DeTracker Security Feed

$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year

🚨 Blockaid detected an ongoing exploit on an unnamed vault on Base. A brand-new contract was added to the vault's whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker's contract. ~$2.02M drained from the vault so far across ~4 txs. Attack

Blockaid detected an ongoing exploit on an unnamed vault on the Base network. A new contract was whitelisted, borrowed aBaswstETH, and sent it to an attacker's contract, draining approximately $2.02 million across four transactions.

Source: Blockaid (opens in a new tab)

🚨SlowMist TI Alert🚨 💸 @Goldpesatoken Loss: ~$114.9k 🔍 Root Cause: GPXHooks' reBalance() performs liquidity operations through the shared, flash-accounted PositionManager inside an attacker-controlled PoolManager unlock without verifying that the PositionManager's GPX/USDC

Goldpesatoken (GPX) suffered a loss of approximately $114.9k due to a vulnerability in its reBalance() function. The function performed liquidity operations through a shared PositionManager without proper verification, allowing an attacker to exploit it.

Source: SlowMist Team (opens in a new tab)

#Goldpesatoken #USDC

🚨SlowMist TI Alert🚨 💸 MALT Loss: ~$72k 🔍 Root Cause: swap(uint256,uint256,address) records the caller’s input and pre-swap reserves, then invokes an external rebalanceHook before transferring the requested output. The hook withdraws DAI from the Capital Source and deposits

MALT experienced a loss of approximately $72k due to a vulnerability in its swap function. The function recorded caller input and pre-swap reserves, then invoked an external rebalanceHook before transferring output, allowing for manipulation.

Source: SlowMist Team (opens in a new tab)

#DAI #MALT

NEAR Intents reports $3.8 million loss after smart contract bug

NEAR Intents reported a $3.8 million loss due to a smart contract bug in its Omni deposit and withdrawal infrastructure. The platform stated it would fully compensate affected users and is working with security partners to trace and recover the funds. Services were stopped but expected to resume within an hour, though some cross-chain deposits and withdrawals may remain unavailable for up to 12 hours.

Source: Crypto Briefing (opens in a new tab)

#NEARIntents

MetaMask says no user funds were hit in validator security incident

MetaMask reported a security incident affecting its Ethereum validator infrastructure on September 30, 2026, leading to the diversion of approximately 0.36 ETH in staking rewards. As a precaution, around 17,000 validators holding approximately 523,000 ETH are exiting, a process expected to complete by October 7, 2026. MetaMask confirmed no user wallets or funds were compromised.

Source: Crypto Briefing (opens in a new tab)

#Lido #MetaMask