Defimon Alerts
Ir al canal en Telegram
⚠️ DeFi security alerts by @DecurityHQ 💎 Instant alerts @defimon_subscription_bot defimon.xyz
Mostrar másEl país no está especificadoCriptomonedas16 265
4 416
Suscriptores
+224 horas
+257 días
+7530 días
Carga de datos en curso...
Canales Similares
Sin datos
¿Algún problema? Por favor, actualice la página o contacte a nuestro gerente de soporte.
Nube de Etiquetas
Menciones Entrantes y Salientes
---
---
---
---
---
---
Atraer Suscriptores
julio '26
julio '26
+82
en 0 canales
junio '26
+139
en 3 canales
Get PRO
mayo '26
+234
en 1 canales
Get PRO
abril '26
+261
en 0 canales
Get PRO
marzo '26
+250
en 0 canales
Get PRO
febrero '26
+176
en 1 canales
Get PRO
enero '26
+434
en 1 canales
Get PRO
diciembre '25
+357
en 4 canales
Get PRO
noviembre '25
+368
en 0 canales
Get PRO
octubre '25
+541
en 3 canales
Get PRO
septiembre '25
+419
en 6 canales
Get PRO
agosto '25
+126
en 1 canales
Get PRO
julio '25
+172
en 3 canales
Get PRO
junio '25
+203
en 0 canales
Get PRO
mayo '25
+176
en 3 canales
Get PRO
abril '25
+221
en 3 canales
Get PRO
marzo '25
+248
en 1 canales
Get PRO
febrero '25
+724
en 0 canales
Get PRO
enero '250
en 0 canales
Get PRO
diciembre '24
+19
en 1 canales
| Fecha | Crecimiento de Suscriptores | Menciones | Canales | |
| 20 julio | +5 | |||
| 19 julio | +3 | |||
| 18 julio | +9 | |||
| 17 julio | +13 | |||
| 16 julio | +5 | |||
| 15 julio | +5 | |||
| 14 julio | +4 | |||
| 13 julio | +2 | |||
| 12 julio | +2 | |||
| 11 julio | +4 | |||
| 10 julio | +2 | |||
| 09 julio | +3 | |||
| 08 julio | +4 | |||
| 07 julio | +1 | |||
| 06 julio | +1 | |||
| 05 julio | +1 | |||
| 04 julio | +6 | |||
| 03 julio | +1 | |||
| 02 julio | +5 | |||
| 01 julio | +6 |
Publicaciones del Canal
💌 Onchain message:
This is the Allbridge team. We have identified this wallet as connected to the July 19, 2026 Allbridge Core exploit ($1.65M+). We are formally offering a white-hat agreement: return 80% of the funds to this address within 48 hours. In exchange, you may keep the remaining 20% as a bounty, and we will not pursue further legal action or share identifying information with law enforcement. If we do not hear from you, we will proceed with full on-chain forensic tracing, exchange notifications, and law enforcement referral.📤 From: 0xabcf3f27aa91abda8865125c43c095bb9cf9732d 📥 To: 0x651591b68a9c9650fb23f642162353306281ffde 🌎 Network: mainnet Etherscan
| 2 | 💌 Onchain message:
SECURITY ALERT (whitehat): BarnBridge SmartYield CompoundProvider 0xdaa037f99d168b552c0c61b7fb64cf7819d78310 has a hijacked controller. Your USDC allowance to it is still live and (~25 019 USDC) drainable. Protect your funds, REVOKE ALL YOUR ALLOWANCES RIGHT NOW nano XBankStaking.sol! This is a free warning - no funds, links or bounty requested. @beacon302 aka DK27ss
📤 From: 0x622b4c078f1175c9aee10e9e79572f19cfedfeaf
📥 To: 0x71f12a5b0e60d2ff8a87fd34e7dcff3c10c914b0
🌎 Network: mainnet
Etherscan | 15 |
| 3 | 💌 Onchain message:
SECURITY ALERT (whitehat): BarnBridge SmartYield CompoundProvider 0xdaa037f99d168b552c0c61b7fb64cf7819d78310 has a hijacked controller. Your USDC allowance to it is still live and (~25 019 USDC) drainable. Protect your funds, REVOKE ALL YOUR ALLOWANCES RIGHT NOW nano XBankStaking.sol! This is a free warning - no funds, links or bounty requested.
📤 From: 0x622b4c078f1175c9aee10e9e79572f19cfedfeaf
📥 To: 0x71f12a5b0e60d2ff8a87fd34e7dcff3c10c914b0
🌎 Network: mainnet
Etherscan | 7 |
| 4 | 💌 Onchain message:
Hi — I’m the whitehat who found and escalated the old BarnBridge proposal #15 approval risk that affected your wallet.
Your address appeared to be the largest at-risk wallet, with roughly $3.2M exposed. I couldn’t reach you directly, so I escalated through SEAL 911. My understanding is that the warning reached you and the funds were protected.
I’m very glad the funds were saved. I’m reaching out now to ask whether you would consider a voluntary bounty/recognition for the investigation and urgent escalation work.
You can verify my role with SEAL 911. I’m not asking you to click links or send funds blindly.
If open to discussing, please reply here or contact me on X: @onechesss
📤 From: 0xda9d65086a986624cbf71989118938f0cf9a0c68
📥 To: 0xae911067fed8f7adf93ee5c1a14757f2d06b7dd0
🌎 Network: mainnet
Etherscan | 398 |
| 5 | 💌 Onchain message:
URGENT RETURN REQUEST
The 145,965.658533 USDC received by this address was transferred without my authorization from:
0x66666f3364cf650699299f08e37b5d5cedae6d29
Arbitrum transaction:
0xb611485b646d1c0b9c30d5266d724334c2479b10d235c459e3e6bc48828058a6
The incident and both addresses have been reported to Hyperliquid, Circle and blockchain security teams. The funds are being traced, and preservation and freezing requests are being prepared for exchanges, bridges and law enforcement.
Please return the full amount to my NEW secure address:
0xafc9e1ef02df2c99447272f1619689ca1db02c59
If this was intended as a white-hat action, contact me through Blockscan Chat. A reasonable recovery bounty can be discussed only after the funds are safely returned.
I will not make any advance payment or disclose any private information.
📤 From: 0xefdcbf40d383c479ae807a4a405c5ad45ab4ce13
📥 To: 0x1eb488919fcf5e6f658725370e2f635c3fc47f73
🌎 Network: arbitrum
Etherscan | 408 |
| 6 | 💌 Onchain message:
This address received approximately 145,965.658038 USDT stolen from my wallet in transaction [TX HASH]. All evidence has been preserved, and tracing and preservation requests are being submitted to law enforcement and relevant exchanges. Please return the full amount to this new secure address: [0xafc9e1ef02df2c99447272f1619689ca1db02c59]. If this was an accidental or white-hat action, reply through Blockscan Chat.
📤 From: 0xefdcbf40d383c479ae807a4a405c5ad45ab4ce13
📥 To: 0x1eb488919fcf5e6f658725370e2f635c3fc47f73
🌎 Network: arbitrum
Etherscan | 415 |
| 7 | 🚨 BSC NFT Auction Marketplace - Loss ~$8.3K (2026-07-19)
Network: BNB Chain
Type: Logic Error (double-settlement / delist refund)
An NFT auction/marketplace proxy (0x46c9…1e09, impl 0x3735…044d, unverified) allows a listing to be both settled and cancelled. The attacker minted a throwaway NFT, listed it, then in a single flash-loaned tx (Moolah/Lista WBNB) called buyNow→completeAuction — which pays the seller from the sent value — and immediately delist, which refunds the same ~2.2176 BNB payment from the contract's escrow pool. Because completeAuction never clears the sale's paid/bid state, delist double-pays, draining ~4.4 BNB of other users' escrowed funds. Attacker was both seller and buyer, netting ~2.173 BNB (~$4.06K) profit; marketplace lost ~4.44 BNB (~$8.3K).
TX: https://bscscan.com/tx/0x79dbf5d676c1f1d89cabc046743746b828fc0fa4ed70854c8b77335cd1c194df
Attacker: https://bscscan.com/address/0xeaaf475db34fb66f098e51cbf0eeeff76f496974
Victim: https://bscscan.com/address/0x46c958a169b9f2688e126080c4ec422956621e09 (unverified impl)
@defimon_subscription_bot | 548 |
| 8 | 🚨 RWT Token - Loss ~$118K (2026-07-19)
Token: $RWT @ $0.00144
Network: BNB Chain
Type: Logic Error (deflationary burn-from-pair price manipulation + Flash Loan)
An unverified "sell" contract (0x8812) exposes an unprotected sell() that, each call, swaps RWT→USDT into the RWT/USDT PancakePair, adds liquidity, then burns ~72M RWT directly out of the pair's reserves (RWT.burn is onlyOwner and the sell contract holds that role) and sync()s. Repeatedly burning the pool's RWT collapses its reserve and inflates RWT's USDT price, letting the caller extract USDT from the LP far above fair value. The attacker flash-loaned 1M USDT and looped the routine 18×, draining the PancakePair (−158.6K USDT / −110M RWT) and netting ~118K USDT.
TX: https://bscscan.com/tx/0x22300140e7c44899c2602382a6e7a4a34a70f47f9736721744bc6434c07171dc
Attacker: https://bscscan.com/address/0x84dd3a5d4de44c8ad0ce032beab8bc3f01d1dcf7
Victim: https://bscscan.com/address/0xc1c2ef25372f12ce18d35044446064b720c4aa27
@defimon_subscription_bot | 631 |
| 9 | 💌 Onchain message:
Hello Phisher.You directly stole my bounty secret note.Please return the funds.Thank you
📤 From: 0x61e6301614178a2ca21bfa0fbb30aba06acc2d1c
📥 To: 0x6659659b8518f53f7a8d9b73ca4f4bd4e4ae824f
🌎 Network: mainnet
Etherscan | 681 |
| 10 | 🚨 perp.com - Loss $3,062 (2026-07-16)
Token: $vETH (Perpetual Protocol)
Network: Optimism
Type: Access Control / Missing Permission Check
Perpetual Protocol's OrderBook exposes updateFundingGrowthAndLiquidityCoefficientInFundingPayment() as an unprotected external function (OrderBook.sol:232) — it lacks the _requireOnlyClearingHouse() guard used by its sibling functions. The attacker opened a tiny liquidity order, then called it directly with a fabricated funding growth (twPremiumX96 = 1e70), corrupting their order's cached funding-growth state. On settleAllFunding the corrupted cache produced a bogus funding payment (~1.46e36), inflating the account's realized PnL, which was then withdrawn as USDC — draining the vaults of ~$3,062.
TX: https://optimistic.etherscan.io/tx/0xb0a8a3cc76fb17bf965ab1dee3b76b62f79ca72def31e12f8ad8b1711625df08
Attacker: https://optimistic.etherscan.io/address/0x957c6cF5E0F69597dB7A8065c94af1A48aBCA47d
Victim: https://optimistic.etherscan.io/address/0x772f48f073c1f328c264619fc3bba28e3efdefb0
X: https://x.com/perpprotocol
@defimon_subscription_bot | 695 |
| 11 | 💌 Onchain message:
Please, I beg you. If you cannot return everything, please just return the 445 LINK to my new address. You can keep the rest as a bounty. This was my life savings. I am begging for your mercy. Thank you.
📤 From: 0x8d9c6dc7d3d619b04ebd14e5767812b1edcb3eca
📥 To: 0xba5f4cde46fa8d2e6dc83acca6463d4980eb1e4b
🌎 Network: mainnet
Etherscan | 741 |
| 12 | 💌 Onchain message:
Hello. This is my life savings. Please keep 10% bounty and return 90% to this address. Tahnk you.
📤 From: 0x8d9c6dc7d3d619b04ebd14e5767812b1edcb3eca
📥 To: 0xba5f4cde46fa8d2e6dc83acca6463d4980eb1e4b
🌎 Network: mainnet
Etherscan | 834 |
| 13 | More than 2 months after $5.8M Trusted Volumes exploit one of the attackers returned 1,122 ETH ($2M):
https://etherscan.io/tx/0x2406411a50b537d5eb3a1a488b4ac2e4f8cf6f331147fa81fedf34851b793f0a | 824 |
| 14 | 💌 Onchain message:
We have finalized the negotiations with the original exploiter: https://etherscan.io/tx/0x06a4ad1eaa15d7796c0aaead610ea1a90c2db9553fbd39aaf12120fda6e108b9. They returned the funds and received their bug bounty. Contact us at tvbugbounty@proton.me to negotiate.
📤 From: 0x1ef9bfb1e7480c01d3d00e9bca5f29625c6c4806
📥 To: 0xfa4f52df02e5f3563bc4569a6b43bb6aca617e07
🌎 Network: mainnet
Etherscan | 759 |
| 15 | 🚨 bunker.finance - Loss ~$5.6K (2026-07-16)
Token: $bETH (Bunker Ether, price unavailable)
Network: Ethereum
Type: Oracle Manipulation / Collateral Valuation Flaw (NFT lending)
Bunker is a CryptoPunk-collateralized Compound fork. The attacker flash-loaned 1 PUNK from the NFTX vault, redeemed CryptoPunk #1893, and deposited it as collateral (CNft.mint) into Bunker's NFT lending markets. The CNftPriceOracle values the NFT via the NFTX vault's Uniswap floor price, massively over-pricing the single punk. Against this inflated collateral the attacker drained the markets' liquidity — borrowing 1.59 ETH (bETH) + 1,297 USDC in comptroller 0x01a9…0a83, then 1.1 ETH + 50 USDC in comptroller 0x6bc8…4db5 — then withdrew the same punk (CNft.redeem passed the liquidity check) and returned it to NFTX to repay the flash loan, leaving the borrows unbacked. Net ~$5.6K extracted (2.69 ETH + ~1.35K USDC).
TX: https://etherscan.io/tx/0x5b9dc05c2636da600a22d13d5a6a01de7ededfec0227df56a5ed1a61e007457a
Attacker: https://etherscan.io/address/0xeaaf475db34fb66f098e51cbf0eeeff76f496974
Victim: https://etherscan.io/address/0x2e35bd135942dd0b303444bebdce097d81b9e0f3
X: https://x.com/bunker_finance
@defimon_subscription_bot | 719 |
| 16 | 🚨 CrowdRingCircle (众环CRC) - Loss ~$201K (2026-07-16)
Token: $CRC @ $0.005816
Network: BNB Chain
Type: Logic Error (Reserve Manipulation via burn-from-pair + sync)
The CRC token's `_update` override contains a "sell destroy" mechanism: on every transfer to a DEX pair (`isDexPair[to] && sellDestroyEnabled`), it burns `amount` directly from the pair's own balance via `_safeDeductBalance(to, amount)` and then calls `IUniswapV2Pair(to).sync()` (CrowdRingCircle.sol:185-191). By repeatedly pushing CRC into the PancakeSwap CRC/USDT LP, the attacker forced the pair to burn its own CRC reserves and re-sync, skewing the reserve ratio and inflating CRC's price. Flash-funded via PancakeSwap Infinity Vault + Venus + Aave-style borrow, the attacker then swapped a small amount of CRC for the USDT side of the pool at the manipulated rate, draining it. The LP pair lost ~209K USDT and ~35.86M CRC; the attacker EOA netted ~$201K USDT.
TX: https://bscscan.com/tx/0xeaef22325e02ac65a8e1f2e1a3a43f7b7ac8d2323ce6f698a90813e77017c834
Attacker: https://bscscan.com/address/0x34579ea92a07a88f5505dfaa4d99ab94b2784087
Victim: https://bscscan.com/address/0xd8799a644850c065388c22df4ee0c28472922526 (CRC/USDT Cake-LP)
Token: https://bscscan.com/address/0x8581433150f2c48ff2efe5a22b17c7d405054509
@defimon_subscription_bot | 690 |
| 17 | We are proud to partner with Hexens on Glider Monitor! This is a unique integration that not only detects but also assesses your exposure to the DeFi incidents:
https://hexens.io/solutions/glider-monitor | 725 |
| 18 | 💌 Onchain message:
For settlement finalising and continue bug bounty discussion we require you to return 1,122 ETH to our address - 0xb6f28ed0f919a12822fe78f6d610e5e09a6fe450
📤 From: 0x1ef9bfb1e7480c01d3d00e9bca5f29625c6c4806
📥 To: 0xc3ebddea4f69df717a8f5c89e7cf20c1c0389100
🌎 Network: mainnet
Etherscan | 725 |
| 19 | 💎 To subscribers:
We post all verified alerts to this channel. Some may be big hacks like yesterday's Ostium $20M loss and some are small sub-10k drains.
Since it's not our job to decide which alerts are useful to a particular user, we post all of them.
If you need to respond to certain alerts and deprioritize others, the best way is to do this is to subscribe to our Websocket API and receive full raw feed of all our alerts (including non-verified) in real time.
The cost is only $200/month, ~20 times cheaper than Hypernative or other providers!
What's included:
— Defimon Signals Telegram subscription,
— API access to the signals (confirmed attacks)
— API access to all raw alerts (instant events before LLM verification)
— 1 key to all 8 supported chains.
Subscribe on the website https://defimon.xyz/subscribe or using the bot @defimon_subscription_bot | 746 |
| 20 | https://arbiscan.io/address/0x321Df194646029e7A6193Ea05573d4B9c398bfD9 | 784 |
