Crypto Users Hit by DeFi Exploits & Hacks
Crypto users, from casual traders to DeFi participants and investors, are experiencing a growing unease and frustration stemming from a lack of genuine security and transparency within the ecosystem. They feel misled by advertised 'safety' features and are exposed to significant financial risk due to vulnerabilities in bridges, protocols, and token launches, leading to substantial losses and a loss of confidence.
SOURCES (60)
“Yes we accidentally minted 18 billion intsted of ten but we will burn 7 and use the rest for airdrops for our first 200 holders”
“I am utterly disgusted with Wirex's practices. They arbitrarily deducted 10.845959 SOL (worth over 8,000 HKD) from my account under a predatory "Storage Fee" clause. To be clear, I don't even care about the money anymore-what is unacceptable is how disgraceful and scam-like this method is. Seizing users' crypto assets under hidden or obscure inactivity terms without prominent advance notice is pure exploitation. When I contacted support to question this, their live chat and”
“USDC has the same restrictions. Dai and LUSD are probably the only major stable coins without such backdoors. USDS is borderline, because there is no backdoor but the contract is upgradeable.”
Silly transparent blockchains with nonfungible tokens....
“I must be very brave to be using Phantom as cold storage but I’m not so brave no”
“Is Google Drive even encrypted? Google should scan for seed phrases for additional revenue. Besides that, nobody should call himself Crypto developer with such a shitty setup.”
“You have to be careful here. Loopers just got liquidated this past week because of an Oracle manipulation attack”
“Millions more like. There are over 30 millions listed projects on the exchanges. It's nuts how shitcoins became the face of crypto.”
“A crypto dev who goes by Gomtu (@gomtu_xyz) just got drained for around $49K, & the way it happened is worth walking through, because so many have fallen for similar scams. Here's the chain, from his own posts on X.. He was setting up a new MacBook. Installed Chrome, signed into his main Google account, turned on Sync. Then he searched "homebrew," the package manager basically every Mac dev installs on day one. He clicked the top result. It was a Google sponsored ad. The page b”
“Yeah they list a ton of scam tokens and love to wash their own volume. They’ve been hiding behind the we’re still in beta excuse for 4 years now. I seriously doubt they would’ve returned your money if you hadn’t called them out publicly. And they're talking to you about red flags lol”
“I’m sharing an open-source project I developed after dealing with a real case involving a Ronin Waypoint/keyless wallet compromised through a malicious EIP-7702 delegation . This is NOT a wallet recovery service. Do not send me your seed phrase, private key, recovery password, OTP, Waypoint token, client shard, or any other secret. The problem was a recovery deadlock: The wallet had a malicious EIP-7702 delegation, and any RON sent to the compromised wallet for gas could be swept before the owne”
“Especially the trending part at fomo app, which ever token that's trending I checked it has scammers running them, either a honey pot, a good ol' rug pul, slow draining, you name it and you'll find some there. When checking the contract adress and the distribution from phase genesis of the creation and forward I'd say that app is for true degens and gamblers.”
“Usually incentives break the cycle before organic demand does. aave and compound got their early liquidity depth through token emissions basically paying people to be guinea pigs while the risk model was still unproven, not because holders suddenly trusted it. The supply cap thing you're hinting at might be the real unlock though. Cap total borrow/deposit low enough that even a nasty 30% flash crash can't actually break the market, let real money stress test it with bounded downside, the”
“Around 60% of crypto platforms exploited since early 2025 had undergone independent security audits, according to CoinGecko. The bigger issue? Many of the attacks reportedly happened outside conventional audit scope. As more capital and real-world assets move on-chain, security can't be treated as a one-time audit checklist. Continuous monitoring, risk controls, and resilient infrastructure will become increasingly important for institutional adoption. submitted by /u/cSigmaFinan”
“You think your Bitcoin is safe just because your hardware wallet is offline. $130 million was recently drained from cold storage to prove that assumption wrong. The brutal truth : a $150 piece of plastic doesn't make you invulnerable. If you secure your wealth with a single 24-word seed phrase, you haven't eliminated your single point of failure — you just moved it. Attackers aren’t hacking the blockchain anymore. They are exploiting blind signing, compromised supply chains, and physical”
“Why does cronos need their own chain? Why dont just use eth? Idiots or scammers? Prob both”
“The worst part is nobody talks about the admin key risk until it gets turned and suddenly your 9% yield is locked up for weeks while some multisig figures out what to do. That gap between the APY you see and the actual risk you're taking is where all the pain hides Most people skip past the docs anyway, they just see the number and ape in. Pricing that control surface into the yield display would scare half the liquidity away overnight”
“I agree with you that this is one of the least worst things Crypto dot com has done to their users. They actually used their centralization to protect their users from harm for once ... unlike the time they diluted MCO holders or the time they unilaterally voted against their users to increase the supply of CRO by 200%. (Also, centralized mining pools have, without warning, reorged Bitcoin in the past to protect against a major bug in 2013, resulting in at least 1 known double-spend.)”
“They all have staff that sell your information to scammers. Coinbase being especially bad for it.”
“If they are able to halt the chain the good for them. This doesn’t open any questions. A big coin like bitcoin no one can halt the chain. For smaller coins if they cns pull that off then good for you to save people’s money. If you had the power to shutdown the chain on an altcoin to prevent 70million in theft then it’s the right thing to do and bless you. Not that many coins have that ability so if it’s available it’s great to see people doing it.”
“Cronos responded by halting the blockchain, while Tectonic warned users not to interact with the protocol. Sounds decentralized /s”
“only around $6M managed to get out from the estimated $75M, I think halting the network was lowkey worth it. but idk what do you guys think?”
“Since OP only posted a link What happened: An exploit against lending protocol Tectonic affected an estimated $75 million . Cronos responded by halting the blockchain , while Tectonic warned users not to interact with the protocol. How the apparent exploit worked: According to researcher Weilin Li, the attacker exploited TONIC's 20% collateral factor combined with very thin liquidity . They rapidly pumped TONIC's market price roughly 100× , making their TONIC collateral appear enormously”
“I'm all-in with the Monad ecosystem. Been slowly stacking since mainnet launch. Currently have my bag split between native staking and liquid staking. Using the shMON LST as collateral for borrowing funds that I'm using for liquidity pooling. Recently moved from the DUST/USDC pool (i use Neverland a lot) into a WMON/USDC pool with ~110% vAPY. I'll probably hold that position until incentives dry up and then move back to the old pool. Otherwise, I stopped participating in perps last w”
“Is there any info in any of those screen shots showing that this is legitimately the changenow team? ... all I see are names with (changeNOW) next to them. I didn't see any header info.”
“i had this problem for years. I had great runs, make money for days or even weeks, and then give everything back in a single day. I though it was me lacking discipline or weak mental but after years of being stuck in this cycle, i eventually realized what is actually happening. the problem is that we are treating discipline as our safety system. “just be more disciplined” sounds like good advice, but it’s a very bad advice for active trader, discipline completely falls apart when you are stresse”
“man thats rough, 44 emails of empty promises would make anyone lose their mind. a year is way past "system issue" territory, at this point its just theft with extra steps the whole non-custodial claim falls apart when they can lock your funds indefinitely like this. reminds me why i stopped trusting these smaller exchanges no matter how convenient they look hope the FSA actually does something but these regulators move slower than continental drift. keep posting everywhere you can, pub”
“The good old days. When "blockchain" was the buzzword and the most technically advanced. How things have gotten worse...”
“When we watch EVM protocols get drained of fifty million dollars in a single block because some founder left their administrative private keys sitting in an unencrypted plaintext file on an AWS server, we're not looking at a smart contract exploit. We're looking at primitive, indefensible operational negligence. Yet, every time this happens, the headlines scream about a "sophisticated hacker" or a "protocol exploit." The developers get dragged through the mud, while t”
“Yea bus His Point is What happens when the Bots are making Thousands Transactions 24/7”
“Phishing. It's always phishing. "Hey you need to verify your seedphrase write it here" Come on who is that stupid? I don't understand. First thing everyone tells you in crypto is never under any circumstances share your seed with absolutely anyone, doesn't matter if it's Binance support or whoever the fuck they say they are. Never write your seed anywhere in the internet, never, under any circumstances. It's not that hard. It's literally the crypto version of &q”
“This guy could have done " soft rugging". That's where there's not like a Dev share for the coin but The leak just buys some earlier than other people, they would know all of the tricks to be able to be first in line and they would know the exact time. The prophets would be lower but they would be less visible. And it leaves the burning of the Dev token as one more thing to draw attention to this. He got free marketing out of it.”
“People are buying and selling this thing. May just have to accept and then assume a large amount of insanity. Try to find some way to get ahead of it somehow”
“You said they stuck to their promise, that's why they feel like you're promoting it. Also it seems they just pulled the rug.”
“I read the article. Leaks didn't rug pull, the 250k was made from transaction fees”
“ugliest part is NAV only gets audited when withdrawals hit, and then the hole's already socialized.”
Wallet drainers on fake websites and drainers on Google ads
“Obligatory reminder that THORChain devs are either corrupt or incompetent and any person that has any funds invested there is at this point reckless: June 29, 2021 — ~$140K — Ethereum Bifrost parsing bug let a crafted ERC-20 masquerade as ETH and withdraw real assets. July 15, 2021 — ~$8M — Attacker exploited the ETH Router/Bifrost flow to make nonexistent ETH deposits appear valid and drain the ETH pool. July 22, 2021 — ~$8M — A second ETH Router/Bifrost exploit used fake deposit events and ref”
ive heard wazirx is also charging users in a similar way.
You know when they use the term core it’s going to be fud which follows
“More info: https://stacker.news/items/1555439?commentId=1555585 submitted by /u/CapoDoFrango [link] [comments]”
