Skip to main content
Glama

Hacks & exploits

security_incidents
Read-only

Search public crypto hack and exploit records by protocol, technique, date, chain, or minimum USD lost, and see total losses to assess DeFi risk.

Instructions

Public record of crypto hacks/exploits (DefiLlama hacks DB): search by protocol/technique, filter by date (YYYY-MM-DD), min USD lost, chain. Returns matches and total lost.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
chainNo
limitNo
queryNo
sinceNo
minUsdNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.3.0

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare readOnlyHint=true and openWorldHint=true, so the agent knows this is a safe read and that it queries an external source. The description adds that it uses the DefiLlama hacks DB and returns matches and total lost, which is useful context. However, it doesn't disclose pagination behavior, rate limits, or the exact shape of returned matches, which would be helpful for an open-world read.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense sentence with no waste, front-loading the resource and then the filtering options. It is efficient but slightly packed; a second sentence on return format or usage context could help without bloat.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 5-parameter read-only tool with no output schema, the description covers the core purpose and main filters but leaves gaps: the limit parameter is undocumented, return structure is only vaguely described ('matches and total lost'), and no guidance on behavior when no results are found. It is adequate but incomplete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It names the concepts of each parameter (protocol/technique for query, date for since, min USD lost for minUsd, chain for chain) but omits limit entirely and doesn't specify formats (e.g., YYYY-MM-DD is given for dates, which is helpful). It adds meaning beyond the schema but not fully.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: search and filter a public record of crypto hacks/exploits from the DefiLlama hacks DB. It is clearly distinct from siblings like list_hackathons or sanctions_check. It doesn't name a sibling it might be confused with, but its purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage (search by protocol/technique, filter by date, min USD lost, chain) but does not state when to use this tool versus alternatives like sanctions_check or a general search. No explicit when-not-to-use guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.