Neurobay Services
Raise capital for your enterprise
Business Advisory
Struggling to grow? Get expert advice
Property
Seamless Property Acquisition for Investors & Entrepreneurs
A full stack marketing team at your fingertips
Outsourced Marketing Team (Storytelling)
AML/KYC Compliance Services
Lorem ipsum dolor sit amet, consectetur.
Neurobay Supporting Services
Global compliance in AML
UAE Crypto Licensing Services
ADGM, DIFC & VARA licensing services
Neurobay's curated services accelerate your business to reach it's full potential
Outsourced Marketing Team (Storytelling)
A full stack marketing team at your fingertips
AML/KYC Compliance Services
Lorem ipsum dolor sit amet, consectetur.
Driving innovation and growth
Outsourced Marketing Team (Storytelling)
A full stack marketing team at your fingertips
Our Team
Meet our dynamic team 
AML/KYC Compliance Services
Lorem ipsum dolor sit amet, consectetur.

WEB3 BATTLEFRONT: Notable HACKS

December 5, 2025

Thanos snaps his fingers and half the universe turns to dust.

In Web3, a lone hacker or a small crew can do the same thing to money, one exploit, one transaction, and half a billion dollars simply vanishes from the system, leaving almost no trace except a cold trail on a blockchain explorer.

 In the fast-evolving world of Web3, hackers exploiting vulnerabilities with precision and turning complex protocols into treasure troves, isn’t exactly breaking news, the possibility of a hack big enough to rattle the command chains is low but never entirely zero. 

Web3 hacks mostly exploit smart contract bugs, private key compromises, phishing/social engineering, and infrastructure flaws, leading to over $1.6B stolen in Q1 2025 alone across 197 incidents. 

Here are some notable hacks that have taken place in recent years:  

Bybit Exchange

In 2025, crypto exchange Bybit was hit by one of the biggest hacks in history, losing over $1.5 billion in Ethereum. 

Attackers managed to break into the exchange’s infrastructure, compromise a developer’s machine, tamper with transaction approval flows,

neurobay
Author: neurobay

Stay ahead with our latest insights
Subscribe to our blog
and abuse stolen API keys to move funds out of supposedly secure cold wallets, exposing deep weaknesses in how even “offline” systems were protected.​

Ronin Network

Back in 2022, the Ronin Network, which powered the game Axie Infinity, lost $625 million when hackers took control of its bridge.

They used social engineering to trick or compromise developers, collecting all the private keys needed for the 13‑of‑13 multisig wallet that approved bridge withdrawals, then signing fake transactions to drain the funds in a single stroke.​

Radiant Capital

In 2024 Radiant Capital’s incident showed how dangerous malware and “blind signing” can be.

Attackers infected developers’ hardware wallets via Telegram-delivered malware, then spoofed Safe{Wallet} transaction prompts so they looked normal.
Developers thought they were approving routine transactions, but in reality, they were signing malicious ones that handed control and funds over to the attacker’s contracts.​

PenPie

PenPie, a DeFi protocol, was hacked in September 2024 due to a reentrancy bug.

The attacker deployed a malicious market contract, used flash loans to stuff it with temporary liquidity, and then repeatedly triggered a reward-harvesting function before balances were properly updated.
This allowed them to claim inflated rewards and convert them back into real assets, draining about $27 million from the system.​

LI.FI Protocol

In July 2024, LI.FI Protocol lost $9 million because of a flaw in a newly deployed contract called GasZipFacet.

The contract failed to validate what kind of transaction it was executing, so the attacker sent carefully crafted calldata that made it perform a transferFrom instead of a normal swap.

Since the protocol didn’t check this properly, the attacker could pull user funds straight out of the contract.​

Polter Finance

Polter Finance suffered an $8–12 million loss in November 2024 after an attacker manipulated its price oracle.

By feeding the system an artificially high price for a token, the attacker deposited a tiny amount of that token as collateral, which the protocol then treated as extremely valuable.

Using this fake collateral value, they repeatedly borrowed other assets like wrapped FTM, steadily draining the lending pools before the error was noticed.​

Qix NPM Packages

Not all attacks hit blockchains directly, some hit the software supply chain.

In September 2025, a threat actor took over the npm account of well-known developer Qix, who maintained popular JavaScript libraries such as chalk and debug.

The attacker pushed new malicious versions that injected wallet-stealing code into websites and apps using these packages.

For a few hours, millions of downstream projects were potentially exposed before the compromise was discovered and the bad versions were pulled.​

Kame Aggregator

Kame Aggregator’s September 2025 exploit was a more “classic” smart contract issue.

The protocol allowed a swap function to call arbitrary executors without strict validation.

An attacker deployed a malicious contract and routed swaps through it, abusing that freedom to execute arbitrary logic and siphon off around $1.3 million in user funds.

This showed how dangerous it is to let untrusted contracts plug into core routing without strong checks and permissions.

Final Thoughts

Web3 hacks often target weak points like smart contract errors, leaked private keys, phishing scams, and infrastructure gaps.

This evolving threat environment demands constant vigilance through rigorous security audits, robust key management, improved user education, and resilient infrastructure designs.

The promise of decentralized innovation can only thrive if the ecosystem’s participants prioritize security as a foundational pillar, learning from each incident to build stronger, more transparent protocols that can withstand future onslaughts.

Ignoring these lessons risks undermining trust, which remains the most valuable currency in Web3’s continued growth.

Email: contact@neurobaystrategy.com
Whatsapp: +971 58 593 5904

References

AliceHsu (2024). 2024 DeFi Smart Contract Hack Incident Review. [online] Cymetrics Tech Blog. Available at: https://tech-blog.cymetrics.io/en/posts/alice/2024_defi_hack/.
Behnke, R. (2025). Month in Review: Top DeFi Hacks of September 2025. [online] Halborn.com. Available at: https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-september-2025 [Accessed 1 Dec. 2025].
Guardrail.ai. (2025). Guardrail | Decoding 2025’s biggest web3 hacks: lessons & trends. [online] Available at: https://www.guardrail.ai/blog/quill-audits-decoding-2025-biggest-web3-hacks-lessons-and-trends [Accessed 1 Dec. 2025].
Hassan, K. (2025). The Most Notorious Hackers in 2025. [online] DeepStrike. Available at: https://deepstrike.io/blog/most-notorious-hackers-2025 [Accessed 1 Dec. 2025].
Immunefi (2023). The Top 10 Most Common Vulnerabilities In Web3. [online] Immunefi - Trusted by 400+ Customers. Available at: https://immunefi.com/blog/all/top-10-web3-vulnerabilities/.
Luker (2025). MetaMask Security Report: March 2025. [online] Metamask.io. Available at: https://metamask.io/news/metamask-security-report.
owasp.org. (n.d.). OWASP Smart Contract Top 10 | OWASP Foundation. [online] Available at: https://owasp.org/www-project-smart-contract-top-10/.
Team, F.E. (2025). FailSafe Web3 Security Report 2025. [online] FailSafe. Available at: https://getfailsafe.com/failsafe-web3-security-report-2025/ [Accessed 1 Dec. 2025].
Three Sigma. (2024). 2024 Most Exploited DeFi Vulnerabilities - By Three Sigma. [online] Available at: https://threesigma.xyz/blog/exploit/2024-defi-exploits-top-vulnerabilities [Accessed 1 Dec. 2025].
Auditone.io. (2024a). The PenPie Hack: Understanding the September 2024 Reentrancy Exploit and the Role of Auditing in DeFi Security | Blockchain Audit Company | AuditOne. [online] Available at: https://www.auditone.io/blog-posts/the-penpie-hack-understanding-the-september-2024-reentrancy-exploit-and-the-role-of-auditing-in-defi-security [Accessed 3 Dec. 2025].
Auditone.io. (2024b). Unpacking Multisig Hacks In DeFi Radiant Capital’s Case | Blockchain Audit Company | AuditOne. [online] Available at: https://www.auditone.io/blog-posts/unpacking-multisig-hacks-in-defi-radiant-capitals-case [Accessed 3 Dec. 2025].
Ekhator, O. (2025). How did Bybit hack 2025 happen: the full story. [online] Techpoint Africa. Available at: https://techpoint.africa/guide/bybit-hack-2025/.
Hila Ramati, Gal Benmocha and Aminov, D. (2025). Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond. [online] wiz.io. Available at: https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk.
Three Sigma. (2024a). LI.FI Protocol Exploit: $9M Drained | Three Sigma. [online] Available at: https://threesigma.xyz/blog/exploit/lifi-9m-protocol-exploit-analysis [Accessed 3 Dec. 2025].
Three Sigma. (2024b). Polter Finance Exploit: Fork-and-Pray Failure - Three Sigma. [online] Available at: https://threesigma.xyz/blog/exploit/polter-finance-exploit-explained-usd12m-loss [Accessed 3 Dec. 2025].
Wilson Center. (2025). The Bybit Heist: What Happened & What Now? [online] Available at: https://www.wilsoncenter.org/article/bybit-heist-what-happened-what-now.

Recent Blog
November 12, 2024
How fundraising consultants can help your business scale

Every business needs funding to grow. This is where fund raising plays a vital role. When companies want to expand or take on bigger projects, having funds is essential. But the process can be complex.

Get In Touch With Us

One of our team will come back to you

linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram