π¨ Hack Alert!
Target: MILCplatform
What happened: π¨ A significant security incident has been reported involving the @MILCplatform bridge on both BNB and Ethereum networks.
Blockaid's Exploit Detection system has identified a compromise where the historical bridge admin wallet was exploited.
This incident allowed the new exploiter EOA to withdraw MLT (MediLoc Token) from bridge contracts. Furthermore, the attacker has gained admin control, facilitating the transfer of assets to their wallets.
Details about the attack method and the compromised roles indicate serious implications for the affected bridge contracts.
πTweet URL: View Tweet
Target: MILCplatform
What happened: π¨ A significant security incident has been reported involving the @MILCplatform bridge on both BNB and Ethereum networks.
Blockaid's Exploit Detection system has identified a compromise where the historical bridge admin wallet was exploited.
This incident allowed the new exploiter EOA to withdraw MLT (MediLoc Token) from bridge contracts. Furthermore, the attacker has gained admin control, facilitating the transfer of assets to their wallets.
Details about the attack method and the compromised roles indicate serious implications for the affected bridge contracts.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Raydium
What happened: A security incident was reported involving the project @Raydium, where the platform was drained of $1.3 million worth of crypto.
The attacker's initial funding came from the exchange #KuCoin. After the theft was executed, the stolen funds were bridged from #Solana to Ethereum (ETH).
Additionally, the attacker deposited 810 $ETH into #TornadoCash and 7 ETH into #FixedFloat.
This incident highlights significant vulnerabilities in the protocol.
πTweet URL: View Tweet
Target: Raydium
What happened: A security incident was reported involving the project @Raydium, where the platform was drained of $1.3 million worth of crypto.
The attacker's initial funding came from the exchange #KuCoin. After the theft was executed, the stolen funds were bridged from #Solana to Ethereum (ETH).
Additionally, the attacker deposited 810 $ETH into #TornadoCash and 7 ETH into #FixedFloat.
This incident highlights significant vulnerabilities in the protocol.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Humanityprot
What happened: On June 9, the identity protocol Humanity experienced a significant exploit leading to the loss of approximately $36 million. The incident occurred after an employee's laptop was compromised, which exposed multisig keys to the attackers. This breach allowed them to gain administrative control over the bridge across Ethereum and BNB Chain.
Following the exploit, the attackers upgraded the contracts, drained around 141 million $H, and minted an additional 200 million $H directly to their own wallet. This malicious activity resulted in a drastic crash of the $H token, which fell by over 80%.
The incident is described as an operational security failure rather than a smart contract bug, emphasizing the importance of securing endpoints against key compromises. Cyvers has reported that monitoring on-chain behavior in real time is critical to defending against such breaches.
πTweet URL: View Tweet
Target: Humanityprot
What happened: On June 9, the identity protocol Humanity experienced a significant exploit leading to the loss of approximately $36 million. The incident occurred after an employee's laptop was compromised, which exposed multisig keys to the attackers. This breach allowed them to gain administrative control over the bridge across Ethereum and BNB Chain.
Following the exploit, the attackers upgraded the contracts, drained around 141 million $H, and minted an additional 200 million $H directly to their own wallet. This malicious activity resulted in a drastic crash of the $H token, which fell by over 80%.
The incident is described as an operational security failure rather than a smart contract bug, emphasizing the importance of securing endpoints against key compromises. Cyvers has reported that monitoring on-chain behavior in real time is critical to defending against such breaches.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: aztecnetwork
What happened: A suspicious transaction has been detected involving the Router contract of Aztec Network.
The exploit resulted in a loss of approximately $2.19 million. The attacker's address is reported as 0x0f18d8b44a740272f0be4d08338d2b165b7edd17 on the Ethereum blockchain.
This incident highlights the ongoing vulnerabilities within DeFi contracts and the need for further security measures.
Tweet URL: View Tweet
Target: aztecnetwork
What happened: A suspicious transaction has been detected involving the Router contract of Aztec Network.
The exploit resulted in a loss of approximately $2.19 million. The attacker's address is reported as 0x0f18d8b44a740272f0be4d08338d2b165b7edd17 on the Ethereum blockchain.
This incident highlights the ongoing vulnerabilities within DeFi contracts and the need for further security measures.
Tweet URL: View Tweet
π¨ Hack Alert!
Target: Thetanuts Finance
What happened: Thetanuts Finance experienced an exploit on the Ethereum blockchain, leading to the theft of approximately $105.5K in USDC.
The attack was facilitated by a flaw in the legacy vault's redemption formula, which used
Key forensic details include:
- Attacker address: 0x30498e4466789E534c72e03B52A16c978655b41e
- Loot wallet: 0xAf3a0FdBFB0e3127247B66a042310e09C32F2299
- Vulnerable index token: 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7
- Attack transaction details: Link to transaction
Tweet URL: View Tweet
Target: Thetanuts Finance
What happened: Thetanuts Finance experienced an exploit on the Ethereum blockchain, leading to the theft of approximately $105.5K in USDC.
The attack was facilitated by a flaw in the legacy vault's redemption formula, which used
backing * amount / totalSupply to determine share payouts. The attacker manipulated the index token supply, resulting in inflated redemptions. This enabled multiple cycles of minting and claiming assets beyond the original deposits.Key forensic details include:
- Attacker address: 0x30498e4466789E534c72e03B52A16c978655b41e
- Loot wallet: 0xAf3a0FdBFB0e3127247B66a042310e09C32F2299
- Vulnerable index token: 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7
- Attack transaction details: Link to transaction
Tweet URL: View Tweet
π¨ Hack Alert!
Target: Aztec Connect
What happened: A detailed technical analysis has been published regarding the $2.19 million asset theft from Aztec Connect.
The exploit occurred through a vulnerability in a deprecated Aztec Connect RollupProcessor contract, which allowed attackers to bypass the settlement boundary. This manipulation resulted in the creation of an L1/L2 state discrepancy, facilitating the draining of approximately $2.19 million from the protocol.
The attack leveraged an inconsistency between numRealTxs and decodedslots, enabling forged deposits to be processed by the zero-knowledge proof while evading detection from the L1 settlement verification process.
The report elaborates on several aspects of the attack, including the root cause of the vulnerability, the discrepancy between ZK commitment and the settlement boundary, and the mechanisms of the atomic exploit execution, alongside details on on-chain fund tracing.
This incident underscores the critical necessity for Rollup systems to ensure that settlement boundaries align strictly with the commitment scopes of zero-knowledge public inputs.
π*Tweet URL:* [View Tweet](https://twitter.com/SlowMistTeam/status/2066543275981557823)
Target: Aztec Connect
What happened: A detailed technical analysis has been published regarding the $2.19 million asset theft from Aztec Connect.
The exploit occurred through a vulnerability in a deprecated Aztec Connect RollupProcessor contract, which allowed attackers to bypass the settlement boundary. This manipulation resulted in the creation of an L1/L2 state discrepancy, facilitating the draining of approximately $2.19 million from the protocol.
The attack leveraged an inconsistency between numRealTxs and decodedslots, enabling forged deposits to be processed by the zero-knowledge proof while evading detection from the L1 settlement verification process.
The report elaborates on several aspects of the attack, including the root cause of the vulnerability, the discrepancy between ZK commitment and the settlement boundary, and the mechanisms of the atomic exploit execution, alongside details on on-chain fund tracing.
This incident underscores the critical necessity for Rollup systems to ensure that settlement boundaries align strictly with the commitment scopes of zero-knowledge public inputs.
π*Tweet URL:* [View Tweet](https://twitter.com/SlowMistTeam/status/2066543275981557823)
β€1
π¨ Hack Alert!
Target: escapeHatch
What happened: A follow-up exploit impacted the escapeHatch on a different deployment, specifically the "Private Rollup Bridge" contract (0x7379).
The root cause of the exploit involved circuit public input binding issues, where the olddataroot was transformed into two independent witnesses. One was utilized in the join-split circuit for private note membership verification, while another was exposed as the public input validated against L1 state.
This configuration allowed an attacker to create a fake Merkle tree with self-owned notes of arbitrary value, successfully proving membership against this fake root. As a result, the Solidity verification check was bypassed, allowing the attacker to withdraw funds.
While the escape hatch circuit has been eliminated from the codebase in aztec-connect PR #402, the deployed verifier contract still contains the vulnerable EscapeHatchVk that permits flawed proofs to pass on-chain verification.
There is an additional note regarding a similar unbinding issue, though it was not vital for the current attack.
πTweet URL: View Tweet
Target: escapeHatch
What happened: A follow-up exploit impacted the escapeHatch on a different deployment, specifically the "Private Rollup Bridge" contract (0x7379).
The root cause of the exploit involved circuit public input binding issues, where the olddataroot was transformed into two independent witnesses. One was utilized in the join-split circuit for private note membership verification, while another was exposed as the public input validated against L1 state.
This configuration allowed an attacker to create a fake Merkle tree with self-owned notes of arbitrary value, successfully proving membership against this fake root. As a result, the Solidity verification check was bypassed, allowing the attacker to withdraw funds.
While the escape hatch circuit has been eliminated from the codebase in aztec-connect PR #402, the deployed verifier contract still contains the vulnerable EscapeHatchVk that permits flawed proofs to pass on-chain verification.
There is an additional note regarding a similar unbinding issue, though it was not vital for the current attack.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: PancakeSwap
What happened: On June 20, 2026, a PancakeSwap V2 pool pairing OLPC against LABUBU was exploited on BNB Chain.
The exploit resulted in the theft of USDT valued at approximately $1.11M, with the attacker netting around $960K from the operation.
The root cause of the vulnerability is under investigation. However, on-chain fund analysis indicates that a transfer of about 10 OLPC was routed through the attacker contract, which subsequently triggered the burning of 51.9M OLPC and 124K LABUBU to
The attacker's address is
Additional on-chain details include:
- OLPC token:
- LABUBU token:
- Drained pool:
- Routing pools:
- LABUBU/WBNB
- WBNB/USDT
- Attack transaction: link.
πTweet URL: View Tweet
Target: PancakeSwap
What happened: On June 20, 2026, a PancakeSwap V2 pool pairing OLPC against LABUBU was exploited on BNB Chain.
The exploit resulted in the theft of USDT valued at approximately $1.11M, with the attacker netting around $960K from the operation.
The root cause of the vulnerability is under investigation. However, on-chain fund analysis indicates that a transfer of about 10 OLPC was routed through the attacker contract, which subsequently triggered the burning of 51.9M OLPC and 124K LABUBU to
0xβ¦dead from the OLPC/LABUBU pair 0xedb7...f365. As a consequence, the pair's actual balance collapsed while its cached reserves were not resynced, allowing the attacker to sweep the LABUBU side and route it through the LABUBU/WBNB and WBNB/USDT pools, ultimately exiting with 1,115,903 USDT.The attacker's address is
0x18d6c39ae9e537f948aa2212d44d8c23944fc188. Additional on-chain details include:
- OLPC token:
0x58815cdf9955121a6274680ab396a36fc9e00000 - LABUBU token:
0x3494dfe19b721dac6c5c8d7470c8f89548177777 - Drained pool:
0xedb7dcb4cdfec957f8df5cbf5e94229a6cc9f365 - Routing pools:
- LABUBU/WBNB
0xdfacdc33e913710ead31ee40f9c5363ea673c421 - WBNB/USDT
0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae - Attack transaction: link.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: jaredsmev
What happened: π¨ A recent exploit detected by the Blockaid Exploit Detection system involved the @jaredsmev MEV bot on Ethereum.
The attack occurred due to attacker-controlled contracts that deceived an automated MEV execution system, leading to unauthorized token approvals.
As a result of this manipulation, a significant sum of $7.5 million was drained from the system.
Forensic details include the exploit transaction link provided: https://t.co/ltmzveNGuv.
πTweet URL: View Tweet
Target: jaredsmev
What happened: π¨ A recent exploit detected by the Blockaid Exploit Detection system involved the @jaredsmev MEV bot on Ethereum.
The attack occurred due to attacker-controlled contracts that deceived an automated MEV execution system, leading to unauthorized token approvals.
As a result of this manipulation, a significant sum of $7.5 million was drained from the system.
Forensic details include the exploit transaction link provided: https://t.co/ltmzveNGuv.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: taikoxyz
What happened: Blockaid's exploit detection system has identified an ongoing exploit targeting @taikoxyz's ERC20 Vault on Ethereum. The financial impact is assessed to be over $1 million.
Further details are presumably available in the thread that follows this tweet, which may elaborate on the nature of the exploit and its implications.
πTweet URL: View Tweet
Target: taikoxyz
What happened: Blockaid's exploit detection system has identified an ongoing exploit targeting @taikoxyz's ERC20 Vault on Ethereum. The financial impact is assessed to be over $1 million.
Further details are presumably available in the thread that follows this tweet, which may elaborate on the nature of the exploit and its implications.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: KyberNetwork
What happened: On November 22, 2023, KyberNetwork experienced flashloan exploits across multiple chains, resulting in a significant financial impact with a loss of approximately $47 million.
The exploiter address moved 2,000 ETH, equating to around $3.3 million, to Tornado Cash through the address 0x6B686cf613F05D09C097eECFc349c091e6F2ad8D just yesterday.
This incident highlights the ongoing vulnerabilities in DeFi protocols and the critical need for vigilance in the space.
πTweet URL: View Tweet
Target: KyberNetwork
What happened: On November 22, 2023, KyberNetwork experienced flashloan exploits across multiple chains, resulting in a significant financial impact with a loss of approximately $47 million.
The exploiter address moved 2,000 ETH, equating to around $3.3 million, to Tornado Cash through the address 0x6B686cf613F05D09C097eECFc349c091e6F2ad8D just yesterday.
This incident highlights the ongoing vulnerabilities in DeFi protocols and the critical need for vigilance in the space.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: AIDCToken
What happened: π¨ SlowMist TI Alert π¨
AIDC token on BSC has been exploited.
πΈ Loss: 220.12 WBNB (~$120929.35)
π Root Cause: AIDCToken's
π Attacker: 0x89eb2c99e970d831525c7a52badc290afa116b63
π Victim: 0x2725033282b3bd4be8873b7f0f622c18e3b7cbd8 (Pancake V2 AIDC/WBNB Pair)
π Vulnerable Contract: 0x5021d71859f81b4c905b573591db8f9cc4a0c6fe (AIDCToken)
The attacker exploited a flawed burn mechanism where sell-induced burn debt is wrongly imposed on the liquidity pool, enabling repeated reserve manipulation and a final swap that drained nearly all WBNB from the Pair.
πTweet URL: View Tweet
Target: AIDCToken
What happened: π¨ SlowMist TI Alert π¨
AIDC token on BSC has been exploited.
πΈ Loss: 220.12 WBNB (~$120929.35)
π Root Cause: AIDCToken's
_sellTransfer() accumulates a 30% burn amount without deducting it from the seller. Subsequently, any non-Pair transfer triggers _executeAccumulatedBurn(), which incorrectly burns tokens from the uniswapPair balance instead of the seller. After burning, sync() is called, artificially deflating the AIDC reserve in the AMM, allowing the attacker to drain WBNB.π Attacker: 0x89eb2c99e970d831525c7a52badc290afa116b63
π Victim: 0x2725033282b3bd4be8873b7f0f622c18e3b7cbd8 (Pancake V2 AIDC/WBNB Pair)
π Vulnerable Contract: 0x5021d71859f81b4c905b573591db8f9cc4a0c6fe (AIDCToken)
The attacker exploited a flawed burn mechanism where sell-induced burn debt is wrongly imposed on the liquidity pool, enabling repeated reserve manipulation and a final swap that drained nearly all WBNB from the Pair.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Humanity Protocol
What happened: In June 2026, the crypto space experienced 40 significant hacks, accumulating total losses of $75.87 million, marking a 7.13% month-over-month decrease from May, where losses were $81.7 million.
Key incidents include the #Humanity Protocol hack, which alone resulted in a staggering $31 million loss.
Additionally, both the #Aztec Bridge and #Aztec Connect were targeted in the same month, suffering combined losses of approximately $4 million.
The exploiter of #Humanity Protocol has been actively laundering stolen funds across various chains, including Bitcoin, Solana, Hyperliquid, and BNB Chain. Notably, these funds have been mixed with proceeds associated with the #KelpDAO exploiter, indicating a potential connection between the threat actors involved in both incidents.
Other notable hacks from the month included the Syscoin Bridge with losses of $10 million, the JaredFromSubway.eth MEV bot with $7.5 million, and more.
This overview highlights significant financial impacts on various projects and demonstrates the ongoing challenges in securing assets in the crypto ecosystem.
πTweet URL: View Tweet
Target: Humanity Protocol
What happened: In June 2026, the crypto space experienced 40 significant hacks, accumulating total losses of $75.87 million, marking a 7.13% month-over-month decrease from May, where losses were $81.7 million.
Key incidents include the #Humanity Protocol hack, which alone resulted in a staggering $31 million loss.
Additionally, both the #Aztec Bridge and #Aztec Connect were targeted in the same month, suffering combined losses of approximately $4 million.
The exploiter of #Humanity Protocol has been actively laundering stolen funds across various chains, including Bitcoin, Solana, Hyperliquid, and BNB Chain. Notably, these funds have been mixed with proceeds associated with the #KelpDAO exploiter, indicating a potential connection between the threat actors involved in both incidents.
Other notable hacks from the month included the Syscoin Bridge with losses of $10 million, the JaredFromSubway.eth MEV bot with $7.5 million, and more.
This overview highlights significant financial impacts on various projects and demonstrates the ongoing challenges in securing assets in the crypto ecosystem.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: hinkalprotocol
*What happened:* Specter has reported that the @hinkalprotocol was exploited for approximately $820K. The exploiter deposited 410 $ETH, which is around $700K, into Tornado Cash. Additionally, 44.7 $ETH was bridged from Ethereum to Bitcoin through the address bc1qr2sf...zn3w via Thorchain.
πTweet URL: View Tweet
Target: hinkalprotocol
*What happened:* Specter has reported that the @hinkalprotocol was exploited for approximately $820K. The exploiter deposited 410 $ETH, which is around $700K, into Tornado Cash. Additionally, 44.7 $ETH was bridged from Ethereum to Bitcoin through the address bc1qr2sf...zn3w via Thorchain.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: UXLINK
What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.
Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.
These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.
πTweet URL: View Tweet
Target: UXLINK
What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.
Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.
These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Bonk Inu
What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.
πTweet URL: View Tweet
Target: Bonk Inu
What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Tether
What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.
While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.
This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.
πTweet URL: View Tweet
Target: Tether
What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.
While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.
This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BonkDAO
What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.
Cases like this show that governance is only effective when it provides real security constraints around critical actions.
Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.
This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.
πTweet URL: View Tweet
Target: BonkDAO
What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.
Cases like this show that governance is only effective when it provides real security constraints around critical actions.
Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.
This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BitTorrent Bridge
What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.
πTweet URL: View Tweet
Target: BitTorrent Bridge
What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.
πTweet URL: View Tweet
gm all, we just dropped our H1 defi hack report
$935M gone in 6 months across 87 hacks. basically one every 2 days
the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable
full breakdown here if useful for your decks/calls:
https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
$935M gone in 6 months across 87 hacks. basically one every 2 days
the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable
full breakdown here if useful for your decks/calls:
https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
Quillaudits
The H1 2026 DeFi Hack Report | QuillAudits
$935.3M lost across 87 DeFi hacks in H1 2026. Key compromise and bridge exploits drove 82.7% of losses. Explore the full H1 2026 Web3 security report.
π¨ Hack Alert!
Target: LumiFinance
*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the @LumiFinance protocol on Arbitrum.
So far, approximately $270,000 has been drained from the protocol.
Further details can be found in the accompanying thread.
πTweet URL: View Tweet
Target: LumiFinance
*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the @LumiFinance protocol on Arbitrum.
So far, approximately $270,000 has been drained from the protocol.
Further details can be found in the accompanying thread.
πTweet URL: View Tweet