Just got a bug reward from @safetrade🫡
I stumbled upon the website by chance.
I decided to perform a penetration test on it and discovered a bug with a medium severity rating. I reported it, and the report was accepted.
Thank you, Safetrade.
🚨SlowMist TI Alert🚨
💸 GebProxyActions Loss: ~5.9436 ETH
🔍 Root Cause: `GebProxyActions.quitSystem` lacks caller access control. Victims previously called it directly instead of via DSProxy delegatecall, causing `ownsSAFE[safe]` to be set to the GebProxyActions contract. The attacker called `GebProxyActions.quitSystem(manager, safe, dst)` directly, bypassing GebSafeManager's `safeAllowed` check and transferring collateral to themselves.
📌 Attacker: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
📌 Victim: CollateralJoin1 0xe843783144acdf485ff86d726bcb67dd316e0bbe (SAFE #3, #5, #8, #18)
📌 Vulnerable Contract: GebProxyActions 0x84fe452d9fb495a335c74a225e6ad52c35eb8616
Powered by https://t.co/Mz5jOnx997
Tx: https://t.co/A2od86bQf0
🚨 ALERT — Exploit on Ethereum
A GEB/RAI-style CDP deployment (Reflexer's GEB framework, in Global Settlement since Jan 2021) was just drained of its leftover ETH-A collateral. ~5.94($14k) ETH stolen.
Root cause:
several SAFEs were owned by the shared GebProxyActions library itself (0x84fe452d9fb495a335c74a225e6ad52c35eb8616), not by user proxies. Its quitSystem() is public and unauthenticated, so the attacker called it directly — GebSafeManager's msg.sender == ownsSAFE[safe] check passed (the library calling as itself) — and migrated other users' collateral to himself, then freeCollateral + exit.
Flow (per SAFE): processSAFE → quitSystem → freeCollateral → CollateralJoin.exit → WETH.withdraw
Attack tx: https://t.co/KAmU46mQB8
Attacker: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896
Exploit contract: 0x6a213f0b5bd9eed865d3e2efc867b73dfe9039e7
Lesson: never let a stateless, shared "proxy-actions" contract become the registered owner of a position — its public helpers turn into anyone's withdraw button.
Subscribe to our TG bot for real-time attack alerts 👉 https://t.co/XXmb8rT3VA
🚨 A HACKER JUST DRAINED $75 MILLION AND AN ENTIRE BLOCKCHAIN SHUT ITSELF DOWN TO STOP THEM.
Tectonic, a lending protocol on Cronos, the network built by Crypto. com, just got exploited.
How do you drain $75 million from a lending protocol without stealing a single password.
You don't steal anything. You manipulate the price of collateral until the protocol itself hands you the money.
Onchain researcher Weilin Li estimates the attacker pumped the price of TONIC, a thinly traded token, roughly 100x in a short window. Then used that inflated, fake value as collateral to borrow around $75 million in other assets. The protocol thought it was lending against real value. It wasn't.
You'd expect an attacker moving that fast to get all of it out before anyone could react.
They didn't. Only about $6.29 million made it out, bridged to Ethereum and swapped into 2,592 ETH. Cronos Network halted mid-attack, freezing roughly $68.7 million before it could leave the chain.
Read that again. A blockchain, the actual network, paused itself to trap stolen funds mid-heist.
Now validators are facing a decision most crypto networks never have to make in public. Restart the chain as-is and let the attacker keep what already moved, or roll back transactions to try to reverse it, which raises its own argument about whether a "decentralized" network should be able to undo history at all.
Tectonic hasn't confirmed the exact amount or root cause yet. Crypto .com says its own app and exchange weren't touched.
$6 million got away. $68.7 million is sitting frozen, waiting on a decision that could define how "immutable" this chain actually is.
🚨 Exploit Alert — Ethereum
~10.7 ETH was drained from two legacy Visor/Gamma FLOAT-ETH Hypervisor vaults via a flash-loan price manipulation.
🔍 Root cause: the Hypervisor mints LP shares in deposit() off the Uniswap V3 pool's INSTANTANEOUS spot price (currentTick()/slot0) with no TWAP and no spot-vs-oracle deviation check — while withdraw() redeems shares for a proportional slice of the real underlying tokens. Minting is spot-priced, redemption is not. Move the spot price and deposit→withdraw becomes a net drain. Deposits are permissionless (whitelist disabled).
🧾 On-chain:
Attacker: 0xaea29218262dc6b0904ca077f6527c49dfd426d9
Contract: 0x05303c95ee7ff76daf1421b28e024635d7fe51ab
Vaults: 0x85cbed52…a8a70c · 0xc86b1e7f…c1153
Tx: 0x3d7549db65344da2a41067e17791b17fac16ec6b8e5132e82e243f6541de5cff
Block: 25874402 · 2026-08-31
In two days we open the public season of Break QoreChain.
On September 1 the bug bounty over the network itself opens for structured submissions: scope, severity classification, pool address and payout schedule, all published that day. The standing bounty of 67,500,000 QOR has been active since mainnet launch. Post-quantum implementation issues, including side channels, carry the highest priority.
What is already committed and published: guaranteed minimums paid in USDT within days of triage, rewards in stablecoins rather than only our own token, full safe harbour for good-faith researchers under the SEAL Whitehat agreement, and every valid report published after the fix, with credit.
Anything you report before opening is covered retroactively at full program rates. If you already found something, do not wait.
[email protected]
https://t.co/31m5ICBsoC
It seems @TectonicFi has been exploited for around $66M!
The root cause is simple: TONIC, it's own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC's price surged by 100x within 20 minutes.
The @CronosNetwork has paused the entire chain. The attacker only succeeded in bridging out ~$6M to Ethereum, leaving $60M on Cronos chain.
It's been the third mango-market style attack recently.... The previous ones are Moonwell, reUSD (Pendle YT).
Attacker's profit now parks the money in the following addresses:
- 60M on Cronos (perhaps to avoid blacklisting, the money was deposited into a DEX pool): https://t.co/ZTqje1dsZG
- 6M bridged onto Ethereum: https://t.co/s4Fr3gJvTd
- Attacker's borrow position: https://t.co/pupNIGLXKW
An update for our Jupiter Card users:
Earlier today, a security incident affected another card program on Solana. As a precaution, our card partner briefly paused card-balance withdrawals while they completed their security checks.
That check is now complete and everything is back to normal.
To be clear:
- No Jupiter accounts were affected
- Card payments worked as normal throughout
- Your on-chain wallets were never impacted
- Your funds were never at risk
You can withdraw your card balance as usual.
Thank you for your patience, we kept you updated by email throughout and we'll always put your security first.
Thanks for your attention to this matter.
Everything is in Tornado Cash. 455.8 ETH in 22 deposits, done in 28 minutes
The drain ran from 16:49 to 19:26 UTC. Total taken: $1.11M
His wallets:
- FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj drained the accounts, 21,405 transactions, now at zero
- 7XigoEaHxpoHp819fnajGqsz329Lve9c2SXSq8KaFRVf took the last 886.94 SOL
- Dn1qRqxgCY6XzNe3kMEbGmEPY24MQCD5W1uA8xeBPNch bridged that second batch out
- 0x2ce21e4921d3eb116526c3651dac0257657338d5 is where all of it landed on Ethereum, 456.01 ETH in total
He started washing sixteen minutes after the money hit Ethereum and worked down the denominations: four deposits of 100 ETH, five of 10, five of 1, eight of 0.1. He swept his own dust. 0.14 ETH is what is left on the address
He opened with a $190 bridge from Ethereum at 13:40 to pay for gas, and closed by sending $1.02M back the same way
He had two hours and thirty seven minutes, and nobody ever closed the door.
HEADS UP | Rumors circulating that @Avici exploit traces to @raincards infra
> Unconfirmed chatter suggests the root cause may sit at the shared infrastructure layer rather than being isolated to Avici, which would widen the impact if true. Nothing verified yet, treat this as speculation only.
If you hold funds on Avici or others rain powered neobanks, withdraw as a precaution. Wait for official confirmation before assuming other platforms are affected.
list: etherfi cash avalanche card plasma one tangem pay avici kast offramp currency dakota nuvei cadana wallbit takenos western union wyoming frnt uniswap tria xplace oobit exacard lavacard tuyo card...
looked into the @avici exploit on chain, thanks to @Helius rpc for the usage. Wishing the team the best - genuinely can't imagine anything worse as a founder.
- 2,973 collateral accounts were drained.
- Direct losses:
- 825,769 USDC
- 292,827 USDT
- $1,118,597 total
- Attack sequence:
- SubmitSignatures: 10,728 calls
- AddCollateralAdmin: 3,500 calls
- WithdrawCollateralAsset: 7,124 calls
- A representative withdrawal is this transaction
(https://t.co/GpkiZ5kGmN).
The attacker submitted valid Ed25519 signatures from existing admins, added FVNF… as a collateral admin, then withdrew the collateral.
Possibilities are:
1. Smart contract exploit - a signature replay/message-binding bug—signatures were verified but not securely bound to the exact collateral, action and
one-time nonce.
2. Infra exploit - an off-chain signing API or key service was compromised and produced fresh valid signatures.
The attacker converted funds through Jupiter and placed three deBridge orders:
- Order 1 (https://t.co/0LNH7S8Wei)
- Order 2 (https://t.co/7fy4l2I9MH)
- Order 3 (https://t.co/xSEaGqiXV9)
All are already ClaimedUnlock. About $1.113M USDC was bridged toward Ethereum.
Primary Ethereum consolidation address:
0x2ce21e4921d3eb116526c3651dac0257657338d5
It deposited 455.1 ETH into Tornado Cash across 15 transactions—4×100 ETH, 5×10 ETH, 5×1 ETH and 1×0.1 ETH. The full
transactions and commitments are visible on its Blockscout history
(https://t.co/NjM8r5oJeW).
the rabbit hole goes much deeper
- @avici got exploited for over $500K
- @useTria under attack too
- @Solayer_Pay also impacted
looks like that @raincards (crypto card issuer) got exploited
‼️$142,000 lost due to an exploit
1 hour ago 5,2M $ENJ tokens were stolen via a malicious transfer call
Attacker swapped everything to $ETH and $DAI with no further movements
The wallet was initially funded from Tornado Cash in BNB
0x5ec1BA7892D11059c39557b762a97DD695778Ca5
⚠️ EXPLOIT HAPPENING RIGHT NOW ON THE LATEST @fomo iOS APP ⚠️
6 hours ago FOMO updated its iOS app for "Small bug fixes" and they must have accidentally added something malicious in its new code.
A friend of mine opened his phone around 15 mins ago to place a trade and his balance got drained instantly.
It was 662 SOL worth around $62k, might not be a lot of money to some of you guys but it was almost everything he had.
He could literally watch the funds moving on-chain, but on the FOMO app it still showed as if his balance was there.
He thought the app was non-custodial, idk what happened here.
So far reports have shown that the Android version of the app is unaffected and this is only targeting iOS users.
Please be careful everyone, the estimated damage is around $6m so far.
I'd suggest to delete the app for now until there's more clarity and whether the team will refund the lost money.