Security incident timeline

What failed is more useful than how loud the headline was.

Filter eight documented events by year, failure family and outcome. Every event remains readable in the HTML when JavaScript is unavailable.

8 incidents shown

Bridge verification

Wormhole · restored/backed

Verification logic allowed unbacked wrapped ETH

Failure: The Solana-side verification path accepted a fraudulent state, enabling 120,000 wrapped ETH to be minted without corresponding collateral.

Containment: The network was halted and the verification vulnerability was fixed.

Outcome: ETH was added so wrapped ETH was again backed one-for-one; this was recapitalization, not an attacker return.

Wormhole incident report
Bridge validators

Ronin · restored/backed

Compromised validator authority approved bridge withdrawals

Failure: The attacker obtained enough validator keys to satisfy the bridge approval threshold.

Containment: The bridge paused while validators, limits and governance controls were redesigned.

Outcome: The rebuilt bridge reopened on 28 June 2022; Ronin said user balances were fully backed and users made whole, with treasury treatment stated separately.

Ronin bridge reopening report
Contract logic

Euler V1 · funds returned

A missing health check enabled self-liquidation

Failure: An interaction involving donateToReserves allowed an attacker to create an unhealthy position and extract value through liquidation.

Containment: The affected V1 system did not simply resume; the team investigated and pursued recovery while rebuilding.

Outcome: Euler said all recoverable funds were returned after negotiation with the exploiter.

Euler Foundation recovery announcement
Software supply chain

Ledger Connect Kit · contained

Malicious package versions reached third-party DApps

Failure: A phished former employee account was used to publish malicious Connect Kit versions that could redirect signed transactions.

Containment: Ledger and partners disabled the rogue path and released genuine version 1.1.8.

Outcome: Ledger hardware and Ledger Live were outside the stated scope; affected-user recovery remained separate from the package fix.

Ledger incident timeline
Contract accounting

Radiant · bad debt repaid

An empty-reserve market exposed liquidity-index behavior

Failure: A newly launched native USDC market on Arbitrum was manipulated with a flash-loan sequence.

Containment: The affected market was paused and reviewed.

Outcome: Communal bad debt was addressed through a DAO repayment plan using project resources, not returned attacker funds.

Radiant January post-mortem
Signer operations

Radiant · recovery ongoing at cutoff

Compromised devices deceived multisig contributors

Failure: Radiant said contributor devices displayed expected data while malicious ownership-changing transactions were signed.

Containment: Affected markets and administrative paths were addressed while investigators examined device compromise.

Outcome: Radiant's 2026 update described recovery as ongoing and uncertain; this card does not claim affected users were made whole.

Radiant recovery-phase update
Signer operations

Bybit · customer assets backed

A compromised signing interface deceived a cold-wallet ceremony

Failure: Preliminary forensics linked the event to compromised Safe developer credentials and malicious interface behavior during a routine transfer.

Containment: Bybit moved funds from Safe-administered addresses and kept withdrawals operating.

Outcome: A later proof-of-reserves report said in-scope customer assets were backed one-for-one; that is not the same as stolen funds returning.

Bybit forensic update
Contract math

Cetus · protocol relaunched

An overflow-check flaw distorted CLMM liquidity

Failure: Cetus reported a flaw in an open-source math library that enabled artificially large liquidity with minimal input.

Containment: Pools and contracts were disabled; Sui validators froze transactions from named attacker addresses.

Outcome: Cetus patched, audited and relaunched on 8 June 2025 under a recovery plan. Frozen, restored and returned funds remain distinct categories.

Cetus incident report