๐ Big news! SolidityScan is now integrated with @soneium, bringing seamless smart contract security to your fingertips.
Easily access security scores, gain real-time insights into vulnerabilities, and explore full threat reports โ directly from verified contracts on Soneium.
Zcash completed an emergency NU6.2 upgrade after a critical soundness bug was found in the Orchard shielded pool.
Orchard was briefly disabled via soft fork, then re-enabled after the hard fork. No exploitation reported.
#Zcash#Security
ATM token on BNB Chain was reportedly exploited via a custom transferFrom() logic flaw, with ~20% auto-swap mechanics allegedly abused repeatedly.
Estimated loss: ~$243.5K.
#BSC#DeFiSecurity
Ledger Donjon disclosed a lab laser fault-injection technique that can bypass Ed25519 verification on the TROPIC01 chip (used in Trezor Safe 7), enabling unauthorized firmware execution with physical access.
#Security#HardwareWallet
Phala says it patched a Phala Cloud API vuln that allowed unauthorized changes to some CVMs.
If you used affected Offchain KMS CVMs: replace CVMs + rotate any secrets/env vars and relevant AWS/ECR credentials.
#Web3Security#CloudSecurity
BNB Chain: TesseraDAO ($TSR) exploited via unauthorized minting.
Reportedly 99M TSR were minted and dumped for ~$2.4M, crashing TSR ~99%.
Proceeds were reported sent to Tornado Cash.
#DeFi#exploit
Fluidโs off-chain Merkle rewards distribution infra was reportedly compromised, enabling fraudulent reward claims (~$215K loss).
Core lending/DEX contracts and user funds were reported as unaffected; claims were paused and keys revoked.
#Web3Security#DeFi
Whitehat recovery: researcher Florent coordinated with the HongCoin team to unlock ~1,003 ETH (~$2M) stuck in a 2016 ICO refund contract due to legacy overflow/refund-logic bugs.
#Ethereum#SmartContractSecurity
Gnosis Pay: active exploit tied to the Zodiac โdelay module,โ per Gnosis co-founder Martin Koppelmann.
Attacker can initiate txs from Safe wallets using the module; containment ongoing (bridge validators asked to pause).
#Web3Security#DeFi
Fluid says it identified & contained a compromise of its off-chain Merkle rewards distribution infrastructure.
Team says core protocol smart contracts and user funds were unaffected; investigation + post-mortem pending.
#Web3Security#DeFi
Gravity Bridge (Ethereum โ Cosmos) was drained for ~US$5.4M; researchers suspect compromised signing key(s) vs a contract bug.
Bridge has been halted while the team investigates.
#Web3Security#DeFi
Alephiumโs TokenBridge was reportedly exploited via forged bridge messages, draining ~$815K.
If you used the bridge recently, monitor onchain activity and follow official incident updates.
#Web3Security#Bridge
Court-ordered action led Circle to blacklist an Ethereum address, freezing ~12.6M USDC tied to Zamaโs cUSDC wrapper contract.
Because funds are pooled in the wrapper, other users may be affected.
#DeFi#USDC
DxSale legacy liquidity locker contracts on BNB Chain were reportedly exploited, draining ~$7.3M from 1,400+ old LP locks (per SlowMist Hacked).
Claims of potential team-linked wallet connections are circulating and remain unverified.
#DeFi#exploit
Sui reported another mainnet โnetwork stall,โ with transactions paused while the core team implemented a fix.
A subsequent outage was later attributed to a bug introduced in the 1.72 releaseโs gas charging logic.
#Sui#Web3Security
DxSale legacy liquidity locker contracts on BNB Chain were reportedly exploited, with estimates of ~$7.3M drained across 1,400+ old LP locks.
Attribution claims are circulating but remain unverified.
#DeFi#Security
SlowMist reports MoneyMonโs LegendaryMoneyMonNft contract was drained (~85,519 USDT).
Cause: signature verification allowed a zero-address bypass (ecrecover -> address(0) accepted after admin set to 0x0), enabling arbitrary reward claims and swaps on PancakeSwap.
#Web3Security #SmartContract
SlowMist reports Joe Agent ($JOE) was exploited via a single-function reentrancy bug in `_removeLiquidityViaContract`.
Loss reported: 62.5 BNB + ~1.196M JOE (via ~25 reentrancy loops).
#DeFi#exploit
Sui mainnet reported a โnetwork stall,โ with transactions temporarily paused while the core team implemented a fix.
No root cause details yet in public coverage.
#Sui#Web3Security