$5.4M gone from @gravity_bridge. An attacker minted worthless tokens on Osmosis, poisoned the token registry with a fabricated denom string, and walked out with real assets. They didn't break the code. They just found where it stopped asking questions.
https://t.co/OPFcsqimxS
Gravity Bridge did not offer a white-hat bounty. It did not send an on-chain message to the attacker.
It did not publish a wallet-flagging campaign or coordinate publicly with exchanges.
$5.4M gone from @gravity_bridge. An attacker minted worthless tokens on Osmosis, poisoned the token registry with a fabricated denom string, and walked out with real assets. They didn't break the code. They just found where it stopped asking questions.
https://t.co/OPFcsqimxS
$5.4M gone from @gravity_bridge. An attacker minted worthless tokens on Osmosis, poisoned the token registry with a fabricated denom string, and walked out with real assets. They didn't break the code. They just found where it stopped asking questions.
https://t.co/OPFcsqimxS
A 2021 @dxsale locker, an unprotected admin key, $7.3 million gone. @DecurityHQ flagged the risk in 2023 for $500. Two compromised contracts holding $15.5 million remain untouched, for now.
https://t.co/TnKmTa8TIv
Using owner privileges and EIP-7702 batch delegation, they unlocked and drained more than 1,400 liquidity pools on BNB Chain in a single coordinated flow.
Fees were set to zero.
A 2021 @dxsale locker, an unprotected admin key, $7.3 million gone. @DecurityHQ flagged the risk in 2023 for $500. Two compromised contracts holding $15.5 million remain untouched, for now.
https://t.co/TnKmTa8TIv
A 2021 @dxsale locker, an unprotected admin key, $7.3 million gone. @DecurityHQ flagged the risk in 2023 for $500. Two compromised contracts holding $15.5 million remain untouched, for now.
https://t.co/TnKmTa8TIv
$3.98 million drained from 88 Gnosis Safes across three chains on New Market Trading. A third-party Safe module trusted caller-supplied data over msg.sender. One missing require check. Anyone who read the source code could drain every wallet.
https://t.co/7fHWPH8b6F
One poisoned VS Code extension silently auto-updated to 2.2 million developers, TeamPCP walked out with 3,800 GitHub internal repositories in 11 minutes, the culmination of 8 months spent climbing the developer supply chain one trusted tool at a time.
https://t.co/LpNblQcPsS
One poisoned VS Code extension silently auto-updated to 2.2 million developers, TeamPCP walked out with 3,800 GitHub internal repositories in 11 minutes, the culmination of 8 months spent climbing the developer supply chain one trusted tool at a time.
https://t.co/LpNblQcPsS
$3.98 million drained from 88 Gnosis Safes across three chains on New Market Trading. A third-party Safe module trusted caller-supplied data over msg.sender. One missing require check. Anyone who read the source code could drain every wallet.
https://t.co/7fHWPH8b6F
New Market Trading reached for it as the entry point for privileged Safe actions, placed no additional access control behind it, and shipped it to production.
$3.98 million drained from 88 Gnosis Safes across three chains on New Market Trading. A third-party Safe module trusted caller-supplied data over msg.sender. One missing require check. Anyone who read the source code could drain every wallet.
https://t.co/7fHWPH8b6F
A malicious node is believed to have exploited @THORChain GG20 TSS signing stack to leak vault key material, reconstructed the private key offline, and drained $10.7M across multiple chains. Safeguards fired automatically, node operators completed the rest.
https://t.co/mF6XQIjXV2
A malicious node is believed to have exploited @THORChain GG20 TSS signing stack to leak vault key material, reconstructed the private key offline, and drained $10.7M across multiple chains. Safeguards fired automatically, node operators completed the rest.
https://t.co/mF6XQIjXV2
A malicious node is believed to have exploited @THORChain GG20 TSS signing stack to leak vault key material, reconstructed the private key offline, and drained $10.7M across multiple chains. Safeguards fired automatically, node operators completed the rest.
https://t.co/mF6XQIjXV2
You plugged AI into everything. Someone mapped it before you did. 170 packages. 518M downloads. OpenAI's signing certificates. The stack nobody audited became the attack surface. Be paranoid by default.
https://t.co/hooCVkF9se
npm installs without verification because verification at scale is an unsolved problem and the ecosystem was built on the assumption that most packages, most of the time, are what they claim to be.
You plugged AI into everything. Someone mapped it before you did. 170 packages. 518M downloads. OpenAI's signing certificates. The stack nobody audited became the attack surface. Be paranoid by default.
https://t.co/hooCVkF9se
You plugged AI into everything. Someone mapped it before you did. 170 packages. 518M downloads. OpenAI's signing certificates. The stack nobody audited became the attack surface. Be paranoid by default.
https://t.co/hooCVkF9se