Skip to main content
AVOID.NET

Avoid your next
big mistake

Crowdsourced due diligence for crypto

Evidence-backed risk intelligence powered by the swarm
Collective intelligence with AI analysis

Scan a walletBrowse investigationsSubmit evidenceHow it works

Featured Investigations

197·
sort:
avoid.net/zksnarks-zcash-nft-project14/100[CRITICAL]

zkSNARKs is an anonymously-run, 10,000-piece Zcash-based PFP NFT collection ('shielded identities') sold via a blind auction on the Zilkroad marketplace that closed September 17, 2026, netting the team an estimated $17-17.5 million. On-chain investigator ZachXBT publicly accused the project of extracting these funds while delivering none of its promised governance framework, community tooling, or ecosystem partnerships, and of retaining a 10% free team allocation plus 5% secondary royalties against roughly $2,000 in minting costs. Separately, NFT-community figure Leonidas (LeonidasNFT) alleged, without independent verification, that the same team was previously behind Ordinals-related projects characterized as exit scams. The story broke September 19, 2026 and remains a fast-developing, largely unverified allegation from named individuals rather than a regulatory or judicial finding; Zcash's shielded-transaction design also makes independent on-chain verification of fund flows unusually difficult.

avoid.net/zksnarks-nft-zcash22/100[CRITICAL]

zkSNARKs is a 10,000-piece profile-picture NFT collection launched on the Zcash blockchain in September 2026. The project raised approximately $17 million through a blind auction of 8,000 units at a clearing price of 1.5 ZEC each. On September 19, 2026, on-chain investigator ZachXBT publicly accused the anonymous project team of extracting funds while delivering no governance infrastructure, community tools, or ecosystem integrations as promised, characterizing the launch as an eight-figure money grab comparable to prior Ordinals exit schemes.

avoid.net/manic-android-banking-trojan-crypto-wallet-targeting-malware1/100[CRITICAL]

Manic is an active Android malware family, publicly disclosed by the Dutch mobile-threat intelligence firm ThreatFabric on August 20, 2026 and separately covered by Kaspersky, that combines banking-trojan credential theft with spyware and full device-takeover capabilities. It monitors 169 Android app package IDs — including banks, payment apps, cryptocurrency wallets and exchanges, government eID services, authenticator apps, messengers, browsers and email clients — and is notable for an invisible-overlay keystroke capture technique paired with Accessibility-service replay, plus a novel offline Wi-Fi/Bluetooth mesh exfiltration mechanism that relays stolen data through other nearby infected phones even when the source device has no internet access. Manic is not a company or product to be trusted but an active criminal threat; it is indexed here as a risk entity so that crypto holders on Android can recognize and avoid it.

avoid.net/fake-gta-6-crypto-wallet-drainer-sites2/100[CRITICAL]

Security researchers at Malwarebytes identified phishing websites posing as GTA 6 fan countdown pages and "leaked copy" sale sites that deploy wallet-draining code against visitors who connect a crypto wallet to pay. The infrastructure includes a Solana-specific drainer and a separate script targeting seven EVM-compatible chains, with evidence pointing to a rented drainer-as-a-service backend and geofencing of CIS-country visitors. This is a confirmed active phishing/scam operation, not a legitimate entity, and it warrants the lowest possible trust rating.

avoid.net/ray-youssef-doj-indictment-20268/100[CRITICAL]

Ray Youssef, co-founder and former CEO of the peer-to-peer crypto marketplace Paxful and founder of NoOnes, was federally indicted in early 2026 by the U.S. Attorney's Office for the Eastern District of California on charges alleging conspiracy to violate Bank Secrecy Act anti-money-laundering requirements, operating an unlicensed money transmitting business, and facilitating illegal prostitution-related transactions tied to the Backpage.com advertising site. The indictment followed Paxful Holdings Inc.'s own guilty plea and $4 million criminal penalty in the same court, and a 2024 guilty plea by Paxful co-founder Artur Schaback. Youssef denies the charges and is fighting them; as of this writing no conviction has occurred and the case is pending, so allegations against him remain unproven.

avoid.net/splash-optim-finance-oada-cardano-stableswap-exploit22/100[CRITICAL]

On September 13, 2026, an attacker exploited a validator flaw in Splash Protocol's ADA/OADA StableSwap pool on Cardano, draining approximately 2,434,648 ADA and 1,988,222 OADA in two transactions. Splash subsequently patched the underlying vulnerability, but roughly 2.42 million ADA remains unrecovered and OADA holders are unable to redeem their positions as of mid-September 2026, with Optim Finance still auditing impacted addresses and no confirmed remediation path announced.

avoid.net/manic-android-banking-trojan0/100[CRITICAL]

Manic is an active Android malware family first identified by ThreatFabric and Kaspersky in 2026, combining banking-trojan credential theft, spyware, and remote device takeover. It targets 169 Android application package IDs including cryptocurrency wallets, exchanges, banks, authenticators, and government eID services, and employs a novel offline Wi-Fi mesh relay to exfiltrate stolen data through chains of nearby infected devices even without direct internet access. Primary targeting is concentrated on Ukraine, with secondary reach across Russia, Europe, and global fintech and cryptocurrency platforms.

avoid.net/abracadabra-money28/100[WARNING]

Abracadabra Money is a multi-chain DeFi lending protocol founded in 2021 that allows users to mint Magic Internet Money (MIM), a USD-pegged stablecoin, using interest-bearing tokens as collateral. The protocol has suffered four significant security incidents between 2022 and 2025, losing over $21 million in aggregate, and its MIM stablecoin has lost its dollar peg on multiple occasions. The protocol is also linked to the Wonderland/Sifu scandal of early 2022, which caused severe reputational and financial contagion across its interconnected 'Frog Nation' ecosystem.

avoid.net/fake-crypto-aml-checker-drainer-campaign1/100[CRITICAL]

A coordinated campaign of fraudulent websites impersonating cryptocurrency AML (anti-money-laundering) compliance-check services — most prominently the legitimate provider AMLBot, alongside generic "AML Check" branding — has been documented by cybersecurity firm Malwarebytes and corroborated by multiple crypto and security news outlets since August 2026. The sites lure users into connecting wallets under the pretext of a compliance scan and then induce them to approve malicious transactions or token permissions that drain their assets. This is an assessment of the scam campaign and its known malicious infrastructure, not of AMLBot itself, which appears to be an impersonated victim brand rather than a perpetrator.

avoid.net/19-extension-chrome-edge-wallet-drainer-batch-september-20263/100[CRITICAL]

In late August 2026, security researchers at Socket published research identifying 19 Chrome and Edge browser extensions sharing a common modular malware framework, tracked internally as "Superior," that could drain multi-chain cryptocurrency wallets, steal hardware-wallet seed phrases, and hijack exchange sessions. Fourteen of the extensions were allegedly created directly by the threat actor as clean, functional tools that later received malicious updates, while five — including the QuickLens extension previously flagged in a separate March 2026 incident — were allegedly acquired from legitimate developers before being weaponized. The campaign's infrastructure and code allegedly trace back to at least February 2024, making it a longer-running and broader operation than the single-extension QuickLens incident that first drew public attention.

avoid.net/quicklens-chrome-extension-supply-chain-attack2/100[CRITICAL]

QuickLens ("Search Screen with Google Lens"), a Chrome extension with roughly 7,000 users, was allegedly acquired via an ownership transfer on February 1, 2026 and subsequently weaponized in a malicious update (version 5.8) released February 17, 2026. Security researchers documented crypto-wallet-draining code, ClickFix-style social-engineering malware delivery, and theft of Gmail, Facebook Business Manager, and YouTube data before Google removed the extension from the Chrome Web Store. A later report (August 2026) ties QuickLens to a broader 19-extension campaign of purchased-and-weaponized browser add-ons.

avoid.net/miloud-abderrahmane-isis-crypto-facilitator1/100[CRITICAL]

Miloud Abderrahmane is a French national designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on June 22, 2026, for allegedly conducting cryptocurrency transactions on behalf of ISIS-affiliated individuals in Syria and for allegedly providing instructional and manufacturing information on explosives to ISIS supporters. Two TRON blockchain addresses linked to him were added to the Specially Designated Nationals (SDN) list, and blockchain analytics firms have reported on-chain activity connecting the wallets to alleged ISIS-linked donation campaigns. He was designated as part of a broader OFAC action against three individuals and six entities accused of routing crypto and fiat funds to ISIS across Europe, the Middle East, and West Africa.

avoid.net/router-protocol10/100[CRITICAL]

Router Protocol, a Coinbase Ventures-backed cross-chain bridge infrastructure project launched in 2020, announced on September 5, 2026 that it will cease all operations by September 30, 2026 and permanently burn 303,333,198 ROUTE tokens (roughly 30% of maximum supply) after failing to find a buyer, licensing partner, or sustainable business model. The shutdown announcement disclosed, for the first time in prominent fashion, two 2025 security incidents affecting the protocol's bridge infrastructure — a February 2025 exploit the team says was 80% recovered through negotiation, and a July 2025 exploit whose losses the team says were never recovered. ROUTE's token price fell roughly 50% on the news to a new all-time low near $0.00004, and withdrawal guidance for holders and bridge users has been fragmented across individual exchanges rather than centrally coordinated.

avoid.net/isis-k-crypto-wallet-network-tron-monero-sdn-designations2/100[CRITICAL]

On July 1, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) updated its Specially Designated Nationals (SDN) list entry for ISIS-Khorasan (ISIS-K) to add 134 cryptocurrency wallet addresses — 131 on TRON and 3 on Monero — used to solicit and move donations for the group's propaganda arm. Stablecoin issuer Tether froze the balances on all 131 TRON addresses within the sanctions window, while the three Monero addresses remain functionally beyond the reach of issuer-level freezing due to that network's privacy design. The action followed a June 22, 2026 OFAC designation of individuals and money-service businesses across Europe, the Middle East, and West Africa accused of facilitating ISIS financial transfers.

avoid.net/tartswap-tart-solana-mint-6mxygsp9qdjieqgcuhjbsru6vu1ymtyndwntsx6uwbtv7/100[CRITICAL]

A Solana SPL token trading under the name and ticker "TartSwap" (TART) at mint address 6MXygsP9QDJiEqGCuHjbsru6vU1YmtynDWnTsx6uWbTv shows on-chain hallmarks of a high-risk, illiquid meme-token launch: on-chain analytics show effectively zero real liquidity ($0–$0.03) despite a multi-million-dollar reported valuation and trading volume, alongside flagged insider wallet clusters. The name and branding duplicate an unrelated, separately-documented "TartSwap" project that describes itself as a BNB Chain-only decentralized exchange and explicitly warns that no TART contract address other than its own BNB Chain address should be trusted. No independent news coverage, audit, or regulatory record specific to this Solana token was found; findings below rely primarily on on-chain analytics tools and the rival project's own materials.

avoid.net/iran-irgc-crypto-exchange-network-ofac-sectoral-sanctions2/100[CRITICAL]

Between June and September 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated a network of Iranian and Iran-linked cryptocurrency exchanges — including Nobitex, Wallex, Bitpin, Ramzinex, Shelbit Exchange, Aban Tether, and BitBank — for allegedly laundering funds on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and helping the Iranian regime evade sanctions. On August 24, 2026, as part of a campaign named 'Operation Economic Outcast,' OFAC issued a first-of-its-kind sectoral determination under Executive Order 13902 naming digital assets a sanctionable sector of Iran's economy, extending secondary-sanctions risk to any foreign person or entity operating in or supporting that sector, not just entities with direct terrorism links. Treasury and blockchain-analytics research describe IRGC-associated wallets as having received billions of dollars in cryptocurrency in 2025 alone.

avoid.net/bitpapa-exchange6/100[CRITICAL]

Bitpapa (legally Bitpapa IC FZC LLC, also doing business as Baba House LLC and Papa Holding Ltd) is a UAE-registered peer-to-peer cryptocurrency exchange serving primarily Russian, Ukrainian, Belarusian, and other CIS-region users. It has been designated under sanctions programs in four separate jurisdictions — the United States (OFAC, March 2024), Ukraine (July 2025), the United Kingdom (May 2026), and the European Union (2026, effective August 2026) — each alleging that Bitpapa facilitated Russian sanctions evasion, including transactions with darknet markets and sanctioned banks and exchanges. The platform also independently lists the rouble-pegged A7A5 stablecoin, which researchers have linked to a sanctions-evasion network tied to a sanctioned political figure and a state-owned Russian bank.

avoid.net/exmo-exchange-uk-russia-sanctions-shutdown4/100[CRITICAL]

EXMO Exchange Limited, a cryptocurrency exchange founded in 2014 that built a large user base among Russian-, Ukrainian-, and Kazakh-speaking traders, was designated by the UK Foreign, Commonwealth and Development Office (FCDO) on 26 May 2026 under the Russia sanctions regime, as part of an 18-entity action targeting alleged crypto and banking infrastructure supporting Russia's war economy. Following the designation, EXMO confirmed on 14 July 2026 that group entities had become "effectively paralyzed," halted new registrations and deposits, and began an orderly wind-down in which 29.4% of every client balance — reflecting both a long-standing shortfall from a December 2020 hot-wallet hack and newly frozen custodian assets — was converted into a non-tradable, non-withdrawable IOU token called USDRecover. EXMO disputes the sanctions designation but says it is cooperating with UK authorities while managing the closure.

avoid.net/exmo-exchange-limited6/100[CRITICAL]

EXMO Exchange Limited, a UK-registered cryptocurrency exchange founded in 2014 and popular among Russian-, Ukrainian-, and Kazakh-speaking traders, was designated under the UK Russia (Sanctions) (EU Exit) Regulations 2019 on May 26, 2026, for allegedly supporting Russia's financial sector. The designation triggered an orderly wind-down announced in July 2026. Users face a 29.4% shortfall on their balances — attributed by the exchange to a combination of unrecovered funds from a December 2020 hot-wallet hack and sanctions-related custodian freezes — replaced by a non-tradable, non-withdrawable IOU instrument called USDRecover (USDRec). The EU followed with its own designation on August 23, 2026. EXMO disputes the sanctions but states it is cooperating with authorities.

avoid.net/southeast-asian-pig-butchering-scam-centers-doj-strike-force-20261/100[CRITICAL]

This entry covers a network of cryptocurrency investment-fraud operations — commonly called 'pig butchering' scams — run from guarded compounds in Myanmar (Burma), Cambodia, and Laos, and the U.S. Department of Justice's interagency Scam Center Strike Force formed in November 2025 to dismantle them. Named operating entities such as Ko Thet Company, Sanduo Group, Giant Company, and the much larger Prince Group have been criminally indicted or charged by U.S. prosecutors, and hundreds of millions of dollars in cryptocurrency tied to these operations have been restrained. U.S. and UN investigators allege the compounds rely heavily on trafficked and coerced labor, and independent researchers report that scam operators are increasingly using AI-generated personas, deepfakes, and voice cloning to run schemes at greater scale.

avoid.net/oramama-token-oramama-pump-and-dump4/100[CRITICAL]

ORAMAMA ($ORAMAMA) is a Solana meme coin alleged by blockchain investigator ZachXBT to have been the target of a coordinated pump-and-dump scheme executed on February 22, 2026, via a network of purchased X (formerly Twitter) accounts that had spent weeks manufacturing fake U.S.-Iran war panic content to build audiences. According to ZachXBT's investigation, reported by multiple crypto-news outlets in late March 2026, on-chain analysis indicated the operation generated six-figure profits before the accounts abandoned the token entirely. No independently verifiable on-chain contract/mint address for the token could be located in public reporting.

avoid.net/oramama-token-oramama3/100[CRITICAL]

$ORAMAMA is a Solana-based meme token that served as the vehicle for a coordinated pump-and-dump scheme identified by on-chain investigator ZachXBT. On February 22, 2026, ten accounts within a larger 16-account network on X simultaneously promoted the token after building audiences through AI-assisted fabrication of US-Iran war panic content, then abandoned all mention of it once operators had exited their positions for six-figure profits. X suspended all 16 identified accounts following ZachXBT's public disclosure on March 23, 2026.

avoid.net/a7a5-russian-ruble-stablecoin3/100[CRITICAL]

A7A5 is a ruble-pegged stablecoin launched in January 2025 by Kyrgyzstan-registered issuer Old Vector on behalf of A7 LLC, a cross-border payments firm co-owned by sanctioned Moldovan fugitive Ilan Shor and Russian state-owned defense-sector bank Promsvyazbank (PSB). US, UK and EU authorities have sanctioned A7A5, its issuer, and its principal trading venues (Grinex, formerly Garantex), alleging the token was designed to help Russian individuals, businesses and the state evade Western financial restrictions and, per UK officials, to help fund Russia's war effort. The scout's claim that A7A5 launched in "February 2026" is not supported by any source found and appears to be incorrect; multiple Tier 1/Tier 2 sources place the launch in January 2025.

avoid.net/coldcard-wallet-coinkite-firmware-exploit28/100[WARNING]

Coldcard is a Bitcoin hardware wallet manufactured by Canadian company Coinkite. Beginning July 30, 2026, attackers exploited a five-year-old firmware bug that caused seed generation to use a weak software pseudorandom number generator instead of the device hardware entropy source, reducing effective key strength to as low as 40 bits on older models. Galaxy Research estimated total losses of approximately 1,816 to 2,417 BTC (roughly $116–$151 million USD) across more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026. Coinkite published a security advisory and patched firmware but has not announced any compensation program for affected users.

avoid.net/haruko42/100[WARNING]

Haruko is a London-based institutional digital asset infrastructure provider founded in 2021, serving over 80 clients globally across 100+ centralized venues, 30 blockchains, and 250 on-chain protocols. In September 2026, the company confirmed a targeted cyberattack affecting 15 institutional clients, in which attackers exploited a server-side process vulnerability to extract access tokens and gain read-only API access to client data; a small but confirmed amount of client funds was stolen. Haruko stated it patched the vulnerability, rotated server-side secrets, and committed to publishing a technical post-mortem.

avoid.net/revolut-data-breach-fake-government-request-september-202630/100[WARNING]

On September 12, 2026, Revolut confirmed that an unauthorized third party had obtained sensitive data belonging to approximately 680 customers by submitting fraudulent information requests from a compromised email account operating inside Italy's Ministry of the Interior domain (pec.interno.it), which passed SPF, DKIM, and DMARC authentication checks. The exposed data reportedly included passport copies, identity verification selfies, IBANs, account statements, and full Bitcoin transaction histories. Revolut stated that its own systems and customer funds were not compromised, characterizing the incident as a social engineering attack against its data-request verification procedures rather than an intrusion.

avoid.net/htx-fca-uk-enforcement-illegal-crypto-promotions-202610/100[CRITICAL]

The UK Financial Conduct Authority commenced High Court proceedings on 21 October 2025 against Huobi Global S.A. (the Panamanian entity behind the HTX exchange, formerly Huobi) and multiple categories of 'persons unknown', alleging repeated breach of Section 21 of the Financial Services and Markets Act 2000 by promoting cryptoasset services to UK consumers without authorisation. This is the FCA's first enforcement action against an offshore crypto exchange for illegal financial promotions. As of August 2026, proceedings are stayed while settlement talks continue; no court ruling on the merits has been issued.

avoid.net/huobi-htx7/100[CRITICAL]

HTX (formerly Huobi), one of the world's largest cryptocurrency exchanges, was designated by the UK government on May 26, 2026 under the Russia (Sanctions) (EU Exit) Regulations 2019, marking the first time the UK applied banking-style Regulation 17A correspondent-banking sanctions to a crypto exchange of this scale. The UK's Foreign, Commonwealth and Development Office alleged that the Panama-registered operating entity, Huobi Global S.A., channeled approximately USD 1.5 billion to Russia-linked entities — including the A7 payments network and previously sanctioned exchange Garantex — allegedly aiding the evasion of international trade blockades tied to Russia's invasion of Ukraine. HTX disputed the allegations, asserting that Huobi Global S.A. is legally distinct from the online exchange platform, while on-chain analytics firms published data flagging up to USD 7.6 billion in total Russia-linked flows through HTX since 2021.

avoid.net/solana-summit-toronto82/100[VERIFIED]

Solana Summit Canada is a two-day blockchain conference scheduled for September 23–24, 2026 at St. Lawrence Market North in Toronto, Ontario. The event is organized by Superteam Canada, a Solana Foundation-supported regional community chapter, and is listed as an official event on solana.com/events. No fraud indicators, fake ticket schemes, or scam activity have been identified in connection with this event.

avoid.net/hemi-genesis-drop-merklebox-exploit38/100[WARNING]

Hemi is a modular Layer-2 blockchain protocol designed to bridge Bitcoin and Ethereum into a single supernetwork, co-founded by former Bitcoin core developer Jeff Garzik and Max Sanchez. On September 7, 2026, an attacker exploited a reentrancy vulnerability in the MerkleBox smart contract used for Hemi's Genesis Drop token distribution, draining approximately 124.5 million unclaimed HEMI tokens, which were liquidated for roughly $255,000 in stablecoins. The exploit was isolated to the Genesis Drop claim contract; the core Hemi network, HEMI and veHEMI tokens, and bridge infrastructure were not affected.

avoid.net/bitbank-iranian-crypto-exchange2/100[CRITICAL]

BitBank, also known as BitBank3 and operating at bitbank3.com, is an Iranian digital asset exchange designated by the U.S. Treasury's Office of Foreign Assets Control (OFAC) on September 17, 2026. According to OFAC, the exchange is a priority digital asset venture controlled by sanctioned Iranian financier Babak Zanjani, and was used between June and July 2026 to transfer hundreds of millions of dollars in Bitcoin to the Islamic Revolutionary Guard Corps (IRGC). The designation is part of Operation Economic Outcast, a broader U.S. government campaign to sever financial channels used by the Iranian regime.

avoid.net/trezor-email-provider-breach-brevo-september-202622/100[CRITICAL]

On September 9, 2026, attackers exploited a SAML SSO misconfiguration at Brevo, Trezor's third-party email marketing provider, to access 138 Brevo customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. The messages falsely claimed a critical STM32 microcontroller entropy vulnerability required users to re-enter their seed phrases; approximately 2,500 users clicked the malicious link before Trezor disabled the phishing domain within 20 minutes. No cryptocurrency losses have been confirmed as of mid-September 2026, but the incident forms part of a pattern of third-party supply-chain attacks targeting Trezor users across multiple vendor relationships.

avoid.net/claude-ai-crypto-arbitrage-bot-youtube-tutorial-scam0/100[CRITICAL]

A coordinated scam operation, active between at least February and August 2026, distributed nine near-identical YouTube tutorials purporting to teach viewers how to deploy a "Claude-built" AI crypto arbitrage bot. According to TRM Labs, the deployed smart contracts contained no trading logic whatsoever and simply forwarded any funds sent to them to operator-controlled addresses; 224 victims lost 274.60 ETH (approximately $517,205 USD) across six shared collection addresses. SentinelOne independently documented the same pattern of Ethereum drainers masquerading as AI trading bots on YouTube, tracing an overlapping campaign that collected over $900,000 USD from a single operator address.

avoid.net/ai-dating-scam-network-dora-doni-romi-cluster0/100[CRITICAL]

A China-based app studio, tracked by Anthropic as GTG-15001, operated a network of more than 20 fraudulent dating applications that allegedly used Anthropic's Claude AI to power thousands of undisclosed fake personas. During a two-week period in April 2026, the operation engaged at least 25,000 users — primarily men in the United States — through approximately 4,700 AI-generated profiles that sent roughly 2.36 million messages while users paid real money via in-app coin purchases to continue conversations. Anthropic published findings in September 2026, banned associated accounts, and reported the operator to Apple and Google; most named apps were removed by early September 2026, though Kira reportedly remained on Google Play as of September 16, 2026.

avoid.net/input-output-group-iog-youtube-channel-hijack-deepfake-hoskinson-giveaway-scam5/100[CRITICAL]

On September 18, 2026, unknown attackers hijacked the official YouTube channel of Input Output Group (IOG), the core development company behind the Cardano blockchain, and broadcast an approximately two-hour fraudulent livestream. The broadcast used suspected AI-generated video of IOG founder Charles Hoskinson to impersonate a Project Catalyst town hall and solicit cryptocurrency from viewers via QR code, promising to double any ADA sent. IOG and Hoskinson publicly warned users not to engage with channel content, and IOG confirmed it was working with YouTube to recover the account. This incident was not an attack on the Cardano blockchain or user wallets; it was a social-media account compromise targeting IOG's YouTube presence.

avoid.net/7zarc4/100[CRITICAL]

7zarc is a pseudonymous individual whose wallet cluster was publicly identified by on-chain investigator ZachXBT in September 2026 as allegedly having received 4,870 ETH (approximately $15 million) traceable to the Raidparty project's alleged $70 million exit scam. The wallets went dormant in 2022 and reactivated in September 2026, with the ETH subsequently moved to deposit addresses across multiple centralized exchanges. No charges have been filed and no court or regulatory finding has been made; the allegations originate from ZachXBT's on-chain analysis published on X.

avoid.net/raidparty4/100[CRITICAL]

Raidparty was an Ethereum-based play-to-earn idle MMO game launched in approximately 2021, featuring NFT heroes and fighters and a native token called Confetti (CFTI). On-chain investigator ZachXBT alleged in September 2026 that approximately $70 million was misappropriated in an exit scam, and identified a dormant wallet cluster linked to the pseudonym 7zarc moving 4,870 ETH (approximately $15 million) of alleged exit-scam proceeds to centralized exchange deposit addresses after roughly four years of inactivity. No arrests, regulatory actions, or court filings have been publicly identified as of the investigation date; the allegations originate from ZachXBT's on-chain analysis and have not been adjudicated.

avoid.net/layerzero-labs32/100[WARNING]

LayerZero Labs is the Vancouver-based company that develops and maintains the LayerZero cross-chain messaging protocol and the ZRO governance token. The company became the subject of significant controversy following the April 2026 $292 million KelpDAO bridge exploit, in which LayerZero's own infrastructure was compromised and its personnel had previously approved the single-verifier configuration that enabled the attack. LayerZero Labs formally admitted in May 2026 that it 'made a mistake,' after weeks of publicly attributing blame to KelpDAO — a reversal that triggered a broader ecosystem migration estimated at approximately $15 billion in assets moving to competing bridge infrastructure.

avoid.net/ismael-sanchez-cryptofx3/100[CRITICAL]

Ismael Sanchez (also identified in SEC filings as Ismael Zarco Sanchez) was a lead salesperson who ran the Chicago office of CryptoFX LLC, a Houston-based operation that the SEC alleges was in reality a $300 million Ponzi scheme defrauding roughly 40,000 predominantly Latino investors between 2020 and 2022. On February 12, 2026, a federal jury in the Southern District of Texas found Sanchez liable for securities fraud and broker/securities-registration violations. The underlying CryptoFX scheme, run principally by Mauricio Chavez and Giorgio Benvenuto, was halted by an SEC emergency action in September 2022, and Sanchez was among 17 additional individuals charged by the SEC in March 2024.

avoid.net/cryptofx-llc2/100[CRITICAL]

CryptoFX LLC was a Houston, Texas-based company that the SEC has alleged operated a $300 million Ponzi scheme from approximately May 2020 to October 2022, targeting over 40,000 predominantly Latino investors across ten U.S. states and two foreign countries. The scheme purported to generate returns of 15 to 100 percent through cryptocurrency and foreign exchange trading but instead used investor funds to make Ponzi payments, pay commissions, and finance the personal expenses of its principals and network leaders. The SEC halted operations via emergency action in September 2022; a court-appointed receiver is administering recovery proceedings, and enforcement actions against 19 individuals and the company itself have resulted in judgments and ongoing litigation as of 2026.

avoid.net/symbiosis-finance-bridgev2-sybtc-exploit-september-202630/100[WARNING]

On September 11, 2026, an attacker exploited two chained vulnerabilities in Symbiosis Finance's BridgeV2 smart contract, depositing 330 satoshis (~$0.25) and minting approximately 46.1 billion unbacked synthetic Bitcoin (syBTC) tokens — over 2,000 times Bitcoin's entire circulating supply. The attacker liquidated roughly 4.39 WBTC (~$336,000) on Uniswap before the incident was contained; Symbiosis recovered approximately 15 BTC (~$1.15 million) and suspended its native Bitcoin bridge pending a full security rewrite. This event is distinct from the broader Symbiosis Finance protocol, which has processed over $10 billion in cross-chain volume since 2022 and whose non-Bitcoin routing remained operational throughout.

avoid.net/operation-token-mirrors-doj-crypto-market-manipulation-ring2/100[CRITICAL]

Operation Token Mirrors is a multi-phase FBI and IRS Criminal Investigation undercover operation in which federal agents created fictitious cryptocurrency tokens — most notably the Ethereum-based 'NexFundAI' — to infiltrate and document alleged wash trading and pump-and-dump schemes offered as fee-based 'market making' services. The operation produced two coordinated enforcement waves: an initial October 2024 action by the U.S. Attorney for the District of Massachusetts charging 18 individuals and entities tied to Gotbit, CLS Global, ZM Quant, and MyTrade; and a subsequent 2025–2026 action by the U.S. Attorney for the Northern District of California charging 10 additional foreign nationals connected to Gotbit, Vortex, Antier Solutions, and Contrarian. As of mid-2026, Gotbit founder Aleksei Andriunin has been sentenced to eight months in prison, Gotbit has been ordered to cease operations and forfeit approximately $23 million, at least three other individuals have pleaded guilty or been sentenced, and three Singapore-based executives have been extradited to the United States to face trial.

avoid.net/symbiosis-finance38/100[WARNING]

Symbiosis Finance is a cross-chain DEX and bridge protocol launched in March 2022, enabling token swaps across 50+ EVM and non-EVM networks via synthetic assets and a permissioned relayer network. On September 11, 2026, an attacker exploited a message-validation flaw in its BridgeV2 contract, minting approximately 46.1 billion unbacked syBTC tokens on BNB Chain and extracting around $336,000 in real funds; total protocol losses were estimated at 9.97 BTC (~$770,000). The Bitcoin Bridge remains offline as of mid-September 2026, and a structural relayer-collusion risk — whereby two-thirds of MPC nodes acting together could drain user funds — persists independently of the exploit patch.

avoid.net/dcent-wallet28/100[WARNING]

DCENT Wallet is a hardware and software cryptocurrency wallet product developed by South Korean cybersecurity firm IoTrust Co., Ltd., founded in 2017 and headquartered in Seoul. On September 16, 2026, IoTrust publicly disclosed that it detected abnormal asset transfers on its DCENT App Wallet and launched an emergency investigation, urging all App Wallet users and any hardware wallet users who shared a mnemonic phrase with the App Wallet to move funds immediately. As of the date of this investigation, no root cause, loss total, or number of affected users has been disclosed, and the incident remains active.

avoid.net/bonk-fun44/100[WARNING]

BONK.fun (also marketed as LetsBONK.fun) is a no-code meme coin launchpad on the Solana blockchain, launched in April 2025 as a joint initiative between the BONK community and Raydium protocol. The platform rapidly captured majority market share from Pump.fun by mid-2025 before losing significant ground later that year, and suffered a domain-level security breach in March 2026 caused by a social engineering attack on its domain service provider — an incident attributed to the third-party infrastructure provider, not the platform's own code or contracts. The platform is operationally linked to Bonk, Inc. (Nasdaq: BNKK), a publicly traded company that holds a revenue sharing interest in the platform.

avoid.net/chainflip42/100[WARNING]

Chainflip is a decentralized cross-chain swap protocol that uses a validator network, threshold signature schemes, and a Substrate-based State Chain to facilitate native asset swaps across blockchains without wrapped tokens or bridges. On September 12, 2026, an attacker exploited a flaw in Chainflip's TRON USDT memo-handling logic, triggering duplicate payouts across six transactions totaling 736,442.17 USDT over approximately 90 minutes. Chainflip halted the entire network, patched the vulnerability, and committed to making affected liquidity providers whole, though the specific reimbursement mechanism and a complete technical post-mortem remained pending as of the time of reporting.

avoid.net/prince-group-transnational-criminal-organization0/100[CRITICAL]

The Prince Group Transnational Criminal Organization (TCO) is a Cambodia-based criminal enterprise designated by the U.S. Treasury's OFAC under Executive Order 13581. U.S. and UK authorities allege the network operates industrial-scale cyber-enabled fraud (including cryptocurrency investment scams commonly called pig-butchering), human trafficking into forced-labor scam compounds, and global money laundering. As of June 2026, OFAC has cumulatively designated 146 individuals and entities within the network. The group's identified leader, Chen Zhi, was stripped of Cambodian citizenship and sent to China in January 2026; he faces a U.S. federal indictment. Hu Xiaowei has been publicly named by OFAC as the TCO's second-in-command.

avoid.net/tac-network28/100[WARNING]

TAC Network (TON Application Chain) is a Cosmos-based EVM Layer 1 blockchain designed to bridge Ethereum-compatible decentralized applications to the TON and Telegram ecosystem. On August 22, 2026, the network suffered a critical exploit via a shared Cosmos EVM vesting-account vulnerability, resulting in the drainage of approximately 2.99 billion TAC tokens (28.6% of total supply) from the bonded staking pool. The TAC Foundation responded by halting the chain and subsequently migrating the entire BEP20 TAC token supply on BNB Chain to a new contract that deliberately excluded attacker-linked addresses — a supply rewrite that raised token integrity questions for existing holders.

avoid.net/ascendex-exchange4/100[CRITICAL]

AscendEX (formerly BitMax) was a centralized cryptocurrency exchange founded in 2018 and headquartered in Singapore. On July 1, 2026, the exchange permanently ceased all operations, citing failure to obtain EU MiCA authorization and the collapse of an undisclosed strategic liquidity transaction. As of July 6, 2026, all automated withdrawals were suspended and moved to manual review, with the exchange explicitly stating it cannot guarantee the timing or amounts of user fund returns.

avoid.net/zachxbt-crypto-influencer-paid-promotion-leak-200-influencers-september-202512/100[CRITICAL]

In early September 2025, on-chain investigator ZachXBT published a leaked rate sheet listing more than 200 crypto influencer accounts offered paid promotional deals, with Solana wallet addresses attached to each entry and per-post pricing ranging from $50 to $60,000. Of roughly 160 accounts that accepted payment, fewer than five disclosed their posts as advertising, representing a compliance rate below 3% against FTC and ASA disclosure standards. The incident exposed a systemic pattern of undisclosed paid promotion across crypto social media and has been cited in connection with influencer-driven promotional chains that preceded token collapses.

avoid.net/harmony-protocol8/100[CRITICAL]

Harmony Protocol, a Layer 1 blockchain launched in 2019, suffered a critical consensus-layer exploit on August 12, 2026, in which attackers exploited a quorum verification bug and a cross-shard receipt replay vulnerability to forge approximately 3.01 trillion ONE tokens across six transactions — nominally valued at roughly $3.56 billion at pre-incident pricing. The incident is Harmony's second major security failure in four years, following the approximately $100 million Horizon bridge hack attributed to North Korea's Lazarus Group in June 2022. On September 6, 2026, Harmony proposed sunsetting its Layer 1 entirely and migrating the ONE token to Ethereum as an ERC-20.

avoid.net/aquifer-amm28/100[WARNING]

Aquifer is a proprietary automated market maker (AMM) on Solana focused on stablecoin swaps, which had accumulated approximately $2.8 million in total value locked prior to a security incident on August 31, 2026. Attacker-controlled wallets on both Solana and Ethereum drained approximately $2.5 million from the protocol in what Aquifer attributed to a wallet compromise rather than a smart contract vulnerability. A 20% white-hat bounty offer with a September 3, 2026 deadline passed without any publicly confirmed return of funds, and no technical post-mortem has been released.

avoid.net/bitmex-exchange28/100[WARNING]

BitMEX (Bitcoin Mercantile Exchange), operated by HDR Global Trading Limited, is a Seychelles-registered cryptocurrency derivatives exchange that permanently shut down on September 23, 2026, ending an 11-year run. The exchange accumulated more than $200 million in total regulatory penalties across CFTC, FinCEN, and DOJ proceedings for willful failures to maintain adequate anti-money laundering and know-your-customer programs; its three co-founders and a senior employee each pleaded guilty to Bank Secrecy Act violations, though all four subsequently received presidential pardons in March 2025. Closure followed a two-year failed sale process, and the disposition of the exchange's approximately $270 million insurance fund remained publicly unresolved at the time of shutdown.

avoid.net/tectonic-protocol18/100[CRITICAL]

Tectonic is a decentralized lending protocol on Crypto.com's Cronos blockchain, forked from Compound and launched in December 2021. On August 30, 2026, an unidentified attacker exploited the protocol by manipulating the price of its thinly traded TONIC governance token approximately 100-fold in roughly 20 minutes, then borrowed an estimated $120.4 million in liquid assets against the inflated collateral. The incident forced Cronos validators to halt the entire blockchain and execute a controversial rollback of 10,961 blocks, reversing approximately $111.2 million in stolen funds while leaving $9.19 million permanently unrecovered. The exploit caused Tectonic's total value locked to collapse from approximately $121.7 million to roughly $3 million.

avoid.net/0x5a76a2830859c321a50937a22fde571fbf4810f338/100[WARNING]

This Ethereum address is the official ERC-20 token contract for Binibit (BINI), an upgradeable ERC1967 proxy deployed around August 5, 2026, by an externally owned account funded through OKX. Binibit is a self-described blockchain ecosystem incorporating a centralized exchange, a decentralized exchange (BaiDEX), a Layer 1 network (BiniChain), and a token launchpad, incorporated as Binibit S.A. in Panama. No regulatory actions, OFAC sanctions, or verified fraud findings were identified as of September 2026; however, the project presents several elevated risk factors including anonymous individual leadership, no publicly available security audit, a proxy contract architecture that permits future contract upgrades, and a small number of Trustpilot complaints alleging locked accounts and blocked withdrawals.

avoid.net/faruk-fatih-ozer0/100[CRITICAL]

Faruk Fatih Ozer is the Turkish founder and CEO of Thodex, a cryptocurrency exchange that collapsed in April 2021 after he fled to Albania, leaving approximately 391,000 users unable to access an estimated $2 billion in funds. He was arrested in Albania in August 2022, extradited to Turkey in April 2023, and sentenced on September 7, 2023 to 11,196 years, 10 months, and 15 days in prison on charges of aggravated fraud, founding a criminal organization, and money laundering. He was found dead in Tekirdag F-Type High Security Prison on November 1, 2025, with Turkish authorities indicating initial findings pointed to suicide.

avoid.net/dritan-kapllani-jr3/100[CRITICAL]

Dritan Kapllani Jr. is a U.S.-based individual who, according to blockchain investigator ZachXBT and a May 2026 federal criminal complaint, is allegedly the central figure behind approximately $19 million in cryptocurrency social engineering thefts spanning 2025–2026. He is named as Co-Conspirator 1 (CC-1) in the DOJ complaint filed May 11, 2026 against co-defendant Trenton Richard David Johnston in the Southern District of Florida. As of September 16, 2026, Kapllani has not been formally charged.

avoid.net/nesa-nes28/100[WARNING]

Nesa is a Cosmos-based Layer-1 blockchain marketed as infrastructure for verifiable, privacy-preserving AI, with its NES token launched via Binance Alpha in mid-2026. On August 24, 2026, an attacker exploited an integer-underflow vulnerability in the shared Cosmos EVM module to inflate a NES balance roughly 200x and bridge approximately $50 million worth of tokens (25.8% of stated supply) out via Hyperlane to Ethereum, crashing the NES price as much as 90% before a partial recovery; extreme slippage limited the attacker's realized profit to roughly $60,000. The same vendor-level bug hit MANTRA, TAC, and KiiChain in the same window, and Cosmos Labs has since admitted it wrongly cleared the underlying flaw months earlier; Nesa's own post-incident transparency has drawn separate criticism for withholding technical detail that peer chains disclosed.

avoid.net/cosmos-evm-vulnerability-august-2026-six-chain-exploit18/100[CRITICAL]

A critical integer underflow vulnerability (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was reported via bug bounty on April 25, 2026, but was incorrectly assessed by Cosmos Labs as posing no risk to live production networks. Between August 20 and August 25, 2026, attackers exploited the flaw across six Cosmos EVM-based blockchains, draining approximately $5.72 million in total. Cosmos Labs confirmed in its August 28 post-mortem that its initial clearance of the bug was in error, and that its patch-release process failed to provide downstream chains adequate notice to upgrade before exploitation began.

avoid.net/mirror5/100[CRITICAL]

Mirror Protocol was a Terra-based DeFi platform enabling synthetic assets (mAssets) that tracked prices of US stocks. The protocol suffered a $90 million exploit in October 2021 that went undetected for seven months, a governance attack campaign in December 2021 targeting $40 million in community funds, and a second $2 million oracle exploit in May 2022. It became permanently inactive in August 2022 following the catastrophic collapse of the Terra/LUNA/UST ecosystem, which was orchestrated by its parent company Terraform Labs under Do Kwon, who was subsequently convicted of fraud and sentenced to 15 years in prison.

avoid.net/trenton-johnston-crypto-social-engineering-theft-ring2/100[CRITICAL]

Trenton Richard David Johnston, a 20-year-old Canadian national, pleaded guilty on June 10, 2026 in U.S. District Court (Southern District of Florida) to conspiracy to commit money laundering in connection with a social engineering scheme that caused losses exceeding $13 million in cryptocurrency. Johnston operated as part of a broader theft ring — connected to 'The Com' hacker network — alongside co-conspirators including Miami resident Brandon Michael Tardibone and an uncharged individual identified by blockchain investigator ZachXBT as Dritan Kapllani Jr., who is alleged to be linked to approximately $19 million in total social engineering thefts. The scheme involved impersonating support representatives from Google, Trezor, and other crypto companies to trick victims into surrendering access to their digital wallets.

avoid.net/trenton-richard-johnston2/100[CRITICAL]

Trenton Richard David Johnston is a Canadian national who pleaded guilty on June 10, 2026 in U.S. District Court in Miami to conspiracy to commit wire fraud and conspiracy to commit money laundering in connection with a social-engineering cryptocurrency theft scheme that caused at least $13.04 million in victim losses. Johnston, who was 19 at the time of his March 2026 arrest and had overstayed a U.S. tourist visa, is identified as Co-Conspirator 2 in federal filings that name Dritan Kapllani Jr. as Co-Conspirator 1 in the same 185 BTC theft. He awaits sentencing and has agreed to deportation to Canada.

avoid.net/yelo-yelotree0/100[CRITICAL]

Yelo, known online as @yelotree, is a crypto key opinion leader (KOL) and former professional Fortnite esports player with approximately 180,000 Twitter followers who also operated a luxury car rental business in Miami. As of May 2026, Yelo faces federal criminal charges alleging he laundered funds stolen from cryptocurrency holders through that rental business, with a potential sentence of up to 30 years. Separately, Yelo participated in undisclosed paid promotion of the Sharpei memecoin on Solana in October 2024, which subsequently suffered a documented rug pull that erased 96% of its market value.

avoid.net/brandon-michael-tardibone4/100[CRITICAL]

Brandon Michael Tardibone, 28, of Miami, Florida, was federally indicted on May 11, 2026 in the Southern District of Florida (case 1:26-cr-20181) on charges of conspiracy to commit money laundering and harboring an alien unlawfully present in the United States. Prosecutors allege he provided housing and material support to Canadian co-defendant Trenton Richard David Johnston — who allegedly orchestrated a $13 million cryptocurrency fraud scheme via social-engineering impersonation attacks — while Johnston was unlawfully overstaying his visa, and that both defendants jointly laundered more than $1 million of stolen proceeds through luxury goods and South Florida nightlife. All charges are allegations; both defendants are presumed innocent unless and until proven guilty at trial.

avoid.net/coinex-exchange-closure-september-202642/100[WARNING]

On September 15, 2026, CoinEx founder Yang Haipo announced the permanent wind-down of the CoinEx centralized exchange after nine years of operation, citing prolonged market downturns, declining trading volumes, and rising regulatory compliance costs. The exchange has published a phased closure schedule ending December 22, 2026, after which unclaimed balances will move to private custody subject to a 5% monthly fee. This incident page covers the shutdown event and its user-impact risks; a separate corpus entry covers CoinEx's broader operational history.

avoid.net/tbtfw-beverly-hills-luxury-car-dealer-crypto-laundering-vector28/100[WARNING]

TBTFW is an exotic car dealership at 9737 Wilshire Boulevard in Beverly Hills, California, operated by Zach Ersoff through Spur Ridge Holdings LLC. In September 2026, on-chain investigator ZachXBT alleged that stolen cryptocurrency from the Malone Lam $245 million RICO case was routed via Monero to TBTFW for vehicle purchases, with Austin Fine (@xmrfine) named as an alleged intermediary. As of September 16, 2026, no criminal charges have been filed against TBTFW, Zach Ersoff, or Spur Ridge Holdings in connection with the laundering allegations.

avoid.net/austin-fine-xmrfine18/100[CRITICAL]

Austin Fine, known online as @xmrfine, is a crypto-adjacent individual who on September 9, 2026 was publicly accused by on-chain investigator ZachXBT of allegedly facilitating money laundering on behalf of Malone Lam, the ringleader of a $245 million cryptocurrency theft ring who pleaded guilty to RICO conspiracy on September 8, 2026. ZachXBT alleged that Fine converted stolen crypto assets into luxury goods — including vehicles purchased through Beverly Hills dealership TBTFW — using Monero as an intermediary, and charged fees for doing so. As of September 16, 2026, no criminal charges have been filed against Austin Fine, and no public response from Fine has been documented.

avoid.net/swiss-bitcoin-pay42/100[WARNING]

Swiss Bitcoin Pay is a non-custodial Bitcoin payment processor incorporated as Swiss Bitcoin Pay Sàrl in Neuchâtel, Switzerland, serving over 1,000 merchants in 21 countries since late 2022. On September 14, 2026, the company took its servers offline after detecting suspected unauthorized access to its internal systems. No customer funds or private keys were reported as compromised, but five categories of sensitive personal and financial data were confirmed as potentially exposed, creating material phishing and social-engineering risk for affected merchants and customers.

avoid.net/orange-finance28/100[WARNING]

Orange Finance is an Arbitrum-based automated liquidity management protocol designed for LPDfi (liquidity provider DeFi), enabling users to earn swap fees and options premiums via concentrated AMM vaults. On January 8, 2025, the protocol suffered a critical security breach in which an attacker compromised the admin private key, exploited a misconfigured multi-signature wallet that required only a single signature to execute, and drained approximately $843,556 across all active vaults. The protocol was flagged by ZachXBT and has not resumed normal operations since the incident.

avoid.net/shibarium28/100[WARNING]

Shibarium is a layer-2 blockchain built on Ethereum, launched in August 2023 as the scaling solution for the Shiba Inu (SHIB) ecosystem. The network has faced a series of significant incidents including a failed initial launch that trapped $1.7 million in bridged funds, a September 2025 flash loan exploit that drained approximately $4.1 million from its cross-chain bridge via validator key compromise, persistent rug pull activity on its DeFi layer, allegations of code plagiarism, and ongoing transparency concerns stemming from fully pseudonymous leadership. Shibarium initiated a novel NFT-based restitution program following the 2025 exploit but as of early 2026 the recovery path remained unresolved.

avoid.net/aethir36/100[WARNING]

Aethir is a Singapore-based decentralized GPU cloud computing protocol operating as a Decentralized Physical Infrastructure Network (DePIN), founded in 2021 by Mark Rydon and Daniel Wang. The project raised approximately $109M across funding rounds and a $100M+ checker node sale, launched its ATH token in June 2024, and claims $147M+ ARR from enterprise AI and gaming clients. Risk factors include a 95% token price decline from its all-time high, a redirected Season 3 community airdrop, a cross-chain bridge exploit in April 2026 resulting in up to $400K in losses, heavy insider token allocation, and a ZachXBT flag whose specific basis has not been publicly detailed.

avoid.net/bankr18/100[CRITICAL]

Bankr is an AI-powered crypto wallet and trading bot built on the Base network (Ethereum L2), allowing users to trade, swap, and manage funds through natural-language commands on X (Twitter) and Farcaster. In May 2026, the platform suffered two separate security incidents within weeks of each other: a prompt-injection attack exploiting Grok that drained approximately $150,000–$175,000 in DRB tokens, and a distinct key-compromise or session-token breach that affected 14 user wallets and drained an estimated $170,000–$385,000 in total. Bankr publicly committed to reimbursing all affected users, but no confirmed completion of that reimbursement has been documented in available sources as of the investigation date.

avoid.net/su-zhu3/100[CRITICAL]

Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.

avoid.net/satish-kumbhani0/100[CRITICAL]

Satish Kumbhani is the founder of BitConnect, a cryptocurrency platform that the U.S. Department of Justice, SEC, and multiple state regulators have determined operated as a global Ponzi scheme defrauding investors of approximately $2.4 billion between 2016 and 2018. Kumbhani was indicted by a federal grand jury in San Diego on February 25, 2022, on charges carrying a maximum penalty of 70 years in prison, and has remained a fugitive from justice since disappearing from India following his U.S. indictment.

avoid.net/donald-g-basile-bitcoin-latinum-ltnm2/100[CRITICAL]

Donald G. Basile is the founder of Bitcoin Latinum (LTNM) and CEO of Monsoon Blockchain Corporation. On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil fraud complaint against Basile and two entities he controlled — GIBF GP, Inc. and Monsoon Blockchain Corporation — alleging he raised approximately $16 million from hundreds of investors through materially false statements about nonexistent insurance coverage and asset backing. The SEC alleges more than 80% of investor funds were diverted to personal use, including real estate purchases and a $160,000 horse. The case is a civil action; no criminal charges have been reported as of the investigation date.

avoid.net/xinbi-guarantee0/100[CRITICAL]

Xinbi Guarantee is a Chinese-language illicit online marketplace that operated via Telegram, functioning as an escrow service connecting transnational criminal syndicates with vendors selling scam infrastructure, money laundering services, stolen data, and human trafficking recruitment. On September 9, 2026, the U.S. Treasury's OFAC designated Xinbi Guarantee as a significant transnational criminal organization under Executive Order 13581, and the DOJ's Scam Center Strike Force seized two cryptocurrency wallets and obtained restraining orders covering 47 additional wallets, together freezing approximately $52.8 million. Blockchain analytics firms place the platform's total transaction throughput at between $24 billion and $36 billion since approximately 2022.

avoid.net/mantra-chain-august-2026-exploit38/100[WARNING]

On August 20, 2026, MANTRA Chain — an RWA-focused Cosmos-based Layer 1 — suffered an exploit of a critical vulnerability in its upstream Cosmos EVM module, forcing a full network halt of approximately 30 hours and causing its OM token to drop 18% to a record low of $0.004126. Approximately 720.9 million OM tokens worth roughly $3.6 million were drained across the incident, part of a coordinated attack pattern that ultimately affected six Cosmos EVM chains and converted approximately $5.72 million in stolen assets across the ecosystem. This page covers the August 2026 security incident; the April 2025 token price collapse is documented separately under the 'mantra-chain' entry.

avoid.net/cosmos-labs28/100[WARNING]

Cosmos Labs, the organization maintaining the shared Cosmos EVM module, received a responsible disclosure of a critical balance-underflow vulnerability on April 25, 2026, incorrectly assessed it as low-risk to production networks, and shipped a silent patch on August 19, 2026 without issuing a vulnerability advisory or privately notifying downstream chain operators. Between August 20 and August 25, 2026, attackers exploited the unpatched or unmitigated vulnerability across six Cosmos-based blockchains — including MANTRA, TAC, and KiiChain — converting approximately $5.72 million in stolen tokens through decentralized and centralized exchanges. Cosmos Labs acknowledged in an August 28 post-mortem that it had incorrectly cleared the bug as safe and that its coordinated-disclosure process was insufficient.

avoid.net/mantra-chain-upstream-exploit-august-202632/100[WARNING]

On August 20-21, 2026, MANTRA Chain halted all block production after an attacker exploited a critical vulnerability (ASA-2026-002) in the shared Cosmos EVM ICS20 precompile, a component developed by Cosmos Labs and used by multiple chains. MANTRA's OM token fell 18.5% to an all-time low of $0.004126 during the approximately 30-hour outage, and the chain resumed on August 22 after deploying patched version 8.4.0. MANTRA stated no user funds were exploited and that only two project-managed wallets were affected, but the team has not published a technical post-mortem nor disclosed what, if anything, was extracted from those wallets, leaving the full financial scope of the incident unresolved as of August 27, 2026.

avoid.net/mantra-chain10/100[CRITICAL]

MANTRA Chain, a Cosmos-EVM layer-1 blockchain focused on real-world asset tokenization, halted all block production on August 20, 2026 after an attacker exploited a known vulnerability in the shared Cosmos EVM ICS20 precompile module. The network was offline for approximately 30 hours, the native OM token fell 18% to an all-time low of $0.004126, and South Korean exchanges Upbit, Bithumb, and Coinone placed OM on delisting watchlists. This is MANTRA's second major crisis in 2026, following the April 2025 collapse of OM by more than 90%, and occurs in the context of a broader Cosmos EVM security incident that also affected KiiChain and TAC.

avoid.net/hefu-chai-and-huaisong-xiang-former-robinhood-engineers8/100[CRITICAL]

Hefu Chai, 36, and Huaisong Xiang, 30, both former Robinhood software engineers, were criminally charged by federal prosecutors in the Southern District of New York, unsealed on September 15, 2026, with commodities fraud and wire fraud. Prosecutors allege the pair misappropriated confidential internal information about upcoming Robinhood Crypto token listings and used it to open positions in perpetual futures on the decentralized exchange Hyperliquid ahead of public listing announcements between 2025 and 2026, each allegedly profiting more than $50,000. The charges are allegations only; no conviction has occurred, and no plea, trial outcome, or sentencing has been reported as of this writing.

avoid.net/donald-g-basile-bitcoin-latinum-fraud3/100[CRITICAL]

Donald G. Basile is a technology entrepreneur and the founder of Bitcoin Latinum (LTNM), a cryptocurrency token marketed in 2021 as 'the world's first insured digital asset.' On April 17, 2026, the U.S. Securities and Exchange Commission filed a civil fraud suit against Basile and two entities he controlled, GIBF GP, Inc. and Monsoon Blockchain Corporation, alleging he raised approximately $16 million from hundreds of investors via Simple Agreements for Future Tokens (SAFTs) using false claims of a $1 billion insurance policy and a diversified backing trust that never existed, and that he diverted more than 80% of investor funds to personal use. Basile and Bitcoin Latinum had also faced multiple private civil suits alleging securities fraud since 2022, predating the SEC action.

avoid.net/hefu-chai-huaisong-xiang5/100[CRITICAL]

Hefu Chai and Huaisong Xiang are former Robinhood Crypto engineers charged by the U.S. Department of Justice on September 15, 2026 with commodities fraud and wire fraud. Prosecutors allege they misappropriated confidential information from Robinhood's internal token-listing pipeline and used it to pre-position perpetual futures trades on the decentralized exchange Hyperliquid between 2025 and 2026, with each defendant allegedly profiting more than $50,000. The charges are allegations only; no conviction or guilty plea has been entered as of the date of this investigation.

avoid.net/blockstream42/100[WARNING]

Blockstream is a Bitcoin infrastructure company founded in 2014, led by cryptographer Adam Back, that develops the Liquid Network sidechain, Core Lightning, Blockstream Green wallet, Blockstream Jade hardware wallet, and Blockstream Satellite. The company achieved unicorn status with a $3.2 billion valuation in 2021 and has raised over $400 million in total financing. In September 2026, the Liquid Network suffered a critical ~$320 million exploit that drained approximately 4,000 BTC from its federation wallet, with ~598 BTC remaining unrecovered; the company also faces unresolved allegations regarding its Bitcoin Mining Note product and the undisclosed prior fraud conviction of its former mining division head.

avoid.net/soulja-boy-deandre-cortez-way12/100[CRITICAL]

Soulja Boy, born DeAndre Cortez Way, is an American rapper who became one of the most extensively documented celebrity crypto promoters linked to rug pulls and abandoned projects. Blockchain investigator ZachXBT documented 73 crypto promotions and 16 NFT collections between 2021 and 2023, estimating Way earned approximately $730,000 from paid endorsements, several of which subsequently rugged or were abandoned. The SEC charged Way in March 2023 for undisclosed paid promotion of TRX and BTT tokens; unlike six co-defendants who settled, Way did not initially respond to the charges, resulting in a default judgment. The SEC later filed to dismiss remaining claims against Way in 2026 as part of a broader resolution with the Justin Sun/Tron defendants. Way issued a public apology in December 2025, claiming ignorance of the fraudulent nature of the projects, though the timing coincided with renewed controversy after Base co-founder Jesse Pollak publicly disclosed a $1,500 investment in a new Soulja Boy-linked memecoin on the Base network.

avoid.net/soulja-boy-deshawn-raymond8/100[CRITICAL]

Soulja Boy (legal name DeAndre Cortez Way; also referenced as DeShawn Raymond) is an American rapper with an extensive, multi-year documented history of promoting cryptocurrency tokens and NFT collections, a large share of which were subsequently identified as rug pulls, abandoned projects, or otherwise fraudulent. On-chain investigator ZachXBT's April 2023 research catalogued 73 crypto promotions and 16 NFT drops linked to him, estimating over $730,000 in promotional earnings, and the U.S. Securities and Exchange Commission separately charged him in 2023 for undisclosed paid touting of Tronix (TRX) and BitTorrent (BTT). The pattern resurfaced in December 2025 when Base co-founder Jesse Pollak publicly engaged with a new Soulja Boy-linked meme token, prompting ZachXBT to revive the allegations and renewed industry criticism, followed by a public apology from Soulja Boy.

avoid.net/liquid-network-exploit-september-202618/100[CRITICAL]

On September 6, 2026, attackers exploited a cache-verification bug in Blockstream's open-source Elements software to mint roughly 4,000 unbacked L-BTC on the Liquid Network and peg them out for real Bitcoin via federation member SideSwap, draining approximately 95% of the sidechain's BTC reserves (~$320 million). The attackers, claiming to be white hats, returned about 3,400 BTC (~85%) after a patch was deployed but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty, which Blockstream has refused to authorize, calling it theft. The incident halted Liquid Network operations for several days and renewed scrutiny of the security assumptions underlying federated Bitcoin sidechains used by exchanges.

avoid.net/ukrainian-fake-crypto-investment-ring-kyiv-20260/100[CRITICAL]

A Kyiv-based criminal network allegedly operated multiple fake cryptocurrency investment platforms that targeted victims across more than 20 countries, with an estimated peak monthly turnover of up to $1 million. Ukrainian law enforcement, including the National Police of Ukraine, the Security Service of Ukraine (SBU), and the Office of the Prosecutor General, dismantled the operation in early September 2026 through 34 coordinated raids. The alleged organizer, a 25-year-old IT specialist, recruited over 46 Ukrainian citizens to staff the ring, which combined fabricated investment dashboards, wallet-draining malware, and identity data harvesting.

avoid.net/liquid-network22/100[CRITICAL]

Liquid Network is a Bitcoin sidechain developed and operated by Blockstream, secured by a federation of exchanges and institutions. On September 6, 2026, an attacker exploited a cache key collision bug in the Elements codebase to mint approximately 4,000 unbacked L-BTC and redeem them for real Bitcoin via the SideSwap peg-out platform, draining roughly 95% of the Liquid Federation's reserves (about $320 million) in under 40 minutes. The attacker, claiming to be a white-hat, returned about 3,400 BTC after Blockstream patched the bug but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty that Blockstream has publicly refused to honor, leaving the network's reserves under-collateralized and exchanges facing an extended service disruption.

avoid.net/kyiv-crypto-drainer-ring-fake-investment-platforms-september-20263/100[CRITICAL]

In early September 2026, Ukraine's Security Service (SBU) and National Police announced the dismantling of a Kyiv-based network that allegedly ran fake cryptocurrency investment platforms and used a 'test transaction' approval-phishing technique to drain victims' wallets. Authorities said the operation, allegedly organized by a 25-year-old IT specialist and staffed by more than 46 Ukrainian citizens, generated turnover of up to $1 million a month at its peak and had identified at least 62 victims across more than 20 countries. As of the most recent reporting, no suspects had been named publicly and formal notices of suspicion had reportedly not yet been served, with the case proceeding under the Prosecutor General's Office.

avoid.net/poolin-technology8/100[CRITICAL]

Poolin Technology Pte. Ltd., once the world's largest Bitcoin mining pool, halted all mining and hosting operations on July 10, 2026 and filed for Chapter 11 bankruptcy in the U.S. Bankruptcy Court for the District of New Jersey on July 22, 2026, with roughly $173 million in total obligations against less than $10 million in assets. The largest liability, $163.7 million owed to approximately 11,700 wallet customers as unpaid "IOU" tokens issued after Poolin froze withdrawals in September 2022, is projected to recover only about 32 cents on the dollar through a court-supervised sale of the company's two remaining Texas mining sites, a process still underway as of this writing.

avoid.net/liquid-network-elements-cache-bug-exploit-september-202618/100[CRITICAL]

On September 6, 2026, an unidentified attacker exploited an ambiguous cache-key encoding flaw in the open-source Elements software underpinning Blockstream's Liquid Network sidechain. Approximately 3,998.5 unbacked L-BTC (valued at roughly $320 million) were minted and pegged out for native Bitcoin, draining an estimated 95% of the federation's reserves. The attacker returned 3,400 BTC on September 7 and retained 598.5 BTC (~$47 million), characterizing the retention as a 15% bounty; Blockstream's September 11 public statement rejects this characterization and refuses to treat the incident as a white-hat disclosure, stating the retained funds constitute theft.

avoid.net/hunter-biden-laptop-token22/100[CRITICAL]

$LAPTOP is an ERC-20 memecoin launched on the Base blockchain on September 9, 2026 by Hunter Biden, son of former U.S. President Joe Biden. The token surged to a reported peak near $190–$225 shortly after launch before collapsing approximately 98–99% within hours, with an estimated four out of five buyers suffering losses. Biden disputes characterizations of the collapse as a rug pull, attributing the crash to insufficient liquidity and automated sniper-bot activity, while asserting that team tokens remained locked and unsold throughout.

avoid.net/sideswap38/100[WARNING]

SideSwap is an open-source, non-custodial peer-to-peer trading platform and wallet built on Blockstream's Liquid Network, founded in 2020 by Scott Millar. On September 6, 2026, SideSwap's Peg-out Authorization Key (PAK) was the mechanism through which approximately 3,996 real BTC — worth roughly $320 million — was released from the Liquid federation reserve in a single transaction, following an Elements software vulnerability that allowed the minting of unbacked L-BTC. SideSwap's own post-mortem acknowledged operational oversights including keeping its PAK key connected to the internet at all times and running no size, velocity, or origin checks on peg-out orders, though the underlying vulnerability originated in the open-source Elements codebase maintained by Blockstream.

avoid.net/blockstream-liquid-network32/100[WARNING]

The Liquid Network is a Bitcoin sidechain operated by Blockstream via a federated multi-signature custody model, designed for fast, confidential BTC transfers between exchanges and financial institutions. On September 6, 2026, attackers exploited a cache-key collision vulnerability in the open-source Elements software to mint approximately 4,000 unbacked L-BTC and drain roughly $320 million from the federation reserve — one of the largest Bitcoin-adjacent security incidents on record. Attackers claiming to be white-hat researchers subsequently returned approximately 3,400 BTC while retaining ~598.5 BTC (~$47M) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft.

avoid.net/liquid-network-blockstream28/100[WARNING]

Liquid Network is a Bitcoin sidechain operated by Blockstream and a federation of member exchanges, launched in 2018 to enable fast inter-exchange BTC settlement via a pegged asset called L-BTC. On September 6, 2026, attackers exploited a range-proof cache collision vulnerability in the underlying Elements software to mint approximately 4,000 unbacked L-BTC tokens and redeem them for roughly $320 million in real Bitcoin from the federation reserve, representing one of the largest crypto hacks of 2026. Attackers returned approximately 85% of funds after the vulnerability was patched, but retained roughly 598.5 BTC (~$47 million) as a self-declared bounty; Blockstream publicly rejected the bounty demand and characterized the retention as theft, not responsible disclosure.

avoid.net/evmos-network30/100[WARNING]

Evmos was a Cosmos-based, EVM-compatible proof-of-stake blockchain developed by Tharsis Labs that launched on mainnet in April 2022 and raised $27 million in a token sale led by Polychain Capital. The network was formally shut down on approximately May 18, 2026, after Governance Proposal #331 passed with 99.8% approval, halting all block production at block height 37,318,000. Following discontinuation, an authorization vulnerability in the Evmos vesting and lockup module — left unpatched because the codebase was no longer maintained — was exploited in August 2026 to drain approximately $3 million from BounceBit Chain, a third-party network built on the Evmos stack.

avoid.net/term-finance-governance-exploit-august-202610/100[CRITICAL]

On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.

avoid.net/ivan-obukhov-foscom-fze2/100[CRITICAL]

Ivan Obukhov is a UAE-based Ukrainian national designated by OFAC on August 24, 2026, as part of Operation Economic Outcast. U.S. Treasury alleges that since 2023 he processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Qods Force, and that he has for years brokered Iranian shadow-fleet vessels. His UAE-registered company Foscom FZE, which he acquired in 2022, was simultaneously designated under Executive Order 13224 as an entity controlled by Obukhov.

avoid.net/defi-governance-attack-wave-20260/100[CRITICAL]

Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.

avoid.net/nishad-singh12/100[CRITICAL]

Nishad Singh is a former software engineer who served as Director of Engineering at FTX, the cryptocurrency exchange that collapsed in November 2022 following the misappropriation of more than $8 billion in customer funds. Singh pleaded guilty in February 2023 to six criminal charges including wire fraud, commodities fraud, securities fraud, money laundering conspiracy, and campaign finance violations, and was sentenced in October 2024 to time served with no prison after providing extensive cooperation against FTX founder Sam Bankman-Fried. A supplemental CFTC civil settlement was reached in April 2026, requiring Singh to disgorge $3.7 million and subjecting him to a five-year trading ban.

avoid.net/kyle-davies3/100[CRITICAL]

Kyle Davies is the co-founder of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion in liabilities owed to 27 creditors. Following the collapse, Davies evaded liquidators, was sentenced in absentia to four months imprisonment in Singapore for failing to cooperate with court-ordered investigations, and received a nine-year ban from Singapore's Monetary Authority of Singapore (MAS) for regulatory violations including providing false information to regulators. He subsequently co-founded OPNX, a crypto bankruptcy claims exchange that also failed and shut down in early 2024.

avoid.net/justin-sun7/100[CRITICAL]

Justin Sun is the founder of the TRON blockchain and TRX token, and the controlling figure behind HTX (formerly Huobi) and Poloniex exchanges. In March 2023, the U.S. Securities and Exchange Commission charged Sun and three of his companies with fraud, market manipulation through wash trading, unregistered securities offerings, and orchestrating an undisclosed celebrity promotion scheme; the case partially settled in March 2026 with Rainberry Inc. paying a $10 million penalty while claims against Sun personally were dismissed. Sun has faced additional scrutiny including a reported FBI/DOJ criminal investigation, UK sanctions against an HTX entity over alleged Russia-linked transactions, a $114 million hot-wallet hack at Poloniex in November 2023, and disputed claims of diplomatic immunity through a Grenada WTO ambassadorship he held until mid-2022.

avoid.net/curve-finance62/100[CAUTIONARY]

Curve Finance is a major decentralized exchange (DEX) on Ethereum optimized for stablecoin and pegged-asset trading, operating since January 2020. On July 30, 2023, a latent vulnerability in the Vyper smart-contract compiler (versions 0.2.15, 0.2.16, and 0.3.0) was exploited across multiple Curve liquidity pools, draining approximately $70 million and triggering a near-systemic crisis when the resulting CRV price drop threatened to cascade-liquidate founder Michael Egorov's heavily collateralized on-chain loans. Roughly 73% of stolen funds were ultimately recovered or returned, and in December 2023 the Curve DAO voted to disburse approximately $49 million in compensation to affected liquidity providers.

avoid.net/changpeng-zhao8/100[CRITICAL]

Changpeng Zhao (CZ), born February 10, 1977, is the founder and former CEO of Binance, the world's largest cryptocurrency exchange by trading volume. On November 21, 2023, Zhao pleaded guilty to a federal charge of failing to implement an effective anti-money laundering (AML) program under the Bank Secrecy Act, as part of a landmark $4.3 billion resolution between Binance and U.S. federal regulators. He was sentenced to four months in federal prison in April 2024, served that term, and was subsequently pardoned by President Donald Trump in October 2025.

avoid.net/sinbad-io2/100[CRITICAL]

Sinbad.io was a Bitcoin mixing service that operated from October 2022 until its seizure by U.S., Dutch, and Finnish law enforcement in November 2023. OFAC designated it a key money-laundering tool of North Korea's Lazarus Group, which used it to launder proceeds from multiple major crypto hacks including Axie Infinity's Ronin Bridge and Atomic Wallet. On-chain analytics firms assessed it to be highly likely a rebranding of Blender.io, the first crypto mixer ever sanctioned by OFAC.

avoid.net/gate32/100[WARNING]

Gate.io (formerly Bter.com) is a centralized cryptocurrency exchange founded in 2013 by Han Lin, serving over 30 million users across 224 countries. The exchange has been flagged by on-chain investigator ZachXBT for allegedly concealing a $230 million hack attributed to North Korean state-sponsored hackers (Lazarus Group) that occurred in April 2018 and was never publicly disclosed to users. Additional concerns include a manipulated futures price feed incident causing millions in user losses in 2025, an AML-based ban by India's Financial Intelligence Unit in 2024, persistent user complaints about frozen withdrawals, and alleged wash trading activity inflating reported volumes.

avoid.net/dforce-lending28/100[WARNING]

dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.

avoid.net/roll32/100[WARNING]

Roll (tryroll.com) is an Ethereum-based social token infrastructure platform that allows creators to mint, distribute, and manage branded personal tokens. On March 14, 2021, Roll suffered a critical security breach in which an attacker compromised the private keys of its hot wallet and liquidated approximately $5.7 million worth of social tokens across 42 different creator tokens, routing stolen ETH through Tornado Cash. Roll subsequently upgraded its security infrastructure via a Fireblocks MPC integration and raised a $10M Series A in September 2021, but the root cause of the private key compromise was never publicly confirmed.

avoid.net/aperocket22/100[CRITICAL]

ApeRocket is a DeFi yield farming aggregator and optimizer originally deployed on Binance Smart Chain (BSC) and Polygon in 2021. The protocol suffered two simultaneous flash loan exploits on July 14, 2021, resulting in combined losses of approximately $1.26 million and a 63% collapse in its native SPACE token price. The project attempted a V2 relaunch with improved security, but the SPACE token currently shows zero trading volume and effectively zero market capitalization, indicating the protocol is inactive.

avoid.net/xtoken10/100[CRITICAL]

xToken (XTK) was a DeFi protocol offering wrapped staking tokens and liquidity management on Ethereum, founded by Michael J. Cohen in 2020. The protocol suffered two major flash loan exploits in 2021 — a $24.5 million attack in May and a $4.5 million attack in August — resulting in total losses exceeding $29 million and the permanent retirement of its flagship xSNX product. The XTK governance token subsequently lost approximately 99.84% of its value, and compensation paid to victims was significantly below the amounts stolen.

avoid.net/cream-lending0/100[CRITICAL]

C.R.E.A.M. Finance (Crypto Rules Everything Around Me) is a decentralized lending and borrowing protocol launched in August 2020, forked from Compound Finance. The protocol suffered three major exploits in 2021 totaling approximately $185 million in losses, making it one of the most frequently and severely hacked DeFi protocols in history. On-chain investigator ZachXBT flagged the protocol and its founders, and the CREAM token has collapsed more than 99% from its all-time high.

avoid.net/vee-finance12/100[CRITICAL]

Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.

avoid.net/compound-v228/100[WARNING]

Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.

avoid.net/badger-dao10/100[CRITICAL]

Badger DAO is a decentralized autonomous organization and DeFi protocol launched in December 2020 focused on generating yield on Bitcoin-backed assets via Ethereum-based vaults. In December 2021, a front-end attack exploiting a compromised Cloudflare API key resulted in approximately $120–130 million in user funds being drained across roughly 500 wallets. As of 2025, the protocol has seen significant decline: its flagship eBTC product was sunset, BADGER was delisted from Binance, and total value locked has fallen to low single-digit millions.

avoid.net/vulcan-forged28/100[WARNING]

Vulcan Forged is a UK-based blockchain gaming studio and NFT marketplace operating on Polygon and its own Elysium Layer-1 blockchain, best known for VulcanVerse and its native PYR token. In December 2021 the platform suffered one of the largest gaming-sector hacks on record: an attacker exploited Vulcan Forged's servers to extract private keys from 96 semi-custodial wallets, stealing approximately 4.5 million PYR tokens then valued at roughly $140 million. The platform subsequently refunded affected users from its treasury and pledged to migrate to non-custodial wallets, but the incident exposed fundamental centralization and custodial risks in its architecture.

avoid.net/moola-market28/100[WARNING]

Moola Market is a decentralized lending protocol built on the Celo blockchain, founded in 2020 by Patrick Baron and backed by Polychain Capital. In October 2022, the protocol suffered a price manipulation exploit draining approximately $9.1 million, making it one of the largest DeFi incidents on Celo; over 93% of funds were returned by the attacker within hours in exchange for a roughly $500,000 bounty. The protocol subsequently relaunched with reduced collateral thresholds, but its TVL and MOO token value have declined sharply since the incident.

avoid.net/phemex10/100[CRITICAL]

Phemex is a centralized cryptocurrency derivatives exchange founded in November 2019 by former Morgan Stanley executives and registered in the British Virgin Islands. In January 2025, the exchange suffered one of the largest crypto hacks of that year, with an estimated $69–85 million drained from hot wallets across 16 blockchains, subsequently attributed to North Korea's Lazarus Group through on-chain evidence linking the same wallets to the February 2025 Bybit hack. Phemex has also faced formal regulatory enforcement actions in Ontario, Canada, and operates without authorization in the United Kingdom.

avoid.net/zksync57/100[CAUTIONARY]

ZKsync is an Ethereum Layer 2 scaling protocol built on zero-knowledge rollup technology, developed by Matter Labs, which has raised approximately $458 million in venture capital. The protocol has faced multiple significant controversies including a $5 million airdrop contract exploit in April 2025, a contentious 2024 token airdrop marred by sybil attack failures and community backlash, a South Korean regulatory probe into alleged price manipulation, compromised social media accounts spreading false SEC investigation claims, and an intellectual property theft lawsuit filed against Matter Labs by defunct firm BANKEX. User funds in the core protocol have not been directly compromised, but the pattern of incidents has substantially eroded community trust.

avoid.net/kinto-bridge28/100[WARNING]

Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.

avoid.net/electrum62/100[CAUTIONARY]

Electrum is an open-source, non-custodial Bitcoin wallet first released in November 2011 by Thomas Voegtlin and maintained by Electrum Technologies GmbH. It is widely regarded as one of the most feature-rich and long-standing Bitcoin desktop wallets, but has been the persistent target of large-scale phishing campaigns exploiting its open peer network architecture, resulting in more than $25 million in user losses documented between 2018 and 2020.

avoid.net/athena-bitcoin22/100[CRITICAL]

Athena Bitcoin, Inc. (OTC: ABIT) is one of the largest Bitcoin ATM (BTM) operators in the United States, with approximately 3,600–4,100 kiosks across 29 states and five countries. The company faces multiple active lawsuits, including a September 2025 action by the Washington, D.C. Attorney General alleging that 93% of deposits into its D.C.-area kiosks were tied to fraud and that the company charged undisclosed fees of up to 26% per transaction while refusing refunds to scam victims. Athena disputes the allegations and states it employs robust consumer-protection protocols; as of the investigation date, no court has adjudicated the merits of these claims.

avoid.net/sality-botnet-eggjagger-crypto-clipboard-stealer2/100[CRITICAL]

Sality is a long-running malware family and peer-to-peer botnet first discovered in 2003, attributed by CrowdStrike to a Russia-based eCrime group tracked as SALTY SPIDER. For at least the eight years preceding its disruption, the botnet's primary payload was EggJagger, a clipboard-hijacking tool that silently replaced cryptocurrency wallet addresses on infected machines with attacker-controlled addresses. On August 31, 2026, a coordinated operation involving the U.S. Department of Justice, FBI, international law enforcement from Bulgaria, Hungary, and Romania, CrowdStrike, and the Shadowserver Foundation severed more than 15,000 infected machines from the botnet's infrastructure via a peer-to-peer sinkholing operation, though no arrests were announced and malware already installed on compromised machines remained active pending manual remediation.

avoid.net/rain-financial-crypto-card-infrastructure58/100[CAUTIONARY]

Rain (legal entity: Signify Holdings, Inc.) is a New York-headquartered fintech company founded in 2021 that provides stablecoin-powered card issuing and payments infrastructure to enterprises, neobanks, and developers. The company is a Visa and Mastercard Principal Member, serves over 200 enterprise partners, and processed roughly $3 billion in annualized transactions as of early 2026. In August 2026, an authorization flaw in an outdated Rain Solana smart contract was exploited, draining approximately $1.1 million from card-collateral accounts across multiple partner programs; Rain upgraded all affected contracts and partner programs reimbursed affected users in full.

avoid.net/outsider-enterprise2/100[CRITICAL]

Outsider Enterprise is a China-based phishing-as-a-service operation, attributed by researchers to a threat actor known as ChenLun, that sold subscription-based phishing kits through a Telegram bot since at least July 2023. On June 12, 2026, Google filed a civil RICO and Lanham Act lawsuit against 25 Doe defendants (case No. 1:26-cv-04982-VM, S.D.N.Y.), and the FBI announced Operation Ghost Hook the following day, seizing domains and approximately $100,000 from the operation's payment wallets. The FBI's Cyber Division has linked the platform to an estimated $1.9 billion in losses and approximately 3.87 million compromised payment card numbers; post-takedown research published September 3, 2026 found the affiliate network remained active with over 700 new phishing domains identified after the enforcement action.

avoid.net/pancakebunny18/100[CRITICAL]

PancakeBunny was a Binance Smart Chain yield aggregator and optimizer built by a team known as Mound, launched in December 2020. The protocol suffered two major flash loan exploits in 2021: a May 20, 2021 attack that caused the BUNNY token to crash over 95% and wiped out approximately $200 million in market capitalization, and a July 16, 2021 attack on its Polygon fork PolyBunny that resulted in $2.4 million in losses. Both exploits stemmed from oracle price manipulation vulnerabilities in the minting reward logic, and the protocol has never recovered to its pre-exploit state.

avoid.net/euler-finance58/100[CAUTIONARY]

Euler Finance is an Ethereum-based non-custodial lending protocol founded in 2020 by Michael Bentley (PhD, Oxford) that pioneered permissionless lending for long-tail ERC-20 assets. On March 13, 2023, the protocol suffered a ~$197 million flash loan exploit — the largest DeFi hack of 2023 — caused by a missing health check in the donateToReserves() function. In an unusual outcome, the attacker, who communicated under the alias 'Jacob,' returned approximately $240 million in assets (including ETH price appreciation) over three weeks following on-chain negotiations, enabling full user restitution. The protocol relaunched as Euler V2 in September 2024 with a modular architecture, 45+ security audits, and subsequently grew TVL to over $1.5 billion by early 2025.

avoid.net/bnb-chain-bridge16/100[CRITICAL]

The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.

avoid.net/transit-finance2/100[CRITICAL]

Transit Finance (also known as Transit Swap) is a cross-chain DEX aggregator supporting over 122 decentralized exchanges across Ethereum, BNB Chain, TRON, Solana, Polygon, and other networks. The protocol has suffered two confirmed security exploits: a $28.9 million hack in October 2022 due to an arbitrary external call vulnerability in its routing contract, with approximately $18.9 million recovered; and a second $1.88 million exploit in May 2026 via a deprecated TRON smart contract that remained on-chain and exploitable years after official deprecation. ZachXBT flagged the protocol amid broader DeFi monitoring, and the 2022 attacker routed funds through OFAC-sanctioned Tornado Cash.

avoid.net/ranger-finance22/100[CRITICAL]

Ranger Finance was a Solana-based perpetual contract aggregator that raised $1.9M in seed funding in January 2025 and launched its RNGR token in January 2026. Within two months of token launch, community governance voted to liquidate the project treasury following allegations that the team made materially misleading claims about trading volume and revenue during its ICO. The project formally shut down in May 2026 after the treasury liquidation and approximately $900,000 in exposure from the DPRK-linked Drift Protocol exploit left operations unsustainable, with employees and vendors not fully compensated.

avoid.net/cover-protocol18/100[CRITICAL]

Cover Protocol was a decentralized insurance marketplace on Ethereum, launched in November 2020 after a troubled rebrand from the failed SAFE token project. On December 28, 2020, a critical smart contract vulnerability in its Blacksmith farming contract allowed an attacker to mint approximately 40 quintillion COVER tokens and extract over $4 million in assets, crashing the token price by more than 97%. After a failed merger with Yearn Finance and the abrupt departure of core developers, the protocol permanently shut down on September 5, 2021, distributing remaining treasury funds to token holders.

avoid.net/paid-network12/100[CRITICAL]

PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.

avoid.net/bunny10/100[CRITICAL]

PancakeBunny (Bunny Finance) was a Binance Smart Chain yield-optimizer developed by the anonymous team MOUND (Mound Inc.), which received a $1.6 million seed round led by Binance Labs in April 2021. The protocol suffered three separate exploits across 2021–2022 totaling over $127 million in losses, including a $45 million flash loan attack in May 2021, a $2.4 million polyBUNNY exploit on Polygon in July 2021, and an $80 million hack of its affiliated lending protocol Qubit Finance in January 2022. The BUNNY token has lost more than 99% of its all-time high value, the protocol transitioned to a DAO structure in early 2022, and no stolen funds from any exploit were publicly confirmed as recovered.

avoid.net/belt-finance28/100[WARNING]

Belt Finance (belt.fi) is a multi-strategy yield aggregator and stableswap AMM built primarily on Binance Smart Chain (BSC), developed by South Korean blockchain firm Ozys. On May 29, 2021, the protocol was exploited via a flash loan attack that netted the attacker approximately $6.23 million in BUSD and caused an estimated $50 million in total pool losses. The protocol announced a phased compensation plan for affected users but full repayment status remains unverified; the protocol has continued operating in diminished form, with current TVL of approximately $12 million as of 2025.

avoid.net/popsicle-finance12/100[CRITICAL]

Popsicle Finance is a cross-chain automated yield optimization protocol, launched in March 2021, that suffered a critical $20.7 million exploit in August 2021 due to a reward-tracking vulnerability in its Sorbetto Fragola pools. The protocol is part of Daniele Sestagalli's 'Frog Nation' ecosystem alongside Wonderland (TIME) and Abracadabra Money (MIM), which was later engulfed in a major scandal when the treasury manager of Wonderland was revealed to be Michael Patryn, a convicted felon and co-founder of the fraudulent QuadrigaCX exchange. The project subsequently rebranded as WAGMI in 2023 but remains a high-risk entity given the severity of the 2021 exploit, the laundering of stolen funds through Tornado Cash, and the broader Frog Nation governance failures.

avoid.net/baton-corporation-ltd-pump-fun12/100[CRITICAL]

Baton Corporation Ltd is the UK-incorporated company that owns and operates Pump.fun, the dominant Solana-based memecoin launchpad launched in January 2024. The company and its three named founders — Noah Tweedale, Alon Cohen, and Dylan Kerler — are defendants in a live federal RICO class action in the Southern District of New York (Aguilar v. Baton Corporation Ltd., 1:25-cv-00880-CM) after Judge Colleen McMahon allowed wire fraud, illegal gambling, and unlicensed money transmission claims to proceed following a motion-to-dismiss ruling issued August 31, 2026. The platform has also received a formal regulatory warning from the UK Financial Conduct Authority and had its iOS app delisted from U.S. and Indian App Stores in September 2026.

avoid.net/coldcard-coinkite42/100[WARNING]

Coldcard is a Bitcoin-only hardware wallet manufactured by Toronto-based Coinkite, founded in 2013 by Rodolfo Novak and Peter Gray. The device held a strong community reputation for security-focused design, open-source firmware, and air-gapped operation until a firmware bug introduced in March 2021 was exploited beginning July 30, 2026, resulting in approximately $116 million in Bitcoin losses across more than 5,200 addresses. Coinkite has acknowledged the vulnerability, issued patched firmware, and suspended data deletion in anticipation of litigation; class-action proceedings had been threatened but not yet filed as of September 2026.

avoid.net/mango-markets12/100[CRITICAL]

Mango Markets was a Solana-based decentralized trading platform offering spot trading, perpetual futures, and lending with cross-margining. In October 2022, trader Avraham Eisenberg executed an oracle manipulation attack, draining approximately $116–117 million from the protocol through artificially inflated MNGO collateral. The protocol subsequently faced enforcement actions from the DOJ, SEC, and CFTC, settled with regulators in 2024, and formally shut down in January 2025.

avoid.net/genesis-global8/100[CRITICAL]

Genesis Global Capital, LLC was the institutional crypto lending subsidiary of Digital Currency Group (DCG), founded in 2018 as an extension of Genesis Global Trading. Following cascading losses from Three Arrows Capital's June 2022 default and FTX's November 2022 collapse, Genesis halted customer withdrawals on November 16, 2022 and filed for Chapter 11 bankruptcy on January 19, 2023, with liabilities estimated between $1 billion and $10 billion owed to over 100,000 creditors. The entity faced multiple regulatory actions including SEC charges for unregistered securities offerings, a New York Attorney General fraud lawsuit naming DCG CEO Barry Silbert by name, and a separate 2025 SEC settlement against DCG and former Genesis CEO Soichiro Moro for misleading investors about Genesis's financial condition.

avoid.net/beanstalk-farms28/100[WARNING]

Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.

avoid.net/the-dao10/100[CRITICAL]

The DAO was a decentralized autonomous organization launched on the Ethereum blockchain in April 2016 that raised approximately $150 million in Ether — the largest crowdfunding to date at the time — before being drained of 3.6 million ETH (roughly $50–60 million) on June 17, 2016, via a reentrancy vulnerability in its smart contract code. The hack triggered an acrimonious debate over blockchain immutability and led to a contentious hard fork of the Ethereum network on July 20, 2016, splitting it into Ethereum (ETH) and Ethereum Classic (ETC). In 2017 the U.S. SEC concluded that DAO tokens constituted unregistered securities, marking a landmark regulatory precedent for the entire crypto industry.

avoid.net/bondly22/100[CRITICAL]

Bondly Finance is a DeFi and NFT protocol launched in September 2020 that suffered a major exploit on July 14-15, 2021, in which 373 million BONDLY tokens were minted via owner-level credentials and sold into liquidity pools, causing an 82% token price collapse and approximately $5.9-7.5 million in losses. The exploit originated from the protocol owner's address, prompting blockchain security firm PeckShield to allege a potential rug pull, though the team attributed it to compromised credentials belonging to CEO Brandon Smith. Following acquisition by Animoca Brands in September 2021 and a rebrand to Forj in May 2022, the project has undergone significant leadership changes; the original founder departed under a cloud of unresolved questions about the exploit's true origin.

avoid.net/beanstalk12/100[CRITICAL]

Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.

avoid.net/yield-protocol38/100[WARNING]

Yield Protocol was a decentralized finance protocol offering fixed-rate, fixed-term borrowing and lending on Ethereum and Arbitrum, launched in October 2020 and funded by Paradigm. It suffered multiple security incidents including collateral damage from the March 2023 Euler Finance hack and a critical smart contract vulnerability patched via Immunefi in April 2023, before announcing a full wind-down in October 2023 citing insufficient demand and regulatory pressure. After official operations ceased in December 2023, abandoned smart contracts on Arbitrum were exploited in April 2024 for approximately $181,000 via a flash loan attack on pool balance discrepancies.

avoid.net/blessed-trust-hexa-whale2/100[CRITICAL]

Blessed Trust Limited and Hexa Whale Trading Limited are two Hong Kong-incorporated entities that U.S. federal prosecutors allege served as the central laundering vehicles for over $1.5 billion in proceeds from sanctioned Iranian crude oil and petroleum sales. On September 14, 2026, the U.S. Attorney's Office for the Southern District of New York filed a civil forfeiture complaint (case 1:26-cv-08010) seeking $61,192,367.59 USDT frozen across ten TRON addresses, with Tether having already frozen those assets in June and July 2025. The allegations, which remain unproven in court, describe both entities routing funds through Binance accounts to IRGC-linked money-services businesses and the Iranian exchange Nobitex; Binance offboarded both companies and is not named as a defendant.

avoid.net/coinw60/100[CRITICAL]

CoinW6 is a fraudulent cryptocurrency trading platform at the center of the SEC's first-ever enforcement action targeting a pig butchering (relationship investment) scam, filed September 17, 2024 in the U.S. District Court for the Central District of California (Case No. 2:24-cv-07924). According to the SEC's complaint, operators of CoinW6 posed as wealthy professionals on LinkedIn and Instagram, cultivated romantic relationships with victims over WhatsApp, then directed at least 11 investors to a fake trading interface that displayed fabricated returns, stealing approximately $2.2 million between July 2022 and December 2023. As of mid-2026, the case remains pending, with the SEC seeking service by publication after defendants failed to appear.

avoid.net/chipmixer0/100[CRITICAL]

ChipMixer was a darknet Bitcoin mixing service that operated from August 2017 to March 2023, processing over $3 billion in illicit cryptocurrency on behalf of ransomware groups, North Korean state hackers, Russian military intelligence, and darknet drug markets. On March 15, 2023, U.S. and German authorities seized its infrastructure, domains, and approximately $46 million in cryptocurrency in a coordinated international takedown. Minh Quoc Nguyen, 49, a Vietnamese national residing in Hanoi, was charged in the Eastern District of Pennsylvania with money laundering, operating an unlicensed money transmitting business, and identity theft; he remains a fugitive.

avoid.net/acala-network32/100[WARNING]

Acala Network is a Polkadot-native DeFi hub offering a multi-collateralized stablecoin (aUSD), liquid staking, and an AMM DEX. On August 14, 2022, a misconfiguration in a newly deployed liquidity pool caused 3.022 billion aUSD to be erroneously minted, triggering a 99% depeg; approximately 98% of the erroneous tokens were subsequently recovered and burned via community governance votes. The incident raised significant concerns about the protocol's claimed decentralization after the team unilaterally placed the network in maintenance mode and froze token transfers without an on-chain vote.

avoid.net/sovryn38/100[WARNING]

Sovryn is a Bitcoin-backed decentralized finance protocol built on the Rootstock (RSK) sidechain, offering lending, borrowing, margin trading, and AMM services with its native SOV governance token. The protocol suffered a confirmed $1.1 million price manipulation exploit in October 2022 targeting its legacy lending pools, with approximately half of funds recovered via developer intervention. A separate critical smart contract vulnerability was disclosed via bug bounty in March 2021 but was not exploited. ZachXBT has flagged the entity; no detailed public post from ZachXBT specifically detailing Sovryn allegations was independently located at time of investigation.

avoid.net/htx28/100[WARNING]

HTX (formerly Huobi Global) is one of the world's largest cryptocurrency exchanges, rebranded in September 2023 following the de facto acquisition of Huobi by interests linked to Justin Sun in late 2022. The exchange has suffered at least three significant security incidents totaling over $130 million in losses since September 2023, and in May 2026 was sanctioned by the UK government for alleged facilitation of Russian sanctions evasion — the first such crypto-exchange designation under the UK Russia sanctions framework. HTX also faces FCA legal proceedings over illegal financial promotions to UK consumers, has withdrawn its Hong Kong licensing applications twice, and has been publicly criticized for opaque reserve practices.

avoid.net/fixedfloat10/100[CRITICAL]

FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.

avoid.net/layerzero-executor-wallet-incident-july-202662/100[CAUTIONARY]

On July 15, 2026, security firm PeckShield and on-chain analyst Specter reported that LayerZero executor wallets appeared to have been drained of approximately $2.4 million across eight blockchain networks. LayerZero Core responded the same day, stating the transfers were routine internal inventory rebalancing and that no exploit had occurred and no user funds were at risk. The incident was not independently confirmed as a security breach, and as of the date of this investigation LayerZero's denial has not been publicly contradicted by on-chain forensic analysis or a third-party post-mortem.

avoid.net/sheldon-xia22/100[CRITICAL]

Sheldon Xia is the founder of BitMart, a cryptocurrency exchange he launched in 2017 and led as CEO until April 2025, when he assumed the role of Group President. BitMart suffered a $196 million hot-wallet hack in December 2021; Xia publicly pledged full compensation from company funds but victims reported they had not been repaid as of early 2022. In July 2026 BitMart announced it would shut down, and the closure has been accompanied by reports of frozen user withdrawals, unpaid employee wages, and demands for reserve disclosures that Xia has disputed as based on fabricated information.

avoid.net/zondacrypto-collapse2/100[CRITICAL]

Zondacrypto (operated by BB Trade Estonia OÜ, formerly BitBay) was one of Poland's largest cryptocurrency exchanges before its 2026 collapse. On-chain analysis published in April 2026 showed the exchange's operational Bitcoin reserves had fallen by roughly 99.7% since mid-2024, the site went offline that month, and both the exchange's founder and its later CEO became unreachable. Estonia's financial regulator revoked the company's licence in June 2026, a Tallinn court declared it bankrupt on August 27, 2026, and Polish prosecutors opened a fraud investigation estimating customer losses near 350 million zloty (approximately $94-97 million) affecting an estimated 30,000 or more people.

avoid.net/tria42/100[WARNING]

Tria is a self-custodial Solana-based neobank founded in 2022 by Vijit Katta and Parth Bhalla that raised $12 million in pre-seed and strategic funding in October 2025. On August 28, 2026, an attacker exploited an authorization-bypass vulnerability in an outdated Rain Solana card contract shared across multiple neobank products, draining $431,945 from 636 Tria card users. Tria pledged full refunds plus a 10% bonus to affected users; its native token fell more than 10% following public disclosure. The incident did not affect user self-custodial wallets — only card-collateral balances staged for spending were compromised.

avoid.net/radoslaw-piesiewicz20/100[CRITICAL]

Radoslaw Piesiewicz (born February 20, 1981) is a Polish sports administrator who has served as president of the Polish Olympic Committee (PKOl) since 2023. On August 27, 2026, he was detained by Poland's Central Bureau for Combating Cybercrime in connection with a criminal investigation into the collapsed cryptocurrency exchange Zondacrypto. A Polish court subsequently ordered him held for three months pending the investigation; as of the date of this report, formal charges had not been publicly filed and no conviction has been entered.

avoid.net/przemyslaw-kral4/100[CRITICAL]

Przemyslaw Kral is the former CEO of Zondacrypto (formerly BitBay), Poland's largest cryptocurrency exchange, which collapsed in April 2026 amid a criminal fraud investigation. Polish prosecutors charged Kral with alleged participation in large-scale fraud and money laundering in connection with estimated customer losses ranging from approximately 350 million zloty ($97 million) to as much as 2.4 billion zloty ($650 million) according to later prosecutor estimates, affecting approximately 30,000 users. Kral departed Poland for Israel in April 2026 and holds dual Polish-Israeli citizenship; as of September 2026 he has reportedly been cooperating with prosecutors, though his precise location and formal legal status remain subjects of conflicting and unconfirmed reporting.

avoid.net/tectonic-cronos-august-2026-tonic-price-manipulation-exploit18/100[CRITICAL]

On August 30, 2026, an unknown attacker manipulated the price of TONIC — the thinly traded governance token of Tectonic, the dominant lending protocol on the Cronos blockchain — by approximately 100-fold in roughly 20 minutes, then deposited the artificially inflated tokens as collateral and borrowed an estimated $75 million in liquid assets from the protocol's pools. Cronos validators halted all block production network-wide within minutes, freezing approximately $68.7 million on-chain; roughly $6 million had already been bridged to Ethereum before the halt and could not be recovered by rollback. Validators subsequently rolled the chain back to its pre-attack state — discarding approximately 11,000 blocks and reversing nearly two hours of third-party transactions — and resumed block production at block 90,896,189 (23:49:01 UTC, August 30). As of September 1, 2026, no compensation plan, final loss figure, or formal post-mortem had been published by Tectonic or Cronos Labs.

avoid.net/cronos-chain26/100[WARNING]

Cronos is an EVM-compatible blockchain developed by Crypto.com and operated by Cronos Labs, running a capped, invitation-only validator set. On August 30, 2026, validators halted block production and executed a full chain rollback after a price-manipulation exploit drained an estimated $75 million from Tectonic, the chain's dominant lending protocol; the rollback erased approximately two hours of transaction history network-wide and recovered most of the stolen funds on-chain, while roughly $6.29 million that had already been bridged to Ethereum was not recovered. The incident reignited longstanding debates about immutability, validator centralization, and the degree of operational control Crypto.com holds over the network.

avoid.net/the-sandbox-sand-oft-exploit34/100[WARNING]

On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.

avoid.net/the-sandbox-sand-bridge-exploit38/100[WARNING]

On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.

avoid.net/bit-com62/100[CAUTIONARY]

Bit.com was a cryptocurrency derivatives exchange operated by Matrixport, a Singapore-headquartered digital asset financial services firm founded by Bitmain co-founder Jihan Wu. The exchange launched in August 2020 and achieved a top-two global ranking in Bitcoin options volume before conducting an orderly, phased shutdown completed March 31, 2026, citing business restructuring. No fraud allegations, regulatory enforcement actions, or user fund losses have been identified against the exchange itself; the parent company Matrixport rebranded as BIT in March 2026 and continues operating under multiple licensed jurisdictions.

avoid.net/zondacrypto2/100[CRITICAL]

Zondacrypto (operating entity: BB Trade Estonia OÜ), formerly known as BitBay and once Poland's largest cryptocurrency exchange, was declared bankrupt by the Harju County Court in Tallinn on August 27, 2026 after CEO Przemyslaw Kral departed to Israel in April 2026 and an on-chain forensic analysis found the exchange's hot-wallet Bitcoin reserves had fallen by approximately 99.7 percent. Polish prosecutors have opened a criminal fraud investigation, with estimated customer losses of roughly 350 million PLN (approximately $82–97 million) affecting up to 30,000 users who cannot access their funds. The collapse also triggered the arrest of Polish Olympic Committee president Radoslaw Piesiewicz on bribery allegations and the bankruptcy of affiliated fintech Femion Technology.

avoid.net/voltage-finance15/100[CRITICAL]

Voltage Finance (formerly FuseFi) is a decentralized finance protocol operating on the Fuse Network, offering token swapping, lending, liquidity farming, and cross-chain bridging via an automated market maker. The protocol has been the subject of two confirmed security exploits: a March 2022 reentrancy attack that drained approximately $4.67 million from its lending pools via a third-party partner (Ola Finance), and a March 2025 insider-related exploit of its Simple Staking pools resulting in approximately $322,000 in losses. No funds were recovered in either incident as of the time of this investigation.

avoid.net/yearn-dai-vault62/100[CAUTIONARY]

On February 4, 2021, an attacker exploited Yearn Finance's v1 yDAI vault using a multi-protocol flash loan to manipulate exchange rates in Curve Finance's 3pool, causing approximately $11 million in vault losses while the attacker personally profited roughly $2.8 million. Yearn Finance's security team contained the exploit within eleven minutes, preserving $24 million of the vault's $35 million under management. Yearn subsequently reimbursed affected depositors by minting 9.7 million DAI against YFI collateral in a MakerDAO vault, with the intent to repay the debt from ongoing protocol revenue.

avoid.net/cetus-protocol28/100[WARNING]

Cetus Protocol is a concentrated liquidity market maker (CLMM) decentralized exchange deployed on the Sui and Aptos blockchains. On May 22, 2025, the protocol suffered one of the largest DeFi exploits in history when an attacker exploited an integer overflow vulnerability in its smart contract math library to drain approximately $223 million from liquidity pools. Roughly $162 million was frozen on-chain through emergency validator action by the Sui network, and following a governance vote the protocol relaunched in June 2025 with partial user compensation.

avoid.net/blender-io0/100[CRITICAL]

Blender.io was a Bitcoin mixing service that operated from approximately 2018 to 2022, processing over $500 million in Bitcoin before being shut down. On May 6, 2022, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated it as a Specially Designated National, marking the first time a virtual currency mixer had ever been sanctioned by the United States government. The service was designated for its role in laundering over $20.5 million in proceeds from North Korea's Lazarus Group following the $620 million Ronin Network hack, as well as for processing funds tied to Russian ransomware groups and the Hydra darknet market.

avoid.net/coincheck38/100[WARNING]

Coincheck is a Tokyo-based cryptocurrency exchange that suffered what was, at the time, the largest cryptocurrency hack in history on January 26, 2018, when approximately 523 million NEM (XEM) tokens valued at roughly $534 million were stolen from a low-security hot wallet. The exchange was operating without a Financial Services Agency (FSA) license at the time of the breach, had failed to implement standard multisignature security for NEM holdings, and received multiple business improvement orders from Japanese regulators in the aftermath. Coincheck was subsequently acquired by Monex Group in April 2018, obtained its FSA license in January 2019, and listed on the Nasdaq in December 2024 via a SPAC merger under the ticker CNCK.

avoid.net/harvest-finance22/100[CRITICAL]

Harvest Finance is a decentralized yield-aggregation protocol (token: FARM) that suffered a landmark $33.8 million flash loan-based price manipulation attack on October 26, 2020, one of the largest DeFi exploits of that year. Pre-attack, the protocol held over $1 billion in TVL while being governed by a single anonymous admin key—a concentration of power flagged by multiple security auditors and researchers. The protocol continues to operate with substantially reduced TVL (~$12 million as of 2025), though the stolen funds were never recovered and the attacker was never publicly identified or charged.

avoid.net/pickle10/100[CRITICAL]

Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.

avoid.net/compounder-finance2/100[CRITICAL]

Compounder Finance was an Ethereum-based DeFi yield aggregator that launched in November 2020 and executed a deliberate rug pull approximately 22 days later, stealing between $10.8 million and $12.5 million from investors. Anonymous developers embedded hidden 'Evil Strategy' smart contracts behind a publicly visible but unmonitored 24-hour timelock, then drained all user funds and deleted the project's website and social media accounts. No funds were recovered and the perpetrators have never been publicly identified.

avoid.net/yearn-finance58/100[CAUTIONARY]

Yearn Finance is a decentralized yield aggregator on Ethereum that routes user deposits into lending protocols to maximize returns. Founded by Andre Cronje in 2020, the protocol has suffered at least four documented security exploits between 2021 and 2025, with aggregate losses exceeding $20 million, and its founder departed in 2022 citing sustained pressure from an SEC investigation. Governance concerns, an interconnected web of affiliated DeFi protocols implicated in their own major hacks, and repeated failures to deprecate vulnerable legacy code compound the protocol's risk profile.

avoid.net/bitmart12/100[CRITICAL]

BitMart is a centralized cryptocurrency exchange founded in 2017 by Sheldon Xia and headquartered in the Cayman Islands. In December 2021, the exchange suffered one of the largest centralized exchange hacks on record, with approximately $196 million stolen from two hot wallets after a private key was compromised. In July 2026, BitMart announced a full wind-down of operations; the shutdown has since been accompanied by widespread reports of frozen customer withdrawals, the formation of a creditors committee, and an ongoing restructuring process that remains unresolved as of September 2026.

avoid.net/grim-finance8/100[CRITICAL]

Grim Finance was a Fantom-based DeFi yield optimizer (fork of Beefy Finance) that suffered a devastating reentrancy exploit on December 19, 2021, resulting in approximately $30 million in user funds stolen. The vulnerability — a missing reentrancy guard in the depositFor() function — had existed in an audited codebase and was classified by security researchers as an entirely preventable, well-understood attack class. The protocol has since collapsed to a near-zero TVL of roughly $29,000 and its proposed compensation plan yielded no meaningful restitution for affected users.

avoid.net/ola-finance28/100[WARNING]

Ola Finance is a multi-chain decentralized lending protocol offering a 'lending-as-a-service' platform that allows third parties to deploy isolated Compound-style lending pools across multiple blockchains. On March 31, 2022, the protocol's deployment on the Fuse Network was exploited via a reentrancy vulnerability in ERC677 token logic, resulting in approximately $4.67 million in stolen assets. The attacker used Tornado Cash to obscure initial funding, laundered proceeds through Ethereum and BNB Chain wallets, and was never publicly identified; a partial compensation plan was offered but fell materially short of full victim restitution.

avoid.net/mango-markets-v310/100[CRITICAL]

Mango Markets V3 was a Solana-based decentralized margin trading protocol that suffered a $116 million oracle manipulation attack in October 2022 executed by Avraham Eisenberg, who artificially inflated the MNGO token price to extract funds against fabricated collateral. The protocol subsequently reached a partial recovery settlement, faced SEC and CFTC enforcement actions, and formally wound down operations by January 2025.

avoid.net/jimbos-protocol18/100[CRITICAL]

Jimbos Protocol was an Arbitrum-based DeFi liquidity protocol designed to provide a semi-stable floor price for its native JIMBO token. On May 28, 2023, just three days after launching its V2, the protocol was exploited via a flash loan attack that drained approximately 4,090 ETH (~$7.5 million) by exploiting a lack of slippage control in the JimboController contract. The attacker rejected a $800,000 bounty offer, laundered the full amount through Tornado Cash, and remains unidentified; no funds have been recovered.

avoid.net/cypher12/100[CRITICAL]

Cypher Protocol was a Solana-based cross-margin decentralized exchange (DEX) and perpetuals trading platform that suffered a critical smart contract exploit in August 2023 resulting in approximately $1 million in losses. Following the exploit, an insider contributor known as 'Hoak' systematically drained over $314,000 from the community redemption fund established to reimburse hack victims, admitting publicly to gambling the funds away. The protocol appears effectively defunct, having failed to deliver meaningful restitution to users who received roughly 31 cents on the dollar from the original exploit fund before that fund itself was embezzled.

avoid.net/huobi28/100[WARNING]

Huobi, rebranded to HTX in September 2023, is a major centralized cryptocurrency exchange founded in 2013 that came under the de facto control of Tron founder Justin Sun in late 2022. The exchange has suffered three significant security incidents since September 2023, faces extensive regulatory non-compliance across multiple jurisdictions, and its proof-of-reserves methodology has been subject to credible allegations of double-counting and asset manipulation by investigative outlets.

avoid.net/munchables10/100[CRITICAL]

Munchables is a Blast-chain NFT game that suffered a $62.5 million exploit on March 26, 2024, when a contractor later attributed to North Korea exploited a backdoor they had embedded in the project's upgradeable smart contracts before launch. The developer surrendered private keys and the full sum was recovered within approximately 24 hours, but the incident exposed fundamental failures in contractor due diligence and smart contract architecture.

avoid.net/dmm-bitcoin52/100[CAUTIONARY]

DMM Bitcoin was a licensed Japanese cryptocurrency exchange operated by DMM Group (DMM.com) that launched in January 2018. In May 2024 it suffered the eighth-largest crypto theft in history when North Korean state-sponsored hackers attributed to the TraderTraitor subgroup of Lazarus Group stole 4,502.9 BTC (approximately $305–308 million USD) through a sophisticated supply-chain attack targeting Ginco, a third-party wallet management provider. Following the hack, Japan's Financial Services Agency issued a business improvement order, the exchange restricted operations, and in December 2024 announced full closure with all customer assets transferred to SBI VC Trade by March 2025.

avoid.net/xt-exchange22/100[CRITICAL]

XT Exchange (XT.com), founded in 2018 and registered in Seychelles, is a centralized cryptocurrency exchange that has been flagged by multiple regulatory authorities — including the UK FCA, Dubai VARA, Thailand SEC, and the Seychelles FSA — for operating without proper licensing. The exchange suffered a $1.7 million hot wallet exploit in November 2024 due to a compromised private key, and has accumulated substantial user complaints alleging unjustified account freezing, asset seizure, and blocked withdrawals. Independent analysis has also raised concerns about inflated trading volumes and inadequate proof-of-reserves transparency.

avoid.net/inverse-finance-frontier10/100[CRITICAL]

Inverse Finance Frontier (originally called Anchor) was a variable-rate lending market on Ethereum operated by Inverse Finance DAO, founded by Nour Haridy in 2020. The protocol suffered two separate oracle manipulation exploits in 2022 — one in April resulting in $15.6 million in losses and a second in June resulting in $5.8 million in bad debt — both attributed to vulnerabilities in how Frontier priced collateral assets. The protocol is now deprecated in favor of Inverse Finance's FiRM fixed-rate market, and the DAO continues to work down residual bad debt from both incidents.

avoid.net/mm-finance-cronos28/100[WARNING]

MM Finance (also known as Mad Meerkat Finance) was the largest decentralized exchange on the Cronos blockchain. On May 4, 2022, the protocol suffered a frontend compromise in which an attacker injected a malicious router contract address, redirecting approximately $2 million in user funds to the attacker's wallet over roughly three hours. The stolen funds were laundered via Tornado Cash and routed through OKX; the team pledged reimbursement via trading fee airdrops, though full recovery of stolen assets was not confirmed. The MMF token subsequently lost approximately 99.9% of its value from its April 2022 all-time high.

avoid.net/wintermute38/100[WARNING]

Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.

avoid.net/crema-finance28/100[WARNING]

Crema Finance is a Solana-based concentrated liquidity market maker (CLMM) DEX protocol that launched in January 2022. On July 2, 2022, the protocol suffered a critical exploit in which an attacker used a fake tick account and flash loans to drain approximately $8.78 million from multiple liquidity pools. Following on-chain negotiations, the attacker returned roughly $7.1 million and retained approximately $1.68 million as an agreed white-hat bounty; Crema subsequently issued a CRM token compensation plan for affected users and submitted a revised codebase for re-audit by SlowMist before reopening.

avoid.net/nomad10/100[CRITICAL]

Nomad was a cross-chain messaging bridge operated by Illusory Systems, Inc. that suffered one of the largest DeFi exploits in history on August 1–2, 2022, when a smart contract initialization bug allowed approximately $190 million in user funds to be drained in a chaotic free-for-all involving over 300 wallet addresses. The protocol never recovered meaningful user adoption after a December 2022 relaunch, faced a class action lawsuit and an FTC enforcement action, and in December 2025 agreed to a settlement requiring repayment of $37.5 million to affected users.

avoid.net/slope-wallet28/100[WARNING]

Slope Wallet (Slope Finance) was a Solana-based mobile cryptocurrency wallet that suffered a catastrophic security breach on August 2, 2022, in which over 9,200 wallets were drained of approximately $4–8 million in assets due to the app transmitting users' unencrypted seed phrases to a third-party telemetry service (Sentry). The root cause was a severe security misconfiguration by Slope Finance, in which the mobile application logged plaintext private key material without proper scrubbing. No formal victim compensation was established, the team declined to publicly accept responsibility, and founder Leal Cheung subsequently launched a new project (zkME) without resolution for affected users.

avoid.net/transit-swap18/100[CRITICAL]

Transit Swap is a cross-chain DEX aggregator incubated by TokenPocket, supporting swaps across Ethereum, BNB Chain, Polygon, Tron, Solana, and other networks. On October 1–2, 2022, an attacker exploited an input validation vulnerability in the platform's swap contract, draining approximately $21–28.9 million in user funds across Ethereum and BNB Chain. The attacker subsequently returned roughly 70% of stolen assets after security firms identified the exploiter's IP address and email, though an estimated 30% of funds — including amounts routed through Tornado Cash — remain unrecovered.

avoid.net/templedao32/100[WARNING]

TempleDAO is a DeFi yield protocol launched on Ethereum in August 2021, designed to offer low-volatility, fractionally backed yields on deposited assets. On October 11, 2022, an associated staking product, STAX Finance, suffered a smart contract exploit due to missing access control on the migrateStake() function, resulting in approximately $2.34 million in stolen funds that were subsequently laundered through Tornado Cash. The core TempleDAO vaults were not directly compromised, but the team's anonymous structure and the unrecovered stolen funds remain notable risk factors.

avoid.net/euler-v110/100[CRITICAL]

Euler Finance V1 was a permissionless DeFi lending protocol on Ethereum that launched in December 2021 and was exploited for approximately $197 million on March 13, 2023, in what was the largest DeFi hack of that year. The attack exploited a missing health check in the donateToReserves function introduced in EIP-14, despite the codebase having undergone multiple external audits. In a highly unusual outcome, the pseudonymous attacker known as 'Jacob' returned all recoverable funds by April 3, 2023, with the total recovered value reaching approximately $240 million due to ETH price appreciation during the recovery period.

avoid.net/kokomo-finance2/100[CRITICAL]

Kokomo Finance was a purported non-custodial lending and borrowing protocol launched on the Optimism blockchain on March 25, 2023. Within approximately 24 hours of launch, its developers executed a deliberate exit scam, stealing approximately $4 to $4.5 million in user funds through smart contract manipulation. The project was subsequently linked by on-chain investigator ZachXBT to a serial scam ring responsible for over $20 million in losses across multiple DeFi protocols.

avoid.net/sushiswap52/100[CAUTIONARY]

SushiSwap is a decentralized exchange (DEX) and DeFi protocol launched in August 2020 as a fork of Uniswap, offering an automated market maker (AMM), governance token (SUSHI), and multi-chain liquidity pools. The protocol has endured a series of serious controversies spanning its entire history: a founding exit-scam attempt by anonymous creator Chef Nomi, early operational control handed to convicted fraudster Sam Bankman-Fried, an SEC subpoena issued to the protocol and its CEO in 2023, a $3.3 million smart contract exploit the same year, allegations that North Korean IT workers were embedded in its developer team, disputed DAO treasury centralization in 2024, and a governance process in late 2025 where a single wallet controlled 99.9% of a vote. TVL has declined approximately 98.7% from its 2022 peak of over $8 billion to roughly $100 million as of late 2025.

avoid.net/bitrue18/100[CRITICAL]

Bitrue is a Singapore-incorporated centralized cryptocurrency exchange founded in 2018 that suffered a confirmed $23 million hot wallet exploit in April 2023, with stolen funds subsequently laundered through Tornado Cash as recently as June 2025. The exchange holds no license from Singapore's Monetary Authority (MAS) and relies on a VASP registration in Lithuania — a lower-tier regulatory framework — while accumulating a persistent record of user complaints alleging unjustified account freezes and asset seizures.

avoid.net/azukidao28/100[WARNING]

AzukiDAO is an informal decentralized autonomous organization formed in late June 2023 by a self-described group of 72 to 74 Azuki NFT holders in response to widespread community outrage over the Azuki Elementals NFT launch. Within days of its formation, AzukiDAO's BEAN governance token airdrop contract was exploited via a signature replay vulnerability, resulting in the theft of approximately 35 ETH ($68,000). On-chain investigator ZachXBT had previously flagged the Azuki project's founder Zagabond (Alex Xu) for alleged involvement in multiple prior abandoned NFT projects, and his findings were central to the community grievances that motivated AzukiDAO's creation.

avoid.net/leetswap32/100[WARNING]

LeetSwap was a decentralized exchange (DEX) launched on Coinbase's Base Layer 2 network in mid-2023 and briefly held the position of the network's largest DEX by trading volume and total value locked. On August 1, 2023, shortly after Base's mainnet opened to all users, an attacker exploited a publicly exposed smart contract function to drain approximately 342 ETH (~$630,000) from multiple liquidity pools. The protocol halted trading, partially recovered funds through white-hat rescue operations, and has since operated at a fraction of its pre-exploit TVL, with no public audit ever confirmed prior to the incident.

avoid.net/stakecom28/100[WARNING]

Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.

ZachXBT Intelligence · Backfilled

3
avoid.net/lazarus-group2/100[CRITICAL]

Lazarus Group is a cyber threat actor that the U.S. Department of Justice, FBI, Treasury/OFAC, and the United Nations Panel of Experts have attributed to North Korea's Reconnaissance General Bureau (RGB), a military intelligence agency of the Democratic People's Republic of Korea (DPRK). U.S. and allied government agencies allege the group and its sub-units (tracked in industry reporting as APT38, BlueNoroff, TraderTraitor, and Stardust Chollima) have conducted destructive cyberattacks and large-scale cryptocurrency thefts since at least 2009, including what blockchain-analytics firm Chainalysis describes as a cumulative total exceeding $6 billion in stolen crypto assets, funds the UN Panel of Experts and U.S. officials allege support North Korea's weapons programs. This entry documents named individuals, government indictments, sanctions, and specific hacking incidents, distinguishing DOJ/FBI/OFAC/UN attributions from private-sector research findings.

avoid.net/tornado-cash28/100[WARNING]

Tornado Cash is an open-source, non-custodial cryptocurrency mixing protocol on Ethereum, launched in 2019, that obscures the on-chain link between deposit and withdrawal addresses. The U.S. Treasury sanctioned the protocol in August 2022 over its alleged use by the North Korea-linked Lazarus Group and other illicit actors to launder billions of dollars; those sanctions were struck down by the Fifth Circuit in November 2024 and formally lifted by OFAC in March 2025. Separately, co-founder Alexey Pertsev was convicted of money laundering in the Netherlands in 2024 (appeal pending), and co-founder Roman Storm was convicted in August 2025 of one count of conspiring to operate an unlicensed money-transmitting business while a New York jury deadlocked on more serious money-laundering and sanctions-violation charges that remain unresolved pending post-trial motions and a possible retrial.

avoid.net/compound-finance55/100[CAUTIONARY]

Compound Finance is one of the earliest and most established decentralized lending protocols on Ethereum, launched in 2018 and governed since 2020 by a DAO around the COMP token. The protocol's smart-contract core has never suffered a direct exploit of user funds, but it has been repeatedly hit by operational and front-end security failures — a costly 2021 token-distribution bug, a 2023 X/Twitter account compromise used for phishing, a 2024 DNS hijack of its website, and a 2024 governance controversy in which a whale-backed group used purchased voting power to pass a treasury allocation over community objections. Combined with declining total value locked and a 2023 leadership departure, these incidents warrant continued scrutiny even though the underlying lending contracts have a long audit history and no reported loss of user deposits from a core-protocol hack.

200 entities tracked · record updated 2026-09
Page transparency log
Last updated fingerprint: 4DHy2N…rE8x