en
Feedback
Defendor — DeFi Security

Defendor — DeFi Security

Open in Telegram
2 462
Subscribers
+224 hours
+177 days
+7430 days

Data loading in progress...

Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
August '26
August '26
+114
in 4 channels
July '26
+128
in 3 channels
Get PRO
June '26
+188
in 0 channels
Get PRO
May '26
+170
in 0 channels
Get PRO
April '26
+164
in 4 channels
Get PRO
March '26
+69
in 1 channels
Get PRO
February '26
+71
in 0 channels
Get PRO
January '26
+150
in 1 channels
Get PRO
December '25
+302
in 0 channels
Get PRO
November '25
+402
in 4 channels
Get PRO
October '25
+123
in 3 channels
Get PRO
September '25
+239
in 0 channels
Get PRO
August '25
+125
in 0 channels
Get PRO
July '25
+565
in 3 channels
Date
Subscriber Growth
Mentions
Channels
31 August+4
30 August+8
29 August+3
28 August+3
27 August+6
26 August+2
25 August+5
24 August+2
23 August+2
22 August+2
21 August+5
20 August+11
19 August+9
18 August0
17 August+1
16 August+5
15 August+2
14 August0
13 August+8
12 August+15
11 August+1
10 August0
09 August+3
08 August0
07 August0
06 August+7
05 August+5
04 August0
03 August+2
02 August+2
01 August+1
Channel Posts
🚨 Tectonic Finance Exploited for ~$66M in Price Manipulation Attack TONIC's own governance token, used as collateral with a
🚨 Tectonic Finance Exploited for ~$66M in Price Manipulation Attack TONIC's own governance token, used as collateral with a 20% factor and thin liquidity, was pumped 100x in 20 minutes to enable over-borrowing. Cronos paused the chain, limiting the attacker to bridging out ~$6M of the $66M; it's the third Mango Markets-style attack recently, after Moonwell and Pendle YT. 🔗 Details

2
🚨 Malware Campaign Targets Claude Users, Steals Crypto Silently Infostealer campaigns are grabbing passwords and browser dat
🚨 Malware Campaign Targets Claude Users, Steals Crypto Silently Infostealer campaigns are grabbing passwords and browser data from Claude users, putting exchange logins and hot wallets at risk. One victim was hit via a malicious download link inside his own Claude chat, with a rigged SKILL[.]md file reinstalling the malware on every load; the campaign hit 29 organizations in two days, per Huntress. 🔗 Details
304
3
💸 The Avici Attacker Turned $190 Into $670K via Signature Flaw A $190 wallet exploited a signature check bug, self-approving
💸 The Avici Attacker Turned $190 Into $670K via Signature Flaw A $190 wallet exploited a signature check bug, self-approving as admin on 1,100+ collateral accounts and draining them one by one. Nearly 8,900 transactions ran; the first ~$576K left within 15 minutes, with a median take of just $24. 🔗 Details
2 273
4
🌊 Full Sail Vault Exploit — How the Oracle Manipulation Worked A single-response oracle feed accepted a SUI price at 1/100 n
🌊 Full Sail Vault Exploit — How the Oracle Manipulation Worked A single-response oracle feed accepted a SUI price at 1/100 normal, understating vault AUM and letting the attacker mint excess shares, then restored the real price before withdrawing. 63 deposit/withdraw pairs hit three vaults; no deviation check covered AUM calculation or share minting. 🔗 Details
315
5
🔬 Hexens Breaks Down Why QKD's Proofs Are Solid, But Hardware Isn't Hexens explains that QKD promises security from physics,
🔬 Hexens Breaks Down Why QKD's Proofs Are Solid, But Hardware Isn't Hexens explains that QKD promises security from physics, but real attacks exploit gaps between the ideal protocol and actual equipment, like detector blinding attacks that steal keys undetected. Fixes like decoy states and MDI-QKD close these gaps, though large real-world networks still rely on trusted relay nodes rather than pure physics-based security. 🔗 Details
320
6
🕵️ ZachXBT Links "M1llionz" to $667K French Home Invasion Robberies On-chain tracing connects the French cybercriminal to tw
🕵️ ZachXBT Links "M1llionz" to $667K French Home Invasion Robberies On-chain tracing connects the French cybercriminal to two violent April 2026 robberies, with stolen crypto laundered through Chainflip, KuCoin, and Monero exchanges. ZachXBT's investigation led to a $93K Tether freeze, and social media posts allegedly tie the suspect's own wallets directly to the stolen funds. 🔗 Details
337
7
✅ Avici Confirms Root Cause, Full Refunds for Affected Users A vulnerability in a Solana card contract from issuing partner R
✅ Avici Confirms Root Cause, Full Refunds for Affected Users A vulnerability in a Solana card contract from issuing partner Rain affected card balances, not self-custodial wallets; 1,685 users lost $500,859.22. The contract has been upgraded, no further unauthorized activity has been observed, and all affected users will be refunded in full. 🔗 Details
346
8
🚨 Ajna Fi Loses ~$775K to Liquidation Accounting Exploit Attackers manipulated liquidation accounting across multiple pools
🚨 Ajna Fi Loses ~$775K to Liquidation Accounting Exploit Attackers manipulated liquidation accounting across multiple pools on Ethereum, hitting syrupUSDC, wstETH, rETH, cbETH, WBTC, and others. Defimon flagged the prepared attack over an hour before the first exploit transaction, but the team failed to react in time. 🔗 Details
528
9
🔴 Cosmos Labs Releases Post-Mortem on Multi-Chain EVM Exploit A misjudged risk assessment led Cosmos Labs to patch a critica
🔴 Cosmos Labs Releases Post-Mortem on Multi-Chain EVM Exploit A misjudged risk assessment led Cosmos Labs to patch a critical balance-underflow bug silently rather than privately, and a public PR describing the exploit path preceded attacks on six chains that lost roughly $5.7M combined. MANTRA, TAC, and KiiChain were hit first; Cosmos Labs coordinated with 40 chains to halt and patch, and has committed to reworking its disclosure process. 🔗 Details
358
10
🚨 Solana Neobank Avici Reportedly Hacked, $600K+ Drained More than $600,000 has reportedly been drained from user accounts o
🚨 Solana Neobank Avici Reportedly Hacked, $600K+ Drained More than $600,000 has reportedly been drained from user accounts on the Solana-based neobank. Details on the root cause have not yet been disclosed. 🔗 Details
464
11
🚔 Two TeamPCP Members Arrested in Perth, Australia Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested over
🚔 Two TeamPCP Members Arrested in Perth, Australia Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were arrested over the group's npm supply chain attacks. The group is linked to the Shai-Hulud worm and other npm ecosystem compromises. 🔗 Details
384
12
🐄 CashCowCoin Loses ~$117.4K in Reserve-Draining Exploit A flawed sell function let the router burn CCC tokens post-swap whi
🐄 CashCowCoin Loses ~$117.4K in Reserve-Draining Exploit A flawed sell function let the router burn CCC tokens post-swap while keeping the reduced WBNB reserve, draining the pool across 80 repeated sell cycles. Stolen funds were routed through a profit splitter contract to a separate owner wallet. 🔗 Details
381
13
🔐 Researchers Reproduce Transaction Replacement Attack on Ledger OneKey Anzen exploited a race condition in Ledger Ethereum
🔐 Researchers Reproduce Transaction Replacement Attack on Ledger OneKey Anzen exploited a race condition in Ledger Ethereum app 1.22.1, letting an attacker swap the transaction being signed while the user still sees the original one. Ledger fixed the issue in version 1.22.3, and users on older versions are urged to update. 🔗 Details
416
14
🔑 Realio Network Loses $6.2M After Signing Key Takeover Attackers seized realio[.]fund's single hot signing key and swept tr
🔑 Realio Network Loses $6.2M After Signing Key Takeover Attackers seized realio[.]fund's single hot signing key and swept treasury and custodial wallets across five chains, draining 127.9M RIO ($6.2M). No contract bug or user approval was involved; the attacker has cashed out roughly $317K so far. 🔗 Details
418
15
🚨 Moonwell on Base Loses ~$5.7M in Oracle Manipulation Exploit The attacker manipulated the MAMO collateral oracle, pushing
🚨 Moonwell on Base Loses ~$5.7M in Oracle Manipulation Exploit The attacker manipulated the MAMO collateral oracle, pushing its price up roughly 8x, then borrowed real cbBTC against the inflated mMAMO collateral. About 71.36 cbBTC (~$5.7M) was drained across multiple transactions, with the largest single borrow around $1.15M. 🔗 Details
441
16
⚡ Core Lightning Urges Node Operators to Upgrade or Go Offline Maintainers are handling multiple AI-generated vulnerability r
⚡ Core Lightning Urges Node Operators to Upgrade or Go Offline Maintainers are handling multiple AI-generated vulnerability reports and warn operators to install an upcoming patch or go offline. Fix details stay under a two-week embargo, with no public CVE or advisory yet. 🔗 Details
417
17
🔓 Provenance Blockchain Bug Let Anyone Self-Grant Admin Control A stale supply field let any user pass a "controls 100% of s
🔓 Provenance Blockchain Bug Let Anyone Self-Grant Admin Control A stale supply field let any user pass a "controls 100% of supply" check with zero tokens, granting admin, mint, and withdraw rights on 82 live markers. Two transactions were enough to exploit it; the bug was reported in April and fully fixed by June, with no funds lost. 🔗 Details
431
18
📚 Curated Web3 Security Hub Worth a Bookmark This resource collects role-based roadmaps for EVM, Solana, Move, Cairo and ZK
📚 Curated Web3 Security Hub Worth a Bookmark This resource collects role-based roadmaps for EVM, Solana, Move, Cairo and ZK auditors, plus tools for fuzzing, invariant testing, formal verification and AI-assisted workflows. It also includes public audit reports, incident response guides and launch checklists for both builders and auditors. 🔗 Details
426
19
🚨 Cosmos Labs Urges Chains to Patch Cosmos EVM Now Chains running Cosmos EVM versions below v0.6.2 or v0.7.2 should immediat
🚨 Cosmos Labs Urges Chains to Patch Cosmos EVM Now Chains running Cosmos EVM versions below v0.6.2 or v0.7.2 should immediately halt and upgrade to the patched releases. Teams that haven't shared security contact details with Cosmos Labs are asked to reach out for critical updates. 🔗 Details
448
20
🚨 Enjin Loses ~$162K in Storage Slot Collision Exploit The exploit abused a slot collision between an adapter's initialize f
🚨 Enjin Loses ~$162K in Storage Slot Collision Exploit The exploit abused a slot collision between an adapter's initialize function and the proxy's pendingManager storage, letting the attacker hijack manager rights via DELEGATECALL. After gaining control, the attacker registered a malicious adapter and drained victim assets through a liquidation path. 🔗 Details
463