CASE STUDY: How our investigation discovered the ZondaCrypto liquidity issues, one of Europe's largest crypto scandals. [Read the case study]

Incident Reports // 16.03.2026 // 3 min read // recoveris-team

Weekly Incident Report: March 9–15, 2026

Over $4.1M drained across six incidents in March 9–15: flash loan exploits, front-end hijacks, a supply chain attack, and an NFT escrow theft. Weekly incident breakdown by Recoveris.

Six incidents with six distinct attack vectors, and over $4.1 million drained from DeFi protocols and retail users.

This week’s report covers a flash loan exploit on a BNB Chain lending platform, an ERC2771 meta-transaction vulnerability that enabled instant reward theft, a front-end domain hijack with a crypto drainer planted directly on the UI, a supply chain compromise delivering a clipboard hijacker to retail users, an NFT escrow theft via a smart contract flaw, and a front-end phishing redirect that bypassed smart contract security entirely.


Venus Protocol — ~$3.7M | March 15 | BNB Chain

A suspected flash loan exploit on the Venus Protocol lending platform allowed attackers to drain approximately $3.7 million from the BNB Chain-based protocol. Flash loan attacks manipulate price oracles or protocol logic within a single transaction, making them difficult to detect in advance without robust circuit breakers and real-time monitoring.

Read full coverage


DBXen — ~$150,000 | March 12 | Multi-chain

Attackers exploited an ERC2771 meta-transaction implementation bug in the DBXen staking platform. The vulnerability allowed them to spoof transaction origin, bypass access controls, instantly claim accumulated staking rewards, and bridge the stolen funds. ERC2771 bugs have become an increasingly targeted class of vulnerability, particularly in protocols that support gasless transactions without proper context validation.

Read full coverage


Bonk.fun — $100,000+ | March 12 | Front-end

Threat actors executed a front-end domain hijacking attack against Bonk.fun, planting a crypto drainer directly on the platform’s user interface. Users interacting with what appeared to be the legitimate site were exposed to wallet-draining scripts. This class of attack bypasses all smart contract-level security, targeting users at the interface layer where standard on-chain defenses offer no protection.

Read full coverage


AppsFlyer — Unknown Loss | March 9–10 | Supply Chain

A compromised Web SDK distributed by mobile attribution platform AppsFlyer delivered a crypto clipper payload to retail users. The clipper silently replaced copied wallet addresses with attacker-controlled addresses at the clipboard level, redirecting transactions without user awareness. This supply chain attack affected downstream users of applications integrating the compromised SDK, with the total financial impact still undetermined.

Read full coverage


Gondi — ~$230,000 | March 9 | Smart Contract

An exploit targeting Gondi’s Sell and Repay smart contract function led to the theft of NFTs held in escrow. The vulnerability allowed attackers to extract escrowed assets by manipulating the contract’s settlement logic. Gondi has announced plans to compensate affected users.

Read full coverage


Compound Finance — $0 User Loss | March 8 | Front-end

Compound Finance’s front-end domain was compromised and redirected users to a phishing site. No user funds were lost in this incident, but the attack demonstrates a pattern that has now affected Compound multiple times: sophisticated threat actors targeting the DNS and domain infrastructure layer rather than the underlying protocol. Smart contract audits and on-chain security provide no protection against this attack class.

Read full coverage


Takeaway

This week’s incidents reflect two converging trends. The first is the continued diversification of attack vectors: threat actors are no longer focusing exclusively on smart contract exploits. Front-end hijacks, supply chain compromises, and meta-transaction vulnerabilities each require different detection and response frameworks. The second is the critical role of response speed. In flash loan exploits and domain hijacks alike, the window for meaningful intervention is narrow.

If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.

Schedule a confidential consultation with Recoveris

Read more

Crypto Source of Funds report: evidence checklist
18.09.2026

Crypto Source of Funds report: evidence checklist

What should a crypto Source of Funds report include? An evidence checklist for bank reviews, exchange records, DeFi profits and complex asset histories.

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call
16.09.2026

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call

Crypto asset recovery moves at blockchain speed. Marcin Zarakowski and Patrick Prinz explain tracing, freezing and Europe’s intelligence gap.

Why I joined Recoveris
15.09.2026

Why I joined Recoveris

Aleksander Góra explains why he joined Recoveris to scale digital asset compliance, investigations and Source of Funds services for institutions.