QuillMonitor : Web3 Hacks and Alerts
227 subscribers
1 photo
182 links
Download Telegram
🚨 Hack Alert! @channel
Target: NGP token
What happened: #CertiKAlert 🚨

We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.

https://t.co/aT35te0VWi

The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.

Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP token
What happened: #CertiKAlert 🚨

We have seen a ~$2M exploit on NGP token, whose transfer logic states that 35% of the selling amount is deducted from the pool balance, which is then synced.

https://t.co/aT35te0VWi

The exploiter flashloaned $211M to manipulate the NGP token balance to such a low value that the aforementioned deduction in selling 1.36M NGP reduces the NGP reserve value 13.6 million times from 477K to 0.035. This breaks the k=xy swapping curve, allowing the exploiter to drain the victim pool.

Stay vigilant!
Tweet URL: <https://twitter.com/CertiKAlert/status/1968524034464977366|View on Twitter>
🚨 Hack Alert! @channel
Target: Request Finance
What happened: A phishing theft has occurred resulting in a loss of $6.28 million. The attack involved a drainer customer identified by the address 0x1623...9aC9, which converted stolen assets into ETH and moved various amounts including 753 stETH pending a Lido withdrawal. Additionally, 123 ETH was bridged to Bitcoin and TRON, and 71 ETH was moved via NEAR Intents. Following this, the drainer's fee address (0xa2e8...4F8) transferred 312.8 ETH to a new address (0x5e91bfcfbddc1868770f17a4cb4f65043d17a64b). This incident shows the rapid movement of stolen funds across multiple chains. Users are advised to remain vigilant.
πŸ”—Tweet URL: <https://twitter.com/realScamSniffer/status/1968702743046205531 |View on Twitter>
🚨 Hack Alert! @channel
Target: Request Finance
What happened: A victim lost $41,326 after mistakenly copying the wrong centralized exchange deposit address from contaminated transfer history. This incident highlights the risks associated with handling transfer histories that may be compromised.
πŸ”—Tweet URL: <https://twitter.com/realScamSniffer/status/1969066493775405433 |View on Twitter>
🚨 Hack Alert! @channel
Target: UXLINK
What happened: Our system has detected $11.3M in suspicious transactions involving UXLINK. An ETH address executed a delegateCall, removed the admin role, and called "addOwnerWithThreshold" before transferring $4M USDT, $500K USDC, 3.7 WBTC, and 25 ETH. All USDC/USDT were swapped to DAI on ETH network, while on Arbitrum USDT was swapped to ETH and bridged to ETH network. Another address after few min received 10M UXLINK (~$3M), began swapping, but still holds ~$2.2M unswapped. This incident indicates a significant breach involving unauthorized transactions and fund movements. The tweet provides a detailed sequence of actions linked to the potential hack and financial impact. The context implies ongoing suspicious activity related to the UXLINK project.
Tweet URL: <https://twitter.com/CyversAlerts/status/1970167036002132425|View on Twitter>
🚨 Hack Alert! @channel
Target: NGP
What happened: A $2M exploit occurred on the $NGP token. The attack leveraged the token's transfer logic which deducts 35% of the selling amount from the pool balance. The exploiter executed a flashloan of $211M to artificially lower the NGP balance. By selling just 1.36M NGP, the reserve was slashed from 477K to a mere 0.035, significantly impacting the token's value. This incident highlights vulnerabilities in the token's mechanics that were exploited.
πŸ”—Tweet URL: <https://twitter.com/guardrailai/status/1970192200601366568 |View on Twitter>
🚨 Hack Alert! @channel

Target: hypervaultfi

What happened: A significant withdrawal of approximately $3.6 million worth of cryptocurrencies has been detected from the HyperVault protocol.

The funds were originally bridged from Hyperliquid to the Ethereum blockchain, where they were swapped into ETH.

Following the swap, a total of 752 ETH was deposited into Tornado Cash, raising concerns about a potential rug pull.


Tweet URL: <https://twitter.com/PeckShieldAlert/status/1971476404173930660|View on Twitter>
🚨 Hack Alert! @channel
Target: Griffin AI

What happened: On September 24, 2025, Griffin AI experienced an exploit resulting in a loss of approximately $3 million due to a vulnerability in LayerZero.

The attack occurred just hours after the token launch, where an attacker minted 5 billion unauthorized $GAIN tokens, causing a drastic price drop of 87%.

The tweet provides details on the incident, indicating a significant financial impact and naming the exploited project and the method of attack.

πŸ”—Tweet URL: <https://twitter.com/guardrailai/status/1971612441370148923 |View on Twitter>
🚨 Hack Alert! @channel

Target: HyperDrive DeFi

What happened: An exploit has occurred on HyperDrive DeFi.

The attacker exploited an arbitrary call in the router, leading to the theft of users' funds totaling 672,934 USDT and 110,244 thBILL, amounting to approximately $782,000.

This incident highlights the vulnerabilities present in the protocol.

Users are advised to stay vigilant.

For more details, refer to the provided link.

Tweet URL: <https://twitter.com/CertiKAlert/status/1972117426893738341|View on Twitter>
🚨 Hack Alert! @channel
Target: RadiantCapital

What happened: The tweet reports a specific security incident involving Radiant Capital.

The incident details include the exploiter who swapped approximately $14 million in DAI for 3,490.2 ETH. Additionally, they deposited 2,243.2 ETH into Tornado Cash, indicating potential money laundering or attempts to obfuscate the funds.

This incident highlights a specific action taken by an exploiter affecting the Radiant Capital project.

πŸ”—Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972124721132269835 |View on Twitter>
🚨 Hack Alert! @channel

Target: ResupplyFi

What happened: The #Resupply exploiter has deposited 1,607 $ETH, approximately valued at $6.5M, into #TornadoCash.

These funds trace back to an exploit on June 2025 involving @ResupplyFi, which resulted in a significant loss of $9.6M.

This incident highlights the ongoing exploitation of funds within the crypto ecosystem.

Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972492625556222188|View on Twitter>
🚨 Hack Alert! @channel

Target: UXLINK

What happened: A significant security incident has been reported involving the #UXLINK exploiter. The exploiter swapped 28.67 $WBTC for approximately 778 $ETH, valued at around $3.27 million. Following this, the exploiter has initiated deposits into #TornadoCash, which raises concerns about the laundering of the funds.

This incident highlights the ongoing issues with exploits in the Web3 space and the need for vigilance against illicit transactions.



Tweet URL: <https://twitter.com/PeckShieldAlert/status/1972917298286739458|View on Twitter>
🚨 Hack Alert!

Target: hyperdrivedefi

What happened: On September 27, 2025, a recent exploit occurred on @hyperdrivedefi, a DeFi yield protocol on Hyperliquid.

Hackers drained approximately $773,000 from the platform through a vulnerability in its router contract.

The incident affected two user positions in the Treasury Bill market, which involved 673K USDT0 and 110K thBILL.

The attacker utilized arbitrary calls to siphon funds, subsequently bridging them to BNB Chain and Ethereum for laundering.

Tweet URL: https://twitter.com/guardrailai/status/1973377059297587231
🚨 Hack Alert!
Target: THORChain

What happened: DPRK-linked actors bridged $7 million from Ethereum to Bitcoin following the WooX hack. This occurred via @THORChain, just weeks after THORChain’s founder was phished.

The reported funds highlight the ongoing threats associated with hacks and the potential exploitation of protocols.

πŸ”—Tweet URL: https://twitter.com/hackenclub/status/1973428947778957318
🚨 Hack Alert!

Target: Scam Sniffer

What happened: In September 2025, total losses attributed to phishing scams amounted to $11.78 million, affecting 15,513 victims.

The data indicates a decrease of 3.2% in losses compared to August, but an increase of 1.9% in the number of victims.

A key insight highlighted is the prevalence of "Permit" signature phishing schemes, which have proven to be the most dominant threat in this area. A notable incident included the largest single loss, where an address (0x0d18…D7e3) lost approximately $6.5 million after signing multiple phishing permits.

Tweet URL: https://twitter.com/realScamSniffer/status/1975186034771292303
🚨 Hack Alert!
Target: mooCurveUSDC-USDf

What happened: A victim lost $163,112 worth of mooCurveUSDC-USDf after signing a malicious "increaseAllowance" signature.

This incident highlights the risks involved with signing transactions that may appear legitimate but are actually malicious.

The specific amount lost is detailed, providing a clear understanding of the financial impact involved in this security breach.

πŸ”—Tweet URL: https://twitter.com/realScamSniffer/status/1975352731100717278
Please open Telegram to view this post
VIEW IN TELEGRAM
🚨 Hack Alert!

Target: OracleBNB

What happened: A rug pull incident has been reported involving the project @OracleBNB on the BNB Chain.

The project has allegedly rugged, leading to significant concerns among its users.

Additionally, it has been noted that @OracleBNB has already deleted its social media platform, indicating an effort to distance themselves from the incident.

No specific amounts regarding the financial impact have been detailed in this alert.

Tweet URL: https://twitter.com/PeckShieldAlert/status/1976560418832404617
🚨 Hack Alert!
Target: Hyperliquid

What happened: A victim lost approximately $21 million worth of cryptocurrencies on Hyperliquid due to a private key leak.

The hacker has bridged the stolen funds to Ethereum, which includes 17.75 million DAI and 3.11 million MSYRUPUSDP.

Forensic details reveal the impacted victim address is 0x0cdC...E955 and the tweet originates from PeckShieldAlert.

πŸ”—Tweet URL: https://twitter.com/PeckShieldAlert/status/1976577386469839269
😒1