QuillMonitor : Web3 Hacks and Alerts
225 subscribers
1 photo
181 links
Download Telegram
🚨 Hack Alert!

Target: Drift Protocol

What happened: Drift Protocol suffered an exploit resulting in approximately $280 million stolen, highlighting significant issues in trust and visibility within the project’s security framework.

In this incident, there was no smart contract failure; instead, attackers focused on the human layer, employing social engineering to compromise multisig signer accounts. The attackers meticulously executed their plan over several days, initiating setup for durable nonce accounts by March 23 and exploiting weaknesses during the multisig migration by March 27, which culminated in the execution of the exploit on April 1.

As a direct result of this coordinated effort, 20+ Solana protocols were affected, causing additional millions in secondary losses and ongoing cross-chain laundering. The incident bears similarity to the Bybit hack, as in both attackers manipulated multisig approvals resulting in unintentional authorization of malicious transactions.

The significance of this event transcends just a security breach; it questions governance structures within the protocol. With a 2-out-of-5 multisig setup lacking a timelock, this reflects a critical point of failure rather than decentralization. The attack highlights a worrying trend where human compromise is becoming the primary attack vector in Web3 environments.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Drift Protocol

What happened: $285M was drained in under 12 minutes from the Drift Protocol exploit.

The exploit did not involve a contract bug or code vulnerability, but rather privileged access without limits, allowing unrestricted actions.

A detailed breakdown of the incident explains how the exploit was staged over several weeks and how legitimate approvals were weaponized.

The content also discusses the need for a stronger architecture to prevent such attacks in the future, emphasizing the purpose of Guardian.


Tweet URL: View Tweet
🚨 Hack Alert!

Target: DriftProtocol

What happened: The @DriftProtocol exploiter has been identified as having stolen $285 million worth of cryptocurrency. Recently, they moved 185 $SOL, equivalent to $15,000, to #ChangeNow. This transaction is linked directly to the exploit involving the Drift Protocol, confirming a significant financial impact on the project.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: SquidMulticall

What happened: A series of suspicious transactions were detected targeting a specific victim address (0xaCc0c1f672B03B9a5fED4535f840f09B85f40E98) across multiple chains including Arbitrum, BSC, Avalanche, Optimism, and Base.

The estimated total losses amount to approximately $517K.

The victim had pre-existing MAXUINT approvals to a SquidMulticall-related contract at the same address (0xaD6Cea45f98444a922a2b4fE96b8C90F0862D2F4), which allowed the attacker to exploit these approvals. The attacker leveraged the permissionless run() entrypoint to execute crafted multicalls with transferFrom payloads, enabling the transfer of tokens directly from the victim's address.

πŸ”—*Tweet URL:* [View Tweet](
https://twitter.com/Phalconxyz/status/2041463211493662942)
🚨 Hack Alert!

Target: HLP

What happened: A PeckShield alert indicates that HLP has suffered approximately $1.5 million in losses over the past 24 hours. The attacker managed to accumulate a long position of $15 million in $Fartcoin, equating to 145.24 million tokens, distributed across four wallets.

In a low-liquidity market, the attacker executed a "suicide" liquidation, which triggered the Accidental Liquidation (ADL) mechanism to activate. This forced HLP to absorb the resulting toxic asset, resulting in a significant amount of bad debt incurred.

On paper, the loss amounts to $3 million. However, it is suggested that the attacker may have secured a much larger net profit by cross-venue hedging.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Polkadot Hyperbridge

What happened: The tweet discusses the specific exploit of the Polkadot Hyperbridge that resulted in significant financial loss.

A forged proof was accepted due to a failure in the verification function, which didn't check the proof bound to its payload. Subsequently, an admin role change was executed instantaneously without any time delay or secondary authorization.

Additionally, a whopping 1 billion DOT tokens were minted against a circulating supply of only 356,000, and there was no supply cap to prevent this. The exploit culminated in the full pool being drained in a single transaction, devoid of any rate limits.

The tweet emphasizes that implementing hard constraints at any one of these stages could have potentially thwarted the exploit, detailing the operational gaps in the security policy and automated responses.

Overall, this tweet reports on a specific security incident, detailing how the exploit occurred and its implications.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: KelpDAO

What happened: A significant incident has affected KelpDAO, involving the transfer of at least ~$290M.

Funds can be traced to two specific addresses: approximately ~$250M has been traced to address 0x5d3919F12bCc35c26Eee5F8226A9bee90c257Ccc, and around ~$2.5M to address 0xCBb24A6B4DAfaAA1a759A2F413eA0eB6AE1455CC.

This indicates a successful exploit impacting the project, with substantial financial loss.

Tweet URL: View Tweet
❀1
🚨 Hack Alert!

Target: Aave

What happened: A phishing attack resulted in a loss of 3 WBTC, valued at $221K, after a user signed an increaseApproval signature on the Ethereum network.

The stolen WBTC had recently been withdrawn from Aave. This incident is part of a larger scheme where $585K has been drained from four victims within the past 11 hours using the same drainer method.

The victim's address is 0x5d908c88bE270889C0953E7dfF1C8E1D699cEeA3.

Forensic details include an approval transaction linked here: https://t.co/BP0UbotFzh and the drain transaction can be found at: https://t.co/MAscc7rQLz.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: KelpDAO

What happened: The Arbitrum Security Council has taken emergency action to freeze 30,766 ETH, valued at approximately $70 million. This frozen ETH is associated with the recent KelpDAO exploit, indicating a significant security incident involving funds related to this specific project on the Arbitrum One network. The situation reflects a proactive response to a confirmed hack, emphasizing the impact on stakeholders involved.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: Cork Protocol

What happened: The Cork Protocol fell victim to an exploit involving both a multi-transaction setup and a single atomic transaction, resulting in a loss of $12 million.

Unusual on-chain activity preceded this single transaction, which successfully drained the funds.

While traditional monitoring methods might have detected the unusual activity, they would not have been able to prevent the exploit from executing.

This incident was presented by JosΓ© Cardoso, the Head of BD at Hypernative, during the Rekt Security Summit in Cannes.

πŸ”—Tweet URL: View Tweet
❀1
🚨 Hack Alert!
Target: KelpDAO

What happened: A recent security incident involves the @KelpDAO exploiter who has transferred all funds from Ethereum to Bitcoin, with a total amount of $1,979 BTC moved.

Additionally, the @Balancer exploiter has resumed activity after five months, now laundering $700K worth of ETH into BTC via @THORChain.

The incident highlights notable exploits within these DeFi protocols, marking significant fund movements between chains.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Balancer

What happened: 🚨 The Balancer exploiter, who previously stole approximately $120 million, has been reported active again after five months.

In the past couple of hours, the exploiter transferred 1,100 ETH, valued at $2.55 million, and is in the process of laundering these funds by converting ETH to BTC through THORChain.

The details of the transactions include ETH currently sitting at the following addresses:
1. bc1qlyzhp6en4tk2mkt6sl83lzhxm55ycq2yjcm6u7
2. bc1qx4lwa6ewj5z0t6k4q86yd0gy62ej058hye7y93.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target:

What happened: A suspicious transaction was detected targeting an unverified contract on Ethereum.

An estimated loss of ~$983K occurred due to a missing access-control check in the contract’s execute() function, which allowed arbitrary call execution.

The attacker exploited a pre-existing unlimited yvWETH approval from the victim address, draining 384.67 yvWETH, which was unwound for about 429.2 ETH.

The attack transaction can be viewed here: https://t.co/CjS9S0biHi.

Tweet URL: View Tweet
🚨 Hack Alert!

Target: KyberSwap

What happened: KyberSwap was subjected to a reentrancy attack on November 23, 2023.

The attack led to a significant financial impact, resulting in a loss of approximately ~$47M.

Following the incident, an exploiter has laundered 2,900 $ETH, equivalent to $6.8M, through Tornado Cash as part of the illicit activities related to this hack.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: syndicateio

What happened: An exploit has occurred involving the project Syndicate through a compromise of the Commons bridge.

Approximately 18.5 million SYND tokens were acquired by the attacker, leading to a financial impact of around $330,000. The stolen funds were subsequently bridged to Ethereum.

This incident highlights the need for increased vigilance in the Web3 space.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: AftermathFi

What happened: An exploit has been detected involving AftermathFi, resulting in approximately $900,000 worth of USDC being drained from the platform. The situation is currently under investigation.

Users are advised to remain vigilant as details are still emerging regarding this incident.

Further updates will follow as more information becomes available.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wasabi Protocol

What happened: 🚨 Alert: A significant security incident has been detected involving the Wasabi Protocol.

An address funded via Tornado Cash has deployed a malicious contract on both the Base and Ethereum networks.

This incident has led to the theft of approximately $4.5M across multiple assets, which include $WETH, $PEPE, $MOG, $USDC, $BITCOIN, $VIRTUAL, $ZYN, $REKT, $cbBTC, and $AERO.

The stolen funds were consolidated into $ETH and then bridged to the Ethereum network, followed by distribution across multiple addresses.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!

Target: KelpDAO

What happened: In April 2026, the crypto space experienced 40 major hacks totaling $647M, marking a significant 1,140% increase from March's $52.2M.

Among these, the KelpDAO and DriftProtocol exploits rank in the Top 10 hacks since 2021.

The KelpDAO exploiter used rsETH supplied to Aave to borrow a substantial amount of ETH, subsequently laundering the stolen funds into Bitcoin. This incident has posed a serious risk of bad debt exposure within the Aave ecosystem.

In response to these exploitations, DeFi United is taking coordinated measures to absorb the resulting liquidity shortfall and prevent further systemic contagion.


Top 5 noted hacks include:
- KelpDAO: $292M (Ranked #7, Jan 2021 – Apr 2026)
- Drift: $285M (Ranked #9, Jan 2021 – Apr 2026)
- Rhea Finance: $20M
- Grinex: $13.74M
- Wasabi Protocol

Tweet URL: View Tweet
🚨 Hack Alert!

Target: Wasabi Perp

What happened: Wasabi Perp drained over $5 million across Ethereum, Base, and Blast this morning.

No smart contract bug or oracle manipulation was involved. The incident resulted from a single private key that held admin authority across all three chains. When this key was compromised, the protocol was drained through its own privileged functions in a span of two hours.

The attack could have been prevented with various measures:

- Drainer deployment: Hypernative's detection engine flagged the attacker's orchestrator contract three minutes before the first drain, suggesting that a pre-configured response could have paused vaults before any transactions settled.

- Privilege escalation: Monitoring RoleGranted events against a pre-approved destination list could have flagged unscheduled grants from a known admin wallet, signaling key compromise.

- Vault drain: Implementing a strategy whitelist on strategyDeposit could have prevented collateral from being routed to an unrecognized address, ensuring that the attacker's contract never received funds.

- Pool implementation swap: Governance policies that block any upgradeToAndCall to pre-unauthorized implementations would have stopped the pool from flipping to attacker bytecode in the same block as the proposal.

The contracts functioned as intended. All signatures were valid, indicating that the underlying trust model was the gap that led to the incident.

Tweet URL: View Tweet
🚨 Hack Alert!
Target: Wasabi Perp

What happened: Wasabi Perp suffered a significant loss of over $5M last week across three different chains.

The first drain transaction occurred at 07:49 UTC, while Hypernative's detection engine had flagged the attacker's orchestrator contract as a suspected drainer just three minutes prior.

Additionally, there was a monitor identifying drainer-class bytecode being deployed from wallets linked to protocol admin infrastructure, which surfaced this signal before any privileged call took place. This was crucial information that, if paired with an automated response, could have led to pausing vaults before the initial transaction finalized.

Despite the warning signal being available, the required response to mitigate the loss was not configured in time.

πŸ”—Tweet URL: View Tweet
🚨 Hack Alert!
Target: EkuboProtocol

What happened: A suspicious transaction has been detected involving @EkuboProtocol.

An address funded via Railgun executed a single transaction, generating approximately $1.4 million on the Ethereum network.

The attacker received 17 WBTC, swapped them for ETH, and subsequently deposited the funds into @TornadoCash.

Individuals who approved specific v2 contracts should revoke access immediately to prevent potential losses.

For those wishing to safeguard against such scams, they are invited to contact the account to arrange a demo of their security solution.

πŸ”—Tweet URL: View Tweet