Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit

A Bored Ape-style illustration of an ape with blue skin, brown shoulder-length hair, a grimace with red lipstick, bloodshot heavy-lidded eyes, a skull-print scarf, and a nurse's topAll my Desperate ApeWives gone :( (attribution)
Exploiters took advantage of a legacy approvals bug in an old payment processor called Limit Break, which the platform had stopped using in late 2024. The bug affected listings on Magic Eden's EVM marketplace, which the company had shut down earlier this year. The attackers were able to steal numerous NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate Apewives. Attackers also subsequently stole 660 wETH (~$1.78 million).

A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.

Meter token prices crash after unauthorized mint

An exploiter was able to mint unbacked wrapped MTR and MTRG tokens, notionally priced at more than $2.3 million. They sold some of the tokens on a decentralized exchange, crashing the MTRG price by more than 88%. The price of the project's MTR token — which is supposed to maintain a stable price based on the cost to produce 10 kWh of electricity — also plummeted by approximately the same percentage. Meter has attributed the exploit to a "block validation flaw".

Meter paused the blockchain and bridge, and has urged people not to trade the token. They have warned that "Transactions after block 100731417 may not be honored", suggesting they are considering a blockchain rollback.

Meter suffered another bridge attack in February 2022, which amounted to $4.3 million.

Payy Network bridge fully drained of $1.8 million

The Payy Network, a stablecoin infrastructure company, disclosed that a bridge contract had been fully drained of funds, netting attackers $1.8 million. They later stated that the theft was "NOT a compromised key, social engineering or exploit of our off-chain infrastructure," but has not disclosed what it was. They also announced that the stolen funds were "users' non-custodial deposits to Payy Network / Payy Wallet", which is somewhat of an oxymoron.

Payy Network has halted all activity following the attack.

Duelbits crypto casino goes offline after $7 million theft

The Duelbits crypto gambling site lost around $7 million to an apparent hot wallet compromise. The site went offline shortly after the attack, and the company has said the site will stay offline "until we have clarity". The Curaçao-based platform offers casino games and sportsbetting.

Bitget crypto exchange hacked for $388 million, pauses withdrawals

Attackers stole $387.5 million in crypto assets from Bitget, a cryptocurrency exchange originally founded in Singapore and headquartered out of the Seychelles. Centralized stablecoin issuers Circle and Tether (issuers of USDC and USDT) froze $318,000 in stolen assets, but the vast majority were swapped to decentralized cryptocurrencies and have not been frozen.

Bitget CEO Gracy Chen has said the company believes that a North Korean cybercrime group may be behind the theft. Bitget halted withdrawals shortly after the theft was noticed, citing the need to prevent attackers from stealing more assets. Bitget has said they have sufficient assets to cover the stolen funds.

Projects on the defunct Neutron chain lose $1.8 million to governance attack, Cosmos Hub halts chain

Neutron, a blockchain in the Cosmos ecosystem that entered maintenance mode in June, suffered a governance attack when someone spent $20,200 to acquire enough NTRN governance tokens to pass a vote allowing them to take control of the Neutron-based Astroport and Drop applications, whose contracts contained a combined $9.5 million in assets.

Neutron was paused shortly after the attack, and validators subsequently paused the entire Cosmos Hub network. Together, the pauses prevented the attacker from cashing out the entire amount, though they successfully made off with $1.8 million that they were able to bridge to Ethereum prior to the pause. Cosmos Hub remained paused for approximately 24 hours. During the pause, validators coordinated to move approximately 1.73 million ATOM from the attacker's wallet to a multi-signature wallet controlled by a group of companies operating network validators.

Single attacker steals $2.25 million from three crypto projects in the "Artificial Superintelligence Alliance"

One attacker stole crypto tokens from three cryptocurrency projects that are part of what's called the "Artificial Superintelligence Alliance" — a group of crypto projects "dedicated to decentralized Artificial General Intelligence". The attack occurred within just one day, netting around $2.25 million in actual profits, though the stolen tokens were notionally priced considerably higher.

Most of the profits came from stolen FET tokens, which are linked to Fetch.ai. The attacker was also able to perform unauthorized mints of various tokens, crashing their prices but earning the attacker little in the way of profits. Security researchers noticed that attackers stole assets from sixteen wallets spanning the three companies, suggesting they had significant access to all three companies' systems. Almost $290,000 was taken from a contract used for company payroll.

4,000 BTC (~$320 million) stolen from Liquid Network by claimed whitehats, 90% returned

An unauthorized withdrawal of 3,998.5 BTC (~$320 million) from the Liquid Network, a bitcoin sidechain, prompted a network halt. By disabling nodes that bridge between Liquid and the bitcoin mainchain, attackers are limited in their ability to cash out via bridge. Blockstream, the developers of Liquid Network, also said they had contacted exchanges to ask them to pause LBTC deposits and withdrawals, cutting off another avenue.

The unauthorized transaction included a message reading "we are whitehats. contact us on chain", suggesting the possibility that the withdrawal was in fact well-intentioned security researchers aiming to "rescue" funds after discovering they were vulnerable and then return them to a secure wallet. After some back and forth, the attacker returned 3,400 BTC (~$272 million) keeping 600 BTC (~$48 million), likely as a "bounty".

More Markets exploited for $9.3 million

Defi lending project More Markets lost $9.3 million after an attacker was able to trick the lending protocol logic and empty the project's reserve. The attack was noticed by blockchain security researchers at Blockaid; More Labs later announced they were investigating. Oddly, while acknowledging that funds had been stolen, they wrote, "Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused." They claimed that only 5% of the assets were bridged out of the Flow blockchain, though did not explain how they planned to prevent the attacker from moving more tokens or collapsing the token price entirely.

Crypto.com-affiliated Cronos blockchain halted after Tectonic theft

The ostensibly decentralized Cronos blockchain was halted after a price manipulation attack allowed an attacker to borrow around $120 million against nearly worthless collateral from the Tectonic lending platform. The attacker pumped the price of the thinly traded TONIC token, the native token of Tectonic, then borrowed against it. The attacker cashed out approximately $9.19 million by bridging it to Ethereum before the Cronos chain was halted, limiting their profits. The blockchain was offline for almost 24 hours, during which time it was rolled back to a block prior to the hack — essentially undoing all the transactions that occurred after that block.

Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain — though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.