleges that since 2023 he processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Qods Force, and that he has for years brokered Iranian shadow-fleet vessels. His UAE-registered company Foscom FZE, which he acquired in 2022, was simultaneously designated under Executive Order 13224 as an entity controlled by Obukhov.

avoid.net/maya-protocol28/100[WARNING]

Maya Protocol (MAYAChain) is a decentralized cross-chain liquidity network and friendly fork of THORChain that launched its mainnet in April 2023. On August 18, 2026, an attacker chained six software vulnerabilities in a single 23-message transaction to fabricate approximately 49.45 million CACAO tokens, drain roughly $1.36 million in Bitcoin and other assets off-chain, and trigger an 88.7% collapse in CACAO's price. The team halted the network globally in response; as of late August 2026, the attacker had not returned funds, no formal post-mortem had been published by the team, and no swap-resumption timeline had been announced.

avoid.net/ofac-operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-20260/100[CRITICAL]

On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a sweeping sanctions campaign against Iran that, for the first time, designated Iran's entire digital assets sector as sanctionable under Executive Order 13902. The action named nearly 60 entities, individuals, and vessels and listed 30 crypto wallet addresses across Bitcoin, Ethereum, and TRON linked to the Mabna Institute and IRGC-Qods Force. The sectoral determination creates broad secondary sanctions exposure for any foreign crypto business — exchange, custodian, OTC desk, or DeFi protocol — that maintains material Iran-nexus counterparty relationships, regardless of whether those counterparties are individually listed.

avoid.net/the-sandbox-sand30/100[WARNING]

The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.

avoid.net/maya-protocol-mayachain12/100[CRITICAL]

Maya Protocol is a permissionless, decentralized cross-chain liquidity network built on MAYAChain, a THORChain fork that launched mainnet in April 2023. On August 18, 2026, the protocol suffered its first documented loss-of-funds incident: an attacker chained six software vulnerabilities in a single 23-message transaction to extract approximately $1.36 million in hard assets (including 20.83 BTC) and trigger a broader pool-value impact estimated at $11 million, while CACAO crashed 89%. MAYAChain halted all operations on August 18, 2026, and has not resumed as of August 23, 2026; no funds have been returned.

avoid.net/kyle-davies3/100[CRITICAL]

Kyle Davies is the co-founder of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion in liabilities owed to 27 creditors. Following the collapse, Davies evaded liquidators, was sentenced in absentia to four months imprisonment in Singapore for failing to cooperate with court-ordered investigations, and received a nine-year ban from Singapore's Monetary Authority of Singapore (MAS) for regulatory violations including providing false information to regulators. He subsequently co-founded OPNX, a crypto bankruptcy claims exchange that also failed and shut down in early 2024.

avoid.net/su-zhu3/100[CRITICAL]

Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.

avoid.net/orbit-chain-bridge8/100[CRITICAL]

Orbit Bridge is the cross-chain bridging protocol of Orbit Chain, developed by South Korean blockchain company Ozys. On December 31, 2023, attackers compromised seven of ten multisig private keys and drained approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Ethereum vault in the largest crypto hack of New Year's Eve 2023. The attack has been attributed with medium-to-high confidence to North Korea's Lazarus Group, with an additional alleged insider-threat dimension involving Ozys' former chief information security officer, who allegedly sabotaged the company firewall weeks before the exploit.

avoid.net/superrare45/100[WARNING]

SuperRare is a curated Ethereum-based NFT art marketplace founded in 2018 by John Crain, Charles Crain, and Jonathan Perkins, operating as a high-end platform for 1-of-1 digital artworks with its own governance token RARE. On July 28, 2025, a critical access control vulnerability in the platform's RareStakingV1 staking contract was exploited, resulting in the theft of approximately 11.9 million RARE tokens worth roughly $731,000. SuperRare subsequently reimbursed the 61 affected wallets by August 5, 2025, and the RARE token recovered approximately 41% following the remediation announcement.

avoid.net/axiom-dex-insider-trading-202622/100[CRITICAL]

In February 2026, blockchain investigator ZachXBT published findings alleging that employees of Axiom Exchange, a Y Combinator-backed Solana trading platform, abused internal customer support dashboards to track private user wallet activity and execute insider trades over approximately one year. The alleged scheme, centered on senior business development employee Broox Bauer, exploited the platform's lack of role-based access controls to compile non-public trading data on high-profile crypto traders, with a secondary layer of alleged front-running on Polymarket prediction markets using advance knowledge of ZachXBT's impending report. No formal criminal charges had been publicly announced as of the investigation's release.

avoid.net/nishad-singh12/100[CRITICAL]

Nishad Singh is a former software engineer who served as Director of Engineering at FTX, the cryptocurrency exchange that collapsed in November 2022 following the misappropriation of more than $8 billion in customer funds. Singh pleaded guilty in February 2023 to six criminal charges including wire fraud, commodities fraud, securities fraud, money laundering conspiracy, and campaign finance violations, and was sentenced in October 2024 to time served with no prison after providing extensive cooperation against FTX founder Sam Bankman-Fried. A supplemental CFTC civil settlement was reached in April 2026, requiring Singh to disgorge $3.7 million and subjecting him to a five-year trading ban.

avoid.net/novatech-ltd2/100[CRITICAL]

NovaTech Ltd. (also marketed as NovaTech FX) was a crypto trading and multi-level marketing program incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion from June 2019 through May 2023. The SEC alleges it raised more than $650 million from over 200,000 investors worldwide — largely from Haitian-American communities — while conducting only a small fraction of the promised trading. The scheme collapsed in May 2023; the SEC filed civil fraud charges in August 2024 and the Petions had not been served as of mid-2025, reportedly located in Panama.

avoid.net/curve-finance62/100[CAUTIONARY]

Curve Finance is a major decentralized exchange (DEX) on Ethereum optimized for stablecoin and pegged-asset trading, operating since January 2020. On July 30, 2023, a latent vulnerability in the Vyper smart-contract compiler (versions 0.2.15, 0.2.16, and 0.3.0) was exploited across multiple Curve liquidity pools, draining approximately $70 million and triggering a near-systemic crisis when the resulting CRV price drop threatened to cascade-liquidate founder Michael Egorov's heavily collateralized on-chain loans. Roughly 73% of stolen funds were ultimately recovered or returned, and in December 2023 the Curve DAO voted to disburse approximately $49 million in compensation to affected liquidity providers.

avoid.net/wormhole-bridge63/100[CAUTIONARY]

Wormhole Bridge is a cross-chain messaging and token bridge protocol originally developed by Certus One, later owned by Jump Crypto, enabling asset transfers between Solana, Ethereum, and other blockchains. On February 2, 2022, an attacker exploited a signature verification flaw in the Solana-side smart contract to fraudulently mint 120,000 wrapped ETH (wETH) worth approximately $320–326 million without posting collateral, making it the second-largest DeFi exploit in history at the time. Jump Crypto replenished the stolen ETH within 24 hours to prevent ecosystem collapse, and a court-authorized counter-exploit in February 2023 recovered approximately $140 million of the remaining stolen funds.

avoid.net/cetus-protocol28/100[WARNING]

Cetus Protocol is a concentrated liquidity market maker (CLMM) decentralized exchange deployed on the Sui and Aptos blockchains. On May 22, 2025, the protocol suffered one of the largest DeFi exploits in history when an attacker exploited an integer overflow vulnerability in its smart contract math library to drain approximately $223 million from liquidity pools. Roughly $162 million was frozen on-chain through emergency validator action by the Sui network, and following a governance vote the protocol relaunched in June 2025 with partial user compensation.

avoid.net/bitcoin-latinum-ltnm-donald-basile2/100[CRITICAL]

Bitcoin Latinum (LTNM) is a cryptocurrency token launched in 2020 by Donald G. Basile through his companies GIBF GP, Inc. and Monsoon Blockchain Corporation. In April 2026, the U.S. Securities and Exchange Commission charged Basile with orchestrating a $16 million investor fraud scheme, alleging he raised funds through Simple Agreements for Future Tokens (SAFTs) using fabricated insurance coverage claims and nonexistent asset-backing structures, then diverted millions to personal expenses. The token, which peaked near $9,336 in December 2021, has since collapsed to near zero, and multiple civil lawsuits from defrauded investors preceded the SEC action.

avoid.net/transit-finance2/100[CRITICAL]

Transit Finance (also known as Transit Swap) is a cross-chain DEX aggregator supporting over 122 decentralized exchanges across Ethereum, BNB Chain, TRON, Solana, Polygon, and other networks. The protocol has suffered two confirmed security exploits: a $28.9 million hack in October 2022 due to an arbitrary external call vulnerability in its routing contract, with approximately $18.9 million recovered; and a second $1.88 million exploit in May 2026 via a deprecated TRON smart contract that remained on-chain and exploitable years after official deprecation. ZachXBT flagged the protocol amid broader DeFi monitoring, and the 2022 attacker routed funds through OFAC-sanctioned Tornado Cash.

avoid.net/eminence10/100[CRITICAL]

Eminence Finance (EMN) was an unfinished, unaudited NFT gaming protocol being developed by Yearn Finance founder Andre Cronje that was exploited on September 29, 2020, resulting in the theft of approximately $15 million in DAI from its bonding curve contracts. The contracts had never been officially announced or released to the public, but community members discovered and deposited into them after Cronje's cryptic tweets; the attacker returned $8 million to Cronje's deployer address but $7 million was never recovered. The incident became a defining case study in DeFi's 'degen' culture and the risks of deploying unaudited smart contracts to Ethereum mainnet.

avoid.net/yearn-finance58/100[CAUTIONARY]

Yearn Finance is a decentralized yield aggregator on Ethereum that routes user deposits into lending protocols to maximize returns. Founded by Andre Cronje in 2020, the protocol has suffered at least four documented security exploits between 2021 and 2025, with aggregate losses exceeding $20 million, and its founder departed in 2022 citing sustained pressure from an SEC investigation. Governance concerns, an interconnected web of affiliated DeFi protocols implicated in their own major hacks, and repeated failures to deprecate vulnerable legacy code compound the protocol's risk profile.

avoid.net/vee-finance12/100[CRITICAL]

Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.

avoid.net/compound-v228/100[WARNING]

Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.

avoid.net/pnetwork12/100[CRITICAL]

pNetwork is a cross-chain bridge and interoperability protocol built on the pTokens architecture, enabling assets to move between Bitcoin, Ethereum, BNB Chain, and other networks via wrapped synthetic tokens. The protocol has suffered two major security incidents — a September 2021 pBTC-on-BSC hack losing approximately $12 million, and a November 2022 pGALA incident that triggered a $28 million lawsuit by Gala Games and Huobi alleging pNetwork's own engineers caused the vulnerability through a leaked private key, then allegedly profited from a self-described 'white hat' rescue. As of 2025, the PNT governance token trades at a fraction of its 2021 peak and the protocol operates with negligible market capitalization and trading volume.

avoid.net/prismalst10/100[CRITICAL]

Prisma Finance is a Liquity-forked, Ethereum-based DeFi protocol that allowed users to mint overcollateralized stablecoins (mkUSD and ULTRA) against liquid staking tokens (LSTs) such as wstETH, rETH, sfrxETH, and cbETH. On March 28, 2024, a critical vulnerability in the protocol's MigrateTroveZap helper contract was exploited for approximately $11.6 million, with a total loss across all attacker wallets of roughly $12.3 million; the primary exploiter sent the majority of stolen funds through Tornado Cash while claiming a 'whitehat rescue,' and as of 2026 the protocol's TVL has collapsed from a pre-exploit peak of approximately $220 million to under $300K.

avoid.net/unibtc32/100[WARNING]

uniBTC is a synthetic Bitcoin liquid restaking token issued by Bedrock protocol, enabling wBTC holders to earn BTC-native yield via the Babylon staking protocol while retaining liquidity. In September 2024, a critical minting vulnerability in multiple uniBTC vault smart contracts across eight blockchains was exploited for approximately $2 million after a third-party security firm disclosed the flaw hours before the attack. Post-incident forensics by Fuzzland, disclosed in June 2025, attributed the exploit to an insider threat — a former employee who embedded malware into Fuzzland's internal codebase and used privileged access to execute the attack; Bedrock has since integrated Chainlink Proof of Reserve and expanded to multiple new chains.

avoid.net/kinto-bridge28/100[WARNING]

Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.

avoid.net/curve-llamalend52/100[CAUTIONARY]

Curve LlamaLend (also referred to as the crvUSD lending markets) is a decentralized, permissionless isolated lending protocol built by Curve Finance that allows users to borrow crvUSD against crypto collateral using the LLAMMA soft-liquidation mechanism. The protocol has experienced multiple distinct incidents since launch: a $10 million bad-debt event in June 2024 tied to the founder's oversized leveraged positions, an oracle-manipulation attack on the sDOLA market in March 2026 resulting in approximately $240,000 in borrower losses, an October 2025 market crash that left the CRV-long vault approximately $700,000 underbacked, and a May 2026 third-party exploit (Stake DAO) that forced the sunsetting of an associated Arbitrum LlamaLend market. The protocol's core contracts have not been directly compromised by a code-level hack, but recurring bad-debt events, oracle design flaws in permissionlessly created markets, and governance concentration risks have drawn sustained scrutiny including a flag from on-chain investigator ZachXBT.

avoid.net/axiom-exchange-employee-insider-trading-scandal30/100[WARNING]

Axiom Exchange is a Y Combinator-backed, non-custodial Solana trading terminal founded in 2024 that generated over $390 million in revenue within roughly a year of launch. On February 26, 2026, blockchain investigator ZachXBT published findings alleging that at least one senior employee, Broox Bauer, systematically abused internal customer support tools to access private wallet data and share it with outside parties for front-running purposes, a scheme alleged to have operated for approximately ten months. The company issued a statement expressing disappointment, revoked access to the affected tools, and pledged an internal investigation, but no formal regulatory or legal charges had been announced as of the time of this report.

avoid.net/pancakebunny18/100[CRITICAL]

PancakeBunny was a Binance Smart Chain yield aggregator and optimizer built by a team known as Mound, launched in December 2020. The protocol suffered two major flash loan exploits in 2021: a May 20, 2021 attack that caused the BUNNY token to crash over 95% and wiped out approximately $200 million in market capitalization, and a July 16, 2021 attack on its Polygon fork PolyBunny that resulted in $2.4 million in losses. Both exploits stemmed from oracle price manipulation vulnerabilities in the minting reward logic, and the protocol has never recovered to its pre-exploit state.

avoid.net/beanstalk-farms28/100[WARNING]

Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.

avoid.net/ranger-finance22/100[CRITICAL]

Ranger Finance was a Solana-based perpetual contract aggregator that raised $1.9M in seed funding in January 2025 and launched its RNGR token in January 2026. Within two months of token launch, community governance voted to liquidate the project treasury following allegations that the team made materially misleading claims about trading volume and revenue during its ICO. The project formally shut down in May 2026 after the treasury liquidation and approximately $900,000 in exposure from the DPRK-linked Drift Protocol exploit left operations unsustainable, with employees and vendors not fully compensated.

avoid.net/paid-network12/100[CRITICAL]

PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.

avoid.net/bunny10/100[CRITICAL]

PancakeBunny (Bunny Finance) was a Binance Smart Chain yield-optimizer developed by the anonymous team MOUND (Mound Inc.), which received a $1.6 million seed round led by Binance Labs in April 2021. The protocol suffered three separate exploits across 2021–2022 totaling over $127 million in losses, including a $45 million flash loan attack in May 2021, a $2.4 million polyBUNNY exploit on Polygon in July 2021, and an $80 million hack of its affiliated lending protocol Qubit Finance in January 2022. The BUNNY token has lost more than 99% of its all-time high value, the protocol transitioned to a DAO structure in early 2022, and no stolen funds from any exploit were publicly confirmed as recovered.

avoid.net/burgerswap22/100[CRITICAL]

BurgerSwap is a decentralized exchange (DEX) and automated market maker (AMM) protocol launched in September 2020 on Binance Smart Chain (BSC), built around the native BURGER governance token. On May 28, 2021, the protocol suffered a flash loan and reentrancy exploit that drained approximately $7.2 million in user funds across 14 transactions. Uniswap founder Hayden Adams publicly noted that a critical line of code enforcing the constant-product formula had been deliberately removed from BurgerSwap's fork of Uniswap v2, raising allegations of an intentional vulnerability or insider involvement by the anonymous development team.

avoid.net/aperocket22/100[CRITICAL]

ApeRocket is a DeFi yield farming aggregator and optimizer originally deployed on Binance Smart Chain (BSC) and Polygon in 2021. The protocol suffered two simultaneous flash loan exploits on July 14, 2021, resulting in combined losses of approximately $1.26 million and a 63% collapse in its native SPACE token price. The project attempted a V2 relaunch with improved security, but the SPACE token currently shows zero trading volume and effectively zero market capitalization, indicating the protocol is inactive.

avoid.net/bondly22/100[CRITICAL]

Bondly Finance is a DeFi and NFT protocol launched in September 2020 that suffered a major exploit on July 14-15, 2021, in which 373 million BONDLY tokens were minted via owner-level credentials and sold into liquidity pools, causing an 82% token price collapse and approximately $5.9-7.5 million in losses. The exploit originated from the protocol owner's address, prompting blockchain security firm PeckShield to allege a potential rug pull, though the team attributed it to compromised credentials belonging to CEO Brandon Smith. Following acquisition by Animoca Brands in September 2021 and a rebrand to Forj in May 2022, the project has undergone significant leadership changes; the original founder departed under a cloud of unresolved questions about the exploit's true origin.

avoid.net/qubit10/100[CRITICAL]

Qubit Finance was a Binance Smart Chain lending and cross-chain bridge protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logic error in the QBridge Ethereum-BSC bridge to mint approximately 77,162 qXETH tokens without depositing any ETH, then drained roughly $80 million in protocol assets; no funds were ever recovered and the attacker was never identified.

avoid.net/sudorare2/100[CRITICAL]

SudoRare was an anonymous NFT automated market maker (AMM) protocol launched on August 23, 2022, presented as a fork of SudoSwap and LooksRare. Approximately six hours after launch, the anonymous development team executed a premeditated rugpull via a backdoored smart contract, draining approximately 519 ETH (valued at $815,000–$852,000) from user deposits before deleting all online presence. Blockchain security firms PeckShield and CertiK traced a funding wallet to Kraken, but no public arrests or legal proceedings have been reported.

avoid.net/gmx-v1-perps28/100[WARNING]

GMX V1 was a decentralized perpetual exchange on Arbitrum and Avalanche that operated from September 2021 until July 2025, when a reentrancy exploit drained approximately $42 million from its GLP liquidity pool. The protocol has since disabled all V1 trading and GLP minting; it is no longer an active product, with users directed to GMX V2, which was unaffected by the exploit.

avoid.net/themis-protocol32/100[WARNING]

Themis Protocol is a DeFi lending and borrowing platform deployed on Arbitrum that allows users to collateralize Uniswap v3 LP positions and Balancer LP tokens to borrow stablecoins and blue-chip assets. On June 27, 2023, approximately eleven days after its beta launch, the protocol suffered a flash loan oracle manipulation exploit resulting in approximately $370,000 in losses. The attacker laundered the stolen funds via Tornado Cash, the protocol was suspended indefinitely, and TVL effectively dropped to near zero following the incident.

avoid.net/stakecom28/100[WARNING]

Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.

avoid.net/radiant-v210/100[CRITICAL]

Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that suffered two significant security incidents in 2024: a $4.5 million flash loan exploit in January 2024 and a far more devastating $50 million multisig compromise in October 2024. The October hack, attributed by Mandiant with high confidence to North Korean state-sponsored group UNC4736 (Citrine Sleet / AppleJeus), involved a months-long social engineering campaign, macOS malware deployment on developer devices, and manipulation of hardware wallet signing interfaces to drain funds across BNB Chain and Arbitrum.

avoid.net/fixedfloat10/100[CRITICAL]

FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.

avoid.net/curio10/100[CRITICAL]

Curio (CurioDAO) is a multi-chain real-world asset (RWA) DeFi protocol that suffered a critical smart contract exploit on March 23, 2024, resulting in approximately $16 million in losses after an attacker exploited a voting-power privilege escalation vulnerability to mint approximately 1 billion unauthorized CGT governance tokens. The protocol had no known third-party security audits prior to the exploit and relied on internal reviews. Curio announced a recovery plan including a new CGT 2.0 token and a phased compensation program, though independent verification of full compensation delivery remains limited.

avoid.net/grand-base5/100[CRITICAL]

Grand Base was a decentralized real-world asset (RWA) synthetic trading protocol launched on Coinbase's Base layer-2 blockchain in early 2024. On April 15, 2024, the protocol suffered a critical security incident in which its deployer wallet was compromised, allowing an attacker to mint approximately 32.5 million unauthorized GB tokens and drain roughly $2 million in liquidity. The GB token subsequently lost over 99% of its value; no verified recovery or compensation plan has been confirmed, and the project's long-term operational status remains uncertain.

avoid.net/leadblocks-morpho-blue-market38/100[WARNING]

LeadBlock's Morpho Blue Market refers to a permissionless lending market and associated MetaMorpho vault curated by LeadBlock Partners on the Morpho Blue protocol. On October 13, 2024, an oracle misconfiguration in the LeadBlock-curated PAXG/USDC market enabled an opportunistic user to borrow approximately $230,000 in USDC against only $350 of PAXG collateral, exploiting an overvalued asset price of $2.6 trillion per unit of gold. The incident was attributed to an incorrectly configured SCALE_FACTOR by LeadBlock's oracle provider and raised questions about the adequacy of pre-launch testing and risk curation practices.

avoid.net/impermax-v332/100[WARNING]

Impermax V3 is the third major iteration of Impermax Finance, a DeFi leveraged yield-farming and lending protocol that allows liquidity providers to use Uniswap V3 LP tokens as collateral. The protocol suffered two separate critical exploits in 2025 — a ~$300,000 flash-loan collateral valuation attack in April and a ~$380,000 liquidation logic exploit in November — both on the Base chain, resulting in cumulative losses exceeding $680,000 and leaving lenders with unresolved bad debt. These incidents follow a 2022 private key compromise affecting the IMX token, representing a recurring pattern of security failures across the protocol's history.

avoid.net/foom-cash28/100[WARNING]

FOOM Cash (foom.cash) is a pseudonymous, privacy-focused decentralized lottery protocol built on Ethereum and Base, marketed as an 'upgraded Tornado Cash' using zk-SNARKs cryptography. On February 26, 2026, the protocol suffered a $2.26 million exploit caused by a critical deployment error in its Groth16 trusted setup — a flaw publicly known from an identical exploit on Veil Cash days earlier that the team failed to patch. The team had been silent for approximately three months prior to the attack and was subsequently flagged as a notable risk by AVOID.NET due to compounding concerns: anonymous founders, serious operational negligence, misleading post-incident communications, and unverifiable audit claims.

avoid.net/socket-security-malicious-browser-extension-campaign-august-20262/100[CRITICAL]

On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.

avoid.net/evmos-network30/100[WARNING]

Evmos was a Cosmos-based, EVM-compatible proof-of-stake blockchain developed by Tharsis Labs that launched on mainnet in April 2022 and raised $27 million in a token sale led by Polychain Capital. The network was formally shut down on approximately May 18, 2026, after Governance Proposal #331 passed with 99.8% approval, halting all block production at block height 37,318,000. Following discontinuation, an authorization vulnerability in the Evmos vesting and lockup module — left unpatched because the codebase was no longer maintained — was exploited in August 2026 to drain approximately $3 million from BounceBit Chain, a third-party network built on the Evmos stack.

avoid.net/term-finance-governance-exploit-august-202610/100[CRITICAL]

On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.

avoid.net/the-sandbox-sand-bridge-exploit38/100[WARNING]

On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.

avoid.net/defi-governance-attack-wave-20260/100[CRITICAL]

Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.

avoid.net/coinkite-coldcard13/100[CRITICAL]

Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.

avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-202638/100[WARNING]

On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.

avoid.net/h1-2026-crypto-hack-landscape-ai-agent-attack-vector-emerges0/100[CRITICAL]

The first half of 2026 established a new all-time record for cryptocurrency exploit frequency, with 207–212 verified incidents (varying by methodology) resulting in $972 million to $1.32 billion in losses depending on the reporting firm. North Korea's Lazarus Group (TraderTraitor subunit) was responsible for approximately 55–66% of total losses through two concentrated attacks in April 2026, while AI-powered autonomous agents emerged as a distinct and novel attack surface for the first time in widely documented crypto security history.

avoid.net/june-2026-cross-chain-bridge-exploit-127m-three-protocols10/100[CRITICAL]

An alleged coordinated cross-chain bridge exploit on June 14, 2026 is described as draining $127 million from three DeFi protocols — identified only as BridgeLink, CrossFlow, and Relay Protocol — across Ethereum, Arbitrum, and Polygon in under 12 minutes. This specific incident, including the protocol names, the $127M figure, and the 03:42 UTC timestamp, cannot be independently verified through any Tier 1 or Tier 2 source as of June 30, 2026; the sole primary source is a blog post by Nadcab Labs, an Indian blockchain development services company with a commercial interest in publishing DeFi security content. While a severe pattern of verified cross-chain bridge exploits across 2026 provides real context, the specific claims in this investigation request should be treated as unverified until corroborated by credible on-chain analysis or major news coverage.

avoid.net/abracadabra-money-mim-depeg-june-202612/100[CRITICAL]

Abracadabra Money's Magic Internet Money (MIM) stablecoin experienced a severe depeg event in June 2026, falling from its $1 target to approximately $0.43–$0.50, a collapse of over 50%. The crisis built over ten days beginning June 15, 2026, and was accompanied by $994 million in cross-market liquidations and a broader crypto market downturn. Emergency measures launched June 25 — including sharply raised Cauldron interest rates and suspended Curve bribes — represent the protocol's fourth major stability incident since 2024.

avoid.net/abracadabra-finance-mim-stablecoin22/100[CRITICAL]

Abracadabra Finance is a multi-chain DeFi lending protocol that allows users to mint its USD-pegged stablecoin Magic Internet Money (MIM) against interest-bearing collateral. The protocol has suffered four significant security exploits between January 2024 and October 2025, with cumulative losses exceeding $21 million, and its MIM stablecoin depegged twice in a single week in June 2026 — reaching as low as $0.80 — due to critically thin DEX exit liquidity. As of mid-June 2026, MIM was trading approximately 18% below its $1 peg, with the protocol relying on a 140 million SPELL token incentive program to attract liquidity providers.

avoid.net/bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m0/100[CRITICAL]

BridgeLink, CrossFlow, and Relay Protocol are three DeFi bridge protocols alleged to have been drained of a combined $127 million in a coordinated cross-chain exploit beginning at 03:42 UTC on June 14, 2026. The incident is described as exploiting a signature replay vulnerability combined with premature finality acceptance across Ethereum, Arbitrum, and Polygon. As of June 16, 2026, no Tier 1 or Tier 2 sources — including CoinDesk, The Block, Reuters, or Bloomberg — have published corroborating coverage, and no on-chain transaction hashes or official protocol statements have been publicly produced; the investigation page reflects low source confidence accordingly.

avoid.net/afi-protocol37/100[WARNING]

AFI Protocol (Artificial Financial Intelligence) is a DeFi infrastructure project building Proof-of-Reserve systems for Real-World Assets (RWAs) on Ethereum, offering yield-bearing ERC-4626 vaults backed by tokenized off-chain collateral. The protocol reported over $225 million in total value locked as of mid-2026 and maintains institutional partnerships with Multipli, Pendle, Morpho, and others. On May 30, 2026, the protocol suffered a $480,000 exploit targeting its afiUSD vault, with stolen funds partially laundered through Tornado Cash; recovery efforts were ongoing as of June 2026.

avoid.net/lucifer-drainer0/100[CRITICAL]

Lucifer Drainer is a criminal drainer-as-a-service (DaaS) platform that industrializes cryptocurrency wallet theft through a structured affiliate model. Active since at least early 2025, it operates by providing affiliates with phishing kits, automated site-cloning tools, and commission-split infrastructure (operators retain 20% per successful drain) while affiliates supply phishing traffic. Despite Telegram bot bans in August 2025 and documentation domain suspension in November 2025, the operation migrated to IPFS and remained active as of May 2026, making it one of the most operationally resilient drainer platforms in the current threat landscape.

avoid.net/lcx-exchange52/100[CAUTIONARY]

LCX Exchange (Liechtenstein Cryptoassets Exchange) is a regulated crypto trading platform incorporated in Liechtenstein and registered with the country's Financial Market Authority (FMA). On January 8, 2022, the exchange suffered a hot wallet compromise resulting in the theft of approximately $6.8–7.94 million in various cryptocurrencies; LCX subsequently covered all user losses from company funds and cooperated with multi-jurisdictional law enforcement, ultimately freezing approximately 60% of stolen assets. As of 2024–2025, LCX remains operational, holds multiple licenses under the Liechtenstein Blockchain Act (TVTG), and has filed a pre-application for a pan-European MiCA license.

avoid.net/cryptospain-lvaro-romillo-madeira-invest-club3/100[CRITICAL]

Álvaro Romillo Castillo, a Spanish crypto influencer known online as CryptoSpain, was arrested on November 6, 2025, and ordered held without bail by Spain's National Court on charges of mass fraud and leading a criminal organization through Madeira Invest Club (MIC). Prosecutors allege MIC operated as a Ponzi scheme from early 2023 through September 2024, collecting approximately €185.5 million from 3,062 investors across multiple countries by promising guaranteed returns of up to 20% on fictitious luxury-asset contracts. As of May 2026, ten defendants have been formally charged and the case remains in pre-trial proceedings before Judge José Luis Calama; no verdict has been entered.

avoid.net/balancer42/100[WARNING]

Balancer is a decentralized automated market maker (AMM) protocol on Ethereum, founded in 2018 by Fernando Martinelli and Mike McDonald, that allows multi-token liquidity pools with customizable weighting. The protocol has suffered six documented security incidents between 2020 and 2025, resulting in cumulative losses exceeding $140 million, including a catastrophic $128 million exploit in November 2025 caused by an arithmetic precision flaw in Composable Stable Pool contracts. Despite multiple audits by major firms including Trail of Bits, OpenZeppelin, and Certora, systemic smart contract vulnerabilities and a highly complex protocol architecture have repeatedly exposed user funds to loss.

avoid.net/abracadabra-money28/100[WARNING]

Abracadabra Money is a multi-chain DeFi lending protocol founded in 2021 that allows users to mint Magic Internet Money (MIM), a USD-pegged stablecoin, using interest-bearing tokens as collateral. The protocol has suffered four significant security incidents between 2022 and 2025, losing over $21 million in aggregate, and its MIM stablecoin has lost its dollar peg on multiple occasions. The protocol is also linked to the Wonderland/Sifu scandal of early 2022, which caused severe reputational and financial contagion across its interconnected 'Frog Nation' ecosystem.

avoid.net/uwulend8/100[CRITICAL]

UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave, founded in September 2022 by Michael Patryn (pseudonym 0xSifu), co-founder of the collapsed Canadian crypto exchange QuadrigaCX. In June 2024, the protocol suffered two successive exploits totaling approximately $23 million — a $19.3 million oracle manipulation attack on June 10 followed by a $3.7 million secondary drain on June 13 by the same attacker — rendering it one of the largest DeFi hacks of 2024. The protocol's association with a founder carrying prior criminal convictions and a history of involvement in failed or scandal-ridden crypto ventures constitutes a persistent and material reputational and risk concern.

avoid.net/lifi-protocol38/100[WARNING]

LI.FI (formerly Li.Finance) is a cross-chain liquidity aggregation protocol founded in 2021 that routes swaps across bridges and DEXs via a unified API, SDK, and widget. The protocol has suffered two distinct smart contract exploits — a $600,000 approval drain in March 2022 and an approximately $11.6 million drain in July 2024 — with security firm PeckShield noting the root causes were 'basically the same.' Both incidents involved arbitrary-call vulnerabilities that allowed attackers to abuse users' infinite token approvals, raising concerns about repeated security failures despite prior disclosure.

avoid.net/anubis-dao2/100[CRITICAL]

AnubisDAO was a dog-themed DeFi project that launched a 24-hour token sale on October 28, 2021, raising approximately 13,597 ETH (~$60 million) through the sale of its native ANKH token on the Copper liquidity bootstrapping platform. Twenty hours into the fundraise, all pooled funds were drained to an external wallet by the address that had created and controlled the liquidity pool, leaving investors holding worthless ANKH tokens with no liquid market. No funds have been recovered; the project had no website, whitepaper, or publicly identified team at launch.

avoid.net/libra-token2/100[CRITICAL]

LIBRA ($LIBRA) is a Solana-based memecoin launched on February 14, 2025 by Kelsier Ventures as part of the 'Viva La Libertad' project, and publicly endorsed by Argentine President Javier Milei minutes after its creation. Within roughly one hour, the token's market cap peaked near $4.6 billion before crashing approximately 89% as insider wallets linked to the founding team extracted an estimated $87–107 million in liquidity, leaving an estimated 44,000–114,000 retail investors with severe losses. The incident triggered over 112 criminal complaints in Argentina, a federal fraud investigation, congressional proceedings, international asset freezes, and an Interpol Red Notice request against key operator Hayden Davis.

avoid.net/avraham-eisenberg2/100[CRITICAL]

Avraham Eisenberg, also known as 'Avi Eisenberg,' is a crypto trader who in October 2022 executed an oracle manipulation attack against Mango Markets, a Solana-based DeFi protocol, extracting approximately $110–117 million in digital assets. He publicly claimed the scheme was a 'highly profitable trading strategy' and a legal use of the protocol, returned approximately $67 million after a DAO-mediated settlement, and was subsequently charged by the DOJ, SEC, and CFTC. A federal jury convicted him in April 2024, but a federal judge vacated all criminal convictions in May 2025 on grounds of improper venue and insufficient evidence of material misrepresentation; prosecutors have appealed. Eisenberg is currently serving a separate 52-month federal prison sentence for possession of child sexual abuse material.

avoid.net/zkasino3/100[CRITICAL]

ZKasino was a Web3 gambling platform that raised approximately $33 million from over 10,000 investors through a 'Bridge-to-Earn' campaign in early 2024, promising depositors their ETH would be returnable within 30 days. Instead, the platform converted depositor ETH into its native ZKAS tokens and staked the funds on Lido without user consent, prompting Dutch authorities (FIOD) to arrest founder Elham Nourzai in April 2024 and seize over EUR 11 million in assets. A second suspect linked to the WhiteRock token project was arrested in the UAE in July 2025 and faces extradition to the Netherlands, while partial refunds to affected depositors remained incomplete as of late 2025.

avoid.net/mango-markets12/100[CRITICAL]

Mango Markets was a Solana-based decentralized trading platform offering spot trading, perpetual futures, and lending with cross-margining. In October 2022, trader Avraham Eisenberg executed an oracle manipulation attack, draining approximately $116–117 million from the protocol through artificially inflated MNGO collateral. The protocol subsequently faced enforcement actions from the DOJ, SEC, and CFTC, settled with regulators in 2024, and formally shut down in January 2025.

avoid.net/genesis-global8/100[CRITICAL]

Genesis Global Capital, LLC was the institutional crypto lending subsidiary of Digital Currency Group (DCG), founded in 2018 as an extension of Genesis Global Trading. Following cascading losses from Three Arrows Capital's June 2022 default and FTX's November 2022 collapse, Genesis halted customer withdrawals on November 16, 2022 and filed for Chapter 11 bankruptcy on January 19, 2023, with liabilities estimated between $1 billion and $10 billion owed to over 100,000 creditors. The entity faced multiple regulatory actions including SEC charges for unregistered securities offerings, a New York Attorney General fraud lawsuit naming DCG CEO Barry Silbert by name, and a separate 2025 SEC settlement against DCG and former Genesis CEO Soichiro Moro for misleading investors about Genesis's financial condition.

avoid.net/bnb-chain-bridge16/100[CRITICAL]

The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.

avoid.net/blender-io0/100[CRITICAL]

Blender.io was a Bitcoin mixing service that operated from approximately 2018 to 2022, processing over $500 million in Bitcoin before being shut down. On May 6, 2022, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated it as a Specially Designated National, marking the first time a virtual currency mixer had ever been sanctioned by the United States government. The service was designated for its role in laundering over $20.5 million in proceeds from North Korea's Lazarus Group following the $620 million Ronin Network hack, as well as for processing funds tied to Russian ransomware groups and the Hydra darknet market.

avoid.net/adshares-bridge-ads28/100[WARNING]

Adshares is a Warsaw-based decentralized advertising protocol operating a proprietary dPoS blockchain with cross-chain bridges to Ethereum, BSC, Base, and Polygon. In May 2026 its Ethereum bridge was exploited for approximately $628,000 through fake wrapped-token minting, making it one of eight bridge exploits tracked by PeckShield that month. Approximately 86% of stolen funds were returned after the team offered a 10% whitehat bounty, but no public post-mortem has been published and the root cause of the bridge compromise remains unconfirmed.

avoid.net/fake-jupiter-cjup-airdrop-phishing-campaign0/100[CRITICAL]

An ongoing phishing campaign impersonates Jupiter Exchange (Solana DEX aggregator) by airdropping counterfeit tokens labeled '$CJUP' directly into Solana wallets, then directing recipients to wallet-draining websites that automatically empty connected wallets. First documented in early 2024 and still active as of May 2026, the campaign exploits the widespread recognition of Jupiter's legitimate annual 'Jupuary' airdrop program, which has distributed over $1 billion in real $JUP tokens since 2024.

avoid.net/catfi-memecoin-eth-father-park0/100[CRITICAL]

CATFI is a Solana-based memecoin launched in early 2025 via Pump.fun that was the subject of a coordinated rug pull orchestrated by a South Korean operator known online as 'Eth Father,' identified by prosecutors only as Mr. Park. The scheme artificially inflated the token 1,001-fold within 26 hours before a mass exit drained investor funds, causing approximately 900 million KRW (~$600,000) in losses across at least 256 victims. In May 2026 the Seoul Southern District Prosecutors' Office charged five individuals, marking South Korea's first criminal prosecution of a decentralized-exchange rug pull under the Virtual Asset User Protection Act.

avoid.net/exmo-exchange-limited4/100[CRITICAL]

EXMO Exchange Limited is a UK-registered cryptocurrency exchange founded circa 2013 by Russian nationals Eduard Bark and Ivan Petukhovskiy. The exchange suffered a hot wallet hack in December 2020 losing approximately $10.5 million in user funds, faced multiple regulatory failures including a failed FCA registration and a UK ASA ruling for misleading advertising, and was sanctioned by the UK government on May 26, 2026 under Russia (Sanctions) (EU Exit) Regulations 2019 for alleged facilitation of Russian sanctions evasion via transactions with sanctioned entities Garantex, Grinex, and Chatex totaling over $19.5 million. Blockchain analysis by TRM Labs found that EXMO's claimed operational separation from its Russia-facing spinoff EXMO.me was not reflected in actual custodial wallet infrastructure.

avoid.net/solana-mev-sandwich-bots0/100[CRITICAL]

Solana MEV sandwich bots are automated programs that exploit Solana's transaction ordering mechanisms to front-run and back-run retail user trades, extracting an estimated $370 million to $500 million from users between January 2024 and May 2025. The practice has drawn enforcement responses from the Solana Foundation, Jito Labs, and Marinade Finance, and is the subject of an active federal class-action lawsuit in the Southern District of New York naming Pump.fun, Solana Labs, and related entities. While coordinated countermeasures reduced attack profitability by an estimated 60-70% in 2025, attacks continue and disproportionately harm memecoin traders using high slippage settings on Raydium and Pump.fun.

avoid.net/radiant-capital18/100[CRITICAL]

Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that launched in July 2022 on Arbitrum. In 2024 it suffered two separate security incidents totaling approximately $54.5 million in losses: a $4.5 million flash loan exploit in January 2024 and a $50 million multisig compromise in October 2024 attributed by Mandiant to North Korean state-sponsored hackers (UNC4736/Citrine Sleet). The October 2024 hack reduced TVL by roughly 98%, led to major exchange delistings, and stolen funds were subsequently laundered through Tornado Cash.

avoid.net/the-dao10/100[CRITICAL]

The DAO was a decentralized autonomous organization launched on the Ethereum blockchain in April 2016 that raised approximately $150 million in Ether — the largest crowdfunding to date at the time — before being drained of 3.6 million ETH (roughly $50–60 million) on June 17, 2016, via a reentrancy vulnerability in its smart contract code. The hack triggered an acrimonious debate over blockchain immutability and led to a contentious hard fork of the Ethereum network on July 20, 2016, splitting it into Ethereum (ETH) and Ethereum Classic (ETC). In 2017 the U.S. SEC concluded that DAO tokens constituted unregistered securities, marking a landmark regulatory precedent for the entire crypto industry.

avoid.net/parity-multisig5/100[CRITICAL]

Parity Multisig was a multi-signature wallet implementation developed by Parity Technologies, founded by Ethereum co-founder Gavin Wood. The software suffered two catastrophic security failures in 2017: a July hack in which 153,037 ETH (approximately $30–32 million at the time) was stolen from three Ethereum project wallets via an unguarded initialization function, and a November incident in which GitHub user devops199 accidentally triggered a self-destruct on the shared library contract, permanently freezing 513,774 ETH (approximately $150–280 million at the time) across 587 wallets. The frozen funds have never been recovered, and the July 2017 attacker resumed laundering stolen ETH through the exchange eXch in May 2024 after seven years of inactivity.

avoid.net/gate32/100[WARNING]

Gate.io (formerly Bter.com) is a centralized cryptocurrency exchange founded in 2013 by Han Lin, serving over 30 million users across 224 countries. The exchange has been flagged by on-chain investigator ZachXBT for allegedly concealing a $230 million hack attributed to North Korean state-sponsored hackers (Lazarus Group) that occurred in April 2018 and was never publicly disclosed to users. Additional concerns include a manipulated futures price feed incident causing millions in user losses in 2025, an AML-based ban by India's Financial Intelligence Unit in 2024, persistent user complaints about frozen withdrawals, and alleged wash trading activity inflating reported volumes.

avoid.net/lendfme30/100[WARNING]

Lendf.me was a decentralized lending protocol built by dForce Network and launched in September 2019 as a fork of Compound v1. On April 19, 2020, an attacker exploited a reentrancy vulnerability involving ERC-777 tokens to drain approximately $25.2 million from the protocol — at the time representing 99.95% of its total value locked. The attacker returned nearly all funds within two days after inadvertently exposing identifying metadata, and the original Lendf.me contract was permanently deprecated following the incident.

avoid.net/cheesebank18/100[CRITICAL]

Cheese Bank was an Ethereum-based DeFi lending protocol that launched in September 2020 and suffered a $3.3 million exploit on November 6, 2020, caused by a flash loan attack combined with price oracle manipulation on Uniswap. The anonymous team claimed to have patched the vulnerability, but the protocol never recovered meaningful activity, the CHEESE token collapsed in value, and the project is widely considered abandoned. ZachXBT has flagged the entity as a high-risk project.

avoid.net/alpha-finance18/100[CRITICAL]

Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) is a DeFi protocol best known for its leveraged yield farming product Alpha Homora. On February 13, 2021, Alpha Homora V2 was exploited for approximately $37.5 million via a sophisticated attack that required insider knowledge of an unannounced smart contract, draining funds from its Iron Bank (Cream Finance) integration. By March 2023, the protocol had repaid less than 2% of the resulting $32 million debt to Iron Bank despite a formal repayment agreement, triggering a second crisis in which user funds were frozen.

avoid.net/spartan12/100[CRITICAL]

Spartan Protocol is a decentralized liquidity and synthetic-asset protocol that launched on Binance Smart Chain (BSC) in 2020 and was operated by a fully anonymous, community-driven team. On May 2, 2021, a critical vulnerability in the protocol's liquidity-share calculation logic was exploited via flash loan, resulting in approximately $30 million in stolen funds — ranking it among the largest DeFi exploits of that era. The protocol attempted a v2 rebuild with re-audited contracts but has since fallen to near-zero TVL and market cap, with no meaningful development activity recorded after 2024.

avoid.net/rari-capital8/100[CRITICAL]

Rari Capital was a DeFi yield-aggregation and lending protocol launched in July 2020 by teenage co-founders Jai Bhavnani, Jack Lipstone, and David Lucid. It suffered two major security exploits — a $11 million hack in May 2021 and an $80 million reentrancy hack in April 2022 — and subsequently merged with Fei Protocol to form Tribe DAO before winding down in 2022. In September 2024, the SEC secured final court judgments against the company and all three co-founders for misleading investors and operating as unregistered brokers.

avoid.net/acala-network32/100[WARNING]

Acala Network is a Polkadot-native DeFi hub offering a multi-collateralized stablecoin (aUSD), liquid staking, and an AMM DEX. On August 14, 2022, a misconfiguration in a newly deployed liquidity pool caused 3.022 billion aUSD to be erroneously minted, triggering a 99% depeg; approximately 98% of the erroneous tokens were subsequently recovered and burned via community governance votes. The incident raised significant concerns about the protocol's claimed decentralization after the team unilaterally placed the network in maintenance mode and froze token transfers without an on-chain vote.

avoid.net/squid-games2/100[CRITICAL]

SQUID was a BEP-20 token on the Binance Smart Chain launched in late October 2021 that exploited the viral popularity of the Netflix series 'Squid Game.' On November 1, 2021, anonymous developers executed a rug pull, draining at least $3.38 million in liquidity and abandoning the project, causing the token price to collapse from a peak of $2,861.80 to effectively zero within minutes. More than 43,000 investors suffered losses, with no arrests made and the perpetrators remaining unidentified as of mid-2026.

avoid.net/grim-finance8/100[CRITICAL]

Grim Finance was a Fantom-based DeFi yield optimizer (fork of Beefy Finance) that suffered a devastating reentrancy exploit on December 19, 2021, resulting in approximately $30 million in user funds stolen. The vulnerability — a missing reentrancy guard in the depositFor() function — had existed in an audited codebase and was classified by security researchers as an entirely preventable, well-understood attack class. The protocol has since collapsed to a near-zero TVL of roughly $29,000 and its proposed compensation plan yielded no meaningful restitution for affected users.

avoid.net/lcx54/100[CAUTIONARY]

LCX (Liechtenstein Cryptoassets Exchange) is a regulated crypto exchange and tokenization platform headquartered in Vaduz, Liechtenstein, holding eight registrations under the Liechtenstein Financial Market Authority (FMA) pursuant to the Token and Trusted Technology Service Provider Act (TVTG). In January 2022 the exchange suffered a hot wallet compromise in which approximately $7.94 million in crypto assets were stolen, with stolen funds rapidly laundered through Tornado Cash; LCX subsequently used its own funds to compensate affected users and cooperated with international law enforcement to freeze an alleged 60% of stolen assets. The exchange is flagged by ZachXBT and carries a below-average trust score primarily due to the 2022 hack, ongoing user complaints about withdrawal delays and account freezes, and the broader security posture concerns that led to the compromise.

avoid.net/superfluid38/100[WARNING]

Superfluid is an asset streaming and programmable cash flow protocol founded in 2020, deployed across Ethereum, Polygon, and multiple other EVM chains. On February 8, 2022, an attacker exploited a context serialization vulnerability in the protocol's host contract, draining approximately $8.7 million in assets from multiple projects including QiDAO, Stake DAO, Stacker Ventures, and Museum of Crypto Art. The protocol patched the vulnerability within hours, partially compensated affected parties, and has continued operating with additional audits and a native SUP token launch in 2025.

avoid.net/treasure32/100[WARNING]

TreasureDAO is an Arbitrum-based NFT gaming ecosystem and marketplace powered by the MAGIC token. In March 2022 its marketplace suffered a critical smart contract exploit that allowed attackers to acquire NFTs for free, resulting in approximately $1.4 million in losses across 153 NFTs. Separately, blockchain investigator ZachXBT raised concerns in February 2022 about a core team engineer's alleged prior involvement in failed NFT projects. The project has since experienced severe financial distress, shut down its Treasure Chain layer-2 network in May 2025 after five months of operation, and executed major layoffs in a pivot to AI-agent products.

avoid.net/beanstalk12/100[CRITICAL]

Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.

avoid.net/templedao32/100[WARNING]

TempleDAO is a DeFi yield protocol launched on Ethereum in August 2021, designed to offer low-volatility, fractionally backed yields on deposited assets. On October 11, 2022, an associated staking product, STAX Finance, suffered a smart contract exploit due to missing access control on the migrateStake() function, resulting in approximately $2.34 million in stolen funds that were subsequently laundered through Tornado Cash. The core TempleDAO vaults were not directly compromised, but the team's anonymous structure and the unrecovered stolen funds remain notable risk factors.

avoid.net/save38/100[WARNING]

Save (formerly Solend) is a Solana-based algorithmic lending and borrowing protocol that has operated since 2021. The protocol has been flagged by ZachXBT and carries a history of two significant incidents: a controversial governance vote in June 2022 that briefly granted the team emergency powers to seize a user's wallet, and a $1.26 million oracle manipulation exploit in November 2022. The protocol rebranded from Solend to Save in late 2024 and continues to operate with approximately $74 million in total value locked as of mid-2026.

avoid.net/ratio-finance22/100[CRITICAL]

Ratio Finance is a defunct Solana-based collateralized debt position (CDP) protocol that allowed users to mint the USDr stablecoin against yield-bearing LP token collateral. The protocol raised $8.4 million across multiple rounds from investors including Alameda Research, Solana Ventures, and CMS Holdings, then launched its RATIO governance token in March 2022 at an all-time high near $2.24. The project suffered a private key compromise on or around December 3, 2022, after which the protocol's TVL fell to zero, the RATIO token lost over 99.9% of its value, and all social media activity ceased by December 2023.

avoid.net/level-perps28/100[WARNING]

Level Finance (also marketed as Level Perps) is a decentralized perpetual derivatives exchange that launched on BNB Chain in Q4 2022 and later expanded to Arbitrum. In May 2023 the protocol suffered a $1.1 million exploit caused by a logic bug in its referral reward contract that was missed by two prior security audits. The protocol's LVL token has declined approximately 99.9% from its all-time high, and as of 2025-2026 the protocol shows near-zero TVL ($32K), zero fees, and zero revenue, indicating effective dormancy.

avoid.net/uwerx12/100[CRITICAL]

Uwerx (WERX) was a purported decentralized freelancing platform that conducted a multi-stage token presale in 2023 before suffering a flash loan exploit on August 2, 2023, one day after its Uniswap listing, resulting in the loss of approximately 176 ETH (~$324,000). Despite two prior smart contract audits by SolidProof and InterFi Network, neither audit identified the exploited vulnerability. The project subsequently relaunched on Polygon in October 2023 but has since been listed as abandoned on CoinSniper, with the token trading at effectively zero value and only six recorded holders as of early 2026.

avoid.net/exactly32/100[WARNING]

Exactly Protocol is a decentralized, non-custodial fixed-rate and variable-rate lending protocol deployed on the Optimism Layer 2 network. On August 18, 2023, the protocol suffered a critical exploit resulting in approximately $7.3–$12 million in ETH stolen from 117 user accounts due to insufficient input validation in its DebtManager periphery contract. The protocol has since resumed operations, engaged law enforcement, offered a $700,000 bounty, and passed a governance proposal to compensate affected users with EXA tokens.

avoid.net/harbor-protocol28/100[WARNING]

Harbor Protocol is a decentralized collateralized-debt-position (CDP) protocol built on the Comdex chain (Cosmos SDK / CosmWasm) that enabled users to mint the Composite stablecoin (CMST) against whitelisted collateral assets. The protocol suffered two distinct security incidents in 2023 — an oracle-manipulation liquidation event in June and a direct vault drain exploit in August — after which its total value locked collapsed to effectively zero. As of 2025 the protocol appears inactive, with the HARBOR governance token near worthless and no meaningful community or development activity detected.

avoid.net/locus-finance22/100[CRITICAL]

Locus Finance is a DeFi yield-vault protocol launched in July 2023 by Iakov Levin, the founder of the defunct custodial crypto platform Midas Investments, which collapsed in December 2022 with a reported $63.3 million deficit. On December 30, 2023, Locus suffered a $320,964 exploit due to a developer private key leak during a CTO transition. The LOCUS token has declined over 99% from its all-time high, the protocol's TVL is near zero, and Levin is subject to regulatory enforcement actions in California and Wisconsin related to his prior venture.

avoid.net/wise-lending-v122/100[CRITICAL]

Wise Lending V1 is the first version of the Wise Lending decentralized lending and yield-aggregation protocol deployed on Ethereum, built from scratch by WiseSoft LLC and founded by Peter Girr. The V1 deployment suffered two confirmed on-chain exploits within approximately three months, losing an estimated $700,000+ in total user funds across both incidents, with no publicly documented recovery or compensation plan. ZachXBT has flagged the entity, and post-exploit TVL collapsed effectively to zero.

avoid.net/bungee42/100[WARNING]

Bungee Exchange is a cross-chain bridge aggregator and liquidity routing protocol developed by Socket (formerly SocketDotTech), founded in 2021 by Vaibhav Chellani and Rishabh Khurana. On January 16, 2024, the underlying Socket infrastructure was exploited via an inadequately validated smart contract route, resulting in approximately $3.3 million stolen from roughly 700 wallets with infinite token approvals. The protocol recovered approximately $2.23 million of the stolen funds one week later and resumed operations; it remains active as of 2026.

avoid.net/shido22/100[CRITICAL]

Shido Network (SHIDO) is a Layer-1 proof-of-stake blockchain project founded in Sweden in 2021. On February 29, 2024, an attacker exploited the Ethereum-based SHIDO staking contract by transferring ownership to a new address and upgrading it with a hidden token-withdrawal function, draining over 4.3 billion tokens and causing the price to collapse 94% within 30 minutes. On-chain investigator ZachXBT linked the exploit to a serial hacker responsible for the OKX (December 2023) and Concentric Finance (January 2024) hacks, with the attack vector in each case being private key compromise via social engineering.

avoid.net/lava42/100[WARNING]

Lava (lavadefi.io) is a decentralized, non-custodial multichain lending and borrowing protocol deployed on Arbitrum and Base, operating since March 2024. The protocol suffered two documented exploit incidents in 2024 totaling approximately $470,000 in losses, both rooted in protocol logic vulnerabilities and flash loan abuse. The platform was flagged by on-chain investigator ZachXBT, and separately the lava.xyz Bitcoin lending product drew significant backlash in late 2025 after quietly switching users from a self-custodial DLC-based model to a fully custodial setup without adequate disclosure.

avoid.net/pike-v122/100[CRITICAL]

Pike V1 (also known as Pike Beta) was a cross-chain DeFi lending protocol built by Nuts Finance that suffered two smart contract exploits within four days in April 2024, resulting in approximately $1.98 million in user losses. A vulnerability identified by auditing partner OtterSec prior to launch was never remediated, and a subsequent botched patch introduced even more severe vulnerabilities. The project's October 2024 token generation event further damaged investor trust after the team launched the $P token with only $10,000 in initial liquidity despite having raised $6.45 million in a presale.

avoid.net/yolo-games28/100[WARNING]

YOLO Games is an on-chain gambling platform built on the Blast Layer 2 network, offering high-risk games such as YOLO, Moon or Doom, and Poke the Bear, with a native $YOLO token as its reward mechanism. In June 2024, an access control vulnerability in a third-party Liquidity Bootstrapping Pool (LBP) contract was exploited, resulting in the extraction of approximately $1.387 million, of which 90% was subsequently returned by the attacker acting as a whitehat. The $YOLO token has since collapsed approximately 99.6% from its all-time high and the protocol shows near-zero fee activity as of 2025-2026, suggesting severe user attrition or effective abandonment.

avoid.net/lifi-finance32/100[WARNING]

LI.FI is a Berlin-based cross-chain bridge and DEX aggregation protocol founded in 2021 by Philipp Zentner and Max Klenk. The protocol has suffered two significant smart contract exploits — a $600,000 loss in March 2022 and an $11.6 million loss in July 2024 — both stemming from the same class of arbitrary-call vulnerability, prompting criticism from security researchers that lessons were not learned. Separately, blockchain investigator ZachXBT alleged in June 2025 that North Korean (DPRK) actors accounted for an estimated 15–25% of the protocol's volume during May 2025, using LI.FI to launder funds from the Bybit hack.

avoid.net/polynetwork10/100[CRITICAL]

Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered two major security breaches: a $610 million exploit in August 2021 (the largest DeFi hack at the time, with funds ultimately returned) and a second exploit in July 2023 in which attackers minted billions in notional value of tokens, extracting an estimated $10–20 million in real assets. The protocol permanently terminated all services on September 30, 2024.

avoid.net/zkfinance32/100[WARNING]

zkFinance is a DeFi lending and borrowing protocol deployed on zkSync Era that also offers bridging, cross-chain swaps, and a concentrated-liquidity DEX. The protocol suffered a documented $200,000 protocol logic exploit attributed to an oracle misconfiguration in November 2024 and has since registered near-zero TVL ($24,990) with no active loans outstanding. The team is pseudonymous, no public founder identities have been verified, and the protocol's native ZGT token has attracted minimal exchange listing activity and negligible on-chain trading volume.

avoid.net/dexx10/100[CRITICAL]

DEXX is a Solana-based on-chain memecoin trading terminal that suffered a catastrophic private key compromise on November 16, 2024, resulting in approximately $30 million in user losses across more than 8,600 wallets. Despite marketing itself as non-custodial, DEXX stored user private keys in plaintext on its own servers — a centralization risk that CertiK had flagged as unresolved prior to the breach. A partial compensation initiative led by LBank was announced in early 2025, but full recovery of stolen funds remains unlikely as the attacker laundered substantial ETH through Tornado Cash.

avoid.net/zklend20/100[CRITICAL]

zkLend was a decentralized money-market lending protocol built on Starknet (Ethereum Layer 2), founded in 2022 by Brian Fu and Jane Ma and backed by Delphi Digital, Three Arrows Capital, and StarkWare. On February 11–12, 2025, the protocol suffered a critical flash-loan exploit that drained approximately $9.57 million in user funds through manipulation of the lending_accumulator variable and precision-loss rounding errors. The protocol permanently ceased operations in June 2025, allocating a $200,000 treasury remnant to a user recovery fund — leaving the vast majority of affected users uncompensated.

avoid.net/forcebridge20/100[CRITICAL]

ForceBridge is a cross-chain bridge operated by Magickbase on the Nervos Network (CKB), enabling transfers between Nervos and Ethereum and BNB Chain. On June 2, 2025, the bridge was exploited via an access control vulnerability — likely a compromised private key — resulting in approximately $3.7–3.9 million in user funds being stolen and laundered through Tornado Cash. The exploit occurred just one day after Magickbase announced the bridge's sunset, raising questions about the timing and origin of the attack.

avoid.net/futureswap22/100[CRITICAL]

Futureswap is a decentralized perpetual futures exchange built on Arbitrum and Avalanche that raised $12 million in 2021 but has been effectively dormant since 2023. The protocol suffered three separate exploits between December 2025 and January 2026, resulting in cumulative losses exceeding $1.3 million, while the team made no public response to any incident. ZachXBT flagged the entity as a risk, and the protocol's last known audit dates to 2021.

avoid.net/goose-finance32/100[WARNING]

Goose Finance is an anonymous-team yield farming and decentralized exchange protocol launched on Binance Smart Chain in February 2021, best known for its EGG governance and reward token. The protocol achieved rapid early traction, reaching third-most-popular DeFi app on BSC within one month, before its EGG token collapsed more than 99% from an all-time high near $172. A post-audit smart contract exploit in March 2026 drained approximately $8,000 via a share accounting flaw, and independent analysts have flagged the layered farming tokenomics as structurally unsustainable.

avoid.net/lmlusdt-staking-protocol4/100[CRITICAL]

The LML/USDT staking protocol was a yield-bearing staking contract deployed on Binance Smart Chain (BSC) that suffered a catastrophic price manipulation exploit on April 1, 2026, resulting in approximately $950,000 in losses. An attacker aggregated flash loans totaling 309,529,000 USDT, artificially inflated the LML token price by purchasing nearly the entire circulating supply and burning it, then claimed outsized staking rewards against the manipulated price. Stolen funds — converted to 450.6 ETH — were subsequently laundered through Tornado Cash, and no public team response or recovery effort has been documented.

avoid.net/ankr-helio28/100[WARNING]

On December 1–2, 2022, a former Ankr employee carried out a supply chain attack that compromised the protocol's deployer private key, enabling the minting of trillions of aBNBc tokens and the draining of approximately $5 million in liquidity. Hours later, a separate attacker exploited Helio Protocol's slow price oracle to borrow $16.4 million in HAY stablecoin against nearly worthless aBNBc collateral, ultimately netting around $15.5 million. Combined losses exceeded $20 million, making it one of the most significant DeFi insider-threat incidents of 2022.

avoid.net/alchemix50/100[WARNING]

Alchemix Finance is an Ethereum-based DeFi protocol that offers self-repaying loans, allowing users to deposit yield-bearing collateral and borrow synthetic assets whose debt is automatically paid down by the underlying yield. The protocol has experienced several notable security incidents since its February 2021 launch, including a June 2021 alETH transmuter bug (~2,700 ETH overclaimed), and a July 2023 Curve pool exploit (~$20M stolen and subsequently fully returned). Alchemix has maintained operational continuity through each incident and continues to develop a V3 upgrade with an active Immunefi bug bounty program.

avoid.net/stake-com38/100[WARNING]

Stake.com is the world's largest crypto gambling platform by revenue, founded in 2017 by Australian entrepreneurs Ed Craven and Bijan Tehrani and operating under a Curacao gaming license. In September 2023, the platform suffered a $41 million hot wallet breach that the FBI formally attributed to North Korea's Lazarus Group (APT38). The platform faces mounting legal and regulatory pressure across multiple jurisdictions, including a landmark California civil suit filed by the Los Angeles City Attorney in 2025, multiple class action lawsuits, and a UK exit following a Gambling Commission investigation.

avoid.net/roman-storm22/100[CRITICAL]

Roman Storm is a Russian-born, naturalized U.S. citizen and co-founder of Tornado Cash, an Ethereum-based cryptocurrency mixing protocol sanctioned by OFAC in August 2022. He was arrested in August 2023 and indicted in the Southern District of New York on three counts: conspiracy to commit money laundering, conspiracy to operate an unlicensed money transmitting business, and conspiracy to violate U.S. sanctions (IEEPA). A jury convicted him in August 2025 on the unlicensed money transmitting count while deadlocking on the two more serious charges, and prosecutors have filed to retry him on the deadlocked counts in October 2026.

avoid.net/pickle-finance28/100[WARNING]

Pickle Finance was a DeFi yield aggregator launched in September 2020 that allowed users to auto-compound returns via tokenized strategy vaults called 'Jars.' On November 21, 2020, an attacker exploited a combination of smart contract vulnerabilities in the unaudited ControllerV4 contract to drain 19,759,355 DAI (~$19.7 million) from the pDAI Jar in what analysts described as one of the most technically complex DeFi exploits of its era. The protocol subsequently partnered with Yearn Finance, issued a CORNICHON compensation token to victims, and continued operating until it announced a full shutdown effective October 1, 2025.

avoid.net/infini-protocol22/100[CRITICAL]

Infini is a Hong Kong-based stablecoin neobank offering yield, payments, and enterprise treasury tools built on DeFi infrastructure. In February 2025, the platform suffered a $49.5 million exploit when a former contract developer who had secretly retained administrative privileges drained the Morpho MEVCapital USDC Vault across two transactions. Founder Christian Li pledged personal coverage of losses and offered a 20% bounty to the attacker; as of mid-2026 the stolen funds have not been recovered, with the exploiter laundering proceeds through Tornado Cash.

avoid.net/satish-kumbhani0/100[CRITICAL]

Satish Kumbhani is the founder of BitConnect, a cryptocurrency platform that the U.S. Department of Justice, SEC, and multiple state regulators have determined operated as a global Ponzi scheme defrauding investors of approximately $2.4 billion between 2016 and 2018. Kumbhani was indicted by a federal grand jury in San Diego on February 25, 2022, on charges carrying a maximum penalty of 70 years in prison, and has remained a fugitive from justice since disappearing from India following his U.S. indictment.

avoid.net/justin-sun7/100[CRITICAL]

Justin Sun is the founder of the TRON blockchain and TRX token, and the controlling figure behind HTX (formerly Huobi) and Poloniex exchanges. In March 2023, the U.S. Securities and Exchange Commission charged Sun and three of his companies with fraud, market manipulation through wash trading, unregistered securities offerings, and orchestrating an undisclosed celebrity promotion scheme; the case partially settled in March 2026 with Rainberry Inc. paying a $10 million penalty while claims against Sun personally were dismissed. Sun has faced additional scrutiny including a reported FBI/DOJ criminal investigation, UK sanctions against an HTX entity over alleged Russia-linked transactions, a $114 million hot-wallet hack at Poloniex in November 2023, and disputed claims of diplomatic immunity through a Grenada WTO ambassadorship he held until mid-2022.

avoid.net/inverse-finance38/100[WARNING]

Inverse Finance is an Ethereum-based DeFi protocol known for its DOLA stablecoin and FiRM fixed-rate lending market, founded in late 2020 by Nour Haridy. The protocol suffered two oracle price manipulation exploits within two months in 2022 — the first in April for approximately $15.6 million and the second in June for a protocol loss of approximately $5.8 million — collectively representing one of the most significant serial oracle attack sequences in DeFi history. The protocol has since deprecated the vulnerable Anchor and Frontier lending markets, rebuilt on FiRM with Chainlink oracles, and undertaken a multi-year bad-debt repayment program.

avoid.net/sinbad-io2/100[CRITICAL]

Sinbad.io was a Bitcoin mixing service that operated from October 2022 until its seizure by U.S., Dutch, and Finnish law enforcement in November 2023. OFAC designated it a key money-laundering tool of North Korea's Lazarus Group, which used it to launder proceeds from multiple major crypto hacks including Axie Infinity's Ronin Bridge and Atomic Wallet. On-chain analytics firms assessed it to be highly likely a rebranding of Blender.io, the first crypto mixer ever sanctioned by OFAC.

avoid.net/fei-rari6/100[CRITICAL]

Fei Protocol and Rari Capital merged in December 2021 under Tribe DAO to form a combined DeFi liquidity and lending platform. On April 30, 2022, a reentrancy attack targeting a known flaw in the Compound Finance codebase drained approximately $80 million from seven Rari Fuse lending pools. Tribe DAO ultimately wound down in late 2022 following contentious governance disputes over victim compensation, and Rari Capital's co-founders faced SEC enforcement action in 2024.

avoid.net/ronin-network22/100[CRITICAL]

Ronin Network is an Ethereum sidechain developed by Sky Mavis to support the Axie Infinity play-to-earn game. In March 2022, it suffered the largest cryptocurrency hack in history when attackers — subsequently attributed by the FBI and U.S. Treasury to North Korea's Lazarus Group — exploited compromised validator private keys to drain approximately $625 million in ETH and USDC. A second, smaller exploit occurred in August 2024, though those funds were returned by a white-hat MEV bot operator.

avoid.net/nomad-bridge8/100[CRITICAL]

Nomad Bridge, operated by Illusory Systems Inc., was a cross-chain asset bridge that suffered a catastrophic $190 million exploit on August 1, 2022, when a routine smart contract upgrade inadvertently initialized trusted Merkle roots to a zero value, rendering all message proofs automatically valid. The vulnerability enabled a widely replicated 'crowd-sourced' draining event involving approximately 300 addresses over roughly 150 minutes — widely regarded as the first 'permissionless' mass-exploitation event in DeFi history. Subsequent actions include a class-action lawsuit, a December 2025 FTC settlement requiring repayment of approximately $37.5 million to affected users, and the 2025 arrest and extradition of a key suspect, Russian-Israeli national Alexander Gurevich.

avoid.net/harmony-horizon-bridge4/100[CRITICAL]

The Harmony Horizon Bridge was a cross-chain bridge enabling asset transfers between Harmony, Ethereum, and Binance Smart Chain. On June 23–24, 2022, attackers exploited a critically under-configured 2-of-5 multisignature scheme to steal approximately $99.7 million across 14 asset types. The FBI formally attributed the attack to the North Korean state-linked Lazarus Group (APT38) in January 2023.

avoid.net/chipmixer0/100[CRITICAL]

ChipMixer was a darknet Bitcoin mixing service that operated from August 2017 to March 2023, processing over $3 billion in illicit cryptocurrency on behalf of ransomware groups, North Korean state hackers, Russian military intelligence, and darknet drug markets. On March 15, 2023, U.S. and German authorities seized its infrastructure, domains, and approximately $46 million in cryptocurrency in a coordinated international takedown. Minh Quoc Nguyen, 49, a Vietnamese national residing in Hanoi, was charged in the Eastern District of Pennsylvania with money laundering, operating an unlicensed money transmitting business, and identity theft; he remains a fugitive.

avoid.net/valuedefi8/100[CRITICAL]

Value DeFi (formerly YFValue/YFV) was a DeFi yield aggregation and AMM protocol that suffered three documented security exploits between August 2020 and May 2021, resulting in combined losses of approximately $24 million. Beyond the technical failures, the project was found to have used a paid actress from Fiverr to impersonate a co-founder named 'Anna Tanaka,' raising severe concerns about team identity, transparency, and intent. The VALUE token is effectively defunct, trading at a fraction of a cent with a near-zero market cap.

avoid.net/bearnfi12/100[CRITICAL]

bEarn.fi (BearnFi) is a Binance Smart Chain-based cross-chain yield farming and algorithmic stablecoin protocol that launched in late 2020. On May 16, 2021, an attacker exploited a smart contract denomination mismatch to drain approximately $10.85 million in BUSD from the protocol's bVaults via a flash loan attack. The project subsequently became inactive, with its native BFI token recording no price data after mid-2023 and a market capitalization of effectively zero. The entity has been flagged by ZachXBT.

avoid.net/punk-protocol22/100[CRITICAL]

Punk Protocol was an Ethereum-based DeFi project that positioned itself as a decentralized annuity and pension service. On August 10, 2021, it suffered a critical smart contract exploit due to a missing access-control modifier in its CompoundModel contract, resulting in approximately $8.95 million in stablecoin losses; roughly $5 million was partially recovered via a white-hat frontrunner who retained a $1 million bounty. The project launched without a security audit, has published no meaningful updates since late 2021, and its PUNK token currently trades at effectively zero volume, indicating the project is dormant or abandoned.

avoid.net/dao-maker-vesting22/100[CRITICAL]

DAO Maker Vesting refers to the smart contract infrastructure operated by DAO Maker, a crypto launchpad platform, that was compromised in two separate exploits in 2021 resulting in combined losses of approximately $11 million. The August 2021 incident drained $7 million in USDC from 5,251 user accounts via a compromised admin private key, and a second exploit in September 2021 extracted approximately $4 million from vesting contracts via an unauthenticated init() function vulnerability. Victims allege that DAO Maker has failed to honor its full compensation commitments over three years after the hacks, with governance manipulation alleged to have been used to cancel the USDR reimbursement program.

avoid.net/mirror5/100[CRITICAL]

Mirror Protocol was a Terra-based DeFi platform enabling synthetic assets (mAssets) that tracked prices of US stocks. The protocol suffered a $90 million exploit in October 2021 that went undetected for seven months, a governance attack campaign in December 2021 targeting $40 million in community funds, and a second $2 million oracle exploit in May 2022. It became permanently inactive in August 2022 following the catastrophic collapse of the Terra/LUNA/UST ecosystem, which was orchestrated by its parent company Terraform Labs under Do Kwon, who was subsequently convicted of fraud and sentenced to 15 years in prison.

avoid.net/indexed-finance12/100[CRITICAL]

Indexed Finance was an Ethereum-based decentralized protocol offering passively managed index pools, launched in late 2020. On October 14, 2021, the protocol suffered a sophisticated $16 million flash loan exploit targeting its DEFI5 and CC10 pools, destroying most user funds. The alleged attacker, Canadian mathematics prodigy Andean Medjedovic, was later charged by U.S. prosecutors in February 2025 in connection with $65 million in combined DeFi thefts and remains a fugitive as of early 2026.

avoid.net/anubisdao2/100[CRITICAL]

AnubisDAO was an OlympusDAO fork that launched on October 28, 2021, and raised approximately 13,556 WETH (roughly $60 million) in under 20 hours through a Copper Liquidity Bootstrapping Pool. Before the sale concluded, the entire pool was drained to an external wallet, wiping investors to zero; on-chain investigator ZachXBT later identified two pseudonymous actors — Beerus and Ersan — as the likely perpetrators, and traced the stolen funds through Tornado Cash in 2023. No criminal charges have been publicly confirmed, no investor recovery has occurred, and the ANKH token is worthless.

avoid.net/monox10/100[CRITICAL]

MonoX was a decentralized exchange protocol built on Ethereum and Polygon using a novel single-token liquidity model, which raised $5M in September 2021 and launched mainnet shortly before suffering a critical smart contract exploit on November 30, 2021. The attacker exploited a missing validation check in the swap function — using the MONO token as both input and output — to artificially inflate its price and drain approximately $31M in user funds across both chains. The protocol attempted a relaunch via MonoX 2.0 with a debt-token compensation mechanism, but MONO has since collapsed to near-zero value with negligible trading activity.

avoid.net/bitmart18/100[CRITICAL]

BitMart is a centralized cryptocurrency exchange that operated for nine years before announcing a wind-down on July 26, 2026, citing a nine-year run and the decision to cease operations. On August 21, 2026, the exchange reversed course, announcing it was exploring a restructuring plan with law firm White & Case as an alternative to full closure, while trading halted as scheduled on August 26. The restructuring pivot occurred amid mounting user reports of frozen or throttled withdrawals, allegations of unpaid employee wages, an unreleased proof-of-reserves commitment, and on-chain data showing sharply reduced outflows — patterns that critics have compared to the pre-collapse behavior of failed exchanges in 2022.

avoid.net/agave52/100[CAUTIONARY]

Agave was a decentralized lending protocol on Gnosis Chain forked from Aave v2, developed by members of the 1Hive community. On March 15, 2022, the protocol suffered a reentrancy exploit that drained approximately $5.5 million in user funds, part of a coordinated $11.7 million attack that simultaneously hit Hundred Finance. The protocol paused operations following the hack and formally closed down in March 2024 with no documented user compensation.

avoid.net/audius58/100[CAUTIONARY]

Audius is a decentralized music streaming protocol and its native AUDIO token, launched in 2020 on Ethereum and subsequently migrated to Solana. On July 23, 2022, an attacker exploited a critical re-initialization vulnerability in Audius governance smart contracts, draining 18.56 million AUDIO tokens (valued at approximately $6 million at the time) from the community treasury before swapping them for approximately $1.08 million in ETH via Uniswap and routing funds through Tornado Cash. The platform has continued to operate since the exploit, deploying patched contracts and expanding user and artist partnerships, but the AUDIO token has declined approximately 99.6% from its all-time high and the exploit raised serious questions about audit quality.

avoid.net/curve-dex62/100[CAUTIONARY]

Curve Finance is a major decentralized exchange and automated market maker (AMM) on Ethereum, optimized for low-slippage swaps of pegged assets such as stablecoins. On July 30, 2023, several of its liquidity pools were drained of approximately $70 million due to a reentrancy vulnerability in the Vyper smart contract compiler (versions 0.2.15, 0.2.16, and 0.3.0), one of the largest DeFi exploits of 2023. Separately, founder Michael Egorov's practice of using large CRV holdings as loan collateral across multiple DeFi protocols created systemic risk that culminated in a $140 million liquidation event in June 2024, generating over $10 million in bad debt across connected protocols.

avoid.net/ankr58/100[CAUTIONARY]

Ankr is a Web3 infrastructure and liquid staking protocol founded in 2017, providing RPC endpoints for over 75 blockchains and BNB Chain-based liquid staking products. In December 2022, a former employee executed a supply chain attack that compromised Ankr's private deployer key, enabling unlimited minting of aBNBc tokens and resulting in approximately $5 million in direct losses, with cascading secondary losses of roughly $19 million through Helio Protocol's HAY stablecoin depeg. Ankr subsequently compensated affected users, implemented multi-signature controls, and continues to operate, though questions persist over the completeness of user reimbursement.

avoid.net/launchzone18/100[CRITICAL]

LaunchZone (LZ) was a Binance Smart Chain-based DeFi launchpad and IDO platform originally launched as BSCex in December 2020, later rebranded in March 2021. On February 27, 2023, the protocol suffered a critical smart contract exploit in its Bscex SwapX contract, resulting in approximately $700,000 drained from its liquidity pool and a total of nearly $7.8 million in cumulative losses as additional vulnerable contracts were identified. The platform ceased operations on March 26, 2023, with over 75,000 user wallets remaining exposed weeks after the initial attack. ZachXBT has flagged this entity as a risk.

avoid.net/myalgo12/100[CRITICAL]

MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.

avoid.net/kokomo-finance2/100[CRITICAL]

Kokomo Finance was a purported non-custodial lending and borrowing protocol launched on the Optimism blockchain on March 25, 2023. Within approximately 24 hours of launch, its developers executed a deliberate exit scam, stealing approximately $4 to $4.5 million in user funds through smart contract manipulation. The project was subsequently linked by on-chain investigator ZachXBT to a serial scam ring responsible for over $20 million in losses across multiple DeFi protocols.

avoid.net/sentiment32/100[WARNING]

Sentiment is an undercollateralized DeFi lending protocol originally deployed on Arbitrum, later migrating activity to HyperLiquid L1. On April 4, 2023, the protocol suffered a read-only reentrancy exploit resulting in approximately $1 million in losses, of which 90% was returned by the attacker following a negotiated $95,000 bounty. ZachXBT has flagged the entity for elevated risk; the protocol remains operational with a low TVL of roughly $518,000 as of 2025.

avoid.net/bitrue18/100[CRITICAL]

Bitrue is a Singapore-incorporated centralized cryptocurrency exchange founded in 2018 that suffered a confirmed $23 million hot wallet exploit in April 2023, with stolen funds subsequently laundered through Tornado Cash as recently as June 2025. The exchange holds no license from Singapore's Monetary Authority (MAS) and relies on a VASP registration in Lithuania — a lower-tier regulatory framework — while accumulating a persistent record of user complaints alleging unjustified account freezes and asset seizures.

avoid.net/jimbos-protocol18/100[CRITICAL]

Jimbos Protocol was an Arbitrum-based DeFi liquidity protocol designed to provide a semi-stable floor price for its native JIMBO token. On May 28, 2023, just three days after launching its V2, the protocol was exploited via a flash loan attack that drained approximately 4,090 ETH (~$7.5 million) by exploiting a lack of slippage control in the JimboController contract. The attacker rejected a $800,000 bounty offer, laundered the full amount through Tornado Cash, and remains unidentified; no funds have been recovered.

avoid.net/multichain10/100[CRITICAL]

Multichain (formerly AnySwap) was a cross-chain bridge protocol that collapsed in mid-2023 following the arrest of its CEO Zhaojun by Chinese police in May 2023, which resulted in the seizure of private keys controlling over $1.5 billion in user assets. On July 7, 2023, approximately $126–127 million was drained from Multichain bridge reserves in transfers widely attributed to Chinese authorities or insiders with access to the CEO's confiscated key material. The protocol formally ceased operations on July 14, 2023, leaving users with unrecoverable losses.

avoid.net/eralend28/100[WARNING]

EraLend (formerly Nexon Finance) is a decentralized lending protocol on zkSync Era that suffered a $3.4 million read-only reentrancy exploit on July 25, 2023, draining its USDC pool due to a vulnerability in inherited SyncSwap oracle code. The protocol's pre-hack audit by PeckShield explicitly assumed a trusted price oracle, leaving the vulnerable oracle mechanism unexamined. EraLend relaunched post-hack with a fee-based compensation plan but has seen its TVL decline sharply to approximately $138,000 as of 2025-2026.

avoid.net/bald4/100[CRITICAL]

BALD was a memecoin launched on Coinbase's Base Layer 2 network on July 29, 2023, allegedly named as a reference to Coinbase CEO Brian Armstrong's appearance. After attracting over $66 million in ETH to its liquidity pool through aggressive liquidity additions and a price surge of approximately 4,000,000% within 24 hours, the anonymous deployer removed approximately $25.6 million in liquidity on July 31, 2023, causing the token price to collapse by roughly 90%. On-chain investigators linked the deployer's wallet to addresses with documented interactions with Alameda Research, with Wintermute's head of research publicly identifying former Alameda co-CEO Sam Trabucco as the most likely suspect — though no conclusive proof of identity was ever established.

ZachXBT Intelligence · Backfilled

5
avoid.net/pink-drainer2/100[CRITICAL]

Pink Drainer was a pseudonymous wallet-drainer-as-a-service operation that supplied phishing kits and malicious smart-contract infrastructure to affiliate scammers between roughly April 2023 and May 2024. Security researchers, principally Scam Sniffer and blockchain investigator ZachXBT, attribute upward of $75-85 million in stolen crypto assets across an estimated 20,000-21,000+ victims to wallets and infrastructure linked to the group before it announced its retirement in May 2024. No law enforcement agency has publicly identified or charged the individuals behind the operation, so all attributions of activity and identity in this report come from private security researchers rather than courts or regulators.

avoid.net/lazarus-group2/100[CRITICAL]

Lazarus Group is a cyber threat actor that the U.S. Department of Justice, FBI, Treasury/OFAC, and the United Nations Panel of Experts have attributed to North Korea's Reconnaissance General Bureau (RGB), a military intelligence agency of the Democratic People's Republic of Korea (DPRK). U.S. and allied government agencies allege the group and its sub-units (tracked in industry reporting as APT38, BlueNoroff, TraderTraitor, and Stardust Chollima) have conducted destructive cyberattacks and large-scale cryptocurrency thefts since at least 2009, including what blockchain-analytics firm Chainalysis describes as a cumulative total exceeding $6 billion in stolen crypto assets, funds the UN Panel of Experts and U.S. officials allege support North Korea's weapons programs. This entry documents named individuals, government indictments, sanctions, and specific hacking incidents, distinguishing DOJ/FBI/OFAC/UN attributions from private-sector research findings.

avoid.net/pumpdotfun27/100[WARNING]

pump.fun is a Solana-based token launchpad, operated by UK-registered Baton Corporation Ltd, that lets anyone create a tradable token in seconds via an automated bonding curve and has generated hundreds of millions of dollars in fees since its January 2024 launch. The platform has been the subject of a UK Financial Conduct Authority warning, a suspended and later reinstated livestream feature that hosted graphic and abusive content, a $1.9-2 million insider exploit by a former contractor who was later criminally convicted, and consolidated U.S. federal class-action and RICO litigation alleging pump.fun and infrastructure partners ran a rigged 'casino' extracting billions of dollars from retail traders. None of the core securities or racketeering allegations against pump.fun have been adjudicated; independent research also indicates the overwhelming majority of tokens launched on the platform end as failed or abandoned projects.

avoid.net/ton-blockchain44/100[WARNING]

TON (The Open Network) is a public layer-1 blockchain originally developed by Telegram and now deeply integrated with the Telegram messaging app under Pavel Durov's direction. It is a live, widely used network with legitimate exchanges, DeFi protocols, and hundreds of millions of Telegram Mini App users, but it has also become a recurring venue for phishing drainers, pyramid schemes, rug pulls, malware command-and-control infrastructure, and illicit Telegram-based marketplaces, in part because analytics and forensic tooling for TON lagged behind more established chains. Separately, Telegram co-founder Pavel Durov faces an unresolved criminal investigation in France opened in 2024 and, since July 2026, an in-absentia terrorism-related charge in Russia; neither has resulted in a conviction.

avoid.net/compound-finance55/100[CAUTIONARY]

Compound Finance is one of the earliest and most established decentralized lending protocols on Ethereum, launched in 2018 and governed since 2020 by a DAO around the COMP token. The protocol's smart-contract core has never suffered a direct exploit of user funds, but it has been repeatedly hit by operational and front-end security failures — a costly 2021 token-distribution bug, a 2023 X/Twitter account compromise used for phishing, a 2024 DNS hijack of its website, and a 2024 governance controversy in which a whale-backed group used purchased voting power to pass a treasury allocation over community objections. Combined with declining total value locked and a 2023 leadership departure, these incidents warrant continued scrutiny even though the underlying lending contracts have a long audit history and no reported loss of user deposits from a core-protocol hack.

200 entities tracked · record updated 2026-09
Page transparency log
Last updated fingerprint: 4DHy2N…rE8x