es
Feedback
5 300
Suscriptores
+324 horas
-17 días
+2030 días
Archivo de publicaciones
on old Flamincome contracts hacked for ~$345.9k. Attacker flashloaned ~$18M USDT, inflated VaultYUSDT share price by staking USDP LP into Strategy, then redeemed liquid aUSDT. @EthSecurity1

@DCENTWALLETS has reported abnormal asset transfers involving its App Wallet. Users should update the DCENT app to the latest version before making any transfers. @EthSecurity1

@Bonfiretoken Loss: ~ $50k RootCause: Access control missing in BonfireSwap router's transfer. The function does not check msg.sender == from nor verify the caller's allowance on `from It seems all stolen funds locked in attacker contract lol! @EthSecurity1

LayerZero Labs reportedly faced repeated operational security failures, including losing control of a critical private key used to manage a live FRNT deployment. @EthSecurity1

Blackrock ruined crypto market. Fuck @Ethsecurity1

A MEV bot front-runs a ~$7.81M rsETH exploit on Ethereum. MEV bot "yoink" front-ran an attacker's ~$7.81M exploit on whale 0x40E9's leveraged rsETH held in a Gnosis Safe, capturing the full amount after the malicious tx entered the mempool. Root cause was a whitelisted Safe module exposing an ungated recipe entrypoint that passed fully caller-controlled calldata into execTransactionFromModuleReturnData via DELEGATECALL, enabling arbitrary code execution in the Safe's context. TX: etherscan.io/tx/0x0e7680b06 Victim (whale 0x40E9): etherscan.io/address/0x40e9 Original exploiter: etherscan.io/address/0x0dC2 Frontrunner (yoink MEV bot): etherscan.io/address/0xfde0 @EthSecurity1

Yam finance hacked for 48 ETH Rootcause: governance attack @EthSecurity1

- Weaponizing image scaling against production AI systems - link - The solution to crypto’s Lazarus problem could be simpler than expected. Guardian nodes with a timelock allows good actors to cancel a malicious proposal before it is executed. - link - You’re Probably Using WebViews Wrong: Common Security Pitfalls for Mobile Developers - link @EthSecurity1

Trezor phishing emails came from Trezor’s own sending address ~347,000 Trezor newsletter subscribers received a warning about a fake hardware defect sent from real address mailing@trezor.io @EthSecurity1

seems Revolut exposed personally identifiable information @EthSecurity1

- DNSFilter Research Finds Bad Actors Using Fake CAPTCHAs for Malware Attempts -link - Security lessons from the oldest bug bounty program w/ Fredrik Svantes (Ethereum Foundation). - link @Ethsecurity1

- Detailed LIQUID post-mortem - link - Brevo have closed a security incident that allowed an attacker to access 120 Brevo accounts. The majority of those have no suspicious activity. The bad actor used the access to send phishing emails to the client's contactbase. - link - @ether_fi Liquid (liquidETH) holders were drained for ~15.45 ETH via the Veda AtomicQueue. - link - an ongoing exploit on @symbiosis_fi on BSC. Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4. ~$336k realized WBTC proceeds so far. @EthSecurity1

-DeFi Security 101 playlist - Meet “Blackhat” - a developer who dusted off a 4-year-old factory contract and deployed 700+ honeypot tokens in just over a month, harvesting $100K+ from unsuspecting traders - link @EthSecurity1

- Pectra's Impact On Smart Contract Security -link - How does the EVM dispatch smart contract functions? -link @Ethsecurity

- Move for Solidity Developers IV: Cross-Contract Call -link - You’re Probably Using WebViews Wrong: Common Security Pitfalls for Mobile Developers -link @EthSecurity1

What do you think about LIQUID network hacker who kept 15% of (4000 BTC) as bounty
Anonymous voting

what you think about liquid hacker who kept 15 % of (4000 BTC) stolen BTC as bounty
Anonymous voting