FlixoCrypt

Security incident registry

Which platforms have a real, dated security or custody incident on record — hand-verified, not guessed.

Get notified about new incidents

One email if a new incident is recorded for any platform in the catalogue.

Nobitex 1.5/5

Major hack on 2 July 2026: attackers (linked to geopolitical actors) drained approximately $90 million in Bitcoin, Ethereum, Dogecoin and other assets, leaked source code, and forced site offline for security assessment.

Last verified 2026-07-05

Bonzo Lend protocol on Hedera exploited for $9 million on July 11, 2026, due to compromised Supra price oracle causing 77% token value decline. No breach of Hedera core infrastructure.

Last verified 2026-07-12

WazirX 3.5/5

WazirX suffered a security breach in July 2021 resulting in approximately $8 million in cryptocurrency theft; no major incidents reported since 2026 launch of ZERO model.

Last verified 2026-07-19

Wormhole Bridge suffered a major exploit in February 2022 resulting in theft of approximately USD 325 million in wrapped Ethereum and USDC across Solana and Ethereum chains. The incident exposed a validation vulnerability in the bridge's smart contracts. The Solana ecosystem fund and Jump Crypto reimbursed affected users in full.

Last verified 2026-07-25

Bitfinex 3.5/5

June 2016: $120 million theft affecting approximately 120,000 users; accounts were restored from insurance; 2021–2022: SEC investigations regarding unregistered securities trading and stablecoin claims.

Last verified 2026-07-27

BitMart 3.5/5

Major security breach in December 2023; hackers accessed hot wallets and stole approximately $200 million in Bitcoin, Ethereum, and USDT. BitMart recovered most user funds through insurance and reserves within weeks.

Last verified 2026-08-05

Taiko 3.8/5

Critical network outage on 30 June 2026; restored online 13:30 UTC with no user funds lost. Cross-chain assets matched 1:1 with Ethereum mainnet.

Last verified 2026-06-30

KuCoin 3.9/5

2020 hot-wallet hack (~$280M, largely recovered/reimbursed); 2024–25 US DOJ settlement, KYC now mandatory.

Last verified 2026-06-29

Bybit 4/5

February 2025: ~$1.5B Ethereum hot-wallet hack (largest crypto theft to date); Bybit covered customer funds and remained solvent.

Last verified 2026-06-29

CoinStats 4/5

2023 security incident affected a subset of connected wallets via a third-party provider; non-custodial connections should be read-only.

Last verified 2026-06-29

Crypto.com 4.1/5

Crypto.com suffered a $34 million security breach in January 2023 affecting approximately 483 users; funds were recovered and platform security was strengthened.

Last verified 2026-07-09

Trust Wallet 4.2/5

No protocol breach; a 2022–23 browser-extension vulnerability was patched. User risk is phishing/seed theft.

Last verified 2026-06-29

Coinbase 4.3/5

No major exchange-level custody breach; 2025 disclosed an insider-data incident affecting some users.

Last verified 2026-06-29

Binance 4.4/5

2019 hot-wallet hack (~7,000 BTC, reimbursed via SAFU); 2023 US DOJ/CFTC settlement ($4.3B).

Last verified 2026-07-04

Ledger 4.5/5

2020 e-commerce database leak exposed customer contact data (not funds); keys never compromised. "Ledger Recover" (2023) drew privacy debate.

Last verified 2026-06-29

Security incident registry — FAQ

How is this list built? +

Every entry is hand-verified against the platform's full notable_incidents text — we deliberately don't rely on a keyword search, because phrases like "no protocol breach; user risk includes phishing and seed-phrase theft" describe general risk categories, not an actual event, and a keyword match alone would wrongly flag that as an incident.

Does a platform's absence from this list mean it's completely safe? +

No. It means no genuine, specific, dated incident was found in public reporting as of the last-verified date — the same honest limit disclosed on every review's verification info. Absence of evidence is not evidence of absence.

Will I be notified about new incidents? +

If you subscribe below (for one platform or all of them), yes — once alerting is fully wired up. Subscriptions are captured now; see a platform's own review page to subscribe to alerts for just that platform.

How often is this updated? +

As new incidents are verified and added to a platform's review. Each entry links through to the full review with sourcing and a last-verified date.

Reviewed by Arjun Mehta

Editorial lead overseeing FlixoCrypt's research, sourcing and verification process

Last verified: