---
title: "Crypto Hacks Tracker"
date: 2026-07-27
author: "Irene Austria"
featured_image: "https://coinlaw.io/wp-content/uploads/2026/07/crypto-hacks-tracker.jpg"
---

# Crypto Hacks Tracker

Canonical URL: <https://coinlaw.io/crypto-hacks-tracker/>  
Cite as: CoinLaw, *Crypto Hacks Tracker*.

**What is in scope:** Incidents where the affected project, a regulator, or a court filing disclosed what was taken. The dollar figure is our conversion at the incident date, never a disclosed number.

25 records. Every figure is traced to the primary source linked on its row. Last verified 14 August 2026. Re-checked every 30 days.

| Record | Category | Date | Loss (USD, derived) | Vector | Recovery | Recovered usd | Assets | Timeline | Verified | Source |
|---|---|---|---|---|---|---|---|---|---|---|
| Coinsbuy | cex | 2026-08-09 |  | unknown | partial |  | Ethereum and TRON hot-wallet assets | Coinsbuy confirmed on 10 August 2026 that unauthorized withdrawals hit several platform wallets the previous day, said all affected client funds were covered from its own reserves, and offered a 100,000 dollar reward. The company neither confirmed nor disputed a total, so the loss stays Undisclosed here. For scale only: the independent investigator SpecterAnalyst tallied about 7.9 million dollars across Ethereum and TRON from three linked addresses, with proceeds moved into Monero via exchanges; ChangeNOW froze a six-figure portion, recorded as partial recovery. Reserve compensation to users is not counted as recovery. The intrusion method has not been described, so the vector stays unknown. | 2026-08-14 | [Coinsbuy statement, via Cointelegraph](https://cointelegraph.com/news/coinsbuy-confirms-security-breach-after-wallets-reportedly-drained-of-79m) |
| Coldcard | wallet | 2026-07-30 |  | key-compromise | none |  | Bitcoin held in self-custody wallets whose seeds were generated on affected COLDCARD firmware | Coinkite published its Coldcard Security Advisory on 30 July 2026, updated 1 August. A firmware defect present from version 4.0.1 in March 2021 through 4.1.9 inclusive routed seed generation through a predictable software randomizer rather than the hardware entropy source, leaving Mk2 and Mk3 seeds with roughly 40 bits of effective entropy against the 128 expected, which puts the resulting keys within reach of offline enumeration. Seeds made on Mk4, Mk5 and Q before the fixed releases carry about 72 bits. Fixed firmware 4.2.0 corrects new seed generation but cannot repair a seed already created, so Coinkite told affected holders to migrate funds to a newly generated seed. Seeds built with at least 50 fair, independent, private dice rolls are not considered at risk from this defect alone, and a strong unique BIP-39 passphrase adds an independent barrier, though Coinkite advises passphrase users to migrate as well. TAPSIGNER, OPENDIME and SATSCARD are unaffected. Coinkite states no theft figure and says a formal technical review is still to come, so the loss stays Undisclosed here rather than being implied as zero. For scale only, and expressly not as the recorded figure: Galaxy Research, a third-party chain-analytics firm, estimates 1,596 BTC taken from about 7,300 addresses across three confirmed waves plus 14 smaller incidents, worth more than 100 million dollars, and reports that none of the coins from those three waves have moved. This tracker records the figure the affected vendor states, and a chain-analytics estimate never substitutes for a disclosure. Re-verified 14 Aug 2026: Coinkite has published a technical backgrounder attributing the defect to a random-byte fallback introduced during a library migration, with the formal postmortem still to come, and still states no theft figure, so the loss stays Undisclosed. Third-party tallies keep moving and disagree with each other, TRM Labs counting 1,816 BTC from more than 5,200 addresses across four waves while Galaxy counts 1,596 BTC from about 7,300 addresses, which is exactly why an analytics estimate never substitutes for a disclosure here. | 2026-08-14 | [Coinkite, "Coldcard Security Advisory"](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) |
| Bitcoin Depot | other | 2026-03-23 | 3665000 | key-compromise | none |  | 50.903 BTC from company-controlled settlement wallets | Bitcoin Depot, the crypto ATM operator, discovered on 23 March 2026 that an unauthorized actor had obtained control of credentials for its digital asset settlement accounts and transferred approximately 50.903 Bitcoin from company-controlled wallets. The company determined the incident material on 6 April and filed its 8-K, recording a preliminary loss of approximately 3.665 million dollars, the fair value of the Bitcoin at the incident date, which is the figure stored here per the company own filing. The 8-K states the incident was contained to the corporate environment, with no evidence customer personal information was accessed, and no recovery is reported. Read from the filing text directly, 14 Aug 2026. | 2026-08-14 | [Bitcoin Depot, Form 8-K (Item 1.05)](https://www.sec.gov/Archives/edgar/data/1901799/000119312526147772/btm-20260406.htm) |
| Cetus Protocol | defi | 2025-05-22 | 223000000 | smart-contract | partial | 162000000 | Liquidity pool assets on Sui, with USDC bridged out via CCTP | An arithmetic overflow in the liquidity-pool maths let the attacker drain roughly USD 223 million on 22 May 2025. Cetus paused its contracts and, with the Sui Foundation and validators, froze USD 162 million before it could move. A recovery route with no precedent followed: an onchain community vote, carried by validators representing 90.9 per cent of stake, authorised a protocol upgrade reclaiming the frozen funds from the attacker's accounts WITHOUT their signature, into a 4-of-6 multisig trust held by Cetus, the Sui Foundation and OtterSec. About USD 61 million had already been bridged to Ethereum and is treated as lost. | 2026-07-27 | [Sui Foundation, "Response to the Cetus Incident – Onchain Community Vote"](https://blog.sui.io/cetus-incident-response-onchain-community-vote/) |
| Bybit | cex | 2025-02-21 | 1500000000 | phishing | partial | 43000000 | ETH and staked-ETH derivatives from a cold wallet | Signers approved a transaction through a manipulated Safe multisig interface, handing control of a cold wallet to the attacker. The FBI attributed the theft to North Korea. mETH Protocol retrieved roughly USD 43 million of cmETH, Tether froze USDT linked to the funds, and a seizure followed in Greece; the LazarusBounty programme continues to pay for traces. Bybit met customer withdrawals from its own reserves and loans, which is not counted as recovery here — the bulk of the stolen value remains with the attacker. | 2026-07-27 | [FBI, "North Korea Responsible for $1.5 Billion Bybit Hack"](https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack) |
| WazirX | cex | 2024-07-18 | 230000000 | phishing | none |  | ETH and ERC-20 tokens from the exchange Ethereum multisig | WazirX own preliminary report, published the day of the attack, states a loss of funds exceeding USD 230 million from a six-signatory multisig run on Liminal custody infrastructure; the stored figure is that stated floor. Signers approved what the interface showed while the actual payload upgraded the wallet to a malicious contract, the same manipulated-signing class as the Bybit theft. No recovery from the attacker; parent Zettai obtained a Singapore moratorium (HC/OA 861/2024) and restructured user claims under a scheme of arrangement, which redistributes the loss rather than recovering it. | 2026-07-30 | [WazirX, "Preliminary Report: Cyber Attack on WazirX Multisig Wallet"](https://wazirx.com/blog/preliminary-report-cyber-attack-on-wazirx-multisig-wallet/) |
| DMM Bitcoin | cex | 2024-05-31 | 308000000 | key-compromise | none |  | 4,502.9 BTC leaked from exchange wallets | DMM Bitcoin disclosed an unauthorised outflow of 4,502.9 BTC on 31 May 2024 and covered customer balances in full with support from DMM group companies — a reimbursement, not a recovery. None of the stolen bitcoin came back: it was mixed through CoinJoin, moved across bridging services and traced onward to the Huione Guarantee marketplace. Japan's Financial Services Agency issued an administrative action in September 2024, and DMM Bitcoin wound down, transferring accounts to SBI VC Trade by March 2025. | 2026-07-27 | [金融庁 (Japan FSA), "株式会社DMM Bitcoinに対する行政処分について"](https://www.fsa.go.jp/news/r6/sonota/20240926/20240926.html) |
| Poloniex | cex | 2023-11-10 | 126000000 | key-compromise | partial |  | Assets across ETH, BTC, TRON and XRP hot wallets | Hot wallets across several chains were drained on 10 November 2023. Poloniex stated it had identified and frozen a portion of the assets held at the attacker's addresses and offered a 5 per cent white-hat bounty for the return of the rest. The frozen portion has not been quantified publicly, so no recovered figure is recorded. Poloniex separately committed to reimbursing affected users from operating revenue, which is not counted as recovery here. | 2026-07-27 | [Poloniex, "Announcement on Poloniex Hack Incident"](https://support.poloniex.com/hc/en-us/articles/18976674677911-Announcement-on-Poloniex-Hack-Incident) |
| Mixin Network | other | 2023-09-23 | 200000000 | unknown | none |  | Mainnet assets held by the network | Mixin announcement, read at source: in the early morning of 23 September 2023 Hong Kong time the database of the network cloud service provider was attacked, and after initial verification the funds involved are approximately 200 million US dollars, the figure stored here. Deposits and withdrawals were suspended; Google and SlowMist were brought in. Mixin offered a 20 million dollar bounty for return of the funds. The precise mechanism behind the database compromise and the final recovery position were never published, so vector and recovery stay unrecorded. | 2026-07-30 | [Mixin Kernel announcement, 25 September 2023](https://x.com/MixinKernel/status/1706139175018529139) |
| Curve Finance | defi | 2023-07-30 | 70000000 | smart-contract | partial | 52300000 | CRV/ETH, alETH, msETH and pETH pool liquidity | A reentrancy guard defect in Vyper 0.2.15, 0.2.16 and 0.3.0 left several pools exploitable — the flaw was in the compiler, not in Curve's own contracts. By 7 August 2023 about 73 per cent, some USD 52.3 million, had been returned by white hats and MEV operators who had front-run the attackers, including c0ffeebabe.eth returning funds taken from the CRV/ETH and msETH pools. | 2026-07-27 | [Chainalysis, "Curve Finance Pools Exploited Due to Code Vulnerabilities"](https://www.chainalysis.com/blog/curve-finance-liquidity-pool-hack/) |
| Multichain | bridge | 2023-07-06 | 126000000 | unknown | none |  | wETH, wBTC and USDC, with close to USD 120 million from the Fantom bridge alone | Assets left Multichain's bridges in July 2023 with no exploit transaction to point to. The team said its CEO had been taken into custody by Chinese police in May 2023 and that it had lost access to the MPC keys; his sister then moved remaining funds to addresses she controlled, describing it as asset preservation, before also being detained. Multichain ceased operations. The vector is recorded as unknown because the source itself frames it as a possible hack or rug pull rather than a determined exploit. Nothing was returned. | 2026-07-27 | [Chainalysis, "Multichain Exploit: Possible hack or rug pull"](https://www.chainalysis.com/blog/multichain-exploit-july-2023/) |
| Atomic Wallet | wallet | 2023-06-02 | 100000000 | unknown | none |  | User funds drained from non-custodial wallets across multiple chains | Users of the non-custodial wallet reported drained balances on 2 June 2023. Atomic Wallet said fewer than 0.1 percent of active users were affected and never published its own loss total; the USD 100 million figure and the date come from the FBI, whose August 2023 press release attributes the theft to DPRK TraderTraitor actors, the group also behind Harmony Horizon and Ronin. The company has announced no reimbursement and no recovery of the stolen funds; the attack mechanism was never officially established. | 2026-07-30 | [FBI, "FBI Identifies Cryptocurrency Funds Stolen by DPRK"](https://www.fbi.gov/news/press-releases/fbi-identifies-cryptocurrency-funds-stolen-by-dprk) |
| Euler Finance | defi | 2023-03-13 | 197000000 | smart-contract | recovered | 240000000 | DAI, WBTC, stETH and USDC drawn from the lending pools | Flash-loan assisted exploit of the donation and liquidation logic on 13 March 2023. The exploiter returned assets in tranches through late March following negotiation with Euler Labs, and Euler recorded all recoverable funds returned on 3 April 2023. Value returned to the protocol by the exploiter; this was not an operator reimbursement. | 2026-07-27 | [Euler Finance, "War &amp; Peace: Behind the Scenes of Euler's $240M Exploit Recovery"](https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery) |
| FTX | cex | 2022-11-11 | 413000000 | unknown | none |  | Mixed digital assets drained from FTX.com and FTX US wallets | Funds drained from both exchanges the night the company filed for Chapter 11. The stored figure is the debtors own accounting from their 17 January 2023 statement: 323 million dollars of FTX.com assets and 90 million of FTX US assets were subject to unauthorized third-party transfers post-petition. The attack mechanism was never officially established by the debtors, and the recovery position of those specific funds was never cleanly separated from the estate recoveries, so both stay unrecorded here rather than guessed. | 2026-07-30 | [FTX Debtors, "FTX Debtors Provide Additional Information to Customers and Other Stakeholders"](https://www.prnewswire.com/news-releases/ftx-debtors-provide-additional-information-to-customers-and-other-stakeholders-301723770.html) |
| Mango Markets | defi | 2022-10-11 | 110000000 | smart-contract | partial | 67000000 | USDC, SOL and other collateral drawn against inflated MNGO positions | Avraham Eisenberg pumped MNGO across three venues so the oracle price rose more than thirteen-fold in half an hour, then borrowed against the inflated collateral. He returned roughly USD 67 million in USDC and SOL under a governance proposal the Mango DAO approved on 13 October 2022, keeping USD 47 million as a claimed bug bounty in exchange for the DAO agreeing not to pursue him. Mango added USD 25 million from its own treasury to compensate users, which is not counted as recovery here. The CFTC, SEC and Department of Justice each brought charges regardless of the DAO vote. | 2026-07-27 | [CFTC, "CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 million from Ma](https://www.cftc.gov/PressRoom/PressReleases/8647-23) |
| Nomad Bridge | bridge | 2022-08-01 | 190000000 | bridge-exploit | partial | 37000000 | WBTC, WETH, USDC and other bridged assets | A botched initialisation let any message prove valid, and the exploit turned into a free-for-all: over 300 addresses drained the bridge by copying the original transaction. Nomad published a recovery address and offered up to a 10 per cent bounty, treating anyone returning at least 90 per cent of what they took as a white hat. More than USD 37 million, about a fifth, came back that way. | 2026-07-27 | [Nomad, "The Road to Recovery"](https://medium.com/nomad-xyz-blog/the-road-to-recovery-6abe5eec8ff1) |
| Harmony Horizon Bridge | bridge | 2022-06-24 | 100000000 | key-compromise | none |  | ETH, USDC, WBTC and other bridged assets | The FBI confirmed in January 2023 that Lazarus Group actors were responsible for the theft reported on 24 June 2022. The proceeds were laundered through Tornado Cash and later through RAILGUN, and the FBI has continued to track the assets in North Korean-controlled wallets. Nothing has been returned. A Harmony proposal to mint ONE to compensate holders was rejected by its community, so there was no reimbursement either. | 2026-07-27 | [FBI, "FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft"](https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft) |
| Beanstalk | defi | 2022-04-17 | 77000000 | smart-contract | none |  | Non-Beanstalk user assets drained from protocol liquidity pools | Beanstalk Farms own postmortem, read at source: the credit-based stablecoin protocol was attacked at 12:24 UTC on 17 April 2022, with approximately 77 million dollars of non-Beanstalk user assets stolen from its liquidity pools, the figure stored here. The attacker used a flash loan to pass a malicious governance proposal and send the funds to their own wallet; the team shut off governance, paused the protocol, and burned the remaining Beans in the exploiter contract. Larger figures circulated for total protocol impact, but the tracker records the victim stated theft. The protocol later relaunched through a community recapitalization, which is funding, not recovery. | 2026-07-30 | [Beanstalk Farms, "Beanstalk Governance Exploit"](https://bean.money/blog/beanstalk-governance-exploit) |
| Ronin Bridge | bridge | 2022-03-23 | 625000000 | key-compromise | partial | 30000000 | 173,600 ETH and 25.5m USDC drained from the bridge | Five of nine validator keys were compromised through social engineering, letting the attacker forge withdrawals. The FBI attributed the theft to the Lazarus Group. Law enforcement and industry partners seized more than USD 30 million of the stolen funds in September 2022, around a tenth of the total and the first DPRK crypto seizure on record. Separately, Sky Mavis reimbursed affected users from a USD 150 million funding round plus balance-sheet funds — that reimbursement is not counted as recovery here. | 2026-07-27 | [Chainalysis, "Crypto Community Makes Profiting Hard for North Korean Hackers"](https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/) |
| Wormhole | bridge | 2022-02-02 | 326000000 | smart-contract | none |  | 120,000 wETH minted on Solana without collateral | A signature-verification flaw let the attacker mint 120,000 wETH on Solana without posting collateral. Jump Crypto replaced the full amount within roughly a day so the protocol stayed solvent, and a USD 10 million bounty offer to the attacker went unanswered. None of the stolen value has been recovered: the assets remain in the attacker's wallets. This is the clearest case where reimbursement and recovery diverge — users were made whole, the theft was not reversed. | 2026-07-27 | [Chainalysis, "Lessons from the Wormhole Exploit"](https://www.chainalysis.com/blog/wormhole-hack-february-2022/) |
| BitMart | cex | 2021-12-04 | 150000000 | key-compromise | none |  | ETH and BSC hot-wallet assets across many tokens | BitMart own breach notice, read at source: a large-scale security breach on 4 December 2021 hit one ETH and one BSC hot wallet, with hackers withdrawing assets of approximately 150 million US dollars, the figure stored here; the company later attributed the breach to a stolen private key that compromised both wallets. Third-party analysts put the total nearer 196 million, but the tracker records what the victim disclosed. BitMart compensated affected users from its own funding, which is not counted as recovery; nothing is recorded as recovered from the attacker. | 2026-07-30 | [BitMart, "BitMart Security Breach Update"](https://support.bitmart.com/hc/en-us/articles/4411998987419) |
| BadgerDAO | defi | 2021-12-02 | 116300000 | phishing | partial | 9123000 | 2017 BTC, 53 DIGG, 26.56 ETH, 730 CVX | A malicious snippet injected into the front end via an unauthorised Cloudflare API key prompted users to grant unlimited token approvals, which the attacker then drew on. Badger paused all contracts, stranding assets the attacker had taken but not yet withdrawn. BIP 76 and 77 recovered those to a DAO multisig and BIP 78 returned them to the wallets they came from: $9.123M, which Badger states is 7% of funds lost and left 40% of affected users whole. The remaining ~$121M has not been recovered from the attacker. Treasury-funded restitution under BIP 79/80 is reimbursement, not recovery, and is excluded here. | 2026-07-28 | [BadgerDAO Recovery Phase (project statement, archived)](https://web.archive.org/web/20211230id_/https://badger.com/_next/data/Bt8WnsWXuTAn_1JpNX_sK/recovery-phase.json) |
| Poly Network | bridge | 2021-08-10 | 610000000 | bridge-exploit | recovered | 610000000 | ETH, BSC and Polygon assets across the cross-chain pools | The attacker, who used the moniker Mr. White Hat, began returning assets voluntarily the day after the exploit. Tether released 33,431,200 USDT frozen during the attack on 25 August 2021. Poly Network stated recovery of all affected user assets complete on 26 August 2021. Value returned to the protocol; this was not an operator reimbursement. | 2026-07-27 | [Poly Network, "Asset Recovery Complete"](https://medium.com/poly-network/poly-network-asset-recovery-complete-a7ba33c2f2e4) |
| KuCoin | cex | 2020-09-25 | 281000000 | key-compromise | partial | 204000000 | BTC, ETH and a long tail of ERC-20 tokens from hot wallets | Hot-wallet private keys were compromised and the FBI later attributed the theft to the Lazarus Group. KuCoin put recovery at about 84 per cent, roughly USD 204 million, achieved largely by token issuers freezing or reissuing affected contracts and by exchanges blocking the laundering routes. Value returned to KuCoin rather than paid out of its own pocket, so it is counted here. | 2026-07-27 | [KuCoin, "The Latest Updates About the KuCoin Security Incident"](https://www.kucoin.com/announcement/en-the-latest-updates-about-the-kucoin-security-incident) |
| Coincheck | cex | 2018-01-26 |  | unknown | none |  | Customer-held NEM (XEM), sent externally from the exchange | The largest exchange theft of its era, recorded here on the regulator own words: Japan FSA bulletins state that on 26 January 2018 virtual currency (NEM) held by Coincheck was illicitly transmitted externally following unauthorized access, and that business-improvement orders and on-site inspections followed across the industry. Every loss and compensation figure Coincheck published was denominated in yen and XEM, and the company notices from the period are no longer online, so this row records no US dollar loss rather than a converted or second-hand one. The episode led directly to Japan revised crypto exchange regulation. | 2026-07-30 | [Japan FSA, Access FSA No. 176 (administrative actions, virtual currency exchangers)](https://www.fsa.go.jp/access/29/176a.html) |

Quoting a figure with a link to this page needs no permission. Reuse of the compiled dataset is licensed under CC BY 4.0: credit CoinLaw and link back.

Definition of Cross-Chain. Link to full glossary entry follows the description.**Cross-Chain**Cross-chain is the ability to move data or assets between separate blockchains via bridges, messaging protocols, or interoperability networks.

[Read more](https://coinlaw.io/glossary/cross-chain/)

Definition of Cold Wallet. Link to full glossary entry follows the description.**Cold Wallet**A cold wallet is an offline crypto storage method that keeps private keys disconnected from the internet, reducing the risk of hacking and unauthorized access.

[Read more](https://coinlaw.io/glossary/cold-wallet/)

Definition of Hot Wallet. Link to full glossary entry follows the description.**Hot Wallet**A hot wallet is an internet-connected crypto wallet for fast transactions and [DeFi](https://coinlaw.io/glossary/defi/) access, but it carries higher security risks than offline storage.

[Read more](https://coinlaw.io/glossary/hot-wallet/)

Definition of Stablecoin. Link to full glossary entry follows the description.**Stablecoin**A stablecoin is a cryptocurrency tied to a reserve asset like the US dollar, designed to maintain a stable value for trading, payments, and transfers.

[Read more](https://coinlaw.io/glossary/stablecoin/)

Definition of ERC-20. Link to full glossary entry follows the description.**ERC-20**An Ethereum technical standard defining a common interface for fungible tokens, specifying six core methods and two events so wallets, exchanges, and contracts can interact with any token uniformly.

[Read more](https://coinlaw.io/glossary/erc-20/)