Exploiter: https://t.co/fSVu3B6w16
Some of the exploit transactions:
Mint $LBTC to exploiter: https://t.co/5atrgyNmvs
Supply $LBTC to ionic: https://t.co/cgP3L5e1HS
Borrow assets from ionic: https://t.co/Yi65obNfb7
⚠️#OKLinkAlert
The @ionicmoney platform on @modenetwork suffered a security breach, resulting in an estimated loss of $8.8 million.
The exploit was enabled by the introduction of a new market for a fake $LBTC token, which was deployed by the attacker.
@ionicmoney has warned users to avoid interacting with the application until further notice.
Approximately 1,300 $ETH has been bridged to Ethereum and laundered through @TornadoCash. The remaining funds are still held at the exploiter's address on @modenetwork, and we will continue to monitor asset movements in real time.
Funds are currently held at the following address, and we will monitor asset movements continuously in real time.
🔗https://t.co/0dxcDP9zz7
🔗https://t.co/wYFDASDb8g
🔗https://t.co/hUxy8S1fMB
⚠️#OKLinkAlert
The @TheGemPad protocol experienced a security breach on Ethereum, BNB, and Base networks, resulting in a loss of approximately $2.2 million.
The attack was made possible due to the absence of nonReentrant protection in the GempadLock contract.
Below is one of the attack transactions:
https://t.co/I0R1OIve8Q
💡Reminds: Double-check recipient addresses for onchain transactions.
Users lost billions copying wrong addresses from compromised records.
Verify directly! Avoid copying from transaction or chat histories.
⛑️OKLink Security Report - November
No major Rug Pull scams this month!
In November, total network losses hit approximately $203 million, with phishing scams responsible for $131 million (64.8%).
👉Note: On November 13th, a user mistakenly copied an incorrect address from a compromised transaction history, leading to a $129 million loss due to a phishing attack. The attacker returned all assets within an hour.
⚠️#OKLinkAlert@XTexchange experienced an abnormal transfer of assets from the platform wallet 0xdb3d...fd7c, involving assets valued at approximately $1.7 million.
The hacker has swapped the stolen funds for 461.58 $ETH which is currently held at the address 0xB43f...8F83.
@XTexchange stated that these assets are owned by the platform and will not in any way harm the interests of their customers or users.
The attack was made possible due to missing input validation in claimReward() and the lack of nonReentrant protection in wrapNativeToken(), allowing the attacker to drain all assets from the pools while bypassing the health factor check.
The @DeltaPrimeDefi experienced a security breach on #Arbitrum and #Avalanche resulting in a loss of approximately $4.8 million.
Below is one of the attack transactions:
https://t.co/6Mh8vDEFOS
We're at the DeFi Security Summit today! 🔒
Joining forces to make blockchain applications safer — both onchain and off-chain.
Excited to connect with everyone here in Bangkok!
Stay alert for phishing attacks using "permit" and "approve" on social platforms this month.
✅ Verify receiving addresses carefully.
✅ Secure private keys for multi-sign wallets.
More details🔗 https://t.co/bmyBB4utFF
⛑️OKX Explorer Security Monthly Report
In October, onchain losses totaled $181 million, up 38.9% from last month. Phishing scams caused $43.53 million in losses.
👉On Oct 11, a Blast user lost $35 million in fwDETH due to a phishing "permit" signature.
👉On Oct 16, Radiant Capital's multi-sign wallets were breached, resulting in $58 million in losses.
⚠️#OKLinkAlert@tapioca_dao reported that they recently fell victim to a social engineering attack, resulting in the compromise of the USDO stablecoin and the TAP token vesting contract.
The total loss amounts to approximately 591 ETH and $2.8 million USDC: https://t.co/atlFY716cw
@tapioca_dao reported that they recently fell victim to a social engineering attack, resulting in the compromise of the USDO stablecoin and the TAP token vesting contract.
The total loss amounts to approximately 591 ETH and $2.8 million USDC:
https://t.co/58spOI0HeB
@RDNTCapital urges its users to revoke access to the following contracts on https://t.co/17xNU1VXwe:
1️⃣0xF4B1486DD74D07706052A33d31d7c0AAFD0659E1
2️⃣0x30798cFe2CCa822321ceed7e6085e633aAbC492F
3️⃣0xd50Cf00b6e600Dd036Ba8eF475677d816d6c4281
4️⃣0xA950974f64aA33f27F6C5e017eEE93BF7588ED07