Term Labs was targeted in a governance attack, resulting in a loss of approximately $8.5 million. The stolen funds, including 2,843 ETH and $1.6 million DAI, are currently held at a specific address.
The address labeled Bofur Capital lost $2M due to an address poisoning attack after withdrawing from Compound. A phisher sent a small USDC transaction to spoof the address, and the victim mistakenly copied the wrong address, leading to the drain. The stolen funds were swapped to 2M DAI.
A victim address has been drained of approximately $25 million in assets for the second time since 2023. The stolen assets were swapped for DAI and are now held at a specific address.
Unknown victims were drained of $25.6 million in crypto, including aWBTC, DAI, WBTC, and ETH. The hacker swapped the stolen funds and holds them across four addresses.
A third-party Gnosis Safe module named SquidRouterModule was exploited on Ethereum and Base, draining approximately $3.2 million from 86 wallets. The module had improper access control, allowing unauthorized token spending.
Transit Finance suffered an exploit on its deprecated TRON smart contract, resulting in approximately $1.88 million in DAI being drained. The stolen funds were transferred to an Ethereum address. The team confirmed it was isolated to legacy code, stated that current contracts are secure, and completed remediation.