Major hack on 2 July 2026: attackers (linked to geopolitical actors) drained approximately $90 million in Bitcoin, Ethereum, Dogecoin and other assets, leaked source code, and forced site offline for security assessment.
Last verified 2026-07-05
Which platforms have a real, dated security or custody incident on record — hand-verified, not guessed.
Get notified about new incidents
One email if a new incident is recorded for any platform in the catalogue.
Major hack on 2 July 2026: attackers (linked to geopolitical actors) drained approximately $90 million in Bitcoin, Ethereum, Dogecoin and other assets, leaked source code, and forced site offline for security assessment.
Last verified 2026-07-05
Bonzo Lend protocol on Hedera exploited for $9 million on July 11, 2026, due to compromised Supra price oracle causing 77% token value decline. No breach of Hedera core infrastructure.
Last verified 2026-07-12
WazirX suffered a security breach in July 2021 resulting in approximately $8 million in cryptocurrency theft; no major incidents reported since 2026 launch of ZERO model.
Last verified 2026-07-19
Wormhole Bridge suffered a major exploit in February 2022 resulting in theft of approximately USD 325 million in wrapped Ethereum and USDC across Solana and Ethereum chains. The incident exposed a validation vulnerability in the bridge's smart contracts. The Solana ecosystem fund and Jump Crypto reimbursed affected users in full.
Last verified 2026-07-25
June 2016: $120 million theft affecting approximately 120,000 users; accounts were restored from insurance; 2021–2022: SEC investigations regarding unregistered securities trading and stablecoin claims.
Last verified 2026-07-27
Major security breach in December 2023; hackers accessed hot wallets and stole approximately $200 million in Bitcoin, Ethereum, and USDT. BitMart recovered most user funds through insurance and reserves within weeks.
Last verified 2026-08-05
Critical network outage on 30 June 2026; restored online 13:30 UTC with no user funds lost. Cross-chain assets matched 1:1 with Ethereum mainnet.
Last verified 2026-06-30
2020 hot-wallet hack (~$280M, largely recovered/reimbursed); 2024–25 US DOJ settlement, KYC now mandatory.
Last verified 2026-06-29
February 2025: ~$1.5B Ethereum hot-wallet hack (largest crypto theft to date); Bybit covered customer funds and remained solvent.
Last verified 2026-06-29
2023 security incident affected a subset of connected wallets via a third-party provider; non-custodial connections should be read-only.
Last verified 2026-06-29
Crypto.com suffered a $34 million security breach in January 2023 affecting approximately 483 users; funds were recovered and platform security was strengthened.
Last verified 2026-07-09
No protocol breach; a 2022–23 browser-extension vulnerability was patched. User risk is phishing/seed theft.
Last verified 2026-06-29
No major exchange-level custody breach; 2025 disclosed an insider-data incident affecting some users.
Last verified 2026-06-29
2019 hot-wallet hack (~7,000 BTC, reimbursed via SAFU); 2023 US DOJ/CFTC settlement ($4.3B).
Last verified 2026-07-04
2020 e-commerce database leak exposed customer contact data (not funds); keys never compromised. "Ledger Recover" (2023) drew privacy debate.
Last verified 2026-06-29
Every entry is hand-verified against the platform's full notable_incidents text — we deliberately don't rely on a keyword search, because phrases like "no protocol breach; user risk includes phishing and seed-phrase theft" describe general risk categories, not an actual event, and a keyword match alone would wrongly flag that as an incident.
No. It means no genuine, specific, dated incident was found in public reporting as of the last-verified date — the same honest limit disclosed on every review's verification info. Absence of evidence is not evidence of absence.
If you subscribe below (for one platform or all of them), yes — once alerting is fully wired up. Subscriptions are captured now; see a platform's own review page to subscribe to alerts for just that platform.
As new incidents are verified and added to a platform's review. Each entry links through to the full review with sourcing and a last-verified date.
Reviewed by Arjun Mehta
Editorial lead overseeing FlixoCrypt's research, sourcing and verification process
Last verified: