ch
Feedback
EthSecurity

EthSecurity

前往频道在 Telegram
5 266
订阅者
+124 小时
-67
-5130
吸引订阅者
八月 '26
八月 '26
+49
在4个频道中
七月 '26
+160
在3个频道中
Get PRO
六月 '26
+142
在5个频道中
Get PRO
五月 '26
+73
在2个频道中
Get PRO
四月 '26
+93
在1个频道中
Get PRO
三月 '26
+77
在2个频道中
Get PRO
二月 '26
+88
在3个频道中
Get PRO
一月 '26
+93
在2个频道中
Get PRO
十二月 '25
+326
在4个频道中
Get PRO
十一月 '25
+130
在2个频道中
Get PRO
十月 '25
+106
在2个频道中
Get PRO
九月 '25
+147
在5个频道中
Get PRO
八月 '25
+67
在5个频道中
Get PRO
七月 '25
+91
在4个频道中
Get PRO
六月 '25
+103
在3个频道中
Get PRO
五月 '25
+52
在6个频道中
Get PRO
四月 '25
+99
在5个频道中
Get PRO
三月 '25
+107
在6个频道中
Get PRO
二月 '25
+188
在9个频道中
Get PRO
一月 '25
+73
在3个频道中
Get PRO
十二月 '24
+163
在2个频道中
Get PRO
十一月 '24
+196
在2个频道中
Get PRO
十月 '24
+264
在8个频道中
Get PRO
九月 '24
+225
在0个频道中
Get PRO
八月 '24
+153
在0个频道中
Get PRO
七月 '24
+101
在0个频道中
Get PRO
六月 '24
+63
在0个频道中
Get PRO
五月 '24
+109
在4个频道中
Get PRO
四月 '24
+170
在1个频道中
Get PRO
三月 '24
+215
在1个频道中
Get PRO
二月 '24
+142
在0个频道中
Get PRO
一月 '24
+200
在0个频道中
Get PRO
十二月 '23
+165
在0个频道中
Get PRO
十一月 '23
+523
在1个频道中
Get PRO
十月 '23
+205
在0个频道中
Get PRO
九月 '23
+307
在0个频道中
Get PRO
八月 '23
+245
在0个频道中
Get PRO
七月 '23
+893
在0个频道中
Get PRO
六月 '23
+1 603
在0个频道中
日期
订阅者增长
提及
频道
27 八月0
26 八月+4
25 八月+2
24 八月+3
23 八月+3
22 八月+2
21 八月0
20 八月+3
19 八月+1
18 八月+1
17 八月+3
16 八月+1
15 八月0
14 八月+1
13 八月+2
12 八月+2
11 八月+3
10 八月+1
09 八月+2
08 八月+4
07 八月+1
06 八月+1
05 八月+1
04 八月0
03 八月0
02 八月+4
01 八月+4
频道帖子
- The Ultimate Web3 Security Checklist by Digibastion. A comprehensive checklist including personal, devops, mobile, browser, and other security topics. -link - A deep dive into DPRK IT worker operation after a compromise of one of their machines - link - Meet Gerardo Salgado aka Tammy Hans (the old one) a DPRK IT Worker who infected himself with Contagious Interview malware a thread by Narcass3. - link @EthSecurity1

2
$Enjin hacked for $162K RootCause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol. @EthSecurity1
742
3
https://x.com/0xyashish/status/2092172553695662566?s=61 @EthSecurity1
386
4
- A manipulator used a sandwich attack on Pendle’s YT to depress PT-reUSD price by ~3%, triggering $36M in Morpho liquidations across 19 borrowers and seizing 38.64M PT with zero bad debt. - The attacker/liquidator captured ~$1.09M profit via a non-atomic strategy requiring ~$6.5M capital to deposit seized PT as collateral, borrow stables, and unwind gradually, bypassing atomic MEV competition that only yielded builders ~4.2 ETH. - On-chain links show synchronized funding and withdrawals from the same Gate.io hot wallet to both the YT manipulation address and main liquidation strategy, though evidence remains circumstantial. @EthSecurity1
656
5
Cosmos recommend that if you run a public chain that uses a Cosmos EVM version less than v0.6.2 and v0.7.2, you should immediately halt the blockchain and upgrade it to include the patches in those releases. @EthSecurity1
813
6
- FACADE High-Precision Insider Threat Detection Using Contrastive Learning. -link - Deflationary Token Risks, ERC4626 Override Gaps, and Rust Shift Overflows -link @EthSecurity1
488
7
there is another Idea about Arrakis incident: The attacker stole the unclaimed LP fees with a "sandwich" attack The mint and redeem functions both require the input and output to be proportional to the deposited LP + unclaimed fees + idle balance in the two tokens. That means, if the pool holds x:y of token A:token B (in the LP position, plus fees and idle balance), your input/output will also be proportional to x:y. Thus, you cannot manipulate the price to fool the vault when burn() is called, the fees are collected. These fees are then compounded into the pool. This creates the vulnerability. The attacker then performs: swap1 → mint → swap2 → burn → swap3. After swap1, and later when burn() is called, the collected fees add more liquidity back to the LP, so when swapping back in swap3 @EthSecurity1
777
8
If you want to go GOD LEVEL in SYSTEM DESIGN, learn these concepts NOW: 1. Caching 2. API Design 3. Load Balancing 4. Rate Limiting 5. Scalability 6. Fault Tolerance 7. Authentication 8. Message Queues 9. Data Modelling 10. Object Storage 11. Database Sharding & Partitioning 12. Database Replication 13. CAP Theorem 14. Consistent Hashing 15. Serverless 16. Microservices 17. Event Driven Architecture 18. Service Discovery 19. API Security 20. Multi Agent Architecture @EthSecurity1
397
9
Every Ledger running the Ethereum app is vulnerable to signature substitution A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original While the review UI was pending, the APDU loop kept accepting commands. A second P1_FIRST in store mode reset the global signing context to a new tx without opening a new review. The approval callback signed whatever was in memory when the user tapped OK. @EthSecurity1
727
10
The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was hacked for 2.94 WETH via a Uniswap V3 spot-price manipulation. RootCause: the vault's mint() and burn() value its Uniswap V3 position off the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. The vault does have a TWAP check — but it only guards the manager's rebalance() swap, never mint/burn. @EthSecurity1
872
11
Term finance hacked for $8.5M RooCause: governance attack through Dao @EthSecurity1
875
12
$sand token minted 14.9B across 2 addresses: 0xAbE0...4D22 & 0x638C...F296 @EthSecurity1
906
13
- Secure Contract Development in TON: Top 9 Pitfalls in Tact & FunC -link - The Real Minimal Proxy - Powered by EIP-7702 - link - Understanding Auto Market Makers for bug bounty - link @EthSecurity1
983
14
- Developer Arrested Over Tornado Cash Research. Federico Carrone was released after 24 hours following an overwhelming international intervention from UAE, UK, US, all around European Union, Argentina and the Catholic Church. A good ending to what could have been a Tigran Gambaryan style incident. - Oracle Security Workshop - link - Secure Your ZK Code: Best Practices for Devs & Auditors - link @EthSecurity1
1 240
15
Maya protocol hacked for $1.3M ClaudeAI report: https://claude.ai/code/artifact/469af51b-8f6c-44f0-a213-f7520c9f4b2d @EthSecurity1
998
16
Fox Market on BNB Chain hacked for $120K RootCause: through a same-transaction spot-price manipulation bug in its bond mint p
Fox Market on BNB Chain hacked for $120K RootCause: through a same-transaction spot-price manipulation bug in its bond mint path. The attacker used massive flash liquidity to push the FOX/USDT pool, minted bonds against a stale pre-swap price, dumped the unlocked referral @EthSecurity1
977
17
- Anchor - a framework providing several convenient developer tools for writing Solana programs by Solana Foundation. - A Solana Static Analyser & Reverse Engineering tool. - link - hashcat v7.0.0 release including support for MetaMask and various wallet cracking. @EthSecurity1
1 032
18
Safepal Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw." @EthSecurity1
706
19
How to Setup an Ethereum Node Part 1 and Part 2 Inside Ethereum’s Engine: How the Execution Layer Actually Works - link  @EthSecurity1
1 230
20
- How to protect yourself from Google Forms scams -link - My Smart Contract Auditing Mental Model - Not a checklist! - link - Compressed NFTs on Solana - link - ape-safe - Account plugin for the Safe multisig wallet (previously known as Gnosis Safe) for the Ape Framework. @EthSecurity1
1 081