ch
Feedback
Defendor — DeFi Security

Defendor — DeFi Security

前往频道在 Telegram
2 359
订阅者
+224 小时
+177
+6530

数据加载中...

相似频道
无数据
有任何问题?请刷新页面或联系我们的客服
进出提及
---
---
---
---
---
---
吸引订阅者
七月 '26
七月 '26
+99
在3个频道中
六月 '26
+188
在0个频道中
Get PRO
五月 '26
+170
在0个频道中
Get PRO
四月 '26
+164
在4个频道中
Get PRO
三月 '26
+69
在1个频道中
Get PRO
二月 '26
+71
在0个频道中
Get PRO
一月 '26
+150
在1个频道中
Get PRO
十二月 '25
+302
在0个频道中
Get PRO
十一月 '25
+402
在4个频道中
Get PRO
十月 '25
+123
在3个频道中
Get PRO
九月 '25
+239
在0个频道中
Get PRO
八月 '25
+125
在0个频道中
Get PRO
七月 '25
+565
在3个频道中
日期
订阅者增长
提及
频道
25 七月+4
24 七月+1
23 七月+9
22 七月+4
21 七月+1
20 七月+4
19 七月+2
18 七月+2
17 七月+5
16 七月+3
15 七月+5
14 七月0
13 七月+1
12 七月+1
11 七月0
10 七月+4
09 七月+17
08 七月+9
07 七月+2
06 七月+2
05 七月0
04 七月0
03 七月+4
02 七月+8
01 七月+11
频道帖子
🏦 OpenZeppelin Launches Institutional Security Practice for Onchain Finance OpenZeppelin is positioning itself as an end-to-
🏦 OpenZeppelin Launches Institutional Security Practice for Onchain Finance OpenZeppelin is positioning itself as an end-to-end security partner for banks and financial institutions moving tokenization, payments, custody, and settlement into production, backed by $250B+ secured across 900+ audits and zero exploits in fully-remediated code. Clients include DTCC, Fidelity Digital Assets, WisdomTree, and Coinbase, with coverage spanning architecture through ongoing production monitoring. 🔗 Details

2
🔢 DeBond Drained for $542K via Duplicate Bond ID Exploit DeBond's bond group registry allowed duplicate bond IDs, and its ex
🔢 DeBond Drained for $542K via Duplicate Bond ID Exploit DeBond's bond group registry allowed duplicate bond IDs, and its exchange logic counted exception matches rather than tracking unique membership, breaking the burn-before-mint assumption and letting an attacker mint unbacked bonds. The attacker registered output groups with duplicate IDs, triggering skipped burns while minting new bonds, then sold them for 542,144 USDC from liquidity pools. 🔗 Details
205
3
⚠️ LayerZero Deprecating Support for Several Chains Across Three Waves LayerZero is winding down DVN, Executor, and Stargate
⚠️ LayerZero Deprecating Support for Several Chains Across Three Waves LayerZero is winding down DVN, Executor, and Stargate support across several chains in three waves, with deadlines on July 30, August 28, and September 30. Users holding Stargate pool or Hydra assets on affected chains must bridge to supported chains like Ethereum, Arbitrum, or Base before their respective deadlines or risk losing access to funds permanently. 🔗 Details
229
4
🚨 Triple-A Hot Wallets Drained for $9.3M+ Across Four Chains Triple-A hot wallets on TRON, Ethereum, TON, and Solana are bei
🚨 Triple-A Hot Wallets Drained for $9.3M+ Across Four Chains Triple-A hot wallets on TRON, Ethereum, TON, and Solana are being actively drained, with over $9.3M swapped and bridged to Ethereum for consolidation. 🔗 Details
266
5
📚 A Curated List of the Best Smart Contracts to Study awesome-smart-contracts by shafu0x collects production-grade repos fro
📚 A Curated List of the Best Smart Contracts to Study awesome-smart-contracts by shafu0x collects production-grade repos from Uniswap, Morpho, MakerDAO, Aave, Curve, EigenLayer, Solady, and more in one place. If you audit or write Solidity, these are the codebases worth studying for patterns, architecture, and edge-case handling. 🔗 Details
287
6
🚨 Guru Fund Exploited via Misconfigured Legacy Adapter Contract A legacy, unverified adapter deployed on March 11 with unexp
🚨 Guru Fund Exploited via Misconfigured Legacy Adapter Contract A legacy, unverified adapter deployed on March 11 with unexpected permissions was exploited on Ethereum, draining funds across six token funds including BEACHDEGEN, GURUFUND, BOOST, MESSYFUND, MESSYAI, and MESSYDEFI. The team has paused the protocol and disabled the component, but has confirmed it lacks sufficient reserves to reimburse affected users and is attempting to contact the attacker for recovery. 🔗 Details
299
7
📦 ERC-7540 Async Vault Standard Now in OpenZeppelin Community Contracts ERC-7540 extends ERC-4626 to support asynchronous se
📦 ERC-7540 Async Vault Standard Now in OpenZeppelin Community Contracts ERC-7540 extends ERC-4626 to support asynchronous settlement, letting vaults handle real-world assets that require compliance checks or clearing windows before redemption, with requests filled on equal terms rather than first-come-first-served. Built in collaboration with Tokenized Vault, Centrifuge, and Superform. 🔗 Details
319
8
🔮 Lien Finance Loses $542K via Crafted Bond Pricing Manipulation The attacker permissionlessly registered crafted bond group
🔮 Lien Finance Loses $542K via Crafted Bond Pricing Manipulation The attacker permissionlessly registered crafted bond groups, minted near-worthless bond tokens, then swapped them against GeneralizedDotc OTC pool liquidity where the pricing logic overvalued the bonds relative to their real collateral. The result was ~542K USDC drained from LP allowances in exchange for tokens backed by essentially nothing. 🔗 Details
338
9
🤖 Rekt: Zero Equals Zero, and Nobody Checked Using the Bonzo Finance exploit as a lens, Rekt argues that blind trust in auto
🤖 Rekt: Zero Equals Zero, and Nobody Checked Using the Bonzo Finance exploit as a lens, Rekt argues that blind trust in automated outputs, whether a BLS verifier, an AI denial algorithm, or a license plate reader, shares the same missing step: accepting an answer before verifying whether it deserves belief. From nH Predict reversals at 90% to 1,400+ AI-fabricated court citations, the pattern repeats across every domain, and the human in the loop keeps moving further from the check that matters most. 🔗 Details
346
10
🚨 B² Squared Network Reportedly Drained for $3.86M An attacker drained 8.59M B2 tokens on BNB Chain, swapped them for 5,409
🚨 B² Squared Network Reportedly Drained for $3.86M An attacker drained 8.59M B2 tokens on BNB Chain, swapped them for 5,409 WBNB, bridged the funds to Ethereum, and is currently routing proceeds to Zcash via NEAR Intents. 🔗 Details
348
11
🌉 Verus Ethereum Bridge Drained Again for $7.54M A second attacker exploited the same Verus Ethereum bridge import path as t
🌉 Verus Ethereum Bridge Drained Again for $7.54M A second attacker exploited the same Verus Ethereum bridge import path as the May 2026 incident, triggering unbacked payouts to drain ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves. The same contract, same entry path, and same bug class, suggesting the original vulnerability was never fully patched. 🔗 Details
367
12
🌉 AFX Bridge Exploited for $24.15M via Compromised Validator Keys AFX lost ~$24.15M USDC after an attacker submitted signatu
🌉 AFX Bridge Exploited for $24.15M via Compromised Validator Keys AFX lost ~$24.15M USDC after an attacker submitted signatures satisfying the bridge's 5-of-7 validator quorum with 7,142 of 10,000 total power, exceeding the required >2/3 threshold. The signature verification logic was not bypassed, suggesting the validator keys themselves were either compromised or misused, though on-chain evidence alone cannot confirm how. 🔗 Details
353
13
🔑 Critical Flaw in Zilliqa Ledger App Exposes Private Keys From On-Chain Data A nonce-generation bug in the Zilliqa Ledger a
🔑 Critical Flaw in Zilliqa Ledger App Exposes Private Keys From On-Chain Data A nonce-generation bug in the Zilliqa Ledger app has been present since 2019, causing Schnorr signatures to use predictably biased nonces with the top 64 bits fixed at zero, allowing private key recovery from just 5+ on-chain signatures using lattice reduction. Affected keys cannot be secured by simply moving funds, as attackers can front-run transfers using the already-derived private key. Users should await official Zilliqa guidance before taking any action. 🔗 Details
367
14
🔧 Physical Crypto Attacks Up 33% in H1 2026, $124M at Risk CertiK's H1 2026 Wrench Attack Report recorded 52 verified physic
🔧 Physical Crypto Attacks Up 33% in H1 2026, $124M at Risk CertiK's H1 2026 Wrench Attack Report recorded 52 verified physical attacks, a 33.3% year-over-year increase, with $124.2M in recorded exposure and home invasions emerging as the dominant vector. 🔗 Details
353
15
🗓️ Weekly Web3 Security Roundup: $1.35M Lost Two notable incidents combined for roughly $1.35M in losses across the Web3 eco
🗓️ Weekly Web3 Security Roundup: $1.35M Lost Two notable incidents combined for roughly $1.35M in losses across the Web3 ecosystem this week, July 13-19. A full vulnerability breakdown and in-depth analysis of each case is available in the linked report. 🔗 Details
361
16
🔮 42DAO Exploited for $900K+ via Single-Signer Oracle Flaw A MakerDAO Median-style oracle with a signing threshold of bar=1
🔮 42DAO Exploited for $900K+ via Single-Signer Oracle Flaw A MakerDAO Median-style oracle with a signing threshold of bar=1 let an authorized signer push BTCB price to 10²⁰, enabling the attacker to borrow 4.5M BLC against inflated collateral and swap proceeds for ~761K USDT. A second attacker followed up by manipulating the price downward via the Dog liquidation module, netting an additional ~$122K. 🔗 Details
396
17
🛠️ 840+ DeFi Hacks Now Explorable in a Live In-Browser Debugger crypto[.]training/hacks wraps every DeFiHackLabs PoC in root
🛠️ 840+ DeFi Hacks Now Explorable in a Live In-Browser Debugger crypto[.]training/hacks wraps every DeFiHackLabs PoC in root cause analysis, opcode-level EVM replay, and matched victim source, no RPC needed. The analysis and build pipeline is fully open source on GitHub. 🔗 Details
391
18
🐛 OpenZeppelin Bug Digest #9: Three Notable Findings This edition covers a Stellar rule-downgrade attack, a ZK circuit misco
🐛 OpenZeppelin Bug Digest #9: Three Notable Findings This edition covers a Stellar rule-downgrade attack, a ZK circuit misconstraint that would have frozen all PrivacyBoost withdrawals after tree 16, and the signed-integer exploit behind Aftermath Finance's April hack. All three share the same root failure: assumptions about what downstream code will enforce that turned out to be wrong. 🔗 Details
395
19
🔬 Why Certora Built AutoProver Now Certora CEO Mooly Sagiv says writing specifications has been the decade-long barrier to f
🔬 Why Certora Built AutoProver Now Certora CEO Mooly Sagiv says writing specifications has been the decade-long barrier to formal verification scaling, and LLMs now make it possible to automate that step for every developer, not just teams with formal methods expertise. The timing is deliberate: most new code is being written by LLMs, many 2026 DeFi hacks were carried out with AI assistance, and security tooling needs to match that pace. 🔗 Details
567
20
🌉 Wanchain Cardano-BNB Bridge Exploited for ~$500K 203M NIGHT tokens were falsely minted on Wanchain's Cardano-BNB bridge, l
🌉 Wanchain Cardano-BNB Bridge Exploited for ~$500K 203M NIGHT tokens were falsely minted on Wanchain's Cardano-BNB bridge, likely via a forged message, then swapped for 2.83M ADA (~$500K) on Cardano. 🔗 Details
401