🚨~$4M exploit on DeFi protocol Makina Finance's smart contracts happened ~13 hrs ago
Details show this is a price calculation manipulation exploit, done by using a flashloan.
🚨SlowMist TI Alert🚨
MistEye has detected potential suspicious activities related to @makinafi.
The root cause is that the liquidity of tokens in the MIM-3LP3CRV-f pool is manipulated through a flash loan first.
This causes the calc_withdraw_one_coin function to calculate an amount of 3Crv tokens that can be withdrawn exceeding expectations, thus pushing up the AUM of the vault.
Since the price of DUSD is determined by the AUM of the vault, the price of DUSD can be indirectly manipulated by calling the updateTotalAum function with the inflated AUM.
As always, stay vigilant!
https://t.co/givjJuDUXB
#PeckShieldAlert@makinafi has been exploited for ~1,299 $ETH (~$4.13M).
The hacker was frontrun by MEV Builder (0xa6c2...).
The stolen funds are currently held in 2 addresses:
0xbed2...dE25 ($3.3M) & 0x573d...910e ($880K)
#PeckShieldAlert ZachXBT reported that on January 10, 2026, a victim lost $282M+ worth of $LTC & $BTC due to a hardware wallet social engineering #scam.
The attacker has bridged 928.7 $BTC (~$71M) to #Ethereum (19,631.1 $ETH), Ripple (3.15M $XRP), and Litecoin (77.2K $LTC) via #THORChain.
Subsequently, 1,468.66 $ETH ($4.9M) was laundered via #TornadoCash, 735 $ETH ($2.4M) was sent to #WhiteBit, 100 $ETH to #ChangeNOW, 2,402 $ETH ($8M) to #KuCoin, & 143 $ETH ($477K) to #Huobi.
🚨SlowMist: Analysis of Truebit Protocol Incident🚨
On Jan 8, @Truebitprotocol was exploited via an integer overflow vulnerability in its Purchase contract, allowing the attacker to mint $TRU at near-zero cost and drain 8,535 $ETH (~$26.44M) 💰
🔍 Root cause: Missing overflow protection in an integer addition led to incorrect price calculation. The stolen funds were later funneled into Tornado Cash 🌪️
🛡️ Recommendation: For contracts compiled with Solidity < 0.8.0, always use SafeMath to protect all arithmetic operations and prevent overflow-related logic flaws.
📄 Full analysis 👇
🔗 https://t.co/RLDOw5Ifj3
🚨 SlowMist TI Alert 🚨
The @Truebitprotocol has suffered a security incident. Its smart contract 0x764C64b2A09b09Acb100B80d8c505Aa6a0302EF2 was maliciously exploited, resulting in the theft of 8,535 $ETH (~$26.44M).
⚠️ Do NOT interact with this contract. Stay alert and follow official updates.
https://t.co/xSbXYBpZFL
Today, we became aware of a security incident involving one or more malicious actors. The affected smart contract is 0x764C64b2A09b09Acb100B80d8c505Aa6a0302EF2 and we strongly advise the public not to interact with this contract until further notice. We are in contact with law enforcement and taking all available measures to address the situation. We will share updates through our official channels as they become available.
🚨A smart contract exploit from 1hr ago just drained ~8536 ETH, worth around ~$26M
The code was live on Ethereum for almost 5 years already. Source code unverified - only bytecode is public.
Another 26M hack. @Truebitprtocol
I haven't decompiled the vulnerable code yet, but the root cause appears to be a mispriced minting function of its purchase contract that allows anyone to purchase TRU token at a very low price.
The first attacker (26M profit): 0xcd4755645595094a8ab984d0db7e3b4aabde72a5c87c4f176a030629c47fb014The
second attacker (~250k profit): 0x71496352b02f974a3898c1b743e9fc2befb935e6c2a3e421134ec09b63052f4b@Truebitprotocol
This contract has been a very old contract deployed ~5 years ago... It seems old contracts are getting more "popular" among attackers now.
btw a friend of mine shared me a screenshot of the second hacker celebrating in his chat group 😂 (not sure if it's genuine)
---
Disclaimer:
This is my prelminary analysis and I may make mistakes.
A victim lost a total of 5,544 ETH (~$6.5M) along with other assets valued at $396K in 2022
The attacker’s wallet remained dormant until 2025, by which time the ETH was worth approximately $17M.
Between October 10 and November 26, 2025, the attacker deposited 5,500 ETH into Tornado Cash (100 ETH × 55).
The wallet still holds $396K in DAI and 44 ETH.
Victim wallet:
0x8975dBC1b8F25EC994815626D070899ddA896511
Attacker wallet:
0x0bb298be4c2656391d961bbe3248ddfc6e77746d
Stay smart