Another private key compromised... Still single sign and no timelock for large amount minting.
Currently 955 $eBTC tokens are held by 0x6a0109d3c5ab56277096c75e8f5d1d1d45243415.
Beosin Trace is investigating the stolen funds and the exploiter address.
We are currently investigating a security incident impacting the Echo bridge on Monad. All cross-chain transactions remain suspended while the investigation is underway.
We will continue to provide timely updates through our official channels as more information becomes available.
π¨ @THORChain has been exploited for about $7.2 M crypto assets and the stolen funds have been bridged and swapped into $ETH on Ethereum.
The consolidated address is 0xd477b69551f49C0519F9B18c55030676138890Bd and holds 3,174.86 $ETH. Beosin Trace is monitoring the fund flow.
The hacked funds have been swapped into $ETH and currently held by 0xc3ebddea4f69df717a8f5c89e7cf20c1c0389100 (1,291.07 $ETH) and 0x61e6301614178a2ca21bfa0fbb30aba06acc2d1c (1,222.12 $ETH).
π¨ @trustedvolumes has been attacked with a loss of about $5.9 M (~$3M $ETH, $1.37M $WBTC, 206k $USDT and ~1.27M $USDC).
Beosin is investigating the exploitation and tracing the funds.
π¨ @trustedvolumes has been attacked with a loss of about $5.9 M (~$3M $ETH, $1.37M $WBTC, 206k $USDT and ~1.27M $USDC).
Beosin is investigating the exploitation and tracing the funds.
The attacker has had 116,500 rsETH ($290M+) stolen on Ethereum and Arbitrum by exploiting 1/1 DVN operated by @LayerZero_Core.
Beosin Trace is monitoring and tracing the stolen funds. Stay vigilant!
Earlier today we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several L2s while we investigate.
We are working with @LayerZero_Core, @unichain, our auditors and top security experts on RCA.
We will keep you posted as we learn more about this situation. Please follow only the official @KelpDAO handle for the updates.
This attack was enabled by a combination of:
- Pre-signed durable nonce transactions, allowing delayed execution
- Compromise of multiple multisig signersβ approvals, likely through targeted social engineering or transaction misrepresentation
2/ The attacker made $CVT valuation extremely high by manipulating the oracle price. Then, by leveraging Drift's cross-margin and exchange functions, a large amount of almost valueless CVTS were deposited and real assets were withdrawn, resulting in losses of about $270M.
1/ The core of the vulnerability in Drift Protocol lies in the breach of the multisig governance mechanism. The attacker updated the administrator privileges of the Drift state account and initialized a spot market vault based on a scam token $CVT.
We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. Weβll provide additional updates from this account.
π¨ 80M $USR were exploited and part of funds have been swapped into 5,500 $ETH held by 0x6db6006c38468cdc0fd7d1c251018b1b696232ed and being swapped into $USDC and $ETH held by 0xb945ec1be1f42777f3aa7d683562800b4cdd3890.
Beosin is monitoring the fund flow. Stay vigilant!
#Resolv
Resolv has experienced an exploit that allowed the attackers to mint 50mn of unbacked USR.
The team has currently paused all the protocol functions to prevent further malicious actions and is actively working on recovery.
π¨ An exploit/whitehat rescue has been detected on @FOOMCASH and it seems to be another potential victim of misconfigured Groth16 verifier.
Txn hash: https://t.co/nBRCpjTRE3
The stolen assets are held by the following addresses:
16xusPKLMyqK68SkhfXDtic6AJPDi51tqh
12V7jhcPnqnGbRFMasSW2CZVBd8qpvUgAK
135oSa2fobTxtHtm5dwTREDyRY2o1DG1Aw
1PN2BoHU4buDQWcrNHk9T9NBA2qX8oyYEc
The 4 addresses are being monitored and traced by Beosin #TRACE.
According to the fund flow analysis of Beosin Trace, about 2319.4 $ETH (~$394 million) of IoTeX security incident have been bridged into $BTC via @THORChain.
π¨ Update on the recent security incident:
Our team has contained the situation and the IoTeX chain is being secured. Current data confirms the exploit impact is around $2M USD (including USDC, USDT, IOTX, and WBTC).
Investigations show this was a sophisticated, long-planned attack by professional actors targeting multiple chains. We are working closely with exchanges and law enforcement to freeze stolen funds, investigate and recover funds.
Chain operations and deposits will resume in 24-48 hours as we finalize security upgrades. Thank you for your patience and we will provide further updates transparently.π‘οΈ
π¨ Beosin Trace is monitoring the stolen funds flow. Currently the funds are held by 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 (4,267.09 $ETH) and 0x273589ca3713e7becf42069f9fb3f0c164ce850a (4,001 $ETH).
Today, we became aware of a security incident involving one or more malicious actors. The affected smart contract is 0x764C64b2A09b09Acb100B80d8c505Aa6a0302EF2 and we strongly advise the public not to interact with this contract until further notice. We are in contact with law enforcement and taking all available measures to address the situation. We will share updates through our official channels as they become available.
1/ A comprehensive on-chain data investigation into Huione Pay / H-Pay after its stated suspension of operations and postponement of withdrawals.
#huione#aml#KYT
6/After Huione Pay issued its deferred withdrawal notice, we used Beosin Trace to trace and analyze its addresses and found that its related hot wallets held over 8.17 million $USDT.
Following the notice, it activated a batch of new wallet addresses which continue to move funds.