ar
Feedback
Defendor — DeFi Security

Defendor — DeFi Security

الذهاب إلى القناة على Telegram
2 454
المشتركون
+324 ساعات
+177 أيام
+8530 أيام
أرشيف المشاركات
🔴 Cosmos Labs Releases Post-Mortem on Multi-Chain EVM Exploit A misjudged risk assessment led Cosmos Labs to patch a critica
🔴 Cosmos Labs Releases Post-Mortem on Multi-Chain EVM Exploit A misjudged risk assessment led Cosmos Labs to patch a critical balance-underflow bug silently rather than privately, and a public PR describing the exploit path preceded attacks on six chains that lost roughly $5.7M combined. MANTRA, TAC, and KiiChain were hit first; Cosmos Labs coordinated with 40 chains to halt and patch, and has committed to reworking its disclosure process. 🔗 Details

🚨 Solana Neobank Avici Reportedly Hacked, $600K+ Drained More than $600,000 has reportedly been drained from user accounts o
🚨 Solana Neobank Avici Reportedly Hacked, $600K+ Drained More than $600,000 has reportedly been drained from user accounts on the Solana-based neobank. Details on the root cause have not yet been disclosed. 🔗 Details

🚔 Two TeamPCP Members Arrested in Perth, Australia Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested over
🚔 Two TeamPCP Members Arrested in Perth, Australia Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested over the group's npm supply chain attacks. The group is linked to the Shai-Hulud worm and other npm ecosystem compromises. 🔗 Details

🐄 CashCowCoin Loses ~$117.4K in Reserve-Draining Exploit A flawed sell function let the router burn CCC tokens post-swap whi
🐄 CashCowCoin Loses ~$117.4K in Reserve-Draining Exploit A flawed sell function let the router burn CCC tokens post-swap while keeping the reduced WBNB reserve, draining the pool across 80 repeated sell cycles. Stolen funds were routed through a profit splitter contract to a separate owner wallet. 🔗 Details

🔐 Researchers Reproduce Transaction Replacement Attack on Ledger OneKey Anzen exploited a race condition in Ledger Ethereum
🔐 Researchers Reproduce Transaction Replacement Attack on Ledger OneKey Anzen exploited a race condition in Ledger Ethereum app 1.22.1, letting an attacker swap the transaction being signed while the user still sees the original one. Ledger fixed the issue in version 1.22.3, and users on older versions are urged to update. 🔗 Details

🔑 Realio Network Loses $6.2M After Signing Key Takeover Attackers seized realio[.]fund's single hot signing key and swept tr
🔑 Realio Network Loses $6.2M After Signing Key Takeover Attackers seized realio[.]fund's single hot signing key and swept treasury and custodial wallets across five chains, draining 127.9M RIO ($6.2M). No contract bug or user approval was involved; the attacker has cashed out roughly $317K so far. 🔗 Details

🚨 Moonwell on Base Loses ~$5.7M in Oracle Manipulation Exploit The attacker manipulated the MAMO collateral oracle, pushing
🚨 Moonwell on Base Loses ~$5.7M in Oracle Manipulation Exploit The attacker manipulated the MAMO collateral oracle, pushing its price up roughly 8x, then borrowed real cbBTC against the inflated mMAMO collateral. About 71.36 cbBTC (~$5.7M) was drained across multiple transactions, with the largest single borrow around $1.15M. 🔗 Details

⚡ Core Lightning Urges Node Operators to Upgrade or Go Offline Maintainers are handling multiple AI-generated vulnerability r
Core Lightning Urges Node Operators to Upgrade or Go Offline Maintainers are handling multiple AI-generated vulnerability reports and warn operators to install an upcoming patch or go offline. Fix details stay under a two-week embargo, with no public CVE or advisory yet. 🔗 Details

🔓 Provenance Blockchain Bug Let Anyone Self-Grant Admin Control A stale supply field let any user pass a "controls 100% of s
🔓 Provenance Blockchain Bug Let Anyone Self-Grant Admin Control A stale supply field let any user pass a "controls 100% of supply" check with zero tokens, granting admin, mint, and withdraw rights on 82 live markers. Two transactions were enough to exploit it; the bug was reported in April and fully fixed by June, with no funds lost. 🔗 Details

📚 Curated Web3 Security Hub Worth a Bookmark This resource collects role-based roadmaps for EVM, Solana, Move, Cairo and ZK
📚 Curated Web3 Security Hub Worth a Bookmark This resource collects role-based roadmaps for EVM, Solana, Move, Cairo and ZK auditors, plus tools for fuzzing, invariant testing, formal verification and AI-assisted workflows. It also includes public audit reports, incident response guides and launch checklists for both builders and auditors. 🔗 Details

🚨 Cosmos Labs Urges Chains to Patch Cosmos EVM Now Chains running Cosmos EVM versions below v0.6.2 or v0.7.2 should immediat
🚨 Cosmos Labs Urges Chains to Patch Cosmos EVM Now Chains running Cosmos EVM versions below v0.6.2 or v0.7.2 should immediately halt and upgrade to the patched releases. Teams that haven't shared security contact details with Cosmos Labs are asked to reach out for critical updates. 🔗 Details

🚨 Enjin Loses ~$162K in Storage Slot Collision Exploit The exploit abused a slot collision between an adapter's initialize f
🚨 Enjin Loses ~$162K in Storage Slot Collision Exploit The exploit abused a slot collision between an adapter's initialize function and the proxy's pendingManager storage, letting the attacker hijack manager rights via DELEGATECALL. After gaining control, the attacker registered a malicious adapter and drained victim assets through a liquidation path. 🔗 Details

🔍 Adevar Labs Named Among Top Move Audit Firms for 2026 The ranking covers the leading Aptos and Sui audit specialists, incl
🔍 Adevar Labs Named Among Top Move Audit Firms for 2026 The ranking covers the leading Aptos and Sui audit specialists, including OtterSec, MoveBit, Certora, and Adevar Labs, based on portfolio depth and formal verification capability. Choice depends on chain, budget, and whether your protocol needs Move Prover formal verification for critical invariants. 🔗 Details

🕵️ Open Krit Privately Flagged Same Cosmos-EVM Bug 3 Weeks Before KiiChain Hack Open Krit reported the same unsafe StateDB b
🕵️ Open Krit Privately Flagged Same Cosmos-EVM Bug 3 Weeks Before KiiChain Hack Open Krit reported the same unsafe StateDB balance-subtraction primitive to another Cosmos-based project weeks earlier, which fixed it fast — but didn't check other chains, partly since only bounty-program targets get proactively researched. The underflow alone isn't exploitable without a separate reachability bug, which is why it wasn't flagged as industry-wide; they say it shows why upstream/downstream security coordination matters. 🔗 Details

🔴 KiiChain Drained ~$148M in Cosmos-EVM Exploit, Chain Halted Attacker exploited three bugs in the shared Cosmos EVM module
🔴 KiiChain Drained ~$148M in Cosmos-EVM Exploit, Chain Halted Attacker exploited three bugs in the shared Cosmos EVM module to drain 148M KII, bridging 67.6M KII to BSC via Hyperlane and selling most of it; the chain halted at block 9355723, freezing 80.7M KII (54.4%) on-chain. Root cause fixes are being tested before restart; two of three upstream bugs remain unpatched, leaving other Cosmos EVM chains with vesting accounts exposed. 🔗 Details

🚨 Specter Investigation: Ongoing EVM Wallet Draining An attacker has drained $415K+ from 30+ victim addresses across EVM cha
🚨 Specter Investigation: Ongoing EVM Wallet Draining An attacker has drained $415K+ from 30+ victim addresses across EVM chains and is still actively sweeping funds. A separate attacker drained roughly $870K from 100+ addresses on August 10, with one victim losing $800K; root cause remains unidentified. 🔗 Details

🌉 Warp Green Bridge Was Exploited — Root Cause Confirmed The ERC20 bridge was exploited via a flaw on the Chia-side; damage
🌉 Warp Green Bridge Was Exploited — Root Cause Confirmed The ERC20 bridge was exploited via a flaw on the Chia-side; damage is confirmed limited to $93,000 USDC, now converted to ETH by the attacker. The protocol remains paused while the team works with validators on a full postmortem; the CAT bridge (wXCH) appears unaffected. 🔗 Details

🚨 Cosmos EVM Module Hit by Ongoing Security Incident Cosmos Labs security teams are responding and have advised affected Cos
🚨 Cosmos EVM Module Hit by Ongoing Security Incident Cosmos Labs security teams are responding and have advised affected Cosmos EVM chains to halt validators. A full incident report will follow once the situation is resolved. 🔗 Details

⚠️ BitcoinIRA & iTrustCapital Allegedly Breached, Undisclosed Per Zach: both US crypto investment platforms suffered data bre
⚠️ BitcoinIRA & iTrustCapital Allegedly Breached, Undisclosed Per Zach: both US crypto investment platforms suffered data breaches this year, leaking personal, banking, and portfolio data — undisclosed publicly. One victim lost $1.2M+ in June 2026 after a threat actor exploited the leaked database. 🔗 Details

🔒 Ledger Ethereum App Vulnerability — Already Fixed A flaw in certain clear-signing flows of the Ledger Ethereum app was fou
🔒 Ledger Ethereum App Vulnerability — Already Fixed A flaw in certain clear-signing flows of the Ledger Ethereum app was found by Ledger Donjon and patched two weeks ago, per CTO Charles Guillemet. Users on updated firmware and apps are protected; Guillemet noted a security firm disclosed the issue only after the fix shipped. 🔗 Details