Investigations
Showing the 200 most recently updated of 952 scored 0–20.
Critical · scores 0–20
200Gurhan Kiziloz is a Turkish-British entrepreneur who co-founded BlockDAG Network, a Layer-1 blockchain project that claimed to raise up to $442 million in a presale running from December 2023 to February 2026. His identity was concealed for over two years while a public-facing CEO served as the project's visible representative; Kiziloz confirmed his role in a December 2025 investor AMA. His prior UK fintech Lanistar received an FCA consumer warning in November 2020 and was liquidated by a UK High Court in September 2025. In May 2026, a Brazilian court ordered the freeze of approximately $213 million in USDT across 48 wallets linked to Kiziloz over alleged unpaid gambling taxes and unregistered crypto sales; a Brazilian federal appellate court subsequently narrowed the freeze in August 2026, with full adjudication ongoing.
avoid.net/ramil-ventura-palafox→0/100[CRITICAL]Ramil Ventura Palafox, a dual U.S.-Philippine citizen and founder of Praetorian Group International (PGI), was sentenced on February 12, 2026 to 20 years in federal prison after pleading guilty to wire fraud and money laundering for operating a Bitcoin Ponzi scheme that received over $201 million from more than 90,000 investors worldwide between December 2019 and October 2021. On April 6, 2026, he removed his GPS monitoring device and failed to report to prison, becoming a federal fugitive; the FBI placed him on its Most Wanted list, and he was arrested approximately 12 days later in Los Angeles, California, where he remains in federal custody.
avoid.net/codexfield→12/100[CRITICAL]CodexField is a decentralized code-management and developer marketplace platform built on BNB Greenfield that won first place in BNB Chain's Hackvolution hackathon in September 2023. On July 9, 2026, on-chain researcher Specter alleged the project may be executing a rug pull, citing partially verified cross-chain fund movements totaling 17.3 million USDT and claiming total user funds at risk of approximately USD 85 million. As of the investigation date, CodexField and BNB Chain have not publicly responded to the allegations, and the USD 85 million figure lacks a complete published on-chain trace.
avoid.net/radoslaw-piesiewicz→20/100[CRITICAL]Radoslaw Piesiewicz (born February 20, 1981) is a Polish sports administrator who has served as president of the Polish Olympic Committee (PKOl) since 2023. On August 27, 2026, he was detained by Poland's Central Bureau for Combating Cybercrime in connection with a criminal investigation into the collapsed cryptocurrency exchange Zondacrypto. A Polish court subsequently ordered him held for three months pending the investigation; as of the date of this report, formal charges had not been publicly filed and no conviction has been entered.
avoid.net/przemyslaw-kral→4/100[CRITICAL]Przemyslaw Kral is the former CEO of Zondacrypto (formerly BitBay), Poland's largest cryptocurrency exchange, which collapsed in April 2026 amid a criminal fraud investigation. Polish prosecutors charged Kral with alleged participation in large-scale fraud and money laundering in connection with estimated customer losses ranging from approximately 350 million zloty ($97 million) to as much as 2.4 billion zloty ($650 million) according to later prosecutor estimates, affecting approximately 30,000 users. Kral departed Poland for Israel in April 2026 and holds dual Polish-Israeli citizenship; as of September 2026 he has reportedly been cooperating with prosecutors, though his precise location and formal legal status remain subjects of conflicting and unconfirmed reporting.
avoid.net/superior-browser-extension-campaign-wallet-drainer→2/100[CRITICAL]The 'Superior' campaign is a coordinated supply-chain attack involving 19 malicious browser extensions for Chrome and Edge, identified and named by Socket Security in August 2026. The campaign reached approximately 80,000 users, deploys a modular multi-chain wallet-draining framework targeting EVM, Solana, and Tron wallets, and remained active as of late August 2026, with confirmed infrastructure rotation on August 14, 2026. No individual or group has been publicly named as the actor; the campaign name derives from tags found in the malicious JavaScript modules.
avoid.net/more-markets→17/100[CRITICAL]More Markets is a DeFi lending protocol built on the Flow EVM blockchain by More Labs, operating as a fork of Aave V3. On August 31, 2026, an attacker exploited the protocol's E-Mode mechanism using Ankr's ankrFLOW liquid staking token as collateral to drain approximately 15.5 million WFLOW tokens, valued at roughly $9.3 million according to security firm Blockaid's initial estimate. The protocol subsequently paused operations and disputed the scale of losses reported by Blockaid, attributing the root vulnerability to a third party, though a post-mortem had not been published as of the date of this report.
avoid.net/zondacrypto→2/100[CRITICAL]Zondacrypto (operating entity: BB Trade Estonia OÜ), formerly known as BitBay and once Poland's largest cryptocurrency exchange, was declared bankrupt by the Harju County Court in Tallinn on August 27, 2026 after CEO Przemyslaw Kral departed to Israel in April 2026 and an on-chain forensic analysis found the exchange's hot-wallet Bitcoin reserves had fallen by approximately 99.7 percent. Polish prosecutors have opened a criminal fraud investigation, with estimated customer losses of roughly 350 million PLN (approximately $82–97 million) affecting up to 30,000 users who cannot access their funds. The collapse also triggered the arrest of Polish Olympic Committee president Radoslaw Piesiewicz on bribery allegations and the bankruptcy of affiliated fintech Femion Technology.
avoid.net/xtoken→10/100[CRITICAL]xToken (XTK) was a DeFi protocol offering wrapped staking tokens and liquidity management on Ethereum, founded by Michael J. Cohen in 2020. The protocol suffered two major flash loan exploits in 2021 — a $24.5 million attack in May and a $4.5 million attack in August — resulting in total losses exceeding $29 million and the permanent retirement of its flagship xSNX product. The XTK governance token subsequently lost approximately 99.84% of its value, and compensation paid to victims was significantly below the amounts stolen.
avoid.net/rivus-dao→8/100[CRITICAL]Rivus DAO was a Bittensor-focused liquid staking protocol on Ethereum that raised approximately $4.23 million in an April 2024 IDO before suffering a rugpull classified by DefiLlama as a Third-party Dev Backdoor Exploit on September 16, 2024. The incident effectively drained protocol TVL from its operational peak to under $2,500, and the RIVUS governance token lost more than 99.8% of its all-time high value. On-chain investigator ZachXBT has flagged this entity; the project attempted a relaunch in October 2024 but is currently listed as inactive with no trading activity.
avoid.net/tectonic-cronos-august-2026-tonic-price-manipulation-exploit→18/100[CRITICAL]On August 30, 2026, an unknown attacker manipulated the price of TONIC — the thinly traded governance token of Tectonic, the dominant lending protocol on the Cronos blockchain — by approximately 100-fold in roughly 20 minutes, then deposited the artificially inflated tokens as collateral and borrowed an estimated $75 million in liquid assets from the protocol's pools. Cronos validators halted all block production network-wide within minutes, freezing approximately $68.7 million on-chain; roughly $6 million had already been bridged to Ethereum before the halt and could not be recovered by rollback. Validators subsequently rolled the chain back to its pre-attack state — discarding approximately 11,000 blocks and reversing nearly two hours of third-party transactions — and resumed block production at block 90,896,189 (23:49:01 UTC, August 30). As of September 1, 2026, no compensation plan, final loss figure, or formal post-mortem had been published by Tectonic or Cronos Labs.
avoid.net/bitcoin-depot→0/100[CRITICAL]Bitcoin Depot was once the largest operator of cryptocurrency ATMs in North America, running approximately 9,700 kiosks at peak. Facing enforcement actions from at least 11 state agencies, a voluntary information request from the SEC, an FTC inquiry, and lawsuits from the attorneys general of Massachusetts and Iowa alleging the company knowingly facilitated hundreds of millions of dollars in consumer fraud, Bitcoin Depot filed for Chapter 11 bankruptcy on May 18, 2026, and immediately took its entire kiosk network offline. This page focuses specifically on the fraud facilitation angle — the mechanisms by which the ATM network was allegedly used to funnel scam proceeds, the regulatory responses that followed, and the consumer harm caused both by third-party scammers and by the abrupt bankruptcy shutdown itself.
avoid.net/web3port→5/100[CRITICAL]Web3Port is a Hong Kong-registered crypto market-making and incubation firm alleged to have orchestrated the dumping of 66 million MOVE tokens one day after the Movement Labs token launch in December 2024, generating approximately $38 million in downward price pressure. Binance subsequently banned and froze the profits of the market-making account it associated with Web3Port, citing misconduct. A U.S. Department of Justice grand jury investigation into the MOVE token launch is ongoing as of 2026, and movement Labs — the project whose token Web3Port allegedly manipulated — filed for Chapter 11 bankruptcy in July 2026.
avoid.net/avraham-eisenberg→2/100[CRITICAL]Avraham Eisenberg, also known as 'Avi Eisenberg,' is a crypto trader who in October 2022 executed an oracle manipulation attack against Mango Markets, a Solana-based DeFi protocol, extracting approximately $110–117 million in digital assets. He publicly claimed the scheme was a 'highly profitable trading strategy' and a legal use of the protocol, returned approximately $67 million after a DAO-mediated settlement, and was subsequently charged by the DOJ, SEC, and CFTC. A federal jury convicted him in April 2024, but a federal judge vacated all criminal convictions in May 2025 on grounds of improper venue and insufficient evidence of material misrepresentation; prosecutors have appealed. Eisenberg is currently serving a separate 52-month federal prison sentence for possession of child sexual abuse material.
avoid.net/audia6-crypto-laundering-network→0/100[CRITICAL]AudiA6 was a professional cryptocurrency money laundering service allegedly operating from 2021 through 2025, accused of processing approximately $389.7 million (EUR 336 million) in illicit funds for ransomware gangs and other cybercriminals. The service also administered the Dark2Web dark web cybercrime forum. A US-led international law enforcement operation dismantled AudiA6's infrastructure on June 10, 2026, and two alleged operators were arrested in Batumi, Georgia and charged by the US Department of Justice.
avoid.net/faruk-fatih-ozer→0/100[CRITICAL]Faruk Fatih Ozer is the Turkish founder and CEO of Thodex, a cryptocurrency exchange that collapsed in April 2021 after he fled to Albania, leaving approximately 391,000 users unable to access an estimated $2 billion in funds. He was arrested in Albania in August 2022, extradited to Turkey in April 2023, and sentenced on September 7, 2023 to 11,196 years, 10 months, and 15 days in prison on charges of aggravated fraud, founding a criminal organization, and money laundering. He was found dead in Tekirdag F-Type High Security Prison on November 1, 2025, with Turkish authorities indicating initial findings pointed to suicide.
avoid.net/ruja-ignatova→0/100[CRITICAL]Ruja Ignatova, known as the 'Cryptoqueen,' is the Bulgaria-born German co-founder of OneCoin, a fraudulent pyramid scheme that defrauded approximately 3.5 million victims of more than $4 billion between 2014 and 2019. Indicted in 2017 by a U.S. grand jury on charges of wire fraud, money laundering, and securities fraud, she fled law enforcement in October 2017 and remains a fugitive. She is currently an FBI Ten Most Wanted Fugitive with a $5 million reward for information leading to her arrest.
avoid.net/hayden-davis→0/100[CRITICAL]Hayden Mark Davis (born November 27, 1996) is an American cryptocurrency marketer and CEO of Kelsier Ventures who orchestrated the launch of the $LIBRA token on February 14, 2025 — a memecoin promoted by Argentine President Javier Milei that collapsed 85–95% within hours, causing an estimated $251 million in losses across approximately 44,000 to 74,000 investors. On-chain analytics by Bubblemaps and Nansen identified insider wallets tied to Davis and associates extracting between $87 million and $107 million in liquidity during the price peak. Davis is subject to an Interpol Red Notice sought by Argentine prosecutors, a U.S. federal class action (Hurlock v. Kelsier, S.D.N.Y.), and parallel Argentine criminal proceedings; he denies fraud allegations, characterizing the collapse as 'a plan gone miserably wrong.'
avoid.net/harmony-one-august-2026-layer-1-mint-exploit→16/100[CRITICAL]On August 12, 2026, an unidentified attacker exploited two consensus-layer vulnerabilities in the Harmony ONE mainnet to mint approximately 4 billion unauthorized ONE tokens, inflating the circulating supply by roughly 26%. Approximately 97% of the minted tokens reached cryptocurrency exchange deposit wallets before freezes could be enacted. Harmony deployed an emergency patch within roughly five hours, suspended its cross-chain bridge, and subsequently executed a full blockchain rollback to the pre-exploit state of August 11, 2026, erasing more than 109,000 legitimate transactions in the process. This incident is distinct from the June 2022 Horizon bridge hack.
avoid.net/alpha-homora→20/100[CRITICAL]Alpha Homora is a leveraged yield farming protocol developed by Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) that allows users to take on leveraged positions in liquidity pools. On February 13, 2021, the protocol suffered a critical exploit in which an attacker drained approximately $37.5 million from Iron Bank (C.R.E.A.M. Finance) by exploiting multiple smart contract vulnerabilities in Alpha Homora V2, including a hidden undisclosed sUSD lending pool, a rounding miscalculation in the borrow function, and an unrestricted reserve function callable by anyone. The resulting bad debt between the two protocols remained largely unresolved for years, culminating in a public dispute in 2023 in which Iron Bank froze Alpha Homora user accounts, and Alpha Homora proposed surrendering approximately $32 million in user funds to satisfy the outstanding obligation.
avoid.net/lazarus-group-mach-o-man-clickfix-macos-campaign→0/100[CRITICAL]In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.
avoid.net/operation-economic-outcast-iran-digital-asset-sanctions→0/100[CRITICAL]Operation Economic Outcast is a U.S. Treasury-led sanctions campaign announced on August 24, 2026, that for the first time designated Iran's entire digital asset sector as a sanctionable segment of the Iranian economy under Executive Order 13902. The action designated nearly 60 entities, individuals, and vessels and issued five sectoral sanctions determinations — covering digital assets, technology, gold, aviation, and shipping — creating secondary sanctions exposure for any person or business globally that operates in or provides services to Iran's crypto sector. This page documents the regulatory framework, key designations, and compliance implications relevant to anyone interacting with Iran-adjacent protocols, wallets, or exchanges.
avoid.net/pickle→10/100[CRITICAL]Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.
avoid.net/coinw6→0/100[CRITICAL]CoinW6 is a fraudulent cryptocurrency trading platform at the center of the SEC's first-ever enforcement action targeting a pig butchering (relationship investment) scam, filed September 17, 2024 in the U.S. District Court for the Central District of California (Case No. 2:24-cv-07924). According to the SEC's complaint, operators of CoinW6 posed as wealthy professionals on LinkedIn and Instagram, cultivated romantic relationships with victims over WhatsApp, then directed at least 11 investors to a fake trading interface that displayed fabricated returns, stealing approximately $2.2 million between July 2022 and December 2023. As of mid-2026, the case remains pending, with the SEC seeking service by publication after defendants failed to appear.
avoid.net/gary-wang→18/100[CRITICAL]Zixiao 'Gary' Wang is the co-founder and former Chief Technology Officer of FTX, the cryptocurrency exchange that collapsed in November 2022 following the discovery of an $8 billion shortfall caused by the misappropriation of customer funds to affiliated hedge fund Alameda Research. Wang pleaded guilty in December 2022 to four counts of wire fraud and conspiracy, served as a principal cooperating witness against former CEO Sam Bankman-Fried, and was sentenced in November 2024 to time served with three years of supervised release and $11 billion in forfeiture obligations.
avoid.net/qubit-finance→5/100[CRITICAL]Qubit Finance was a BSC-based DeFi lending and borrowing protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logical flaw in the protocol's Ethereum-BSC cross-chain bridge (QBridge), minting 77,162 qXETH without depositing any real ETH on Ethereum, ultimately draining approximately $80 million in user funds. No funds were recovered, the attacker's identity was never established, and the compensation plan announced by the team was never verifiably fulfilled.
avoid.net/prisma-fi→12/100[CRITICAL]Prisma Finance was an Ethereum-based collateralized debt position (CDP) protocol that issued stablecoins (mkUSD and ULTRA) backed by liquid staking and restaking tokens (LRTs/LSTs). On March 28, 2024, a critical input validation flaw in the MigrateTroveZap contract was exploited via flash loan, resulting in the theft of approximately 3,479 ETH (~$12 million) from user vaults. Following the exploit, the core team effectively abandoned the protocol, which was subsequently shut down via DAO governance (PIP-46) and succeeded by Resupply Finance.
avoid.net/edward-zimbardi-the-crypto-program→2/100[CRITICAL]The Crypto Program was an alleged cryptocurrency investment fraud operated by Edward Zimbardi, 59, of Flowery Branch, Georgia between June 2022 and August 2023. Prosecutors allege the scheme collected more than $165 million from over 6,000 investors worldwide by promising guaranteed 25% monthly returns on fictitious digital advertising packages. A federal grand jury indicted Zimbardi on July 8, 2026 on 25 counts; he was deported from Fiji to U.S. custody on August 14, 2026 and the case is currently pending trial.
avoid.net/snowdog→5/100[CRITICAL]Snowdog (SDOG) was an Avalanche-based OlympusDAO fork launched in November 2021 as a self-described '8-day decentralized reserve meme coin experiment' by the anonymous team behind Snowbank DAO. The project accumulated a $44 million MIM treasury before a planned token buyback on November 25, 2021, collapsed the token price by over 90% within seconds, with alleged insiders exploiting a hidden 'challengeKey' mechanism to extract approximately $20 million in profits while ordinary holders were locked out. The team declined to acknowledge deliberate wrongdoing, characterizing the event as a 'game-theory experiment gone wrong,' and subsequently renounced ownership, leaving investors with near-total losses.
avoid.net/mango-markets-v3→10/100[CRITICAL]Mango Markets V3 was a Solana-based decentralized margin trading protocol that suffered a $116 million oracle manipulation attack in October 2022 executed by Avraham Eisenberg, who artificially inflated the MNGO token price to extract funds against fabricated collateral. The protocol subsequently reached a partial recovery settlement, faced SEC and CFTC enforcement actions, and formally wound down operations by January 2025.
avoid.net/cftc-crypto-atm-scam-warning→5/100[CRITICAL]On August 26–27, 2026, the U.S. Commodity Futures Trading Commission issued a formal consumer alert titled 'Pause Before You Pay: Unusual Money Transfer Instructions May Signal Fraud,' warning the public about a sharp rise in cryptocurrency ATM scams. The warning was grounded in FBI Internet Crime Complaint Center data showing that U.S. residents filed 13,460 complaints involving cryptocurrency kiosks in 2025, reporting $388,981,267 in losses — a 58% year-over-year increase. More than half of all complaints involved people over 50, who collectively reported losses exceeding $302 million, making this demographic the primary target of the attack pattern.
avoid.net/operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-2026→0/100[CRITICAL]On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a whole-of-government sanctions campaign against Iran and its enablers, issuing the first-ever sectoral sanctions determination covering Iran's digital assets sector under Executive Order 13902. The action designated 78 individuals, entities, and vessels across 13 jurisdictions and structurally expanded secondary sanctions exposure so that any foreign person anywhere in the world who operates in or provides support to Iran's digital asset sector may now be designated — without OFAC needing to name them in advance. This page documents the regulatory action itself, the named designees with crypto relevance, and the compliance implications for global exchanges, OTC desks, and DeFi infrastructure.
avoid.net/ivan-obukhov-foscom-fze→2/100[CRITICAL]Ivan Obukhov is a UAE-based Ukrainian national designated by OFAC on August 24, 2026, as part of Operation Economic Outcast. U.S. Treasury alleges that since 2023 he processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Qods Force, and that he has for years brokered Iranian shadow-fleet vessels. His UAE-registered company Foscom FZE, which he acquired in 2022, was simultaneously designated under Executive Order 13224 as an entity controlled by Obukhov.
avoid.net/ofac-operation-economic-outcast-iran-digital-assets-sectoral-sanctions-august-2026→0/100[CRITICAL]On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, a sweeping sanctions campaign against Iran that, for the first time, designated Iran's entire digital assets sector as sanctionable under Executive Order 13902. The action named nearly 60 entities, individuals, and vessels and listed 30 crypto wallet addresses across Bitcoin, Ethereum, and TRON linked to the Mabna Institute and IRGC-Qods Force. The sectoral determination creates broad secondary sanctions exposure for any foreign crypto business — exchange, custodian, OTC desk, or DeFi protocol — that maintains material Iran-nexus counterparty relationships, regardless of whether those counterparties are individually listed.
avoid.net/maya-protocol-mayachain→12/100[CRITICAL]Maya Protocol is a permissionless, decentralized cross-chain liquidity network built on MAYAChain, a THORChain fork that launched mainnet in April 2023. On August 18, 2026, the protocol suffered its first documented loss-of-funds incident: an attacker chained six software vulnerabilities in a single 23-message transaction to extract approximately $1.36 million in hard assets (including 20.83 BTC) and trigger a broader pool-value impact estimated at $11 million, while CACAO crashed 89%. MAYAChain halted all operations on August 18, 2026, and has not resumed as of August 23, 2026; no funds have been returned.
avoid.net/kyle-davies→3/100[CRITICAL]Kyle Davies is the co-founder of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion in liabilities owed to 27 creditors. Following the collapse, Davies evaded liquidators, was sentenced in absentia to four months imprisonment in Singapore for failing to cooperate with court-ordered investigations, and received a nine-year ban from Singapore's Monetary Authority of Singapore (MAS) for regulatory violations including providing false information to regulators. He subsequently co-founded OPNX, a crypto bankruptcy claims exchange that also failed and shut down in early 2024.
avoid.net/su-zhu→3/100[CRITICAL]Su Zhu is the co-founder and former CEO of Three Arrows Capital (3AC), a Singapore-based cryptocurrency hedge fund that collapsed in June 2022 with approximately $3.5 billion owed to 27 creditors, triggering cascading bankruptcies at Voyager Digital, Celsius Network, and Genesis Global Trading. Zhu was convicted of contempt of court for failing to cooperate with liquidators, arrested at Singapore's Changi Airport in September 2023 while allegedly attempting to flee, and sentenced to four months in prison. Following his release he became involved in additional ventures including OPNX, a bankruptcy-claims trading exchange that was fined $2.7 million by Dubai's Virtual Assets Regulatory Authority and subsequently shut down in February 2024.
avoid.net/orbit-chain-bridge→8/100[CRITICAL]Orbit Bridge is the cross-chain bridging protocol of Orbit Chain, developed by South Korean blockchain company Ozys. On December 31, 2023, attackers compromised seven of ten multisig private keys and drained approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Ethereum vault in the largest crypto hack of New Year's Eve 2023. The attack has been attributed with medium-to-high confidence to North Korea's Lazarus Group, with an additional alleged insider-threat dimension involving Ozys' former chief information security officer, who allegedly sabotaged the company firewall weeks before the exploit.
avoid.net/nishad-singh→12/100[CRITICAL]Nishad Singh is a former software engineer who served as Director of Engineering at FTX, the cryptocurrency exchange that collapsed in November 2022 following the misappropriation of more than $8 billion in customer funds. Singh pleaded guilty in February 2023 to six criminal charges including wire fraud, commodities fraud, securities fraud, money laundering conspiracy, and campaign finance violations, and was sentenced in October 2024 to time served with no prison after providing extensive cooperation against FTX founder Sam Bankman-Fried. A supplemental CFTC civil settlement was reached in April 2026, requiring Singh to disgorge $3.7 million and subjecting him to a five-year trading ban.
avoid.net/novatech-ltd→2/100[CRITICAL]NovaTech Ltd. (also marketed as NovaTech FX) was a crypto trading and multi-level marketing program incorporated in St. Vincent and the Grenadines and operated by Cynthia and Eddy Petion from June 2019 through May 2023. The SEC alleges it raised more than $650 million from over 200,000 investors worldwide — largely from Haitian-American communities — while conducting only a small fraction of the promised trading. The scheme collapsed in May 2023; the SEC filed civil fraud charges in August 2024 and the Petions had not been served as of mid-2025, reportedly located in Panama.
avoid.net/bitcoin-latinum-ltnm-donald-basile→2/100[CRITICAL]Bitcoin Latinum (LTNM) is a cryptocurrency token launched in 2020 by Donald G. Basile through his companies GIBF GP, Inc. and Monsoon Blockchain Corporation. In April 2026, the U.S. Securities and Exchange Commission charged Basile with orchestrating a $16 million investor fraud scheme, alleging he raised funds through Simple Agreements for Future Tokens (SAFTs) using fabricated insurance coverage claims and nonexistent asset-backing structures, then diverted millions to personal expenses. The token, which peaked near $9,336 in December 2021, has since collapsed to near zero, and multiple civil lawsuits from defrauded investors preceded the SEC action.
avoid.net/transit-finance→2/100[CRITICAL]Transit Finance (also known as Transit Swap) is a cross-chain DEX aggregator supporting over 122 decentralized exchanges across Ethereum, BNB Chain, TRON, Solana, Polygon, and other networks. The protocol has suffered two confirmed security exploits: a $28.9 million hack in October 2022 due to an arbitrary external call vulnerability in its routing contract, with approximately $18.9 million recovered; and a second $1.88 million exploit in May 2026 via a deprecated TRON smart contract that remained on-chain and exploitable years after official deprecation. ZachXBT flagged the protocol amid broader DeFi monitoring, and the 2022 attacker routed funds through OFAC-sanctioned Tornado Cash.
avoid.net/eminence→10/100[CRITICAL]Eminence Finance (EMN) was an unfinished, unaudited NFT gaming protocol being developed by Yearn Finance founder Andre Cronje that was exploited on September 29, 2020, resulting in the theft of approximately $15 million in DAI from its bonding curve contracts. The contracts had never been officially announced or released to the public, but community members discovered and deposited into them after Cronje's cryptic tweets; the attacker returned $8 million to Cronje's deployer address but $7 million was never recovered. The incident became a defining case study in DeFi's 'degen' culture and the risks of deploying unaudited smart contracts to Ethereum mainnet.
avoid.net/vee-finance→12/100[CRITICAL]Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.
avoid.net/pnetwork→12/100[CRITICAL]pNetwork is a cross-chain bridge and interoperability protocol built on the pTokens architecture, enabling assets to move between Bitcoin, Ethereum, BNB Chain, and other networks via wrapped synthetic tokens. The protocol has suffered two major security incidents — a September 2021 pBTC-on-BSC hack losing approximately $12 million, and a November 2022 pGALA incident that triggered a $28 million lawsuit by Gala Games and Huobi alleging pNetwork's own engineers caused the vulnerability through a leaked private key, then allegedly profited from a self-described 'white hat' rescue. As of 2025, the PNT governance token trades at a fraction of its 2021 peak and the protocol operates with negligible market capitalization and trading volume.
avoid.net/prismalst→10/100[CRITICAL]Prisma Finance is a Liquity-forked, Ethereum-based DeFi protocol that allowed users to mint overcollateralized stablecoins (mkUSD and ULTRA) against liquid staking tokens (LSTs) such as wstETH, rETH, sfrxETH, and cbETH. On March 28, 2024, a critical vulnerability in the protocol's MigrateTroveZap helper contract was exploited for approximately $11.6 million, with a total loss across all attacker wallets of roughly $12.3 million; the primary exploiter sent the majority of stolen funds through Tornado Cash while claiming a 'whitehat rescue,' and as of 2026 the protocol's TVL has collapsed from a pre-exploit peak of approximately $220 million to under $300K.
avoid.net/pancakebunny→18/100[CRITICAL]PancakeBunny was a Binance Smart Chain yield aggregator and optimizer built by a team known as Mound, launched in December 2020. The protocol suffered two major flash loan exploits in 2021: a May 20, 2021 attack that caused the BUNNY token to crash over 95% and wiped out approximately $200 million in market capitalization, and a July 16, 2021 attack on its Polygon fork PolyBunny that resulted in $2.4 million in losses. Both exploits stemmed from oracle price manipulation vulnerabilities in the minting reward logic, and the protocol has never recovered to its pre-exploit state.
avoid.net/paid-network→12/100[CRITICAL]PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.
avoid.net/bunny→10/100[CRITICAL]PancakeBunny (Bunny Finance) was a Binance Smart Chain yield-optimizer developed by the anonymous team MOUND (Mound Inc.), which received a $1.6 million seed round led by Binance Labs in April 2021. The protocol suffered three separate exploits across 2021–2022 totaling over $127 million in losses, including a $45 million flash loan attack in May 2021, a $2.4 million polyBUNNY exploit on Polygon in July 2021, and an $80 million hack of its affiliated lending protocol Qubit Finance in January 2022. The BUNNY token has lost more than 99% of its all-time high value, the protocol transitioned to a DAO structure in early 2022, and no stolen funds from any exploit were publicly confirmed as recovered.
avoid.net/qubit→10/100[CRITICAL]Qubit Finance was a Binance Smart Chain lending and cross-chain bridge protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logic error in the QBridge Ethereum-BSC bridge to mint approximately 77,162 qXETH tokens without depositing any ETH, then drained roughly $80 million in protocol assets; no funds were ever recovered and the attacker was never identified.
avoid.net/sudorare→2/100[CRITICAL]SudoRare was an anonymous NFT automated market maker (AMM) protocol launched on August 23, 2022, presented as a fork of SudoSwap and LooksRare. Approximately six hours after launch, the anonymous development team executed a premeditated rugpull via a backdoored smart contract, draining approximately 519 ETH (valued at $815,000–$852,000) from user deposits before deleting all online presence. Blockchain security firms PeckShield and CertiK traced a funding wallet to Kraken, but no public arrests or legal proceedings have been reported.
avoid.net/radiant-v2→10/100[CRITICAL]Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that suffered two significant security incidents in 2024: a $4.5 million flash loan exploit in January 2024 and a far more devastating $50 million multisig compromise in October 2024. The October hack, attributed by Mandiant with high confidence to North Korean state-sponsored group UNC4736 (Citrine Sleet / AppleJeus), involved a months-long social engineering campaign, macOS malware deployment on developer devices, and manipulation of hardware wallet signing interfaces to drain funds across BNB Chain and Arbitrum.
avoid.net/fixedfloat→10/100[CRITICAL]FixedFloat (ff.io) is a non-custodial, no-KYC cryptocurrency swap exchange launched in 2018 that suffered two confirmed security breaches in 2024 totaling approximately $28.9 million in stolen assets. Both attacks were attributed to the same threat actor exploiting vulnerabilities in FixedFloat's third-party hosting provider, Time4VPS, and stolen funds were routed through the eXch mixer — a service subsequently shut down by German authorities for laundering proceeds from major crypto thefts. The platform resumed operations after a two-month suspension but has faced ongoing scrutiny for its anonymity-first model, opaque team structure, and inadequate incident disclosure.
avoid.net/curio→10/100[CRITICAL]Curio (CurioDAO) is a multi-chain real-world asset (RWA) DeFi protocol that suffered a critical smart contract exploit on March 23, 2024, resulting in approximately $16 million in losses after an attacker exploited a voting-power privilege escalation vulnerability to mint approximately 1 billion unauthorized CGT governance tokens. The protocol had no known third-party security audits prior to the exploit and relied on internal reviews. Curio announced a recovery plan including a new CGT 2.0 token and a phased compensation program, though independent verification of full compensation delivery remains limited.
avoid.net/grand-base→5/100[CRITICAL]Grand Base was a decentralized real-world asset (RWA) synthetic trading protocol launched on Coinbase's Base layer-2 blockchain in early 2024. On April 15, 2024, the protocol suffered a critical security incident in which its deployer wallet was compromised, allowing an attacker to mint approximately 32.5 million unauthorized GB tokens and drain roughly $2 million in liquidity. The GB token subsequently lost over 99% of its value; no verified recovery or compensation plan has been confirmed, and the project's long-term operational status remains uncertain.
avoid.net/socket-security-malicious-browser-extension-campaign-august-2026→2/100[CRITICAL]On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.
avoid.net/term-finance-governance-exploit-august-2026→10/100[CRITICAL]On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.
avoid.net/defi-governance-attack-wave-2026→0/100[CRITICAL]Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.
avoid.net/coinkite-coldcard→13/100[CRITICAL]Coinkite is a Toronto-based Bitcoin hardware company founded in 2013 by Rodolfo Novak and Peter Gray, best known for its Coldcard hardware wallet, which had been widely regarded as one of the most secure Bitcoin signing devices available. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coldcard devices — a build configuration error introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of the device's hardware entropy source — draining an estimated $116 million to $130 million in Bitcoin from more than 5,200 addresses across at least four attack waves, making it the largest hardware wallet exploit in crypto history. Legal proceedings are anticipated and Coinkite has suspended its data deletion policy while victims and law firms assess potential litigation.
avoid.net/h1-2026-crypto-hack-landscape-ai-agent-attack-vector-emerges→0/100[CRITICAL]The first half of 2026 established a new all-time record for cryptocurrency exploit frequency, with 207–212 verified incidents (varying by methodology) resulting in $972 million to $1.32 billion in losses depending on the reporting firm. North Korea's Lazarus Group (TraderTraitor subunit) was responsible for approximately 55–66% of total losses through two concentrated attacks in April 2026, while AI-powered autonomous agents emerged as a distinct and novel attack surface for the first time in widely documented crypto security history.
avoid.net/june-2026-cross-chain-bridge-exploit-127m-three-protocols→10/100[CRITICAL]An alleged coordinated cross-chain bridge exploit on June 14, 2026 is described as draining $127 million from three DeFi protocols — identified only as BridgeLink, CrossFlow, and Relay Protocol — across Ethereum, Arbitrum, and Polygon in under 12 minutes. This specific incident, including the protocol names, the $127M figure, and the 03:42 UTC timestamp, cannot be independently verified through any Tier 1 or Tier 2 source as of June 30, 2026; the sole primary source is a blog post by Nadcab Labs, an Indian blockchain development services company with a commercial interest in publishing DeFi security content. While a severe pattern of verified cross-chain bridge exploits across 2026 provides real context, the specific claims in this investigation request should be treated as unverified until corroborated by credible on-chain analysis or major news coverage.
avoid.net/abracadabra-money-mim-depeg-june-2026→12/100[CRITICAL]Abracadabra Money's Magic Internet Money (MIM) stablecoin experienced a severe depeg event in June 2026, falling from its $1 target to approximately $0.43–$0.50, a collapse of over 50%. The crisis built over ten days beginning June 15, 2026, and was accompanied by $994 million in cross-market liquidations and a broader crypto market downturn. Emergency measures launched June 25 — including sharply raised Cauldron interest rates and suspended Curve bribes — represent the protocol's fourth major stability incident since 2024.
avoid.net/bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m→0/100[CRITICAL]BridgeLink, CrossFlow, and Relay Protocol are three DeFi bridge protocols alleged to have been drained of a combined $127 million in a coordinated cross-chain exploit beginning at 03:42 UTC on June 14, 2026. The incident is described as exploiting a signature replay vulnerability combined with premature finality acceptance across Ethereum, Arbitrum, and Polygon. As of June 16, 2026, no Tier 1 or Tier 2 sources — including CoinDesk, The Block, Reuters, or Bloomberg — have published corroborating coverage, and no on-chain transaction hashes or official protocol statements have been publicly produced; the investigation page reflects low source confidence accordingly.
avoid.net/lucifer-drainer→0/100[CRITICAL]Lucifer Drainer is a criminal drainer-as-a-service (DaaS) platform that industrializes cryptocurrency wallet theft through a structured affiliate model. Active since at least early 2025, it operates by providing affiliates with phishing kits, automated site-cloning tools, and commission-split infrastructure (operators retain 20% per successful drain) while affiliates supply phishing traffic. Despite Telegram bot bans in August 2025 and documentation domain suspension in November 2025, the operation migrated to IPFS and remained active as of May 2026, making it one of the most operationally resilient drainer platforms in the current threat landscape.
avoid.net/cryptospain-lvaro-romillo-madeira-invest-club→3/100[CRITICAL]Álvaro Romillo Castillo, a Spanish crypto influencer known online as CryptoSpain, was arrested on November 6, 2025, and ordered held without bail by Spain's National Court on charges of mass fraud and leading a criminal organization through Madeira Invest Club (MIC). Prosecutors allege MIC operated as a Ponzi scheme from early 2023 through September 2024, collecting approximately €185.5 million from 3,062 investors across multiple countries by promising guaranteed returns of up to 20% on fictitious luxury-asset contracts. As of May 2026, ten defendants have been formally charged and the case remains in pre-trial proceedings before Judge José Luis Calama; no verdict has been entered.
avoid.net/uwulend→8/100[CRITICAL]UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave, founded in September 2022 by Michael Patryn (pseudonym 0xSifu), co-founder of the collapsed Canadian crypto exchange QuadrigaCX. In June 2024, the protocol suffered two successive exploits totaling approximately $23 million — a $19.3 million oracle manipulation attack on June 10 followed by a $3.7 million secondary drain on June 13 by the same attacker — rendering it one of the largest DeFi hacks of 2024. The protocol's association with a founder carrying prior criminal convictions and a history of involvement in failed or scandal-ridden crypto ventures constitutes a persistent and material reputational and risk concern.
avoid.net/anubis-dao→2/100[CRITICAL]AnubisDAO was a dog-themed DeFi project that launched a 24-hour token sale on October 28, 2021, raising approximately 13,597 ETH (~$60 million) through the sale of its native ANKH token on the Copper liquidity bootstrapping platform. Twenty hours into the fundraise, all pooled funds were drained to an external wallet by the address that had created and controlled the liquidity pool, leaving investors holding worthless ANKH tokens with no liquid market. No funds have been recovered; the project had no website, whitepaper, or publicly identified team at launch.
avoid.net/libra-token→2/100[CRITICAL]LIBRA ($LIBRA) is a Solana-based memecoin launched on February 14, 2025 by Kelsier Ventures as part of the 'Viva La Libertad' project, and publicly endorsed by Argentine President Javier Milei minutes after its creation. Within roughly one hour, the token's market cap peaked near $4.6 billion before crashing approximately 89% as insider wallets linked to the founding team extracted an estimated $87–107 million in liquidity, leaving an estimated 44,000–114,000 retail investors with severe losses. The incident triggered over 112 criminal complaints in Argentina, a federal fraud investigation, congressional proceedings, international asset freezes, and an Interpol Red Notice request against key operator Hayden Davis.
avoid.net/zkasino→3/100[CRITICAL]ZKasino was a Web3 gambling platform that raised approximately $33 million from over 10,000 investors through a 'Bridge-to-Earn' campaign in early 2024, promising depositors their ETH would be returnable within 30 days. Instead, the platform converted depositor ETH into its native ZKAS tokens and staked the funds on Lido without user consent, prompting Dutch authorities (FIOD) to arrest founder Elham Nourzai in April 2024 and seize over EUR 11 million in assets. A second suspect linked to the WhiteRock token project was arrested in the UAE in July 2025 and faces extradition to the Netherlands, while partial refunds to affected depositors remained incomplete as of late 2025.
avoid.net/mango-markets→12/100[CRITICAL]Mango Markets was a Solana-based decentralized trading platform offering spot trading, perpetual futures, and lending with cross-margining. In October 2022, trader Avraham Eisenberg executed an oracle manipulation attack, draining approximately $116–117 million from the protocol through artificially inflated MNGO collateral. The protocol subsequently faced enforcement actions from the DOJ, SEC, and CFTC, settled with regulators in 2024, and formally shut down in January 2025.
avoid.net/genesis-global→8/100[CRITICAL]Genesis Global Capital, LLC was the institutional crypto lending subsidiary of Digital Currency Group (DCG), founded in 2018 as an extension of Genesis Global Trading. Following cascading losses from Three Arrows Capital's June 2022 default and FTX's November 2022 collapse, Genesis halted customer withdrawals on November 16, 2022 and filed for Chapter 11 bankruptcy on January 19, 2023, with liabilities estimated between $1 billion and $10 billion owed to over 100,000 creditors. The entity faced multiple regulatory actions including SEC charges for unregistered securities offerings, a New York Attorney General fraud lawsuit naming DCG CEO Barry Silbert by name, and a separate 2025 SEC settlement against DCG and former Genesis CEO Soichiro Moro for misleading investors about Genesis's financial condition.
avoid.net/bnb-chain-bridge→16/100[CRITICAL]The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.
avoid.net/blender-io→0/100[CRITICAL]Blender.io was a Bitcoin mixing service that operated from approximately 2018 to 2022, processing over $500 million in Bitcoin before being shut down. On May 6, 2022, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated it as a Specially Designated National, marking the first time a virtual currency mixer had ever been sanctioned by the United States government. The service was designated for its role in laundering over $20.5 million in proceeds from North Korea's Lazarus Group following the $620 million Ronin Network hack, as well as for processing funds tied to Russian ransomware groups and the Hydra darknet market.
avoid.net/fake-jupiter-cjup-airdrop-phishing-campaign→0/100[CRITICAL]An ongoing phishing campaign impersonates Jupiter Exchange (Solana DEX aggregator) by airdropping counterfeit tokens labeled '$CJUP' directly into Solana wallets, then directing recipients to wallet-draining websites that automatically empty connected wallets. First documented in early 2024 and still active as of May 2026, the campaign exploits the widespread recognition of Jupiter's legitimate annual 'Jupuary' airdrop program, which has distributed over $1 billion in real $JUP tokens since 2024.
avoid.net/catfi-memecoin-eth-father-park→0/100[CRITICAL]CATFI is a Solana-based memecoin launched in early 2025 via Pump.fun that was the subject of a coordinated rug pull orchestrated by a South Korean operator known online as 'Eth Father,' identified by prosecutors only as Mr. Park. The scheme artificially inflated the token 1,001-fold within 26 hours before a mass exit drained investor funds, causing approximately 900 million KRW (~$600,000) in losses across at least 256 victims. In May 2026 the Seoul Southern District Prosecutors' Office charged five individuals, marking South Korea's first criminal prosecution of a decentralized-exchange rug pull under the Virtual Asset User Protection Act.
avoid.net/exmo-exchange-limited→4/100[CRITICAL]EXMO Exchange Limited is a UK-registered cryptocurrency exchange founded circa 2013 by Russian nationals Eduard Bark and Ivan Petukhovskiy. The exchange suffered a hot wallet hack in December 2020 losing approximately $10.5 million in user funds, faced multiple regulatory failures including a failed FCA registration and a UK ASA ruling for misleading advertising, and was sanctioned by the UK government on May 26, 2026 under Russia (Sanctions) (EU Exit) Regulations 2019 for alleged facilitation of Russian sanctions evasion via transactions with sanctioned entities Garantex, Grinex, and Chatex totaling over $19.5 million. Blockchain analysis by TRM Labs found that EXMO's claimed operational separation from its Russia-facing spinoff EXMO.me was not reflected in actual custodial wallet infrastructure.
avoid.net/solana-mev-sandwich-bots→0/100[CRITICAL]Solana MEV sandwich bots are automated programs that exploit Solana's transaction ordering mechanisms to front-run and back-run retail user trades, extracting an estimated $370 million to $500 million from users between January 2024 and May 2025. The practice has drawn enforcement responses from the Solana Foundation, Jito Labs, and Marinade Finance, and is the subject of an active federal class-action lawsuit in the Southern District of New York naming Pump.fun, Solana Labs, and related entities. While coordinated countermeasures reduced attack profitability by an estimated 60-70% in 2025, attacks continue and disproportionately harm memecoin traders using high slippage settings on Raydium and Pump.fun.
avoid.net/radiant-capital→18/100[CRITICAL]Radiant Capital is a decentralized cross-chain lending protocol built on LayerZero that launched in July 2022 on Arbitrum. In 2024 it suffered two separate security incidents totaling approximately $54.5 million in losses: a $4.5 million flash loan exploit in January 2024 and a $50 million multisig compromise in October 2024 attributed by Mandiant to North Korean state-sponsored hackers (UNC4736/Citrine Sleet). The October 2024 hack reduced TVL by roughly 98%, led to major exchange delistings, and stolen funds were subsequently laundered through Tornado Cash.
avoid.net/the-dao→10/100[CRITICAL]The DAO was a decentralized autonomous organization launched on the Ethereum blockchain in April 2016 that raised approximately $150 million in Ether — the largest crowdfunding to date at the time — before being drained of 3.6 million ETH (roughly $50–60 million) on June 17, 2016, via a reentrancy vulnerability in its smart contract code. The hack triggered an acrimonious debate over blockchain immutability and led to a contentious hard fork of the Ethereum network on July 20, 2016, splitting it into Ethereum (ETH) and Ethereum Classic (ETC). In 2017 the U.S. SEC concluded that DAO tokens constituted unregistered securities, marking a landmark regulatory precedent for the entire crypto industry.
avoid.net/parity-multisig→5/100[CRITICAL]Parity Multisig was a multi-signature wallet implementation developed by Parity Technologies, founded by Ethereum co-founder Gavin Wood. The software suffered two catastrophic security failures in 2017: a July hack in which 153,037 ETH (approximately $30–32 million at the time) was stolen from three Ethereum project wallets via an unguarded initialization function, and a November incident in which GitHub user devops199 accidentally triggered a self-destruct on the shared library contract, permanently freezing 513,774 ETH (approximately $150–280 million at the time) across 587 wallets. The frozen funds have never been recovered, and the July 2017 attacker resumed laundering stolen ETH through the exchange eXch in May 2024 after seven years of inactivity.
avoid.net/cheesebank→18/100[CRITICAL]Cheese Bank was an Ethereum-based DeFi lending protocol that launched in September 2020 and suffered a $3.3 million exploit on November 6, 2020, caused by a flash loan attack combined with price oracle manipulation on Uniswap. The anonymous team claimed to have patched the vulnerability, but the protocol never recovered meaningful activity, the CHEESE token collapsed in value, and the project is widely considered abandoned. ZachXBT has flagged the entity as a high-risk project.
avoid.net/alpha-finance→18/100[CRITICAL]Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) is a DeFi protocol best known for its leveraged yield farming product Alpha Homora. On February 13, 2021, Alpha Homora V2 was exploited for approximately $37.5 million via a sophisticated attack that required insider knowledge of an unannounced smart contract, draining funds from its Iron Bank (Cream Finance) integration. By March 2023, the protocol had repaid less than 2% of the resulting $32 million debt to Iron Bank despite a formal repayment agreement, triggering a second crisis in which user funds were frozen.
avoid.net/spartan→12/100[CRITICAL]Spartan Protocol is a decentralized liquidity and synthetic-asset protocol that launched on Binance Smart Chain (BSC) in 2020 and was operated by a fully anonymous, community-driven team. On May 2, 2021, a critical vulnerability in the protocol's liquidity-share calculation logic was exploited via flash loan, resulting in approximately $30 million in stolen funds — ranking it among the largest DeFi exploits of that era. The protocol attempted a v2 rebuild with re-audited contracts but has since fallen to near-zero TVL and market cap, with no meaningful development activity recorded after 2024.
avoid.net/rari-capital→8/100[CRITICAL]Rari Capital was a DeFi yield-aggregation and lending protocol launched in July 2020 by teenage co-founders Jai Bhavnani, Jack Lipstone, and David Lucid. It suffered two major security exploits — a $11 million hack in May 2021 and an $80 million reentrancy hack in April 2022 — and subsequently merged with Fei Protocol to form Tribe DAO before winding down in 2022. In September 2024, the SEC secured final court judgments against the company and all three co-founders for misleading investors and operating as unregistered brokers.
avoid.net/squid-games→2/100[CRITICAL]SQUID was a BEP-20 token on the Binance Smart Chain launched in late October 2021 that exploited the viral popularity of the Netflix series 'Squid Game.' On November 1, 2021, anonymous developers executed a rug pull, draining at least $3.38 million in liquidity and abandoning the project, causing the token price to collapse from a peak of $2,861.80 to effectively zero within minutes. More than 43,000 investors suffered losses, with no arrests made and the perpetrators remaining unidentified as of mid-2026.
avoid.net/grim-finance→8/100[CRITICAL]Grim Finance was a Fantom-based DeFi yield optimizer (fork of Beefy Finance) that suffered a devastating reentrancy exploit on December 19, 2021, resulting in approximately $30 million in user funds stolen. The vulnerability — a missing reentrancy guard in the depositFor() function — had existed in an audited codebase and was classified by security researchers as an entirely preventable, well-understood attack class. The protocol has since collapsed to a near-zero TVL of roughly $29,000 and its proposed compensation plan yielded no meaningful restitution for affected users.
avoid.net/beanstalk→12/100[CRITICAL]Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.
avoid.net/uwerx→12/100[CRITICAL]Uwerx (WERX) was a purported decentralized freelancing platform that conducted a multi-stage token presale in 2023 before suffering a flash loan exploit on August 2, 2023, one day after its Uniswap listing, resulting in the loss of approximately 176 ETH (~$324,000). Despite two prior smart contract audits by SolidProof and InterFi Network, neither audit identified the exploited vulnerability. The project subsequently relaunched on Polygon in October 2023 but has since been listed as abandoned on CoinSniper, with the token trading at effectively zero value and only six recorded holders as of early 2026.
avoid.net/polynetwork→10/100[CRITICAL]Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered two major security breaches: a $610 million exploit in August 2021 (the largest DeFi hack at the time, with funds ultimately returned) and a second exploit in July 2023 in which attackers minted billions in notional value of tokens, extracting an estimated $10–20 million in real assets. The protocol permanently terminated all services on September 30, 2024.
avoid.net/dexx→10/100[CRITICAL]DEXX is a Solana-based on-chain memecoin trading terminal that suffered a catastrophic private key compromise on November 16, 2024, resulting in approximately $30 million in user losses across more than 8,600 wallets. Despite marketing itself as non-custodial, DEXX stored user private keys in plaintext on its own servers — a centralization risk that CertiK had flagged as unresolved prior to the breach. A partial compensation initiative led by LBank was announced in early 2025, but full recovery of stolen funds remains unlikely as the attacker laundered substantial ETH through Tornado Cash.
avoid.net/zklend→20/100[CRITICAL]zkLend was a decentralized money-market lending protocol built on Starknet (Ethereum Layer 2), founded in 2022 by Brian Fu and Jane Ma and backed by Delphi Digital, Three Arrows Capital, and StarkWare. On February 11–12, 2025, the protocol suffered a critical flash-loan exploit that drained approximately $9.57 million in user funds through manipulation of the lending_accumulator variable and precision-loss rounding errors. The protocol permanently ceased operations in June 2025, allocating a $200,000 treasury remnant to a user recovery fund — leaving the vast majority of affected users uncompensated.
avoid.net/forcebridge→20/100[CRITICAL]ForceBridge is a cross-chain bridge operated by Magickbase on the Nervos Network (CKB), enabling transfers between Nervos and Ethereum and BNB Chain. On June 2, 2025, the bridge was exploited via an access control vulnerability — likely a compromised private key — resulting in approximately $3.7–3.9 million in user funds being stolen and laundered through Tornado Cash. The exploit occurred just one day after Magickbase announced the bridge's sunset, raising questions about the timing and origin of the attack.
avoid.net/lmlusdt-staking-protocol→4/100[CRITICAL]The LML/USDT staking protocol was a yield-bearing staking contract deployed on Binance Smart Chain (BSC) that suffered a catastrophic price manipulation exploit on April 1, 2026, resulting in approximately $950,000 in losses. An attacker aggregated flash loans totaling 309,529,000 USDT, artificially inflated the LML token price by purchasing nearly the entire circulating supply and burning it, then claimed outsized staking rewards against the manipulated price. Stolen funds — converted to 450.6 ETH — were subsequently laundered through Tornado Cash, and no public team response or recovery effort has been documented.
avoid.net/satish-kumbhani→0/100[CRITICAL]Satish Kumbhani is the founder of BitConnect, a cryptocurrency platform that the U.S. Department of Justice, SEC, and multiple state regulators have determined operated as a global Ponzi scheme defrauding investors of approximately $2.4 billion between 2016 and 2018. Kumbhani was indicted by a federal grand jury in San Diego on February 25, 2022, on charges carrying a maximum penalty of 70 years in prison, and has remained a fugitive from justice since disappearing from India following his U.S. indictment.
avoid.net/justin-sun→7/100[CRITICAL]Justin Sun is the founder of the TRON blockchain and TRX token, and the controlling figure behind HTX (formerly Huobi) and Poloniex exchanges. In March 2023, the U.S. Securities and Exchange Commission charged Sun and three of his companies with fraud, market manipulation through wash trading, unregistered securities offerings, and orchestrating an undisclosed celebrity promotion scheme; the case partially settled in March 2026 with Rainberry Inc. paying a $10 million penalty while claims against Sun personally were dismissed. Sun has faced additional scrutiny including a reported FBI/DOJ criminal investigation, UK sanctions against an HTX entity over alleged Russia-linked transactions, a $114 million hot-wallet hack at Poloniex in November 2023, and disputed claims of diplomatic immunity through a Grenada WTO ambassadorship he held until mid-2022.
avoid.net/sinbad-io→2/100[CRITICAL]Sinbad.io was a Bitcoin mixing service that operated from October 2022 until its seizure by U.S., Dutch, and Finnish law enforcement in November 2023. OFAC designated it a key money-laundering tool of North Korea's Lazarus Group, which used it to launder proceeds from multiple major crypto hacks including Axie Infinity's Ronin Bridge and Atomic Wallet. On-chain analytics firms assessed it to be highly likely a rebranding of Blender.io, the first crypto mixer ever sanctioned by OFAC.
avoid.net/fei-rari→6/100[CRITICAL]Fei Protocol and Rari Capital merged in December 2021 under Tribe DAO to form a combined DeFi liquidity and lending platform. On April 30, 2022, a reentrancy attack targeting a known flaw in the Compound Finance codebase drained approximately $80 million from seven Rari Fuse lending pools. Tribe DAO ultimately wound down in late 2022 following contentious governance disputes over victim compensation, and Rari Capital's co-founders faced SEC enforcement action in 2024.
avoid.net/nomad-bridge→8/100[CRITICAL]Nomad Bridge, operated by Illusory Systems Inc., was a cross-chain asset bridge that suffered a catastrophic $190 million exploit on August 1, 2022, when a routine smart contract upgrade inadvertently initialized trusted Merkle roots to a zero value, rendering all message proofs automatically valid. The vulnerability enabled a widely replicated 'crowd-sourced' draining event involving approximately 300 addresses over roughly 150 minutes — widely regarded as the first 'permissionless' mass-exploitation event in DeFi history. Subsequent actions include a class-action lawsuit, a December 2025 FTC settlement requiring repayment of approximately $37.5 million to affected users, and the 2025 arrest and extradition of a key suspect, Russian-Israeli national Alexander Gurevich.
avoid.net/harmony-horizon-bridge→4/100[CRITICAL]The Harmony Horizon Bridge was a cross-chain bridge enabling asset transfers between Harmony, Ethereum, and Binance Smart Chain. On June 23–24, 2022, attackers exploited a critically under-configured 2-of-5 multisignature scheme to steal approximately $99.7 million across 14 asset types. The FBI formally attributed the attack to the North Korean state-linked Lazarus Group (APT38) in January 2023.
avoid.net/chipmixer→0/100[CRITICAL]ChipMixer was a darknet Bitcoin mixing service that operated from August 2017 to March 2023, processing over $3 billion in illicit cryptocurrency on behalf of ransomware groups, North Korean state hackers, Russian military intelligence, and darknet drug markets. On March 15, 2023, U.S. and German authorities seized its infrastructure, domains, and approximately $46 million in cryptocurrency in a coordinated international takedown. Minh Quoc Nguyen, 49, a Vietnamese national residing in Hanoi, was charged in the Eastern District of Pennsylvania with money laundering, operating an unlicensed money transmitting business, and identity theft; he remains a fugitive.
avoid.net/valuedefi→8/100[CRITICAL]Value DeFi (formerly YFValue/YFV) was a DeFi yield aggregation and AMM protocol that suffered three documented security exploits between August 2020 and May 2021, resulting in combined losses of approximately $24 million. Beyond the technical failures, the project was found to have used a paid actress from Fiverr to impersonate a co-founder named 'Anna Tanaka,' raising severe concerns about team identity, transparency, and intent. The VALUE token is effectively defunct, trading at a fraction of a cent with a near-zero market cap.
avoid.net/bearnfi→12/100[CRITICAL]bEarn.fi (BearnFi) is a Binance Smart Chain-based cross-chain yield farming and algorithmic stablecoin protocol that launched in late 2020. On May 16, 2021, an attacker exploited a smart contract denomination mismatch to drain approximately $10.85 million in BUSD from the protocol's bVaults via a flash loan attack. The project subsequently became inactive, with its native BFI token recording no price data after mid-2023 and a market capitalization of effectively zero. The entity has been flagged by ZachXBT.
avoid.net/mirror→5/100[CRITICAL]Mirror Protocol was a Terra-based DeFi platform enabling synthetic assets (mAssets) that tracked prices of US stocks. The protocol suffered a $90 million exploit in October 2021 that went undetected for seven months, a governance attack campaign in December 2021 targeting $40 million in community funds, and a second $2 million oracle exploit in May 2022. It became permanently inactive in August 2022 following the catastrophic collapse of the Terra/LUNA/UST ecosystem, which was orchestrated by its parent company Terraform Labs under Do Kwon, who was subsequently convicted of fraud and sentenced to 15 years in prison.
avoid.net/indexed-finance→12/100[CRITICAL]Indexed Finance was an Ethereum-based decentralized protocol offering passively managed index pools, launched in late 2020. On October 14, 2021, the protocol suffered a sophisticated $16 million flash loan exploit targeting its DEFI5 and CC10 pools, destroying most user funds. The alleged attacker, Canadian mathematics prodigy Andean Medjedovic, was later charged by U.S. prosecutors in February 2025 in connection with $65 million in combined DeFi thefts and remains a fugitive as of early 2026.
avoid.net/anubisdao→2/100[CRITICAL]AnubisDAO was an OlympusDAO fork that launched on October 28, 2021, and raised approximately 13,556 WETH (roughly $60 million) in under 20 hours through a Copper Liquidity Bootstrapping Pool. Before the sale concluded, the entire pool was drained to an external wallet, wiping investors to zero; on-chain investigator ZachXBT later identified two pseudonymous actors — Beerus and Ersan — as the likely perpetrators, and traced the stolen funds through Tornado Cash in 2023. No criminal charges have been publicly confirmed, no investor recovery has occurred, and the ANKH token is worthless.
avoid.net/monox→10/100[CRITICAL]MonoX was a decentralized exchange protocol built on Ethereum and Polygon using a novel single-token liquidity model, which raised $5M in September 2021 and launched mainnet shortly before suffering a critical smart contract exploit on November 30, 2021. The attacker exploited a missing validation check in the swap function — using the MONO token as both input and output — to artificially inflate its price and drain approximately $31M in user funds across both chains. The protocol attempted a relaunch via MonoX 2.0 with a debt-token compensation mechanism, but MONO has since collapsed to near-zero value with negligible trading activity.
avoid.net/bitmart→18/100[CRITICAL]BitMart is a centralized cryptocurrency exchange that operated for nine years before announcing a wind-down on July 26, 2026, citing a nine-year run and the decision to cease operations. On August 21, 2026, the exchange reversed course, announcing it was exploring a restructuring plan with law firm White & Case as an alternative to full closure, while trading halted as scheduled on August 26. The restructuring pivot occurred amid mounting user reports of frozen or throttled withdrawals, allegations of unpaid employee wages, an unreleased proof-of-reserves commitment, and on-chain data showing sharply reduced outflows — patterns that critics have compared to the pre-collapse behavior of failed exchanges in 2022.
avoid.net/launchzone→18/100[CRITICAL]LaunchZone (LZ) was a Binance Smart Chain-based DeFi launchpad and IDO platform originally launched as BSCex in December 2020, later rebranded in March 2021. On February 27, 2023, the protocol suffered a critical smart contract exploit in its Bscex SwapX contract, resulting in approximately $700,000 drained from its liquidity pool and a total of nearly $7.8 million in cumulative losses as additional vulnerable contracts were identified. The platform ceased operations on March 26, 2023, with over 75,000 user wallets remaining exposed weeks after the initial attack. ZachXBT has flagged this entity as a risk.
avoid.net/myalgo→12/100[CRITICAL]MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.
avoid.net/kokomo-finance→2/100[CRITICAL]Kokomo Finance was a purported non-custodial lending and borrowing protocol launched on the Optimism blockchain on March 25, 2023. Within approximately 24 hours of launch, its developers executed a deliberate exit scam, stealing approximately $4 to $4.5 million in user funds through smart contract manipulation. The project was subsequently linked by on-chain investigator ZachXBT to a serial scam ring responsible for over $20 million in losses across multiple DeFi protocols.
avoid.net/bitrue→18/100[CRITICAL]Bitrue is a Singapore-incorporated centralized cryptocurrency exchange founded in 2018 that suffered a confirmed $23 million hot wallet exploit in April 2023, with stolen funds subsequently laundered through Tornado Cash as recently as June 2025. The exchange holds no license from Singapore's Monetary Authority (MAS) and relies on a VASP registration in Lithuania — a lower-tier regulatory framework — while accumulating a persistent record of user complaints alleging unjustified account freezes and asset seizures.
avoid.net/jimbos-protocol→18/100[CRITICAL]Jimbos Protocol was an Arbitrum-based DeFi liquidity protocol designed to provide a semi-stable floor price for its native JIMBO token. On May 28, 2023, just three days after launching its V2, the protocol was exploited via a flash loan attack that drained approximately 4,090 ETH (~$7.5 million) by exploiting a lack of slippage control in the JimboController contract. The attacker rejected a $800,000 bounty offer, laundered the full amount through Tornado Cash, and remains unidentified; no funds have been recovered.
avoid.net/multichain→10/100[CRITICAL]Multichain (formerly AnySwap) was a cross-chain bridge protocol that collapsed in mid-2023 following the arrest of its CEO Zhaojun by Chinese police in May 2023, which resulted in the seizure of private keys controlling over $1.5 billion in user assets. On July 7, 2023, approximately $126–127 million was drained from Multichain bridge reserves in transfers widely attributed to Chinese authorities or insiders with access to the CEO's confiscated key material. The protocol formally ceased operations on July 14, 2023, leaving users with unrecoverable losses.
avoid.net/bald→4/100[CRITICAL]BALD was a memecoin launched on Coinbase's Base Layer 2 network on July 29, 2023, allegedly named as a reference to Coinbase CEO Brian Armstrong's appearance. After attracting over $66 million in ETH to its liquidity pool through aggressive liquidity additions and a price surge of approximately 4,000,000% within 24 hours, the anonymous deployer removed approximately $25.6 million in liquidity on July 31, 2023, causing the token price to collapse by roughly 90%. On-chain investigators linked the deployer's wallet to addresses with documented interactions with Alameda Research, with Wintermute's head of research publicly identifying former Alameda co-CEO Sam Trabucco as the most likely suspect — though no conclusive proof of identity was ever established.
avoid.net/poloniex→10/100[CRITICAL]Poloniex is a cryptocurrency exchange founded in 2014 and acquired in 2019 by an investor group led by Tron founder Justin Sun. On November 10, 2023, the exchange suffered one of the largest hot wallet compromises in crypto history, with attackers draining approximately $126 million across Ethereum, TRON, and Bitcoin networks in an attack attributed by multiple blockchain security firms to North Korea's Lazarus Group. The exchange has also faced significant regulatory enforcement actions, including a $7.59 million OFAC sanctions settlement and a $10.4 million SEC settlement for operating an unregistered national securities exchange.
avoid.net/orbit-bridge→10/100[CRITICAL]Orbit Bridge is a cross-chain interoperability protocol developed by South Korean blockchain firm Ozys that suffered one of the largest bridge exploits in crypto history on December 31, 2023, losing approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI. The attacker allegedly compromised seven of ten multisig signatories after a former chief information security officer allegedly weakened the company firewall before departing, and blockchain analysts have linked the attack's patterns to North Korea's Lazarus Group, though no formal attribution has been confirmed by authorities. As of 2025, the majority of stolen funds remain unrecovered, with the attacker having laundered over 17,000 ETH through Tornado Cash.
avoid.net/abracadabra-spell→10/100[CRITICAL]Abracadabra.money is a multi-chain DeFi lending protocol that allows users to mint the MIM (Magic Internet Money) USD-pegged stablecoin using interest-bearing tokens as collateral. The protocol has been compromised three times since January 2024, losing a combined total of over $21 million, and its founding ecosystem was shaken in January 2022 when co-founder Daniele Sestagalli's associate — Wonderland's pseudonymous treasury manager known as 0xSifu — was publicly identified as Michael Patryn, a convicted felon and co-founder of the fraudulent exchange QuadrigaCX. The SPELL token has declined approximately 99.5% from its November 2021 all-time high, and the protocol's total value locked has collapsed from over $776 million to under $30 million.
avoid.net/atomic-wallet-hack→0/100[CRITICAL]In June 2023, Atomic Wallet — an Estonian non-custodial cryptocurrency wallet with approximately five million users — suffered a major security breach in which attackers drained funds from an estimated 5,500 user wallets. Blockchain analytics firms Elliptic and on-chain investigators attributed the attack to North Korea's Lazarus Group with high confidence, and the FBI later confirmed this attribution. The total loss figure is disputed, with Elliptic placing it above $100 million and independent researcher Taylor Monahan estimating a minimum of $115 million; the underlying attack vector was never publicly confirmed by Atomic Wallet.
avoid.net/easyfi-network→18/100[CRITICAL]EasyFi Network was a Polygon-based DeFi lending protocol that suffered one of the largest private-key compromise incidents in early DeFi history. On April 19, 2021, an attacker remotely compromised founder Ankitt Gaur's machine and extracted MetaMask admin keys, stealing approximately $6 million in stablecoins and 2.98 million EASY tokens (face value ~$75–80 million, liquid value ~$6 million). Following a hard fork to a new EZ token and a partial compensation plan, the protocol never recovered meaningful adoption; the EZ token as of 2025 trades at near-zero value.
avoid.net/changpeng-zhao→8/100[CRITICAL]Changpeng Zhao (CZ), born February 10, 1977, is the founder and former CEO of Binance, the world's largest cryptocurrency exchange by trading volume. On November 21, 2023, Zhao pleaded guilty to a federal charge of failing to implement an effective anti-money laundering (AML) program under the Bank Secrecy Act, as part of a landmark $4.3 billion resolution between Binance and U.S. federal regulators. He was sentenced to four months in federal prison in April 2024, served that term, and was subsequently pardoned by President Donald Trump in October 2025.
avoid.net/compounder-finance→2/100[CRITICAL]Compounder Finance was an Ethereum-based DeFi yield aggregator that launched in November 2020 and executed a deliberate rug pull approximately 22 days later, stealing between $10.8 million and $12.5 million from investors. Anonymous developers embedded hidden 'Evil Strategy' smart contracts behind a publicly visible but unmonitored 24-hour timelock, then drained all user funds and deleted the project's website and social media accounts. No funds were recovered and the perpetrators have never been publicly identified.
avoid.net/lubian→5/100[CRITICAL]LuBian (lubian.com) was a China-based Bitcoin mining pool that briefly ranked among the world's six largest before ceasing operations in early 2021. The pool is alleged to have functioned as a money laundering vehicle for Chen Zhi's Prince Group, a transnational criminal organization that operated forced-labor pig-butchering scam compounds in Cambodia. In October 2025, the U.S. Department of Justice announced the largest forfeiture in its history — approximately 127,271 BTC (~$15 billion) — directly linked to LuBian and Chen Zhi's criminal enterprise.
avoid.net/cover-protocol→18/100[CRITICAL]Cover Protocol was a decentralized insurance marketplace on Ethereum, launched in November 2020 after a troubled rebrand from the failed SAFE token project. On December 28, 2020, a critical smart contract vulnerability in its Blacksmith farming contract allowed an attacker to mint approximately 40 quintillion COVER tokens and extract over $4 million in assets, crashing the token price by more than 97%. After a failed merger with Yearn Finance and the abrupt departure of core developers, the protocol permanently shut down on September 5, 2021, distributing remaining treasury funds to token holders.
avoid.net/furucombo→10/100[CRITICAL]Furucombo is an Ethereum-based DeFi composability protocol launched in March 2020 that enables users to batch complex multi-protocol transactions via a drag-and-drop interface. On February 27, 2021, the protocol suffered a critical 'evil contract' exploit in which an attacker spoofed a new Aave v2 implementation via Furucombo's proxy, draining approximately $14–15 million in ETH and ERC-20 tokens from 22 users who had granted standing token approvals to the platform. The team responded with a compensation plan issuing iouCOMBO tokens subject to a 360-day vesting schedule, but the incident exposed fundamental risks in delegatecall-based proxy architectures and broad token approval models.
avoid.net/easyfi→10/100[CRITICAL]EasyFi was a Layer 2 DeFi lending protocol operating on Polygon Network, forked from Compound Finance, that suffered one of the largest DeFi hacks of 2021 when an attacker compromised the CEO's MetaMask admin keys on April 19, 2021, stealing approximately $81 million in EASY tokens and stablecoins. The protocol attempted a hard fork and compensation plan, but a significant portion of token holders on decentralized exchanges alleged they remained uncompensated, and community members raised concerns about transparency, censorship of dissent, and the fundamental security failure of managing over $100 million in assets through a single admin key held in a browser extension. ZachXBT has flagged EasyFi as a high-risk entity.
avoid.net/popsicle-finance→12/100[CRITICAL]Popsicle Finance is a cross-chain automated yield optimization protocol, launched in March 2021, that suffered a critical $20.7 million exploit in August 2021 due to a reward-tracking vulnerability in its Sorbetto Fragola pools. The protocol is part of Daniele Sestagalli's 'Frog Nation' ecosystem alongside Wonderland (TIME) and Abracadabra Money (MIM), which was later engulfed in a major scandal when the treasury manager of Wonderland was revealed to be Michael Patryn, a convicted felon and co-founder of the fraudulent QuadrigaCX exchange. The project subsequently rebranded as WAGMI in 2023 but remains a high-risk entity given the severity of the 2021 exploit, the laundering of stolen funds through Tornado Cash, and the broader Frog Nation governance failures.
avoid.net/badger-dao→10/100[CRITICAL]Badger DAO is a decentralized autonomous organization and DeFi protocol launched in December 2020 focused on generating yield on Bitcoin-backed assets via Ethereum-based vaults. In December 2021, a front-end attack exploiting a compromised Cloudflare API key resulted in approximately $120–130 million in user funds being drained across roughly 500 wallets. As of 2025, the protocol has seen significant decline: its flagship eBTC product was sunset, BADGER was delisted from Binance, and total value locked has fallen to low single-digit millions.
avoid.net/inverse-finance-frontier→10/100[CRITICAL]Inverse Finance Frontier (originally called Anchor) was a variable-rate lending market on Ethereum operated by Inverse Finance DAO, founded by Nour Haridy in 2020. The protocol suffered two separate oracle manipulation exploits in 2022 — one in April resulting in $15.6 million in losses and a second in June resulting in $5.8 million in bad debt — both attributed to vulnerabilities in how Frontier priced collateral assets. The protocol is now deprecated in favor of Inverse Finance's FiRM fixed-rate market, and the DAO continues to work down residual bad debt from both incidents.
avoid.net/saddle-finance→10/100[CRITICAL]Saddle Finance was an Ethereum-based automated market maker (AMM) optimized for pegged-value assets such as stablecoins and wrapped BTC, founded in 2020 and launched in January 2021. The protocol suffered a critical exploit on April 30, 2022, when an attacker leveraged an unpatched MetaSwapUtils library bug to drain approximately $11 million via flash-loan-assisted price manipulation, with $3.8 million subsequently rescued by security firm BlockSec. The protocol formally wound down in September 2023 following a DAO vote (SIP-54) triggered in part by the broader DeFi security climate after the Curve Finance hack.
avoid.net/blizz-finance→10/100[CRITICAL]Blizz Finance was a decentralized lending protocol on Avalanche, forked from Aave v2, that launched in November 2021 and was rendered insolvent in May 2022 when the Terra LUNA collapse triggered a Chainlink oracle circuit breaker that froze the LUNA price at $0.10 while the token's actual market price fell to near zero. Attackers exploited the stale price feed to borrow approximately $8.3 million in protocol assets using nearly worthless LUNA as collateral, draining the protocol entirely. The team announced permanent shutdown shortly after, recovering and distributing only approximately $1.5 million to affected users.
avoid.net/nomad→10/100[CRITICAL]Nomad was a cross-chain messaging bridge operated by Illusory Systems, Inc. that suffered one of the largest DeFi exploits in history on August 1–2, 2022, when a smart contract initialization bug allowed approximately $190 million in user funds to be drained in a chaotic free-for-all involving over 300 wallet addresses. The protocol never recovered meaningful user adoption after a December 2022 relaunch, faced a class action lawsuit and an FTC enforcement action, and in December 2025 agreed to a settlement requiring repayment of $37.5 million to affected users.
avoid.net/kannagi→3/100[CRITICAL]Kannagi Finance was a decentralized yield aggregation protocol launched on zkSync Era in June 2023. On July 29, 2023, the project's anonymous team executed an exit scam, draining approximately $2.13 million in user funds and reducing TVL from $2.13 million to $0.17. The stolen funds were subsequently laundered through the Tornado Cash crypto mixer, and all project infrastructure — website, Twitter, and GitHub repositories — was deleted.
avoid.net/concentric→18/100[CRITICAL]Concentric (Concentric.fi) was an automated liquidity management protocol built on Camelot v3 on the Arbitrum network, offering vault-based yield optimization for concentrated liquidity positions. On January 22, 2024, the protocol suffered a critical security breach when a team member's deployer wallet was compromised through a targeted social engineering attack, resulting in approximately $1.85 million in losses and a 57% crash in the CONE token price. The protocol was subsequently halted entirely, and blockchain forensics firm CertiK linked the exploiter's wallets to prior incidents targeting OKX, UnoRe, and LunaFi, suggesting a sophisticated and recurring threat actor.
avoid.net/munchables→10/100[CRITICAL]Munchables is a Blast-chain NFT game that suffered a $62.5 million exploit on March 26, 2024, when a contractor later attributed to North Korea exploited a backdoor they had embedded in the project's upgradeable smart contracts before launch. The developer surrendered private keys and the full sum was recovered within approximately 24 hours, but the incident exposed fundamental failures in contractor due diligence and smart contract architecture.
avoid.net/hedgey→18/100[CRITICAL]Hedgey is a token vesting, lockup, and claims protocol that served over 100 on-chain projects before suffering a critical smart contract exploit on April 19, 2024, resulting in the theft of approximately $44.7 million across Ethereum and Arbitrum. The vulnerability — a missing input validation check in the ClaimCampaigns.sol contract — was present despite two prior audits by ConsenSys Diligence. No confirmed recovery of stolen funds has been reported; Hedgey was subsequently acquired by Anchorage Digital in late 2025.
avoid.net/terra-20→7/100[CRITICAL]Terra 2.0 (LUNA) is a replacement blockchain launched in May 2022 by Terraform Labs following the catastrophic collapse of the original Terra network and its algorithmic stablecoin TerraUSD (UST), which erased approximately $40–60 billion in market value in one week. The project's founder, Do Kwon, was arrested in March 2023, found liable for securities fraud in a U.S. civil trial in April 2024, pleaded guilty to wire fraud and conspiracy in August 2025, and was sentenced to 15 years in federal prison in December 2025. Terraform Labs itself filed for Chapter 11 bankruptcy in January 2024 and received court approval to wind down operations by September 2024, leaving Terra 2.0 as a severely diminished chain with minimal developer activity and an approximately 79% year-over-year decline in token value.
avoid.net/ooki→5/100[CRITICAL]Ooki Protocol (formerly bZx Protocol) is a decentralized margin trading and lending protocol on Ethereum that was the subject of the first-ever CFTC enforcement action against a DAO, resulting in a 2023 default judgment ordering the protocol to cease operations and pay $643,542 in penalties. The protocol suffered four separate security incidents between 2020 and 2021 totaling over $64 million in losses, including a $55 million phishing-based hack attributed by Kaspersky to the North Korean state-linked BlueNoroff group. Following the CFTC judgment, the Ooki DAO's website was ordered shut down and the protocol has been effectively defunct.
avoid.net/meerkat-finance→4/100[CRITICAL]Meerkat Finance was a Binance Smart Chain yield-vault protocol that launched on March 3, 2021 and was drained of approximately $31.56 million in BUSD and BNB less than 24 hours later. On-chain evidence indicates the project's own deployer address executed the exploit, pointing to an intentional exit scam rather than an external hack. A developer identifying as 'Jamboo' subsequently claimed the drain was a 'trial' testing user greed, promised full refunds, and approximately 95% of funds were eventually recovered under heavy pressure from Binance and the BSC community.
avoid.net/uranium-finance→4/100[CRITICAL]Uranium Finance was a Binance Smart Chain-based automated market maker (AMM) that was exploited twice in April 2021, resulting in total losses of approximately $54.7 million. The larger exploit on April 28, 2021, drained roughly $53.3 million across 26 liquidity pools due to a mathematical error in its forked Uniswap v2 pair contracts; the protocol subsequently shut down permanently. In March 2026, U.S. authorities indicted Jonathan Spalletta, a Maryland resident, on computer fraud and money laundering charges in connection with both attacks, after previously seizing approximately $31 million in cryptocurrency in February 2025.
avoid.net/stablemagnet→2/100[CRITICAL]StableMagnet was a stablecoin yield and DEX protocol launched on Binance Smart Chain (BSC) that executed a deliberate rug pull on June 23-24, 2021, stealing approximately $27 million in USDT, USDC, and BUSD from over 1,000 users. The team concealed a malicious backdoor by substituting an unverified SwapUtils library for the one shown in publicly audited source code — a novel attack vector that exposed a critical gap in how block explorers verify linked library code. Following an anonymous white-hat investigation and Manchester police arrests, most of the stolen funds were eventually returned by late 2022.
avoid.net/cream-lending→0/100[CRITICAL]C.R.E.A.M. Finance (Crypto Rules Everything Around Me) is a decentralized lending and borrowing protocol launched in August 2020, forked from Compound Finance. The protocol suffered three major exploits in 2021 totaling approximately $185 million in losses, making it one of the most frequently and severely hacked DeFi protocols in history. On-chain investigator ZachXBT flagged the protocol and its founders, and the CREAM token has collapsed more than 99% from its all-time high.
avoid.net/arbix-finance→2/100[CRITICAL]Arbix Finance was a yield farming protocol on Binance Smart Chain (BSC) that executed a deliberate rug pull on January 4, 2022, draining approximately $10 million in user funds. The anonymous development team minted 10 million unbacked ARBX tokens, dumped them on PancakeSwap to collapse the price, drained all user vaults, bridged the stolen assets to Ethereum via AnySwap, laundered them through Tornado Cash, and deleted the project website, Twitter, and Telegram accounts. Despite holding a CertiK audit from November 2021, the exploited contract fell entirely outside the audit scope.
avoid.net/dego-finance→10/100[CRITICAL]Dego Finance is a multi-chain NFT and DeFi aggregator protocol launched in September 2020 by an anonymous team. On February 10, 2022, an attacker compromised the team's deployer private keys and drained approximately $10 million from liquidity pools on Uniswap and PancakeSwap across Ethereum, Binance Smart Chain, and Cronos. No stolen funds were recovered; the project responded with a token migration but offered no direct restitution to affected liquidity providers.
avoid.net/hundred-finance→8/100[CRITICAL]Hundred Finance was a multi-chain DeFi lending protocol forked from Compound V2 that suffered at least two major security exploits totaling approximately $13.6 million in direct losses, alongside a related $11 million joint attack with Agave Finance on Gnosis Chain. The protocol was unable to recover stolen funds and shut down in August 2023 following a governance vote, with remaining treasury funds allocated toward partial victim compensation. Stolen funds remained unrecovered as of 2024, with the April 2023 attacker moving assets through decentralized exchanges more than a year after the exploit.
avoid.net/defrost→18/100[CRITICAL]Defrost Finance was an Avalanche-based CDP (Collateralized Debt Position) DeFi protocol that allowed users to collateralize yield-bearing tokens to mint an H2O USD-pegged stablecoin. In December 2022 the protocol suffered a two-stage exploit resulting in approximately $12 million in losses; multiple blockchain security firms — including CertiK, PeckShield, and De.Fi Security — alleged the attack constituted an insider rug pull enabled by admin key access, a conclusion the team denied. Funds were subsequently returned and a refund contract was deployed in January 2023, but the protocol has since effectively ceased meaningful operations with under $100,000 in TVL, and the MELT governance token has lost nearly all of its value.
avoid.net/euler-v1→10/100[CRITICAL]Euler Finance V1 was a permissionless DeFi lending protocol on Ethereum that launched in December 2021 and was exploited for approximately $197 million on March 13, 2023, in what was the largest DeFi hack of that year. The attack exploited a missing health check in the donateToReserves function introduced in EIP-14, despite the codebase having undergone multiple external audits. In a highly unusual outcome, the pseudonymous attacker known as 'Jacob' returned all recoverable funds by April 3, 2023, with the total recovered value reaching approximately $240 million due to ETH price appreciation during the recovery period.
avoid.net/merlin-dex→5/100[CRITICAL]Merlin DEX was a decentralized exchange built on zkSync Era that suffered a confirmed insider rug pull on April 26-27, 2023, during its MAGE token Liquidity Generation Event. Rogue backend developers exploited excessive smart contract permissions granted to a privileged 'Feeto' address to drain approximately $1.82 million in user funds. Despite a prior CertiK audit, centralization risks flagged during review were not effectively remediated; CertiK subsequently acknowledged partial responsibility and launched a compensation plan, recovering only $160,000 of the stolen amount.
avoid.net/hector-lending→8/100[CRITICAL]Hector Lending is a defunct DeFi lending protocol built on the Fantom blockchain and operated by Hector Network (also known as Hector DAO). It was one of several products in an ecosystem whose treasury declined from approximately $110 million to near zero through a combination of alleged team mismanagement, three separate security incidents, and a court-ordered receivership. The broader Hector Network entered BVI receivership in February 2024 and subsequently obtained US Chapter 15 bankruptcy recognition — the first DAO ever to do so — in July 2024.
avoid.net/zunami-protocol→10/100[CRITICAL]Zunami Protocol is an Ethereum-based DeFi yield aggregator and stablecoin issuer (UZD, zETH) that suffered at least four separate security incidents between January 2023 and May 2025, losing a combined estimated $2.86 million or more in user funds. The protocol is notable for ignoring a prior warning from SlowMist before its largest smart contract exploit, and for a May 2025 incident in which an admin key compromise allegedly drained $500,000, with the team subsequently going silent for weeks and development activity having ceased months prior.
avoid.net/mixin-network→10/100[CRITICAL]Mixin Network is a Hong Kong-based layer-2 cross-chain payment protocol that suffered the largest single crypto hack of 2023 when attackers compromised its cloud service provider's database and drained approximately $200 million in ETH, BTC, and USDT. The network remains operational but has only partially compensated users, the majority of stolen funds remain unrecovered, and a dormant attacker wallet moved funds to Tornado Cash in February 2026.
avoid.net/velocore-v2→12/100[CRITICAL]Velocore V2 was a ve(3,3) decentralized exchange (DEX) deployed on the Linea and zkSync Era layer-2 blockchains. On June 2, 2024, the protocol suffered a critical smart contract exploit that drained approximately $6.8 million in ETH from its volatile liquidity pools. The attacker laundered stolen funds through Tornado Cash, no recovery was achieved, and the team subsequently announced a treasury liquidation rather than a protocol relaunch.
avoid.net/uwu-lend→10/100[CRITICAL]UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave V2, launched in September 2022 and operated by Michael Patryn (known pseudonymously as 0xSifu), a co-founder of the collapsed Canadian crypto exchange QuadrigaCX and a convicted felon. In June 2024, the protocol was exploited twice by the same attacker — first for approximately $19.3 million on June 10 and again for $3.7 million on June 13 — via oracle price manipulation using flash loans, bringing combined losses to approximately $23 million.
avoid.net/btc24h→18/100[CRITICAL]BTC24H is an ERC-20 token and associated DAO platform launched on Polygon in late 2024, marketed as a mechanism for continuous Bitcoin distribution through high-yield daily payouts. The platform's Lock contract suffered a critical access-control vulnerability in December 2024 that allowed any caller to drain tokens, resulting in an estimated $85,700 loss. Multiple independent scam-detection services rate associated BTC24H web domains as high-risk or outright malicious, and the project's tokenomics — 5% daily returns for 30 days via a multi-level referral structure — exhibit structural characteristics consistent with unsustainable high-yield investment programs.
avoid.net/phemex→10/100[CRITICAL]Phemex is a centralized cryptocurrency derivatives exchange founded in November 2019 by former Morgan Stanley executives and registered in the British Virgin Islands. In January 2025, the exchange suffered one of the largest crypto hacks of that year, with an estimated $69–85 million drained from hot wallets across 16 blockchains, subsequently attributed to North Korea's Lazarus Group through on-chain evidence linking the same wallets to the February 2025 Bybit hack. Phemex has also faced formal regulatory enforcement actions in Ontario, Canada, and operates without authorization in the United Kingdom.
avoid.net/cetus-clmm→18/100[CRITICAL]Cetus Protocol is a concentrated liquidity market maker (CLMM) and the dominant decentralized exchange on the Sui Network, launched in 2023. On May 22, 2025, an arithmetic overflow vulnerability in its fixed-point math library enabled an attacker to drain approximately $223 million from liquidity pools in the largest DeFi exploit of 2025, of which roughly $162 million was subsequently frozen by Sui validators and later returned to affected users via an on-chain governance vote. The incident raised significant concerns about smart contract security, audit effectiveness, and the degree of decentralization on the Sui network.
avoid.net/garden→14/100[CRITICAL]Garden Finance (garden.finance) is a Bitcoin cross-chain bridge and swap protocol launched in December 2023 by former Ren Protocol core team members, using Hashed Timelock Contracts (HTLCs) and an intents-based solver network to enable non-custodial Bitcoin swaps across chains. In October 2025, a compromised solver operator lost approximately $11.4 million in a security incident attributed by forensic investigators to a North Korea-linked threat actor. Prior to the exploit, blockchain investigator ZachXBT alleged that a substantial portion of Garden's volume — with estimates ranging from 25% to over 75% — originated from illicit sources including funds stolen in the $1.46 billion Bybit hack by Lazarus Group, allegations the team disputed but did not fully refute.
avoid.net/cyrus-finance→18/100[CRITICAL]Cyrus Finance is a decentralized yield-optimizer protocol operating on the BNB Smart Chain that markets itself as a high-yield DeFi platform utilizing PancakeSwap liquidity pairs and single-sided vaults. On March 22, 2026, the protocol suffered a $5 million flash loan exploit attributed to flawed pool-share accounting in its smart contracts, with no reported fund recovery. Multiple secondary domains (cyrusfinance.xyz) associated with the Cyrus Finance brand have been independently flagged as potentially malicious fake-broker sites that simulate trading activity and block user withdrawals.
avoid.net/poly-network→10/100[CRITICAL]Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered the largest DeFi hack in history in August 2021 (~$611M stolen, nearly all returned), followed by a second exploit in July 2023 (~$10M realized losses) attributed to compromised multisig private keys. The protocol permanently shut down all services on September 30, 2024.
avoid.net/cashio→5/100[CRITICAL]Cashio was a Solana-based algorithmic stablecoin protocol that issued the CASH token, collateralized by Saber LP tokens. On March 23, 2022, an attacker exploited a critical missing validation flaw in the smart contract to mint approximately 2 billion CASH tokens backed by worthless fake collateral, draining roughly $52 million in real assets and permanently destroying the token's USD peg. The protocol was unaudited, never compensated victims in full, and its pseudonymous creator later admitted the code was rushed and insecure.
avoid.net/elephant-money→10/100[CRITICAL]Elephant Money is a Binance Smart Chain DeFi protocol offering the ELEPHANT reward token and TRUNK stablecoin that suffered a $22.2 million flash loan price-manipulation exploit in April 2022, with stolen funds laundered through Tornado Cash. Independent analysts have additionally alleged that the protocol's yield mechanics constitute a structurally unsustainable Ponzi scheme dependent on continuous new capital inflows.
avoid.net/transit-swap→18/100[CRITICAL]Transit Swap is a cross-chain DEX aggregator incubated by TokenPocket, supporting swaps across Ethereum, BNB Chain, Polygon, Tron, Solana, and other networks. On October 1–2, 2022, an attacker exploited an input validation vulnerability in the platform's swap contract, draining approximately $21–28.9 million in user funds across Ethereum and BNB Chain. The attacker subsequently returned roughly 70% of stolen assets after security firms identified the exploiter's IP address and email, though an estimated 30% of funds — including amounts routed through Tornado Cash — remain unrecovered.
avoid.net/bunni-v2→10/100[CRITICAL]Bunni V2 was a decentralized exchange and liquidity layer built on Uniswap v4, developed by Timeless Finance. On September 1-2, 2025, the protocol suffered a critical exploit draining approximately $8.4 million across Ethereum and Unichain through a rounding-direction vulnerability in its withdrawal mechanism. The team permanently shut down the protocol on October 23, 2025, citing inability to finance a secure relaunch after the exploit erased 97% of TVL.
avoid.net/deus-finance→10/100[CRITICAL]DEUS Finance is a decentralized derivatives and synthetic asset protocol built primarily on Fantom, co-founded by Lafayette Tabor and Mohammad Abrishami. The protocol suffered three separate security exploits between March 2022 and May 2023, resulting in combined losses exceeding $22 million across flash loan oracle attacks and a smart contract implementation flaw, with stolen funds routed through Tornado Cash in the 2022 incidents. Repeated security failures across distinct vulnerability classes raise severe concerns about the protocol's security practices and long-term viability.
avoid.net/fortress-loans→18/100[CRITICAL]Fortress Loans (fortress.loans) was an algorithmic money market and lending protocol on BNB Chain (Binance Smart Chain), launched in April 2021 by the JetFuel Finance team. On May 8, 2022, the protocol was drained of all funds — approximately $2.98 million — through a combined governance manipulation and oracle price manipulation attack. The protocol has been effectively inactive since, with DefiLlama recording a TVL of approximately $1,168 as of 2024, and the FTS governance token has lost effectively all of its value.
avoid.net/gym-network→12/100[CRITICAL]Gym Network (GYMNET) is a Binance Smart Chain-based DeFi protocol launched in March 2022 that operates an affiliate investment scheme with hallmarks of a Ponzi structure, requiring continuous recruitment to sustain promised returns of up to 250% annually. The project was founded by Claudio Catrini, who has prior involvement in the OneCoin fraud, and suffered a $2.1 million smart contract exploit in June 2022. The GYMNET token has declined approximately 99.8% from its all-time high of $1.90 to under $0.004 as of 2026.
avoid.net/harmony-bridge→10/100[CRITICAL]Harmony's Horizon Bridge is a cross-chain bridge connecting the Harmony (ONE) blockchain to Ethereum and Binance Smart Chain, launched in October 2020. In June 2022, it was exploited for approximately $100 million by the Lazarus Group, a North Korea-affiliated state-sponsored hacking collective, through compromise of a 2-of-5 multisig scheme controlling bridge funds. The FBI formally confirmed Lazarus Group attribution in January 2023; as of 2025, full victim restitution has not been achieved.
avoid.net/dragoma→3/100[CRITICAL]Dragoma was a move-to-earn GameFi project built on the Polygon network whose native DMA token collapsed 99.8% within hours of its MEXC exchange listing on August 8, 2022, in what blockchain security firm PeckShield identified as a rug pull. Approximately $3.5 million in investor funds were allegedly drained by the development team and deposited into centralized exchanges. The project's website and all social media channels were subsequently deleted, and no known recovery or law enforcement action against the responsible parties has been publicly confirmed.
avoid.net/pando-rings→18/100[CRITICAL]Pando Rings is an algorithmic lending and borrowing protocol built on the Mixin Network by Fox One, modeled on Compound Finance. On November 5, 2022, an attacker exploited a price oracle vulnerability tied to the sBTC-WBTC LP token on 4swap to drain approximately $21.9 million in ETH, BTC, and EOS from the protocol; an additional ~$50 million remained frozen in the attacker's wallets. The protocol subsequently suffered further losses in the September 2023 Mixin Network infrastructure breach, and as of late 2023 remained in a limited operational state with interest accrual and liquidations suspended.
avoid.net/atlantis-loans→12/100[CRITICAL]Atlantis Loans was a decentralized lending and borrowing protocol built on BNB Chain (BSC) that was abandoned by its development team in April 2023 due to financial distress. Despite the abandonment, active smart contracts and unrevoked user approvals remained on-chain, which an attacker exploited in June 2023 through a malicious governance proposal, ultimately draining an estimated $2.5 million from users. The protocol is now defunct, its website is down, and its TVL has collapsed to near zero.
avoid.net/alphapo→10/100[CRITICAL]AlphaPo is a cryptocurrency payment processor incorporated in Panama and operating primarily in the online gambling sector, serving clients such as HypeDrop, Bovada, and Ignition. On July 22, 2023, attackers drained approximately $60 million in ETH, BTC, and TRX from its hot wallets via a private key compromise, disrupting withdrawals across multiple dependent platforms. On-chain investigator ZachXBT and subsequently the FBI attributed the attack to the DPRK-affiliated Lazarus Group (also designated TraderTraitor and APT38), placing the incident within a broader 2023 North Korean cryptocurrency theft campaign that totaled over $200 million.
avoid.net/cypher→12/100[CRITICAL]Cypher Protocol was a Solana-based cross-margin decentralized exchange (DEX) and perpetuals trading platform that suffered a critical smart contract exploit in August 2023 resulting in approximately $1 million in losses. Following the exploit, an insider contributor known as 'Hoak' systematically drained over $314,000 from the community redemption fund established to reimburse hack victims, admitting publicly to gambling the funds away. The protocol appears effectively defunct, having failed to deliver meaningful restitution to users who received roughly 31 cents on the dollar from the original exploit fund before that fund itself was embezzled.
avoid.net/okx-dex→18/100[CRITICAL]OKX DEX is the decentralized exchange aggregator operated by OKX (Aux Cayes FinTech Co. Ltd.), one of the world's largest centralized crypto exchanges. In December 2023, the DEX suffered a ~$2.7 million exploit caused by a suspected private key leak and a centralized proxy upgrade mechanism with no multi-signature protection. The broader OKX entity has faced severe regulatory sanctions including a $504 million U.S. DOJ settlement in February 2025 for operating an unlicensed money-transmitting business and facilitating over $5 billion in suspicious transactions, a €1.1 million Malta AML fine, and repeated scrutiny over its DEX aggregator being used by North Korea's Lazarus Group to launder stolen funds from the $1.5 billion Bybit hack in early 2025.
avoid.net/dough-finance→12/100[CRITICAL]Dough Finance was an Ethereum-based DeFi lending and margin-trading protocol co-founded by Chase Herro and Zachary Folkman. On July 12, 2024, the protocol was exploited via a flash loan attack that drained approximately $2.1–2.5 million in user funds due to unvalidated calldata in its ConnectorDeleverageParaswap smart contract. The protocol's website is shut down, the vast majority of the approximately 2,700 affected users have received no meaningful compensation, and the co-founders have since launched World Liberty Financial alongside Donald Trump, earning an alleged $65 million in revenues from that new venture.
avoid.net/monoswap→18/100[CRITICAL]MonoSwap is a decentralized exchange (DEX) and launchpad built on the Blast L2 network that launched in late February 2024. On July 24, 2024, the protocol was compromised via a social engineering attack in which a developer was tricked into installing infostealer malware disguised as a video conferencing app, allowing attackers to drain approximately $1.3 million in staked liquidity. The stolen funds were subsequently laundered through Tornado Cash, and the protocol has remained largely inactive with negligible TVL since the incident.
avoid.net/penpie→10/100[CRITICAL]Penpie is a yield-boosting DeFi protocol built on Pendle Finance by the Magpie DAO ecosystem, allowing users to earn boosted yields on Pendle liquidity pools without directly locking PENDLE tokens. On September 3, 2024, an attacker exploited a reentrancy vulnerability in Penpie's staking contract to drain approximately $27.3 million across Ethereum and Arbitrum, subsequently laundering all stolen funds through Tornado Cash and ignoring recovery appeals. The protocol filed reports with the FBI and Singapore Police but recovered no funds; a partial community compensation plan was proposed but not fully executed.
avoid.net/dogwiftools→4/100[CRITICAL]DogWifTools is a Solana-based memecoin tooling platform that markets features explicitly designed to simulate artificial trading volume, conceal supply concentration across hundreds of wallets, and inflate engagement metrics on pump.fun — capabilities that security researchers and blockchain analysts characterize as enabling wash trading and coordinated pump-and-dump schemes. In January 2025, the platform suffered a supply-chain attack in which threat actors trojaned versions 1.6.3 through 1.6.6 with a Remote Access Trojan, draining an estimated $10 million from users' wallets; the attacker group framed the theft as vigilante justice against scammers. No known regulatory action has been taken against DogWifTools operators, who remain anonymous.
avoid.net/infini→12/100[CRITICAL]Infini is a Hong Kong-based stablecoin neobank offering yield-bearing accounts and a global payment card. On February 24, 2025, a former developer who had covertly retained administrative privileges over Infini's smart contracts drained approximately $49.5 million in USDC from the Morpho MEVCapital vault, converting the funds to ETH and routing them through Tornado Cash. As of May 2026, no funds have been recovered, and the attacker's wallet remained active through at least February 2026.
avoid.net/kelp→18/100[CRITICAL]Kelp (also known as Kelp DAO) is a liquid restaking protocol built on Ethereum and EigenLayer that issues rsETH, a liquid restaked token. In April 2026 the protocol suffered the largest DeFi exploit of 2026 to date when attackers, attributed to North Korea's Lazarus Group, drained approximately $292 million in rsETH through a compromised LayerZero cross-chain bridge configuration. The protocol and an industry coalition dubbed DeFi United are actively working to restore collateral and resume operations as of May 2026.
avoid.net/unleash-protocol→18/100[CRITICAL]Unleash Protocol is a decentralized intellectual property finance (IPFi) platform built on the Story Protocol blockchain, launched in early 2024. On December 30, 2025, the protocol suffered a confirmed $3.9 million exploit in which an attacker gained unauthorized administrative control through its multisignature governance system, executed an unauthorized smart contract upgrade, and laundered 1,337 ETH through Tornado Cash. The protocol subsequently paused all operations; as of early 2026 no recovery or user compensation plan has been publicly confirmed.
avoid.net/ploutos-money→12/100[CRITICAL]Ploutos Money was a multi-chain DeFi lending and leveraged farming protocol, forked from Aave v3.0.2, that operated across Ethereum, Arbitrum, Hemi, Hyperliquid, Avalanche, Polygon, Base, Plasma, and Katana. On February 26, 2026, the protocol lost approximately $388,000 (187.36 ETH) after its USDC price oracle was misconfigured to reference Chainlink's BTC/USD feed instead of the correct USDC/USD feed. Immediately following the exploit, the team deleted its website, GitHub repository, and all social media accounts without issuing any warning or post-mortem, prompting on-chain security firms CertiK and BlockSec to conclude that the incident was an inside job rather than an external attack.
avoid.net/binance-bridge→10/100[CRITICAL]Binance Bridge (BSC Token Hub) was the official cross-chain bridge connecting the BNB Beacon Chain (BEP2) and BNB Smart Chain (BEP20), operated by Binance. On October 6-7, 2022, an attacker exploited a critical flaw in the bridge's IAVL Merkle proof verification logic inherited from Cosmos SDK, forging deposit proofs to mint 2 million BNB (approximately $586 million at time of exploit). Although the BNB Chain was halted by validators to contain the damage — trapping roughly $430 million on-chain — approximately $110–137 million escaped to other networks before the halt took effect.
avoid.net/skyward-finance→18/100[CRITICAL]Skyward Finance was a permissionless token launchpad built on the NEAR Protocol, launched in June 2021. On November 2, 2022, a smart contract vulnerability in its treasury redemption function was exploited, resulting in the loss of approximately 1.1 million NEAR tokens (~$3.2 million USD). The exploit rendered the SKYWARD token and protocol treasury effectively worthless, and the team publicly advised users to withdraw all remaining funds and cease interacting with the platform.
avoid.net/gdac→10/100[CRITICAL]GDAC was a South Korean cryptocurrency exchange operated by Peertec Co., Ltd. that launched in May 2018 and was registered as a Virtual Asset Service Provider (VASP) with Korea's Financial Intelligence Unit (KoFIU). On April 9, 2023, attackers drained approximately $13–14 million from its hot wallets — representing 23% of total custodial assets — causing the exchange to permanently shut down with no compensation offered to affected users.
avoid.net/kyberswap-elastic→10/100[CRITICAL]KyberSwap Elastic is the concentrated liquidity automated market maker (AMM) component of Kyber Network, a decentralized exchange protocol deployed across more than a dozen EVM-compatible blockchains. On November 22–23, 2023, it suffered the largest DeFi exploit of that year — approximately $48–56 million drained via a precision rounding bug in its tick-crossing swap logic — after which the alleged attacker issued an on-chain ultimatum demanding full executive control of the company. Canadian national Andean Medjedovic was indicted by U.S. prosecutors in February 2025 on charges including wire fraud, computer hacking, and extortion; he remains a fugitive as of mid-2026.
avoid.net/heco-bridge→5/100[CRITICAL]Heco Bridge was the official cross-chain bridge connecting the HECO Chain (HTX Eco Chain) to Ethereum, operated by HTX (formerly Huobi) and associated with Justin Sun. On November 22, 2023, the bridge operator's private key was compromised, resulting in the theft of approximately $86.6 million in crypto assets; combined with a simultaneous HTX hot wallet breach, total losses reached approximately $99 million. Blockchain analytics firm Elliptic attributed the attack to North Korea's Lazarus Group, which subsequently laundered over $100 million of the proceeds through Tornado Cash. The HECO Network was permanently shut down on January 15, 2025.
avoid.net/solareum→12/100[CRITICAL]Solareum was a Solana-based Telegram trading bot that shut down on March 30, 2024 following a security exploit that drained approximately $523,000 (2,800+ SOL) from over 300 user wallets. Prosecutors later revealed in a January 2025 court filing that the Solareum team had unknowingly hired a North Korean (DPRK) developer in December 2023, who subsequently facilitated the theft of 6,045 SOL worth roughly $1.4 million; the FBI seized approximately $950,000 in USDT two months after the hack. The project offered no compensation to victims, deleted its website and community channels, and is no longer operational.
avoid.net/xbridge→12/100[CRITICAL]XBridge is a cross-chain bridge protocol built by SaitaChain (formerly Saitama Inu), designed to connect Ethereum Mainnet and BNB Chain. On April 24, 2024, the protocol suffered a $1.44 million exploit caused by a critical access-control vulnerability in its smart contracts, with stolen funds subsequently routed through Tornado Cash. The parent company, Saitama LLC, faces U.S. federal charges of wire fraud and market manipulation, with CEO Manpreet Kohli arrested in the UK in October 2024 and facing extradition proceedings.
avoid.net/convergence→18/100[CRITICAL]Convergence (CVG) is an Ethereum-based DeFi yield-aggregation protocol built on top of Curve and Convex Finance. On August 1, 2024, an attacker exploited a missing input-validation check in the CvxRewardDistributor contract — introduced by a post-audit gas-optimization change — to mint 58 million CVG tokens and sell them for approximately $212,000, collapsing the token price by 99%. The protocol never recovered; following a community DAO vote, the team pivoted operations to a successor project called Tangent Finance (TGN).
avoid.net/us-government-crypto-wallet→10/100[CRITICAL]The US government holds one of the largest concentrations of seized cryptocurrency in the world, accumulated through major law enforcement actions including the 2016 Bitfinex hack and the Silk Road darknet marketplace. In October 2024, a government-controlled wallet linked to Bitfinex seizure funds was drained of approximately $20 million in what was subsequently attributed to alleged insider theft by John Daghita, son of a US Marshals Service contractor, who was arrested in Saint Martin in March 2026 after a blockchain investigation by ZachXBT exposed the scheme.
avoid.net/moonhacker→18/100[CRITICAL]MoonHacker is an independently deployed DeFi vault protocol built on Optimism that was designed to interact with the Moonwell lending protocol. On December 23, 2024, MoonHacker vault contracts suffered a flash loan exploit due to improper input validation and absent access controls in the executeOperation function, resulting in the loss of approximately $320,000 USDC. The Moonwell team confirmed no affiliation with MoonHacker, the vault deployers remain anonymous, and stolen funds were converted to DAI and routed through Tornado Cash, complicating recovery efforts.
avoid.net/kalax→5/100[CRITICAL]Kalax (ticker: KALA) was a non-custodial yield aggregator deployed on the Blast and Scroll blockchains in 2024 that marketed itself as an auto-compounding protocol for DEXs and lending markets. Despite commissioning a Beosin security audit and publishing promotional security guarantees, the project's founders are alleged to have executed an exit scam on October 14, 2024, abandoning the protocol and deleting all official social media accounts after draining user funds from protocol vaults. The kalax.io domain subsequently redirected to an unrelated gambling site, with no team communications issued to affected depositors.
avoid.net/tmx-tribe→18/100[CRITICAL]TMX TRIBE (also marketed as Tribe DEX) is a decentralized perpetual futures exchange operating on Arbitrum and Optimism that launched its TMX token in mid-2025. On January 5-7, 2026, an attacker exploited a critical logic flaw in unverified, unaudited smart contracts to drain approximately $1.4 million in user funds over 36 hours, with stolen assets subsequently bridged to Ethereum and laundered via Tornado Cash. The team deployed no emergency pause during the attack, issued no public statement for days afterward, and produced no post-mortem or user compensation plan, raising serious concerns about operational competence and transparency. ZachXBT has flagged the entity.
avoid.net/merlin→4/100[CRITICAL]Merlin DEX was a decentralized exchange built on zkSync Era that was drained of approximately $1.82 million on April 26, 2023, during its public MAGE token liquidity generation event. Security investigators, including auditor CertiK, concluded the incident was an insider rug pull executed by the protocol's own back-end development team, who had embedded a backdoor granting themselves unlimited withdrawal rights over all liquidity pools. The rogue developers, allegedly a group of Serbian nationals, have never been publicly identified or prosecuted, and no meaningful recovery of stolen funds has been confirmed. This entity is distinct from Merlin Chain, an unrelated Bitcoin Layer 2 protocol.
avoid.net/levyathan→18/100[CRITICAL]Levyathan was a Binance Smart Chain DeFi protocol billing itself as the first crypto index fund on BSC, launching in mid-2021. On July 30, 2021, the project collapsed after private keys controlling the token minting contract were left exposed in a public GitHub repository for approximately four months, enabling an attacker to mint and dump a quadrillion LEV tokens. A concurrent bug in the emergencyWithdraw() function compounded losses for stakers, and stolen funds were bridged to Ethereum and routed through Tornado Cash; the project never recovered and effectively disbanded.
avoid.net/atomic-wallet→18/100[CRITICAL]Atomic Wallet is a non-custodial, multi-currency cryptocurrency wallet founded in 2017 and headquartered in Tallinn, Estonia. In June 2023, attackers attributed to North Korea's Lazarus Group (TraderTraitor) stole approximately $100 million in cryptocurrency from an estimated 5,500 user wallets in one of the largest crypto theft events of that year. Prior to the hack, an independent security firm had publicly disclosed unresolved critical vulnerabilities in the wallet's cryptography implementation as early as February 2022, and Atomic Wallet did not adequately address those findings before the breach occurred.
avoid.net/sunrayfinance→8/100[CRITICAL]Sunray Finance was a perpetual-trading DEX protocol on Arbitrum that suffered a critical exploit on October 30, 2024, resulting in approximately $2.7–2.9 million in losses. An attacker — using what the team attributed to a compromised private key — upgraded the protocol's management contract and minted 200 sextillion SUN tokens, then swapped a portion for USDT before the token price collapsed to zero. The project website subsequently went offline with no confirmed fund recovery, and the protocol's pre-exploit marketing included unverified claims of SoftBank backing and unsustainable 299% annual yield promises.
avoid.net/lnd→12/100[CRITICAL]LND (lnd.fi) was a non-custodial, multichain DeFi lending protocol built on Sonic (a high-performance EVM chain) as a fork of Aave V3. On May 9, 2025, the protocol was drained of approximately $1.27–1.42 million by a developer who gained Pool Admin credentials and introduced a malicious access control modification 41 days before executing the exploit; the official postmortem attributed the attacker to a DPRK (North Korea) IT worker embedded in the team under false pretenses. As of mid-2025, the lnd.fi domain is no longer operated by the team and appears listed for resale, indicating the protocol ceased operations following the incident.
avoid.net/402bridge→18/100[CRITICAL]402bridge (also written x402bridge) was a short-lived cross-chain bridge protocol built on the x402 HTTP payment standard, operating at 402bridge.fun. On October 28, 2025, approximately 13 hours after deployment, an attacker exploited a leaked admin private key to drain $17,693 in USDC from 227 user wallets in under 30 minutes; the protocol ceased operations immediately afterward and no user compensation has been announced. Security firm SlowMist noted that while the incident appeared consistent with a private key leak, the possibility of insider involvement could not be ruled out.
avoid.net/pink-drainer→2/100[CRITICAL]Pink Drainer was a pseudonymous wallet-drainer-as-a-service operation that supplied phishing kits and malicious smart-contract infrastructure to affiliate scammers between roughly April 2023 and May 2024. Security researchers, principally Scam Sniffer and blockchain investigator ZachXBT, attribute upward of $75-85 million in stolen crypto assets across an estimated 20,000-21,000+ victims to wallets and infrastructure linked to the group before it announced its retirement in May 2024. No law enforcement agency has publicly identified or charged the individuals behind the operation, so all attributions of activity and identity in this report come from private security researchers rather than courts or regulators.
avoid.net/lazarus-group→2/100[CRITICAL]Lazarus Group is a cyber threat actor that the U.S. Department of Justice, FBI, Treasury/OFAC, and the United Nations Panel of Experts have attributed to North Korea's Reconnaissance General Bureau (RGB), a military intelligence agency of the Democratic People's Republic of Korea (DPRK). U.S. and allied government agencies allege the group and its sub-units (tracked in industry reporting as APT38, BlueNoroff, TraderTraitor, and Stardust Chollima) have conducted destructive cyberattacks and large-scale cryptocurrency thefts since at least 2009, including what blockchain-analytics firm Chainalysis describes as a cumulative total exceeding $6 billion in stolen crypto assets, funds the UN Panel of Experts and U.S. officials allege support North Korea's weapons programs. This entry documents named individuals, government indictments, sanctions, and specific hacking incidents, distinguishing DOJ/FBI/OFAC/UN attributions from private-sector research findings.