Skip to main content
AVOID.NET

Investigations

Showing the 200 most recently updated of 475 scored 21–40.

Dangerous · scores 2140

200
avoid.net/layerzero-dvn-single-verifier-configuration-risk32/100[WARNING]

LayerZero is a cross-chain messaging protocol whose permissive Decentralized Verifier Network (DVN) architecture allowed integrating protocols to deploy bridges secured by a single verifier. In April 2026, this design pattern was exploited by the DPRK-affiliated Lazarus Group (TraderTraitor unit), which compromised LayerZero Labs' own DVN infrastructure to forge cross-chain messages and drain approximately $292 million from KelpDAO's rsETH bridge — the largest DeFi exploit of 2026. LayerZero has since publicly admitted a mistake in allowing its DVN to operate as a 1-of-1 verifier for high-value transactions and has announced policy changes, but the incident triggered a $15 billion migration of secured value away from LayerZero to competing infrastructure. A separate August 2026 exploit of The Sandbox's LayerZero-powered bridge deepened concerns about systemic risk across LayerZero integrations.

avoid.net/the-sandbox-sand-oft-exploit34/100[WARNING]

On August 21-22, 2026, an attacker exploited a configuration flaw in The Sandbox's SAND omnichain fungible token (OFT) contract on Base, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 events over approximately five hours. Despite a nominal face-value figure of roughly $49 billion, actual liquid losses were contained to approximately 14.75 million SAND (~$675,000) and 79.74 ETH drained from the Ethereum OFT Adapter. The Sandbox halted Base and BNB Smart Chain bridges, removed LayerZero peer settings via multisig, and subsequently announced a 1:1 treasury-funded compensation plan for affected liquidity providers using a pre-exploit snapshot.

avoid.net/the-sandbox-sand-bridge-exploit38/100[WARNING]

On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.

avoid.net/the-sandbox-sand30/100[WARNING]

The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.

avoid.net/team-finance28/100[WARNING]

Team Finance is a DeFi token-locking and vesting platform operated by TrustSwap Inc. that suffered a critical $14.5 million exploit on October 27, 2022, when an attacker abused a validation flaw in its Uniswap V2-to-V3 migration function. The attacker ultimately returned approximately $7 million, retaining roughly 10% as a self-declared bug bounty; Team Finance subsequently switched auditors to CertiK and reported full user reimbursement by June 2023.

avoid.net/cronos-chain26/100[WARNING]

Cronos is an EVM-compatible blockchain developed by Crypto.com and operated by Cronos Labs, running a capped, invitation-only validator set. On August 30, 2026, validators halted block production and executed a full chain rollback after a price-manipulation exploit drained an estimated $75 million from Tectonic, the chain's dominant lending protocol; the rollback erased approximately two hours of transaction history network-wide and recovered most of the stolen funds on-chain, while roughly $6.29 million that had already been bridged to Ethereum was not recovered. The incident reignited longstanding debates about immutability, validator centralization, and the degree of operational control Crypto.com holds over the network.

avoid.net/coinsbuy-exchange-august-2026-hot-wallet-drain30/100[WARNING]

On August 9, 2026, wallets associated with Coinsbuy — a B2B crypto payment processor and exchange — were drained of approximately $7.9 million across Ethereum and TRON in a coordinated attack completed within roughly one hour. The attacker linked both chains via cross-chain swapper Bridgers and subsequently laundered the majority of proceeds through FixedFloat and into Monero; ChangeNOW froze a six-figure portion. Coinsbuy stated it covered all client losses from company reserves and offered a $100,000 bounty for information leading to the perpetrators' identification.

avoid.net/seedify28/100[WARNING]

Seedify (Seedify.fund) is a blockchain gaming incubator and IDO/IGO launchpad founded in February 2021 by Levent Cem Aydan, operating on BNB Chain, Ethereum, and Avalanche with its native SFUND token. The platform suffered a critical $1.2–1.7 million bridge exploit in September 2025 attributed by ZachXBT and CZ (Binance) to the North Korean DPRK-affiliated 'Contagious Interview' hacking campaign, causing SFUND to collapse approximately 80–99% and affecting approximately 64,000 token holders. The platform's SFUND token has declined more than 99% from its November 2021 all-time high of approximately $17.67, and the project has been flagged by ZachXBT in connection with the on-chain forensics tying the exploit to state-sponsored theft infrastructure.

avoid.net/maya-protocol-august-2026-six-bug-exploit22/100[CRITICAL]

On August 18, 2026, an attacker exploited MAYAChain—the decentralized cross-chain liquidity network operated by Maya Protocol—by chaining six distinct software bugs in a single 23-message transaction. The exploit allowed the attacker to inflate a liquidity pool by approximately 49.45 million CACAO tokens, gain near-total control of that pool, and extract roughly $1.65–1.7 million in Bitcoin and other assets. CACAO's price fell approximately 89% and total network pool value dropped by an estimated $11 million, prompting an emergency network halt. As of late August 2026, the attacker's Bitcoin wallet remained unspent and no patch timeline or LP compensation framework had been publicly confirmed.

avoid.net/coinhub-bitcoin-atm-fraud-facilitation-network22/100[CRITICAL]

Coinhub, operated by Nevada-based LSGT Services LLC, is one of the largest remaining Bitcoin ATM operators in the United States with approximately 2,000 machines following Bitcoin Depot's May 2026 bankruptcy. The company has faced confirmed regulatory enforcement actions in California and Connecticut, has been named in U.S. Senate correspondence over its role in facilitating elder fraud, and has been identified by the ICIJ as a major recipient of bitcoin liquidity from Kraken despite ongoing scam-related losses at its machines. Coinhub has not been charged with fraud or any crime; all regulatory findings to date relate to consumer-protection violations including excessive fees and missing disclosures.

avoid.net/allbridge28/100[WARNING]

Allbridge is a cross-chain bridging protocol founded in 2021 that operates Allbridge Classic and Allbridge Core, supporting stablecoin transfers across more than 20 blockchains. The protocol has suffered three separate security incidents since its launch: a $573K flash loan exploit on BNB Chain in April 2023, a $1.65M flash loan attack on its Solana deployment in July 2026, and a $191K CCTP router exploit on Base in August 2026 involving forged Circle attestation messages. The recurrence of similar vulnerability classes across deployments — and the failure to apply 2023 remediations to all active chains — raises systemic concerns about the protocol's security review and deployment practices.

avoid.net/avici38/100[WARNING]

Avici (ticker: AVICI) is a Solana-based, self-custodial neobank and crypto payment platform that launched its token via an on-chain MetaDAO sale in October 2025. On August 28–29, 2026, attackers exploited an outdated Solana card contract supplied by Avici's issuing partner Rain, draining an estimated $500,859 to over $1 million from approximately 1,685 user card accounts; Avici pledged full refunds, filed an FBI IC3 report, and the stolen funds were ultimately moved through Tornado Cash. Separately, third-party scammers created fake airdrop sites impersonating Avici to drain additional user wallets.

avoid.net/fogo38/100[WARNING]

Fogo is a Layer 1 blockchain built on the Solana Virtual Machine (SVM), designed for institutional-grade, low-latency trading and settlement. It launched its public mainnet in January 2026 after raising approximately $20.5 million across multiple funding rounds. On August 29, 2026, the Fogo Foundation disclosed a wallet breach in which an unknown actor transferred 400 million FOGO tokens (approximately 4% of total supply, valued at roughly $3.88 million at the time) to an external address, causing the token price to fall approximately 18–20%.

avoid.net/term-finance22/100[CRITICAL]

Term Finance is an Ethereum-based DeFi fixed-rate lending protocol developed by Term Labs, Inc., which raised $8 million in funding from investors including Electric Capital and Maelstrom. On August 23, 2026, an attacker bootstrapped with 2 ETH sourced from Tornado Cash, acquired majority voting control of the protocol's sparsely held DAO governance token at a cost of approximately $951, and passed malicious proposals to drain an estimated $8.5 million (2,843 ETH and 1.68 million USDC) from Term's Meta Vaults. In response, Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles; as of the time of writing, no recovery of stolen funds has been confirmed and no concrete user compensation plan has been announced.

avoid.net/coldcard-coinkite28/100[WARNING]

Coinkite is a Toronto-based company founded in 2012 that manufactures Coldcard, a Bitcoin-only hardware wallet widely regarded before 2026 as one of the most secure consumer self-custody products available. Beginning July 30, 2026, attackers exploited a firmware vulnerability introduced in March 2021 that caused seed generation to fall back on a weak software pseudorandom number generator instead of hardware entropy, reducing effective key strength from 128 bits to as low as 40 bits. Across four documented attack waves through early August 2026, approximately 1,816 BTC valued at roughly $116 million was drained from more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026.

avoid.net/maya-protocol28/100[WARNING]

Maya Protocol (MAYAChain) is a decentralized cross-chain liquidity network and friendly fork of THORChain that launched its mainnet in April 2023. On August 18, 2026, an attacker chained six software vulnerabilities in a single 23-message transaction to fabricate approximately 49.45 million CACAO tokens, drain roughly $1.36 million in Bitcoin and other assets off-chain, and trigger an 88.7% collapse in CACAO's price. The team halted the network globally in response; as of late August 2026, the attacker had not returned funds, no formal post-mortem had been published by the team, and no swap-resumption timeline had been announced.

avoid.net/axiom-dex-insider-trading-202622/100[CRITICAL]

In February 2026, blockchain investigator ZachXBT published findings alleging that employees of Axiom Exchange, a Y Combinator-backed Solana trading platform, abused internal customer support dashboards to track private user wallet activity and execute insider trades over approximately one year. The alleged scheme, centered on senior business development employee Broox Bauer, exploited the platform's lack of role-based access controls to compile non-public trading data on high-profile crypto traders, with a secondary layer of alleged front-running on Polymarket prediction markets using advance knowledge of ZachXBT's impending report. No formal criminal charges had been publicly announced as of the investigation's release.

avoid.net/cetus-protocol28/100[WARNING]

Cetus Protocol is a concentrated liquidity market maker (CLMM) decentralized exchange deployed on the Sui and Aptos blockchains. On May 22, 2025, the protocol suffered one of the largest DeFi exploits in history when an attacker exploited an integer overflow vulnerability in its smart contract math library to drain approximately $223 million from liquidity pools. Roughly $162 million was frozen on-chain through emergency validator action by the Sui network, and following a governance vote the protocol relaunched in June 2025 with partial user compensation.

avoid.net/compound-v228/100[WARNING]

Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.

avoid.net/unibtc32/100[WARNING]

uniBTC is a synthetic Bitcoin liquid restaking token issued by Bedrock protocol, enabling wBTC holders to earn BTC-native yield via the Babylon staking protocol while retaining liquidity. In September 2024, a critical minting vulnerability in multiple uniBTC vault smart contracts across eight blockchains was exploited for approximately $2 million after a third-party security firm disclosed the flaw hours before the attack. Post-incident forensics by Fuzzland, disclosed in June 2025, attributed the exploit to an insider threat — a former employee who embedded malware into Fuzzland's internal codebase and used privileged access to execute the attack; Bedrock has since integrated Chainlink Proof of Reserve and expanded to multiple new chains.

avoid.net/kinto-bridge28/100[WARNING]

Kinto was a KYC-enforced Ethereum Layer 2 built on the Arbitrum Nitro stack, marketing itself as a 'safety-first' DeFi protocol with built-in AML and identity verification. On July 10, 2025, an attacker exploited a CPIMP proxy vulnerability in the $K token contract on Arbitrum, minting 110,000 unauthorized tokens and draining approximately $1.55–1.9 million from Uniswap V4 and Morpho Blue liquidity pools. Despite a partial recovery effort dubbed 'Phoenix,' the project announced shutdown effective September 30, 2025, as fundraising options collapsed and the team ran unpaid for months.

avoid.net/axiom-exchange-employee-insider-trading-scandal30/100[WARNING]

Axiom Exchange is a Y Combinator-backed, non-custodial Solana trading terminal founded in 2024 that generated over $390 million in revenue within roughly a year of launch. On February 26, 2026, blockchain investigator ZachXBT published findings alleging that at least one senior employee, Broox Bauer, systematically abused internal customer support tools to access private wallet data and share it with outside parties for front-running purposes, a scheme alleged to have operated for approximately ten months. The company issued a statement expressing disappointment, revoked access to the affected tools, and pledged an internal investigation, but no formal regulatory or legal charges had been announced as of the time of this report.

avoid.net/beanstalk-farms28/100[WARNING]

Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.

avoid.net/ranger-finance22/100[CRITICAL]

Ranger Finance was a Solana-based perpetual contract aggregator that raised $1.9M in seed funding in January 2025 and launched its RNGR token in January 2026. Within two months of token launch, community governance voted to liquidate the project treasury following allegations that the team made materially misleading claims about trading volume and revenue during its ICO. The project formally shut down in May 2026 after the treasury liquidation and approximately $900,000 in exposure from the DPRK-linked Drift Protocol exploit left operations unsustainable, with employees and vendors not fully compensated.

avoid.net/burgerswap22/100[CRITICAL]

BurgerSwap is a decentralized exchange (DEX) and automated market maker (AMM) protocol launched in September 2020 on Binance Smart Chain (BSC), built around the native BURGER governance token. On May 28, 2021, the protocol suffered a flash loan and reentrancy exploit that drained approximately $7.2 million in user funds across 14 transactions. Uniswap founder Hayden Adams publicly noted that a critical line of code enforcing the constant-product formula had been deliberately removed from BurgerSwap's fork of Uniswap v2, raising allegations of an intentional vulnerability or insider involvement by the anonymous development team.

avoid.net/aperocket22/100[CRITICAL]

ApeRocket is a DeFi yield farming aggregator and optimizer originally deployed on Binance Smart Chain (BSC) and Polygon in 2021. The protocol suffered two simultaneous flash loan exploits on July 14, 2021, resulting in combined losses of approximately $1.26 million and a 63% collapse in its native SPACE token price. The project attempted a V2 relaunch with improved security, but the SPACE token currently shows zero trading volume and effectively zero market capitalization, indicating the protocol is inactive.

avoid.net/bondly22/100[CRITICAL]

Bondly Finance is a DeFi and NFT protocol launched in September 2020 that suffered a major exploit on July 14-15, 2021, in which 373 million BONDLY tokens were minted via owner-level credentials and sold into liquidity pools, causing an 82% token price collapse and approximately $5.9-7.5 million in losses. The exploit originated from the protocol owner's address, prompting blockchain security firm PeckShield to allege a potential rug pull, though the team attributed it to compromised credentials belonging to CEO Brandon Smith. Following acquisition by Animoca Brands in September 2021 and a rebrand to Forj in May 2022, the project has undergone significant leadership changes; the original founder departed under a cloud of unresolved questions about the exploit's true origin.

avoid.net/gmx-v1-perps28/100[WARNING]

GMX V1 was a decentralized perpetual exchange on Arbitrum and Avalanche that operated from September 2021 until July 2025, when a reentrancy exploit drained approximately $42 million from its GLP liquidity pool. The protocol has since disabled all V1 trading and GLP minting; it is no longer an active product, with users directed to GMX V2, which was unaffected by the exploit.

avoid.net/themis-protocol32/100[WARNING]

Themis Protocol is a DeFi lending and borrowing platform deployed on Arbitrum that allows users to collateralize Uniswap v3 LP positions and Balancer LP tokens to borrow stablecoins and blue-chip assets. On June 27, 2023, approximately eleven days after its beta launch, the protocol suffered a flash loan oracle manipulation exploit resulting in approximately $370,000 in losses. The attacker laundered the stolen funds via Tornado Cash, the protocol was suspended indefinitely, and TVL effectively dropped to near zero following the incident.

avoid.net/stakecom28/100[WARNING]

Stake.com is a Curaçao-licensed cryptocurrency gambling and sports betting platform co-founded in 2017 by Australians Ed Craven and Bijan Tehrani, operating as one of the largest crypto casinos globally with reported 2024 revenue of $4.7 billion. On September 4, 2023, the platform suffered a critical security breach in which approximately $41.35 million in cryptocurrency was drained from its hot wallets across Ethereum, BNB Smart Chain, and Polygon networks; the FBI formally attributed the attack to North Korea's Lazarus Group (APT38) within 48 hours. Stake.com restored full operations within five hours of the incident and stated that user funds were not affected, though the root cause — a likely hot wallet private key compromise — has never been officially confirmed by the company.

avoid.net/leadblocks-morpho-blue-market38/100[WARNING]

LeadBlock's Morpho Blue Market refers to a permissionless lending market and associated MetaMorpho vault curated by LeadBlock Partners on the Morpho Blue protocol. On October 13, 2024, an oracle misconfiguration in the LeadBlock-curated PAXG/USDC market enabled an opportunistic user to borrow approximately $230,000 in USDC against only $350 of PAXG collateral, exploiting an overvalued asset price of $2.6 trillion per unit of gold. The incident was attributed to an incorrectly configured SCALE_FACTOR by LeadBlock's oracle provider and raised questions about the adequacy of pre-launch testing and risk curation practices.

avoid.net/impermax-v332/100[WARNING]

Impermax V3 is the third major iteration of Impermax Finance, a DeFi leveraged yield-farming and lending protocol that allows liquidity providers to use Uniswap V3 LP tokens as collateral. The protocol suffered two separate critical exploits in 2025 — a ~$300,000 flash-loan collateral valuation attack in April and a ~$380,000 liquidation logic exploit in November — both on the Base chain, resulting in cumulative losses exceeding $680,000 and leaving lenders with unresolved bad debt. These incidents follow a 2022 private key compromise affecting the IMX token, representing a recurring pattern of security failures across the protocol's history.

avoid.net/foom-cash28/100[WARNING]

FOOM Cash (foom.cash) is a pseudonymous, privacy-focused decentralized lottery protocol built on Ethereum and Base, marketed as an 'upgraded Tornado Cash' using zk-SNARKs cryptography. On February 26, 2026, the protocol suffered a $2.26 million exploit caused by a critical deployment error in its Groth16 trusted setup — a flaw publicly known from an identical exploit on Veil Cash days earlier that the team failed to patch. The team had been silent for approximately three months prior to the attack and was subsequently flagged as a notable risk by AVOID.NET due to compounding concerns: anonymous founders, serious operational negligence, misleading post-incident communications, and unverifiable audit claims.

avoid.net/evmos-network30/100[WARNING]

Evmos was a Cosmos-based, EVM-compatible proof-of-stake blockchain developed by Tharsis Labs that launched on mainnet in April 2022 and raised $27 million in a token sale led by Polychain Capital. The network was formally shut down on approximately May 18, 2026, after Governance Proposal #331 passed with 99.8% approval, halting all block production at block height 37,318,000. Following discontinuation, an authorization vulnerability in the Evmos vesting and lockup module — left unpatched because the codebase was no longer maintained — was exploited in August 2026 to drain approximately $3 million from BounceBit Chain, a third-party network built on the Evmos stack.

avoid.net/stakedao-vsdcrv-deployer-key-exploit-may-202638/100[WARNING]

On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.

avoid.net/abracadabra-finance-mim-stablecoin22/100[CRITICAL]

Abracadabra Finance is a multi-chain DeFi lending protocol that allows users to mint its USD-pegged stablecoin Magic Internet Money (MIM) against interest-bearing collateral. The protocol has suffered four significant security exploits between January 2024 and October 2025, with cumulative losses exceeding $21 million, and its MIM stablecoin depegged twice in a single week in June 2026 — reaching as low as $0.80 — due to critically thin DEX exit liquidity. As of mid-June 2026, MIM was trading approximately 18% below its $1 peg, with the protocol relying on a 140 million SPELL token incentive program to attract liquidity providers.

avoid.net/afi-protocol37/100[WARNING]

AFI Protocol (Artificial Financial Intelligence) is a DeFi infrastructure project building Proof-of-Reserve systems for Real-World Assets (RWAs) on Ethereum, offering yield-bearing ERC-4626 vaults backed by tokenized off-chain collateral. The protocol reported over $225 million in total value locked as of mid-2026 and maintains institutional partnerships with Multipli, Pendle, Morpho, and others. On May 30, 2026, the protocol suffered a $480,000 exploit targeting its afiUSD vault, with stolen funds partially laundered through Tornado Cash; recovery efforts were ongoing as of June 2026.

avoid.net/abracadabra-money28/100[WARNING]

Abracadabra Money is a multi-chain DeFi lending protocol founded in 2021 that allows users to mint Magic Internet Money (MIM), a USD-pegged stablecoin, using interest-bearing tokens as collateral. The protocol has suffered four significant security incidents between 2022 and 2025, losing over $21 million in aggregate, and its MIM stablecoin has lost its dollar peg on multiple occasions. The protocol is also linked to the Wonderland/Sifu scandal of early 2022, which caused severe reputational and financial contagion across its interconnected 'Frog Nation' ecosystem.

avoid.net/lifi-protocol38/100[WARNING]

LI.FI (formerly Li.Finance) is a cross-chain liquidity aggregation protocol founded in 2021 that routes swaps across bridges and DEXs via a unified API, SDK, and widget. The protocol has suffered two distinct smart contract exploits — a $600,000 approval drain in March 2022 and an approximately $11.6 million drain in July 2024 — with security firm PeckShield noting the root causes were 'basically the same.' Both incidents involved arbitrary-call vulnerabilities that allowed attackers to abuse users' infinite token approvals, raising concerns about repeated security failures despite prior disclosure.

avoid.net/adshares-bridge-ads28/100[WARNING]

Adshares is a Warsaw-based decentralized advertising protocol operating a proprietary dPoS blockchain with cross-chain bridges to Ethereum, BSC, Base, and Polygon. In May 2026 its Ethereum bridge was exploited for approximately $628,000 through fake wrapped-token minting, making it one of eight bridge exploits tracked by PeckShield that month. Approximately 86% of stolen funds were returned after the team offered a 10% whitehat bounty, but no public post-mortem has been published and the root cause of the bridge compromise remains unconfirmed.

avoid.net/gate32/100[WARNING]

Gate.io (formerly Bter.com) is a centralized cryptocurrency exchange founded in 2013 by Han Lin, serving over 30 million users across 224 countries. The exchange has been flagged by on-chain investigator ZachXBT for allegedly concealing a $230 million hack attributed to North Korean state-sponsored hackers (Lazarus Group) that occurred in April 2018 and was never publicly disclosed to users. Additional concerns include a manipulated futures price feed incident causing millions in user losses in 2025, an AML-based ban by India's Financial Intelligence Unit in 2024, persistent user complaints about frozen withdrawals, and alleged wash trading activity inflating reported volumes.

avoid.net/lendfme30/100[WARNING]

Lendf.me was a decentralized lending protocol built by dForce Network and launched in September 2019 as a fork of Compound v1. On April 19, 2020, an attacker exploited a reentrancy vulnerability involving ERC-777 tokens to drain approximately $25.2 million from the protocol — at the time representing 99.95% of its total value locked. The attacker returned nearly all funds within two days after inadvertently exposing identifying metadata, and the original Lendf.me contract was permanently deprecated following the incident.

avoid.net/acala-network32/100[WARNING]

Acala Network is a Polkadot-native DeFi hub offering a multi-collateralized stablecoin (aUSD), liquid staking, and an AMM DEX. On August 14, 2022, a misconfiguration in a newly deployed liquidity pool caused 3.022 billion aUSD to be erroneously minted, triggering a 99% depeg; approximately 98% of the erroneous tokens were subsequently recovered and burned via community governance votes. The incident raised significant concerns about the protocol's claimed decentralization after the team unilaterally placed the network in maintenance mode and froze token transfers without an on-chain vote.

avoid.net/superfluid38/100[WARNING]

Superfluid is an asset streaming and programmable cash flow protocol founded in 2020, deployed across Ethereum, Polygon, and multiple other EVM chains. On February 8, 2022, an attacker exploited a context serialization vulnerability in the protocol's host contract, draining approximately $8.7 million in assets from multiple projects including QiDAO, Stake DAO, Stacker Ventures, and Museum of Crypto Art. The protocol patched the vulnerability within hours, partially compensated affected parties, and has continued operating with additional audits and a native SUP token launch in 2025.

avoid.net/treasure32/100[WARNING]

TreasureDAO is an Arbitrum-based NFT gaming ecosystem and marketplace powered by the MAGIC token. In March 2022 its marketplace suffered a critical smart contract exploit that allowed attackers to acquire NFTs for free, resulting in approximately $1.4 million in losses across 153 NFTs. Separately, blockchain investigator ZachXBT raised concerns in February 2022 about a core team engineer's alleged prior involvement in failed NFT projects. The project has since experienced severe financial distress, shut down its Treasure Chain layer-2 network in May 2025 after five months of operation, and executed major layoffs in a pivot to AI-agent products.

avoid.net/templedao32/100[WARNING]

TempleDAO is a DeFi yield protocol launched on Ethereum in August 2021, designed to offer low-volatility, fractionally backed yields on deposited assets. On October 11, 2022, an associated staking product, STAX Finance, suffered a smart contract exploit due to missing access control on the migrateStake() function, resulting in approximately $2.34 million in stolen funds that were subsequently laundered through Tornado Cash. The core TempleDAO vaults were not directly compromised, but the team's anonymous structure and the unrecovered stolen funds remain notable risk factors.

avoid.net/save38/100[WARNING]

Save (formerly Solend) is a Solana-based algorithmic lending and borrowing protocol that has operated since 2021. The protocol has been flagged by ZachXBT and carries a history of two significant incidents: a controversial governance vote in June 2022 that briefly granted the team emergency powers to seize a user's wallet, and a $1.26 million oracle manipulation exploit in November 2022. The protocol rebranded from Solend to Save in late 2024 and continues to operate with approximately $74 million in total value locked as of mid-2026.

avoid.net/ratio-finance22/100[CRITICAL]

Ratio Finance is a defunct Solana-based collateralized debt position (CDP) protocol that allowed users to mint the USDr stablecoin against yield-bearing LP token collateral. The protocol raised $8.4 million across multiple rounds from investors including Alameda Research, Solana Ventures, and CMS Holdings, then launched its RATIO governance token in March 2022 at an all-time high near $2.24. The project suffered a private key compromise on or around December 3, 2022, after which the protocol's TVL fell to zero, the RATIO token lost over 99.9% of its value, and all social media activity ceased by December 2023.

avoid.net/level-perps28/100[WARNING]

Level Finance (also marketed as Level Perps) is a decentralized perpetual derivatives exchange that launched on BNB Chain in Q4 2022 and later expanded to Arbitrum. In May 2023 the protocol suffered a $1.1 million exploit caused by a logic bug in its referral reward contract that was missed by two prior security audits. The protocol's LVL token has declined approximately 99.9% from its all-time high, and as of 2025-2026 the protocol shows near-zero TVL ($32K), zero fees, and zero revenue, indicating effective dormancy.

avoid.net/exactly32/100[WARNING]

Exactly Protocol is a decentralized, non-custodial fixed-rate and variable-rate lending protocol deployed on the Optimism Layer 2 network. On August 18, 2023, the protocol suffered a critical exploit resulting in approximately $7.3–$12 million in ETH stolen from 117 user accounts due to insufficient input validation in its DebtManager periphery contract. The protocol has since resumed operations, engaged law enforcement, offered a $700,000 bounty, and passed a governance proposal to compensate affected users with EXA tokens.

avoid.net/harbor-protocol28/100[WARNING]

Harbor Protocol is a decentralized collateralized-debt-position (CDP) protocol built on the Comdex chain (Cosmos SDK / CosmWasm) that enabled users to mint the Composite stablecoin (CMST) against whitelisted collateral assets. The protocol suffered two distinct security incidents in 2023 — an oracle-manipulation liquidation event in June and a direct vault drain exploit in August — after which its total value locked collapsed to effectively zero. As of 2025 the protocol appears inactive, with the HARBOR governance token near worthless and no meaningful community or development activity detected.

avoid.net/locus-finance22/100[CRITICAL]

Locus Finance is a DeFi yield-vault protocol launched in July 2023 by Iakov Levin, the founder of the defunct custodial crypto platform Midas Investments, which collapsed in December 2022 with a reported $63.3 million deficit. On December 30, 2023, Locus suffered a $320,964 exploit due to a developer private key leak during a CTO transition. The LOCUS token has declined over 99% from its all-time high, the protocol's TVL is near zero, and Levin is subject to regulatory enforcement actions in California and Wisconsin related to his prior venture.

avoid.net/wise-lending-v122/100[CRITICAL]

Wise Lending V1 is the first version of the Wise Lending decentralized lending and yield-aggregation protocol deployed on Ethereum, built from scratch by WiseSoft LLC and founded by Peter Girr. The V1 deployment suffered two confirmed on-chain exploits within approximately three months, losing an estimated $700,000+ in total user funds across both incidents, with no publicly documented recovery or compensation plan. ZachXBT has flagged the entity, and post-exploit TVL collapsed effectively to zero.

avoid.net/shido22/100[CRITICAL]

Shido Network (SHIDO) is a Layer-1 proof-of-stake blockchain project founded in Sweden in 2021. On February 29, 2024, an attacker exploited the Ethereum-based SHIDO staking contract by transferring ownership to a new address and upgrading it with a hidden token-withdrawal function, draining over 4.3 billion tokens and causing the price to collapse 94% within 30 minutes. On-chain investigator ZachXBT linked the exploit to a serial hacker responsible for the OKX (December 2023) and Concentric Finance (January 2024) hacks, with the attack vector in each case being private key compromise via social engineering.

avoid.net/pike-v122/100[CRITICAL]

Pike V1 (also known as Pike Beta) was a cross-chain DeFi lending protocol built by Nuts Finance that suffered two smart contract exploits within four days in April 2024, resulting in approximately $1.98 million in user losses. A vulnerability identified by auditing partner OtterSec prior to launch was never remediated, and a subsequent botched patch introduced even more severe vulnerabilities. The project's October 2024 token generation event further damaged investor trust after the team launched the $P token with only $10,000 in initial liquidity despite having raised $6.45 million in a presale.

avoid.net/yolo-games28/100[WARNING]

YOLO Games is an on-chain gambling platform built on the Blast Layer 2 network, offering high-risk games such as YOLO, Moon or Doom, and Poke the Bear, with a native $YOLO token as its reward mechanism. In June 2024, an access control vulnerability in a third-party Liquidity Bootstrapping Pool (LBP) contract was exploited, resulting in the extraction of approximately $1.387 million, of which 90% was subsequently returned by the attacker acting as a whitehat. The $YOLO token has since collapsed approximately 99.6% from its all-time high and the protocol shows near-zero fee activity as of 2025-2026, suggesting severe user attrition or effective abandonment.

avoid.net/lifi-finance32/100[WARNING]

LI.FI is a Berlin-based cross-chain bridge and DEX aggregation protocol founded in 2021 by Philipp Zentner and Max Klenk. The protocol has suffered two significant smart contract exploits — a $600,000 loss in March 2022 and an $11.6 million loss in July 2024 — both stemming from the same class of arbitrary-call vulnerability, prompting criticism from security researchers that lessons were not learned. Separately, blockchain investigator ZachXBT alleged in June 2025 that North Korean (DPRK) actors accounted for an estimated 15–25% of the protocol's volume during May 2025, using LI.FI to launder funds from the Bybit hack.

avoid.net/zkfinance32/100[WARNING]

zkFinance is a DeFi lending and borrowing protocol deployed on zkSync Era that also offers bridging, cross-chain swaps, and a concentrated-liquidity DEX. The protocol suffered a documented $200,000 protocol logic exploit attributed to an oracle misconfiguration in November 2024 and has since registered near-zero TVL ($24,990) with no active loans outstanding. The team is pseudonymous, no public founder identities have been verified, and the protocol's native ZGT token has attracted minimal exchange listing activity and negligible on-chain trading volume.

avoid.net/futureswap22/100[CRITICAL]

Futureswap is a decentralized perpetual futures exchange built on Arbitrum and Avalanche that raised $12 million in 2021 but has been effectively dormant since 2023. The protocol suffered three separate exploits between December 2025 and January 2026, resulting in cumulative losses exceeding $1.3 million, while the team made no public response to any incident. ZachXBT flagged the entity as a risk, and the protocol's last known audit dates to 2021.

avoid.net/goose-finance32/100[WARNING]

Goose Finance is an anonymous-team yield farming and decentralized exchange protocol launched on Binance Smart Chain in February 2021, best known for its EGG governance and reward token. The protocol achieved rapid early traction, reaching third-most-popular DeFi app on BSC within one month, before its EGG token collapsed more than 99% from an all-time high near $172. A post-audit smart contract exploit in March 2026 drained approximately $8,000 via a share accounting flaw, and independent analysts have flagged the layered farming tokenomics as structurally unsustainable.

avoid.net/ankr-helio28/100[WARNING]

On December 1–2, 2022, a former Ankr employee carried out a supply chain attack that compromised the protocol's deployer private key, enabling the minting of trillions of aBNBc tokens and the draining of approximately $5 million in liquidity. Hours later, a separate attacker exploited Helio Protocol's slow price oracle to borrow $16.4 million in HAY stablecoin against nearly worthless aBNBc collateral, ultimately netting around $15.5 million. Combined losses exceeded $20 million, making it one of the most significant DeFi insider-threat incidents of 2022.

avoid.net/stake-com38/100[WARNING]

Stake.com is the world's largest crypto gambling platform by revenue, founded in 2017 by Australian entrepreneurs Ed Craven and Bijan Tehrani and operating under a Curacao gaming license. In September 2023, the platform suffered a $41 million hot wallet breach that the FBI formally attributed to North Korea's Lazarus Group (APT38). The platform faces mounting legal and regulatory pressure across multiple jurisdictions, including a landmark California civil suit filed by the Los Angeles City Attorney in 2025, multiple class action lawsuits, and a UK exit following a Gambling Commission investigation.

avoid.net/roman-storm22/100[CRITICAL]

Roman Storm is a Russian-born, naturalized U.S. citizen and co-founder of Tornado Cash, an Ethereum-based cryptocurrency mixing protocol sanctioned by OFAC in August 2022. He was arrested in August 2023 and indicted in the Southern District of New York on three counts: conspiracy to commit money laundering, conspiracy to operate an unlicensed money transmitting business, and conspiracy to violate U.S. sanctions (IEEPA). A jury convicted him in August 2025 on the unlicensed money transmitting count while deadlocking on the two more serious charges, and prosecutors have filed to retry him on the deadlocked counts in October 2026.

avoid.net/pickle-finance28/100[WARNING]

Pickle Finance was a DeFi yield aggregator launched in September 2020 that allowed users to auto-compound returns via tokenized strategy vaults called 'Jars.' On November 21, 2020, an attacker exploited a combination of smart contract vulnerabilities in the unaudited ControllerV4 contract to drain 19,759,355 DAI (~$19.7 million) from the pDAI Jar in what analysts described as one of the most technically complex DeFi exploits of its era. The protocol subsequently partnered with Yearn Finance, issued a CORNICHON compensation token to victims, and continued operating until it announced a full shutdown effective October 1, 2025.

avoid.net/infini-protocol22/100[CRITICAL]

Infini is a Hong Kong-based stablecoin neobank offering yield, payments, and enterprise treasury tools built on DeFi infrastructure. In February 2025, the platform suffered a $49.5 million exploit when a former contract developer who had secretly retained administrative privileges drained the Morpho MEVCapital USDC Vault across two transactions. Founder Christian Li pledged personal coverage of losses and offered a 20% bounty to the attacker; as of mid-2026 the stolen funds have not been recovered, with the exploiter laundering proceeds through Tornado Cash.

avoid.net/inverse-finance38/100[WARNING]

Inverse Finance is an Ethereum-based DeFi protocol known for its DOLA stablecoin and FiRM fixed-rate lending market, founded in late 2020 by Nour Haridy. The protocol suffered two oracle price manipulation exploits within two months in 2022 — the first in April for approximately $15.6 million and the second in June for a protocol loss of approximately $5.8 million — collectively representing one of the most significant serial oracle attack sequences in DeFi history. The protocol has since deprecated the vulnerable Anchor and Frontier lending markets, rebuilt on FiRM with Chainlink oracles, and undertaken a multi-year bad-debt repayment program.

avoid.net/ronin-network22/100[CRITICAL]

Ronin Network is an Ethereum sidechain developed by Sky Mavis to support the Axie Infinity play-to-earn game. In March 2022, it suffered the largest cryptocurrency hack in history when attackers — subsequently attributed by the FBI and U.S. Treasury to North Korea's Lazarus Group — exploited compromised validator private keys to drain approximately $625 million in ETH and USDC. A second, smaller exploit occurred in August 2024, though those funds were returned by a white-hat MEV bot operator.

avoid.net/punk-protocol22/100[CRITICAL]

Punk Protocol was an Ethereum-based DeFi project that positioned itself as a decentralized annuity and pension service. On August 10, 2021, it suffered a critical smart contract exploit due to a missing access-control modifier in its CompoundModel contract, resulting in approximately $8.95 million in stablecoin losses; roughly $5 million was partially recovered via a white-hat frontrunner who retained a $1 million bounty. The project launched without a security audit, has published no meaningful updates since late 2021, and its PUNK token currently trades at effectively zero volume, indicating the project is dormant or abandoned.

avoid.net/dao-maker-vesting22/100[CRITICAL]

DAO Maker Vesting refers to the smart contract infrastructure operated by DAO Maker, a crypto launchpad platform, that was compromised in two separate exploits in 2021 resulting in combined losses of approximately $11 million. The August 2021 incident drained $7 million in USDC from 5,251 user accounts via a compromised admin private key, and a second exploit in September 2021 extracted approximately $4 million from vesting contracts via an unauthenticated init() function vulnerability. Victims allege that DAO Maker has failed to honor its full compensation commitments over three years after the hacks, with governance manipulation alleged to have been used to cancel the USDR reimbursement program.

avoid.net/sentiment32/100[WARNING]

Sentiment is an undercollateralized DeFi lending protocol originally deployed on Arbitrum, later migrating activity to HyperLiquid L1. On April 4, 2023, the protocol suffered a read-only reentrancy exploit resulting in approximately $1 million in losses, of which 90% was returned by the attacker following a negotiated $95,000 bounty. ZachXBT has flagged the entity for elevated risk; the protocol remains operational with a low TVL of roughly $518,000 as of 2025.

avoid.net/eralend28/100[WARNING]

EraLend (formerly Nexon Finance) is a decentralized lending protocol on zkSync Era that suffered a $3.4 million read-only reentrancy exploit on July 25, 2023, draining its USDC pool due to a vulnerability in inherited SyncSwap oracle code. The protocol's pre-hack audit by PeckShield explicitly assumed a trusted price oracle, leaving the vulnerable oracle mechanism unexamined. EraLend relaunched post-hack with a fee-based compensation plan but has seen its TVL decline sharply to approximately $138,000 as of 2025-2026.

avoid.net/balancer-v232/100[WARNING]

Balancer V2 is a decentralized automated market maker (AMM) protocol launched in 2021 on Ethereum and multiple chains that separates AMM logic from token custody via a central Vault architecture. The protocol has experienced at least four documented security incidents across its V1 and V2 deployments, including a November 2025 exploit that drained approximately $128 million and directly led to the dissolution of Balancer Labs, the corporate entity behind the protocol, announced in March 2026.

avoid.net/remitano28/100[WARNING]

Remitano is a peer-to-peer cryptocurrency exchange operated by Babylon Solutions Limited, incorporated in Seychelles and active since 2015. The platform suffered a confirmed hot wallet hack in September 2023 resulting in approximately $2.7 million in losses, with the Lazarus Group (North Korea-linked) alleged as a probable suspect. Regulatory authorities in Malaysia, the United Kingdom, and Seychelles have issued warnings or taken enforcement actions against Remitano for operating without authorization, and the operating entity Babylon Solutions Limited was dissolved and struck off as of January 1, 2023.

avoid.net/arena-socialfi32/100[WARNING]

Arena SocialFi (originally Stars Arena, rebranded to The Arena) is an Avalanche-based SocialFi platform launched September 2023. The platform suffered a critical reentrancy exploit on October 7, 2023, losing approximately $2.9 million in AVAX; it subsequently recovered ~90% of stolen funds via a bounty agreement. Following the hack, the original team dissolved and the platform was acquired and rebuilt under new leadership, launching the ARENA token in 2024 and raising $2 million in pre-seed funding.

avoid.net/astrid-finance38/100[WARNING]

Astrid Finance is an Ethereum-based liquid restaking protocol built on EigenLayer, allowing users to deposit liquid staking tokens (stETH, rETH, cbETH) in exchange for liquid restaked tokens. On October 28, 2023, the protocol suffered a smart contract exploit due to a missing input validation check in its withdraw function, resulting in the theft of approximately $228,000 in assets. The attacker eventually returned 80% of stolen funds after an on-chain negotiation and legal threat by the team; all affected users received refunds, and the vulnerable contracts remain paused pending re-audit.

avoid.net/raft22/100[CRITICAL]

Raft is a decentralized Ethereum CDP lending protocol that issued the R stablecoin, collateralized by liquid staking tokens (stETH, rETH). On November 10, 2023, an attacker exploited a precision loss vulnerability to mint approximately $6.7 million in unbacked R tokens, draining 1,577 ETH from the protocol and causing the R stablecoin to depeg by up to 50%. Due to a coding error the attacker burned 1,570 of the stolen ETH to an inaccessible burn address, effectively losing money on the attack; the protocol subsequently implemented a partial recovery plan offering approximately 42% restitution to affected users and announced plans to phase out the current version.

avoid.net/yield-protocol38/100[WARNING]

Yield Protocol was a decentralized finance protocol offering fixed-rate, fixed-term borrowing and lending on Ethereum and Arbitrum, launched in October 2020 and funded by Paradigm. It suffered multiple security incidents including collateral damage from the March 2023 Euler Finance hack and a critical smart contract vulnerability patched via Immunefi in April 2023, before announcing a full wind-down in October 2023 citing insufficient demand and regulatory pressure. After official operations ceased in December 2023, abandoned smart contracts on Arbitrum were exploited in April 2024 for approximately $181,000 via a flash loan attack on pool balance discrepancies.

avoid.net/holograph28/100[WARNING]

Holograph is an omnichain tokenization protocol that enables cross-chain asset transfers, launched in 2022 by CXIP Labs with $6.5 million in seed funding. On June 13, 2024, a former technical contractor exploited admin-level access to the protocol's operator contract to mint 1 billion unauthorized HLG tokens worth approximately $14.4 million, crashing the token price by over 80%. Four suspects were subsequently arrested in Italy and extradited to France, where criminal proceedings are ongoing; approximately 80% of stolen tokens were reported recovered by law enforcement.

avoid.net/okx-nft-aggregator30/100[WARNING]

OKX NFT Aggregator is the NFT marketplace and aggregation layer of OKX, one of the world's largest crypto exchanges, supporting over 21 blockchains and 32 aggregated markets. The product has been implicated in a smart contract storage-collision exploit (June 2024), operates within an exchange that pleaded guilty to U.S. AML violations and agreed to a $504 million DOJ settlement (February 2025), and saw its parent DEX aggregator suspended in March 2025 after North Korea's Lazarus Group used the broader OKX Web3 infrastructure to launder approximately $100 million from the Bybit hack. ZachXBT has flagged the entity in the context of these broader OKX platform concerns.

avoid.net/coinstats35/100[WARNING]

CoinStats is an Armenian-founded cryptocurrency portfolio tracking application with approximately 1.5 million users, founded in 2017 by Narek Gevorgyan. On June 22, 2024, the platform suffered a significant security breach in which 1,590 internally-hosted wallets were compromised and approximately $2.2 million in cryptocurrency was stolen, with attribution pointing to North Korea's Lazarus Group. The platform has since rebuilt its infrastructure and restored operations, but no confirmed compensation program for affected users has been publicly documented.

avoid.net/rho-markets38/100[WARNING]

Rho Markets is a DeFi lending protocol (Compound V2 fork) deployed on Scroll, an Ethereum Layer 2 ZK-rollup network. On July 19, 2024, a misconfigured price oracle allowed an MEV bot to extract approximately $7.6 million in user funds; the operator voluntarily returned all funds after demanding a public acknowledgment of the misconfiguration. Despite full fund recovery, the protocol's TVL collapsed to near-zero and remains essentially inactive as of 2026.

avoid.net/onyx-v222/100[CRITICAL]

Onyx Protocol is a Compound Finance fork and DeFi lending platform on Ethereum that launched a V2 iteration in 2024 following two devastating exploits — one in November 2023 ($2.1M) and a second in September 2024 ($3.8M) — both exploiting the same known vulnerability in the Compound V2 codebase. After the second hack, the community voted to shut down the Ethereum lending market and relaunch as Onyx Core; V2 targeting compliance with the U.S. CLARITY Act launched in Q3 2025 on a new XCN Ledger infrastructure. Total confirmed losses across both exploits exceed $5.9 million.

avoid.net/upcx28/100[WARNING]

UPCX is a blockchain payment protocol that suffered a $70 million exploit on April 1, 2025, when an attacker compromised an administrative private key and used it to push a malicious smart contract upgrade, draining 18.4 million UPC tokens from management accounts. The attack was enabled by the absence of multisig controls on privileged protocol functions, despite having undergone CertiK and Cyberscope audits that did not catch the operational key management risk. Despite listing on a Japanese FSA-licensed exchange just 11 days prior, no recovery of stolen funds was reported.

avoid.net/loopscale38/100[WARNING]

Loopscale is a Solana-based DeFi lending protocol (formerly Bridgesplit) launched on April 10, 2025, backed by Coinbase Ventures, Solana Labs, and CoinFund. On April 26, 2025 — just 16 days after launch — the protocol suffered a $5.8 million oracle pricing exploit affecting its Genesis Vaults, an attack vector that had been flagged in its pre-launch OShield security audit but was allegedly inadequately remediated. All stolen funds were ultimately recovered via negotiation with the exploiter, and user deposits suffered no permanent loss.

avoid.net/prxvt38/100[WARNING]

PRXVT (ticker: PRXVT) is a privacy-focused AI-agent token launched on the Base blockchain via the Virtuals Protocol launchpad. The project markets itself as the governance and utility token for px402, an alleged zero-knowledge payment SDK designed to enable anonymous USDC transactions for autonomous AI agents. In early January 2026 the project's staking contract was exploited via a reward-claiming vulnerability, causing the token price to crash to an all-time low and prompting a contested emergency removal of a liquidity pool that was publicly represented as locked for ten years.

avoid.net/aethir36/100[WARNING]

Aethir is a Singapore-based decentralized GPU cloud computing protocol operating as a Decentralized Physical Infrastructure Network (DePIN), founded in 2021 by Mark Rydon and Daniel Wang. The project raised approximately $109M across funding rounds and a $100M+ checker node sale, launched its ATH token in June 2024, and claims $147M+ ARR from enterprise AI and gaming clients. Risk factors include a 95% token price decline from its all-time high, a redirected Season 3 community airdrop, a cross-chain bridge exploit in April 2026 resulting in up to $400K in losses, heavy insider token allocation, and a ZachXBT flag whose specific basis has not been publicly detailed.

avoid.net/purrlend22/100[CRITICAL]

Purrlend is a non-custodial DeFi lending and borrowing protocol deployed on HyperEVM and MegaETH, operating as an Aave-style fork designed for leveraged yield farming. On April 25, 2026, the protocol suffered a multisig permission exploit that drained approximately $1.52 million across both networks, collapsing its TVL by roughly 70%. As of late May 2026, the protocol remains paused with no published post-mortem, recovery plan, or user compensation details.

avoid.net/port3-network38/100[WARNING]

Port3 Network is a Web3 social data protocol and AI data layer founded in 2022, backed by KuCoin Ventures and Jump Crypto, with products including SoQuest, SoSignal, and SoPush targeting Web3 community engagement and data aggregation. In November 2025 the project suffered a critical exploit in which an attacker leveraged a boundary-condition vulnerability in the third-party CATERC20 cross-chain standard to mint approximately 1 billion unauthorized PORT3 tokens valued at roughly $13 million, triggering an 80% token price collapse and full contract migration. ZachXBT has flagged the entity, and the token has been delisted from at least one major exchange (Coinone) following the incident.

avoid.net/iotex38/100[WARNING]

IoTeX is a Layer 1 blockchain and DePIN (Decentralized Physical Infrastructure Network) platform founded in 2017 by Raullen Chai, Qevan Guo, Jing Sun, and Xinxin Fan, with its native IOTX token launched via ICO in 2018. In February 2026 the project suffered a significant security incident when a compromised private key on the Ethereum side of its ioTube cross-chain bridge allowed an attacker to drain approximately $4.3–$4.4 million in assets and mint 410 million unauthorized CIOTX tokens, with total estimated damages disputed between $4.4 million (official) and $8.8 million (PeckShield). Additional concerns include a prior market-maker-linked near-zero price anomaly on Binance in October 2025, governance centralization risks from its 36-delegate Roll-DPoS consensus model, and on-chain analyst reports alleging the attacker's wallet was funded by the same entity behind the $49 million Infini Finance hack of 2025.

avoid.net/neutrl33/100[WARNING]

Neutrl is a DeFi protocol issuing NUSD, a market-neutral synthetic dollar backed by OTC altcoin arbitrage and delta-neutral futures hedging strategies. The protocol raised $5 million in seed funding in April 2025 and grew to over $136 million in TVL. In March 2026 Neutrl suffered a DNS hijacking attack — part of a coordinated campaign targeting .fi domain protocols — that compromised its frontend interface, though the team maintained that smart contract reserves and user funds were not directly drained.

avoid.net/hyperbridge32/100[WARNING]

Hyperbridge is a cross-chain interoperability protocol built by Polytope Labs (founded by Nigerian engineers Seun Lanlege and David Salami) that uses cryptographic proofs to facilitate asset and message transfers across blockchains. On April 13, 2026, an attacker exploited a Merkle Mountain Range (MMR) proof verification vulnerability in the Token Gateway contract, minting 1 billion fraudulent bridged DOT tokens and extracting losses initially reported at $237,000 but later revised to approximately $2.5 million across Ethereum, Base, BNB Chain, and Arbitrum. The exploit occurred less than two weeks after the project publicly mocked the possibility of being hacked in an April Fools joke, and followed alleged dismissals of security researchers who had flagged vulnerabilities beforehand.

avoid.net/juicebox-v340/100[WARNING]

Juicebox is an Ethereum-based programmable treasury and crowdfunding protocol first launched in July 2021 by a pseudonymous developer known as Jango, enabling projects to raise ETH, issue contributor tokens, and manage on-chain treasuries without intermediaries. V3 is the third major iteration of the core contracts, deployed in September 2022, and subsequently patched through versions 3.1, 3.1.1, and 3.1.2 to address a series of high-severity and critical accounting vulnerabilities. A protocol logic exploit in April 2026 resulted in an alleged $52,000 loss via a borrowFrom spoof attack, and the platform's permissionless architecture has enabled misuse by bad actors operating fraudulent fundraising projects.

avoid.net/coincheck38/100[WARNING]

Coincheck is a Tokyo-based cryptocurrency exchange that suffered what was, at the time, the largest cryptocurrency hack in history on January 26, 2018, when approximately 523 million NEM (XEM) tokens valued at roughly $534 million were stolen from a low-security hot wallet. The exchange was operating without a Financial Services Agency (FSA) license at the time of the breach, had failed to implement standard multisignature security for NEM holdings, and received multiple business improvement orders from Japanese regulators in the aftermath. Coincheck was subsequently acquired by Monex Group in April 2018, obtained its FSA license in January 2019, and listed on the Nasdaq in December 2024 via a SPAC merger under the ticker CNCK.

avoid.net/akropolis30/100[WARNING]

Akropolis is an Ethereum-based DeFi protocol founded in 2017 by Ana Andrianova and Kate Kurbanova, offering yield aggregation and undercollateralized lending through its Delphi and Sparta products. On November 12, 2020, the protocol suffered a $2.03 million DAI exploit via a reentrancy and flash loan attack — a vulnerability that was missed across multiple third-party smart contract audits. The project subsequently rebranded to Kaon in early 2025, having never recovered the stolen funds or fully compensated affected users.

avoid.net/belt-finance28/100[WARNING]

Belt Finance (belt.fi) is a multi-strategy yield aggregator and stableswap AMM built primarily on Binance Smart Chain (BSC), developed by South Korean blockchain firm Ozys. On May 29, 2021, the protocol was exploited via a flash loan attack that netted the attacker approximately $6.23 million in BUSD and caused an estimated $50 million in total pool losses. The protocol announced a phased compensation plan for affected users but full repayment status remains unverified; the protocol has continued operating in diminished form, with current TVL of approximately $12 million as of 2025.

avoid.net/vesper-finance38/100[WARNING]

Vesper Finance is an Ethereum-based DeFi yield aggregator co-founded by former Bitcoin Core developer Jeff Garzik that launched in early 2021 and briefly exceeded $1 billion in TVL. The protocol suffered a confirmed $3.37 million oracle manipulation exploit on Rari Fuse Pool #23 in November 2021, and was indirectly exposed to a May 2024 Sonne Finance exploit that required treasury remediation. Vesper remains operational as of 2025 with approximately $48–55 million TVL, though its native VSP token has lost over 99% of its all-time-high value.

avoid.net/bns28/100[WARNING]

BitBNS (Bitbns) is an Indian cryptocurrency exchange founded in 2017 by Gaurav Dahake, Prashant Singh, and Srikanth Sethumadhavan, operating under Buyhatke Internet Private Limited and headquartered in Bengaluru. In February 2022 the exchange suffered a $7.5 million hack that it concealed from users under the guise of 'system maintenance' for over a year until on-chain investigator ZachXBT publicly exposed the breach in March 2023. The exchange subsequently froze user withdrawals for approximately two years, drawing multiple court actions in India and sustained criticism for withholding customer funds while continuing to accept new deposits.

avoid.net/wintermute38/100[WARNING]

Wintermute is a London-headquartered algorithmic trading firm and cryptocurrency market maker founded in 2017 by Evgeny Gaevoy. On September 20, 2022, the firm's DeFi operations were exploited for approximately $160 million after an attacker leveraged a known cryptographic vulnerability in the Profanity vanity address tool to compromise Wintermute's admin private key. The stolen funds were never recovered, though the firm remained solvent, repaid its outstanding DeFi loans, and has continued operating and expanding into U.S. markets.

avoid.net/rocketswap-base22/100[CRITICAL]

RocketSwap is a decentralized exchange (DEX) launched on the Coinbase Base Layer 2 network in mid-2023 that suffered a $865,000 private key compromise exploit just days after Base's public launch, making it one of the first major exploits on the network. The attack, confirmed by security firms PeckShield and Certik as a private key compromise, was compounded by a separate $69,000 social engineering loss one week prior, and the hacker subsequently laundered stolen funds through Tornado Cash, Binance, OKX, and a self-created memecoin called LoveRCKT. The project has been flagged by ZachXBT and community analysts, with some alleging that pre-exploit proxy contract modifications and the team's decision to silence communications point to possible insider involvement, though this has not been conclusively proven.

avoid.net/gmblcomputer38/100[WARNING]

GMBL.COMPUTER is an Arbitrum-based DeFi gambling protocol that launched in September 2023 and was exploited within hours of going live, losing approximately 471 ETH (~$770,000) due to an off-chain server signature vulnerability and a flaw in its referral system. The exploiter returned roughly half of the stolen funds (235 ETH) after the team issued a conditional bug bounty offer. The protocol operates with an anonymous team, no disclosed security audits, no regulatory licensing, and as of 2025 shows near-zero trading volume and minimal on-chain activity.

avoid.net/blueberry32/100[WARNING]

Blueberry Protocol is an Ethereum-based decentralized leveraged yield farming and prime brokerage protocol developed by Composable Corp. In February 2024, the protocol suffered a significant exploit caused by an oracle misconfiguration that allowed a flash loan attacker to drain approximately 457.7 ETH (~$1.35M) from three lending markets; most funds were rescued by white hat MEV operator c0ffeebabe.eth but ~91 ETH (~$265,000) was permanently lost to validator payments. Despite completing multiple Sherlock and Hacken audits and raising $2.5M in a June 2024 Series A, the protocol's security track record and history of audit findings raise material concerns for prospective users.

avoid.net/super-sushi-samurai28/100[WARNING]

Super Sushi Samurai (SSS) is a Telegram-based blockchain game launched on the Blast layer-2 network in March 2024. On March 21, 2024 — four days after launch — a critical infinite-mint vulnerability in the SSS token contract was exploited, draining approximately $4.6–4.8 million (1,310 ETH) from its liquidity pool and causing the token to lose over 99% of its value. The attacker claimed to be a white-hat actor, and most funds were returned minus a 5% bounty; however, approximately 40 ETH were separately stolen by a distinct black-hat actor and the failed audit by Verichains raises material security governance concerns.

avoid.net/gala28/100[WARNING]

Gala Games is a blockchain gaming platform founded in 2019 by Eric Schiermeyer and Wright Thurston whose GALA token has been at the center of two major controversies: a 2023 civil lawsuit alleging Thurston stole 8.6 billion GALA tokens (~$130M) from company wallets, and a separate May 2024 smart contract exploit in which an unauthorized minter minted 5 billion tokens worth approximately $200M. Both co-founders have filed competing civil suits alleging misappropriation of hundreds of millions of dollars, while Thurston also faces an unrelated SEC fraud action over a separate crypto mining venture.

avoid.net/indodax28/100[WARNING]

Indodax (formerly Bitcoin Indonesia) is Indonesia's largest licensed cryptocurrency exchange, founded in 2014 by Oscar Darmawan and William Sutanto and serving over 9.6 million users. In September 2024, the exchange suffered a major security breach attributed to North Korea's Lazarus Group, resulting in approximately $22–25 million in losses across multiple blockchains. The exchange pledged full reimbursement to affected users, resumed operations within roughly 80 hours, and has since undergone a leadership restructuring.

avoid.net/wxeta22/100[CRITICAL]

WXETA (Wrapped Xeta) is an ERC-20 token deployed on Ethereum using a Diamond (EIP-2535) upgradeable proxy architecture, associated with XETA Capital / XETA Genesis — a DeFi yield platform incorporated in Belize that claimed up to 20% monthly returns via high-frequency trading algorithms. The underlying XETA ecosystem is named as a co-defendant in a federal civil RICO lawsuit filed in January 2025 alleging tens of millions of dollars in investor fraud, and ZachXBT has flagged the entity. The platform ceased onboarding new members at end of 2023 and converted member positions into non-liquid NFTs, leaving the withdrawal status of the bulk of investor funds disputed.

avoid.net/banana-gun32/100[WARNING]

Banana Gun is a Telegram-based crypto trading bot launched in 2023 that allows users to snipe token launches on EVM chains and Solana. The project has experienced two major security incidents: a smart contract bug at token launch in September 2023 that caused the BANANA token to crash 99.7%, and a $3 million exploit in September 2024 in which attackers leveraged a Telegram message oracle vulnerability to drain 11 users. Separate, unresolved allegations from on-chain researchers claim the team arranged an exclusive order flow deal with block builder Titan that funneled millions of dollars in user bribe payments away from Ethereum validators.

avoid.net/bingx32/100[WARNING]

BingX is a Singapore-headquartered centralized cryptocurrency exchange founded in 2018 (originally as Bingbon), operating across 160+ countries with over 10 million reported users. In September 2024, the exchange suffered a confirmed hot wallet breach totaling approximately $52 million across at least seven blockchain networks, with on-chain forensics subsequently linking the attack to North Korea's Lazarus Group. The exchange pledged full user compensation from reserves and resumed withdrawals within days, but independently unverified regulatory claims and initial opacity around the breach raise ongoing due-diligence concerns.

avoid.net/berally32/100[WARNING]

Berally is a SocialFi and AI-agent social trading platform built on the Berachain blockchain, issuing the BRLY token via a public presale on Fjord Foundry in late 2024. In March 2025, the project suffered a significant security incident in which its deployer private key was alleged to have been leaked, resulting in all vesting tokens being dumped into its liquidity pool and approximately $90,000 drained from the pool. The BRLY token subsequently collapsed to roughly 99% below its all-time high, trading has effectively ceased, and community members have alleged the incident was an inside job, though this has not been formally substantiated.

avoid.net/moonwell-lending28/100[WARNING]

Moonwell is a decentralized, non-custodial lending and borrowing protocol deployed on Base, Optimism, Moonbeam, and Moonriver, operating as a fork of Compound v2. The protocol has suffered at least five distinct security incidents between 2022 and 2026, resulting in combined losses and bad debt exceeding $5 million, including repeated oracle failures, a flash loan exploit, a near-successful governance attack, and an AI-assisted smart contract misconfiguration. Despite multiple audits by Halborn and Code4rena, the pattern of recurring vulnerabilities and the removal of its Immunefi bug bounty program in early 2025 have raised significant security concerns.

avoid.net/stake-dao36/100[WARNING]

Stake DAO is a non-custodial DeFi protocol built around liquid staking, yield aggregation, and governance participation via veToken mechanics. The protocol has suffered three documented security incidents since 2023, the most severe of which — a May 2026 deployer private key compromise — enabled the minting of 5.4 trillion fraudulent vsdCRV tokens on Arbitrum, resulting in roughly $91,000 in realized losses despite a nominally catastrophic exposure. Repeated operational security failures across a two-year span, including a March 2026 oracle exploit draining $176,000 from its Votemarket product, indicate a pattern of infrastructure risk that audited smart contracts alone have not resolved.

avoid.net/evoq-finance38/100[WARNING]

Evoq Finance is a peer-to-peer lending optimizer built on BNB Chain that routes deposits through Venus Protocol to match suppliers and borrowers directly, aiming for improved capital efficiency. On September 10, 2025, the protocol suffered a critical security incident in which an attacker compromised the owner's private key, used the transferOwnership function to seize contract control, and upgraded the proxy contract to a malicious version, draining approximately $420,000 from both the protocol and user-approved accounts. Following the exploit, the protocol's total value locked collapsed to near zero and no verified public post-mortem or recovery plan has been identified. ZachXBT has flagged this entity.

avoid.net/kipseli38/100[WARNING]

Kipseli (also styled Kipseli Capital) is a proprietary trading firm and on-chain market-maker founded in early 2018, operating the Kipseli PropAMM on Base Mainnet. The protocol was listed among exploited platforms during the April 2026 wave of DeFi attacks, and the broader PropAMM category to which it belongs was the subject of a March 2026 empirical report by 0x documenting systematic quote-spoofing behavior that caused measurable trader harm. ZachXBT has flagged the entity. No public smart-contract audit or post-incident disclosure has been identified as of May 2026.

avoid.net/dforce-lending28/100[WARNING]

dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.

avoid.net/kucoin28/100[WARNING]

KuCoin is a global cryptocurrency exchange founded in 2017 that has accumulated one of the most serious regulatory and security records in the industry. The exchange suffered a $285 million hot-wallet hack in September 2020 attributed to North Korea's Lazarus Group, and in January 2025 pleaded guilty to operating an unlicensed money transmitting business in the United States, agreeing to pay over $297 million in fines and forfeitures and exit the US market for at least two years. On-chain investigator ZachXBT has publicly alleged that KuCoin continues to enable illicit fund flows by ignoring victim and law enforcement requests.

avoid.net/roll32/100[WARNING]

Roll (tryroll.com) is an Ethereum-based social token infrastructure platform that allows creators to mint, distribute, and manage branded personal tokens. On March 14, 2021, Roll suffered a critical security breach in which an attacker compromised the private keys of its hot wallet and liquidated approximately $5.7 million worth of social tokens across 42 different creator tokens, routing stolen ETH through Tornado Cash. Roll subsequently upgraded its security infrastructure via a Fireblocks MPC integration and raised a $10M Series A in September 2021, but the root cause of the private key compromise was never publicly confirmed.

avoid.net/nowswap22/100[CRITICAL]

NowSwap is an Ethereum-based automated market maker (AMM) decentralized exchange that launched in July 2021, positioning itself as the first DEX optimized for small-size trades under $3,000. On September 15, 2021, the protocol suffered a smart contract exploit resulting in the loss of approximately $1.07 million in USDT and WETH, caused by an incomplete code update that left an invalid K-value check in the pair contract. Following the exploit, the protocol's total value locked effectively collapsed to near zero and has remained dormant, with no evidence of remediation, audit, or resumed operations.

avoid.net/bent-finance28/100[WARNING]

Bent Finance is an Ethereum-based DeFi yield aggregator built on top of Curve Finance and Convex Finance, offering staking and liquidity pool boosting for the BENT token. In December 2021, the protocol suffered an insider exploit in which a rogue developer with access to the contract deployer private key inserted a backdoor into the cvxCRV and MIM pool contracts, resulting in the theft of approximately 440 ETH (~$1.75M). Stolen funds were ultimately returned by the attacker and reimbursed to users by late December 2021, but the incident caused a 73% BENT token price collapse and left the protocol with negligible TVL.

avoid.net/portal28/100[WARNING]

Portal (PORTAL) is a Web3 gaming platform and cross-chain token project that launched on Binance Launchpool on February 29, 2024, reaching an all-time high of approximately $4.41 before collapsing over 99% to below $0.01 by late 2025. The project has been flagged due to concerns including extreme token holder concentration, a low audited code coverage percentage, a pre-seed investor price roughly 30x below the listing price creating immediate sell pressure, active phishing and wallet-drainer campaigns impersonating the project, and a partially anonymous founding team. No formal regulatory action by the SEC, CFTC, or DOJ has been publicly confirmed as of May 2026.

avoid.net/meter30/100[WARNING]

Meter (meter.io) is a layer-1 blockchain protocol and cross-chain bridge infrastructure founded in 2018, operating a dual-token system (MTR and MTRG) with an EVM-compatible sidechain and a multi-chain bridge product called Meter Passport. On February 5, 2022, Meter Passport suffered a critical smart contract exploit that drained approximately $4.4 million in wETH and BNB, with cascading losses of approximately $2.1–3.3 million to the Hundred Finance lending protocol. The team committed to a PASS token reimbursement scheme but full recovery for affected users remained contingent on foundation revenues, and stolen funds were partially laundered through Tornado Cash.

avoid.net/crema-finance28/100[WARNING]

Crema Finance is a Solana-based concentrated liquidity market maker (CLMM) DEX protocol that launched in January 2022. On July 2, 2022, the protocol suffered a critical exploit in which an attacker used a fake tick account and flash loans to drain approximately $8.78 million from multiple liquidity pools. Following on-chain negotiations, the attacker returned roughly $7.1 million and retained approximately $1.68 million as an agreed white-hat bounty; Crema subsequently issued a CRM token compensation plan for affected users and submitted a revised codebase for re-audit by SlowMist before reopening.

avoid.net/midas-capital32/100[WARNING]

Midas Capital is a multichain DeFi isolated lending protocol that forked its codebase from Rari Capital's Fuse implementation. The protocol suffered two separate security exploits in 2023 totaling approximately $1.26 million in losses, with both incidents attributed to known smart contract vulnerabilities that had previously affected other Compound V2 forks. ZachXBT flagged the protocol, and the second exploit resulted in laundered funds routed through Tornado Cash.

avoid.net/paraspace-lending-v128/100[WARNING]

ParaSpace Lending V1 was an Ethereum-based cross-margin NFT and fungible token lending protocol launched in December 2022. In March 2023, a price manipulation exploit targeting the AutoCompoundApe contract nearly drained $5 million (2,909 ETH) from the protocol; blockchain security firm BlockSec intervened in a white-hat operation to recover the funds. In May 2023, a separate internal governance crisis erupted when over 19 team members accused CEO Yubo Ruan of misappropriating approximately 1,454.5 ETH (~$2.7M) from the recovered funds, allegations Ruan denied. The protocol subsequently rebranded through a merger with Parallel Finance, forming ParaX in August 2023, while the original V1 contracts were wound down and remain at minimal TVL as of 2026.

avoid.net/azukidao28/100[WARNING]

AzukiDAO is an informal decentralized autonomous organization formed in late June 2023 by a self-described group of 72 to 74 Azuki NFT holders in response to widespread community outrage over the Azuki Elementals NFT launch. Within days of its formation, AzukiDAO's BEAN governance token airdrop contract was exploited via a signature replay vulnerability, resulting in the theft of approximately 35 ETH ($68,000). On-chain investigator ZachXBT had previously flagged the Azuki project's founder Zagabond (Alex Xu) for alleged involvement in multiple prior abandoned NFT projects, and his findings were central to the community grievances that motivated AzukiDAO's creation.

avoid.net/arcadia-v122/100[CRITICAL]

Arcadia Finance v1 was a decentralized margin lending protocol deployed on Ethereum and Optimism that suffered a critical reentrancy exploit on July 10, 2023, resulting in the loss of approximately $459,030 across both chains. The attack exploited a missing reentrancy guard in the vault liquidation function combined with absent untrusted-input validation, allowing the attacker to bypass collateral health checks and drain darcWETH and darcUSDC vaults. The stolen funds on Optimism were largely laundered through Tornado Cash; the protocol subsequently paused all contracts and issued a bounty ultimatum to the attacker that went unanswered.

avoid.net/leetswap32/100[WARNING]

LeetSwap was a decentralized exchange (DEX) launched on Coinbase's Base Layer 2 network in mid-2023 and briefly held the position of the network's largest DEX by trading volume and total value locked. On August 1, 2023, shortly after Base's mainnet opened to all users, an attacker exploited a publicly exposed smart contract function to drain approximately 342 ETH (~$630,000) from multiple liquidity pools. The protocol halted trading, partially recovered funds through white-hat rescue operations, and has since operated at a fraction of its pre-exploit TVL, with no public audit ever confirmed prior to the incident.

avoid.net/earningfarm22/100[CRITICAL]

Earning.Farm is an Ethereum-based DeFi yield aggregator that deployed leveraged yield strategies on top of Aave. The protocol suffered two distinct security incidents — a flash loan attack in October 2022 that drained approximately 750 ETH (~$950,000), followed by a reentrancy exploit in August 2023 that resulted in an additional ~$528,000 loss. The protocol has been flagged by ZachXBT and has shown no evidence of recovery, compensation to users, or resumed operations following either incident.

avoid.net/woofi-swap28/100[WARNING]

WOOFi Swap is a decentralized exchange (DEX) built by WOO Network, operating on 12+ blockchain networks including Arbitrum, Avalanche, and Optimism, and using a proprietary synthetic Proactive Market Maker (sPMM) algorithm. On March 5, 2024, the protocol suffered a critical oracle manipulation exploit on Arbitrum in which an attacker used flash loans to manipulate WOO token pricing to near zero, stealing approximately $8.75 million; funds were not recovered. The parent platform WOO X also suffered a separate $14 million phishing-linked breach in July 2025 attributed to North Korean state-sponsored threat actors, compounding the ecosystem's security record.

avoid.net/dolomite32/100[WARNING]

Dolomite is a decentralized money market and trading protocol originally launched on Ethereum in 2019 and migrated to Arbitrum in 2022. The protocol suffered a $1.8 million exploit in March 2024 due to a reentrancy vulnerability in a legacy 2019 Ethereum contract. The platform drew significant controversy in 2026 when Trump-affiliated World Liberty Financial (WLFI) used 5 billion WLFI tokens as collateral to borrow $75 million on Dolomite — a platform co-founded by WLFI's own chief technology officer — driving USD1 pool utilization to 93% and trapping ordinary depositors.

avoid.net/alex28/100[WARNING]

ALEX (Automated Liquidity Exchange) is a decentralized finance protocol built on the Stacks blockchain, designed to bring DeFi capabilities to Bitcoin. The protocol has suffered two major security exploits: a $4.3 million hack in May 2024 attributed to North Korea's Lazarus Group via a private key compromise of its XLink bridge, and an $8.3 million exploit in June 2025 caused by a smart contract access control vulnerability. In both cases, ALEX Lab Foundation pledged full user reimbursement, though partial recovery of 2024 stolen funds remained ongoing as of mid-2025, and the native ALEX token has declined approximately 99.9% from its all-time high.

avoid.net/deltaprime22/100[CRITICAL]

DeltaPrime is a decentralized leveraged farming and lending protocol deployed on Arbitrum and Avalanche. The protocol suffered two major security exploits in 2024 — a $5.98 million private key compromise in September and a $4.8 million smart contract vulnerability in November — totaling over $10.7 million in losses. On-chain investigator ZachXBT alleged that DeltaPrime had previously employed North Korean IT workers with alleged ties to the DPRK-linked Lazarus Group, raising concerns about insider access as a contributing factor to the first exploit.

avoid.net/m2-exchange38/100[WARNING]

M2 Exchange is an Abu Dhabi-based centralized cryptocurrency exchange licensed by the ADGM FSRA that suffered a $13.7 million hot wallet breach on October 31, 2024, attributed to an access control vulnerability spanning Bitcoin, Ethereum, and Solana. The exchange claims to have covered all customer losses from company reserves within hours of the incident, though the lack of a public post-mortem and two CEO transitions within eighteen months raise unresolved transparency questions.

avoid.net/xt-exchange22/100[CRITICAL]

XT Exchange (XT.com), founded in 2018 and registered in Seychelles, is a centralized cryptocurrency exchange that has been flagged by multiple regulatory authorities — including the UK FCA, Dubai VARA, Thailand SEC, and the Seychelles FSA — for operating without proper licensing. The exchange suffered a $1.7 million hot wallet exploit in November 2024 due to a compromised private key, and has accumulated substantial user complaints alleging unjustified account freezing, asset seizure, and blocked withdrawals. Independent analysis has also raised concerns about inflated trading volumes and inadequate proof-of-reserves transparency.

avoid.net/gempad28/100[WARNING]

GemPad is a multi-chain no-code token launchpad and crowdfunding platform operating primarily on BNB Smart Chain, Ethereum, and Base, launched around 2021. On December 17, 2024, a reentrancy vulnerability in its LP Locker V2 smart contract was exploited across three chains, draining approximately $1.9–$2.2 million in locked liquidity from at least 27 dependent projects. Stolen funds were routed through Tornado Cash, and GemPad issued no public compensation plan for affected projects.

avoid.net/moby38/100[WARNING]

Moby Trade (moby.trade) is an on-chain options protocol built on Arbitrum and Berachain, launched in 2024 and backed by an Arbitrum Foundation grant. On January 8, 2025, the protocol suffered a critical security breach when a private key controlling proxy admin contracts was compromised, resulting in approximately $2.5 million in user funds being drained; roughly $1.5 million was subsequently recovered through an intervention by the SEAL911 security team. The protocol resumed operations after the incident and expanded to Berachain mainnet in February 2025, but the unrecovered ~$1 million in ETH and WBTC was routed through privacy mixers including Railgun and Tornado Cash, leaving those funds effectively unrecoverable.

avoid.net/orange-finance28/100[WARNING]

Orange Finance is an Arbitrum-based automated liquidity management protocol designed for LPDfi (liquidity provider DeFi), enabling users to earn swap fees and options premiums via concentrated AMM vaults. On January 8, 2025, the protocol suffered a critical security breach in which an attacker compromised the admin private key, exploited a misconfigured multi-signature wallet that required only a single signature to execute, and drained approximately $843,556 across all active vaults. The protocol was flagged by ZachXBT and has not resumed normal operations since the incident.

avoid.net/fourmeme38/100[WARNING]

four.meme is a permissionless meme token launchpad built on BNB Chain (BSC), operated under the Four (formerly BinaryX) ecosystem, that enables zero-KYC token creation with automatic bonding-curve-to-PancakeSwap liquidity migration. The platform suffered two confirmed smart contract exploits within six weeks in early 2025, losing a combined total of approximately $310,000 in user and pool funds. Repeat critical vulnerabilities, a phishing campaign that hijacked Google search results, and ecosystem-wide spam and token-pollution incidents raise substantial safety concerns for users.

avoid.net/zoth-zeusd28/100[WARNING]

Zoth is a Dubai-based real-world asset (RWA) restaking protocol and the issuer of ZeUSD, a CDP-style stablecoin backed by tokenized fixed-income assets including U.S. T-Bills and ETFs. In March 2025, the protocol suffered two separate security incidents within three weeks: a $285,000 logic-flaw exploit on March 1 and a critical $8.4–8.85 million admin key compromise on March 21, the latter resulting in the theft of 8.85 million USD0++ tokens. The stolen funds remain largely unrecovered as of mid-2025, with Zoth offering a $500,000 bounty and engaging Crystal Blockchain BV for forensic investigation.

avoid.net/arcadia-v228/100[WARNING]

Arcadia V2 is a non-custodial leverage farming and liquidity management protocol operating primarily on Base, developed by Belgium-based Arcadia Finance (founded 2021, backed by Coinbase Ventures). The protocol has suffered two serious security exploits: a July 2023 reentrancy attack on its V1 codebase draining approximately $455K across Ethereum and Optimism, and a more severe July 2025 arbitrary calldata exploit on V2's Rebalancer contract that drained approximately $3.6M on Base despite multiple prior audits. ZachXBT has flagged the protocol as a high-risk entity given this pattern of repeated critical security failures.

avoid.net/woo-x38/100[WARNING]

WOO X is a centralized cryptocurrency exchange founded in 2019 and incubated by Taiwanese quantitative trading firm Kronos Research, offering spot and derivatives trading with a focus on deep liquidity and low fees. The exchange has experienced two significant security events: a November 2023 liquidity crisis triggered by a $26 million hack of its primary market maker Kronos Research, and a July 2025 $14 million breach of nine user accounts attributed to a North Korean state-sponsored group (UNC4899/Lazarus) via phishing of a developer. Both incidents resulted in user compensation from company reserves, though the pattern of security failures and structural dependency on Kronos Research represent elevated counterparty and operational risk.

avoid.net/numa32/100[WARNING]

numa. (stylized with a period) is a non-custodial DeFi protocol on Arbitrum and Sonic that issues LST-backed synthetic assets (nuUSD, nuBTC, nuETH, nuGOLD) through a burn-and-mint tokenomics model. The protocol suffered two separate exploits in 2025 — a $506K price manipulation attack in April and a $313K collateral valuation exploit in August — resulting in cumulative losses exceeding $800K and a token price decline of approximately 99% from its peak. ZachXBT has flagged the entity in the context of trust intelligence monitoring.

avoid.net/texture28/100[WARNING]

Texture Finance is a Solana-based decentralized lending protocol founded in 2021 and backed by $5 million in venture funding from P2P Capital, Sino Global Capital, Wintermute, and Jane Street Capital. In July 2025, a missing ownership check in its USDC vault smart contract allowed an attacker to steal approximately $2.2 million in user funds; the protocol negotiated a 10% greyhat bounty and recovered roughly $1.98 million. User withdrawals remained disabled following the exploit, and a formal repayment timeline had not been published as of mid-2025.

avoid.net/shibarium28/100[WARNING]

Shibarium is a layer-2 blockchain built on Ethereum, launched in August 2023 as the scaling solution for the Shiba Inu (SHIB) ecosystem. The network has faced a series of significant incidents including a failed initial launch that trapped $1.7 million in bridged funds, a September 2025 flash loan exploit that drained approximately $4.1 million from its cross-chain bridge via validator key compromise, persistent rug pull activity on its DeFi layer, allegations of code plagiarism, and ongoing transparency concerns stemming from fully pseudonymous leadership. Shibarium initiated a novel NFT-based restitution program following the 2025 exploit but as of early 2026 the recovery path remained unresolved.

avoid.net/mars-perps28/100[WARNING]

Mars Perps was the perpetual futures product of Mars Protocol, deployed on the Neutron outpost of the Cosmos ecosystem. On December 14, 2025, the protocol suffered a mechanism design exploit that drained $973,079 USDC from lending depositors via skew-based same-block arbitrage. The exploit ultimately triggered a full protocol wind-down, which concluded in March 2026 with user funds returned and community channels closed.

avoid.net/blend-pools-v232/100[WARNING]

Blend Pools V2 is a modular, permissionless lending protocol built on the Stellar blockchain by Script3, launched as an upgrade to Blend V1 with additions including flash loans and a reduced backstop threshold. In February 2026, a community-managed pool built on top of the protocol (YieldBlox DAO Pool) suffered a $10.8 million oracle manipulation exploit; Script3 stated the core V2 contracts were not at fault, attributing the incident to pool-operator misconfiguration of the Reflector VWAP oracle.

avoid.net/panoptic-v1137/100[WARNING]

Panoptic V1.1 is a permissionless, oracle-free perpetual options protocol built on Uniswap V3 liquidity positions, developed by Panoptic Labs and incubated by Advanced Blockchain AG. On August 25, 2025, a Cantina researcher disclosed a critical position-spoofing vulnerability rooted in the protocol's XOR-based fingerprinting system, placing approximately $4–5 million in user funds at risk. A coordinated whitehat rescue secured over 98% of remaining at-risk funds, and ZachXBT flagged the incident, contributing to reduced community trust in the V1.1 deployment.

avoid.net/us-permissionless-dollar28/100[WARNING]

US Permissionless Dollar (USPD) is a decentralized, over-collateralized stablecoin protocol built on Ethereum by Permissionless Technologies, the team behind the Morpher trading platform. In December 2025, the protocol suffered a critical exploit via a clandestine proxy deployment attack — later dubbed CPIMP — that had silently compromised admin privileges since September 2025, resulting in approximately $1 million in losses. The project has undergone audits by Nethermind and Resonance Security but the exploit bypassed audited code by targeting the deployment layer, raising unresolved questions about operational security and the viability of the planned V2 relaunch.

avoid.net/mscst22/100[CRITICAL]

MSCST is a BSC-based DeFi auto-staking token associated with MSC Protocol (MetaSuperCoin), which advertised an implausible fixed APY of 38,585% over 400 days with no public team or audits. On December 29, 2025, a flash loan attacker exploited a missing access control vulnerability in the protocol's releaseReward() function, draining approximately $130,000 (149 BNB) from the GPC/WBNB PancakeSwap liquidity pool. The project has been flagged by ZachXBT and received no recovery response from an identifiable development team.

avoid.net/saga32/100[WARNING]

Saga is a Layer 1 blockchain protocol built on Cosmos that allows developers to deploy parallelized, VM-agnostic dedicated chains called Chainlets, with a primary focus on gaming applications. The SAGA token launched on April 9, 2024 at an all-time high of approximately $7.53, but had declined roughly 99% from that peak by late 2025. In January 2026, the protocol's SagaEVM chainlet suffered a $7 million smart contract exploit that drained bridged assets, caused the Saga Dollar stablecoin to depeg, and led to a 55% TVL crash.

avoid.net/solvbtc38/100[WARNING]

SolvBTC is the flagship wrapped Bitcoin product of Solv Protocol, designed to represent Bitcoin in DeFi systems across multiple chains. In March 2026, the BRO vault component of the protocol suffered a $2.7 million exploit due to a double-mint logic flaw in the BitcoinReserveOffering smart contract. Separately, in January 2025, the protocol faced credible public allegations of TVL manipulation prior to its SOLV token launch.

avoid.net/harvest-finance22/100[CRITICAL]

Harvest Finance is a decentralized yield-aggregation protocol (token: FARM) that suffered a landmark $33.8 million flash loan-based price manipulation attack on October 26, 2020, one of the largest DeFi exploits of that year. Pre-attack, the protocol held over $1 billion in TVL while being governed by a single anonymous admin key—a concentration of power flagged by multiple security auditors and researchers. The protocol continues to operate with substantially reduced TVL (~$12 million as of 2025), though the stolen funds were never recovered and the attacker was never publicly identified or charged.

avoid.net/chainswap22/100[CRITICAL]

ChainSwap was a cross-chain token bridge protocol connecting Ethereum, Binance Smart Chain, and Huobi Eco Chain, which raised $3 million in April 2021 from investors including Alameda Research and NGC Ventures. The platform suffered two separate smart contract exploits in July 2021 — the first on July 2 draining approximately $800,000, and the second on July 10-11 draining approximately $4.4 million (with some sources citing up to $8 million across affected partner token markets) — collectively devastating more than 20 partner projects. Following the exploits, ChainSwap offered partial compensation via token airdrops; the project's native CHAINS/ASAP token collapsed over 96% from its all-time high and the protocol has since become largely inactive under its original identity, with the @ChainSwapERC Twitter handle rebranding to ChainHub in early 2026.

avoid.net/vulcan-forged28/100[WARNING]

Vulcan Forged is a UK-based blockchain gaming studio and NFT marketplace operating on Polygon and its own Elysium Layer-1 blockchain, best known for VulcanVerse and its native PYR token. In December 2021 the platform suffered one of the largest gaming-sector hacks on record: an attacker exploited Vulcan Forged's servers to extract private keys from 96 semi-custodial wallets, stealing approximately 4.5 million PYR tokens then valued at roughly $140 million. The platform subsequently refunded affected users from its treasury and pledged to migrate to non-custodial wallets, but the incident exposed fundamental centralization and custodial risks in its architecture.

avoid.net/moola-market28/100[WARNING]

Moola Market is a decentralized lending protocol built on the Celo blockchain, founded in 2020 by Patrick Baron and backed by Polychain Capital. In October 2022, the protocol suffered a price manipulation exploit draining approximately $9.1 million, making it one of the largest DeFi incidents on Celo; over 93% of funds were returned by the attacker within hours in exchange for a roughly $500,000 bounty. The protocol subsequently relaunched with reduced collateral thresholds, but its TVL and MOO token value have declined sharply since the incident.

avoid.net/rubic28/100[WARNING]

Rubic is a cross-chain DEX aggregator founded in 2020 by Vladimir Tikhomirov and Alexandra Korneva, supporting swaps across 90+ blockchains. The protocol suffered two significant security incidents within two months in late 2022: a private key compromise in November that drained approximately $1.2 million in RBC tokens, followed by a smart contract exploit on December 25, 2022 that stole roughly $1.4 million in user USDC. Both events caused severe token price collapses, though the platform subsequently implemented new security architecture and remained operational into 2025.

avoid.net/kronos-research28/100[WARNING]

Kronos Research is a Taipei-based cryptocurrency quantitative trading firm and market maker founded in 2018 by Mark Pimentel and Jack Tan. The firm experienced two serious security incidents within months of each other in 2023: an insider sabotage case in which two disgruntled engineers tampered with trading code causing $1.4 million in losses, and an external hack in November 2023 where compromised API keys led to the theft of approximately $25–26 million. The November hack cascaded onto WOO X, an exchange Kronos incubated and served as primary liquidity provider, causing a temporary trading halt and liquidations for 227 users.

avoid.net/minterest22/100[CRITICAL]

Minterest (formerly using the MNT token, later rebranded to MINTY) was a cross-chain DeFi lending and borrowing protocol founded by Josh Rogers and incorporated as Minterest Labs OÜ in Estonia. The protocol suffered a $1.4 million reentrancy exploit on July 14, 2024 — in a market that went live without a completed security audit — and subsequently announced the sunsetting of all operations in November 2025, explicitly stating that hack victims would receive no refund or token compensation as part of the wind-down.

avoid.net/unilend-v238/100[WARNING]

UniLend V2 is a permissionless DeFi lending and borrowing protocol deployed on Ethereum mainnet in February 2024, designed to support all ERC-20 tokens via isolated dual-asset pools. On January 12, 2025, the protocol suffered a smart contract exploit that drained approximately $197,000 from its stETH pool due to a logic flaw in health factor calculations during the asset redemption process. Despite having been audited by PeckShield and SlowMist prior to launch, the exploited vulnerability was not caught or fully remediated, and as of the last available reporting the attacker's 20% bounty offer had not yielded a fund recovery.

avoid.net/resupply32/100[WARNING]

Resupply (resupply.fi / resupply.finance) is a decentralized stablecoin lending protocol built by contributors from Convex Finance and Yearn Finance, succeeding the hacked Prisma Finance protocol after a March 2024 governance vote. The protocol suffered a critical $9.6 million exploit on June 26, 2025, caused by a donation-attack vulnerability in a newly deployed ERC-4626 vault, with stolen funds laundered through Tornado Cash. The team's post-exploit governance response generated significant community controversy, including alleged silencing of critics and a disputed insurance-pool burn proposal, before the bad debt was eventually fully repaid in August 2025.

avoid.net/crosscurve28/100[WARNING]

CrossCurve (formerly EYWA) is a cross-chain DeFi liquidity protocol built in partnership with Curve Finance, backed by $8.5 million in funding including a seed round led by Curve founder Michael Egorov. On February 1-2, 2026, the protocol suffered a critical smart contract exploit in its ReceiverAxelar bridge contract, resulting in an estimated $3 million in user losses across multiple chains; confirmed liquid losses were approximately $1.44 million after exchange freezes limited attacker liquidation. A subsequent Hashlock audit of separate OFT messaging contracts in March 2026 found and resolved additional vulnerabilities, and the protocol has not publicly confirmed full fund recovery from the February exploit.

avoid.net/volo-vault38/100[WARNING]

Volo Vault is a yield-generating vault product operated by Volo Protocol, a BTCFi and liquid staking platform built on the Sui blockchain. In April 2026, three of its vaults were exploited via a compromised admin private key, resulting in approximately $3.5 million in losses across WBTC, XAUm, and USDC holdings. The team committed to absorbing all user losses and ultimately recovered approximately 90% of the stolen funds through coordination with the Sui Foundation, ZachXBT, and ecosystem partners.

avoid.net/revert-lend33/100[WARNING]

Revert Lend is a decentralized lending protocol built by Revert Finance that allows Uniswap v3 liquidity providers to use their LP positions as collateral to borrow ERC-20 tokens. The protocol has experienced two confirmed security incidents: a 2023 exploit of the V3Utils contract resulting in approximately $30,000 in losses, and a January 2026 protocol logic exploit on Base chain resulting in approximately $50,000 in losses. The protocol has undergone multiple audits but the recurrence of exploits raises questions about smart contract security practices.

avoid.net/slope-wallet28/100[WARNING]

Slope Wallet (Slope Finance) was a Solana-based mobile cryptocurrency wallet that suffered a catastrophic security breach on August 2, 2022, in which over 9,200 wallets were drained of approximately $4–8 million in assets due to the app transmitting users' unencrypted seed phrases to a third-party telemetry service (Sentry). The root cause was a severe security misconfiguration by Slope Finance, in which the mobile application logged plaintext private key material without proper scrubbing. No formal victim compensation was established, the team declined to publicly accept responsibility, and founder Leal Cheung subsequently launched a new project (zkME) without resolution for affected users.

avoid.net/steadefi35/100[WARNING]

Steadefi is a decentralized leveraged yield farming protocol operating on Arbitrum and Avalanche. On August 7, 2023, an attacker exploited a compromised deployer private key to drain approximately $1.14 million from the protocol's lending vaults across both chains. The protocol subsequently relaunched with enhanced security measures and issued a token-based compensation plan for affected users, though roughly 70% of stolen funds were never recovered.

avoid.net/htx28/100[WARNING]

HTX (formerly Huobi Global) is one of the world's largest cryptocurrency exchanges, rebranded in September 2023 following the de facto acquisition of Huobi by interests linked to Justin Sun in late 2022. The exchange has suffered at least three significant security incidents totaling over $130 million in losses since September 2023, and in May 2026 was sanctioned by the UK government for alleged facilitation of Russian sanctions evasion — the first such crypto-exchange designation under the UK Russia sanctions framework. HTX also faces FCA legal proceedings over illegal financial promotions to UK consumers, has withdrawn its Hong Kong licensing applications twice, and has been publicly criticized for opaque reserve practices.

avoid.net/huobi28/100[WARNING]

Huobi, rebranded to HTX in September 2023, is a major centralized cryptocurrency exchange founded in 2013 that came under the de facto control of Tron founder Justin Sun in late 2022. The exchange has suffered three significant security incidents since September 2023, faces extensive regulatory non-compliance across multiple jurisdictions, and its proof-of-reserves methodology has been subject to credible allegations of double-counting and asset manipulation by investigative outlets.

avoid.net/cardex28/100[WARNING]

Cardex is an on-chain fantasy trading card game that launched on the Ethereum layer-2 network Abstract in February 2025, offering tokenized digital versions of collectible trading cards for competition in online tournaments. Within one week of launch, a critical operational security failure — the inadvertent exposure of a shared session signer private key on the application's frontend — allowed an attacker to drain approximately $400,000–$470,000 in ETH from roughly 9,000 user wallets over a seven-hour period. The project has been flagged by ZachXBT; user accusations of a rug pull circulated on Telegram, though Abstract core contributors attributed the incident to mishandled credentials rather than intentional fraud. No confirmed restitution fund or formal accountability measure had been publicly disclosed as of the most recent reporting.

avoid.net/tenderize-v237/100[WARNING]

Tenderize V2 is a DeFi liquid staking protocol launched on January 29, 2024, enabling users to mint validator-specific liquid staked tokens (tTokens) for assets including MATIC, LPT, and GRT across Ethereum, Arbitrum, and Sei Network. The protocol suffered a protocol logic exploit on April 7, 2025, resulting in a loss of approximately $10,850 via a proxy upgrade skim technique on Ethereum; the incident was relatively small in dollar terms but raised concerns about smart contract integrity. ZachXBT has flagged this entity, and while the protocol holds multiple security audits including a Hacken audit scoring 9.8/10 and a Halborn audit, its current TVL of approximately $495,000 reflects limited adoption relative to the broader liquid staking market.

avoid.net/griffinai28/100[WARNING]

Griffin AI is a Web3 no-code AI agent builder on BNB Chain that launched its native GAIN token on Binance Alpha on September 24, 2025. Within hours of launch, an attacker exploited a misconfigured LayerZero cross-chain peer to mint 5 billion unauthorized GAIN tokens and dump approximately $3 million worth into the market, crashing the token 87-90% and erasing roughly $36 million in market capitalization. The team subsequently enacted a token migration, a $2.5 million recovery fund, and a re-launch on October 6, 2025, though GAIN continues to trade approximately 95% below its all-time high.

avoid.net/asterafi38/100[WARNING]

Astera.fi is a DeFi credit facility and lending protocol operating on Ethereum's Linea Layer-2 network, issuing the asUSD stablecoin through both over- and under-collateralized mechanisms. On October 9, 2025, the protocol suffered a flash loan exploit via a liquidity index inflation attack that drained approximately $821,856–$880,000 across three lending pools. The protocol has been flagged by ZachXBT and market data indicates near-zero trading activity for asUSD, with the token appearing to have effectively ceased normal operation post-exploit.

avoid.net/ribbon28/100[WARNING]

Ribbon Finance is an Ethereum-based DeFi protocol that pioneered Theta Vaults (DeFi Options Vaults) for structured yield products, later expanding into the Aevo derivatives exchange. The protocol has experienced multiple serious incidents including a $2.7 million oracle exploit in December 2025 whose recovery plan drew widespread community condemnation, a 2021 Sybil attack on its token airdrop by a connected venture capital firm, and a DNS hijacking in 2022. Its native token RBN lost approximately 90% of its value in 2025 alone and sits more than 99% below its all-time high.

avoid.net/subquery-network38/100[WARNING]

SubQuery Network is a Web3 data indexing protocol originally built for the Polkadot ecosystem, founded by Sam Zou and James Bayly out of New Zealand-based OnFinality. The project raised $10.8M in seed and Series A funding, launched its mainnet and SQT token in February 2024, and suffered a significant smart-contract exploit on April 12, 2026 in which a missing access-control modifier allowed an attacker to drain approximately 382 million SQT tokens (~$134,000 USD) from staker and delegator wallets across five transactions. ZachXBT flagged the entity in connection with this incident; the team published a full disclosure report and executed on-chain compensation for all affected wallets.

avoid.net/nemo-yield-trading28/100[WARNING]

Nemo Protocol is a Sui-based DeFi yield trading platform that suffered a $2.6 million exploit on September 7, 2025, caused by an unnamed developer who deployed unaudited code to mainnet while bypassing internal review processes. A security auditor had flagged a related vulnerability 27 days before the attack, which the team acknowledged it failed to address in time. The protocol's TVL has since collapsed to zero and it has been flagged as high-risk by trust intelligence sources.

avoid.net/kame-aggregator32/100[WARNING]

Kame Aggregator is a decentralized exchange (DEX) aggregator protocol built on the Sei blockchain, launched in late May 2025, designed to route token swaps across multiple liquidity sources for optimal pricing. On September 13, 2025, the protocol suffered a critical smart contract exploit in which approximately $1.325 million was drained from 830 user wallets via an arbitrary external call vulnerability in its swap() function. The primary exploiter returned approximately $946,000 after negotiations, while secondary exploiters retained approximately $357,000; the team initiated a compensation program that reached over $1 million USDC in distributions by November 2025.

avoid.net/hyperdrive-hl35/100[WARNING]

Hyperdrive HL (formerly Ambit Finance) is a stablecoin lending and liquid-staking protocol deployed on Hyperliquid EVM, which raised a $6 million Series A in May 2025 led by Hack VC and Arrington Capital. On September 27, 2025, an attacker exploited an arbitrary-call vulnerability in the protocol's router contract, draining approximately $782,000 in USDT0 and thBILL tokens across two markets. The team paused operations, patched the vulnerability, and compensated affected users before resuming, though the incident occurred within a broader wave of security breaches across the Hyperliquid ecosystem.

avoid.net/makina35/100[WARNING]

Makina Finance is a non-custodial DeFi execution engine that launched in late 2025 on Ethereum, enabling automated yield strategies via tokenized vaults called Machines. On January 20, 2026, the protocol suffered a $4.13 million oracle manipulation exploit targeting its DUSD/USDC Curve stableswap pool, despite having completed six independent security audits in the months prior. The team recovered approximately $3.65 million (89% of user losses) within one week and resumed operations on January 26, 2026, though a residual 11% shortfall remained subject to a revenue-share restitution plan.

avoid.net/mona38/100[WARNING]

MONA is the native ERC-20 governance and utility token of DIGITALAX, a Web3 digital fashion NFT platform founded by Emma-Jane MacKinnon-Lee and launched in November 2020. The token reached an all-time high of approximately $5,980 in November 2021 before collapsing more than 99% to trade below $50, with a total market capitalisation under $500,000 as of mid-2026. Third-party security assessors flag critically low liquidity, extreme holder concentration, a below-average security score, and a near-total absence of trading activity, collectively indicating a project in terminal decline.

avoid.net/ola-finance28/100[WARNING]

Ola Finance is a multi-chain decentralized lending protocol offering a 'lending-as-a-service' platform that allows third parties to deploy isolated Compound-style lending pools across multiple blockchains. On March 31, 2022, the protocol's deployment on the Fuse Network was exploited via a reentrancy vulnerability in ERC677 token logic, resulting in approximately $4.67 million in stolen assets. The attacker used Tornado Cash to obscure initial funding, laundered proceeds through Ethereum and BNB Chain wallets, and was never publicly identified; a partial compensation plan was offered but fell materially short of full victim restitution.

avoid.net/mm-finance-cronos28/100[WARNING]

MM Finance (also known as Mad Meerkat Finance) was the largest decentralized exchange on the Cronos blockchain. On May 4, 2022, the protocol suffered a frontend compromise in which an attacker injected a malicious router contract address, redirecting approximately $2 million in user funds to the attacker's wallet over roughly three hours. The stolen funds were laundered via Tornado Cash and routed through OKX; the team pledged reimbursement via trading fee airdrops, though full recovery of stolen assets was not confirmed. The MMF token subsequently lost approximately 99.9% of its value from its April 2022 all-time high.

avoid.net/sharedstake28/100[WARNING]

SharedStake is an Ethereum liquid staking protocol launched in January 2021 that allowed users to deposit ETH in exchange for the vETH2 liquid staking token. In June 2021, a co-founder using the pseudonym 'Kairos' exploited a critical timelock bypass vulnerability in the protocol's vesting contracts — a bug that had been disclosed to the team two months prior — draining approximately $128,000 from liquidity providers and sending 100 ETH through Tornado Cash. The protocol subsequently relaunched as SharedDeposit v2 under remaining team members, though the SGT governance token never recovered.

avoid.net/onyx-protocol22/100[CRITICAL]

Onyx Protocol is a DeFi lending protocol forked from Compound Finance v2, operating on Ethereum and issuing the XCN (Onyxcoin) token. The protocol suffered two major exploits in under twelve months — $2.1 million in October/November 2023 and $3.8 million in September 2024 — both stemming from the same known precision vulnerability in the Compound v2 codebase that the team had been warned about by auditor CertiK in February 2023 and chose not to remediate. Following the second hack the Ethereum-based lending market was shut down and the protocol relaunched as Onyx Core.

avoid.net/geniusai28/100[WARNING]

GNUS.AI (Genius Ventures, Inc.) is a decentralized AI computing platform that issues the GNUS token across Ethereum, Polygon, and Fantom networks. On May 5, 2024, the project suffered a $1.27 million exploit in which an attacker leveraged a Discord breach to steal private key material, mint 100 million counterfeit GNUS tokens, and sell them into live liquidity pools — causing the token price to collapse. The token has traded 98-99% below its all-time high and ZachXBT has flagged the entity as a concern in the crypto community.

avoid.net/vestra-dao32/100[WARNING]

Vestra DAO is an Ethereum-based DeFi and SocialFi protocol operating the VSTR token, launched in late 2024. On December 4, 2024, the protocol suffered a critical smart contract exploit in its staking contract that drained approximately $480,000–$500,000 worth of VSTR tokens — an attack that occurred less than one month after the token began trading. Stolen funds were laundered through Tornado Cash, the token price collapsed by roughly 50%, and the project's ability to fully compensate affected users remains unresolved.

avoid.net/fegex22/100[CRITICAL]

FEGex is a decentralized exchange (DEX) and DeFi launchpad built around the FEG (Feed Every Gorilla) token ecosystem, operating on Ethereum and BNB Chain. The protocol has suffered three separate security exploits between 2022 and 2024, resulting in cumulative losses exceeding $3.6 million and a near-total collapse of token value following the most recent incident. The team operates anonymously and the protocol has demonstrated a repeated inability to prevent critical smart contract vulnerabilities despite multiple third-party audits.

avoid.net/sir38/100[WARNING]

SIR (Synthetics Implemented Right), operating as SIR.trading, is an Ethereum-based DeFi protocol offering non-liquidating leveraged tokens and synthetic assets. On March 30, 2025, just 39 days after its February 20 mainnet launch, the protocol's Vault contract was completely drained of its entire $355,000 TVL through an exploit targeting a novel misuse of Ethereum's transient storage (EIP-1153) introduced in the Dencun upgrade. The attacker laundered proceeds through Railgun; the founder publicly pleaded for a partial return of funds; the protocol subsequently relaunched after completing four additional security audits.

avoid.net/polycule38/100[WARNING]

Polycule (ticker: PCULE) is a Telegram-based trading bot built for the Polymarket prediction market platform, operating on Solana and Polygon. Launched in May 2025 by a founder identified as 'krish' and backed by a $560,000 seed from AllianceDAO, the project gained significant traction before its bot was compromised in January 2026, resulting in approximately $230,000 in user funds stolen. Extended team silence following the incident generated widespread rug pull allegations, and ZachXBT has flagged the entity in connection with these concerns.

avoid.net/resolv22/100[CRITICAL]

Resolv is a DeFi protocol issuing USR, a delta-neutral stablecoin backed by ETH with perpetual futures hedging, developed by Resolv Labs. On March 22, 2026, the protocol suffered a critical exploit in which an attacker compromised Resolv's AWS key management infrastructure to mint 80 million unbacked USR tokens, extracting approximately $23–25 million in ETH and triggering a severe stablecoin depeg. The protocol remains paused as of May 2026 while recovery and infrastructure remediation are underway.

avoid.net/venus-core-pool28/100[WARNING]

Venus Core Pool is the primary lending market of Venus Protocol, the largest decentralized money market on BNB Chain. The protocol has accumulated over $112 million in cumulative losses across at least five separate security incidents since 2021, including oracle manipulation, a phishing attack draining $27 million from the Core Pool itself in September 2025, and a donation-attack exploit in March 2026 that left $2.15 million in unrecoverable bad debt. A critical vulnerability flagged during a 2023 Code4rena security audit was dismissed by the development team and subsequently exploited twice.

avoid.net/aperture-lm28/100[WARNING]

Aperture LM (also marketed as Aperture Finance) is a multi-chain DeFi liquidity management protocol that launched in 2022 and raised $12 million at a reported $250 million valuation. On January 25, 2026, the protocol suffered a critical smart contract exploit due to insufficient input validation in its V3 and V4 helper modules, resulting in $3.67 million stolen from Aperture directly and contributing to a combined ~$17 million loss across a coordinated attack that also hit SwapNet. Stolen funds were laundered through Tornado Cash, no public compensation plan for affected users has been confirmed, and the protocol's closed-source contract architecture was identified as a compounding risk factor that hindered independent security review.

avoid.net/giddy25/100[CRITICAL]

Giddy (also branded DefiQ, Inc.) was a Draper, Utah-based self-custody DeFi wallet and yield-farming platform that launched its GDDY token on the Polygon network in April 2022. The project raised over $15 million from VC investors including Pelion Venture Partners, but has since shut down — leaving the GIDDY token trading more than 99% below its all-time high of approximately $0.35 in May 2022. ZachXBT has flagged the entity as a concern in the crypto trust-intelligence space, and community reviews allege that team members sold tokens prior to the app's public launch and that advertised staking yields were never delivered.

avoid.net/sovryn38/100[WARNING]

Sovryn is a Bitcoin-backed decentralized finance protocol built on the Rootstock (RSK) sidechain, offering lending, borrowing, margin trading, and AMM services with its native SOV governance token. The protocol suffered a confirmed $1.1 million price manipulation exploit in October 2022 targeting its legacy lending pools, with approximately half of funds recovered via developer intervention. A separate critical smart contract vulnerability was disclosed via bug bounty in March 2021 but was not exploited. ZachXBT has flagged the entity; no detailed public post from ZachXBT specifically detailing Sovryn allegations was independently located at time of investigation.

avoid.net/orion-pools28/100[WARNING]

Orion Pools is the automated market maker (AMM) and liquidity pool component of Orion Protocol, a DeFi liquidity aggregator founded in 2018 by Alexey Koloskov. On February 2, 2023, the protocol suffered a $3 million reentrancy exploit targeting its core exchange contract across Ethereum and BNB Chain, with stolen funds subsequently laundered through Tornado Cash. The project later rebranded to Lumia in late 2024, pivoting from a liquidity aggregator to a Layer 2 blockchain.

avoid.net/sirio-finance28/100[WARNING]

Sirio Finance is a DeFAI lending and borrowing protocol built on the Hedera blockchain that launched on January 27, 2025 and suffered a flashloan exploit on February 1, 2025, resulting in an estimated $2–3 million in stolen funds. The exploit occurred within five days of mainnet launch, with post-incident analysis indicating the vulnerability was introduced when the team followed an audit directive from QuillAudits to remove a reentrancy guard from the protocol's smart contracts. The protocol's TVL collapsed to near zero following the hack, and no confirmed recovery of stolen funds or full user compensation has been publicly documented.

avoid.net/hegicold-contract30/100[WARNING]

Hegic is an anonymous-founded, Ethereum-based decentralized options trading protocol originally launched in April 2020. The original (v1) smart contract suffered a critical code defect within hours of mainnet deployment that permanently locked user funds, compounded by misrepresentation of the pre-launch security review. A separate deprecated contract from January 2022 was additionally exploited in February 2025, draining approximately $80,000 in WBTC. While affected users were reimbursed out of team funds in both incidents, the underlying contracts remain permanently compromised.

avoid.net/kiloex38/100[WARNING]

KiloEx is a decentralized perpetual futures exchange (DEX) backed by YZi Labs (formerly Binance Labs), deployed across opBNB, Base, BNB Chain, Taiko, and other networks. In April 2025, the platform suffered a $7.5–8.44 million oracle price manipulation exploit caused by an access control vulnerability in its TrustedForwarder contract; the attacker subsequently returned all stolen funds within 3.5 days after accepting a $750,000 white-hat bounty. The platform relaunched on April 24, 2025 after a partial security audit, with a full comprehensive audit still pending at that time.

avoid.net/odinfun22/100[CRITICAL]

Odin.Fun (ODIN•FUN) is a Bitcoin-based meme coin launchpad and automated market maker launched in January 2025 by Bioniq co-founder Bob Bodily, designed as a Pump.fun analogue for Bitcoin Runes tokens. The platform has suffered at least four confirmed security incidents within its first year of operation, including a critical $7 million (58.2 BTC) AMM liquidity manipulation exploit in August 2025 that left the treasury insolvent and unable to fully compensate affected users. As of the latest available reporting (August–September 2025), the platform remained halted pending security audits, with no committed reopening timeline.

avoid.net/goonfi32/100[WARNING]

GoonFi is a proprietary automated market maker (Prop AMM) operating on Solana, launched in June 2025 with no public team, no frontend, and no published smart-contract audit. On March 28, 2026, a protocol logic vulnerability was exploited via mispricing arbitrage, resulting in approximately $254,000 in losses with no recovery reported. The protocol has been flagged by ZachXBT and is cited by researchers as representative of a broader Solana centralization concern, wherein anonymous, closed-source market makers capture an outsized share of DEX volume with minimal accountability.

avoid.net/pumpdotfun27/100[WARNING]

pump.fun is a Solana-based token launchpad, operated by UK-registered Baton Corporation Ltd, that lets anyone create a tradable token in seconds via an automated bonding curve and has generated hundreds of millions of dollars in fees since its January 2024 launch. The platform has been the subject of a UK Financial Conduct Authority warning, a suspended and later reinstated livestream feature that hosted graphic and abusive content, a $1.9-2 million insider exploit by a former contractor who was later criminally convicted, and consolidated U.S. federal class-action and RICO litigation alleging pump.fun and infrastructure partners ran a rigged 'casino' extracting billions of dollars from retail traders. None of the core securities or racketeering allegations against pump.fun have been adjudicated; independent research also indicates the overwhelming majority of tokens launched on the platform end as failed or abandoned projects.

avoid.net/tornado-cash28/100[WARNING]

Tornado Cash is an open-source, non-custodial cryptocurrency mixing protocol on Ethereum, launched in 2019, that obscures the on-chain link between deposit and withdrawal addresses. The U.S. Treasury sanctioned the protocol in August 2022 over its alleged use by the North Korea-linked Lazarus Group and other illicit actors to launder billions of dollars; those sanctions were struck down by the Fifth Circuit in November 2024 and formally lifted by OFAC in March 2025. Separately, co-founder Alexey Pertsev was convicted of money laundering in the Netherlands in 2024 (appeal pending), and co-founder Roman Storm was convicted in August 2025 of one count of conspiring to operate an unlicensed money-transmitting business while a New York jury deadlocked on more serious money-laundering and sanctions-violation charges that remain unresolved pending post-trial motions and a possible retrial.

avoid.net/coinex32/100[WARNING]

CoinEx is a centralized cryptocurrency exchange that suffered a major hot wallet breach on September 12, 2023, with losses estimated between $54 million and $70 million across multiple blockchains. On-chain investigators ZachXBT and Elliptic attributed the attack to the Lazarus Group (TraderTraitor), a North Korean state-sponsored threat actor, based on wallet address overlap with the contemporaneous Stake.com hack. Stolen proceeds were subsequently laundered in part through the Sinbad Bitcoin mixer, which was sanctioned by the U.S. Treasury's OFAC on November 29, 2023.

avoid.net/strike34/100[WARNING]

Strike (operated by Zap Solutions, Inc.) is a Bitcoin and Lightning Network payments application founded by Jack Mallers. The platform has faced scrutiny over a 2023 data breach it initially denied, the use of Tether (USDT) as a backing for purported USD cash balances for non-US users, and a 2026 proposed merger with Twenty One Capital (XXI) that raises serious conflict-of-interest concerns given Mallers serves as CEO of both entities.