# GET /defi/exploits: $0.005 per call

Recent crypto hacks and exploits (DeFi, bridges, exchanges) from DefiLlama's database: date, amount, technique, chains, funds returned, with totals by type, plus live alerts for protocols whose TVL is suddenly crashing (possible ongoing exploit). Filters: ?days=30&chain=Ethereum&protocol=...&minAmountUsd=1000000.

- **Price:** $0.005 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Answers cached for:** 5 min
- **Data sources:** DefiLlama hacks and protocols (free)
- **Lane:** Crypto & on-chain ([OpenAPI](/openapi/crypto.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/defi-exploits](/sample/defi-exploits). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/defi-exploits"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/defi/exploits?days=30&minAmountUsd=0&limit=25"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/defi/exploits?days=30&minAmountUsd=0&limit=25");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("defi-exploits", {"days":30,"minAmountUsd":0,"limit":25});
```

## Inputs

- `days` (integer; default `30`): Look back this many days.
- `chain` (string): Only hacks on this chain, e.g. Ethereum, Solana, Base (optional).
- `protocol` (string): Only hacks whose name contains this (optional).
- `minAmountUsd` (number; default `0`): Smallest loss to include (USD).
- `limit` (integer; default `25`): Most hacks to list.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "window": {
    "days": 30,
    "from": "2026-08-29"
  },
  "totals": {
    "count": 12,
    "amountUsd": 512000000,
    "returnedUsd": 3000000,
    "byClassification": [
      {
        "classification": "Key Compromise",
        "count": 4,
        "amountUsd": 401000000
      }
    ]
  },
  "hacks": [
    {
      "date": "2026-09-24",
      "name": "Bitget",
      "classification": "Key Compromise",
      "technique": "Hot Wallet Key Compromised",
      "amountUsd": 387000000,
      "chains": [
        "Ethereum",
        "Tron"
      ],
      "bridgeHack": false,
      "targetType": "CEX",
      "returnedFundsUsd": null,
      "source": null
    }
  ],
  "tvlAlerts": [
    {
      "name": "Example Lend",
      "slug": "example-lend",
      "category": "Lending",
      "tvlUsd": 8200000,
      "change1h": -18.2,
      "change1d": -41.5,
      "chains": [
        "Base"
      ],
      "reason": "TVL down 41.5% in 24h"
    }
  ],
  "source": "DefiLlama",
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /token/price](/services/token-price) ($0.005): Live price of any token on Base, Solana, Ethereum, BNB, Arbitrum, Polygon, Optimism or Avalanche from DEX data: USD price, total liquidity, 24h volume, buys/sel
- [GET /token/safety](/services/token-safety) ($0.02): Rug-pull and scam check for any token on Base, Solana, Ethereum, BNB, Arbitrum, Polygon, Optimism or Avalanche.
- [GET /token/report/cached](/services/token-report-cached) ($0.05): Full token report, cached tier (answers up to 15 minutes old, half price): safety (honeypot, taxes, owner powers), holders (concentration, exchange/fund/locked 
- [GET /token/report](/services/token-report) ($0.10): Full token report, live: safety (honeypot, taxes, owner powers), holders (concentration, exchange/fund/locked share), liquidity (depth, locks, pools), price act
- [GET /token/report/deep](/services/token-report-deep) ($0.25): Deep token report: everything in /token/report (safety (honeypot, taxes, owner powers), holders (concentration, exchange/fund/locked share), liquidity (depth, l
- [GET /token/new](/services/token-new) ($0.01): New token launches with real liquidity: tokens whose first DEX pool opened in the last hour (up to 24h) with at least $10k liquidity (adjustable), newest first,
- [GET /token/whales](/services/token-whales) ($0.02): Whale and exchange flows for a token on Base, Ethereum, Arbitrum, Optimism or Polygon, from its latest ~250 transfers: large transfers, deposits/withdrawals per
- [GET /wallet](/services/wallet) ($0.01): Wallet profile on Base, Ethereum or Solana: native balance, token holdings with USD values (top 25), total portfolio value, whether it is a contract, ENS name, 

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).