How to Read a Smart Contract Audit Report
An audit badge tells you almost nothing. The scope section tells you nearly everything — which commit was reviewed, which contracts were in it, and what was excluded.
Searches every incident record, jurisdiction page, glossary term and guide.
An audit badge tells you almost nothing. The scope section tells you nearly everything — which commit was reviewed, which contracts were in it, and what was excluded.
| Disclosed | Incident | Chain | Reported impact | Status |
|---|---|---|---|---|
| Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check | Ethereum | approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 fev 2025) | Resolved | |
| Radiant Capital Signing Compromise, October 2024: What Happened & What to Check | Arbitrum, BNB Chain | approx. US$50 million(Radiant Capital, 17 out 2024) | Contained | |
| WazirX Multisig Compromise, July 2024: What Happened & What to Check | Ethereum | approx. US$234.9 million(WazirX, 18 jul 2024) | Contained | |
| DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check | Bitcoin | 4,502.9 BTC(DMM Bitcoin, 31 maio 2024) | Resolved | |
| Munchables Insider Key Compromise, March 2024: What Happened & What to Check | Blast | approx. US$62 million (returned)(Munchables, 26 mar 2024) | Resolved | |
| Orbit Chain Bridge Compromise, December 2023: What Happened & What to Check | Ethereum, Orbit Chain | approx. US$81.5 million(Orbit Chain, 1 jan 2024) | Contained |
New Zealand has consulted on whether its technology-neutral approach remains adequate, rather than moving to a MiCA-style dedicated regime.
As ofThe substantive question in France is now the transition of nationally registered PSANs into MiCA authorisation, and the AMF publishes the register of who holds what.
As ofThe Dutch registration regime was notably strict in practice, and the transition to European authorisation has been the main development.
As ofOfficial communication has consisted mainly of cautions that virtual currencies are not recognised and that firms offering them are not licensed domestically. Central bank work on distributed ledger technology has proceeded on a separate track from any retail crypto authorisation.
As ofCold storage describes where a key is held. It says nothing about how a transaction gets approved — which is where several…
A token approval is a standing authorisation that outlives the transaction that created it. Here is how to see what yours have…
The most expensive failures in crypto have not broken cryptography. They changed what the signer was shown. Here is what to look…
The hours after a genuine incident are when fake advisories, fake support and fake recovery tools work best. Here is how to…
Self-custody removes one category of risk and adds another. Understanding which is which is the whole decision.
Bridges account for several of the largest losses on record. The reason is structural, and it is visible in every one of…
Who writes here, and what they are working on
Contributor · Ann Arbor, United States
AJ Vicens joined Conisec in 2026 as a contributor, compiling incident records from primary sources — official post-mortems, status pages and on-chain evidence —…
Contributor · Washington, D.C., United States
Jenna McLaughlin joined Conisec in 2026 as a contributor, writing on crypto regulation and maintaining jurisdiction records, working from regulators' own publications rather than…
Contributor · London, United Kingdom
Jordan Robertson joined Conisec in 2026 as a contributor, covering exchange and protocol incidents, with a focus on what a reader can verify for…
Newsroom
Conisec Staff is the byline on factual records compiled and verified by the newsroom rather than written by a single named reporter — Incident…
No tool on Conisec asks for a seed phrase, a private key, a signature or a wallet connection. Nothing on this site connects to a wallet.
Still unsure about something? Ask us — or read how we source and verify, our editorial guidelines and what we will never ask you for.