ChainWatch

2026 Exploit Intelligence

Live · sourced from PeckShield, CertiK, Immunefi, SlowMist

Major crypto exploits, year-to-date

Aggregated incidents across DeFi, CEX, bridges, and wallets. Filter to spot emerging attack trends.

Total stolen
$1.02B
17 incidents
Recovered
$137M
13.4% recovery rate
Largest single loss
$312.0M
Chains affected
10
across active filters
Chain
Category

Cumulative losses · 2026

$1.02B total

Attack vectors by $ lost

Private Key Compromise$598.4M · 58%
Bridge Exploit$201.4M · 20%
Flash Loan$57.0M · 6%
Access Control$51.7M · 5%
Oracle Manipulation$41.5M · 4%
Reentrancy$36.5M · 4%
Smart Contract Bug$14.3M · 1%
Social Engineering$11.2M · 1%
Phishing$6.7M · 1%
Frontend Hijack$4.8M · 0%

Incident log · 17 events

live feed
ChainCategoryVulnerabilityRecoverySource
May 21
BaseLend
Deprecated multisig retained owner privileges.
BaseDeFiAccess Control$18.60M
+$7.5M back
PartialCertiK
May 13
BNBVault
Single-source Chainlink fallback manipulated via low liq.
BNB ChainDeFiOracle Manipulation$22.10MLostPeckShield
May 05
SolanaSwapr
Atomic arb reverted by validator coordination.
SolanaDeFiFlash Loan$9.80M
+$9.8M back
RecoveredImmunefi
Apr 27
BinarisCEX
Cold storage breach attributed to nation-state actor.
EthereumCEXPrivate Key Compromise$198.40M
+$45.0M back
PartialSlowMist
Apr 18
HyperBridge
Light-client proof verifier accepted malformed headers.
ArbitrumBridgeBridge Exploit$76.90M
+$3.0M back
OngoingCertiK
Apr 10
ApeNFT Market
Discord admin compromise → fake mint stole assets.
EthereumNFTSocial Engineering$11.20MLostPeckShield
Apr 02
OptiYield
Cross-function reentrancy in reward distributor.
OptimismDeFiReentrancy$27.60M
+$9.0M back
PartialImmunefi
Mar 25
AvaxKingdom
DNS hijack served malicious approval prompts.
AvalancheGamingFrontend Hijack$4.80MLostCertiK
Mar 17
PolyLend
Rounding error patched; funds returned via bounty.
PolygonDeFiSmart Contract Bug$14.30M
+$14.3M back
RecoveredPeckShield
Mar 09
Tronix Exchange
Insider exfiltration of multisig signer keys.
TronCEXPrivate Key Compromise$88.00M
+$22.0M back
PartialSlowMist
Mar 01
BasedPerps
Unprotected admin function set fee recipient to attacker.
BaseDeFiAccess Control$33.10M
+$1.5M back
OngoingImmunefi
Feb 19
MetaVaultX
Mass phishing kit drained delegated approvals.
EthereumWalletPhishing$6.70MLostCertiK
Feb 11
SolFlare Pools
Pyth feed lag exploited for arbitrage drain.
SolanaDeFiOracle Manipulation$19.40M
+$4.2M back
PartialPeckShield
Feb 03
Krakenize
Hot wallet keys exfiltrated via supply-chain attack.
BitcoinCEXPrivate Key Compromise$312.00MLostSlowMist
Jan 22
ZenithSwap
Whitehat returned funds after reentrancy in claim().
BNB ChainDeFiReentrancy$8.90M
+$8.9M back
RecoveredImmunefi
Jan 14
NovaBridge
Signature verification flaw allowed forged withdrawal proofs.
EthereumBridgeBridge Exploit$124.50MOngoingCertiK
Jan 08
OrbitDEX
Flash loan-driven price manipulation drained LP pools.
ArbitrumDeFiFlash Loan$47.20M
+$12.0M back
PartialPeckShield