Crypto Hacks & Exploits Database
Pricing
from $2.50 / 1,000 results
Crypto Hacks & Exploits Database
Searchable database of crypto hacks & exploits from DefiLlama (540+ incidents). Filter by date, min amount lost, chain, technique, classification, target type and bridge-hack flag; sort by date or size. Flat CSV/Excel, no API key, no proxy.
Pricing
from $2.50 / 1,000 results
Rating
0.0
(0)
Developer
Berkan Kaplan
Maintained by CommunityActor stats
0
Bookmarked
7
Total users
0
Monthly active users
10 days ago
Last modified
Categories
Share
Crypto Hacks & Exploits Database 🛡️
foXLabs crypto series: Token unlocks · Funding rates · DeFi volume & fees · Stablecoins
🎉 Turn crypto exploit history into a clean, structured database — no login, no API key, one row per incident, with the project, amount lost, technique, chain and date. Built for security, DeFi risk and crypto research teams.
🔍 What is the Crypto Hacks & Exploits Database — and when should you use it?
Give this actor project names or chains and it returns matching incidents from public crypto hack / exploit records — as clean, deduplicated rows you can filter, export or feed to an AI agent. Every run reads the source live.
Use it when you need: a project’s exploit history; hacks by technique or chain; or a timeline of incidents.
Use something else when: you need live protocol metrics — this is historical exploit records, not analytics.
🤖 Use with AI agents
Already on the Apify MCP server? Ask for this Actor by name: foxlabs/crypto-hacks-database.
Your agent can pay for its own runs. This Actor is pay-per-event with agentic payments, so an agent can discover it, run it and settle the bill over x402 (USDC on Base) or Skyfire — no Apify account or API token of its own. Billing is the same either way: per delivered record, never for errors.
Otherwise paste this into Claude, ChatGPT, Cursor or any MCP-enabled assistant:
I want to pull crypto exploit company records using the Apify Actor `foxlabs/crypto-hacks-database`.Input: `sinceDate`, `minAmountUsd`, `chain`, `technique` and more — see the Input table below. `maxResults` caps how many results are returned.Start with: {"minAmountUsd":1000000,"maxResults":1000}Ask me what to look up, run the Actor, then summarise the rows as a table.
The machine-readable API, MCP config and OpenAPI definition live at apify.com/foxlabs/crypto-hacks-database.md.
📋 Overview
Everything you need to turn public crypto hack / exploit records into clean, structured data — in one actor, with no login, cookies or API key.
Why teams pick this actor:
- ✅ Whole feed, one call — name or ID in, matching incidents out.
- 🧹 No empty-promise columns — only fields this registry actually fills; degenerate columns are removed.
- 🔗 Stable identifiers — every row carries the source's own IDs, ready to join across runs and to other Fox Labs actors.
- 💰 Per-row pricing — a minimal price per delivered row, no subscription.
- 🤖 Agent-ready — MCP + x402 agentic payments.
✨ Features
- 🔍 Name or ID lookup — relevance-ranked name search or exact registry-ID lookup.
- 🏢 Full entity profile — status, legal form, formation date, address and the registry’s own contact fields.
- 🧹 Clean schema — deduplicated camelCase rows, ready for CSV/Excel/JSON.
🎬 Quick Start
curl -X POST "https://api.apify.com/v2/acts/foxlabs~crypto-hacks-database/runs?token=YOUR_TOKEN" \-H "Content-Type: application/json" \-d '{"minAmountUsd":1000000,"maxResults":1000}'
🚀 Getting Started (3 steps)
- Choose your targets — project names or chains.
- Set the cap —
maxResultslimits how many results are returned. - Run and export — get a clean dataset as JSON, CSV or Excel.
📥 Input
{"minAmountUsd":1000000,"maxResults":1000}
| Field | Type | Description |
|---|---|---|
sinceDate | string | Only include hacks on or after this date (YYYY-MM-DD). Leave empty for all time (540+ incidents back to ~2011). |
minAmountUsd | integer | Only include hacks where at least this much (USD) was lost. 0 = no filter. |
chain | string | Keep only hacks involving this chain. Exact chain label, case-insensitive — use DefiLlama's own spelling: "Ethereum", "BSC", "Solana", "Arbitrum", "Base",… |
technique | string | Keep only hacks whose attack technique contains this text (substring, case-insensitive) — e.g. "Private Key", "Reentrancy", "Flashloan", "Oracle", "Phishing",… |
classification | string | Exact classification filter (e.g. "Protocol Logic", "Infrastructure", "Ecosystem", "Rugpull"). Leave empty for all. |
targetType | string | Exact target type filter (e.g. "DeFi Protocol", "CEX", "Wallet", "Token", "Gaming"). For bridge hacks use the bridge-hacks flag below — "Bridge" is not a target… |
bridgeHackOnly | boolean | Return only cross-chain bridge hacks. |
onlyReturnedFunds | boolean | Return only incidents where DefiLlama records recovered/returned funds (~29 incidents). DefiLlama's recovery data is a USD amount and is inconsistent for some… |
sortBy | string | Order by most recent or by largest amount lost. |
maxResults | integer | Cap the number of incident rows returned. |
📤 Output
One row per result, saved to the dataset. Every row carries scrapedAt. Lookups that cannot be completed are reported in the run log rather than silently dropped.
| Field | Description |
|---|---|
rank | Rank |
dateIso | Date Iso |
name | Name |
amountUsd | Amount Usd |
amountUsdCompact | Amount Usd Compact |
chainsText | Chains Text |
classification | Classification |
technique | Technique |
targetType | Target Type |
bridgeHack | Bridge Hack |
returnedFunds | Returned Funds |
returnedFundsUsd | Returned Funds Usd |
returnedFundsUsdCompact | Returned Funds Usd Compact |
language | Language |
defillamaId | Defillama Id |
generatedAtIso | Generated At Iso |
💼 Use cases
1. Risk screening — check a project’s exploit history. Input: project names. Output: incidents + amounts. Use: a risk assessment.
2. Threat research — analyse exploits by technique. Input: chains or keywords. Output: incidents + techniques. Use: a threat report.
3. Insurance / audit — size losses in a category. Input: chains. Output: incidents + amounts. Use: quantify risk.
🔗 Integration
JavaScript / Node.js
import { ApifyClient } from 'apify-client';const client = new ApifyClient({ token: 'YOUR_TOKEN' });const run = await client.actor('foxlabs/crypto-hacks-database').call({"minAmountUsd":1000000,"maxResults":1000});const { items } = await client.dataset(run.defaultDatasetId).listItems();console.log(items[0]);
Python
from apify_client import ApifyClientclient = ApifyClient('YOUR_TOKEN')run = client.actor('foxlabs/crypto-hacks-database').call(run_input={"minAmountUsd":1000000,"maxResults":1000})for item in client.dataset(run['defaultDatasetId']).iterate_items():print(item)
Automation (n8n / Zapier / Make): schedule or webhook → HTTP request to the actor API with your input → handle the JSON dataset → push to a sheet, CRM or dashboard.
📊 Pricing
Pay-per-event: per delivered record. Empty or failed lookups are never billed. View current pricing.
❓ FAQ
Do I need an account, login or API key? No. This reads public crypto hack / exploit records.
What do I search by? Project names or chains.
How current is the data? Every run queries the source live, so results are as fresh as the registry.
What does each row cover? One incident: the project, amount lost, exploit technique, chain and date.
Can I export to CSV / Excel / JSON? Yes — directly from the Apify dataset.
🐛 Troubleshooting
- Fewer rows than expected — raise
maxResults, or refine the input. - A name returns an unexpected entity — it matched a similar registered name; search the exact registry ID.
- No rows for a name — try the entity’s exact legal name or its registry ID.
⚖️ Is it legal to scrape this data?
This actor reads publicly reported crypto hack and exploit records. Results can still contain personal data (e.g. a person’s name); personal data is protected by the GDPR and similar laws, so only process it with a legitimate basis. See Apify’s blog post on the legality of web scraping.
🤝 Support & contact
- 🌐 Website: data.foxlabs.com.tr
- 📧 Email: info@foxlabs.com.tr
- 🐛 Issues: open a ticket in the Actor’s Issues tab
- 🧰 More clean B2B data actors: Fox Labs on Apify
Changelog
0.1.17 — 2026-09-20 — README examples corrected against the real input schema
- The README's code examples did not match this Actor. They used
queriesandmaxResultsPerQuery— keys that do not exist in this Actor's input schema — with a placeholder value, and the input table listed those same phantom fields. Anyone who copied the AI-agent, cURL, JavaScript or Python example got a failing run. Every example now uses the real schema and matches the Console prefill:{"minAmountUsd":1000000,"maxResults":1000} - The input table is regenerated from
input_schema.json, so it lists the fields the Actor actually accepts. - Removed claims carried over from the same generator template where present: "formation / status monitoring", "a canonical registry record for KYB and due diligence", "every row carries
query", andindustrydescribed as a NACE code. - No code, output field or pricing change.
0.1 — 2026-09-07
- Enabled AI-agent payments (x402) + rebuilt the README to the full standard (What-is / when, AI-agents + x402 agentic payments + MCP, Overview, Features, Use cases, Integration, FAQ, Troubleshooting, Support & contact).
0.0
- Initial release: data from public crypto hack / exploit records by name or registry ID.