A protocol gets drained
A hack is money being taken out of the program that was managing it, or off an exchange's wallet. It differs from everything else in this reference in one way: there is no date. Delistings and unlocks are known weeks ahead; a hack is known minutes after.
- Smart contract
- A program on a blockchain that holds money and enforces the rules itself, with nobody in the middle. It cannot be amended after the fact.
- Oracle
- Where a program learns a price from. It has no eyes of its own: it takes a number from an outside source and trusts it.
- Hot wallet
- An exchange wallet whose key sits on a running server so payouts can go out automatically. Convenient to operate and exposed by definition.
- Bridge
- A crossing for a coin between two blockchains. It holds funds on both sides, which makes it the largest single pile of money on the market.
- Value locked
- Everything people have handed a program to hold or put to work. It is both the protocol's working capital and the amount that can be carried away.
- Feed checked
- every 15 min
- Venues with flag watch
- 11
- Last case in the feed
- 2 days ago
Why it happens
Start with where the money sits. In a bank, people and amendable rules are responsible for it. In this part of the market a smart contract is: a program that holds the funds and enforces the rules itself. Hence the defining property — find a flaw in the rules and you take the money, and there is nobody left to reverse the transfer.
The ways it is done are surprisingly few and they repeat year after year. First, the price was faked: a contract has no eyes of its own, it takes a number from an oracle. If that price can be pushed on a thin market, the contract honestly computes against a bent number and pays out more than it should. Second, permissions were laid out badly: a function only the owner should call turned out to be callable by anyone. Third, not a code exploit at all but a leaked key to a hot wallet — that is how money leaves exchanges, and how the largest stories happen. Fourth, an accounting error in who owns which share of a common pot.
Bridges stand apart — the crossings for coins between chains. A bridge holds funds on both sides by design, which makes it the single largest pile of money anywhere on the market. That is what draws the biggest hacks to it.
Why the price drops instantly and usually does not bounce. Two things vanish at once. First, the value that was locked in the protocol: that was its working capital, and without it the thing does not function. Second, trust — and in this part of the market trust is the product: nobody wants to feed money to a program that has been emptied once. On top of that, if the attacker ended up with the project's token, they sell it, and that pressure is not a one-off.
What happens afterwards: sometimes part of the money comes back — a deal with the attacker, a bounty paid, the matter closed. The protocol may relaunch or make holders whole. That is the only real cause of a bounce after a hack, and it arrives as news rather than from the chart.
How people use it
- The news reaches you after the fall. Chasing it is too late — that is the main thing to know about hacks.
- Buying the dip is dangerous: the protocol lost both its money and its trust, and the second does not come back with the price.
- If a bounce does happen, its cause is a recovery of funds or a payout. Watch for that, not for the shape of the chart.
- Sometimes the exchanges are faster than the feed: a coin's deposits or withdrawals get frozen before anyone explains why.
Where it breaks
A hack has no schedule, so it can be neither prepared for nor checked in advance — which is what puts it outside the rest of this reference. And size misleads: the same amount is lethal for a small protocol and unnoticeable for a large one. Judge it against what was held there, not against the headline.
What we track here
- Reads the public incident record daily and the news feed continuously, so an exploit surfaces within the hour rather than the next day.
- Watches exchanges freezing deposits and withdrawals for a token, which sometimes happens before anybody explains why.
- Classifies each case by what was actually broken — a leaked key and a bent oracle are different futures for the same token.
- Keeps the aftermath in view: recovered funds and payouts are the only real reason the price comes back.
- You get the event with its mechanism attached instead of a red candle and a rumour.
- You can judge the damage against what the protocol was holding rather than against the headline number.
- If you hold the token, a freeze is your signal that moving it may stop working shortly.