QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!
Target: ATM

What happened: 🚨 A security incident involving ATM token has been reported, where an exploit led to a loss of approximately $243,000.

The exploit is identified as a vulnerability in the transferFrom() function, which includes logic that allows the attacker to swap 20% of the transfer amount of ATM for BSC-USD. This enables the attacker to swap out extra funds repeatedly after making the transfer.

The incident highlights the need for vigilance in the crypto space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: GnosisPay

What happened: On 1 June, GnosisPay was exploited, resulting in a loss of approximately $265K.

The incident is reported by CertiK Alert, providing insights into the hack.

For further details, a full analysis can be accessed through the provided link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Infini

What happened: Infini lost $49.5M in two transactions due to a security lapse, where an admin key was never revoked. This incident highlights the vulnerability of neobanks in Web3, inheriting multiple attack surfaces from both traditional and crypto infrastructures. It underscores the importance of comprehensive audits, as a standard audit only covers the bottom layer of the neobank stack, neglecting the other ten critical attack surfaces. The tweet serves as a cautionary tale for those building card-issuing neobanks to consider all potential security weaknesses before their next audit.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: DTXT

What happened: A recent security incident was reported involving the $DTXT/USDT Pair on the Binance Smart Chain (BSC) being drained due to spoofable liquidity-addition detection logic.

The root cause of the exploit stems from how DTXT determines liquidity actions by comparing USDT balance against the pair’s reserves. The attacker exploited this by transferring a small amount of USDT to the pair, misclassifying a large DTXT sell as a liquidity addition and bypassing the associated fees.

The attack utilized a flash loan for assistance, combining liquidity addition/removal strategies with a 1 wei USDT Pair balance spoofing method.

The financial impact of the exploit was significant, with a total profit of approximately 35,041.106 USDT after the repayment of a 1,077,366.001021 USDT flash loan from Moolah.

Forensic details include the attacker’s external owned address (EOA): 0xd304ea1592f733e0a46436a01fe54bd504009526, the attack contract address: 0x3065bc8ed8bd53bdc3fd4633c3097c40726b5f5f, and helper address: 0xd2453ff82e1c5b568ddb260f1f0bb95169895428.

Further details about the DTXT token can be found at 0xac9bf7c320d4ce2d0ac978b83955dd67351897d2 and the DTXT/USDT Pair at 0x90bfc1dbc878ba54858ba8a635b3daebd2ac6c01.

The transaction associated with this incident can be reviewed here: Transaction Link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: Humanity Protocol

What happened: There has been a series of wallet compromises involving the Humanity Protocol.

Approximately $27 million in $H tokens have been transferred and dumped for around 16,320 ETH across six different addresses. The addresses involved in this transaction are as follows:

- 0x456cb73b35022e4b524e5510807776453d984aef
- 0xee4b6b8967aa947ac3aef540ee07ea6099c566f7
- 0xaf2a4989922299eb14a29e332dad1012a8aad3a0
- 0x1dfe5cf3ed5a0ac82fdd0bfcdac7b6c6323f844a
- 0xd1ea823d421e0c829ee11f772af487fd352678ea
- 0x9e995952ef7665b243eeef0693acd7fed7150504

It is essential for users to stay vigilant regarding these wallet compromises.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Asterix

What happened: Asterix experienced a reported attack a few hours ago, resulting in a loss of approximately $40,000.

The incident shares similarities with a previous attack on Flooring, which had a total financial impact exceeding $900,000, from which around $500,000 was rescued by white hat hackers.

Both Asterix and Flooring are based on a common design utilizing a 404-style ERC20/ERC721 hybrid contract under different names/variants.

The root cause of the vulnerabilities seems to stem from a high-bit NFT ID shift/overflow issue. This led to NFT ID reuse and severe breakdowns in ownership, approval, and accounting functions due to an underflow error.

The attack exploited the desynchronization of ownership, approvals, balances, and NFT backing. By manipulating crafted IDs with different high bits that collide with low bits, the attacker could abuse various functions such as exchange, transfer, and unwrap, thereby inflating the fungible token balance and draining liquidity pools, particularly extracting WETH and other valuable assets.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BPool

What happened: A significant exploit has impacted the BPool contract, specifically at address 0x0fa3E014fA2E751F78e53Dca766faC2223327329.

The incident resulted in a loss of approximately 282 ETH, which is equivalent to around $471,000.

This event has raised concerns within the community regarding the security measures in place for such contracts.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: TOP

What happened: The alert describes a specific security incident involving the token $TOP.

Approximately $1.59 million was lost as a result of the attack. The attacker exploited the token's low market value to acquire over 50% of the voting power. This allowed them to pass and execute a governance proposal that resulted in minting a large quantity of TOP to themselves.

The newly minted TOP was swapped for WETH through the Balancer pool, effectively draining the existing liquidity from the liquidity pool (LP).

An attack transaction has been provided for reference: https://t.co/itXv0NCwGO.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Drift

What happened: The tweet discusses an incident involving Drift where the attacker utilized a nine-day strategy to exploit the system.

The attacker created four durable nonce accounts and conducted a council migration with four new signers.

Additionally, there was a timelock set to zero, and all of these actions were visible on-chain prior to the fund drain.

For further details, a full timeline of events is available through the provided links.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: MILCplatform

What happened: 🚨 A significant security incident has been reported involving the @MILCplatform bridge on both BNB and Ethereum networks.

Blockaid's Exploit Detection system has identified a compromise where the historical bridge admin wallet was exploited.

This incident allowed the new exploiter EOA to withdraw MLT (MediLoc Token) from bridge contracts. Furthermore, the attacker has gained admin control, facilitating the transfer of assets to their wallets.

Details about the attack method and the compromised roles indicate serious implications for the affected bridge contracts.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Raydium

What happened: A security incident was reported involving the project @Raydium, where the platform was drained of $1.3 million worth of crypto.

The attacker's initial funding came from the exchange #KuCoin. After the theft was executed, the stolen funds were bridged from #Solana to Ethereum (ETH).

Additionally, the attacker deposited 810 $ETH into #TornadoCash and 7 ETH into #FixedFloat.

This incident highlights significant vulnerabilities in the protocol.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Humanityprot

What happened: On June 9, the identity protocol Humanity experienced a significant exploit leading to the loss of approximately $36 million. The incident occurred after an employee's laptop was compromised, which exposed multisig keys to the attackers. This breach allowed them to gain administrative control over the bridge across Ethereum and BNB Chain.

Following the exploit, the attackers upgraded the contracts, drained around 141 million $H, and minted an additional 200 million $H directly to their own wallet. This malicious activity resulted in a drastic crash of the $H token, which fell by over 80%.

The incident is described as an operational security failure rather than a smart contract bug, emphasizing the importance of securing endpoints against key compromises. Cyvers has reported that monitoring on-chain behavior in real time is critical to defending against such breaches.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: aztecnetwork

What happened: A suspicious transaction has been detected involving the Router contract of Aztec Network.

The exploit resulted in a loss of approximately $2.19 million. The attacker's address is reported as 0x0f18d8b44a740272f0be4d08338d2b165b7edd17 on the Ethereum blockchain.

This incident highlights the ongoing vulnerabilities within DeFi contracts and the need for further security measures.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Thetanuts Finance

What happened: Thetanuts Finance experienced an exploit on the Ethereum blockchain, leading to the theft of approximately $105.5K in USDC.

The attack was facilitated by a flaw in the legacy vault's redemption formula, which used backing * amount / totalSupply to determine share payouts. The attacker manipulated the index token supply, resulting in inflated redemptions. This enabled multiple cycles of minting and claiming assets beyond the original deposits.

Key forensic details include:
- Attacker address: 0x30498e4466789E534c72e03B52A16c978655b41e
- Loot wallet: 0xAf3a0FdBFB0e3127247B66a042310e09C32F2299
- Vulnerable index token: 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7
- Attack transaction details: Link to transaction

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Aztec Connect

What happened: A detailed technical analysis has been published regarding the $2.19 million asset theft from Aztec Connect.

The exploit occurred through a vulnerability in a deprecated Aztec Connect RollupProcessor contract, which allowed attackers to bypass the settlement boundary. This manipulation resulted in the creation of an L1/L2 state discrepancy, facilitating the draining of approximately $2.19 million from the protocol.

The attack leveraged an inconsistency between numRealTxs and decodedslots, enabling forged deposits to be processed by the zero-knowledge proof while evading detection from the L1 settlement verification process.

The report elaborates on several aspects of the attack, including the root cause of the vulnerability, the discrepancy between ZK commitment and the settlement boundary, and the mechanisms of the atomic exploit execution, alongside details on on-chain fund tracing.

This incident underscores the critical necessity for Rollup systems to ensure that settlement boundaries align strictly with the commitment scopes of zero-knowledge public inputs.

πŸ”—*Tweet URL:* [View Tweet](
https://twitter.com/SlowMistTeam/status/2066543275981557823)
❀1
🚨 Hack Alert!
Target: escapeHatch

What happened: A follow-up exploit impacted the escapeHatch on a different deployment, specifically the "Private Rollup Bridge" contract (0x7379).

The root cause of the exploit involved circuit public input binding issues, where the olddataroot was transformed into two independent witnesses. One was utilized in the join-split circuit for private note membership verification, while another was exposed as the public input validated against L1 state.

This configuration allowed an attacker to create a fake Merkle tree with self-owned notes of arbitrary value, successfully proving membership against this fake root. As a result, the Solidity verification check was bypassed, allowing the attacker to withdraw funds.

While the escape hatch circuit has been eliminated from the codebase in aztec-connect PR #402, the deployed verifier contract still contains the vulnerable EscapeHatchVk that permits flawed proofs to pass on-chain verification.

There is an additional note regarding a similar unbinding issue, though it was not vital for the current attack.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: PancakeSwap

What happened: On June 20, 2026, a PancakeSwap V2 pool pairing OLPC against LABUBU was exploited on BNB Chain.

The exploit resulted in the theft of USDT valued at approximately $1.11M, with the attacker netting around $960K from the operation.

The root cause of the vulnerability is under investigation. However, on-chain fund analysis indicates that a transfer of about 10 OLPC was routed through the attacker contract, which subsequently triggered the burning of 51.9M OLPC and 124K LABUBU to 0x…dead from the OLPC/LABUBU pair 0xedb7...f365. As a consequence, the pair's actual balance collapsed while its cached reserves were not resynced, allowing the attacker to sweep the LABUBU side and route it through the LABUBU/WBNB and WBNB/USDT pools, ultimately exiting with 1,115,903 USDT.

The attacker's address is 0x18d6c39ae9e537f948aa2212d44d8c23944fc188.

Additional on-chain details include:
- OLPC token: 0x58815cdf9955121a6274680ab396a36fc9e00000
- LABUBU token: 0x3494dfe19b721dac6c5c8d7470c8f89548177777
- Drained pool: 0xedb7dcb4cdfec957f8df5cbf5e94229a6cc9f365
- Routing pools:
- LABUBU/WBNB 0xdfacdc33e913710ead31ee40f9c5363ea673c421
- WBNB/USDT 0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae
- Attack transaction: link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: jaredsmev

What happened: 🚨 A recent exploit detected by the Blockaid Exploit Detection system involved the @jaredsmev MEV bot on Ethereum.

The attack occurred due to attacker-controlled contracts that deceived an automated MEV execution system, leading to unauthorized token approvals.

As a result of this manipulation, a significant sum of $7.5 million was drained from the system.

Forensic details include the exploit transaction link provided: https://t.co/ltmzveNGuv.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: taikoxyz

What happened: Blockaid's exploit detection system has identified an ongoing exploit targeting @taikoxyz's ERC20 Vault on Ethereum. The financial impact is assessed to be over $1 million.

Further details are presumably available in the thread that follows this tweet, which may elaborate on the nature of the exploit and its implications.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: KyberNetwork

What happened: On November 22, 2023, KyberNetwork experienced flashloan exploits across multiple chains, resulting in a significant financial impact with a loss of approximately $47 million.

The exploiter address moved 2,000 ETH, equating to around $3.3 million, to Tornado Cash through the address 0x6B686cf613F05D09C097eECFc349c091e6F2ad8D just yesterday.

This incident highlights the ongoing vulnerabilities in DeFi protocols and the critical need for vigilance in the space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: AIDCToken

What happened: 🚨 SlowMist TI Alert 🚨

AIDC token on BSC has been exploited.

πŸ’Έ Loss: 220.12 WBNB (~$120929.35)

πŸ” Root Cause: AIDCToken's _sellTransfer() accumulates a 30% burn amount without deducting it from the seller. Subsequently, any non-Pair transfer triggers _executeAccumulatedBurn(), which incorrectly burns tokens from the uniswapPair balance instead of the seller. After burning, sync() is called, artificially deflating the AIDC reserve in the AMM, allowing the attacker to drain WBNB.

πŸ“Œ Attacker: 0x89eb2c99e970d831525c7a52badc290afa116b63
πŸ“Œ Victim: 0x2725033282b3bd4be8873b7f0f622c18e3b7cbd8 (Pancake V2 AIDC/WBNB Pair)
πŸ“Œ Vulnerable Contract: 0x5021d71859f81b4c905b573591db8f9cc4a0c6fe (AIDCToken)

The attacker exploited a flawed burn mechanism where sell-induced burn debt is wrongly imposed on the liquidity pool, enabling repeated reserve manipulation and a final swap that drained nearly all WBNB from the Pair.

πŸ”—Tweet URL: View Tweet