DeTracker Security Feed

$1.0B lost this week $93.7B lost in 30 days $94.9B lost this year

🚨 Blockaid detected an ongoing exploit on an unnamed vault on Base. A brand-new contract was added to the vault's whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker's contract. ~$2.02M drained from the vault so far across ~4 txs. Attack

Blockaid detected an ongoing exploit on an unnamed vault on the Base network. A new contract was whitelisted, borrowed aBaswstETH, and sent it to an attacker's contract, draining approximately $2.02 million across four transactions.

Source: Blockaid (opens in a new tab)

🚨SlowMist TI Alert🚨 💸 @Goldpesatoken Loss: ~$114.9k 🔍 Root Cause: GPXHooks' reBalance() performs liquidity operations through the shared, flash-accounted PositionManager inside an attacker-controlled PoolManager unlock without verifying that the PositionManager's GPX/USDC

Goldpesatoken (GPX) suffered a loss of approximately $114.9k due to a vulnerability in its reBalance() function. The function performed liquidity operations through a shared PositionManager without proper verification, allowing an attacker to exploit it.

Source: SlowMist Team (opens in a new tab)

#Goldpesatoken #USDC

🚨SlowMist TI Alert🚨 💸 MALT Loss: ~$72k 🔍 Root Cause: swap(uint256,uint256,address) records the caller’s input and pre-swap reserves, then invokes an external rebalanceHook before transferring the requested output. The hook withdraws DAI from the Capital Source and deposits

MALT experienced a loss of approximately $72k due to a vulnerability in its swap function. The function recorded caller input and pre-swap reserves, then invoked an external rebalanceHook before transferring output, allowing for manipulation.

Source: SlowMist Team (opens in a new tab)

#DAI #MALT

NEAR Intents reports $3.8 million loss after smart contract bug

NEAR Intents reported a $3.8 million loss due to a smart contract bug in its Omni deposit and withdrawal infrastructure. The platform stated it would fully compensate affected users and is working with security partners to trace and recover the funds. Services were stopped but expected to resume within an hour, though some cross-chain deposits and withdrawals may remain unavailable for up to 12 hours.

Source: Crypto Briefing (opens in a new tab)

#NEARIntents

🚨SlowMist TI Alert🚨 💸 MUS Loss: ~$36.9k 🔍 Root Cause: deposit() included the first-deposit bonus in both the immediate ETH refund and the user’s MUS allocation; withdraw() allowed same-transaction redemption without limiting total ETH returned to the amount deposited.

SlowMist reported a loss of approximately $36.9k due to a vulnerability in the deposit and withdraw functions of a protocol. The issue allowed for the first-deposit bonus to be included in both the ETH refund and MUS allocation, and enabled same-transaction redemption exceeding the deposited ETH amount.

Source: SlowMist Team (opens in a new tab)

#MUS

🚨SlowMist TI Alert🚨 💸 @MCNLabs Loss: ~$92.6k 🔍 Root Cause: LPBonus uses inconsistent reserve values in its reward accounting. AddFistFee divides newly acquired FIST by the MSN reserve when updating oneshareFIST, but CalcPendingUser later multiplies that index by a user

MCN Labs experienced a loss of approximately $92.6k due to inconsistent reserve values used in its reward accounting, specifically within the LPBonus function.

Source: SlowMist Team (opens in a new tab)

#MCNLabs

🚨TenArmor Security Alert🚨 Our system has detected a suspicious attack involving #FIST #FastSwap on #BSC, resulting in an approximately loss of $92.6K. Attack transaction: https://t.co/9sPsBh4nWQ With TenArmor’s TenMonitor, you get early detection and automated response to https://t.co/ZFrDc6aoco

TenArmor Security Alert reports a suspicious attack on FIST FastSwap on BSC, resulting in an approximate loss of $92.6K. The attack transaction has been identified.

Source: TenArmor Alert (opens in a new tab)

#FISTFastSwap