User Response Playbooks
Incident intelligence should end in action. These reports convert exploit patterns into practical wallet-safety steps users can follow quickly.
After a Bridge Exploit
After a Multisig/Admin-Key Incident
After a ZKP / Protocol Bug
If Your Wallet Is Flagged
Blockaid detected an AFX-operated Arbitrum bridge exploit at 2026-07-22 21:30 UTC. A finalized withdrawal moved 24.15M native USDC from the AFX bridge contract to 0x2f29...FEefc; Offchain Labs clarified the native Arbitrum bridge was not exploited.
An authorized signer path appears to have accepted fabricated prices, letting executor 0x321D...BFD9 loop 100x trades and receive $23.7535M in verified OLP payouts. The vault's separate USDC balance drawdown was about $25.31M.
Attacker acquired 882.28B BONK ($4.4M) and voted 'Yes' on a Realms governance proposal to transfer 4.426T BONK ($21.2M) from the DAO treasury to their own wallet, capturing $16.8M in profit.
Mainstreet/MSY depeg fear spread into Altura as users tested instant exits. Altura processed $8.5M+ USDT redemptions, with another ~1.55M AVLT still pending in queue across the Morpho/AVLT liquidity stack.
Critical soundness bug in Orchard shielded pool's elliptic curve scalar multiplication allowed potential unlimited counterfeit ZEC creation. Dormant 4 years. Emergency hard fork NU6.2 deployed. ZEC crashed 37%.
Forged LayerZero packets minted 116,500 uncollateralised rsETH, deposited into Aave as fake collateral to borrow $190M. Aave TVL drawdown hit 37%.
Six-month social-engineering op harvested Security Council signatures via durable nonces, then drained 20+ tokens against wash-traded CarbonVote collateral in 12 minutes.
A tiny SCA input exploited Cetus liquidity math to mint astronomical positions, draining SUI and USDC pools before validators froze $162M.
Attackers used two compromised keys and two phished signatures to upgrade WazirX's Safe wallet to malicious logic, then drained $235M.
A privileged GALA minter minted 5B tokens worth $216M and sold $21.8M before Gala blocklisted the exploiter account.
Mixin blamed a hacked cloud service database after ETH, BTC and stablecoins moved from user or hot-wallet custody into attacker wallets.
Multichain lockup assets moved to unknown wallets, draining about half of Fantom bridge holdings and most Moonriver bridge holdings.
Flash-loan funded contracts abused Euler's leverage and donateToReserves flow to create bad debt, liquidate it at a discount, and drain ETH, WBTC, USDC and DAI.
A well-funded trader pumped MNGO from $0.03 to $0.91, borrowed against inflated collateral, and left Mango with $115M of bad debt.
The BSC Token Hub accepted forged IAVL proofs, minting two batches of 1M BNB. About $127M escaped before BNB Chain paused to contain the rest.
Wintermute's vulnerable vanity hot wallet remained a DeFi vault admin, letting the attacker drain $162.3M and park stablecoins in Curve 3pool.
A routine upgrade left Nomad's Replica contract trusting the zero root, letting anyone replay the exploit call and replace the recipient address.
Two compromised Horizon bridge signer keys were enough to authorize withdrawals, draining ETH, BUSD, ERC20 assets and BSC-side funds.
The attacker borrowed massive liquidity, gained temporary governance power, executed a malicious emergency proposal, and routed about $76M profit to Tornado Cash.
Compromised Sky Mavis validators plus an unrevoked Axie DAO approval gave the attacker enough signatures to withdraw 173,600 ETH and 25.5M USDC.
A Solana verification mismatch let the attacker mint 120k unbacked Wormhole ETH, bridge most of it to Ethereum, and force emergency recapitalization.
Private keys for 96 platform-linked wallets were compromised, draining more than 4.5M PYR plus ETH and MATIC from user accounts.
Two BitMart hot wallets were drained for about $100M on Ethereum and $96M on BSC, then swapped through 1inch toward ETH and BNB.
A front-end compromise tricked users into approving an attacker address, which then pulled wBTC vault tokens and ERC20 assets from wallets.
Flash-loaned funds and two accounts manipulated yUSDVault collateral pricing, allowing the attacker to drain Cream lending vaults.
A Comptroller upgrade over-distributed COMP, then a public drip function refilled the vulnerable contract while governance waited for a fix.
A crafted cross-chain message changed keeper authority and drained Poly proxy lock contracts on Ethereum, BSC and Polygon before funds were negotiated back.