On November 1st, Onyx Protocol encountered a substantial security breach, leading to a loss of approximately $2.1 million. To carry out the attack, the hackers adeptly leveraged a well-documented rounding-off discrepancy inherent to the widely used CompoundV2 fork.
On October 25th, 2023, LastPass, a widely used password manager, fell victim to a security breach. The breach had significant ramifications, affecting approximately 25 users whose assets were distributed across 80 wallets. This breach resulted in a staggering loss of approximately $4.4 million in various cryptocurrencies. Among the affected blockchain networks were Bitcoin, Ethereum, Binance Smart Chain, Polygon, Solana, Cardano, Litecoin, Arbitrum, and Avalanche.
On September 24th, 2023, Huobi Global's HTX exchange fell victim to a security breach, resulting in a substantial loss of $7.9 million. This incident stemmed from the compromise of the protocol’s hot wallets.
Mixin Network, a Hong Kong-based digital asset transactional platform, reported a security breach on 25 September, revealing a loss of approximately $200 million due to a hack of its cloud service provider. The stolen funds accounted for so far are comprised of ETH, USDT (swapped to DAI), and BTC. If the $200M figure stated by Mixin is accurate, it would make this incident the biggest hack of 2023 so far.
On the 4th of September 2023, the popular crypto gambling platform Stake suffered a major security breach due to private key leak resulting in the theft of approximately US $38 million. The preliminary investigation confirms that unauthorized withdrawals were detected from Stake's hot wallets on the Ethereum, Polygon, and Binance Smart Chain networks.
On the 13th of August 2023, at around 10:30 pm UTC, Zunami Protocol suffered a price manipulation attack and lost approximately $2.1 million.
On August 7th, 2023, Steadefi, a sophisticated yield aggregator, fell victim to an assault that resulted in a substantial loss of over $1.14 million.
On the 30th of July, Curve Finance, a decentralized, Automated Market Maker (AMM), was hacked leading to a loss of ~ $45 million in CurveDAO, ETH, and wETH. The attackers exploited a malfunctioning reentrancy lock on different versions of the Vyper programming language (0.2.15, 0.2.16, and 0.3.0) across multiple stable-pools.
On the 22nd of July, Alphapo, a cryptocurrency payment gateway suffered a massive security breach leading to at least $110 million being drained from its hot wallets on Ethereum and Tron blockchain.
Conic Finance, a liquidity pool optimization platform designed for the decentralized finance (DeFi) protocol Curve, encountered an exploit on July 21st, 2023 that resulted in a loss exceeding $3.26 million, attributed to a vulnerability within their smart contract.