A flash-loan exploit of the donation/liquidation logic in the Euler Finance lending protocol drained roughly $197M. The attacker later returned nearly all of the funds, and the assets were recovered.
No verified attacker addresses are listed for this incident. We only publish addresses confirmed against an authoritative source.
Figures are approximate, compiled from public reporting. Attacker addresses are included only where verified against an authoritative source. Attribution (e.g. Lazarus Group) is shown only when publicly stated by an official body.
© 2026 ChainAnalyzer. All rights reserved.