ru
Feedback
Defimon Alerts

Defimon Alerts

Открыть в Telegram

⚠️ DeFi security alerts by @DecurityHQ 💎 Instant alerts @defimon_subscription_bot defimon.xyz

Больше
Страна не указанаКриптовалюты16 087
4 445
Подписчики
-124 часа
+167 дней
+7130 день

Загрузка данных...

Похожие каналы
Нет данных
Возникли проблемы? Пожалуйста, обновите страницу или обратитесь к нашему support-менеджеру .
Входящие и исходящие упоминания
---
---
---
---
---
---
Привлечение подписчиков
июль '26
июль '26
+127
в 1 каналах
июнь '26
+139
в 3 каналах
Get PRO
май '26
+234
в 1 каналах
Get PRO
апрель '26
+261
в 0 каналах
Get PRO
март '26
+250
в 0 каналах
Get PRO
февраль '26
+176
в 1 каналах
Get PRO
январь '26
+434
в 1 каналах
Get PRO
декабрь '25
+357
в 4 каналах
Get PRO
ноябрь '25
+368
в 0 каналах
Get PRO
октябрь '25
+541
в 3 каналах
Get PRO
сентябрь '25
+419
в 6 каналах
Get PRO
август '25
+126
в 1 каналах
Get PRO
июль '25
+172
в 3 каналах
Get PRO
июнь '25
+203
в 0 каналах
Get PRO
май '25
+176
в 3 каналах
Get PRO
апрель '25
+221
в 3 каналах
Get PRO
март '25
+248
в 1 каналах
Get PRO
февраль '25
+724
в 0 каналах
Get PRO
январь '250
в 0 каналах
Get PRO
декабрь '24
+19
в 1 каналах
Дата
Привлечение подписчиков
Упоминания
Каналы
31 июля+3
30 июля+2
29 июля+2
28 июля+12
27 июля+3
26 июля0
25 июля+3
24 июля+5
23 июля+7
22 июля+2
21 июля+6
20 июля+5
19 июля+3
18 июля+9
17 июля+13
16 июля+5
15 июля+5
14 июля+4
13 июля+2
12 июля+2
11 июля+4
10 июля+2
09 июля+3
08 июля+4
07 июля+1
06 июля+1
05 июля+1
04 июля+6
03 июля+1
02 июля+5
01 июля+6
Посты канала
Repost from N/a
🚨 Swan Treasury (STY) - Loss ~$625K (2026-07-30) Token: $STY @ $2.87 Network: BNB Chain Type: Private Key Compromise (signer key leak) The protocol's off-chain signer key (0xdEb4...8284, hardcoded as _signer in ZhaiquanBuy) was compromised. buy() sells STY at a signed discount: buyamount = getBuyamount() * 100 / discount. The attacker crafted valid signatures for their own address with discount=1, buying STY at a 100x discount (~687K STY for ~19.7K USDT via a PancakeSwap flash loan), plus forged claim()/transfer signatures on sibling contracts. Dumping the STY into the STY/USDT pool netted ~$625K USDT. Every ecrecover in the tx resolves to the exact hardcoded signer, confirming the key itself was compromised rather than a signature-logic flaw. TX: https://bscscan.com/tx/0xc8c3325ba2c942a674b26de2063d278c144e92dbc91497ca0c766c915d96cbd4 Attacker: https://bscscan.com/address/0x840ff67cdd5bc3cf51ebf758c35feaac92cdada4 Victim: https://bscscan.com/address/0x27af47fa5681e4c4ef5ffdcff47eb0dd3bac6a8c X: https://x.com/SwanTreasurpaj @defimon_subscription_bot

2
Sorry to see this one end. After Defimon detected the first attack we tried to share the info with guru.fund team but a human factor prevented the protocol to be paused in time. https://x.com/thegurufund/status/2082157975897059562 https://guru.fund/post-mortem
475
3
💌 Onchain message: Glad you choose to do the needful. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA on Ethereum. Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA is not authorised by ChainConnect. ChainConnect, 29 July 2026 📤 From: 0x9c961a0ddc3df10456b05ebec5138737af28b1ea 📥 To: 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 🌎 Network: mainnet Etherscan
536
4
💌 Onchain message: To the party who executed the exploit of the Wanchain Bridge on Cardano on July 20, 2026, resulting in the theft of NIGHT tokens: We are opening a channel to resolve this as a white-hat matter. The offer: return 90% of the exploited NIGHT tokens to the addresses below and retain 10% as a white-hat bounty. If the returned funds are received by August 6, 2026 at UTC 12:00, Wanchain will treat this as a white-hat recovery and will not pursue civil claims against you. This offer expires at the deadline above. Blockchain analytics firms and relevant exchanges have been engaged, and the addresses involved are being monitored and flagged. Please return the funds to: Cardano Address: addr1q8jqrqz0t2vzy5yvl88wtyjgurvhwauw0sqpe698mq04p0ham3clyk6mg6gctwsfuc8hsgqdt0s9laxl585uwu3xvx2s2pglww Ethereum Address: 0xfCeAAaEB8D564a9D0e71Ef36f027b9D162bC334e To communicate, send an on-chain message from the exploit address or contact whitehat@wanchain.org. 📤 From: 0x8faee769b0b2c4072ef11029b1aedd5650145b9d 📥 To: 0x0bc45d27539a153f1941e46ccdf17642d4381a7e 🌎 Network: mainnet Etherscan
554
5
💌 Onchain message: I accept the proposal as a whitehat. Please contact me via Blockscan Chat to discuss the details. 📤 From: 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 📥 To: 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 🌎 Network: mainnet Etherscan
599
6
💌 Onchain message: Message from the LULA TEAM | Last warning message ! We have detected the draining of approximately 578,000 USD worth of LULA tokens on BSC through the exploitation of the recycle() function on the Rental/LULA contract and the PancakeSwap V2 BSC-USD/LULA pool. If at least 25% of the stolen funds (around 144,500 USD in USDT or BNB) are returned within the next 22 hours to the following address: 0x5e16609D18bF366b5502b088E0253dE45fc1CD96 We will consider this a gesture of good faith and will not pursue legal action. You have 22 hours left. 📤 From: 0x5e16609d18bf366b5502b088e0253de45fc1cd96 📥 To: 0x5b114fb2047ef3c0f65dc396f7c89ad593137e34 🌎 Network: bsc Etherscan
115
7
🚨 sashimi.cool - Loss ~$51.8K (2026-07-26) Token: $SASHIMI @ $0.00026 Network: Ethereum Type: Logic Error / Price Manipulation (shared-vault swap accounting) SashimiSwap's "Investment Router" (0xe4fe...9410) keeps virtual reserves in an internal _pools mapping but sources the actual output tokens by draining a shared SashimiInvestment lending vault: _transferOut/_transferETH call ISashimiInvestment.withdrawWithReBalance() to pull WETH whenever the router's own balance is short. Because swap output is priced off a thin/mispriced SASHIMI-WETH pair (0x3fa4...d69d, ~3047 SASHIMI / 27394 virtual WETH) while WETH is redeemed straight from the vault's lending position, the attacker Morpho-flash-loaned 27 WETH, minted collateral, borrowed ~6.2M SASHIMI, then swapped it through the router — forcing SashimiLendingVaultProvider (0x7bc8...ce2b) to redeemUnderlying and hand over 27.08 WETH for a fraction of its value. Vault drained of 27.08 WETH (~$51.8K). TX: https://etherscan.io/tx/0x8a598a4b2fba9bd9e67fbefc3f3e86df405ea89202efc182257f57f212ba5935 Attacker: https://etherscan.io/address/0xff8ef7bc455a57e5893232203052ce0232b39fa2 Victim: https://etherscan.io/address/0x7bc801a840a7c2c027f4e5e48bf618348b0bce2b X: https://x.com/SashimiSwap @defimon_subscription_bot
175
8
💌 Onchain message: Message from the LULA team: We have detected the draining of approximately 578,000 USD worth of LULA tokens on BSC through the exploitation of the recycle() function on the Rental/LULA contract and the PancakeSwap V2 BSC-USD/LULA pool. If at least 25% of the stolen funds (around 144,500 USD in USDT or BNB) are returned within the next 36 hours to the following address: 0x5e16609D18bF366b5502b088E0253dE45fc1CD96 We will consider this a gesture of good faith and will not pursue legal action. 📤 From: 0x5e16609d18bf366b5502b088e0253de45fc1cd96 📥 To: 0x5b114fb2047ef3c0f65dc396f7c89ad593137e34 🌎 Network: bsc Etherscan
473
9
💌 Onchain message: Message from the LULA team: We have detected the draining of approximately 578,000 USD worth of LULA tokens on BSC through the exploitation of the recycle() function on the Rental/LULA contract and the PancakeSwap V2 BSC-USD/LULA pool. If at least 25% of the stolen funds (around 144,500 USD in USDT or BNB) are returned within the next 36 hours to the following address: 0x5e16609D18bF366b5502b088E0253dE45fc1CD96 We will consider this a gesture of good faith and will not pursue legal action. After this deadline, we will initiate all possible legal proceedings (reports to the authorities, on-chain investigation, collaboration with exchanges and law enforcement). 📤 From: 0x5e16609d18bf366b5502b088e0253de45fc1cd96 📥 To: 0x2677806d48325ced7533c54b86ed5e99b129a4ed 🌎 Network: bsc Etherscan
475
10
💌 Onchain message: This address is under investigation in connection with the compromise of this wallet. However, an opportunity remains to resolve this matter through voluntary cooperation. If you wish to discuss a resolution, please respond via an on-chain message by 23:59 UTC on August 4, 2026. We will treat your identity with strict confidence throughout this process. If no response is received by that time, we will assume that you are not interested in pursuing a cooperative resolution, and the investigation will continue accordingly. 📤 From: 0x420cb5a8a8b50bdce02528cde65ac61edb15e68b 📥 To: 0xe242143cc057d85f27c97e0cefba1fff7f4b2a24 🌎 Network: mainnet Etherscan
672
11
💌 Onchain message: We are zeroShadow, a leading blockchain intelligence and investigation firm retained by the client. We can appreciate the skills involved in you to hack the funds from our client’s wallet, and would like to discuss the possibility of you returning a proportion of the funds. If you would like to discuss this opportunity with us then please reply to this message before 2359 UTC on August 4th 2026. If we do not hear from you before this time we will assume that you are unwilling to consider this request. Please be aware that this matter is currently being investigated by multiple parties, including Japanese authorities, the FBI, and us. This offer is made in the spirit of cooperation and with the assurance that we will not pursue any legal claims against you. Upon the successful return of the agreed funds, we will notify all relevant authorities and investigative firms that the matter has been resolved and request that any further investigative efforts be discontinued, to the fullest extent legally and practically possible. We are prepared to resolve this matter confidentially and will not take any action on our part to identify or pursue you once the agreed resolution has been completed. 📤 From: 0x420cb5a8a8b50bdce02528cde65ac61edb15e68b 📥 To: 0x7d170e5d8597d25dc4438b9a2d5f80e38824ff2a 🌎 Network: mainnet Etherscan
682
12
💌 Onchain message: Hello, reaching out to you again as this address is still being monitored by me and Zach and others, you exploited 95eth and 53582 usdc, kindly do the needful and return the 95eth to this address, as you can keep the usdc as bounty fee. Everything is on chain you are still being watched after 2 years+. Do the needful. Refund address: 0xdcFc48E72376563c2e01ba1F7eff71C6Cb3011dA 📤 From: 0xdcfc48e72376563c2e01ba1f7eff71c6cb3011da 📥 To: 0x89c9224fa12a06082c29661e8e8c56ecede853a8 🌎 Network: mainnet Etherscan
635
13
💌 Onchain message: Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x840B3De19e3FAB72fa9A168bD8Dd71B678c57989 on Ethereum. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 is not authorised by ChainConnect. Sender 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30, the bridge deployer signatory. ChainConnect, 28 July 2026 📤 From: 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 📥 To: 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 🌎 Network: mainnet Etherscan
661
14
💌 Onchain message: Test message: Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x840B3De19e3FAB72fa9A168bD8Dd71B678c57989 on Ethereum. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 is not authorised by ChainConnect. ChainConnect, 28 July 2026 📤 From: 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 📥 To: 0x1a335659d0dfe6c1a8151a35b9ddc9c0cf4f59c0 🌎 Network: mainnet Etherscan
609
15
🚨 Projekt (GREEN/GOLD) reward vault - Loss ~$560K (25 Jul 2026) Network: Ethereum Type: Logic Error (buy-to-earn reward/allocation manipulation) An unverified "buy-to-earn" reward vault (0x574f...42cb) credits an ETH allocation via the permissionless trackPurchase(buyer), which reads the buyer's token balance delta to size the reward, then pays it out with massWithdraw() → msg.sender.transfer(alloc). The attacker flash-loaned ~14K WETH from Morpho, pushed it into dozens of Uniswap V2 memecoin pairs (Kirby Inu, ROTTSCHILD, etc.) and skim()'d the tokens to its own contract, registering huge fake "purchase" allocations for near-zero net cost (the flash loan is repaid in the same tx). It then drained ~301.7 ETH (~$560K) from the vault's reward pool via massWithdraw. trackPurchase never verifies real ETH spent, so self-dealing skims inflate the payout arbitrarily. TX: https://etherscan.io/tx/0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64 Attacker: https://etherscan.io/address/0x61e7ad696215688d274c729a4cd0fbbc88fc4f85 Victim: https://etherscan.io/address/0x574fc478bc45ce144105fa44d98b4b2e4bd442cb (unverified) @defimon_subscription_bot
689
16
💌 Onchain message: AFX is extending a white hat settlement offer to the party responsible for the recent bridge incident. Return 70% of the stolen assets to the following address: 0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1B You may retain the remaining 30% as a white hat bounty. Our priority is the recovery of user assets and a swift resolution for the community. We encourage you to act in good faith. This offer is available for a limited time. Best regards, Contract creator of the AFX bridge. 📤 From: 0xa3eca683bcb9d38102033ca4609eb8f2c960847e 📥 To: 0x627654b2782bfc57580ecd11d40869b350b6ebac 🌎 Network: mainnet Etherscan
910
17
💌 Onchain message: This is the second notification and warning. Funds received through exploitation of relayer 0x394311A6Aaa0D8E3411D8b62DE4578D41322d1bD are fully traced. Return 13.28498 ETH to that address by 2026-07-26 22:30 UTC. Prompt return will be treated as voluntary remediation. Relay and relevant service providers have been notified. 📤 From: 0x394311a6aaa0d8e3411d8b62de4578d41322d1bd 📥 To: 0x5e310f9f44fed0314006c2eb4d707af1c9aaa6f9 🌎 Network: mainnet Etherscan
853
18
💌 Onchain message: Funds received through exploitation of relayer 0x394311A6Aaa0D8E3411D8b62DE4578D41322d1bD are fully traced. Return 13.28498 ETH to that address by 2026-07-25 22:30 UTC. Prompt return will be treated as voluntary remediation. Relay and relevant service providers are being notified. 📤 From: 0x394311a6aaa0d8e3411d8b62de4578d41322d1bd 📥 To: 0x5e310f9f44fed0314006c2eb4d707af1c9aaa6f9 🌎 Network: mainnet Etherscan
859
19
Defimon reported an ongoing incident to guru.fund Unfortunately finding a right contact within the affected team to share the details can take precious time. That's why automated incident response is crucial in DeFi. https://defimon.xyz/blog/guru-fund-hack-july-2026 https://x.com/thegurufund/status/2080674650200109244
1 029
20
💌 Onchain message: This is Numa, Guru.Fund dev. We acknowledge the exploit and I am reaching out dev-to-dev: if you can consider returning some or all of the assets in exchange for a bounty, please reply onchain from this address with a secure contact method encoded in the tx data. Behind those vaults there are real users, and we do not have the resources to refund them. If there's a path to an outcome that inflicts the least damage to them, I'm ready to discuss quickly and in good faith. 📤 From: 0x0290334f079b3a04c428c4f5813759c681b208f6 📥 To: 0x1e7bd709fb53ef70f6b6f9c04b1bd2e77d0de29a 🌎 Network: mainnet Etherscan
937