Avoid your next
big mistake
Crowdsourced due diligence for crypto
Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis
Featured Investigations
Bankr is an AI-powered crypto wallet and trading bot built on the Base network (Ethereum L2), allowing users to trade, swap, and manage funds through natural-language commands on X (Twitter) and Farcaster. In May 2026, the platform suffered two separate security incidents within weeks of each other: a prompt-injection attack exploiting Grok that drained approximately $150,000–$175,000 in DRB tokens, and a distinct key-compromise or session-token breach that affected 14 user wallets and drained an estimated $170,000–$385,000 in total. Bankr publicly committed to reimbursing all affected users, but no confirmed completion of that reimbursement has been documented in available sources as of the investigation date.
avoid.net/su-zhu→3/100[CRITICAL]Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.
avoid.net/satish-kumbhani→0/100[CRITICAL]Satish Kumbhani is the founder of BitConnect, a cryptocurrency platform that the U.S. Department of Justice, SEC, and multiple state regulators have determined operated as a global Ponzi scheme defrauding investors of approximately $2.4 billion between 2016 and 2018. Kumbhani was indicted by a federal grand jury in San Diego on February 25, 2022, on charges carrying a maximum penalty of 70 years in prison, and has remained a fugitive from justice since disappearing from India following his U.S. indictment.
avoid.net/donald-g-basile-bitcoin-latinum-ltnm→2/100[CRITICAL]Donald G. Basile is the founder of Bitcoin Latinum (LTNM) and CEO of Monsoon Blockchain Corporation. On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and two entities he controlled — GIBF GP, Inc. and Monsoon Blockchain Corporation — alleging he raised approximately $16 million from hundreds of investors through materially false statements about nonexistent insurance coverage and asset backing. The SEC alleges more than 80% of investor funds were diverted to personal use, including real estate purchases and a $160,000 horse. The case is a civil action; no criminal charges have been reported as of the investigation date.
avoid.net/xinbi-guarantee→0/100[CRITICAL]Xinbi Guarantee is a Chinese-language illicit online marketplace that operated via Telegram, functioning as an escrow service connecting transnational criminal syndicates with vendors selling scam infrastructure, money laundering services, stolen data, and human trafficking recruitment. On September 9, 2026, the U.S. Treasury's OFAC designated Xinbi Guarantee as a significant transnational criminal organization under Executive Order 13581, and the DOJ's Scam Center Strike Force seized two cryptocurrency wallets and obtained restraining orders covering 47 additional wallets, together freezing approximately $52.8 million. Blockchain analytics firms place the platform's total transaction throughput at between $24 billion and $36 billion since approximately 2022.
avoid.net/mantra-chain-august-2026-exploit→38/100[WARNING]On August 20, 2026, MANTRA Chain — an RWA-focused Cosmos-based Layer 1 — suffered an exploit of a critical vulnerability in its upstream Cosmos EVM module, forcing a full network halt of approximately 30 hours and causing its OM token to drop 18% to a record low of $0.004126. Approximately 720.9 million OM tokens worth roughly $3.6 million were drained across the incident, part of a coordinated attack pattern that ultimately affected six Cosmos EVM chains and converted approximately $5.72 million in stolen assets across the ecosystem. This page covers the August 2026 security incident; the April 2025 token price collapse is documented separately under the 'mantra-chain' entry.
avoid.net/cosmos-labs→28/100[WARNING]Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.
avoid.net/mantra-chain-upstream-exploit-august-2026→32/100[WARNING]On August 20-21, 2026, MANTRA Chain halted all block production after an attacker exploited a critical vulnerability (ASA-2026-002) in the shared Cosmos EVM ICS20 precompile, a component developed by Cosmos Labs and used by multiple chains. MANTRA's OM token fell 18.5% to an all-time low of $0.004126 during the approximately 30-hour outage, and the chain resumed on August 22 after deploying patched version 8.4.0. MANTRA stated no user funds were exploited and that only two project-managed wallets were affected, but the team has not published a technical post-mortem nor disclosed what, if anything, was extracted from those wallets, leaving the full financial scope of the incident unresolved as of August 27, 2026.
avoid.net/mantra-chain→10/100[CRITICAL]MANTRA Chain, a Cosmos-EVM layer-1 blockchain focused on real-world asset tokenization, halted all block production on August 20, 2026 after an attacker exploited a known vulnerability in the shared Cosmos EVM ICS20 precompile module. The network was offline for approximately 30 hours, the native OM token fell 18% to an all-time low of $0.004126, and South Korean exchanges Upbit, Bithumb, and Coinone placed OM on delisting watchlists. This is MANTRA's second major crisis in 2026, following the April 2025 collapse of OM by more than 90%, and occurs in the context of a broader Cosmos EVM security incident that also affected KiiChain and TAC.
avoid.net/hefu-chai-and-huaisong-xiang-former-robinhood-engineers→8/100[CRITICAL]Hefu Chai, 36, and Huaisong Xiang, 30, both former Robinhood software engineers, were criminally charged by federal prosecutors in the Southern District of New York, unsealed on September 15, 2026, with commodities fraud and wire fraud. Prosecutors allege the pair misappropriated confidential internal information about upcoming Robinhood Crypto token listings and used it to open positions in perpetual futures on the decentralized exchange Hyperliquid ahead of public listing announcements between 2025 and 2026, each allegedly profiting more than $50,000. The charges are allegations only; no conviction has occurred, and no plea, trial outcome, or sentencing has been reported as of this writing.
avoid.net/donald-g-basile-bitcoin-latinum-fraud→3/100[CRITICAL]Donald G. Basile is a technology entrepreneur and the founder of Bitcoin Latinum (LTNM), a cryptocurrency token marketed in 2021 as 'the world's first insured digital asset.' On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil fraud suit against Basile and two entities he controlled, GIBF GP, Inc. and Monsoon Blockchain Corporation, alleging he raised approximately $16 million from hundreds of investors via Simple Agreements for Future Tokens (SAFTs) using false claims of a $1 billion insurance policy and a diversified backing trust that never existed, and that he diverted more than 80% of investor funds to personal use. Basile and Bitcoin Latinum had also faced multiple private civil suits alleging securities fraud since 2022, predating the SEC action.
avoid.net/hefu-chai-huaisong-xiang→5/100[CRITICAL]Hefu Chai and Huaisong Xiang are former Robinhood Crypto engineers charged by the U.S. Department of Justice on September 15, 2026 with commodities fraud and wire fraud. Prosecutors allege they misappropriated confidential information from Robinhood's internal token-listing pipeline and used it to pre-position perpetual futures trades on the decentralized exchange Hyperliquid between 2025 and 2026, with each defendant allegedly profiting more than $50,000. The charges are allegations only; no conviction or guilty plea has been entered as of the date of this investigation.
avoid.net/blockstream→42/100[WARNING]Blockstream is a Bitcoin infrastructure company founded in 2014, led by cryptographer Adam Back, that develops the Liquid Network sidechain, Core Lightning, Blockstream Green wallet, Blockstream Jade hardware wallet, and Blockstream Satellite. The company achieved unicorn status with a $3.2 billion valuation in 2021 and has raised over $400 million in total financing. In September 2026, the Liquid Network suffered a critical ~$320 million exploit that drained approximately 4,000 BTC from its federation wallet, with ~598 BTC remaining unrecovered; the company also faces unresolved allegations regarding its Bitcoin Mining Note product and the undisclosed prior fraud conviction of its former mining division head.
avoid.net/soulja-boy-deandre-cortez-way→12/100[CRITICAL]Soulja Boy, born DeAndre Cortez Way, is an American rapper who became one of the most extensively documented celebrity crypto promoters linked to rug pulls and abandoned projects. Blockchain investigator ZachXBT documented 73 crypto promotions and 16 NFT collections between 2021 and 2023, estimating Way earned approximately $730,000 from paid endorsements, several of which subsequently rugged or were abandoned. The SEC charged Way in March 2023 for undisclosed paid promotion of TRX and BTT tokens; unlike six co-defendants who settled, Way did not initially respond to the charges, resulting in a default judgment. The SEC later filed to dismiss remaining claims against Way in 2026 as part of a broader resolution with the Justin Sun/Tron defendants. Way issued a public apology in December 2025, claiming ignorance of the fraudulent nature of the projects, though the timing coincided with renewed controversy after Base co-founder Jesse Pollak publicly disclosed a $1,500 investment in a new Soulja Boy-linked memecoin on the Base network.
avoid.net/soulja-boy-deshawn-raymond→8/100[CRITICAL]Soulja Boy (legal name DeAndre Cortez Way; also referenced as DeShawn Raymond) is an American rapper with an extensive, multi-year documented history of promoting cryptocurrency tokens and NFT collections, a large share of which were subsequently identified as rug pulls, abandoned projects, or otherwise fraudulent. On-chain investigator ZachXBT's April 2023 research catalogued 73 crypto promotions and 16 NFT drops linked to him, estimating over $730,000 in promotional earnings, and the U.S. Securities and Exchange Commission separately charged him in 2023 for undisclosed paid touting of Tronix (TRX) and BitTorrent (BTT). The pattern resurfaced in December 2025 when Base co-founder Jesse Pollak publicly engaged with a new Soulja Boy-linked meme token, prompting ZachXBT to revive the allegations and renewed industry criticism, followed by a public apology from Soulja Boy.
avoid.net/liquid-network-exploit-september-2026→18/100[CRITICAL]On September 6, 2026, attackers exploited a cache-verification bug in Blockstream's open-source Elements software to mint roughly 4,000 unbacked L-BTC on the Liquid Network and peg them out for real Bitcoin via federation member SideSwap, draining approximately 95% of the sidechain's BTC reserves (~$320 million). The attackers, claiming to be white hats, returned about 3,400 BTC (~85%) after a patch was deployed but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty, which Blockstream has refused to authorize, calling it theft. The incident halted Liquid Network operations for several days and renewed scrutiny of the security assumptions underlying federated Bitcoin sidechains used by exchanges.
avoid.net/ukrainian-fake-crypto-investment-ring-kyiv-2026→0/100[CRITICAL]A Kyiv-based criminal network allegedly operated multiple fake cryptocurrency investment platforms that targeted victims across more than 20 countries, with an estimated peak monthly turnover of up to $1 million. Ukrainian law enforcement, including the National Police of Ukraine, the Security Service of Ukraine (SBU), and the Office of the Prosecutor General, dismantled the operation in early September 2026 through 34 coordinated raids. The alleged organizer, a 25-year-old IT specialist, recruited over 46 Ukrainian citizens to staff the ring, which combined fabricated investment dashboards, wallet-draining malware, and identity data harvesting.
avoid.net/liquid-network→22/100[CRITICAL]Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.
avoid.net/kyiv-crypto-drainer-ring-fake-investment-platforms-september-2026→3/100[CRITICAL]In early September 2026, Ukraine's Security Service (SBU) and National Police announced the dismantling of a Kyiv-based network that allegedly ran fake cryptocurrency investment platforms and used a 'test transaction' approval-phishing technique to drain victims' wallets. Authorities said the operation, allegedly organized by a 25-year-old IT specialist and staffed by more than 46 Ukrainian citizens, generated turnover of up to $1 million a month at its peak and had identified at least 62 victims across more than 20 countries. As of the most recent reporting, no suspects had been named publicly and formal notices of suspicion had reportedly not yet been served, with the case proceeding under the Prosecutor General's Office.
avoid.net/poolin-technology→8/100[CRITICAL]Poolin Technology Pte. Ltd., once the world's largest Bitcoin mining pool, halted all mining and hosting operations on July 10, 2026 and filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of New Jersey on July 22, 2026, with roughly $173 million in total obligations against less than $10 million in assets. The largest liability, $163.7 million owed to approximately 11,700 wallet customers as unpaid "IOU" tokens issued after Poolin froze withdrawals in September 2022, is projected to recover only about 32 cents on the dollar through a court-supervised sale of the company's two remaining Texas mining sites, a process still underway as of this writing.
avoid.net/liquid-network-elements-cache-bug-exploit-september-2026→18/100[CRITICAL]On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.
avoid.net/hunter-biden-laptop-token→22/100[CRITICAL]$LAPTOP is an ERC-20 memecoin launched on the Base blockchain on September 9, 2026 by Hunter Biden, son of former U.S. President Joe Biden. The token surged to a reported peak near $190–$225 shortly after launch before collapsing approximately 98–99% within hours, with an estimated four out of five buyers suffering losses. Biden disputes characterizations of the collapse as a rug pull, attributing the crash to insufficient liquidity and automated sniper-bot activity, while asserting that team tokens remained locked and unsold throughout.
avoid.net/sideswap→38/100[WARNING]SideSwap is an open-source, non-custodial peer-to-peer trading platform and wallet built on Blockstream's Liquid Network, founded in 2020 by Scott Millar. On September 6, 2026, SideSwap's Peg-out Authorization Key (PAK) was the mechanism through which approximately 3,996 real BTC — worth roughly $320 million — was released from the Liquid federation reserve in a single transaction, following an Elements software vulnerability that allowed the minting of unbacked L-BTC. SideSwap's own post-mortem acknowledged operational oversights including keeping its PAK key connected to the internet at all times and running no size, velocity, or origin checks on peg-out orders, though the underlying vulnerability originated in the open-source Elements codebase maintained by Blockstream.
avoid.net/blockstream-liquid-network→32/100[WARNING]The Liquid Network is a Bitcoin sidechain operated by Blockstream via a federated multi-signature custody model, designed for fast, confidential BTC transfers between exchanges and financial institutions. On September 6, 2026, attackers exploited a cache-key collision vulnerability in the open-source Elements software to mint approximately 4,000 unbacked L-BTC and drain roughly $320 million from the federation reserve — one of the largest Bitcoin-adjacent security incidents on record. Attackers claiming to be white-hat researchers subsequently returned approximately 3,400 BTC while retaining ~598.5 BTC (~$47M) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft.
avoid.net/liquid-network-blockstream→28/100[WARNING]Liquid Network is a Bitcoin sidechain operated by Blockstream and a federation of member exchanges, launched in 2018 to enable fast inter-exchange BTC settlement via a pegged asset called L-BTC. On September 6, 2026, attackers exploited a range-proof cache collision vulnerability in the underlying Elements software to mint approximately 4,000 unbacked L-BTC tokens and redeem them for roughly $320 million in real Bitcoin from the federation reserve, representing one of the largest crypto hacks of 2026. Attackers returned approximately 85% of funds after the vulnerability was patched, but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft, not responsible disclosure.
avoid.net/evmos-network→30/100[WARNING]Evmos was a Cosmos-based, EVM-compatible proof-of-stake blockchain developed by Tharsis Labs that launched on mainnet in April 2022 and raised $27 million in a token sale led by Polychain Capital. The network was formally shut down on approximately May 18, 2026, after Governance Proposal #331 passed with 99.8% approval, halting all block production at block height 37,318,000. Following discontinuation, an authorization vulnerability in the Evmos vesting and lockup module — left unpatched because the codebase was no longer maintained — was exploited in August 2026 to drain approximately $3 million from BounceBit Chain, a third-party network built on the Evmos stack.
avoid.net/term-finance-governance-exploit-august-2026→10/100[CRITICAL]On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.
avoid.net/ivan-obukhov-foscom-fze→2/100[CRITICAL]Ivan Obukhov is a UAE-based Ukrainian national designated by OFAC on August 24, 2026, as part of Operation Economic Outcast. U.S. Treasury alleges that since 2023 he processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Qods Force, and that he has for years brokered Iranian shadow-fleet vessels. His UAE-registered company Foscom FZE, which he acquired in 2022, was simultaneously designated under Executive Order 13224 as an entity controlled by Obukhov.
avoid.net/defi-governance-attack-wave-2026→0/100[CRITICAL]Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.
avoid.net/nishad-singh→12/100[CRITICAL]Nishad Singh is a former software engineer who served as Director of Engineering at FTX, the cryptocurrency exchange that collapsed in November 2022 following the misappropriation of more than $8 billion in customer funds. Singh pleaded guilty in February 2023 to six criminal charges including wire fraud, commodities fraud, securities fraud, money laundering conspiracy, and campaign finance violations, and was sentenced in October 2024 to time served with no prison after providing extensive cooperation against FTX founder Sam Bankman-Fried. A supplemental CFTC civil settlement was reached in April 2026, requiring Singh to disgorge $3.7 million and subjecting him to a five-year trading ban.
avoid.net/kyle-davies→3/100[CRITICAL]Kyle Davies is the co-founder of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion in liabilities owed to 27 creditors. Following the collapse, Davies evaded liquidators, was sentenced in absentia to four months imprisonment in Singapore for failing to cooperate with court-ordered investigations, and received a nine-year ban from Singapore's Monetary Authority of Singapore (MAS) for regulatory violations including providing false information to regulators. He subsequently co-founded OPNX, a crypto bankruptcy claims exchange that also failed and shut down in early 2024.
avoid.net/justin-sun→7/100[CRITICAL]Justin Sun is the founder of the TRON blockchain and TRX token, and the controlling figure behind HTX (formerly Huobi) and Poloniex exchanges. In March 2023, the U.S. Securities and Exchange Commission charged Sun and three of his companies with fraud, market manipulation through wash trading, unregistered securities offerings, and orchestrating an undisclosed celebrity promotion scheme; the case partially settled in March 2026 with Rainberry Inc. paying a $10 million penalty while claims against Sun personally were dismissed. Sun has faced additional scrutiny including a reported FBI/DOJ criminal investigation, UK sanctions against an HTX entity over alleged Russia-linked transactions, a $114 million hot-wallet hack at Poloniex in November 2023, and disputed claims of diplomatic immunity through a Grenada WTO ambassadorship he held until mid-2022.
avoid.net/curve-finance→62/100[CAUTIONARY]Curve Finance is a major decentralized exchange (DEX) on Ethereum optimized for stablecoin and pegged-asset trading, operating since January 2020. On July 30, 2023, a latent vulnerability in the Vyper smart-contract compiler (versions 0.2.15, 0.2.16, and 0.3.0) was exploited across multiple Curve liquidity pools, draining approximately $70 million and triggering a near-systemic crisis when the resulting CRV price drop threatened to cascade-liquidate founder Michael Egorov's heavily collateralized on-chain loans. Roughly 73% of stolen funds were ultimately recovered or returned, and in December 2023 the Curve DAO voted to disburse approximately $49 million in compensation to affected liquidity providers.
avoid.net/changpeng-zhao→8/100[CRITICAL]Changpeng Zhao (CZ), born February 10, 1977, is the founder and former CEO of Binance, the world's largest cryptocurrency exchange by trading volume. On November 21, 2023, Zhao pleaded guilty to a federal charge of failing to implement an effective anti-money laundering (AML) program under the Bank Secrecy Act, as part of a landmark $4.3 billion resolution between Binance and U.S. federal regulators. He was sentenced to four months in federal prison in April 2024, served that term, and was subsequently pardoned by President Donald Trump in October 2025.
avoid.net/sinbad-io→2/100[CRITICAL]Sinbad.io was a Bitcoin mixing service that operated from October 2022 until its seizure by U.S., Dutch, and Finnish law enforcement in November 2023. OFAC designated it a key money-laundering tool of North Korea's Lazarus Group, which used it to launder proceeds from multiple major crypto hacks including Axie Infinity's Ronin Bridge and Atomic Wallet. On-chain analytics firms assessed it to be highly likely a rebranding of Blender.io, the first crypto mixer ever sanctioned by OFAC.
avoid.net/gate→32/100[WARNING]Gate.io (formerly Bter.com) is a centralized cryptocurrency exchange founded in 2013 by Han Lin, serving over 30 million users across 224 countries. The exchange has been flagged by on-chain investigator ZachXBT for allegedly concealing a $230 million hack attributed to North Korean state-sponsored hackers (Lazarus Group) that occurred in April 2018 and was never publicly disclosed to users. Additional concerns include a manipulated futures price feed incident causing millions in user losses in 2025, an AML-based ban by India's Financial Intelligence Unit in 2024, persistent user complaints about frozen withdrawals, and alleged wash trading activity inflating reported volumes.
avoid.net/dforce-lending→28/100[WARNING]dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.
avoid.net/roll→32/100[WARNING]Roll (tryroll.com) is an Ethereum-based social token infrastructure platform that allows creators to mint, distribute, and manage branded personal tokens. On March 14, 2021, Roll suffered a critical security breach in which an attacker compromised the private keys of its hot wallet and liquidated approximately $5.7 million worth of social tokens across 42 different creator tokens, routing stolen ETH through Tornado Cash. Roll subsequently upgraded its security infrastructure via a Fireblocks MPC integration and raised a $10M Series A in September 2021, but the root cause of the private key compromise was never publicly confirmed.
avoid.net/aperocket→22/100[CRITICAL]ApeRocket is a DeFi yield farming aggregator and optimizer originally deployed on Binance Smart Chain (BSC) and Polygon in 2021. The protocol suffered two simultaneous flash loan exploits on July 14, 2021, resulting in combined losses of approximately $1.26 million and a 63% collapse in its native SPACE token price. The project attempted a V2 relaunch with improved security, but the SPACE token currently shows zero trading volume and effectively zero market capitalization, indicating the protocol is inactive.
avoid.net/xtoken→10/100[CRITICAL]xToken (XTK) was a DeFi protocol offering wrapped staking tokens and liquidity management on Ethereum, founded by Michael J. Cohen in 2020. The protocol suffered two major flash loan exploits in 2021 — a $24.5 million attack in May and a $4.5 million attack in August — resulting in total losses exceeding $29 million and the permanent retirement of its flagship xSNX product. The XTK governance token subsequently lost approximately 99.84% of its value, and compensation paid to victims was significantly below the amounts stolen.
avoid.net/cream-lending→0/100[CRITICAL]C.R.E.A.M. Finance (Crypto Rules Everything Around Me) is a decentralized lending and borrowing protocol launched in August 2020, forked from Compound Finance. The protocol suffered three major exploits in 2021 totaling approximately $185 million in losses, making it one of the most frequently and severely hacked DeFi protocols in history. On-chain investigator ZachXBT flagged the protocol and its founders, and the CREAM token has collapsed more than 99% from its all-time high.
avoid.net/vee-finance→12/100[CRITICAL]Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.
avoid.net/compound-v2→28/100[WARNING]Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.
avoid.net/badger-dao→10/100[CRITICAL]Badger DAO is a decentralized autonomous organization and DeFi protocol launched in December 2020 focused on generating yield on Bitcoin-backed assets via Ethereum-based vaults. In December 2021, a front-end attack exploiting a compromised Cloudflare API key resulted in approximately $120–130 million in user funds being drained across roughly 500 wallets. As of 2025, the protocol has seen significant decline: its flagship eBTC product was sunset, BADGER was delisted from Binance, and total value locked has fallen to low single-digit millions.
avoid.net/vulcan-forged→28/100[WARNING]Vulcan Forged is a UK-based blockchain gaming studio and NFT marketplace operating on Polygon and its own Elysium Layer-1 blockchain, best known for VulcanVerse and its native PYR token. In December 2021 the platform suffered one of the largest gaming-sector hacks on record: an attacker exploited Vulcan Forged's servers to extract private keys from 96 semi-custodial wallets, stealing approximately 4.5 million PYR tokens then valued at roughly $140 million. The platform subsequently refunded affected users from its treasury and pledged to migrate to non-custodial wallets, but the incident exposed fundamental centralization and custodial risks in its architecture.
avoid.net/moola-market→28/100[WARNING]Moola Market is a decentralized lending protocol built on the Celo blockchain, founded in 2020 by Patrick Baron and backed by Polychain Capital. In October 2022, the protocol suffered a price manipulation exploit draining approximately $9.1 million, making it one of the largest DeFi incidents on Celo; over 93% of funds were returned by the attacker within hours in exchange for a roughly $500,000 bounty. The protocol subsequently relaunched with reduced collateral thresholds, but its TVL and MOO token value have declined sharply since the incident.
avoid.net/phemex→10/100[CRITICAL]Phemex is a centralized cryptocurrency derivatives exchange founded in November 2019 by former Morgan Stanley executives and registered in the British Virgin Islands. In January 2025, the exchange suffered one of the largest crypto hacks of that year, with an estimated $69–85 million drained from hot wallets across 16 blockchains, subsequently attributed to North Korea's Lazarus Group through on-chain evidence linking the same wallets to the February 2025 Bybit hack. Phemex has also faced formal regulatory enforcement actions in Ontario, Canada, and operates without authorization in the United Kingdom.
avoid.net/zksync→57/100[CAUTIONARY]ZKsync is an Ethereum Layer 2 scaling protocol built on zero-knowledge rollup technology, developed by Matter Labs, which has raised approximately $458 million in venture capital. The protocol has faced multiple significant controversies including a $5 million airdrop contract exploit in April 2025, a contentious 2024 token airdrop marred by sybil attack failures and community backlash, a South Korean regulatory probe into alleged price manipulation, compromised social media accounts spreading false SEC investigation claims, and an intellectual property theft lawsuit filed against Matter Labs by defunct firm BANKEX. User funds in the core protocol have not been directly compromised, but the pattern of incidents has substantially eroded community trust.
avoid.net/kinto-bridge→28/100[WARNING]Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.
avoid.net/electrum→62/100[CAUTIONARY]Electrum is an open-source, non-custodial Bitcoin wallet first released in November 2011 by Thomas Voegtlin and maintained by Electrum Technologies GmbH. It is widely regarded as one of the most feature-rich and long-standing Bitcoin desktop wallets, but has been the persistent target of large-scale phishing campaigns exploiting its open peer network architecture, resulting in more than $25 million in user losses documented between 2018 and 2020.
avoid.net/athena-bitcoin→22/100[CRITICAL]Athena Bitcoin, Inc. (OTC: ABIT) is one of the largest Bitcoin ATM (BTM) operators in the United States, with approximately 3,600–4,100 kiosks across 29 states and five countries. The company faces multiple active lawsuits, including a September 2025 action by the Washington, D.C. Attorney General alleging that 93% of deposits into its D.C.-area kiosks were tied to fraud and that the company charged undisclosed fees of up to 26% per transaction while refusing refunds to scam victims. Athena disputes the allegations and states it employs robust consumer-protection protocols; as of the investigation date, no court has adjudicated the merits of these claims.
avoid.net/sality-botnet-eggjagger-crypto-clipboard-stealer→2/100[CRITICAL]Sality is a long-running malware family and peer-to-peer botnet first discovered in 2003, attributed by CrowdStrike to a Russia-based eCrime group tracked as SALTY SPIDER. For at least the eight years preceding its disruption, the botnet's primary payload was EggJagger, a clipboard-hijacking tool that silently replaced cryptocurrency wallet addresses on infected machines with attacker-controlled addresses. On August 31, 2026, a coordinated operation involving the U.S. Department of Justice, FBI, international law enforcement from Bulgaria, Hungary, and Romania, CrowdStrike, and the Shadowserver Foundation severed more than 15,000 infected machines from the botnet's infrastructure via a peer-to-peer sinkholing operation, though no arrests were announced and malware already installed on compromised machines remained active pending manual remediation.
avoid.net/rain-financial-crypto-card-infrastructure→58/100[CAUTIONARY]Rain (legal entity: Signify Holdings, Inc.) is a New York-headquartered fintech company founded in 2021 that provides stablecoin-powered card issuing and payments infrastructure to enterprises, neobanks, and developers. The company is a Visa and Mastercard Principal Member, serves over 200 enterprise partners, and processed roughly $3 billion in annualized transactions as of early 2026. In August 2026, an authorization flaw in an outdated Rain Solana smart contract was exploited, draining approximately $1.1 million from card-collateral accounts across multiple partner programs; Rain upgraded all affected contracts and partner programs reimbursed affected users in full.
avoid.net/outsider-enterprise→2/100[CRITICAL]Outsider Enterprise is a China-based phishing-as-a-service operation, attributed by researchers to a threat actor known as ChenLun, that sold subscription-based phishing kits through a Telegram bot since at least July 2023. On June 12, 2026, Google filed a civil RICO and Lanham Act lawsuit against 25 Doe defendants (case No. 1:26-cv-04982-VM, S.D.N.Y.), and the FBI announced Operation Ghost Hook the following day, seizing domains and approximately $100,000 from the operation's payment wallets. The FBI's Cyber Division has linked the platform to an estimated $1.9 billion in losses and approximately 3.87 million compromised payment card numbers; post-takedown research published September 3, 2026 found the affiliate network remained active with over 700 new phishing domains identified after the enforcement action.
avoid.net/abracadabra-money→28/100[WARNING]Abracadabra Money is a multi-chain DeFi lending protocol founded in 2021 that allows users to mint Magic Internet Money (MIM), a USD-pegged stablecoin, using interest-bearing tokens as collateral. The protocol has suffered four significant security incidents between 2022 and 2025, losing over $21 million in aggregate, and its MIM stablecoin has lost its dollar peg on multiple occasions. The protocol is also linked to the Wonderland/Sifu scandal of early 2022, which caused severe reputational and financial contagion across its interconnected 'Frog Nation' ecosystem.
avoid.net/pancakebunny→18/100[CRITICAL]PancakeBunny was a Binance Smart Chain yield aggregator and optimizer built by a team known as Mound, launched in December 2020. The protocol suffered two major flash loan exploits in 2021: a May 20, 2021 attack that caused the BUNNY token to crash over 95% and wiped out approximately $200 million in market capitalization, and a July 16, 2021 attack on its Polygon fork PolyBunny that resulted in $2.4 million in losses. Both exploits stemmed from oracle price manipulation vulnerabilities in the minting reward logic, and the protocol has never recovered to its pre-exploit state.
avoid.net/euler-finance→58/100[CAUTIONARY]Euler Finance is an Ethereum-based non-custodial lending protocol founded in 2020 by Michael Bentley (PhD, Oxford) that pioneered permissionless lending for long-tail ERC-20 assets. On March 13, 2023, the protocol suffered a ~$197 million flash loan exploit — the largest DeFi hack of 2023 — caused by a missing health check in the donateToReserves() function. In an unusual outcome, the attacker, who communicated under the alias 'Jacob,' returned approximately $240 million in assets (including ETH price appreciation) over three weeks following on-chain negotiations, enabling full user restitution. The protocol relaunched as Euler V2 in September 2024 with a modular architecture, 45+ security audits, and subsequently grew TVL to over $1.5 billion by early 2025.
avoid.net/bnb-chain-bridge→16/100[CRITICAL]The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.
avoid.net/transit-finance→2/100[CRITICAL]Transit Finance (also known as Transit Swap) is a cross-chain DEX aggregator supporting over 122 decentralized exchanges across Ethereum, BNB Chain, TRON, Solana, Polygon, and other networks. The protocol has suffered two confirmed security exploits: a $28.9 million hack in October 2022 due to an arbitrary external call vulnerability in its routing contract, with approximately $18.9 million recovered; and a second $1.88 million exploit in May 2026 via a deprecated TRON smart contract that remained on-chain and exploitable years after official deprecation. ZachXBT flagged the protocol amid broader DeFi monitoring, and the 2022 attacker routed funds through OFAC-sanctioned Tornado Cash.
avoid.net/ranger-finance→22/100[CRITICAL]Ranger Finance was a Solana-based perpetual contract aggregator that raised $1.9M in seed funding in January 2025 and launched its RNGR token in January 2026. Within two months of token launch, community governance voted to liquidate the project treasury following allegations that the team made materially misleading claims about trading volume and revenue during its ICO. The project formally shut down in May 2026 after the treasury liquidation and approximately $900,000 in exposure from the DPRK-linked Drift Protocol exploit left operations unsustainable, with employees and vendors not fully compensated.
avoid.net/cover-protocol→18/100[CRITICAL]Cover Protocol was a decentralized insurance marketplace on Ethereum, launched in November 2020 after a troubled rebrand from the failed SAFE token project. On December 28, 2020, a critical smart contract vulnerability in its Blacksmith farming contract allowed an attacker to mint approximately 40 quintillion COVER tokens and extract over $4 million in assets, crashing the token price by more than 97%. After a failed merger with Yearn Finance and the abrupt departure of core developers, the protocol permanently shut down on September 5, 2021, distributing remaining treasury funds to token holders.
avoid.net/paid-network→12/100[CRITICAL]PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.
avoid.net/bunny→10/100[CRITICAL]PancakeBunny (Bunny Finance) was a Binance Smart Chain yield-optimizer developed by the anonymous team MOUND (Mound Inc.), which received a $1.6 million seed round led by Binance Labs in April 2021. The protocol suffered three separate exploits across 2021–2022 totaling over $127 million in losses, including a $45 million flash loan attack in May 2021, a $2.4 million polyBUNNY exploit on Polygon in July 2021, and an $80 million hack of its affiliated lending protocol Qubit Finance in January 2022. The BUNNY token has lost more than 99% of its all-time high value, the protocol transitioned to a DAO structure in early 2022, and no stolen funds from any exploit were publicly confirmed as recovered.
avoid.net/belt-finance→28/100[WARNING]Belt Finance (belt.fi) is a multi-strategy yield aggregator and stableswap AMM built primarily on Binance Smart Chain (BSC), developed by South Korean blockchain firm Ozys. On May 29, 2021, the protocol was exploited via a flash loan attack that netted the attacker approximately $6.23 million in BUSD and caused an estimated $50 million in total pool losses. The protocol announced a phased compensation plan for affected users but full repayment status remains unverified; the protocol has continued operating in diminished form, with current TVL of approximately $12 million as of 2025.
avoid.net/popsicle-finance→12/100[CRITICAL]Popsicle Finance is a cross-chain automated yield optimization protocol, launched in March 2021, that suffered a critical $20.7 million exploit in August 2021 due to a reward-tracking vulnerability in its Sorbetto Fragola pools. The protocol is part of Daniele Sestagalli's 'Frog Nation' ecosystem alongside Wonderland (TIME) and Abracadabra Money (MIM), which was later engulfed in a major scandal when the treasury manager of Wonderland was revealed to be Michael Patryn, a convicted felon and co-founder of the fraudulent QuadrigaCX exchange. The project subsequently rebranded as WAGMI in 2023 but remains a high-risk entity given the severity of the 2021 exploit, the laundering of stolen funds through Tornado Cash, and the broader Frog Nation governance failures.
avoid.net/baton-corporation-ltd-pump-fun→12/100[CRITICAL]Baton Corporation Ltd is the UK-incorporated company that owns and operates Pump.fun, the dominant Solana-based memecoin launchpad launched in January 2024. The company and its three named founders — Noah Tweedale, Alon Cohen, and Dylan Kerler — are defendants in a live federal RICO class action in the Southern District of New York (Aguilar v. Baton Corporation Ltd., 1:25-cv-00880-CM) after Judge Colleen McMahon allowed wire fraud, illegal gambling, and unlicensed money transmission claims to proceed following a motion-to-dismiss ruling issued August 31, 2026. The platform has also received a formal regulatory warning from the UK Financial Conduct Authority and had its iOS app delisted from U.S. and Indian App Stores in September 2026.
avoid.net/coldcard-coinkite→42/100[WARNING]Coldcard is a Bitcoin-only hardware wallet manufactured by Toronto-based Coinkite, founded in 2013 by Rodolfo Novak and Peter Gray. The device held a strong community reputation for security-focused design, open-source firmware, and air-gapped operation until a firmware bug introduced in March 2021 was exploited beginning July 30, 2026, resulting in approximately $116 million in Bitcoin losses across more than 5,200 addresses. Coinkite has acknowledged the vulnerability, issued patched firmware, and suspended data deletion in anticipation of litigation; class-action proceedings had been threatened but not yet filed as of September 2026.
avoid.net/mango-markets→12/100[CRITICAL]Mango Markets was a Solana-based decentralized trading platform offering spot trading, perpetual futures, and lending with cross-margining. In October 2022, trader Avraham Eisenberg executed an oracle manipulation attack, draining approximately $116–117 million from the protocol through artificially inflated MNGO collateral. The protocol subsequently faced enforcement actions from the DOJ, SEC, and CFTC, settled with regulators in 2024, and formally shut down in January 2025.
avoid.net/genesis-global→8/100[CRITICAL]Genesis Global Capital, LLC was the institutional crypto lending subsidiary of Digital Currency Group (DCG), founded in 2018 as an extension of Genesis Global Trading. Following cascading losses from Three Arrows Capital's June 2022 default and FTX's November 2022 collapse, Genesis halted customer withdrawals on November 16, 2022 and filed for Chapter 11 bankruptcy on January 19, 2023, with liabilities estimated between $1 billion and $10 billion owed to over 100,000 creditors. The entity faced multiple regulatory actions including SEC charges for unregistered securities offerings, a New York Attorney General fraud lawsuit naming DCG CEO Barry Silbert by name, and a separate 2025 SEC settlement against DCG and former Genesis CEO Soichiro Moro for misleading investors about Genesis's financial condition.
avoid.net/beanstalk-farms→28/100[WARNING]Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.
avoid.net/exmo-exchange-limited→4/100[CRITICAL]EXMO Exchange Limited is a UK-registered cryptocurrency exchange founded circa 2013 by Russian nationals Eduard Bark and Ivan Petukhovskiy. The exchange suffered a hot wallet hack in December 2020 losing approximately $10.5 million in user funds, faced multiple regulatory failures including a failed FCA registration and a UK ASA ruling for misleading advertising, and was sanctioned by the UK government on May 26, 2026 under Russia (Sanctions) (EU Exit) Regulations 2019 for alleged facilitation of Russian sanctions evasion via transactions with sanctioned entities Garantex, Grinex, and Chatex totaling over $19.5 million. Blockchain analysis by TRM Labs found that EXMO's claimed operational separation from its Russia-facing spinoff EXMO.me was not reflected in actual custodial wallet infrastructure.
avoid.net/the-dao→10/100[CRITICAL]The DAO was a decentralized autonomous organization launched on the Ethereum blockchain in April 2016 that raised approximately $150 million in Ether — the largest crowdfunding to date at the time — before being drained of 3.6 million ETH (roughly $50–60 million) on June 17, 2016, via a reentrancy vulnerability in its smart contract code. The hack triggered an acrimonious debate over blockchain immutability and led to a contentious hard fork of the Ethereum network on July 20, 2016, splitting it into Ethereum (ETH) and Ethereum Classic (ETC). In 2017 the U.S. SEC concluded that DAO tokens constituted unregistered securities, marking a landmark regulatory precedent for the entire crypto industry.
avoid.net/bondly→22/100[CRITICAL]Bondly Finance is a DeFi and NFT protocol launched in September 2020 that suffered a major exploit on July 14-15, 2021, in which 373 million BONDLY tokens were minted via owner-level credentials and sold into liquidity pools, causing an 82% token price collapse and approximately $5.9-7.5 million in losses. The exploit originated from the protocol owner's address, prompting blockchain security firm PeckShield to allege a potential rug pull, though the team attributed it to compromised credentials belonging to CEO Brandon Smith. Following acquisition by Animoca Brands in September 2021 and a rebrand to Forj in May 2022, the project has undergone significant leadership changes; the original founder departed under a cloud of unresolved questions about the exploit's true origin.
avoid.net/beanstalk→12/100[CRITICAL]Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.
avoid.net/yield-protocol→38/100[WARNING]Yield Protocol was a decentralized finance protocol offering fixed-rate, fixed-term borrowing and lending on Ethereum and Arbitrum, launched in October 2020 and funded by Paradigm. It suffered multiple security incidents including collateral damage from the March 2023 Euler Finance hack and a critical smart contract vulnerability patched via Immunefi in April 2023, before announcing a full wind-down in October 2023 citing insufficient demand and regulatory pressure. After official operations ceased in December 2023, abandoned smart contracts on Arbitrum were exploited in April 2024 for approximately $181,000 via a flash loan attack on pool balance discrepancies.
avoid.net/blessed-trust-hexa-whale→2/100[CRITICAL]Blessed Trust Limited and Hexa Whale Trading Limited are two Hong Kong-incorporated entities that U.S. federal prosecutors allege served as the central laundering vehicles for over $1.5 billion in proceeds from sanctioned Iranian crude oil and petroleum sales. On September 14, 2026, the U.S. Attorney's Office for the Southern District of New York filed a civil forfeiture complaint (case 1:26-cv-08010) seeking $61,192,367.59 USDT frozen across ten TRON addresses, with Tether having already frozen those assets in June and July 2025. The allegations, which remain unproven in court, describe both entities routing funds through Binance accounts to IRGC-linked money-services businesses and the Iranian exchange Nobitex; Binance offboarded both companies and is not named as a defendant.
avoid.net/coinw6→0/100[CRITICAL]CoinW6 is a fraudulent cryptocurrency trading platform at the center of the SEC's first-ever enforcement action targeting a pig butchering (relationship investment) scam, filed September 17, 2024 in the U.S. District Court for the Central District of California (Case No. 2:24-cv-07924). According to the SEC's complaint, operators of CoinW6 posed as wealthy professionals on LinkedIn and Instagram, cultivated romantic relationships with victims over WhatsApp, then directed at least 11 investors to a fake trading interface that displayed fabricated returns, stealing approximately $2.2 million between July 2022 and December 2023. As of mid-2026, the case remains pending, with the SEC seeking service by publication after defendants failed to appear.
avoid.net/chipmixer→0/100[CRITICAL]ChipMixer was a darknet Bitcoin mixing service that operated from August 2017 to March 2023, processing over $3 billion in illicit cryptocurrency on behalf of ransomware groups, North Korean state hackers, Russian military intelligence, and darknet drug markets. On March 15, 2023, U.S. and German authorities seized its infrastructure, domains, and approximately $46 million in cryptocurrency in a coordinated international takedown. Minh Quoc Nguyen, 49, a Vietnamese national residing in Hanoi, was charged in the Eastern District of Pennsylvania with money laundering, operating an unlicensed money transmitting business, and identity theft; he remains a fugitive.
avoid.net/acala-network→32/100[WARNING]Acala Network is a Polkadot-native DeFi hub offering a multi-collateralized stablecoin (aUSD), liquid staking, and an AMM DEX. On August 14, 2022, a misconfiguration in a newly deployed liquidity pool caused 3.022 billion aUSD to be erroneously minted, triggering a 99% depeg; approximately 98% of the erroneous tokens were subsequently recovered and burned via community governance votes. The incident raised significant concerns about the protocol's claimed decentralization after the team unilaterally placed the network in maintenance mode and froze token transfers without an on-chain vote.
avoid.net/sovryn→38/100[WARNING]Sovryn is a Bitcoin-backed decentralized finance protocol built on the Rootstock (RSK) sidechain, offering lending, borrowing, margin trading, and AMM services with its native SOV governance token. The protocol suffered a confirmed $1.1 million price manipulation exploit in October 2022 targeting its legacy lending pools, with approximately half of funds recovered via developer intervention. A separate critical smart contract vulnerability was disclosed via bug bounty in March 2021 but was not exploited. ZachXBT has flagged the entity; no detailed public post from ZachXBT specifically detailing Sovryn allegations was independently located at time of investigation.
avoid.net/htx→28/100[WARNING]HTX (formerly Huobi Global) is one of the world's largest cryptocurrency exchanges, rebranded in September 2023 following the de facto acquisition of Huobi by interests linked to Justin Sun in late 2022. The exchange has suffered at least three significant security incidents totaling over $130 million in losses since September 2023, and in May 2026 was sanctioned by the UK government for alleged facilitation of Russian sanctions evasion — the first such crypto-exchange designation under the UK Russia sanctions framework. HTX also faces FCA legal proceedings over illegal financial promotions to UK consumers, has withdrawn its Hong Kong licensing applications twice, and has been publicly criticized for opaque reserve practices.
avoid.net/fixedfloat→10/100[CRITICAL]FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.
avoid.net/layerzero-executor-wallet-incident-july-2026→62/100[CAUTIONARY]On July 15, 2026, security firm PeckShield and on-chain analyst Specter reported that LayerZero executor wallets appeared to have been drained of approximately $2.4 million across eight blockchain networks. LayerZero Core responded the same day, stating the transfers were routine internal inventory rebalancing and that no exploit had occurred and no user funds were at risk. The incident was not independently confirmed as a security breach, and as of the date of this investigation LayerZero's denial has not been publicly contradicted by on-chain forensic analysis or a third-party post-mortem.
avoid.net/sheldon-xia→22/100[CRITICAL]Sheldon Xia is the founder of BitMart, a cryptocurrency exchange he launched in 2017 and led as CEO until April 2025, when he assumed the role of Group President. BitMart suffered a $196 million hot-wallet hack in December 2021; Xia publicly pledged full compensation from company funds but victims reported they had not been repaid as of early 2022. In July 2026 BitMart announced it would shut down, and the closure has been accompanied by reports of frozen user withdrawals, unpaid employee wages, and demands for reserve disclosures that Xia has disputed as based on fabricated information.
avoid.net/zondacrypto-collapse→2/100[CRITICAL]Zondacrypto (operated by BB Trade Estonia OÜ, formerly BitBay) was one of Poland's largest cryptocurrency exchanges before its 2026 collapse. On-chain analysis published in April 2026 showed the exchange's operational Bitcoin reserves had fallen by roughly 99.7% since mid-2024, the site went offline that month, and both the exchange's founder and its later CEO became unreachable. Estonia's financial regulator revoked the company's licence in June 2026, a Tallinn court declared it bankrupt on August 27, 2026, and Polish prosecutors opened a fraud investigation estimating customer losses near 350 million zloty (approximately $94-97 million) affecting an estimated 30,000 or more people.
avoid.net/tria→42/100[WARNING]Tria is a self-custodial Solana-based neobank founded in 2022 by Vijit Katta and Parth Bhalla that raised $12 million in pre-seed and strategic funding in October 2025. On August 28, 2026, an attacker exploited an authorization-bypass vulnerability in an outdated Rain Solana card contract shared across multiple neobank products, draining $431,945 from 636 Tria card users. Tria pledged full refunds plus a 10% bonus to affected users; its native token fell more than 10% following public disclosure. The incident did not affect user self-custodial wallets — only card-collateral balances staged for spending were compromised.
avoid.net/radoslaw-piesiewicz→20/100[CRITICAL]Radoslaw Piesiewicz (born February 20, 1981) is a Polish sports administrator who has served as president of the Polish Olympic Committee (PKOl) since 2023. On August 27, 2026, he was detained by Poland's Central Bureau for Combating Cybercrime in connection with a criminal investigation into the collapsed cryptocurrency exchange Zondacrypto. A Polish court subsequently ordered him held for three months pending the investigation; as of the date of this report, formal charges had not been publicly filed and no conviction has been entered.
avoid.net/przemyslaw-kral→4/100[CRITICAL]Przemyslaw Kral is the former CEO of Zondacrypto (formerly BitBay), Poland's largest cryptocurrency exchange, which collapsed in April 2026 amid a criminal fraud investigation. Polish prosecutors charged Kral with alleged participation in large-scale fraud and money laundering in connection with estimated customer losses ranging from approximately 350 million zloty ($97 million) to as much as 2.4 billion zloty ($650 million) according to later prosecutor estimates, affecting approximately 30,000 users. Kral departed Poland for Israel in April 2026 and holds dual Polish-Israeli citizenship; as of September 2026 he has reportedly been cooperating with prosecutors, though his precise location and formal legal status remain subjects of conflicting and unconfirmed reporting.
avoid.net/tectonic-cronos-august-2026-tonic-price-manipulation-exploit→18/100[CRITICAL]On August 30, 2026, an unknown attacker manipulated the price of TONIC — the thinly traded governance token of Tectonic, the dominant lending protocol on the Cronos blockchain — by approximately 100-fold in roughly 20 minutes, then deposited the artificially inflated tokens as collateral and borrowed an estimated $75 million in liquid assets from the protocol's pools. Cronos validators halted all block production network-wide within minutes, freezing approximately $68.7 million on-chain; roughly $6 million had already been bridged to Ethereum before the halt and could not be recovered by rollback. Validators subsequently rolled the chain back to its pre-attack state — discarding approximately 11,000 blocks and reversing nearly two hours of third-party transactions — and resumed block production at block 90,896,189 (23:49:01 UTC, August 30). As of September 1, 2026, no compensation plan, final loss figure, or formal post-mortem had been published by Tectonic or Cronos Labs.
avoid.net/cronos-chain→26/100[WARNING]Cronos is an EVM-compatible blockchain developed by Crypto.com and operated by Cronos Labs, running a capped, invitation-only validator set. On August 30, 2026, validators halted block production and executed a full chain rollback after a price-manipulation exploit drained an estimated $75 million from Tectonic, the chain's dominant lending protocol; the rollback erased approximately two hours of transaction history network-wide and recovered most of the stolen funds on-chain, while roughly $6.29 million that had already been bridged to Ethereum was not recovered. The incident reignited longstanding debates about immutability, validator centralization, and the degree of operational control Crypto.com holds over the network.
avoid.net/the-sandbox-sand-oft-exploit→34/100[WARNING]On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.
avoid.net/the-sandbox-sand-bridge-exploit→38/100[WARNING]On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.
avoid.net/bit-com→62/100[CAUTIONARY]Bit.com was a cryptocurrency derivatives exchange operated by Matrixport, a Singapore-headquartered digital asset financial services firm founded by Bitmain co-founder Jihan Wu. The exchange launched in August 2020 and achieved a top-two global ranking in Bitcoin options volume before conducting an orderly, phased shutdown completed March 31, 2026, citing business restructuring. No fraud allegations, regulatory enforcement actions, or user fund losses have been identified against the exchange itself; the parent company Matrixport rebranded as BIT in March 2026 and continues operating under multiple licensed jurisdictions.
avoid.net/zondacrypto→2/100[CRITICAL]Zondacrypto (operating entity: BB Trade Estonia OÜ), formerly known as BitBay and once Poland's largest cryptocurrency exchange, was declared bankrupt by the Harju County Court in Tallinn on August 27, 2026 after CEO Przemyslaw Kral departed to Israel in April 2026 and an on-chain forensic analysis found the exchange's hot-wallet Bitcoin reserves had fallen by approximately 99.7 percent. Polish prosecutors have opened a criminal fraud investigation, with estimated customer losses of roughly 350 million PLN (approximately $82–97 million) affecting up to 30,000 users who cannot access their funds. The collapse also triggered the arrest of Polish Olympic Committee president Radoslaw Piesiewicz on bribery allegations and the bankruptcy of affiliated fintech Femion Technology.
avoid.net/voltage-finance→15/100[CRITICAL]Voltage Finance (formerly FuseFi) is a decentralized finance protocol operating on the Fuse Network, offering token swapping, lending, liquidity farming, and cross-chain bridging via an automated market maker. The protocol has been the subject of two confirmed security exploits: a March 2022 reentrancy attack that drained approximately $4.67 million from its lending pools via a third-party partner (Ola Finance), and a March 2025 insider-related exploit of its Simple Staking pools resulting in approximately $322,000 in losses. No funds were recovered in either incident as of the time of this investigation.
avoid.net/yearn-dai-vault→62/100[CAUTIONARY]On February 4, 2021, an attacker exploited Yearn Finance's v1 yDAI vault using a multi-protocol flash loan to manipulate exchange rates in Curve Finance's 3pool, causing approximately $11 million in vault losses while the attacker personally profited roughly $2.8 million. Yearn Finance's security team contained the exploit within eleven minutes, preserving $24 million of the vault's $35 million under management. Yearn subsequently reimbursed affected depositors by minting 9.7 million DAI against YFI collateral in a MakerDAO vault, with the intent to repay the debt from ongoing protocol revenue.
avoid.net/cetus-protocol→28/100[WARNING]Cetus Protocol is a concentrated liquidity market maker (CLMM) decentralized exchange deployed on the Sui and Aptos blockchains. On May 22, 2025, the protocol suffered one of the largest DeFi exploits in history when an attacker exploited an integer overflow vulnerability in its smart contract math library to drain approximately $223 million from liquidity pools. Roughly $162 million was frozen on-chain through emergency validator action by the Sui network, and following a governance vote the protocol relaunched in June 2025 with partial user compensation.
avoid.net/blender-io→0/100[CRITICAL]Blender.io was a Bitcoin mixing service that operated from approximately 2018 to 2022, processing over $500 million in Bitcoin before being shut down. On May 6, 2022, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated it as a Specially Designated National, marking the first time a virtual currency mixer had ever been sanctioned by the United States government. The service was designated for its role in laundering over $20.5 million in proceeds from North Korea's Lazarus Group following the $620 million Ronin Network hack, as well as for processing funds tied to Russian ransomware groups and the Hydra darknet market.
avoid.net/coincheck→38/100[WARNING]Coincheck is a Tokyo-based cryptocurrency exchange that suffered what was, at the time, the largest cryptocurrency hack in history on January 26, 2018, when approximately 523 million NEM (XEM) tokens valued at roughly $534 million were stolen from a low-security hot wallet. The exchange was operating without a Financial Services Agency (FSA) license at the time of the breach, had failed to implement standard multisignature security for NEM holdings, and received multiple business improvement orders from Japanese regulators in the aftermath. Coincheck was subsequently acquired by Monex Group in April 2018, obtained its FSA license in January 2019, and listed on the Nasdaq in December 2024 via a SPAC merger under the ticker CNCK.
avoid.net/harvest-finance→22/100[CRITICAL]Harvest Finance is a decentralized yield-aggregation protocol (token: FARM) that suffered a landmark $33.8 million flash loan-based price manipulation attack on October 26, 2020, one of the largest DeFi exploits of that year. Pre-attack, the protocol held over $1 billion in TVL while being governed by a single anonymous admin key—a concentration of power flagged by multiple security auditors and researchers. The protocol continues to operate with substantially reduced TVL (~$12 million as of 2025), though the stolen funds were never recovered and the attacker was never publicly identified or charged.
avoid.net/pickle→10/100[CRITICAL]Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.
avoid.net/compounder-finance→2/100[CRITICAL]Compounder Finance was an Ethereum-based DeFi yield aggregator that launched in November 2020 and executed a deliberate rug pull approximately 22 days later, stealing between $10.8 million and $12.5 million from investors. Anonymous developers embedded hidden 'Evil Strategy' smart contracts behind a publicly visible but unmonitored 24-hour timelock, then drained all user funds and deleted the project's website and social media accounts. No funds were recovered and the perpetrators have never been publicly identified.
avoid.net/yearn-finance→58/100[CAUTIONARY]Yearn Finance is a decentralized yield aggregator on Ethereum that routes user deposits into lending protocols to maximize returns. Founded by Andre Cronje in 2020, the protocol has suffered at least four documented security exploits between 2021 and 2025, with aggregate losses exceeding $20 million, and its founder departed in 2022 citing sustained pressure from an SEC investigation. Governance concerns, an interconnected web of affiliated DeFi protocols implicated in their own major hacks, and repeated failures to deprecate vulnerable legacy code compound the protocol's risk profile.
avoid.net/bitmart→12/100[CRITICAL]BitMart is a centralized cryptocurrency exchange founded in 2017 by Sheldon Xia and headquartered in the Cayman Islands. In December 2021, the exchange suffered one of the largest centralized exchange hacks on record, with approximately $196 million stolen from two hot wallets after a private key was compromised. In July 2026, BitMart announced a full wind-down of operations; the shutdown has since been accompanied by widespread reports of frozen customer withdrawals, the formation of a creditors committee, and an ongoing restructuring process that remains unresolved as of September 2026.
avoid.net/grim-finance→8/100[CRITICAL]Grim Finance was a Fantom-based DeFi yield optimizer (fork of Beefy Finance) that suffered a devastating reentrancy exploit on December 19, 2021, resulting in approximately $30 million in user funds stolen. The vulnerability — a missing reentrancy guard in the depositFor() function — had existed in an audited codebase and was classified by security researchers as an entirely preventable, well-understood attack class. The protocol has since collapsed to a near-zero TVL of roughly $29,000 and its proposed compensation plan yielded no meaningful restitution for affected users.
avoid.net/ola-finance→28/100[WARNING]Ola Finance is a multi-chain decentralized lending protocol offering a 'lending-as-a-service' platform that allows third parties to deploy isolated Compound-style lending pools across multiple blockchains. On March 31, 2022, the protocol's deployment on the Fuse Network was exploited via a reentrancy vulnerability in ERC677 token logic, resulting in approximately $4.67 million in stolen assets. The attacker used Tornado Cash to obscure initial funding, laundered proceeds through Ethereum and BNB Chain wallets, and was never publicly identified; a partial compensation plan was offered but fell materially short of full victim restitution.
avoid.net/mango-markets-v3→10/100[CRITICAL]Mango Markets V3 was a Solana-based decentralized margin trading protocol that suffered a $116 million oracle manipulation attack in October 2022 executed by Avraham Eisenberg, who artificially inflated the MNGO token price to extract funds against fabricated collateral. The protocol subsequently reached a partial recovery settlement, faced SEC and CFTC enforcement actions, and formally wound down operations by January 2025.
avoid.net/jimbos-protocol→18/100[CRITICAL]Jimbos Protocol was an Arbitrum-based DeFi liquidity protocol designed to provide a semi-stable floor price for its native JIMBO token. On May 28, 2023, just three days after launching its V2, the protocol was exploited via a flash loan attack that drained approximately 4,090 ETH (~$7.5 million) by exploiting a lack of slippage control in the JimboController contract. The attacker rejected a $800,000 bounty offer, laundered the full amount through Tornado Cash, and remains unidentified; no funds have been recovered.
avoid.net/cypher→12/100[CRITICAL]Cypher Protocol was a Solana-based cross-margin decentralized exchange (DEX) and perpetuals trading platform that suffered a critical smart contract exploit in August 2023 resulting in approximately $1 million in losses. Following the exploit, an insider contributor known as 'Hoak' systematically drained over $314,000 from the community redemption fund established to reimburse hack victims, admitting publicly to gambling the funds away. The protocol appears effectively defunct, having failed to deliver meaningful restitution to users who received roughly 31 cents on the dollar from the original exploit fund before that fund itself was embezzled.
avoid.net/huobi→28/100[WARNING]Huobi, rebranded to HTX in September 2023, is a major centralized cryptocurrency exchange founded in 2013 that came under the de facto control of Tron founder Justin Sun in late 2022. The exchange has suffered three significant security incidents since September 2023, faces extensive regulatory non-compliance across multiple jurisdictions, and its proof-of-reserves methodology has been subject to credible allegations of double-counting and asset manipulation by investigative outlets.
avoid.net/munchables→10/100[CRITICAL]Munchables is a Blast-chain NFT game that suffered a $62.5 million exploit on March 26, 2024, when a contractor later attributed to North Korea exploited a backdoor they had embedded in the project's upgradeable smart contracts before launch. The developer surrendered private keys and the full sum was recovered within approximately 24 hours, but the incident exposed fundamental failures in contractor due diligence and smart contract architecture.
avoid.net/dmm-bitcoin→52/100[CAUTIONARY]DMM Bitcoin was a licensed Japanese cryptocurrency exchange operated by DMM Group (DMM.com) that launched in January 2018. In May 2024 it suffered the eighth-largest crypto theft in history when North Korean state-sponsored hackers attributed to the TraderTraitor subgroup of Lazarus Group stole 4,502.9 BTC (approximately $305–308 million USD) through a sophisticated supply-chain attack targeting Ginco, a third-party wallet management provider. Following the hack, Japan's Financial Services Agency issued a business improvement order, the exchange restricted operations, and in December 2024 announced full closure with all customer assets transferred to SBI VC Trade by March 2025.
avoid.net/xt-exchange→22/100[CRITICAL]XT Exchange (XT.com), founded in 2018 and registered in Seychelles, is a centralized cryptocurrency exchange that has been flagged by multiple regulatory authorities — including the UK FCA, Dubai VARA, Thailand SEC, and the Seychelles FSA — for operating without proper licensing. The exchange suffered a $1.7 million hot wallet exploit in November 2024 due to a compromised private key, and has accumulated substantial user complaints alleging unjustified account freezing, asset seizure, and blocked withdrawals. Independent analysis has also raised concerns about inflated trading volumes and inadequate proof-of-reserves transparency.
avoid.net/inverse-finance-frontier→10/100[CRITICAL]Inverse Finance Frontier (originally called Anchor) was a variable-rate lending market on Ethereum operated by Inverse Finance DAO, founded by Nour Haridy in 2020. The protocol suffered two separate oracle manipulation exploits in 2022 — one in April resulting in $15.6 million in losses and a second in June resulting in $5.8 million in bad debt — both attributed to vulnerabilities in how Frontier priced collateral assets. The protocol is now deprecated in favor of Inverse Finance's FiRM fixed-rate market, and the DAO continues to work down residual bad debt from both incidents.
avoid.net/mm-finance-cronos→28/100[WARNING]MM Finance (also known as Mad Meerkat Finance) was the largest decentralized exchange on the Cronos blockchain. On May 4, 2022, the protocol suffered a frontend compromise in which an attacker injected a malicious router contract address, redirecting approximately $2 million in user funds to the attacker's wallet over roughly three hours. The stolen funds were laundered via Tornado Cash and routed through OKX; the team pledged reimbursement via trading fee airdrops, though full recovery of stolen assets was not confirmed. The MMF token subsequently lost approximately 99.9% of its value from its April 2022 all-time high.
avoid.net/wintermute→38/100[WARNING]Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.
avoid.net/crema-finance→28/100[WARNING]Crema Finance is a Solana-based concentrated liquidity market maker (CLMM) DEX protocol that launched in January 2022. On July 2, 2022, the protocol suffered a critical exploit in which an attacker used a fake tick account and flash loans to drain approximately $8.78 million from multiple liquidity pools. Following on-chain negotiations, the attacker returned roughly $7.1 million and retained approximately $1.68 million as an agreed white-hat bounty; Crema subsequently issued a CRM token compensation plan for affected users and submitted a revised codebase for re-audit by SlowMist before reopening.
avoid.net/nomad→10/100[CRITICAL]Nomad was a cross-chain messaging bridge operated by Illusory Systems, Inc. that suffered one of the largest DeFi exploits in history on August 1–2, 2022, when a smart contract initialization bug allowed approximately $190 million in user funds to be drained in a chaotic free-for-all involving over 300 wallet addresses. The protocol never recovered meaningful user adoption after a December 2022 relaunch, faced a class action lawsuit and an FTC enforcement action, and in December 2025 agreed to a settlement requiring repayment of $37.5 million to affected users.
avoid.net/slope-wallet→28/100[WARNING]Slope Wallet (Slope Finance) was a Solana-based mobile cryptocurrency wallet that suffered a catastrophic security breach on August 2, 2022, in which over 9,200 wallets were drained of approximately $4–8 million in assets due to the app transmitting users' unencrypted seed phrases to a third-party telemetry service (Sentry). The root cause was a severe security misconfiguration by Slope Finance, in which the mobile application logged plaintext private key material without proper scrubbing. No formal victim compensation was established, the team declined to publicly accept responsibility, and founder Leal Cheung subsequently launched a new project (zkME) without resolution for affected users.
avoid.net/transit-swap→18/100[CRITICAL]Transit Swap is a cross-chain DEX aggregator incubated by TokenPocket, supporting swaps across Ethereum, BNB Chain, Polygon, Tron, Solana, and other networks. On October 1–2, 2022, an attacker exploited an input validation vulnerability in the platform's swap contract, draining approximately $21–28.9 million in user funds across Ethereum and BNB Chain. The attacker subsequently returned roughly 70% of stolen assets after security firms identified the exploiter's IP address and email, though an estimated 30% of funds — including amounts routed through Tornado Cash — remain unrecovered.
avoid.net/templedao→32/100[WARNING]TempleDAO is a DeFi yield protocol launched on Ethereum in August 2021, designed to offer low-volatility, fractionally backed yields on deposited assets. On October 11, 2022, an associated staking product, STAX Finance, suffered a smart contract exploit due to missing access control on the migrateStake() function, resulting in approximately $2.34 million in stolen funds that were subsequently laundered through Tornado Cash. The core TempleDAO vaults were not directly compromised, but the team's anonymous structure and the unrecovered stolen funds remain notable risk factors.
avoid.net/euler-v1→10/100[CRITICAL]Euler Finance V1 was a permissionless DeFi lending protocol on Ethereum that launched in December 2021 and was exploited for approximately $197 million on March 13, 2023, in what was the largest DeFi hack of that year. The attack exploited a missing health check in the donateToReserves function introduced in EIP-14, despite the codebase having undergone multiple external audits. In a highly unusual outcome, the pseudonymous attacker known as 'Jacob' returned all recoverable funds by April 3, 2023, with the total recovered value reaching approximately $240 million due to ETH price appreciation during the recovery period.
avoid.net/kokomo-finance→2/100[CRITICAL]Kokomo Finance was a purported non-custodial lending and borrowing protocol launched on the Optimism blockchain on March 25, 2023. Within approximately 24 hours of launch, its developers executed a deliberate exit scam, stealing approximately $4 to $4.5 million in user funds through smart contract manipulation. The project was subsequently linked by on-chain investigator ZachXBT to a serial scam ring responsible for over $20 million in losses across multiple DeFi protocols.
avoid.net/sushiswap→52/100[CAUTIONARY]SushiSwap is a decentralized exchange (DEX) and DeFi protocol launched in August 2020 as a fork of Uniswap, offering an automated market maker (AMM), governance token (SUSHI), and multi-chain liquidity pools. The protocol has endured a series of serious controversies spanning its entire history: a founding exit-scam attempt by anonymous creator Chef Nomi, early operational control handed to convicted fraudster Sam Bankman-Fried, an SEC subpoena issued to the protocol and its CEO in 2023, a $3.3 million smart contract exploit the same year, allegations that North Korean IT workers were embedded in its developer team, disputed DAO treasury centralization in 2024, and a governance process in late 2025 where a single wallet controlled 99.9% of a vote. TVL has declined approximately 98.7% from its 2022 peak of over $8 billion to roughly $100 million as of late 2025.
avoid.net/bitrue→18/100[CRITICAL]Bitrue is a Singapore-incorporated centralized cryptocurrency exchange founded in 2018 that suffered a confirmed $23 million hot wallet exploit in April 2023, with stolen funds subsequently laundered through Tornado Cash as recently as June 2025. The exchange holds no license from Singapore's Monetary Authority (MAS) and relies on a VASP registration in Lithuania — a lower-tier regulatory framework — while accumulating a persistent record of user complaints alleging unjustified account freezes and asset seizures.
avoid.net/azukidao→28/100[WARNING]AzukiDAO is an informal decentralized autonomous organization formed in late June 2023 by a self-described group of 72 to 74 Azuki NFT holders in response to widespread community outrage over the Azuki Elementals NFT launch. Within days of its formation, AzukiDAO's BEAN governance token airdrop contract was exploited via a signature replay vulnerability, resulting in the theft of approximately 35 ETH ($68,000). On-chain investigator ZachXBT had previously flagged the Azuki project's founder Zagabond (Alex Xu) for alleged involvement in multiple prior abandoned NFT projects, and his findings were central to the community grievances that motivated AzukiDAO's creation.
avoid.net/leetswap→32/100[WARNING]LeetSwap was a decentralized exchange (DEX) launched on Coinbase's Base Layer 2 network in mid-2023 and briefly held the position of the network's largest DEX by trading volume and total value locked. On August 1, 2023, shortly after Base's mainnet opened to all users, an attacker exploited a publicly exposed smart contract function to drain approximately 342 ETH (~$630,000) from multiple liquidity pools. The protocol halted trading, partially recovered funds through white-hat rescue operations, and has since operated at a fraction of its pre-exploit TVL, with no public audit ever confirmed prior to the incident.
avoid.net/stakecom→28/100[WARNING]Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.
avoid.net/gala→28/100[WARNING]Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer and Wright Thurston whose GALA token has been at the center of two major controversies: a 2023 civil lawsuit alleging Thurston stole 8.6 billion GALA tokens (~$130M) from company wallets, and a separate May 2024 smart contract exploit in which an unauthorized minter minted 5 billion tokens worth approximately $200M. Both co-founders have filed competing civil suits alleging misappropriation of hundreds of millions of dollars, while Thurston also faces an unrelated SEC fraud action over a separate crypto mining venture.
avoid.net/okx-nft-aggregator→30/100[WARNING]OKX NFT Aggregator is the NFT marketplace and aggregation layer of OKX, one of the world's largest crypto exchanges, supporting over 21 blockchains and 32 aggregated markets. The product has been implicated in a smart contract storage-collision exploit (June 2024), operates within an exchange that pleaded guilty to U.S. AML violations and agreed to a $504 million DOJ settlement (February 2025), and saw its parent DEX aggregator suspended in March 2025 after North Korea's Lazarus Group used the broader OKX Web3 infrastructure to launder approximately $100 million from the Bybit hack. ZachXBT has flagged the entity in the context of these broader OKX platform concerns.
avoid.net/deltaprime→22/100[CRITICAL]DeltaPrime is a decentralized leveraged farming and lending protocol deployed on Arbitrum and Avalanche. The protocol suffered two major security exploits in 2024 — a $5.98 million private key compromise in September and a $4.8 million smart contract vulnerability in November — totaling over $10.7 million in losses. On-chain investigator ZachXBT alleged that DeltaPrime had previously employed North Korean IT workers with alleged ties to the DPRK-linked Lazarus Group, raising concerns about insider access as a contributing factor to the first exploit.
avoid.net/polynetwork→10/100[CRITICAL]Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered two major security breaches: a $610 million exploit in August 2021 (the largest DeFi hack at the time, with funds ultimately returned) and a second exploit in July 2023 in which attackers minted billions in notional value of tokens, extracting an estimated $10–20 million in real assets. The protocol permanently terminated all services on September 30, 2024.
avoid.net/bingx→32/100[WARNING]BingX is a Singapore-headquartered centralized cryptocurrency exchange founded in 2018 (originally as Bingbon), operating across 160+ countries with over 10 million reported users. In September 2024, the exchange suffered a confirmed hot wallet breach totaling approximately $52 million across at least seven blockchain networks, with on-chain forensics subsequently linking the attack to North Korea's Lazarus Group. The exchange pledged full user compensation from reserves and resumed withdrawals within days, but independently unverified regulatory claims and initial opacity around the breach raise ongoing due-diligence concerns.
avoid.net/kiloex→38/100[WARNING]KiloEx is a decentralized perpetual futures exchange (DEX) backed by YZi Labs (formerly Binance Labs), deployed across opBNB, Base, BNB Chain, Taiko, and other networks. In April 2025, the platform suffered a $7.5–8.44 million oracle price manipulation exploit caused by an access control vulnerability in its TrustedForwarder contract; the attacker subsequently returned all stolen funds within 3.5 days after accepting a $750,000 white-hat bounty. The platform relaunched on April 24, 2025 after a partial security audit, with a full comprehensive audit still pending at that time.
avoid.net/cetus-clmm→18/100[CRITICAL]Cetus Protocol is a concentrated liquidity market maker (CLMM) and the dominant decentralized exchange on the Sui Network, launched in 2023. On May 22, 2025, an arithmetic overflow vulnerability in its fixed-point math library enabled an attacker to drain approximately $223 million from liquidity pools in the largest DeFi exploit of 2025, of which roughly $162 million was subsequently frozen by Sui validators and later returned to affected users via an on-chain governance vote. The incident raised significant concerns about smart contract security, audit effectiveness, and the degree of decentralization on the Sui network.
avoid.net/cozy-v2→42/100[WARNING]Cozy V2 is a DeFi protection marketplace deployed on Optimism that allows users to buy or provide protection against smart contract hacks, depegs, and other on-chain risks. On August 29, 2025, the protocol suffered a $427,000 exploit caused by a missing caller verification check in its withdrawal logic, with funds subsequently bridged to Ethereum mainnet and deposited into Tornado Cash. The incident is notable for its irony: a protocol designed to insure against DeFi hacks was itself hacked through a preventable authorization flaw.
avoid.net/shibarium→28/100[WARNING]Shibarium is a layer-2 blockchain built on Ethereum, launched in August 2023 as the scaling solution for the Shiba Inu (SHIB) ecosystem. The network has faced a series of significant incidents including a failed initial launch that trapped $1.7 million in bridged funds, a September 2025 flash loan exploit that drained approximately $4.1 million from its cross-chain bridge via validator key compromise, persistent rug pull activity on its DeFi layer, allegations of code plagiarism, and ongoing transparency concerns stemming from fully pseudonymous leadership. Shibarium initiated a novel NFT-based restitution program following the 2025 exploit but as of early 2026 the recovery path remained unresolved.
avoid.net/yearn-ether→58/100[CAUTIONARY]Yearn Ether (yETH) is a liquid staking token aggregation vault developed by Yearn Finance, launched under YIP-72 as a self-governed, permissionless product. On November 30, 2025, the yETH weighted stableswap pool was exploited via an arithmetic underflow and stale cache vulnerability, resulting in approximately $9 million in losses — the third major security incident involving a Yearn product since 2021. Approximately $2.4 million was partially recovered; roughly $6.6 million remains unrecovered, with a significant portion laundered through Tornado Cash.
avoid.net/credix→4/100[CRITICAL]CrediX Finance was a DeFi lending protocol launched in July 2025 on the Sonic blockchain that suffered a $4.5 million exploit on August 4, 2025, less than one month after launch. The exploit involved a compromised or insider-controlled admin wallet that minted unbacked synthetic tokens to drain liquidity pools; the team subsequently vanished, deleted all official channels, and failed to honor public recovery promises, prompting widespread allegations of a premeditated exit scam. Note: CrediX Finance (Sonic, 2025) is a distinct entity from Credix Finance (Solana, founded 2021), which is a separate legitimate RWA protocol.
avoid.net/matcha→62/100[CAUTIONARY]Matcha (matcha.xyz) is a DEX aggregator built and operated by 0x Labs, launched in 2020, that routes trades across 130+ liquidity sources on 15+ blockchains using the 0x Protocol. The core Matcha platform has no history of direct exploits; however, Matcha Meta — a related but distinct meta-aggregator product launched later by the same team — suffered a $13.4M exploit in January 2026 via a third-party SwapNet contract, affecting users who had disabled the platform's default one-time approval security setting. 0x Labs is a well-funded, established entity whose protocol contracts have been audited by Trail of Bits, OpenZeppelin, and Ouroboros, and whose bug bounty program offers up to $1M via Immunefi.
avoid.net/curve-llamalend→52/100[CAUTIONARY]Curve LlamaLend (also referred to as the crvUSD lending markets) is a decentralized, permissionless isolated lending protocol built by Curve Finance that allows users to borrow crvUSD against crypto collateral using the LLAMMA soft-liquidation mechanism. The protocol has experienced multiple distinct incidents since launch: a $10 million bad-debt event in June 2024 tied to the founder's oversized leveraged positions, an oracle-manipulation attack on the sDOLA market in March 2026 resulting in approximately $240,000 in borrower losses, an October 2025 market crash that left the CRV-long vault approximately $700,000 underbacked, and a May 2026 third-party exploit (Stake DAO) that forced the sunsetting of an associated Arbitrum LlamaLend market. The protocol's core contracts have not been directly compromised by a code-level hack, but recurring bad-debt events, oracle design flaws in permissionlessly created markets, and governance concentration risks have drawn sustained scrutiny including a flag from on-chain investigator ZachXBT.
avoid.net/kelp→18/100[CRITICAL]Kelp (also known as Kelp DAO) is a liquid restaking protocol built on Ethereum and EigenLayer that issues rsETH, a liquid restaked token. In April 2026 the protocol suffered the largest DeFi exploit of 2026 to date when attackers, attributed to North Korea's Lazarus Group, drained approximately $292 million in rsETH through a compromised LayerZero cross-chain bridge configuration. The protocol and an industry coalition dubbed DeFi United are actively working to restore collateral and resume operations as of May 2026.
avoid.net/upbit→58/100[CAUTIONARY]Upbit is South Korea's largest cryptocurrency exchange by trading volume, operated by Dunamu and commanding approximately 70–80% of the domestic market. The exchange has suffered two significant security breaches — a $49M ETH theft in 2019 and a $36M Solana breach in November 2025, both attributed to North Korea's Lazarus Group — and has faced substantial regulatory sanctions including a $25M AML/KYC fine and a court-contested three-month partial business suspension. While Upbit has consistently reimbursed users from its own assets after security incidents and retains official VASP registration, its pattern of compliance failures, market dominance concerns, and repeated hacks present elevated risk.
avoid.net/aave-v3→58/100[CAUTIONARY]Aave V3 is the third major iteration of the Aave decentralized lending protocol, one of the largest in DeFi with over $14 billion in total value locked across 21 chains as of May 2026. The protocol's core smart contracts have not been directly exploited; however, in April 2026, a $292 million bridge exploit targeting integrated asset KelpDAO's rsETH generated significant bad debt on Aave V3 markets, an event flagged by on-chain investigator ZachXBT. The protocol demonstrated institutional resilience by coordinating a cross-industry recovery fund (DeFi United) that ultimately raised over $327 million, with full rsETH operations restored by May 25, 2026.
avoid.net/giddy→25/100[CRITICAL]Giddy (also branded DefiQ, Inc.) was a Draper, Utah-based self-custody DeFi wallet and yield-farming platform that launched its GDDY token on the Polygon network in April 2022. The project raised over $15 million from VC investors including Pelion Venture Partners, but has since shut down — leaving the GIDDY token trading more than 99% below its all-time high of approximately $0.35 in May 2022. ZachXBT has flagged the entity as a concern in the crypto trust-intelligence space, and community reviews allege that team members sold tokens prior to the app's public launch and that advertised staking yields were never delivered.
avoid.net/flow→54/100[CAUTIONARY]Flow is a layer-1 proof-of-stake blockchain created by Dapper Labs, the company behind NBA Top Shot and CryptoKitties, with FLOW as its native token. The project has faced a serious 2025 protocol-level exploit ($3.9M stolen), a controversial rollback proposal that drew community backlash, multiple rounds of company layoffs, a $4M securities class-action settlement, a separate $7.05M privacy lawsuit settlement, SEC investigation, and delisting from major South Korean exchanges following the breach. The FLOW token has lost over 99% of value from its April 2021 all-time high of $46.16, trading near $0.033 as of mid-2026.
avoid.net/asymmetric-research→77/100[VERIFIED]Asymmetric Research is a specialized blockchain security firm founded by Jonathan Claudius (formerly CSO at Jump Crypto) and Felix Wilhelm (formerly at Google Project Zero and Jump Crypto), with a team of 45+ researchers across North America, Europe, and Asia. The firm focuses on embedded, long-term security partnerships with L1/L2 blockchains and DeFi protocols, and has disclosed multiple high-severity vulnerabilities across Cosmos, Solana, Ethereum, and Circle infrastructure. No regulatory actions, fraud allegations, or client harm incidents have been identified in available sources.
avoid.net/maya-protocol-august-2026-six-bug-exploit→22/100[CRITICAL]On August 18, 2026, an attacker exploited MAYAChain—the decentralized cross-chain liquidity network operated by Maya Protocol—by chaining six distinct software bugs in a single 23-message transaction. The exploit allowed the attacker to inflate a liquidity pool by approximately 49.45 million CACAO tokens, gain near-total control of that pool, and extract roughly $1.65–1.7 million in Bitcoin and other assets. CACAO's price fell approximately 89% and total network pool value dropped by an estimated $11 million, prompting an emergency network halt. As of late August 2026, the attacker's Bitcoin wallet remained unspent and no patch timeline or LP compensation framework had been publicly confirmed.
avoid.net/term-finance→22/100[CRITICAL]Term Finance is an Ethereum-based DeFi fixed-rate lending protocol developed by Term Labs, Inc., which raised $8 million in funding from investors including Electric Capital and Maelstrom. On August 23, 2026, an attacker bootstrapped with 2 ETH sourced from Tornado Cash, acquired majority voting control of the protocol's sparsely held DAO governance token at a cost of approximately $951, and passed malicious proposals to drain an estimated $8.5 million (2,843 ETH and 1.68 million USDC) from Term's Meta Vaults. In response, Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles; as of the time of writing, no recovery of stolen funds has been confirmed and no concrete user compensation plan has been announced.
avoid.net/maya-protocol→28/100[WARNING]Maya Protocol (MAYAChain) is a decentralized cross-chain liquidity network and friendly fork of THORChain that launched its mainnet in April 2023. On August 18, 2026, an attacker chained six software vulnerabilities in a single 23-message transaction to fabricate approximately 49.45 million CACAO tokens, drain roughly $1.36 million in Bitcoin and other assets off-chain, and trigger an 88.7% collapse in CACAO's price. The team halted the network globally in response; as of late August 2026, the attacker had not returned funds, no formal post-mortem had been published by the team, and no swap-resumption timeline had been announced.
avoid.net/the-sandbox-sand→30/100[WARNING]The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.
avoid.net/term-labs→17/100[CRITICAL]Term Labs is the company behind Term Finance, an Ethereum-based fixed-rate DeFi lending protocol that uses an on-chain double-auction mechanism to match borrowers and lenders. The protocol, backed by $8 million in venture funding from Electric Capital, Coinbase Ventures, and Maelstrom, suffered two significant loss events: a $1.6 million oracle misconfiguration in April 2025 (partially recovered) and a governance manipulation attack on August 23, 2026 that drained approximately $8.5 million from its strategy vaults. The 2026 attack represents an active, unresolved incident with no published post-mortem or reimbursement plan at time of writing.
avoid.net/maya-protocol-mayachain→12/100[CRITICAL]Maya Protocol is a permissionless, decentralized cross-chain liquidity network built on MAYAChain, a THORChain fork that launched mainnet in April 2023. On August 18, 2026, the protocol suffered its first documented loss-of-funds incident: an attacker chained six software vulnerabilities in a single 23-message transaction to extract approximately $1.36 million in hard assets (including 20.83 BTC) and trigger a broader pool-value impact estimated at $11 million, while CACAO crashed 89%. MAYAChain halted all operations on August 18, 2026, and has not resumed as of August 23, 2026; no funds have been returned.
avoid.net/roman-storm→22/100[CRITICAL]Roman Storm is a Russian-born, naturalized U.S. citizen and co-founder of Tornado Cash, an Ethereum-based cryptocurrency mixing protocol sanctioned by OFAC in August 2022. He was arrested in August 2023 and indicted in the Southern District of New York on three counts: conspiracy to commit money laundering, conspiracy to operate an unlicensed money transmitting business, and conspiracy to violate U.S. sanctions (IEEPA). A jury convicted him in August 2025 on the unlicensed money transmitting count while deadlocking on the two more serious charges, and prosecutors have filed to retry him on the deadlocked counts in October 2026.
avoid.net/gala-games→42/100[WARNING]Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer (co-founder of Zynga) and Wright Thurston, issuing the GALA utility and governance token. The company has been beset by a high-profile inter-founder legal dispute alleging $130 million in token theft, a May 2024 smart contract exploit in which 5 billion GALA tokens worth approximately $200–240 million were minted by a compromised admin wallet, and co-founder Wright Thurston's prior SEC lawsuit over an unrelated $18 million unregistered securities offering. These compounding governance failures, security incidents, and legal controversies place the platform among the more heavily scrutinized projects in the blockchain gaming sector.
avoid.net/poly-network→10/100[CRITICAL]Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered the largest DeFi hack in history in August 2021 (~$611M stolen, nearly all returned), followed by a second exploit in July 2023 (~$10M realized losses) attributed to compromised multisig private keys. The protocol permanently shut down all services on September 30, 2024.
avoid.net/pnetwork→12/100[CRITICAL]pNetwork is a cross-chain bridge and interoperability protocol built on the pTokens architecture, enabling assets to move between Bitcoin, Ethereum, BNB Chain, and other networks via wrapped synthetic tokens. The protocol has suffered two major security incidents — a September 2021 pBTC-on-BSC hack losing approximately $12 million, and a November 2022 pGALA incident that triggered a $28 million lawsuit by Gala Games and Huobi alleging pNetwork's own engineers caused the vulnerability through a leaked private key, then allegedly profited from a self-described 'white hat' rescue. As of 2025, the PNT governance token trades at a fraction of its 2021 peak and the protocol operates with negligible market capitalization and trading volume.
avoid.net/sudorare→2/100[CRITICAL]SudoRare was an anonymous NFT automated market maker (AMM) protocol launched on August 23, 2022, presented as a fork of SudoSwap and LooksRare. Approximately six hours after launch, the anonymous development team executed a premeditated rugpull via a backdoored smart contract, draining approximately 519 ETH (valued at $815,000–$852,000) from user deposits before deleting all online presence. Blockchain security firms PeckShield and CertiK traced a funding wallet to Kraken, but no public arrests or legal proceedings have been reported.
avoid.net/defrost→18/100[CRITICAL]Defrost Finance was an Avalanche-based CDP (Collateralized Debt Position) DeFi protocol that allowed users to collateralize yield-bearing tokens to mint an H2O USD-pegged stablecoin. In December 2022 the protocol suffered a two-stage exploit resulting in approximately $12 million in losses; multiple blockchain security firms — including CertiK, PeckShield, and De.Fi Security — alleged the attack constituted an insider rug pull enabled by admin key access, a conclusion the team denied. Funds were subsequently returned and a refund contract was deployed in January 2023, but the protocol has since effectively ceased meaningful operations with under $100,000 in TVL, and the MELT governance token has lost nearly all of its value.
avoid.net/bald→4/100[CRITICAL]BALD was a memecoin launched on Coinbase's Base Layer 2 network on July 29, 2023, allegedly named as a reference to Coinbase CEO Brian Armstrong's appearance. After attracting over $66 million in ETH to its liquidity pool through aggressive liquidity additions and a price surge of approximately 4,000,000% within 24 hours, the anonymous deployer removed approximately $25.6 million in liquidity on July 31, 2023, causing the token price to collapse by roughly 90%. On-chain investigators linked the deployer's wallet to addresses with documented interactions with Alameda Research, with Wintermute's head of research publicly identifying former Alameda co-CEO Sam Trabucco as the most likely suspect — though no conclusive proof of identity was ever established.
avoid.net/mixin-network→10/100[CRITICAL]Mixin Network is a Hong Kong-based layer-2 cross-chain payment protocol that suffered the largest single crypto hack of 2023 when attackers compromised its cloud service provider's database and drained approximately $200 million in ETH, BTC, and USDT. The network remains operational but has only partially compensated users, the majority of stolen funds remain unrecovered, and a dormant attacker wallet moved funds to Tornado Cash in February 2026.
avoid.net/unibot→48/100[WARNING]Unibot is a Telegram-based cryptocurrency trading bot launched in May 2023 that enables users to trade on Uniswap and other decentralized exchanges directly within Telegram. On October 31, 2023, Unibot suffered a smart contract router exploit in which approximately $560,000–$640,000 in user tokens were stolen by an external attacker; the team subsequently reimbursed affected users. The platform operates with an anonymous founding team and involves inherent custodial risks because the bot manages user wallet interactions.
avoid.net/gondi-v3→52/100[CAUTIONARY]Gondi V3 is a decentralized, non-custodial NFT lending and borrowing protocol on Ethereum developed by Florida Street, which launched in July 2023 and raised a $5.35 million seed round from Hack.vc, Dragonfly Capital, and Pantera Capital. On March 9, 2026, the protocol suffered a smart contract exploit in its newly deployed Purchase Bundler component, resulting in the theft of approximately 78 NFTs valued at roughly $230,000 from users who had granted approvals to the vulnerable contract. The team disabled the affected feature, pledged full restitution using protocol fees, and engaged security firm Blockaid for a post-incident review; platform operations for other functions resumed the following day.
avoid.net/madeira-invest-club-cryptospain-alvaro-romillo→2/100[CRITICAL]Madeira Invest Club (MIC) was a Spain-based 'private investment club' founded around 2023 by Álvaro Romillo, an online crypto/tax-advice influencer known as "CryptoSpain" or "Luis." Spanish authorities allege MIC operated as a Ponzi scheme that defrauded thousands of investors of roughly €185–260 million by promising fixed ~20% annual returns on nonexistent investments in luxury goods, real estate, watches, whisky, and cryptocurrency. Romillo was arrested in November 2025, denied bail, and formally indicted in December 2025 alongside nine others on charges of mass fraud and criminal organization membership; the case is one of Spain's largest crypto-linked fraud prosecutions to date and remains pending trial.
avoid.net/osmosis-allbtc-nomic-bridge-double-spend-exploit-september-2026→38/100[WARNING]On September 9, 2026, the Cosmos-based DEX Osmosis froze minting, redemption, deposits, and withdrawals for its alloyed Bitcoin token (allBTC) after discovering that a double-spend flaw in the Nomic chain's custom BTC-forwarding mechanism had allowed an attacker to mint 40.650602 nBTC on Osmosis with no corresponding Bitcoin backing, compromising approximately 36% of allBTC's reserves. On-chain researcher Rarma traced the principal exploit activity to June 25, 2026, meaning the vulnerability went undetected for roughly 74 days before public disclosure. An emergency chain upgrade locked 22.65 BTC in the attacker-controlled address; a governance proposal to seize those funds and draw on the Osmosis community pool to cover the remaining ~17.19 BTC shortfall was launched on September 10, 2026, but had not been voted on as of the date of this report.
avoid.net/osmosis-allbtc-nomic-bridge-double-spend→38/100[WARNING]In September 2026, Osmosis, a Cosmos-based decentralized exchange, froze minting, redemption, deposits and withdrawals of its alloyed Bitcoin token (allBTC) after discovering that a double-spend flaw in the Nomic chain's Bitcoin-forwarding mechanism had allowed an attacker to mint tens of millions of dollars in unbacked nBTC months earlier. On-chain analysis traced the exploit's origin to June 25, 2026, with the shortfall (roughly 36% of allBTC's backing) only disclosed publicly on September 9-10, 2026 — a disclosure gap of about 74 days during which allBTC continued trading and was represented as fully Bitcoin-backed. Osmosis says its own chain and the IBC protocol were not directly compromised and has proposed a governance-driven remediation using seized attacker funds and community-pool Bitcoin, but as of this writing the fix remains a pending proposal rather than a completed restoration.
avoid.net/madeira-invest-club→2/100[CRITICAL]Madeira Invest Club (MIC) was a Spanish-language online investment platform that operated from early 2023 until its abrupt closure in September 2024. Its founder, Alvaro Romillo Castillo, known publicly as 'CryptoSpain' or 'Luis,' was arrested in November 2025 under Operation PONEI, coordinated by Spain's Guardia Civil and Europol, on charges of mass fraud, criminal organization, and money laundering. As of mid-2026, Romillo remains in provisional prison, has been formally charged alongside nine co-defendants by a judge of the Audiencia Nacional, and the case is in pre-trial proceedings; no verdict has been issued.
avoid.net/baton-corporation-pump-fun→18/100[CRITICAL]Baton Corporation Ltd is the company behind Pump.fun, a Solana-based memecoin launchpad launched on January 19, 2024, by co-founders Noah Tweedale (CEO), Alon Cohen, and Dylan Kerler. The platform generated over $850 million in cumulative fee revenue and facilitated more than 7 million token launches. As of August 31, 2026, a federal judge in the Southern District of New York allowed RICO wire fraud and unlicensed money transmission claims to proceed against Baton Corporation and all three named founders in Aguilar v. Baton Corporation Ltd., Case No. 1:25-cv-00880-CM, while dismissing securities claims and clearing Solana Labs entirely. The platform has also received a formal unauthorized-business warning from the UK Financial Conduct Authority and had its iOS app removed from the U.S. and India App Stores in September 2026.
avoid.net/baton-corporation-pump-fun-parent→12/100[CRITICAL]Baton Corporation Ltd. is the corporate parent of Pump.fun, a Solana-based memecoin launchpad founded in January 2024 by Noah Tweedale, Alon Cohen, and Dylan Kerler. The platform has generated hundreds of millions of dollars in transaction fees while independent research has repeatedly found that the overwhelming majority of tokens launched on it end in total loss for buyers. Baton Corporation and its three named founders are current RICO defendants in a federal class action in the Southern District of New York, where a judge allowed wire fraud, illegal gambling, and unlicensed money-transmission racketeering claims to survive a motion to dismiss on August 31, 2026, while dismissing related securities and unjust-enrichment claims and dropping Solana Labs and the Solana Foundation from the case entirely.
avoid.net/argent-capital-management-trevor-vernon→3/100[CRITICAL]The U.S. Commodity Futures Trading Commission (CFTC) filed a federal fraud complaint on July 7, 2026 against Trevor L. Vernon and his North Carolina-based firm Argent Capital Management, LLC (ACM), alleging they fraudulently solicited over $14 million from at least 60 participants between March 2022 and February 2026 for an unregistered commodity pool, Argent Capital Partners, LP. The CFTC alleges Vernon hid catastrophic trading losses of more than $8.6 million behind fabricated performance statements, misappropriated over $3 million in Ponzi-style payments to existing participants, spent $136,000 of investor funds on private air travel, and gave false sworn testimony to CFTC investigators. As of this writing the case is a pending civil enforcement action with no reported judgment or settlement.
avoid.net/argent-capital-management-llc-trevor-l-vernon→2/100[CRITICAL]Argent Capital Management LLC is a Delaware-registered commodity pool operator based in Franklin, North Carolina, founded and solely owned by Trevor L. Vernon. On July 7, 2026, the U.S. Commodity Futures Trading Commission filed a civil complaint in the U.S. District Court for the Western District of North Carolina (Case No. 1:26-cv-197), alleging that from March 2022 through February 2026 Vernon and Argent Capital Management fraudulently solicited more than $14 million from at least 60 participants, concealed consistent trading losses behind fabricated account statements, misappropriated approximately $3 million in Ponzi-style payments to earlier investors, and spent $136,000 of investor funds on private air travel. These are allegations in a civil complaint; no criminal charges have been filed and no court adjudication has been reached as of the date of this report.
avoid.net/coinkite→15/100[CRITICAL]Coinkite Inc. is a small, privately held Toronto-based Bitcoin hardware company that manufactures the Coldcard wallet. A firmware defect introduced into Coldcard seed generation in March 2021 went undetected for roughly five years — including, per public claims from the developer who flagged it, a specific warning to Coinkite in May 2025 that was dismissed — until attackers began draining wallets on July 30, 2026, ultimately taking an estimated 1,816 BTC (roughly $116–155 million) from more than 5,200 victims. Coinkite has publicly apologized and shipped fixed firmware, but now faces credible, still-unfiled class-action and product-liability litigation threats from law firms in Canada and the UK, alongside separate allegations — unconfirmed by the company — that its own CTO authored the flawed code.
avoid.net/coinkite-coldcard→13/100[CRITICAL]Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.
avoid.net/gooddollar→42/100[WARNING]GoodDollar is a universal basic income (UBI) crypto protocol founded by Yoni Assia (co-founder and CEO of eToro) that has distributed approximately 2.3 billion G$ tokens to over 963,000 claimants across 222+ countries. In early September 2026, a malicious 'Super App' exploited a Superfluid vulnerability specific to its Celo deployment to bypass whitelisting and liquidation safeguards, allowing excess G$ balances to drain approximately $107,000 from GoodDollar's Celo and XDC reserves, with additional undisclosed losses from external liquidity pools. Reserve and bridging operations remain paused as of mid-September 2026 while both GoodDollar and Superfluid prepare separate incident reports.
avoid.net/gooddollar-superfluid-celo-reserve-exploit→28/100[WARNING]GoodDollar, a universal-basic-income protocol that has distributed roughly 2.3 billion G$ tokens to over 963,000 claimants, disclosed on September 9, 2026 that its Celo and XDC reserves were drained after an attacker exploited a bug in Superfluid's Celo deployment. The attacker allegedly used a malicious 'Super App' to bypass Superfluid's whitelisting and liquidation safeguards, keeping insolvent G$ balances active and exchanging the excess tokens for at least $100,000 in real reserve assets. This is the second major reserve-draining incident in GoodDollar's history, following a December 2023 exploit that saw roughly 14 billion G$ minted illicitly, and as of mid-September 2026 both GoodDollar and Superfluid have yet to publish full incident reports.
avoid.net/bunni-protocol→28/100[WARNING]Bunni Protocol is a Uniswap liquidity-incentive layer developed by Timeless Finance that evolved from a Uniswap v3 LP-token wrapper (v1) to a full DEX built on Uniswap v4 hooks (v2). On September 2, 2025, Bunni v2 suffered an $8.4 million flash-loan exploit caused by a rounding-direction vulnerability in its withdrawal mechanism — a class of issue that multiple auditors had flagged in advance. The team announced permanent shutdown in October 2025, citing the inability to fund the six-to-seven-figure re-audit required for a secure relaunch.
avoid.net/zaid-issam-ahmed-al-jebouri→0/100[CRITICAL]Zaid Issam Ahmed al-Jebouri is an Iraqi national, born October 3, 1988, who was designated a Specially Designated Global Terrorist by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on July 23, 2026. He was sanctioned for his role as a shareholder in El-Kahira for General Trading, a Turkey-registered over-the-counter (OTC) cryptocurrency exchange that OFAC determined had transferred hundreds of thousands of dollars for Hamas and provided underground banking services to organized criminal networks. Seven TRON blockchain addresses attributed to al-Jebouri were added to the Specially Designated Nationals (SDN) list; those wallets had collectively received approximately $38.6 million in digital assets.
avoid.net/anwen-technology-co-ltd-xinbipay-newpay→2/100[CRITICAL]Anwen Technology Co., Ltd. is a Cambodia-based software developer that built XinbiPay, also marketed as NewPay, a cryptocurrency payment and digital wallet application. The U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Anwen Technology on September 9, 2026 for materially supporting Xinbi Guarantee, a Chinese-language online marketplace that U.S. authorities allege facilitated more than $24 billion in illicit digital-asset and fiat transactions tied to pig-butchering scams, romance scams, and other cyber-fraud operations across Southeast Asia. The designation blocks all U.S. property interests of Anwen Technology and generally prohibits U.S. persons from transacting with it.
avoid.net/safew-technology-co-ltd-safew-messaging-app→2/100[CRITICAL]SafeW Technology Co., Ltd. is the developer of SafeW, an end-to-end encrypted messaging application that the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated on September 9, 2026, for materially supporting Xinbi Guarantee, a Chinese-language online marketplace OFAC designated the same day as a significant transnational criminal organization. According to OFAC, Xinbi Guarantee — alleged to have processed more than $24 billion in digital and fiat currency since roughly 2022 in support of Southeast Asian scam centers and money-laundering networks — began migrating its merchant and vendor coordination onto SafeW around June 2025 as law enforcement scrutiny of its prior channels increased. Singapore's police force has publicly disputed OFAC's characterization of SafeW Technology as a Singapore-incorporated entity, stating it has found no evidence to substantiate that claim.
avoid.net/seoul-northern-coin-fraud-ring-91-3-billion-won-scheme→2/100[CRITICAL]A South Korean fraud ring led by two individuals identified in press reports only as Lee (64) and Kim (53) allegedly issued and sold roughly 26-30 worthless cryptocurrencies to victims recruited from stock-investment loss chat rooms between May 2022 and March 2023, taking in an estimated 91.3 billion won (approximately $63 million). On August 19, 2026, the Seoul Northern District Court convicted eight defendants, sentencing the two ringleaders to 14 years in prison each and co-defendants to terms ranging from one year (suspended) to eight years. This is a criminal case with a court verdict already rendered, not merely an allegation; it is being tracked because the underlying tokens, sales operation, and any affiliated apps or exchanges may still pose risk to the public.
avoid.net/jonbur-kim-park-coin-king→3/100[CRITICAL]Park, a South Korean crypto figure known by the aliases "Jonbur Kim" and "HODL Kim" and nicknamed the "Coin King," faces prosecution in South Korea over an alleged multi-token pump-and-dump and market-manipulation scheme spanning the POD (Podo Coin), Grape Coin, and ATT (Artube) tokens, with prosecutors alleging combined investor losses around 340 billion won (roughly $245 million). He was indicted for the Podo Coin scheme in 2023, attempted to flee South Korea by fishing boat in December 2023, was granted bail in January 2024, and was re-arrested in February 2025 on separate Artube-related fraud charges. As of September 2026 prosecutors have requested a 20-year sentence against him, with a court verdict scheduled for October 15, 2026; a separate but thematically similar Seoul coin-fraud ring not shown to include Park was sentenced to up to 14 years in September 2026.
avoid.net/orionx-chile-exchange-shutdown→4/100[CRITICAL]Orionx, a Chilean cryptocurrency exchange founded in 2017 and backed by a June 2025 Tether-led Series A investment, began a permanent shutdown on September 3, 2026 after a forensic audit found that more than $7 million in customer-custodied assets had been moved to wallets outside the company's control. Chile's Financial Market Commission (CMF) had rejected Orionx's application for authorization under the country's Fintech Law in June 2026, and Orionx subsequently filed criminal complaints against two former executives, alleging misappropriation of customer assets over a multi-year period from 2018 to 2021. More than 100,000 registered users are reported to be affected, with recovery of funds uncertain.
avoid.net/bitmex-closure-september-2026→28/100[WARNING]BitMEX, the crypto derivatives exchange that pioneered the perpetual swap contract, announced on July 23, 2026 that it would permanently cease operations on September 23, 2026 at 04:00 UTC, after an 11-year run. The closure follows a failed two-year sale process and is accompanied by a time-sensitive user harm vector: any verified user who fails to withdraw funds before the cutoff faces an indefinite monthly custody fee, and a proposed class-action lawsuit filed on the day of the announcement alleges that the exchange's liquidation mechanism improperly diverted customer collateral into its insurance fund throughout the platform's history.
avoid.net/ernest-ossei-boateng-intercontinental-wealth-network-llc-i-wealth-network-lp→2/100[CRITICAL]Ernest Ossei Boateng is a New Jersey-based individual who, according to a civil complaint filed by the SEC on September 10, 2026, allegedly operated an approximately $16 million Ponzi-like scheme through two companies he controlled — Intercontinental Wealth Network LLC and I Wealth Network LP — targeting primarily Christians of Ghanaian heritage in New York and New Jersey from at least January 2020 through at least March 2026. The SEC alleges more than 200 largely inexperienced investors were harmed, including retirees, clergy members, a widowed mother, taxi drivers, and home health care workers. The case, SEC v. Boateng et al., No. 1:26-cv-05605 (E.D.N.Y.), is a civil enforcement action; no criminal charges have been publicly reported as of the date of this report, and no court findings have been issued.
avoid.net/bb-trade-estonia-o→2/100[CRITICAL]BB Trade Estonia OÜ was the Estonian-registered operating company behind Zondacrypto, formerly Poland's largest cryptocurrency exchange. The company froze customer withdrawals in April 2026, had its virtual currency service license revoked by Estonia's Financial Intelligence Unit on June 29, 2026, and was declared bankrupt by the Harju County Court in Tallinn on August 27, 2026. Polish prosecutors allege fraud affecting up to 30,000 customers with estimated losses of approximately 350 million zloty (roughly $96 million), and at least five individuals have been charged in connection with the investigation as of September 2026.
avoid.net/christopher-alexander-delgado→2/100[CRITICAL]Christopher Alexander Delgado is the founder and former CEO of Goliath Ventures (formerly Gen-Z Venture Firm), an Orlando, Florida-based cryptocurrency investment firm. He was arrested in February 2026 on federal charges of wire fraud and money laundering, and pleaded guilty on June 30, 2026, to conspiracy to commit wire fraud, wire fraud, and money laundering, admitting to causing at least $250 million in investor losses. Prosecutors allege Goliath raised at least $328 million — and as much as $425 million by SEC estimates — from over 1,300 investors through a Ponzi scheme that promised guaranteed monthly returns of 3–8% from cryptocurrency liquidity pools, while placing only approximately $1.5 million in any actual crypto platform.
avoid.net/bb-trade-estonia-zondacrypto-operator→3/100[CRITICAL]BB Trade Estonia OÜ was the Estonian-registered operating entity behind Zondacrypto (formerly Zonda/BitBay), once Poland's largest cryptocurrency exchange with over a million users. The company froze customer withdrawals in April 2026, had its Estonian operating license revoked, and was declared bankrupt by a Tallinn court on August 27, 2026, with liabilities reported to exceed €431 million against roughly €167,000 in assets. Independent on-chain forensics identified hundreds of transfers worth over $21 million routed to a single Kraken deposit address in the months before the collapse, and both the exchange's founder and its later public-facing CEO have gone missing or fled abroad amid a Polish criminal fraud investigation with multiple suspects detained.
avoid.net/orionx→8/100[CRITICAL]Orionx was a Chilean cryptocurrency exchange founded in 2017 that operated in Chile, Peru, Colombia, and Mexico and received a Series A investment led by Tether in June 2025. On September 3, 2026, the exchange began a permanent shutdown after an internal audit revealed a custody shortfall exceeding $7 million in customer assets, and the company filed criminal complaints against two of its co-founders alleging misappropriation of those assets between 2018 and 2021. More than 100,000 registered users face uncertainty over whether they will recover their funds, as Chile's financial regulator has declined to oversee the restitution process.
avoid.net/monsoon-blockchain-corporation→4/100[CRITICAL]Monsoon Blockchain Corporation is a Palo Alto, California-based blockchain company founded and led by Dr. Donald G. Basile, also the founder of the Bitcoin Latinum (LTNM) token. On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil complaint in the Eastern District of New York naming Monsoon Blockchain Corporation as a co-defendant alongside Basile and GIBF GP, Inc., alleging the three parties collectively raised approximately $16 million from hundreds of investors through the fraudulent sale of Simple Agreements for Future Tokens (SAFTs) predicated on false claims of insurance coverage and asset backing. The allegations have not been adjudicated; all charges remain accusations at the civil complaint stage.
avoid.net/donald-basile→4/100[CRITICAL]Donald G. Basile is a Silicon Valley technology executive and the founder and CEO of Bitcoin Latinum (LTNM) and its developer entity Monsoon Blockchain Corporation. In April 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and two entities he controls, alleging he raised approximately $16 million from hundreds of investors through materially false representations about insurance coverage, asset backing, and fund usage. All allegations in the SEC complaint remain untested in court; no ruling or adjudication has been entered as of the date of this report.
avoid.net/edward-zimbardi→2/100[CRITICAL]Edward Zimbardi is a Flowery Branch, Georgia individual who allegedly operated "The Crypto Program," a cryptocurrency-based Ponzi scheme that raised more than $165 million from thousands of investors worldwide between June 2022 and August 2023 by promising a fixed 25% monthly return on "digital advertising packages." He is the subject of a federal criminal indictment (wire fraud, money laundering, and money laundering conspiracy), prior state securities enforcement actions in California and Georgia, and at least one civil lawsuit from an alleged victim. He fled to Fiji in 2025 and was deported to the United States in August 2026 to face prosecution.
avoid.net/ernest-ossei-boateng-intercontinental-wealth-network-i-wealth-network→2/100[CRITICAL]The U.S. Securities and Exchange Commission filed a civil fraud complaint on September 10, 2026 against Ernest Ossei Boateng and his New Jersey-based companies, Intercontinental Wealth Network LLC and I Wealth Network LP, alleging an approximately $16 million Ponzi scheme that ran from at least January 2020 through March 2026. The complaint alleges Boateng, who was not registered with any securities regulator and had twice failed licensing exams, used his standing in the Ghanaian Christian community in New York and New Jersey to solicit over 200 largely inexperienced investors — including retirees, taxi drivers, home health aides, an ailing widow, and at least two churches and a prayer group — with promises of guaranteed, low-risk returns. The case is a civil SEC enforcement action; the allegations are unproven and no criminal charges or final judgment have been reported.
avoid.net/orionx-chile-exchange-shutdown-2026→4/100[CRITICAL]Orionx, a Tether-backed Chilean cryptocurrency exchange founded in 2017, began a permanent shutdown on September 3, 2026 after a forensic audit found more than $7 million in customer assets had been moved to wallets outside the company's custody, affecting over 100,000 registered users across Chile, Peru, Colombia, and Mexico. Chile's financial regulator (CMF) had rejected Orionx's registration application in June 2026 and says it never supervised the exchange, and Orionx has filed criminal complaints against two former co-founders, Roberto Zibert and Joaquín Díaz, alleging multi-year misappropriation of customer funds; both men deny wrongdoing.
avoid.net/coldcard-firmware-exploit-2026→10/100[CRITICAL]Beginning July 30, 2026, attackers exploited a five-year-old build-flag error in Coinkite's Coldcard hardware wallet firmware (versions 4.0.1–4.1.9) that caused seed generation to use a weak software pseudorandom number generator (PRNG) instead of the device's hardware entropy source, reducing effective key strength to as low as 40 bits. Multiple attack waves across four days drained approximately 1,789–1,816 BTC (roughly $114–116 million) from more than 5,200 Bitcoin addresses, making it the largest hardware wallet exploit in recorded history. As of September 2026, approximately 82% of stolen funds remain in attacker-controlled wallets with limited laundering activity; no formal criminal charges or regulatory actions had been announced, and class-action litigation against Coinkite was threatened but not yet formally filed.
avoid.net/ankr-ankrflow-collateral-exploit→38/100[WARNING]Ankr is a multi-chain Web3 infrastructure and liquid staking protocol that has experienced two significant security incidents: a December 2022 insider-enabled infinite-mint exploit of its aBNBc token on BNB Chain (approximately $5 million drained directly, with a secondary $15 million oracle attack on Helio Protocol), and an August 2026 ankrFLOW contract vulnerability that enabled an attacker to mint approximately 8.6 million unbacked ankrFLOW tokens and drain roughly $410,000 in WFLOW (corrected from an initially reported $9.3 million) from the More Markets lending protocol on Flow EVM. In both incidents Ankr's own smart contracts were identified as the vulnerable component, though in the 2026 incident no depositors ultimately lost funds and Flow Foundation committed to replacing the drained reserves.
avoid.net/notional-finance-v1-legacy-escrow→8/100[CRITICAL]Notional Finance is an Ethereum-based fixed-rate lending protocol. On September 4, 2026, the protocol's undecommissioned V1 legacy escrow contract was drained of approximately $1.73 million in stablecoins via an integer-overflow exploit in the free-collateral valuation logic. The stolen funds were converted to approximately 689 ETH and laundered through Tornado Cash. No official post-mortem or recovery plan had been published by the Notional Finance team at the time reporting was conducted.
avoid.net/fx-winning→3/100[CRITICAL]FX Winning (operating as FxWinning Ltd. / FXWinning Limited, via fxwinning.net) was an online forex and cryptocurrency investment brokerage founded around 2020 by Rafael Brito Cutie and David Merino (Quintana), promising customers high monthly returns of 8-15% or more from an 'exclusive' algorithmic trading strategy. The company restricted customer withdrawals beginning in February 2023 and ceased operations entirely in June 2023, after which it was sued by multiple investors alleging fraud. A Miami-Dade County civil court entered default judgments against FxWinning Ltd. and its CEO in 2024, and a final judgment of more than $85 million was entered against two of its principals in March 2025. The entity was never authorized by any recognized financial regulator and displays multiple hallmarks associated with Ponzi-type investment fraud.
ZachXBT Intelligence · Backfilled
3Lazarus Group is a cyber threat actor that the U.S. Department of Justice, FBI, Treasury/OFAC, and the United Nations Panel of Experts have attributed to North Korea's Reconnaissance General Bureau (RGB), a military intelligence agency of the Democratic People's Republic of Korea (DPRK). U.S. and allied government agencies allege the group and its sub-units (tracked in industry reporting as APT38, BlueNoroff, TraderTraitor, and Stardust Chollima) have conducted destructive cyberattacks and large-scale cryptocurrency thefts since at least 2009, including what blockchain-analytics firm Chainalysis describes as a cumulative total exceeding $6 billion in stolen crypto assets, funds the UN Panel of Experts and U.S. officials allege support North Korea's weapons programs. This entry documents named individuals, government indictments, sanctions, and specific hacking incidents, distinguishing DOJ/FBI/OFAC/UN attributions from private-sector research findings.
avoid.net/tornado-cash→28/100[WARNING]Tornado Cash is an open-source, non-custodial cryptocurrency mixing protocol on Ethereum, launched in 2019, that obscures the on-chain link between deposit and withdrawal addresses. The U.S. Treasury sanctioned the protocol in August 2022 over its alleged use by the North Korea-linked Lazarus Group and other illicit actors to launder billions of dollars; those sanctions were struck down by the Fifth Circuit in November 2024 and formally lifted by OFAC in March 2025. Separately, co-founder Alexey Pertsev was convicted of money laundering in the Netherlands in 2024 (appeal pending), and co-founder Roman Storm was convicted in August 2025 of one count of conspiring to operate an unlicensed money-transmitting business while a New York jury deadlocked on more serious money-laundering and sanctions-violation charges that remain unresolved pending post-trial motions and a possible retrial.
avoid.net/compound-finance→55/100[CAUTIONARY]Compound Finance is one of the earliest and most established decentralized lending protocols on Ethereum, launched in 2018 and governed since 2020 by a DAO around the COMP token. The protocol's smart-contract core has never suffered a direct exploit of user funds, but it has been repeatedly hit by operational and front-end security failures — a costly 2021 token-distribution bug, a 2023 X/Twitter account compromise used for phishing, a 2024 DNS hijack of its website, and a 2024 governance controversy in which a whale-backed group used purchased voting power to pass a treasury allocation over community objections. Combined with declining total value locked and a 2023 leadership departure, these incidents warrant continued scrutiny even though the underlying lending contracts have a long audit history and no reported loss of user deposits from a core-protocol hack.