# Crypto Hacks & Exploits Database

> Crypto Hacks & Exploits Database is a paid API for AI agents from api.vextorium.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-01).

Returns a filterable database of crypto hacks and exploits including date, amount stolen, technique, classification, chains, and whether a bridge or CEX was involved — sourced live from DefiLlama.

## Facts

- Endpoint: POST https://api.vextorium.com/defi-hackeos-pago?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/crypto-hacks-exploits-database-2243e75c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VVi4Bxdgoy49IVFaBAyNf

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability crypto-hacks-exploits-database-2243e75c -d '<json body>'
```

Example prompt: Pull the top 20 largest crypto hacks on Ethereum with at least $5 million stolen — I want to see the date, technique, whether it was a bridge exploit, and how much was recovered.

## When to prefer this

Use this endpoint when you need structured, filterable data on historical crypto hacks and exploits sourced from DefiLlama — particularly when assessing protocol or chain risk, researching specific attack techniques, or aggregating exploit statistics. Prefer this over manual DefiLlama browsing when you need programmatic filtering by chain or minimum stolen amount in an agent workflow.

## Known failure modes

- Invalid chain name returns empty results or an error
- Limit out of range (below 1 or above 50) triggers a validation error
- Minimum amount too high returns zero results
- Upstream DefiLlama data unavailability may cause stale or empty responses
- Malformed request body (missing required 'input' wrapper) returns a schema validation error

## How this service works

Database of crypto hacks and exploits: date, amount stolen, technique, classification, chains and whether it was a bridge or CEX. Filterable by chain and minimum amount. Essential to gauge the risk of a protocol or chain. Live from DefiLlama.

## Output

Returns a JSON object containing: a list of hack records (each with name, date, chains, technique, classification, target type, USD amount stolen, funds returned, and bridge flag), total count of matching records, aggregate USD stolen, and the active filter parameters applied.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method",
    "bodyType",
    "body"
   ],
   "properties": {
    "body": {
     "required": [],
     "properties": {
      "cadena": {
       "type": "string",
       "description": "Filter by chain, e.g. Ethereum, BSC, Solana (optional)"
      },
      "limite": {
       "type": "integer",
       "maximum": 50,
       "minimum": 1,
       "description": "Number of hacks (1-50, default 15)"
      },
      "importe_min": {
       "type": "number",
       "description": "Minimum USD stolen to include (optional)"
      }
     }
    },
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "POST"
     ],
     "type": "string"
    },
    "bodyType": {
     "enum": [
      "json",
      "form-data",
      "text"
     ],
     "type": "string"
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": [
      "object",
      "null"
     ],
     "properties": {
      "nota": {
       "type": [
        "string",
        "null"
       ]
      },
      "filtro": {
       "type": [
        "object",
        "null"
       ],
       "properties": {
        "cadena": {
         "type": [
          "string",
          "null"
         ]
        },
        "importe_min_usd": {
         "type": [
          "number",
          "null"
         ]
        }
       }
      },
      "hackeos": {
       "type": [
        "array",
        "null"
       ],
       "items": {
        "type": [
         "null",
         "object"
        ],
        "properties": {
         "fecha": {
          "type": [
           "null",
           "string"
          ]
         },
         "nombre": {
          "type": [
           "null",
           "string"
          ]
         },
         "cadenas": {
          "type": [
           "array",
           "null"
          ],
          "items": {
           "type": [
            "null",
            "string"
           ]
          }
         },
         "tecnica": {
          "type": [
           "null",
           "string"
          ]
         },
         "fue_puente": {
          "type": [
           "boolean",
           "null"
          ]
         },
         "import
… (truncated)
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "nota": "Histórico de hackeos y exploits. Úsalo para valorar el riesgo de un protocolo o cadena. Fuente: DefiLlama.",
  "filtro": {
   "cadena": "todas",
   "importe_min_usd": 100000000
  },
  "hackeos": [
   {
    "fecha": "2026-09-24",
    "nombre": "Bitget",
    "cadenas": [
     "Ethereum",
     "XRP",
     "Tron",
     "Zcash"
    ],
    "tecnica": "Hot Wallet Key Compromised",
    "fue_puente": false,
    "importe_usd": 387000000,
    "clasificacion": "Key Compromise",
    "tipo_objetivo": "CEX",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2026-09-06",
    "nombre": "Liquid Network",
    "cadenas": [
     "Liquid"
    ],
    "tecnica": "Unbacked Cross-Chain Mint",
    "fue_puente": true,
    "importe_usd": 320000000,
    "clasificacion": "Bridge & Cross-Chain",
    "tipo_objetivo": "Chain",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2026-08-30",
    "nombre": "Tectonic",
    "cadenas": [
     "Cronos"
    ],
    "tecnica": "Donation Attack",
    "fue_puente": false,
    "importe_usd": 124470000,
    "clasificacion": "Token & Share Accounting",
    "tipo_objetivo": "DeFi Protocol",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2026-07-31",
    "nombre": "COLDCARD",
    "cadenas": [
     "Bitcoin"
    ],
    "tecnica": "Weak Key Generation",
    "fue_puente": false,
    "importe_usd": 116000000,
    "clasificacion": "Key Compromise",
    "tipo_objetivo": "Wallet",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2026-04-18",
    "nombre": "Kelp",
    "cadenas": [
     "Ethereum",
     "Arbitrum"
    ],
    "tecnica": "Cross-Chain Message Spoofing",
    "fue_puente": true,
    "importe_usd": 293000000,
    "clasificacion": "Bridge & Cross-Chain",
    "tipo_objetivo": "DeFi Protocol",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2026-04-01",
    "nombre": "Drift Trade",
    "cadenas": [
     "Solana"
    ],
    "tecnica": "Proxy Upgrade Hijack",
    "fue_puente": false,
    "importe_usd": 295000000,
    "clasificacion": "Access Control",
    "tipo_objetivo": "DeFi Protocol",
    "fondos_devueltos_usd": null
   },
   {
    "fecha": "2025-11-03",
    "nombre": "Balancer V2",
    "cadenas": [
     "Ethereum",
     "Arbitrum",
     "Base",
     "Polygon",
     "Sonic",
     "Optimism"
    ],
    "tecnica": "Rounding Error",
    "fue_puente": false,
    "importe_usd": 128000000,
    "clasificacion": "Token & Share Accounting",
    "tipo_objetivo": "DeFi Protocol"
… (truncated)
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/crypto-hacks-exploits-database-2243e75c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.vextorium.com](https://www.zero.xyz/host/api.vextorium.com/llms.txt)
