QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!
Target: Raydium

What happened: A security incident was reported involving the project @Raydium, where the platform was drained of $1.3 million worth of crypto.

The attacker's initial funding came from the exchange #KuCoin. After the theft was executed, the stolen funds were bridged from #Solana to Ethereum (ETH).

Additionally, the attacker deposited 810 $ETH into #TornadoCash and 7 ETH into #FixedFloat.

This incident highlights significant vulnerabilities in the protocol.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Humanityprot

What happened: On June 9, the identity protocol Humanity experienced a significant exploit leading to the loss of approximately $36 million. The incident occurred after an employee's laptop was compromised, which exposed multisig keys to the attackers. This breach allowed them to gain administrative control over the bridge across Ethereum and BNB Chain.

Following the exploit, the attackers upgraded the contracts, drained around 141 million $H, and minted an additional 200 million $H directly to their own wallet. This malicious activity resulted in a drastic crash of the $H token, which fell by over 80%.

The incident is described as an operational security failure rather than a smart contract bug, emphasizing the importance of securing endpoints against key compromises. Cyvers has reported that monitoring on-chain behavior in real time is critical to defending against such breaches.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: aztecnetwork

What happened: A suspicious transaction has been detected involving the Router contract of Aztec Network.

The exploit resulted in a loss of approximately $2.19 million. The attacker's address is reported as 0x0f18d8b44a740272f0be4d08338d2b165b7edd17 on the Ethereum blockchain.

This incident highlights the ongoing vulnerabilities within DeFi contracts and the need for further security measures.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Thetanuts Finance

What happened: Thetanuts Finance experienced an exploit on the Ethereum blockchain, leading to the theft of approximately $105.5K in USDC.

The attack was facilitated by a flaw in the legacy vault's redemption formula, which used backing * amount / totalSupply to determine share payouts. The attacker manipulated the index token supply, resulting in inflated redemptions. This enabled multiple cycles of minting and claiming assets beyond the original deposits.

Key forensic details include:
- Attacker address: 0x30498e4466789E534c72e03B52A16c978655b41e
- Loot wallet: 0xAf3a0FdBFB0e3127247B66a042310e09C32F2299
- Vulnerable index token: 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7
- Attack transaction details: Link to transaction

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Aztec Connect

What happened: A detailed technical analysis has been published regarding the $2.19 million asset theft from Aztec Connect.

The exploit occurred through a vulnerability in a deprecated Aztec Connect RollupProcessor contract, which allowed attackers to bypass the settlement boundary. This manipulation resulted in the creation of an L1/L2 state discrepancy, facilitating the draining of approximately $2.19 million from the protocol.

The attack leveraged an inconsistency between numRealTxs and decodedslots, enabling forged deposits to be processed by the zero-knowledge proof while evading detection from the L1 settlement verification process.

The report elaborates on several aspects of the attack, including the root cause of the vulnerability, the discrepancy between ZK commitment and the settlement boundary, and the mechanisms of the atomic exploit execution, alongside details on on-chain fund tracing.

This incident underscores the critical necessity for Rollup systems to ensure that settlement boundaries align strictly with the commitment scopes of zero-knowledge public inputs.

πŸ”—*Tweet URL:* [View Tweet](
https://twitter.com/SlowMistTeam/status/2066543275981557823)
❀1
🚨 Hack Alert!
Target: escapeHatch

What happened: A follow-up exploit impacted the escapeHatch on a different deployment, specifically the "Private Rollup Bridge" contract (0x7379).

The root cause of the exploit involved circuit public input binding issues, where the olddataroot was transformed into two independent witnesses. One was utilized in the join-split circuit for private note membership verification, while another was exposed as the public input validated against L1 state.

This configuration allowed an attacker to create a fake Merkle tree with self-owned notes of arbitrary value, successfully proving membership against this fake root. As a result, the Solidity verification check was bypassed, allowing the attacker to withdraw funds.

While the escape hatch circuit has been eliminated from the codebase in aztec-connect PR #402, the deployed verifier contract still contains the vulnerable EscapeHatchVk that permits flawed proofs to pass on-chain verification.

There is an additional note regarding a similar unbinding issue, though it was not vital for the current attack.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: PancakeSwap

What happened: On June 20, 2026, a PancakeSwap V2 pool pairing OLPC against LABUBU was exploited on BNB Chain.

The exploit resulted in the theft of USDT valued at approximately $1.11M, with the attacker netting around $960K from the operation.

The root cause of the vulnerability is under investigation. However, on-chain fund analysis indicates that a transfer of about 10 OLPC was routed through the attacker contract, which subsequently triggered the burning of 51.9M OLPC and 124K LABUBU to 0x…dead from the OLPC/LABUBU pair 0xedb7...f365. As a consequence, the pair's actual balance collapsed while its cached reserves were not resynced, allowing the attacker to sweep the LABUBU side and route it through the LABUBU/WBNB and WBNB/USDT pools, ultimately exiting with 1,115,903 USDT.

The attacker's address is 0x18d6c39ae9e537f948aa2212d44d8c23944fc188.

Additional on-chain details include:
- OLPC token: 0x58815cdf9955121a6274680ab396a36fc9e00000
- LABUBU token: 0x3494dfe19b721dac6c5c8d7470c8f89548177777
- Drained pool: 0xedb7dcb4cdfec957f8df5cbf5e94229a6cc9f365
- Routing pools:
- LABUBU/WBNB 0xdfacdc33e913710ead31ee40f9c5363ea673c421
- WBNB/USDT 0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae
- Attack transaction: link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: jaredsmev

What happened: 🚨 A recent exploit detected by the Blockaid Exploit Detection system involved the @jaredsmev MEV bot on Ethereum.

The attack occurred due to attacker-controlled contracts that deceived an automated MEV execution system, leading to unauthorized token approvals.

As a result of this manipulation, a significant sum of $7.5 million was drained from the system.

Forensic details include the exploit transaction link provided: https://t.co/ltmzveNGuv.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: taikoxyz

What happened: Blockaid's exploit detection system has identified an ongoing exploit targeting @taikoxyz's ERC20 Vault on Ethereum. The financial impact is assessed to be over $1 million.

Further details are presumably available in the thread that follows this tweet, which may elaborate on the nature of the exploit and its implications.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: KyberNetwork

What happened: On November 22, 2023, KyberNetwork experienced flashloan exploits across multiple chains, resulting in a significant financial impact with a loss of approximately $47 million.

The exploiter address moved 2,000 ETH, equating to around $3.3 million, to Tornado Cash through the address 0x6B686cf613F05D09C097eECFc349c091e6F2ad8D just yesterday.

This incident highlights the ongoing vulnerabilities in DeFi protocols and the critical need for vigilance in the space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: AIDCToken

What happened: 🚨 SlowMist TI Alert 🚨

AIDC token on BSC has been exploited.

πŸ’Έ Loss: 220.12 WBNB (~$120929.35)

πŸ” Root Cause: AIDCToken's _sellTransfer() accumulates a 30% burn amount without deducting it from the seller. Subsequently, any non-Pair transfer triggers _executeAccumulatedBurn(), which incorrectly burns tokens from the uniswapPair balance instead of the seller. After burning, sync() is called, artificially deflating the AIDC reserve in the AMM, allowing the attacker to drain WBNB.

πŸ“Œ Attacker: 0x89eb2c99e970d831525c7a52badc290afa116b63
πŸ“Œ Victim: 0x2725033282b3bd4be8873b7f0f622c18e3b7cbd8 (Pancake V2 AIDC/WBNB Pair)
πŸ“Œ Vulnerable Contract: 0x5021d71859f81b4c905b573591db8f9cc4a0c6fe (AIDCToken)

The attacker exploited a flawed burn mechanism where sell-induced burn debt is wrongly imposed on the liquidity pool, enabling repeated reserve manipulation and a final swap that drained nearly all WBNB from the Pair.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Humanity Protocol

What happened: In June 2026, the crypto space experienced 40 significant hacks, accumulating total losses of $75.87 million, marking a 7.13% month-over-month decrease from May, where losses were $81.7 million.

Key incidents include the #Humanity Protocol hack, which alone resulted in a staggering $31 million loss.

Additionally, both the #Aztec Bridge and #Aztec Connect were targeted in the same month, suffering combined losses of approximately $4 million.

The exploiter of #Humanity Protocol has been actively laundering stolen funds across various chains, including Bitcoin, Solana, Hyperliquid, and BNB Chain. Notably, these funds have been mixed with proceeds associated with the #KelpDAO exploiter, indicating a potential connection between the threat actors involved in both incidents.

Other notable hacks from the month included the Syscoin Bridge with losses of $10 million, the JaredFromSubway.eth MEV bot with $7.5 million, and more.

This overview highlights significant financial impacts on various projects and demonstrates the ongoing challenges in securing assets in the crypto ecosystem.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: hinkalprotocol

*What happened:* Specter has reported that the
@hinkalprotocol was exploited for approximately $820K. The exploiter deposited 410 $ETH, which is around $700K, into Tornado Cash. Additionally, 44.7 $ETH was bridged from Ethereum to Bitcoin through the address bc1qr2sf...zn3w via Thorchain.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: UXLINK

What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.

Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.

These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Bonk Inu

What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Tether

What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.

While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.

This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BonkDAO

What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.

Cases like this show that governance is only effective when it provides real security constraints around critical actions.

Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.

This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BitTorrent Bridge

What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.

πŸ”—Tweet URL: View Tweet
gm all, we just dropped our H1 defi hack report

$935M gone in 6 months across 87 hacks. basically one every 2 days

the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable

full breakdown here if useful for your decks/calls:

https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
🚨 Hack Alert!
Target: LumiFinance

*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the
@LumiFinance protocol on Arbitrum.

So far, approximately $270,000 has been drained from the protocol.

Further details can be found in the accompanying thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: dripsnetwork

What happened: 🚨 A confirmed security incident has occurred involving @dripsnetwork, resulting in a loss of 24,882.99 DAI.

The root cause of the hack was identified as an integer type conversion flaw within the DaiDripsHub's give(address,uint128) function.

This flaw allowed attackers to pass 2^128 - reserveBalance, exceeding the maximum limit for int128. As a result, converting amt to int128 led to a negative value, flipping the intent of the function from "user pays" to "reserve withdraws to user," effectively draining funds from the reserve.

The attacker was identified as the address: 0x84da7a5e2315eb798f04b75554aeb15047269cce.

The affected contract (DaiReserve) is identified by address: 0xf9bbb2df44cfe46e501cf91c99b2f8fef9d9d44a and the vulnerable contract (Hub Proxy) is at: 0x73043143e0a6418cc45d82d4505b096b802fd365.

Additionally, the attack contract is: 0x00c64b5a926ba1fcec30efad88c344c619f54f12.

Forensic details on the attack can be found via the transaction links:
- https://t.co/Ea31eupMUX
- https://t.co/uJEuuVr6PP.

πŸ”—Tweet URL: View Tweet