Solidrate Audit Reports
658 subscribers
50 photos
48 links
Security Audit
DM @sophie_solidrate for audit and partnership requests
Download Telegram
⚑️Shibarium paused after an exploit where fake data hit its ETH-linked contracts.
Team says bridge restart + user refunds next.

Lesson: cross-chain inputs must be attested & rate limited, not just parsed.

#BlockchainSecurity

Source: The Block πŸ‘‡
https://theblock.co/post/373368/shiba-inu-shibarium-preps-bridge-restart-plans-user-refunds-after-4-million-exploit
❀7πŸ‘2πŸ”₯2😁1
⚑️A Hyperliquid user just lost $21M after a private key compromise. Funds were bridged out within minutes.

🌫️Lesson: rotate keys, segment risk, and monitor for abnormal approvals.



⚑️Source: CoinDesk / Yahoo Finance / The Block

https://coindesk.com/business/2025/10/10/usd21m-crypto-theft-on-hyperliquid-tied-to-private-key-leak-peckshield

https://sg.finance.yahoo.com/news/21m-crypto-theft-hyperliquid-tied-133841170.html

https://theblock.co/post/374145/21-million-stolen-from-hyperliquid-user-after-apparent-private-key-compromise-peckshield
πŸ‘3❀2πŸ”₯1πŸ‘1
⚑️Analysts say yesterday’s crypto crash likely under-reported liquidations β€” some APIs captured just ~5% of real flow.

⚑️That’s how you get β€œ$19–40B” headlines while $300–400B vanishes.

🌫️Lesson for builders: audit β‰  enough. Add stress tests, circuit-breakers, withdrawal delays, and live anomaly alerts.


⚑️Sources:

https://thestreet.com/crypto/trading/analyst-warns-market-crash-wiped-out-400b

https://telegraph.co.uk/business/2025/10/11/markets-chaos-trump-triggers-record-crypto-crash/

https://forbes.com/sites/digital-assets/2025/10/12/trump-surprise-triggers-huge-crypto-flash-crash-as-traders-brace-for-bitcoin-ethereum-xrp-bnb-and-solana-price-wipeout/
❀3πŸ”₯3πŸ‘2πŸ‘1
⚑️Astra Nova ($RVV) says a third-party market-maker account was compromised rapid dumps sent the token down ~70%.

🌫️Lesson for teams: third-party keys = blast radius. Enforce withdrawal policies, signer separation, and real-time off-exchange monitoring.

Source:
https://www.edgen.tech/news/crypto/astra-novas-third-party-market-maker-account-hacked-rvv-token-plunges-70
πŸ‘3πŸ”₯2πŸ‘1😁1
⚑️Major AWS outage disrupted multiple apps (incl. crypto platforms). No clear evidence of a cyberattack so far, still a wake-up call on single-cloud blast radius.

🌫️Action: multi-region failover, cloud-agnostic runbooks, status-page decoupling.

#AWS

Sources: Economic Times & Coinpedia
https://economictimes.indiatimes.com/news/international/us/amazon-robinhood-snapchat-cloud-crash-cyberattack-today-aws-outage-explained-did-china-just-bring-amazon-down-along-with-robinhood-snapchat-what-happened-heres-what-experts-are-saying/articleshow/124702482.cms

https://coinpedia.org/news/chinas-cyberattack-claim-aws-outage-rock-the-internet-coinbase-among-platforms-hit/
πŸ‘3❀1πŸ”₯1πŸ‘1
⚑️$3M in XRP stolen: the user imported a hardware-wallet seed into a mobile app, turning β€œcold” storage into hot without realizing.

🌫️Do now: separate cold/hot seeds, add a BIP39 passphrase, enforce withdrawal delays & anomaly alerts.

Source: CoinDesk

https://coindesk.com/tech/2025/10/19/xrp-investor-says-usd3m-in-xrp-was-stolen-cold-wallet-maker-says-seed-import-made-wallet-hot
πŸ‘3❀1πŸ”₯1πŸ‘1
⚑️Roughly 15,959 BTC (~$1.8 billion) linked to the 2020 LuBian mining pool hack has just been moved across four wallets in what appears to be a coordinated transaction.

⚑️When dormant hack funds of this scale start moving, it’s a stress test for every exchange risk engine, chain analytics platform, and AML pipeline out there.

🌫️Stay sharp, monitor flows, and verify counterparties.
πŸ”₯4πŸ‘2❀1πŸ‘1
⚑️Garden Finance suffered a multi-chain exploit: the attacker drained up to ~$10M across Arbitrum, Solana and more, and SEED dropped >60% within minutes.

⚑️The team is offering a 10% β€œwhite hat bounty” and asking for the funds back. Bridges remain DeFi’s softest attack surface.
❀3πŸ‘1πŸ”₯1πŸ₯°1
⚑️Balancer exploited across multiple chains. Latest estimates range $110M–$128M drained, mostly WETH / osETH / wstETH from affected pools; some forks also paused. Incident appears centered on v2-style pool mechanics.

🌫️Immediate actions: enable per-pool pause/guardians, raise LST wrapper limits, add withdrawal delays, and monitor cross-chain vault flows in real time.
πŸ‘3πŸ”₯2❀1πŸ‘Ž1πŸ‘1
China vs. U.S. over the LuBian BTC heist. China’s CVERC alleges the U.S. β€œorchestrated” the 2020 hack that drained 127,000 BTC (~$13B) from LuBian; U.S. narratives frame it as a lawful seizure tied to criminal probes.

Takeaway for builders: custody trails matter. Tag & trace treasury UTXOs, document funding provenance, and design incident-response playbooks for law-enforcement holds vs. criminal theft scenarios.
❀2πŸ‘2πŸ”₯2πŸ‘1
πŸ›‘οΈExciting news!

Solidrate has successfully concluded the DEX audit for
@kedolik_swap

βœ… Report: https://github.com/solidrate/audits/blob/main/kedolik-swap-audit-report.pdf
πŸ‘3πŸ”₯1πŸ₯°1πŸ‘1