π¨ Hack Alert!
Target: UXLINK
What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.
Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.
These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.
πTweet URL: View Tweet
Target: UXLINK
What happened: The tweet reports that an exploiter associated with @UXLINKofficial has executed a significant transaction. They swapped approximately 10.54 million $DAI for 6,000.8 $ETH.
Following this, the exploiter deposited 6,038 $ETH into Tornado Cash. In total, they have deposited 14,336.6 $ETH into Tornado Cash in the last two weeks.
These actions indicate a possible exploitation event involving funds from @UXLINKofficial, with notable transfers to Tornado Cash, a platform often used for obfuscating transactions, suggesting an attempt to hide stolen funds.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Bonk Inu
What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.
πTweet URL: View Tweet
Target: Bonk Inu
What happened: A malicious governance proposal has been identified on the Bonk Inu protocol. The proposal led to the transfer of all Bonk balances from a treasury totaling 4.426 trillion tokens, which is valued at approximately $21.3 million. All funds were sent to the address 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ. Users are advised to stay vigilant regarding this incident.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Tether
What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.
While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.
This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.
πTweet URL: View Tweet
Target: Tether
What happened: A TRON address managed to outpace Tether's freeze by 6 minutes, successfully withdrawing 3.125 million USDT during that time.
While the freeze was still pending, approximately 1.237 million USDT was transferred to Binance.
This incident highlights the vulnerability in the freeze process and the executed timing of the withdrawal before the action could be finalized.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BonkDAO
What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.
Cases like this show that governance is only effective when it provides real security constraints around critical actions.
Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.
This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.
πTweet URL: View Tweet
Target: BonkDAO
What happened: BonkDAO was reportedly attacked for over $20M via a malicious governance proposal that stayed live for 6 days without intervention.
Cases like this show that governance is only effective when it provides real security constraints around critical actions.
Without timely monitoring and a meaningful response window, the process can work as designed while the security model fails.
This incident highlights the vulnerabilities in governance systems and the necessity for effective security measures.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BitTorrent Bridge
What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.
πTweet URL: View Tweet
Target: BitTorrent Bridge
What happened: An exploit was detected on the @BitTorrent Bridge on Ethereum. Approximately $13.3 million was drained from the BTTC bridge predicate contracts. This loss includes around 7,285 ETH along with other ERC20 assets. For full details, refer to the thread linked in the post.
πTweet URL: View Tweet
gm all, we just dropped our H1 defi hack report
$935M gone in 6 months across 87 hacks. basically one every 2 days
the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable
full breakdown here if useful for your decks/calls:
https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
$935M gone in 6 months across 87 hacks. basically one every 2 days
the wild part is 82.7% of it was just key compromise and bridge exploits. not some crazy new attack, mostly ops failures that were preventable
full breakdown here if useful for your decks/calls:
https://www.quillaudits.com/reports/quill-ledger-h1-2026-defi-security-report
Quillaudits
The H1 2026 DeFi Hack Report | QuillAudits
$935.3M lost across 87 DeFi hacks in H1 2026. Key compromise and bridge exploits drove 82.7% of losses. Explore the full H1 2026 Web3 security report.
π¨ Hack Alert!
Target: LumiFinance
*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the @LumiFinance protocol on Arbitrum.
So far, approximately $270,000 has been drained from the protocol.
Further details can be found in the accompanying thread.
πTweet URL: View Tweet
Target: LumiFinance
*What happened:* Blockaid's exploit detection system has identified a specific ongoing exploit involving the @LumiFinance protocol on Arbitrum.
So far, approximately $270,000 has been drained from the protocol.
Further details can be found in the accompanying thread.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: dripsnetwork
What happened: π¨ A confirmed security incident has occurred involving @dripsnetwork, resulting in a loss of 24,882.99 DAI.
The root cause of the hack was identified as an integer type conversion flaw within the
This flaw allowed attackers to pass
The attacker was identified as the address: 0x84da7a5e2315eb798f04b75554aeb15047269cce.
The affected contract (DaiReserve) is identified by address: 0xf9bbb2df44cfe46e501cf91c99b2f8fef9d9d44a and the vulnerable contract (Hub Proxy) is at: 0x73043143e0a6418cc45d82d4505b096b802fd365.
Additionally, the attack contract is: 0x00c64b5a926ba1fcec30efad88c344c619f54f12.
Forensic details on the attack can be found via the transaction links:
- https://t.co/Ea31eupMUX
- https://t.co/uJEuuVr6PP.
πTweet URL: View Tweet
Target: dripsnetwork
What happened: π¨ A confirmed security incident has occurred involving @dripsnetwork, resulting in a loss of 24,882.99 DAI.
The root cause of the hack was identified as an integer type conversion flaw within the
DaiDripsHub's give(address,uint128) function. This flaw allowed attackers to pass
2^128 - reserveBalance, exceeding the maximum limit for int128. As a result, converting amt to int128 led to a negative value, flipping the intent of the function from "user pays" to "reserve withdraws to user," effectively draining funds from the reserve. The attacker was identified as the address: 0x84da7a5e2315eb798f04b75554aeb15047269cce.
The affected contract (DaiReserve) is identified by address: 0xf9bbb2df44cfe46e501cf91c99b2f8fef9d9d44a and the vulnerable contract (Hub Proxy) is at: 0x73043143e0a6418cc45d82d4505b096b802fd365.
Additionally, the attack contract is: 0x00c64b5a926ba1fcec30efad88c344c619f54f12.
Forensic details on the attack can be found via the transaction links:
- https://t.co/Ea31eupMUX
- https://t.co/uJEuuVr6PP.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BarnBridge
What happened: A governance attack has been reported affecting the BarnBridge SMART Yield (cUSDC) protocol on Ethereum.
The incident led to estimated losses of around $776K. The attacker gained DAO governance authority and upgraded the SmartYield/controller proxy to a malicious implementation.
This upgrade allowed the contract to invoke CompoundProviderβs privileged takeUnderlying function, utilizing pre-existing USDC approvals from 50 user accounts, which forwarded the aggregated funds to the attacker via transferFees.
The fund-draining transactions associated with the attack are documented in the following links:
1) https://t.co/XuEhUfZHnQ
2) https://t.co/6cmXSi81Sd
π*Tweet URL:* [View Tweet](https://twitter.com/Phalconxyz/status/2077243530280587721)
Target: BarnBridge
What happened: A governance attack has been reported affecting the BarnBridge SMART Yield (cUSDC) protocol on Ethereum.
The incident led to estimated losses of around $776K. The attacker gained DAO governance authority and upgraded the SmartYield/controller proxy to a malicious implementation.
This upgrade allowed the contract to invoke CompoundProviderβs privileged takeUnderlying function, utilizing pre-existing USDC approvals from 50 user accounts, which forwarded the aggregated funds to the attacker via transferFees.
The fund-draining transactions associated with the attack are documented in the following links:
1) https://t.co/XuEhUfZHnQ
2) https://t.co/6cmXSi81Sd
π*Tweet URL:* [View Tweet](https://twitter.com/Phalconxyz/status/2077243530280587721)
π¨ Hack Alert!
Target: Ostium
What happened: π¨ Exploit Alert reported that @Ostium on Arbitrum was exploited for approximately $11.86M USDC.
This exploit drained around 32% of the vault's total value locked (TVL) of $34.3M.
The attack was due to a Private Key Compromise involving the Oracle Signer, leading to price manipulation. This enabled the attacker's smart account to act as a registered forwarder and submit favorable price reports signed by the compromised oracle.
The attacker executed 20 loops of the delegatedAction to open and close trades at a significant profit, siphoning funds from the $oLP vault.
On-Chain Details:
- Loss: 11,862,445 USDC
- Attacker Address: 0xD1794196f0fc99c7f27970e661597d77d9a85869
- Victim Vault Address: 0x20d419a8e12c45f88fda7c5760bb6923cee27f98
- Exploit Transaction: https://t.co/CFNLeorE4J
πTweet URL: View Tweet
Target: Ostium
What happened: π¨ Exploit Alert reported that @Ostium on Arbitrum was exploited for approximately $11.86M USDC.
This exploit drained around 32% of the vault's total value locked (TVL) of $34.3M.
The attack was due to a Private Key Compromise involving the Oracle Signer, leading to price manipulation. This enabled the attacker's smart account to act as a registered forwarder and submit favorable price reports signed by the compromised oracle.
The attacker executed 20 loops of the delegatedAction to open and close trades at a significant profit, siphoning funds from the $oLP vault.
On-Chain Details:
- Loss: 11,862,445 USDC
- Attacker Address: 0xD1794196f0fc99c7f27970e661597d77d9a85869
- Victim Vault Address: 0x20d419a8e12c45f88fda7c5760bb6923cee27f98
- Exploit Transaction: https://t.co/CFNLeorE4J
πTweet URL: View Tweet
π¨ Hack Alert!
Target: cascadexyz
*What happened:* @cascadexyz has suffered an exploit impacting the CLS vault.
The attack resulted in the draining of 1.34M $USDC from user funds.
The attacker has bridged the stolen funds from Arbitrum to Solana, and subsequently to Ethereum via RelayProtocol in DAI.
πTweet URL: View Tweet
Target: cascadexyz
*What happened:* @cascadexyz has suffered an exploit impacting the CLS vault.
The attack resulted in the draining of 1.34M $USDC from user funds.
The attacker has bridged the stolen funds from Arbitrum to Solana, and subsequently to Ethereum via RelayProtocol in DAI.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Wanchain
What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.
An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.
This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.
The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.
The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma
πTweet URL: View Tweet
Target: Wanchain
What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.
An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.
This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.
The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.
The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma
πTweet URL: View Tweet
π¨ Hack Alert!
Target: AFXXYZ
*What happened:* An exploit was detected on July 22, 2026, targeting the AFXXYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.
Approximately 24.15 million USDC has been drained from the protocol due to this incident.
The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.
The exploit transaction can be tracked through the provided link.
πTweet URL: View Tweet
Target: AFXXYZ
*What happened:* An exploit was detected on July 22, 2026, targeting the AFXXYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.
Approximately 24.15 million USDC has been drained from the protocol due to this incident.
The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.
The exploit transaction can be tracked through the provided link.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: BSquaredNetwork
What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.
The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.
As a result of this exploit, the value of $B2 has dropped by 15%.
πTweet URL: View Tweet
Target: BSquaredNetwork
What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.
The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.
As a result of this exploit, the value of $B2 has dropped by 15%.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: VerusCoin
What happened: π¨ ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.
The attacker exploited the bridge import path (
Details of the incident include:
- Exploit transaction: https://t.co/vdpA08tzFP
- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.
Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.
πTweet URL: View Tweet
Target: VerusCoin
What happened: π¨ ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.
The attacker exploited the bridge import path (
submitImports), successfully draining approximately $7.54M from bridge reserves, which included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.Details of the incident include:
- Exploit transaction: https://t.co/vdpA08tzFP
- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.
Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Drift
What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.
The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.
This incident marks a major security breach impacting Drift, leading to a substantial financial impact.
πTweet URL: View Tweet
Target: Drift
What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.
The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.
This incident marks a major security breach impacting Drift, leading to a substantial financial impact.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: LienFinance
What happened: π¨ A hack was reported involving @LienFinance that resulted in an exploitation on the Ethereum network, leading to a loss of approximately $542,144 USDC.
The attacker executed the exploit by manipulating the pricing in Lien's GeneralizedDotc bond-to-ERC20 OTC pools. They registered crafted bond groups, subsequently swapping newly minted bond tokens against the pool's liquidity.
Key details of the incident include:
- The exploit transaction can be tracked at: https://t.co/bhjBdVya0x
- Attacker's address: 0x0D7d9023531aD1A88414E216Ee2715F63561808a
- Orchestration contract used: 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e
The attacker used a permissionless approach to register new bond groups on BondMakerCollateralizedEth, leveraging a crafted payoff function. The manipulated bond tokens were swapped for USDC from the liquidity pool, which resulted in the extraction of funds due to an overvaluation of the bonds relative to their real collateral value.
This incident highlights the potential vulnerabilities in price manipulation and the need for robust security measures.
πTweet URL: View Tweet
Target: LienFinance
What happened: π¨ A hack was reported involving @LienFinance that resulted in an exploitation on the Ethereum network, leading to a loss of approximately $542,144 USDC.
The attacker executed the exploit by manipulating the pricing in Lien's GeneralizedDotc bond-to-ERC20 OTC pools. They registered crafted bond groups, subsequently swapping newly minted bond tokens against the pool's liquidity.
Key details of the incident include:
- The exploit transaction can be tracked at: https://t.co/bhjBdVya0x
- Attacker's address: 0x0D7d9023531aD1A88414E216Ee2715F63561808a
- Orchestration contract used: 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e
The attacker used a permissionless approach to register new bond groups on BondMakerCollateralizedEth, leveraging a crafted payoff function. The manipulated bond tokens were swapped for USDC from the liquidity pool, which resulted in the extraction of funds due to an overvaluation of the bonds relative to their real collateral value.
This incident highlights the potential vulnerabilities in price manipulation and the need for robust security measures.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: TripleAHQ
What happened: Specter has reported that @TripleAHQ wallets have been drained of more than $9.7M worth of cryptocurrency across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The attacker bridged the stolen funds to Ethereum. Currently, 5,227 ETH is being consolidated at the address: 0x01F8...53b1.
πTweet URL: View Tweet
Target: TripleAHQ
What happened: Specter has reported that @TripleAHQ wallets have been drained of more than $9.7M worth of cryptocurrency across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The attacker bridged the stolen funds to Ethereum. Currently, 5,227 ETH is being consolidated at the address: 0x01F8...53b1.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: gardenfi
What happened: Blockaid has detected an ongoing exploit affecting @gardenfi's HTLC.
An amount of approximately $450,000 in USDT has been drained so far across multiple chains: Ethereum, Base, Arbitrum, and Binance Smart Chain.
This incident reflects a significant security incident involving theft of funds from the specified protocol.
πTweet URL: View Tweet
Target: gardenfi
What happened: Blockaid has detected an ongoing exploit affecting @gardenfi's HTLC.
An amount of approximately $450,000 in USDT has been drained so far across multiple chains: Ethereum, Base, Arbitrum, and Binance Smart Chain.
This incident reflects a significant security incident involving theft of funds from the specified protocol.
πTweet URL: View Tweet
π1
π¨ Hack Alert!
Target: Across Protocol
What happened: The tweet reports a specific hack involving the Across Protocol. The exploiter, identified with a labeled address, returned 331.8 ETH, valued at approximately $623.9K, to the Across Protocol Hub Pool Owner Multisig. However, the protocol was attacked on the Solana blockchain, resulting in a loss of around $3.6 million worth of cryptocurrencies being drained from it. The incident outlines confirmed financial loss and an acknowledgment of prior exploit activity.
πTweet URL: View Tweet
Target: Across Protocol
What happened: The tweet reports a specific hack involving the Across Protocol. The exploiter, identified with a labeled address, returned 331.8 ETH, valued at approximately $623.9K, to the Across Protocol Hub Pool Owner Multisig. However, the protocol was attacked on the Solana blockchain, resulting in a loss of around $3.6 million worth of cryptocurrencies being drained from it. The incident outlines confirmed financial loss and an acknowledgment of prior exploit activity.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Pro token
What happened: π¨ Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.
Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.
This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.
πTweet URL: View Tweet
Target: Pro token
What happened: π¨ Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.
Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.
This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.
πTweet URL: View Tweet