We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JSON libraries in production today, even with 2.x around.
No classpath gadget. One payload-> RCE.
Three crypto protocols lost $35M in the week of July 5. Two of them never had their code broken. 👇
If your security program ends at the contract audit, you are defending the one door the attackers didn't use.
Read as a red teamer would:
→ BonkDAO, $20M. Zero exploit. The attacker spent $4.4M buying BONK on the open market, then passed BIP #76 through token-weighted governance on Realms. Seven addresses voted. Attacker-linked wallets held 99.878% of the power cast. 18,000+ holders did not show up. The proposal sat live for six days. 4.43 trillion BONK left the treasury. Return: 4.5x. That is not a hack, it is a hostile takeover through the front door.
→ https://t.co/dDx8czK1tA, $6.04M. Root cause was not the code. An Ark had its deposit cap zeroed during offboarding, but it was never removed from the vault's NAV calculation. Zeroing a cap stops inflows; it does not stop the impaired market from setting your share price. The attacker spent three months quietly accumulating Silo vault tokens that had been mispriced since Stream Finance died in November 2025, donated them into that Ark, and redeemed. The $65.4M Morpho flash loan was liquidity for the final transaction, not the vulnerability. An offboarding checklist would have caught this. An audit would not.
→ Bonzo Lend, $9.05M. Supra's Hedera verifier accepted a SAUCE price update signed with a degenerate BLS signature and a zero-valued public key, inflating the price by twelve orders of magnitude. 250 SAUCE, worth about three dollars, borrowed 6.63M USDC and 34.5M wHBAR. Eight seconds. $5.25M bridged to Ethereum. Bonzo's contracts worked exactly as designed. Hedera TVL fell 40% in a day.
The through-line: governance, oracles, and third-party dependencies do not appear in your audit scope. That is where the money went.
The kicker: https://t.co/dDx8czK1tA is shutting down. Five years, a Maker Foundation spinout, $200M peak TVL, ended by a $6M loss because a deprecated adapter stayed in a pricing formula. The loss did not have to be large. It had to be unowned.
If you are defending this surface:
- Red-team governance as an attack path: token concentration, quorum floors, timelocks, proposal review SLA, emergency multisig.
- Bound your oracle consumers. Reject out-of-range deltas regardless of signature validity. Redundant feeds. Your vendor's bug becomes your loss.
- Treat asset offboarding as a security control with an owner and a completion test, not a housekeeping ticket.
- Monitor proposals and votes as security events, not community chatter.
You audited the code. Who is attacking everything around it?
If you don't know the answer, that's the engagement. DM us.
#OffensiveSecurity #Web3Security #DeFi
I got permanently banned from @Hacker0x01. Account deleted. No explanation.
Years of work gone overnight. Submission history, achievements, leaderboard ranks, every contribution I made to the security and crypto ecosystems through HackerOne. Wiped, like I was never there.
How to access servers behind Cloudflare by bypassing the firewall?
@FearsOff#bugbountytips#cloudflare#firewall#bypass
1) Found a sweet hostname but Cloudflare Firewall blocks you? There's a neat trick attackers can use if the origin is misconfigured.
Marwan Hachem, COO of FearsOff Cybersecurity, warns that a critical #RoundCube vulnerability threatens national security across governments and major institutions, urging urgent updates as exploits are now publicly available. #GNT
If you’re using cPanel, Plesk, ISPConfig, or DirectAdmin, you’re likely in the line of fire for CVE-2025-49113 – all of them bundle Roundcube by default. If your server/website exposes any of these ports: 2083, 2086, 2087, or 2096, you’re vulnerable.
#CVE#roundcube@FearsOff
Excited to share that I reported CVE-2025-48745, Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization. This bug has existed undetected for 10 years and affects over 53 Million hosts.
Details and PoC will be published soon.
We're giving time to all affected parties to make the necessary patches/updates. Safe versions are 1.6.11 and 1.5.10 LTS. https://t.co/yRhNe8iRkF #roundcube #cve
@NahamSec 1. Interest: the battle of hacker logic against the mistakes of engineers
2. At some point, you realize which program is more suitable to your liking, regardless of its maximum and minimum payments(or there are none at all)It's unexplainable🙄
3.The program gives you cookies🙈
After leaving the hospital, I noticed that I finally have 1k reputation in @Hacker0x01 🥳
It was a difficult hike up this "mountain"
Good luck and happy hacking to everyone! Stay safe!
This year was very memorable for me, it was the third consecutive year where I was top-1 in the security @Hacker0x01 program, as well as it became a record for me in terms of the number of reputation.
Happy hacking && Happy New Year!
#TogetherWeHitHarder
Hackers, at the end of the year, try looking at your old reports that were missing a little detail to make them valid, and you might find them, @Hacker0x01
https://t.co/PuFzsrNlwl