Defimon Alerts
Open in Telegram
⚠️ DeFi security alerts by @DecurityHQ 💎 Instant alerts @defimon_subscription_bot defimon.xyz
Show moreThe country is not specifiedCryptocurrencies14 997
4 603
Subscribers
No data24 hours
+517 days
+13730 days
Data loading in progress...
Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Tags Cloud
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '26
September '26
+50
in 0 channels
August '26
+157
in 3 channels
Get PRO
July '26
+131
in 1 channels
Get PRO
June '26
+139
in 3 channels
Get PRO
May '26
+234
in 1 channels
Get PRO
April '26
+261
in 0 channels
Get PRO
March '26
+250
in 0 channels
Get PRO
February '26
+176
in 1 channels
Get PRO
January '26
+434
in 1 channels
Get PRO
December '25
+357
in 4 channels
Get PRO
November '25
+368
in 0 channels
Get PRO
October '25
+541
in 3 channels
Get PRO
September '25
+419
in 6 channels
Get PRO
August '25
+126
in 1 channels
Get PRO
July '25
+172
in 3 channels
Get PRO
June '25
+203
in 0 channels
Get PRO
May '25
+176
in 3 channels
Get PRO
April '25
+221
in 3 channels
Get PRO
March '25
+248
in 1 channels
Get PRO
February '25
+724
in 0 channels
Get PRO
January '250
in 0 channels
Get PRO
December '24
+19
in 1 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 06 September | +6 | |||
| 05 September | +2 | |||
| 04 September | +8 | |||
| 03 September | +18 | |||
| 02 September | +8 | |||
| 01 September | +8 |
Channel Posts
🚨 Rocket network exploited for $287K - deposits, withdrawals and trading are paused.
https://x.com/RCKTFoundation/status/2096594778863669498
| 2 | 💌 Onchain message:
We are offering a one-time whitehat resolution.
Return 90% of the withdrawn funds (approx. $287k) to 0x7b9f3d1c5573f61b10765b7801618f8354a449d0 and keep the remaining 10% as a whitehat bounty. Return in full within this window and we consider the matter closed with no further action.
This offer stands until 2026-09-10 23:59 UTC.
The withdrawal paths and onward addresses have been traced and flagged. Connection data from the incident has been preserved and referred to law enforcement.
After the deadline the terms change and we proceed with criminal and civil action.
Reply here or at info@rocketfoundation.io
📤 From: 0x5fbcac4f41d0ca39caa8d20db0291794c63ccdfe
📥 To: 0x2010d3043ea5418e8f5f955fe4c349dbd387f433
🌎 Network: mainnet
Etherscan | 380 |
| 3 | Defimon detected a malicious governance proposal that attempts to drain Olas.network Treasury - $100K at risk
Tornado-funded attacker registered ENS name "autonolas-deployer.eth" and submitted a proposal titled "Owner migration: transfer treasury ownership from old timelock to Safe updater".
In fact proposal execution would move Treasury ownership away from the legit Autonolas Timelock to the attacker contract, who could then rebalance and withdraw all 40.196 ETH.
There is 3 days to defeat the proposal. We have shared the alert in the community chat of the Olas network.
TX: https://etherscan.io/tx/0xe435eed3f2fe2be35a663c8f779738023f9e2cb0ae4f576fdf4d1f63dd09b524
Attacker: https://etherscan.io/address/0xd4f8d1ae1658926a076cf2e52ec1eca94c755451
Victim: https://etherscan.io/address/0xa0da53447c0f6c4987964d8463da7e6628b30f82 | 548 |
| 4 | 💌 Onchain message:
I am the owner of the hacked wallet. Please consider returning 80% of the assets. This is an enormous sum of money for me. I am not someone born into wealth. I built up these savings by spending more than ten hours every day for years doing on-chain trades. You may keep 20% of the total amount. I will not pursue this matter further. I only hope to recover my funds.
Here is my new receiving address:
0x454489232c92A09Cb1946baa965b1C8dd2F7A8BC
我是被盗钱包的主人,请考虑退回80%的资产。这对于我来讲是非常大的一笔钱,我并不是那些生来富有的人,我是通过连续几年每天十几个小时努力进行链上交易才获得这一点积蓄,你需要金额的多少,我不会对这个事情进行追究,只需要拿回我的金额,你可以留下金额的20%。
这是我新的收款地址:
0x454489232c92A09Cb1946baa965b1C8dd2F7A8BC
📤 From: 0x66cefafb50a6ae7a64d9346590b7f63b400f82c4
📥 To: 0xfdcaede2d1d34288d11b09a22b56c0caf5baeb33
🌎 Network: mainnet
Etherscan | 588 |
| 5 | 💌 Onchain message:
Balancer DAO — Notice to wallet owner:
We understand this wallet is linked to the exploit of Balancer V1 on Aug 31st, 2026. We are treating this as an opportunity for cooperation and would prefer to resolve this without escalation.
If you are willing to cooperate, reply to this message and begin contact procedures before September 8th, 21:00 UTC. If we do not hear from you by that time, we will assume you are unwilling to help make the liquidity providers whole and will escalate our response.
We would like to extend you an offer: return the funds to the DAO multisig address in exchange for a bounty. The details of this offer shall be arranged privately. Upon verification that the returned funds meet the criterias, Balancer will not pursue legal action or investigative steps aimed at identifying or prosecuting the owner of the returning wallet that are based solely on the fact of the return.
If you do not accept this offer or do not respond in time, we will use all technical, on-chain, and legal measures to identify and pursue the attacker. In that case, any bounty will instead be used to reward verified informants who help identify and lead to prosecution of the attacker.
To proceed, respond to this message privately via Blockscan (https://chat.blockscan.com). After successful verification, all communications will be coordinated with SEAL911, Hypernative, and Balancer’s legal team.
📤 From: 0x3877188e9e5da25b11fdb7f5e8d4fdddce2d2270
📥 To: 0x338c7ec9befbb451d66fd8a468c32184f5689a41
🌎 Network: mainnet
Etherscan | 741 |
| 6 | Community alert: Defimon detected a governance takeover attempt of Yam.finance
Attacker self-delegated ~504K $YAM (~3.3% of supply, just over the quorum) and submitted YamGovernorAlpha proposal #45 with an empty description ("0x"). The single action calls setPendingAdmin(attacker) on the YAM Timelock. If the vote passes and executes, the attacker becomes pendingAdmin and can acceptAdmin to seize full control of the Timelock - admin of all YAM protocol contracts and the DAO treasury.
There is ~$337K at risk. The protocol is dormant, so if you hold YAM vote against before block 25897343 (around 34 hours left).
TX: etherscan.io/tx/0xf3c9b1d7094bd11e6aa065c5efb009afa682a961c72e3f4c1bc20e6a25d2e25a
Attacker: etherscan.io/address/0x26881EacC00Bcccd7c4ebE14BD7840dD989Bf982 | 1 214 |
| 7 | A binary-options settlement bug has been exploited on Injective.com according to ErthlingPaddy. Attacker bridged ~$4.9M to Ethereum, the funds are unmoved.
https://x.com/ErthlingPaddy/status/2094506159344406623 | 888 |
| 8 | Solana prop AMM Aquifer (AquiferDEX.io) exploited for ~$2.5M
Attacker (Ethereum): https://etherscan.io/address/0x2dfe9e969796e2797278b02761dd9ad6ae922746
Attacker (Solana): https://solscan.io/account/7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J
X: https://x.com/_aquifer_ | 922 |
| 9 | 💌 Onchain message:
AQUIFER WHITEHAT OFFER — 31 AUG 2026
This is an official Aquifer communication regarding the exploit of:
AQU1FRd7papthgdrwPTTq5JacJh8YtwEXaBfKU3bTz45
Aquifer's Solana upgrade authority has published and authorized this offer on-chain.
Reference Solana transaction:
u1hoSUTzhe3hhnGiUiwvjtzd9Ji8EQPxjnTSKtW2hHDqY9ukYySftNp9eMHsBHsYezBKFcNyoZapYHYu4XaaZbQ
Solana upgrade authority:
8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA
This message is directed to the party controlling:
Solana:
7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J
Ethereum:
0x2Dfe9e969796e2797278b02761dd9Ad6aE922746
Aquifer offers the following whitehat resolution:
Return at least 80% of the assets or equivalent value associated with the exploit to the designated recovery addresses no later than:
3 September 2026, 14:00 UTC
You may retain up to 20% as a whitehat bounty.
Subject to applicable law and full compliance with these terms, Aquifer will not pursue civil claims against you arising from this incident.
This offer does not bind law-enforcement, regulatory, sanctions, or other governmental authorities.
Authorized Ethereum communications address:
0x09dA08045830492B24b3b8A0022375e662bbE91d
Recovery addresses:
Solana:
8af8RnAgyKzNt4fjDaP8w8pBekYVux1ja4AofavRyjox
Ethereum:
0xb7EAA8cd5dFAD8021d9fB19c8a21613679f268F5
You may respond using an Ethereum Input Data Message to this address.
📤 From: 0x09da08045830492b24b3b8a0022375e662bbe91d
📥 To: 0x2dfe9e969796e2797278b02761dd9ad6ae922746
🌎 Network: mainnet
Etherscan | 798 |
| 10 | 💌 Onchain message:
Hi. We would like to chat and offer you a bounty. Please get in touch. You can DM our official account on Twitter or message us on Telegram (@ckhbtc).
📤 From: 0x91e4f2e8770cad99bf3f1905c0336ebf8b964640
📥 To: 0x5a18c382ed5bb01814296ee03026dbf5b32a69ea
🌎 Network: mainnet
Etherscan | 756 |
| 11 | 💌 Onchain message:
Hello
Looks like you have hacked my wallet. This amount of money you hacked is honestly a lot for me and it hurts more than what you think.
I would really appreciate if you return 50% of that and happily keep the rest for you.
Also really really curious to know how did you do that?
I did follow all security practices as far as I know.
📤 From: 0xdc612f2119b7d1069c3b8b28ba7aca46c725fa4f
📥 To: 0x70506537f3dff3075de6ebbd09d5f6fa52a18ad0
🌎 Network: base
Etherscan | 865 |
| 12 | 💌 Onchain message:
we have sent you a blockscan chat message to negotiate a bounty for the return of funds. Please contact us to discuss.
📤 From: 0xddbf679d6332d9e5b409865b9671d1927255b52a
📥 To: 0xd71dd9b6e634412713c47fe7ae02c628e338c384
🌎 Network: mainnet
Etherscan | 889 |
| 13 | 🚨 Ajna.finance lost ~$775K due to liquidation accounting manipulation on Ethereum. Defimon detected a prepared attack more than one hour before the first exploit tx, notified Ajna in their Discord, but the team failed to react.
Pools hit (~$775K total):
• syrupUSDC $173.7K
• wstETH $159.8K
• rETH $127.4K + $15.6K
• cbETH $124.8K + $12.1K
• WBTC $101.8K
• WETH/USDC $42.0K
• sDAI $18.0K
Sample TX: https://etherscan.io/tx/0x12dfde527ef62882bfabb64362c9ae0e6bfb628363bd298d0d0956c9a114e4f5
Attackers:
https://etherscan.io/address/0x6f2f5236b10fe7162da077a2779f8b5f04b7827e
https://etherscan.io/address/0xc213145ef56c0f162e0c3d79e6e107b25cb8c453
https://etherscan.io/address/0xcccc640018f8c2b00fa45f456017ad2378eb3447
X: https://x.com/ajnafi
⏱️ Early detection alerts: @defimon_subscription_bot | 992 |
| 14 | 💌 Onchain message:
While conducting some onchain research,I came across several wallets with unusual permission activity. One of them appears to be yours.
Security notice: A few months old anomalous signature associated with your wallet was detected and revoked. The signature appears to have granted unauthorized spending authority, which was used to access the wallet before the permission was neutralized.
I secured the affected authorization to prevent any further movement of funds. You should immediately review and revoke any remaining approvals or delegated permissions associated with the wallet.
Due to your carelessness in managing your wallet permissions, the recovered funds will be returned in 6 separate transactions within 30 days after you confirm your wallet is clean. I will provide further details with each batch as the recovery proceeds.
I am an independent security researcher, not the party responsible for the original compromise. I have no intention of retaining the recovered assets. If you consider the recovery useful, a small voluntary tip is appreciated, but it is not required.
📤 From: 0xe19b523f0066599d53da313f8a6e4aeee66aaa4e
📥 To: 0xc2800adec3c2b9ee4ec8dc4d0bdd91b6b948df0d
🌎 Network: bsc
Etherscan | 880 |
| 15 | 💌 Onchain message:
avici hacker? if so pls consider donating pls:(
📤 From: robertdownonlyjr.eth
📥 To: 0x2ce21e4921d3eb116526c3651dac0257657338d5
🌎 Network: mainnet
Etherscan | 848 |
| 16 | 💌 Onchain message:
You have received a message via Blockscan chat to discuss the bounty and return of funds.
📤 From: 0x39d787fdf7384597c7208644dbb6fda1cca4ebdf
📥 To: 0xe4ed3720d16802dfaac61183b0ec3fe13520b908
🌎 Network: mainnet
Etherscan | 866 |
| 17 | 💌 Onchain message:
We’re aware of the exploit and want to resolve this as a white-hat disclosure. Return 70% of the funds to this address and we’ll consider the matter closed and cease further pursuit
📤 From: 0x64e7ff734848dc7b04d00da71615649d321c04a3
📥 To: 0xb00d08e09fa48c2e1d48ac3ede2ffea354341215
🌎 Network: mainnet
Etherscan | 879 |
| 18 | 🚨 CashCowCoin (CCC) - Loss ~$117K (2026-08-27)
Token: $CCC @ $0.012194
Network: BNB Chain
Type: Oracle Manipulation (Flash Loan)
The CashCowCoin sale/AMM contract (0xf523…41c7, impl 0x4287…a9ac) prices buys/sells from the spot reserves of the CCC/WBNB PancakePair via getReserves(). The attacker flash-loaned ~416,831 WBNB from a Moolah lending market (0x8f73…5d8c), donated WBNB directly into the pair and called sync() to inflate its reserves, then cycled buy/sell against the manipulated price to extract the pair's real liquidity. The CCC/WBNB pair (0x1dbe…97c0) was drained from ~165.5 WBNB to ~0.018 WBNB; ~165.47 WBNB (~$117K) netted to the attacker after repaying the flash loan.
TX: https://bscscan.com/tx/0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43
Attacker: https://bscscan.com/address/0x7977bdeee3a79dc85cc18739692e796b5d2513c4
Victim: https://bscscan.com/address/0xf523224c6171f81c54b93f474ed4c78de91241c7
@defimon_subscription_bot | 861 |
| 19 | 💌 Onchain message:
We are Match Systems, investigating this incident in cooperation with law enforcement. We have identified your Spanish IP and see that the stolen funds are being spent through gambling.
Contact us to negotiate the return of the remaining assets. If an agreed return is completed, the victim will withdraw all claims. Cooperation now is your best opportunity to avoid further legal consequences.
Contact: @matchsystems_info / info@matchsystems.com
📤 From: 0x8e7385c3e6208eed3e3042f7d4899f625470e97f
📥 To: 0x5d2fc3c2e011da5b390db56d0577a173bb2632aa
🌎 Network: mainnet
Etherscan | 910 |
| 20 | 💌 Onchain message:
Make a refund to the owner address 6XWsJWycok7wi557oN4E4Q9Dvmagp9zFTxA6U8gfBisn
0x5A9A72F4326fA4FA15753013EF907aDd09030317
You can keep 33% as bounty reward.
📤 From: 0x5a9a72f4326fa4fa15753013ef907add09030317
📥 To: 0x84f5433b8868276cd7c37190069124d322ef4905
🌎 Network: mainnet
Etherscan | 10 |
