Defimon Alerts
Відкрити в Telegram
⚠️ DeFi security alerts by @DecurityHQ 💎 Instant alerts @defimon_subscription_bot defimon.xyz
Показати більшеКраїна не вказанаКриптовалюти16 166
4 429
Підписники
+724 години
+287 днів
+7230 день
Триває завантаження даних...
Схожі канали
Немає даних
Виникли проблеми? Будь ласка, оновіть сторінку або зверніться до нашого support-менеджера.
Хмара тегів
Вхідні та вихідні згадування
---
---
---
---
---
---
Залучення підписників
липень '26
липень '26
+102
в 1 каналах
червень '26
+139
в 3 каналах
Get PRO
травень '26
+234
в 1 каналах
Get PRO
квітень '26
+261
в 0 каналах
Get PRO
березень '26
+250
в 0 каналах
Get PRO
лютий '26
+176
в 1 каналах
Get PRO
січень '26
+434
в 1 каналах
Get PRO
грудень '25
+357
в 4 каналах
Get PRO
листопад '25
+368
в 0 каналах
Get PRO
жовтень '25
+541
в 3 каналах
Get PRO
вересень '25
+419
в 6 каналах
Get PRO
серпень '25
+126
в 1 каналах
Get PRO
липень '25
+172
в 3 каналах
Get PRO
червень '25
+203
в 0 каналах
Get PRO
травень '25
+176
в 3 каналах
Get PRO
квітень '25
+221
в 3 каналах
Get PRO
березень '25
+248
в 1 каналах
Get PRO
лютий '25
+724
в 0 каналах
Get PRO
січень '250
в 0 каналах
Get PRO
грудень '24
+19
в 1 каналах
| Дата | Залучення підписників | Згадування | Канали | |
| 24 липня | +5 | |||
| 23 липня | +7 | |||
| 22 липня | +2 | |||
| 21 липня | +6 | |||
| 20 липня | +5 | |||
| 19 липня | +3 | |||
| 18 липня | +9 | |||
| 17 липня | +13 | |||
| 16 липня | +5 | |||
| 15 липня | +5 | |||
| 14 липня | +4 | |||
| 13 липня | +2 | |||
| 12 липня | +2 | |||
| 11 липня | +4 | |||
| 10 липня | +2 | |||
| 09 липня | +3 | |||
| 08 липня | +4 | |||
| 07 липня | +1 | |||
| 06 липня | +1 | |||
| 05 липня | +1 | |||
| 04 липня | +6 | |||
| 03 липня | +1 | |||
| 02 липня | +5 | |||
| 01 липня | +6 |
Дописи каналу
Defimon reported an ongoing incident to guru.fund
Unfortunately finding a right contact within the affected team to share the details can take precious time. That's why automated incident response is crucial in DeFi.
https://defimon.xyz/blog/guru-fund-hack-july-2026
https://x.com/thegurufund/status/2080674650200109244
| 2 | 💌 Onchain message:
This is Numa, Guru.Fund dev. We acknowledge the exploit and I am reaching out dev-to-dev: if you can consider returning some or all of the assets in exchange for a bounty, please reply onchain from this address with a secure contact method encoded in the tx data.
Behind those vaults there are real users, and we do not have the resources to refund them. If there's a path to an outcome that inflicts the least damage to them, I'm ready to discuss quickly and in good faith.
📤 From: 0x0290334f079b3a04c428c4f5813759c681b208f6
📥 To: 0x1e7bd709fb53ef70f6b6f9c04b1bd2e77d0de29a
🌎 Network: mainnet
Etherscan | 513 |
| 3 | 🚨 lien.finance - Loss $542K (2026-07-24)
Network: Ethereum
Type: Oracle / Price Manipulation
Lien Finance's GeneralizedDotc bond-to-ERC20 OTC pools were drained. An attacker-deployed orchestration contract (0xe74d17c1) permissionlessly registered new bond groups on the BondMakerCollateralizedEth (0xda6fc562) with a crafted payoff function, then swapped the newly-minted bond tokens through the GeneralizedDotc pools (0x656e...ef18, 0x7db8...6a75). The bond price returned by _calcRateBondToErc20 (bondPricer.calcBondPriceAndSpread using oracle price + volatility) was inflated relative to real collateral value, so worthless bonds were exchanged for the full USDC allowance the liquidity provider (0xa961...4d80) had granted to the pools — netting ~542K USDC to the attacker EOA.
TX: https://etherscan.io/tx/0xb96d572b557a12f5ef193e88cca86123a6ae1b6e98b0eeee265870c85848e0e7
Attacker: https://etherscan.io/address/0x0d7d9023531ad1a88414e216ee2715f63561808a
Victim: https://etherscan.io/address/0x656e5e976d523a427f05b0c212a22a89ccd9ef18
X: https://x.com/LienFinance
@defimon_subscription_bot | 552 |
| 4 | 💌 Onchain message:
Withdrawals are now open for afiUSD depositors who submitted redemption requests before the May 30, 2026 incident.
Eligible users have 30 days from today to complete their withdrawals. Please withdraw your available funds within this window.
If you have any questions or need assistance, please contact us on Telegram: @Oxriskyops.
📤 From: 0xb05c3e305f414c8a68afdfbdd9e53b5654a62c1d
📥 To: 0xce223804c890d77dcd85649dbcf08e1944d0e8c5
🌎 Network: mainnet
Etherscan | 613 |
| 5 | 💌 Onchain message:
Withdrawals are now open for afiUSD depositors who submitted redemption requests before the May 30, 2026 incident.
Eligible users have 30 days from today to complete their withdrawals. Please withdraw your available funds within this window.
📤 From: 0xb05c3e305f414c8a68afdfbdd9e53b5654a62c1d
📥 To: 0xcbc18b4a6cd4aa71b294e0696c8b33952859d9d7
🌎 Network: mainnet
Etherscan | 614 |
| 6 | Exploit or rug? 🧐
https://www.defimon.xyz/blog/verus-bridge-hack-july-2026 | 676 |
| 7 | 🚨 verus.io - Loss $7.33M (2026-07-23)
Token: $VRSC
Network: Ethereum
Type: Forged Proof / Bridge Verification Bypass
The Verus<>Ethereum bridge Delegator (0x7151...7f63) was drained via a crafted submitImports() call. The attacker supplied forged cross-chain import/notarization proofs that passed VerusProof (0x54e0...d4ce) verification, letting them "release" reserves that were never locked on the Verus side. The bridge paid out ~1.14K ETH, 71.5 tBTC, 59.4 MKR, plus USDC/USDT/DAI/EUROC/scrvUSD (~$7.33M total) to attacker address 0xcfd0...2d54.
TX: https://etherscan.io/tx/0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
Attacker: https://etherscan.io/address/0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54
Victim: https://etherscan.io/address/0x71518580f36feceffe0721f06ba4703218cd7f63
X: https://x.com/VerusCoin
@defimon_subscription_bot | 652 |
| 8 | 💌 Onchain message:
AFX is extending a white hat settlement offer to the party responsible for the recent bridge incident.
Return 70% of the stolen assets to the following address:
0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1B
You may retain the remaining 30% as a white hat bounty.
Our priority is the recovery of user assets and a swift resolution for the community.
We encourage you to act in good faith. This offer is available for a limited time.
📤 From: 0x20e96a897a073e44d2e3e0e95df7a916252c7730
📥 To: 0x627654b2782bfc57580ecd11d40869b350b6ebac
🌎 Network: arbitrum
Etherscan | 911 |
| 9 | 💌 Onchain message:
The 2.3657 WETH you swept from 0x1656bd18dFAF7E0f88505550604125799eDdf1aF (tx 0x8679272bc0f2dd0c5411dc26bab0182083cd8a909486d03802e7b953af468f68) was research capital for an authorized Uniswap v4 security disclosure, not a stray. We will gladly pay a 10% bounty for its return to 0xd43acB82b54fC72fC85BaeA2168e469cE7cabEC7. Thank you.
📤 From: 0xd43acb82b54fc72fc85baea2168e469ce7cabec7
📥 To: c0ffeebabe.eth
🌎 Network: mainnet
Etherscan | 671 |
| 10 | 💌 Onchain message:
Hi bro I have $2m in the project you exploited please it's my life, anyway I can get them back?
Thank you
📤 From: 0xec3257085ea55d58414ed9f05f5ae7ea4240d865
📥 To: 0x627654b2782bfc57580ecd11d40869b350b6ebac
🌎 Network: mainnet
Etherscan | 650 |
| 11 | 💌 Onchain message:
Message from the BSquaredNetwork team:
We have detected the draining of 8.591M $B2. If you return at least 10% of the stolen funds (approximately 386,000 USD) within the next 24 hours to this address, we will consider this a gesture of good faith and will not initiate legal proceedings.
After this deadline, we will launch all possible legal procedures (reporting to authorities, on-chain tracing, collaboration with exchanges and law enforcement).
The choice is yours.
📤 From: 0x3ce2572cc2e8f279dc53009106a7cf315382c248
📥 To: 0xf977427ec8e583c55d413061fc205bcd57e8bf6d
🌎 Network: bsc
Etherscan | 671 |
| 12 | 💌 Onchain message:
Return 70% of the funds to 0xBdc77a0c69f13207aCB70a6981Cad60B4c1D1942 (the Hinkal owner address, which you can verify) and keep 30%. If you do, we treat it as a white-hat recovery, take no civil action, and describe it publicly as a return rather than an attack. This ends here.
The funds are also difficult to move without exposure, and that only grows over time. Do it within 24 hours, by 23 July at 23:59 UTC.
If you want to talk it through, we're at recover@hinkal.pro.
请将70%的资金退还至 0xBdc77a0c69f13207aCB70a6981Cad60B4c1D1942(Hinkal 所有者的地址,你可以自行核实),其余30%可由你保留。如果你这样做,我们将把此事视为白帽追回,不采取任何民事法律行动,并在公开说明中将其描述为资金返还,而非攻击。此事到此为止。
此外,要在不暴露身份的情况下转移这些资金也很困难,而且随着时间推移,暴露的风险只会越来越大。请在24小时内完成,即最迟于7月23日23:59(UTC)之前。
如果你希望进一步沟通,请发送邮件至 recover@hinkal.pro。
📤 From: 0xbdc77a0c69f13207acb70a6981cad60b4c1d1942
📥 To: 0x892eb71069fc8df4f7a6c3d4456075f2bb3bf317
🌎 Network: mainnet
Etherscan | 676 |
| 13 | Defimon.xyz + Glide.r.xyz = find contracts vulnerable to the same attack the moment an exploit happens
https://x.com/glider_xyz/status/2079574892769374364 | 830 |
| 14 | 💌 Onchain message:
This is the Allbridge team. We have identified this wallet as connected to the July 19, 2026 Allbridge Core exploit ($1.65M+). We are formally offering a white-hat agreement: return 80% of the funds to this address within 48 hours. In exchange, you may keep the remaining 20% as a bounty, and we will not pursue further legal action or share identifying information with law enforcement. If we do not hear from you, we will proceed with full on-chain forensic tracing, exchange notifications, and law enforcement referral.
📤 From: 0xabcf3f27aa91abda8865125c43c095bb9cf9732d
📥 To: 0x651591b68a9c9650fb23f642162353306281ffde
🌎 Network: mainnet
Etherscan | 887 |
| 15 | 💌 Onchain message:
SECURITY ALERT (whitehat): BarnBridge SmartYield CompoundProvider 0xdaa037f99d168b552c0c61b7fb64cf7819d78310 has a hijacked controller. Your USDC allowance to it is still live and (~25 019 USDC) drainable. Protect your funds, REVOKE ALL YOUR ALLOWANCES RIGHT NOW nano XBankStaking.sol! This is a free warning - no funds, links or bounty requested. @beacon302 aka DK27ss
📤 From: 0x622b4c078f1175c9aee10e9e79572f19cfedfeaf
📥 To: 0x71f12a5b0e60d2ff8a87fd34e7dcff3c10c914b0
🌎 Network: mainnet
Etherscan | 15 |
| 16 | 💌 Onchain message:
SECURITY ALERT (whitehat): BarnBridge SmartYield CompoundProvider 0xdaa037f99d168b552c0c61b7fb64cf7819d78310 has a hijacked controller. Your USDC allowance to it is still live and (~25 019 USDC) drainable. Protect your funds, REVOKE ALL YOUR ALLOWANCES RIGHT NOW nano XBankStaking.sol! This is a free warning - no funds, links or bounty requested.
📤 From: 0x622b4c078f1175c9aee10e9e79572f19cfedfeaf
📥 To: 0x71f12a5b0e60d2ff8a87fd34e7dcff3c10c914b0
🌎 Network: mainnet
Etherscan | 7 |
| 17 | 💌 Onchain message:
Hi — I’m the whitehat who found and escalated the old BarnBridge proposal #15 approval risk that affected your wallet.
Your address appeared to be the largest at-risk wallet, with roughly $3.2M exposed. I couldn’t reach you directly, so I escalated through SEAL 911. My understanding is that the warning reached you and the funds were protected.
I’m very glad the funds were saved. I’m reaching out now to ask whether you would consider a voluntary bounty/recognition for the investigation and urgent escalation work.
You can verify my role with SEAL 911. I’m not asking you to click links or send funds blindly.
If open to discussing, please reply here or contact me on X: @onechesss
📤 From: 0xda9d65086a986624cbf71989118938f0cf9a0c68
📥 To: 0xae911067fed8f7adf93ee5c1a14757f2d06b7dd0
🌎 Network: mainnet
Etherscan | 826 |
| 18 | 💌 Onchain message:
URGENT RETURN REQUEST
The 145,965.658533 USDC received by this address was transferred without my authorization from:
0x66666f3364cf650699299f08e37b5d5cedae6d29
Arbitrum transaction:
0xb611485b646d1c0b9c30d5266d724334c2479b10d235c459e3e6bc48828058a6
The incident and both addresses have been reported to Hyperliquid, Circle and blockchain security teams. The funds are being traced, and preservation and freezing requests are being prepared for exchanges, bridges and law enforcement.
Please return the full amount to my NEW secure address:
0xafc9e1ef02df2c99447272f1619689ca1db02c59
If this was intended as a white-hat action, contact me through Blockscan Chat. A reasonable recovery bounty can be discussed only after the funds are safely returned.
I will not make any advance payment or disclose any private information.
📤 From: 0xefdcbf40d383c479ae807a4a405c5ad45ab4ce13
📥 To: 0x1eb488919fcf5e6f658725370e2f635c3fc47f73
🌎 Network: arbitrum
Etherscan | 738 |
| 19 | 💌 Onchain message:
This address received approximately 145,965.658038 USDT stolen from my wallet in transaction [TX HASH]. All evidence has been preserved, and tracing and preservation requests are being submitted to law enforcement and relevant exchanges. Please return the full amount to this new secure address: [0xafc9e1ef02df2c99447272f1619689ca1db02c59]. If this was an accidental or white-hat action, reply through Blockscan Chat.
📤 From: 0xefdcbf40d383c479ae807a4a405c5ad45ab4ce13
📥 To: 0x1eb488919fcf5e6f658725370e2f635c3fc47f73
🌎 Network: arbitrum
Etherscan | 754 |
| 20 | 🚨 BSC NFT Auction Marketplace - Loss ~$8.3K (2026-07-19)
Network: BNB Chain
Type: Logic Error (double-settlement / delist refund)
An NFT auction/marketplace proxy (0x46c9…1e09, impl 0x3735…044d, unverified) allows a listing to be both settled and cancelled. The attacker minted a throwaway NFT, listed it, then in a single flash-loaned tx (Moolah/Lista WBNB) called buyNow→completeAuction — which pays the seller from the sent value — and immediately delist, which refunds the same ~2.2176 BNB payment from the contract's escrow pool. Because completeAuction never clears the sale's paid/bid state, delist double-pays, draining ~4.4 BNB of other users' escrowed funds. Attacker was both seller and buyer, netting ~2.173 BNB (~$4.06K) profit; marketplace lost ~4.44 BNB (~$8.3K).
TX: https://bscscan.com/tx/0x79dbf5d676c1f1d89cabc046743746b828fc0fa4ed70854c8b77335cd1c194df
Attacker: https://bscscan.com/address/0xeaaf475db34fb66f098e51cbf0eeeff76f496974
Victim: https://bscscan.com/address/0x46c958a169b9f2688e126080c4ec422956621e09 (unverified impl)
@defimon_subscription_bot | 747 |
