Six incidents with six distinct attack vectors, and over $4.1 million drained from DeFi protocols and retail users.
This week’s report covers a flash loan exploit on a BNB Chain lending platform, an ERC2771 meta-transaction vulnerability that enabled instant reward theft, a front-end domain hijack with a crypto drainer planted directly on the UI, a supply chain compromise delivering a clipboard hijacker to retail users, an NFT escrow theft via a smart contract flaw, and a front-end phishing redirect that bypassed smart contract security entirely.
Venus Protocol — ~$3.7M | March 15 | BNB Chain
A suspected flash loan exploit on the Venus Protocol lending platform allowed attackers to drain approximately $3.7 million from the BNB Chain-based protocol. Flash loan attacks manipulate price oracles or protocol logic within a single transaction, making them difficult to detect in advance without robust circuit breakers and real-time monitoring.
DBXen — ~$150,000 | March 12 | Multi-chain
Attackers exploited an ERC2771 meta-transaction implementation bug in the DBXen staking platform. The vulnerability allowed them to spoof transaction origin, bypass access controls, instantly claim accumulated staking rewards, and bridge the stolen funds. ERC2771 bugs have become an increasingly targeted class of vulnerability, particularly in protocols that support gasless transactions without proper context validation.
Bonk.fun — $100,000+ | March 12 | Front-end
Threat actors executed a front-end domain hijacking attack against Bonk.fun, planting a crypto drainer directly on the platform’s user interface. Users interacting with what appeared to be the legitimate site were exposed to wallet-draining scripts. This class of attack bypasses all smart contract-level security, targeting users at the interface layer where standard on-chain defenses offer no protection.
AppsFlyer — Unknown Loss | March 9–10 | Supply Chain
A compromised Web SDK distributed by mobile attribution platform AppsFlyer delivered a crypto clipper payload to retail users. The clipper silently replaced copied wallet addresses with attacker-controlled addresses at the clipboard level, redirecting transactions without user awareness. This supply chain attack affected downstream users of applications integrating the compromised SDK, with the total financial impact still undetermined.
Gondi — ~$230,000 | March 9 | Smart Contract
An exploit targeting Gondi’s Sell and Repay smart contract function led to the theft of NFTs held in escrow. The vulnerability allowed attackers to extract escrowed assets by manipulating the contract’s settlement logic. Gondi has announced plans to compensate affected users.
Compound Finance — $0 User Loss | March 8 | Front-end
Compound Finance’s front-end domain was compromised and redirected users to a phishing site. No user funds were lost in this incident, but the attack demonstrates a pattern that has now affected Compound multiple times: sophisticated threat actors targeting the DNS and domain infrastructure layer rather than the underlying protocol. Smart contract audits and on-chain security provide no protection against this attack class.
Takeaway
This week’s incidents reflect two converging trends. The first is the continued diversification of attack vectors: threat actors are no longer focusing exclusively on smart contract exploits. Front-end hijacks, supply chain compromises, and meta-transaction vulnerabilities each require different detection and response frameworks. The second is the critical role of response speed. In flash loan exploits and domain hijacks alike, the window for meaningful intervention is narrow.
If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.