ch
Feedback
Defendor — DeFi Security

Defendor — DeFi Security

前往频道在 Telegram
2 523
订阅者
+624 小时
+97 天
+10430 天

数据加载中...

相似频道
无数据
有任何问题?请刷新页面或联系我们的客服
进出提及
---
---
---
---
---
---
吸引订阅者
九月 '26
九月 '26
+78
在2个频道中
八月 '26
+117
在4个频道中
Get PRO
七月 '26
+128
在3个频道中
Get PRO
六月 '26
+188
在0个频道中
Get PRO
五月 '26
+170
在0个频道中
Get PRO
四月 '26
+164
在4个频道中
Get PRO
三月 '26
+69
在1个频道中
Get PRO
二月 '26
+71
在0个频道中
Get PRO
一月 '26
+150
在1个频道中
Get PRO
十二月 '25
+302
在0个频道中
Get PRO
十一月 '25
+402
在4个频道中
Get PRO
十月 '25
+123
在3个频道中
Get PRO
九月 '25
+239
在0个频道中
Get PRO
八月 '25
+125
在0个频道中
Get PRO
七月 '25
+565
在3个频道中
日期
订阅者增长
提及
频道
18 九月+2
17 九月+6
16 九月+2
15 九月0
14 九月+3
13 九月+1
12 九月+4
11 九月+5
10 九月+3
09 九月+10
08 九月+1
07 九月+1
06 九月+6
05 九月+1
04 九月+11
03 九月+15
02 九月+3
01 九月+4
频道帖子
🔓 Nimiq Loses ~$50.4K to Meta-Transaction Signature Bypass The swap contract's execute() never verified the user's signature
🔓 Nimiq Loses ~$50.4K to Meta-Transaction Signature Bypass The swap contract's execute() never verified the user's signature directly, relying on preRelayedCall, but OpenGSN let the attacker register their own accept-everything paymaster and forwarder. This let the attacker forge open() requests against a liquidity wallet's unlimited approvals, opening and redeeming HTLCs with a known secret to drain USDC, USDT0, and USDC.e. 🔗 Details

2
🔓 Researchers Chained a libheif RCE and SSO Flaw to Access OpenAI's Internal Repos An unpatched heap overflow in libheif, re
🔓 Researchers Chained a libheif RCE and SSO Flaw to Access OpenAI's Internal Repos An unpatched heap overflow in libheif, reached through HEIC image uploads on OpenAI's Discourse forum, gave researchers code execution. An SSO misconfiguration then let them hijack employee ChatGPT/Codex accounts and open a PR in OpenAI's internal monorepo, all within 72 hours. 🔗 Details
169
3
🔓 Nostra Finance Loses ~$3.5M to NSTR Oracle Manipulation A manipulated NSTR price let a single account borrow ETH, STRK, US
🔓 Nostra Finance Loses ~$3.5M to NSTR Oracle Manipulation A manipulated NSTR price let a single account borrow ETH, STRK, USDC, USDT, WBTC, and DAI against inflated collateral on Starknet. The attacker has bridged roughly $1.92M of the stolen funds to Ethereum so far. 🔗 Details
265
4
🔓 Likwid Finance Loses 74.31 BNB to Stale Price Reuse Bug A zero-leverage branch never updated pairReserves, so the borrow f
🔓 Likwid Finance Loses 74.31 BNB to Stale Price Reuse Bug A zero-leverage branch never updated pairReserves, so the borrow function kept quoting the same price on every call instead of reflecting AMM price impact. The attacker looped the margin/borrow cycle 14 times, settling a large token amount entirely at the first-trade price. 🔗 Details
269
5
📅 Weekly Web3 Security Roundup: Sep 7–13 BlockSec highlights 2 notable incidents from the week, with roughly $320M lost in t
📅 Weekly Web3 Security Roundup: Sep 7–13 BlockSec highlights 2 notable incidents from the week, with roughly $320M lost in total. The report includes a vulnerability breakdown and in-depth analysis, covering the Liquid Network and Symbiosis exploits. 🔗 Details
283
6
🤝 S&P Global to Acquire OpenZeppelin The deal aims to combine S&P Global's risk assessment capabilities with OpenZeppelin's
🤝 S&P Global to Acquire OpenZeppelin The deal aims to combine S&P Global's risk assessment capabilities with OpenZeppelin's onchain security standards. The companies plan to build next-generation onchain security assessments and benchmarks as capital markets shift onchain. 🔗 Details
312
7
⚠️ Where EVM Assumptions Silently Break On Arc Mainnet USDC is Arc's native asset, not ETH, so transfers can revert on blockl
⚠️ Where EVM Assumptions Silently Break On Arc Mainnet USDC is Arc's native asset, not ETH, so transfers can revert on blocklisted or destroyed addresses, and SELFDESTRUCT burns funds instead of preserving them. Native USDC uses 18 decimals while ERC-20 USDC uses 6, and a CallFrom precompile preserves the original caller across contracts, both easy to miss when porting Ethereum code untested on Arc. 🔗 Details
325
8
🐌 Certora Finds Order-Book Liveness Bug in Sui Perpetuals Expired maker orders returned zero fill without reducing the taker
🐌 Certora Finds Order-Book Liveness Bug in Sui Perpetuals Expired maker orders returned zero fill without reducing the taker's remaining size, letting a stale prefix of orders force unbounded matching work per transaction. A timestamp boundary mismatch let orders be posted already expired, and since cleanup only ran after full traversal, a large enough stale prefix could exhaust gas and revert before ever being removed. 🔗 Details
330
9
🕵🏽 QuillAudits Finds Certificate Replay Bug in Gold-Backed Vault Releasing gold handed the custody certificate back to the
🕵🏽 QuillAudits Finds Certificate Replay Bug in Gold-Backed Vault Releasing gold handed the custody certificate back to the customer instead of burning it, leaving it fully valid. Redepositing that same certificate let the customer mint a fresh batch of claim tokens against gold that had already left the vault. 🔗 Details
349
10
🔓 Flamincome Loses ~$345.9K to NAV Manipulation via Curve LP Staking Staking Curve LP mid-transaction instantly bumped the s
🔓 Flamincome Loses ~$345.9K to NAV Manipulation via Curve LP Staking Staking Curve LP mid-transaction instantly bumped the strategy's reported NAV since it prices holdings at spot get_virtual_price() with no manipulation-resistant oracle. The attacker used an $18M flash loan to inflate NAV, redeemed oversized shares for liquid aUSDT, and repaid the loan in one transaction. 🔗 Details
357
11
🔓 Startale Smart Accounts Drained via Transient Storage Re-Init Bug An initialization flag stored in transient storage stays
🔓 Startale Smart Accounts Drained via Transient Storage Re-Init Bug An initialization flag stored in transient storage stays live for the whole transaction, not just the constructor, letting anyone re-initialize a freshly deployed account with malicious code. The attacker deployed and hijacked victim accounts in the same transaction across 330 counterfactual accounts, draining ~$2,876 so far with no capital or signatures required. 🔗 Details
361
12
🔓 BonfireSwap Router Loses ~$47K to Missing Authorization Check The router's transfer function let any caller spend a holder
🔓 BonfireSwap Router Loses ~$47K to Missing Authorization Check The router's transfer function let any caller spend a holder's BONFIRE approval without verifying ownership or authorization. The attacker looped this across ~65 approved holders, force-selling their tokens and skimming the proceeds to their own contract. 🔗 Details
364
13
🐛 LayerZero Boosts Bug Bounty to $3.5M, Merges Stargate Program The LayerZero v2 bug bounty increases to $3.5M and now absor
🐛 LayerZero Boosts Bug Bounty to $3.5M, Merges Stargate Program The LayerZero v2 bug bounty increases to $3.5M and now absorbs the legacy Stargate program, effective immediately. The V1 bug bounty and relayer will both be deprecated on December 15, alongside STG-to-ZRO conversion closing the same day. 🔗 Details
389
14
🛠️ Anvil Builds Collateral Infrastructure on OpenZeppelin Contracts Anvil leverages OpenZeppelin's battle-tested standards f
🛠️ Anvil Builds Collateral Infrastructure on OpenZeppelin Contracts Anvil leverages OpenZeppelin's battle-tested standards for token standards, governance, proxy patterns, and access control across its protocol. OpenZeppelin has conducted multiple security audits on Anvil since 2024, supporting both design and ongoing security review as the protocol evolves. 🔗 Details
380
15
🔄 Cronos Rolled Back 11,000 Blocks to Reverse $111.2M Tectonic Exploit Validators halted the chain mid-attack and rewound hi
🔄 Cronos Rolled Back 11,000 Blocks to Reverse $111.2M Tectonic Exploit Validators halted the chain mid-attack and rewound history to before a governance token pump let an attacker borrow $120.4M against inflated collateral. Roughly $9.19M had already left Cronos before the halt and remains unrecovered; Tectonic has cut TONIC's collateral factor to zero over several weeks but announced no depositor compensation plan. 🔗 Details
385
16
🤖 MEV Bot Front-Runs $7.81M rsETH Exploit, Steals Entire Haul A whitelisted Safe module exposed an entrypoint that forwarded
🤖 MEV Bot Front-Runs $7.81M rsETH Exploit, Steals Entire Haul A whitelisted Safe module exposed an entrypoint that forwarded caller-supplied calldata into a DELEGATECALL with no access gating, letting anyone execute code inside the victim's Safe. An attacker deployed the exploit into the mempool, but a MEV bot spotted it first and front-ran the transaction, capturing the full $7.8M for itself. 🔗 Details
403
17
🔐 OpenZeppelin: Why Quantum Risk Isn't Just a Future Problem Once a public key is exposed on-chain, a future quantum compute
🔐 OpenZeppelin: Why Quantum Risk Isn't Just a Future Problem Once a public key is exposed on-chain, a future quantum computer could recover the private key and forge authorizations, making "expose now, forge later" the real threat. NIST's post-quantum standards offer replacements, but migration is costly and complex, and already-exposed keys can only be protected by moving funds before quantum computers arrive. 🔗 Details
538
18
🎮 24 New Runnable EVM Exploit PoCs Now Live Each August-September incident is a browser-based Foundry PoC with full opcode d
🎮 24 New Runnable EVM Exploit PoCs Now Live Each August-September incident is a browser-based Foundry PoC with full opcode debugging, source stepping, and live balance tracking, not just a write-up. The batch covers recent hacks like Ajna, Balancer V1, Zentra, Notional, and OMNI404, with offline Foundry versions also available. 🔗 Details
402
19
🔓 Spiral V2 Loses ~10.7 ETH to Same-Block Spot Price Exploit Collateral was valued off Uniswap V4's spot price with no TWAP
🔓 Spiral V2 Loses ~10.7 ETH to Same-Block Spot Price Exploit Collateral was valued off Uniswap V4's spot price with no TWAP protection, and the same-block swap guard was keyed to tx.origin instead of the actual caller. The attacker used 6 different wallets to bypass the guard, borrowing against inflated collateral within the same block as the price pump. 🔗 Details
412
20
🏦 YAM Finance Governance Takeover Drains ~$121K After executing the malicious proposal to seize Timelock admin, the attacker
🏦 YAM Finance Governance Takeover Drains ~$121K After executing the malicious proposal to seize Timelock admin, the attacker cut the delay to 12 hours and used gov-only functions to release WETH collateral from old farming contracts. The stolen 48.15 ETH was cashed out through FixedFloat. 🔗 Details
415