QuillMonitor : Web3 Hacks and Alerts
226 subscribers
1 photo
182 links
Download Telegram
🚨 Hack Alert!

Target: sillytuna

What happened: An attacker has successfully drained approximately $24 million worth of $aEthUSDC from the project @sillytuna.

After the heist, the attacker swapped around $2 million worth of $DAI and $ETH for 6,174.4 $XMR, which is currently held on #Hyperliquid.

In addition to this, they have deposited nearly $6.5 million in $USDC and $USDT into centralized exchanges, including OKX, MEXC, and Bitkan.

Furthermore, the attacker laundered 375 $ETH through #TornadoCash.

Tweet URL: View Tweet
🚨 Hack Alert!

Target:

What happened: A suspicious transaction targeting an unknown contract (the AM/USDT pool) on BSC has resulted in an estimated loss of ~$131K.

The incident was due to a flawed burn mechanism that was exploited to manipulate the pool’s AM reserves. The attacker first adjusted toBurnAmount and then executed the burn logic after manipulating the pool’s AM balance. This tactic reduced the AM reserve to an abnormally low level, allowing the attacker to sell AM back into the pool at an artificially inflated price, thus realizing their profit.

The attack transaction can be viewed at: https://t.co/9I9xeLwHlg.

Identified by Phalcon Security and analyzed via Phalcon Explorer.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: DBXencrypto

*What happened:* ALERT! There has been a significant security incident involving
@DBXencrypto's contract, resulting in an estimated loss of ~$150K.

The root cause of the incident is traced back to an inconsistency in the sender's identity under ERC2771 meta-transactions, which enabled the attacker to exploit the reward accounting logic, leading to the drainage of assets from the contract.

Specifically, within the burnBatch() function, the gasWrapper() modifier updates the state using msgSender() (the actual user), whereas the callback onTokenBurned() uses msg.sender (the forwarder). This inconsistency leads to a situation where accCycleBatchesBurned is correctly noted for the user, but lastActiveCycle is incorrectly updated for the forwarder.

As a result, when updateStats() is executed for the user, the contract wrongly concludes that there are unprocessed burned batches due to the updated statement, causing miscalculations of rewards and fees, ultimately allowing the attacker to withdraw excess funds for profit.

The attack transactions are available at:
1.
https://t.co/IZcREEKdS2
2.
https://t.co/kJNCZAhpm1

*Tweet URL:* [View Tweet](
https://twitter.com/Phalconxyz/status/2031955394025996688)
🚨 Hack Alert!

Target:

What happened: A phishing incident resulted in a loss of $720,108 in valBUSD and valTUSD after victims signed malicious increaseAllowance signatures. These signatures enabled the attackers to drain funds from the affected wallets.

The report highlights the dangers of phishing attacks and the importance of verifying signatures before confirming any transaction, especially those that request allowances.

This incident serves as a critical reminder for users to stay vigilant against phishing attempts in the Web3 space.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: VenusProtocol

What happened: 🚨 @VenusProtocol on BSC was exploited for ~$3.7M on March 15.

Root cause: supply cap bypass via direct ERC-20 transfers to a vToken contract, a known Compound V2 design flaw previously flagged in Venus’s own Code4rena audit.

Example tx: https://t.co/qSMEA4RjPc
~50 exploit transactions in total.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Ethereum

What happened: A user lost approximately $1.77 million in USDC after falling victim to a phishing scheme involving a gasless approval signature on the Ethereum network. This incident demonstrates the risks associated with signing permissions without proper scrutiny. The phishing attack successfully compromised the user's funds. For more information, refer to the tweet link.

🔗Tweet URL: View Tweethttps://twitter.com/realScamSniffer/status/2033695871448326478
🚨 Hack Alert!

Target: Venus

What happened: The market on Venus for the token $THE has experienced a significant exploit, resulting in approximately $2.15 million in bad debt.

The attacker initially withdrew 7,400 $ETH from Tornado Cash, subsequently borrowing $9.9 million to purchase $THE. They manipulated the market by donating 36.1 million $THE directly to the vTHE contract, which enabled them to bypass the supply cap and inflate the exchange rate by 3.81x.

Post-attack, a notable investor, @justinsuntron, who is among the top 5 holders of $XVS, deposited 621,000 $XVS totaling about $1.95 million to HTX Global. Additionally, the attacker, identified as #BNBBridgeExploiter and a top 16 holder of $XVS, retains 135,000 $XVS valued at roughly $421,000.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Movie Token

What happened: On March 10, Movie Token (MT) was exploited.

The incident resulted in a significant financial loss totaling approximately $242,000.

For a detailed analysis of the exploit and its ramifications, a link is provided for further reading.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: ResolvLabs

What happened: A significant exploit has been reported involving a stablecoin, resulting in an $80 million loss due to a flaw in the completeSwap() function at @ResolvLabs.

An attacker took advantage of this vulnerability to mint approximately $80 million of unbacked $USR, without draining any collateral. This led to a catastrophic depeg, causing the value of $USR to plummet to around $0.257, a ~74% drop.

The on-chain activity indicates that the attacker’s address is 0x04A288a7789DD6Ade935361a4fB1Ec5db513caEd, and roughly $23.8 million has been swapped into ETH and is currently held at address 0x8ED8cF0C1c531C1b20848E78f1CB32fa5B99b81C.

In response, Resolv has paused all protocol functions to address the issue and work on recovery.

This incident showcases the critical nature of proper backing and validation mechanisms for stablecoins, as failure to maintain backing can lead to drastic consequences for the entire ecosystem.

Tweet URL: View Tweet
2👍2
🚨 Hack Alert!
Target: PancakeSwap

What happened: An alert has been issued regarding a suspicious transaction that targeted a PancakeSwap pool (BCE–USDT) on the Binance Smart Chain (BSC) a few hours ago.

The incident led to a total loss of approximately $679,000. Preliminary analysis indicates that the root cause of the hack was a flawed burn mechanism in the BCE token.

To execute the attack, the hacker deployed two malicious contracts which were designed to bypass buy/sell restrictions, subsequently triggering token burns within the pool.

This manipulation significantly skewed the pool reserves, which enabled the attacker to drain the BCE–USDT pool, resulting in a total profit of around $679,000.

Forensic details include the attack transaction link: https://t.co/1JqoWCpaA2.

🔗Tweet URL: View Tweet
🚨 Hack Alert!

Target: Stake

What happened: Incident Summary:
A suspicious transaction targeting an unknown contract named Stake on the Binance Smart Chain (BSC) led to a financial loss of approximately $133K.

Root Cause:
The issue stemmed from a vulnerable spot-price dependency in the Stake contract.

Attack Flow:
1. The attacker manipulated the TUR price in the TUR–NOBEL pool.
2. They staked TUR in the Stake contract, which triggered reward calculations based on the inflated price.
3. Amplified rewards were claimed through referred accounts, draining all TUR from the contract.
4. The attacker swapped the stolen TUR for USDT as profit.

Forensic Details:
- Attacker Addresses:
• 0xC93A5Ab3737081F00788B61DA42281955d3dF692
• Referrer account 1: 0xFd11c78A2fFC9102080F1AcCFb2c9Cd2ce2AcEaB
• Referrer account 2: 0x9007983C0b1db337e3c0FF29771027b8E2bE550B
• Referrer account 3: 0xEf79bbD4EFaC4bE248aF6525971002F80eB251e0
- Attack Transaction: Link to transaction

Tweet URL: View Tweet
🚨 Hack Alert!

Target:

What happened: A total of approximately $18.2 million has been lost by a Kraken user due to a suspected social engineering scam. The scam involved multiple transactions rather than a single event, with on-chain data indicating that the victim began transferring funds to the scammer on February 23.

This information has been reported by @zachxbt and involves significant financial loss, highlighting the ongoing risks of social engineering attacks in the crypto space.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: DolaSavings

What happened: On March 2, an attacker targeted the DolaSavings contract on Ethereum.

The attack method involved a large flashloan, draining a vault and making a brief donation to spoof a healthy price. Initially, it was difficult to identify what was being attacked. When the dust settled, $240K was confirmed stolen from the contract.

Interestingly, one protocol in the blast radius reported no losses.

More details can be found in the tweet.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: DriftProtocol

What happened: The @DriftProtocol experienced a significant security incident, with an initial estimated loss of $285 million reported.

Details are likely available in the linked breakdown for further forensic information.

This incident highlights the severe financial impact and implications for the protocol involved.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Drift Protocol

What happened: Drift Protocol suffered an exploit resulting in approximately $280 million stolen, highlighting significant issues in trust and visibility within the project’s security framework.

In this incident, there was no smart contract failure; instead, attackers focused on the human layer, employing social engineering to compromise multisig signer accounts. The attackers meticulously executed their plan over several days, initiating setup for durable nonce accounts by March 23 and exploiting weaknesses during the multisig migration by March 27, which culminated in the execution of the exploit on April 1.

As a direct result of this coordinated effort, 20+ Solana protocols were affected, causing additional millions in secondary losses and ongoing cross-chain laundering. The incident bears similarity to the Bybit hack, as in both attackers manipulated multisig approvals resulting in unintentional authorization of malicious transactions.

The significance of this event transcends just a security breach; it questions governance structures within the protocol. With a 2-out-of-5 multisig setup lacking a timelock, this reflects a critical point of failure rather than decentralization. The attack highlights a worrying trend where human compromise is becoming the primary attack vector in Web3 environments.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Drift Protocol

What happened: $285M was drained in under 12 minutes from the Drift Protocol exploit.

The exploit did not involve a contract bug or code vulnerability, but rather privileged access without limits, allowing unrestricted actions.

A detailed breakdown of the incident explains how the exploit was staged over several weeks and how legitimate approvals were weaponized.

The content also discusses the need for a stronger architecture to prevent such attacks in the future, emphasizing the purpose of Guardian.


Tweet URL: View Tweet
🚨 Hack Alert!

Target: DriftProtocol

What happened: The @DriftProtocol exploiter has been identified as having stolen $285 million worth of cryptocurrency. Recently, they moved 185 $SOL, equivalent to $15,000, to #ChangeNow. This transaction is linked directly to the exploit involving the Drift Protocol, confirming a significant financial impact on the project.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: SquidMulticall

What happened: A series of suspicious transactions were detected targeting a specific victim address (0xaCc0c1f672B03B9a5fED4535f840f09B85f40E98) across multiple chains including Arbitrum, BSC, Avalanche, Optimism, and Base.

The estimated total losses amount to approximately $517K.

The victim had pre-existing MAXUINT approvals to a SquidMulticall-related contract at the same address (0xaD6Cea45f98444a922a2b4fE96b8C90F0862D2F4), which allowed the attacker to exploit these approvals. The attacker leveraged the permissionless run() entrypoint to execute crafted multicalls with transferFrom payloads, enabling the transfer of tokens directly from the victim's address.

🔗*Tweet URL:* [View Tweet](
https://twitter.com/Phalconxyz/status/2041463211493662942)
🚨 Hack Alert!

Target: HLP

What happened: A PeckShield alert indicates that HLP has suffered approximately $1.5 million in losses over the past 24 hours. The attacker managed to accumulate a long position of $15 million in $Fartcoin, equating to 145.24 million tokens, distributed across four wallets.

In a low-liquidity market, the attacker executed a "suicide" liquidation, which triggered the Accidental Liquidation (ADL) mechanism to activate. This forced HLP to absorb the resulting toxic asset, resulting in a significant amount of bad debt incurred.

On paper, the loss amounts to $3 million. However, it is suggested that the attacker may have secured a much larger net profit by cross-venue hedging.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Polkadot Hyperbridge

What happened: The tweet discusses the specific exploit of the Polkadot Hyperbridge that resulted in significant financial loss.

A forged proof was accepted due to a failure in the verification function, which didn't check the proof bound to its payload. Subsequently, an admin role change was executed instantaneously without any time delay or secondary authorization.

Additionally, a whopping 1 billion DOT tokens were minted against a circulating supply of only 356,000, and there was no supply cap to prevent this. The exploit culminated in the full pool being drained in a single transaction, devoid of any rate limits.

The tweet emphasizes that implementing hard constraints at any one of these stages could have potentially thwarted the exploit, detailing the operational gaps in the security policy and automated responses.

Overall, this tweet reports on a specific security incident, detailing how the exploit occurred and its implications.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: KelpDAO

What happened: A significant incident has affected KelpDAO, involving the transfer of at least ~$290M.

Funds can be traced to two specific addresses: approximately ~$250M has been traced to address 0x5d3919F12bCc35c26Eee5F8226A9bee90c257Ccc, and around ~$2.5M to address 0xCBb24A6B4DAfaAA1a759A2F413eA0eB6AE1455CC.

This indicates a successful exploit impacting the project, with substantial financial loss.

Tweet URL: View Tweet
1