Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit

A Bored Ape-style illustration of an ape with blue skin, brown shoulder-length hair, a grimace with red lipstick, bloodshot heavy-lidded eyes, a skull-print scarf, and a nurse's topAll my Desperate ApeWives gone :( (attribution)
Exploiters took advantage of a legacy approvals bug in an old payment processor called Limit Break, which the platform had stopped using in late 2024. The bug affected listings on Magic Eden's EVM marketplace, which the company had shut down earlier this year. The attackers were able to steal numerous NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate Apewives. Attackers also subsequently stole 660 wETH (~$1.78 million).

A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.

Payy Network bridge fully drained of $1.8 million

The Payy Network, a stablecoin infrastructure company, disclosed that a bridge contract had been fully drained of funds, netting attackers $1.8 million. They later stated that the theft was "NOT a compromised key, social engineering or exploit of our off-chain infrastructure," but has not disclosed what it was. They also announced that the stolen funds were "users' non-custodial deposits to Payy Network / Payy Wallet", which is somewhat of an oxymoron.

Payy Network has halted all activity following the attack.

Single attacker steals $2.25 million from three crypto projects in the "Artificial Superintelligence Alliance"

One attacker stole crypto tokens from three cryptocurrency projects that are part of what's called the "Artificial Superintelligence Alliance" — a group of crypto projects "dedicated to decentralized Artificial General Intelligence". The attack occurred within just one day, netting around $2.25 million in actual profits, though the stolen tokens were notionally priced considerably higher.

Most of the profits came from stolen FET tokens, which are linked to Fetch.ai. The attacker was also able to perform unauthorized mints of various tokens, crashing their prices but earning the attacker little in the way of profits. Security researchers noticed that attackers stole assets from sixteen wallets spanning the three companies, suggesting they had significant access to all three companies' systems. Almost $290,000 was taken from a contract used for company payroll.

Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

Term Finance loses $8.5 million to governance attack

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

BounceBit exploited for $3 million, announces shutdown and migration

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

Coinsbuy exploited for $8 milllion

The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.

Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.

Proof of Attendance Protocol (POAP) shuts down

Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.

The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.

Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."

MVMT Labs files for bankruptcy

MVMT Labs, the company behind the Movement blockchain, has filed for bankruptcy, reporting assets of between $100,001 and $500,000 against liabilities of between $1 million and $10 million. The largest unsecured claim, at more than $1.6 million, belongs to co-founder Rushi Manche — whom the company fired in May 2025 after an investigation into the MOVE token launch.

Movement was an Ethereum layer-2 built on Move, the language originally developed for Facebook's dead Libra stablecoin project. It raised tens of millions, including a $38 million Series A led by Polychain in April 2024, before its December 2024 token launch went sideways. The firm opted to give an obscure market maker called Rentech control of 66 million $MOVE, or around 5% of supply, which they promptly dumped, crashing the price.

The Movement blockchain will reportedly continue on under a new company called Move Industries, and pivot away from Ethereum scaling and towards stablecoin operations.

Taiko bridge exploited

The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.