π¨ Hack Alert!
Target: termlabs
*What happened:* π¨ A governance attack targeted @termlabs, resulting in a significant loss of approximately $8.5 million.
The incident involved a theft of 2,843 ETH and around $1.6 million in DAI, which are currently traceable at the address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.
It serves as a reminder for users to stay vigilant in the face of emerging threats.
πTweet URL: View Tweet
Target: termlabs
*What happened:* π¨ A governance attack targeted @termlabs, resulting in a significant loss of approximately $8.5 million.
The incident involved a theft of 2,843 ETH and around $1.6 million in DAI, which are currently traceable at the address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.
It serves as a reminder for users to stay vigilant in the face of emerging threats.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: Arrakis Finance
What happened: π¨ EXPLOIT ALERT | Ethereum
The Arrakis V1 / G-UNI ENSβWETH liquidity-manager vault was drained via a Uniswap V3 spot-price manipulation.
The root cause was identified as the vault's mint() and burn() valuing its Uniswap V3 position based on the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. While the vault did have a TWAP check, it only protects the manager's rebalance() swap, not the mint/burn operations.
Attack flow involved several steps:
1. A flash-loan of 1,800 WETH was taken from Morpho Blue.
2. Around 145 WETH was swapped for ENS on the UniV3 pool to distort the tick/spot price.
3. Vault shares were minted at the inflated valuation by depositing approximately 1,253 WETH plus 13,160 ENS, resulting in around 4,487 shares.
4. The price was restored by swapping back.
5. The shares were burned, allowing the attacker to redeem a more valuable token mix than what was initially deposited.
6. The surplus was converted, and the loan was repaid.
The attacker gained an estimated profit of approximately 2.94 WETH, and the exploit required no privileged access, being a straightforward permissionless flash-loan combined with spot manipulation.
Attacker address: Attacker link
Exploit contract: Exploit contract link
Vault: Vault link
Transaction: Transaction link
πTweet URL: View Tweet
Target: Arrakis Finance
What happened: π¨ EXPLOIT ALERT | Ethereum
The Arrakis V1 / G-UNI ENSβWETH liquidity-manager vault was drained via a Uniswap V3 spot-price manipulation.
The root cause was identified as the vault's mint() and burn() valuing its Uniswap V3 position based on the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. While the vault did have a TWAP check, it only protects the manager's rebalance() swap, not the mint/burn operations.
Attack flow involved several steps:
1. A flash-loan of 1,800 WETH was taken from Morpho Blue.
2. Around 145 WETH was swapped for ENS on the UniV3 pool to distort the tick/spot price.
3. Vault shares were minted at the inflated valuation by depositing approximately 1,253 WETH plus 13,160 ENS, resulting in around 4,487 shares.
4. The price was restored by swapping back.
5. The shares were burned, allowing the attacker to redeem a more valuable token mix than what was initially deposited.
6. The surplus was converted, and the loan was repaid.
The attacker gained an estimated profit of approximately 2.94 WETH, and the exploit required no privileged access, being a straightforward permissionless flash-loan combined with spot manipulation.
Attacker address: Attacker link
Exploit contract: Exploit contract link
Vault: Vault link
Transaction: Transaction link
πTweet URL: View Tweet
π¨ Hack Alert!
Target: MoonwellDeFi
What happened: π¨ An exploit has occurred at the @MoonwellDeFi lending market on Base.
The attacker manipulated the collateral price of relatively illiquid MAMO to borrow real cbBTC.
Approximately $8.7 million has been aggregated from this exploit.
For more details, you can check the provided links.
πTweet URL: View Tweet
Target: MoonwellDeFi
What happened: π¨ An exploit has occurred at the @MoonwellDeFi lending market on Base.
The attacker manipulated the collateral price of relatively illiquid MAMO to borrow real cbBTC.
Approximately $8.7 million has been aggregated from this exploit.
For more details, you can check the provided links.
πTweet URL: View Tweet
π¨ Hack Alert!
Target: CashCowCoin
What happened: π¨ SlowMist TI Alert
CashCowCoin suffered a loss of approximately $117.4K due to a flaw in the unverified trading router implementation.
The flawed
Key forensic details include:
- Attacker EOA:
- Attack Contract:
- Exploited Proxy:
- Victim Pair (CCC/WBNB):
- CCC Token:
- Profit Splitter Contract (holds stolen funds):
- Splitter Owner:
Transaction details can be found at: https://t.co/PaMFp1zahD
πTweet URL: View Tweet
Target: CashCowCoin
What happened: π¨ SlowMist TI Alert
CashCowCoin suffered a loss of approximately $117.4K due to a flaw in the unverified trading router implementation.
The flawed
sell() flow allowed an attacker to exploit the system. After executing a swap from CCC to WBNB via PancakeSwap, the proxy incorrectly transferred the entire newly obtained CCC to a dead address. This process resulted in burning sell-side CCC while keeping a reduced WBNB reserve, which the attacker exploited through 80 iterative sell cycles, draining reserves.Key forensic details include:
- Attacker EOA:
0x7977bdeee3a79dc85cc18739692e796b5d2513c4- Attack Contract:
0x7738b4d7c25e9a7092ae1ab402343b20340daeaf- Exploited Proxy:
0xf523224c6171f81c54b93f474ed4c78de91241c7- Victim Pair (CCC/WBNB):
0x1dbe9458a6840784d5defd62c6b71386100097c0- CCC Token:
0xb9b845f718c32f37e8af8b887ae4eec816c93ccc- Profit Splitter Contract (holds stolen funds):
0xbabf70e515ae71a2177e624994a68d10c61d7a9f- Splitter Owner:
0xca882106194ede1a5014c0fa1532234d084b72a9Transaction details can be found at: https://t.co/PaMFp1zahD
πTweet URL: View Tweet
π¨ Hack Alert!
Target: avici
What happened: π¨ @avici is currently experiencing an exploit that has resulted in a significant loss of approximately $1.02 million.
The alarming report highlights a serious security incident affecting the project, indicating that funds were successfully stolen during this attack.
πTweet URL: View Tweet
Target: avici
What happened: π¨ @avici is currently experiencing an exploit that has resulted in a significant loss of approximately $1.02 million.
The alarming report highlights a serious security incident affecting the project, indicating that funds were successfully stolen during this attack.
πTweet URL: View Tweet
β€2
π¨ Hack Alert!
Target: TectonicFi
What happened: An exploit was detected on Tectonic Finance on the Cronos blockchain involving price manipulation.
Approximately $75 million has been moved to three addresses, with transaction details available for further scrutiny.
Users are advised not to interact with these addresses until it is confirmed safe to do so.
Stay vigilant and monitor the situation closely.
πTweet URL: View Tweet
Target: TectonicFi
What happened: An exploit was detected on Tectonic Finance on the Cronos blockchain involving price manipulation.
Approximately $75 million has been moved to three addresses, with transaction details available for further scrutiny.
Users are advised not to interact with these addresses until it is confirmed safe to do so.
Stay vigilant and monitor the situation closely.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: More Markets
What happened: An exploit has been detected on More Markets (More Labs) on the Flow EVM.
The attacker utilized Ankr bonded LST along with E-mode to drain the WFLOW lending reserve.
In total, 15.5 million WFLOW was emptied from the mFlowWFLOW, which translates to approximately $9.3 million in impact.
The attack transaction cluster includes post-exploit exfiltration details.
More details are provided in the thread.
πTweet URL: View Tweet
Target: More Markets
What happened: An exploit has been detected on More Markets (More Labs) on the Flow EVM.
The attacker utilized Ankr bonded LST along with E-mode to drain the WFLOW lending reserve.
In total, 15.5 million WFLOW was emptied from the mFlowWFLOW, which translates to approximately $9.3 million in impact.
The attack transaction cluster includes post-exploit exfiltration details.
More details are provided in the thread.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: Visor/Gamma
What happened: An exploit has been reported involving the draining of approximately 10.7 ETH from two legacy Visor/Gamma FLOAT-ETH Hypervisor vaults. The incident details a significant vulnerability related to the Hypervisor's minting process of LP shares based on the Uniswap V3 pool's instantaneous spot price without proper checks. The attacker took advantage of this flaw to execute a flash-loan price manipulation exploit.
πTweet URL: View Tweet
Target: Visor/Gamma
What happened: An exploit has been reported involving the draining of approximately 10.7 ETH from two legacy Visor/Gamma FLOAT-ETH Hypervisor vaults. The incident details a significant vulnerability related to the Hypervisor's minting process of LP shares based on the Uniswap V3 pool's instantaneous spot price without proper checks. The attacker took advantage of this flaw to execute a flash-loan price manipulation exploit.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: FloatProtocol
What happened: π¨ SlowMist TI Alert
π° @FloatProtocol Loss: ~$28,000 (10.71 ETH)
π Root Cause: Uniswap V3 spot price (
π Attacker:
π Attack Contract:
π Vulnerable Contracts:
-
-
π Underlying Pool:
Attackers manipulated
Transaction details can be found at: https://t.co/8CDnQ4ZjEo.
πTweet URL: View Tweet
Target: FloatProtocol
What happened: π¨ SlowMist TI Alert
π° @FloatProtocol Loss: ~$28,000 (10.71 ETH)
π Root Cause: Uniswap V3 spot price (
slot0) manipulation via flash loans enabled incorrect LP share pricing in Hypervisor contracts. Critical functions lacked TWAP/oracle validation and slippage protection.π Attacker:
0xaea29218262dc6b0904ca077f6527c49dfd426d9π Attack Contract:
0xb46655eb5b77de277063a75586d1883e951b6c54π Vulnerable Contracts:
-
0x85cbed523459b7f6f81c11e710df969703a8a70c-
0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153π Underlying Pool:
0xe8c2036068fc3b0161ee1def0e8d01df4eac0acAttackers manipulated
currentTick()/getTotalAmounts() by swapping large amounts on the V3 pool to distort slot0, then repeatedly deposited and withdrew with inflated share values.Transaction details can be found at: https://t.co/8CDnQ4ZjEo.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: Aquifer
What happened: Aquifer on Solana was reportedly exploited for approximately $2.5 million across over 90 attack transactions, draining its vaults.
Due to the unavailability of the source code, this analysis is based on preliminary on-chain data. The likely root cause of the exploit was a caller-controlled input-side token program that was not linked to the canonical SPL Token Program. This allowed the attacker to receive actual output tokens without providing the necessary input, as Aquifer trusted the result from the call without validating the actual token balance changes.
During the attack, both the USDC and HYPE token mints were presented as swap parameters, suggesting that the attacker was buying HYPE with USDC. However, the changes in balance and execution trace reveal that only the HYPE vault transferred tokens to the attacker, confirming that there was no actual USDC inflow.
Aquifer erroneously permitted callers to supply the tokenProgramA during the swap process, enabling the attacker to replace it with a malicious program, which accepted and processed the token transfer instructions without conducting a real transfer.
Attack transaction: https://t.co/ItnJUp7QxH
πTweet URL: View Tweet
Target: Aquifer
What happened: Aquifer on Solana was reportedly exploited for approximately $2.5 million across over 90 attack transactions, draining its vaults.
Due to the unavailability of the source code, this analysis is based on preliminary on-chain data. The likely root cause of the exploit was a caller-controlled input-side token program that was not linked to the canonical SPL Token Program. This allowed the attacker to receive actual output tokens without providing the necessary input, as Aquifer trusted the result from the call without validating the actual token balance changes.
During the attack, both the USDC and HYPE token mints were presented as swap parameters, suggesting that the attacker was buying HYPE with USDC. However, the changes in balance and execution trace reveal that only the HYPE vault transferred tokens to the attacker, confirming that there was no actual USDC inflow.
Aquifer erroneously permitted callers to supply the tokenProgramA during the swap process, enabling the attacker to replace it with a malicious program, which accepted and processed the token transfer instructions without conducting a real transfer.
Attack transaction: https://t.co/ItnJUp7QxH
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: Reflexer
What happened: π¨ ALERT β Exploit on Ethereum
A GEB/RAI-style CDP deployment (Reflexer's GEB framework, in Global Settlement since Jan 2021) was just drained of its leftover ETH-A collateral. Approximately 5.94 ETH, valued at around $14k, was stolen.
Root cause: Several SAFEs were owned by the shared GebProxyActions library itself (0x84fe452d9fb495a335c74a225e6ad52c35eb8616), rather than by user proxies. Its quitSystem() is public and unauthenticated, allowing the attacker to call it directly. The GebSafeManager's msg.sender check passed as the library was acting as itself, enabling the migration of other users' collateral to the attacker, followed by freeCollateral and exit operations.
Attack transaction: https://t.co/KAmU46mQB8
Attacker address: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
Exploit contract: 0x6a213f0b5bd9eed865d3e2efc867b73dfe9039e7
Lesson: Never allow a stateless, shared 'proxy-actions' contract to become the registered owner of a position, as its public helpers can become anyone's withdrawal method.
πTweet URL: View Tweet
Target: Reflexer
What happened: π¨ ALERT β Exploit on Ethereum
A GEB/RAI-style CDP deployment (Reflexer's GEB framework, in Global Settlement since Jan 2021) was just drained of its leftover ETH-A collateral. Approximately 5.94 ETH, valued at around $14k, was stolen.
Root cause: Several SAFEs were owned by the shared GebProxyActions library itself (0x84fe452d9fb495a335c74a225e6ad52c35eb8616), rather than by user proxies. Its quitSystem() is public and unauthenticated, allowing the attacker to call it directly. The GebSafeManager's msg.sender check passed as the library was acting as itself, enabling the migration of other users' collateral to the attacker, followed by freeCollateral and exit operations.
Attack transaction: https://t.co/KAmU46mQB8
Attacker address: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
Exploit contract: 0x6a213f0b5bd9eed865d3e2efc867b73dfe9039e7
Lesson: Never allow a stateless, shared 'proxy-actions' contract to become the registered owner of a position, as its public helpers can become anyone's withdrawal method.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: Notional Finance
What happened: PeckShield has reported that the Notional Finance escrow contract may have been exploited.
This incident has resulted in the loss of $1.7M, with funds stolen in both Ethereum and $USDC.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into Tornado Cash.
Forensic details include the transaction address: 0x6b175474e89094c44da98b954eedeac495271d0f.
πTweet URL: View Tweet
Target: Notional Finance
What happened: PeckShield has reported that the Notional Finance escrow contract may have been exploited.
This incident has resulted in the loss of $1.7M, with funds stolen in both Ethereum and $USDC.
The exploiter has swapped the stolen funds into 689.2 $ETH and deposited them into Tornado Cash.
Forensic details include the transaction address: 0x6b175474e89094c44da98b954eedeac495271d0f.
πTweet URL: View Tweet
β€2
π¨ Hack Alert!
Target: DHC
What happened: Skyeye Alert details an exploit on the BNB Chain involving the DHC (Dream Health Chain) staking or "pledge" pool.
The attack drained the pool's reward reserve, leading to the minting of approximately 568,370 DHC from thin air, which was sold for about 71,851 USDT (~$71.8K). This incident caused a significant crash in DHC's value, plummeting by approximately 91% from $0.34 to $0.03.
The root cause of the exploit was identified as a flaw in the pool's reward-claim function. This function pays a fixed reward from the reserve for every call without tracking claims or elapsed time, allowing the attacker to repeatedly claim rewards. The attacker utilized a strategy of looping pledge and claim actions, supported by minimal initial capital through flash loans.
The transaction details indicate that the attacker executed the same reward payout 18 times on one position before dumping the DHC for USDT on PancakeSwap.
Key forensic details include:
- Attack tx: https://t.co/nPsKCnyxnO
- Attacker address: 0xD3A8D0A9F55cf679fff6F277E49AfC95B49D2B07
- Exploit contract: 0x226923D34A10f3D54B57b9F4b685E82c6Cba968A
- Victim pool address: 0xe2a047aaDbac51b0116Af1cE91EbdAe4b4202094
πTweet URL: View Tweet
Target: DHC
What happened: Skyeye Alert details an exploit on the BNB Chain involving the DHC (Dream Health Chain) staking or "pledge" pool.
The attack drained the pool's reward reserve, leading to the minting of approximately 568,370 DHC from thin air, which was sold for about 71,851 USDT (~$71.8K). This incident caused a significant crash in DHC's value, plummeting by approximately 91% from $0.34 to $0.03.
The root cause of the exploit was identified as a flaw in the pool's reward-claim function. This function pays a fixed reward from the reserve for every call without tracking claims or elapsed time, allowing the attacker to repeatedly claim rewards. The attacker utilized a strategy of looping pledge and claim actions, supported by minimal initial capital through flash loans.
The transaction details indicate that the attacker executed the same reward payout 18 times on one position before dumping the DHC for USDT on PancakeSwap.
Key forensic details include:
- Attack tx: https://t.co/nPsKCnyxnO
- Attacker address: 0xD3A8D0A9F55cf679fff6F277E49AfC95B49D2B07
- Exploit contract: 0x226923D34A10f3D54B57b9F4b685E82c6Cba968A
- Victim pool address: 0xe2a047aaDbac51b0116Af1cE91EbdAe4b4202094
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: RedSonic Vault
What happened: An exploit occurred on the Ethereum network affecting the RedSonic Vault. The attacker drained approximately 9.25 ETH using a sophisticated method involving a flash loan. The attack was carried out by borrowing 1,139 WETH from Balancer, which manipulated the vault's share price. The attacker took advantage of a permissionless function that allowed them to register stETH as an additional asset, inflating the value of the vault's share class. The sequence of the attack involved executing a single transaction where the attacker inflated the rsvETH price and redeemed it at an inflated rate to extract more ETH than was initially deposited. This strategic move allowed them to profit from the vault's balance multiple times. This incident highlights significant vulnerabilities in the vaultβs pricing mechanism and execution logic.
πTweet URL: View Tweet
Target: RedSonic Vault
What happened: An exploit occurred on the Ethereum network affecting the RedSonic Vault. The attacker drained approximately 9.25 ETH using a sophisticated method involving a flash loan. The attack was carried out by borrowing 1,139 WETH from Balancer, which manipulated the vault's share price. The attacker took advantage of a permissionless function that allowed them to register stETH as an additional asset, inflating the value of the vault's share class. The sequence of the attack involved executing a single transaction where the attacker inflated the rsvETH price and redeemed it at an inflated rate to extract more ETH than was initially deposited. This strategic move allowed them to profit from the vault's balance multiple times. This incident highlights significant vulnerabilities in the vaultβs pricing mechanism and execution logic.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: LiquidBTC
*What happened:* A significant unauthorized withdrawal has been reported involving SideSwap PAK at @LiquidBTC.
Approximately 4,000 BTC, valued at around $320 million, was withdrawn.
The incident includes the hacker leaving a message claiming to be whitehats and requested to be contacted on-chain.
Forensic details include the transaction address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr.
This event indicates a major security breach with substantial financial impact.
πTweet URL: View Tweet
Target: LiquidBTC
*What happened:* A significant unauthorized withdrawal has been reported involving SideSwap PAK at @LiquidBTC.
Approximately 4,000 BTC, valued at around $320 million, was withdrawn.
The incident includes the hacker leaving a message claiming to be whitehats and requested to be contacted on-chain.
Forensic details include the transaction address: bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr.
This event indicates a major security breach with substantial financial impact.
πTweet URL: View Tweet
β€1
π¨ Hack Alert!
Target: cozyfinance
What happened: Community alert: Blockaid has detected an ongoing exploit on Cozy Finance on the Optimism network.
So far, $170,000 has been drained as a result of this incident.
Further details are expected to follow in the thread.
πTweet URL: View Tweet
Target: cozyfinance
What happened: Community alert: Blockaid has detected an ongoing exploit on Cozy Finance on the Optimism network.
So far, $170,000 has been drained as a result of this incident.
Further details are expected to follow in the thread.
πTweet URL: View Tweet
β€2
π¨ Hack Alert!
Target: WealthManagementV2
What happened: An alert from SlowMist on a significant security incident involving WealthManagementV2 has been issued.
A total of 26,414 USDT was stolen due to exploited owner privileges of the contract, suspected to be caused by a leaked private key.
The attacker gained control of the contract, allowing them to manipulate plan parameters through
The attacker address is noted as
For further details, here are the transaction links:
- Transaction 1
- Transaction 2
πTweet URL: View Tweet
Target: WealthManagementV2
What happened: An alert from SlowMist on a significant security incident involving WealthManagementV2 has been issued.
A total of 26,414 USDT was stolen due to exploited owner privileges of the contract, suspected to be caused by a leaked private key.
The attacker gained control of the contract, allowing them to manipulate plan parameters through
updatePlanConfig without any timelock or restrictions, enabling them to mint inflated interest and withdraw funds.The attacker address is noted as
0xe439422afdd247503f75b4143c4a973eced04a36. The victim contract involved in this incident is WealthManagementV2 with address 0x7b5dda5135811ec0870a75a04d0e1807edc3c93d.For further details, here are the transaction links:
- Transaction 1
- Transaction 2
πTweet URL: View Tweet