The Pro token contract of Crypto DAO was exploited due to missing access control, allowing attackers to call publicly accessible vault functions. The attacker's profit was approximately $52,000, with the contract losing around 167,200 Pro tokens.
Garden Finance experienced a database breach affecting its HTLC contracts, resulting in the draining of approximately $450,000 in USDT across Ethereum, Base, Arbitrum, and BNB Chain. The project stated that an independent solver's off-chain database was compromised, leading to improper fund releases. The application has been temporarily taken offline.
Little Boy Plus, a DeFi mining protocol on BSC, was exploited due to an arithmetic error in the LBPHashrate contract's _update() function, allowing an attacker to mint LBP tokens and drain approximately $367,000 USDT.
Solana-based decentralized exchange Raydium disclosed a vulnerability in its deprecated AMM V3 program, which allowed an attacker to drain approximately $1.34 million from five inactive liquidity pools. No current users or active programs were affected, and Raydium will compensate losses from its treasury.
The DTXT/USDT liquidity pair on BSC was exploited due to a forgeable liquidity-addition detection logic in the DTXT contract, allowing an attacker to bypass sell fees and drain the pool. The loss is approximately $35,041 USDT.
The DeFi project AROS on BSC was exploited via a smart contract vulnerability, draining approximately $295,300 USDT from the AROS/USDT PancakeSwap liquidity pool.
The LegendaryMoneyMonNft contract was exploited due to a signature verification flaw in its claimRewared function, allowing an attacker to drain all tokens and swap them for USDT via PancakeSwap. The loss amounted to $85,519.47.
TAC Protocol experienced an exploit on the TON side of its cross-chain layer, resulting in a loss of approximately $2.85 million across USDT, BLUM, and tsTON. The bridge has been paused for analysis and remediation.
The MONA token on BSC was exploited via a Deferred LP Burn / reserve manipulation attack, resulting in a loss of approximately $60,950. The attack manipulated the MONA/USDT pair by draining USDT reserves.
The TGAI project on BSC suffered a reserve manipulation attack on PancakeSwap V2, where a hacker used a flash loan to manipulate reserves and extract approximately $11,940 in profit.
The BCE-USDT liquidity pool on PancakeSwap (BSC chain) was exploited due to a vulnerability in the BCE token's burn mechanism, resulting in a loss of approximately $679,000. An attacker used malicious contracts to bypass restrictions and manipulate reserves.
DeFi yield protocol Cyrus Finance on BNB Chain was exploited via a flash loan attack that manipulated the PancakeSwap V3 ETH/USDT pool spot price, leading to an over-extraction of liquidity and a profit of approximately $516,840 for the attacker.
The AM/USDT pool on BSC was exploited due to a vulnerability in its burn mechanism, allowing manipulation of AM reserves and artificial price inflation. An estimated $131,000 was lost.