I got a leaked document from a Botify investor.
• ~$1.5M spent on KOL marketing, listings, fake metrics and even a UEFA partnership.
• Supply gifted to friends and family
The token pumped to $67M and now it's completely abandoned.
I checked all the transactions on-chain and everything matches.
I am here to tell the full story 🧵
10% of tvl bounties as marketing fiction for large protocols
immunefi popularized "up to 10% of impacted funds" presentation for critical bounties. this sounds impressive until you check the caps.
looking at top-50 protocols, the payout is always capped by dollar amount. for top-20 protocols, it results in effective rate of 0.05% avg, 0.003% median.
as an example, aave has $33b tvl, but max crit bounty is $1m. "0.003% for a crit" doesn't sound nearly as alluring and doesn't guide researcher priorities as well.
yearn has never adopted % bounties, while having a track record of multiple max critical payouts to show for it. this should be another thing security researchers look at. high advertised bounties are meaningless if they have never been paid out.
actionable suggestions for immunefi:
- show effective % alongside advertised %
- display max payout history, not just total paid
data: immunefi, defillama
if you want to explore raw data by yourself: https://t.co/QWqgm5oP4A
The rug is completed
@Axe_capital deleted his account
@HypurrCap rugged 10k~ hype from the eco
Dude is apparently "doxxed" someone should find this dude lol
Feels bad for anyone who bought especially after people were vouching for him
Believe in Karma
‼️🇮🇱 Smartphones worldwide were silently infected with Israeli malware via malicious ads
Simply viewing their ads was enough to get infected.
Surveillance company Intellexa gained full access to cameras, microphones, chat apps, emails, GPS locations, photos, files, and browsing activity.
UPDATE 2 – The HL Whale 0xb317 has increased his position again:
>Received another $10M from Binance and immediately deposited the entire amount on Hyperliquid
>Increased his existing long position, which now totals $69M with 5x leverage
>Currently showing an unrealized PnL of $1.1M
[SBF says:]
1) President Trump just pardoned Juan Orlando Hernández (JOH), the former President of Honduras.
I spent a year and a half living in the same unit as @JuanOrlandoH. I got to know him fairly well. I'd like to think we became friends.
Juan Orlando is the most innocent prisoner I've met.
NEW: Solidity Version 0.8.31 is OUT!
Virtual modifiers and usage of `send` and `transfer` methods of `address` type variables now give you a deprecation warning (good stuff). No Critical Severity vulnerabilities found/fixed here🫡
#CertiKInsight 🚨
The BunniV2 exploiter has deposited 2295.8 ETH (~$7.23M) into @TornadoCash in 22 batches of 100 ETH, 9 batches of 10 ETH and 5 batches of 1 ETH.
BunniV2 was exploited on 2 September 2025.
https://t.co/xrX0Si6klw
someone just got drained for $27m across all chains
website link auto download + auto executable file which went through all passwords and backups for all chains
crypto is way too dangerous man wtf
Did the Founder of Curve Finance Finally Solve Impermanent Loss Forever?
Impermanent Loss is one of the biggest problems for DeFi LPs. It is the temporary value drop for DeFi liquidity providers due to price volatility and causes many LPs to miss out on upside.
Yield Basis is Curve Founder Michael Egorov’s prospective solution to impermanent loss in DeFi. Here’s how it works:
#PeckShieldAlert@bunni_xyz Exploiter labeled address has deposited 2,295.8 $ETH (worth $7.3M) into #TornadoCash.
This comes after Bunni suffered an exploit on Sep. 2, resulting in a loss of ~$8.4M. The team has announced a shutdown in October.
🚨On Dec 1, @yearnfi was exploited, resulting in ~$9M in losses.
🛠️The SlowMist security team analyzed the incident and identified the root cause:👇
The vulnerability stems from the logic inside the _calc_supply function used to calculate supply in Yearn’s yETH Weighted Stableswap Pool contract. Due to unsafe mathematical operations, the function allows overflow and rounding during calculation. This flaw leads to a significant deviation when computing the product of the new supply and virtual balance, enabling attackers to manipulate liquidity to specific values and mint an excessive supply of LP tokens, thereby profiting illicitly.
🔍We recommend strengthened edge-case testing and the use of secure, validated arithmetic operations to prevent severe vulnerabilities like overflow in similar protocols.
Full analysis👉 https://t.co/aVzCpSc65n
#PeckShieldAlert @USPD_io has reported an exploit resulting in a loss of ~$1M. Please revoke all token approvals to USDP contract.
https://t.co/4mQqoE8EWO
🚨Beware of Solana #Phishing Attacks: Wallet Owner Permissions Can Be Altered
1️⃣Recently, we assisted a victim of a phishing attack that resulted in the unauthorized transfer of his account’s Owner permission. This is similar to the "malicious multisig" –style attack commonly seen on #TRON.
The victim lost over $3M in assets. Another $2M locked in DeFi protocols was inaccessible — though fortunately, this portion has now been successfully recovered with help from the relevant #DeFi teams.👏
2️⃣How the #Solana Owner Modification Works🔐
The attacker exploited two counter-intuitive behaviors:
🔹No visible balance change during signing: Wallets typically simulate transactions and show balance effects. The attacker crafted a transaction with no visible changes, lowering suspicion.
🔹Users don’t intuitively expect ownership to be changeable: Unlike Ethereum EOAs, Solana accounts allow their Owner field to be reassigned, which many users don’t realize.
3️⃣Understanding Solana Account Ownership🧩
Solana accounts fall into two major types:
🔹Normal Accounts
🔹PDA (Program-Derived Accounts)
Token accounts also use their own ownership rules enforced by the token program, which are frequently targeted in phishing campaigns.
4️⃣MistTrack Tracing🕵️
Our @MistTrack_io analysis of the attacker’s address revealed highly complex fund movements. Assets were routed primarily through two hubs:
🔹BaBcXD…
🔹7pSj1R…
The laundering pattern included:
• rapid multi-address hops
• multi-platform mixing
• cross-chain cycling
• CEX deposits
• reuse of DeFi assets
5️⃣How to Protect Yourself from Similar Attacks🛡️
This incident ultimately stems from phishing. Attackers use fake:
✨ airdrops
✨ quests
✨ whitelist invites
✨ announcements
✨ reward claims
These links trigger signature requests containing high-risk operations like Owner reassignment.
Before clicking or signing, always ask:
🔹 Is the source legitimate?
🔹 Is this really from the official team?
🔹 What exactly is this signature doing?
🔹 Are there unfamiliar permissions or unknown addresses?
If you don’t understand the permission request — STOP! Never sign out of uncertainty‼️
6️⃣Best Practices to Reduce Risk🧊
✔️Use a low-value wallet for interactions, quests, and airdrop hunting.
✔️Keep high-value assets isolated — ideally in cold storage.
✔️Avoid granting unlimited approvals; limit allowances whenever possible.
✔️Always verify URLs and signature prompts.
✔️Never approve operations that seem unrelated to what you intended to do.
Your strongest defense is simple:
⛔Don’t click blindly. Don’t sign blindly.
🔗Details: https://t.co/3ljUts50oI