<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Blockchain Breaches</title>
    <link>https://www.blockchainbreaches.com</link>
    <description>Latest blog posts from Blockchain Breaches</description>
    <language>en</language>
    <lastBuildDate>Sun, 24 May 2026 16:18:37 GMT</lastBuildDate>
    <atom:link href="https://www.blockchainbreaches.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Wasabi Protocol Deployer EOA Compromise</title>
      <link>https://www.blockchainbreaches.com/breaches/wasabi-protocol-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/wasabi-protocol-2026</guid>
      <description>Wasabi Protocol&apos;s perp vaults across Ethereum, Base, Berachain and Blast lost $5M when a compromised deployer EOA with sole ADMIN_ROLE allowed UUPS upgrades.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Volo Sui Admin Key Social Engineering</title>
      <link>https://www.blockchainbreaches.com/breaches/volo-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/volo-2026</guid>
      <description>Volo Protocol&apos;s Sui vaults lost $3.5M after social engineering compromised the admin key. The team froze $500K in 30 minutes and blocked a $2.1M WBTC bridge.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>KelpDAO rsETH LayerZero Bridge</title>
      <link>https://www.blockchainbreaches.com/breaches/kelpdao-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/kelpdao-2026</guid>
      <description>$292M unbacked rsETH minted after attackers exploited KelpDAO&apos;s 1-of-1 LayerZero DVN setup; the largest DeFi hack of 2026, with TVL falling $13B after.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Rhea Finance Two-Day Margin Drain</title>
      <link>https://www.blockchainbreaches.com/breaches/rhea-finance-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/rhea-finance-2026</guid>
      <description>Rhea Finance on NEAR lost $18.4M after a two-day setup of fake tokens, 423 wallets and 8 Ref pools exploited a slippage-summing flaw in margin trading.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Hyperbridge MMR Proof Bypass</title>
      <link>https://www.blockchainbreaches.com/breaches/hyperbridge-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/hyperbridge-2026</guid>
      <description>1B bridged DOT minted on Hyperbridge after a missing bounds check in VerifyProof let an attacker forge MMR proofs; realised loss ~$2.5M.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Drift Protocol Durable-Nonce Hijack</title>
      <link>https://www.blockchainbreaches.com/breaches/drift-protocol-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/drift-protocol-2026</guid>
      <description>DPRK social-engineers tricked Drift Security Council members into blind-signing durable-nonce txs that handed over admin control, draining $285M on Solana.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Resolv USR Stablecoin Cloud-KMS Drain</title>
      <link>https://www.blockchainbreaches.com/breaches/resolv-labs-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/resolv-labs-2026</guid>
      <description>Resolv Labs lost $25M after attackers compromised its AWS KMS keys; a $100K USDC deposit minted 50M USR and depegged the stablecoin 74% in 17 minutes.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Solv BRO Double-Mint Exploit</title>
      <link>https://www.blockchainbreaches.com/breaches/solv-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/solv-2026</guid>
      <description>Solv Protocol&apos;s BRO vault lost $2.73M when an ERC-3525 double-mint bug let the attacker turn 135 BRO into ~567M BRO over 22 deposits, then swap for 38 SolvBTC.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Venus Protocol Phishing Liquidation</title>
      <link>https://www.blockchainbreaches.com/breaches/venus-protocol-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/venus-protocol-2026</guid>
      <description>A Venus Protocol user was phished into delegating account control, losing ~$3.7M from their supplied position. Venus contracts were never compromised.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>IoTeX ioTube Bridge Key Compromise</title>
      <link>https://www.blockchainbreaches.com/breaches/iotex-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/iotex-2026</guid>
      <description>$4.3M drained from IoTeX&apos;s ioTube bridge via a validator key compromise; attacker also minted 111M CIOTX and 9.3M CCS. IoTeX pledged full user compensation.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Moonwell Oracle Decimals Mismatch</title>
      <link>https://www.blockchainbreaches.com/breaches/moonwell-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/moonwell-2026</guid>
      <description>~$1.78M drained from Moonwell on Base after a newly listed market used a price feed with a decimals mismatch, mis-valuing collateral so attackers borrowed out.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>YieldBlox Stellar Single-Trade Oracle</title>
      <link>https://www.blockchainbreaches.com/breaches/yieldblox-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/yieldblox-2026</guid>
      <description>YieldBlox&apos;s Stellar lending pool lost $10.2M after a single USTRY-for-USDC sell at 501x market rate defined the Reflector oracle price in a quiet 15-min window.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Step Finance Treasury Drain</title>
      <link>https://www.blockchainbreaches.com/breaches/step-finance-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/step-finance-2026</guid>
      <description>Step Finance lost 261,854 SOL ($27M) from treasury and fee wallets to a &apos;sophisticated&apos; actor. STEP fell 96%; Step, SolanaFloor and Remora all shut down.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Makina MachineShareOracle Drain</title>
      <link>https://www.blockchainbreaches.com/breaches/makina-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/makina-2026</guid>
      <description>$4.13M extracted from Makina&apos;s DUSD/USDC Curve pool via flash-loan oracle manipulation against MachineShareOracle; white-hat talks recovered 89% in a week.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SagaEVM Ethermint Mint Bypass</title>
      <link>https://www.blockchainbreaches.com/breaches/saga-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/saga-2026</guid>
      <description>SagaEVM lost $7M in 11 minutes when an Ethermint bug let crafted messages bypass validation, minting Saga Dollar (D) without collateral and bridging to ETH.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>TMXTribe Reward Exploit</title>
      <link>https://www.blockchainbreaches.com/breaches/tmxtribe-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/tmxtribe-2026</guid>
      <description>TMXTribe, a staking/rewards protocol, lost ~$1.4M when a distribution accounting flaw let an attacker repeatedly over-claim, draining the reward reserve.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sun, 18 Jan 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Truebit Integer Overflow</title>
      <link>https://www.blockchainbreaches.com/breaches/truebit-2026</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/truebit-2026</guid>
      <description>Truebit lost $26.4M when an integer overflow in TRU&apos;s five-year-old bonding-curve contract let the attacker mint TRU near-free and sell back for 8,500 ETH.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Aevo Legacy Ribbon DOV Oracle Drain</title>
      <link>https://www.blockchainbreaches.com/breaches/aevo-2025</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/aevo-2025</guid>
      <description>An oracle upgrade created an 18-vs-8 decimal precision mismatch in Aevo&apos;s legacy Ribbon DOV vaults, draining $2.7M. Aevo shut down vaults hours later.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>USPD Stablecoin Mint Bug</title>
      <link>https://www.blockchainbreaches.com/breaches/uspd-2025</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/uspd-2025</guid>
      <description>USPD, a newer decentralized stablecoin, lost ~$1M via a mint/collateral flaw that allowed minting against insufficient backing, briefly depegging the token.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Yearn yETH Infinite Mint</title>
      <link>https://www.blockchainbreaches.com/breaches/yearn-2025</link>
      <guid isPermaLink="true">https://www.blockchainbreaches.com/breaches/yearn-2025</guid>
      <description>Yearn&apos;s yETH StableSwap pool minted 235 septillion yETH from a 16-wei deposit after a liquidity removal reset supply to zero but left cached virtual balances.</description>
      <author>Blockchain Breaches</author>
      <pubDate>Sun, 30 Nov 2025 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>