EthSecurity
Открыть в Telegram
5 266
Подписчики
+124 часа
-67 дней
-5130 день
Загрузка данных...
Похожие каналы
Облако тегов
Входящие и исходящие упоминания
---
---
---
---
---
---
Привлечение подписчиков
август '26
август '26
+49
в 4 каналах
июль '26
+160
в 3 каналах
Get PRO
июнь '26
+142
в 5 каналах
Get PRO
май '26
+73
в 2 каналах
Get PRO
апрель '26
+93
в 1 каналах
Get PRO
март '26
+77
в 2 каналах
Get PRO
февраль '26
+88
в 3 каналах
Get PRO
январь '26
+93
в 2 каналах
Get PRO
декабрь '25
+326
в 4 каналах
Get PRO
ноябрь '25
+130
в 2 каналах
Get PRO
октябрь '25
+106
в 2 каналах
Get PRO
сентябрь '25
+147
в 5 каналах
Get PRO
август '25
+67
в 5 каналах
Get PRO
июль '25
+91
в 4 каналах
Get PRO
июнь '25
+103
в 3 каналах
Get PRO
май '25
+52
в 6 каналах
Get PRO
апрель '25
+99
в 5 каналах
Get PRO
март '25
+107
в 6 каналах
Get PRO
февраль '25
+188
в 9 каналах
Get PRO
январь '25
+73
в 3 каналах
Get PRO
декабрь '24
+163
в 2 каналах
Get PRO
ноябрь '24
+196
в 2 каналах
Get PRO
октябрь '24
+264
в 8 каналах
Get PRO
сентябрь '24
+225
в 0 каналах
Get PRO
август '24
+153
в 0 каналах
Get PRO
июль '24
+101
в 0 каналах
Get PRO
июнь '24
+63
в 0 каналах
Get PRO
май '24
+109
в 4 каналах
Get PRO
апрель '24
+170
в 1 каналах
Get PRO
март '24
+215
в 1 каналах
Get PRO
февраль '24
+142
в 0 каналах
Get PRO
январь '24
+200
в 0 каналах
Get PRO
декабрь '23
+165
в 0 каналах
Get PRO
ноябрь '23
+523
в 1 каналах
Get PRO
октябрь '23
+205
в 0 каналах
Get PRO
сентябрь '23
+307
в 0 каналах
Get PRO
август '23
+245
в 0 каналах
Get PRO
июль '23
+893
в 0 каналах
Get PRO
июнь '23
+1 603
в 0 каналах
| Дата | Привлечение подписчиков | Упоминания | Каналы | |
| 27 августа | 0 | |||
| 26 августа | +4 | |||
| 25 августа | +2 | |||
| 24 августа | +3 | |||
| 23 августа | +3 | |||
| 22 августа | +2 | |||
| 21 августа | 0 | |||
| 20 августа | +3 | |||
| 19 августа | +1 | |||
| 18 августа | +1 | |||
| 17 августа | +3 | |||
| 16 августа | +1 | |||
| 15 августа | 0 | |||
| 14 августа | +1 | |||
| 13 августа | +2 | |||
| 12 августа | +2 | |||
| 11 августа | +3 | |||
| 10 августа | +1 | |||
| 09 августа | +2 | |||
| 08 августа | +4 | |||
| 07 августа | +1 | |||
| 06 августа | +1 | |||
| 05 августа | +1 | |||
| 04 августа | 0 | |||
| 03 августа | 0 | |||
| 02 августа | +4 | |||
| 01 августа | +4 |
Посты канала
- The Ultimate Web3 Security Checklist by Digibastion. A comprehensive checklist including personal, devops, mobile, browser, and other security topics. -link
- A deep dive into DPRK IT worker operation after a compromise of one of their machines - link
- Meet Gerardo Salgado aka Tammy Hans (the old one) a DPRK IT Worker who infected himself with Contagious Interview malware a thread by Narcass3. - link
@EthSecurity1
| 2 | $Enjin hacked for $162K
RootCause: The protocol allows adapters with different storage layouts to execute in the storage context of the Managed Delegate Proxy via DELEGATECALL. However, the public initialize(uint256) function of a registered adapter writes to the adapter's slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker can exploit this storage slot collision by invoking the adapter's initialize(uint256) through DELEGATECALL, causing their own address to be written into the proxy's pendingManager slot. They can then simply call acceptManager() to complete the privilege takeover and gain managerial control of the protocol.
@EthSecurity1 | 742 |
| 3 | https://x.com/0xyashish/status/2092172553695662566?s=61
@EthSecurity1 | 386 |
| 4 | - A manipulator used a sandwich attack on Pendle’s YT to depress PT-reUSD price by ~3%, triggering $36M in Morpho liquidations across 19 borrowers and seizing 38.64M PT with zero bad debt.
- The attacker/liquidator captured ~$1.09M profit via a non-atomic strategy requiring ~$6.5M capital to deposit seized PT as collateral, borrow stables, and unwind gradually, bypassing atomic MEV competition that only yielded builders ~4.2 ETH.
- On-chain links show synchronized funding and withdrawals from the same Gate.io hot wallet to both the YT manipulation address and main liquidation strategy, though evidence remains circumstantial.
@EthSecurity1 | 656 |
| 5 | Cosmos recommend that if you run a public chain that uses a Cosmos EVM version less than v0.6.2 and v0.7.2, you should immediately halt the blockchain and upgrade it to include the patches in those releases.
@EthSecurity1 | 813 |
| 6 | - FACADE High-Precision Insider Threat Detection Using Contrastive Learning. -link
- Deflationary Token Risks, ERC4626 Override Gaps, and Rust Shift Overflows -link
@EthSecurity1 | 488 |
| 7 | there is another Idea about Arrakis incident:
The attacker stole the unclaimed LP fees with a "sandwich" attack
The mint and redeem functions both require the input and output to be proportional to the deposited LP + unclaimed fees + idle balance in the two tokens. That means, if the pool holds x:y of token A:token B (in the LP position, plus fees and idle balance), your input/output will also be proportional to x:y. Thus, you cannot manipulate the price to fool the vault
when burn() is called, the fees are collected. These fees are then compounded into the pool. This creates the vulnerability.
The attacker then performs: swap1 → mint → swap2 → burn → swap3. After swap1, and later when burn() is called, the collected fees add more liquidity back to the LP, so when swapping back in swap3
@EthSecurity1 | 777 |
| 8 | If you want to go GOD LEVEL in SYSTEM DESIGN, learn these concepts NOW:
1. Caching
2. API Design
3. Load Balancing
4. Rate Limiting
5. Scalability
6. Fault Tolerance
7. Authentication
8. Message Queues
9. Data Modelling
10. Object Storage
11. Database Sharding & Partitioning
12. Database Replication
13. CAP Theorem
14. Consistent Hashing
15. Serverless
16. Microservices
17. Event Driven Architecture
18. Service Discovery
19. API Security
20. Multi Agent Architecture
@EthSecurity1 | 397 |
| 9 | Every Ledger running the Ethereum app is vulnerable to signature substitution
A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original
While the review UI was pending, the APDU loop kept accepting commands. A second P1_FIRST in store mode reset the global signing context to a new tx without opening a new review. The approval callback signed whatever was in memory when the user tapped OK.
@EthSecurity1 | 727 |
| 10 | The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was hacked for 2.94 WETH via a Uniswap V3 spot-price manipulation.
RootCause: the vault's mint() and burn() value its Uniswap V3 position off the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. The vault does have a TWAP check — but it only guards the manager's rebalance() swap, never mint/burn.
@EthSecurity1 | 872 |
| 11 | Term finance hacked for $8.5M
RooCause: governance attack through Dao
@EthSecurity1 | 875 |
| 12 | $sand token minted 14.9B across 2 addresses: 0xAbE0...4D22 & 0x638C...F296
@EthSecurity1 | 906 |
| 13 | - Secure Contract Development in TON: Top 9 Pitfalls in Tact & FunC -link
- The Real Minimal Proxy - Powered by EIP-7702 - link
- Understanding Auto Market Makers for bug bounty - link
@EthSecurity1 | 983 |
| 14 | - Developer Arrested Over Tornado Cash Research. Federico Carrone was released after 24 hours following an overwhelming international intervention from UAE, UK, US, all around European Union, Argentina and the Catholic Church. A good ending to what could have been a Tigran Gambaryan style incident.
- Oracle Security Workshop - link
- Secure Your ZK Code: Best Practices for Devs & Auditors - link
@EthSecurity1 | 1 240 |
| 15 | Maya protocol hacked for $1.3M
ClaudeAI report: https://claude.ai/code/artifact/469af51b-8f6c-44f0-a213-f7520c9f4b2d
@EthSecurity1 | 998 |
| 16 | Fox Market on BNB Chain hacked for $120K
RootCause: through a same-transaction spot-price manipulation bug in its bond mint path.
The attacker used massive flash liquidity to push the FOX/USDT pool, minted bonds against a stale pre-swap price, dumped the unlocked referral
@EthSecurity1 | 977 |
| 17 | - Anchor - a framework providing several convenient developer tools for writing Solana programs by Solana Foundation.
- A Solana Static Analyser & Reverse Engineering tool. - link
- hashcat v7.0.0 release including support for MetaMask and various wallet cracking.
@EthSecurity1 | 1 032 |
| 18 | Safepal Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw."
@EthSecurity1 | 706 |
| 19 | How to Setup an Ethereum Node Part 1 and Part 2
Inside Ethereum’s Engine: How the Execution Layer Actually Works - link
@EthSecurity1 | 1 230 |
| 20 | - How to protect yourself from Google Forms scams -link
- My Smart Contract Auditing Mental Model - Not a checklist! - link
- Compressed NFTs on Solana - link
- ape-safe - Account plugin for the Safe multisig wallet (previously known as Gnosis Safe) for the Ape Framework.
@EthSecurity1 | 1 081 |
