🧵 [4/9] 🚨 Supply chain attack:
A victim likely lost $723K after interacting with a website compromised by the Lottie Player supply chain attack.
Remember: Even seemingly legitimate websites may pose risks. Stay vigilant! 🔍
https://t.co/RJjsYHK2pV
Let's see what does high/crit in the first 24h means.
In 24h protocol can confirm either:
Funds drainable
Funds permanently lockable
Users rekt LP profits/principle gone
Traders bleeding on every tx
Bots skimming vaults each iteration
That's just the first 24h.
As someone who transitioned from traditional cybersec to Web3 security, here’s how I did it:
1. Learned smart contract development
2. Studied smart contract security basics
3. Practiced in public contests
4. Took on private audits
💡 What leads to restricted access in liquidity pools? 🤔
In our third Critical Spotlight episode, Isabel Burruezo Lopez, Principal Security Engineer at Halborn, explains DoS vulnerabilities in liquidity pools and practical security measures for #blockchain developers. 🛡️
Y’all please, for the love of all things holy, cement this inside your brains.
I have seen SO MANY BLOODY PEOPLE absolutely f*cked recently by this, and it’s a rapidly growing problem.
🚨WARNING 🚨
If you go to get on a video call...
and you see this screen...
YOU ARE ABOUT TO GET REKT!
1. STOP what you are doing!
2. Close the window.
3. Do not say ANYTHING to the person youre supposed to have the call with.
4. Message https://t.co/KpaDMTqJ5L for help!
Web3 security market is popping - 15 security contests in parallel, so many security researchers booked and busy. Every serious protocol is doing multiple security audits nowadays and I see no slowing down of this trend anytime soon✌️
ALERT! Our system has detected a suspicious transaction targeting an unknown project on #Base, resulting in a loss of approximately $1M. The affected project appears to be a #Compound fork, with multiple markets being drained. As the contracts are not open-source, we suspect this may be a classic price manipulation attack caused by reliance on Uniswap's spot price.
Attack TX: https://t.co/PkAc317fKZ
Subscribe to BlockSec Phalcon today to get alerted in realtime and take automatic actions to protect your assets. https://t.co/5cGK9A1psv
A small hack I use to suppress the "Function state mutability can be restricted to view" warning in my PoCs is a noView modifier to modify state uint _noView; modifier noView() { _noView++; _; }
📑 Root cause analysis from past DeFi incidents. Hope this stuff can help devs to avoid the same mistakes as much as possible.
Now covered 95 incidents.
https://t.co/4tSjtqBhuU
#DeFi#Web3
We've just released a detailed analysis of the @lifiprotocol LiFi Attack, where a vulnerability in the GasZipFacet contract resulted in significant losses.
👉 Check out the full report here: https://t.co/O1D0vWZAdI
📊 Explore the MetaSleuth Chart here: https://t.co/NFU6wuYXwM
🔍 We used #MetaSleuth to trace the stolen funds and reveal the full impact of the exploit.
🕵️ Simplify and enhance your on-chain investigations with #MetaSleuth