QuillMonitor : Web3 Hacks and Alerts
224 subscribers
1 photo
177 links
Download Telegram
🚨 Hack Alert!
Target: cascadexyz

*What happened:*
@cascadexyz has suffered an exploit impacting the CLS vault.

The attack resulted in the draining of 1.34M $USDC from user funds.

The attacker has bridged the stolen funds from Arbitrum to Solana, and subsequently to Ethereum via RelayProtocol in DAI.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wanchain

What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.

An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.

This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.

The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.

The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: AFXXYZ

*What happened:* An exploit was detected on July 22, 2026, targeting the AFX
XYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.

Approximately 24.15 million USDC has been drained from the protocol due to this incident.

The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.

The exploit transaction can be tracked through the provided link.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: BSquaredNetwork

What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.

The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.

As a result of this exploit, the value of $B2 has dropped by 15%.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: VerusCoin

What happened: 🚨 ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.

The attacker exploited the bridge import path (submitImports), successfully draining approximately $7.54M from bridge reserves, which included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

Details of the incident include:

- Exploit transaction: https://t.co/vdpA08tzFP

- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63

- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c

- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.

Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Drift

What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.

The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.

This incident marks a major security breach impacting Drift, leading to a substantial financial impact.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: LienFinance

What happened: 🚨 A hack was reported involving @LienFinance that resulted in an exploitation on the Ethereum network, leading to a loss of approximately $542,144 USDC.

The attacker executed the exploit by manipulating the pricing in Lien's GeneralizedDotc bond-to-ERC20 OTC pools. They registered crafted bond groups, subsequently swapping newly minted bond tokens against the pool's liquidity.

Key details of the incident include:
- The exploit transaction can be tracked at: https://t.co/bhjBdVya0x
- Attacker's address: 0x0D7d9023531aD1A88414E216Ee2715F63561808a
- Orchestration contract used: 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e

The attacker used a permissionless approach to register new bond groups on BondMakerCollateralizedEth, leveraging a crafted payoff function. The manipulated bond tokens were swapped for USDC from the liquidity pool, which resulted in the extraction of funds due to an overvaluation of the bonds relative to their real collateral value.

This incident highlights the potential vulnerabilities in price manipulation and the need for robust security measures.

🔗Tweet URL: View Tweet
1
🚨 Hack Alert!
Target: TripleAHQ

What happened: Specter has reported that @TripleAHQ wallets have been drained of more than $9.7M worth of cryptocurrency across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The attacker bridged the stolen funds to Ethereum. Currently, 5,227 ETH is being consolidated at the address: 0x01F8...53b1.

🔗Tweet URL: View Tweet
1
🚨 Hack Alert!
Target: gardenfi

What happened: Blockaid has detected an ongoing exploit affecting @gardenfi's HTLC.

An amount of approximately $450,000 in USDT has been drained so far across multiple chains: Ethereum, Base, Arbitrum, and Binance Smart Chain.

This incident reflects a significant security incident involving theft of funds from the specified protocol.

🔗Tweet URL: View Tweet
👍1
🚨 Hack Alert!
Target: Across Protocol

What happened: The tweet reports a specific hack involving the Across Protocol. The exploiter, identified with a labeled address, returned 331.8 ETH, valued at approximately $623.9K, to the Across Protocol Hub Pool Owner Multisig. However, the protocol was attacked on the Solana blockchain, resulting in a loss of around $3.6 million worth of cryptocurrencies being drained from it. The incident outlines confirmed financial loss and an acknowledgment of prior exploit activity.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Pro token

What happened: 🚨 Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.

Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.

This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: $LULA

What happened: An exploit involving the $LULA token on Binance Smart Chain (BSC) has led to a theft of approximately $578,000. The attacker manipulated the reserve using a privileged recycle() function within the Rental contract. This function allowed direct transfers of $LULA from the PancakeSwap V2 pair, subsequently invoking sync(), which updated the reserves to manipulated balances. To execute the attack, the attacker performed a large USDT-to-LULA swap to inflate the pair's USDT reserve, then repeatedly triggered the recycle() function, effectively shrinking the LULA reserve. Finally, a small amount of LULA was swapped back, draining the liquidity pool. Transaction details can be found here: Transaction Link.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: SetProtocol

What happened: 🚨 A security incident has been reported involving @SetProtocol with a loss of approximately 9.6K USD.

The root cause of the exploit was a vulnerability in the Index Coop ExchangeIssuance.issueSetForExactToken function, which trusted arbitrary SetToken states without locking. This flaw allowed a malicious manager to utilize a pre-issue hook to inflate the positionMultiplier via NAV issue/redeem with a fake valuation.

As a result, the BasicIssuanceModule.issue function read the inflated real units during the transfer process, leading to an asset drain based on a TOCTOU-based attack.

Details of the incident include:
- Attacker address: 0x0736930ae35eafefa789f11edf41d7b799e7c99d
- Victim address: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance)
- Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948
- Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58
- Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802

The impact was significant, with ExchangeIssuance losing real assets after the attacker issued a BHSET with only 0.05 WETH and exploited the vulnerability to inflate component units by approximately 93.66 times, enabling excessive transferFrom transactions during the issue process.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: COLDCARDwallet

What happened: A serious wallet-drain incident has been reported concerning @COLDCARDwallet due to weak randomness in seed generation.

Approximately 594 BTC, valued at around $38M, was stolen from about 500 addresses within a timeframe of 25 minutes.

Coinkite has issued a security advisory urging users to be cautious if their seed was generated on a Mk3 running firmware 4.0.1 or later.

This incident highlights the severe risks associated with weak randomness in wallet security and emphasizes the need for constant vigilance.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: LOOPSDAO

What happened: A security incident was reported involving LOOPSDAO and LpdFi on the BSC blockchain.

An exploit resulted in the theft of approximately $690K in USDC. The attacker manipulated the LPD/USDC spot price and opened an inflated buy-interest position, which allowed them to drain the protocol-owned liquidity pool through the claimInterest function.

The exploit transaction details can be found at the following links:
- https://t.co/yzolZwfzd4
- https://t.co/evHA0KFRiS

🔗Tweet URL: View Tweet
1
🚨 Hack Alert!
Target: AFX Bridge

What happened: AFX Bridge has experienced two exploit incidents, highlighting a serious security vulnerability. In July alone, approximately $97 million was lost across 14 incidents. A significant 88.3% of these losses were due to compromised keys and operational failures rather than flaws in the code. This alarming trend emphasizes ongoing vulnerabilities in the system and the need for improved security measures.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: aztecnetwork

What happened: PeckShield has reported that an exploiter associated with @aztecnetwork has deposited 300 $ETH worth approximately $572,100 into Tornado Cash.

Additionally, the exploiter has deposited a total of 500 $ETH into Tornado Cash as of today.

It is noted that @aztecnetwork suffered an exploit in June 2026, resulting in a total loss of $2.165M in cryptocurrency.

This indicates a specific incident involving a financial impact related to an exploit affecting the Aztec Network.

🔗Tweet URL: View Tweet
2
🚨 Hack Alert!
Target: coinsbuycom

What happened: Specter has reported that wallets associated with @coinsbuycom have likely lost approximately $7.9 million due to a drain that affected both the TRON and Ethereum networks. The attacker has been active, depositing a portion of the stolen funds through various services, including ChangeNOW, FixedFloat, and BingX.

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: USM

What happened: 🚨 SlowMist TI Alert

💸 Loss: ~70.83 ETH

🔍 Root Cause: A pricing logic flaw in ethFromDefund() of USM's defund() function has been exploited.
The function used arithmetic mean of current and estimated final FUM sell prices for single redemptions but lacked "split invariance." This issue, combined with per-redemption state contraction (adjShrinkFactor) and integer rounding, allowed 64 small defund() calls to return more ETH than one large call for the same FUM amount.

Attacker EOA: 0xb92b2e47680c89da8f951b8963ef469f461a50fc
Attacker Contract: 0x5a5e29ba89663a3558273354e990426f3cac7de7
Victim Contract (USM): 0x2a7fff44c19f39468064ab5e5c304de01d591675
Profit Receiver: 0xe3c6346b6f282029312d2caf4677ef39beabbf99

Transaction Link: Click Here

🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: harmonyprotocol

What happened: An exploit has occurred on Harmony Protocol where billions of $ONE tokens were falsely minted to several addresses. The affected team is taking proactive measures to freeze these funds. Users are advised to stay vigilant to protect against potential losses.

🔗Tweet URL: View Tweet
👍1
🚨 Hack Alert!
Target: ColdCard

What happened: The ColdCard wallet incident is currently active, marking it as the largest hardware-wallet exploit recorded, with losses of around $130M and continuing to rise.

The exploit involves at least 15 attackers who are taking advantage of a seed-generation bug. Affected seeds can be brute-forced offline without the need for physical access to the devices.

For more information, you can refer to the tweet link.

🔗Tweet URL: View Tweet