Exploits Exploity Tools Narzędzia Learn Edukacja About O nas Wallet Risk → Follow on X
Live Verus-Ethereum Bridge exploited May 18 · 1,625 ETH + 103.6 tBTC drained via validation flaw · See analysis → Verus-Ethereum Bridge zhakowany 18 maja · 1 625 ETH + 103.6 tBTC skradzione · Zobacz analizę →
Web3 Security & Blockchain Forensics Bezpieczeństwo Web3 i Forensyka Blockchain

Follow
the money.
Śledź
pieniądze.

On-chain intelligence. DeFi exploit analysis. Blockchain forensics. Every hack leaves a trail — we read it.

Analityka on-chain. Exploity DeFi. Forensyka blockchain. Każdy hack zostawia ślad — my go czytamy.

$1.4B
Bybit hack 2025
Hack Bybit 2025
$2.3B+
Lost in 2026 YTD
Stracone 2026 YTD
84
Forensic tools tracked
Narzędzi forensycznych
Live Now Dostępne
Know who you're
transacting with.
Wiedz, z kim
transagujesz.
Instant OFAC sanctions check, mixer exposure, and hack cluster analysis for any EVM wallet.
Natychmiastowa weryfikacja sankcji OFAC, ekspozycja na mixery i analiza skupisk hakerów dla każdego portfela EVM.
Scan a wallet → Sprawdź portfel →
ETH · BSC · Polygon · Arbitrum · Base · OP
6 risk factors czynniki ryzyka
<2s scan time czas skanu
free tier included darmowy plan
BTC/USD ETH/USD TOTAL
LIVE
Stolen 2026
$2.34B
↑ live estimate
Threat Level
CRITICAL
Bridges · Key Comp.
Wallet Risk Scorer
Wallet Risk Scorer
Is this wallet safe? Score it in seconds.
Czy ten portfel jest bezpieczny? Sprawdź w sekundy.
Live Now Dostępne
KelpDAO LayerZero Bridge -$292M ·
Drift Protocol (Lazarus Group) -$285M ·
Bybit 2025 -$1.4B ·
Cetus Protocol integer overflow -$223M ·
Step Finance private key -$27.3M ·
BTC exchange reserves 7-year low 2.21M BTC ·
Verus-ETH Bridge validation flaw -1625 ETH ·
Truebit oracle overflow -$26.2M ·
KelpDAO LayerZero Bridge -$292M ·
Drift Protocol (Lazarus Group) -$285M ·
Bybit 2025 -$1.4B ·
Cetus Protocol integer overflow -$223M ·
Step Finance private key -$27.3M ·
BTC exchange reserves 7-year low 2.21M BTC ·
Verus-ETH Bridge validation flaw -1625 ETH ·
Truebit oracle overflow -$26.2M ·
STOLEN IN 2026 — TRACKED EXPLOITS SKRADZIONE W 2026 — ŚLEDZONE EXPLOITY
$0
~$185 lost per second · based on tracked exploits
~$185 tracone na sekundę · na podstawie śledzonych exploitów
THREAT LEVEL POZIOM ZAGROŻENIA
CRITICAL
Bridges · Key Compromise
PROTOCOL SCANNER SKANER PROTOKOŁÓW
Aave v3
47 exploits tracked · 2026 YTD
47 exploitów śledzonych · 2026 YTD

The damage in numbers

Straty w liczbach

Total Lost 2026 YTD
Straty 2026 YTD
$2.3B+
as of May 2026
stan na maj 2026
Largest Single Hack
Największy jednorazowy hack
$1.4B
Bybit — Feb 2025
Bridge Exploits 2026
Exploity mostów 2026
74%
of total losses
wszystkich strat
Funds Recovered
Odzyskane środki
<3%
historically
historycznie
BTC Exchange Reserves
Rezerwy BTC na giełdach
2.21M
7-year low (Glassnode)
7-letnie minimum (Glassnode)
Lazarus Group 2025–26
Grupa Lazarus 2025–26
$1.7B+
attributed to DPRK
przypisane KRLD
Exploit Database
Baza Exploitów

Recent DeFi attacks decoded

Najnowsze ataki DeFi — rozkodowane

Not just the amount stolen. We trace attack vectors, follow fund flows, and explain the mechanics behind every exploit.

Nie tylko kwota. Śledzimy wektory ataku, przepływy środków i wyjaśniamy mechanikę każdego exploita.

KelpDAO
Critical
$292M
Apr 19, 2026 · LayerZero Bridge · ETH/rsETH
🌉 Bridge Exploit
Attacker manipulated LayerZero message validation to drain rsETH without proper backing confirmation. Second incident for Kelp within 12 months. Lazarus Group suspected.
defillama.com/hacks
Drift Protocol
Critical
$285M
Apr 1, 2026 · Solana DEX · Social Engineering
🎭 Social Engineering
6-month infiltration by Lazarus Group via fake employee identity. Pre-signed hidden authorizations allowed full fund drain. North Korea-linked operation.
rekt.news
Bybit Exchange
Historic
$1.4B
Feb 2025 · CEX · Supply Chain Attack
⛓️ Supply Chain
Largest crypto hack in history. Attackers compromised signing infrastructure, tricking signers into approving malicious transactions transferring wallet control.
rekt.news/bybit-rekt
Cetus Protocol
High
$223M
May 2025 · Sui Network · Integer Overflow
🔢 Math Error
Integer overflow in liquidity calculation. Attacker exploited flawed overflow check to drain pools. Classic arithmetic vulnerability in smart contract code.
rekt.news/cetus-protocol
Verus-ETH Bridge
High
1,625 ETH
May 18, 2026 · Cross-chain Bridge · Validation Flaw
🌉 Bridge Exploit
Bridge released ETH assets without confirming Verus-side backing. Attacker swapped stolen assets to ~5,402 ETH. Pattern: bridges release without verification.
x.com/AppData_Insight · our analysis
Step Finance
Medium
$27.3M
2026 · Solana · Private Key Compromise
🔑 Key Compromise
Private key leak led to full protocol drain. Most common attack vector for smaller protocols — human error or compromised developer infrastructure.
defillama.com/hacks

How a bridge exploit works

Jak działa exploit mostu

Step-by-step breakdown of the most dangerous attack vector in DeFi. 74% of 2026 losses came from bridges.

Krok po kroku — najgroźniejszy wektor ataku w DeFi. 74% strat 2026 pochodzi z mostów.

🌉 Cross-Chain Bridge Exploit — Pattern Analysis Exploit Mostu Cross-Chain — Analiza Wzorca
01
Attacker deposits assets on Chain A
Atakujący deponuje aktywa na Chain A
Legitimate deposit triggers a cross-chain message to Chain B via the bridge oracle/relayer. This is the setup phase.
Legalny depozyt wysyła wiadomość cross-chain do Chain B przez oracle/relayer mostu.
tx: 0x1a2b3c... → Bridge Contract → emit LockEvent(amount=1000ETH)
02
Validation flaw exploited
Wykorzystanie luki w walidacji
Bridge on Chain B does NOT properly verify the message authenticity, amount, or source state. Attacker crafts a fake or replayed message.
Most na Chain B nie weryfikuje prawidłowo autentyczności wiadomości. Atakujący tworzy fałszywą lub powtórzoną wiadomość.
// Missing: require(msg.sender == trustedRelayer)
03
Drain — assets minted without backing
Drenaż — aktywa mintowane bez pokrycia
Bridge mints wrapped tokens on Chain B without corresponding locked funds on Chain A. Attacker receives unbacked tokens worth millions.
Most mintuje wrapped tokeny na Chain B bez odpowiednich zablokowanych środków na Chain A.
mint(attacker, 292_000_000 USDC) // no backing on Chain A
04
Laundering — funds disappear
Pranie — środki znikają
Funds routed through DEXs → mixers (Tornado Cash) → multiple hops across chains → exchange deposits in VASP-light jurisdictions.
Środki przechodzą przez DEXy → mixery → multiple hopy → depozyty na giełdach bez KYC.
→ Uniswap → Tornado → Binance deposit 0x... (flagged)
05
Forensic trail — nothing is truly hidden
Ślad forensyczny — nic nie jest naprawdę ukryte
Arkham / Chainalysis cluster addresses, trace mixer outputs, flag exchange deposits. Blockchain is permanent. Every hop is recorded.
Arkham / Chainalysis klastruje adresy, śledzi wyjścia mixera, flaguje depozyty. Blockchain jest permanentny.
Arkham: 0xDrain → [Tornado cluster] → Binance:KYC_flagged

Tools of the trade

Narzędzia badacza

Every tool used in blockchain forensics, from free explorers to institutional-grade intelligence platforms.

Każde narzędzie używane w forensyce blockchain — od darmowych explorerów po platformy klasy instytucjonalnej.

Free
Etherscan
Blockchain Explorer
ETH blockchain explorer — every transaction, wallet balance, contract code, and token approval ever recorded on Ethereum. Starting point for any investigation.
Freemium
Arkham Intelligence
Fund Flow Tracing
Visual fund flow tracer with labeled wallets (exchanges, protocols, known hackers). Best free tool for following stolen funds across multiple chains.
Freemium
Glassnode
On-Chain Analytics
MVRV, SOPR, exchange reserves, LTH/STH cost basis. Gold standard for Bitcoin on-chain metrics. Free tier = weekly data, enough to start.
Free
Coinglass
Derivatives & Sentiment
Funding rates, open interest, liquidation maps, long/short ratios. The derivatives layer most analysts miss. Cross-reference with on-chain for full picture.
Free
Breadcrumbs
Visual Investigation
Free visual wallet relationship mapper. Drag-and-drop interface for tracing suspicious fund flows and building case timelines. No account needed.
Paid
Nansen
Smart Money Tracking
Wallet behavior analysis, smart money labels, risk-scoring algorithms. See where institutional and whale money is moving before prices react.
Free
Dune Analytics
Custom SQL Queries
Write SQL against raw blockchain data. Build custom dashboards, spot bulk deposits, rapid swaps, or contract interaction anomalies before anyone else.
Freemium
MistTrack
AML & Risk Scoring
SlowMist's AML platform. Risk scores, entity labels, cross-chain tracing. Particularly strong on Asian exchange data and DeFi protocol interactions.
Institutional
TRM Labs
Blockchain Intelligence
Institutional blockchain risk intelligence. Real-time risk tags, cross-chain clustering, law enforcement integrations. Industry standard for compliance teams.
Institutional
Merkle Science
Crypto Risk & Forensics
Predictive crypto risk platform. Deep forensics, compliance, investigations for regulators, exchanges, and crypto businesses. Publishes attribution reports.
Institutional
Chainalysis
Investigation & Compliance
Reactor tool visualizes wallet relationships and maps to exchanges/darknet markets. Used by law enforcement globally. The industry's most cited forensic tool.
Free
Solscan
Solana Explorer
Solana equivalent of Etherscan. Essential for investigating Solana-based DeFi exploits like Drift Protocol and Step Finance. Token approvals, program interactions.
Deep Analysis
Głęboka Analiza

Read the full investigation

Przeczytaj pełne śledztwo

Forensic walkthroughs, on-chain investigations, and threat intelligence. Real methodology, real sources, fully traceable.

Pełne analizy forensyczne, śledztwa on-chain i raporty wywiadowcze. Prawdziwa metodologia, prawdziwe źródła.

DeFi Exploit Feed

Kanał Exploitów DeFi

Real-time data pulled from DeFiLlama's public API — the 10 most recent tracked hacks, sorted by date.

Dane pobierane w czasie rzeczywistym z publicznego API DeFiLlama — 10 najnowszych śledzonych włamań.

via DeFiLlama API Loading… All hacks → Wszystkie →
Protocol / Project Protokół
Funds Lost Stracone
Attack Type Typ ataku
Date
Severity
Fetching from DeFiLlama…
Latest Investigations
Najnowsze Śledztwa

Published research

Opublikowane badania

Forensic walkthroughs, threat intelligence, and on-chain analysis — fully documented, real sources, traceable methodology.

Analizy forensyczne, wywiad o zagrożeniach i analiza on-chain — w pełni udokumentowane, prawdziwe źródła, sprawdzalna metodologia.

🔬
Forensic Investigation
Śledztwo Forensyczne
Tracing $292M: How Stolen rsETH From KelpDAO Passed Through 14 Wallets
Śledzenie $292M: Jak skradzione rsETH z KelpDAO przeszło przez 14 portfeli
Step by step: Arkham + Etherscan analysis of the KelpDAO LayerZero bridge exploit. Every wallet hop documented, every mixer interaction mapped. Lazarus fingerprint confirmed.
Krok po kroku: analiza exploitu mostu KelpDAO LayerZero. Każdy skok portfela udokumentowany. Odcisk palca Lazarusa potwierdzony.
🛠️
Tools Guide
Przewodnik po Narzędziach
How to Use Arkham Intelligence: Complete Fund Tracing Guide (Free Tier)
Jak używać Arkham Intelligence: kompletny przewodnik śledzenia środków (darmowy)
From zero to tracing stolen funds in 30 minutes. Entity labels, flow graphs, cluster analysis — all on the free plan. Zero coding required.
Od zera do śledzenia skradzionych środków w 30 minut. Etykiety podmiotów, grafy przepływów, analiza klastrów — w darmowym planie. Zero kodowania.
Threat Intelligence
Wywiad o Zagrożeniach
Lazarus Group 2026: New Tactics, Same Patterns, $1.7B in 18 Months
Lazarus Group 2026: Nowe taktyki, te same wzorce, $1.7B w 18 miesięcy
DPRK's crypto hacking unit has evolved. Fake LinkedIn profiles, 6-month infiltrations, pre-signed tx abuse — full tactical breakdown with on-chain evidence.
Skrzydło hakerskie KRLD ewoluowało. Fałszywe profile LinkedIn, 6-miesięczne infiltracje. Pełna analiza taktyczna z dowodem on-chain.
Security Analysis
Analiza Bezpieczeństwa
Why Does EVERY Bridge Get Hacked? Analyzed 11 Exploits Since 2023
Dlaczego KAŻDY most zostaje zhakowany? Przeanalizowałem 11 exploitów od 2023
The root cause isn't bugs in the code — it's an architectural trust problem. A forensic breakdown of 11 bridge exploits totaling $3.1B and what they all have in common.
Główna przyczyna to nie błędy w kodzie — to architektoniczny problem zaufania. Analiza 11 exploitów mostów na łączną kwotę $3.1B i to co mają wspólnego.

Follow the analysis live

Śledź analizy na żywo

Breaking exploits, forensic threads, and on-chain data — published within hours of each event. Follow @AppData_Insight on X.

Bieżące exploity, wątki forensyczne i dane on-chain — publikowane w ciągu godzin od każdego zdarzenia. Obserwuj @AppData_Insight na X.

🔬
AppData Insight
@AppData_Insight
Web3 security researcher. Tracing stolen funds, decoding DeFi exploits and on-chain intelligence — published as threads.
Badacz bezpieczeństwa Web3. Śledzenie skradzionych środków, analiza exploitów DeFi — publikowane jako wątki na X.
Follow
THREAD Coming soon Wkrótce
Traced 1,625 ETH ($11.5M) stolen from the Verus-ETH bridge. 5 staging wallets. Tornado Cash. Binance deposit flagged. Lazarus cluster overlap at step 4.
Śledziłem 1 625 ETH ($11.5M) skradzione z mostu Verus-ETH. 5 portfeli stagingowych. Tornado Cash. Depozyt Binance oflagowany. Nakładka klastra Lazarus w kroku 4.
Read full forensic breakdown → Czytaj pełną analizę →
THREAD Coming soon Wkrótce
5 on-chain signals that were screaming BUY before BTC hit $108k. Exchange reserves at 7-year lows. LTH SOPR below 1. Realized cap surge. None of this was on Twitter.
5 sygnałów on-chain krzyczało KUP zanim BTC osiągnął $108k. Rezerwy giełdowe na 7-letnim minimum. LTH SOPR poniżej 1. Wzrost realized cap.
Read full analysis → Czytaj pełną analizę →
THREAD Coming soon Wkrótce
Why does EVERY bridge get hacked? Analyzed 11 exploits since 2023. The root cause isn't bugs — it's an architectural trust problem that nobody has fully solved.
Dlaczego KAŻDY most zostaje zhakowany? Przeanalizowałem 11 exploitów od 2023. Główna przyczyna to nie błędy — to architektoniczny problem zaufania.
Read full breakdown → Czytaj pełną analizę →
View all threads on X Wszystkie wątki na X

On-chain intelligence.
Built in the open.

Wywiad on-chain.
Budowany jawnie.

AppData Insight is an independent blockchain forensics publication. We trace stolen funds, analyze DeFi exploits, and decode on-chain data — with sources, transaction hashes, and methodology you can verify yourself.

AppData Insight to niezależna publikacja z zakresu forensyki blockchain. Śledzimy skradzione środki, analizujemy exploity DeFi i dekodujemy dane on-chain — ze źródłami, hashami transakcji i metodologią, którą możesz samodzielnie zweryfikować.

🔍
Source-verified only
Tylko ze źródłami
Every claim links to a transaction, a wallet, or a public record. No anonymous tips labeled as fact.
Każde twierdzenie linkuje do transakcji lub publicznego rejestru. Żadnych anonimowych doniesień.
⛓️
Blockchain-native methodology
Metodologia blockchain-native
We use the same tools as professional investigators: Arkham Intelligence, Etherscan, Dune Analytics, on-chain clustering heuristics.
Używamy tych samych narzędzi co zawodowi śledczy: Arkham, Etherscan, Dune Analytics, heurystyki klastrowania.
🌍
Fully independent
W pełni niezależni
No protocol funding. No VC backing. What you read is what the data shows — not what anyone paid us to find.
Żadnego finansowania protokołów. Co czytasz, to co dane pokazują — nie to, za co ktoś zapłacił.
AJ
Adrian Jezik
Founder · Blockchain Forensics Researcher
Założyciel · Badacz Forensyki Blockchain

Independent on-chain investigator specializing in fund tracing, exploit post-mortems, and cross-chain analytics. Building public knowledge around Web3 security — so the community can defend itself.

Niezależny śledczy on-chain specjalizujący się w śledzeniu środków, analizie exploitów i analityce cross-chain. Buduję publiczną wiedzę wokół bezpieczeństwa Web3.

Work with AppData Insight

Współpracuj z AppData Insight

We partner with tools, protocols, and funds that believe in public on-chain transparency. All partnerships are disclosed. Conclusions are always ours.

Współpracujemy z narzędziami, protokołami i funduszami wierzącymi w przejrzystość on-chain. Wszystkie partnerstwa są ujawniane. Wnioski zawsze są nasze.

📋
Sponsored Investigation
Sponsorowane Śledztwo
Commission a deep-dive into a specific protocol, hack, or on-chain pattern. Sponsor is disclosed publicly — conclusions are ours alone.
Zamów analizę konkretnego protokołu, hacka lub wzorca on-chain. Sponsor jest ujawniony publicznie — wnioski są wyłącznie nasze.
🔗
Tool Affiliate
Afiliat Narzędzi
We already recommend Arkham, Glassnode, and Dune in our articles. If your tool is part of the forensics stack, let's talk.
Już rekomendujemy Arkham, Glassnode i Dune. Jeśli twoje narzędzie należy do forensics stack — porozmawiajmy o afiliacji.
🛡️
Security Advisory
Doradztwo Bezpieczeństwa
Pre-launch forensic review of your bridge, vault, or multisig architecture. We identify patterns that led to every major exploit of 2023–2026.
Forensyczny przegląd architektury mostu, vault lub multisig przed uruchomieniem. Identyfikujemy wzorce każdego większego exploita 2023–2026.
📡
Newsletter Placement
Reklama w Newsletterze
Reach a security-focused, technically sophisticated crypto audience: researchers, devs, and funds — not retail speculators.
Dotrzyj do technicznie wymagającej publiczności: badaczy, deweloperów i funduszy — nie retail speculatorów.

All commercial relationships are disclosed in the relevant content. We don't do undisclosed promotions.

Wszystkie relacje komercyjne są ujawniane w odpowiedniej treści. Nie prowadzimy ukrytych promocji.

Get in touch → Skontaktuj się →