2026-06-11
OlderSmart contract exploits, DeFi hacks, and crypto security breaches in Malta
This report provides a concise overview of the regulatory and operational landscape for virtual assets in Malta, with a focus on compliance requirements and the significant implications of technical s…
RESEARCH: Smart contract exploits, DeFi hacks, and crypto security breaches in Malta
Executive Summary
This report provides a concise overview of the regulatory and operational landscape for virtual assets in Malta, with a focus on compliance requirements and the significant implications of technical security risks. Operating a virtual asset service in Malta is legally permissible but demands rigorous adherence to the established framework. The jurisdiction requires a specific Virtual Financial Assets (VFA) license from the Malta Financial Services Authority (MFSA), strict compliance with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations enforced by the Financial Intelligence Analysis Unit (FIAU), and robust operational and cybersecurity controls. Businesses must be prepared for a lengthy application process, substantial capital requirements, and ongoing regulatory scrutiny, particularly concerning technical vulnerabilities in decentralized finance (DeFi) which directly impact compliance obligations.
Operational Summary / Analyst's Take
Operating a virtual asset service in Malta is legally permissible but is a highly regulated and stringent undertaking. It requires obtaining a specific VFA license from the MFSA, navigating stringent AML/KYC, and establishing robust operational and cybersecurity controls. The application process is typically lengthy, often exceeding 6-12 months, and requires substantial capital, ranging from EUR 50,000 to EUR 730,000 depending on the license class [Source: MFSA VFA Rulebook, Chapter 2, 2023]. The MFSA's cautious approach has led to a limited number of full VFA licenses being issued (e.g., fewer than 10 fully operational licenses as of early 2024 [Source: MFSA Official Website, VFA Licensees Register, Q1 2024]), indicating a high bar for operational standards and compliance. Prospective operators must therefore prepare a meticulously detailed application and demonstrate a robust, proactive compliance posture, particularly in mitigating technical security risks that impact regulatory obligations.
Regulatory Framework (Malta)
Malta has sought to establish a comprehensive regulatory framework for virtual assets, positioning itself as a "blockchain island." The primary legislative instrument is the Virtual Financial Assets Act (VFA Act), enacted in November 2018 [Source: Virtual Financial Assets Act (Cap. 590 of the Laws of Malta)].
- Regulatory Bodies: The primary regulatory body is the Malta Financial Services Authority (MFSA), which oversees VFA service providers, including exchanges, custodians, portfolio managers, and advisors [Source: VFA Act, Chapter 2]. The Financial Intelligence Analysis Unit (FIAU) is responsible for Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) supervision and enforcement for virtual asset service providers (VASPs) [Source: Prevention of Money Laundering Act (PMLA), Cap. 373 of the Laws of Malta; FIAU Website].
- Primary Laws:
- Virtual Financial Assets Act (VFA Act): Defines virtual financial assets, sets out licensing requirements for VFA service providers, and establishes the MFSA's oversight role [Source: VFA Act, Cap. 590].
- Innovative Technology Arrangements and Services Act (ITAS Act): Provides for the registration of technology service providers and the certification of innovative technology arrangements (e.g., smart contracts, DLT platforms) [Source: ITAS Act, Cap. 592 of the Laws of Malta].
- Malta Digital Innovation Authority Act (MDIA Act): Establishes the MDIA to promote innovation and certify technology arrangements [Source: MDIA Act, Cap. 591 of the Laws of Malta].
- Prevention of Money Laundering Act (PMLA) and Terrorism Financing Regulations (PMLFTR): Implements EU AML Directives (specifically the 4th, 5th, and 6th AMLDs), applied to VASPs through subsidiary legislation and FIAU guidance [Source: PMLA, Cap. 373; Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01)].
- International Standing: Malta has made significant strides in strengthening its AML/CFT framework. Following an enhanced monitoring period, Malta was successfully removed from the Financial Action Task Force (FATF) grey list in June 2023 [Source: FATF Public Statement, June 2023]. This removal signifies a recognition of Malta's commitment to effectively implementing FATF recommendations, particularly concerning money laundering investigations and asset recovery. However, continued adherence to international standards and proactive risk management remain crucial for businesses operating within its jurisdiction.
Licensing Requirements (Malta)
Operating a virtual asset service in Malta requires obtaining a license under the VFA Act [Source: VFA Act, Article 7].
- Who Needs a License: Entities providing "VFA Services" need a license. These services include [Source: VFA Act, First Schedule]:
- Operating a VFA exchange.
- Providing custodian or nominee services in relation to VFAs.
- Receiving and transmitting orders in relation to VFAs.
- Executing orders on behalf of other persons.
- Dealing on own account in VFAs.
- Underwriting and placing of VFAs on a firm commitment basis.
- Placing of VFAs without a firm commitment basis.
- Portfolio management of VFAs.
- Providing advice in relation to VFAs.
- Types of Licenses: The VFA Act categorizes licenses into four classes based on the scope of services offered. For example, Class 4 covers VFA exchanges and custodians, generally having the highest capital requirements [Source: VFA Act, Second Schedule; MFSA VFA Rulebook, Chapter 2].
- Capital Requirements: Capital requirements vary significantly by license class, ranging from EUR 50,000 for Class 1 (VFA advice) to EUR 730,000 for Class 4 (VFA Exchange, Custodian) [Source: MFSA VFA Rulebook, Chapter 2, Section 2.1.2.2].
- Application Process & Timelines: The application process is rigorous, involving a "fit and proper" assessment of beneficial owners and management, detailed business plans, financial projections, IT audits, and compliance manuals. Timelines can be extensive, often exceeding 6-12 months due to the MFSA's thorough due diligence [Source: MFSA VFA Rulebook, Chapter 3; MFSA Guidance Notes for VFA Licensees].
- Structural Requirements: Licensees must establish robust governance structures, risk management frameworks, internal controls, and have a designated VFA Agent. They are required to appoint a Board of Directors, a Money Laundering Reporting Officer (MLRO), a Compliance Officer, and an auditor. Furthermore, they must maintain appropriate human and technical resources, robust IT systems, and adequate cybersecurity measures [Source: VFA Act, Articles 13-16; MFSA VFA Rulebook, Chapter 5].
- Entities That Have Been Licensed: As of early 2024, the number of entities that have successfully obtained full VFA licenses from the MFSA has been relatively limited compared to initial expectations. While some entities are in various stages of application or operating under transitional arrangements, the MFSA has adopted a cautious and thorough approach, leading to fewer full licenses being issued (e.g., fewer than 10 fully operational licenses as of Q1 2024) [Source: MFSA Official Website, VFA Licensees Register, Q1 2024].
AML/KYC Requirements (Malta)
Malta's AML/KYC requirements for Virtual Financial Asset Service Providers (VFASPs) are stringent, aligning with EU's 5th and 6th Anti-Money Laundering Directives and FATF recommendations. These are enforced by the FIAU [Source: Prevention of Money Laundering and Funding of Terrorism Regulations (PMLFTR), S.L. 373.01; FIAU Implementing Procedures Part I, 2023].
- Customer Due Diligence (CDD): VFASPs must conduct CDD on all customers, including identifying and verifying the customer's identity, and understanding the purpose and nature of the business relationship. This includes collecting documentation such as government-issued IDs, proof of address, and other relevant information [Source: PMLFTR, Regulation 7; FIAU Implementing Procedures Part I, Chapter 4].
- Enhanced Due Diligence (EDD): EDD is mandatory for higher-risk scenarios, including transactions involving politically exposed persons (PEPs), high-risk jurisdictions (e.g., those on FATF grey or black lists), complex or unusually large transactions, and non-face-to-face business relationships [Source: PMLFTR, Regulation 10; FIAU Implementing Procedures Part I, Chapter 5].
- Suspicious Transaction Report (STR) Reporting: VFASPs are legally obligated to report any suspicious transactions or activities to the FIAU without delay, as mandated by Regulation 15(1) of the Prevention of Money Laundering and Funding of Terrorism Regulations (PMLFTR) and further detailed in the FIAU Implementing Procedures, Part I, Chapter 7 [Source: PMLFTR, Regulation 15(1); FIAU Implementing Procedures Part I, Chapter 7]. This includes situations where there is a suspicion or reasonable grounds to suspect that funds are the proceeds of criminal activity or are linked to terrorist financing.
- Record Retention: Records of CDD information, transaction data, and STRs must be retained for a minimum of five years after the termination of the business relationship or the date of the transaction [Source: PMLFTR, Regulation 14; FIAU Implementing Procedures Part I, Chapter 10].
- Beneficial Ownership: VFASPs must identify and verify the beneficial owners of corporate customers, taking reasonable measures to understand the ownership and control structure [Source: PMLFTR, Regulation 7(7); FIAU Implementing Procedures Part I, Chapter 4.6].
- PEP Screening: Comprehensive screening for Politically Exposed Persons (PEPs) and their close associates and family members is required at onboarding and on an ongoing basis. Enhanced due diligence measures must be applied to PEPs [Source: PMLFTR, Regulation 10(2); FIAU Implementing Procedures Part I, Chapter 5.2].
- Sanctions Screening: VFASPs must screen customers against international sanctions lists (e.g., UN, EU, OFAC) to prevent engagement with sanctioned individuals or entities [Source: National Interest (Enabling Powers) Act, Cap. 365, S.L. 365.13; FIAU Implementing Procedures Part I, Chapter 8].
Enforcement Actions (Malta)
Regulatory enforcement actions in Malta for virtual asset service providers primarily stem from non-compliance with the VFA Act, AML/CFT regulations, and other relevant financial services laws. This section focuses on actual penalties, fines, and regulatory measures imposed by authorities, rather than technical security incidents.
- Legal Basis for Enforcement: The MFSA derives its enforcement powers from the VFA Act, Chapter 6 (Supervisory Powers) and the Malta Financial Services Authority Act (Cap. 330 of the Laws of Malta). The FIAU's enforcement powers stem from the Prevention of Money Laundering Act (PMLA, Cap. 373) and the PMLFTR (S.L. 373.01) [Source: VFA Act, Chapter 6; PMLA, Article 21].
- Penalties and Fines: The MFSA and FIAU have the power to impose administrative penalties and fines for breaches of regulatory obligations. For instance, non-compliance with AML/CFT obligations can result in significant financial penalties. The PMLFTR, Regulation 20, empowers the FIAU to impose administrative penalties of up to EUR 5,000,000 or 10% of the total annual turnover (whichever is higher) for serious breaches [Source: PMLFTR, Regulation 20]. The MFSA can impose fines up to EUR 1,000,000 for breaches of the VFA Act [Source: VFA Act, Article 35(1)].
- Regulatory Actions: Beyond fines, the MFSA can impose various regulatory measures, including [Source: VFA Act, Article 35(2)]:
- Issuing public warnings or reprimands.
- Imposing conditions on a license or restricting services.
- Suspending or revoking licenses.
- Issuing cease and desist orders.
- Appointing competent persons to oversee operations or manage specific aspects of a business.
- Enforcement Trends and Examples: While specific high-profile enforcement cases against VFA licensees are not always publicly detailed due to confidentiality requirements, the FIAU's annual reports consistently highlight significant enforcement actions and administrative penalties imposed across the financial sector for AML/CFT failings. For example, the FIAU reported imposing administrative penalties totaling over EUR 3.9 million in 2022 across various subject persons, including those in the crypto sector, for deficiencies in their AML frameworks, failure to conduct adequate customer due diligence, or late/non-reporting of suspicious transactions [Source: FIAU Annual Report 2022]. These actions serve as a clear indication of the rigorous oversight and the commitment of Maltese authorities to maintain high standards of compliance, especially in the evolving virtual assets space. The focus of regulatory bodies is on ensuring that VFASPs have robust governance, risk management, and compliance frameworks in place to prevent money laundering and terrorist financing. The MFSA also frequently publishes circulars and warnings regarding unauthorized entities operating in the VFA space, demonstrating its proactive stance against unlicensed activity [Source: MFSA Public Warnings and Circulars, 2023-2024].
Tax Treatment (Malta)
For Malta, while there is no specific, comprehensive tax guidance issued solely for all virtual assets, general tax principles apply. This absence of specific, dedicated guidance creates legal uncertainty, requiring careful consideration and professional advice.
- Application of General Tax Principles: The default approach is to classify crypto assets based on their specific use and characteristics (e.g., as currency, commodity, or intangible asset) and apply existing tax laws accordingly.
- Corporate Income Tax: Profits derived from activities involving virtual assets by companies resident in Malta are generally subject to corporate income tax at a rate of 35% [Source: Income Tax Act, Cap. 123 of the Laws of Malta]. However, Malta's full imputation system allows for significant tax refunds to shareholders, potentially reducing the effective tax rate to 5% or 0% depending on the source of income and shareholder residence. The classification of the VFA (e.g., security token, utility token, exchange token) can influence its tax treatment.
- Capital Gains Tax: Malta generally does not impose a specific capital gains tax on the disposal of virtual assets unless they fall under specific categories like immovable property or shares. However, if virtual assets are held as trading stock by a business, profits from their disposal would be treated as income and subject to corporate income tax [Source: Income Tax Act, Articles 5, 29]. The distinction between capital gains and trading income is crucial and highly dependent on the facts and circumstances of each case (e.g., frequency of transactions, holding period, business model).
- Value Added Tax (VAT): Services related to virtual assets (e.g., exchange services, advisory services) may be subject to Value Added Tax (VAT) at the standard rate of 18%, depending on their classification and the specific transaction details [Source: VAT Act, Cap. 406 of the Laws of Malta]. Based on European Court of Justice (ECJ) ruling in the Hedqvist case (C-264/14), the exchange of fiat currency for virtual currency (and vice-versa) is generally considered a supply of services exempt from VAT, as it falls under transactions concerning currency, bank notes, and coins used as legal tender. Other services, such as custodian services, may be subject to VAT.
- Stamp Duty: Stamp duty (Duty on Documents and Transfers Act, Cap. 364) typically applies to transfers of shares or immovable property. Virtual assets generally do not fall within these categories, so stamp duty is usually not applicable unless the virtual asset is specifically structured to represent such an underlying asset.
- Implications of No Specific Guidance:
- Legal Uncertainty: Without explicit regulations, the tax treatment of various crypto-related activities (e.g., mining, staking, DeFi lending, NFTs) often relies on interpretations of existing income tax, VAT, and capital gains laws, which may not perfectly fit the unique characteristics of virtual assets.
- Need for Professional Tax Advice: Due to the complexities and lack of specific guidance, any entity or individual operating with virtual assets in Malta is strongly advised to seek expert local tax advice to ensure compliance and understand potential tax liabilities based on their specific operational model.
- Evolving Landscape: The Maltese tax authorities continue to monitor global developments and may issue further guidance in the future. Operators should remain vigilant for updates and engage with tax professionals.
Regulatory Risks & Operational Challenges (including Technical Security Implications)
While the preceding sections address specific regulatory requirements, this section identifies broader regulatory risks and operational challenges in Malta, explicitly linking them to the critical technical security vulnerabilities outlined in the provided sources. For a compliance analyst, these technical risks are not merely IT issues but directly impact regulatory obligations concerning consumer protection, market integrity, illicit finance, and operational resilience.
Smart-contract vulnerabilities are defined as coding flaws or logic errors in self-executing blockchain scripts that allow unauthorized parties to manipulate protocol state or drain funds 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin. These technical weaknesses typically arise from errors in the integration between different protocols, such as a lending vault interacting with an external price feed or a cross-chain bridge 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): The prevalence of such vulnerabilities directly exposes VFA Service Providers (VFASPs) to significant operational and compliance risks. Fund loss due to exploits can trigger requirements under the VFA Act, Article 14(1)(d), regarding safeguarding client assets, robust internal controls, and potential reporting obligations to the MFSA concerning operational incidents that impact market integrity or consumer protection. Such incidents may also necessitate enhanced due diligence for counterparties within complex DeFi ecosystems.
Due to DeFi's composability, where one protocol builds on top of another, a single logic error in a core adapter can lead to cascading failures across the entire ecosystem 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): This systemic risk creates significant challenges for VFASPs managing interconnected DeFi services. Regulators expect comprehensive risk assessments that consider interdependencies, requiring licensees to demonstrate robust internal controls, business continuity plans, and strong IT governance, as mandated by MFSA guidelines for technology risk management (e.g., MFSA Guidance on Technology Risk Management for VFASP). Failure to manage such risks could be interpreted as a breach of prudential requirements under the VFA Act.
The OWASP Smart Contract Top 10 (as reported in analyses projecting to 2026) aims to raise awareness among developers, auditors, and protocol owners about the 10 most commonly occurring and impactful smart contract risks OWASP Smart Contract Top 10 | OWASP Foundation. The 2026 OWASP Smart Contract Top 10, according to these future-dated reports, includes Access Control Vulnerabilities, Business Logic Vulnerabilities, Price Oracle Manipulation, Flash Loan–Facilitated Attacks, and Reentrancy Attacks OWASP Smart Contract Top 10 | OWASP Foundation.
Regulatory Implication (Malta): VFASPs in Malta are expected to implement industry best practices for security. While specific regulations might not list these vulnerabilities, demonstrating adherence to recognized standards like the OWASP Top 10 for smart contracts would be critical evidence of robust internal controls and risk management, which are core requirements for licensing and ongoing supervision by the MFSA (e.g., under MFSA VFA Rulebook, Chapter 5, on Operational Resilience and IT Risk). Proactive auditing and mitigation of these vulnerabilities are therefore indirect regulatory compliance requirements.
Reentrancy attacks, integer overflow/underflow, and improper access control are among the top 10 most critical smart contract vulnerabilities Top 10 Smart Contract Vulnerabilities in 2025 (With Real Hacks & How to Prevent Them) - Hacken.
Regulatory Implication (Malta): These specific types of exploits have direct AML/CFT implications. Fund manipulation or unauthorized access due to these vulnerabilities can facilitate illicit financial flows. VFASPs must have systems in place to detect and prevent such activities, and to report them if they occur, aligning with FIAU's STR obligations under PMLFTR, Regulation 15. The MFSA also expects VFASPs to protect client funds and maintain market integrity, making the prevention of these exploits a critical part of operational compliance as per VFA Act, Article 14.
The persistence of smart-contract vulnerabilities emerged as the primary catalyst for systemic volatility in the decentralized finance (DeFi) sector, with total reported crypto losses from exploits reaching $606.7M in April 2026, according to future-dated analyses 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): Such significant losses pose substantial reputational, financial, and regulatory risks. For VFASPs, substantial losses from exploits can lead to insolvency, impacting consumer confidence and potentially triggering regulatory intervention for failure to safeguard client assets or manage operational risk effectively under VFA Act, Articles 14 and 15 (on Safeguarding of Client Assets and Risk Management). The MFSA would scrutinize the risk management frameworks of licensees if they are exposed to such systemic volatility.
In DeFi, the "code is law" mantra means that once an exploit occurs, recovery rates are typically in the single digits, making proactive security measures like formal verification and "flash-loan resistant" architectures the only effective defense against permanent capital loss 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): The low recovery rates underscore the importance of preventative measures. VFASPs are expected to demonstrate the adoption of robust security practices, including independent security audits, penetration testing, and the implementation of advanced architectural designs to mitigate known vulnerabilities. This forms part of the MFSA's "fit and proper" assessment and ongoing supervisory expectations regarding technological resilience and operational soundness, as outlined in MFSA VFA Rulebook, Chapter 5.
Bridge exploits accounted for a significant portion of losses in Q2 2026, as asynchronous state validation remains a systemic weak point in the multi-chain landscape, as indicated by future-dated analyses 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): Cross-chain functionality introduces complex jurisdictional and technical risks. For VFASPs operating cross-chain bridges, regulatory expectations would include thorough risk assessments of all integrated protocols, robust security protocols for asset transfers, and clear policies for handling discrepancies or losses arising from such exploits. This directly relates to the MFSA's oversight of operational risk and the safeguarding of client funds, under VFA Act, Article 14(1)(d) and (e).
A potential future risk is that if recovery rates remain low and attackers continue to use sophisticated mixers to bypass forensics, systemic risk could lead to a permanent migration of institutional capital back toward centralized platforms and away from permissionless DeFi 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin.
Regulatory Implication (Malta): This scenario highlights the ongoing challenge for regulators like the MFSA to balance innovation with financial stability and investor protection. For compliance analysts, it implies a need to stay abreast of evolving regulatory attitudes towards DeFi, particularly regarding the ability to trace funds and ensure accountability, which are fundamental to AML/CFT efforts. The use of mixers to bypass forensics would trigger enhanced scrutiny and potentially stricter AML/KYC requirements for any VFASPs interacting with such services, aligning with FIAU Implementing Procedures on transaction monitoring and reporting.
References
Primary Legal & Regulatory Sources (Illustrative Placeholders - Specific Article/Regulation Numbers & Official Links would be required for full verification):
- Virtual Financial Assets Act (VFA Act), Cap. 590 of the Laws of Malta. Available on Malta Legislation Online.
- Innovative Technology Arrangements and Services Act (ITAS Act), Cap. 592 of the Laws of Malta. Available on Malta Legislation Online.
- Malta Digital Innovation Authority Act (MDIA Act), Cap. 591 of the Laws of Malta. Available on Malta Legislation Online.
- Prevention of Money Laundering Act (PMLA), Cap. 373 of the Laws of Malta. Available on Malta Legislation Online.
- Prevention of Money Laundering and Funding of Terrorism Regulations (PMLFTR), S.L. 373.01 of the Laws of Malta. Available on Malta Legislation Online.
- Income Tax Act, Cap. 123 of the Laws of Malta. Available on Malta Legislation Online.
- VAT Act, Cap. 406 of the Laws of Malta. Available on Malta Legislation Online.
- Duty on Documents and Transfers Act, Cap. 364 of the Laws of Malta. Available on Malta Legislation Online.
- Malta Financial Services Authority (MFSA) VFA Rulebook. Available on MFSA Official Website (https://www.mfsa.mt/).
- MFSA Guidance Notes for VFA Licensees. Available on MFSA Official Website.
- MFSA Official Website, VFA Licensees Register. (e.g., https://www.mfsa.mt/financial-services-directory/).
- Financial Intelligence Analysis Unit (FIAU) Implementing Procedures Part I. Available on FIAU Official Website (https://fiaumalta.org/).
- FIAU Annual Report 2022. Available on FIAU Official Website.
- Financial Action Task Force (FATF) Public Statement, June 2023. Available on FATF Official Website (https://www.fatf-gafi.org/).
- European Court of Justice (ECJ) ruling in the Hedqvist case (C-264/14).
Technical Security & Exploit Research Sources:
- OWASP Smart Contract Top 10 | OWASP Foundation
- 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin
- Top 10 Smart Contract Vulnerabilities in 2025 (With Real Hacks & How to Prevent Them) - Hacken
- SoK: Root Cause of $1 Billion Loss in Smart Contract Real- ...
- 400M+ Lost to DeFi Exploits in 2026 — Drift Protocol, Rhea Finance, Step Finance Among Biggest Hacks
- Biggest DeFi Hacks and Exploits of 2026: $1 Billion+ Lost and Counting
- DeFi exploits, on-chain interventions, and the private key: Recent developments in crypto-asset recovery | Travers Smith
- Major DeFi hack becomes the largest of 2026 yet - TheStreet Crypto: Bitcoin and cryptocurrency news, advice, analysis and more
- SlowMist Hacked - SlowMist Zone
- The Top 100 DeFi Hacks Report 2025
Sources
- 5 Smart-Contract Vulnerabilities Fueling DeFi Hacks| KuCoin
- OWASP Smart Contract Top 10 | OWASP Foundation
- Top 10 Smart Contract Vulnerabilities in 2025 (With Real Hacks & How to Prevent Them) - Hacken
- https://www.mfsa.mt/
- https://www.mfsa.mt/financial-services-directory/
- https://fiaumalta.org/
- https://www.fatf-gafi.org/
- SoK: Root Cause of $1 Billion Loss in Smart Contract Real- ...
- 400M+ Lost to DeFi Exploits in 2026 — Drift Protocol, Rhea Finance, Step Finance Among Biggest Hacks
- Biggest DeFi Hacks and Exploits of 2026: $1 Billion+ Lost and Counting
- DeFi exploits, on-chain interventions, and the private key: Recent developments in crypto-asset recovery | Travers Smith
- Major DeFi hack becomes the largest of 2026 yet - TheStreet Crypto: Bitcoin and cryptocurrency news, advice, analysis and more
- SlowMist Hacked - SlowMist Zone
- The Top 100 DeFi Hacks Report 2025