Revoke.cash logo

Approval Hacks & Exploits

Over $355M stolen since 2020.

When you approve a token on a dapp, you're trusting that contract with access to your funds. If that contract gets exploited, attackers can use your approval to steal everything you approved. The exploits below have done exactly that. Check if you're affected.

Multichain Exploit Checker

Check your address against all known exploits across all networks at once with Revoke Premium.

Upgrade to Premium

Magic Eden / Limit Break Hack

24 Sep 2026
$2.8M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Robinhood Chain Logo
Berachain Logo
ApeChain Logo

At least $2.8M has been stolen from users of Limit Break's Payment Processor, the NFT trading protocol Magic Eden used in 2024. A flaw lets attackers act on behalf of any wallet that approved it, taking NFTs and tokens like WETH. Attacks are ongoing on several chains, while a whitehat rescue moved over 23,000 NFTs to safety. Anyone who approved Payment Processor V2 or V3 on any chain should revoke.

Lien Finance Hack

24 Jul 2026
$540k stolen
Ethereum Logo

Around $542k in USDC was stolen from liquidity providers of Lien Finance, an abandoned 2020-era DeFi protocol on Ethereum, on 24 July 2026. Its contracts were still live and unpatched. The attacker created fake bonds that Lien's trading pools massively overvalued, then swapped them for USDC that liquidity providers had approved to those pools. Anyone with approvals to Lien Finance's pools should revoke them.

BarnBridge Governance Attack

15 Jul 2026
$780k stolen
Ethereum Logo

About $777k in USDC was stolen from users of BarnBridge, a DeFi protocol on Ethereum that shut down in 2023. On 15 July 2026, an attacker cheaply bought control of the abandoned project's DAO and passed a malicious proposal giving them control over its SMART Yield contracts, then drained USDC from wallets with leftover approvals. Anyone who ever used BarnBridge should revoke all approvals to it.

Bitmor Hack

25 May 2026
$7k stolen
Base Logo

About $7k was stolen from users of Bitmor, a Bitcoin-focused DeFi platform on Base, on 25 May 2026. Attackers took over an admin wallet for Bitmor's DCA feature, which made regular Bitcoin purchases for users, and swapped the Uniswap router it traded through for a malicious contract. That contract drained approved USDC from users with active DCA plans. Anyone who approved Bitmor's DCA contract should revoke that approval.

Ekubo Hack

5 May 2026
$1.42M stolen
Ethereum Logo
Arbitrum Logo

Close to $1.42M was stolen from users of Ekubo, a DEX that started on Starknet and expanded to Ethereum and Arbitrum. A bug in Ekubo's gas-optimized swap routers let attackers spend the token approvals of anyone who had approved them. Liquidity providers and Starknet were unaffected. The routers cannot be fixed, so anyone who approved them should revoke. Ekubo published a post-mortem and a plan to reimburse victims.

CoW Swap DNS Hijack

14 Apr 2026
$1.2M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Polygon Logo
Gnosis Chain Logo
Plume Logo
Gravity Alpha (Unsupported) Logo

On 14 April 2026, attackers hijacked the cow.fi domain of DEX aggregator CoW Swap through social engineering of its registrar and the .fi registry. For several hours, visitors were sent to a fake site that drained about $1.2M through malicious approvals and signatures and also tried to steal seed phrases. Our list of attacker addresses may be incomplete, so check any approvals made on 14 April 2026.

GONDI Hack

9 Mar 2026
$230k stolen
Ethereum Logo
HyperEVM Logo

Roughly $230k in NFTs was stolen from users of GONDI, an NFT lending protocol, on 9 March 2026. A flaw in its recently updated Purchase Bundler contract let an attacker take NFTs from wallets that had approved it, unless those NFTs were locked in an active loan. GONDI disabled the affected feature and is working to make users whole. Anyone who approved its Purchase Bundler contracts should revoke.

Aperture Finance Hack

25 Jan 2026
$3.7M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Unichain Logo
Scroll Logo
Manta Pacific Logo

On 25 January 2026, attackers stole about $3.7M from users of Aperture Finance, an AI-powered platform for managing liquidity positions on decentralized exchanges. A flaw in some of its contracts let anyone spend the token approvals and Uniswap LP position (NFT) approvals that users had granted them. Only certain parts of Aperture's platform were affected, so anyone who has used Aperture Finance should check whether they are affected and revoke.

SwapNet Hack

25 Jan 2026
$13.43M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Polygon Logo
Monad Logo
Plasma Logo
Katana Logo
Unichain Logo
Blast Logo
HyperEVM Logo

About $13.4M was stolen from users of SwapNet, a DEX aggregator built into the Matcha Meta trading app, on 25 January 2026. A flaw let an attacker spend approvals that users had granted directly to SwapNet after turning off Matcha's default one-time approval. SwapNet paused its contracts, and Matcha removed SwapNet and the setting. SwapNet can switch its contracts back on, so anyone who approved them directly should revoke.

Thirdweb Bridge Hack

9 Dec 2025
$34k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Polygon Logo
Unichain Logo

About $34k in USDC was stolen through an old version of thirdweb's Bridge contract. On 10 April 2025 thirdweb found and patched a flaw that let anyone spend the token approvals given to the bridge, but a legacy deployment of the same code was left running. That contract was drained in three transactions between April and December 2025 before thirdweb disabled it. Anyone who approved either deployment should revoke.

402bridge Hack / Rug Pull

27 Oct 2025
$21k stolen
Base Logo

Malicious actors stole about $21k in USDC from users of 402bridge, a payment protocol on Base built on Coinbase's x402 standard. On 28 October 2025, the team said its admin private key had leaked, letting attackers take over the contract and pull USDC from any wallet that had approved it. Limited communication from the team has fueled speculation that this was a rug pull. Anyone who approved 402bridge should revoke.

dTRINITY dLEND Hack

28 Sep 2025
$56k stolen
Sonic Logo
Fraxtal Logo

Attackers stole $56k through dLEND, the lending product of dTRINITY, on Fraxtal and Sonic on 28 September 2025. A flaw in its collateral swap contracts let anyone use the approvals that wallets had given these contracts to take their dLEND deposits. According to dTRINITY, the stolen funds belonged only to its own team members. The swap feature was removed from the website, but anyone who approved these contracts should revoke.

Kame Aggregator Hack

12 Sep 2025
$360k stolen
Sei Logo

Over $1.3M was stolen from users of Kame Aggregator, a token swap aggregator on Sei, on 12 September 2025. A flaw in its swap router let attackers spend the tokens of anyone who had approved it. The main attacker returned most of the funds for a 20% bounty and whitehats recovered $22k, leaving about $360k with the attackers. Kame offered full reimbursement, and anyone who approved the router should revoke.

Arcadia Finance Hack

15 Jul 2025
$3.6M stolen
Base Logo

Around $3.6M was stolen from users of Arcadia Finance, a DeFi protocol on Base, on 15 July 2025. Attackers abused a flaw in its optional automation services, which rebalance and compound liquidity positions. Because these automations could also pull tokens that users had approved to their own Arcadia Accounts, Arcadia advised all users to revoke those token approvals and to disable any active automations.

Bankroll Network Hack

19 Jun 2025
$35k stolen
Ethereum Logo
BNB Chain Logo

About $35k was stolen on 19 June 2025 from wallets that still had approvals to old Bankroll Network contracts on Ethereum and BNB Chain. A math bug in the contracts' dividend bookkeeping let an attacker pull tokens from any wallet that had approved them. The project was abandoned years ago, but its contracts are still live, so anyone who ever used Bankroll Network should revoke.

Moby Trade Hack

8 Jan 2025
$1.9M stolen
Arbitrum Logo

About $1.9M was lost by users of Moby Trade, an options trading platform on Arbitrum, on 8 January 2025. An attacker stole an admin key and replaced Moby's contracts with malicious versions, draining its pools and taking tokens straight from wallets that had approved them. A whitehat rescued part of the funds, but the attacker still controls the contracts, so anyone who approved Moby should revoke.

Orange Finance Hack

7 Jan 2025
$840k stolen
Arbitrum Logo

Over $840k was stolen from users of Orange Finance, a DeFi vault protocol on Arbitrum. Its admin multisig was set up to need only one signature, so a single leaked key let an attacker take over and replace the code of Orange's vault contracts. The attacker emptied the vaults and also took tokens from wallets that had approved them. Anyone who approved Orange Finance vaults should revoke.

Fisclend Rug Pull

3 Jan 2025
$600k stolen
Sonic Logo
World Chain Logo
ApeChain Logo

Around $600k was stolen from users of Fisclend, a lending protocol on ApeChain, World Chain and Sonic that was live for only a few months. On 3 January 2025 the team rug pulled, borrowing out users' deposits against their own worthless FIS token. They later upgraded several market contracts, which they still control, into backdoored versions that can drain token approvals. Anyone who approved Fisclend's contracts should revoke.

Radiant Capital Hack

16 Oct 2024
$60M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo

Around $60M was stolen from Radiant Capital, a cross-chain lending protocol, in October 2024. North Korea-linked hackers used malware on developers' devices to trick them into signing away control of the lending pools on Arbitrum and BNB Chain. Their malicious code drained the pools and began taking tokens from wallets that had approved them. It is still draining wallets, so anyone who approved Radiant on any chain should revoke.

2024 LI.FI Hack

16 Jul 2024
$11.6M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Mantle Logo
Rootstock Logo
Gnosis Chain Logo
Linea Logo
Blast Logo
zkSync Era Logo
Scroll Logo
Celo Logo
Mode Logo
Aurora Logo
Metis Logo
Boba Logo
Fuse Logo
Fantom (Unsupported) Logo
Polygon zkEVM (Unsupported) Logo
Moonbeam (Unsupported) Logo
Moonriver (Unsupported) Logo

Roughly $11.6M was stolen on 16 July 2024 from users of LI.FI, a cross-chain bridge and DEX aggregator. A newly added part of the LI.FI contract let attackers use the token approvals of wallets that had given LI.FI unlimited approvals. LI.FI removed the vulnerable part on all chains within hours, so remaining approvals can no longer be exploited through this bug.

WINR Hack

31 May 2024
$11k stolen
Arbitrum Logo

Around $11k in WINR tokens was stolen from users of WINR Protocol (JustBet), a gaming protocol on Arbitrum. Its MixedSwapRouter let the caller name which wallet should pay for a swap, without checking that the caller was a real trading pool. An attacker used a fake pool to make it pull tokens from wallets that had approved the router. Anyone who approved the WINR MixedSwapRouter should revoke.

Magpie Hack

23 Apr 2024
$130k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Blast Logo
zkSync Era Logo
Manta Pacific Logo
Polygon zkEVM (Unsupported) Logo

About $130k was stolen from users of Magpie, a cross-chain DEX aggregator now called Fly, on 23 April 2024. A flaw in its router contracts let an attacker disguise a transfer command so it slipped past a safety check, taking tokens from wallets that had approved the routers. Magpie shut the routers down and reimbursed affected users. Anyone who still has approvals to these old routers should revoke.

Rico Credit System Hack

20 Apr 2024
$45k stolen
Arbitrum Logo

Around $45k was stolen from Rico Credit System, a stablecoin protocol on Arbitrum, and its users on 20 April 2024. A flaw in its main contract let an attacker make it move tokens out of wallets that had approved it, on top of draining the funds the protocol itself held. The team turned off its website after the attack. Anyone who approved the Rico contract should revoke.

Merkle Trade Hack

18 Apr 2024
$20k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo

About $20k was stolen from users of Merkle Trade, a perpetual futures exchange, after it launched a new Swap & Deposit feature on EVM chains on 18 April 2024. The feature's contract let anyone move tokens that users had approved to it. Merkle Trade switched back to its older contract and promised full reimbursement, but the new contract cannot be paused, so anyone who used the feature should revoke.

Dolomite Hack

20 Mar 2024
$180k stolen
Ethereum Logo

Over $1.8M was stolen on 20 March 2024 from users of an old version of Dolomite, a DeFi exchange and lending protocol. The attacker abused a flaw in a discontinued 2019 contract on Ethereum to drain wallets that still had approvals to it. Dolomite suspended the contract within an hour and recovered 90% of the funds from the attacker, then used its treasury to cover the remaining $180k.

ParaSwap Hack

20 Mar 2024
$324k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Fantom (Unsupported) Logo

About $324k was lost by users of ParaSwap (now Velora) after a flaw was found in its new Augustus V6 swap contract on 20 March 2024. The flaw let anyone take tokens from wallets that had approved it. ParaSwap and whitehats rescued most at-risk funds, and a ParaSwap DAO grant refunded affected users. The flawed contract still exists on several chains, so anyone who approved Augustus V6 should revoke.

Unizen Hack

8 Mar 2024
$3.2M stolen
Ethereum Logo

About $3.6M was drained from wallets that had approved Unizen, a cross-chain DEX aggregator, and attackers kept around $3.2M of it. A contract upgrade on 8 March 2024 introduced a flaw that let anyone move tokens out of those wallets. Unizen rolled back the upgrade about eleven hours later, so the flaw is fixed, and it reimbursed affected users with the help of an interest-free personal loan from its CEO.

Seneca Hack

28 Feb 2024
$1.3M stolen
Ethereum Logo
Arbitrum Logo

An attacker drained about $6.4M from wallets that had approved Seneca, a stablecoin protocol on Ethereum and Arbitrum. After Seneca offered a 20% bounty, the attacker returned roughly 80% and kept around $1.3M. A flaw in Seneca's Chamber contracts let anyone spend the tokens that users had approved to them. The contracts cannot be upgraded or paused, so any remaining approval is still exploitable and should be revoked.

Concentric Hack

22 Jan 2024
$1.7M stolen
Arbitrum Logo

Over $1.7M was stolen from users of Concentric, a liquidity management protocol on Arbitrum. Attackers tricked a team member into installing malware, stole the key to the protocol's admin wallet and used it to replace the code of Concentric's vault contracts. They drained the vaults and then used the new code to take tokens from wallets that had approved them. Anyone who approved Concentric's vaults should revoke.

Socket Hack

16 Jan 2024
$1M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo

About $3.3M was stolen on 16 January 2024 from wallets with token approvals to Socket, the cross-chain bridge technology behind Bungee Exchange. A faulty feature added three days earlier let an attacker drain them. Socket switched it off within about 15 minutes, so the flaw can no longer be used. The attacker later returned 1,032 ETH, keeping roughly $1M, and Socket covered the rest for affected users.

Liquid Crypto Hack

10 Jan 2024
$2k stolen
Ethereum Logo
BNB Chain Logo
Avalanche Logo
Mantle Logo

About $2k was stolen from users of Liquid Crypto (LQDX), a multichain liquidity protocol, on 10 January 2024. Its zap contracts let anyone make a deposit on behalf of any wallet that had approved them, pulling that wallet's tokens into a Liquid Crypto pool without its consent. Liquid Crypto deployed new contracts but left the old zaps in place, so any approvals to them should be revoked.

Floor Protocol Hack

17 Dec 2023
$1.6M stolen
Ethereum Logo

About $1.6M worth of NFTs, mostly Bored Apes and Pudgy Penguins, was stolen on 17 December 2023 from users of Floor Protocol, an NFT fractionalization platform. A flaw in one of its helper contracts let an attacker take NFTs that users had approved to the protocol. The team patched the contract within hours, stopping losses that could have been over 10 times larger, so this issue is fixed.

NFT Trader Hack

16 Dec 2023
$600k stolen
Ethereum Logo

Close to $3M worth of NFTs, mostly Bored Apes and Mutant Apes, was stolen from users of the peer-to-peer platform NFT Trader through a bug in its old contracts. Most of the apes were returned after Yuga Labs and Boring Security DAO negotiated a bounty, but attackers kept around $600k, including over 113,000 ApeCoin and some NFTs. Anyone who approved NFT Trader's old contracts should revoke.

Ledger Connect Kit Hack

14 Dec 2023
$610k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo

Around $610k was stolen from users of many crypto websites like SushiSwap and Revoke.cash on 14 December 2023, and Tether froze about $27k of it. Attackers slipped wallet-draining code into Ledger Connect Kit, a code library these sites used to support Ledger wallets. Ledger pledged to reimburse affected users. Some listed addresses are generic drainer infrastructure, so a match does not always mean you were affected.

Unibot Hack

31 Oct 2023
$640k stolen
Ethereum Logo

About $640k of tokens was drained on 31 October 2023 from wallets that had approved a new router contract of Unibot, a Telegram trading bot. A flaw let anyone make the router move tokens out of those wallets. Unibot halted trading on it after about nine hours and refunded affected users from its own funds, but the router was abandoned rather than fixed, so any remaining approvals should be revoked.

Maestro Hack

24 Oct 2023
$500k stolen
Ethereum Logo

Over $500k was stolen from users of Maestro, an automated Telegram trading bot, on 24 October 2023. A new version of its router contract had a flaw that let anyone make it move tokens out of wallets that had approved it. Maestro fixed the router within 30 minutes by upgrading it and refunded all affected users in full. The router is safe to use again, so revoking is not necessary.

Galxe Frontend Hack

6 Oct 2023
$270k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Celo Logo
Fantom (Unsupported) Logo

Over $270k was stolen from users of Galxe, a popular Web3 community building platform, on 6 October 2023. Attackers tricked Galxe's domain registrar into handing over its domain, then pointed the Galxe website to a fake copy that asked visitors to approve their tokens to the attackers. Galxe later refunded affected users. Anyone who approved something on the Galxe website that day should check and revoke those approvals.

CivTrade Hack

8 Jul 2023
$270k stolen
Ethereum Logo
Polygon Logo

Over $270k was stolen from users of CivTrade, CivFund's platform for limit orders on Uniswap V3, on 8 July 2023. Functions that should have been restricted could be called by anyone, which let attackers pull approved tokens from users' wallets in two waves that day. CivFund paused the CivTrade contracts and never relaunched the product. Anyone with approvals to CivTrade should revoke them.

Biswap v3 Migrator Hack

30 Jun 2023
$865k stolen
BNB Chain Logo

About $865k was stolen from liquidity providers of Biswap, a decentralized exchange on BNB Chain, on 30 June 2023. A flaw in the migrator contracts Biswap released to help users move liquidity from its v2 to its new v3 let attackers abuse users' approvals to steal their liquidity. Biswap fully compensated affected users in July 2023, but anyone who approved the migrators should still revoke.

Unagii Hack

28 Jun 2023
$60k stolen
Ethereum Logo

About $58k was stolen from users of Unagii, a DeFi yield platform, on 28 June 2023. A helper contract for its WETH vault did not check who was allowed to withdraw, so anyone could cash out other users' vault shares. The team used the same flaw to rescue about $94k of at-risk funds and reimbursed affected users. The contract was never fixed, so anyone who used it should revoke.

Hashflow Hack

14 Jun 2023
$40k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Avalanche Logo
Polygon Logo

About $40k was stolen from users of decentralized exchange Hashflow through old contracts it had already retired, which let anyone move tokens from wallets that still approved them. On 14 June 2023 a whitehat hacker first rescued over $600k so owners could claim it back, but blackhat hackers took more afterwards. The old contracts remain vulnerable, so revoke any approvals to them before claiming rescued funds.

Atlantis Loans Hack

10 Jun 2023
$2.5M stolen
BNB Chain Logo
Polygon Logo

Over $2.5M was stolen from users of Atlantis Loans, a lending protocol on BNB Chain abandoned by its team in April 2023. An attacker passed a malicious governance proposal in June 2023 that put backdoors into several of its contracts, then used them to drain tokens from wallets that had approved them. The same attack hit its Polygon deployment a month later. Anyone with remaining approvals should revoke them.

SushiSwap Hack

9 Apr 2023
$1.7M stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Gnosis Chain Logo
Arbitrum Nova Logo
Boba Logo
Fuse Logo
Fantom (Unsupported) Logo
Moonbeam (Unsupported) Logo
Moonriver (Unsupported) Logo
Polygon zkEVM (Unsupported) Logo

Over $3.3M was drained from SushiSwap users in April 2023, of which the attacker and the bots that copied them ultimately kept about $1.7M. A flaw in SushiSwap's RouteProcessor2 router let anyone make it pull tokens out of any wallet that had approved it. The router was deployed on 14 chains and cannot be paused or fixed, so Sushi replaced it. Anyone with a remaining approval should revoke.

Harvest Keeper Rug Pull

17 Mar 2023
$930k stolen
Ethereum Logo
BNB Chain Logo
Polygon Logo

Over $930k was stolen by Harvest Keeper, a supposedly AI-powered trading platform, from its own users in March 2023. Besides running off with around $710k in deposits, the scammers used approvals that users had given them to drain around $219k in tokens on BNB Chain, Ethereum and Polygon. The project turned out to be a scam, so anyone who approved the listed address should revoke.

BSCex Hack

27 Feb 2023
$7.8M stolen
BNB Chain Logo

Over $7.8M was stolen from users of BSCex SwapX, a decentralized exchange on BNB Chain that later rebranded to LaunchZone. A flaw in four of its old contracts let anyone spend the tokens users had approved to them. The first drain happened on 27 February 2023, the other contracts were hit in the following weeks, and smaller drains have continued for years. Anyone with approvals to them should revoke.

Revert Finance Hack

18 Feb 2023
$30k stolen
Ethereum Logo
Arbitrum Logo
Optimism Logo
Polygon Logo

About $30k was stolen from users of Revert Finance, a Uniswap V3 liquidity management tool, on 18 February 2023. Its V3Utils contract let the caller choose which contract it would send swap instructions to, so an attacker could make it spend the token approvals users had given it. Revert reimbursed affected users, but V3Utils cannot be paused or patched and is still exploitable, so anyone who approved it should revoke.

Dexible Hack

17 Feb 2023
$2M stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo

Over $2M was stolen from users of Dexible, a multi-chain DEX aggregator, on 17 February 2023. A flaw in its newest contracts let the attacker choose where Dexible sent a trade, so they sent it to token contracts and took the funds users had approved. Funds were only drained on Ethereum and Arbitrum, but Dexible urged users to revoke on all six chains where the contract was deployed.

Rubic Hack

25 Dec 2022
$1.51M stolen
Ethereum Logo

About $1.5M was stolen from users of Rubic, a cross-chain DEX aggregator, on 25 December 2022. Rubic had added the USDC token to its list of trusted swap routers, which let an attacker make Rubic's contracts move USDC out of wallets that had approved them. Rubic paused the contracts and compensated users, but they were never repaired and unpausing would reopen the flaw. Anyone who approved these contracts should revoke.

Polynomial Protocol Hack

18 Nov 2022
$7k stolen
Optimism Logo

Around $7k in USDC was stolen from users of Polynomial Protocol, a derivatives platform on Optimism, in November 2022. A helper contract that swapped and deposited tokens in one step did not check its swap instructions, so attackers could use it to spend its users' approvals. Polynomial removed it from its website and reimbursed affected users, but anyone who approved the old contract should still revoke.

Brahma Hack

9 Nov 2022
$90k stolen
Ethereum Logo

Around $90k of USDC was stolen from users of Brahma, a DeFi vault protocol, on 9 November 2022. The Zapper contract used to deposit into Brahma's TopGear vault did not check the instructions it was given, so the attacker could make it pull USDC from any wallet that had approved it. Anyone who approved Brahma's TopGear Zapper should revoke that approval.

BitKeep Swap Hack

17 Oct 2022
$1.1M stolen
BNB Chain Logo
Polygon Logo

About $1.1M was stolen from users of BitKeep Wallet, now called Bitget Wallet, on BNB Chain and Polygon. A weakness in its BitKeep Swap contracts let an attacker use the token approvals users had given them, often unlimited, to drain those tokens from their wallets. BitKeep suspended the swap service and reimbursed affected users. Anyone who still has approvals for the old BitKeep Swap contracts should revoke them.

Rabby Swap Hack

11 Oct 2022
$200k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Gnosis Chain Logo
Celo Logo
Aurora Logo
Arbitrum Nova Logo
Metis Logo
Astar Logo
Boba Logo
Fantom (Unsupported) Logo
Cronos (Unsupported) Logo
Harmony (Unsupported) Logo
Moonbeam (Unsupported) Logo
Kaia (Unsupported) Logo
HECO (Unsupported) Logo

About $200k was stolen from users of Rabby, a multi-chain wallet from the DeBank team, on 11 October 2022. The contract behind Rabby's new Swap feature carried out any instructions a caller gave it, so an attacker used it to pull tokens from wallets that had approved it. Rabby reimbursed affected users, but the contract was never fixed and exists on 19 chains, so past Rabby Swap users should revoke.

Transit Swap Hack

1 Oct 2022
$5M stolen
Ethereum Logo
BNB Chain Logo

About $5M was lost by users of Transit Swap, a cross-chain DEX aggregator on Ethereum and BNB Chain, in October 2022. A flaw let anyone spend the approvals that wallets had given it, and an attacker drained about $24M before most of it was handed back and refunded. The contracts were switched off rather than repaired and could be switched back on, so anyone who approved Transit Swap should revoke.

Celer Frontend Hack

17 Aug 2022
$240k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Aurora Logo
Metis Logo
Astar Logo
Fantom (Unsupported) Logo

About $240k was stolen from users of Celer's cBridge on 17 August 2022. Hackers hijacked internet routing (BGP) for a server behind cBridge's website, so visitors were shown a fake version that asked for unlimited token approvals to the hackers' contracts. Celer's own contracts were not affected, and Celer pledged to fully compensate affected users. Anyone who approved the hackers' contracts should revoke.

Curve Frontend Hack

9 Aug 2022
$610k stolen
Ethereum Logo

About $610k was stolen from users of the decentralized exchange Curve on 9 August 2022. Hackers hijacked the DNS records for curve.fi and sent visitors to a copy of the site that asked them to approve a malicious contract, which then drained their tokens. Curve's own smart contracts were not affected. Anyone who approved a contract through curve.fi that day should revoke approvals to the attacker's contract.

PREMINT Frontend Hack

17 Jul 2022
$400k stolen
Ethereum Logo

Over $400k worth of NFTs was stolen from users of PREMINT, a popular NFT registration platform, on 17 July 2022. Hackers injected malicious code into its official website, which showed a fake wallet verification prompt that actually gave the hackers' wallets control over users' NFTs. PREMINT reimbursed affected users, but many victims still have active approvals to the attackers' wallets and should revoke them.

Quixotic Hack

1 Jul 2022
$150k stolen
Optimism Logo

Around $150k in tokens was stolen from users of Quixotic, an NFT marketplace on Optimism, on 1 July 2022. A flaw in its exchange contract let an attacker name any wallet that had approved it as the buyer of worthless NFTs, paid for with that wallet's approved tokens. The contract was paused within hours and can never be switched back on, so this exploit is over. Quixotic refunded affected users.

Namecheap DNS Hijack

23 Jun 2022
$550k stolen
Ethereum Logo

Over $550k was stolen from users of several popular dapps, including Convex, Ribbon, DeFi Saver and Allbridge, in June 2022. Hackers hijacked these websites' DNS records at domain registrar Namecheap and injected malicious code that asked users to grant unlimited approvals to attacker contracts, many at addresses closely resembling the protocols' real contracts. Anyone who approved one of these contracts should revoke.

BasketDAO Hack

27 Mar 2022
$1.2M stolen
Ethereum Logo

About $1.2M was stolen from users of BasketDAO, a DeFi protocol that bundled several tokens into a single index token. Two of its contracts had flaws that let attackers take tokens from any wallet that had approved them. BasketDAO was already winding down after an earlier exploit in October 2021 and was later absorbed by PieDAO. Drains continued into 2024, so anyone who approved these contracts should revoke.

Auctus Hack

26 Mar 2022
$750k stolen
Ethereum Logo

Over $750k was stolen from users of Auctus, a decentralized options protocol on Ethereum. A flaw in one of its older beta contracts, ACOWriter, let attackers drain tokens from any wallet that had approved it. The main theft happened on 26 March 2022, three days before Auctus disclosed the problem and urged users to revoke, and smaller copycat drains followed. Anyone who ever approved this contract should revoke.

2022 LI.FI Hack

20 Mar 2022
$600k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Gnosis Chain Logo
Fantom (Unsupported) Logo
Moonriver (Unsupported) Logo

Around $600k was stolen from users of LI.FI, a cross-chain bridge and DEX aggregator, on 20 March 2022. A flaw in its new swap feature let an attacker make the LI.FI contract move tokens out of wallets that had approved it. LI.FI fixed the contract the same day by only allowing calls to approved exchanges, and reimbursed affected users. Remaining approvals to this contract are no longer exploitable.

2022 Multichain Hack

17 Jan 2022
$3M stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Avalanche Logo
Polygon Logo
Gnosis Chain Logo
Celo Logo
Telos EVM Logo
IoTeX (Unsupported) Logo
Fantom (Unsupported) Logo

Around $3M was kept by attackers who exploited a bug in the contracts of Multichain (formerly Anyswap), a cross-chain swap router. Roughly $5.5M was drained in total, about half of which was recovered by whitehats and negotiated returns. The vulnerable routers cannot be upgraded and were never patched, and Multichain shut down in 2023, so wallets with leftover approvals are still being drained, most recently in 2026. Anyone who approved them should revoke.

Sorbet Finance Hack

11 Dec 2021
$744k stolen
Ethereum Logo

About $744k was stolen from users of Sorbet Finance, Gelato's app for G-UNI liquidity pools, in December 2021. A flaw in a router contract that users approved through Sorbet let anyone spend those approvals. Gelato rescued about $26M of at-risk funds into an escrow, but attackers beat its bots on some transactions. GEL holders later approved refunds. The router cannot be patched, so remaining approvals to it should be revoked.

BadgerDAO Frontend Hack

2 Dec 2021
$111.1M stolen
Ethereum Logo

Over $120M was stolen from users of BadgerDAO, a DeFi platform for earning yield on Bitcoin, on 2 December 2021. Hackers injected malicious code into its official website that tricked users into granting unlimited token approvals to the hackers' wallet. About $9M was later recovered and returned, leaving around $111M lost. These approvals stay dangerous until removed, so anyone who used Badger's website in late 2021 should revoke.

dYdX Hack

27 Nov 2021
$200k stolen
Ethereum Logo

Hackers stole just over $200k from dYdX users through a new deposit contract that could be tricked into spending the token approvals users had given it. After the bug was reported on 27 November 2021, dYdX rescued about $2M of vulnerable funds into an escrow only their owners can withdraw from and reimbursed the stolen amount itself. Anyone who still has an approval to this contract should revoke it.

bZx Hack

5 Nov 2021
$55M stolen
BNB Chain Logo
Polygon Logo

Over $55M was stolen from DeFi platform bZx and its users in November 2021. Hackers phished a bZx developer and took over the admin keys for its BNB Chain and Polygon deployments, while the separately governed Ethereum deployment was unaffected. They changed the contracts to drain both the protocol and any wallet with active approvals. bZx, later renamed Ooki, approved a compensation plan, but anyone with approvals should revoke.

BasketDAO Peripheral Exploit

24 Oct 2021
$343k stolen
Ethereum Logo

About $343k was stolen from users of BasketDAO, a DeFi protocol for creating token baskets. A flaw in its DelayedBDIBurner contract let an attacker transfer BDI tokens out of any wallet that had approved the contract. BasketDAO disabled its delayed mint and burn modules and pointed users to the main BDI contract instead. Anyone who still has an approval for the DelayedBDIBurner should revoke it.

StableMagnet Rug Pull

23 Jun 2021
$27M stolen
BNB Chain Logo

Over $27M was stolen from StableMagnet, a stablecoin exchange on BNB Chain, by its own developers in June 2021. They hid a backdoor in unverified code linked to the main contract, letting them empty the liquidity pools and drain wallets that had approved it. UK police later arrested two people and seized around $22M, but little of that has been confirmed as returned. Anyone with approvals should revoke.

Zapper Hack

13 Jun 2021
$370k stolen
Ethereum Logo

Around $367k was stolen through Zapper's retired Polygon Bridge contract, which let anyone use the token approvals it still held. Zapper learned of the flaw on 13 June 2021 and rescued at-risk funds itself. A bot copied the rescue and later returned $465k, but a second bot quietly took about $367k over nineteen months. Wallets were still being drained in 2026, so anyone who used Zapper's Polygon Bridge should revoke.

Furucombo Hack

27 Feb 2021
$14M stolen
Ethereum Logo

Over $14M was stolen from users of Furucombo, an app for combining several DeFi actions into one transaction, on 27 February 2021. The attacker tricked Furucombo's main contract into running their own malicious code by passing it off as a new version of Aave, one of its trusted integrations. That code then took the tokens users had approved to Furucombo. Anyone with approvals to this contract should revoke them.

Bancor Hack

18 Jun 2020
$135k stolen
Ethereum Logo

About $135k was taken from users of Bancor, a decentralized exchange, in June 2020. A newly deployed Bancor contract let anyone move tokens out of wallets that had approved it. Bancor's team used the flaw first to move over $400k of at-risk funds to safety, but automated front-running bots copied the rescue and took about $135k. Anyone with approvals to these old contracts should revoke them.