🚨 Hack Alert!
Target: Wanchain
What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.
An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.
This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.
The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.
The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma
🔗Tweet URL: View Tweet
Target: Wanchain
What happened: Wanchain's Cardano bridge was reportedly attacked, resulting in approximately 515 million $NIGHT drained from the bridge Treasury.
An initial investigation suggests that the vulnerability was due to a non-injective signed-message encoding in the TreasuryCheck validator. The signed message construction involved raw concatenation of variable-length redeemer fields without proper delimiters or length prefixes.
This flaw allowed different field-value tuples to produce identical byte strings, which in turn enabled hash and signature reuse.
The attack has been verified by decompiling the on-chain Plutus V2 bytecode and analyzing the exploit transaction.
The specific transaction linked to the attack can be found here: https://t.co/hmmPlgmfma
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: AFXXYZ
*What happened:* An exploit was detected on July 22, 2026, targeting the AFXXYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.
Approximately 24.15 million USDC has been drained from the protocol due to this incident.
The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.
The exploit transaction can be tracked through the provided link.
🔗Tweet URL: View Tweet
Target: AFXXYZ
*What happened:* An exploit was detected on July 22, 2026, targeting the AFXXYZ protocol on the Arbitrum network. The vulnerability was associated with a bridge that AFX operates.
Approximately 24.15 million USDC has been drained from the protocol due to this incident.
The Blockaid team has been collaborating with the Arbitrum team to manage the incident, engage with AFX, and assist in containing the stolen funds.
The exploit transaction can be tracked through the provided link.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: BSquaredNetwork
What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.
The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.
As a result of this exploit, the value of $B2 has dropped by 15%.
🔗Tweet URL: View Tweet
Target: BSquaredNetwork
What happened: A significant security incident has been reported involving the @BSquaredNetwork on the BNB Chain. The protocol has been drained of 8.591 million $B2 tokens, which is approximately worth $3.86 million.
The attacker executed a series of swaps, converting the stolen funds into over 5,000 $WBNB, after which they swapped these for 1,128 $ETH. The stolen assets were then bridged out via NEAR Intents.
As a result of this exploit, the value of $B2 has dropped by 15%.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: VerusCoin
What happened: 🚨 ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.
The attacker exploited the bridge import path (
Details of the incident include:
- Exploit transaction: https://t.co/vdpA08tzFP
- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.
Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.
🔗Tweet URL: View Tweet
Target: VerusCoin
What happened: 🚨 ALERT: An exploit has targeted the VerusCoin Ethereum Bridge on Ethereum.
The attacker exploited the bridge import path (
submitImports), successfully draining approximately $7.54M from bridge reserves, which included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.Details of the incident include:
- Exploit transaction: https://t.co/vdpA08tzFP
- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker EOA address: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
- Loot wallet information: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
This incident reflects similarities to the May 2026 Verus Bridge exploit, involving the same bridge contract and import path but with a different attacker and loot wallet.
Important note: Exchanges, stablecoin issuers, and monitoring teams should actively flag the attacker and loot wallet for all downstream movements.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Drift
What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.
The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.
This incident marks a major security breach impacting Drift, leading to a substantial financial impact.
🔗Tweet URL: View Tweet
Target: Drift
What happened: Drift suffered an exploit on April 1, 2026, resulting in a significant loss of approximately $285 million worth of cryptocurrencies.
The exploiter-labeled address has since deposited 23,095.1 ETH (valued at around $44.4 million) into Tornado Cash and 0.85 ETH into Bybit, indicating movement of the stolen funds.
This incident marks a major security breach impacting Drift, leading to a substantial financial impact.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: LienFinance
What happened: 🚨 A hack was reported involving @LienFinance that resulted in an exploitation on the Ethereum network, leading to a loss of approximately $542,144 USDC.
The attacker executed the exploit by manipulating the pricing in Lien's GeneralizedDotc bond-to-ERC20 OTC pools. They registered crafted bond groups, subsequently swapping newly minted bond tokens against the pool's liquidity.
Key details of the incident include:
- The exploit transaction can be tracked at: https://t.co/bhjBdVya0x
- Attacker's address: 0x0D7d9023531aD1A88414E216Ee2715F63561808a
- Orchestration contract used: 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e
The attacker used a permissionless approach to register new bond groups on BondMakerCollateralizedEth, leveraging a crafted payoff function. The manipulated bond tokens were swapped for USDC from the liquidity pool, which resulted in the extraction of funds due to an overvaluation of the bonds relative to their real collateral value.
This incident highlights the potential vulnerabilities in price manipulation and the need for robust security measures.
🔗Tweet URL: View Tweet
Target: LienFinance
What happened: 🚨 A hack was reported involving @LienFinance that resulted in an exploitation on the Ethereum network, leading to a loss of approximately $542,144 USDC.
The attacker executed the exploit by manipulating the pricing in Lien's GeneralizedDotc bond-to-ERC20 OTC pools. They registered crafted bond groups, subsequently swapping newly minted bond tokens against the pool's liquidity.
Key details of the incident include:
- The exploit transaction can be tracked at: https://t.co/bhjBdVya0x
- Attacker's address: 0x0D7d9023531aD1A88414E216Ee2715F63561808a
- Orchestration contract used: 0xe74d17c1bE3721E65e0af286D47B3BA58B08062e
The attacker used a permissionless approach to register new bond groups on BondMakerCollateralizedEth, leveraging a crafted payoff function. The manipulated bond tokens were swapped for USDC from the liquidity pool, which resulted in the extraction of funds due to an overvaluation of the bonds relative to their real collateral value.
This incident highlights the potential vulnerabilities in price manipulation and the need for robust security measures.
🔗Tweet URL: View Tweet
❤1
🚨 Hack Alert!
Target: TripleAHQ
What happened: Specter has reported that @TripleAHQ wallets have been drained of more than $9.7M worth of cryptocurrency across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The attacker bridged the stolen funds to Ethereum. Currently, 5,227 ETH is being consolidated at the address: 0x01F8...53b1.
🔗Tweet URL: View Tweet
Target: TripleAHQ
What happened: Specter has reported that @TripleAHQ wallets have been drained of more than $9.7M worth of cryptocurrency across multiple chains, including TRON, Ethereum, Polygon, and Arbitrum. The attacker bridged the stolen funds to Ethereum. Currently, 5,227 ETH is being consolidated at the address: 0x01F8...53b1.
🔗Tweet URL: View Tweet
❤1
🚨 Hack Alert!
Target: gardenfi
What happened: Blockaid has detected an ongoing exploit affecting @gardenfi's HTLC.
An amount of approximately $450,000 in USDT has been drained so far across multiple chains: Ethereum, Base, Arbitrum, and Binance Smart Chain.
This incident reflects a significant security incident involving theft of funds from the specified protocol.
🔗Tweet URL: View Tweet
Target: gardenfi
What happened: Blockaid has detected an ongoing exploit affecting @gardenfi's HTLC.
An amount of approximately $450,000 in USDT has been drained so far across multiple chains: Ethereum, Base, Arbitrum, and Binance Smart Chain.
This incident reflects a significant security incident involving theft of funds from the specified protocol.
🔗Tweet URL: View Tweet
👍1
🚨 Hack Alert!
Target: Across Protocol
What happened: The tweet reports a specific hack involving the Across Protocol. The exploiter, identified with a labeled address, returned 331.8 ETH, valued at approximately $623.9K, to the Across Protocol Hub Pool Owner Multisig. However, the protocol was attacked on the Solana blockchain, resulting in a loss of around $3.6 million worth of cryptocurrencies being drained from it. The incident outlines confirmed financial loss and an acknowledgment of prior exploit activity.
🔗Tweet URL: View Tweet
Target: Across Protocol
What happened: The tweet reports a specific hack involving the Across Protocol. The exploiter, identified with a labeled address, returned 331.8 ETH, valued at approximately $623.9K, to the Across Protocol Hub Pool Owner Multisig. However, the protocol was attacked on the Solana blockchain, resulting in a loss of around $3.6 million worth of cryptocurrencies being drained from it. The incident outlines confirmed financial loss and an acknowledgment of prior exploit activity.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Pro token
What happened: 🚨 Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.
Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.
This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.
🔗Tweet URL: View Tweet
Target: Pro token
What happened: 🚨 Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.
Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.
This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: $LULA
What happened: An exploit involving the $LULA token on Binance Smart Chain (BSC) has led to a theft of approximately $578,000. The attacker manipulated the reserve using a privileged
🔗Tweet URL: View Tweet
Target: $LULA
What happened: An exploit involving the $LULA token on Binance Smart Chain (BSC) has led to a theft of approximately $578,000. The attacker manipulated the reserve using a privileged
recycle() function within the Rental contract. This function allowed direct transfers of $LULA from the PancakeSwap V2 pair, subsequently invoking sync(), which updated the reserves to manipulated balances. To execute the attack, the attacker performed a large USDT-to-LULA swap to inflate the pair's USDT reserve, then repeatedly triggered the recycle() function, effectively shrinking the LULA reserve. Finally, a small amount of LULA was swapped back, draining the liquidity pool. Transaction details can be found here: Transaction Link.🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: SetProtocol
What happened: 🚨 A security incident has been reported involving @SetProtocol with a loss of approximately 9.6K USD.
The root cause of the exploit was a vulnerability in the Index Coop
As a result, the
Details of the incident include:
- Attacker address: 0x0736930ae35eafefa789f11edf41d7b799e7c99d
- Victim address: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance)
- Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948
- Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58
- Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802
The impact was significant, with ExchangeIssuance losing real assets after the attacker issued a BHSET with only 0.05 WETH and exploited the vulnerability to inflate component units by approximately 93.66 times, enabling excessive
🔗Tweet URL: View Tweet
Target: SetProtocol
What happened: 🚨 A security incident has been reported involving @SetProtocol with a loss of approximately 9.6K USD.
The root cause of the exploit was a vulnerability in the Index Coop
ExchangeIssuance.issueSetForExactToken function, which trusted arbitrary SetToken states without locking. This flaw allowed a malicious manager to utilize a pre-issue hook to inflate the positionMultiplier via NAV issue/redeem with a fake valuation.As a result, the
BasicIssuanceModule.issue function read the inflated real units during the transfer process, leading to an asset drain based on a TOCTOU-based attack.Details of the incident include:
- Attacker address: 0x0736930ae35eafefa789f11edf41d7b799e7c99d
- Victim address: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance)
- Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948
- Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58
- Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802
The impact was significant, with ExchangeIssuance losing real assets after the attacker issued a BHSET with only 0.05 WETH and exploited the vulnerability to inflate component units by approximately 93.66 times, enabling excessive
transferFrom transactions during the issue process.🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: COLDCARDwallet
What happened: A serious wallet-drain incident has been reported concerning @COLDCARDwallet due to weak randomness in seed generation.
Approximately 594 BTC, valued at around $38M, was stolen from about 500 addresses within a timeframe of 25 minutes.
Coinkite has issued a security advisory urging users to be cautious if their seed was generated on a Mk3 running firmware 4.0.1 or later.
This incident highlights the severe risks associated with weak randomness in wallet security and emphasizes the need for constant vigilance.
🔗Tweet URL: View Tweet
Target: COLDCARDwallet
What happened: A serious wallet-drain incident has been reported concerning @COLDCARDwallet due to weak randomness in seed generation.
Approximately 594 BTC, valued at around $38M, was stolen from about 500 addresses within a timeframe of 25 minutes.
Coinkite has issued a security advisory urging users to be cautious if their seed was generated on a Mk3 running firmware 4.0.1 or later.
This incident highlights the severe risks associated with weak randomness in wallet security and emphasizes the need for constant vigilance.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: LOOPSDAO
What happened: A security incident was reported involving LOOPSDAO and LpdFi on the BSC blockchain.
An exploit resulted in the theft of approximately $690K in USDC. The attacker manipulated the LPD/USDC spot price and opened an inflated buy-interest position, which allowed them to drain the protocol-owned liquidity pool through the claimInterest function.
The exploit transaction details can be found at the following links:
- https://t.co/yzolZwfzd4
- https://t.co/evHA0KFRiS
🔗Tweet URL: View Tweet
Target: LOOPSDAO
What happened: A security incident was reported involving LOOPSDAO and LpdFi on the BSC blockchain.
An exploit resulted in the theft of approximately $690K in USDC. The attacker manipulated the LPD/USDC spot price and opened an inflated buy-interest position, which allowed them to drain the protocol-owned liquidity pool through the claimInterest function.
The exploit transaction details can be found at the following links:
- https://t.co/yzolZwfzd4
- https://t.co/evHA0KFRiS
🔗Tweet URL: View Tweet
❤1
🚨 Hack Alert!
Target: AFX Bridge
What happened: AFX Bridge has experienced two exploit incidents, highlighting a serious security vulnerability. In July alone, approximately $97 million was lost across 14 incidents. A significant 88.3% of these losses were due to compromised keys and operational failures rather than flaws in the code. This alarming trend emphasizes ongoing vulnerabilities in the system and the need for improved security measures.
🔗Tweet URL: View Tweet
Target: AFX Bridge
What happened: AFX Bridge has experienced two exploit incidents, highlighting a serious security vulnerability. In July alone, approximately $97 million was lost across 14 incidents. A significant 88.3% of these losses were due to compromised keys and operational failures rather than flaws in the code. This alarming trend emphasizes ongoing vulnerabilities in the system and the need for improved security measures.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: aztecnetwork
What happened: PeckShield has reported that an exploiter associated with @aztecnetwork has deposited 300 $ETH worth approximately $572,100 into Tornado Cash.
Additionally, the exploiter has deposited a total of 500 $ETH into Tornado Cash as of today.
It is noted that @aztecnetwork suffered an exploit in June 2026, resulting in a total loss of $2.165M in cryptocurrency.
This indicates a specific incident involving a financial impact related to an exploit affecting the Aztec Network.
🔗Tweet URL: View Tweet
Target: aztecnetwork
What happened: PeckShield has reported that an exploiter associated with @aztecnetwork has deposited 300 $ETH worth approximately $572,100 into Tornado Cash.
Additionally, the exploiter has deposited a total of 500 $ETH into Tornado Cash as of today.
It is noted that @aztecnetwork suffered an exploit in June 2026, resulting in a total loss of $2.165M in cryptocurrency.
This indicates a specific incident involving a financial impact related to an exploit affecting the Aztec Network.
🔗Tweet URL: View Tweet
❤2
🚨 Hack Alert!
Target: coinsbuycom
What happened: Specter has reported that wallets associated with @coinsbuycom have likely lost approximately $7.9 million due to a drain that affected both the TRON and Ethereum networks. The attacker has been active, depositing a portion of the stolen funds through various services, including ChangeNOW, FixedFloat, and BingX.
🔗Tweet URL: View Tweet
Target: coinsbuycom
What happened: Specter has reported that wallets associated with @coinsbuycom have likely lost approximately $7.9 million due to a drain that affected both the TRON and Ethereum networks. The attacker has been active, depositing a portion of the stolen funds through various services, including ChangeNOW, FixedFloat, and BingX.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: USM
What happened: 🚨 SlowMist TI Alert
💸 Loss: ~70.83 ETH
🔍 Root Cause: A pricing logic flaw in
The function used arithmetic mean of current and estimated final FUM sell prices for single redemptions but lacked "split invariance." This issue, combined with per-redemption state contraction (
Attacker EOA:
Attacker Contract:
Victim Contract (USM):
Profit Receiver:
Transaction Link: Click Here
🔗Tweet URL: View Tweet
Target: USM
What happened: 🚨 SlowMist TI Alert
💸 Loss: ~70.83 ETH
🔍 Root Cause: A pricing logic flaw in
ethFromDefund() of USM's defund() function has been exploited. The function used arithmetic mean of current and estimated final FUM sell prices for single redemptions but lacked "split invariance." This issue, combined with per-redemption state contraction (
adjShrinkFactor) and integer rounding, allowed 64 small defund() calls to return more ETH than one large call for the same FUM amount. Attacker EOA:
0xb92b2e47680c89da8f951b8963ef469f461a50fc Attacker Contract:
0x5a5e29ba89663a3558273354e990426f3cac7de7 Victim Contract (USM):
0x2a7fff44c19f39468064ab5e5c304de01d591675 Profit Receiver:
0xe3c6346b6f282029312d2caf4677ef39beabbf99 Transaction Link: Click Here
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: harmonyprotocol
What happened: An exploit has occurred on Harmony Protocol where billions of $ONE tokens were falsely minted to several addresses. The affected team is taking proactive measures to freeze these funds. Users are advised to stay vigilant to protect against potential losses.
🔗Tweet URL: View Tweet
Target: harmonyprotocol
What happened: An exploit has occurred on Harmony Protocol where billions of $ONE tokens were falsely minted to several addresses. The affected team is taking proactive measures to freeze these funds. Users are advised to stay vigilant to protect against potential losses.
🔗Tweet URL: View Tweet
👍1
🚨 Hack Alert!
Target: ColdCard
What happened: The ColdCard wallet incident is currently active, marking it as the largest hardware-wallet exploit recorded, with losses of around $130M and continuing to rise.
The exploit involves at least 15 attackers who are taking advantage of a seed-generation bug. Affected seeds can be brute-forced offline without the need for physical access to the devices.
For more information, you can refer to the tweet link.
🔗Tweet URL: View Tweet
Target: ColdCard
What happened: The ColdCard wallet incident is currently active, marking it as the largest hardware-wallet exploit recorded, with losses of around $130M and continuing to rise.
The exploit involves at least 15 attackers who are taking advantage of a seed-generation bug. Affected seeds can be brute-forced offline without the need for physical access to the devices.
For more information, you can refer to the tweet link.
🔗Tweet URL: View Tweet
🚨 Hack Alert!
Target: Maya Protocol
What happened: A significant exploit has occurred on Maya Protocol, resulting in a loss of approximately $1.7 million. The attacker manipulated the system by inflating the accounting with a false subsidy. This allowed them to add and remove liquidity, ultimately enabling the extraction of around 48.87 million CACAO tokens and 98.82 LINK tokens from shared liquidity. This incident highlights ongoing vulnerabilities within DeFi protocols, and users are advised to remain vigilant.
🔗Tweet URL: View Tweet
Target: Maya Protocol
What happened: A significant exploit has occurred on Maya Protocol, resulting in a loss of approximately $1.7 million. The attacker manipulated the system by inflating the accounting with a false subsidy. This allowed them to add and remove liquidity, ultimately enabling the extraction of around 48.87 million CACAO tokens and 98.82 LINK tokens from shared liquidity. This incident highlights ongoing vulnerabilities within DeFi protocols, and users are advised to remain vigilant.
🔗Tweet URL: View Tweet
❤1