es
Feedback
5 318
Suscriptores
+124 horas
+177 días
+6430 días
Archivo de publicaciones
seems @secondfiapp hacked for 130 millions ADA @EthSecurity1

Seems @origin_trail’s StakingStorage contract on Base was hacked~ 27M $TRAC Rootcause: A flaw in the owner verification logic
+1
Seems @origin_trail’s StakingStorage contract on Base was hacked~ 27M $TRAC Rootcause: A flaw in the owner verification logic of the Hub contract. This allowed the attacker to call Hub.0x46e46a09() and register their malicious contract (0xAa86) into the authorized contracts list. The attacker then manipulated storage in StakingStorage to drain the funds. Attacker address: 0xbB31f31480Cf4BcF70d0E1ff0dF7f09218F8D2A3 Exploit transactions: •0x18ccaa7baba166fa45bbd75cc01d58f60f6b6ac2ad1425a6d93295ccff096533 •0xb8e2a8f2b7cd436c22b3eb05d307aee3e561185a2687e96187068b2ef28c1f7e @EthSecurity1

- Cryptominers’ Anatomy: Shutting Down Mining Botnets - link -Trust, But Measure: A Friendly Intro to TEEs with Intel TDX - link @EthSecurity1

Taiko hacked for ~$2M @EthSecurity1

Repost from Defimon Alerts
💌 Onchain message: Transaction 📤 From: 0x3dc6cda5967e0df81b3eb93cf88ad62006ffa52a 📥 To: 0x71d4416a7a85e08a5fe7227ca3b44fc639e94e97 🌎 Network: mainnet 💬 Message:
I see karma has caught up with JaredFromSubway. This bot drained 50 ETH from my wallet. Whoever has these funds should have them returned to everyone who has been drained.

JaredFromSubway's MEV bot hacked. Rootcause: Attacker deploys fake wrapper tokens (fWETH, fUSDC, fUSDT) along with fake liqui
JaredFromSubway's MEV bot hacked. Rootcause: Attacker deploys fake wrapper tokens (fWETH, fUSDC, fUSDT) along with fake liquidity pools designed to look profitable The bot spots the "opportunity" and does what it's programmed to do, approving attacker-controlled helper contracts as spenders During early tests, those approvals get used immediately, so nothing appears suspicious In later transactions, the bot grants approvals that are never consumed or revoked, leaving the attacker with unlimited spending power Once enough approvals are collected, the attacker executes the final drain WETH, USDC, and USDT are pulled directly from the bot contract via transferFrom and sent to the attacker's wallet (0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0) in a transaction The bot approved more than 92 WETH to one of the attacker's helper contracts, and that approval simply remained active until the funds were drained. *jared sorry for your loss @EthSecurity1

- Unphishable - a series of educational challenges to help you understand and identify common Web3 phishing attacks - - Catching Phishing Ethereum Smart Contracts leveraging EVM Opcodes - link @EthSecurity1

Michael Kong, Andre Cronje, and David Richardson are resigning from the Sonic Labs board . Note: sonic funded hundred millions @EthSecurity1

seems @namada MASP hacked ~$600K ATOM, USDC, OSMO, TIA, NYM all swept from the shielded pool (over IBC) - Privacy chain + stale indexer = invisible hack @EthSecurity1

@mySwapxyz (Starknet) Hacked ~$305K Rootcause : Attacker deployed a fake "EVIL" token to manipulate the pool accounting and drain the shared vault: 137.96 ETH, 45K USDC, 19.9K USDT, 230K STRK voyager.online/contract/0x029f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518 https://starkscan.co/contract/0x29f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518 @EthSecurity1

- Advanced Foundry Cheatcodes Series Part 1 Part 2 Part 3 Part 4 - OpenSense - Starknet Cairo's Security - link - DPRK Civil Engineer Fake Profile Process. Actual DPRK instructional video on how to create their civil engineering profile(s). And here is a sample session with a DPRK Licensed Civil Engineer. @EthSecurity1

seems Aztec hacked twice $2.1M @EthSecurity1

- Blockchain Forensics: Attribution Techniques and the Role of OSINT. -link - Abusing Developer Trust in Cursor and VS Code Remote Development - link - Safer cold storage on Ethereum - link @EthSecurity1

- Blockchain Forensics: Attribution Techniques and the Role of OSINT. -link - Abusing Developer Trust in Cursor and VS Code Remote Development -link

- From PowerShell to Payload: Darktrace’s Detection of a Novel Cryptomining Malware - link - How to secure $70 billion in DeFi: Aave's approach to Web3 security - link - The Dark Side of Upgrades: Uncovering Security Risks in Smart Contract Upgrades. - link @EthSecurity1

Aztec Router exploit for $2.1M Rootcause: deposit transactions were committed to the rollup state root, while the correspondi
+3
Aztec Router exploit for $2.1M Rootcause: deposit transactions were committed to the rollup state root, while the corresponding fund-transfer obligation could be bypassed. https://etherscan.io/tx/0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1 @EthSecurity1

Aztec Router exploit root cause: deposit transactions were committed to the rollup state root, while the corresponding fund-t
+3
Aztec Router exploit root cause: deposit transactions were committed to the rollup state root, while the corresponding fund-transfer obligation could be bypassed. @EthSecurity1

- Coinbase thinks vibe-coding 50% of its platform is a good idea. - link - Paradigm’s Reth Client Bug Briefly Freezes Ethereum Mainnet Nodes. - link - Phished Founder, Liquidated Thief by Rekt. A rollercoaster of a $13M theft and recovery through a swift governance action by Venus Protocol. - link @EthSecurity1