#CertiKStatsAlert 🚨
Combining all the incidents in April we’ve confirmed ~$651M lost to exploits with
~$3.5M of the total attributed to phishing.
April has had the highest losses recorded since March 2022 (~$715M), excluding Feb 2025 (Bybit).
More details below 👇
Terrifyingly sophisticated attack:
1. Identified the RPC infrastructure used by the DVN, then selectively compromised two independent RPC nodes.
2. Delivered a targeted spoofed response only to the DVN, while returning truthful RPC data to all other IP addresses, including internal monitoring and indexing systems.
3. Implemented operational cleanup and self-destruction mechanisms.
4. Launched DDoS attacks against the uncompromised RPCs to force failover onto the poisoned nodes.
Wrote up a Ledger Stax vulnerability.
MCU recovery flow exposed a host-controlled reset_handler over USB/BLE, leading to bricking or boot-time code execution.
https://t.co/tvM5bNlfLw
🏆 Hacker Awards 2025 – Nominees & Winners
We’re thrilled to announce the nominees for Hacker Awards 2025!
🏅 Top Earner of 2025: @bbarwik – $920k (Biggest Payout: $250k)
🏅 Most Critical Findings: @0xTonraq – 12 criticals
🏅 Most Valid Reports: @0xTonraq – 46 reports
🏅 Top Security Team: @CertiK
🏅 Ultimate Contributor of the Year: @ziko29504803 – 84 programs influenced, Summer Security event winner, HackenProof ambassador
🏅 Top Contest & DualDefense Hunter: @alexbabits
🏅 Breakthrough Hacker of the Year: – Joined April 2025, now top 13!
You’re all legends! Thank you for your contributions to cybersecurity! 👏
Can a simple animation compromise security? 🤔
Two incidents, from XSS in Lottie-powered doodles to malicious npm packages, show the risks of third-party code.
Read more in our latest blog👇
https://t.co/sAkWA5FM0g
Join the next episode of #KseniaConnects as we explore the critical topic of security in centralized finance! 🔒
🧠 Topic: Building Trust in #CeFi: What Makes an Exchange Secure
⏰ Time: Tuesday, 10/06, 13:00 PM UTC
✨ Set a reminder: https://t.co/mqRcyRyBIf
🎤 Speaker: Peiyu Wang @wisp_fly, Auditing Partner at @CertiK
👩💼 Moderator: Ksenia, Growth Lead at @BitMartExchange
#Crypto #Blockchain #BitMart
Honoured to join Ledger’s 2025 Hall of Fame (first entry since 2022)! Hardest gadget I’ve ever probed—tough for attackers too.
Huge thanks to Vincent (@b0l0k_) and the @DonjonLedger / @Ledger crew for the recognition.
https://t.co/yScWiefQe3
🥞@PancakeSwap's Infinity update introduces a modular architecture with Vaults, Pool Managers, and Hooks—unlocking powerful new capabilities for developers.
We highlight key security considerations for building safe, effective hooks👇
https://t.co/cHK9X1fl7m
There are a lot amount of people capitalizing on this hack to sell their fancy multisig, semi-custodial, MPC, blah blah blah product to you.
They say that they would've prevented this hack.
Those products make your attack surface LARGER, not smaller.
Do not believe their lies
Innovative customization is now possible with @Uniswap's V4 hooks, enabling advanced DeFi applications. But with flexibility comes new security challenges.🧐
Explore the risks and best practices for securing Uniswap V4 hooks in our latest blog: 👇
https://t.co/t7RwR1qBBb
I will present the "Web2 Meets Web3: Hacking Decentralized Applications" at the AppSec Village at DEFCON tomorrow. Come check it out! https://t.co/jAXkgBNC6x