🚨 ALERT — Exploit on Ethereum
A GEB/RAI-style CDP deployment (Reflexer's GEB framework, in Global Settlement since Jan 2021) was just drained of its leftover ETH-A collateral. ~5.94($14k) ETH stolen.
Root cause:
several SAFEs were owned by the shared GebProxyActions library itself (0x84fe452d9fb495a335c74a225e6ad52c35eb8616), not by user proxies. Its quitSystem() is public and unauthenticated, so the attacker called it directly — GebSafeManager's msg.sender == ownsSAFE[safe] check passed (the library calling as itself) — and migrated other users' collateral to himself, then freeCollateral + exit.
Flow (per SAFE): processSAFE → quitSystem → freeCollateral → CollateralJoin.exit → WETH.withdraw
Attack tx: https://t.co/KAmU46mQB8
Attacker: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
Exploit contract: 0x6a213f0b5bd9eed865d3e2efc867b73dfe9039e7
Lesson: never let a stateless, shared "proxy-actions" contract become the registered owner of a position — its public helpers turn into anyone's withdraw button.
Subscribe to our TG bot for real-time attack alerts 👉 https://t.co/XXmb8rT3VA
🚨 Exploit Alert — Ethereum
~10.7 ETH was drained from two legacy Visor/Gamma FLOAT-ETH Hypervisor vaults via a flash-loan price manipulation.
🔍 Root cause: the Hypervisor mints LP shares in deposit() off the Uniswap V3 pool's INSTANTANEOUS spot price (currentTick()/slot0) with no TWAP and no spot-vs-oracle deviation check — while withdraw() redeems shares for a proportional slice of the real underlying tokens. Minting is spot-priced, redemption is not. Move the spot price and deposit→withdraw becomes a net drain. Deposits are permissionless (whitelist disabled).
🧾 On-chain:
Attacker: 0xaea29218262dc6b0904ca077f6527c49dfd426d9
Contract: 0x05303c95ee7ff76daf1421b28e024635d7fe51ab
Vaults: 0x85cbed52…a8a70c · 0xc86b1e7f…c1153
Tx: 0x3d7549db65344da2a41067e17791b17fac16ec6b8e5132e82e243f6541de5cff
Block: 25874402 · 2026-08-31
Our SkyEye monitor continuously detects emerging on-chain attacks—many of which have not yet been reported elsewhere.
Explore the latest incidents:
https://t.co/tAbAPiY2ky
Want real-time attack alerts? Subscribe to our Telegram channel and stay ahead of emerging threats. 🔔
🚨 EXPLOIT ALERT | Ethereum
@ArrakisFinance
The Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was drained via a Uniswap V3 spot-price manipulation.
Root cause: the vault's mint() and burn() value its Uniswap V3 position off the instantaneous pool.slot0() spot price, with NO TWAP or deviation guard on the user deposit/withdraw path. The vault does have a TWAP check — but it only guards the manager's rebalance() swap, never mint/burn.
Attack flow (one tx):
1. Flash-loan 1,800 WETH from Morpho Blue
2. Swap ~145 WETH → ENS on the UniV3 pool to skew the tick / spot price
3. mint() vault shares at the distorted valuation (deposit ~1,253 WETH + ~13,160 ENS → ~4,487 shares)
4. Swap back to restore the price
5. burn() the shares → redeem a richer token mix than deposited
6. Convert surplus, repay the loan
Attacker profit ≈ 2.94 WETH. No privileged access required — pure permissionless flash-loan + spot manipulation.
Attacker: https://t.co/xUCBLqxkXA
Exploit contract: https://t.co/xgJwHaRmOH
Vault: https://t.co/isRoO3Eqmv
Tx: https://t.co/KPdsgAP1kO
🚨 ALERT: Term Finance was exploited on Ethereum for an estimated ~$8.5M.
The attacker cheaply acquired majority voting power in a thinly held governance token, passed malicious proposals, seized control of the protocol’s vaults, and drained the assets.
Txs:
https://t.co/gyDuMu6UpL
https://t.co/jLFhXwtitM
Attacker addresses:
https://t.co/shRbvZlY8G
https://t.co/LrYt7ikS9v
🚨[SkyEye Alert] Flashstake V2 - Loss 0.55 WETH ($886) (2026-08-20)
Network: Ethereum
Type: Economic Design / Mispriced Reward Pool
Flashstake V2 was exploited through its instant upfront reward path.
FlashProtocol.stake() calculates minted FLASH only from the
deposited token quantity, lock duration, locked balance and total
supply—without valuing FLASH against external markets. When FlashApp
is selected as the reward receiver, receiveFlash() immediately sells
the freshly minted reward into its FLASH/WETH pool.
The attacker borrowed 10 ETH from Uniswap V4 PoolManager but spent
only 0.11679 WETH to acquire 296,288 legacy FLASH through DODO,
Uniswap V2 and the AMP/FLASH pool. They locked it for 653 days,
received 145,125 FLASH upfront and atomically sold it for 0.54529
WETH.
The reward pool’s WETH reserve fell by 28.25%. After repaying the
borrowed ETH, the attacker made 0.4284 ETH ($696) net profit.
Root cause: cheap externally sourced FLASH could generate unit-based
upfront rewards and be converted immediately into real WETH, with no
oracle sanity check, vesting, cooldown or payout cap. No oracle was
manipulated—the mispriced reward pool itself was the extraction
sink.
TX:
https://t.co/z37H0k9QiE
Attacker:
https://t.co/3fB77QcUZO
Victim:
https://t.co/LoNXcjQzzN
(FLASH/WETH Reward Pool)
X: https://t.co/mwSE0gMWaC
⚡️ Detected 2026-08-20 20:14:23 UTC
⏱️ Real-time alerts: https://t.co/XXmb8rT3VA
We just released our EVM bytecode decompiler🥰🥰🥰.
Paste a contract address → readable Solidity back. Works on unverified contracts, no source needed.
Ethereum + BNB Chain. No login, no signup — just open it and go.
Enjoy it. https://t.co/XpBzymXTIV
🚨 ALERT: @LienFinance was exploited on Ethereum for ~$542K USDC.
The attacker appears to have manipulated pricing in Lien’s GeneralizedDotc bond-to-ERC20 OTC pools by registering crafted bond groups, then swapping newly minted bond tokens against pool liquidity.
Details below 🧵
1/ Exploit tx:
https://t.co/bhjBdVya0x
Attacker:
0x0D7d9023531aD1A88414E216Ee2715F63561808a
Orchestration contract:
0xe74d17c1bE3721E65e0af286D47B3BA58B08062e
2/ The attacker permissionlessly registered new bond groups on BondMakerCollateralizedEth, using a crafted payoff function.
Those newly minted bond tokens were then routed through GeneralizedDotc OTC pools, where pricing from `_calcRateBondToErc20` appears to have overvalued the bonds relative to real collateral value.
3/ As a result, near-worthless bond tokens were swapped for USDC from pool liquidity.
The USDC came from allowances granted by LP:
0xA961684a3a654fb2cCA8F8991226C0CEfc514d80
Final USDC received by attacker:
~542,144 USDC
4/ Affected contracts include:
GeneralizedDotc pool:
0x656e5e976d523a427f05b0c212a22a89ccd9ef18
Type: Oracle / price manipulation
Network: Ethereum
Loss: ~$542K
I verified the main tx path and the final 542,144.628604 USDC transfer on-chain via the exploit transaction / Blockscout mirror.
🚨 ALERT: @exvulsec detected a new exploit targeting the @VerusCoin Ethereum Bridge on Ethereum.
The attacker used the bridge import path (`submitImports`) to trigger Ethereum-side payouts, draining ~$7.54M from bridge reserves across ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
Details below 🧵
1/ Exploit tx:
https://t.co/vdpA08tzFP
Target bridge:
0x71518580f36FeCEFfE0721F06bA4703218cD7F63
Attacker EOA:
0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
Loot wallet:
0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
2/ On-chain, the attacker called `submitImports` on the Verus Ethereum Bridge, after which bridge-held assets were paid out to the loot wallet.
This appears consistent with the May 2026 Verus Bridge incident: same bridge contract, same import path, and a similar bug class, but with a new attacker and loot wallet.
3/ Exchanges, stablecoin issuers, and monitoring teams should flag the attacker and loot wallet for downstream movements:
Attacker:
0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
Loot:
0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
🚨 ALERT: ~159M $ZIL (~$400K) from 46 dormant wallets was swept into a fresh aggregator, then split 30M/30M/99M via hops. Zilliqa confirmed a partner exchange cold-wallet theft.Wallet: https://t.co/BnAiAXQr8F
Txs: https://t.co/EjVLgq90Sd https://t.co/Mzgj3GHwGQ
🚨🚨🚨Security Alert: CompoundProvider Allowance Sweep
CompoundProvider suffered an exploit on Ethereum, resulting in the theft of `774,943.379409` USDC in tx `0xd191fead1b9a2244f2837560f35d4fc865404914d229bfcb0172d1a7a9895afb`.
🔍 Root Cause
The attacker appears to have called an unverified proxy entrypoint that let arbitrary third-party addresses and amounts flow into `CompoundProvider._takeUnderlying`, so any address that had already approved the provider could be drained via `USDC.transferFrom`. The stolen balance was then forwarded by `transferFees()` to the attacker-controlled `feesOwner`, although the exact missing authorization check remains medium-confidence because the implementation contract is unverified.
🧾 On-chain Details
• Exploiter EOA:
`0xf908610e9174c7cd6e9dfd371e238be4511297a1`
• Attack tx:
https://t.co/RxQwimqlmM
🚨 EXPLOIT ALERT 🚨
@Ostium on #Arbitrum has just been exploited for ~$11.86M USDC, draining roughly 32% of the vault’s $34.3M TVL.
🔍 How it happened:
The attack stems from a Private Key Compromise (Oracle Signer) resulting in price manipulation.
A compromised privileged key allowed the attacker’s smart account to act as a registered forwarder. By submitting highly favorable price reports signed by the compromised, authorized oracle, they bypassed the OstiumVerifier.verify() checks.
The attacker then executed 20 loops of delegatedAction ➡️ openTrade + performUpkeep(closeTradeMarket). By feeding these self-signed favorable prices, they were able to instantly open and close trades at a massive profit, siphoning funds from the $oLP vault.
📝 On-Chain Details:
Loss: 11,862,445 USDC
Attacker: 0xD1794196f0fc99c7f27970e661597d77d9a85869
Victim (Vault): 0x20d419a8e12c45f88fda7c5760bb6923cee27f98
Exploit Tx:
https://t.co/CFNLeorE4J
Stay safe out there! 🛡️
#DeFi #Web3Security #CryptoAlert #Arbitrum #HackAlert
@doublezero Massive milestones require uncompromising security. As the DoubleZero network scales past $20B+ TCV, safeguarding the underlying infrastructure and smart contracts is more critical than ever. We're keeping our eyes on the ecosystem. 🛡️ @doublezero