QuillMonitor : Web3 Hacks and Alerts
223 subscribers
1 photo
176 links
Download Telegram
🚨 Hack Alert!
Target: aztecnetwork

What happened: PeckShield has reported that an exploiter associated with @aztecnetwork has deposited 300 $ETH worth approximately $572,100 into Tornado Cash.

Additionally, the exploiter has deposited a total of 500 $ETH into Tornado Cash as of today.

It is noted that @aztecnetwork suffered an exploit in June 2026, resulting in a total loss of $2.165M in cryptocurrency.

This indicates a specific incident involving a financial impact related to an exploit affecting the Aztec Network.

πŸ”—Tweet URL: View Tweet
❀2
🚨 Hack Alert!
Target: coinsbuycom

What happened: Specter has reported that wallets associated with @coinsbuycom have likely lost approximately $7.9 million due to a drain that affected both the TRON and Ethereum networks. The attacker has been active, depositing a portion of the stolen funds through various services, including ChangeNOW, FixedFloat, and BingX.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: USM

What happened: 🚨 SlowMist TI Alert

πŸ’Έ Loss: ~70.83 ETH

πŸ” Root Cause: A pricing logic flaw in ethFromDefund() of USM's defund() function has been exploited.
The function used arithmetic mean of current and estimated final FUM sell prices for single redemptions but lacked "split invariance." This issue, combined with per-redemption state contraction (adjShrinkFactor) and integer rounding, allowed 64 small defund() calls to return more ETH than one large call for the same FUM amount.

Attacker EOA: 0xb92b2e47680c89da8f951b8963ef469f461a50fc
Attacker Contract: 0x5a5e29ba89663a3558273354e990426f3cac7de7
Victim Contract (USM): 0x2a7fff44c19f39468064ab5e5c304de01d591675
Profit Receiver: 0xe3c6346b6f282029312d2caf4677ef39beabbf99

Transaction Link: Click Here

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: harmonyprotocol

What happened: An exploit has occurred on Harmony Protocol where billions of $ONE tokens were falsely minted to several addresses. The affected team is taking proactive measures to freeze these funds. Users are advised to stay vigilant to protect against potential losses.

πŸ”—Tweet URL: View Tweet
πŸ‘1
🚨 Hack Alert!
Target: ColdCard

What happened: The ColdCard wallet incident is currently active, marking it as the largest hardware-wallet exploit recorded, with losses of around $130M and continuing to rise.

The exploit involves at least 15 attackers who are taking advantage of a seed-generation bug. Affected seeds can be brute-forced offline without the need for physical access to the devices.

For more information, you can refer to the tweet link.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Maya Protocol

What happened: A significant exploit has occurred on Maya Protocol, resulting in a loss of approximately $1.7 million. The attacker manipulated the system by inflating the accounting with a false subsidy. This allowed them to add and remove liquidity, ultimately enabling the extraction of around 48.87 million CACAO tokens and 98.82 LINK tokens from shared liquidity. This incident highlights ongoing vulnerabilities within DeFi protocols, and users are advised to remain vigilant.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Flashstake V2

What happened: A hack alert was issued regarding Flashstake V2, where a total loss of 0.55 WETH (approximately $886) occurred on August 20, 2026.

The hack exploited an economic design flaw within the platform's reward pool structure. The attack leveraged the instant upfront reward mechanism, where the protocol calculated minted FLASH solely based on token deposits, lock duration, and total supply, neglecting external market values.

The attacker borrowed 10 ETH through Uniswap V4's PoolManager but only spent 0.11679 WETH to acquire a significant amount of legacy FLASH through DODO and Uniswap V2. After locking the acquired FLASH for 653 days, they received 145,125 FLASH in upfront rewards, which were then immediately sold for 0.54529 WETH.

As a result, the reward pool’s WETH reserve decreased by 28.25%. Following the repayment of borrowed ETH, the attacker netted a profit of 0.4284 ETH (approximately $696). The root cause identified was the mispriced reward pool that allowed for external FLASH to generate immediate rewards without proper checks or limits, leading to the financial loss.

Transaction Hash: https://t.co/z37H0k9QiE
Attacker Address: https://t.co/3fB77QcUZO
Victim Address: https://t.co/LoNXcjQzzN (FLASH/WETH Reward Pool)

Incident detected on 2026-08-20 20:14:23 UTC.

For real-time alerts, visit: https://t.co/XXmb8rT3VA

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: TheSandboxGame

What happened: 🚨 Blockaid has detected an ongoing exploit affecting @TheSandboxGame SAND OFT on Base.

Attackers have hijacked LayerZero delegate permissions using the approveAndCall method and have minted unbacked SAND tokens.

So far, approximately $49 billion face-value SAND has been minted across more than 400 transactions, and the attack is still ongoing.

More details are available in the thread.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: termlabs

*What happened:* 🚨 A governance attack targeted
@termlabs, resulting in a significant loss of approximately $8.5 million.

The incident involved a theft of 2,843 ETH and around $1.6 million in DAI, which are currently traceable at the address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

It serves as a reminder for users to stay vigilant in the face of emerging threats.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Arrakis Finance

What happened: 🚨 EXPLOIT ALERT | Ethereum

The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault was drained via a Uniswap V3 spot-price manipulation.

The root cause was identified as the vault's mint() and burn() valuing its Uniswap V3 position based on the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. While the vault did have a TWAP check, it only protects the manager's rebalance() swap, not the mint/burn operations.

Attack flow involved several steps:
1. A flash-loan of 1,800 WETH was taken from Morpho Blue.
2. Around 145 WETH was swapped for ENS on the UniV3 pool to distort the tick/spot price.
3. Vault shares were minted at the inflated valuation by depositing approximately 1,253 WETH plus 13,160 ENS, resulting in around 4,487 shares.
4. The price was restored by swapping back.
5. The shares were burned, allowing the attacker to redeem a more valuable token mix than what was initially deposited.
6. The surplus was converted, and the loan was repaid.

The attacker gained an estimated profit of approximately 2.94 WETH, and the exploit required no privileged access, being a straightforward permissionless flash-loan combined with spot manipulation.

Attacker address: Attacker link
Exploit contract: Exploit contract link
Vault: Vault link
Transaction: Transaction link

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: MoonwellDeFi

What happened: 🚨 An exploit has occurred at the @MoonwellDeFi lending market on Base.

The attacker manipulated the collateral price of relatively illiquid MAMO to borrow real cbBTC.

Approximately $8.7 million has been aggregated from this exploit.

For more details, you can check the provided links.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: CashCowCoin

What happened: 🚨 SlowMist TI Alert

CashCowCoin suffered a loss of approximately $117.4K due to a flaw in the unverified trading router implementation.

The flawed sell() flow allowed an attacker to exploit the system. After executing a swap from CCC to WBNB via PancakeSwap, the proxy incorrectly transferred the entire newly obtained CCC to a dead address. This process resulted in burning sell-side CCC while keeping a reduced WBNB reserve, which the attacker exploited through 80 iterative sell cycles, draining reserves.

Key forensic details include:
- Attacker EOA: 0x7977bdeee3a79dc85cc18739692e796b5d2513c4
- Attack Contract: 0x7738b4d7c25e9a7092ae1ab402343b20340daeaf
- Exploited Proxy: 0xf523224c6171f81c54b93f474ed4c78de91241c7
- Victim Pair (CCC/WBNB): 0x1dbe9458a6840784d5defd62c6b71386100097c0
- CCC Token: 0xb9b845f718c32f37e8af8b887ae4eec816c93ccc
- Profit Splitter Contract (holds stolen funds): 0xbabf70e515ae71a2177e624994a68d10c61d7a9f
- Splitter Owner: 0xca882106194ede1a5014c0fa1532234d084b72a9

Transaction details can be found at: https://t.co/PaMFp1zahD

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: avici

What happened: 🚨 @avici is currently experiencing an exploit that has resulted in a significant loss of approximately $1.02 million.

The alarming report highlights a serious security incident affecting the project, indicating that funds were successfully stolen during this attack.

πŸ”—Tweet URL: View Tweet
❀2
🚨 Hack Alert!
Target: TectonicFi

What happened: An exploit was detected on Tectonic Finance on the Cronos blockchain involving price manipulation.

Approximately $75 million has been moved to three addresses, with transaction details available for further scrutiny.

Users are advised not to interact with these addresses until it is confirmed safe to do so.

Stay vigilant and monitor the situation closely.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: More Markets

What happened: An exploit has been detected on More Markets (More Labs) on the Flow EVM.

The attacker utilized Ankr bonded LST along with E-mode to drain the WFLOW lending reserve.

In total, 15.5 million WFLOW was emptied from the mFlowWFLOW, which translates to approximately $9.3 million in impact.

The attack transaction cluster includes post-exploit exfiltration details.

More details are provided in the thread.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Visor/Gamma

What happened: An exploit has been reported involving the draining of approximately 10.7 ETH from two legacy Visor/Gamma FLOAT-ETH Hypervisor vaults. The incident details a significant vulnerability related to the Hypervisor's minting process of LP shares based on the Uniswap V3 pool's instantaneous spot price without proper checks. The attacker took advantage of this flaw to execute a flash-loan price manipulation exploit.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: FloatProtocol

What happened: 🚨 SlowMist TI Alert

πŸ’° @FloatProtocol Loss: ~$28,000 (10.71 ETH)

πŸ” Root Cause: Uniswap V3 spot price (slot0) manipulation via flash loans enabled incorrect LP share pricing in Hypervisor contracts. Critical functions lacked TWAP/oracle validation and slippage protection.

πŸ“Œ Attacker: 0xaea29218262dc6b0904ca077f6527c49dfd426d9
πŸ“Œ Attack Contract: 0xb46655eb5b77de277063a75586d1883e951b6c54
πŸ“Œ Vulnerable Contracts:
- 0x85cbed523459b7f6f81c11e710df969703a8a70c
- 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153
πŸ“Œ Underlying Pool: 0xe8c2036068fc3b0161ee1def0e8d01df4eac0ac

Attackers manipulated currentTick()/getTotalAmounts() by swapping large amounts on the V3 pool to distort slot0, then repeatedly deposited and withdrew with inflated share values.

Transaction details can be found at: https://t.co/8CDnQ4ZjEo.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Aquifer

What happened: Aquifer on Solana was reportedly exploited for approximately $2.5 million across over 90 attack transactions, draining its vaults.

Due to the unavailability of the source code, this analysis is based on preliminary on-chain data. The likely root cause of the exploit was a caller-controlled input-side token program that was not linked to the canonical SPL Token Program. This allowed the attacker to receive actual output tokens without providing the necessary input, as Aquifer trusted the result from the call without validating the actual token balance changes.

During the attack, both the USDC and HYPE token mints were presented as swap parameters, suggesting that the attacker was buying HYPE with USDC. However, the changes in balance and execution trace reveal that only the HYPE vault transferred tokens to the attacker, confirming that there was no actual USDC inflow.

Aquifer erroneously permitted callers to supply the tokenProgramA during the swap process, enabling the attacker to replace it with a malicious program, which accepted and processed the token transfer instructions without conducting a real transfer.

Attack transaction: https://t.co/ItnJUp7QxH

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Reflexer

What happened: 🚨 ALERT β€” Exploit on Ethereum

A GEB/RAI-style CDP deployment (Reflexer's GEB framework, in Global Settlement since Jan 2021) was just drained of its leftover ETH-A collateral. Approximately 5.94 ETH, valued at around $14k, was stolen.

Root cause: Several SAFEs were owned by the shared GebProxyActions library itself (0x84fe452d9fb495a335c74a225e6ad52c35eb8616), rather than by user proxies. Its quitSystem() is public and unauthenticated, allowing the attacker to call it directly. The GebSafeManager's msg.sender check passed as the library was acting as itself, enabling the migration of other users' collateral to the attacker, followed by freeCollateral and exit operations.

Attack transaction: https://t.co/KAmU46mQB8
Attacker address: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
Exploit contract: 0x6a213f0b5bd9eed865d3e2efc867b73dfe9039e7

Lesson: Never allow a stateless, shared 'proxy-actions' contract to become the registered owner of a position, as its public helpers can become anyone's withdrawal method.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Notional Finance

What happened: PeckShield has reported that the Notional Finance escrow contract may have been exploited.

This incident has resulted in the loss of $1.7M, with funds stolen in both Ethereum and $USDC.

The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into Tornado Cash.

Forensic details include the transaction address: 0x6b175474e89094c44da98b954eedeac495271d0f.

πŸ”—Tweet URL: View Tweet
❀2
🚨 Hack Alert!
Target: DHC

What happened: Skyeye Alert details an exploit on the BNB Chain involving the DHC (Dream Health Chain) staking or "pledge" pool.

The attack drained the pool's reward reserve, leading to the minting of approximately 568,370 DHC from thin air, which was sold for about 71,851 USDT (~$71.8K). This incident caused a significant crash in DHC's value, plummeting by approximately 91% from $0.34 to $0.03.

The root cause of the exploit was identified as a flaw in the pool's reward-claim function. This function pays a fixed reward from the reserve for every call without tracking claims or elapsed time, allowing the attacker to repeatedly claim rewards. The attacker utilized a strategy of looping pledge and claim actions, supported by minimal initial capital through flash loans.

The transaction details indicate that the attacker executed the same reward payout 18 times on one position before dumping the DHC for USDT on PancakeSwap.

Key forensic details include:
- Attack tx: https://t.co/nPsKCnyxnO
- Attacker address: 0xD3A8D0A9F55cf679fff6F277E49AfC95B49D2B07
- Exploit contract: 0x226923D34A10f3D54B57b9F4b685E82c6Cba968A
- Victim pool address: 0xe2a047aaDbac51b0116Af1cE91EbdAe4b4202094

πŸ”—Tweet URL: View Tweet
❀1