QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!
Target: AftermathFi

What happened: An exploit has been detected involving AftermathFi, resulting in approximately $900,000 worth of USDC being drained from the platform. The situation is currently under investigation.

Users are advised to remain vigilant as details are still emerging regarding this incident.

Further updates will follow as more information becomes available.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wasabi Protocol

What happened: 🚨 Alert: A significant security incident has been detected involving the Wasabi Protocol.

An address funded via Tornado Cash has deployed a malicious contract on both the Base and Ethereum networks.

This incident has led to the theft of approximately $4.5M across multiple assets, which include $WETH, $PEPE, $MOG, $USDC, $BITCOIN, $VIRTUAL, $ZYN, $REKT, $cbBTC, and $AERO.

The stolen funds were consolidated into $ETH and then bridged to the Ethereum network, followed by distribution across multiple addresses.

🔗Tweet URL: View Tweet
🚨 Hack Alert!

Target: KelpDAO

What happened: In April 2026, the crypto space experienced 40 major hacks totaling $647M, marking a significant 1,140% increase from March's $52.2M.

Among these, the KelpDAO and DriftProtocol exploits rank in the Top 10 hacks since 2021.

The KelpDAO exploiter used rsETH supplied to Aave to borrow a substantial amount of ETH, subsequently laundering the stolen funds into Bitcoin. This incident has posed a serious risk of bad debt exposure within the Aave ecosystem.

In response to these exploitations, DeFi United is taking coordinated measures to absorb the resulting liquidity shortfall and prevent further systemic contagion.


Top 5 noted hacks include:
- KelpDAO: $292M (Ranked #7, Jan 2021 – Apr 2026)
- Drift: $285M (Ranked #9, Jan 2021 – Apr 2026)
- Rhea Finance: $20M
- Grinex: $13.74M
- Wasabi Protocol

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Wasabi Perp

What happened: Wasabi Perp drained over $5 million across Ethereum, Base, and Blast this morning.

No smart contract bug or oracle manipulation was involved. The incident resulted from a single private key that held admin authority across all three chains. When this key was compromised, the protocol was drained through its own privileged functions in a span of two hours.

The attack could have been prevented with various measures:

- Drainer deployment: Hypernative's detection engine flagged the attacker's orchestrator contract three minutes before the first drain, suggesting that a pre-configured response could have paused vaults before any transactions settled.

- Privilege escalation: Monitoring RoleGranted events against a pre-approved destination list could have flagged unscheduled grants from a known admin wallet, signaling key compromise.

- Vault drain: Implementing a strategy whitelist on strategyDeposit could have prevented collateral from being routed to an unrecognized address, ensuring that the attacker's contract never received funds.

- Pool implementation swap: Governance policies that block any upgradeToAndCall to pre-unauthorized implementations would have stopped the pool from flipping to attacker bytecode in the same block as the proposal.

The contracts functioned as intended. All signatures were valid, indicating that the underlying trust model was the gap that led to the incident.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wasabi Perp

What happened: Wasabi Perp suffered a significant loss of over $5M last week across three different chains.

The first drain transaction occurred at 07:49 UTC, while Hypernative's detection engine had flagged the attacker's orchestrator contract as a suspected drainer just three minutes prior.

Additionally, there was a monitor identifying drainer-class bytecode being deployed from wallets linked to protocol admin infrastructure, which surfaced this signal before any privileged call took place. This was crucial information that, if paired with an automated response, could have led to pausing vaults before the initial transaction finalized.

Despite the warning signal being available, the required response to mitigate the loss was not configured in time.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: EkuboProtocol

What happened: A suspicious transaction has been detected involving @EkuboProtocol.

An address funded via Railgun executed a single transaction, generating approximately $1.4 million on the Ethereum network.

The attacker received 17 WBTC, swapped them for ETH, and subsequently deposited the funds into @TornadoCash.

Individuals who approved specific v2 contracts should revoke access immediately to prevent potential losses.

For those wishing to safeguard against such scams, they are invited to contact the account to arrange a demo of their security solution.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: trustedvolumes

What happened: @trustedvolumes has suffered a significant security breach resulting in the loss of approximately $5.9M. The funds stolen include $3.02M in Ethereum (ETH), $1.37M in Wrapped Bitcoin (WBTC), and 1.47M in stablecoins.

The attacker has converted the stolen funds by swapping them for 2.513K ETH. This incident was reported by PeckShieldAlert, highlighting the ongoing vulnerabilities in the platform.

🔗Tweet URL: View Tweet
🚨 Hack Alert!

Target: TrustedVolumes

What happened: A security incident involving the @trustedvolumes platform occurred on May 7th, resulting in a loss of approximately $6.7 million.

The exploiter has laundered a total of $278K in stolen funds to date. Specifically, they deposited 10.2 ETH, valued at $23.6K, to Tornado Cash and laundered 110 ETH, approximately $250K, through THORChain to Bitcoin.

Additionally, the attacker attempted to deposit 0.5 ETH to Railgun but ultimately reversed the transaction.

Forensic details indicate the ongoing laundering of the stolen funds, highlighting the impact and methods used in this exploit.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: TransitFinance

What happened: 🚨 Hack Alert: @TransitFinance has reportedly been hacked for approximately $1.88 million.

The stolen funds are currently sitting in a specific address holding $DAI: 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5.

For further details, refer to the provided link.

Tweet URL: View Tweet
😁1
🚨 Hack Alert!

Target: THORChain

What happened: @THORChain has been exploited for approximately $10 million worth of crypto.

This includes 36.75 BTC valued at around $3 million and approximately $7 million worth of assets from BNB Chain, Ethereum, and Base.

The stolen funds primarily remain in the following addresses:
- bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37
- 0xd477b69551f49C0519F9B18c55030676138890Bd

Tweet URL: View Tweet
🚨 Hack Alert!

Target: VerusCoin

What happened: 🚨 A suspicious transaction has been reported draining approximately $11.4 million in assets.

The incident involved the @VerusCoin Verus-Ethereum bridge contract, where 1625.36 ETH, 103.56 tBTC, and 147.65K USDC were stolen.

The transaction took place at address 0x71518580f36feceffe0721f06ba4703218cd7f63.

Users are advised to remain vigilant regarding this breach.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Adshares

What happened: The Adshares bridge experienced an exploit on May 17, 2026, leading to losses estimated at around $628K. The attacker has refunded 256 $ETH, which is approximately $540.7K, representing 86% of the stolen funds, back to the deployer. This incident highlights a significant security breach where a large amount of funds was compromised and partly returned following the exploit.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: WUSD

What happened: PeckShield reported an exploit affecting WUSD and GLOVE on Ethereum, resulting in approximately $207K being stolen. The attacker swapped the stolen assets for around 98 ETH and subsequently deposited them into Railgun.

This incident showcases a significant security breach, leading to a substantial financial impact on the affected project.

Forensic details indicate the exploiter's actions following the theft, highlighting the method of conversion and usage of the stolen funds.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: SquidRouterModule

What happened: 🚨 An ongoing exploit has been detected targeting the SquidRouterModule on Ethereum and Base.

A total of 86 Gnosis Safes have been drained resulting in a loss of approximately $3 million within about 2 hours.

All stolen tokens were swapped to DAI using Uniswap V3 pools controlled by the attacker.

More details can be found in the thread.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: THORChain

What happened: THORChain's GG20 TSS library experienced a significant security breach that resulted in a loss of $10.7M across 10 chains in just minutes. The incident was due to a failure in the library's security updates, remaining three years behind the necessary releases. A critical missing proof check allowed a malicious node to leak vault key material during signing rounds. This ultimately led to the reconstruction of the full private key, enabling the theft. Notably, no flash loan or bridge exploit was involved; rather, this event stemmed from vulnerabilities in an inadequately audited cryptographic library that had not been scrutinized since its vulnerabilities became known.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Hyperbridge

What happened: In April, the Hyperbridge was exploited, resulting in a substantial drop of 5-8% in the price of DOT on centralized exchanges.

Following the exploit, major exchanges like Upbit and Bithumb suspended all DOT deposits and withdrawals.

This incident rendered every liquidity pool position and vault share backed by bridged DOT effectively worthless.

The tweet highlights the widespread exposure asset managers, exchanges, and stablecoin issuers face due to such risks, emphasizing the importance of timely awareness in the market.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: New Market Trading

What happened: On May 25, New Market Trading experienced a significant security incident where $3.78 million was lost due to a targeted attack.

Multiple user Gnosis Safe wallets were compromised in this exploit.

The vulnerable contract involved in the hack was identified as the SquidRouterModule.

A detailed report includes the attack contract, available here: https://t.co/RLNAiQknyY.

The sample attack transaction can be viewed at: https://t.co/D8wEY9ZmmR.

The addresses of the attackers are listed as follows:
- https://t.co/mcmStalXaM
- https://t.co/VRCDnSvyBB
- https://t.co/L8YUQe998K

For more information, you can reach out to the protocol contact @frankhep.

🔗*Tweet URL:* [View Tweet](
https://twitter.com/QuillAuditsAI/status/2059230772633153995)
1
🚨 Hack Alert!
Target: StakeDAO

What happened: An ongoing exploit has been detected targeting StakeDAO on the Arbitrum chain. The attacker has minted over 5.4 trillion vsdCRV tokens and is currently swapping them for ETH.

This incident highlights the vulnerabilities present in the platform and the active measures being taken to address the situation.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: LegendaryMoneyMonNft

What happened: 🚨 A hack has been reported involving the LegendaryMoneyMonNft contract.

💸 Total loss amounts to 85,519.47 USDT.

🔍 The root cause of the exploit was identified in the cliamRewred function, which allowed arbitrary reward claiming. The authorization relied on verify(), which checks that recoverSigner(...) == admin. However, recoverSigner failed to validate ecrecover returning address(0), and the changeadmin() function permitted setting the admin to a zero address.

📌 The attacker exploited this vulnerability using an invalid signature (r=0, s=0, v=27), enabling them to pass the authorization check because the admin was set to the zero address momentarily.

📌 Attacker Address: 0xe1582248c593df4b367e131922438fec9d76e787
📌 Victim Contract Address: 0x92d60629ff5d53a0098b51e9b1d59546d1d8e5b6
📌 Vulnerable Contract Address: 0x92d60629ff5d53a0098b51e9b1d59546d1d8e5b6.

The attacker drained tokens from the contract and subsequently swapped them for USDT via PancakeSwap.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: ONTR

What happened: A security incident was reported by SlowMist involving the ONTR token contract.

Loss amounted to 49.4801 WETH, approximately $98,315.16.

The root cause was an access control vulnerability in the onlyOwner modifier of the ONTR token contract. Due to the owner address being set to zero, any address could bypass checks. The attacker exploited this by changing ownership to their contract through transferOwnership().

Following the exploit, the attacker executed a sequence of calls: desertJasper() added a hidden balance, and glenFlash() executed ashBud(), resulting in a massive balance increase without affecting total supply.

The stolen funds were transferred and swapped for real WETH via PancakeSwap.

Attacker's address: 0xe806b37a9f965bd9d54aadf9560c78957550b760.

Victim pair address: 0xd46d89f4675bc96328fbdeb443842cdb5fcd83fd.

Vulnerable contract address: 0xf074865358b0dd039beee075831f8a2ae6b1f3f3.

🔗Tweet URL: View Tweet