QuillMonitor : Web3 Hacks and Alerts
223 subscribers
1 photo
176 links
Download Telegram
🚨 Hack Alert!
Target: Pro token

What happened: 🚨 Blockaid has detected an ongoing exploit on Pro token by @CryptoDAOGlobal.

Currently, ~$8.2M USDT is held by the exploiter and winning addresses, indicating a significant financial impact.

This situation highlights the potential vulnerabilities in the Pro token protocol and the urgent need for security measures to address this ongoing issue.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: $LULA

What happened: An exploit involving the $LULA token on Binance Smart Chain (BSC) has led to a theft of approximately $578,000. The attacker manipulated the reserve using a privileged recycle() function within the Rental contract. This function allowed direct transfers of $LULA from the PancakeSwap V2 pair, subsequently invoking sync(), which updated the reserves to manipulated balances. To execute the attack, the attacker performed a large USDT-to-LULA swap to inflate the pair's USDT reserve, then repeatedly triggered the recycle() function, effectively shrinking the LULA reserve. Finally, a small amount of LULA was swapped back, draining the liquidity pool. Transaction details can be found here: Transaction Link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: SetProtocol

What happened: 🚨 A security incident has been reported involving @SetProtocol with a loss of approximately 9.6K USD.

The root cause of the exploit was a vulnerability in the Index Coop ExchangeIssuance.issueSetForExactToken function, which trusted arbitrary SetToken states without locking. This flaw allowed a malicious manager to utilize a pre-issue hook to inflate the positionMultiplier via NAV issue/redeem with a fake valuation.

As a result, the BasicIssuanceModule.issue function read the inflated real units during the transfer process, leading to an asset drain based on a TOCTOU-based attack.

Details of the incident include:
- Attacker address: 0x0736930ae35eafefa789f11edf41d7b799e7c99d
- Victim address: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance)
- Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948
- Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58
- Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802

The impact was significant, with ExchangeIssuance losing real assets after the attacker issued a BHSET with only 0.05 WETH and exploited the vulnerability to inflate component units by approximately 93.66 times, enabling excessive transferFrom transactions during the issue process.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: COLDCARDwallet

What happened: A serious wallet-drain incident has been reported concerning @COLDCARDwallet due to weak randomness in seed generation.

Approximately 594 BTC, valued at around $38M, was stolen from about 500 addresses within a timeframe of 25 minutes.

Coinkite has issued a security advisory urging users to be cautious if their seed was generated on a Mk3 running firmware 4.0.1 or later.

This incident highlights the severe risks associated with weak randomness in wallet security and emphasizes the need for constant vigilance.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: LOOPSDAO

What happened: A security incident was reported involving LOOPSDAO and LpdFi on the BSC blockchain.

An exploit resulted in the theft of approximately $690K in USDC. The attacker manipulated the LPD/USDC spot price and opened an inflated buy-interest position, which allowed them to drain the protocol-owned liquidity pool through the claimInterest function.

The exploit transaction details can be found at the following links:
- https://t.co/yzolZwfzd4
- https://t.co/evHA0KFRiS

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: AFX Bridge

What happened: AFX Bridge has experienced two exploit incidents, highlighting a serious security vulnerability. In July alone, approximately $97 million was lost across 14 incidents. A significant 88.3% of these losses were due to compromised keys and operational failures rather than flaws in the code. This alarming trend emphasizes ongoing vulnerabilities in the system and the need for improved security measures.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: aztecnetwork

What happened: PeckShield has reported that an exploiter associated with @aztecnetwork has deposited 300 $ETH worth approximately $572,100 into Tornado Cash.

Additionally, the exploiter has deposited a total of 500 $ETH into Tornado Cash as of today.

It is noted that @aztecnetwork suffered an exploit in June 2026, resulting in a total loss of $2.165M in cryptocurrency.

This indicates a specific incident involving a financial impact related to an exploit affecting the Aztec Network.

πŸ”—Tweet URL: View Tweet
❀2
🚨 Hack Alert!
Target: coinsbuycom

What happened: Specter has reported that wallets associated with @coinsbuycom have likely lost approximately $7.9 million due to a drain that affected both the TRON and Ethereum networks. The attacker has been active, depositing a portion of the stolen funds through various services, including ChangeNOW, FixedFloat, and BingX.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: USM

What happened: 🚨 SlowMist TI Alert

πŸ’Έ Loss: ~70.83 ETH

πŸ” Root Cause: A pricing logic flaw in ethFromDefund() of USM's defund() function has been exploited.
The function used arithmetic mean of current and estimated final FUM sell prices for single redemptions but lacked "split invariance." This issue, combined with per-redemption state contraction (adjShrinkFactor) and integer rounding, allowed 64 small defund() calls to return more ETH than one large call for the same FUM amount.

Attacker EOA: 0xb92b2e47680c89da8f951b8963ef469f461a50fc
Attacker Contract: 0x5a5e29ba89663a3558273354e990426f3cac7de7
Victim Contract (USM): 0x2a7fff44c19f39468064ab5e5c304de01d591675
Profit Receiver: 0xe3c6346b6f282029312d2caf4677ef39beabbf99

Transaction Link: Click Here

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: harmonyprotocol

What happened: An exploit has occurred on Harmony Protocol where billions of $ONE tokens were falsely minted to several addresses. The affected team is taking proactive measures to freeze these funds. Users are advised to stay vigilant to protect against potential losses.

πŸ”—Tweet URL: View Tweet
πŸ‘1
🚨 Hack Alert!
Target: ColdCard

What happened: The ColdCard wallet incident is currently active, marking it as the largest hardware-wallet exploit recorded, with losses of around $130M and continuing to rise.

The exploit involves at least 15 attackers who are taking advantage of a seed-generation bug. Affected seeds can be brute-forced offline without the need for physical access to the devices.

For more information, you can refer to the tweet link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Maya Protocol

What happened: A significant exploit has occurred on Maya Protocol, resulting in a loss of approximately $1.7 million. The attacker manipulated the system by inflating the accounting with a false subsidy. This allowed them to add and remove liquidity, ultimately enabling the extraction of around 48.87 million CACAO tokens and 98.82 LINK tokens from shared liquidity. This incident highlights ongoing vulnerabilities within DeFi protocols, and users are advised to remain vigilant.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Flashstake V2

What happened: A hack alert was issued regarding Flashstake V2, where a total loss of 0.55 WETH (approximately $886) occurred on August 20, 2026.

The hack exploited an economic design flaw within the platform's reward pool structure. The attack leveraged the instant upfront reward mechanism, where the protocol calculated minted FLASH solely based on token deposits, lock duration, and total supply, neglecting external market values.

The attacker borrowed 10 ETH through Uniswap V4's PoolManager but only spent 0.11679 WETH to acquire a significant amount of legacy FLASH through DODO and Uniswap V2. After locking the acquired FLASH for 653 days, they received 145,125 FLASH in upfront rewards, which were then immediately sold for 0.54529 WETH.

As a result, the reward pool’s WETH reserve decreased by 28.25%. Following the repayment of borrowed ETH, the attacker netted a profit of 0.4284 ETH (approximately $696). The root cause identified was the mispriced reward pool that allowed for external FLASH to generate immediate rewards without proper checks or limits, leading to the financial loss.

Transaction Hash: https://t.co/z37H0k9QiE
Attacker Address: https://t.co/3fB77QcUZO
Victim Address: https://t.co/LoNXcjQzzN (FLASH/WETH Reward Pool)

Incident detected on 2026-08-20 20:14:23 UTC.

For real-time alerts, visit: https://t.co/XXmb8rT3VA

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: TheSandboxGame

What happened: 🚨 Blockaid has detected an ongoing exploit affecting @TheSandboxGame SAND OFT on Base.

Attackers have hijacked LayerZero delegate permissions using the approveAndCall method and have minted unbacked SAND tokens.

So far, approximately $49 billion face-value SAND has been minted across more than 400 transactions, and the attack is still ongoing.

More details are available in the thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: termlabs

*What happened:* 🚨 A governance attack targeted
@termlabs, resulting in a significant loss of approximately $8.5 million.

The incident involved a theft of 2,843 ETH and around $1.6 million in DAI, which are currently traceable at the address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

It serves as a reminder for users to stay vigilant in the face of emerging threats.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Arrakis Finance

What happened: 🚨 EXPLOIT ALERT | Ethereum

The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault was drained via a Uniswap V3 spot-price manipulation.

The root cause was identified as the vault's mint() and burn() valuing its Uniswap V3 position based on the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. While the vault did have a TWAP check, it only protects the manager's rebalance() swap, not the mint/burn operations.

Attack flow involved several steps:
1. A flash-loan of 1,800 WETH was taken from Morpho Blue.
2. Around 145 WETH was swapped for ENS on the UniV3 pool to distort the tick/spot price.
3. Vault shares were minted at the inflated valuation by depositing approximately 1,253 WETH plus 13,160 ENS, resulting in around 4,487 shares.
4. The price was restored by swapping back.
5. The shares were burned, allowing the attacker to redeem a more valuable token mix than what was initially deposited.
6. The surplus was converted, and the loan was repaid.

The attacker gained an estimated profit of approximately 2.94 WETH, and the exploit required no privileged access, being a straightforward permissionless flash-loan combined with spot manipulation.

Attacker address: Attacker link
Exploit contract: Exploit contract link
Vault: Vault link
Transaction: Transaction link

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: MoonwellDeFi

What happened: 🚨 An exploit has occurred at the @MoonwellDeFi lending market on Base.

The attacker manipulated the collateral price of relatively illiquid MAMO to borrow real cbBTC.

Approximately $8.7 million has been aggregated from this exploit.

For more details, you can check the provided links.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: CashCowCoin

What happened: 🚨 SlowMist TI Alert

CashCowCoin suffered a loss of approximately $117.4K due to a flaw in the unverified trading router implementation.

The flawed sell() flow allowed an attacker to exploit the system. After executing a swap from CCC to WBNB via PancakeSwap, the proxy incorrectly transferred the entire newly obtained CCC to a dead address. This process resulted in burning sell-side CCC while keeping a reduced WBNB reserve, which the attacker exploited through 80 iterative sell cycles, draining reserves.

Key forensic details include:
- Attacker EOA: 0x7977bdeee3a79dc85cc18739692e796b5d2513c4
- Attack Contract: 0x7738b4d7c25e9a7092ae1ab402343b20340daeaf
- Exploited Proxy: 0xf523224c6171f81c54b93f474ed4c78de91241c7
- Victim Pair (CCC/WBNB): 0x1dbe9458a6840784d5defd62c6b71386100097c0
- CCC Token: 0xb9b845f718c32f37e8af8b887ae4eec816c93ccc
- Profit Splitter Contract (holds stolen funds): 0xbabf70e515ae71a2177e624994a68d10c61d7a9f
- Splitter Owner: 0xca882106194ede1a5014c0fa1532234d084b72a9

Transaction details can be found at: https://t.co/PaMFp1zahD

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: avici

What happened: 🚨 @avici is currently experiencing an exploit that has resulted in a significant loss of approximately $1.02 million.

The alarming report highlights a serious security incident affecting the project, indicating that funds were successfully stolen during this attack.

πŸ”—Tweet URL: View Tweet
❀2
🚨 Hack Alert!
Target: TectonicFi

What happened: An exploit was detected on Tectonic Finance on the Cronos blockchain involving price manipulation.

Approximately $75 million has been moved to three addresses, with transaction details available for further scrutiny.

Users are advised not to interact with these addresses until it is confirmed safe to do so.

Stay vigilant and monitor the situation closely.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: More Markets

What happened: An exploit has been detected on More Markets (More Labs) on the Flow EVM.

The attacker utilized Ankr bonded LST along with E-mode to drain the WFLOW lending reserve.

In total, 15.5 million WFLOW was emptied from the mFlowWFLOW, which translates to approximately $9.3 million in impact.

The attack transaction cluster includes post-exploit exfiltration details.

More details are provided in the thread.

πŸ”—Tweet URL: View Tweet
❀1