QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!
Target: taikoxyz

What happened: Blockaid's exploit detection system has identified an ongoing exploit targeting @taikoxyz's ERC20 Vault on Ethereum. The financial impact is assessed to be over $1 million.

Further details are presumably available in the thread that follows this tweet, which may elaborate on the nature of the exploit and its implications.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: KyberNetwork

What happened: On November 22, 2023, KyberNetwork experienced flashloan exploits across multiple chains, resulting in a significant financial impact with a loss of approximately $47 million.

The exploiter address moved 2,000 ETH, equating to around $3.3 million, to Tornado Cash through the address 0x6B686cf613F05D09C097eECFc349c091e6F2ad8D just yesterday.

This incident highlights the ongoing vulnerabilities in DeFi protocols and the critical need for vigilance in the space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: AIDCToken

What happened: 🚨 SlowMist TI Alert 🚨

AIDC token on BSC has been exploited.

πŸ’Έ Loss: 220.12 WBNB (~$120929.35)

πŸ” Root Cause: AIDCToken's _sellTransfer() accumulates a 30% burn amount without deducting it from the seller. Subsequently, any non-Pair transfer triggers _executeAccumulatedBurn(), which incorrectly burns tokens from the uniswapPair balance instead of the seller. After burning, sync() is called, artificially deflating the AIDC reserve in the AMM, allowing the attacker to drain WBNB.

πŸ“Œ Attacker: 0x89eb2c99e970d831525c7a52badc290afa116b63
πŸ“Œ Victim: 0x2725033282b3bd4be8873b7f0f622c18e3b7cbd8 (Pancake V2 AIDC/WBNB Pair)
πŸ“Œ Vulnerable Contract: 0x5021d71859f81b4c905b573591db8f9cc4a0c6fe (AIDCToken)

The attacker exploited a flawed burn mechanism where sell-induced burn debt is wrongly imposed on the liquidity pool, enabling repeated reserve manipulation and a final swap that drained nearly all WBNB from the Pair.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Humanity Protocol

What happened: In June 2026, the crypto space experienced 40 significant hacks, accumulating total losses of $75.87 million, marking a 7.13% month-over-month decrease from May, where losses were $81.7 million.

Key incidents include the #Humanity Protocol hack, which alone resulted in a staggering $31 million loss.

Additionally, both the #Aztec Bridge and #Aztec Connect were targeted in the same month, suffering combined losses of approximately $4 million.

The exploiter of #Humanity Protocol has been actively laundering stolen funds across various chains, including Bitcoin, Solana, Hyperliquid, and BNB Chain. Notably, these funds have been mixed with proceeds associated with the #KelpDAO exploiter, indicating a potential connection between the threat actors involved in both incidents.

Other notable hacks from the month included the Syscoin Bridge with losses of $10 million, the JaredFromSubway.eth MEV bot with $7.5 million, and more.

This overview highlights significant financial impacts on various projects and demonstrates the ongoing challenges in securing assets in the crypto ecosystem.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: hinkalprotocol

*What happened:* Specter has reported that the
@hinkalprotocol was exploited for approximately $820K. The exploiter deposited 410 $ETH, which is around $700K, into Tornado Cash. Additionally, 44.7 $ETH was bridged from Ethereum to Bitcoin through the address bc1qr2sf...zn3w via Thorchain.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: UXLINK

What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.

Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.

These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Bonk Inu

What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Tether

What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.

While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.

This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BonkDAO

What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.

Cases like this show that governance is only effective when it provides real security constraints around critical actions.

Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.

This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BitTorrent Bridge

What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.

πŸ”—Tweet URL: View Tweet
gm all, we just dropped our H1 defi hack report

$935M gone in 6 months across 87 hacks. basically one every 2 days

the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable

full breakdown here if useful for your decks/calls:

https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
🚨 Hack Alert!
Target: LumiFinance

*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the
@LumiFinance protocol on Arbitrum.

So far, approximately $270,000 has been drained from the protocol.

Further details can be found in the accompanying thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: dripsnetwork

What happened: 🚨 A confirmed security incident has occurred involving @dripsnetwork, resulting in a loss of 24,882.99 DAI.

The root cause of the hack was identified as an integer type conversion flaw within the DaiDripsHub's give(address,uint128) function.

This flaw allowed attackers to pass 2^128 - reserveBalance, exceeding the maximum limit for int128. As a result, converting amt to int128 led to a negative value, flipping the intent of the function from "user pays" to "reserve withdraws to user," effectively draining funds from the reserve.

The attacker was identified as the address: 0x84da7a5e2315eb798f04b75554aeb15047269cce.

The affected contract (DaiReserve) is identified by address: 0xf9bbb2df44cfe46e501cf91c99b2f8fef9d9d44a and the vulnerable contract (Hub Proxy) is at: 0x73043143e0a6418cc45d82d4505b096b802fd365.

Additionally, the attack contract is: 0x00c64b5a926ba1fcec30efad88c344c619f54f12.

Forensic details on the attack can be found via the transaction links:
- https://t.co/Ea31eupMUX
- https://t.co/uJEuuVr6PP.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BarnBridge

What happened: A governance attack has been reported affecting the BarnBridge SMART Yield (cUSDC) protocol on Ethereum.

The incident led to estimated losses of around $776K. The attacker gained DAO governance authority and upgraded the SmartYield/controller proxy to a malicious implementation.

This upgrade allowed the contract to invoke CompoundProvider’s privileged takeUnderlying function, utilizing pre-existing USDC approvals from 50 user accounts, which forwarded the aggregated funds to the attacker via transferFees.

The fund-draining transactions associated with the attack are documented in the following links:
1)
https://t.co/XuEhUfZHnQ
2)
https://t.co/6cmXSi81Sd

πŸ”—*Tweet URL:* [View Tweet](
https://twitter.com/Phalconxyz/status/2077243530280587721)
🚨 Hack Alert!
Target: Ostium

What happened: 🚨 Exploit Alert reported that @Ostium on Arbitrum was exploited for approximately $11.86M USDC.

This exploit drained around 32% of the vault's total value locked (TVL) of $34.3M.

The attack was due to a Private Key Compromise involving the Oracle Signer, leading to price manipulation. This enabled the attacker's smart account to act as a registered forwarder and submit favorable price reports signed by the compromised oracle.

The attacker executed 20 loops of the delegatedAction to open and close trades at a significant profit, siphoning funds from the $oLP vault.

On-Chain Details:
- Loss: 11,862,445 USDC
- Attacker Address: 0xD1794196f0fc99c7f27970e661597d77d9a85869
- Victim Vault Address: 0x20d419a8e12c45f88fda7c5760bb6923cee27f98
- Exploit Transaction: https://t.co/CFNLeorE4J

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: cascadexyz

*What happened:*
@cascadexyz has suffered an exploit impacting the CLS vault.

The attack resulted in the draining of 1.34M $USDC from user funds.

The attacker has bridged the stolen funds from Arbitrum to Solana, and subsequently to Ethereum via RelayProtocol in DAI.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wanchain

What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.

An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.

This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.

The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.

The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: AFXXYZ

*What happened:* An exploit was detected on July 22, 2026, targeting the AFX
XYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.

Approximately 24.15 million USDC has been drained from the protocol due to this incident.

The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.

The exploit transaction can be tracked through the provided link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: BSquaredNetwork

What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.

The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.

As a result of this exploit, the value of $B2 has dropped by 15%.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: VerusCoin

What happened: 🚨 ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.

The attacker exploited the bridge import path (submitImports), successfully draining approximately $7.54M from bridge reserves, which included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

Details of the incident include:

- Exploit transaction: https://t.co/vdpA08tzFP

- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63

- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c

- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.

Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Drift

What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.

The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.

This incident marks a major security breach impacting Drift, leading to a substantial financial impact.

πŸ”—Tweet URL: View Tweet