DeTracker Security Feed

$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year

Ethereum Foundation funds $100K grant for Vyper compiler verification

The Ethereum Foundation has funded a $100,000 grant for the formal verification of the Vyper compiler, aiming to enhance DeFi security by ensuring the reliability of code translation from source to bytecode. This initiative addresses potential compiler bugs that could affect protocols like Curve and Yearn, which collectively hold over $2 billion in TVL.

Source: Crypto Briefing (opens in a new tab)

#Curve #Yearn

DeFi hack attack: Three exploits snatch $11M in a single day

Three DeFi projects, Payy Network, Duelbits, and Meter.io, were exploited on September 24, 2026, resulting in a total loss of over $11 million. Payy Network's bridge was drained of $1.8 million, Duelbits suffered a suspected private key compromise resulting in a $7 million loss, and Meter.io experienced a bridge attack where unbacked tokens worth $2.3 million were minted and dumped. All affected protocols have paused operations.

Source: Protos (opens in a new tab)

#Across #Duelbits #Meter.io #PayyNetwork #USDC

#PeckShieldAlert #Duelbits has seen a suspicious outflow of ~$4.3M in crypto on #Ethereum and #BNBChain, including 836 ETH($2.23M), 1.146M USDT, 209 BNB ($160.68K), 96.805K USDC, 12.398B SHIB ($70.17K), and 31.515K DAI. The attacker has since swapped the stolen funds for 1587.87 https://t.co/zJ5HUtIghQ

Duelbits experienced a suspicious outflow of approximately $4.3 million in cryptocurrency across Ethereum and BNB Chain. The stolen funds were subsequently swapped by the attacker.

Source: PeckShield Alert (opens in a new tab)

#DAI #Duelbits #USDC #USDT

🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity https://t.co/tQzDocJMhd

Attackers are posing as a Web3 company and using remote job interviews to trick candidates into deploying and running malicious projects locally. The disguised application is presented as a real estate and crypto investment platform called RoyalCity.

Source: SlowMist Team (opens in a new tab)

Bridges lost another $24.6M to cross-chain verification failures in July and August. Blockaid's Cosigner screens every transaction before it's signed, so teams moving funds across chains don't route into a compromised bridge or sign a forged payout. Read more: https://t.co/anZLzsA4Py

Bridges lost $24.6 million due to cross-chain verification failures in July and August. Blockaid's Cosigner tool screens transactions to prevent routing into compromised bridges or signing forged payouts.

Source: Blockaid (opens in a new tab)

Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft

A campaign targeting iPhones running iOS 18.4-18.6.2 via Safari is exploiting vulnerabilities consistent with the DarkSword lineage to steal files, Keychain data, and keyboard input, specifically targeting imToken, TokenPocket, and TronLink wallet applications. This campaign reuses previously disclosed vulnerabilities.

Source: SlowMist Medium (opens in a new tab)

#NOTE #Parallel #TokenPocket #TronLink #imToken