uk
Feedback
EthSecurity

EthSecurity

Відкрити в Telegram
5 312
Підписники
+524 години
+187 днів
+6330 день
Архів дописів
- DeFi Lending has 3 bps Crime Drag on EVM and Solana - link - Wallet Security with Patrick Collins and Xavier Hendrickx. A good discussion on present and future wallet security trends. - link - Cracking DePIN: Decentralized Devices, Centralized Disasters. - link @EthSecurity1

seems allbridge hacked! If you have liquidity in affected pools, please withdraw now. @EthSecurity1

Across bridge’s relayer hacked for 1370 ETH RootCause: The attacker crafted deposits the relayer's bot read as real fill requests and paid out real ETH on Ethereum for, while the matching claim on Solana had nothing reimbursable behind it. Deposits got paused for exactly this reason: to stop new ones being minted. Follow the money and the intent is obvious. The main wallet was gassed from Tornado Cash, the Solana side funded through a no-KYC instant swapper. No stolen keys, no reentrancy, no flash loan. Just a function stamped "unsafe" that turned out to mean it. @EthSecurity1

🚨METAMASK NEARLY GOT HACKED BY NORTH KOREA Consensys unknowingly hired a North Korean developer using the alias "Tyler Knapp" who contributed to MetaMask's core code for nearly a month. The company detected the threat and revoked all access immediately. Product releases were paused and a full code audit confirmed no backdoors were deployed and no funds were compromised. @EthSecurity1

DeFiTuna was hacked for $569,601 USDC on Solana. Rootcause:The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker- controlled liquidity positions. @EthSecurity1

Post Contract Deployment Checklist: - Triple check the code on Etherscan. Make your auditor look too! - Did you init everything correctly? - Does your multi-sig actually work? Do a test tx! - Put Alarms on Events (super easy on tenderly) - Dune dashboard - Open source contracts repo - Pay the auditor lol - Put contract address in your docs! - Tag the commit hash as a deployment - Upload audit report to github @EthSecurity1

- The DeFi Lending Endgame - link @EthSecurity1

- Ethereum’s future hinges on TEEs. - link - Ledger CTO | Charles Guillemet with Patrick Collins on wallet security. - link @EthSecurity1

These pornographers bots are boring, telegram team must remove them ASAP @EthSecurity1

Specter has reported that LayerZero Executor wallets appear to have been compromised, resulting in $2.4M worth of crypto drained across multiple chains @EthSecurity1

@Lumi_Finance hacked for ~ $264k Root Cause: A vulnerability in Lumi smart accounts allowed token approvals to be performed a
@Lumi_Finance hacked for ~ $264k Root Cause: A vulnerability in Lumi smart accounts allowed token approvals to be performed as a side effect during UserOperation validation. Due to improper validation logic, an attacker-controlled paymaster could trigger approval operations during the validation phase and obtain ERC20 allowances from multiple smart accounts without explicit user intent. Attacker: 0xce1a3bb0b98d0d90c7dd0620ab86c9a771888d88 Victim: Multiple Lumi smart accounts affected by unintended token approvals during UserOp validation Malicious contract: 0x56362412ae17cac443aafbab4289946ad958e8a1 @EthSecurity1

- CVE-2025-48384: Breaking Git with a carriage return and cloning RCE. - link - The Phishing Dojo by The Red Guild. A threat simulation platform designed to help crypto users identify and defend against social engineering, phishing, scams, and other notorious threats in the crypto ecosystem. - Is EIP7702 a double edged sword? featuring FrankResearcher talking about security implications of the recent upgrade. - link @EthSecurity1

Bonzo Lend (@bonzo_finance) hacked for $9M. The attacker deposited 3$ of collateral and walked out with $9M, without forging a single signature RootCuase: Wallet A submitted a price update where the BLS signature field was [0,0]. A zeroed signature. No real committee ever signs a zero. To verify a BLS signature you run a pairing check, roughly e(signature, G) == e(H(message), pubkey). Supra's verifier built that check and handed it to Hedera's alt_bn128 pairing precompile (system contract 0.0.8). Both the submitted signature AND the referenced committee public key were the point at infinity (zero). @EthSecurity1

RIP Lindsey Graham

- Mixers, Bridges, and Dusting Attacks: An On-Chain Detective on Crypto Criminals’ Key Mistakes - link - Arbitrage Profits at Decentralized Exchanges  - A rare recording of a live scammer call and an impromptu interview - link @EthSecurity1

- ZKVM Determinism That Lasts: From Audits to Continuous Verification. - link - The $1.5B Problem: How Exchanges Can Build Safer Cold Storage. - link - Maya Dotan - UnSafe: When web2 security undermines web3. - link @EthSecurity1

this wallet holds 500,000 OCT: octC5eR9pLGKbpzTbDgHowkFt8HW7LZYb2gzehzxHamxuAZ recover its private key, tell us how you did it and receive another 500,000 OCT, for a total of 1 million. https://github.com/octra-labs/hfhe-challenge @EthSecurity1

Rootcause: Proofless Deposition what the fuck its mean in privacy protocol context? @EthSecurity1

- Restaking Protocols: Exposing the Achilles' Heels. - link - From Chaos to confidence: Simulate and clear sign your transactions. - link - Securing AI-Assisted DeFi Development with Formal Verification. - link @EthSecurity1