Real-time DeFi exploit intelligence

Know if the next DeFi exploit puts your protocol at risk

We track confirmed exploits as they break, pin the root cause, and check your repos for the same flaw — then email you.

Exploits tracked
86

Exploits tracked

Losses logged
$17.4M

Losses logged

EVM chains
6

EVM chains

How it works

Exploit to inbox, one pipeline

01

Detect

Confirmed exploits, ingested as they surface across security channels.

02

Classify

Each one analyzed against the attack tx to pin the root cause.

03

Match

Your watched repos checked for the same flaw on your branch.

04

Alert

If you're exposed, a clear email with the finding and the incident.

Live feed

Latest confirmed exploits

Cook Financeoracle manipulation

Cook Finance on BNB Chain lost ~$4.2K when an attacker flash-loaned WBNB to manipulate thin PancakeSwap component pools (ibBUSD/USDT, ibBUSD/USDC) used by IssuanceModuleV2 to price CKToken index issuance/redemption, allowing them to mint the BGSC index cheaply and redeem components worth far more.

Unknown protocolunknown

A compromised wallet on Ethereum with an EIP-7702 delegation to a 'ContractWork' drainer contract was drained of 184.77 stETH (~$333K); after the victim's key was seized to set the delegation and approve stETH, the attacker used the drainer's onlyOwner pull() to transferFrom the victim to a fresh EOA.

PHX Tokenunknown

PHX Token on BNB Chain was exploited for ~$89.5K via its deflationary burn-on-sell logic: the token's `_takeSellFee` burned 50% of the PancakeSwap pair's PHX balance and called `sync()`, allowing a flashloan-funded attacker to skew reserves to near-zero PHX and drain ~156.2 WBNB from the LP.

Behodleraccess control

Behodler's PyroWETH10 token on Ethereum had a broken transferFrom that checked allowance of the recipient rather than msg.sender, allowing an attacker to drain holders who had approved the PyroWethProxy and redeem ~3.57 ETH (~$6.4K).

Features

For teams who can't find out from Twitter

Real-time detection

Exploits land in your feed with protocol, chain, and attack tx.

Root-cause classification

Tagged by vuln class — reentrancy, access control, oracle, and more.

Your-repo matching

We check whether the same exploited pattern lives in your code.

Targeted alerts

Email only when you're plausibly exposed — signal, not noise.

Free public feed

Every confirmed incident, free. Paid adds repo monitoring.

Private by design

Per-account isolation with row-level security. Your watchlist is yours.

Pricing

Free to watch. Priced for what's at stake.

Free

Stay informed on every confirmed exploit.

$0/ forever
  • Full confirmed-exploit feed
  • Root-cause vulnerability classes
  • Incident details & on-chain context
Browse the feed
For protocols

Pro

Get alerted before an exploit reaches you.

$499/ month
  • Everything in Free
  • Monitor your public repositories
  • Automated vulnerability matching
  • Targeted email alerts when exposed
  • Per-account private watchlist
Start watching

Enterprise

For funds, DAOs & multi-protocol teams.

Custom
  • Everything in Pro
  • Private repositories
  • Multiple protocols & seats
  • Priority alert SLA
  • Dedicated support
Contact us

FAQ

Questions, answered

How fast are alerts?

Exploits hit the feed within ~a minute of detection; repo-match alerts follow as analysis completes.

Which repositories can I monitor?

Any public repo, any branch. No write access needed — just the URL.

Which chains are covered?

EVM chains. Each incident links the attack tx so you can verify it yourself.

Is the feed really free?

Yes. Browsing every confirmed incident is free. Pro ($499/mo) adds repo monitoring and alerts.

How is my watchlist kept private?

Per-account row-level security. Incidents are shared; your watchlist is not.

Don't find out from the timeline.

Start with the free exploit feed, then watch your own repositories the moment it matters.