On 21 February 2025 Bybit reported unauthorized activity involving an ETH multisig cold wallet: a transfer to a warm wallet was manipulated so signers approved a UI that masked a change of wallet control, and ETH holdings were drained. Bybit stated other wallets were unaffected, withdrawals continued, and client assets remained 1:1 backed; later updates covered service restoration and partial recovery work. FBI attributed the theft to North Korean TraderTraitor actors.
On 18 July 2024 WazirX reported a cyber attack on a multisig wallet operated with Liminal custody infrastructure, with losses exceeding $230 million. Trading was later paused; WazirX filed complaints with Indian authorities, launched a recovery bounty, and published preliminary forensic notes. Users should treat ongoing restructuring/recovery communications as material custody risk.
In December 2023 a malicious release of the Ledger Connect Kit NPM package drained funds from users who interacted with affected dapps. Hardware seed storage was not directly compromised; the attack targeted web connectors.
In December 2023 a malicious release of the Ledger Connect Kit NPM package drained funds from users who interacted with affected dapps. Hardware seed storage was not directly compromised; the attack targeted web connectors.
In July 2023 multiple Curve pools using a faulty Vyper compiler release were drained via reentrancy. Curve and related parties published incident updates; some funds were later returned by whitehats / negotiations. Reference for compiler + pool-implementation risk in DeFi blue chips.
Multichain (formerly Anyswap) suffered a catastrophic 2023 failure involving MPC key control and halted bridging; Fantom and other ecosystems faced large bridged-asset risk. Included as Fantom-adjacent bridge contagion reference—not a Fantom L1 consensus bug.
Ledger Recover optional seed backup feature sparked community concern about firmware update paths and recovery model trust assumptions, even for users who never opt in.
Ledger Recover optional seed backup feature sparked community concern about firmware update paths and recovery model trust assumptions, even for users who never opt in.
Early mainnet period included typical L1 growing pains and ecosystem phishing; tracked as low-severity context for operational maturity, not a single catastrophic protocol hack.
Another extended Solana mainnet outage in February 2023 (large block propagation / consensus progress failure). Solana Labs and validators published post-incident notes; users could not transact until restart.
October 2022 BSC token hub bridge exploit. Binance paused the bridge and coordinated recovery actions; relevant to Binance ecosystem risk beyond the CEX order book.
Solana mainnet-beta halted for roughly 17 hours in September 2022 after a surge of bot duplicate transactions exhausted resources. Validators coordinated a restart. Classic liveness / congestion incident—not a consensus key theft.
Wormhole bridge exploit (Feb 2022) minted unbacked wrapped ETH on Solana after a signature verification flaw. Jump Crypto publicly stated it replenished the shortfall. Reference for cross-chain messaging risk on Solana-adjacent bridges—not a Solana L1 consensus failure.
In mid-January 2022 Crypto.com detected unauthorized crypto withdrawals affecting hundreds of user accounts (public reporting ~$34M across ~483 users). Withdrawals were suspended for about 14 hours while controls were hardened. Crypto.com said customers were reimbursed and later rolled out stronger withdrawal locks, SMS OTP, and an Account Protection Programme in select markets.
In December 2021 BitMart reported a large-scale security breach of ETH and BSC hot wallets after a stolen private key, with ~$150M withdrawn per BitMart (independent estimates nearer ~$200M). Withdrawals were suspended; BitMart said it would use its own funding to compensate affected users and resume services after security checks.
Coinbase has publicly discussed waves of account takeovers driven by phishing and social-engineering of SMS/2FA, and has published security guidance and product changes (app-based 2FA, warnings).
On 16 October 2020 OKEx suspended crypto withdrawals after a private-key holder cooperating with authorities became unreachable, blocking multisig authorization. Spot trading continued; OKX later said user assets remained fully reserved. Unrestricted withdrawals reopened around 26–27 November 2020 after the key holder returned and hot-wallet checks. Treat as a material key-person / custody authorization risk, not a hot-wallet drain.
In September 2020 KuCoin reported large unauthorized withdrawals from hot wallets (BTC, ERC-20 and other tokens). Cold wallets were stated safe; deposits/withdrawals were suspended while hot wallets were redeployed. KuCoin said user losses would be covered by the exchange and its insurance fund and published ongoing recovery updates with project partners.
Ethereum Classic suffered multiple deep reorg / 51% attacks in 2020, enabling double-spend of ETC on exchanges. Relevant for proof-of-work security budget and exchange confirmation policies on minority PoW chains.
On 12 March 2020 extreme ETH volatility plus oracle / auction failures led to zero-bid Maker vault liquidations and protocol shortfall. Maker governance later ran auctions and process changes. Foundational DeFi liquidation/oracle stress case (Maker → Sky lineage).
On 12 March 2020 extreme ETH volatility plus oracle / auction failures led to zero-bid Maker vault liquidations and protocol shortfall. Maker governance later ran auctions and process changes. Foundational DeFi liquidation/oracle stress case (Maker → Sky lineage).
In May 2019 Binance reported a security breach that withdrew about 7,000 BTC from a hot wallet. The exchange covered customer balances and later published post-incident security upgrades.
On 2 August 2016 Bitfinex halted trading and crypto deposits/withdrawals after discovering a security breach limited to Bitcoin wallets. Bitfinex later documented ~119,756 BTC stolen, credited BFX tokens against customer losses, and stated all BFX were redeemed within about eight months. Later DOJ recoveries related to the stolen coins are separate from the original operational failure.
In June 2016 an attacker drained The DAO smart contract via a recursive call vulnerability. The Ethereum community hard-forked to reverse the theft; the non-forking chain continued as Ethereum Classic. Foundational case for immutability vs social recovery trade-offs.
In June 2016 an attacker drained The DAO smart contract via a recursive call vulnerability. The Ethereum community hard-forked to reverse the theft; the non-forking chain continued as Ethereum Classic. Foundational case for immutability vs social recovery trade-offs.
As with other communities, Kaspa users are targeted by fake wallets and support scams. Protocol consensus security is separate from user social-engineering risk.
Users of Trezor (and other hardware wallets) are frequently targeted by fake support sites and phishing that try to extract seed phrases. Device firmware compromise is not implied; the risk is social engineering around recovery.
Kraken maintains a public security program and has published materials on platform security controls. Tracked here as transparency posture rather than a single catastrophic outage.
NEAR’s Rainbow Bridge and related cross-chain tooling introduce bridge-operator and smart-contract assumptions beyond L1 consensus. Tracked as disclosure/context for NEAR ecosystem bridging risk.
Optimism has published status incidents around sequencer downtime and upgrades. Users temporarily cannot post L2 transactions while L1 deposits/withdrawals follow bridge rules. Tracks L2 operator centralization / liveness risk.
Arbitrum One has experienced sequencer stalls and status incidents where L2 inclusion paused until recovery. Same class of risk as other optimistic rollups: soft-confirmations depend on a privileged operator until decentralization improves.
Aave users are routinely targeted by fake apps and phishing that request unlimited token approvals. Protocol smart-contract risk is separate from social-engineering drains; included as ongoing retail risk context.
Fake Uniswap frontends and support impersonators remain a major loss vector. Core AMM contracts are distinct from website phishing; users must verify URLs and approvals.
Polygon PoS users have periodically faced bridge congestion, maintenance, and historical Plasma exit complexity. Tracked as bridge / operator operational risk for POL ecosystem exposure—not a complete history of every outage.
TokenScouts publishes independent overview pages for cryptocurrencies, wallets, and exchanges. Use them as a starting point for research — not as financial advice.
Every project is different. Check official documentation, compare multiple sources, and never share private keys or seed phrases. If a claim sounds guaranteed or risk-free, treat it as a warning sign.
Browse the latest reviews above or continue with the blog for deeper explainers on wallets, staking, mining, and market mechanics.