Valas Finance on BNB Chain was exploited through reward accounting, not stolen keys. A fresh staker could capture BB5D rewards that accrued before joining, then use that value as collateral to pull out WBNB/BNB.
Source: DefimonAlerts. Major BSC exploit: in tx 0x6a79...2f96f60a, an unprivileged caller took over the CPIMP/NewBCT proxy 0xAf15...c3e0. No stolen key needed. The upgrade path was exposed to anyone, so protocol logic could be replaced on-chain.
Source: DefimonAlerts. KEOM on Polygon zkEVM was drained by a protocol bug, not a normal MEV race. With tiny deposits, one actor pulled nearly all cash from kNative and kWETH. This matters because a core redeem accounting invariant failed.
@pcaversaccio I just investigated it and I think this is a transaction to update all lockedBalance of contracts created by zero transfer TORN token 2 day prior
https://t.co/z4hvWH4SL3…
@HypernativeLabs I think it is exploited by the proposal suspicious
. This transaction to update all lockedBalance of all contracts created by zero transfer TORN by 2 days prior
https://t.co/z4hvWH4SL3
Here is the proposal:
https://t.co/0n8CZJ0rCI