Hello 🦊 fam! We're thrilled to announce that we’re the 1st wallet to enable privacy-preserving security alerts w/ @blockaid_
Our latest feature simulates transactions & signatures directly in your wallet to alert you about malicious requests before you ✍️https://t.co/e1B2GMNe13
🚨 @OnyxProtocol Exploited for 1,164 $ETH (~$2.1M) 🚨
The attacker exploited a critical vulnerability in CompoundV2 forks.
On-chain details 👇
To execute the exploit, the attacker took out a substantial flash loan in ETH, swiftly converting it to PEPE tokens and contributing PEPE tokens to a specific pool.
Due to the precision loss, fewer shares were burned, enabling the withdrawal of assets.
The malicious contract was funded from TornadoCash.
Malicious Tx: https://t.co/OAE20CmviW
Exploiter addresses:
0x085bdff2c522e8637d4154039db8746bb8642bff
0x4c9c8661243e9e9a15a35b8873317eb881330c98
The attacker has already laundered ~1,140 ETH (equivalent to $1.25 million) to the crypto mixing service Tornado Cash
Stay Safe 🛡
🚨UPDATE🚨 On July 6th, @MultichainOrg faced a $126M hack! We have detected real time 👇
🚀But today exciting news! @MultichainOrg has resumed processing bridge transactions after 117 days of downtime.
💼 Many bridge transactions successfully went through.
🛡️ We're closely monitoring the real-time
developments!
#CyversAlert
#PeckShieldAlert ~32 hacks netted $32.47M (with ~$5.1M worth of cryptos recovered) in October 2023.
Top 5 hacks:
• An #Fantom Foundation employee’s wallet was drained of ~$7M worth of cryptos
•Philippine-based exchange Coins[.]ph lost 12.2M XRP (~$6M) in a potential exploit
•Several victims lost ~$4.4M as a result of the #LastPass hack
•burgel.eth was drained for ~$3M across multiple addresses
•#StarsArena was hacked for ~$3M worth of #AVAX
#FTX Exploiter bridged around 86K $ETH to #Bitcoin during October
🚨A scammer executes RugPulls on a daily basis 🚨
Two tokens on #BASE have experienced #rugpulls, leading to the acquisition of ~95.35 $WETH and ~107.61 $WETH.
Tokens involved:
1⃣ 0x2Fe40A68F3F3a56103608f7b55f79161b5c4A32C
2⃣ 0x18E1867b7BbDab2aE621e4Abb9EccD05db189C00
We are helping the @OnyxProtocol team right now with an incident they are experiencing - an empty market attack. In the past, we worked with Compound to outline how to open new markets safely: https://t.co/12r8NmceLU
@OnyxProtocol@peckshield The Onyx Protocol hacker exploited a known bug, a rounding issue behind the popular CompoundV2 fork, explained blockchain investigator PeckShield soon after alerting about the hack that went unnoticed by the protocol.
https://t.co/vytgXHxLhF
All they had to do was respond to my message and negotiate returning funds.
Instead the exploiter is now looking at five years in prison in France for the attack.
The @OnyxProtocol was attacked due to *precision loss vulnerability*. In OnyxProtocol, the oPEPE market was initialized (by proposal 22) shortly before the attack. The attacker minted small shares and donated a large amount of PEPE to the oPEPE market, causing the exchange rate to be biased, and borrowed Ether. Then the PEPE was all redeemed back to the attacker due to the precision loss bug in the redeemUnderlying function.
Here is the attack tx:
https://t.co/jku7Phbllz
#CertiKSkynetAlert 🚨
@OnyxProtocol was exploited via a malicious flash loan resulting in ~$2.1m lost
The vulnerability is due to a known rounding issue in CompoundV2 forks.
The issue was outlined in Onyx’s audit and acknowledged by the Onyx team.
https://t.co/eQDgn3LJJr
#CertiKStatsAlert 🚨
Combining all the incidents in October we’ve confirmed ~$32.2M lost to exploits, hacks and scams.
Exit scams were ~$8M
Flash loans were ~$1.7M
Exploits were ~$22M
See more details below 👇
Rabby Wallet is now seamlessly integrated with @mpcvault 🎉
MPCVault is a self-service, multi-chain, multi-sig, and multi-asset non-custodial banking solution. It has become the go-to choice for Web3 companies, offering top-tier security and control.
MPCVault users can now connect to Rabby Wallet and explore the Web3 ecosystem smoothly!
Our DNS monitoring successfully captured the Frax Finance front-end domain's ISP was changed from "Cloudflare" to "DDOS-GUARD" since "2023-10-31T22:34:44.618Z".
🚨SlowMist Security Alert🚨
According to @fraxfinance , Frax Finance's DNS has been attacked!
SlowMist's CISO @IM_23pds reminds that this is the third recent security incident where domain names have been taken over through social engineering. Stay vigilant!
@realScamSniffer captured the Frax Finance's DNS change👇