QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!

Target: THORChain

What happened: @THORChain has been exploited for approximately $10 million worth of crypto.

This includes 36.75 BTC valued at around $3 million and approximately $7 million worth of assets from BNB Chain, Ethereum, and Base.

The stolen funds primarily remain in the following addresses:
- bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37
- 0xd477b69551f49C0519F9B18c55030676138890Bd

Tweet URL: View Tweet
🚨 Hack Alert!

Target: VerusCoin

What happened: 🚨 A suspicious transaction has been reported draining approximately $11.4 million in assets.

The incident involved the @VerusCoin Verus-Ethereum bridge contract, where 1625.36 ETH, 103.56 tBTC, and 147.65K USDC were stolen.

The transaction took place at address 0x71518580f36feceffe0721f06ba4703218cd7f63.

Users are advised to remain vigilant regarding this breach.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Adshares

What happened: The Adshares bridge experienced an exploit on May 17, 2026, leading to losses estimated at around $628K. The attacker has refunded 256 $ETH, which is approximately $540.7K, representing 86% of the stolen funds, back to the deployer. This incident highlights a significant security breach where a large amount of funds was compromised and partly returned following the exploit.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: WUSD

What happened: PeckShield reported an exploit affecting WUSD and GLOVE on Ethereum, resulting in approximately $207K being stolen. The attacker swapped the stolen assets for around 98 ETH and subsequently deposited them into Railgun.

This incident showcases a significant security breach, leading to a substantial financial impact on the affected project.

Forensic details indicate the exploiter's actions following the theft, highlighting the method of conversion and usage of the stolen funds.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: SquidRouterModule

What happened: 🚨 An ongoing exploit has been detected targeting the SquidRouterModule on Ethereum and Base.

A total of 86 Gnosis Safes have been drained resulting in a loss of approximately $3 million within about 2 hours.

All stolen tokens were swapped to DAI using Uniswap V3 pools controlled by the attacker.

More details can be found in the thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: THORChain

What happened: THORChain's GG20 TSS library experienced a significant security breach that resulted in a loss of $10.7M across 10 chains in just minutes. The incident was due to a failure in the library's security updates, remaining three years behind the necessary releases. A critical missing proof check allowed a malicious node to leak vault key material during signing rounds. This ultimately led to the reconstruction of the full private key, enabling the theft. Notably, no flash loan or bridge exploit was involved; rather, this event stemmed from vulnerabilities in an inadequately audited cryptographic library that had not been scrutinized since its vulnerabilities became known.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Hyperbridge

What happened: In April, the Hyperbridge was exploited, resulting in a substantial drop of 5-8% in the price of DOT on centralized exchanges.

Following the exploit, major exchanges like Upbit and Bithumb suspended all DOT deposits and withdrawals.

This incident rendered every liquidity pool position and vault share backed by bridged DOT effectively worthless.

The tweet highlights the widespread exposure asset managers, exchanges, and stablecoin issuers face due to such risks, emphasizing the importance of timely awareness in the market.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: New Market Trading

What happened: On May 25, New Market Trading experienced a significant security incident where $3.78 million was lost due to a targeted attack.

Multiple user Gnosis Safe wallets were compromised in this exploit.

The vulnerable contract involved in the hack was identified as the SquidRouterModule.

A detailed report includes the attack contract, available here: https://t.co/RLNAiQknyY.

The sample attack transaction can be viewed at: https://t.co/D8wEY9ZmmR.

The addresses of the attackers are listed as follows:
- https://t.co/mcmStalXaM
- https://t.co/VRCDnSvyBB
- https://t.co/L8YUQe998K

For more information, you can reach out to the protocol contact @frankhep.

πŸ”—*Tweet URL:* [View Tweet](
https://twitter.com/QuillAuditsAI/status/2059230772633153995)
❀1
🚨 Hack Alert!
Target: StakeDAO

What happened: An ongoing exploit has been detected targeting StakeDAO on the Arbitrum chain. The attacker has minted over 5.4 trillion vsdCRV tokens and is currently swapping them for ETH.

This incident highlights the vulnerabilities present in the platform and the active measures being taken to address the situation.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: LegendaryMoneyMonNft

What happened: 🚨 A hack has been reported involving the LegendaryMoneyMonNft contract.

πŸ’Έ Total loss amounts to 85,519.47 USDT.

πŸ” The root cause of the exploit was identified in the cliamRewred function, which allowed arbitrary reward claiming. The authorization relied on verify(), which checks that recoverSigner(...) == admin. However, recoverSigner failed to validate ecrecover returning address(0), and the changeadmin() function permitted setting the admin to a zero address.

πŸ“Œ The attacker exploited this vulnerability using an invalid signature (r=0, s=0, v=27), enabling them to pass the authorization check because the admin was set to the zero address momentarily.

πŸ“Œ Attacker Address: 0xe1582248c593df4b367e131922438fec9d76e787
πŸ“Œ Victim Contract Address: 0x92d60629ff5d53a0098b51e9b1d59546d1d8e5b6
πŸ“Œ Vulnerable Contract Address: 0x92d60629ff5d53a0098b51e9b1d59546d1d8e5b6.

The attacker drained tokens from the contract and subsequently swapped them for USDT via PancakeSwap.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: ONTR

What happened: A security incident was reported by SlowMist involving the ONTR token contract.

Loss amounted to 49.4801 WETH, approximately $98,315.16.

The root cause was an access control vulnerability in the onlyOwner modifier of the ONTR token contract. Due to the owner address being set to zero, any address could bypass checks. The attacker exploited this by changing ownership to their contract through transferOwnership().

Following the exploit, the attacker executed a sequence of calls: desertJasper() added a hidden balance, and glenFlash() executed ashBud(), resulting in a massive balance increase without affecting total supply.

The stolen funds were transferred and swapped for real WETH via PancakeSwap.

Attacker's address: 0xe806b37a9f965bd9d54aadf9560c78957550b760.

Victim pair address: 0xd46d89f4675bc96328fbdeb443842cdb5fcd83fd.

Vulnerable contract address: 0xf074865358b0dd039beee075831f8a2ae6b1f3f3.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Alephium TokenBridge

What happened: 🚨 An exploit targeting the Alephium TokenBridge on Ethereum has been reported. Approximately $815K was drained in about 7 minutes due to the compromise of 3 out of 4 guardian keys, which were used to sign forged VAAs. This resulted in the minting of 13.76M wrapped ALPH, exceeding 100% of the prior supply. Additionally, USDT, USDC, WBTC, and WETH were unlocked from custody. More details are available in the following thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: TesseraDao

What happened: A significant exploit has been reported involving TesseraDao on the BNB Chain.

Approximately 99 million $TSR tokens were minted and subsequently dumped, resulting in a 99% decrease in value.

The exploiter converted the $TSR into around 2.5 million $USDT and transferred the stolen funds to Ethereum. Further laundering of 1,285.5 $ETH was executed using Tornado Cash.

This incident highlights a major security breach in an established project, leading to substantial financial loss.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: New Market Trading

What happened: New Market Trading experienced a significant loss of $3.78 million in just 15 minutes due to a security incident.

The attack resulted in 88 Safes being drained across Ethereum, Base, and Arbitrum.

Notably, there was no flash loan or bridge exploit involved. The attacker exploited a vulnerability by reading a public contract, copying a delegate address, and invoking an unguarded function.

The recommended fix for this vulnerability was quite simple, requiring only one line of code:
require(msg.sender == delegate);

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: gravitybridge

*What happened:* 🚨 The Gravity Bridge was compromised with an attack that resulted in the draining of $5.4 million.

The attacker executed a series of maneuvers involving the minting of 4 worthless tokens on the Osmosis platform, one for each custody asset: USDC, USDT, WETH, and PAXG.

These tokens were then IBC-transferred to the Gravity chain. The attacker called the permissionless deployERC20() method on Ethereum while using a fabricated cosmosDenom string that included the actual token addresses.

The validators attested to this event, allowing the registry to write fake IBC denoms that were incorrectly mapped to the real custody contracts. Consequently, the attacker was able to withdraw fake balances while the bridge released the real tokens.

On-chain evidence highlights that the denom-to-ERC20 registry was improperly written with the true custody token addresses instead of the new wrapper contracts, as confirmed by 4 MsgERC20DeployedClaim transactions on the Gravity chain. The exact code path responsible for this error is still under review in an official postmortem.

*Tweet URL:* [View Tweet](
https://twitter.com/QuillAuditsAI/status/2062164090269921642)
🚨 Hack Alert!
Target: ATM

What happened: 🚨 A security incident involving ATM token has been reported, where an exploit led to a loss of approximately $243,000.

The exploit is identified as a vulnerability in the transferFrom() function, which includes logic that allows the attacker to swap 20% of the transfer amount of ATM for BSC-USD. This enables the attacker to swap out extra funds repeatedly after making the transfer.

The incident highlights the need for vigilance in the crypto space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: GnosisPay

What happened: On 1 June, GnosisPay was exploited, resulting in a loss of approximately $265K.

The incident is reported by CertiK Alert, providing insights into the hack.

For further details, a full analysis can be accessed through the provided link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Infini

What happened: Infini lost $49.5M in two transactions due to a security lapse, where an admin key was never revoked. This incident highlights the vulnerability of neobanks in Web3, inheriting multiple attack surfaces from both traditional and crypto infrastructures. It underscores the importance of comprehensive audits, as a standard audit only covers the bottom layer of the neobank stack, neglecting the other ten critical attack surfaces. The tweet serves as a cautionary tale for those building card-issuing neobanks to consider all potential security weaknesses before their next audit.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: DTXT

What happened: A recent security incident was reported involving the $DTXT/USDT Pair on the Binance Smart Chain (BSC) being drained due to spoofable liquidity-addition detection logic.

The root cause of the exploit stems from how DTXT determines liquidity actions by comparing USDT balance against the pair’s reserves. The attacker exploited this by transferring a small amount of USDT to the pair, misclassifying a large DTXT sell as a liquidity addition and bypassing the associated fees.

The attack utilized a flash loan for assistance, combining liquidity addition/removal strategies with a 1 wei USDT Pair balance spoofing method.

The financial impact of the exploit was significant, with a total profit of approximately 35,041.106 USDT after the repayment of a 1,077,366.001021 USDT flash loan from Moolah.

Forensic details include the attacker’s external owned address (EOA): 0xd304ea1592f733e0a46436a01fe54bd504009526, the attack contract address: 0x3065bc8ed8bd53bdc3fd4633c3097c40726b5f5f, and helper address: 0xd2453ff82e1c5b568ddb260f1f0bb95169895428.

Further details about the DTXT token can be found at 0xac9bf7c320d4ce2d0ac978b83955dd67351897d2 and the DTXT/USDT Pair at 0x90bfc1dbc878ba54858ba8a635b3daebd2ac6c01.

The transaction associated with this incident can be reviewed here: Transaction Link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: Humanity Protocol

What happened: There has been a series of wallet compromises involving the Humanity Protocol.

Approximately $27 million in $H tokens have been transferred and dumped for around 16,320 ETH across six different addresses. The addresses involved in this transaction are as follows:

- 0x456cb73b35022e4b524e5510807776453d984aef
- 0xee4b6b8967aa947ac3aef540ee07ea6099c566f7
- 0xaf2a4989922299eb14a29e332dad1012a8aad3a0
- 0x1dfe5cf3ed5a0ac82fdd0bfcdac7b6c6323f844a
- 0xd1ea823d421e0c829ee11f772af487fd352678ea
- 0x9e995952ef7665b243eeef0693acd7fed7150504

It is essential for users to stay vigilant regarding these wallet compromises.

Tweet URL: View Tweet