Wanchain bridge on Cardano exploited for more than $9 million

An attacker exploited the Wanchain bridge, stealing 515 million NIGHT tokens that had been bridged from Cardano to BNB. The NIGHT token belongs to Midnight, a privacy-focused blockchain linked to Cardano. The stolen tokens were priced at $9 million to $10 million at the time of the theft, although the massive outflow of tokens briefly caused the NIGHT token price to drop by about 43%.

Allbridge exploited for $1.66 million

The Allbridge blockchain bridge was exploited for $1.66 million in a flash loan attack. The attacker took advantage of a flaw in the project's logic that reprices assets against one another, after discovering that the same would happen even when borrowing an asset against collateral denominated in the same token. They were able to manipulate the project's internal pricing logic so that the asset's actual price diverged away from reality, pocketing $1.66 million in proceeds.

Across Protocol exploited for $3.35 million

The Solana deployment of the Across bridge was hacked for around $3.35 million. According to Across, the stolen funds belonged to Risk Labs, the foundation supporting the project, rather than users of the bridge.

Taiko bridge exploited

The Taiko bridge, which allows assets to be transferred between the Ethereum mainnet and the Taiko Ethereum layer-2 chain, was exploited for at least $1.7 million before the network was halted, limiting losses. An attacker was able to forge withdrawal requests to appear as though they matched real deposits. Crypto security firm BlockSec said that the attacker may have gained access to a signing key that had been exposed on GitHub.

Aztec Connect hacked for a second time in less than a week

Three days after Aztec Labs' deprecated Aztec Connect blockchain bridge was exploited for $2.1 million, the project has been hacked again for the same amount. Aztec Labs confirmed the second exploit, again trying to emphasize that the code was deprecated four years ago.

The hacks are part of a spate of exploits targeting legacy smart contracts belonging to projects including Raydium and DxSale. Although some projects have developed techniques to circumvent the immutable nature of blockchains and allow smart contracts to be upgraded or retired, many legacy contracts cannot be changed or shut down, leaving them vulnerable to attack indefinitely.

Deprecated project Aztec Connect exploited for $2.1 million

Aztec Connect, an abandoned defi privacy bridge from Aztec Labs, was drained of $2.1 million after an attacker exploited a bug in the project's smart contracts. Although the project was deprecated three years ago, funds remained in the legacy system. "Aztec Labs holds no admin keys or control over the system; it cannot be paused or upgraded by us," the project posted on social media.

The theft is only the latest in a string of attacks targeting vulnerable legacy smart contracts, many of which cannot be deleted, paused, or changed due to blockchains' immutable nature. Raydium and DxSale are two other platforms that have recently suffered losses due to old, insecure code.

Secret bridge exploited for $4.67 million a week before anyone notices

The bridge between the Cosmos-based Secret network and Axelar network was exploited via an infinite mint bug that went unnoticed for a week. An attacker exploited a smart contract in order to mint a large quantity of wrapped Axelar tokens on the Secret network, which they then redeeemed for around $4.67 million.

The exploit, which occurred on June 10, went unnoticed until June 17, when a transaction failed with a message suggesting that more tokens had been bridged out of the Secret network than had been bridged in.

Secret has warned, "If you hold Axelar-bridged saXXX tokens on Secret, please be aware their backing was affected and your funds may be lost."

Gravity Bridge drained of $5.4 million

Gravity Bridge, a bridge between the Cosmos and Ethereum blockchains, suffered $5.4 million in losses likely due compromised private keys. The developers of the protocol urged validators to halt while the theft was investigated, and the bridge was indeed halted shortly after. Two weeks after the hack, the Gravity Bridge interface remained unavailable.

Verus bridge hacked for $11.6 million

An attacker stole $11.6 million in various crypto assets from the Verus–Ethereum bridge, which allows users to use tokens from the Verus network on the Ethereum chain and vice versa. The attacker then swapped the tokens for ETH, limiting the ability for issuers of more centralized tokens to freeze the stolen assets.

Verus halted the entire Verus network after the exploit was detected in hopes of limiting further damage.

The exploiter later accepted a bounty offer by Verus, returning 4,052 ETH (~$8.5 million) while keeping the remaining ~25% as a "bounty".

TAC bridge exploited for $2.8 million

The TAC bridge, which bridges assets from the Ethereum blockchain to the Telegram-linked TON chain, was exploited for $2.8 million. The project paused the bridge and announced they were investigating.

The project has announced they intend to "restor[e] bridge liquidity through a legally structured sale of Foundation's TAC token treasury reserves."

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.