QuillMonitor : Web3 Hacks and Alerts
226 subscribers
1 photo
182 links
Download Telegram
🚨 Hack Alert!
Target: Venus

What happened: #PeckShieldAlert reported a specific incident involving the address 0x5636...2008, which had previously been associated with a phishing attempt that resulted in a loss of $13M on the Venus protocol. Although that amount was later recovered by the protocol, the address has now been liquidated for a total of $3.44M in $vBNB and $vUSDT. This indicates a significant financial impact related to the prior phishing incident, showcasing ongoing risks in the ecosystem.

The details provided specify the amounts involved and the specific address tied to these incidents, making it a concrete security report.

πŸ”—Tweet URL: https://twitter.com/PeckShieldAlert/status/1976834660010541176
❀1
🚨 Hack Alert!
Target: ASTER

What happened: A victim lost $72,572 worth of $ASTER due to a malicious "permit" signature. This incident highlights the risks associated with signing unknown or suspicious transaction requests, leading to a significant financial loss for the user.

πŸ”—Tweet URL: https://twitter.com/realScamSniffer/status/1977018875729653927
🚨 Hack Alert!

Target: WBTC, tBTC

What happened: A victim experienced a loss of $209,816, which was comprised of $WBTC and $tBTC. This incident occurred after the victim signed malicious signatures related to "permit" and "increaseApproval".

The details reveal a specific exploit involving the deceptive use of contract permissions to siphon funds from the victim.

The tweet provides a direct link to the incident for further information.

Tweet URL: https://twitter.com/realScamSniffer/status/1977940011170615369
🚨 Hack Alert!

Target: LuBian

What happened: A LuBian-labeled address has been active after 3 years of dormancy, transferring 9,757 BTC, which is valued at approximately $1.1 billion, to two new wallets. This transfer occurs against the backdrop of the U.S. government preparing to forfeit 127,271 BTC, valued at around $14.3 billion, which was stolen from LuBian in December 2020.

The involvement of the dormant address and the significant transfer could indicate movements related to previously stolen funds.

Further implications may arise for the LuBian incident as these actions unfold.

Tweet URL: https://twitter.com/PeckShieldAlert/status/1978379955571732572
🚨 Hack Alert!
Target: Bittensor

What happened: An investigation concerning the $28 million Bittensor hack from 2024 has been detailed. The investigation identified one of the suspects involved by tracing anime NFT wash trades linked to a former employee.

The efforts also led to the investigator earning a whitehat bounty for their contributions to the case.

πŸ”—Tweet URL: https://twitter.com/zachxbt/status/1978465677578301723
🚨 Hack Alert!

Target: Ellipal

What happened: A video has gone viral detailing a significant theft involving a US-based victim who lost $3.05 million, equivalent to 1.2 million XRP from their Ellipal wallet.

The incident includes tracing of the stolen funds, providing insights into the theft and consequences for future similar incidents.

Key takeaways are shared for preventing similar thefts in the future.

Tweet URL: https://twitter.com/zachxbt/status/1979899767212699910
🚨 Hack Alert!

Target: SwissBorg

What happened: In the SwissBorg exploit, $41 million was stolen in a matter of minutes.

The incident involved a malicious payload concealed within a standard transaction, which allowed the attacker to gain full control of the funds. Blind signing is highlighted as a significant vulnerability that needs to be addressed, particularly when large sums of money are involved.

Hypernative Guardian aims to mitigate such incidents by simulating and inspecting every transaction prior to execution, which makes any hidden changes visible and enables automated enforcement flows.

Tweet URL: https://twitter.com/HypernativeLabs/status/1980257782994510127
🚨 Hack Alert!
Target: SparkDex

What happened: On August 7, a would-be hacker attempted to drain $1.5 million from SparkDex. However, the hacker lost $85,000 of their own funds instead.

The incident was detected by Hypernative, which identified the malicious contracts immediately after deployment. As a response, SparkDEX paused the perpetuals market.

The attacker's $85,000 deposit was subsequently trapped, which prevented what could have been $1.5 million in losses.

This situation may represent the first documented case in decentralized finance (DeFi) where an attacker incurred a loss while trying to exploit a project. It underscores the importance of real-time detection and rapid response in maintaining security within the Web3 space.

πŸ”—Tweet URL: https://twitter.com/HypernativeLabs/status/1980621582281142373
🚨 Hack Alert!

Target: Radiant Capital

What happened: Radiant Capital faced a significant security breach on 16 October 2024, resulting in the draining of their lending pool on BSC and ARB, leading to a loss of approximately $53 million.

The attacker exploited the multi-sig wallet by compromising three out of eleven signers, which enabled them to replace the implementation contracts for the Radiant Lending Pool.

Subsequently, 2834.6 ETH (around $10.8 million) was deposited into Tornado Cash, with part of this amount (2213.8 ETH) being bridged from Arbitrum. The extra ETH was acquired through swapping to DAI and back.

This incident underscores the need for enhanced security measures in handling multi-sig wallets and managing user access.

Tweet URL: https://twitter.com/CertiKAlert/status/1981215744361996338
🚨 Hack Alert!

Target: WBTC

What happened: The tweet discusses address poisoning, a method where users are deceived by look-alike malicious addresses. It references a real-world incident where a WBTC whale lost $71 million to such a scam. This specific example indicates a significant hack resulting in financial loss.

The tweet encourages viewers to watch a webinar where further information about this incident and its implications on wallet security is provided.

"Address poisoning -- the spamming of your transaction history with look-alike malicious addresses -- sounds too simple to work. And yet it routinely tricks a broad spectrum of crypto users.

In The Security Blindspot for Wallets, Hypernative's CTO Dan Caspi looks at a real-world example of a WBTC whale losing $71M to a scammer."

Tweet URL: https://twitter.com/HypernativeLabs/status/1982734297988546597
🚨 Hack Alert!

Target: 402bridge

What happened: @402bridge has been exploited,
~17K $USDC was stolen.

Users are advised to revoke their allowance to the address 0xed1AFc4DCfb39b9ab9d67f3f7f7d02803cEA9FC5 to mitigate any further risks.

For more details, here’s a link to the alert: https://t.co/G07UxR0vYC

Tweet URL: https://twitter.com/PeckShieldAlert/status/1983029273528283503
🚨 Hack Alert!

Target: Base

What happened: A recent exploit occurred on an unverified contract on the Base network, resulting in the loss of 55 WETH, approximately valued at $220K.
This incident involved a victim who had previously approved the contract.
The vulnerability lies within the contract's public uniswapV3SwapCallback() method, which lacks adequate access control, allowing for arbitrary transfer calls.
The affected address is 0xE143b486ab0413Df0D6DAd2caf6d2f61CAC54730.

Users are advised to revoke any approvals to this address.
Stay vigilant!

Tweet URL: https://twitter.com/CertiKAlert/status/1983742817022439822
🚨 Hack Alert!
Target: SparkDEX

What happened: In March 2024, Flare Networks partnered with Hypernative to implement real-time monitoring across its network, which included protection for key projects like SparkDEX.

On August 7, attackers attempted to exploit SparkDEX, but they faced a coordinated security response from Flare, SparkDEX, and Hypernative.

As a result of this ecosystem-wide security strategy, a $1.5 million exploit attempt was stopped, and the attackers lost $85,000.

This incident demonstrates the value of proactive ecosystem-level defenses, pointing towards a future in Web3 security that emphasizes smarter systems over merely higher walls.

πŸ”—Tweet URL: https://twitter.com/HypernativeLabs/status/1983821366278164775
🚨 Hack Alert!

Target: Balancer

What happened: 🚨 Hack Alert 🚨

@Balancer has been drained of ~$70.8M across multiple chains.

Stolen assets include:
6,851.12 $osETH (~$27M)
6,587.44 $WETH (~$24.5M)
4,259.84 $wstETH (~$19.3M)

Stay safu!

Tweet URL: https://twitter.com/getfailsafe/status/1985262450514735410
🚨 Hack Alert!

Target:

What happened: An ongoing attack has been reported with an estimated loss of approximately $88 million. Multiple chains are involved in this incident, indicating a significant security breach affecting a wide range of assets. Further details about the specific project or method of attack were not mentioned, but the scale of the loss highlights the severity of the situation.

This incident has raised concerns in the Web3 community as it unfolds, with updates expected as the situation develops.

Tweet URL: https://twitter.com/PeckShieldAlert/status/1985263682310611037
🚨 Hack Alert!

Target: Balancer

What happened: Update on the attack involving Balancer and its forks.

The incident has resulted in total losses across multiple chains amounting to approximately $128.64 million.

Details regarding the specific nature of the attack and its implications for the affected projects are still unfolding.

For further updates, please refer to the provided link.

Tweet URL: https://twitter.com/PeckShieldAlert/status/1985281156259201044
🚨 Hack Alert!
Target:

What happened: Our system detected an address poisoning attack earlier today, resulting in a loss of 1.256M $USDT.

The scammer sent 0.001 $USDT to the victim just 4 minutes later. The victim unknowingly transferred 1.2M $USDT to the scammer.

The funds sat untouched for 6 hours before the scammer swapped them 30 mins ago to avoid a freeze.

Stay Safe: Always double-check the full wallet address before sending funds.

πŸ”—Tweet URL: https://twitter.com/CyversAlerts/status/1985301923545632828
🚨 Hack Alert!
Target: Stream

What happened: Stream is investigating the loss of approximately $93 million in Stream fund assets.

This loss has been disclosed by an external fund manager, indicating a significant incident that may involve theft or misappropriation of funds.

The investigation by Stream is ongoing to determine the details and circumstances surrounding the loss.

πŸ”—Tweet URL: https://twitter.com/CertiKAlert/status/1985563962432503974
🚨 Hack Alert!
Target: MoonwellDeFi

What happened: 🚨 Multiple exploit transactions have been detected on the @MoonwellDeFi lending contract.

The exploiter managed to repeatedly borrow over 20 wstETH with only about ~0.02 wrstETH flashloaned and deposited. This was made possible due to a faulty oracle that incorrectly returned the wrst price of approximately $5.8M.

The financial impact of this exploit resulted in a profit of 295 ETH, which is valued at around $1M.

Stay vigilant!

πŸ”—Tweet URL: https://twitter.com/CertiKAlert/status/1985620452992253973
🚨 Hack Alert!

Target: aBasUSDC

What happened: A victim lost $304,595 worth of $aBasUSDC after signing a malicious "permit" signature.

This incident highlights a specific security breach where funds were successfully stolen through a phishing-style attack.

The total amount lost in this hack is approximately $304,595, underscoring the risks associated with signing malicious transactions.

Tweet URL: https://twitter.com/realScamSniffer/status/1986100818639229193
🚨 Hack Alert!

Target: DIMO Network

What happened: Our alert system has detected suspicious activity relating to DIMO Network.

A Dimo admin wallet was used to upgrade proxy 0x07C64bd1B23b7C9B0ABf80b8613f58e5B00ED5dD and withdraw 30M $DIMO tokens.

These tokens were then sold for approximately $40k.

Tweet URL: https://twitter.com/CertiKAlert/status/1986740107190112715