fa
Feedback
5 266
مشترکین
+124 ساعت
-67 روز
-5130 روز

در حال بارگیری داده...

جذب مشترکین
اوت '26
اوت '26
+49
در 4 کانال‌ها
ژوئیه '26
+160
در 3 کانال‌ها
Get PRO
ژوئن '26
+142
در 5 کانال‌ها
Get PRO
مه '26
+73
در 2 کانال‌ها
Get PRO
آوریل '26
+93
در 1 کانال‌ها
Get PRO
مارس '26
+77
در 2 کانال‌ها
Get PRO
فوریه '26
+88
در 3 کانال‌ها
Get PRO
ژانویه '26
+93
در 2 کانال‌ها
Get PRO
دسامبر '25
+326
در 4 کانال‌ها
Get PRO
نوامبر '25
+130
در 2 کانال‌ها
Get PRO
اکتبر '25
+106
در 2 کانال‌ها
Get PRO
سپتامبر '25
+147
در 5 کانال‌ها
Get PRO
اوت '25
+67
در 5 کانال‌ها
Get PRO
ژوئیه '25
+91
در 4 کانال‌ها
Get PRO
ژوئن '25
+103
در 3 کانال‌ها
Get PRO
مه '25
+52
در 6 کانال‌ها
Get PRO
آوریل '25
+99
در 5 کانال‌ها
Get PRO
مارس '25
+107
در 6 کانال‌ها
Get PRO
فوریه '25
+188
در 9 کانال‌ها
Get PRO
ژانویه '25
+73
در 3 کانال‌ها
Get PRO
دسامبر '24
+163
در 2 کانال‌ها
Get PRO
نوامبر '24
+196
در 2 کانال‌ها
Get PRO
اکتبر '24
+264
در 8 کانال‌ها
Get PRO
سپتامبر '24
+225
در 0 کانال‌ها
Get PRO
اوت '24
+153
در 0 کانال‌ها
Get PRO
ژوئیه '24
+101
در 0 کانال‌ها
Get PRO
ژوئن '24
+63
در 0 کانال‌ها
Get PRO
مه '24
+109
در 4 کانال‌ها
Get PRO
آوریل '24
+170
در 1 کانال‌ها
Get PRO
مارس '24
+215
در 1 کانال‌ها
Get PRO
فوریه '24
+142
در 0 کانال‌ها
Get PRO
ژانویه '24
+200
در 0 کانال‌ها
Get PRO
دسامبر '23
+165
در 0 کانال‌ها
Get PRO
نوامبر '23
+523
در 1 کانال‌ها
Get PRO
اکتبر '23
+205
در 0 کانال‌ها
Get PRO
سپتامبر '23
+307
در 0 کانال‌ها
Get PRO
اوت '23
+245
در 0 کانال‌ها
Get PRO
ژوئیه '23
+893
در 0 کانال‌ها
Get PRO
ژوئن '23
+1 603
در 0 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
27 اوت0
26 اوت+4
25 اوت+2
24 اوت+3
23 اوت+3
22 اوت+2
21 اوت0
20 اوت+3
19 اوت+1
18 اوت+1
17 اوت+3
16 اوت+1
15 اوت0
14 اوت+1
13 اوت+2
12 اوت+2
11 اوت+3
10 اوت+1
09 اوت+2
08 اوت+4
07 اوت+1
06 اوت+1
05 اوت+1
04 اوت0
03 اوت0
02 اوت+4
01 اوت+4
پست‌های کانال
- The Ultimate Web3 Security Checklist by Digibastion. A comprehensive checklist including personal, devops, mobile, browser, and other security topics. -link - A deep dive into DPRK IT worker operation after a compromise of one of their machines - link - Meet Gerardo Salgado aka Tammy Hans (the old one) a DPRK IT Worker who infected himself with Contagious Interview malware a thread by Narcass3. - link @EthSecurity1

2
$Enjin hacked for $162K RootCause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol. @EthSecurity1
742
3
https://x.com/0xyashish/status/2092172553695662566?s=61 @EthSecurity1
386
4
- A manipulator used a sandwich attack on Pendle’s YT to depress PT-reUSD price by ~3%, triggering $36M in Morpho liquidations across 19 borrowers and seizing 38.64M PT with zero bad debt. - The attacker/liquidator captured ~$1.09M profit via a non-atomic strategy requiring ~$6.5M capital to deposit seized PT as collateral, borrow stables, and unwind gradually, bypassing atomic MEV competition that only yielded builders ~4.2 ETH. - On-chain links show synchronized funding and withdrawals from the same Gate.io hot wallet to both the YT manipulation address and main liquidation strategy, though evidence remains circumstantial. @EthSecurity1
656
5
Cosmos recommend that if you run a public chain that uses a Cosmos EVM version less than v0.6.2 and v0.7.2, you should immediately halt the blockchain and upgrade it to include the patches in those releases. @EthSecurity1
813
6
- FACADE High-Precision Insider Threat Detection Using Contrastive Learning. -link - Deflationary Token Risks, ERC4626 Override Gaps, and Rust Shift Overflows -link @EthSecurity1
488
7
there is another Idea about Arrakis incident: The attacker stole the unclaimed LP fees with a "sandwich" attack The mint and redeem functions both require the input and output to be proportional to the deposited LP + unclaimed fees + idle balance in the two tokens. That means, if the pool holds x:y of token A:token B (in the LP position, plus fees and idle balance), your input/output will also be proportional to x:y. Thus, you cannot manipulate the price to fool the vault when burn() is called, the fees are collected. These fees are then compounded into the pool. This creates the vulnerability. The attacker then performs: swap1 → mint → swap2 → burn → swap3. After swap1, and later when burn() is called, the collected fees add more liquidity back to the LP, so when swapping back in swap3 @EthSecurity1
777
8
If you want to go GOD LEVEL in SYSTEM DESIGN, learn these concepts NOW: 1. Caching 2. API Design 3. Load Balancing 4. Rate Limiting 5. Scalability 6. Fault Tolerance 7. Authentication 8. Message Queues 9. Data Modelling 10. Object Storage 11. Database Sharding & Partitioning 12. Database Replication 13. CAP Theorem 14. Consistent Hashing 15. Serverless 16. Microservices 17. Event Driven Architecture 18. Service Discovery 19. API Security 20. Multi Agent Architecture @EthSecurity1
397
9
Every Ledger running the Ethereum app is vulnerable to signature substitution A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original While the review UI was pending, the APDU loop kept accepting commands. A second P1_FIRST in store mode reset the global signing context to a new tx without opening a new review. The approval callback signed whatever was in memory when the user tapped OK. @EthSecurity1
727
10
The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was hacked for 2.94 WETH via a Uniswap V3 spot-price manipulation. RootCause: the vault's mint() and burn() value its Uniswap V3 position off the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. The vault does have a TWAP check — but it only guards the manager's rebalance() swap, never mint/burn. @EthSecurity1
872
11
Term finance hacked for $8.5M RooCause: governance attack through Dao @EthSecurity1
875
12
$sand token minted 14.9B across 2 addresses: 0xAbE0...4D22 & 0x638C...F296 @EthSecurity1
906
13
- Secure Contract Development in TON: Top 9 Pitfalls in Tact & FunC -link - The Real Minimal Proxy - Powered by EIP-7702 - link - Understanding Auto Market Makers for bug bounty - link @EthSecurity1
983
14
- Developer Arrested Over Tornado Cash Research. Federico Carrone was released after 24 hours following an overwhelming international intervention from UAE, UK, US, all around European Union, Argentina and the Catholic Church. A good ending to what could have been a Tigran Gambaryan style incident. - Oracle Security Workshop - link - Secure Your ZK Code: Best Practices for Devs & Auditors - link @EthSecurity1
1 240
15
Maya protocol hacked for $1.3M ClaudeAI report: https://claude.ai/code/artifact/469af51b-8f6c-44f0-a213-f7520c9f4b2d @EthSecurity1
998
16
Fox Market on BNB Chain hacked for $120K RootCause: through a same-transaction spot-price manipulation bug in its bond mint p
Fox Market on BNB Chain hacked for $120K RootCause: through a same-transaction spot-price manipulation bug in its bond mint path. The attacker used massive flash liquidity to push the FOX/USDT pool, minted bonds against a stale pre-swap price, dumped the unlocked referral @EthSecurity1
977
17
- Anchor - a framework providing several convenient developer tools for writing Solana programs by Solana Foundation. - A Solana Static Analyser & Reverse Engineering tool. - link - hashcat v7.0.0 release including support for MetaMask and various wallet cracking. @EthSecurity1
1 032
18
Safepal Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw." @EthSecurity1
706
19
How to Setup an Ethereum Node Part 1 and Part 2 Inside Ethereum’s Engine: How the Execution Layer Actually Works - link  @EthSecurity1
1 230
20
- How to protect yourself from Google Forms scams -link - My Smart Contract Auditing Mental Model - Not a checklist! - link - Compressed NFTs on Solana - link - ape-safe - Account plugin for the Safe multisig wallet (previously known as Gnosis Safe) for the Ape Framework. @EthSecurity1
1 081