EthSecurity
5.23K subscribers
112 photos
20 files
766 links
Download Telegram
sorra staking lost 43 k$. why? because of in every withdraw userRewardDistributed increasing. hacker withdraw 1wei multiple time. https://app.blocksec.com/explorer/tx/eth/0x6439d63cc57fb68a32ea8ffd8f02496e8abad67292be94904c0b47a4d14ce90d @EthSecurity1
πŸ”₯8❀1🫑1
odosprotocol on ETH and Base, hacked for ~$50k . The root cause is arbitrary call vulnerability. attack tx: https://app.blocksec.com/explorer/tx/base/0xd10faa5b33ddb501b1dc6430896c966048271f2510ff9ed681dd6d510c5df9f6 @EthSecurity1
πŸ”₯3πŸ‘1
Forwarded from Vladimir S. | Officer's Channel (Vladimir S. | officercia)
DeepSeek has been hacked: all of their data in the public domain - secret keys, unencrypted chats, logs, and even the backend.

Researchers from wiz.io were performing a normal infrastructure check when they unintentionally uncovered a database that is fully open, allowing anyone to obtain access.

I cannot confirm or deny their conclusions at this time. But I think it's interesting enough news to share: x.com/officer_cia/status/1884740598579540060

#ai #news #security
πŸ”₯6❀1πŸ‘1
Vladimir S. | Officer's Channel
DeepSeek has been hacked: all of their data in the public domain - secret keys, unencrypted chats, logs, and even the backend. Researchers from wiz.io were performing a normal infrastructure check when they unintentionally uncovered a database that is fully…
1 Million Deepseek Data Breach

DeepSeek AI Data Breach Exposes Over 1 Million Logs and Sensitive Secrets - Chinese AI startup DeepSeek left a database exposed online, leaking over 1 million log lines, chat histories, API keys, and sensitive backend details

Seems service had backdoor
@EthSecurity1
250 LBTC hacked form ionicmoney. why? because ionic listed fake LBTC on mode chain

Thus, the attacker can call mint() with fabricated inputs and pass the check. @EthSecurity1
🀯8😁2😱1
Web3 Security Auditor's 2024 Rewind - The Highlights https://blog.openzeppelin.com/web3-security-auditors-2024-rewind @EthSecurity1
πŸ‘7
Zklend been hacked for ~3600 ETH on starknet @EthSecurity1
🀬14πŸ”₯3⚑1
ZKlend Hack rootcause: The attacker manipulated the "lending_accumulator" to be very large at 4.069297906051644020, then took advantage of the rounding error during ztoken mint() and withdraw() to repeatedly deposit 4.069297906051644021 wstETH getting 2 wei then withdraw 4.069297906051644020*1.5 -1 = 6.103946859077466029 wstETH to expend just 1 wei. @EthSecurity1
πŸ‘13
Forwarded from Vladimir S. | Officer's Channel (Vladimir S. | officercia)
SlowMist founder: we discovered that the hacker who attacked zkLend has a close connection to the hacker who attacked EraLend in July 2023, and we suspect they are the same person: x.com/officer_cia/status/1890132436589445291?12

#security #privacy #investigation
πŸ”₯7😁3πŸ‘1
Urgent Update for Geth Users!
Attention validators! If you are running Geth v1.15.1, upgrade to v1.15.2 immediately to prevent potential financial loss! @EthSecurity1
⚑5πŸ”₯2
Seems Abstract wallets are being drained !
cardex_space involved
~ 180 ether loss
@EthSecurity1
😁5🀯5