Add PoC: CrowdRingCircle sell-destroy reserve manipulation (~201.36K …
A Proof of Concept (PoC) details a reserve manipulation exploit in CrowdRingCircle's sell-destroy mechanism on BSC, which drained approximately 201.36K USDT.
$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year
A Proof of Concept (PoC) details a reserve manipulation exploit in CrowdRingCircle's sell-destroy mechanism on BSC, which drained approximately 201.36K USDT.
A Proof of Concept (PoC) indicates an unguarded funding-growth update in Perpetual Protocol v2 (Curie) on Optimism drained a vault of approximately 3,062.21 USDC.
An exploit on MALT on the Polygon network resulted in the draining of approximately 13,440 DAI from the Capital Source treasury. The exploit involved unisolated treasury rebalance capital, allowing a negligible swap to yield a disproportionate MALT output.
Blockaid detected an ongoing exploit on an unnamed vault on the Base network. A new contract was whitelisted, borrowed aBaswstETH, and sent it to an attacker's contract, draining approximately $2.02 million across four transactions.
Source: Blockaid (opens in a new tab)
A Proof of Concept (PoC) for a Pancake V3 swap-helper exploit has been added, detailing a signed delta bug that drained approximately 1.65 BNB on the BNB Chain.
Goldpesatoken (GPX) suffered a loss of approximately $114.9k due to a vulnerability in its reBalance() function. The function performed liquidity operations through a shared PositionManager without proper verification, allowing an attacker to exploit it.
MALT experienced a loss of approximately $72k due to a vulnerability in its swap function. The function recorded caller input and pre-swap reserves, then invoked an external rebalanceHook before transferring output, allowing for manipulation.
An exploit on PositionManager on the BNB Chain resulted in the loss of approximately 32,080 USDT. The attack involved inflating share prices by manipulating the spot price of USDT/BTCB before depositing, allowing for the draining of the vault's own PancakeSwap V3 position.
An improper access control vulnerability in FlashLoopAdapter on the Ethereum chain resulted in a loss of $305,000.
NEAR Intents reported a $3.8 million loss due to a smart contract bug in its Omni deposit and withdrawal infrastructure. The platform stated it would fully compensate affected users and is working with security partners to trace and recover the funds. Services were stopped but expected to resume within an hour, though some cross-chain deposits and withdrawals may remain unavailable for up to 12 hours.
SKYDAO experienced a swap logic flaw resulting in a loss of $183,483 on the BSC chain.
SlowMist reported a loss of approximately $36.9k due to a vulnerability in the deposit and withdraw functions of a protocol. The issue allowed for the first-deposit bonus to be included in both the ETH refund and MUS allocation, and enabled same-transaction redemption exceeding the deposited ETH amount.
MCN Labs experienced a loss of approximately $92.6k due to inconsistent reserve values used in its reward accounting, specifically within the LPBonus function.
TenArmor Security Alert reports a suspicious attack on FIST FastSwap on BSC, resulting in an approximate loss of $92.6K. The attack transaction has been identified.
An exploit PoC for AllbridgeCCTP details a phantom deposit vulnerability via unverified CCTP message attestation, leading to an estimated loss of $189.75K USDC on Base.