News listDeFi becomes a hacker's backyard? 13 attacks in one month, $630 million stolen
動區 BlockTempo2026-05-01 07:29:30 Hot

DeFi becomes a hacker's backyard? 13 attacks in one month, $630 million stolen

ORIGINALDeFi變成駭客後花園?一個月13起攻擊、6.3億美元被捲
AI Impact AnalysisGrok analyzing...
📄Full Article· Automatically extracted by trafilaturaGemini 翻譯1594 words
April 2026 was the month with the highest recorded amount of cryptocurrency stolen. According to DeFiLlama, at least 13 DeFi protocols were attacked within 30 days, resulting in cumulative losses exceeding $630 million. The two incidents involving Drift Protocol and KelpDAO alone accounted for 92% of the month's total losses, with both being attributed by security firms to the North Korean Lazarus Group. From the start on April Fools' Day to the final blow on the last day of the month when Wasabi Protocol was drained of $5 million, there was hardly a safe day. (Context: Ledger CTO warns: 2026 is the worst year for hackers, DeFi single-signature architecture harbors systemic crisis) (Background: Kelp DAO hacked: 10+ DeFi protocols including Ethena and ether.fi cut off LayerZero cross-chain bridge connections) With hackers running rampant, April's DeFi landscape felt like a hacker's backyard, with an incident occurring on average every three days. This included everything from stolen admin keys and hijacked cross-chain bridges to protocols losing half their TVL. - 04/01|Drift Protocol|Solana|$285 million: Attacker stole admin keys, forged CVT tokens as collateral, and drained over half of the TVL within 12 minutes. Lazarus Group suspected. The largest single attack of 2026. - 04/12|Hyperbridge|$2.5 million: Cross-chain bridge contract vulnerability exploited. - 04/16|Rhea Finance|$18.4 million: Unauthorized withdrawal from protocol liquidity pools. - 04/16|Grinex|$15 million: Second incident of the day, trading platform funds stolen. - 04/18|KelpDAO|Ethereum / LayerZero|$293 million: Attacker hijacked RPC nodes, utilized 1-of-1 validator configuration to inject fake messages, and drained 116,500 rsETH (18% of circulating supply). Lazarus Group confirmed. AAVE TVL evaporated by $10 billion in a single day. - 04/20|ThetanutsFi|$50,000: Small-scale exploit. - 04/20|JuiceboxETH|Ethereum|$52,000: Second incident of the day, contract vulnerability. - 04/21|Volo|Sui|$3.5 million: Protocol funds on the Sui chain stolen. - 04/25|Purrlend|$1.52 million: Lending protocol attacked. - 04/26|Scallop.io|$142,000: Small-scale exploit. - 04/27|ZetaChain|$334,000: Cross-chain protocol exploited. - 04/29|AftermathFi|$1.14 million: Abnormal withdrawal from protocol liquidity pools. - 04/30|Wasabi Protocol|ETH / Base / Blast / Berachain|Over $5 million: Admin keys stolen; attacker granted themselves administrative permissions and replaced the contract with a malicious version, draining four chains simultaneously. Time-lock set to zero. The final blow of April. All turned into pocket money for the General. Of the $630 million total losses in April, Drift Protocol ($285 million) and KelpDAO ($293 million) accounted for $578 million, or 92%. While the attack methods differed, on-chain tracking by security firms TRM Labs and Chainalysis both pointed to the same criminal syndicate: the North Korean Lazarus Group. These two attacks triggered an exodus of approximately $13 billion in DeFi funds. Ledger CTO Charles Guillemet warned: "DeFi's single-signature architecture harbors a systemic crisis; 2026 is highly likely to be the worst year for hackers." The final blow to an old protocol: Wasabi Wasabi Protocol was breached on the last day of April, though the amount was "only" over $5 million. Wasabi itself had implemented an access control framework supporting time-locks, but the delay was set to zero—equivalent to installing a safe but leaving it unlocked. DeFi father Andre Cronje said in April: "Decentralized finance is dead, it's all for-profit enterprises now." It seems hard to argue with him now.
Data Status✓ Full text extractedRead Original (動區 BlockTempo)
🔍Historical Similar Events· Keyword + Asset Matching0 items
No similar events found (requires more data samples or embedding search; currently MVP keyword matching)
Raw Information
ID:d49683e6b0
Source:動區 BlockTempo
Published:2026-05-01 07:29:30
Category:hot · Export Category hot
Symbols:Unspecified
Community Votes:+0 /0 · ⭐ 1 Important · 💬 0 Comments
DeFi becomes a hacker's backyard? 13 attacks in one month, $630 million stolen | Feel.Trading