Crypto Users Hit by DeFi Exploits & Hacks
Crypto users, from casual traders to DeFi participants and investors, are experiencing a growing unease and frustration stemming from a lack of genuine security and transparency within the ecosystem. They feel misled by advertised 'safety' features and are exposed to significant financial risk due to vulnerabilities in bridges, protocols, and token launches, leading to substantial losses and a loss of confidence.
SOURCES (60)
“Fable/Opus 4.8 and GPT-5.6 Sol are a security risk. The code they will write is not secure, and they are not capable enough to secure it. Don't use those two models.”
“This is the perfect definition of what crypto is, a launchpad for scamming. Welcome to crypto!”
Great topic tbh, especially the not giving away custody part.
“I wonder how people fall for these scams…and then I realize the bigger scammers who don’t want KYC so they can get large sums of money without having to give out identifying information and they got taken for a ride when the exchange turned out to be fake…and it just warms my heart that these people got fleeced…as much as you don’t want to give your information to these exchanges that identifying information is what’s likely to make sure the exchange is real Coinbase and Robinhood are just 2 eas”
“The problem is people do sometimes start with just $10. But those sites are controlled by the scammers, so they make it look like you are making a lot of money. & they usually do let you withdraw $ at 1st… then they get you to add more & more $ thinking you’re gonna get rich. Then when you try to take $ out again tell you some bs like you have to pay taxes or fees… which doesn’t make any sense b/c if that was true they could just deduct it from whatever you made. But believe it or not so”
“very unfortunate, why would you trust a new exchange and even deposit all your crypto. I would at least try with very small amount. less than $10!”
“Super common unfortunately. Just look at [ r/cryptoscams ]( r/cryptoscams ). Reminder to all newbies: * Only use well known exchanges like Kraken, UpHold, Coinbase, heck even RobinHood. * & keep all convos about crypto, investing, trading public. Only scammers want to talk privately”
[Robinhood] ★ 1/5 (v2026.28.0) — In 2024, I sent $50 in ETH to a scammer and reported the mistake to Robinhood in hopes that they could help. Instead, they restricted my account…
“The problem is that "non-custodial" became a UX slogan instead of a security description.”
“Original exploit (May 7, 2026): TrustedVolumes (an independent DeFi liquidity provider and RFQ market maker used by 1inch Fusion) lost approximately $5.87M–$6.7M in a single transaction. The stolen assets were ~1,291 WETH, 206k USDT, ~17 WBTC, and ~1.27M USDC. The attacker (same operator behind the March 2025 1inch Fusion V1 exploit) used a vulnerability in TrustedVolumes’ custom RFQ swap proxy. Recent development (July 17, 2026): One of the exploiter’s wallets sent 1,122.12 ETH (≈ $2.068 millio”
“Been looking at LocalTrade and Hacken lists one audit under BNB chain and solidity. What I still don’t understand is whether that review only covers the token contract or any current Defi contracts behind the product. A token audit does not tell me much about upgrade permissions admin controls oracle dependencies or offchain custody. The main risk is treating the whole Defi stack as audited when the public scope may be much narrower. Has anyone found the dated report and exact contract addresses”
“saw this play out liv yesterdaye. this is unfortunate. product is good but this shouldn't have happened. waiting on their updates. they have 40m in reveneue and 20m raised recently. maybe that could help in making users whole?”
“Blockaid reported an exploit against Ostium on Arbitrum in which an attacker allegedly used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to manufacture artificial trade profit, triggering an approximately $18 million USDC Vault payout. I recently published an investor-facing Ostium protocol autopsy. It was not public before the exploit, and it did not identify this specific flaw. I do not want to claim otherwise. What it did identify was the set of questions that”
“We just dropped our Q2 Crypto Industry Report, above are some of the biggest things that defined Q2. Personally, the biggest event for me was the whole KelpDAO and LayerZero saga as it had such lasting effects on DeFi. What were some of the most memorable events for you guys? Our full report: https://www.coingecko.com/research/publications/2026-q2-crypto-report submitted by /u/khai0001 [link] [comments]”
“Approval phishing does not need your keys or your seed phrase. You visit a site, it asks you to sign or approve something, and that approval quietly hands a contract standing permission to move your funds. It can sit unused for a while, then drain the wallet later. A few habits that hold for any wallet: - Treat every signature request as a permission grant, not a formality. - Check what contract you are approving and what it is allowed to do. - Revoke old approvals you no longer use (revoke.cash”
“nowadays, there are many such cases of Security breach. It's better to take care of your funds”
“tried to post about /r/Nanogotchi and it was taken down without any reason. Nano (XNO) is a cryptocurrency, and it didn't break any of the rules so? submitted by /u/K1LLerCal [link] [comments]”
“dude oil sales generate revenue amounting hundreds of millions a week. mixers are not magic with regards to volume. they are not dealing with your a few thousand dollars worth of crypto. Iranians have been experts in crypto since before this subreddit was founded.”
“Good for those registrants that they arent going into defi, crypto and defi fully transitioned into a scam casino filled with fishing, hacks, exploits, insider trading etc. over the last 3 years. The average investor should stay away.”
“Nobody outside of crypto is using any of this. Some do, but on their own chain”
“They care about editorial coverage from specific media outlets, here's a list of what Wikipedia sees as 'reliable': https://en.wikipedia.org/wiki/Wikipedia:Reliable_sources/Perennial_sources if you notice - there are ZERO crypto media outlets in there. Qatar-funded Aljazeera however, is considered 'independent' and 'reliable' publication. See the irony there?”
“That’s the key distinction. Morpho’s isolation contains protocol-wide contagion, but for vault depositors it can concentrate risk in the curator’s decisions. The curator doesn’t need to “rug” anyone; chasing yield into weak collateral or thin liquidity is enough. I’d qualify one point: curator quality is the first screen for vault depositors, but it is irrelevant for direct Blue suppliers, where oracle design, LLTV, liquidity, and liquidation conditions dominate. Aave and Compound spread individ”
“So it's been almost 2 years since the hack, there was a whole Singapore court scheme, "phased withdrawals," re-KYC drives, trading resumed like it's business as usual now... and I still can't withdraw a single rupee of my lacs sitting on the platform. Genuinely lost track of what stage we're even at. Last I checked: Hack happened July 2024, ~$230M gone INR withdrawals opened in phases, then a chunk stayed frozen "due to investigations" Singapore court approved”
“1.7% is interesting, but the definition of new to defi still depends heavily on that four protocol reference set. the stronger signal may be what happens after 30 and 90 days. if those $8 wallets graduate from memecoins into swaps, lending, or stablecoin balances, it is onboarding. if not, it was a campaign with very good address generation.”
“good breakdown. the part about vault risk is what most people gloss over, they see the morpho name and think it's all the same safety net but it's really not. each vault is its own little gamble on the curator's judgment. i'd weight curator quality above almost everything else for morpho specifically. the immutable core is nice but if some vault manager decides to chase yield into a market with sketchy collateral and thin liquidity, that core isn't gonna save you. aave and co”
“I wrote a user- and investor-focused review of Morpho, covering Morpho Blue, MetaMorpho vaults, fund flows, privileged controls, revenue, and failure modes. This is a protocol snapshot, not a full security audit. My conclusion is moderate risk : Strength: Morpho Blue is an immutable, non-upgradable lending primitive. Governance cannot rewrite deployed markets or pause withdrawals in the core. Core trade-off: The minimal design reduces admin risk, but each isolated market carries its own oracle,”
“Respectfully, that is not a fair characterization. The list includes summer.fi , Raydium, Curve, Gnosis Pay, Gravity Bridge, Stake DAO, Polymarket, Thorchain, Kelp, Drift, Aave, Moonwell, Aperture, Yearn, Euler, Balancer, Silo, ... I got a third of the way down the list. Point is, many of those protocols have been around for years, had hundred of millions or billions in TVL, had respectable teams, were not anonymous, had VC funding, top tier audits, etc, and still got hacked. So no, I don't”
“This is exactly why "don't trust, verify" became one of crypto's core principles”
“right, it is not DeFi contracts. But it does not change the argument, the system as strong as its weakest part.”
“kelp dao was crazy but not really defi. it was their multisig setup and the human mistake. the whole idea of deifnis removing those points of failure. the thing that kelp exposed was the contagion something like this could have ok big protocols like aave, and that's something aave should fix with isolated vaults, but don't think it's an existential risk for them. even without a recovery they'd would have had a really small percentage of bad debt, which is obviously not great, but”
“The main plague of DeFi is the trustless operating model - it's inherently prone to breaches. Take the recent Kelp DAO hack. My question is: how is it even possible for someone to show up, mint 300M almost instantly, withdraw it, move it to another protocol, use it as collateral, borrow against it, and instantly withdraw again? 300M is not small money, even for the big protocols. There should be brakes, cooldown periods. As long as instant, trustless withdrawals of sums that size are possibl”
“The world's best hackers have been trying to break them and failing. https://defillama.com/hacks There is, right now, $73B TVL in DeFi, total. According to the list above, there have been hacks to the sum total of $16.7B. That is an insane %. DeFi's fault, of many, has always been that it's impossible to retain a portfolio long term and avoid a portion of it go up in smoke one day. Even if you size conservatively and not leave over 5% of your portfolio in any one place, do your due d”
“Same thoughts here. Like, most of the op never reply to the posts. Karma farming or grooming for scams prob.”
“wrote this post elsewhere a few weeks ago, would love to read different opinions on AI and defi security. The consensus right now is that DeFi is too risky, that everyone should get their money out, that yields should be 4x higher to compensate. That may be true in the short term, nobody knows how capable these new AI models really are, and if attackers get first-mover access, it could get ugly. I'm not here to tell anyone to keep their money in DeFi during this period of uncertainty, especi”
“Drift Protocol has opened up for some of the insurance claims from the hack that happened a while back. They also rebranded to Velocity Exchange. https://x.com/VelocityDEX/status/2074517868041957380 submitted by /u/BartAfterDark [link] [comments]”
“Your error was storing bitcoins on a computer connected to Internet. Windows is a nest of viruses (actually, Windows itself is a virus, but that's another problem) When you set up your trustwallet seed, the virus saved it and sent it to the virus creator, who just waited for you to fund the wallet before emptying it. You need a cold wallet. That can either be a hardware wallet from a reputable brand, or a software wallet on a computer/phone that never sees the Internet. I hope you only lost”
“The problem isn't people not using hardware wallet. But if someone connects to web 3 with it, it still vulnerable”
“The downside is that you can lose it in the old fashioned way, which i almost certainly would. Remember that scene in Silicon Valley where they're desperately searching for the hardware wallet in the pair of trousers in the landfill 😂”
“Why is this openly allowed. How is this even legal? They're making thousands rugging people on memecoins. submitted by /u/mannythomson [link] [comments]”
I worked on trust wallet years ago with Victor. It’s open source
“Total bullshit, again some people trying to build a narrative to sell some future for some crypto that makes no sense. This will never happened.”
“For the next few years cycle, I can see a large portion of DeFi dying off. Only protocols with true PMF and demand will survive. Assuming Clarity Act passes, only top infrastructure will survive. imo it's fixed yield venues like Pendle that will attract institutions, lending and borrowing and perps. Who are your winners and losers? submitted by /u/Chads_ [link] [comments]”
“The main problem with cryptography is not the crypto use case. If SHA and other classical algos get(when) obliterated by qc then I'm pretty sure wise guys will develop or enhance existing qc resistant algos.”
Exactly.. crypto is just a casino and a scam, BTC and ETH included.
“The casino analogy is accurate, but I think the bigger issue is time horizon. Most people evaluate a protocol over a week and ignore whether it's still functioning the same way six months after a stress event.”
“Green candles lie. 🩸 You are cheering for $64,000. But deep inside the blockchain, the "diamond hands" just quietly bled $280 million in a single day. They want you to think the bottom is in. The data says otherwise. Is this a true reversal, or the ultimate bull trap? Don't become someone else's exit liquidity. Uncover the hidden truth behind the $64K illusion. 👇 submitted by /u/sylsau [link] [comments]”
“The bottleneck is pure latency and infra risk. Most oracles can’t pull real-time feeds for TradFi assets without getting manipulated, and settling that volatility on-chain without institutional clearing houses is a systemic nightmare for LPs. Until data scales, it's just a crypto-only casino”
