Losses by month
By attack class
Share of USD stolen. Count in brackets.
By chain
An incident on several chains is counted once per chain, so shares can sum past 100%.
By target
Who was hit.
Year on year
Same window, one year earlier. Read incident counts with care: the dataset logs more small incidents each year, so a rising count partly reflects wider coverage. USD totals and the median are the steadier comparison.
Run-rate forecast
A full-year projection from the year-to-date pace, with and without the single largest incident. Hack losses are lumpy, so the gap between the two lines is the honest uncertainty.
Ten years of attack classes
Share of each year's USD stolen, by attack class. Darker means a larger share. Uses the target and chain filters; ignores the date range.
What the trend says
Year by year
largest ÷ median = how much one event dominates| Year | Stolen | Incidents | Median | Largest | Largest ÷ median | Top 5 share | CEX share |
|---|
Why the numbers differ
The public dataset beside figures firms have published for the same year. Different scope and method, so the gap is the story a careful report explains.
| Year | Published figure | Published | DefiLlama | Why they can differ |
|---|
Everything below is computed from the dataset. Bracketed lines mark what Merkle's own data would add: the fund-flow graph, alert timestamps and attribution.
Headline options
Context the reader needs
Hack Track draft
Same-technique precedents
X thread
LinkedIn post
Every incident in the period
| Date | Target | USD | Technique | Chains | Type |
|---|
Report draft
Every number below comes from the data on screen. Edit freely: the lint re-runs as you type.
SEO brief
Lint
House style plus search basics.
Sanctioned addresses by asset
Digital currency addresses in the OFAC SDN list.
By sanctions program
An address can sit under several programs.
Screen addresses
Paste one address per line. Exact match against the list; EVM addresses compare case-insensitively. This is the free baseline any exchange can run. What paid analytics adds is attribution and indirect exposure.
Entities with the most listed addresses
| Entity | Addresses | Assets | Programs |
|---|
Story angles in this list
Method
Hack data. The public DefiLlama hacks dataset (api.llama.fi/hacks), fetched live by your browser on every load. If DefiLlama is unreachable the page renders a bundled snapshot dated 1 October 2026. The line under the title says which path served the page.
What the data counts. One row per incident: date, target, USD amount at the time, attack class and technique, chains, target type and returned funds where known. Amounts are DefiLlama's estimates and get revised after an incident as recoveries and fuller accounting arrive.
What it leaves out. Scams, pig butchering, sanctions evasion, ransomware and darknet flows. Those categories need attribution and laundering-path data, which is what a blockchain-intelligence firm's internal graph adds. A Merkle Science version of this desk would join these rows to that graph: where the funds went, which services they touched, how much was frozen.
Year on year. The comparison window is the same calendar dates one year earlier, with the same filters. Incident counts rise partly because the dataset records more small incidents over time, so the draft leads on USD and the median and treats the count as a secondary figure.
Forecast. Year-to-date losses divided by days elapsed, times 365. A second line drops the single largest incident. It is a run-rate and makes no claim about the next big hack.
Sanctions. The OFAC SDN list (SDN.XML from the Treasury sanctions list service), parsed for every "Digital Currency Address" identifier. The page bundles the parse of the 30 September 2026 publication; refresh by re-running the parse.
Trends and peers. Year rows are computed from the dataset. Published figures are quoted from each firm's report or its press coverage, with links. Different firms count different things (hacks only, or hacks plus scams; DeFi only, or exchanges too), so the comparison explains a gap and makes no claim that one figure is wrong.
Hack Track writer. Headlines, context, precedents and posts are generated from the incident row and its neighbours in the dataset. Lines in square brackets mark data a forensics team would add: alert timestamps, fund-flow graphs and attribution, which this public prototype does not have.
Lint. Flags em and en dashes, "X, not Y" style antithesis, hype openers, sentences over 35 words, a title outside 30 to 65 characters, a meta description outside 120 to 160, and a primary keyword missing from the title or opening paragraph.
Who built this. Edward Tay, as a work sample for the Merkle Science Content Writer application. It is an independent prototype on public data and has no connection to Merkle Science's products or internal data.