Building an agent pipeline: TG channels, Telethon, LLMs, human-in-the-loop on drafts. Not prompt magic — real engineering. If you’re shipping something similar, let’s connect in the replies.
#Web3#buildinpublic
🚨SlowMist TI Alert🚨
$DTXT/USDT Pair on BSC Drained Due to Spoofable Liquidity-Addition Detection Logic
Root cause:
DTXT determines whether an action is liquidity addition, liquidity removal, or a sell by comparing the difference between USDT.balanceOf(pair) and the Pair’s reserves. The attacker was able to transfer a tiny amount of USDT directly to the Pair, causing a large DTXT sell to be misclassified as liquidity addition, thereby bypassing the sell fee / swapFee logic.
Primitive:
Flash-loan-assisted liquidity addition/removal + 1 wei USDT Pair balance spoofing + direct Pair.swap to drain USDT.
Profit:
Approximately 35,041.106 USDT, after repaying a 1,077,366.001021 USDT flash loan from Moolah.
Related wallet addresses:
Attacker EOA: 0xd304ea1592f733e0a46436a01fe54bd504009526
Attack contract: 0x3065bc8ed8bd53bdc3fd4633c3097c40726b5f5f
Helper: 0xd2453ff82e1c5b568ddb260f1f0bb95169895428
DTXT: 0xac9bf7c320d4ce2d0ac978b83955dd67351897d2
DTXT/USDT Pair: 0x90bfc1dbc878ba54858ba8a635b3daebd2ac6c01
Tx:
https://t.co/yjgv0ojH8N
If you’re aware of the recent Zcash situation, something similar once existed in Aurora.
In 2022, @PwningEth discovered a critical bug that could have allowed attackers to mint unlimited ETH and put over $500M in assets at risk. earning him $6M
bounty
Complete breakdown below 👇
GitHub - aligorithm/Zero-Health: Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from LLM, Web, API https://t.co/NQlXbzGlzi
How an attacker can simply keep flash-loan funds for free in a $160,000,000 protocol
This bug was discovered by @asymmetric_re, they're ranked #1 on Immunefi and has earned more than $14,400,000 in combined bug bounty payouts.
Complete breakdown below 👇
$1,155,397.39 REKT by @Polymarket
116 traders affected.
They changed the rules after we bet.
MicroStrategy SOLD Bitcoin. Market resolved NO.
wtf?
Join us: #StopPolyScam
Drop 2 GTD & 7 WL @PondSyndicate
> Supply : 555
> Price : FreeMint
> Chain : ETH
How to join 👇🏻
1️⃣ Follow @lakzonevn & @PondSyndicate
2️⃣ Like & RT
3️⃣ Drop EVM wallet
⏳ 24h
10 WEBSITES EVERY INTERNET USER SHOULD CHECK TONIGHT.
Bookmark all of them. Most people don't know half of these exist.
1. https://t.co/zwR28T6wZa
Shows every data breach your email is in and what got leaked.
2. https://t.co/3c9sMcOYLH
Shows every social profile, photo, and login tied to an email address.
3. https://t.co/MOsvtupjHn
Free disposable email for any signup you don't trust.
4. https://t.co/t6W6t9kzvQ
Burner inbox that self-destructs in 10 minutes.
5. https://t.co/lHWq4ZeJXH
A directory of direct links to delete your account from any major service.
6. https://t.co/vpVXkaS6Uc
Check if your face was used to train AI image models without consent.
7. https://t.co/cC7q3S3Uui
Tells you if your VPN is actually hiding your real location or leaking it.
8. https://t.co/1Q31VRhSQ6
Shows how trackable your browser fingerprint is, even in incognito mode.
9. https://t.co/TVtBWcv6Sw
Tells you which programs on your PC are useless bloatware or spyware.
10. https://t.co/yvtYh3ade9
Drop any file or link. It scans against 70+ antivirus engines instantly.
The internet is hostile by default. These websites are your free defense.
Estos genios están publicando repos GRATIS en Github que sustituyen herramientas por las que las empresas pagan miles de dólares.
Aquí te paso un hilo con los mejores que he analizado esta semana
[Guarda esto] 👇
Tu agente de IA está ciego
Sabe razonar, sabe escribir, sabe programar
Pero no puede leer lo que está pasando ahora mismo en internet
Este repo le da ojos
Se llama Agent-Reach y con una sola CLI conecta tu agente a Twitter, Reddit, YouTube, GitHub, Bilibili y XiaohongShu
Sin pagar APIs. Sin configuraciones raras. Un solo comando.
✅ Lee y busca en Twitter/X en tiempo real
✅ Scraping de Reddit sin límites
✅ Búsqueda y transcripción de YouTube
✅ Acceso completo a GitHub
✅ Compatible con Claude Code, Cursor y cualquier agente CLI
✅ Cero tarifas de API
✅ Licencia MIT
Lo que cambia esto en la práctica:
Le preguntas a tu agente qué está diciendo la gente sobre tu competencia en Reddit ahora mismo y te responde con datos reales
Le pides que monitorice menciones de tu producto en Twitter y lo hace
Le das una URL de YouTube y te transcribe el video completo para trabajar con él
19.5k estrellas. 1.7k forks. Licencia MIT.
Dale ojos a tu agente
repo aquí 👇