šØTHREAD #nft#BTC#ETH#BNB#SOL
HOW TO SPOT SCAMS š§µ.
The best way to protect yourself from fraud, scams, and theft is to learn to spot them.
Here are 4 common scams and how to spot them: š
@DawnF628630 You have to be very careful not to fall into the wrong hands
I will advise you base on safety on here to only get In touch with this recovery agent, @OnChainRscue they will guide you through and recover your lost.
@veg_davi You have to be very careful not to fall into the wrong hands
I will advise you base on safety on here to only get In touch with this recovery agent, @OnChainRscue they will guide you through and recover your lost.
I understand how you feel, I too was sc*mmed by an elon imposter, my lawyer recommended me to @OnChainRscue for their deploying back services they were of big help to me tracking my sc*mmed money and got me refunded you should
I understand how you feel, I too was sc*mmed by an elon imposter, my lawyer recommended me to @OnChainRscue for their deploying back services they were of big help to me tracking my sc*mmed money and got me refunded you should
šØ$7.6M gone from @rhea_finance
Attacker deployed fake tokens, added liquidity to fresh pools, and fooled the oracle layer.
~$470M stolen YTD.
We as whitehats aren't doing enough.
ALERT! Our system detected a series of suspicious transactions targeting one victim address (0xaCc0c1f672B03B9a5fED4535f840f09B85f40E98) across Arbitrum, BSC, Avalanche, Optimism, and Base, with estimated total losses of about $517K.
The victim had pre-existing MAX_UINT approvals to a SquidMulticall-related contract deployed at the same address across all affected chains (0xaD6Cea45f98444a922a2b4fE96b8C90F0862D2F4); the attacker leveraged these approvals through the permissionless run() entrypoint, executing crafted multicalls with transferFrom payloads to transfer tokens directly from the victim.
š¦ Found by #PhalconSecurity, š¦ Analyzed via #PhalconExplorer.
āļøZoo Finance got hacked for ~27k
The bug was in @ZooFinanceIO custom hook built on UniswapV4, using a custom `ln()` price curve
The hook approximated execution price with a simple midpoint average instead of integrating properly, creating a directional bias where:
1. ATH to vATH - slightly overpay the swapper
2. vATH to ATH - slightly underpay the pool
The attacker chained 20+ alternating swaps inside a single `unlock()` callback, each round trip netting a small profit.
Weekly Web3 Security Incident Roundup | Mar 16 ā Mar 22, 2026
During the past week, BlockSec detected and analyzed seven attack incidents, with total estimated losses of ~$82.7M.
š¦ Detected by #PhalconSecurity, š· Analyzed via #PhalconExplorer.
šØ SlowMist TI Alert: LiteLLM Supply Chain Attack
The widely used LLM routing library #LiteLLM (~97M monthly downloads) was recently reported to be affected by a PyPI supply chain attack. A suspected malicious version (1.82.8) may lead to sensitive data exposure upon installation.
ā ļø Potential impact includes:
⢠SSH keys
⢠Cloud credentials (AWS / GCP / Azure)
⢠Kubernetes configs
⢠Git credentials & API keys
⢠Shell history, database passwords, crypto wallets, etc.
Notably, the risk may be triggered automatically via a .pth mechanism during Python startup, meaning no explicit function call is required in certain cases.
š„ Potentially affected scenarios:
⢠Direct installation of LiteLLM
⢠Projects depending on LiteLLM
⢠Indirect dependencies (e.g. AI tooling ecosystems)
⢠Shared environments or containers
š Suggested check:
pip show litellm
If version = 1.82.8, further investigation is recommended.
There are reports suggesting possible large-scale data exposure and credential leakage, though the full scope is still being assessed.
š Recommended actions:
⢠Remove or replace the affected version
⢠Rotate relevant credentials as a precaution
⢠Review logs, access records, and sensitive data usage
Stay vigilant!
ALERT! Our system detected a suspicious transaction targeting a PancakeSwap pool (BCEāUSDT) on #BSC hours ago, resulting in ~$679K in losses.
The root cause appears to be a flawed burn mechanism in the BCE token. The attacker deployed two malicious contracts to bypass buy/sell restrictions and trigger token burns within the pool.
This manipulation skewed the pool reserves, allowing the attacker to drain the BCEāUSDT pool for ~$679K in profit.
The attack Tx: https://t.co/1JqoWCpaA2
š¦ Found by #PhalconSecurity, š¦ Analyzed via #PhalconExplorer.
ā ļø With crypto adoption growing and stablecoins accelerating cross-border fund flows, VASPs face increasingly complex #AML & #KYT challenges.
šššWe're thrilled to announce our new product: SlowMist KYT, transforming years of blockchain intelligence into a full-lifecycle compliance system
šFor more detailed industry insights and AML trends, read our latest report:
https://t.co/eIQdrvnPe6
šØ AI Agents like #openclaw are evolving into high-privilege operators across AI and Web3 environments.
To address these risks, we introduce a comprehensive security Solution for #AI and #Web3 Agents ā designed to make autonomous systems observable, controllable, and auditable.āØ
š”ļø The architecture forms a five-layer āDigital Fortressā around AI Agents:
š¹ MistEye serves as the retina (threat perception)
š¹ MistTrack as the immune system (on-chain risk control)
š¹ OpenClaw security practices as the skeleton (behavioral constraints)
š¹ MistAgent as the brain (deep analysis and auditing)
š¹ ADSS as the armor (full lifecycle protection)
š Read the Full Security Solution:
https://t.co/c6achBBAwp
ALERT! Our system detected a suspicious transaction targeting the MTāWBNB pool on #BSC hours ago, resulting in an estimated loss of ~$242K. The root cause stems from a flawed buyer-limitation mechanism: in deflation mode normal buys revert while router/pair are whitelisted, allowing the attacker to bypass restrictions via router swaps and liquidity removal to obtain MT from the pair.
The attacker then sold MT to accumulate pendingBurnAmount and called distributeFees() to burn MT directly from the pair, artificially pumping the price before swapping MT back to WBNB for profit. Additionally, a referral rule allowing the first 0.2 MT transfer to bypass buyer limits enabled the attacker to bootstrap the attack.
Attack TX: https://t.co/yuLpgYkRky
š¦ Found by #PhalconSecurity, š¦ Analyzed via #PhalconExplorer.
#PeckShieldAlert The attacker who drained $24M worth of $aEthUSDC from @sillytuna has swapped ~$2M worth of $DAI & $ETH for 6,174.4 $XMR, which is currently held on #Hyperliquid.
Additionally, they have deposited ~6.5M $USDC & $USDT into CEXs including OKX, MEXC, & Bitkan, and laundered 375 $ETH via #TornadoCash.
#PeckShieldAlert A @sillytuna (0xd2e8...ca41)-related address has been drained of ~$24M worth of $aEthUSDC in an address poisoning attack.
~$20M in $DAI is currently sitting in 2 attacker-controlled staging wallets (not yet mixed):
-0xdCA9...c9C4 (~$10M)
-0xd0c2...dd3e (~$10M)
The attacker has already begun bridging small amounts to #Arbitrum.