A GitHub repository impersonating the Qwen AI model distributed a malicious ZIP file containing an information-stealing Trojan named StealC. The repository redirected users to download the malicious file, which contained a Lua interpreter and obfuscated script designed to collect sensitive data including browser credentials, cryptocurrency wallets, and system information. The malware uses a multi-stage delivery chain, with C2 communication falling back to an Ethereum RPC call on the Polygon chain.
The USM protocol suffered an exploit due to a pricing logic flaw in the defund() function, resulting in a loss of approximately $136,000 worth of ETH. The attacker manipulated internal pricing using a flash loan and multiple calls to extract excess ETH.
A legacy vault of Thetanuts Finance on Ethereum was exploited due to a flaw in redemption math and integer calculations, resulting in a net loss of approximately $105,000 after a whitehat recovered most of the drained funds. Current products and active contracts were unaffected.
Solana-based decentralized exchange Raydium disclosed a vulnerability in its deprecated AMM V3 program, which allowed an attacker to drain approximately $1.34 million from five inactive liquidity pools. No current users or active programs were affected, and Raydium will compensate losses from its treasury.
Transit Finance suffered an exploit on its deprecated TRON smart contract, resulting in approximately $1.88 million in DAI being drained. The stolen funds were transferred to an Ethereum address. The team confirmed it was isolated to legacy code, stated that current contracts are secure, and completed remediation.