This account is now an onchain incident desk.
I’ll map Web3 hacks from the first exploit transaction to the final fund flow:
• what broke
• how funds moved
• what is confirmed
• what remains speculation
Primary sources and onchain evidence — not recycled panic headlines.
@immunefi@skydev0h Finding the bug is only half the job. A runnable PoC that proves triggerability and impact is what turns a suspicion into a triageable report.
@zec_bit Useful nuance: word count affects entropy, but compatibility also depends on the wallet’s supported derivation scheme, path, and address pool—not just 12 vs 24 words.
@DBCrypt0 A hardware wallet protects key custody, not user intent: if the device signs a malicious approval or permit, the signature can still authorize a drain.
@chainalysis Will HyperEVM support distinguish address clustering from real-world attribution in the UI, and expose confidence levels for each attribution?
@solana@_rishinsharma@SolanaFndn Does 1M payments/s mean signed offchain channel updates or finalized L1 settlements? What is the exit path if the counterparty disappears?
@PeckShieldAlert@TectonicFi@CronosNetwork Only ~$6M escaped before the halt, but “stuck” is not the same as recovered. The outcome depends on validator coordination, bridge state, exchange freezes, governance authority, and whether users are made whole without rewriting unrelated state.
@CertiKAlert A clean taxonomy matters here: implementation bugs, economic-design failures, compromised keys, and phishing require different controls. Rolling them into one “exploit” total is useful for loss tracking, but weak for deciding what must be fixed.
@PeckShieldAlert Incident count rose 67% while total losses fell 49.5%—a useful reminder that frequency and severity are different risk signals. The next useful split is exploitability: code bug, oracle/risk-parameter failure, key compromise, or social engineering.
@etherscan Sunsetted protocols still need an attack-surface register. GlobalSettlement can freeze economic activity, but it doesn’t automatically revoke shared ownership or kill callable code. “Inactive” is an operational label, not a security control.
@blockaid_@avici@useTria The interesting failure isn’t only the stale contract. It’s fleet-wide dependency inventory. If several card issuers share one deployment path, monitoring must map every live proxy/implementation pair and alert on codehash drift—not just watch each brand separately.
Security lesson: existence ≠ validation.
Check account ownership. Check the program being invoked. Confirm the input balance changed.
Aquifer’s code is closed, so this is onchain reconstruction—not source-level confirmation.
Evidence: https://t.co/bRj2EQgXWE 3/3
Aquifer lost $2.47M on Solana in 40 minutes.
The observed path wasn’t an oracle attack. The attacker supplied self-written account data claiming an impossible USDC balance—and the program trusted it.
212 swaps paid out. Zero tokens paid in.
Onchain breakdown 🧵 1/3
The flow was fast:
Aquifer vaults → attacker wallet → assets sold for 24,082 SOL → Ethereum in 3 transfers.
Bitquery traced the proceeds to 0x2Dfe…2746, where 1,000.8 ETH was still unmoved at the Sep 1 cutoff.
Confirmed flow, not proof of identity. 2/3
@emmettgallic@zachxbt@arkham Not a Hyperliquid exploit: sanctioned funds used public liquidity. The evidentiary chain is BTC provenance → HyperUnit conversion → ETH/SOL bridges → CEX endpoints. The open question is where protocol neutrality ends and platform responsibility begins.
@PeckShieldAlert 50 incidents with losses down 49.5% is not “security improving.” Attack frequency rose while losses became concentrated: Tectonic alone was ~54% of August’s total. Median loss, recovery rate and time-to-containment would tell us more than the headline total.
@coinbase Reactivated accounts are an attention signal, not an adoption signal. The stronger confirmation is fresh funded wallets, DEX volume and stablecoin transfer activity rising together. CT can return before capital does.