Messages in this channel will no longer be automatically deleted
🚨 Hack Alert! @channel
Target: EIP-7702
What happened: 🚨 EIP-7702 auto‑drain case
Leaked key → delegated to a malicious 7702 contract. After bridging, the contract fallback auto-forwarded native token in the same tx—no attacker tx needed. Looks like a bridge issue, but the wallet was already compromised.
Takeaways:
- Phishers love 7702: batch signatures = one‑click drain (we’ve seen multi‑million losses).
- With a leaked key, attackers use 7702 auto‑drainers to siphon any incoming native token instantly.
Advice:
- Key leaked? Removing the 7702 delegation is useless—they’ll re‑delegate. Treat the wallet as burned; migrate now.
- Don’t sign 7702 batches you don’t fully understand.
Stay sharp and sign carefully.
Tweet URL: <https://twitter.com/realScamSniffer/status/1968143337573191919|View on Twitter>
Target: EIP-7702
What happened: 🚨 EIP-7702 auto‑drain case
Leaked key → delegated to a malicious 7702 contract. After bridging, the contract fallback auto-forwarded native token in the same tx—no attacker tx needed. Looks like a bridge issue, but the wallet was already compromised.
Takeaways:
- Phishers love 7702: batch signatures = one‑click drain (we’ve seen multi‑million losses).
- With a leaked key, attackers use 7702 auto‑drainers to siphon any incoming native token instantly.
Advice:
- Key leaked? Removing the 7702 delegation is useless—they’ll re‑delegate. Treat the wallet as burned; migrate now.
- Don’t sign 7702 batches you don’t fully understand.
Stay sharp and sign carefully.
Tweet URL: <https://twitter.com/realScamSniffer/status/1968143337573191919|View on Twitter>
🚨 Hack Alert! @channel
Target:
What happened: 🚨 Copy-paste can cost you everything.
Address poisoning plants fake lookalike addresses in your transaction history. One routine paste, and your funds are gone.
Read our latest blog to learn how this attack works:
🔗 https://t.co/VCEW7WtBmz
Then join us on Sept. 25 to find out how wallets can address this and other risks before they damage user trust.
📅 The Security Blindspot for Wallets: The Problem of Drainers & Poisoners
🔗 Register here: https://t.co/wQHkuSaVgT
Tweet URL: <https://twitter.com/HypernativeLabs/status/1968300168924533055|View on Twitter>
Target:
What happened: 🚨 Copy-paste can cost you everything.
Address poisoning plants fake lookalike addresses in your transaction history. One routine paste, and your funds are gone.
Read our latest blog to learn how this attack works:
🔗 https://t.co/VCEW7WtBmz
Then join us on Sept. 25 to find out how wallets can address this and other risks before they damage user trust.
📅 The Security Blindspot for Wallets: The Problem of Drainers & Poisoners
🔗 Register here: https://t.co/wQHkuSaVgT
Tweet URL: <https://twitter.com/HypernativeLabs/status/1968300168924533055|View on Twitter>
🚨 Hack Alert! @channel
Target: newgoldprotocol
What happened: #PeckShieldAlert The $NGP token from @newgoldprotocol was exploited for ~$2M.
$NGP has dropped -88% in an hour, and the exploiter has deposited the stolen funds (443.8 $ETH) into #TornadoCash.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1968512105880977569|View on Twitter>
Target: newgoldprotocol
What happened: #PeckShieldAlert The $NGP token from @newgoldprotocol was exploited for ~$2M.
$NGP has dropped -88% in an hour, and the exploiter has deposited the stolen funds (443.8 $ETH) into #TornadoCash.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1968512105880977569|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
Target: NGP
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP token
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
Target: NGP token
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP token
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
Target: NGP token
What happened: #CertiKAlert 🚨
We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.
https://t.co/aT35te0VWi
The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.
Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
🚨 Hack Alert! @channel
Target: Request Finance
What happened: A phishing theft has occurred resulting in a loss of $6.28 million. The attack involved a drainer customer identified by the address 0x1623...9aC9, which converted stolen assets into ETH and moved various amounts including 753 stETH pending a Lido withdrawal. Additionally, 123 ETH was bridged to Bitcoin and TRON, and 71 ETH was moved via NEAR Intents. Following this, the drainer's fee address (0xa2e8...4F8) transferred 312.8 ETH to a new address (0x5e91bfcfbddc1868770f17a4cb4f65043d17a64b). This incident shows the rapid movement of stolen funds across multiple chains. Users are advised to remain vigilant.
🔗Tweet URL: <https://twitter.com/realScamSniffer/status/1968702743046205531 |View on Twitter>
Target: Request Finance
What happened: A phishing theft has occurred resulting in a loss of $6.28 million. The attack involved a drainer customer identified by the address 0x1623...9aC9, which converted stolen assets into ETH and moved various amounts including 753 stETH pending a Lido withdrawal. Additionally, 123 ETH was bridged to Bitcoin and TRON, and 71 ETH was moved via NEAR Intents. Following this, the drainer's fee address (0xa2e8...4F8) transferred 312.8 ETH to a new address (0x5e91bfcfbddc1868770f17a4cb4f65043d17a64b). This incident shows the rapid movement of stolen funds across multiple chains. Users are advised to remain vigilant.
🔗Tweet URL: <https://twitter.com/realScamSniffer/status/1968702743046205531 |View on Twitter>
🚨 Hack Alert! @channel
Target: Request Finance
What happened: A victim lost $41,326 after mistakenly copying the wrong centralized exchange deposit address from contaminated transfer history. This incident highlights the risks associated with handling transfer histories that may be compromised.
🔗Tweet URL: <https://twitter.com/realScamSniffer/status/1969066493775405433 |View on Twitter>
Target: Request Finance
What happened: A victim lost $41,326 after mistakenly copying the wrong centralized exchange deposit address from contaminated transfer history. This incident highlights the risks associated with handling transfer histories that may be compromised.
🔗Tweet URL: <https://twitter.com/realScamSniffer/status/1969066493775405433 |View on Twitter>
🚨 Hack Alert! @channel
Target: UXLINK
What happened: Our system has detected $11.3M in suspicious transactions involving UXLINK. An ETH address executed a delegateCall, removed the admin role, and called "addOwnerWithThreshold" before transferring $4M USDT, $500K USDC, 3.7 WBTC, and 25 ETH. All USDC/USDT were swapped to DAI on ETH network, while on Arbitrum USDT was swapped to ETH and bridged to ETH network. Another address after few min received 10M UXLINK (~$3M), began swapping, but still holds ~$2.2M unswapped. This incident indicates a significant breach involving unauthorized transactions and fund movements. The tweet provides a detailed sequence of actions linked to the potential hack and financial impact. The context implies ongoing suspicious activity related to the UXLINK project.
Tweet URL: <https://twitter.com/CyversAlerts/status/1970167036002132425|View on Twitter>
Target: UXLINK
What happened: Our system has detected $11.3M in suspicious transactions involving UXLINK. An ETH address executed a delegateCall, removed the admin role, and called "addOwnerWithThreshold" before transferring $4M USDT, $500K USDC, 3.7 WBTC, and 25 ETH. All USDC/USDT were swapped to DAI on ETH network, while on Arbitrum USDT was swapped to ETH and bridged to ETH network. Another address after few min received 10M UXLINK (~$3M), began swapping, but still holds ~$2.2M unswapped. This incident indicates a significant breach involving unauthorized transactions and fund movements. The tweet provides a detailed sequence of actions linked to the potential hack and financial impact. The context implies ongoing suspicious activity related to the UXLINK project.
Tweet URL: <https://twitter.com/CyversAlerts/status/1970167036002132425|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP
What happened: A $2M exploit occurred on the $NGP token. The attack leveraged the token's transfer logic which deducts 35% of the selling amount from the pool balance. The exploiter executed a flashloan of $211M to artificially lower the NGP balance. By selling just 1.36M NGP, the reserve was slashed from 477K to a mere 0.035, significantly impacting the token's value. This incident highlights vulnerabilities in the token's mechanics that were exploited.
🔗Tweet URL: <https://twitter.com/guardrailai/status/1970192200601366568 |View on Twitter>
Target: NGP
What happened: A $2M exploit occurred on the $NGP token. The attack leveraged the token's transfer logic which deducts 35% of the selling amount from the pool balance. The exploiter executed a flashloan of $211M to artificially lower the NGP balance. By selling just 1.36M NGP, the reserve was slashed from 477K to a mere 0.035, significantly impacting the token's value. This incident highlights vulnerabilities in the token's mechanics that were exploited.
🔗Tweet URL: <https://twitter.com/guardrailai/status/1970192200601366568 |View on Twitter>
🚨 Hack Alert! @channel
Target: hypervaultfi
What happened: A significant withdrawal of approximately $3.6 million worth of cryptocurrencies has been detected from the HyperVault protocol.
The funds were originally bridged from Hyperliquid to the Ethereum blockchain, where they were swapped into ETH.
Following the swap, a total of 752 ETH was deposited into Tornado Cash, raising concerns about a potential rug pull.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1971476404173930660|View on Twitter>
Target: hypervaultfi
What happened: A significant withdrawal of approximately $3.6 million worth of cryptocurrencies has been detected from the HyperVault protocol.
The funds were originally bridged from Hyperliquid to the Ethereum blockchain, where they were swapped into ETH.
Following the swap, a total of 752 ETH was deposited into Tornado Cash, raising concerns about a potential rug pull.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1971476404173930660|View on Twitter>
🚨 Hack Alert! @channel
Target: Griffin AI
What happened: On September 24, 2025, Griffin AI experienced an exploit resulting in a loss of approximately $3 million due to a vulnerability in LayerZero.
The attack occurred just hours after the token launch, where an attacker minted 5 billion unauthorized $GAIN tokens, causing a drastic price drop of 87%.
The tweet provides details on the incident, indicating a significant financial impact and naming the exploited project and the method of attack.
🔗Tweet URL: <https://twitter.com/guardrailai/status/1971612441370148923 |View on Twitter>
Target: Griffin AI
What happened: On September 24, 2025, Griffin AI experienced an exploit resulting in a loss of approximately $3 million due to a vulnerability in LayerZero.
The attack occurred just hours after the token launch, where an attacker minted 5 billion unauthorized $GAIN tokens, causing a drastic price drop of 87%.
The tweet provides details on the incident, indicating a significant financial impact and naming the exploited project and the method of attack.
🔗Tweet URL: <https://twitter.com/guardrailai/status/1971612441370148923 |View on Twitter>
🚨 Hack Alert! @channel
Target: HyperDrive DeFi
What happened: An exploit has occurred on HyperDrive DeFi.
The attacker exploited an arbitrary call in the router, leading to the theft of users' funds totaling 672,934 USDT and 110,244 thBILL, amounting to approximately $782,000.
This incident highlights the vulnerabilities present in the protocol.
Users are advised to stay vigilant.
For more details, refer to the provided link.
Tweet URL: <https://twitter.com/CertiKAlert/status/1972117426893738341|View on Twitter>
Target: HyperDrive DeFi
What happened: An exploit has occurred on HyperDrive DeFi.
The attacker exploited an arbitrary call in the router, leading to the theft of users' funds totaling 672,934 USDT and 110,244 thBILL, amounting to approximately $782,000.
This incident highlights the vulnerabilities present in the protocol.
Users are advised to stay vigilant.
For more details, refer to the provided link.
Tweet URL: <https://twitter.com/CertiKAlert/status/1972117426893738341|View on Twitter>
🚨 Hack Alert! @channel
Target: RadiantCapital
What happened: The tweet reports a specific security incident involving Radiant Capital.
The incident details include the exploiter who swapped approximately $14 million in DAI for 3,490.2 ETH. Additionally, they deposited 2,243.2 ETH into Tornado Cash, indicating potential money laundering or attempts to obfuscate the funds.
This incident highlights a specific action taken by an exploiter affecting the Radiant Capital project.
🔗Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972124721132269835 |View on Twitter>
Target: RadiantCapital
What happened: The tweet reports a specific security incident involving Radiant Capital.
The incident details include the exploiter who swapped approximately $14 million in DAI for 3,490.2 ETH. Additionally, they deposited 2,243.2 ETH into Tornado Cash, indicating potential money laundering or attempts to obfuscate the funds.
This incident highlights a specific action taken by an exploiter affecting the Radiant Capital project.
🔗Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972124721132269835 |View on Twitter>
🚨 Hack Alert! @channel
Target: ResupplyFi
What happened: The #Resupply exploiter has deposited 1,607 $ETH, approximately valued at $6.5M, into #TornadoCash.
These funds trace back to an exploit on June 2025 involving @ResupplyFi, which resulted in a significant loss of $9.6M.
This incident highlights the ongoing exploitation of funds within the crypto ecosystem.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972492625556222188|View on Twitter>
Target: ResupplyFi
What happened: The #Resupply exploiter has deposited 1,607 $ETH, approximately valued at $6.5M, into #TornadoCash.
These funds trace back to an exploit on June 2025 involving @ResupplyFi, which resulted in a significant loss of $9.6M.
This incident highlights the ongoing exploitation of funds within the crypto ecosystem.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972492625556222188|View on Twitter>
🚨 Hack Alert! @channel
Target: UXLINK
What happened: A significant security incident has been reported involving the #UXLINK exploiter. The exploiter swapped 28.67 $WBTC for approximately 778 $ETH, valued at around $3.27 million. Following this, the exploiter has initiated deposits into #TornadoCash, which raises concerns about the laundering of the funds.
This incident highlights the ongoing issues with exploits in the Web3 space and the need for vigilance against illicit transactions.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972917298286739458|View on Twitter>
Target: UXLINK
What happened: A significant security incident has been reported involving the #UXLINK exploiter. The exploiter swapped 28.67 $WBTC for approximately 778 $ETH, valued at around $3.27 million. Following this, the exploiter has initiated deposits into #TornadoCash, which raises concerns about the laundering of the funds.
This incident highlights the ongoing issues with exploits in the Web3 space and the need for vigilance against illicit transactions.
Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972917298286739458|View on Twitter>
🚨 Hack Alert!
Target: hyperdrivedefi
What happened: On September 27, 2025, a recent exploit occurred on @hyperdrivedefi, a DeFi yield protocol on Hyperliquid.
Hackers drained approximately $773,000 from the platform through a vulnerability in its router contract.
The incident affected two user positions in the Treasury Bill market, which involved 673K USDT0 and 110K thBILL.
The attacker utilized arbitrary calls to siphon funds, subsequently bridging them to BNB Chain and Ethereum for laundering.
Tweet URL: https://twitter.com/guardrailai/status/1973377059297587231
Target: hyperdrivedefi
What happened: On September 27, 2025, a recent exploit occurred on @hyperdrivedefi, a DeFi yield protocol on Hyperliquid.
Hackers drained approximately $773,000 from the platform through a vulnerability in its router contract.
The incident affected two user positions in the Treasury Bill market, which involved 673K USDT0 and 110K thBILL.
The attacker utilized arbitrary calls to siphon funds, subsequently bridging them to BNB Chain and Ethereum for laundering.
Tweet URL: https://twitter.com/guardrailai/status/1973377059297587231
🚨 Hack Alert!
Target: THORChain
What happened: DPRK-linked actors bridged $7 million from Ethereum to Bitcoin following the WooX hack. This occurred via @THORChain, just weeks after THORChain’s founder was phished.
The reported funds highlight the ongoing threats associated with hacks and the potential exploitation of protocols.
🔗Tweet URL: https://twitter.com/hackenclub/status/1973428947778957318
Target: THORChain
What happened: DPRK-linked actors bridged $7 million from Ethereum to Bitcoin following the WooX hack. This occurred via @THORChain, just weeks after THORChain’s founder was phished.
The reported funds highlight the ongoing threats associated with hacks and the potential exploitation of protocols.
🔗Tweet URL: https://twitter.com/hackenclub/status/1973428947778957318
