Add PoC: CrowdRingCircle sell-destroy reserve manipulation (~201.36K …
A Proof of Concept (PoC) details a reserve manipulation exploit in CrowdRingCircle's sell-destroy mechanism on BSC, which drained approximately 201.36K USDT.
$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year
A Proof of Concept (PoC) details a reserve manipulation exploit in CrowdRingCircle's sell-destroy mechanism on BSC, which drained approximately 201.36K USDT.
A Proof of Concept (PoC) indicates an unguarded funding-growth update in Perpetual Protocol v2 (Curie) on Optimism drained a vault of approximately 3,062.21 USDC.
The stUSDS module is launching a permissioned keeper to automate transaction submissions for adjusting stUSDS parameters according to the Dynamic Interest Rate Model. This automation aims to reduce manual work for signers and is planned for deployment on October 8, 2026.
Source: Sky Forum (opens in a new tab)
An exploit on MALT on the Polygon network resulted in the draining of approximately 13,440 DAI from the Capital Source treasury. The exploit involved unisolated treasury rebalance capital, allowing a negligible swap to yield a disproportionate MALT output.
Blockaid detected an ongoing exploit on an unnamed vault on the Base network. A new contract was whitelisted, borrowed aBaswstETH, and sent it to an attacker's contract, draining approximately $2.02 million across four transactions.
Source: Blockaid (opens in a new tab)
A Proof of Concept (PoC) for a Pancake V3 swap-helper exploit has been added, detailing a signed delta bug that drained approximately 1.65 BNB on the BNB Chain.
Goldpesatoken (GPX) suffered a loss of approximately $114.9k due to a vulnerability in its reBalance() function. The function performed liquidity operations through a shared PositionManager without proper verification, allowing an attacker to exploit it.
MALT experienced a loss of approximately $72k due to a vulnerability in its swap function. The function recorded caller input and pre-swap reserves, then invoked an external rebalanceHook before transferring output, allowing for manipulation.
Microsoft's official X account was compromised for approximately 30 minutes on October 2, 2026, and used to promote a fraudulent $Clippy token. Microsoft regained control, removed the posts, and is investigating the incident.
Aave founder Stani Kulechov stated that Aave v3 remained unaffected after an attacker exploited a third-party adapter, draining approximately $305,000 from two Safe multisig wallets.
Core Lightning has warned that attackers are targeting unpatched Bitcoin nodes running version 26.06.7 or earlier, urging operators to upgrade immediately.
An exploit on PositionManager on the BNB Chain resulted in the loss of approximately 32,080 USDT. The attack involved inflating share prices by manipulating the spot price of USDT/BTCB before depositing, allowing for the draining of the vault's own PancakeSwap V3 position.
An improper access control vulnerability in FlashLoopAdapter on the Ethereum chain resulted in a loss of $305,000.
NEAR Intents reported a $3.8 million loss due to a smart contract bug in its Omni deposit and withdrawal infrastructure. The platform stated it would fully compensate affected users and is working with security partners to trace and recover the funds. Services were stopped but expected to resume within an hour, though some cross-chain deposits and withdrawals may remain unavailable for up to 12 hours.
MetaMask reported a security incident affecting its Ethereum validator infrastructure on September 30, 2026, leading to the diversion of approximately 0.36 ETH in staking rewards. As a precaution, around 17,000 validators holding approximately 523,000 ETH are exiting, a process expected to complete by October 7, 2026. MetaMask confirmed no user wallets or funds were compromised.