<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>0xtracer</title><link>https://0xtracer.xyz/</link><description>Recent content on 0xtracer</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://0xtracer.xyz/index.xml" rel="self" type="application/rss+xml"/><item><title>Volo Vaults</title><link>https://0xtracer.xyz/incidents/2026-04-22-volo-vaults/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-22-volo-vaults/</guid><description>Volo, a protocol in the Sui ecosystem, disclosed on X that Volo Vaults experienced a security vulnerability today, resulting in approximately $3.5 million in assets (WBTC, XAUm, and USDC) being stolen. Volo stated tha&amp;hellip;</description></item><item><title>Curve Finance Reentrancy Deep Dive</title><link>https://0xtracer.xyz/analysis/curve-finance-reentrancy/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/analysis/curve-finance-reentrancy/</guid><description>&lt;h2 id="overview">Overview&lt;/h2>
&lt;p>On July 30, 2023, multiple Curve Finance pools were exploited due to a reentrancy vulnerability in Vyper compiler versions 0.2.15, 0.2.16, and 0.3.0.&lt;/p>
&lt;h2 id="root-cause">Root Cause&lt;/h2>
&lt;p>The Vyper compiler&amp;rsquo;s &lt;code>@nonreentrant&lt;/code> decorator was malfunctioning in affected versions. The reentrancy lock storage slot was being incorrectly mapped, causing the guard to not trigger on reentrant calls.&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-vyper" data-lang="vyper">@external
@nonreentrant(&amp;#34;lock&amp;#34;)
def remove_liquidity(...):
# This should have been protected by reentrancy guard
# but the compiler bug allowed reentrant calls
&lt;/code>&lt;/pre>&lt;h2 id="attack-flow">Attack Flow&lt;/h2>
&lt;ol>
&lt;li>Attacker calls &lt;code>add_liquidity()&lt;/code> on the vulnerable pool&lt;/li>
&lt;li>During the callback (via raw_call), attacker reenters &lt;code>remove_liquidity()&lt;/code>&lt;/li>
&lt;li>The reentrancy guard fails to block the second call&lt;/li>
&lt;li>Pool state is inconsistent — attacker withdraws more than deposited&lt;/li>
&lt;/ol>
&lt;h2 id="proof-of-concept">Proof of Concept&lt;/h2>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-solidity" data-lang="solidity">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">interface&lt;/span> &lt;span style="color:#a6e22e">ICurvePool&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">function&lt;/span> &lt;span style="color:#a6e22e">add_liquidity&lt;/span>(&lt;span style="color:#66d9ef">uint256&lt;/span>[&lt;span style="color:#ae81ff">2&lt;/span>] calldata amounts, &lt;span style="color:#66d9ef">uint256&lt;/span> min_mint_amount) &lt;span style="color:#66d9ef">external&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">function&lt;/span> &lt;span style="color:#a6e22e">remove_liquidity&lt;/span>(&lt;span style="color:#66d9ef">uint256&lt;/span> _amount, &lt;span style="color:#66d9ef">uint256&lt;/span>[&lt;span style="color:#ae81ff">2&lt;/span>] calldata min_amounts) &lt;span style="color:#66d9ef">external&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">contract&lt;/span> &lt;span style="color:#a6e22e">CurveExploit&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> ICurvePool pool;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">bool&lt;/span> entered;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">function&lt;/span> &lt;span style="color:#a6e22e">attack&lt;/span>() &lt;span style="color:#66d9ef">external&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> pool.add_liquidity([&lt;span style="color:#ae81ff">1&lt;/span> &lt;span style="color:#66d9ef">ether&lt;/span>, &lt;span style="color:#ae81ff">0&lt;/span>], &lt;span style="color:#ae81ff">0&lt;/span>);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> receive() &lt;span style="color:#66d9ef">external&lt;/span> &lt;span style="color:#66d9ef">payable&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> (&lt;span style="color:#f92672">!&lt;/span>entered) {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> entered &lt;span style="color:#f92672">=&lt;/span> &lt;span style="color:#66d9ef">true&lt;/span>;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> pool.remove_liquidity(pool.balanceOf(&lt;span style="color:#66d9ef">address&lt;/span>(this)), [&lt;span style="color:#ae81ff">0&lt;/span>, &lt;span style="color:#ae81ff">0&lt;/span>]);
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> }
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="key-takeaway">Key Takeaway&lt;/h2>
&lt;p>This incident highlights the risk of relying on compiler-level security guarantees. The vulnerability existed not in the Solidity/Vyper source code but in the compiled bytecode. Auditing only the source code would not have caught this bug.&lt;/p></description></item><item><title>Euler Finance Flash Loan Attack Analysis</title><link>https://0xtracer.xyz/analysis/euler-flash-loan/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/analysis/euler-flash-loan/</guid><description>&lt;h2 id="overview">Overview&lt;/h2>
&lt;p>On March 13, 2023, Euler Finance was exploited for approximately $197M through a sophisticated flash loan attack that abused the protocol&amp;rsquo;s donation mechanism.&lt;/p>
&lt;h2 id="root-cause">Root Cause&lt;/h2>
&lt;p>Euler&amp;rsquo;s &lt;code>donateToReserves()&lt;/code> function allowed users to donate eTokens to the protocol reserves without a corresponding health check. This enabled attackers to manipulate their debt-to-collateral ratio.&lt;/p>
&lt;h2 id="attack-flow">Attack Flow&lt;/h2>
&lt;ol>
&lt;li>Flash loan large amount of DAI from Aave&lt;/li>
&lt;li>Deposit into Euler → receive eDAI&lt;/li>
&lt;li>Mint maximum dDAI (debt tokens) through leveraged borrowing&lt;/li>
&lt;li>Call &lt;code>donateToReserves()&lt;/code> with eDAI — reduces collateral without repaying debt&lt;/li>
&lt;li>Account is now underwater → trigger self-liquidation at a profit&lt;/li>
&lt;li>Repay flash loan, keep the difference&lt;/li>
&lt;/ol>
&lt;h2 id="vulnerable-code">Vulnerable Code&lt;/h2>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-solidity" data-lang="solidity">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">function&lt;/span> &lt;span style="color:#a6e22e">donateToReserves&lt;/span>(&lt;span style="color:#66d9ef">uint&lt;/span> subAccountId, &lt;span style="color:#66d9ef">uint&lt;/span> amount) &lt;span style="color:#66d9ef">external&lt;/span> {
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#75715e">// Missing: health check after donation
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">&lt;/span> &lt;span style="color:#75715e">// The function reduces the sender&amp;#39;s eToken balance
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">&lt;/span> &lt;span style="color:#75715e">// without verifying they remain solvent
&lt;/span>&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e">&lt;/span> reserves &lt;span style="color:#f92672">+=&lt;/span> amount;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> balanceOf[sender] &lt;span style="color:#f92672">-=&lt;/span> amount;
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>}
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h2 id="key-takeaway">Key Takeaway&lt;/h2>
&lt;p>Any state-changing function that modifies a user&amp;rsquo;s collateral or debt position must include a health factor check afterward. The &lt;code>donateToReserves()&lt;/code> function was audited but the edge case of self-donation leading to insolvency was missed.&lt;/p></description></item><item><title>Vercel</title><link>https://0xtracer.xyz/incidents/2026-04-19-vercel/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-19-vercel/</guid><description>Vercel CEO Guillermo Rauch stated on X that the company is currently conducting a full investigation into a security incident. The incident originated from a compromise of Context.ai, an AI platform used by a Vercel e&amp;hellip;</description></item><item><title>DNS registrar for eth.limo</title><link>https://0xtracer.xyz/incidents/2026-04-18-dns-registrar-for-eth-limo/</link><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-18-dns-registrar-for-eth-limo/</guid><description>Vitalik Buterin stated on X that the DNS registrar for eth.limo has been attacked. He advised users to temporarily avoid accessing vitalik.eth.limo or any other eth.limo-related pages until official confirmation is gi&amp;hellip;</description></item><item><title>Kelp DAO's rsETH bridge</title><link>https://0xtracer.xyz/incidents/2026-04-18-kelp-dao-s-rseth-bridge/</link><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-18-kelp-dao-s-rseth-bridge/</guid><description>LayerZero issued a statement saying that on April 18, KelpDAO suffered an attack resulting in approximately $290 million in losses. The incident is initially assessed to have been carried out by a highly sophisticated&amp;hellip;</description></item><item><title>Grinex</title><link>https://0xtracer.xyz/incidents/2026-04-16-grinex/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-16-grinex/</guid><description>According to The Block, Grinex, an exchange registered in Kyrgyzstan with ties to the Russian crypto market, has suspended withdrawals and trading following a large-scale cyberattack. A statement on the exchange’s web&amp;hellip;</description></item><item><title>Rhea Finance</title><link>https://0xtracer.xyz/incidents/2026-04-16-rhea-finance/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-16-rhea-finance/</guid><description>According to CertiK, a security incident occurred in the NEAR ecosystem DeFi protocol Rhea Finance. The attacker created multiple fake token contracts and added liquidity to newly created pools, allegedly misleading t&amp;hellip;</description></item><item><title>CowSwap</title><link>https://0xtracer.xyz/incidents/2026-04-14-cowswap/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-14-cowswap/</guid><description>Blockchain security firm Blockaid reported that its system has detected a front-end attack on the decentralized exchange CoW Swap, and that cow.fi has been flagged as a malicious site. Blockaid warned that users who h&amp;hellip;</description></item><item><title>dango</title><link>https://0xtracer.xyz/incidents/2026-04-13-dango/</link><pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-13-dango/</guid><description>The DeFi project Dango released an update three hours after disclosing a security incident last night, stating that the white-hat hacker has fully returned the stolen funds and received a bug bounty. User funds were n&amp;hellip;</description></item><item><title>Hyperbridge</title><link>https://0xtracer.xyz/incidents/2026-04-13-hyperbridge/</link><pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-13-hyperbridge/</guid><description>Based on monitoring by CertiK Alert, the Hyperbridge gateway contract fell victim to an exploit. The attacker utilized forged messages to manipulate administrative permissions of the Polkadot token contract on the Eth&amp;hellip;</description></item><item><title>Zerion</title><link>https://0xtracer.xyz/incidents/2026-04-11-zerion/</link><pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-11-zerion/</guid><description>An employee device at Zerion was compromised through an AI-driven social engineering attack, allegedly linked to a DPRK-associated advanced persistent threat (APT) group. The attacker successfully obtained the employe&amp;hellip;</description></item><item><title>Denaria</title><link>https://0xtracer.xyz/incidents/2026-04-05-denaria/</link><pubDate>Sun, 05 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-05-denaria/</guid><description>Decentralized perpetual futures trading platform Denaria announced on X that it suffered a smart contract attack yesterday, resulting in a loss of approximately $165,000. The team is currently working with Linea and a&amp;hellip;</description></item><item><title>TMM</title><link>https://0xtracer.xyz/incidents/2026-04-05-tmm/</link><pubDate>Sun, 05 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-05-tmm/</guid><description>According to ExVul monitoring, a TMM/USDT reserve manipulation attack occurred on the BSC (BNB Chain), resulting in a loss of approximately 1.665 million USDT. The attacker utilized flash loans from Lista DAO Moolah,&amp;hellip;</description></item><item><title>HypurrFi</title><link>https://0xtracer.xyz/incidents/2026-04-04-hypurrfi/</link><pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-04-hypurrfi/</guid><description>DeFi lending protocol HypurrFi tweeted that the hypurr.fi domain has been hijacked. The team has migrated its infrastructure to hypurrfi .com. The protocol itself, user funds, and team infrastructure remain unaffected.</description></item><item><title>Adobe</title><link>https://0xtracer.xyz/incidents/2026-04-03-adobe/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-03-adobe/</guid><description>GoPlus has issued a security alert regarding a suspected cyberattack on Adobe, involving the potential leak of approximately 13 million users&amp;rsquo; data. Affected users may face heightened risks, including phishing emails&amp;hellip;</description></item><item><title>Drift Protocol</title><link>https://0xtracer.xyz/incidents/2026-04-02-drift-protocol/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-02-drift-protocol/</guid><description>According to The Block, the Solana-based decentralized exchange Drift Protocol has been hit by a major exploit, with losses totaling at least $200 million. Some estimates suggest the figure is closer to $270 million,&amp;hellip;</description></item><item><title>Galaxy Digital</title><link>https://0xtracer.xyz/incidents/2026-04-02-galaxy-digital/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-02-galaxy-digital/</guid><description>A spokesperson for Galaxy Digital disclosed that the company recently contained a cybersecurity incident. Unauthorized access was strictly limited to an isolated development and testing environment; production systems&amp;hellip;</description></item><item><title>Trust Wallet</title><link>https://0xtracer.xyz/incidents/2026-04-02-trust-wallet/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-02-trust-wallet/</guid><description>According to ZachXBT, the Trust Wallet Discord vanity URL (discord[.]gg/trustwallet) has been hijacked and currently directs users to a phishing server. Users are advised to avoid using links from official channels—in&amp;hellip;</description></item><item><title>LML/USDT staking protocol</title><link>https://0xtracer.xyz/incidents/2026-04-01-lml-usdt-staking-protocol/</link><pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-04-01-lml-usdt-staking-protocol/</guid><description>According to BlockSec monitoring, an unknown contract on the BSC (BNB Smart Chain)—suspected to be the LML/USDT staking protocol—has been exploited for approximately $950,000. Analysis indicates the vulnerability stem&amp;hellip;</description></item><item><title>Arf's official X account, @arf_one</title><link>https://0xtracer.xyz/incidents/2026-03-31-arf-s-official-x-account-arf-one/</link><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-31-arf-s-official-x-account-arf-one/</guid><description>Huma Finance issued a warning on X stating that the official X account of its partner Arf, @arf_one, has been compromised. Please refrain from interacting with any posts from that account until it has been fully secured.</description></item><item><title>axios@1.14.1</title><link>https://0xtracer.xyz/incidents/2026-03-31-axios-1-14-1/</link><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-31-axios-1-14-1/</guid><description>Socket has detected an active supply chain attack targeting version 1.14.1 of the core npm package, axios. The attacker injected malicious code into axios by introducing a malicious dependency that first appeared toda&amp;hellip;</description></item><item><title>Steakhouse Financial</title><link>https://0xtracer.xyz/incidents/2026-03-31-steakhouse-financial/</link><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-31-steakhouse-financial/</guid><description>Steakhouse Financial disclosed yesterday that it was targeted by a phone-based social engineering attack against its provider, OVH Cloud. The attacker modified the DNS A records of the main website and app subdomains&amp;hellip;</description></item><item><title>unknown contract (Stake) on BSC</title><link>https://0xtracer.xyz/incidents/2026-03-27-unknown-contract-stake-on-bsc/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-27-unknown-contract-stake-on-bsc/</guid><description>According to monitoring by BlockSec Phalcon, a suspicious transaction targeting an unknown contract (Stake) on the BSC chain has been detected, resulting in a loss of approximately $133,000. The attacker exploited a s&amp;hellip;</description></item><item><title>Moonwell</title><link>https://0xtracer.xyz/incidents/2026-03-26-moonwell/</link><pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-26-moonwell/</guid><description>According to The Block, DeFi lending protocol Moonwell is facing a governance attack on its Moonriver deployment, where an unknown attacker spent approximately $1,800 to acquire 40 million MFAM tokens and managed to b&amp;hellip;</description></item><item><title>LiteLLM</title><link>https://0xtracer.xyz/incidents/2026-03-25-litellm/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-25-litellm/</guid><description>SlowMist&amp;rsquo;s CISO 23pds warned on X: &amp;ldquo;A major supply chain attack has hit LiteLLM (97M monthly downloads) via PyPI. Simply executing pip install litellm allows attackers to steal sensitive data: SSH keys, cloud logins (&amp;hellip;</description></item><item><title>Bitcoin Depot</title><link>https://0xtracer.xyz/incidents/2026-03-23-bitcoin-depot/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-23-bitcoin-depot/</guid><description>According to Decrypt, Bitcoin ATM operator Bitcoin Depot disclosed in a filing with the U.S. Securities and Exchange Commission that it experienced a security breach on March 23. Approximately 50.9 BTC, valued at arou&amp;hellip;</description></item><item><title>PancakeSwap BCE-USDT</title><link>https://0xtracer.xyz/incidents/2026-03-23-pancakeswap-bce-usdt/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-23-pancakeswap-bce-usdt/</guid><description>According to BlockSec Phalcon&amp;rsquo;s monitoring, the BCE-USDT pool on PancakeSwap (BSC chain) was exploited a few hours ago, resulting in a loss of approximately $679,000. The root cause lies in a vulnerability within the&amp;hellip;</description></item><item><title>Resolv Labs</title><link>https://0xtracer.xyz/incidents/2026-03-22-resolv-labs/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-22-resolv-labs/</guid><description>PeckShield alerted on X that Resolv Labs’ stablecoin, $USR, has seen multiple suspicious large-scale minting events. A total of $80 billion worth of USR has been minted so far.</description></item><item><title>Neutrl</title><link>https://0xtracer.xyz/incidents/2026-03-19-neutrl/</link><pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-19-neutrl/</guid><description>The DeFi protocol Neutrl announced on platform X that its frontend appears to have been compromised and that the team is conducting an urgent investigation. Out of an abundance of caution, the official advisory recomm&amp;hellip;</description></item><item><title>dTRINITY</title><link>https://0xtracer.xyz/incidents/2026-03-18-dtrinity/</link><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-18-dtrinity/</guid><description>dTRINITY disclosed on X that yesterday, the dLEND deployment on Ethereum suffered its first deposit inflation attack. This incident drained the dUSD liquidity in the lending pool, resulting in approximately $257,000 i&amp;hellip;</description></item><item><title>Venus Protocol</title><link>https://0xtracer.xyz/incidents/2026-03-15-venus-protocol/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-15-venus-protocol/</guid><description>An attacker exploited a vulnerability in the Venus Protocol, utilizing flash loans to acquire a substantial amount of assets. In this attack, the attacker’s address (0x1a35&amp;hellip;6231) successfully obtained 20 BTC, 1.5 mi&amp;hellip;</description></item><item><title>AM/USDT pool</title><link>https://0xtracer.xyz/incidents/2026-03-12-am-usdt-pool/</link><pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-12-am-usdt-pool/</guid><description>The AM/USDT pool on the BSC chain was exploited several hours ago, with estimated losses of approximately $131,000. The root cause lies in a vulnerability within the burn mechanism, which was exploited to manipulate t&amp;hellip;</description></item><item><title>DBXen</title><link>https://0xtracer.xyz/incidents/2026-03-12-dbxen/</link><pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-12-dbxen/</guid><description>According to monitoring by BlockSec Phalcon, the DBXen contract was attacked this morning, with estimated losses of approximately $150,000.The root cause lies in a sender identity inconsistency within the ERC-2771 met&amp;hellip;</description></item><item><title>BONKfun</title><link>https://0xtracer.xyz/incidents/2026-03-11-bonkfun/</link><pubDate>Wed, 11 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-11-bonkfun/</guid><description>BONKfun announced on X that its official website fell victim to a malicious social engineering attack on March 11. The attacker hijacked the BONKfun domain via the Domain Name Service (DNS) provider and transferred it&amp;hellip;</description></item><item><title>Gondi</title><link>https://0xtracer.xyz/incidents/2026-03-10-gondi/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-10-gondi/</guid><description>The NFT platform Gondi recently suffered a smart contract vulnerability attack, resulting in the theft of approximately 78 NFTs, with losses of about $230,000. According to an official announcement from Gondi, the att&amp;hellip;</description></item><item><title>MT-WBNB LP</title><link>https://0xtracer.xyz/incidents/2026-03-10-mt-wbnb-lp/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-10-mt-wbnb-lp/</guid><description>According to BlockSec Phalcon&amp;rsquo;s monitoring, a suspicious transaction targeting the MT-WBNB liquidity pool on BSC was detected several hours ago, resulting in an estimated loss of approximately $242,000. The root cause&amp;hellip;</description></item><item><title>Solv Protocol</title><link>https://0xtracer.xyz/incidents/2026-03-06-solv-protocol/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-06-solv-protocol/</guid><description>The Bitcoin staking protocol Solv Protocol stated on X that its BRO Vault experienced a limited exploit. Fewer than 10 users were affected, with a loss of 38.0474 SolvBTC (approximately $2.7 million). Other vaults and&amp;hellip;</description></item><item><title>Inverse Finance</title><link>https://0xtracer.xyz/incidents/2026-03-02-inverse-finance/</link><pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-02-inverse-finance/</guid><description>According to BlockSec Phalcon’s monitoring, its system detected a suspicious transaction targeting an Inverse Finance contract on Ethereum several hours ago, resulting in a loss of approximately $240,000. The incident&amp;hellip;</description></item><item><title>Bitrefill</title><link>https://0xtracer.xyz/incidents/2026-03-01-bitrefill/</link><pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-03-01-bitrefill/</guid><description>Bitcoin payment service provider Bitrefill disclosed on X that it suffered a cyberattack on March 1, 2026, resulting in a customer data breach. The attack originated from a compromised employee laptop, which allowed t&amp;hellip;</description></item><item><title>Stake Nova</title><link>https://0xtracer.xyz/incidents/2026-02-27-stake-nova/</link><pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-27-stake-nova/</guid><description>Stake Nova suffered a loss of approximately $137,014, representing about 95% of user deposits. The root cause was an unchecked validation issue in the RedeemNovaSol() function, which led to a flash-loan exploit that d&amp;hellip;</description></item><item><title>FOOMCASH</title><link>https://0xtracer.xyz/incidents/2026-02-26-foomcash/</link><pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-26-foomcash/</guid><description>The privacy gaming platform FOOMCASH was attacked on Base and Ethereum, resulting in a loss of 24,283,773,519,600 $FOOM (approximately $2.26 million). The vulnerability was caused by a misconfiguration of the verifica&amp;hellip;</description></item><item><title>Holdstation</title><link>https://0xtracer.xyz/incidents/2026-02-25-holdstation/</link><pubDate>Wed, 25 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-25-holdstation/</guid><description>The Holdstation team has confirmed on X that its DeFAI Smart Wallet product experienced a security incident. According to the latest update, the total loss has been confirmed at approximately 462,000 USDT. The team st&amp;hellip;</description></item><item><title>WLFI</title><link>https://0xtracer.xyz/incidents/2026-02-23-wlfi/</link><pubDate>Mon, 23 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-23-wlfi/</guid><description>WLFI announced on X that USD1 experienced an organized attack this morning. The attackers reportedly compromised the accounts of several WLFI co-founders, paying influencers to spread FUD (Fear, Uncertainty, and Doubt&amp;hellip;</description></item><item><title>IoTeX</title><link>https://0xtracer.xyz/incidents/2026-02-21-iotex/</link><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-21-iotex/</guid><description>The IoT-focused public chain IoTeX suffered a professional hacker attack caused by a private key compromise of the ioTube bridge’s Ethereum-side validator owner. This allowed the attacker to gain administrative privil&amp;hellip;</description></item><item><title>Moonwell</title><link>https://0xtracer.xyz/incidents/2026-02-18-moonwell/</link><pubDate>Wed, 18 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-18-moonwell/</guid><description>According to Decrypt, the DeFi lending protocol Moonwell incurred approximately $1.78 million in bad debt due to an oracle configuration error.</description></item><item><title>Arbitrum Governance</title><link>https://0xtracer.xyz/incidents/2026-02-03-arbitrum-governance/</link><pubDate>Tue, 03 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-03-arbitrum-governance/</guid><description>Arbitrum has issued a security alert: The official X account for Arbitrum Governance (@arbitrumdao_gov) has been compromised. Do not click on any links posted by this account or engage with it. The team is working to&amp;hellip;</description></item><item><title>CrossCurve</title><link>https://0xtracer.xyz/incidents/2026-02-02-crosscurve/</link><pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-02-02-crosscurve/</guid><description>The cross-chain liquidity protocol CrossCurve (formerly EYWA) has confirmed that its cross-chain bridge protocol is under attack, due to a vulnerability in its smart contract that was exploited, resulting in the theft&amp;hellip;</description></item><item><title>Step Finance</title><link>https://0xtracer.xyz/incidents/2026-01-31-step-finance/</link><pubDate>Sat, 31 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-31-step-finance/</guid><description>Step Finance has issued a statement on X regarding a recent exploit, disclosing that approximately $40 million was stolen from its treasury due to a compromise of an executive&amp;rsquo;s device. Upon detecting the vulnerabilit&amp;hellip;</description></item><item><title>Solar</title><link>https://0xtracer.xyz/incidents/2026-01-27-solar/</link><pubDate>Tue, 27 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-27-solar/</guid><description>Solar, the official Solana Mandarin community, highly suspects its official X account (@Solana_zh) has been hacked. The team currently lacks access and is working urgently with X support to resolve the issue. Recovery&amp;hellip;</description></item><item><title>unknown contract</title><link>https://0xtracer.xyz/incidents/2026-01-27-unknown-contract/</link><pubDate>Tue, 27 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-27-unknown-contract/</guid><description>According to BlockSec monitoring, an unknown contract on the BSC network was exploited. The attacker leveraged a design flaw in the “burn pair” mechanism to execute two reverse swaps, resulting in losses of approximat&amp;hellip;</description></item><item><title>Aperture Finance</title><link>https://0xtracer.xyz/incidents/2026-01-26-aperture-finance/</link><pubDate>Mon, 26 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-26-aperture-finance/</guid><description>Aperture Finance posted on X stating that it has detected an exploit affecting Aperture V3/V4 contracts. To prevent new approvals, core functionalities have been suspended in the front-end application, and the team is&amp;hellip;</description></item><item><title>SwapNet</title><link>https://0xtracer.xyz/incidents/2026-01-26-swapnet/</link><pubDate>Mon, 26 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-26-swapnet/</guid><description>According to PeckShield, Matcha Meta reported that SwapNet suffered a security breach, with losses reaching $16.8 million. The attacker swapped approximately 10.5 million USDC for around 3,655 ETH on Base, and has beg&amp;hellip;</description></item><item><title>Scroll</title><link>https://0xtracer.xyz/incidents/2026-01-25-scroll/</link><pubDate>Sun, 25 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-25-scroll/</guid><description>Scroll alerted on X that the X account of co-founder @shenhaichen has been compromised. They are actively working to recover the account and advise users not to interact with any links or direct messages.</description></item><item><title>Mithril</title><link>https://0xtracer.xyz/incidents/2026-01-21-mithril/</link><pubDate>Wed, 21 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-21-mithril/</guid><description>According to an announcement from Paradex, the internal systems of the Mithril trading bot were compromised by an attacker, resulting in the exposure of approximately 57 user subkeys. While these subkeys do not allow&amp;hellip;</description></item><item><title>SagaEVM</title><link>https://0xtracer.xyz/incidents/2026-01-21-sagaevm/</link><pubDate>Wed, 21 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-21-sagaevm/</guid><description>According to an official announcement from Saga, the SagaEVM chain has suffered an attack involving a series of malicious contract deployments, cross-chain operations, and liquidity withdrawals. The attacker transferr&amp;hellip;</description></item><item><title>Makinafi</title><link>https://0xtracer.xyz/incidents/2026-01-20-makinafi/</link><pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-20-makinafi/</guid><description>According to PeckShieldAlert monitoring, the Makinafi protocol was exploited by hackers, resulting in a loss of approximately 1,299 ETH (about $4.13 million). The stolen funds are currently held in two addresses: 0xbe&amp;hellip;</description></item><item><title>SynapLogic</title><link>https://0xtracer.xyz/incidents/2026-01-20-synaplogic/</link><pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-20-synaplogic/</guid><description>According to a BlockSec alert, the SynapLogic contract lacked critical parameter validation in the swapExactTokensForETHSupportingFeeOnTransferTokens function, allowing attackers to manipulate the whitelist logic and&amp;hellip;</description></item><item><title>FutureSwap</title><link>https://0xtracer.xyz/incidents/2026-01-14-futureswap/</link><pubDate>Wed, 14 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-14-futureswap/</guid><description>The FutureSwap protocol deployed on Arbitrum was exploited again via a reentrancy vulnerability, following its first attack four days ago, resulting in a loss of approximately $74,000. The attacker had previously abus&amp;hellip;</description></item><item><title>Truebit</title><link>https://0xtracer.xyz/incidents/2026-01-09-truebit/</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-09-truebit/</guid><description>The blockchain verification protocol Truebit was suspected to have been hacked, losing 8,535 ETH, valued at approximately $26.44 million.</description></item><item><title>Darren Lau</title><link>https://0xtracer.xyz/incidents/2026-01-08-darren-lau/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-08-darren-lau/</guid><description>CertiK Alert tweeted that the X account of Darren Lau, founder of The Daily Ape, has been compromised by hackers. The CertiK security team warns users not to click any links or approve any transactions before control&amp;hellip;</description></item><item><title>Polycule</title><link>https://0xtracer.xyz/incidents/2026-01-08-polycule/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-08-polycule/</guid><description>The Polymarket-based trading bot project Polycule has been hacked. The Polycule team stated that approximately $230,000 in user funds were affected in this incident. The related bots have been taken offline, and patch&amp;hellip;</description></item><item><title>IPOR USDC Fusion Optimizer</title><link>https://0xtracer.xyz/incidents/2026-01-06-ipor-usdc-fusion-optimizer/</link><pubDate>Tue, 06 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-06-ipor-usdc-fusion-optimizer/</guid><description>Fusion has released a security update stating that its IPOR USDC Fusion Optimizer contains a vulnerability in the Arbitrum Vault. The IPOR team was notified and confirmed on January 6 that the vulnerability had result&amp;hellip;</description></item><item><title>TMX</title><link>https://0xtracer.xyz/incidents/2026-01-06-tmx/</link><pubDate>Tue, 06 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-06-tmx/</guid><description>According to CertiK Alert, a vulnerability involving a contract related to TMX on Arbitrum has been detected, with estimated losses of around $1.4 million. During the exploit loop, the attacker minted and staked TMX L&amp;hellip;</description></item><item><title>Arbitrum</title><link>https://0xtracer.xyz/incidents/2026-01-05-arbitrum/</link><pubDate>Mon, 05 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-05-arbitrum/</guid><description>Multiple suspicious transactions involving proxy contracts were detected on Arbitrum (ARB), with estimated losses of approximately $1.5 million. Preliminary analysis indicates that the sole deployer of the USDGambit a&amp;hellip;</description></item><item><title>Bitlight Labs</title><link>https://0xtracer.xyz/incidents/2026-01-05-bitlight-labs/</link><pubDate>Mon, 05 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-05-bitlight-labs/</guid><description>The X (formerly Twitter) account of Bitlight Labs, a Bitcoin RGB protocol and Lightning Network stablecoin payment infrastructure provider, was suspected of being compromised and posted content related to a meme token.</description></item><item><title>OLY token holders</title><link>https://0xtracer.xyz/incidents/2026-01-05-oly-token-holders/</link><pubDate>Mon, 05 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-05-oly-token-holders/</guid><description>According to TenArmorAlert, a sandwich attack involving OLY has been detected on BSC, causing estimated losses of around $63,400.</description></item><item><title>HitBTC</title><link>https://0xtracer.xyz/incidents/2026-01-04-hitbtc/</link><pubDate>Sun, 04 Jan 2026 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2026-01-04-hitbtc/</guid><description>SlowMist team has issued a security advisory stating that it has identified a potentially critical vulnerability on the HitBTC exchange platform. The issue has been responsibly disclosed to HitBTC in advance via priva&amp;hellip;</description></item><item><title>Unleash Protocol</title><link>https://0xtracer.xyz/incidents/2025-12-30-unleash-protocol/</link><pubDate>Tue, 30 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-30-unleash-protocol/</guid><description>The Unleash Protocol project deployed on Story Protocol suffered an unauthorized contract upgrade, followed by the malicious transfer of user assets. The attacker manipulated the project’s multisig governance privileg&amp;hellip;</description></item><item><title>MSCST</title><link>https://0xtracer.xyz/incidents/2025-12-29-mscst/</link><pubDate>Mon, 29 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-29-mscst/</guid><description>On the BSC network, an unknown smart contract MSCST suffered a flash loan attack, resulting in an estimated loss of approximately $130,000. The root cause of the exploit lies in the lack of access control (ACL) within&amp;hellip;</description></item><item><title>Debot</title><link>https://0xtracer.xyz/incidents/2025-12-27-debot/</link><pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-27-debot/</guid><description>SlowMist founder Cos stated on the X platform that the team is currently following up on the DeBot incident and monitoring on-chain activity. According to him, users’ private keys associated with DeBot have been compr&amp;hellip;</description></item><item><title>Flow</title><link>https://0xtracer.xyz/incidents/2025-12-27-flow/</link><pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-27-flow/</guid><description>The Flow Foundation announced that an attacker exploited a vulnerability in the Flow execution layer, transferring approximately $3.9 million in assets off the network before validators were able to coordinate and hal&amp;hellip;</description></item><item><title>Trust Wallet</title><link>https://0xtracer.xyz/incidents/2025-12-26-trust-wallet/</link><pubDate>Fri, 26 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-26-trust-wallet/</guid><description>Trust Wallet has issued an official notice confirming that version 2.68 of its browser extension contains a security vulnerability, and advised all users running version 2.68 to immediately disable it and upgrade to v&amp;hellip;</description></item><item><title>Futureswap</title><link>https://0xtracer.xyz/incidents/2025-12-17-futureswap/</link><pubDate>Wed, 17 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-17-futureswap/</guid><description>According to monitoring by SlowMist’s MistEye security monitoring system, potential suspicious activities related to @futureswapx have been detected. Further analysis indicates that the root cause lies in an attacker&amp;hellip;</description></item><item><title>ICRYPEX Global</title><link>https://0xtracer.xyz/incidents/2025-12-17-icrypex-global/</link><pubDate>Wed, 17 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-17-icrypex-global/</guid><description>SlowMist has issued a security alert to the cryptocurrency exchange ICRYPEX Global, stating that a potentially critical vulnerability has been identified.</description></item><item><title>Yearn Finance V1</title><link>https://0xtracer.xyz/incidents/2025-12-17-yearn-finance-v1/</link><pubDate>Wed, 17 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-17-yearn-finance-v1/</guid><description>According to monitoring by Paidun, Yearn Finance V1 suffered a hacker attack, resulting in a total loss of approximately USD 300,000. The attacker has converted the stolen funds into 103 ETH, which are currently held&amp;hellip;</description></item><item><title>Azbitm</title><link>https://0xtracer.xyz/incidents/2025-12-16-azbitm/</link><pubDate>Tue, 16 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-16-azbitm/</guid><description>SlowMist sent a security alert to the cryptocurrency exchange Azbitm, stating that a potential vulnerability has been detected.</description></item><item><title>Aevo</title><link>https://0xtracer.xyz/incidents/2025-12-14-aevo/</link><pubDate>Sun, 14 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-14-aevo/</guid><description>On December 14, Aevo announced that a vulnerability introduced during a smart contract upgrade led to an attack on the legacy Ribbon DOV vault on December 12, resulting in losses of approximately $2.7 million.</description></item><item><title>ZEROBASE</title><link>https://0xtracer.xyz/incidents/2025-12-12-zerobase/</link><pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-12-zerobase/</guid><description>According to SlowMist founder Yu Cos and ZEROBASE officials, a malicious contract on the BSC chain, “Vault” (0x0dd2…2396), impersonated the ZEROBASE frontend to trick users into authorizing USDT. The incident is suspe&amp;hellip;</description></item><item><title>0G Foundation</title><link>https://0xtracer.xyz/incidents/2025-12-11-0g-foundation/</link><pubDate>Thu, 11 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-11-0g-foundation/</guid><description>The 0G Foundation posted on X that a targeted attack on December 11 resulted in a breach of their reward contract. The attacker exploited the emergency withdrawal function of the 0G reward contract, which is used for&amp;hellip;</description></item><item><title>Almanak</title><link>https://0xtracer.xyz/incidents/2025-12-11-almanak/</link><pubDate>Thu, 11 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-11-almanak/</guid><description>According to an announcement by Almanak, during today’s airdrop, operational errors and a DDoS attack caused delays in claims and failures in wallet deployment. The claim function was originally scheduled to open at 1&amp;hellip;</description></item><item><title>PEPE</title><link>https://0xtracer.xyz/incidents/2025-12-04-pepe/</link><pubDate>Thu, 04 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-04-pepe/</guid><description>According to cybersecurity firm Blockaid, the official website of the meme coin PEPE was compromised by attackers, who modified the website’s front-end code, causing users visiting the site to be redirected to a malic&amp;hellip;</description></item><item><title>USPD</title><link>https://0xtracer.xyz/incidents/2025-12-04-uspd/</link><pubDate>Thu, 04 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-04-uspd/</guid><description>According to PeckShieldAlert, the stablecoin project USPD has suffered a major security breach, resulting in approximately $1 million in losses. The USPD team later confirmed that the protocol had been exploited, with&amp;hellip;</description></item><item><title>React</title><link>https://0xtracer.xyz/incidents/2025-12-03-react/</link><pubDate>Wed, 03 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-03-react/</guid><description>According to Finance Feeds, hackers exploited a vulnerability in the React JavaScript library to inject code into websites that steals funds from cryptocurrency wallets, primarily targeting cryptocurrency platforms. O&amp;hellip;</description></item><item><title>Goldfinch</title><link>https://0xtracer.xyz/incidents/2025-12-02-goldfinch/</link><pubDate>Tue, 02 Dec 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-12-02-goldfinch/</guid><description>The on-chain private fund Goldfinch’s old contract on Ethereum (0x0689) contained a vulnerability. Because the user deltatiger.eth did not revoke the authorization in time, they were exploited and lost approximately U&amp;hellip;</description></item><item><title>Yearn Finance</title><link>https://0xtracer.xyz/incidents/2025-11-30-yearn-finance/</link><pubDate>Sun, 30 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-30-yearn-finance/</guid><description>According to PeckShieldAlert on X, Yearn Finance suffered an attack in which the hacker drained the liquidity pool by infinitely minting yETH, causing losses of roughly $9 million. Approximately 1,000 ETH (about $3 mi&amp;hellip;</description></item><item><title>Upbit</title><link>https://0xtracer.xyz/incidents/2025-11-27-upbit/</link><pubDate>Thu, 27 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-27-upbit/</guid><description>Upbit CEO Woo Kyung-sik issued a public statement regarding the recent security breach and apologized to users, noting that the incident resulted from shortcomings in Upbit’s internal security management. On the morni&amp;hellip;</description></item><item><title>Agentic FoF</title><link>https://0xtracer.xyz/incidents/2025-11-24-agentic-fof/</link><pubDate>Mon, 24 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-24-agentic-fof/</guid><description>BasisOS disclosed on X: “Due to a security breach, the Agentic FoF was compromised, resulting in approximately USD 531,000 in leaked funds. All vaults have now been suspended, and withdrawals from the Agentic FoF have&amp;hellip;</description></item><item><title>Port3 Network</title><link>https://0xtracer.xyz/incidents/2025-11-23-port3-network/</link><pubDate>Sun, 23 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-23-port3-network/</guid><description>The decentralized AI data network Port3 Network disclosed on X that its token PORT3 was maliciously minted by a hacker exploiting a cross-chain bridge vulnerability. According to on-chain analyst Yujin, the attacker u&amp;hellip;</description></item><item><title>Aerodrome</title><link>https://0xtracer.xyz/incidents/2025-11-21-aerodrome/</link><pubDate>Fri, 21 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-21-aerodrome/</guid><description>Aerodrome, a DEX built on Base, posted on X that the centralized domains of Velodrome and Aerodrome were hijacked on November 21 due to an internal security vulnerability at NameSilo, resulting in redirection to malic&amp;hellip;</description></item><item><title>DMT 空投(@dexmaxai)</title><link>https://0xtracer.xyz/incidents/2025-11-20-dmt-dexmaxai/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-20-dmt-dexmaxai/</guid><description>GoPlus has issued a security alert: Users who claimed the DMT airdrop from @dexmaxai are advised to revoke approvals immediately or transfer their assets to a secure wallet. Multiple victims reported today that they w&amp;hellip;</description></item><item><title>GANA Payment</title><link>https://0xtracer.xyz/incidents/2025-11-20-gana-payment/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-20-gana-payment/</guid><description>According to on-chain security analyst ZachXBT, the payment project GANA Payment on the BSC chain was attacked a few hours ago, resulting in an estimated loss of $3.1 million. The attacker has deposited 1,140 BNB (aro&amp;hellip;</description></item><item><title>WLFI</title><link>https://0xtracer.xyz/incidents/2025-11-20-wlfi/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-20-wlfi/</guid><description>According to a WLFI announcement, prior to the platform’s official launch, some user wallets were compromised due to phishing attacks or mnemonic phrase leaks. WLFI emphasized that the incident was not caused by any p&amp;hellip;</description></item><item><title>Nofx AI</title><link>https://0xtracer.xyz/incidents/2025-11-17-nofx-ai/</link><pubDate>Mon, 17 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-17-nofx-ai/</guid><description>SlowMist founder Cos reminded users of the NOFX AI open-source automated trading system to be aware of potential security risks. Although the NOFX AI open-source work has shown good intentions, real theft incidents ha&amp;hellip;</description></item><item><title>Aftermath</title><link>https://0xtracer.xyz/incidents/2025-11-14-aftermath/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-14-aftermath/</guid><description>Sui’s official X account issued a reminder stating that the X account of Aftermath, a liquid staking protocol in the Sui ecosystem, has been compromised. Users are advised not to interact with the account until the te&amp;hellip;</description></item><item><title>Hyperliquid</title><link>https://0xtracer.xyz/incidents/2025-11-13-hyperliquid/</link><pubDate>Thu, 13 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-13-hyperliquid/</guid><description>According to Arkham’s monitoring, an attacker allegedly carried out a deliberate exploit against HLP (Hyperliquidity Provider) on Hyperliquid. The attacker used 19 wallets and $3 million in principal to open a leverag&amp;hellip;</description></item><item><title>Polymarket</title><link>https://0xtracer.xyz/incidents/2025-11-11-polymarket/</link><pubDate>Tue, 11 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-11-polymarket/</guid><description>According to a post by crypto trader @25usdc, hackers are exploiting the comment section of Polymarket to carry out scam activities, resulting in losses exceeding $500,000. The attackers post links to their phishing w&amp;hellip;</description></item><item><title>Moonwell</title><link>https://0xtracer.xyz/incidents/2025-11-04-moonwell/</link><pubDate>Tue, 04 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-04-moonwell/</guid><description>According to CertiK’s monitoring, the Moonwell lending contract suffered multiple attack transactions. The attacker exploited an incorrect oracle price for wrst (around USD 5.8 million). By using a flash loan of only&amp;hellip;</description></item><item><title>Balancer V2</title><link>https://0xtracer.xyz/incidents/2025-11-03-balancer-v2/</link><pubDate>Mon, 03 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-03-balancer-v2/</guid><description>The DeFi protocol Balancer V2 suffered a vulnerability exploit that affected its Composable Stable Pools. The root cause of the incident was an incorrect rounding direction in the Stable Pool’s “exact-out” swap path&amp;hellip;.</description></item><item><title>Berachain</title><link>https://0xtracer.xyz/incidents/2025-11-03-berachain/</link><pubDate>Mon, 03 Nov 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-11-03-berachain/</guid><description>Berachain announced that approximately USD 12.8 million in funds lost due to the BEX/Balancer v2 vulnerability have been fully returned to the Berachain Foundation’s deployer address, and the blockchain has now resume&amp;hellip;</description></item><item><title>Garden Finance</title><link>https://0xtracer.xyz/incidents/2025-10-31-garden-finance/</link><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-31-garden-finance/</guid><description>According to CertiK Alert, the Garden attacker has transferred 501 BNB and 1,910 ETH (worth approximately $6.65 million) to Tornado Cash.The address starting with 0x98BC still holds around $910,000 in assets.It is rep&amp;hellip;</description></item><item><title>402Bridge</title><link>https://0xtracer.xyz/incidents/2025-10-28-402bridge/</link><pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-28-402bridge/</guid><description>402Bridge posted on X to alert users that a token theft incident had occurred. The technical team is investigating the entire process and advised all users to immediately revoke existing authorizations and transfer th&amp;hellip;</description></item><item><title>GMGN</title><link>https://0xtracer.xyz/incidents/2025-10-28-gmgn/</link><pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-28-gmgn/</guid><description>GMGN co-founder Haze posted on X (Twitter):&amp;ldquo;We have noticed a deliberate external phishing attack targeting GMGN. The attacker induced users to click by forging a third-party token website, triggering unauthorized tra&amp;hellip;</description></item><item><title>GMGN</title><link>https://0xtracer.xyz/incidents/2025-10-25-gmgn/</link><pubDate>Sat, 25 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-25-gmgn/</guid><description>On October 27, GMGN Co-founder Haze posted on X, stating that the team has completed compensation payments to users affected by the MEV attack. He noted that 48 hours earlier, GMGN had suffered an MEV attack involving&amp;hellip;</description></item><item><title>Noble</title><link>https://0xtracer.xyz/incidents/2025-10-23-noble/</link><pubDate>Thu, 23 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-23-noble/</guid><description>According to monitoring by Scam Sniffer, the official X account of Noble was compromised, and the attacker used it to post phishing tweets.</description></item><item><title>DoodiPals</title><link>https://0xtracer.xyz/incidents/2025-10-21-doodipals/</link><pubDate>Tue, 21 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-21-doodipals/</guid><description>The Solana-based mini entertainment project DoodiPals suffered a private key leak. The attacker sold tokens from dozens of wallets and exchanged them for SOL, making a total profit of about 917 SOL (approximately $171&amp;hellip;</description></item><item><title>Sharwa.Finance</title><link>https://0xtracer.xyz/incidents/2025-10-20-sharwa-finance/</link><pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-20-sharwa-finance/</guid><description>According to a BlockSec Phalcon alert, Sharwa.Finance disclosed that it had suffered an attack and subsequently suspended operations. However, several hours later, multiple suspicious transactions occurred again, sugg&amp;hellip;</description></item><item><title>Astra Nova</title><link>https://0xtracer.xyz/incidents/2025-10-19-astra-nova/</link><pubDate>Sun, 19 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-19-astra-nova/</guid><description>Astra Nova announced on X that its third-party managed account was compromised, allowing the attacker to take control and liquidate assets. The team stated that they are taking necessary measures and will involve law&amp;hellip;</description></item><item><title>Typus Finance</title><link>https://0xtracer.xyz/incidents/2025-10-15-typus-finance/</link><pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-15-typus-finance/</guid><description>According to Typus Finance’s post-incident analysis report, on October 15, 2025, an attacker exploited a critical vulnerability in the project’s oracle module to drain funds from the TLP contract. The stolen assets in&amp;hellip;</description></item><item><title>Watt Protocol</title><link>https://0xtracer.xyz/incidents/2025-10-09-watt-protocol/</link><pubDate>Thu, 09 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-09-watt-protocol/</guid><description>According to monitoring by Scam Sniffer, the official X account of Watt Protocol was compromised, and the attacker used it to post phishing tweets.</description></item><item><title>MIN Spell</title><link>https://0xtracer.xyz/incidents/2025-10-04-min-spell/</link><pubDate>Sat, 04 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-04-min-spell/</guid><description>MIN Spell posted on X that the team discovered a security vulnerability affecting some deprecated V4 Cauldrons on the Ethereum mainnet. During the attack, the attacker minted 1.79 million MIM. Shortly afterward, the D&amp;hellip;</description></item><item><title>BNB Chain</title><link>https://0xtracer.xyz/incidents/2025-10-01-bnb-chain/</link><pubDate>Wed, 01 Oct 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-10-01-bnb-chain/</guid><description>On October 1, BNB Chain officially announced that its English Twitter account had been compromised and was under emergency recovery, warning users not to click on any links.Subsequent investigation revealed that the i&amp;hellip;</description></item><item><title>dTRINITY</title><link>https://0xtracer.xyz/incidents/2025-09-28-dtrinity/</link><pubDate>Sun, 28 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-28-dtrinity/</guid><description>The DeFi protocol dTRINITY suffered an exploit targeting its swap adapter contracts, resulting in the loss of approximately $56,000 belonging to core team members.</description></item><item><title>Hyperdrive</title><link>https://0xtracer.xyz/incidents/2025-09-27-hyperdrive/</link><pubDate>Sat, 27 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-27-hyperdrive/</guid><description>The DeFi protocol Hyperdrive, built on the Hyperliquid chain, was exploited. The attacker repeatedly abused an arbitrary call vulnerability in the router, resulting in a loss of approximately $782,000.</description></item><item><title>HyperVault</title><link>https://0xtracer.xyz/incidents/2025-09-26-hypervault/</link><pubDate>Fri, 26 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-26-hypervault/</guid><description>The DeFi protocol HyperVault, built on the Hyperliquid chain, has executed a rug pull, making off with approximately $3.61 million.</description></item><item><title>GriffinAI</title><link>https://0xtracer.xyz/incidents/2025-09-24-griffinai/</link><pubDate>Wed, 24 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-24-griffinai/</guid><description>The attackers exploited a misconfigured LayerZero bridge along with a compromised private key for the GAIN BSC contract. By setting a malicious peer contract on Ethereum, they bypassed validation checks and minted 5 b&amp;hellip;</description></item><item><title>SBI Crypto</title><link>https://0xtracer.xyz/incidents/2025-09-24-sbi-crypto/</link><pubDate>Wed, 24 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-24-sbi-crypto/</guid><description>According to on-chain investigator ZachXBT, Japan’s financial giant SBI Group may have experienced a security breach involving its cryptocurrency mining subsidiary, SBI Crypto. Wallet addresses associated with the com&amp;hellip;</description></item><item><title>Corepound</title><link>https://0xtracer.xyz/incidents/2025-09-23-corepound/</link><pubDate>Tue, 23 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-23-corepound/</guid><description>The DeFi project Corepound, built on the Core DAO blockchain, has carried out a rug pull, making off with approximately $400,000.</description></item><item><title>Seedify</title><link>https://0xtracer.xyz/incidents/2025-09-23-seedify/</link><pubDate>Tue, 23 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-23-seedify/</guid><description>Meta Alchemist, founder of the Web3 incubator and launchpad platform Seedify, announced on X that one of its SFUND bridges was recently hacked. According to Seedify’s official account, a DPRK-affiliated group known fo&amp;hellip;</description></item><item><title>UXLINK</title><link>https://0xtracer.xyz/incidents/2025-09-22-uxlink/</link><pubDate>Mon, 22 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-22-uxlink/</guid><description>AI-driven Web3 social platform UXLINK suffered an attack affecting platform-related assets, resulting in losses exceeding USD 11 million. Investigation showed that the attacker had prepared for months prior to the inc&amp;hellip;</description></item><item><title>Yala</title><link>https://0xtracer.xyz/incidents/2025-09-14-yala/</link><pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-14-yala/</guid><description>On September 14, the stablecoin protocol Yala disclosed that a recent security incident occurred when a hacker abused a temporary deployment key during the setup of an authorized cross-chain bridge. The attacker deplo&amp;hellip;</description></item><item><title>Kame Aggregator</title><link>https://0xtracer.xyz/incidents/2025-09-12-kame-aggregator/</link><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-12-kame-aggregator/</guid><description>Kame Aggregator suffered an exploit due to a design flaw in the swap() function, which allowed arbitrary executor calls. This vulnerability enabled attackers to transfer tokens authorized to the AggregationRouter by u&amp;hellip;</description></item><item><title>Shibarium Bridge</title><link>https://0xtracer.xyz/incidents/2025-09-12-shibarium-bridge/</link><pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-12-shibarium-bridge/</guid><description>The Shibarium bridge, connecting the Layer 2 network of the same name to Ethereum, was targeted in a flash loan attack, resulting in a loss of approximately $2.4 million. The attacker used a flash loan to purchase 4.6&amp;hellip;</description></item><item><title>Aqua</title><link>https://0xtracer.xyz/incidents/2025-09-08-aqua/</link><pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-08-aqua/</guid><description>On-chain investigator ZachXBT reported that the Solana project Aqua has likely executed a rug pull involving approximately 21,770 SOL (~$4.65M). A few hours ago, the funds were split into four parts, moved through mul&amp;hellip;</description></item><item><title>Nemo Protocol</title><link>https://0xtracer.xyz/incidents/2025-09-08-nemo-protocol/</link><pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-08-nemo-protocol/</guid><description>Nemo Protocol, a DeFi protocol on Sui, was attacked, resulting in a loss of approximately $2.4 million.</description></item><item><title>SwissBorg</title><link>https://0xtracer.xyz/incidents/2025-09-08-swissborg/</link><pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-08-swissborg/</guid><description>Swiss crypto platform SwissBorg suffered a security incident in which approximately 192,600 SOL (~$41.5M) was stolen on Solana. According to SwissBorg’s official statement, the incident was caused by a compromised par&amp;hellip;</description></item><item><title>Bunni</title><link>https://0xtracer.xyz/incidents/2025-09-02-bunni/</link><pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-09-02-bunni/</guid><description>Bunni, a DEX built on Uniswap v4, was exploited on Ethereum and UniChain, with total losses of approximately $8.4 million.</description></item><item><title>BetterBank</title><link>https://0xtracer.xyz/incidents/2025-08-27-betterbank/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-27-betterbank/</guid><description>The PulseChain-based defi project BetterBank was exploited by an attacker who took advantage of a vulnerability that allowed them to mint arbitrary tokens, some of which they then swapped for ETH. The attacker later r&amp;hellip;</description></item><item><title>Equilibria Finance</title><link>https://0xtracer.xyz/incidents/2025-08-24-equilibria-finance/</link><pubDate>Sun, 24 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-24-equilibria-finance/</guid><description>According to an announcement from Equilibria Finance, a vulnerability was discovered in the ePENDLE auto-compounder contract on Ethereum, resulting in a loss of approximately 13.36 ETH. The issue stemmed from the stk-&amp;hellip;</description></item><item><title>ABCCApp</title><link>https://0xtracer.xyz/incidents/2025-08-23-abccapp/</link><pubDate>Sat, 23 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-23-abccapp/</guid><description>ABCCApp on BSC was reportedly attacked, resulting in a loss of approximately $10.1K. The root cause was that the contract’s addFixedDay() function lacked access control, and fixedDay was used in calculating claimable&amp;hellip;</description></item><item><title>Puffer Finance</title><link>https://0xtracer.xyz/incidents/2025-08-20-puffer-finance/</link><pubDate>Wed, 20 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-20-puffer-finance/</guid><description>According to SlowMist Threat Intelligence, puffer[.]fi and @puffer_finance have been compromised.</description></item><item><title>D3X AI</title><link>https://0xtracer.xyz/incidents/2025-08-16-d3x-ai/</link><pubDate>Sat, 16 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-16-d3x-ai/</guid><description>D3X AI (@D3X_AI) was attacked on BSC, resulting in a loss of approximately $158.9K. The root cause was that the exchange() function of contract 0xb8ad relied on the spot price of the d3xat token from a UniswapV2 pair,&amp;hellip;</description></item><item><title>Level</title><link>https://0xtracer.xyz/incidents/2025-08-15-level/</link><pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-15-level/</guid><description>The official X account of the stablecoin protocol Level was reportedly compromised, and a fraudulent airdrop link was posted.</description></item><item><title>BtcTurk</title><link>https://0xtracer.xyz/incidents/2025-08-14-btcturk/</link><pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-14-btcturk/</guid><description>The Turkish cryptocurrency exchange BtcTurk has reportedly suffered another hack. BtcTurk acknowledged “unusual activity” in its hot wallets and has suspended deposits and withdrawals. However, the exchange did not di&amp;hellip;</description></item><item><title>ODIN.FUN</title><link>https://0xtracer.xyz/incidents/2025-08-12-odin-fun/</link><pubDate>Tue, 12 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-12-odin-fun/</guid><description>The Bitcoin-based memecoin launchpad ODIN.FUN suffered an exploit, losing approximately 58.2 BTC (around $7 million). The attacker allegedly manipulated the prices of several tokens and then withdrew bitcoin based on&amp;hellip;</description></item><item><title>Credix</title><link>https://0xtracer.xyz/incidents/2025-08-04-credix/</link><pubDate>Mon, 04 Aug 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-08-04-credix/</guid><description>The decentralized lending protocol Credix suffered an exploit, losing approximately $4.5 million. The attacker gained control of an admin wallet, minted tokens, and drained liquidity pools. After the incident, Credix&amp;hellip;</description></item><item><title>SuperRare</title><link>https://0xtracer.xyz/incidents/2025-07-28-superrare/</link><pubDate>Mon, 28 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-28-superrare/</guid><description>According to monitoring by SlowMist&amp;rsquo;s MistEye security system, the NFT platform SuperRare was exploited. The root cause of the vulnerability was an incorrect permission check in the updateMerkleRoot function, which al&amp;hellip;</description></item><item><title>WOO X</title><link>https://0xtracer.xyz/incidents/2025-07-24-woo-x/</link><pubDate>Thu, 24 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-24-woo-x/</guid><description>Crypto trading platform WOO X suffered an attack resulting in a loss of approximately $14 million. According to the official disclosure, the incident stemmed from a targeted phishing attack that compromised a team mem&amp;hellip;</description></item><item><title>Swarms</title><link>https://0xtracer.xyz/incidents/2025-07-21-swarms/</link><pubDate>Mon, 21 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-21-swarms/</guid><description>The AI agent protocol Swarms disclosed on the X platform that its community Discord account had been compromised. Earlier today, a team member’s Discord account was breached after receiving a malicious direct message&amp;hellip;</description></item><item><title>CoinDCX</title><link>https://0xtracer.xyz/incidents/2025-07-19-coindcx/</link><pubDate>Sat, 19 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-19-coindcx/</guid><description>On July 19, on-chain investigator ZachXBT posted on his personal channel: “Looks like the India centralized exchange &amp;lsquo;CoinDCX&amp;rsquo; was likely drained for ~$44.2M almost 17 hours ago and has yet to disclose the incident to&amp;hellip;</description></item><item><title>VDS</title><link>https://0xtracer.xyz/incidents/2025-07-17-vds/</link><pubDate>Thu, 17 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-17-vds/</guid><description>According to monitoring by SlowMist&amp;rsquo;s MistEye security system, VDS on the BSC appears to have been attacked, with an estimated loss of around $13,000.</description></item><item><title>BigONE</title><link>https://0xtracer.xyz/incidents/2025-07-16-bigone/</link><pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-16-bigone/</guid><description>According to monitoring by the SlowMist security team, cryptocurrency exchange BigONE has suffered a supply chain attack, with losses exceeding $27 million. The attacker breached the production network and altered the&amp;hellip;</description></item><item><title>Arcadia Finance</title><link>https://0xtracer.xyz/incidents/2025-07-15-arcadia-finance/</link><pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-15-arcadia-finance/</guid><description>According to the incident analysis report released by Arcadia Finance, at 04:05 AM UTC on July 15, 2025, an active exploit targeting a series of peripheral contracts occurred. The attacker abused the delegated powers&amp;hellip;</description></item><item><title>Pundi AI</title><link>https://0xtracer.xyz/incidents/2025-07-12-pundi-ai/</link><pubDate>Sat, 12 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-12-pundi-ai/</guid><description>Pundi AI recently experienced a security breach resulting in the unauthorized minting of 1 million tokens. The incident was caused by a vulnerability in the token swap contract, which was exploited via a front-running&amp;hellip;</description></item><item><title>Plasma</title><link>https://0xtracer.xyz/incidents/2025-07-11-plasma/</link><pubDate>Fri, 11 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-11-plasma/</guid><description>The official X account of @PlasmaFDN has been compromised. The attacker is posting phishing links using the X Bot UA spoofing trick—the URLs appear legitimate at first glance but redirect to a phishing site: https://v&amp;hellip;</description></item><item><title>Kinto</title><link>https://0xtracer.xyz/incidents/2025-07-10-kinto/</link><pubDate>Thu, 10 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-10-kinto/</guid><description>Ramon Recuero, co-founder of Kinto, a modular exchange platform in the Arbitrum ecosystem, tweeted about the recent attack, stating that the hacker exploited a vulnerability on Arbitrum that allowed unlimited minting&amp;hellip;</description></item><item><title>GMX</title><link>https://0xtracer.xyz/incidents/2025-07-09-gmx/</link><pubDate>Wed, 09 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-09-gmx/</guid><description>On July 9, according to monitoring by MistTrack’s MistEye security system, the well-known decentralized trading platform GMX (@GMX_IO) suffered an attack, resulting in asset losses exceeding $42 million. Analysis indi&amp;hellip;</description></item><item><title>Texture</title><link>https://0xtracer.xyz/incidents/2025-07-09-texture/</link><pubDate>Wed, 09 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-09-texture/</guid><description>An attacker exploited a vulnerability in the Solana-based lending protocol Texture, stealing approximately $2.2 million in user funds from one of the project’s vaults. Shortly after the incident, Texture offered the a&amp;hellip;</description></item><item><title>ZKSwap</title><link>https://0xtracer.xyz/incidents/2025-07-09-zkswap/</link><pubDate>Wed, 09 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-09-zkswap/</guid><description>ZKSwap’s Ethereum Layer 1 bridge suffered an exploit in which the attacker leveraged its emergency withdrawal mechanism, resulting in a loss of approximately $5 million. Analysis revealed that the component responsibl&amp;hellip;</description></item><item><title>Synthetix</title><link>https://0xtracer.xyz/incidents/2025-07-06-synthetix/</link><pubDate>Sun, 06 Jul 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-07-06-synthetix/</guid><description>The @synthetix_io main X(Twitter) account has been hacked. Please DO NOT interact with links from this account while we work to regain control.</description></item><item><title>PANews</title><link>https://0xtracer.xyz/incidents/2025-06-27-panews/</link><pubDate>Fri, 27 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-27-panews/</guid><description>The @PANewsCN X account has been compromised. Do not click on any recent links or interact with its posts. Please wait for an official update.</description></item><item><title>Resupply</title><link>https://0xtracer.xyz/incidents/2025-06-26-resupply/</link><pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-26-resupply/</guid><description>According to monitoring by the MistEye system, decentralized stablecoin protocol Resupply appears to have suffered an exploit, with estimated losses of around $9.5 million. The attacker manipulated the cvcrvUSD exchan&amp;hellip;</description></item><item><title>MEV Bot</title><link>https://0xtracer.xyz/incidents/2025-06-25-mev-bot/</link><pubDate>Wed, 25 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-25-mev-bot/</guid><description>A suspicious attack involving MEV bot 0xb5cb occurred on BSC, resulting in losses of approximately $2 million.</description></item><item><title>Silo Labs</title><link>https://0xtracer.xyz/incidents/2025-06-25-silo-labs/</link><pubDate>Wed, 25 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-25-silo-labs/</guid><description>According to Silo Labs&amp;rsquo; postmortem report, an unreleased leverage feature smart contract deployed on Ethereum mainnet and Sonic was exploited during its testing phase. The affected contract was separate from Silo’s co&amp;hellip;</description></item><item><title>CoinTelegraph</title><link>https://0xtracer.xyz/incidents/2025-06-23-cointelegraph/</link><pubDate>Mon, 23 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-23-cointelegraph/</guid><description>According to monitoring by Scam Sniffer, the front end of CoinTelegraph has been hacked—exercise caution. Reportedly, clicking the CoinTelegraph website triggers a pop-up containing “airdrop” information that cannot b&amp;hellip;</description></item><item><title>CoinMarketCap</title><link>https://0xtracer.xyz/incidents/2025-06-21-coinmarketcap/</link><pubDate>Sat, 21 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-21-coinmarketcap/</guid><description>According to monitoring by Scam Sniffer, the front end of CoinMarketCap has been compromised. Users are advised to remain vigilant. Following an investigation, CoinMarketCap confirmed that a total of 76 accounts were&amp;hellip;</description></item><item><title>Hacken</title><link>https://0xtracer.xyz/incidents/2025-06-21-hacken/</link><pubDate>Sat, 21 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-21-hacken/</guid><description>The private key of a wallet with minting privileges for Web3 security firm Hacken’s native token, HAI, was leaked. According to Hacken, the incident was caused by “human error during architectural changes.” After gain&amp;hellip;</description></item><item><title>Abstract Chain</title><link>https://0xtracer.xyz/incidents/2025-06-20-abstract-chain/</link><pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-20-abstract-chain/</guid><description>According to reports from social media users, the official X account of Abstract Chain appears to have been compromised. The attacker is impersonating the project to promote a fake “official token” scam.</description></item><item><title>a16z</title><link>https://0xtracer.xyz/incidents/2025-06-19-a16z/</link><pubDate>Thu, 19 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-19-a16z/</guid><description>a16z stated on social media:“Earlier today, our X account was briefly compromised. During that time, the account promoted a token and other fake content — none of which originated from a16z. Apologies for any confusio&amp;hellip;</description></item><item><title>Mehdi Farooq</title><link>https://0xtracer.xyz/incidents/2025-06-19-mehdi-farooq/</link><pubDate>Thu, 19 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-19-mehdi-farooq/</guid><description>Mehdi Farooq, a partner at crypto VC firm Hypersphere, disclosed on X that he fell victim to a fake Zoom meeting phishing attack, resulting in the draining of six crypto wallets and the loss of his savings accumulated&amp;hellip;</description></item><item><title>Nobitex</title><link>https://0xtracer.xyz/incidents/2025-06-18-nobitex/</link><pubDate>Wed, 18 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-18-nobitex/</guid><description>The Iran-based Nobitex cryptocurrency exchange suffered a $90 million hack, and the attacker has also promised to imminently release data and source code from the platform. The hacking group appears to have burned the&amp;hellip;</description></item><item><title>Meta Pool</title><link>https://0xtracer.xyz/incidents/2025-06-17-meta-pool/</link><pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-17-meta-pool/</guid><description>An attacker exploited a vulnerability in the staking contract for Meta Pool, which is a liquid staking project. This allowed them to mint 9,700 mpETH, the project&amp;rsquo;s liquid staking token, which is notionally worth $27&amp;hellip;</description></item><item><title>Echo Protocol</title><link>https://0xtracer.xyz/incidents/2025-06-14-echo-protocol/</link><pubDate>Sat, 14 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-14-echo-protocol/</guid><description>Echo Protocol, a project built on the Bitcoin ecosystem, has experienced a compromise of its official X (formerly Twitter) account. Users are advised to refrain from interacting with any recent posts or links and to a&amp;hellip;</description></item><item><title>ether.fi</title><link>https://0xtracer.xyz/incidents/2025-06-07-ether-fi/</link><pubDate>Sat, 07 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-07-ether-fi/</guid><description>The official ether.fi Discord was hacked, and fraudulent messages containing scam links were posted. ether.fi urges users not to interact with any links within the Discord.</description></item><item><title>ALEX Protocol</title><link>https://0xtracer.xyz/incidents/2025-06-06-alex-protocol/</link><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-06-alex-protocol/</guid><description>On June 6, 2025, ALEX Protocol was attacked due to a vulnerability in its on-chain self-listing verification logic, which is constrained by limitations on Stacks. As a result, multiple asset pools were drained, with t&amp;hellip;</description></item><item><title>Force Bridge</title><link>https://0xtracer.xyz/incidents/2025-06-01-force-bridge/</link><pubDate>Sun, 01 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-01-force-bridge/</guid><description>The Force Bridge, a cross-chain bridge on the Nervos Network, is suspected to have been compromised, with approximately $3.7 million in assets stolen. The Nervos team has urgently suspended all contracts and is active&amp;hellip;</description></item><item><title>MegaETH</title><link>https://0xtracer.xyz/incidents/2025-06-01-megaeth/</link><pubDate>Sun, 01 Jun 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-06-01-megaeth/</guid><description>MegaETH stated that its X (formerly Twitter) account has been compromised, warning users not to click on any links or view recent posts.</description></item><item><title>Malda</title><link>https://0xtracer.xyz/incidents/2025-05-30-malda/</link><pubDate>Fri, 30 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-30-malda/</guid><description>The vulnerability originated in the Migrator.sol contract. The contract allowed the Mendi Comptroller address to be passed dynamically, rather than being hardcoded. This enabled the attacker to supply their own malici&amp;hellip;</description></item><item><title>Cork Protocol</title><link>https://0xtracer.xyz/incidents/2025-05-28-cork-protocol/</link><pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-28-cork-protocol/</guid><description>On May 28, SlowMist detected potential suspicious activity related to Cork Protocol. According to the SlowMist security team’s analysis, the root cause of the attack was the lack of strict validation on user-supplied&amp;hellip;</description></item><item><title>Usual Protocol</title><link>https://0xtracer.xyz/incidents/2025-05-27-usual-protocol/</link><pubDate>Tue, 27 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-27-usual-protocol/</guid><description>According to monitoring by SlowMist, Usual Protocol suffered a sophisticated arbitrage attack. The attacker exploited a price discrepancy between the protocol’s internal mechanisms and external markets. The core issue&amp;hellip;</description></item><item><title>Cetus</title><link>https://0xtracer.xyz/incidents/2025-05-22-cetus/</link><pubDate>Thu, 22 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-22-cetus/</guid><description>On May 22, according to community reports, the SUI ecosystem’s liquidity provider Cetus Protocol was reportedly attacked. Liquidity pool depth dropped sharply, and multiple token pairs on Cetus experienced significant&amp;hellip;</description></item><item><title>Nexo</title><link>https://0xtracer.xyz/incidents/2025-05-22-nexo/</link><pubDate>Thu, 22 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-22-nexo/</guid><description>According to monitoring by the SlowMist security team, the digital asset wealth management platform Nexo suffered a sandwich attack due to a lack of access control in one of its contracts, resulting in a loss of appro&amp;hellip;</description></item><item><title>Nitron</title><link>https://0xtracer.xyz/incidents/2025-05-16-nitron/</link><pubDate>Fri, 16 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-16-nitron/</guid><description>On May 16th, Demex&amp;rsquo;s lending market Nitron was exploited, resulting in a loss of $950,559 in user funds. According to Demex&amp;rsquo;s post-incident analysis, the root cause of the exploit was a donation-based oracle manipulat&amp;hellip;</description></item><item><title>Zunami Protocol</title><link>https://0xtracer.xyz/incidents/2025-05-15-zunami-protocol/</link><pubDate>Thu, 15 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-15-zunami-protocol/</guid><description>Zunami Protocol has reported a hack in which the collateral for zunUSD and zunETH was stolen, resulting in a loss of approximately $500,000. The attacker has transferred the stolen funds to Tornado Cash.</description></item><item><title>ZKsync</title><link>https://0xtracer.xyz/incidents/2025-05-13-zksync/</link><pubDate>Tue, 13 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-13-zksync/</guid><description>ZKsync Developers posted on X that the official X accounts of both ZKsync and Matter Labs have been compromised. Please do not interact with these accounts or click on any related links.</description></item><item><title>Sheffield United</title><link>https://0xtracer.xyz/incidents/2025-05-12-sheffield-united/</link><pubDate>Mon, 12 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-12-sheffield-united/</guid><description>The English football club @SheffieldUnited has confirmed that its official X account was hacked. The attacker posted a Solana token address.</description></item><item><title>MobiusDAO</title><link>https://0xtracer.xyz/incidents/2025-05-11-mobiusdao/</link><pubDate>Sun, 11 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-11-mobiusdao/</guid><description>Mobius Token on BSC is suspected to have been exploited, with estimated losses of $2.15 million.</description></item><item><title>Cointelegraph</title><link>https://0xtracer.xyz/incidents/2025-05-10-cointelegraph/</link><pubDate>Sat, 10 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-10-cointelegraph/</guid><description>Cointelegraph’s official X account was reportedly compromised and used to send phishing links to contributors on the platform. Crypto KOL @thedefiedge reported receiving a DM from the account, asking him to review an&amp;hellip;</description></item><item><title>BitoPro</title><link>https://0xtracer.xyz/incidents/2025-05-08-bitopro/</link><pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-08-bitopro/</guid><description>According to on-chain investigator ZachXBT, crypto exchange BitoPro was reportedly hacked on May 8, 2025, resulting in losses of approximately $11.5 million. The attacker drained assets from BitoPro’s hot wallets on T&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2025-05-05-curve-finance/</link><pubDate>Mon, 05 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-05-curve-finance/</guid><description>Curve Finance’s official website and X account were compromised in quick succession. On May 5, attackers first took control of the project’s X account and used it to post a phishing message promoting a fake airdrop. T&amp;hellip;</description></item><item><title>TRON DAO</title><link>https://0xtracer.xyz/incidents/2025-05-02-tron-dao/</link><pubDate>Fri, 02 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-02-tron-dao/</guid><description>TRON DAO stated on X that its account was compromised on May 2, 2025, at 9:25 AM PST. During the breach, an unauthorized party published a post containing contract address, sent private messages, and followed several&amp;hellip;</description></item><item><title>Hyperliquid</title><link>https://0xtracer.xyz/incidents/2025-05-01-hyperliquid/</link><pubDate>Thu, 01 May 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-05-01-hyperliquid/</guid><description>Hyperliquid&amp;rsquo;s X account is suspected to have been compromised. Please do not trust any content it posts or click on any links, to avoid potential losses.</description></item><item><title>Aventa</title><link>https://0xtracer.xyz/incidents/2025-04-27-aventa/</link><pubDate>Sun, 27 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-27-aventa/</guid><description>According to the SlowMist MistEye security monitoring system, Aventa, which specializes in creating intuitive Web3 utilities for the crypto community, appears to have been attacked, resulting in a loss of approximatel&amp;hellip;</description></item><item><title>LIFE Protocol</title><link>https://0xtracer.xyz/incidents/2025-04-27-life-protocol/</link><pubDate>Sun, 27 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-27-life-protocol/</guid><description>According to the SlowMist MistEye security monitoring system, LIFE Protocol has been attacked, resulting in a loss of over $51,000.</description></item><item><title>QuantMaster</title><link>https://0xtracer.xyz/incidents/2025-04-27-quantmaster/</link><pubDate>Sun, 27 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-27-quantmaster/</guid><description>A member of the crypto community previously revealed that &amp;ldquo;a smart contract of a certain Web3 project was suspected to have been implanted with malicious code by an employee,&amp;rdquo; leading to losses of several hundred thou&amp;hellip;</description></item><item><title>Grafana</title><link>https://0xtracer.xyz/incidents/2025-04-26-grafana/</link><pubDate>Sat, 26 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-26-grafana/</guid><description>The open-source data visualization tool Grafana has responded to a recent attack, stating that the attacker forked a Grafana repository, executed a curl command to inject malicious code, and exported environment varia&amp;hellip;</description></item><item><title>Impermax</title><link>https://0xtracer.xyz/incidents/2025-04-26-impermax/</link><pubDate>Sat, 26 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-26-impermax/</guid><description>Impermax was attacked on the Base network. In a tweet, Impermax stated that someone launched a flash loan attack and drained its V3 liquidity pools. The team is currently investigating and advises users not to interac&amp;hellip;</description></item><item><title>Loopscale</title><link>https://0xtracer.xyz/incidents/2025-04-26-loopscale/</link><pubDate>Sat, 26 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-26-loopscale/</guid><description>A modular DeFi lending market built on Solana, Loopscale, has suffered an attack. The root cause of the exploit has been identified as an isolated issue with Loopscale’s pricing of RateX-based collateral. The incident&amp;hellip;</description></item><item><title>Term Labs</title><link>https://0xtracer.xyz/incidents/2025-04-26-term-labs/</link><pubDate>Sat, 26 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-26-term-labs/</guid><description>On April 26, 2025, lending protocol Term Labs introduced an internal inconsistency in decimal precision during an update to the tETH oracle, resulting in incorrect pricing of the tETH asset within the protocol. This m&amp;hellip;</description></item><item><title>ACB</title><link>https://0xtracer.xyz/incidents/2025-04-24-acb/</link><pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-24-acb/</guid><description>According to the SlowMist MistEye security monitoring system, ACB appears to have been attacked on BSC, resulting in a loss of approximately $22,000.</description></item><item><title>NUMA.</title><link>https://0xtracer.xyz/incidents/2025-04-18-numa/</link><pubDate>Fri, 18 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-18-numa/</guid><description>NUMA was attacked on the Arbitrum chain, resulting in a loss of approximately $530,000. The attacker swapped all assets to ETH, bridged them to Ethereum mainnet, and deposited the funds into Tornado Cash.</description></item><item><title>DIN</title><link>https://0xtracer.xyz/incidents/2025-04-16-din/</link><pubDate>Wed, 16 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-16-din/</guid><description>The official X account of AI blockchain project DIN (@din_lol_) has been compromised by a hacker. Current posts from the account are not from the official team, and users are advised not to click any links or engage w&amp;hellip;</description></item><item><title>R0AR</title><link>https://0xtracer.xyz/incidents/2025-04-16-r0ar/</link><pubDate>Wed, 16 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-16-r0ar/</guid><description>R0AR has been exploited, with total losses amounting to approximately $780K. According to analysis by the SlowMist security team, the root cause of the exploit was the presence of a backdoor in the contract. During de&amp;hellip;</description></item><item><title>KiloEx</title><link>https://0xtracer.xyz/incidents/2025-04-15-kiloex/</link><pubDate>Tue, 15 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-15-kiloex/</guid><description>The decentralized perpetual futures exchange KiloEx was attacked, involving assets across multiple chains including BNB and Base. According to an analysis by the SlowMist Security Team, the root cause of the incident&amp;hellip;</description></item><item><title>Aergo</title><link>https://0xtracer.xyz/incidents/2025-04-14-aergo/</link><pubDate>Mon, 14 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-14-aergo/</guid><description>The official website of hybrid blockchain project Aergo is temporarily unavailable due to a DDoS attack. The technical team is actively working on the issue and aims to restore access as soon as possible. Aergo remind&amp;hellip;</description></item><item><title>ZKsync</title><link>https://0xtracer.xyz/incidents/2025-04-13-zksync/</link><pubDate>Sun, 13 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-13-zksync/</guid><description>The ZKsync security team discovered that an admin account had been compromised, giving the hacker control of approximately $5 million worth of ZK tokens — the remaining unclaimed tokens from the ZKsync airdrop. The ZK&amp;hellip;</description></item><item><title>Jake Gallen</title><link>https://0xtracer.xyz/incidents/2025-04-11-jake-gallen/</link><pubDate>Fri, 11 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-11-jake-gallen/</guid><description>Jake Gallen, CEO of digital asset trading platform Emblem Vault, was hacked after a suspicious Zoom video call, resulting in the loss of over $100,000 worth of Bitcoin and Ethereum. The attacker posed as a YouTube con&amp;hellip;</description></item><item><title>MEV Bot</title><link>https://0xtracer.xyz/incidents/2025-04-08-mev-bot/</link><pubDate>Tue, 08 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-08-mev-bot/</guid><description>According to the SlowMist MistEye security monitoring system, a MEV bot (address: 0x49e27d11379f5208cbb2a4963b903fd65c95de09) has lost approximately 116.7 ETH due to a lack of access control.</description></item><item><title>Next Earth</title><link>https://0xtracer.xyz/incidents/2025-04-08-next-earth/</link><pubDate>Tue, 08 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-08-next-earth/</guid><description>According to the SlowMist MistEye security monitoring system, the NFT project Next Earth has suffered a reentrancy attack on Polygon.</description></item><item><title>UPCX</title><link>https://0xtracer.xyz/incidents/2025-04-01-upcx/</link><pubDate>Tue, 01 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-01-upcx/</guid><description>According to an announcement from blockchain payment platform UPCX, unauthorized activity was detected in its management accounts. As a precaution, the platform has urgently suspended UPC deposits and withdrawals. The&amp;hellip;</description></item><item><title>Zapper</title><link>https://0xtracer.xyz/incidents/2025-04-01-zapper/</link><pubDate>Tue, 01 Apr 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-04-01-zapper/</guid><description>According to an official announcement from DeFi asset management protocol Zapper, its .fi domain was hijacked via social engineering. The current zapper(.fi) page is malicious and should be avoided — users are strongl&amp;hellip;</description></item><item><title>SIR.trading</title><link>https://0xtracer.xyz/incidents/2025-03-30-sir-trading/</link><pubDate>Sun, 30 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-30-sir-trading/</guid><description>According to the SlowMist MistEye security monitoring system, the leveraged trading project SIR.trading (@leveragesir) on the Ethereum chain has been attacked, resulting in a loss of over $300,000 in assets. The root&amp;hellip;</description></item><item><title>Min Token (MIN)</title><link>https://0xtracer.xyz/incidents/2025-03-28-min-token-min/</link><pubDate>Fri, 28 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-28-min-token-min/</guid><description>According to monitoring by SlowMist&amp;rsquo;s security team, Min Token (MIN) is suspected to have been attacked on BSC, resulting in a loss of approximately $21,400.</description></item><item><title>Abracadabra</title><link>https://0xtracer.xyz/incidents/2025-03-25-abracadabra/</link><pubDate>Tue, 25 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-25-abracadabra/</guid><description>An attacker using a flash loan attack stole $13 million in the Magic Internet Money token from the Abracadabra Money project. The attack was enabled by a bug in the platform&amp;rsquo;s smart contracts, and the hacker ultimatel&amp;hellip;</description></item><item><title>Watcher.Guru</title><link>https://0xtracer.xyz/incidents/2025-03-21-watcher-guru/</link><pubDate>Fri, 21 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-21-watcher-guru/</guid><description>The media platform Watcher.Guru, which focuses on cryptocurrency and financial market news, posted on X that its account was hacked today. Watcher.Guru is still investigating the specific method of the breach and has&amp;hellip;</description></item><item><title>Zoth</title><link>https://0xtracer.xyz/incidents/2025-03-21-zoth/</link><pubDate>Fri, 21 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-21-zoth/</guid><description>RWA restaking platform Zoth suffered a $8.29 million hack after an attacker gained access to admin privileges that allowed them to modify the platform&amp;rsquo;s smart contracts. The hacker &amp;ldquo;upgraded&amp;rdquo; the contract to a malicio&amp;hellip;</description></item><item><title>Four.Meme</title><link>https://0xtracer.xyz/incidents/2025-03-18-four-meme/</link><pubDate>Tue, 18 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-18-four-meme/</guid><description>BNB-based memecoin launchpad Four.Meme was attacked. According to the SlowMist security team’s analysis, the attacker purchased a small amount of tokens before launch through the 0x7f79f6df function of Four.Meme, and&amp;hellip;</description></item><item><title>Voltage Finance</title><link>https://0xtracer.xyz/incidents/2025-03-18-voltage-finance/</link><pubDate>Tue, 18 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-18-voltage-finance/</guid><description>On March 18, the Simple Staking pools of Voltage Finance, a DeFi platform built on the Fuse Network, suffered an unauthorized withdrawal, resulting in a total loss of $171,027.20 in USDCE and $151,085.87 in WETH.</description></item><item><title>Kaito AI</title><link>https://0xtracer.xyz/incidents/2025-03-16-kaito-ai/</link><pubDate>Sun, 16 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-16-kaito-ai/</guid><description>Kaito official representative Sandra (@sandraaleow) posted on X that Kaito AI founder Yu Hu and Kaito&amp;rsquo;s X account have been compromised. However, no KAITO wallets have been affected.</description></item><item><title>Berally</title><link>https://0xtracer.xyz/incidents/2025-03-14-berally/</link><pubDate>Fri, 14 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-14-berally/</guid><description>Berally, a platform for social trading using AI agents within the Berachain ecosystem, is suspected to have been hacked. The official statement reads: “Partial information of the deployer&amp;rsquo;s key was leaked, leading to&amp;hellip;</description></item><item><title>1inch</title><link>https://0xtracer.xyz/incidents/2025-03-05-1inch/</link><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-05-1inch/</guid><description>An attacker exploited a smart contract belonging to the 1inch DEX aggregator, stealing $5 million in the USDC stablecoin and wETH. According to the platform, the vulnerability existed in &amp;ldquo;smart contracts using the obs&amp;hellip;</description></item><item><title>Meow</title><link>https://0xtracer.xyz/incidents/2025-03-05-meow/</link><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-05-meow/</guid><description>Jupiter co-founder Meow&amp;rsquo;s X account was reportedly hacked and posted token CA-related content, which has now been deleted. Users are advised to stay vigilant.</description></item><item><title>Pond.fun</title><link>https://0xtracer.xyz/incidents/2025-03-05-pond-fun/</link><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-05-pond-fun/</guid><description>According to Pond.fun&amp;rsquo;s official disclosure, the Linea-based meme coin launchpad Pond.fun was hacked this morning. Initial on-chain and off-chain evidence suggests that Pond.fun’s lead software engineer was behind the&amp;hellip;</description></item><item><title>Zoth</title><link>https://0xtracer.xyz/incidents/2025-03-01-zoth/</link><pubDate>Sat, 01 Mar 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-03-01-zoth/</guid><description>Zoth, a restaking platform for &amp;ldquo;real world assets&amp;rdquo; (or RWAs), was hacked for around $ 285,000 when an exploiter discovered a bug in the platform&amp;rsquo;s collateral calculations.</description></item><item><title>Wemix</title><link>https://0xtracer.xyz/incidents/2025-02-28-wemix/</link><pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-28-wemix/</guid><description>According to Yonhap News Agency, Kim Seok-hwan, a representative of Wemix Foundation, a blockchain subsidiary of Wemade, admitted at an emergency meeting that they lost approximately 8.65 million WEMIX tokens (worth a&amp;hellip;</description></item><item><title>Pumpfun</title><link>https://0xtracer.xyz/incidents/2025-02-27-pumpfun/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-27-pumpfun/</guid><description>Pumpfun&amp;rsquo;s X account has been hacked, and the attacker is using it to promote fake tokens.</description></item><item><title>Suji Yan</title><link>https://0xtracer.xyz/incidents/2025-02-26-suji-yan/</link><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-26-suji-yan/</guid><description>Suji Yan, the founder of the Mask Network, suffered the loss of more than $4 million in various cryptocurrency assets to an apparent wallet hack.</description></item><item><title>Infini</title><link>https://0xtracer.xyz/incidents/2025-02-24-infini/</link><pubDate>Mon, 24 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-24-infini/</guid><description>The crypto-focused stablecoin neobank Infini was attacked, with the attacker gaining access to a wallet with admin rights and stealing nearly $50 million from the company.</description></item><item><title>Bybit</title><link>https://0xtracer.xyz/incidents/2025-02-21-bybit/</link><pubDate>Fri, 21 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-21-bybit/</guid><description>Safe multisig UI manipulated via malware, Lazarus Group attributed</description></item><item><title>Cardex</title><link>https://0xtracer.xyz/incidents/2025-02-18-cardex/</link><pubDate>Tue, 18 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-18-cardex/</guid><description>On February 18, 2025, Abstract discovered a security incident involving the Cardex app within The Portal, affecting approximately 9,000 wallets with a total loss of around $400,000 in ETH. A leaked key in Cardex&amp;rsquo;s fro&amp;hellip;</description></item><item><title>Shaw</title><link>https://0xtracer.xyz/incidents/2025-02-16-shaw/</link><pubDate>Sun, 16 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-16-shaw/</guid><description>According to community reports, the X account of ai16z founder Shaw has allegedly been compromised by hackers. Users are advised to exercise caution and avoid interacting with suspicious links.</description></item><item><title>LIBRA</title><link>https://0xtracer.xyz/incidents/2025-02-15-libra/</link><pubDate>Sat, 15 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-15-libra/</guid><description>Argentine President Javier Milei promoted a cryptocurrency called $LIBRA on social media. Following his endorsement, the token&amp;rsquo;s price surged rapidly but later suffered a severe crash.</description></item><item><title>zkLend</title><link>https://0xtracer.xyz/incidents/2025-02-12-zklend/</link><pubDate>Wed, 12 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-12-zklend/</guid><description>The leading lending platform on the Starknet chain, zkLend, has suffered an attack. The core reason for this breach lies in the fact that the value of the accumulator in an empty market can be manipulated and amplifie&amp;hellip;</description></item><item><title>Four.Meme</title><link>https://0xtracer.xyz/incidents/2025-02-11-four-meme/</link><pubDate>Tue, 11 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-11-four-meme/</guid><description>The memecoin platform Four.Meme was attacked. According to an analysis by the SlowMist security team, the attacker was able to execute a frontrunning attack by pre-creating a liquidity pool on PancakeSwap v3 with an e&amp;hellip;</description></item><item><title>Cashverse</title><link>https://0xtracer.xyz/incidents/2025-02-08-cashverse/</link><pubDate>Sat, 08 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-08-cashverse/</guid><description>According to monitoring by the SlowMist security team, Cashverse appears to have been attacked on BSC.</description></item><item><title>BankX</title><link>https://0xtracer.xyz/incidents/2025-02-07-bankx/</link><pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-07-bankx/</guid><description>According to monitoring by the SlowMist security team, BankX appears to have been attacked on BSC, ETH, and Optimism.</description></item><item><title>Jupiter</title><link>https://0xtracer.xyz/incidents/2025-02-06-jupiter/</link><pubDate>Thu, 06 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-06-jupiter/</guid><description>JupiterDAO confirmed on X that the official Jupiter X account (@JupiterExchange) has been compromised. Users are advised not to click on any links or copy-paste any contract addresses.</description></item><item><title>Mohammed Dewji MO</title><link>https://0xtracer.xyz/incidents/2025-02-06-mohammed-dewji-mo/</link><pubDate>Thu, 06 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-06-mohammed-dewji-mo/</guid><description>The X account of Tanzanian businessman and entrepreneur Mohammed Dewji MO (@moodewji) was compromised. The hacker falsely announced the launch of a TANZANIA token and sold it to investors.</description></item><item><title>Dr Mahathir Mohamad</title><link>https://0xtracer.xyz/incidents/2025-02-05-dr-mahathir-mohamad/</link><pubDate>Wed, 05 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-05-dr-mahathir-mohamad/</guid><description>According to a post by SlowMist founder Cos on X, the X account of former Malaysian Prime Minister Dr Mahathir Mohamad (@chedetofficial) was compromised and used to promote a fake token. The creator of the associated&amp;hellip;</description></item><item><title>Ionic</title><link>https://0xtracer.xyz/incidents/2025-02-04-ionic/</link><pubDate>Tue, 04 Feb 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-02-04-ionic/</guid><description>On February 4, 2025, the Ionic protocol suffered a social engineering attack, allowing the attacker to use a forged Lombard Bitcoin Token (LBTC) as collateral. This asset was deployed on the Mode network. The attacker&amp;hellip;</description></item><item><title>The Tor Project</title><link>https://0xtracer.xyz/incidents/2025-01-31-the-tor-project/</link><pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-31-the-tor-project/</guid><description>The Tor Project X account has been compromised. The hacker is using the account to promote a fake token. Users should stay vigilant.</description></item><item><title>TIME</title><link>https://0xtracer.xyz/incidents/2025-01-31-time/</link><pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-31-time/</guid><description>The official TIME Magazine X account was allegedly compromised and posted about the TIME token.</description></item><item><title>Dean Norris</title><link>https://0xtracer.xyz/incidents/2025-01-26-dean-norris/</link><pubDate>Sun, 26 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-26-dean-norris/</guid><description>According to DL News, Dean Norris, the actor who played Hank Schrader in Breaking Bad, became the target of a hack on the X platform for the second time in six months. The attack started with a tweet from Norris&amp;rsquo; acco&amp;hellip;</description></item><item><title>AdsPower</title><link>https://0xtracer.xyz/incidents/2025-01-24-adspower/</link><pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-24-adspower/</guid><description>The AdsPower security team discovered a breach in which hackers distributed malicious code, resulting in the compromise of some third-party browser extensions.</description></item><item><title>Jair Messias Bolsonaro</title><link>https://0xtracer.xyz/incidents/2025-01-24-jair-messias-bolsonaro/</link><pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-24-jair-messias-bolsonaro/</guid><description>The X account of former Brazilian President Jair Messias Bolsonaro was hacked and used to promote the token. The original post has since been deleted.</description></item><item><title>ODOS</title><link>https://0xtracer.xyz/incidents/2025-01-24-odos/</link><pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-24-odos/</guid><description>According to monitoring by the SlowMist security team, due to a lack of input validation in @odosprotocol, the vulnerability has been exploited across multiple chains, resulting in approximately $100,000 in losses. OD&amp;hellip;</description></item><item><title>Nasdaq</title><link>https://0xtracer.xyz/incidents/2025-01-23-nasdaq/</link><pubDate>Thu, 23 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-23-nasdaq/</guid><description>According to The Block, Nasdaq&amp;rsquo;s official X account was hacked, and the attackers used it to promote fraudulent meme coins.</description></item><item><title>Phemex</title><link>https://0xtracer.xyz/incidents/2025-01-23-phemex/</link><pubDate>Thu, 23 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-23-phemex/</guid><description>The Singapore-based Phemex cryptocurrency exchange&amp;rsquo;s hot wallets were hacked, resulting in a loss of approximately $70 million.</description></item><item><title>AST</title><link>https://0xtracer.xyz/incidents/2025-01-22-ast/</link><pubDate>Wed, 22 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-22-ast/</guid><description>According to monitoring by the SlowMist security team, AST was allegedly attacked on BSC.</description></item><item><title>Dan Finlay</title><link>https://0xtracer.xyz/incidents/2025-01-21-dan-finlay/</link><pubDate>Tue, 21 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-21-dan-finlay/</guid><description>MetaMask posted on X: “This morning, our co-founder Dan Finlay&amp;rsquo;s Farcaster account was compromised and used to promote a memecoin. We are in touch with the Farcaster team to help investigate the incident.&amp;quot;</description></item><item><title>Stability AI</title><link>https://0xtracer.xyz/incidents/2025-01-16-stability-ai/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-16-stability-ai/</guid><description>Stability AI&amp;rsquo;s official X account posted information related to the STAI token contract, which appears to have been compromised. Be cautious to avoid falling victim to a scam.</description></item><item><title>ZKsync Ignite</title><link>https://0xtracer.xyz/incidents/2025-01-16-zksync-ignite/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-16-zksync-ignite/</guid><description>The ZKsync team tweeted that the @ZKsyncIgnite account has been compromised. Do not interact with the account or click any links. Wait for the @zksync account to confirm when the account has been reclaimed.</description></item><item><title>CAT Protocol</title><link>https://0xtracer.xyz/incidents/2025-01-15-cat-protocol/</link><pubDate>Wed, 15 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-15-cat-protocol/</guid><description>The CAT Protocol within the Bitcoin ecosystem posted on Platform X, stating that they recently detected and mitigated an attempted attack on the CAT Protocol, confirming that no user funds were lost. On January 18, CA&amp;hellip;</description></item><item><title>DAWN</title><link>https://0xtracer.xyz/incidents/2025-01-15-dawn/</link><pubDate>Wed, 15 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-15-dawn/</guid><description>According to Scam Sniffer&amp;rsquo;s monitoring, the X account of the decentralized autonomous wireless network project DAWN was compromised and used to post phishing tweets.</description></item><item><title>The Idols</title><link>https://0xtracer.xyz/incidents/2025-01-14-the-idols/</link><pubDate>Tue, 14 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-14-the-idols/</guid><description>The attacker exploited a vulnerability in The Idols project&amp;rsquo;s smart contract to steal 97 stETH (approximately $324,000) from the project.</description></item><item><title>Moonray</title><link>https://0xtracer.xyz/incidents/2025-01-13-moonray/</link><pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-13-moonray/</guid><description>Moonray&amp;rsquo;s Discord was Compromised, and the attackers posted fraudulent airdrop messages. Users are advised to stay cautious and aware of potential risks.</description></item><item><title>Mosca</title><link>https://0xtracer.xyz/incidents/2025-01-13-mosca/</link><pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-13-mosca/</guid><description>Mosca appears to have suffered another attack on BSC, resulting in losses of approximately $37,600.</description></item><item><title>UniLend</title><link>https://0xtracer.xyz/incidents/2025-01-13-unilend/</link><pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-13-unilend/</guid><description>On January 13, 2025, the SlowMist MistEye security monitoring system detected an attack on UniLend, resulting in a loss of ~$197K.</description></item><item><title>BUIDL</title><link>https://0xtracer.xyz/incidents/2025-01-12-buidl/</link><pubDate>Sun, 12 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-12-buidl/</guid><description>BUIDL was suspected to have been attacked on BSC, resulting in an approximate loss of $8K.</description></item><item><title>Foresight Ventures</title><link>https://0xtracer.xyz/incidents/2025-01-12-foresight-ventures/</link><pubDate>Sun, 12 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-12-foresight-ventures/</guid><description>According to Foresight News, the Foresight Ventures X account was hacked and is currently in the process of being recovered. Please do not click or trust any links or token information posted by this account.</description></item><item><title>Litecoin</title><link>https://0xtracer.xyz/incidents/2025-01-12-litecoin/</link><pubDate>Sun, 12 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-12-litecoin/</guid><description>Litecoin posted on X, stating that their X account was briefly compromised and some unauthorized content was published. These posts were deleted within seconds. They are still investigating the incident but have immed&amp;hellip;</description></item><item><title>Ryan Zarick</title><link>https://0xtracer.xyz/incidents/2025-01-12-ryan-zarick/</link><pubDate>Sun, 12 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-12-ryan-zarick/</guid><description>The X account of Ryan Zarick, co-founder and CTO of LayerZero Labs, was briefly compromised and used to post a fraudulent airdrop claim along with a phishing link.</description></item><item><title>Aizel Network</title><link>https://0xtracer.xyz/incidents/2025-01-11-aizel-network/</link><pubDate>Sat, 11 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-11-aizel-network/</guid><description>The official X account of the blockchain AI project Aizel Network was hacked at noon on January 11 and is currently in the process of being recovered. The official reminder to users is to be cautious of the content po&amp;hellip;</description></item><item><title>SuperVerse</title><link>https://0xtracer.xyz/incidents/2025-01-11-superverse/</link><pubDate>Sat, 11 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-11-superverse/</guid><description>The SuperVerse X account was compromised and used to post a fraudulent airdrop claim containing a phishing link.</description></item><item><title>Alien Base</title><link>https://0xtracer.xyz/incidents/2025-01-10-alien-base/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-10-alien-base/</guid><description>Multiple attack transactions targeting the Alien Base BunniHub contract resulted in a loss of approximately $38,000.</description></item><item><title>FortuneWheel</title><link>https://0xtracer.xyz/incidents/2025-01-10-fortunewheel/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-10-fortunewheel/</guid><description>FortuneWheel was suspected to have been attacked on BSC, resulting in an approximate loss of $21.6K.</description></item><item><title>Holoworld AI</title><link>https://0xtracer.xyz/incidents/2025-01-10-holoworld-ai/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-10-holoworld-ai/</guid><description>tong, the founder of Holoworld AI, posted on X stating that the Holoworld AI X account has been hacked. Please do not click on any links.</description></item><item><title>HORS</title><link>https://0xtracer.xyz/incidents/2025-01-08-hors/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-08-hors/</guid><description>HORS was suspected to have been attacked on BSC, resulting in an approximate loss of $10.3K.</description></item><item><title>Moby</title><link>https://0xtracer.xyz/incidents/2025-01-08-moby/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-08-moby/</guid><description>According to Moby Post-Mortem Report, on January 8, an attacker took control of the Private Key used to authorize upgrades to Moby’s core contracts, compromising the protocol. This led to the exposure of 3.77 wBTC, 20&amp;hellip;</description></item><item><title>Orange Finance</title><link>https://0xtracer.xyz/incidents/2025-01-08-orange-finance/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-08-orange-finance/</guid><description>The Arbitrum-based liquidity management project Orange Finance suffered a $830,000 asset theft due to a misconfigured multi-sig. The attacker gained ownership of each vault, modified their implementations, and withdre&amp;hellip;</description></item><item><title>Virtuals Protocol</title><link>https://0xtracer.xyz/incidents/2025-01-08-virtuals-protocol/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-08-virtuals-protocol/</guid><description>Virtuals Protocol announced on X that their official Discord server has been compromised. They advised users not to click on any posts or private messages from administrators until further notice.</description></item><item><title>IPC</title><link>https://0xtracer.xyz/incidents/2025-01-07-ipc/</link><pubDate>Tue, 07 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-07-ipc/</guid><description>IPC was suspected to have been attacked on BSC, resulting in an approximate loss of $590K.</description></item><item><title>Mosca</title><link>https://0xtracer.xyz/incidents/2025-01-06-mosca/</link><pubDate>Mon, 06 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-06-mosca/</guid><description>Mosca was reportedly attacked on BSC, resulting in an approximate loss of $19,500.</description></item><item><title>Solv Protocol</title><link>https://0xtracer.xyz/incidents/2025-01-05-solv-protocol/</link><pubDate>Sun, 05 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-05-solv-protocol/</guid><description>The official X account of Solv Protocol has been compromised. Users are advised not to click on any suspicious links.</description></item><item><title>Babylon</title><link>https://0xtracer.xyz/incidents/2025-01-04-babylon/</link><pubDate>Sat, 04 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-04-babylon/</guid><description>The official X account of the Babylon was compromised, and the hacker used it to post tweets containing phishing links.</description></item><item><title>Sorra</title><link>https://0xtracer.xyz/incidents/2025-01-04-sorra/</link><pubDate>Sat, 04 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-04-sorra/</guid><description>Sorra was suspected to have been attacked on ETH, resulting in an approximate loss of $43K.</description></item><item><title>0xScope</title><link>https://0xtracer.xyz/incidents/2025-01-03-0xscope/</link><pubDate>Fri, 03 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-03-0xscope/</guid><description>lmk.fun (formerly Scopescan) issued an alert on the X platform, warning that the X account of the Web3 knowledge graph protocol 0xScope (@ScopeProtocol) has been hacked. Users are advised not to click on any links or&amp;hellip;</description></item><item><title>Centrifuge</title><link>https://0xtracer.xyz/incidents/2025-01-03-centrifuge/</link><pubDate>Fri, 03 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-03-centrifuge/</guid><description>The official X account of the RWA lending protocol Centrifuge was compromised, and fake information was posted.</description></item><item><title>LAURA</title><link>https://0xtracer.xyz/incidents/2025-01-01-laura/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-01-laura/</guid><description>LAURA was suspected to have been attacked on ETH, resulting in an approximate loss of $48.2K.</description></item><item><title>NoOnes</title><link>https://0xtracer.xyz/incidents/2025-01-01-noones/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2025-01-01-noones/</guid><description>The peer-to-peer cryptocurrency trading platform NoOnes suffered a major security breach earlier this month. CEO Ray Youssef explained that the breach occurred on January 1st due to an exploit involving their Solana b&amp;hellip;</description></item><item><title>Superchain Eco</title><link>https://0xtracer.xyz/incidents/2024-12-31-superchain-eco/</link><pubDate>Tue, 31 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-31-superchain-eco/</guid><description>According to monitoring by Scam Sniffer, the X account of Superchain Eco (@SuperchainEco) was compromised and used to post phishing links.</description></item><item><title>FEG</title><link>https://0xtracer.xyz/incidents/2024-12-29-feg/</link><pubDate>Sun, 29 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-29-feg/</guid><description>The FEG project suffered an attack resulting in a loss of approximately $1 million. Analysis suggests that the root cause of the incident appears to be a composability issue arising from the integration with the under&amp;hellip;</description></item><item><title>Standing on Bizness (BIZNESS)</title><link>https://0xtracer.xyz/incidents/2024-12-28-standing-on-bizness-bizness/</link><pubDate>Sat, 28 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-28-standing-on-bizness-bizness/</guid><description>Standing on Bizness (BIZNESS) appears to have been subjected to a reentrancy attack on Base, resulting in an estimated loss of $15,700.</description></item><item><title>Yat Siu</title><link>https://0xtracer.xyz/incidents/2024-12-26-yat-siu/</link><pubDate>Thu, 26 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-26-yat-siu/</guid><description>Animoca Brands tweeted that @ysiu social media account has been compromised. There is no official token or NFT launch from Animoca Brands. The token launch on Solana as claimed in a post was made by the hacker. Please&amp;hellip;</description></item><item><title>Moonhacker</title><link>https://0xtracer.xyz/incidents/2024-12-23-moonhacker/</link><pubDate>Mon, 23 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-23-moonhacker/</guid><description>The Moonhacker contract suffered a flash loan attack, resulting in a loss of approximately $320,000.</description></item><item><title>Vivek Ramaswamy</title><link>https://0xtracer.xyz/incidents/2024-12-20-vivek-ramaswamy/</link><pubDate>Fri, 20 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-20-vivek-ramaswamy/</guid><description>Regarding rumors about the collaboration between DOGE and USUAL, Azoria CEO James Fishback clarified that he had contacted DOGE&amp;rsquo;s head of department, Vivek Ramaswamy, whose account was compromised.</description></item><item><title>zkPass</title><link>https://0xtracer.xyz/incidents/2024-12-20-zkpass/</link><pubDate>Fri, 20 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-20-zkpass/</guid><description>According to Scam Sniffer&amp;rsquo;s monitoring, the privacy-preserving data verification protocol zkPass&amp;rsquo;s X account was compromised and used to post phishing tweets.</description></item><item><title>Slurpycoin</title><link>https://0xtracer.xyz/incidents/2024-12-19-slurpycoin/</link><pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-19-slurpycoin/</guid><description>Slurpycoin on BSC suffered a flash loan attack. The attacker exploited the buyback mechanism to manipulate the token price and profited ~$3K from sandwich arbitrage.</description></item><item><title>Anthropic</title><link>https://0xtracer.xyz/incidents/2024-12-18-anthropic/</link><pubDate>Wed, 18 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-18-anthropic/</guid><description>The official X account of AI startup Anthropic, backed by Amazon, appears to have been compromised, posting an unknown token contract address related to AI Agents.</description></item><item><title>HarryPotterObamaSonic10Inu</title><link>https://0xtracer.xyz/incidents/2024-12-18-harrypotterobamasonic10inu/</link><pubDate>Wed, 18 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-18-harrypotterobamasonic10inu/</guid><description>A series of exploiting transactions on Ethereum targeting the liquidity pool of the HarryPotterObamaSonic10Inu 2.0 token. The attacker profited approximately $243K and deposited the funds into Tornado.</description></item><item><title>GemPad</title><link>https://0xtracer.xyz/incidents/2024-12-17-gempad/</link><pubDate>Tue, 17 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-17-gempad/</guid><description>The lock contract of the DeFi platform GemPad was exploited on the BSC, ETH, Base, and Polygon networks, resulting in a loss of approximately $2 million.</description></item><item><title>BTC24H (BTC24H)</title><link>https://0xtracer.xyz/incidents/2024-12-16-btc24h-btc24h/</link><pubDate>Mon, 16 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-16-btc24h-btc24h/</guid><description>BTC24H (BTC24H) is suspected to have been attacked on Polygon, with an estimated loss of $85,700.</description></item><item><title>Decentralized Finance (DCF)</title><link>https://0xtracer.xyz/incidents/2024-12-15-decentralized-finance-dcf/</link><pubDate>Sun, 15 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-15-decentralized-finance-dcf/</guid><description>Decentralized Finance (DCF) was attacked on the BSC chain, resulting in a loss of approximately $8,800.</description></item><item><title>Drake</title><link>https://0xtracer.xyz/incidents/2024-12-15-drake/</link><pubDate>Sun, 15 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-15-drake/</guid><description>Canadian rapper Drake&amp;rsquo;s X account (with over 39 million followers) was allegedly compromised on Saturday evening, promoting a Solana meme coin based on his cartoon &amp;ldquo;alter ego&amp;rdquo; character. The coin&amp;rsquo;s trading volume reac&amp;hellip;</description></item><item><title>JHY (JHY)</title><link>https://0xtracer.xyz/incidents/2024-12-14-jhy-jhy/</link><pubDate>Sat, 14 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-14-jhy-jhy/</guid><description>A suspicious attack involving JHY (JHY) occurred on the BSC chain, resulting in a loss of approximately $11,200.</description></item><item><title>bnbs (bnbs)</title><link>https://0xtracer.xyz/incidents/2024-12-12-bnbs-bnbs/</link><pubDate>Thu, 12 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-12-bnbs-bnbs/</guid><description>A suspicious reentrancy attack involving bnbs (bnbs) occurred on the BSC chain, resulting in a loss of approximately $20,300.</description></item><item><title>Clober</title><link>https://0xtracer.xyz/incidents/2024-12-10-clober/</link><pubDate>Tue, 10 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-10-clober/</guid><description>Clober DEX liquidity vault on Base Network was exploited resulting in a loss of 133.7 ETH (~$501k). The root cause of the attack was a reentrancy vulnerability in the _burn() function of the Rebalancer contract.</description></item><item><title>Haven Protocol</title><link>https://0xtracer.xyz/incidents/2024-12-10-haven-protocol/</link><pubDate>Tue, 10 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-10-haven-protocol/</guid><description>The algorithmic stablecoin protocol Haven Protocol has issued a warning about a hack exploiting a vulnerability in &amp;ldquo;range proof validation.&amp;rdquo; This flaw allows attackers to mint illicit XHV undetected. According to repo&amp;hellip;</description></item><item><title>LABUBU (LABUBU)</title><link>https://0xtracer.xyz/incidents/2024-12-10-labubu-labubu/</link><pubDate>Tue, 10 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-10-labubu-labubu/</guid><description>A suspicious attack involving LABUBU (LABUBU) occurred on the BSC chain, resulting in a loss of approximately $11,900.</description></item><item><title>Cardano Foundation</title><link>https://0xtracer.xyz/incidents/2024-12-08-cardano-foundation/</link><pubDate>Sun, 08 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-08-cardano-foundation/</guid><description>The Cardano Community posted on X, stating that the Cardano Foundation&amp;rsquo;s X account has been compromised. They are currently addressing the issue and advised users to temporarily ignore all posts from the account.</description></item><item><title>MAAT</title><link>https://0xtracer.xyz/incidents/2024-12-07-maat/</link><pubDate>Sat, 07 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-07-maat/</guid><description>The Omnichain meta-yield aggregator MAAT tweeted that a security breach in the MAAT alpha version, resulting in unauthorized withdrawals of $240,000 USDT.</description></item><item><title>Arata</title><link>https://0xtracer.xyz/incidents/2024-12-06-arata/</link><pubDate>Fri, 06 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-06-arata/</guid><description>Arata tweeted that the Arata ecosystem and CEX wallet have been exploited. The hacker managed to sell a significant portion of the tokens.</description></item><item><title>Vestra DAO</title><link>https://0xtracer.xyz/incidents/2024-12-04-vestra-dao/</link><pubDate>Wed, 04 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-04-vestra-dao/</guid><description>Vestra DAO tweeted that a hacker exploited a vulnerability in the locked staking contract, manipulating the reward mechanism to claim rewards exceeding their entitlement. As a result, a total of 73,720,000 VSTR tokens&amp;hellip;</description></item><item><title>RunWay (BYC)</title><link>https://0xtracer.xyz/incidents/2024-12-03-runway-byc/</link><pubDate>Tue, 03 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-03-runway-byc/</guid><description>According to the SlowMist security team’s monitoring, RunWay (BYC) appears to have been attacked on BSC, resulting in a loss of approximately $100K.</description></item><item><title>Brett</title><link>https://0xtracer.xyz/incidents/2024-12-02-brett/</link><pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-02-brett/</guid><description>According to community feedback, the official X account of the Meme token Brett on the Base chain has reportedly been compromised and used to post false information. Please stay vigilant against related risks.</description></item><item><title>DeBox</title><link>https://0xtracer.xyz/incidents/2024-12-02-debox/</link><pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-02-debox/</guid><description>DeBox officially announced that due to the leakage of the private key of an operational account&amp;rsquo;s personal EOA wallet, 31.03 ETH and 4.879 million BOX tokens were stolen.</description></item><item><title>GAGAW (GAGAW)</title><link>https://0xtracer.xyz/incidents/2024-12-02-gagaw-gagaw/</link><pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-02-gagaw-gagaw/</guid><description>The GAGAW (GAGAW) on BSC is suspected to have been attacked, resulting in a loss of approximately $70K.</description></item><item><title>Clipper DEX</title><link>https://0xtracer.xyz/incidents/2024-12-01-clipper-dex/</link><pubDate>Sun, 01 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-01-clipper-dex/</guid><description>According to Clipper&amp;rsquo;s post-mortem, on December 1, 2024, an attacker exploited a vulnerability in a smart contract used by Clipper, manipulating the single-asset deposit and withdrawal feature. This manipulation affec&amp;hellip;</description></item><item><title>Spectral</title><link>https://0xtracer.xyz/incidents/2024-12-01-spectral/</link><pubDate>Sun, 01 Dec 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-12-01-spectral/</guid><description>Spectral tweeted that they received an alert about a vulnerability affecting certain tokens on the bonding curve contracts on Syntax, which was used to remove approximately $200K in liquidity.</description></item><item><title>XT Exchange</title><link>https://0xtracer.xyz/incidents/2024-11-28-xt-exchange/</link><pubDate>Thu, 28 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-28-xt-exchange/</guid><description>The cryptocurrency exchange XT has reportedly fallen victim to a hacking incident, resulting in the loss of approximately $1.7 million worth of crypto assets. The hacker has converted the funds into 461.58 ETH and dep&amp;hellip;</description></item><item><title>DCF</title><link>https://0xtracer.xyz/incidents/2024-11-25-dcf/</link><pubDate>Mon, 25 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-25-dcf/</guid><description>On November 25, DCF on the BNB Chain was attacked, resulting in a loss of approximately $440,000. The root cause of the vulnerability was an error in the logic implemented by the project team in the transfer function&amp;hellip;</description></item><item><title>Pump Science</title><link>https://0xtracer.xyz/incidents/2024-11-25-pump-science/</link><pubDate>Mon, 25 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-25-pump-science/</guid><description>The DeSci project Pump Science tweeted that the wallet T5j2UB&amp;hellip;jjb8sc was exploited due to an oversight in their GitHub repository. The exploiter gained access to the keypair, which had been embedded in the source co&amp;hellip;</description></item><item><title>Akashalife (AK1111)</title><link>https://0xtracer.xyz/incidents/2024-11-24-akashalife-ak1111/</link><pubDate>Sun, 24 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-24-akashalife-ak1111/</guid><description>The Akashalife (AK1111) on BSC was suspected to have been attacked, resulting in a loss of approximately $31.5K.</description></item><item><title>JRNY</title><link>https://0xtracer.xyz/incidents/2024-11-23-jrny/</link><pubDate>Sat, 23 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-23-jrny/</guid><description>On-chain investigator ZachXBT stated on his personal Telegram channel that the wallet associated with crypto KOL JRNY appears to have been compromised, with approximately $4 million worth of crypto assets transferred&amp;hellip;</description></item><item><title>Matez (MATEZ)</title><link>https://0xtracer.xyz/incidents/2024-11-22-matez-matez/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-22-matez-matez/</guid><description>The Matez (MATEZ) on BSC is suspected to have been attacked, resulting in a loss of at least $80K.</description></item><item><title>Sweepr Token (SWEEPR)</title><link>https://0xtracer.xyz/incidents/2024-11-22-sweepr-token-sweepr/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-22-sweepr-token-sweepr/</guid><description>The Sweepr Token (SWEEPR) on ETH was suspected to have been attacked, resulting in a loss of approximately $14K.</description></item><item><title>BSCGem (BSCGem)</title><link>https://0xtracer.xyz/incidents/2024-11-20-bscgem-bscgem/</link><pubDate>Wed, 20 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-20-bscgem-bscgem/</guid><description>According to monitoring by the SlowMist Security Team, the BSCGem (BSCGem) on BSC is suspected to have been attacked, resulting in a loss of approximately $17.3K.</description></item><item><title>MFT (MFT)</title><link>https://0xtracer.xyz/incidents/2024-11-17-mft-mft/</link><pubDate>Sun, 17 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-17-mft-mft/</guid><description>The MFT (MFT) on BSC is suspected to have been attacked, resulting in a loss of approximately $33.7K.</description></item><item><title>Polter Finance</title><link>https://0xtracer.xyz/incidents/2024-11-17-polter-finance/</link><pubDate>Sun, 17 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-17-polter-finance/</guid><description>The lending project Polter Finance on Fantom lost ~$12 million due to an oracle price-related flash loan attack on its newly launched SpookySwap (BOO) market.</description></item><item><title>DEXX</title><link>https://0xtracer.xyz/incidents/2024-11-16-dexx/</link><pubDate>Sat, 16 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-16-dexx/</guid><description>On-chain trading terminal stored private keys insecurely server-side</description></item><item><title>Giggle Academy</title><link>https://0xtracer.xyz/incidents/2024-11-16-giggle-academy/</link><pubDate>Sat, 16 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-16-giggle-academy/</guid><description>Binance co-founder CZ confirmed on X that the official X account of his educational project, Giggle Academy, has been hacked.</description></item><item><title>dogwifcoin (WIF)</title><link>https://0xtracer.xyz/incidents/2024-11-15-dogwifcoin-wif/</link><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-15-dogwifcoin-wif/</guid><description>The X account of the meme project dogwifcoin (WIF) is suspected to have been hacked, posting multiple token contract messages. Users are advised to stay vigilant.</description></item><item><title>GMGN</title><link>https://0xtracer.xyz/incidents/2024-11-15-gmgn/</link><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-15-gmgn/</guid><description>GMGN stated in the community, &amp;ldquo;The GMGN website has suffered a malicious attack, suspected to involve multiple methods, including common crawler attacks and flood attacks. The development team is currently working on&amp;hellip;</description></item><item><title>Thala Labs</title><link>https://0xtracer.xyz/incidents/2024-11-15-thala-labs/</link><pubDate>Fri, 15 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-15-thala-labs/</guid><description>Farm contract vulnerability exploited, funds recovered via negotiation</description></item><item><title>vETH</title><link>https://0xtracer.xyz/incidents/2024-11-14-veth/</link><pubDate>Thu, 14 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-14-veth/</guid><description>The vETH token suffered an attack, resulting in approximately $450K in losses.</description></item><item><title>DeltaPrime</title><link>https://0xtracer.xyz/incidents/2024-11-11-deltaprime/</link><pubDate>Mon, 11 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-11-deltaprime/</guid><description>The DeltaPrime DeFi protocol, was attacked on Avalanche and Arbitrum, with an initial estimated loss of $4.75 million.</description></item><item><title>BGM</title><link>https://0xtracer.xyz/incidents/2024-11-10-bgm/</link><pubDate>Sun, 10 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-10-bgm/</guid><description>The BGM token on BSC was attacked, resulting in losses exceeding $450K, with the attacker profiting through price manipulation.</description></item><item><title>CoinPoker</title><link>https://0xtracer.xyz/incidents/2024-11-08-coinpoker/</link><pubDate>Fri, 08 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-08-coinpoker/</guid><description>On November 8, a hacker breached the CoinPoker’s hot wallet, resulting in the unauthorized draining of approximately $2M USD. The attack spanned across multiple blockchain networks, including BNB Chain, Ethereum, and&amp;hellip;</description></item><item><title>MetaWin</title><link>https://0xtracer.xyz/incidents/2024-11-04-metawin/</link><pubDate>Mon, 04 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-04-metawin/</guid><description>According to on-chain detective ZachXBT, the cryptocurrency gambling platform MetaWin was reportedly attacked, resulting in the theft of over $4 million on the Ethereum and Solana blockchains.</description></item><item><title>Wiz Khalifa</title><link>https://0xtracer.xyz/incidents/2024-11-04-wiz-khalifa/</link><pubDate>Mon, 04 Nov 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-11-04-wiz-khalifa/</guid><description>According to on-chain investigator ZachXBT, American rapper Wiz Khalifa&amp;rsquo;s X account was hacked, posting fake announcements about a WIZ token. The hacker responsible is reportedly the same person who compromised Andy A&amp;hellip;</description></item><item><title>Lottie Player</title><link>https://0xtracer.xyz/incidents/2024-10-31-lottie-player/</link><pubDate>Thu, 31 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-31-lottie-player/</guid><description>According to monitoring by Scam Sniffer, Lottie Player suffered a supply chain attack, impacting projects such as 1inch and Movement.</description></item><item><title>M2 Exchange</title><link>https://0xtracer.xyz/incidents/2024-10-31-m2-exchange/</link><pubDate>Thu, 31 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-31-m2-exchange/</guid><description>UAE-based exchange lost funds on BTC, ETH, and Solana chains</description></item><item><title>SUNRAY FINANCE</title><link>https://0xtracer.xyz/incidents/2024-10-31-sunray-finance/</link><pubDate>Thu, 31 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-31-sunray-finance/</guid><description>SUNRAY FINANCE experienced a private key compromise, allowing the exploiter to gain control of the SUN and ARC tokens and sell them off, draining the funds from DEX pairs. So far, the attacker has stolen approximately&amp;hellip;</description></item><item><title>Keystone</title><link>https://0xtracer.xyz/incidents/2024-10-30-keystone/</link><pubDate>Wed, 30 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-30-keystone/</guid><description>The official X account of the hardware wallet Keystone is suspected to have been hacked. Users are advised to remain vigilant and be cautious of potential risks.</description></item><item><title>Shoebill Finance</title><link>https://0xtracer.xyz/incidents/2024-10-30-shoebill-finance/</link><pubDate>Wed, 30 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-30-shoebill-finance/</guid><description>On Oct 31st, Collaterizable Leverage Lending Platform Shoebill Finance experienced a security incident affecting the BTC Market on the BOB chain. The incident stemmed from an unexpected interaction within the oracle c&amp;hellip;</description></item><item><title>Andy Ayrey</title><link>https://0xtracer.xyz/incidents/2024-10-29-andy-ayrey/</link><pubDate>Tue, 29 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-29-andy-ayrey/</guid><description>Andy Ayrey, founder of the AI bot project Truth Terminal, announced the launch of a new token IB on X. It is suspected that his account may have been hacked.</description></item><item><title>Essence Finance</title><link>https://0xtracer.xyz/incidents/2024-10-26-essence-finance/</link><pubDate>Sat, 26 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-26-essence-finance/</guid><description>Scroll ecosystem stablecoin project Essence Finance is suspected of rugpulled, its stablecoin CHI has fallen by more than 92% to $0.077 in the past 24h, more than $20 million of collateral is suspected to have been re&amp;hellip;</description></item><item><title>Aark Digital</title><link>https://0xtracer.xyz/incidents/2024-10-25-aark-digital/</link><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-25-aark-digital/</guid><description>During a routine GM token burn, Aark Digital encountered a callback error due to a third-party contract modification. To resolve this, Aark Digital initiated a contract upgrade and GM delisting to adjust affected user&amp;hellip;</description></item><item><title>U.S. Government-Controlled Wallet</title><link>https://0xtracer.xyz/incidents/2024-10-25-u-s-government-controlled-wallet/</link><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-25-u-s-government-controlled-wallet/</guid><description>According to a MistTrack tweet, a suspicious outflow was detected from a wallet controlled by the U.S. government (0xc9E&amp;hellip;34c): nearly $20 million was transferred to 0x3486ee700ccaf3e2f9c5ec9730a2e916a4740a9f, includ&amp;hellip;</description></item><item><title>Unverified Contracts</title><link>https://0xtracer.xyz/incidents/2024-10-25-unverified-contracts/</link><pubDate>Fri, 25 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-25-unverified-contracts/</guid><description>Base chain detected a price manipulation attack targeting unverified lending contracts, where the attacker gained around $1 million in tokens through excessive borrowing.</description></item><item><title>Cryptobottle</title><link>https://0xtracer.xyz/incidents/2024-10-24-cryptobottle/</link><pubDate>Thu, 24 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-24-cryptobottle/</guid><description>In October 2024, Cryptobottle on Polygon suffered three separate attacks, with total losses amounting to approximately $527,000. The attack on October 24 was the largest of the three, where the attacker exploited a cr&amp;hellip;</description></item><item><title>Ramses Exchange</title><link>https://0xtracer.xyz/incidents/2024-10-24-ramses-exchange/</link><pubDate>Thu, 24 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-24-ramses-exchange/</guid><description>The contract of Ramses Exchange on Arbitrum was attacked, resulting in a loss of approximately $93,000.</description></item><item><title>SHARPEI</title><link>https://0xtracer.xyz/incidents/2024-10-23-sharpei/</link><pubDate>Wed, 23 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-23-sharpei/</guid><description>A dog-themed memecoin project called SHARPEI abruptly cashed out $3.4 million, tanking the token price by more than 96% in seconds. The project had been promoted by crypto influencers, but hit a snag when a pitch deck&amp;hellip;</description></item><item><title>MuratiAI</title><link>https://0xtracer.xyz/incidents/2024-10-21-muratiai/</link><pubDate>Mon, 21 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-21-muratiai/</guid><description>The X account of MuratiAI (@MuratiAI), an AI network and bot platform centered around anime, is suspected to have been hacked, with phishing links being posted. Until further notice, please refrain from clicking any l&amp;hellip;</description></item><item><title>Transak</title><link>https://0xtracer.xyz/incidents/2024-10-21-transak/</link><pubDate>Mon, 21 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-21-transak/</guid><description>According to on-chain investigator ZachXBT, the crypto payment service provider Transak recently fell victim to a ransomware attack. Transak reported that the incident occurred when an attacker accessed an employee&amp;rsquo;s&amp;hellip;</description></item><item><title>Ambient Finance</title><link>https://0xtracer.xyz/incidents/2024-10-19-ambient-finance/</link><pubDate>Sat, 19 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-19-ambient-finance/</guid><description>Scroll-based DEX protocol Ambient Finance announced on X platform that their domain has been hijacked. Until further notice, please do not interact with the Ambient Finance frontend.</description></item><item><title>Eigenlayer</title><link>https://0xtracer.xyz/incidents/2024-10-18-eigenlayer/</link><pubDate>Fri, 18 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-18-eigenlayer/</guid><description>The official X account of Eigenlayer, the Ethereum re-staking protocol, is suspected to have been hacked. The hacker has posted a fake phishing link; please do not interact with it.</description></item><item><title>IBXtrade</title><link>https://0xtracer.xyz/incidents/2024-10-18-ibxtrade/</link><pubDate>Fri, 18 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-18-ibxtrade/</guid><description>DeFi analyst Anon Vee posted on X that several users have reported that the Orderly Network ecosystem project IBXtrade is suspected of a rug pull. It is reported that IBXtrade launched a pre-sale three days ago with a&amp;hellip;</description></item><item><title>Tapioca DAO</title><link>https://0xtracer.xyz/incidents/2024-10-18-tapioca-dao/</link><pubDate>Fri, 18 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-18-tapioca-dao/</guid><description>Tapioca DAO experienced a significant security breach, with attackers obtaining relevant private keys through social engineering attacks and stealing approximately $4.7 million in cryptocurrency. On October 25, Tapioc&amp;hellip;</description></item><item><title>Kabosumama</title><link>https://0xtracer.xyz/incidents/2024-10-17-kabosumama/</link><pubDate>Thu, 17 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-17-kabosumama/</guid><description>According to AggrNews, the Instagram account of Kabosumama, the owner of the Shiba Inu Kabosu, the inspiration behind the popular DOG project &amp;ldquo;Doge&amp;rdquo; meme, has been hacked. Kabosumama previously posted on her blog, sta&amp;hellip;</description></item><item><title>Lagrange</title><link>https://0xtracer.xyz/incidents/2024-10-17-lagrange/</link><pubDate>Thu, 17 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-17-lagrange/</guid><description>ZK startup Lagrange&amp;rsquo;s X account has been allegedly compromised, and a scam link related to the LGR token has been posted. Please stay vigilant and be cautious of potential risks.</description></item><item><title>Radiant Capital</title><link>https://0xtracer.xyz/incidents/2024-10-16-radiant-capital/</link><pubDate>Wed, 16 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-16-radiant-capital/</guid><description>Multisig signers compromised via malware-infected PDF, DPRK attributed</description></item><item><title>Zulu Network</title><link>https://0xtracer.xyz/incidents/2024-10-14-zulu-network/</link><pubDate>Mon, 14 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-14-zulu-network/</guid><description>The official X account of Bitcoin L2 Zulu Network appears to have been compromised. The hacker has posted a fake phishing link. Please avoid interacting with it.</description></item><item><title>KOR Protocol</title><link>https://0xtracer.xyz/incidents/2024-10-12-kor-protocol/</link><pubDate>Sat, 12 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-12-kor-protocol/</guid><description>The official X account of the decentralized intellectual property (IP) platform KOR Protocol appears to have been compromised. The hacker has posted a fake phishing link. Please avoid interacting with it.</description></item><item><title>Ordinals Wallet</title><link>https://0xtracer.xyz/incidents/2024-10-11-ordinals-wallet/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-11-ordinals-wallet/</guid><description>According to monitoring by Scam Sniffer, the X account of Ordinals Wallet was hacked, and a phishing link was posted. Upon review, the related post has already been deleted.</description></item><item><title>SPX6900</title><link>https://0xtracer.xyz/incidents/2024-10-11-spx6900/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-11-spx6900/</guid><description>According to meme coin KOL Murad (@MustStopMurad), the official X account of SPX6900 (SPX) has been hacked. Users are advised not to click any links.</description></item><item><title>HYDT</title><link>https://0xtracer.xyz/incidents/2024-10-10-hydt/</link><pubDate>Thu, 10 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-10-hydt/</guid><description>A suspicious attack involving HYDT tokens has occurred on BSC, resulting in a loss of approximately $58,000.</description></item><item><title>Spot On Chain</title><link>https://0xtracer.xyz/incidents/2024-10-06-spot-on-chain/</link><pubDate>Sun, 06 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-06-spot-on-chain/</guid><description>The X account of the crypto data tracking service Spot On Chain has reportedly been compromised. It was said to have posted a fake EIGEN airdrop phishing link this morning, while also disabling the comment section for&amp;hellip;</description></item><item><title>EigenLayer Investor</title><link>https://0xtracer.xyz/incidents/2024-10-05-eigenlayer-investor/</link><pubDate>Sat, 05 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-05-eigenlayer-investor/</guid><description>EigenLayer disclosed on X that in an isolated incident this morning, an email thread involving one investor’s transfer of tokens into custody was compromised by a malicious attacker. As a result, 1,673,645 EIGEN token&amp;hellip;</description></item><item><title>LEGO Group</title><link>https://0xtracer.xyz/incidents/2024-10-05-lego-group/</link><pubDate>Sat, 05 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-05-lego-group/</guid><description>According to a report by Cointelegraph, the homepage of toy manufacturer LEGO Group was hacked on October 5th local time, briefly displaying a &amp;ldquo;LEGO Coin&amp;rdquo; token scam. The fraudulent token was present on the LEGO Group&amp;hellip;</description></item><item><title>Symbiotic</title><link>https://0xtracer.xyz/incidents/2024-10-05-symbiotic/</link><pubDate>Sat, 05 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-05-symbiotic/</guid><description>The official X account of the staking protocol Symbiotic has been suspected of being hacked. The hacker has already posted a fake phishing link. Please do not interact with it.</description></item><item><title>Fire (FIRE)</title><link>https://0xtracer.xyz/incidents/2024-10-01-fire-fire/</link><pubDate>Tue, 01 Oct 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-10-01-fire-fire/</guid><description>The Fire ($FIRE) token on Ethereum was exploited just 24 seconds after its launch, resulting in the theft of 9 ETH (approximately $24,000). The root cause was related to the token burn mechanism within the transfer()&amp;hellip;</description></item><item><title>Bedrock</title><link>https://0xtracer.xyz/incidents/2024-09-27-bedrock/</link><pubDate>Fri, 27 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-27-bedrock/</guid><description>The multi-chain liquidity re-staking protocol Bedrock announced on social media that the team is aware of a security vulnerability involving uniBTC, with the total estimated loss from the theft around $2 million. Acco&amp;hellip;</description></item><item><title>Onyx</title><link>https://0xtracer.xyz/incidents/2024-09-26-onyx/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-26-onyx/</guid><description>Onyx protocol suffered a security breach, resulting in a loss of over $3.8 million. The attacker exploited a known precision issue in the Compound V2 code. Additionally, the NFTLiquidation contract failed to properly&amp;hellip;</description></item><item><title>ReHold</title><link>https://0xtracer.xyz/incidents/2024-09-26-rehold/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-26-rehold/</guid><description>ReHold CTO Michael Semin disclosed on the X platform that on July 15, 2024, ReHold&amp;rsquo;s CEO and co-founder, Renat Gafarov, withdrew over $700,000 from the company&amp;rsquo;s smart contract without his approval. ReHold has since m&amp;hellip;</description></item><item><title>Truflation</title><link>https://0xtracer.xyz/incidents/2024-09-26-truflation/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-26-truflation/</guid><description>According to on-chain sleuth ZachXBT, the project Truflation was hacked a few hours ago for $5M+ on multiple chains from the treasury multisig and personal wallets.</description></item><item><title>ether.fi</title><link>https://0xtracer.xyz/incidents/2024-09-24-ether-fi/</link><pubDate>Tue, 24 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-24-ether-fi/</guid><description>On September 24, ether.fi experienced a security incident involving its domain registrar, Gandi.net, resulting in the compromise of the ether[.]fi domain.</description></item><item><title>Bankroll Network</title><link>https://0xtracer.xyz/incidents/2024-09-22-bankroll-network/</link><pubDate>Sun, 22 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-22-bankroll-network/</guid><description>On September 22, Bankroll Network on BNB was attacked due to a contract vulnerability, resulting in a loss of approximately $230,000.</description></item><item><title>Immutable</title><link>https://0xtracer.xyz/incidents/2024-09-21-immutable/</link><pubDate>Sat, 21 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-21-immutable/</guid><description>The Immutable Discord server was compromised. According to an official tweet from Immutable, a community support contractor’s Discord was compromised, leading to a phishing link being posted.</description></item><item><title>Shezmu</title><link>https://0xtracer.xyz/incidents/2024-09-21-shezmu/</link><pubDate>Sat, 21 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-21-shezmu/</guid><description>A crypto yield platform called Shezmu suffered a loss of around $4.9 million in $ShezUSD after an attacker exploited a flaw that allowed anyone to mint collateral, which they could then use to borrow ShezUSD. These to&amp;hellip;</description></item><item><title>BingX</title><link>https://0xtracer.xyz/incidents/2024-09-20-bingx/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-20-bingx/</guid><description>Hot wallet drained across ETH, BSC, Polygon chains</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2024-09-20-compound/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-20-compound/</guid><description>Compound community’s Discord server has been hacked. Please do not click on any links until the situation is resolved.</description></item><item><title>Masa</title><link>https://0xtracer.xyz/incidents/2024-09-20-masa/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-20-masa/</guid><description>According to on-chain investigator ZachXBT on the X platform, the decentralized AI data network Masa suffered a hack on September 20, incurring losses exceeding six figures in USD. However, Masa did not disclose this&amp;hellip;</description></item><item><title>Banana Gun</title><link>https://0xtracer.xyz/incidents/2024-09-19-banana-gun/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-19-banana-gun/</guid><description>Telegram trading bot contract vulnerability allowed token theft</description></item><item><title>Decentraland</title><link>https://0xtracer.xyz/incidents/2024-09-19-decentraland/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-19-decentraland/</guid><description>The official X account of the metaverse project Decentraland has been hacked. The hacker has posted a fake phishing link. Please avoid interacting with it.</description></item><item><title>DIN</title><link>https://0xtracer.xyz/incidents/2024-09-19-din/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-19-din/</guid><description>The official X account of AI Modular Data Preprocessing Layer DIN was hacked, and a large number of phishing posts and links were sent.</description></item><item><title>Ethena Labs</title><link>https://0xtracer.xyz/incidents/2024-09-19-ethena-labs/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-19-ethena-labs/</guid><description>Ethena Labs posted on X platform that their Ethena domain registrar account was recently compromised. They have taken measures to disable the website until further notice. The protocol is not affected, and funds are s&amp;hellip;</description></item><item><title>DeltaPrime</title><link>https://0xtracer.xyz/incidents/2024-09-16-deltaprime/</link><pubDate>Mon, 16 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-16-deltaprime/</guid><description>DeFi project DeltaPrime has officially confirmed on platform X that a security incident occurred. DeltaPrime Blue (Arbitrum) was attacked and drained for $5.98M. This was due to a compromised private key.</description></item><item><title>BaseBros Fi</title><link>https://0xtracer.xyz/incidents/2024-09-13-basebros-fi/</link><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-13-basebros-fi/</guid><description>The yield-optimizing DeFi protocol BaseBros Fi has vanished after executing a rug pull via an unaudited smart contract.</description></item><item><title>OTSea</title><link>https://0xtracer.xyz/incidents/2024-09-13-otsea/</link><pubDate>Fri, 13 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-13-otsea/</guid><description>Peer-to-peer trading platform OTSea&amp;rsquo;s staking contract on Ethereum was exploited by an EOA, resulting in the theft of approximately $26,000.</description></item><item><title>Omnipus</title><link>https://0xtracer.xyz/incidents/2024-09-11-omnipus/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-11-omnipus/</guid><description>Omnipus contracts were drained of approximately $30,000 during the OPUS token presale. The attack exploited a vulnerability in which the contracts mistakenly believed the attackers had sent too much ETH and refunded t&amp;hellip;</description></item><item><title>Caterpillar Coin</title><link>https://0xtracer.xyz/incidents/2024-09-10-caterpillar-coin/</link><pubDate>Tue, 10 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-10-caterpillar-coin/</guid><description>Caterpillar Coin suffered a flashloan attack resulting in a loss of ~$1.4M and causing a 99% slippage on the token. The attack exploited vulnerabilities in the &amp;ldquo;price protection mechanisms&amp;rdquo;, which led to the manipulat&amp;hellip;</description></item><item><title>Indodax</title><link>https://0xtracer.xyz/incidents/2024-09-10-indodax/</link><pubDate>Tue, 10 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-10-indodax/</guid><description>Indonesian exchange hot wallets drained across multiple networks</description></item><item><title>Jules Urbach</title><link>https://0xtracer.xyz/incidents/2024-09-08-jules-urbach/</link><pubDate>Sun, 08 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-08-jules-urbach/</guid><description>The Render Network posted on X, stating that the X account of its founder and CEO, Jules Urbach, was hacked and used to post fake airdrop information. Please do not click any links from the account, and carefully veri&amp;hellip;</description></item><item><title>Fuel</title><link>https://0xtracer.xyz/incidents/2024-09-06-fuel/</link><pubDate>Fri, 06 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-06-fuel/</guid><description>The Ethereum modular execution layer Fuel posted on X, stating that their official Discord had been attacked. Users are advised not to click on any suspicious links or provide any personal information.</description></item><item><title>Jaylen Brown</title><link>https://0xtracer.xyz/incidents/2024-09-05-jaylen-brown/</link><pubDate>Thu, 05 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-05-jaylen-brown/</guid><description>NBA star Jaylen Brown&amp;rsquo;s X account was hacked, and a large amount of fake token information was posted. Users are advised to be cautious and avoid interacting with fraudulent contracts.</description></item><item><title>NEAR Protocol</title><link>https://0xtracer.xyz/incidents/2024-09-05-near-protocol/</link><pubDate>Thu, 05 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-05-near-protocol/</guid><description>NEAR&amp;rsquo;s official account posted on X, stating that the official X account of NEAR Protocol had been hijacked. The hacker posted a series of messages attacking the Crypto ecosystem.</description></item><item><title>ChainLink</title><link>https://0xtracer.xyz/incidents/2024-09-03-chainlink/</link><pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-03-chainlink/</guid><description>The official ChainLink Discord has been hacked. Please do not click on any links until the situation is resolved.</description></item><item><title>Penpie</title><link>https://0xtracer.xyz/incidents/2024-09-03-penpie/</link><pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-03-penpie/</guid><description>Reentrancy in reward claiming via malicious Pendle market registration</description></item><item><title>Pythia</title><link>https://0xtracer.xyz/incidents/2024-09-03-pythia/</link><pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-03-pythia/</guid><description>The decentralized algorithmic stablecoin protocol Pythia was attacked due to a vulnerability in its staking contract, resulting in a loss of 21 ETH (approximately $53,000).</description></item><item><title>Sei</title><link>https://0xtracer.xyz/incidents/2024-09-03-sei/</link><pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-09-03-sei/</guid><description>Sei&amp;rsquo;s official Discord has been suspected of being hacked. The hacker has posted a fake phishing link. Please do not interact with it.</description></item><item><title>Usual</title><link>https://0xtracer.xyz/incidents/2024-08-31-usual/</link><pubDate>Sat, 31 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-31-usual/</guid><description>The stablecoin protocol Usual posted on X to alert users that its official Discord server has been hacked. Please do not click on any links.</description></item><item><title>Powerledger</title><link>https://0xtracer.xyz/incidents/2024-08-30-powerledger/</link><pubDate>Fri, 30 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-30-powerledger/</guid><description>Australian blockchain energy technology company Powerledger posted on X that its Telegram channel has been hacked. They advise users not to engage with or share any information as they are currently working to resolve&amp;hellip;</description></item><item><title>Witness Chain</title><link>https://0xtracer.xyz/incidents/2024-08-30-witness-chain/</link><pubDate>Fri, 30 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-30-witness-chain/</guid><description>The official Witness Chain Discord has been hacked. Please do not click on any links until the situation is resolved.</description></item><item><title>io.net</title><link>https://0xtracer.xyz/incidents/2024-08-29-io-net/</link><pubDate>Thu, 29 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-29-io-net/</guid><description>Ahmad Shadid, former CEO of the decentralized GPU network io.net, posted on X that the official io.net Discord has been hacked. He has informed the IO team and advised not to click on any shared links.</description></item><item><title>Kylian Mbappe</title><link>https://0xtracer.xyz/incidents/2024-08-29-kylian-mbappe/</link><pubDate>Thu, 29 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-29-kylian-mbappe/</guid><description>French football star Kylian Mbappe&amp;rsquo;s X account was hacked, and a token called MBAPPE was posted. The tweet has since been deleted. The MBAPPE token&amp;rsquo;s market value skyrocketed to tens of millions of dollars within minu&amp;hellip;</description></item><item><title>Orderly Network</title><link>https://0xtracer.xyz/incidents/2024-08-29-orderly-network/</link><pubDate>Thu, 29 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-29-orderly-network/</guid><description>According to an official tweet from Web3 liquidity provider Orderly Network, their Discord server has been compromised. The official team advises users not to click on any links until the situation is fully resolved t&amp;hellip;</description></item><item><title>1inch</title><link>https://0xtracer.xyz/incidents/2024-08-28-1inch/</link><pubDate>Wed, 28 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-28-1inch/</guid><description>According to monitoring by the SlowMist security team, the official 1inch Discord appears to have been hacked, and phishing links have been posted. Please be cautious with your funds.</description></item><item><title>Aave</title><link>https://0xtracer.xyz/incidents/2024-08-28-aave/</link><pubDate>Wed, 28 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-28-aave/</guid><description>The DeFi lending platform Aave was attacked due to a contract vulnerability. The attack occurred in a smart contract outside of Aave&amp;rsquo;s core protocol, which is used to allow users to repay loans using existing collater&amp;hellip;</description></item><item><title>Avalanche</title><link>https://0xtracer.xyz/incidents/2024-08-26-avalanche/</link><pubDate>Mon, 26 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-26-avalanche/</guid><description>According to an official tweet from Avalanche, their Discord server has been compromised. The official team advises users not to click on any links until the situation is fully resolved.</description></item><item><title>ZkSync</title><link>https://0xtracer.xyz/incidents/2024-08-26-zksync/</link><pubDate>Mon, 26 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-26-zksync/</guid><description>ZkSync&amp;rsquo;s official Discord has been compromised, and hackers have posted a malicious link promoting a fake &amp;ldquo;second round airdrop&amp;rdquo; plan, falsely promising users free ZK tokens.</description></item><item><title>Aquarius</title><link>https://0xtracer.xyz/incidents/2024-08-24-aquarius/</link><pubDate>Sat, 24 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-24-aquarius/</guid><description>The official X account of the crypto venture capital firm Aquarius was hacked. The attacker has already changed the username, associated email, and phone number. Additionally, the previous username has been taken over&amp;hellip;</description></item><item><title>Artela</title><link>https://0xtracer.xyz/incidents/2024-08-24-artela/</link><pubDate>Sat, 24 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-24-artela/</guid><description>The parallel-execution EVM public chain Artela announced on the X platform that their official Discord was hacked today. The attacker took control of the Discord channel and spread fake airdrop messages. The team took&amp;hellip;</description></item><item><title>Polygon</title><link>https://0xtracer.xyz/incidents/2024-08-24-polygon/</link><pubDate>Sat, 24 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-24-polygon/</guid><description>Mudit Gupta, the Chief Information Security Officer of Polygon, stated on the X platform that the Polygon Community Discord has been compromised. He advised users not to click on any links within the server as the tea&amp;hellip;</description></item><item><title>HFLH</title><link>https://0xtracer.xyz/incidents/2024-08-23-hflh/</link><pubDate>Fri, 23 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-23-hflh/</guid><description>According to monitoring by the SlowMist security team, the staking and lending protocol HFLH on BNB Chain has been attacked. Users are advised to stay vigilant.</description></item><item><title>McDonald</title><link>https://0xtracer.xyz/incidents/2024-08-21-mcdonald/</link><pubDate>Wed, 21 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-21-mcdonald/</guid><description>On-chain sleuth ZachXBT revealed that McDonald&amp;rsquo;s Instagram account was allegedly hacked and used to promote the meme token GRIMACE.</description></item><item><title>Parcl</title><link>https://0xtracer.xyz/incidents/2024-08-20-parcl/</link><pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-20-parcl/</guid><description>The website frontend of Solana ecosystem real estate trading protocol Parcl has been hacked, extracting tokens from users&amp;rsquo; Solana wallets and displaying fake transaction results in Phantom. Parcl’s official X account&amp;hellip;</description></item><item><title>Luigi D'Onorio DeMeo</title><link>https://0xtracer.xyz/incidents/2024-08-19-luigi-d-onorio-demeo/</link><pubDate>Mon, 19 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-19-luigi-d-onorio-demeo/</guid><description>The X account of AvaLabs COO Luigi D&amp;rsquo;Onorio DeMeo appears to have been compromised. Please do NOT interact with any addresses or links it has posted.</description></item><item><title>Sahara AI</title><link>https://0xtracer.xyz/incidents/2024-08-19-sahara-ai/</link><pubDate>Mon, 19 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-19-sahara-ai/</guid><description>The decentralized AI blockchain platform Sahara AI announced on the X platform that their official Discord has been compromised. Users are advised not to click on any links or respond to any messages until further not&amp;hellip;</description></item><item><title>Vow</title><link>https://0xtracer.xyz/incidents/2024-08-13-vow/</link><pubDate>Tue, 13 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-13-vow/</guid><description>Vow suffers an attack due to a contract vulnerability, resulting in a loss of approximately $1.2 million.</description></item><item><title>iVest DAO</title><link>https://0xtracer.xyz/incidents/2024-08-12-ivest-dao/</link><pubDate>Mon, 12 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-12-ivest-dao/</guid><description>iVest DAO was attacked due to a smart contract vulnerability, resulting in a loss of approximately $172,000.</description></item><item><title>RARI Foundation</title><link>https://0xtracer.xyz/incidents/2024-08-09-rari-foundation/</link><pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-09-rari-foundation/</guid><description>The official Discord server of RARI Foundation has been hacked. Please refrain from using the server until the team has regained control.</description></item><item><title>Nexera</title><link>https://0xtracer.xyz/incidents/2024-08-07-nexera/</link><pubDate>Wed, 07 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-07-nexera/</guid><description>An external attacker gained access to credentials for managing Nexera Fundrs platform&amp;rsquo;s smart contracts. Using these credentials, the attacker transferred NXRA tokens from Fundrs&amp;rsquo; staking contracts on Ethereum. Out of&amp;hellip;</description></item><item><title>OMPx</title><link>https://0xtracer.xyz/incidents/2024-08-06-ompx/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-06-ompx/</guid><description>OMPx was attacked, resulting in a loss of approximately $107,000. The attacker obtained initial funds through Railgun, and the stolen funds have already been deposited into Railgun.</description></item><item><title>Ronin</title><link>https://0xtracer.xyz/incidents/2024-08-06-ronin/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-06-ronin/</guid><description>The Ronin Bridge project experienced unusual cross-chain asset withdrawals, suggesting a potential attack. According to the SlowMist security team, the vulnerability was caused by the modification of weight to an unex&amp;hellip;</description></item><item><title>SATOSHI (SATS)</title><link>https://0xtracer.xyz/incidents/2024-08-03-satoshi-sats/</link><pubDate>Sat, 03 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-03-satoshi-sats/</guid><description>According to monitoring by the SlowMist security team, SATOSHI (SATS) was attacked on Ethereum on August 3rd.</description></item><item><title>Starknet</title><link>https://0xtracer.xyz/incidents/2024-08-02-starknet/</link><pubDate>Fri, 02 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-02-starknet/</guid><description>According to an official tweet from Ethereum Layer 2 network Starknet, their Discord server has been compromised. The official team advises users not to click on any links until the situation is fully resolved.</description></item><item><title>Convergence Finance</title><link>https://0xtracer.xyz/incidents/2024-08-01-convergence-finance/</link><pubDate>Thu, 01 Aug 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-08-01-convergence-finance/</guid><description>Convergence Finance was attacked. 58M CVG have been minted and sold by the hacker for approximately $210,000 ( the whole portion of tokens dedicated to staking emissions); Approximately $2,000 of unclaimed rewards fro&amp;hellip;</description></item><item><title>Terra</title><link>https://0xtracer.xyz/incidents/2024-07-31-terra/</link><pubDate>Wed, 31 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-31-terra/</guid><description>Terra blockchain experienced a security breach that led to the theft of tokens. The attackers exploited a known vulnerability related to the third-party module IBC hooks, stealing the value of cross-chain assets, incl&amp;hellip;</description></item><item><title>Anzen Finance</title><link>https://0xtracer.xyz/incidents/2024-07-30-anzen-finance/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-30-anzen-finance/</guid><description>Anzen Finance, the issuer of RWA stablecoins, announced on the X platform that on July 30, due to an error in the Blast vault contract, a white hat hacker exploited the vault to steal 500,000 USDz. The white hat retur&amp;hellip;</description></item><item><title>Metis</title><link>https://0xtracer.xyz/incidents/2024-07-30-metis/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-30-metis/</guid><description>The Ethereum Layer 2 network Metis issued a warning on Twitter stating that their Discord has been compromised. They advised users not to click on any &amp;ldquo;airdrop links&amp;rdquo; or any other links.</description></item><item><title>Casper Network</title><link>https://0xtracer.xyz/incidents/2024-07-26-casper-network/</link><pubDate>Fri, 26 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-26-casper-network/</guid><description>On July 26, 2024, Casper Network was attacked. Following the attack, Casper Network tweeted that they had worked with validators to pause the network in order to minimize the impact of the security vulnerability until&amp;hellip;</description></item><item><title>SAT20 Labs</title><link>https://0xtracer.xyz/incidents/2024-07-26-sat20-labs/</link><pubDate>Fri, 26 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-26-sat20-labs/</guid><description>On July 26th, the official Twitter account of SAT20 Labs was hacked, and the attacker posted tweets containing links to install malware.</description></item><item><title>MonoSwap</title><link>https://0xtracer.xyz/incidents/2024-07-25-monoswap/</link><pubDate>Thu, 25 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-25-monoswap/</guid><description>Blast ecosystem DEX MonoSwap disclosed on Twitter that the platform has been hacked. Users are advised not to add liquidity or stake. If you have any staking positions, please withdraw them immediately to avoid financ&amp;hellip;</description></item><item><title>Sorta Finance</title><link>https://0xtracer.xyz/incidents/2024-07-25-sorta-finance/</link><pubDate>Thu, 25 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-25-sorta-finance/</guid><description>According to on-chain detective ZachXBT, Sorta Finance is likely to conduct an exit scam on Arbitrum in the future, so do not use the protocol. This scammer has previously stolen over $25 million through scams such as&amp;hellip;</description></item><item><title>TinTinLand</title><link>https://0xtracer.xyz/incidents/2024-07-25-tintinland/</link><pubDate>Thu, 25 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-25-tintinland/</guid><description>According to the SlowMist security team, the community TinTinLand&amp;rsquo;s pinned tweet on July 20 contained a phishing link. With the assistance of the SlowMist security team, TinTinLand promptly resolved the account theft&amp;hellip;</description></item><item><title>DeltaPrime</title><link>https://0xtracer.xyz/incidents/2024-07-23-deltaprime/</link><pubDate>Tue, 23 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-23-deltaprime/</guid><description>On July 23, an attacker exploited a misconfiguration to gain access to $1 million from 13 different Prime accounts. This misconfiguration allowed the attacker to illegitimately transfer ownership of the Prime accounts&amp;hellip;</description></item><item><title>dYdX</title><link>https://0xtracer.xyz/incidents/2024-07-23-dydx/</link><pubDate>Tue, 23 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-23-dydx/</guid><description>On July 23, the dydx.exchange domain was discovered to have been compromised. The attacker changed the DNS Nameservers from Cloudflare to DDoS-Guard. The attacker also successfully removed the DNSSEC settings on the d&amp;hellip;</description></item><item><title>Fake Base Dawgz</title><link>https://0xtracer.xyz/incidents/2024-07-23-fake-base-dawgz/</link><pubDate>Tue, 23 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-23-fake-base-dawgz/</guid><description>The Fake Base Dawgz on Ethereum is suspected of a rug pull, resulting in a loss of over $113,000.</description></item><item><title>Spectra</title><link>https://0xtracer.xyz/incidents/2024-07-23-spectra/</link><pubDate>Tue, 23 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-23-spectra/</guid><description>DeFi protocol Spectra suffered an attack, resulting in a loss of approximately $550,000. Spectra has disabled the application and terminated the router contract to contain the situation, while the core protocol contra&amp;hellip;</description></item><item><title>Kelp DAO</title><link>https://0xtracer.xyz/incidents/2024-07-22-kelp-dao/</link><pubDate>Mon, 22 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-22-kelp-dao/</guid><description>On July 22, 2024, Kelp&amp;rsquo;s DApp began displaying malicious wallet activity transactions aimed at draining funds. Kelp&amp;rsquo;s engineering team evaluated the situation and identified the root cause to be faulty nameservers rou&amp;hellip;</description></item><item><title>Renzo</title><link>https://0xtracer.xyz/incidents/2024-07-22-renzo/</link><pubDate>Mon, 22 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-22-renzo/</guid><description>The liquidity restaking protocol Renzo tweeted that the Renzo Discord server has been compromised by malicious attackers. Please do not click on any links posted in the server.</description></item><item><title>ETHTrustFund</title><link>https://0xtracer.xyz/incidents/2024-07-21-ethtrustfund/</link><pubDate>Sun, 21 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-21-ethtrustfund/</guid><description>ETHTrustFund conducted a rugpull and stole approximately $2 million worth of cryptocurrencies on Base.</description></item><item><title>UPS</title><link>https://0xtracer.xyz/incidents/2024-07-21-ups/</link><pubDate>Sun, 21 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-21-ups/</guid><description>UPS on BNBChain was attacked again, losing about $521K. On April 8th, UPS was previously attacked on BNBChain, losing about $30K.</description></item><item><title>Arbitrum</title><link>https://0xtracer.xyz/incidents/2024-07-20-arbitrum/</link><pubDate>Sat, 20 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-20-arbitrum/</guid><description>The arbitrum.com website appears to have been hacked and is being redirected to the official website of the Meme project MOG. Please stay vigilant and ensure the safety of your assets.</description></item><item><title>Rho Markets</title><link>https://0xtracer.xyz/incidents/2024-07-19-rho-markets/</link><pubDate>Fri, 19 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-19-rho-markets/</guid><description>A misconfiguration in the Rho Markets lending protocol allowed an MEV bot operator to take $7.6 million from the project&amp;rsquo;s users across multiple chains. The MEV bot operator sent an on-chain message indicating their w&amp;hellip;</description></item><item><title>WazirX</title><link>https://0xtracer.xyz/incidents/2024-07-18-wazirx/</link><pubDate>Thu, 18 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-18-wazirx/</guid><description>Safe multisig implementation swapped, Lazarus Group attributed</description></item><item><title>LI.FI</title><link>https://0xtracer.xyz/incidents/2024-07-16-li-fi/</link><pubDate>Tue, 16 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-16-li-fi/</guid><description>According to the monitoring by the SlowMist security team, the cross-chain bridge aggregation protocol LI.FI has experienced suspicious transactions, resulting in user losses of over $10 million. Please revoke approva&amp;hellip;</description></item><item><title>MALOU (NEVER)</title><link>https://0xtracer.xyz/incidents/2024-07-16-malou-never/</link><pubDate>Tue, 16 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-16-malou-never/</guid><description>On BNB Chain, the MALOU (NEVER) token experienced over 99% slippage. The address 0xd7c358b8337d3116f5765060f48C1C71B9908B84 used a backdoor to sell NEVER tokens, obtaining 428 BNB (approximately $240,000), which were&amp;hellip;</description></item><item><title>Minterest</title><link>https://0xtracer.xyz/incidents/2024-07-15-minterest/</link><pubDate>Mon, 15 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-15-minterest/</guid><description>According to Fuzzland co-founder Chaofan Shou, the cross-chain lending protocol Minterest was attacked. The attacker used a flash loan attack, resulting in a loss of approximately $1.4 million for the protocol.</description></item><item><title>Ethena</title><link>https://0xtracer.xyz/incidents/2024-07-14-ethena/</link><pubDate>Sun, 14 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-14-ethena/</guid><description>According to on-chain sleuth ZachXBT, the Ethena Discord server has been hacked. Do not click on any links for the time being.</description></item><item><title>Dough Finance</title><link>https://0xtracer.xyz/incidents/2024-07-12-dough-finance/</link><pubDate>Fri, 12 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-12-dough-finance/</guid><description>Dough Finance was attacked due to a contract vulnerability. Some unauthorized funds were extracted by hackers, resulting in a loss of approximately $2.1 million. Around 76 ETH (approximately $260,000) has been returne&amp;hellip;</description></item><item><title>Unstoppable Domains</title><link>https://0xtracer.xyz/incidents/2024-07-12-unstoppable-domains/</link><pubDate>Fri, 12 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-12-unstoppable-domains/</guid><description>Web3 domain provider Unstoppable Domains stated on Twitter that Unstoppabledomains.com was attacked. Until further notice, please do not open any emails from @unstoppabledomains.com or use the website.</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2024-07-11-compound/</link><pubDate>Thu, 11 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-11-compound/</guid><description>Compound DAO security advisor Michael Lewellen tweeted that the Compound Finance official website (&lt;a href="http://compound.finance">http://compound.finance&lt;/a>) has been compromised and is currently hosting a phishing site. Do not interact with the site&amp;hellip;</description></item><item><title>OpSec</title><link>https://0xtracer.xyz/incidents/2024-07-11-opsec/</link><pubDate>Thu, 11 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-11-opsec/</guid><description>The OpSec staking contract was maliciously upgraded, allowing the attacker to withdraw and sell OPSEC tokens worth approximately 59 ETH (around $182,000).</description></item><item><title>Smart Bank Token (SBT)</title><link>https://0xtracer.xyz/incidents/2024-07-11-smart-bank-token-sbt/</link><pubDate>Thu, 11 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-11-smart-bank-token-sbt/</guid><description>The Smart Bank Token (SBT) contract on BNBChain was attacked, resulting in a loss of approximately $56,000.</description></item><item><title>Wasabi Wallet</title><link>https://0xtracer.xyz/incidents/2024-07-10-wasabi-wallet/</link><pubDate>Wed, 10 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-10-wasabi-wallet/</guid><description>According to a message posted by Wasabi Wallet on Twitter, users have reported that a coordinator named WasabiCoordinator is gradually stealing user funds through a complex attack. Wasabi Wallet advises all users conn&amp;hellip;</description></item><item><title>Doja Cat</title><link>https://0xtracer.xyz/incidents/2024-07-08-doja-cat/</link><pubDate>Mon, 08 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-08-doja-cat/</guid><description>On July 8, rapper Doja Cat&amp;rsquo;s Twitter account was hacked to promote a memecoin. Doja Cat quickly posted on her Instagram account, stating that her Twitter account had been compromised.</description></item><item><title>Linking The World (LW)</title><link>https://0xtracer.xyz/incidents/2024-07-08-linking-the-world-lw/</link><pubDate>Mon, 08 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-08-linking-the-world-lw/</guid><description>According to monitoring by the SlowMist security team, Linking The World (LW) was attacked on BNBChain due to a contract vulnerability, losing approximately $80,000.</description></item><item><title>Interlay</title><link>https://0xtracer.xyz/incidents/2024-07-07-interlay/</link><pubDate>Sun, 07 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-07-interlay/</guid><description>Polkadot issued a warning on Twitter, alerting users that the official Twitter account of Interlay, a cross-chain interoperability project, was compromised and used to post a scam message. Users are advised to be caut&amp;hellip;</description></item><item><title>Authy</title><link>https://0xtracer.xyz/incidents/2024-07-05-authy/</link><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-05-authy/</guid><description>23pds, the CISO at SlowMist, tweeted that the 2FA service Authy has been hacked, resulting in the theft of the phone numbers of 33 million users. If you are an Authy user, please be vigilant against phishing attacks&amp;hellip;.</description></item><item><title>Bittensor</title><link>https://0xtracer.xyz/incidents/2024-07-02-bittensor/</link><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-02-bittensor/</guid><description>On July 2, 2024, the decentralized AI project Bittensor was attacked, resulting in some Bittensor wallet users being compromised. The hackers stole approximately 32,000 TAO tokens, valued at around $8 million. On-chai&amp;hellip;</description></item><item><title>MintRisesPrices</title><link>https://0xtracer.xyz/incidents/2024-07-02-mintrisesprices/</link><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-02-mintrisesprices/</guid><description>MintRisesPrices on BNBChain suffered a reentrancy attack, resulting in a loss of approximately $59,000.</description></item><item><title>Sydney Sweeney</title><link>https://0xtracer.xyz/incidents/2024-07-02-sydney-sweeney/</link><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-02-sydney-sweeney/</guid><description>According to Cointelegraph, the Twitter account of American actress Sydney Sweeney was hacked, with now-deleted posts promoting a crypto token bearing her name in an apparent pump-and-dump scheme.</description></item><item><title>TRUMP (MAGA)</title><link>https://0xtracer.xyz/incidents/2024-07-02-trump-maga/</link><pubDate>Tue, 02 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-02-trump-maga/</guid><description>The Fake TRUMP (MAGA) on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Evolve Bank &amp; Trust</title><link>https://0xtracer.xyz/incidents/2024-07-01-evolve-bank-and-trust/</link><pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-01-evolve-bank-and-trust/</guid><description>On July 1, according to Protos, the crypto-friendly bank Evolve Bank &amp;amp; Trust recently admitted that despite discovering &amp;ldquo;unauthorized activity&amp;rdquo;—specifically, the theft of 33 TB of user data—a month ago, they only publ&amp;hellip;</description></item><item><title>Particle Network</title><link>https://0xtracer.xyz/incidents/2024-07-01-particle-network/</link><pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-07-01-particle-network/</guid><description>According to screenshots shared by X user @bmgentile, the modular chain abstraction Layer 1 project Particle Network issued an official apology statement. They stated that their account email was recently hacked and u&amp;hellip;</description></item><item><title>BorpaToken</title><link>https://0xtracer.xyz/incidents/2024-06-30-borpatoken/</link><pubDate>Sun, 30 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-30-borpatoken/</guid><description>The cross-chain DeFi protocol Entangle announced on X that the official X account of the meme token project BorpaToken, developed by their team, has been compromised. Do not click on any links. The BorpaToken team is&amp;hellip;</description></item><item><title>Cyber</title><link>https://0xtracer.xyz/incidents/2024-06-27-cyber/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-27-cyber/</guid><description>According to Cyber&amp;rsquo;s official Twitter, the Discord server @BuildOnCyber of the decentralized social L2 Cyber (formerly CyberConnect) was compromised. A phishing link was posted in the announcements channel and all per&amp;hellip;</description></item><item><title>APEMAGA</title><link>https://0xtracer.xyz/incidents/2024-06-26-apemaga/</link><pubDate>Wed, 26 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-26-apemaga/</guid><description>APEMAGA on Ethereum suspected to have been attacked, resulting in a loss of approximately $32,000.</description></item><item><title>Metallica</title><link>https://0xtracer.xyz/incidents/2024-06-25-metallica/</link><pubDate>Tue, 25 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-25-metallica/</guid><description>According to Decrypt, the social media account of the renowned heavy metal band Metallica were recently hacked. The hackers used these accounts to promote scam cryptocurrency tokens. Several celebrities were also impl&amp;hellip;</description></item><item><title>DeFiance</title><link>https://0xtracer.xyz/incidents/2024-06-23-defiance/</link><pubDate>Sun, 23 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-23-defiance/</guid><description>Arthur (@Arthur_0x), the founder of DeFiance Capital, posted on X to warn that the official X account of DeFiance Capital has been compromised. Please avoid clicking on any links shared by the account.</description></item><item><title>Ethereum Foundation</title><link>https://0xtracer.xyz/incidents/2024-06-23-ethereum-foundation/</link><pubDate>Sun, 23 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-23-ethereum-foundation/</guid><description>According to the latest official blog post by the Ethereum Foundation, their email account was hacked, and phishing emails were sent to 35,794 recipients. The email falsely claimed that the Foundation was partnering w&amp;hellip;</description></item><item><title>Sportsbet</title><link>https://0xtracer.xyz/incidents/2024-06-23-sportsbet/</link><pubDate>Sun, 23 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-23-sportsbet/</guid><description>According to monitoring by on-chain detective ZachXBT, the online gambling platform Sportsbet was also suspected to be attacked by the same hacker as BtcTurk, resulting in a loss of over $3.5 million.</description></item><item><title>50 Cent</title><link>https://0xtracer.xyz/incidents/2024-06-22-50-cent/</link><pubDate>Sat, 22 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-22-50-cent/</guid><description>The rapper 50 Cent has claimed that his Twitter account and website were hacked to promote a memecoin called GUNIT.</description></item><item><title>BtcTurk</title><link>https://0xtracer.xyz/incidents/2024-06-22-btcturk/</link><pubDate>Sat, 22 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-22-btcturk/</guid><description>The Turkish cryptocurrency exchange BtcTurk has acknowledged that they suffered a hack. The exchange halted deposits and withdrawals while investigating, and said they are working with law enforcement. Furthermore, th&amp;hellip;</description></item><item><title>CoinStats</title><link>https://0xtracer.xyz/incidents/2024-06-22-coinstats/</link><pubDate>Sat, 22 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-22-coinstats/</guid><description>Cryptocurrency portfolio management company CoinStats temporarily suspended user activities after 1,590 crypto wallets were affected by a security incident. CoinStats stated, &amp;ldquo;The attack has been mitigated, and we hav&amp;hellip;</description></item><item><title>Fake CGPT</title><link>https://0xtracer.xyz/incidents/2024-06-21-fake-cgpt/</link><pubDate>Fri, 21 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-21-fake-cgpt/</guid><description>The Fake CGPT on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Dyson</title><link>https://0xtracer.xyz/incidents/2024-06-17-dyson/</link><pubDate>Mon, 17 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-17-dyson/</guid><description>According to monitoring by the SlowMist security team, Dyson on BNBChain was attacked, resulting in a loss of approximately $31,000.</description></item><item><title>WIFCOIN_ETH</title><link>https://0xtracer.xyz/incidents/2024-06-17-wifcoin-eth/</link><pubDate>Mon, 17 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-17-wifcoin-eth/</guid><description>The meme coin WIFCOIN_ETH was suspected to be attacked, with a loss of ~$16K.</description></item><item><title>AutoChain Global</title><link>https://0xtracer.xyz/incidents/2024-06-14-autochain-global/</link><pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-14-autochain-global/</guid><description>AutoChain Global&amp;rsquo;s contract on BNBChain was suspected to be attacked, with a loss of approximately $113,000.</description></item><item><title>Holograph</title><link>https://0xtracer.xyz/incidents/2024-06-14-holograph/</link><pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-14-holograph/</guid><description>The Omnichain NFT protocol Holograph protocol was exploited, resulting in a loss of approximately $14.4 million. According to the team, a former contractor exploited an infinite mint vulnerability in their smart contr&amp;hellip;</description></item><item><title>nftperp</title><link>https://0xtracer.xyz/incidents/2024-06-14-nftperp/</link><pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-14-nftperp/</guid><description>On June 14, NFT perpetual contract trading platform nftperp announced on Twitter that a critical bug had been found in the clearingHouse contract. All vulnerable contracts have been suspended until further notice. On&amp;hellip;</description></item><item><title>UwU Lend</title><link>https://0xtracer.xyz/incidents/2024-06-13-uwu-lend/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-13-uwu-lend/</guid><description>After the attack on June 10, UwU Lend was exploited again by the same attacker, resulting in a loss of $3.72 million. The attacker held a significant amount of USDE tokens obtained from the first attack, which allowed&amp;hellip;</description></item><item><title>JokInTheBoxETH</title><link>https://0xtracer.xyz/incidents/2024-06-10-jokintheboxeth/</link><pubDate>Mon, 10 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-10-jokintheboxeth/</guid><description>MEV Bot JokInTheBoxETH was attacked, lost ~$34K. The root cause of the exploit was poorly implemented unstake function fo the staking contract. Since the unstake function does not check the state of the variable &amp;ldquo;unst&amp;hellip;</description></item><item><title>UwU Lend</title><link>https://0xtracer.xyz/incidents/2024-06-10-uwu-lend/</link><pubDate>Mon, 10 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-10-uwu-lend/</guid><description>On June 10, 2024, according to the security monitoring system MistEye by SlowMist, the digital asset lending platform UwU Lend on the EVM chain was attacked, resulting in a loss of approximately $19.3 million. The att&amp;hellip;</description></item><item><title>YOLO Games</title><link>https://0xtracer.xyz/incidents/2024-06-10-yolo-games/</link><pubDate>Mon, 10 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-10-yolo-games/</guid><description>$1.5 million was stolen from the liquidity pool on the Blast network’s gaming platform YOLO Games. The root cause was the lack of permission checks in the &amp;ldquo;exitPool&amp;rdquo; function, allowing anyone to impersonate liquidity&amp;hellip;</description></item><item><title>Loopring</title><link>https://0xtracer.xyz/incidents/2024-06-09-loopring/</link><pubDate>Sun, 09 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-09-loopring/</guid><description>Ethereum Layer 2 protocol Loopring posted on Twitter that the some Loopring Smart Wallets were targeted in a security breach. The attack exploited wallets with only one Guardian, specifically the Loopring Official Gua&amp;hellip;</description></item><item><title>Lykke</title><link>https://0xtracer.xyz/incidents/2024-06-09-lykke/</link><pubDate>Sun, 09 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-09-lykke/</guid><description>Lykke, the zero-fee crypto exchange, was suspected to be exploited, which resulted in a loss of assets worth over $22.4 million. The root cause of the exploit is unknown at the moment, and the team has yet to acknowle&amp;hellip;</description></item><item><title>Gemholic</title><link>https://0xtracer.xyz/incidents/2024-06-08-gemholic/</link><pubDate>Sat, 08 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-08-gemholic/</guid><description>Gemholic, a crypto project, is accused of a rug pull after moving $3.5M in recently recovered funds and vanishing from social media.</description></item><item><title>SteamSwap (STM)</title><link>https://0xtracer.xyz/incidents/2024-06-07-steamswap-stm/</link><pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-07-steamswap-stm/</guid><description>According to monitoring by the SlowMist security team, SteamSwap(STM) on BNBChain was attacked, resulting in a loss of approximately $105K.</description></item><item><title>TLN Protocol</title><link>https://0xtracer.xyz/incidents/2024-06-07-tln-protocol/</link><pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-07-tln-protocol/</guid><description>According to monitoring by the SlowMist security team, the TLN Protocol on BNBChain has been attacked again. On May 31, TLN Protocol suffered a loss of approximately $280,000 due to a contract vulnerability exploited&amp;hellip;</description></item><item><title>CoinGecko</title><link>https://0xtracer.xyz/incidents/2024-06-05-coingecko/</link><pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-05-coingecko/</guid><description>CoinGecko reported that its third-party email platform GetResponse experienced a data breach on June 5. The compromised data includes users&amp;rsquo; names (if provided during registration), email addresses, IP addresses, and&amp;hellip;</description></item><item><title>Renzo</title><link>https://0xtracer.xyz/incidents/2024-06-05-renzo/</link><pubDate>Wed, 05 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-05-renzo/</guid><description>Renzo&amp;rsquo;s co-founder, Lucas Kozinski, posted a warning on Twitter stating that the @RenzoProtocol Twitter account has been compromised. He advised not to click any links and mentioned that the team is working with Twitt&amp;hellip;</description></item><item><title>NCD</title><link>https://0xtracer.xyz/incidents/2024-06-04-ncd/</link><pubDate>Tue, 04 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-04-ncd/</guid><description>According to monitoring by the SlowMist security team, NCD on BNBChain was attacked, resulting in a loss of approximately $20,000.</description></item><item><title>Velocore</title><link>https://0xtracer.xyz/incidents/2024-06-02-velocore/</link><pubDate>Sun, 02 Jun 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-06-02-velocore/</guid><description>DEX Velocore experienced a security breach on June 2nd, 2024, resulting in financial losses approximating $6.8 million in ETH. The primary cause of the incident was faulty logic within the velocore__execute() function&amp;hellip;</description></item><item><title>DMM Bitcoin</title><link>https://0xtracer.xyz/incidents/2024-05-31-dmm-bitcoin/</link><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-31-dmm-bitcoin/</guid><description>Hot wallet private key compromised, DPRK attributed</description></item><item><title>MixedSwapRouter</title><link>https://0xtracer.xyz/incidents/2024-05-31-mixedswaprouter/</link><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-31-mixedswaprouter/</guid><description>According to monitoring by the SlowMist security team, the MixedSwapRouter on Arbitrum was attacked, resulting in a loss of approximately 293,000 WINR, valued at around $16,000.</description></item><item><title>TLN Protocol</title><link>https://0xtracer.xyz/incidents/2024-05-31-tln-protocol/</link><pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-31-tln-protocol/</guid><description>According to monitoring by the SlowMist security team, the TLN Protocol on BNBChain was attacked, resulting in a loss of approximately $280,000.</description></item><item><title>EXcommunity</title><link>https://0xtracer.xyz/incidents/2024-05-29-excommunity/</link><pubDate>Wed, 29 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-29-excommunity/</guid><description>According to monitoring by the SlowMist security team, EXcommunity on BNBChain is suspected of being attacked, resulting in a loss of approximately $37,000.</description></item><item><title>MetaDragon</title><link>https://0xtracer.xyz/incidents/2024-05-29-metadragon/</link><pubDate>Wed, 29 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-29-metadragon/</guid><description>According to the SlowMist security team, potential suspicious activity has been detected in the GameFi protocol MetaDragon, and users are advised to remain vigilant. MetaDragon stated that users need to convert their&amp;hellip;</description></item><item><title>Orion Protocol</title><link>https://0xtracer.xyz/incidents/2024-05-28-orion-protocol/</link><pubDate>Tue, 28 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-28-orion-protocol/</guid><description>According to the SlowMist security team, the liquidity aggregator protocol Orion&amp;rsquo;s contract was attacked, resulting in a loss of approximately $616,000.</description></item><item><title>Nicola Sebastiani</title><link>https://0xtracer.xyz/incidents/2024-05-27-nicola-sebastiani/</link><pubDate>Mon, 27 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-27-nicola-sebastiani/</guid><description>Sebastiani, co-founder of The Sandbox, posted on X platform that one of The Sandbox team members was hacked and his Twitter account used to send SCAM tweets and DMs, disguised as if these were official.</description></item><item><title>RedKeysGame</title><link>https://0xtracer.xyz/incidents/2024-05-27-redkeysgame/</link><pubDate>Mon, 27 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-27-redkeysgame/</guid><description>According to the SlowMist security team, RedKeysGame on BNBChain was attacked, resulting in a loss of approximately $10,000.</description></item><item><title>Normie</title><link>https://0xtracer.xyz/incidents/2024-05-26-normie/</link><pubDate>Sun, 26 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-26-normie/</guid><description>According to community feedback, the Base ecosystem&amp;rsquo;s meme coin NORMIE has been attacked. The attacker exploited a design flaw in the NORMIE token&amp;rsquo;s cross-chain bridge, manipulating the price on the Base Chain using f&amp;hellip;</description></item><item><title>Rho Markets</title><link>https://0xtracer.xyz/incidents/2024-05-22-rho-markets/</link><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-22-rho-markets/</guid><description>The official Twitter account of Scroll&amp;rsquo;s liquidity layer, Rho Markets, was hacked and posted suspicious links.</description></item><item><title>TonUP</title><link>https://0xtracer.xyz/incidents/2024-05-22-tonup/</link><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-22-tonup/</guid><description>The TON ecosystem Launchpad platform TonUP announced on social media that its recently launched staking contract was attacked, resulting in a loss of 307,264 UP tokens. Upon investigation, it was found that the incide&amp;hellip;</description></item><item><title>YON</title><link>https://0xtracer.xyz/incidents/2024-05-22-yon/</link><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-22-yon/</guid><description>YON on BNBChain was exploited and lost 190 BNB (～$118K) as a result. The vulnerability in the transferFrom function of the target contract (YON) allowed the attacking contract to directly transfer YON to the LP contract.</description></item><item><title>Gala Games</title><link>https://0xtracer.xyz/incidents/2024-05-20-gala-games/</link><pubDate>Mon, 20 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-20-gala-games/</guid><description>On May 20, 2024, the Web3 gaming platform Gala Games was attacked, resulting in a loss of approximately $21.8 million. The attacker minted 5 billion GALA tokens, worth over $200 million, and quickly sold 592 million G&amp;hellip;</description></item><item><title>TCH</title><link>https://0xtracer.xyz/incidents/2024-05-17-tch/</link><pubDate>Fri, 17 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-17-tch/</guid><description>According to the SlowMist security team&amp;rsquo;s monitoring, the TCH token on the BNBChain has been continuously attacked due to a malleability issue, resulting in a loss of approximately $19,000.</description></item><item><title>Fake Notcoin</title><link>https://0xtracer.xyz/incidents/2024-05-16-fake-notcoin/</link><pubDate>Thu, 16 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-16-fake-notcoin/</guid><description>Fake Notcoin on ETH is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>pump.fun</title><link>https://0xtracer.xyz/incidents/2024-05-16-pump-fun/</link><pubDate>Thu, 16 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-16-pump-fun/</guid><description>pump.fun is a Solana-based memecoin generator. On May 16th, the project suffered a $1.9 million exploit by an attacker who then began airdropping the money to somewhat random wallets. pump.fun stated on Twitter that t&amp;hellip;</description></item><item><title>ALEX Lab</title><link>https://0xtracer.xyz/incidents/2024-05-15-alex-lab/</link><pubDate>Wed, 15 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-15-alex-lab/</guid><description>Bitcoin DeFi application ALEX Lab was drained of over $4.3 million in various tokens after a suspected private key compromise attacked its bridging service. Hackers transferred over $300,000 USD worth of BTC, $3.3 mil&amp;hellip;</description></item><item><title>BlockTower Capital</title><link>https://0xtracer.xyz/incidents/2024-05-15-blocktower-capital/</link><pubDate>Wed, 15 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-15-blocktower-capital/</guid><description>BlockTower Capital’s main hedge fund has been compromised and partially drained by fraudsters. The company has $1.7 billion in assets under management. Despite hiring blockchain forensic analysts to investigate the sp&amp;hellip;</description></item><item><title>Equalizer Exchange</title><link>https://0xtracer.xyz/incidents/2024-05-14-equalizer-exchange/</link><pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-14-equalizer-exchange/</guid><description>On May 14th, the decentralized trading protocol Equalizer Exchange within the Fantom ecosystem was suspected to have been attacked. The official team tweeted that they are investigating the incident and advised users&amp;hellip;</description></item><item><title>PI (PI)</title><link>https://0xtracer.xyz/incidents/2024-05-14-pi-pi/</link><pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-14-pi-pi/</guid><description>The PI (PI) on Polygon is suspected of a rug pull, and the current token price has dropped by 100%, causing losses exceeding $490,000.</description></item><item><title>Predy Finance</title><link>https://0xtracer.xyz/incidents/2024-05-14-predy-finance/</link><pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-14-predy-finance/</guid><description>The decentralized exchange Predy Finance on the Arbitrum chain was attacked, resulting in the loss of $464k worth of crypto assets from its lending pool.</description></item><item><title>Sonne Finance</title><link>https://0xtracer.xyz/incidents/2024-05-14-sonne-finance/</link><pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-14-sonne-finance/</guid><description>Based on Compound&amp;rsquo;s Optimism native lending protocol, Sonne Finance has fallen victim to a lightning loan attack by hackers, resulting in losses exceeding $20 million USD.</description></item><item><title>Patton</title><link>https://0xtracer.xyz/incidents/2024-05-13-patton/</link><pubDate>Mon, 13 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-13-patton/</guid><description>Patton on the ETH appears to have exit scammed, resulting in a 100% price drop and causing losses exceeding $260,000.</description></item><item><title>Galaxy Fox</title><link>https://0xtracer.xyz/incidents/2024-05-10-galaxy-fox/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-10-galaxy-fox/</guid><description>According to the monitoring of the SlowMist Security Alert system, the Web3 game project Galaxy Fox has been attacked, resulting in a loss of approximately $300,000.</description></item><item><title>Tsuru</title><link>https://0xtracer.xyz/incidents/2024-05-10-tsuru/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-10-tsuru/</guid><description>According to the SlowMist Security Alert system, potential suspicious activities related to Tsuru have resulted in a loss of 138.78 ETH.</description></item><item><title>Bloom</title><link>https://0xtracer.xyz/incidents/2024-05-09-bloom/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-09-bloom/</guid><description>The Blast ecosystem project Bloom was attacked, resulting in a loss of approximately $540,000. On May 10th, Bloom announced that they had successfully recovered most of the stolen funds. The Bloom team stated that aft&amp;hellip;</description></item><item><title>Fake Lifeform (LFT)</title><link>https://0xtracer.xyz/incidents/2024-05-09-fake-lifeform-lft/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-09-fake-lifeform-lft/</guid><description>Fake Lifeform (LFT) on Ethereum is suspected of an exit scam. The deployer called removeLimits() backdoor to mint additional tokens and dump them on the dex pair to drain 81 ETH (~$243K).</description></item><item><title>NEAR Protocol</title><link>https://0xtracer.xyz/incidents/2024-05-09-near-protocol/</link><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-09-near-protocol/</guid><description>The official Twitter account of the public chain project NEAR Protocol appears to have been compromised. Currently, its profile picture on Twitter has been changed to a solid black image, and its bio has been updated&amp;hellip;</description></item><item><title>GPU</title><link>https://0xtracer.xyz/incidents/2024-05-08-gpu/</link><pubDate>Wed, 08 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-08-gpu/</guid><description>GPU on BNBChain was attacked, with a loss of about $32,000. There is a logic vulnerability in the _transfer function of the contract. When transferring money to yourself, the balance will increase by the amount of the&amp;hellip;</description></item><item><title>GNUS</title><link>https://0xtracer.xyz/incidents/2024-05-06-gnus/</link><pubDate>Mon, 06 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-06-gnus/</guid><description>Fantom ecosystem project GNUS fell victim to an attack, resulting in a loss of approximately $1.27 million. GNUS.ai posted on Twitter: “Due to a recent exploit, a hacker was able to mint fake GNUS tokens on Fantom, tr&amp;hellip;</description></item><item><title>OSN</title><link>https://0xtracer.xyz/incidents/2024-05-06-osn/</link><pubDate>Mon, 06 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-06-osn/</guid><description>OSN on BNBChain is suspected to have been attacked. The attacker initiated multiple attack transactions, resulting in a loss of ~$110K. The attacker took advantage of the OSNLpDividendTracker contract which sells its&amp;hellip;</description></item><item><title>Perpy Finance</title><link>https://0xtracer.xyz/incidents/2024-05-06-perpy-finance/</link><pubDate>Mon, 06 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-06-perpy-finance/</guid><description>The Social Fi project Perpy Finance was attacked. A hacker was able to update the contract and illicitly withdrew 58,489,594 PRY tokens. These were then transferred and exchanged for 41.895 ETH. According to Perpy Fin&amp;hellip;</description></item><item><title>Saturn</title><link>https://0xtracer.xyz/incidents/2024-05-06-saturn/</link><pubDate>Mon, 06 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-06-saturn/</guid><description>Saturn, the new token issuance protocol, was exploited on the BNB chain, which resulted in a loss of 14.16 BNB, worth approximately $8,343. The protocol would reportedly burn and sync the asset amount before any prior&amp;hellip;</description></item><item><title>NOVAMIND_ (NMD)</title><link>https://0xtracer.xyz/incidents/2024-05-02-novamind-nmd/</link><pubDate>Thu, 02 May 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-05-02-novamind-nmd/</guid><description>NOVAMIND_ (NMD) on ETH is suspected of a rug pull. &lt;del>41 ETH (&lt;/del>$123k) was transferred to a multisig and the token price has dropped ~97%.</description></item><item><title>Dune</title><link>https://0xtracer.xyz/incidents/2024-04-30-dune/</link><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-30-dune/</guid><description>The blockchain data analysis platform Dune tweeted that its account was compromised earlier today and a fake post about a Dune Airdrop was live for about 15 minutes. The Dune team now has control over the account again.</description></item><item><title>Pike Finance</title><link>https://0xtracer.xyz/incidents/2024-04-30-pike-finance/</link><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-30-pike-finance/</guid><description>On April 30th, the cross-chain lending protocol Pike Finance tweeted that its Pike Beta protocol had been attacked, resulting in losses of 99,970.48 ARB, 64,126 OP, and 479.39 ETH. The exploit was caused by weak secur&amp;hellip;</description></item><item><title>Yield Protocol</title><link>https://0xtracer.xyz/incidents/2024-04-30-yield-protocol/</link><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-30-yield-protocol/</guid><description>A hacker stole approximately $181,000 worth of crypto assets from Yield’s strategic contracts present on the Arbitrum blockchain. The hacker exploited a discrepancy between the pool token balance and total supply with&amp;hellip;</description></item><item><title>Rain</title><link>https://0xtracer.xyz/incidents/2024-04-29-rain/</link><pubDate>Mon, 29 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-29-rain/</guid><description>Crypto detective ZachXBT stated on his Telegram channel that the Middle Eastern cryptocurrency exchange Rain appears to have been hacked, resulting in a loss of $14.8 million USD. The breach occurred on April 29, 2024&amp;hellip;</description></item><item><title>Ember Sword NFT</title><link>https://0xtracer.xyz/incidents/2024-04-28-ember-sword-nft/</link><pubDate>Sun, 28 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-28-ember-sword-nft/</guid><description>A vulnerability has been detected in the unverified Ember Sword NFT auction that allowed the extraction of 60 WETH, equivalent to approximately $195,000, from 159 victims who approved the contract.</description></item><item><title>xBank Finance</title><link>https://0xtracer.xyz/incidents/2024-04-27-xbank-finance/</link><pubDate>Sat, 27 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-27-xbank-finance/</guid><description>According to feedback from multiple community members, the zkSync ecosystem lending platform @xBankFinance is suspected of a rug pull. Currently, the official account displays that it has been frozen, and the platform&amp;hellip;</description></item><item><title>Fake IO</title><link>https://0xtracer.xyz/incidents/2024-04-26-fake-io/</link><pubDate>Fri, 26 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-26-fake-io/</guid><description>Fake IO on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Pike Finance</title><link>https://0xtracer.xyz/incidents/2024-04-26-pike-finance/</link><pubDate>Fri, 26 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-26-pike-finance/</guid><description>The cross-chain lending protocol Pike Finance tweeted that the USDC pool on Pike Beta has been exploited by a hacker. The total amount of USDC exploited is 299,127. The root cause is led by forged CCTP message to drai&amp;hellip;</description></item><item><title>FENGSHOU (NGFS)</title><link>https://0xtracer.xyz/incidents/2024-04-25-fengshou-ngfs/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-25-fengshou-ngfs/</guid><description>Shortly after the deployment of the FENGSHOU (NGFS) token, it was attacked, resulting in a loss of approximately $191,000. The vulnerability lies in a public &lt;code>delegateCallReserves&lt;/code> function which allows the attacker t&amp;hellip;</description></item><item><title>io.net</title><link>https://0xtracer.xyz/incidents/2024-04-25-io-net/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-25-io-net/</guid><description>io.net founder and CEO Ahmad Shadid announced on social media that io.net&amp;rsquo;s metadata APIs recently experienced a security incident. A malicious party exploited accessible mappings of User IDs to Device IDs, leading to&amp;hellip;</description></item><item><title>YIEDL</title><link>https://0xtracer.xyz/incidents/2024-04-25-yiedl/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-25-yiedl/</guid><description>According to intelligence from the SlowMist Security Team, the YIEDL project on the BSC chain was attacked, with the attacker stealing approximately $300,000. In this incident, the reason lies in the contract’s failur&amp;hellip;</description></item><item><title>Merlin</title><link>https://0xtracer.xyz/incidents/2024-04-24-merlin/</link><pubDate>Wed, 24 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-24-merlin/</guid><description>According to community feedback, the official Discord server of Merlin Chain appears to have been targeted in a hacker attack, where a management account posted a notification containing a phishing link.</description></item><item><title>X Bridge</title><link>https://0xtracer.xyz/incidents/2024-04-24-x-bridge/</link><pubDate>Wed, 24 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-24-x-bridge/</guid><description>The cross-chain bridge X Bridge has experienced multiple suspicious transactions, which are still ongoing. A suspicious address was recently funded by Tornado Cash on BNBChain, then bridged to ETH, and subsequently de&amp;hellip;</description></item><item><title>XBridge</title><link>https://0xtracer.xyz/incidents/2024-04-24-xbridge/</link><pubDate>Wed, 24 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-24-xbridge/</guid><description>The cross-chain bridge project XBridge was exploited due to a smart contract vulnerability on the Ethereum Mainnet and the BNB chain, resulting in a loss of approximately $1.44 million.</description></item><item><title>Fake Safe Token (SAFE)</title><link>https://0xtracer.xyz/incidents/2024-04-23-fake-safe-token-safe/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-23-fake-safe-token-safe/</guid><description>The Fake Safe Token (SAFE) on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Magpie Protocol</title><link>https://0xtracer.xyz/incidents/2024-04-23-magpie-protocol/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-23-magpie-protocol/</guid><description>The decentralized liquidity aggregation protocol Magpie Protocol was attacked due to a contract vulnerability, resulting in $129,000 being stolen from 221 wallets. The root cause is due to unchecked call data. The att&amp;hellip;</description></item><item><title>Velvet Capital</title><link>https://0xtracer.xyz/incidents/2024-04-23-velvet-capital/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-23-velvet-capital/</guid><description>Users reported abnormal activity on the trading platform of the DeFi asset management protocol Velvet Capital on April 23rd. When attempting to connect to the frontend, users were prompted to approve their wallet&amp;rsquo;s ac&amp;hellip;</description></item><item><title>Fake Cruiz (CRUIZ)</title><link>https://0xtracer.xyz/incidents/2024-04-22-fake-cruiz-cruiz/</link><pubDate>Mon, 22 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-22-fake-cruiz-cruiz/</guid><description>The Fake Cruiz (CRUIZ) on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Z123</title><link>https://0xtracer.xyz/incidents/2024-04-22-z123/</link><pubDate>Mon, 22 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-22-z123/</guid><description>Z123 on BSC was attacked by a hacker due to a contract vulnerability, resulting in a loss of approximately $136k. The .update() function of Z123 was repeatedly called which burned extra tokens and inflated the price.</description></item><item><title>ZKasino</title><link>https://0xtracer.xyz/incidents/2024-04-20-zkasino/</link><pubDate>Sat, 20 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-20-zkasino/</guid><description>The decentralized betting platform ZKasino is suspected to have exited. Recently, users on Twitter reported that ZKasino removed the message &amp;ldquo;Ethereum will be returned and can be bridged back&amp;rdquo; from the Bridge Funds in&amp;hellip;</description></item><item><title>Hedgey</title><link>https://0xtracer.xyz/incidents/2024-04-19-hedgey/</link><pubDate>Fri, 19 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-19-hedgey/</guid><description>Hedgey Finance suffered two exploits, one on the Ethereum and another on the Arbitrum network. The ETH attack resulted in a loss of $1.9 million, while the Arbitrum exploit led to a theft of $42.8 million in ARB tokens.</description></item><item><title>Meson Finance</title><link>https://0xtracer.xyz/incidents/2024-04-19-meson-finance/</link><pubDate>Fri, 19 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-19-meson-finance/</guid><description>The Twitter account of the cross-chain bridge Meson Finance posted a tweet containing a phishing link. Meson Finance tweeted that the relevant content has been deleted and confirmed that the issue originated from a th&amp;hellip;</description></item><item><title>PRCL</title><link>https://0xtracer.xyz/incidents/2024-04-17-prcl/</link><pubDate>Wed, 17 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-17-prcl/</guid><description>Fake PRCL on the BNB Chain appears to have exit scammed, resulting in a 100% price drop and causing losses exceeding $100,000.</description></item><item><title>Mars</title><link>https://0xtracer.xyz/incidents/2024-04-16-mars/</link><pubDate>Tue, 16 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-16-mars/</guid><description>Token issuance protocol Mars was attacked and lost about 1M MARS 和 137 个 WBNB.</description></item><item><title>Fake JILLBODEN</title><link>https://0xtracer.xyz/incidents/2024-04-15-fake-jillboden/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-15-fake-jillboden/</guid><description>Fake JILLBODEN on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Fake VDZ</title><link>https://0xtracer.xyz/incidents/2024-04-15-fake-vdz/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-15-fake-vdz/</guid><description>Fake VDZ on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.</description></item><item><title>Grand Base</title><link>https://0xtracer.xyz/incidents/2024-04-15-grand-base/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-15-grand-base/</guid><description>Grand Base, a real world assets platform built on the Base layer-2 blockchain, the team behind the project claimed that the deployer wallet had been compromised, allowing an attacker to drain the project&amp;rsquo;s liquidity p&amp;hellip;</description></item><item><title>GFA token</title><link>https://0xtracer.xyz/incidents/2024-04-14-gfa-token/</link><pubDate>Sun, 14 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-14-gfa-token/</guid><description>The GFA token was exploited on the BNB chain, which resulted in a loss of assets worth approximately $15,000. The root cause of the exploit is a lack of access control. The vulnerable contracts had functions for calcu&amp;hellip;</description></item><item><title>Leaper Finance</title><link>https://0xtracer.xyz/incidents/2024-04-14-leaper-finance/</link><pubDate>Sun, 14 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-14-leaper-finance/</guid><description>According to on-chain analyst ZachXBT&amp;rsquo;s monitoring, the group of scammers who stole 8 figs with Magnate, Kokomo, Lendora, Solfire, etc is back with a new project on Blast @Leaperfinance. Last week they funded an addre&amp;hellip;</description></item><item><title>Fake Masa</title><link>https://0xtracer.xyz/incidents/2024-04-12-fake-masa/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-12-fake-masa/</guid><description>Fake Masa on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Sumer Money</title><link>https://0xtracer.xyz/incidents/2024-04-12-sumer-money/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-12-sumer-money/</guid><description>Sumer Money was exploited on the Base chain due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $310,000. The root cause of the exploit is a lack of reentrancy protection, whi&amp;hellip;</description></item><item><title>Zest Protocol</title><link>https://0xtracer.xyz/incidents/2024-04-12-zest-protocol/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-12-zest-protocol/</guid><description>The Bitcoin-native lending protocol, Zest Protocol twitted that it experienced an attack. The attacker lent out an amount exceeding the value of their collateral by artificially inflating its value. The attack has bee&amp;hellip;</description></item><item><title>Empower AI</title><link>https://0xtracer.xyz/incidents/2024-04-11-empower-ai/</link><pubDate>Thu, 11 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-11-empower-ai/</guid><description>The price of Empower AI (EMPAI) on Ethereum has dropped by 100%. A whale 0xE4808&amp;hellip;f3bA has dumped 1,000,000,000,000 EMPAI for about 66.44 WETH (valued at around $23,750).</description></item><item><title>Fake Monad</title><link>https://0xtracer.xyz/incidents/2024-04-11-fake-monad/</link><pubDate>Thu, 11 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-11-fake-monad/</guid><description>Fake Monad on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake Oasis AI</title><link>https://0xtracer.xyz/incidents/2024-04-10-fake-oasis-ai/</link><pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-10-fake-oasis-ai/</guid><description>Fake Oasis AI on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake Truflation</title><link>https://0xtracer.xyz/incidents/2024-04-10-fake-truflation/</link><pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-10-fake-truflation/</guid><description>Fake Truflation on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Jupiter</title><link>https://0xtracer.xyz/incidents/2024-04-10-jupiter/</link><pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-10-jupiter/</guid><description>Jupiter, a trading aggregator in the Solana ecosystem, tweeted that they noticed a large number of spam bots hitting our RPCs and limited them. Users are advised to try their operations again. The team is working supe&amp;hellip;</description></item><item><title>xBlast</title><link>https://0xtracer.xyz/incidents/2024-04-09-xblast/</link><pubDate>Tue, 09 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-09-xblast/</guid><description>The full-chain Web3 ecosystem xBlast, built inside Telegram, disclosed on Twitter that it had been hacked. The attacker transferred XBL tokens from its project&amp;rsquo;s main wallet address and sold them for approximately 22&amp;hellip;</description></item><item><title>Squid Game (SQUID)</title><link>https://0xtracer.xyz/incidents/2024-04-08-squid-game-squid/</link><pubDate>Mon, 08 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-08-squid-game-squid/</guid><description>Squid Game (SQUID) is a meme token on the BNB chain. On April 8, 2024, the SQUID Game was exploited on the BNB chain due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $87,00&amp;hellip;</description></item><item><title>UPS</title><link>https://0xtracer.xyz/incidents/2024-04-08-ups/</link><pubDate>Mon, 08 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-08-ups/</guid><description>UPS on BNBChain was attacked and lost ~$30K.</description></item><item><title>Wall Street Memes</title><link>https://0xtracer.xyz/incidents/2024-04-07-wall-street-memes/</link><pubDate>Sun, 07 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-07-wall-street-memes/</guid><description>Wall Street Memes (WSM)’s pre-sale contract was attacked, resulting in a loss of ～2.5M WSM, worth of ~$18,000.</description></item><item><title>CondomSOL</title><link>https://0xtracer.xyz/incidents/2024-04-04-condomsol/</link><pubDate>Thu, 04 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-04-condomsol/</guid><description>CondomSOL on Solana has exited, and its Twitter account is no longer accessible. The wallet associated with CondomSOL raised 4,965 SOL, equivalent to approximately $922,000.</description></item><item><title>Robinson Burkey</title><link>https://0xtracer.xyz/incidents/2024-04-04-robinson-burkey/</link><pubDate>Thu, 04 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-04-robinson-burkey/</guid><description>The Twitter account of Wormhole co-founder Robinson Burkey was hacked, and a suspicious link was posted.</description></item><item><title>Avolend Finance</title><link>https://0xtracer.xyz/incidents/2024-04-03-avolend-finance/</link><pubDate>Wed, 03 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-03-avolend-finance/</guid><description>In the Blast ecosystem, the project Avolend Finance is suspected to be a rug pull. Currently, its official website and Twitter account cannot be accessed.</description></item><item><title>OpenLeverage</title><link>https://0xtracer.xyz/incidents/2024-04-01-openleverage/</link><pubDate>Mon, 01 Apr 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-04-01-openleverage/</guid><description>The DeFi protocol OpenLeverage has been attacked, resulting in a loss of approximately $260,000. In light of this, OpenLeverage has decided to discontinue the OpenLeverage trading and lending protocol. OpenLeverage is&amp;hellip;</description></item><item><title>FixedFloat</title><link>https://0xtracer.xyz/incidents/2024-03-31-fixedfloat/</link><pubDate>Sun, 31 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-31-fixedfloat/</guid><description>FixedFloat, a decentralized exchange, tweeted that they have encountered another attack, with hackers exploiting vulnerabilities in their third-party services. The company assured that both company and user funds rema&amp;hellip;</description></item><item><title>Pendle Finance</title><link>https://0xtracer.xyz/incidents/2024-03-30-pendle-finance/</link><pubDate>Sat, 30 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-30-pendle-finance/</guid><description>The founder of yield-trading protocol Pendle Finance tweeted that the team has confirmed being unable to access the official Pendle Twitter account and is currently investigating to resolve the issue. During this peri&amp;hellip;</description></item><item><title>Solareum</title><link>https://0xtracer.xyz/incidents/2024-03-30-solareum/</link><pubDate>Sat, 30 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-30-solareum/</guid><description>The Solana ecosystem is grappling with a spate of drained wallets. A cause has yet to be definitively determined, but some of the thefts were linked to the use of trading bots like Solareum. According to security rese&amp;hellip;</description></item><item><title>Lava</title><link>https://0xtracer.xyz/incidents/2024-03-29-lava/</link><pubDate>Fri, 29 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-29-lava/</guid><description>Lava suffered a flash loan attack, resulting in approximately $340,000 in losses. All lending markets are reportedly paused as the investigation is ongoing.</description></item><item><title>Prisma Finance</title><link>https://0xtracer.xyz/incidents/2024-03-28-prisma-finance/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-28-prisma-finance/</guid><description>Migration contract logic flaw allowed unauthorized withdrawals</description></item><item><title>Decrypt</title><link>https://0xtracer.xyz/incidents/2024-03-27-decrypt/</link><pubDate>Wed, 27 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-27-decrypt/</guid><description>The email newsletter account of Web3 media company Decrypt has been compromised, and a phishing scam email has been sent to all of our subscribers. Please do not click on any links. Currently, the attacker has profite&amp;hellip;</description></item><item><title>Munchables</title><link>https://0xtracer.xyz/incidents/2024-03-27-munchables/</link><pubDate>Wed, 27 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-27-munchables/</guid><description>The Blast ecosystem project Munchables was attacked, resulting in a loss of approximately $62.5 million. On the same day, Blast founder Pacman tweeted: &amp;ldquo;$97m has been secured in a multisig by Blast core contributors&amp;hellip;.</description></item><item><title>ZongZiFa</title><link>https://0xtracer.xyz/incidents/2024-03-25-zongzifa/</link><pubDate>Mon, 25 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-25-zongzifa/</guid><description>The project ZongZiFa on BSC was exploited through a flash loan, resulting in a loss of approximately $229,000. The attacker manipulated the price of ZongZi to gain invitation rewards.</description></item><item><title>Curio Ecosystem</title><link>https://0xtracer.xyz/incidents/2024-03-24-curio-ecosystem/</link><pubDate>Sun, 24 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-24-curio-ecosystem/</guid><description>The RWA infrastructure of the Curio Ecosystem suffered an attack, involving smart contracts based on MakerDAO within its ecosystem. The attacker exploited a permission access logic vulnerability.</description></item><item><title>Lucky Star Currency</title><link>https://0xtracer.xyz/incidents/2024-03-22-lucky-star-currency/</link><pubDate>Fri, 22 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-22-lucky-star-currency/</guid><description>The astrology-based project Lucky Star Currency rug-pulled in October 2023, resulting in a loss of $1.1 million. On March 22, 2024, ownership of the project was transferred to a malicious smart contract, which then dr&amp;hellip;</description></item><item><title>Super Sushi Samurai</title><link>https://0xtracer.xyz/incidents/2024-03-22-super-sushi-samurai/</link><pubDate>Fri, 22 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-22-super-sushi-samurai/</guid><description>The new blockchain game Super Sushi Samurai, based on the Blast layer-2, was attacked due to a vulnerability in its token contract, resulting in a loss of approximately $4.6 million. Shortly after the theft, the attac&amp;hellip;</description></item><item><title>AirDAO</title><link>https://0xtracer.xyz/incidents/2024-03-21-airdao/</link><pubDate>Thu, 21 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-21-airdao/</guid><description>The hackers gained access to AirDAO LP through a social engineering scam and drained the liquidity pool of AMB/ETH. The scam involved an email with a malicious attachment, impersonating one of their known partners. In&amp;hellip;</description></item><item><title>TICKER</title><link>https://0xtracer.xyz/incidents/2024-03-21-ticker/</link><pubDate>Thu, 21 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-21-ticker/</guid><description>TICKER project developer steals $900,000. A developer brought on to run a presale for the TICKER token stole $900,000 from the project. 15% of the token supply was sent to the developer to distribute via an airdrop, b&amp;hellip;</description></item><item><title>Dolomite</title><link>https://0xtracer.xyz/incidents/2024-03-20-dolomite/</link><pubDate>Wed, 20 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-20-dolomite/</guid><description>On March 20th, Dolomite, a decentralized trading protocol in the Arbitrum ecosystem, was attacked due to a vulnerability in its old contracts on the Ethereum mainnet. Approximately 187 victims suffered asset losses to&amp;hellip;</description></item><item><title>LayerSwap</title><link>https://0xtracer.xyz/incidents/2024-03-20-layerswap/</link><pubDate>Wed, 20 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-20-layerswap/</guid><description>The @GoDaddy account for the L2 cross-chain bridge LayerSwap&amp;rsquo;s domain http://layerswap[.]io was compromised. The compromise of the domain led to a phishing site being displayed, resulting in approximately 50 users los&amp;hellip;</description></item><item><title>ParaSwap</title><link>https://0xtracer.xyz/incidents/2024-03-20-paraswap/</link><pubDate>Wed, 20 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-20-paraswap/</guid><description>Decentralized exchange (DEX) aggregator ParaSwap announced the discovery of a critical vulnerability affecting its approved aggregation smart contract Augustus V6. This vulnerability impacts users who have authorized&amp;hellip;</description></item><item><title>Trezor</title><link>https://0xtracer.xyz/incidents/2024-03-20-trezor/</link><pubDate>Wed, 20 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-20-trezor/</guid><description>On the X platform, on-chain investigator ZachXBT reported that the X account of hardware wallet provider Trezor was hacked.</description></item><item><title>TON</title><link>https://0xtracer.xyz/incidents/2024-03-19-ton/</link><pubDate>Tue, 19 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-19-ton/</guid><description>According to on-chain investigator ZachXBT, the X account of TON Blockchain has been compromised.</description></item><item><title>Fake Ansem</title><link>https://0xtracer.xyz/incidents/2024-03-17-fake-ansem/</link><pubDate>Sun, 17 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-17-fake-ansem/</guid><description>According to blockchain investigator ZachXBT, an account impersonating Solana ecosystem KOL Ansem (@blknoiz06) capitalized on the recent meme coin craze to profit over $2.6 million through phishing.</description></item><item><title>Remilia</title><link>https://0xtracer.xyz/incidents/2024-03-17-remilia/</link><pubDate>Sun, 17 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-17-remilia/</guid><description>The treasury of Remilia, the parent company of Milady, has been drained, with assets from multiple official Remilia wallets being transferred and sold. The hot wallet and multi-signature treasury of Remilia&amp;rsquo;s parent c&amp;hellip;</description></item><item><title>Wilder World</title><link>https://0xtracer.xyz/incidents/2024-03-16-wilder-world/</link><pubDate>Sat, 16 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-16-wilder-world/</guid><description>The deployer wallet of the NFT marketplace Wilder World was attacked, and ownership was transferred to the attacker. Following a malicious upgrade, the attacker withdrew WILD and MEOW tokens and converted them into ap&amp;hellip;</description></item><item><title>MOBOX</title><link>https://0xtracer.xyz/incidents/2024-03-15-mobox/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-15-mobox/</guid><description>The DeFi protocol MOBOX was attacked due to a vulnerability in the borrow function, resulting in a loss of approximately $750,000.</description></item><item><title>Mozaic</title><link>https://0xtracer.xyz/incidents/2024-03-15-mozaic/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-15-mozaic/</guid><description>The DeFi project Mozaic was exploited, who stole approximately $2 million from the project. According to Mozaic, this individual was a Mozaic developer who had illegally obtained the private keys of a security module&amp;hellip;</description></item><item><title>NFPrompt</title><link>https://0xtracer.xyz/incidents/2024-03-15-nfprompt/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-15-nfprompt/</guid><description>The AI-driven UGC platform NFPrompt, aimed at the next generation of content creators, disclosed on Twitter that they have experienced a security breach. Hackers infiltrated several wallets, including the wallet of th&amp;hellip;</description></item><item><title>Introspection Token</title><link>https://0xtracer.xyz/incidents/2024-03-14-introspection-token/</link><pubDate>Thu, 14 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-14-introspection-token/</guid><description>On March 14, 2024, according to intelligence from the SlowMist security team, the IT token on the BSC was attacked, with the attacker profiting approximately $15,200. The attacker exploited the transfer function in th&amp;hellip;</description></item><item><title>Cloud AI</title><link>https://0xtracer.xyz/incidents/2024-03-13-cloud-ai/</link><pubDate>Wed, 13 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-13-cloud-ai/</guid><description>The AI service provider Cloud AI reported that both their deployer and treasury account have been compromised by hackers. The attackers acquired 58,900 CloudAI tokens and some ETH. All CloudAI tokens have been exchang&amp;hellip;</description></item><item><title>beoble</title><link>https://0xtracer.xyz/incidents/2024-03-12-beoble/</link><pubDate>Tue, 12 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-12-beoble/</guid><description>The Twitter account of Web3 chat solution beoble has been compromised, with phishing links being posted. Please refrain from clicking on any links until further notice is provided by the official team.</description></item><item><title>Polyhedra</title><link>https://0xtracer.xyz/incidents/2024-03-12-polyhedra/</link><pubDate>Tue, 12 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-12-polyhedra/</guid><description>Polyhedra was exploited due to the compromise of the private keys, which resulted in a loss of 1,400,323 THENA tokens worth approximately $760,000. The contract was maliciously upgraded following the leakage of the pr&amp;hellip;</description></item><item><title>BLASTOFF</title><link>https://0xtracer.xyz/incidents/2024-03-11-blastoff/</link><pubDate>Mon, 11 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-11-blastoff/</guid><description>The Blast ecosystem&amp;rsquo;s LaunchPad and yield aggregator BLASTOFF announced that its Future Yield Minter Vault has been hacked, resulting in the theft of approximately 150 ETH (approximately $600,000). The official team h&amp;hellip;</description></item><item><title>Unizen</title><link>https://0xtracer.xyz/incidents/2024-03-09-unizen/</link><pubDate>Sat, 09 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-09-unizen/</guid><description>The Unizen defi platform lost around $2.1 million in the Tether stablecoin in an attack that took advantage of a vulnerability an external call from the project smart contract. On March 12th, Unizen&amp;rsquo;s CTO Martin Grans&amp;hellip;</description></item><item><title>FLOKIAI (FLOKIAI)</title><link>https://0xtracer.xyz/incidents/2024-03-08-flokiai-flokiai/</link><pubDate>Fri, 08 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-08-flokiai-flokiai/</guid><description>FLOKIAI (FLOKIAI) on the BNB Chain appears to have exit scammed. The address starting with 0xFe54 has exchanged 268,561,795,727,990.23 FLOKIAI tokens for approximately 316.4 BNB, valued at around $148,000.</description></item><item><title>HumanizedAi (HMZ)</title><link>https://0xtracer.xyz/incidents/2024-03-08-humanizedai-hmz/</link><pubDate>Fri, 08 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-08-humanizedai-hmz/</guid><description>HumanizedAi (HMZ) is suspected to have exited scam, with the project team profiting 173 ETH (approximately $665,000). The project&amp;rsquo;s Twitter account and website have been shut down.</description></item><item><title>ClosedAI (ClosedAI)</title><link>https://0xtracer.xyz/incidents/2024-03-07-closedai-closedai/</link><pubDate>Thu, 07 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-07-closedai-closedai/</guid><description>ClosedAI (ClosedAI) appears to have exit scammed on the BNB Chain. The address starting with 0xFe54 has exchanged 277,635,327,881,198.25 ClosedAI tokens for approximately 307.3 BNB, valued at around $13,100.</description></item><item><title>TGBS (TGBS)</title><link>https://0xtracer.xyz/incidents/2024-03-06-tgbs-tgbs/</link><pubDate>Wed, 06 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-06-tgbs-tgbs/</guid><description>On March 6, TGBS (TGBS) was exploited through a flash loan attack, resulting in a loss of approximately $151k.</description></item><item><title>OrdiZK</title><link>https://0xtracer.xyz/incidents/2024-03-05-ordizk/</link><pubDate>Tue, 05 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-05-ordizk/</guid><description>OrdiZK advertized themselves as a privacy bridge between the Ethereum network and Bitcoin, has exited, resulting in approximately $1.4 million in losses.</description></item><item><title>Sherlock</title><link>https://0xtracer.xyz/incidents/2024-03-05-sherlock/</link><pubDate>Tue, 05 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-05-sherlock/</guid><description>The Twitter account of the security company @sherlockdefi was hacked, with the attackers using the account to post a tweet containing phishing links.</description></item><item><title>WOOFi</title><link>https://0xtracer.xyz/incidents/2024-03-05-woofi/</link><pubDate>Tue, 05 Mar 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-03-05-woofi/</guid><description>The sPMM algorithm controlling the pricing of WOOFi trades on DEX WOOFi was exploited on Arbitrum. The exploit consisted of a sequence of flash loans that took advantage of low liquidity to manipulate the price of WOO&amp;hellip;</description></item><item><title>Grayscale Capital</title><link>https://0xtracer.xyz/incidents/2024-02-29-grayscale-capital/</link><pubDate>Thu, 29 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-29-grayscale-capital/</guid><description>Capital Killer, an anti-capitalist hacker group, revealed on twitter that they have attacked the Grayscale official website, claiming it as a gift to the AVAV community in support of fairness and anti-capitalism. Curr&amp;hellip;</description></item><item><title>Shido Network</title><link>https://0xtracer.xyz/incidents/2024-02-29-shido-network/</link><pubDate>Thu, 29 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-29-shido-network/</guid><description>The decentralized cross-chain protocol Shido Network on the Ethereum blockchain appears to be a rug pull. The owner of the SHIDO token staking contract first upgraded the staking contract, then withdrew a large amount&amp;hellip;</description></item><item><title>Seneca</title><link>https://0xtracer.xyz/incidents/2024-02-28-seneca/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-28-seneca/</guid><description>On February 28th, a vulnerability was discovered in the contract of Seneca, an omnichain CDP protocol on the Ethereum network. Hackers exploited constructed calldata parameters to call transferfrom, transferring token&amp;hellip;</description></item><item><title>Serenity Shield</title><link>https://0xtracer.xyz/incidents/2024-02-28-serenity-shield/</link><pubDate>Wed, 28 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-28-serenity-shield/</guid><description>Blockchain data storage protocol Serenity Shield tweeted that the MetaMask wallet associated with the project has been compromised. According to blockchain detective ZachXBT, Serenity Shield was robbed of 6.9 million&amp;hellip;</description></item><item><title>Aleo</title><link>https://0xtracer.xyz/incidents/2024-02-26-aleo/</link><pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-26-aleo/</guid><description>Aleo, a blockchain project that advertises it&amp;rsquo;s a place for &amp;ldquo;fully private applications&amp;rdquo; with &amp;ldquo;built-in privacy&amp;rdquo; has just emailed private identification documents — including selfies and photographs of government iden&amp;hellip;</description></item><item><title>MicroStrategy</title><link>https://0xtracer.xyz/incidents/2024-02-26-microstrategy/</link><pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-26-microstrategy/</guid><description>The Twitter account of MicroStrategy, the largest public holder of BTC, appears to have been compromised, with phishing airdrop links being posted. According to on-chain detective ZachXBT, the incident has resulted in&amp;hellip;</description></item><item><title>RiskOnBlast</title><link>https://0xtracer.xyz/incidents/2024-02-25-riskonblast/</link><pubDate>Sun, 25 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-25-riskonblast/</guid><description>RiskOnBlast, a gambling and trading platform on the new ethereum layer-2 Blast blockchain, appears to be a rug pull. On February 25, the platform drained more than 420 ETH (~$1.3 million) from more than 750 user walle&amp;hellip;</description></item><item><title>Tornado Cash</title><link>https://0xtracer.xyz/incidents/2024-02-25-tornado-cash/</link><pubDate>Sun, 25 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-25-tornado-cash/</guid><description>SlowMist founder Cos tweeted that there is a backdoor code in the Tornado Cash IPFS version frontend that hijacks deposit certificates. A governance attack led to malicious proposals being passed, and the malicious co&amp;hellip;</description></item><item><title>ZoomerCoin</title><link>https://0xtracer.xyz/incidents/2024-02-24-zoomercoin/</link><pubDate>Sat, 24 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-24-zoomercoin/</guid><description>ZoomerCoin on Ethereum suffered a flash loan attack, resulting in a loss of 14.06 ETH (~ $41k).</description></item><item><title>Avalanche</title><link>https://0xtracer.xyz/incidents/2024-02-23-avalanche/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-23-avalanche/</guid><description>On February 23rd, the Avalanche mainnet experienced block production interruptions. Addressing this issue, Ava Labs co-founder Kevin Sekniqi stated on Twitter that the problem appears to be a gossip-related mempool ma&amp;hellip;</description></item><item><title>BitForex</title><link>https://0xtracer.xyz/incidents/2024-02-23-bitforex/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-23-bitforex/</guid><description>On February 23, 2024, Hong Kong-based cryptocurrency exchange BitForex was suspected of an exit scam after approximately $56.5 million in suspicious fund outflows were detected across multiple blockchains. The platfor&amp;hellip;</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2024-02-23-compound/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-23-compound/</guid><description>On the evening of February 23rd, UNI experienced a sudden price surge, causing Compound to fail in promptly updating UNI&amp;rsquo;s price. As a result, the protocol used an incorrect price provided by Uniswap&amp;rsquo;s TWAP (Time-Weig&amp;hellip;</description></item><item><title>Jihoz</title><link>https://0xtracer.xyz/incidents/2024-02-23-jihoz/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-23-jihoz/</guid><description>Axie Infinity co-founder Jihoz tweeted that his personal two addresses have been compromised. The attack is limited to his personal accounts and is unrelated to the validation or operation of the Ronin chain. Addition&amp;hellip;</description></item><item><title>Blueberry Protocol</title><link>https://0xtracer.xyz/incidents/2024-02-22-blueberry-protocol/</link><pubDate>Thu, 22 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-22-blueberry-protocol/</guid><description>Integer rounding error in borrow logic exploited, whitehat rescued funds</description></item><item><title>ARPA</title><link>https://0xtracer.xyz/incidents/2024-02-20-arpa/</link><pubDate>Tue, 20 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-20-arpa/</guid><description>The official Twitter account of ARPA, a permissionless threshold network based on the BLS signature scheme, has been compromised, and false token claiming links have been posted.</description></item><item><title>Rugged Art</title><link>https://0xtracer.xyz/incidents/2024-02-19-rugged-art/</link><pubDate>Mon, 19 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-19-rugged-art/</guid><description>The ERC 404 project Rugged Art was attacked due to a reentrancy vulnerability, resulting in a loss of 11 ETH.</description></item><item><title>Starcoin</title><link>https://0xtracer.xyz/incidents/2024-02-18-starcoin/</link><pubDate>Sun, 18 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-18-starcoin/</guid><description>On February 18th, Starcoin, a project within the Move ecosystem, tweeted that they detected abnormal activities on their network that required immediate attention to safeguard the integrity and security of the system&amp;hellip;.</description></item><item><title>FixedFloat</title><link>https://0xtracer.xyz/incidents/2024-02-16-fixedfloat/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-16-fixedfloat/</guid><description>Hot wallet drained via compromised infrastructure</description></item><item><title>xPET</title><link>https://0xtracer.xyz/incidents/2024-02-16-xpet/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-16-xpet/</guid><description>The CEO of SocialFi xPET tweeted that SocialFi was attacked due to vulnerabilities related to the newly launched PvP feature, resulting in hackers stealing 91.5 ETH (approximately $25,400).</description></item><item><title>Duelbits</title><link>https://0xtracer.xyz/incidents/2024-02-14-duelbits/</link><pubDate>Wed, 14 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-14-duelbits/</guid><description>The hot wallet of the crypto gambling platform Duelbits was attacked, resulting in a loss of approximately $4.6 million.</description></item><item><title>Miner（MINER）</title><link>https://0xtracer.xyz/incidents/2024-02-14-miner-miner/</link><pubDate>Wed, 14 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-14-miner-miner/</guid><description>The ERC-X protocol Miner (MINER) has been attacked, please do not interact. According to the Miner team&amp;rsquo;s analysis, the _update function of the contract was exploited. The root cause of this exploit is a double-transf&amp;hellip;</description></item><item><title>Keith Grossman</title><link>https://0xtracer.xyz/incidents/2024-02-09-keith-grossman/</link><pubDate>Fri, 09 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-09-keith-grossman/</guid><description>Keith Grossman, the president of MoonPay, currently has a compromised X account distributing wallet drainer links.</description></item><item><title>Not Found (404)</title><link>https://0xtracer.xyz/incidents/2024-02-09-not-found-404/</link><pubDate>Fri, 09 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-09-not-found-404/</guid><description>The Not Found (404) project on ETH is suspected to have exited with losses of approximately $156,000, as the deployer withdrew a large amount of liquidity.</description></item><item><title>PlayDapp</title><link>https://0xtracer.xyz/incidents/2024-02-09-playdapp/</link><pubDate>Fri, 09 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-09-playdapp/</guid><description>Attacker gained minter role and minted 1.79B PLA tokens</description></item><item><title>Starlay Finance</title><link>https://0xtracer.xyz/incidents/2024-02-08-starlay-finance/</link><pubDate>Thu, 08 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-08-starlay-finance/</guid><description>A critical security incident within the Starlay protocol’s USDC lending pool on the Acala EVM platform. An exploit was identified and executed due to abnormal behavior in the liquidity index calculation mechanism, whi&amp;hellip;</description></item><item><title>Detto Finance</title><link>https://0xtracer.xyz/incidents/2024-02-02-detto-finance/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-02-detto-finance/</guid><description>The project Detto Finance in the Base ecosystem is suspected of a rug pull, with its social media accounts currently inaccessible, resulting in approximately $95,000 in losses.</description></item><item><title>Phantom</title><link>https://0xtracer.xyz/incidents/2024-02-02-phantom/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-02-02-phantom/</guid><description>The user-friendly crypto wallet designed for DeFi and NFTs, Phantom, reported a DDoS attack on its platform. Someone attempted to overload its systems, causing potential temporary interruptions in some services. User&amp;hellip;</description></item><item><title>Chris Larsen</title><link>https://0xtracer.xyz/incidents/2024-01-31-chris-larsen/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-31-chris-larsen/</guid><description>On January 31st, according to blockchain investigator ZachXBT, Ripple fell victim to a hacking attack resulting in the theft of 213 million XRP, valued at approximately $112.5 million. Ripple&amp;rsquo;s co-founder, Chris Larse&amp;hellip;</description></item><item><title>Klaytn</title><link>https://0xtracer.xyz/incidents/2024-01-31-klaytn/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-31-klaytn/</guid><description>Klaytn, the South Korean public blockchain, tweeted a reminder to users that its official Discord server has been attacked. Until further notice, please refrain from clicking on any links or interacting with any posts&amp;hellip;</description></item><item><title>ZeroLend</title><link>https://0xtracer.xyz/incidents/2024-01-31-zerolend/</link><pubDate>Wed, 31 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-31-zerolend/</guid><description>The lending market ZeroLend has experienced a DDoS attack.</description></item><item><title>Abracadabra Money</title><link>https://0xtracer.xyz/incidents/2024-01-30-abracadabra-money/</link><pubDate>Tue, 30 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-30-abracadabra-money/</guid><description>GMX v1 integration reentrancy via cauldron contract callback</description></item><item><title>Masa</title><link>https://0xtracer.xyz/incidents/2024-01-30-masa/</link><pubDate>Tue, 30 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-30-masa/</guid><description>The official Twitter account of zk-data marketplace Masa is suspected to be compromised, and fake airdrop links have been posted.</description></item><item><title>Andrei Grachev</title><link>https://0xtracer.xyz/incidents/2024-01-29-andrei-grachev/</link><pubDate>Mon, 29 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-29-andrei-grachev/</guid><description>DWF Labs tweeted that the Twitter account of their managing partner, Andrei Grachev, has been compromised.</description></item><item><title>Barley Finance</title><link>https://0xtracer.xyz/incidents/2024-01-29-barley-finance/</link><pubDate>Mon, 29 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-29-barley-finance/</guid><description>Barley Finance tweeted that there has been a vulnerability attack on the wBARL pod. The team is working on resolving the issue. Details are as follows: 1. The exploiter took more than 10% of the total BARL supply in t&amp;hellip;</description></item><item><title>Goledo Finance</title><link>https://0xtracer.xyz/incidents/2024-01-28-goledo-finance/</link><pubDate>Sun, 28 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-28-goledo-finance/</guid><description>GoledoFinance on Conflux was attacked, with a loss of 7.9m $CFX ($1.7M). The Goledo team has completed the initial investigation of the large borrowings in the lending pool. The team has determined that the issue is r&amp;hellip;</description></item><item><title>Wall Street Memes</title><link>https://0xtracer.xyz/incidents/2024-01-28-wall-street-memes/</link><pubDate>Sun, 28 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-28-wall-street-memes/</guid><description>The Wall Street Memes token was subject to a coordinated attack. The hackers exploited a vulnerability with their staking provider and accessed the $WSM staking contract.</description></item><item><title>Citadel Finance</title><link>https://0xtracer.xyz/incidents/2024-01-27-citadel-finance/</link><pubDate>Sat, 27 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-27-citadel-finance/</guid><description>Citadel Finance was exploited on the Arbitrum chain, which resulted in a loss of 43 ETH, worth approximately $93,000. The root cause of the exploit is price manipulation of the underlying assets.</description></item><item><title>Citadel.one</title><link>https://0xtracer.xyz/incidents/2024-01-27-citadel-one/</link><pubDate>Sat, 27 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-27-citadel-one/</guid><description>Portfolio management tool Citadel.one has been attacked, resulting in a loss of approximately $93K.</description></item><item><title>Somesing</title><link>https://0xtracer.xyz/incidents/2024-01-27-somesing/</link><pubDate>Sat, 27 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-27-somesing/</guid><description>South Korean Web3 social music service Somesing announced that it fell victim to a security vulnerability attack last Saturday, resulting in a loss of 730 million native tokens (SSX), equivalent to approximately $11.5&amp;hellip;</description></item><item><title>AltLayer</title><link>https://0xtracer.xyz/incidents/2024-01-26-altlayer/</link><pubDate>Fri, 26 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-26-altlayer/</guid><description>AltLayer, a temporary extension layer built on Optimistic Rollups, tweeted that early this morning, its Twitter profile was not displaying past tweets on the timeline. After approximately 3 hours of handling, the acco&amp;hellip;</description></item><item><title>Staci Warden</title><link>https://0xtracer.xyz/incidents/2024-01-26-staci-warden/</link><pubDate>Fri, 26 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-26-staci-warden/</guid><description>The Algorand Foundation tweeted that the Twitter account of Staci Warden (@StaciW_DC), the CEO of the Foundation, has been compromised.</description></item><item><title>Nebula Revelation</title><link>https://0xtracer.xyz/incidents/2024-01-25-nebula-revelation/</link><pubDate>Thu, 25 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-25-nebula-revelation/</guid><description>On January 25th, the staking contract of the space-themed open-world Web3 game Nebula Revelation suffered a reentrancy attack. On January 28th, Nebula Revelation announced a compensation plan of 159,831 USDT. The team&amp;hellip;</description></item><item><title>Saga DAO</title><link>https://0xtracer.xyz/incidents/2024-01-25-saga-dao/</link><pubDate>Thu, 25 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-25-saga-dao/</guid><description>Saga DAO, a community-run fan club for Solana&amp;rsquo;s sellout mobile phone fell victim to a hacker attack, resulting in a theft of 750 SOL, equivalent to approximately $60,000. On February 2nd, SagaDAO tweeted that all fund&amp;hellip;</description></item><item><title>JohnLennonC0IN (BEATLES)</title><link>https://0xtracer.xyz/incidents/2024-01-24-johnlennonc0in-beatles/</link><pubDate>Wed, 24 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-24-johnlennonc0in-beatles/</guid><description>JohnLennonC0IN (BEATLES) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>GMEE</title><link>https://0xtracer.xyz/incidents/2024-01-23-gmee/</link><pubDate>Tue, 23 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-23-gmee/</guid><description>The blockchain gaming platform GMEE has announced via Twitter that the GMEE token contract on Polygon experienced unauthorized GitLab access a few hours ago, resulting in the theft of 600 million GMEE tokens. Subseque&amp;hellip;</description></item><item><title>Bullran Index</title><link>https://0xtracer.xyz/incidents/2024-01-22-bullran-index/</link><pubDate>Mon, 22 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-22-bullran-index/</guid><description>Bullran Index was attacked due to a lack of permission control. An MEV bot was able to burn the BUI tokens that a user deposited into a custom safe contract and exploit the lack of permission control to extract 136 ETH.</description></item><item><title>Concentric Finance</title><link>https://0xtracer.xyz/incidents/2024-01-22-concentric-finance/</link><pubDate>Mon, 22 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-22-concentric-finance/</guid><description>The DeFi protocol Concentric Finance, built on the Camelot v3 protocol, has suffered a severe security breach. In an official post on social media, Concentric.fi stated that the security breach due to a targeted socia&amp;hellip;</description></item><item><title>HTX</title><link>https://0xtracer.xyz/incidents/2024-01-19-htx/</link><pubDate>Fri, 19 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-19-htx/</guid><description>Tron founder Justin Sun tweeted that Htx.com and HTX_DAO have been attacked by DDoS attack. The official HTX Twitter account also mentioned that the HTX application is currently experiencing interruptions, and the tec&amp;hellip;</description></item><item><title>CRONUS (CRONUS)</title><link>https://0xtracer.xyz/incidents/2024-01-18-cronus-cronus/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-cronus-cronus/</guid><description>CRONUS (CRONUS) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>LongNoseDog (LONG)</title><link>https://0xtracer.xyz/incidents/2024-01-18-longnosedog-long/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-longnosedog-long/</guid><description>LongNoseDog (LONG) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Manta Pacific</title><link>https://0xtracer.xyz/incidents/2024-01-18-manta-pacific/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-manta-pacific/</guid><description>According to a tweet from Manta Network, the Manta Pacific chain encountered an RPC attack at approximately 9 AM UTC. Kenny Li, co-founder of Manta Network (@superanonymousk), provided updates on Twitter regarding the&amp;hellip;</description></item><item><title>Miguel Morel</title><link>https://0xtracer.xyz/incidents/2024-01-18-miguel-morel/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-miguel-morel/</guid><description>Arkham official announced on Twitter that its CEO, Miguel Morel, fell victim to a SIM card swap attack. Miguel Morel&amp;rsquo;s Twitter account was compromised.</description></item><item><title>Poldo (POLDO)</title><link>https://0xtracer.xyz/incidents/2024-01-18-poldo-poldo/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-poldo-poldo/</guid><description>BSC 上的 Poldo (POLDO) 疑跑路，部署者撤走了大量流动性，导致价格下跌 100%。</description></item><item><title>Rosa Finance</title><link>https://0xtracer.xyz/incidents/2024-01-18-rosa-finance/</link><pubDate>Thu, 18 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-18-rosa-finance/</guid><description>The decentralized, non-custodial liquidity market protocol Rosa Finance on Arbitrum was exploited, resulting in a loss of approximately $45,000.</description></item><item><title>BasketDAO</title><link>https://0xtracer.xyz/incidents/2024-01-17-basketdao/</link><pubDate>Wed, 17 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-17-basketdao/</guid><description>The crypto index project BasketDAO was exploited on the Ethereum Mainnet due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $107,000. The root cause of the exploit is an arbi&amp;hellip;</description></item><item><title>Trezor</title><link>https://0xtracer.xyz/incidents/2024-01-17-trezor/</link><pubDate>Wed, 17 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-17-trezor/</guid><description>Trezor, the manufacturer of encrypted hardware wallets, has announced that it is currently investigating a security incident that occurred on January 17, 2024. Unauthorized access was detected to the third-party suppo&amp;hellip;</description></item><item><title>BorzoiCoin (BORZOI)</title><link>https://0xtracer.xyz/incidents/2024-01-16-borzoicoin-borzoi/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-borzoicoin-borzoi/</guid><description>BorzoiCoin (BORZOI) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>FoxFunnies (FXN)</title><link>https://0xtracer.xyz/incidents/2024-01-16-foxfunnies-fxn/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-foxfunnies-fxn/</guid><description>FoxFunnies (FXN) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Hector Network</title><link>https://0xtracer.xyz/incidents/2024-01-16-hector-network/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-hector-network/</guid><description>Another $2.7 million is gone after an apparent thief was able to exploit a smart contract that was intended to distribute payouts to Hector&amp;rsquo;s token holders. They then swapped the tokens from the USDC stablecoin to ETH&amp;hellip;</description></item><item><title>MOE (MOE)</title><link>https://0xtracer.xyz/incidents/2024-01-16-moe-moe/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-moe-moe/</guid><description>MOE (MOE) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>PulseXIncentiveToken (INC)</title><link>https://0xtracer.xyz/incidents/2024-01-16-pulsexincentivetoken-inc/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-pulsexincentivetoken-inc/</guid><description>PulseXIncentiveToken (INC) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Socket</title><link>https://0xtracer.xyz/incidents/2024-01-16-socket/</link><pubDate>Tue, 16 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-16-socket/</guid><description>The interoperability protocol Socket tweeted that the protocol experienced a security incident. An attacker exploited a vulnerability on a newly added module under the Socket Aggregator system. The module was responsi&amp;hellip;</description></item><item><title>Audify (AUDI)</title><link>https://0xtracer.xyz/incidents/2024-01-15-audify-audi/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-audify-audi/</guid><description>Audify (AUDI) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>BoxyDude (BOX)</title><link>https://0xtracer.xyz/incidents/2024-01-15-boxydude-box/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-boxydude-box/</guid><description>BoxyDude (BOX) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>MAR3AI (MAR3)</title><link>https://0xtracer.xyz/incidents/2024-01-15-mar3ai-mar3/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-mar3ai-mar3/</guid><description>MAR3AI (MAR3) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>SolDragon (DRAGON)</title><link>https://0xtracer.xyz/incidents/2024-01-15-soldragon-dragon/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-soldragon-dragon/</guid><description>SolDragon (DRAGON) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Speero (SPEERO)</title><link>https://0xtracer.xyz/incidents/2024-01-15-speero-speero/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-speero-speero/</guid><description>Speero (SPEERO) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>StarkPepe (SPEPE)</title><link>https://0xtracer.xyz/incidents/2024-01-15-starkpepe-spepe/</link><pubDate>Mon, 15 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-15-starkpepe-spepe/</guid><description>StarkPepe (SPEPE) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>ZKFair</title><link>https://0xtracer.xyz/incidents/2024-01-12-zkfair/</link><pubDate>Fri, 12 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-12-zkfair/</guid><description>The community-driven ZK L2 network ZKFair&amp;rsquo;s official Discord has been hacked.Do not click any links until the team regain control of the server.</description></item><item><title>CoinGecko</title><link>https://0xtracer.xyz/incidents/2024-01-11-coingecko/</link><pubDate>Thu, 11 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-11-coingecko/</guid><description>Independent crypto data aggregator CoinGecko&amp;rsquo;s Twitter accounts @CoinGecko and @GeckoTerminal was compromised. One of their team members clicked on a fraudulent Calendly link by accident, granting unauthorized app acc&amp;hellip;</description></item><item><title>Wise Lending</title><link>https://0xtracer.xyz/incidents/2024-01-11-wise-lending/</link><pubDate>Thu, 11 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-11-wise-lending/</guid><description>The @Wise_Lending market was exploited today, resulting in &lt;del>177 ETH loss (&lt;/del>$464K). Our initial analysis shows the share accounting logic is flawed with a precision issue to drain the market funds.</description></item><item><title>ElonTroll (ElonTroll)</title><link>https://0xtracer.xyz/incidents/2024-01-10-elontroll-elontroll/</link><pubDate>Wed, 10 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-10-elontroll-elontroll/</guid><description>Fake ElonTroll on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>XAI</title><link>https://0xtracer.xyz/incidents/2024-01-10-xai/</link><pubDate>Wed, 10 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-10-xai/</guid><description>A Rug Pull occurred with the XAI token on the BNB Chain, where the deployer dumped 20,779 billion XAI tokens, making a profit of approximately $220,000.</description></item><item><title>SEC</title><link>https://0xtracer.xyz/incidents/2024-01-09-sec/</link><pubDate>Tue, 09 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-09-sec/</guid><description>The U.S. Securities and Exchange Commission (SEC) stated on Monday in a release that its Twitter account was compromised on January 9th due to an unauthorized party gaining control of the associated phone number throu&amp;hellip;</description></item><item><title>MangoFarm</title><link>https://0xtracer.xyz/incidents/2024-01-07-mangofarm/</link><pubDate>Sun, 07 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-07-mangofarm/</guid><description>The MangoFarm project is suspected of a rug pull. The official Twitter account of the MangoFarm is no longer accessible.</description></item><item><title>Aragon Network DAO</title><link>https://0xtracer.xyz/incidents/2024-01-06-aragon-network-dao/</link><pubDate>Sat, 06 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-06-aragon-network-dao/</guid><description>Aragon Network DAO recently found itself targeted in a cryptocurrency scam, resulting in a substantial loss of approximately 800,000 USDC. The attack employed a multi-faceted approach, combining counterfeit ERC-20 tok&amp;hellip;</description></item><item><title>Coinspaid</title><link>https://0xtracer.xyz/incidents/2024-01-06-coinspaid/</link><pubDate>Sat, 06 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-06-coinspaid/</guid><description>Cryptocurrency payment service provider Coinspaid experienced multiple unauthorized transactions, with hackers stealing cryptocurrency assets worth $7.5 million.</description></item><item><title>Olaf</title><link>https://0xtracer.xyz/incidents/2024-01-06-olaf/</link><pubDate>Sat, 06 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-06-olaf/</guid><description>According to a report by Cointelegraph, the cryptocurrency venture capital firm Polychain Capital has confirmed that its founder and CEO, Olaf Carlson-Wee, has had his Twitter account compromised. Hackers have posted&amp;hellip;</description></item><item><title>XKingdom Tech</title><link>https://0xtracer.xyz/incidents/2024-01-06-xkingdom-tech/</link><pubDate>Sat, 06 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-06-xkingdom-tech/</guid><description>The SocialFi and GameFi platform XKingdom Tech, built on Arbitrum, has exit-scammed, resulting in approximately $1.2 million in losses. The stolen funds were bridged to Ethereum and transferred to Tornado Cash.</description></item><item><title>CertiK</title><link>https://0xtracer.xyz/incidents/2024-01-05-certik/</link><pubDate>Fri, 05 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-05-certik/</guid><description>The Twitter account of the security firm CertiK was compromised. The attackers posted false information claiming that the Uniswap router contract is vulnerable to a reentrancy attack, along with phishing links. Subseq&amp;hellip;</description></item><item><title>Narwhal</title><link>https://0xtracer.xyz/incidents/2024-01-05-narwhal/</link><pubDate>Fri, 05 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-05-narwhal/</guid><description>The liquidity mining project Narwhal’s token experienced two considerable drops within a two day period leading to an overall slippage of approximately 99%. The project’s official X account @Narwhal_fyi, announced tha&amp;hellip;</description></item><item><title>Chronos</title><link>https://0xtracer.xyz/incidents/2024-01-04-chronos/</link><pubDate>Thu, 04 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-04-chronos/</guid><description>Liquidity layer &amp;amp; AMM Chronos tweeted that its concentrated liquidity pools managed by @dyson_money have been exploited in a manner similar to the gamma exploit. Users are advised to revoke contracts associated with t&amp;hellip;</description></item><item><title>Gamma</title><link>https://0xtracer.xyz/incidents/2024-01-04-gamma/</link><pubDate>Thu, 04 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-04-gamma/</guid><description>The liquidity management protocol Gamma has been attacked, and its post-mortem indicates that there was a flaw in the deposit agent configuration. This flaw allowed the attacker to manipulate the price up to the price&amp;hellip;</description></item><item><title>Atomicals Market</title><link>https://0xtracer.xyz/incidents/2024-01-02-atomicals-market/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-02-atomicals-market/</guid><description>Atomicals Market (Marketplace and Explorer for Atomicals and ARC-20) tweeted that they&amp;rsquo;re currently under ddos attacks.</description></item><item><title>Radiant Capital (Jan)</title><link>https://0xtracer.xyz/incidents/2024-01-02-radiant-capital-jan/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-02-radiant-capital-jan/</guid><description>Empty market manipulation via rounding error in index calculation</description></item><item><title>Wizz Wallet</title><link>https://0xtracer.xyz/incidents/2024-01-02-wizz-wallet/</link><pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-02-wizz-wallet/</guid><description>Wizz Wallet, the wallet of the Atomicals protocol, posted on Twitter that builders within the Atomicals ecosystem, including the Wizz team, have experienced DDoS attacks.</description></item><item><title>NFPrompt</title><link>https://0xtracer.xyz/incidents/2024-01-01-nfprompt/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-01-nfprompt/</guid><description>NFPrompt announced on its social media platform that the team detected issues with Web2 wallet service. They assured users about the security of their funds and recommended using self-custodied Web3 wallets. For users&amp;hellip;</description></item><item><title>Wabalaba Land</title><link>https://0xtracer.xyz/incidents/2024-01-01-wabalaba-land/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2024-01-01-wabalaba-land/</guid><description>A global IP of FREE Digital Collectibles, Art and community Wabalaba Land&amp;rsquo;s Discord has been compromised. Do not click any links until the team regain control of the server.</description></item><item><title>Orbit Chain</title><link>https://0xtracer.xyz/incidents/2023-12-31-orbit-chain/</link><pubDate>Sun, 31 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-31-orbit-chain/</guid><description>Cross-chain bridge signer keys compromised on New Year&amp;rsquo;s Eve</description></item><item><title>Channels Finance</title><link>https://0xtracer.xyz/incidents/2023-12-30-channels-finance/</link><pubDate>Sat, 30 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-30-channels-finance/</guid><description>ChannelsFinance on BSC was attacked, resulting in losses of over $320K. The contract uses an old Compound v2 protocol which has a known vulnerability.</description></item><item><title>Compound Labs</title><link>https://0xtracer.xyz/incidents/2023-12-30-compound-labs/</link><pubDate>Sat, 30 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-30-compound-labs/</guid><description>DeFi lending protocol Compound Labs tweeted that their account was compromised yesterday for ~4 hours until they regained control of the account and removed the spam messages.</description></item><item><title>OKX</title><link>https://0xtracer.xyz/incidents/2023-12-30-okx/</link><pubDate>Sat, 30 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-30-okx/</guid><description>OKX Wallet BRC20 marketplace has experienced a vulnerability where a large number of fake sats are displayed in the order book. Users are advised to immediately cease trading sats to avoid purchasing false assets and&amp;hellip;</description></item><item><title>INSC NFT</title><link>https://0xtracer.xyz/incidents/2023-12-29-insc-nft/</link><pubDate>Fri, 29 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-29-insc-nft/</guid><description>There is a vulnerability in the INSC NFT contract, and multiple hackers have exploited it to steal NFTs and transfer them to Blur and OpenSea for sale. According to Blur market data, the floor price of INSC (ins-20) h&amp;hellip;</description></item><item><title>Fake FomoFi (FOMO) Token</title><link>https://0xtracer.xyz/incidents/2023-12-28-fake-fomofi-fomo-token/</link><pubDate>Thu, 28 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-28-fake-fomofi-fomo-token/</guid><description>Fake FomoFi (FOMO) on BNB Chain is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake NFPrompt (NFP)</title><link>https://0xtracer.xyz/incidents/2023-12-28-fake-nfprompt-nfp/</link><pubDate>Thu, 28 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-28-fake-nfprompt-nfp/</guid><description>Fake NFPrompt (NFP) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Libra Protocol</title><link>https://0xtracer.xyz/incidents/2023-12-28-libra-protocol/</link><pubDate>Thu, 28 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-28-libra-protocol/</guid><description>The inscription project Libra Protocol on Arbitrum is suspected to have exit scammed. Currently, the project team has transferred the received mint fees to the address 0x0c12acc8e53c6ff7ab3fad5eaa97056ae950288f.</description></item><item><title>NebulaNode (NNNN)</title><link>https://0xtracer.xyz/incidents/2023-12-28-nebulanode-nnnn/</link><pubDate>Thu, 28 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-28-nebulanode-nnnn/</guid><description>NebulaNode (NNNN) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Sleepless AI (AI)</title><link>https://0xtracer.xyz/incidents/2023-12-28-sleepless-ai-ai/</link><pubDate>Thu, 28 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-28-sleepless-ai-ai/</guid><description>Sleepless AI (AI) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Thunder</title><link>https://0xtracer.xyz/incidents/2023-12-27-thunder/</link><pubDate>Wed, 27 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-27-thunder/</guid><description>Multi-chain trading platform Thunder suffered an attack. Thunder responded by stating that a third-party service it uses appears to have been targeted. No one&amp;rsquo;s private keys are compromised. Only 114 wallets out of ov&amp;hellip;</description></item><item><title>MegabotETH</title><link>https://0xtracer.xyz/incidents/2023-12-26-megaboteth/</link><pubDate>Tue, 26 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-26-megaboteth/</guid><description>MegabotETH is suspected of a rug pull. Approximately 742k has been stolen.</description></item><item><title>Pike Finance</title><link>https://0xtracer.xyz/incidents/2023-12-26-pike-finance/</link><pubDate>Tue, 26 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-26-pike-finance/</guid><description>Pike Finance, a cross-chain lending protocol on Base, is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Telcoin</title><link>https://0xtracer.xyz/incidents/2023-12-26-telcoin/</link><pubDate>Tue, 26 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-26-telcoin/</guid><description>Recently, Telcoin Wallet was subjected to a targeted attack, and Telcoin tweeted that it is aware of the situation with the Telcoin app. Use of the app has been temporarily frozen while the issue is investigated and a&amp;hellip;</description></item><item><title>Ordinal Dex (ORDEX)</title><link>https://0xtracer.xyz/incidents/2023-12-25-ordinal-dex-ordex/</link><pubDate>Mon, 25 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-25-ordinal-dex-ordex/</guid><description>Ordinal Dex (ORDEX) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Pine Protocol</title><link>https://0xtracer.xyz/incidents/2023-12-22-pine-protocol/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-22-pine-protocol/</guid><description>PineProtocol seems to have been exploited. According to SlowMist&amp;rsquo;s analysis, the exploiter&amp;rsquo;s IP is 116.&lt;em>.&lt;/em>.112. The exploiter has withdrawn ETH from FixedFloat and ChangeNOW, and has transferred 20 ETH to TornadoCash&amp;hellip;.</description></item><item><title>UniSat Wallet</title><link>https://0xtracer.xyz/incidents/2023-12-22-unisat-wallet/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-22-unisat-wallet/</guid><description>UniSat Wallet&amp;rsquo;s official tweet is suspected to have been hacked.It posted a promotional tweet for a program with closed comments and a suspected malicious link.</description></item><item><title>INX</title><link>https://0xtracer.xyz/incidents/2023-12-20-inx/</link><pubDate>Wed, 20 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-20-inx/</guid><description>The INX Digital Company, a security token and digital asset trading platform, announced that on December 20, 2023, it learned of a cyberattack that occurred on the computer systems of a third-party vendor providing se&amp;hellip;</description></item><item><title>0xKofi</title><link>https://0xtracer.xyz/incidents/2023-12-18-0xkofi/</link><pubDate>Mon, 18 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-18-0xkofi/</guid><description>@0xKofi&amp;rsquo;s Twitter account has been hacked; please do not click on the scam link.</description></item><item><title>Metakey</title><link>https://0xtracer.xyz/incidents/2023-12-18-metakey/</link><pubDate>Mon, 18 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-18-metakey/</guid><description>Metakey&amp;rsquo;s Discord has been compromised. Do not click the link in announcements.</description></item><item><title>Flooring Protocol</title><link>https://0xtracer.xyz/incidents/2023-12-17-flooring-protocol/</link><pubDate>Sun, 17 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-17-flooring-protocol/</guid><description>On December 17th, according to SlowMist Cos, Flooring Protocol may have been subjected to a hacker attack, and users are advised to promptly revoke contract authorizations. In a tweet on December 17th, Flooring Protoc&amp;hellip;</description></item><item><title>NFT Trader</title><link>https://0xtracer.xyz/incidents/2023-12-16-nft-trader/</link><pubDate>Sat, 16 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-16-nft-trader/</guid><description>Old contract reentrancy exploited to drain high-value NFTs</description></item><item><title>Ledger Connect Kit</title><link>https://0xtracer.xyz/incidents/2023-12-14-ledger-connect-kit/</link><pubDate>Thu, 14 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-14-ledger-connect-kit/</guid><description>the Ledger Connect Kit suffered a supply chain attack, with attackers stealing at least $600,000. The SlowMist security team immediately initiated an analysis of the relevant code and discovered that the attackers imp&amp;hellip;</description></item><item><title>Levana</title><link>https://0xtracer.xyz/incidents/2023-12-13-levana/</link><pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-13-levana/</guid><description>The perpetual contract on Osmosis, Levana, has been subjected to an attack resulting in a loss exceeding $1.14 million. A post-incident report provided by its team indicates that between December 13th and December 26t&amp;hellip;</description></item><item><title>OKX</title><link>https://0xtracer.xyz/incidents/2023-12-13-okx/</link><pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-13-okx/</guid><description>According to information from SlowMist Zone, the OKX DEX contract appears to have encountered an issue. After SlowMist&amp;rsquo;s analysis, it was found that when users exchange, they authorize the TokenApprove contract, and t&amp;hellip;</description></item><item><title>Peapods Finance</title><link>https://0xtracer.xyz/incidents/2023-12-13-peapods-finance/</link><pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-13-peapods-finance/</guid><description>On December 13th, Peapods Finance was hacked by white hat hackers due to a reentrancy vulnerability. On December 14th, Peapods Finance tweeted that the hackers returned 90% of the funds. On December 15th, the hacker,&amp;hellip;</description></item><item><title>stoic_DAO</title><link>https://0xtracer.xyz/incidents/2023-12-11-stoic-dao/</link><pubDate>Mon, 11 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-11-stoic-dao/</guid><description>There is a price slippage on project stoic_DAO. 10% of the total Zeta token supply was swapped for ~91 ETH.</description></item><item><title>Venus Protocol</title><link>https://0xtracer.xyz/incidents/2023-12-11-venus-protocol/</link><pubDate>Mon, 11 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-11-venus-protocol/</guid><description>According to on-chain data, a user deposited 0.5 BNB into Venus and borrowed a series of assets, including stkBNB, ankrBNB, etc. The user then exchanged them for 116.45 ETH assets and transferred them to another accou&amp;hellip;</description></item><item><title>Abattoir of Zir (DIABLO)</title><link>https://0xtracer.xyz/incidents/2023-12-07-abattoir-of-zir-diablo/</link><pubDate>Thu, 07 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-07-abattoir-of-zir-diablo/</guid><description>Abattoir of Zir (DIABLO) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Time</title><link>https://0xtracer.xyz/incidents/2023-12-07-time/</link><pubDate>Thu, 07 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-07-time/</guid><description>On December 7, 2023, Time on the ETH were attacked due to a security vulnerability in the thirdweb pre-built smart contracts, which resulted in approximately $190,000 in profits for the attacker.</description></item><item><title>Xai</title><link>https://0xtracer.xyz/incidents/2023-12-07-xai/</link><pubDate>Thu, 07 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-07-xai/</guid><description>Xai, a Layer 3 solution for AAA gaming, has issued an alert for phishing impersonating Xai, where attackers have fraudulently obtained approximately $374 ETH, valued at approximately $845.8K.</description></item><item><title>Strong Finance (STRONG)</title><link>https://0xtracer.xyz/incidents/2023-12-06-strong-finance-strong/</link><pubDate>Wed, 06 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-06-strong-finance-strong/</guid><description>Strong Finance (STRONG) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>CKD Token (CKD)</title><link>https://0xtracer.xyz/incidents/2023-12-05-ckd-token-ckd/</link><pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-05-ckd-token-ckd/</guid><description>CKD Token (CKD) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>thirdweb</title><link>https://0xtracer.xyz/incidents/2023-12-05-thirdweb/</link><pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-05-thirdweb/</guid><description>On December 5, 2023, thirdweb, the Web3 base development platform, indicated that a security vulnerability was discovered in pre-built smart contracts. The impacted pre-built contracts include but are not limited to D&amp;hellip;</description></item><item><title>Stargate Snapshot</title><link>https://0xtracer.xyz/incidents/2023-12-04-stargate-snapshot/</link><pubDate>Mon, 04 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-04-stargate-snapshot/</guid><description>A Discord Mod on LayerZero has reported that a scammer who introduced a phishing link within a proposal vote on the Stargate Snapshot platform, enticing users to stake $STG tokens. Over 1K users took part in the vote,&amp;hellip;</description></item><item><title>FCN-TRUST (FCN)</title><link>https://0xtracer.xyz/incidents/2023-12-01-fcn-trust-fcn/</link><pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-01-fcn-trust-fcn/</guid><description>The FCN-TRUST (FCN) token On BSC was exploited for over $504k in a flash loan attack. The attack caused the token price to crash by 99%.</description></item><item><title>MYX Finance (QMYX)</title><link>https://0xtracer.xyz/incidents/2023-12-01-myx-finance-qmyx/</link><pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-12-01-myx-finance-qmyx/</guid><description>MYX Finance (QMYX) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Aerodrome</title><link>https://0xtracer.xyz/incidents/2023-11-29-aerodrome/</link><pubDate>Wed, 29 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-29-aerodrome/</guid><description>Aerodrome tweeted that the frontend is currently compromised, please do not interact with Aerodrome for the time being, the team is investigating.</description></item><item><title>HOUNAX</title><link>https://0xtracer.xyz/incidents/2023-11-29-hounax/</link><pubDate>Wed, 29 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-29-hounax/</guid><description>Virtual Asset Platform HOUNAX Investigated for Fraud. On November 1, HOUNAX was placed by the Hong Kong Securities and Futures Commission (SFC) on a warning list of &amp;ldquo;Suspicious Virtual Asset Trading Platforms,&amp;rdquo; which&amp;hellip;</description></item><item><title>Velodrome</title><link>https://0xtracer.xyz/incidents/2023-11-29-velodrome/</link><pubDate>Wed, 29 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-29-velodrome/</guid><description>Optimism decentralized trading protocol Velodrome tweeted that the frontend is currently compromised, please do not interact with Velodrome for the time being, the team is investigating. On December 1, Velodrome poste&amp;hellip;</description></item><item><title>AssetClub (ACC)</title><link>https://0xtracer.xyz/incidents/2023-11-28-assetclub-acc/</link><pubDate>Tue, 28 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-28-assetclub-acc/</guid><description>AssetClub (ACC) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Symbiogenesis (SYSIS)</title><link>https://0xtracer.xyz/incidents/2023-11-28-symbiogenesis-sysis/</link><pubDate>Tue, 28 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-28-symbiogenesis-sysis/</guid><description>Symbiogenesis (SYSIS) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Expanso (EXPSO)</title><link>https://0xtracer.xyz/incidents/2023-11-27-expanso-expso/</link><pubDate>Mon, 27 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-27-expanso-expso/</guid><description>Expanso (EXPSO) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Jewels (JWL)</title><link>https://0xtracer.xyz/incidents/2023-11-24-jewels-jwl/</link><pubDate>Fri, 24 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-24-jewels-jwl/</guid><description>CJewels (JWL) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>AISurf (AISC)</title><link>https://0xtracer.xyz/incidents/2023-11-23-aisurf-aisc/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-aisurf-aisc/</guid><description>AISurf (AISC) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Changpeng Zhao (CZ)</title><link>https://0xtracer.xyz/incidents/2023-11-23-changpeng-zhao-cz/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-changpeng-zhao-cz/</guid><description>Changpeng Zhao (CZ) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Creso (CRE)</title><link>https://0xtracer.xyz/incidents/2023-11-23-creso-cre/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-creso-cre/</guid><description>Creso (CRE) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>DarkProtocol (DARK)</title><link>https://0xtracer.xyz/incidents/2023-11-23-darkprotocol-dark/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-darkprotocol-dark/</guid><description>DarkProtocol (DARK) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>DigiFund (DFUND)</title><link>https://0xtracer.xyz/incidents/2023-11-23-digifund-dfund/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-digifund-dfund/</guid><description>DigiFund (DFUND) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake TrustPad (TPAD)</title><link>https://0xtracer.xyz/incidents/2023-11-23-fake-trustpad-tpad/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-fake-trustpad-tpad/</guid><description>Fake TrustPad (TPAD) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>GigaDAO (GIGS)</title><link>https://0xtracer.xyz/incidents/2023-11-23-gigadao-gigs/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-gigadao-gigs/</guid><description>Dor (DOR) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>InfStones</title><link>https://0xtracer.xyz/incidents/2023-11-23-infstones/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-infstones/</guid><description>Lido officials say that over the course of the last 24 hours, Lido DAO contributors were made aware of a platform vulnerability that affected an active Node Operator using the Lido on Ethereum protocol (InfStones) som&amp;hellip;</description></item><item><title>IPMB (IPMB)</title><link>https://0xtracer.xyz/incidents/2023-11-23-ipmb-ipmb/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-ipmb-ipmb/</guid><description>IPMB (IPMB) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Kyber Network</title><link>https://0xtracer.xyz/incidents/2023-11-23-kyber-network/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-kyber-network/</guid><description>Kyber Network tweeted that KyberSwap Elastic has experienced a security incident. According to the analysis of the SlowMist security team, the root cause of this attack is that in calculating the number of tokens need&amp;hellip;</description></item><item><title>PAPABEAR (PAPA)</title><link>https://0xtracer.xyz/incidents/2023-11-23-papabear-papa/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-papabear-papa/</guid><description>PAPABEAR (PAPA) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>RepubliK (RPK)</title><link>https://0xtracer.xyz/incidents/2023-11-23-republik-rpk/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-republik-rpk/</guid><description>RepubliK (RPK) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Web (WEB)</title><link>https://0xtracer.xyz/incidents/2023-11-23-web-web/</link><pubDate>Thu, 23 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-23-web-web/</guid><description>Web (WEB) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>HECO Bridge</title><link>https://0xtracer.xyz/incidents/2023-11-22-heco-bridge/</link><pubDate>Wed, 22 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-22-heco-bridge/</guid><description>HTX/HECO bridge operator keys compromised, concurrent HTX hack</description></item><item><title>KyberSwap</title><link>https://0xtracer.xyz/incidents/2023-11-22-kyberswap/</link><pubDate>Wed, 22 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-22-kyberswap/</guid><description>Concentrated liquidity tick boundary double-counting manipulation</description></item><item><title>CredixFinance (CREDIX)</title><link>https://0xtracer.xyz/incidents/2023-11-21-credixfinance-credix/</link><pubDate>Tue, 21 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-21-credixfinance-credix/</guid><description>CredixFinance (CREDIX) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Dor (DOR)</title><link>https://0xtracer.xyz/incidents/2023-11-21-dor-dor/</link><pubDate>Tue, 21 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-21-dor-dor/</guid><description>Dor (DOR) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Loopring</title><link>https://0xtracer.xyz/incidents/2023-11-20-loopring/</link><pubDate>Mon, 20 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-20-loopring/</guid><description>Loopring&amp;rsquo;s Twitter account has been hacked; please do not click on the phishing link.</description></item><item><title>dYdX</title><link>https://0xtracer.xyz/incidents/2023-11-18-dydx/</link><pubDate>Sat, 18 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-18-dydx/</guid><description>About $9m from the dYdX v3 insurance fund were used to fill gaps on liquidations processed in the YFI market, and the CEO said this was pretty clearly a targeted attack against dYdX, including market manipulation of t&amp;hellip;</description></item><item><title>Kronos Research</title><link>https://0xtracer.xyz/incidents/2023-11-18-kronos-research/</link><pubDate>Sat, 18 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-18-kronos-research/</guid><description>Unauthorized API key access drained trading firm funds</description></item><item><title>SpookySwap</title><link>https://0xtracer.xyz/incidents/2023-11-18-spookyswap/</link><pubDate>Sat, 18 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-18-spookyswap/</guid><description>DEX SpookySwap on Fantom tweeted that the team is investigating a frontend vulnerability on their domain. Please do not execute any transactions on the DEX. On November 19, Spooky updated that a 3rd party JavaScript p&amp;hellip;</description></item><item><title>Trader Joe</title><link>https://0xtracer.xyz/incidents/2023-11-18-trader-joe/</link><pubDate>Sat, 18 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-18-trader-joe/</guid><description>Trader Joe, the largest native DEX on Avalanche, tweeted that the team&amp;rsquo;s preliminary analysis identified a potential exploit in a 3rd party analytics plugin hacked JavaScript code used by the frontend.</description></item><item><title>Lendora Protocol</title><link>https://0xtracer.xyz/incidents/2023-11-15-lendora-protocol/</link><pubDate>Wed, 15 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-15-lendora-protocol/</guid><description>Lendora Protocol on Scroll is suspected of an exit scam. The website is now offline and the contracts were paused.</description></item><item><title>PIPI (PIPI)</title><link>https://0xtracer.xyz/incidents/2023-11-15-pipi-pipi/</link><pubDate>Wed, 15 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-15-pipi-pipi/</guid><description>PIPI (PIPI) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 99.92% price decline.</description></item><item><title>BABYFIDO (BABYFIDO)</title><link>https://0xtracer.xyz/incidents/2023-11-14-babyfido-babyfido/</link><pubDate>Tue, 14 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-14-babyfido-babyfido/</guid><description>BABYFIDO (BABYFIDO) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Builders NFT (BuiLDerS)</title><link>https://0xtracer.xyz/incidents/2023-11-14-builders-nft-builders/</link><pubDate>Tue, 14 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-14-builders-nft-builders/</guid><description>Builders NFT (BuiLDerS) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Exzo Network</title><link>https://0xtracer.xyz/incidents/2023-11-14-exzo-network/</link><pubDate>Tue, 14 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-14-exzo-network/</guid><description>Exzo Network tweeted that a recent security breach targeted Exzo ($XZO), resulting from a compromised owner/admin account. The malicious group utilized the compromised admin wallet to transfer the &amp;lsquo;ownership&amp;rsquo; role of&amp;hellip;</description></item><item><title>Raft Protocol</title><link>https://0xtracer.xyz/incidents/2023-11-11-raft-protocol/</link><pubDate>Sat, 11 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-11-raft-protocol/</guid><description>The stablecoin protocol Raft protocol on Ethereum was attacked and lost about $3.3 million in ETH.</description></item><item><title>Samudai</title><link>https://0xtracer.xyz/incidents/2023-11-11-samudai/</link><pubDate>Sat, 11 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-11-samudai/</guid><description>The multisignature wallet addresses of the DAO project Samudai and the wallet of its founder appear to have been compromised, resulting in a loss of approximately $1.25 million.</description></item><item><title>Poloniex</title><link>https://0xtracer.xyz/incidents/2023-11-10-poloniex/</link><pubDate>Fri, 10 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-10-poloniex/</guid><description>Multiple chain hot wallets drained, Lazarus Group suspected</description></item><item><title>God Of Wealth (GOW39)</title><link>https://0xtracer.xyz/incidents/2023-11-09-god-of-wealth-gow39/</link><pubDate>Thu, 09 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-09-god-of-wealth-gow39/</guid><description>God Of Wealth (GOW39) is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>CoinSpot</title><link>https://0xtracer.xyz/incidents/2023-11-08-coinspot/</link><pubDate>Wed, 08 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-08-coinspot/</guid><description>On November 8, 2023, CoinSpot was exploited across two of its hot wallets, resulting in a loss of over 1,283 ETH, worth approximately $2.472 million.</description></item><item><title>Mirage Finance</title><link>https://0xtracer.xyz/incidents/2023-11-08-mirage-finance/</link><pubDate>Wed, 08 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-08-mirage-finance/</guid><description>Mirage Finance has been exploited for ~$12K, $MRG has dropped 54%.</description></item><item><title>MEV Bot</title><link>https://0xtracer.xyz/incidents/2023-11-07-mev-bot/</link><pubDate>Tue, 07 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-07-mev-bot/</guid><description>The MEV Bot (0x05f016765c6c601fd05a10dba1abe21a04f924a5) was exploited and lost about 1k ETH! The core reason is that the 0xf6ebebbb function used to trigger arbitrage in the contract lacks authentication. The attacke&amp;hellip;</description></item><item><title>TheStandard.io</title><link>https://0xtracer.xyz/incidents/2023-11-07-thestandard-io/</link><pubDate>Tue, 07 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-07-thestandard-io/</guid><description>On November 7, TheStandard.io was exploited for ~$290k. The key vulnerability here was the low liquidity in the PAXG pool, which the attacker exploited to manipulate the market. On November 9, 243k $EUROs has been ret&amp;hellip;</description></item><item><title>TrustPad</title><link>https://0xtracer.xyz/incidents/2023-11-06-trustpad/</link><pubDate>Mon, 06 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-06-trustpad/</guid><description>Multi-chain launchpad platform TrustPad tweeted that one of the staking contracts was attacked. According to SlowMist&amp;rsquo;s analysis, the lock time was manipulated due to obtaining an incorrect LockStartTime.</description></item><item><title>Fake Ledger Live Web3</title><link>https://0xtracer.xyz/incidents/2023-11-05-fake-ledger-live-web3/</link><pubDate>Sun, 05 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-05-fake-ledger-live-web3/</guid><description>A fake Ledger Live app on the official Microsoft App Store which was resulted in 16.8+ BTC ($588K) stolen.</description></item><item><title>Tellor</title><link>https://0xtracer.xyz/incidents/2023-11-03-tellor/</link><pubDate>Fri, 03 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-03-tellor/</guid><description>Tellor&amp;rsquo;s Twitter account was compromised, and the hacker posted a phishing link related to the $TRB airdrop.</description></item><item><title>Fake Celestia (TIA)</title><link>https://0xtracer.xyz/incidents/2023-11-01-fake-celestia-tia/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-01-fake-celestia-tia/</guid><description>Fake Celestia (TIA) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 99.5% price decline.</description></item><item><title>Fake Memecoin (MEME)</title><link>https://0xtracer.xyz/incidents/2023-11-01-fake-memecoin-meme/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-01-fake-memecoin-meme/</guid><description>Fake Memecoin (MEME) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Frax Finance</title><link>https://0xtracer.xyz/incidents/2023-11-01-frax-finance/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-01-frax-finance/</guid><description>According to @fraxfinance, Frax Finance&amp;rsquo;s DNS has been attacked. Please don’t use http://frax[.]finance and http://frax[.]com domains until further notice.</description></item><item><title>Monero</title><link>https://0xtracer.xyz/incidents/2023-11-01-monero/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-01-monero/</guid><description>Monero discloses that its community crowdfunding wallet was drained of 2,675.73 XMR (the entire balance). The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR.</description></item><item><title>Onyx Protocol</title><link>https://0xtracer.xyz/incidents/2023-11-01-onyx-protocol/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-11-01-onyx-protocol/</guid><description>Empty market dust attack via known Compound fork rounding bug</description></item><item><title>Dracula (DRAC)</title><link>https://0xtracer.xyz/incidents/2023-10-31-dracula-drac/</link><pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-31-dracula-drac/</guid><description>Dracula (DRAC) on BSC is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Unibot</title><link>https://0xtracer.xyz/incidents/2023-10-31-unibot/</link><pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-31-unibot/</guid><description>According to SlowMist security alert, Unibot has been exploited, and due to the lack of necessary parameter checks, the exploiter can transfer tokens for which users have approved the Unibot contract. Please revoke ap&amp;hellip;</description></item><item><title>Fake Memecoin (MEME)</title><link>https://0xtracer.xyz/incidents/2023-10-30-fake-memecoin-meme/</link><pubDate>Mon, 30 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-30-fake-memecoin-meme/</guid><description>Fake Memecoin (MEME) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake MEMEPAD (MEMEPAD)</title><link>https://0xtracer.xyz/incidents/2023-10-30-fake-memepad-memepad/</link><pubDate>Mon, 30 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-30-fake-memepad-memepad/</guid><description>Fake MEMEPAD (MEMEPAD) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Fake TITANX (TITANX)</title><link>https://0xtracer.xyz/incidents/2023-10-30-fake-titanx-titanx/</link><pubDate>Mon, 30 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-30-fake-titanx-titanx/</guid><description>Fake TITANX (TITANX) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Astrid</title><link>https://0xtracer.xyz/incidents/2023-10-28-astrid/</link><pubDate>Sat, 28 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-28-astrid/</guid><description>The Ethereum liquidity restaking pool Astrid was attacked due to a vulnerability in the withdrawal function, resulting in a loss of approximately $228,000. The parameters of the &lt;code>withdraw()&lt;/code> function, specifically the&amp;hellip;</description></item><item><title>STIMMY</title><link>https://0xtracer.xyz/incidents/2023-10-27-stimmy/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-27-stimmy/</guid><description>STIMMY on Ethereum pulled liquidity to the tune of 43.8 ETH (~$78.8K) and deleted its social platforms.</description></item><item><title>Fake Linea token</title><link>https://0xtracer.xyz/incidents/2023-10-26-fake-linea-token/</link><pubDate>Thu, 26 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-26-fake-linea-token/</guid><description>A fake Linea token is suspected of a rug pull for ~$1.3m. ~$743k has been deposited into Tornado Cash. Contract Address: 0x00000000fEB6A772307C6aA88AB9D57b209aCb18.</description></item><item><title>LastPass</title><link>https://0xtracer.xyz/incidents/2023-10-25-lastpass/</link><pubDate>Wed, 25 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-25-lastpass/</guid><description>On October 25, 2023 alone another ~$4.4M was drained from 25+ victims as a result of the LastPass hack.</description></item><item><title>Maestro Router</title><link>https://0xtracer.xyz/incidents/2023-10-25-maestro-router/</link><pubDate>Wed, 25 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-25-maestro-router/</guid><description>Maestro Router was compromised and approximately $ 510,000 was stolen.</description></item><item><title>Mina Protocol</title><link>https://0xtracer.xyz/incidents/2023-10-25-mina-protocol/</link><pubDate>Wed, 25 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-25-mina-protocol/</guid><description>Mina Protocol on BNB Chain has dropped 100%. 0x0920…a44A has swapped 1,000,000,000,000,000 $MINA for ~474.26 $BNB (worth ~$106.7K).</description></item><item><title>Safereum (SAFEREUM)</title><link>https://0xtracer.xyz/incidents/2023-10-24-safereum-safereum/</link><pubDate>Tue, 24 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-24-safereum-safereum/</guid><description>Safereum has conducted an exit scam for ~$1.3m. Contract Address: 0xb504035a11E672e12a099F32B1672b9C4a78b22f.</description></item><item><title>Julia (JULIA)</title><link>https://0xtracer.xyz/incidents/2023-10-23-julia-julia/</link><pubDate>Mon, 23 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-23-julia-julia/</guid><description>Julia (JULIA) on ETH is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>Coins.ph</title><link>https://0xtracer.xyz/incidents/2023-10-20-coins-ph/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-20-coins-ph/</guid><description>Philippine exchange Coins.ph lost 12 million $XRP ($6 million) in a hack.</description></item><item><title>Fake Celestia (TIA)</title><link>https://0xtracer.xyz/incidents/2023-10-20-fake-celestia-tia/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-20-fake-celestia-tia/</guid><description>Fake Celestia (TIA) on BNB Chain is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>SOMESING (SSX)</title><link>https://0xtracer.xyz/incidents/2023-10-20-somesing-ssx/</link><pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-20-somesing-ssx/</guid><description>Token SOMESING (SSX) on BNB Chain is suspected of a rug pull, with the deployer removing substantial liquidity, causing a 100% price decline.</description></item><item><title>MicDao</title><link>https://0xtracer.xyz/incidents/2023-10-19-micdao/</link><pubDate>Thu, 19 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-19-micdao/</guid><description>MicDao suffered from a flash loan attack. The attacker gained $12,263. Contract address: 0xf6876f6AB2637774804b85aECC17b434a2B57168.</description></item><item><title>Synthetify</title><link>https://0xtracer.xyz/incidents/2023-10-19-synthetify/</link><pubDate>Thu, 19 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-19-synthetify/</guid><description>On October 19, Synthetify Protocol experienced a security incident. The smart contract and the entire platform are currently frozen.</description></item><item><title>The Honest Venture</title><link>https://0xtracer.xyz/incidents/2023-10-19-the-honest-venture/</link><pubDate>Thu, 19 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-19-the-honest-venture/</guid><description>A project named The Honest Venture is a confirmed investment scam with losses of approximately ~$58k.</description></item><item><title>HopeLend</title><link>https://0xtracer.xyz/incidents/2023-10-18-hopelend/</link><pubDate>Wed, 18 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-18-hopelend/</guid><description>On October 18, 2023, , the HopeLend protocol fell victim to a hacker attack. The attack resulted in a loss of approximately 528 ETH, out of which 263.91 ETH were bribed by the frontrunner to a Validator (managed by Li&amp;hellip;</description></item><item><title>Everscale</title><link>https://0xtracer.xyz/incidents/2023-10-17-everscale/</link><pubDate>Tue, 17 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-17-everscale/</guid><description>Blockchain network Everscale said that a large number of EVER tokens have been stolen and they are working closely with exchanges where EVER is listed in order to stop any further outflow of tokens. To halt the action&amp;hellip;</description></item><item><title>Fantom Foundation</title><link>https://0xtracer.xyz/incidents/2023-10-17-fantom-foundation/</link><pubDate>Tue, 17 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-17-fantom-foundation/</guid><description>On October 17, Fantom Foundation Telegram Community Administrator Jane stated that some of Fantom Foundation&amp;rsquo;s hot wallet assets were drained due to a zero-day vulnerability on Google Chrome. According to SlowMist&amp;rsquo;s a&amp;hellip;</description></item><item><title>Ivy</title><link>https://0xtracer.xyz/incidents/2023-10-16-ivy/</link><pubDate>Mon, 16 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-16-ivy/</guid><description>Project Ivy on BSC Suspected of Exit Scam. Contract Address: 0xf99f2Aec50adFde23cc67aB6240168B0a59f1D30 which dropped &amp;gt;94%. EOA 0x5c30 removed $1.58m liquidity which caused the drop.</description></item><item><title>Beluga Protocol</title><link>https://0xtracer.xyz/incidents/2023-10-13-beluga-protocol/</link><pubDate>Fri, 13 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-13-beluga-protocol/</guid><description>The Beluga Protocol on Arbitrum fell victim to a flashloan attack. The attacker made a profit of approximately $175,000 by manipulating the USDT-USDC.e balance, allowing for the withdrawal of extra tokens.</description></item><item><title>BH Token (BlackHole token)</title><link>https://0xtracer.xyz/incidents/2023-10-12-bh-token-blackhole-token/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-bh-token-blackhole-token/</guid><description>BH Token (BlackHole token) suffered an attack. The exploiter (0xFDb) gained 1.2 M USDT. Funds are being swapped for BNB and deposited into Tornado Cash. Contract Address: 0xCC61CC9F2632314c9d452acA79104DDf680952b5. Ex&amp;hellip;</description></item><item><title>CRYPTO_STREET (CST)</title><link>https://0xtracer.xyz/incidents/2023-10-12-crypto-street-cst/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-crypto-street-cst/</guid><description>The CST deployer sold tokens, resulting in a roughly 99% drop in the token price. Contract address: 0x0a92285241b0ea93Eff4195Db4530AF1a4bcfE0c. Deployer address: 0xabE6BC5Ca4Ae76251F0cB647F9817E3566EC3D0b.</description></item><item><title>LastPass</title><link>https://0xtracer.xyz/incidents/2023-10-12-lastpass/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-lastpass/</guid><description>LastPass, a password management platform, is suspected to have suffered a data breach. On October 12, Twitter user flippen.eth tweeted that he had lost more than 20 ETH from his hot wallet overnight after storing his&amp;hellip;</description></item><item><title>Loozr</title><link>https://0xtracer.xyz/incidents/2023-10-12-loozr/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-loozr/</guid><description>There is a fake collab land verification in the Loozr Discord. The verification will take you to a phishing site that connects to a wallet drainer</description></item><item><title>NOWAI</title><link>https://0xtracer.xyz/incidents/2023-10-12-nowai/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-nowai/</guid><description>The @nowaiAI announced their Discord server has been compromised. Do not connect your wallet. It connects to phishing site: hxxps://nowaiguard.github.io/discord/.</description></item><item><title>Platypus</title><link>https://0xtracer.xyz/incidents/2023-10-12-platypus/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-platypus/</guid><description>On October 12th, the stablecoin trading project Platypus Finance appeared to have been hit by a suspected hacker attack, with total losses of around $2.2 million. Platypus Finance tweeted, &amp;ldquo;Due to suspicious activitie&amp;hellip;</description></item><item><title>Wall Street Meme</title><link>https://0xtracer.xyz/incidents/2023-10-12-wall-street-meme/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-12-wall-street-meme/</guid><description>Attacker posted a phishing link in the announcements channel of Wall Street Meme&amp;rsquo;s Discord server.</description></item><item><title>FSL</title><link>https://0xtracer.xyz/incidents/2023-10-11-fsl/</link><pubDate>Wed, 11 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-11-fsl/</guid><description>FSL project is suspected of being a Rug Pull, with a loss of approximately $1.68 million. FSL token plummeted 99.8%.</description></item><item><title>Cryptopreneurs</title><link>https://0xtracer.xyz/incidents/2023-10-10-cryptopreneurs/</link><pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-10-cryptopreneurs/</guid><description>Cryptopreneurs&amp;rsquo; Discord server was hacked and the attacker posted a phishing link.</description></item><item><title>Fake Bitcoin BSC Token</title><link>https://0xtracer.xyz/incidents/2023-10-10-fake-bitcoin-bsc-token/</link><pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-10-fake-bitcoin-bsc-token/</guid><description>On Oct 10, a fake Bitcoin BSC Token (BTCBSC) on BSC was rugged for ~$48.7K. The deployer removed 235.871 WBNB and 4,271,589.56 BTCBSC token from the LP. Contract Address: 0x48747d325d139b1F9cD29d9381Fb73228B9AFfec. De&amp;hellip;</description></item><item><title>Ordswap</title><link>https://0xtracer.xyz/incidents/2023-10-10-ordswap/</link><pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-10-ordswap/</guid><description>On October 10th, the BRC20 exchange platform Ordswap issued a tweet, stating that they had lost control of their website domain, and the issue appeared to be related to the website development and hosting company Netl&amp;hellip;</description></item><item><title>Starksport</title><link>https://0xtracer.xyz/incidents/2023-10-10-starksport/</link><pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-10-starksport/</guid><description>Starksport announced that a community team member&amp;rsquo;s Discord was compromised.</description></item><item><title>Ethereum Foundation</title><link>https://0xtracer.xyz/incidents/2023-10-09-ethereum-foundation/</link><pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-09-ethereum-foundation/</guid><description>The Ethereum Foundation fell victim to a sandwich attack by an MEV Bot when selling 1700 ETH through Uniswap V3, resulting in a loss of $9,101. The MEV Bot profited $4,060 from the attack.</description></item><item><title>Lucky star Currency Token</title><link>https://0xtracer.xyz/incidents/2023-10-09-lucky-star-currency-token/</link><pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-09-lucky-star-currency-token/</guid><description>Lucky star Currency Token on Binance Smart Chain has rugged for ~$1.11 million, down 98%.</description></item><item><title>MetaMundo</title><link>https://0xtracer.xyz/incidents/2023-10-08-metamundo/</link><pubDate>Sun, 08 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-08-metamundo/</guid><description>A phishing link has been posted in the announcements channel of MetaMundo Discord server. Do not interact with hxxps://mint-metamundo.co/.</description></item><item><title>OmniBTC</title><link>https://0xtracer.xyz/incidents/2023-10-08-omnibtc/</link><pubDate>Sun, 08 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-08-omnibtc/</guid><description>OmniBTC&amp;rsquo;s Discord was hacked and the attackers posted a phishing link in the announcement channel.</description></item><item><title>pSeudoEth</title><link>https://0xtracer.xyz/incidents/2023-10-08-pseudoeth/</link><pubDate>Sun, 08 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-08-pseudoeth/</guid><description>On Oct 8, the pSeudoEth token on ETH was exploited for ~$2.3K in a flash loan attack. Contract: 0x62aBdd605E710Cc80a52062a8cC7c5d659dDDbE7. Attacker: 0xea75AeC151f968b8De3789CA201a2a3a7FaeEFbA.</description></item><item><title>zkFlex Finance</title><link>https://0xtracer.xyz/incidents/2023-10-08-zkflex-finance/</link><pubDate>Sun, 08 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-08-zkflex-finance/</guid><description>On Oct 8, zkFlex Finance on ETH was rugged for ~$56K when an address 0x84f90d576247D569D972DB84504b5170aB13bCe7 dumped over 281,164,943.53 zkFlex Finance Tokens for 34.26 WETH. Contract Address: 0x54855D3133669B7EF54A&amp;hellip;</description></item><item><title>Fake CommEx Token</title><link>https://0xtracer.xyz/incidents/2023-10-06-fake-commex-token/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-06-fake-commex-token/</guid><description>There is a large liquidity removal on a fake CommEx token. Deployer removed ~$154k from the LP. BSC: 0xD1C3ee0f845bCc38a8cB9Dc5337dFd5a372Bb8Ed.</description></item><item><title>Galxe</title><link>https://0xtracer.xyz/incidents/2023-10-06-galxe/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-06-galxe/</guid><description>On October 6, an unknown individual contacted our domain service provider Dynadot, impersonating an authorized Galxe member and bypassing the security process with falsified documentation. The impersonator then gained&amp;hellip;</description></item><item><title>MCT</title><link>https://0xtracer.xyz/incidents/2023-10-06-mct/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-06-mct/</guid><description>On October 6th, MCT issued an announcement stating that in the past two days, some users had reported cases of their MCT wallets being compromised. After investigation today, it was discovered that due to the DNS doma&amp;hellip;</description></item><item><title>Stars Arena</title><link>https://0xtracer.xyz/incidents/2023-10-06-stars-arena/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-06-stars-arena/</guid><description>ETH transfer reentrancy in share buying logic</description></item><item><title>DePay</title><link>https://0xtracer.xyz/incidents/2023-10-05-depay/</link><pubDate>Thu, 05 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-05-depay/</guid><description>There is a flashloan attack on the DePay platform that resulted in the theft of 827 USDC. The exploiter used a security issue with DePay router to steal the USDC.</description></item><item><title>friend.tech</title><link>https://0xtracer.xyz/incidents/2023-10-05-friend-tech/</link><pubDate>Thu, 05 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-05-friend-tech/</guid><description>On October 5th, blockchain detective ZachXBT posted on social media, stating that a hacker had made a profit of 234 ETH (~$385,000) in the past 24 hours by conducting SIM card swap attacks on four different friend.tec&amp;hellip;</description></item><item><title>Metropolis World</title><link>https://0xtracer.xyz/incidents/2023-10-05-metropolis-world/</link><pubDate>Thu, 05 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-05-metropolis-world/</guid><description>Metropolis World announced that their Discord server was compromised.</description></item><item><title>GEMIE</title><link>https://0xtracer.xyz/incidents/2023-10-02-gemie/</link><pubDate>Mon, 02 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-02-gemie/</guid><description>The GEMIE Discord server was hacked and the attackers posted phishing links in the announcement channel. Please do not interact with hxxps://gemie.site/.</description></item><item><title>VendX</title><link>https://0xtracer.xyz/incidents/2023-10-02-vendx/</link><pubDate>Mon, 02 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-02-vendx/</guid><description>VendX Discord server was compromised.</description></item><item><title>Fake EigenLayer Token</title><link>https://0xtracer.xyz/incidents/2023-10-01-fake-eigenlayer-token/</link><pubDate>Sun, 01 Oct 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-10-01-fake-eigenlayer-token/</guid><description>There is an exit scam on a fake EigenLayer token. The deployer profited ~$300k. BSC: 0x14ac066ac2CD24CBdE31f78659c11F13aB61E4e7.</description></item><item><title>DKP</title><link>https://0xtracer.xyz/incidents/2023-09-29-dkp/</link><pubDate>Fri, 29 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-29-dkp/</guid><description>There was a large liquidity removal on DKP resulting in losses of approximately $204,000 USDT. The token contract is 0xd06fa1BA7c80F8e113c2dc669A23A9524775cF19.</description></item><item><title>LuckyFactoryNFT</title><link>https://0xtracer.xyz/incidents/2023-09-28-luckyfactorynft/</link><pubDate>Thu, 28 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-28-luckyfactorynft/</guid><description>A phishing link has been posted in the factory-updates channel of LuckyFactoryNFT. Do not interact with the malicious link.</description></item><item><title>Mode</title><link>https://0xtracer.xyz/incidents/2023-09-28-mode/</link><pubDate>Thu, 28 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-28-mode/</guid><description>Mode Discord was hacked. A phishing link was posted in the announcements channel of the Mode Network Discord server.</description></item><item><title>SpaceChain</title><link>https://0xtracer.xyz/incidents/2023-09-27-spacechain/</link><pubDate>Wed, 27 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-27-spacechain/</guid><description>SpaceChain Discord was hacked. A phishing link was posted in the announcements channel of SpaceChain Discord server.</description></item><item><title>Venom Bears</title><link>https://0xtracer.xyz/incidents/2023-09-27-venom-bears/</link><pubDate>Wed, 27 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-27-venom-bears/</guid><description>On September 27th, Venom Bears‘ Discord server was compromised.</description></item><item><title>XSDWETHpool</title><link>https://0xtracer.xyz/incidents/2023-09-26-xsdwethpool/</link><pubDate>Tue, 26 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-26-xsdwethpool/</guid><description>On September 26th, XSDWETHpool On BSC was exploited for ~$12.1k in a flash loan attack. The attacker created a malicious contract to interact with the pool contract and gained 56.96 WBNB. Pool Contract: 0xbfBcB8BDE20c&amp;hellip;</description></item><item><title>Fake Justus Token</title><link>https://0xtracer.xyz/incidents/2023-09-25-fake-justus-token/</link><pubDate>Mon, 25 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-25-fake-justus-token/</guid><description>There is an exit scam on a fake Justus Token associated with fake Twitter Justusztoken. Deployer dumped 302 WBNB for a profit of ~$59k. BSC: 0xae7607dE0F0665220E77b76E18d94965076e684c.</description></item><item><title>HTX (Huobi)</title><link>https://0xtracer.xyz/incidents/2023-09-24-htx-huobi/</link><pubDate>Sun, 24 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-24-htx-huobi/</guid><description>Huobi hot wallet drained, Justin Sun confirmed and covered losses</description></item><item><title>KUB-Split (Split)</title><link>https://0xtracer.xyz/incidents/2023-09-24-kub-split-split/</link><pubDate>Sun, 24 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-24-kub-split-split/</guid><description>There was a flash loan exploit on Kub/Kub-split. The attacker gained ~$78.4k via pool manipulation. Contract: 0xc98E183D2e975F0567115CB13AF893F0E3c0d0bD.</description></item><item><title>Upbit</title><link>https://0xtracer.xyz/incidents/2023-09-24-upbit/</link><pubDate>Sun, 24 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-24-upbit/</guid><description>On September 24th, according to Definalist on Twitter, scammers had deposited fake APT tokens into South Korea&amp;rsquo;s largest exchange, Upbit. After these fake tokens were deposited into numerous user accounts, many users&amp;hellip;</description></item><item><title>BEDU</title><link>https://0xtracer.xyz/incidents/2023-09-23-bedu/</link><pubDate>Sat, 23 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-23-bedu/</guid><description>BEDU announced that a team member in their Discord server has been compromised.</description></item><item><title>Cat Nation</title><link>https://0xtracer.xyz/incidents/2023-09-23-cat-nation/</link><pubDate>Sat, 23 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-23-cat-nation/</guid><description>The token Cat Nation is suspected to be a rug pull. Transaction pool address (ETH): 0xC9C1776802216e074eF7A19555cE70bB473B25c0.</description></item><item><title>DUO</title><link>https://0xtracer.xyz/incidents/2023-09-23-duo/</link><pubDate>Sat, 23 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-23-duo/</guid><description>There was a large liquidity removal on DUO. The Deployer removed $352.6K WBNB of LP in 3 transactions over a 4 day period. BSC: 0x1ED990bdcAEf4B13b01F4996dDe59EcD04F1343A .</description></item><item><title>Mixin Network</title><link>https://0xtracer.xyz/incidents/2023-09-23-mixin-network/</link><pubDate>Sat, 23 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-23-mixin-network/</guid><description>On September 23, the Mixin Network cloud service provider database was attacked, the amount of funds involved was ~$200M.</description></item><item><title>Synthtopia</title><link>https://0xtracer.xyz/incidents/2023-09-23-synthtopia/</link><pubDate>Sat, 23 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-23-synthtopia/</guid><description>Synthtopia Discord server was compromised.</description></item><item><title>BEAST</title><link>https://0xtracer.xyz/incidents/2023-09-22-beast/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-22-beast/</guid><description>There was a large liquidity removal on Unleashed Beast (BEAST). Deployer removed ~$55.3k from the LP. BSC:0x626b596dd10467ea969179235123f884e133074a.</description></item><item><title>BNBpay</title><link>https://0xtracer.xyz/incidents/2023-09-21-bnbpay/</link><pubDate>Thu, 21 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-21-bnbpay/</guid><description>There was a large liquidity removal on BNBpay. Deployer profited ~$114k from this liquidity removal. BSC: 0xaDD62696db2c2fb7DE8e0f07F422e03BF69646A2.</description></item><item><title>Linear Finance</title><link>https://0xtracer.xyz/incidents/2023-09-21-linear-finance/</link><pubDate>Thu, 21 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-21-linear-finance/</guid><description>On September 21st, the Linear stable coin $LUSD appears to be under an exploit attack. While the team investigates, do not buy LUSD, do not trade $LUSD. Liquidations are paused and users accounts are not at risk.</description></item><item><title>PEPEP</title><link>https://0xtracer.xyz/incidents/2023-09-21-pepep/</link><pubDate>Thu, 21 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-21-pepep/</guid><description>There is a 70% slippage on PEPEP. ETH: 0xD33830FcC5E434dBb4efF9D5348d74Ee2cbd505F. Drop caused by EOA 0x4af2 who dumped tokens for ~$45k.</description></item><item><title>TimeSoul</title><link>https://0xtracer.xyz/incidents/2023-09-21-timesoul/</link><pubDate>Thu, 21 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-21-timesoul/</guid><description>A phishing link has been posted in the announcements channel of timesoul Discord server.</description></item><item><title>YZER</title><link>https://0xtracer.xyz/incidents/2023-09-21-yzer/</link><pubDate>Thu, 21 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-21-yzer/</guid><description>On September 21st, a large liquidity of YZER was removed. Deployer profited ~$28.6k from this liquidity removal.</description></item><item><title>Baka Casino (BAKAC)</title><link>https://0xtracer.xyz/incidents/2023-09-20-baka-casino-bakac/</link><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-20-baka-casino-bakac/</guid><description>There is a slippage on Baka Casino (BAKAC) caused by EOA 0x9e5C8 who dumped tokens for ~$57k. The price has dropped 80%. BSC:0x0e9c0f8fcc8e60f8daeb569448a41514eb321471</description></item><item><title>Balancer</title><link>https://0xtracer.xyz/incidents/2023-09-20-balancer/</link><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-20-balancer/</guid><description>On September 20th, the DeFi liquidity protocol Balancer fell victim to a DNS hijacking attack. Funds have been directed to an address starting with 0x6457, resulting in a total loss of approximately $350,000. The atta&amp;hellip;</description></item><item><title>Coinbase Wallet</title><link>https://0xtracer.xyz/incidents/2023-09-20-coinbase-wallet/</link><pubDate>Wed, 20 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-20-coinbase-wallet/</guid><description>On September 20th, SlowMist tweeted that Coinbase Wallet recently integrated the Web3 messaging network protocol (&lt;a href="http://xmtp.org">http://xmtp.org&lt;/a>). As long as the user&amp;rsquo;s wallet address opens the messaging network, it may receive any&amp;hellip;</description></item><item><title>One Mint</title><link>https://0xtracer.xyz/incidents/2023-09-17-one-mint/</link><pubDate>Sun, 17 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-17-one-mint/</guid><description>On September 17th, the NFT solution &amp;ndash; One Mint&amp;rsquo;s Discord account was compromised. The attacker posted malicious links and shut down channels like support.</description></item><item><title>ThalaLabs</title><link>https://0xtracer.xyz/incidents/2023-09-17-thalalabs/</link><pubDate>Sun, 17 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-17-thalalabs/</guid><description>On September 17th, ThalaLabs&amp;rsquo; Twitter account was compromised, and a phishing website was posted, which is linked to a known wallet drainer.</description></item><item><title>Fake BitGo Token</title><link>https://0xtracer.xyz/incidents/2023-09-16-fake-bitgo-token/</link><pubDate>Sat, 16 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-16-fake-bitgo-token/</guid><description>A fake BitGo token on BSC rugged for ~$194.3k WBNB from the honeypot and has moved 909.2 BNB through TornadoCash. BSC: 0xddd00e04cd2e26221cc3c2c7f4781a87e4c79818. Deployer Address: 0xaf85ef92dc34593e2a1d6c65c2a857ad36&amp;hellip;</description></item><item><title>Mark Cuban</title><link>https://0xtracer.xyz/incidents/2023-09-16-mark-cuban/</link><pubDate>Sat, 16 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-16-mark-cuban/</guid><description>Mark Cuban, a billionaire entrepreneur and owner of the Dallas Mavericks, fell victim to a hack on September 16th. Altogether, he was set back by around $870,000 across 10 cryptocurrencies. He said he moved his remain&amp;hellip;</description></item><item><title>FriendChipsTech</title><link>https://0xtracer.xyz/incidents/2023-09-15-friendchipstech/</link><pubDate>Fri, 15 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-15-friendchipstech/</guid><description>The FriendChipsTech token on ETH was suspected to be a rug pull, resulting in a loss of ~$77.5K. The exploiter created a malicious contract (0x1dB0B6012D64452ED6aa98e87F7c308DB0281E40) to mint tokens and dump them for&amp;hellip;</description></item><item><title>Remitano</title><link>https://0xtracer.xyz/incidents/2023-09-14-remitano/</link><pubDate>Thu, 14 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-14-remitano/</guid><description>A massive suspicious withdrawal occurred on cryptocurrency exchange Remitano, with $2.7 million worth of cryptocurrency being withdrawn. Some blockchain analysts believe the exchange may have been hacked. Tether has f&amp;hellip;</description></item><item><title>JPEX</title><link>https://0xtracer.xyz/incidents/2023-09-13-jpex/</link><pubDate>Wed, 13 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-13-jpex/</guid><description>On September 13th, the Hong Kong Securities and Futures Commission issued a statement titled &amp;ldquo;Regarding Unregulated Virtual Asset Trading Platforms,&amp;rdquo; stating that the virtual asset trading platform JPEX did not have a&amp;hellip;</description></item><item><title>CoinEx</title><link>https://0xtracer.xyz/incidents/2023-09-12-coinex/</link><pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-12-coinex/</guid><description>The cryptocurrency exchange CoinEx suffered a hacker attack. The cause of the incident was initially determined to be the leakage of hot wallet private keys. The damage caused is estimated to have reached US$70 millio&amp;hellip;</description></item><item><title>OxODexPool</title><link>https://0xtracer.xyz/incidents/2023-09-12-oxodexpool/</link><pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-12-oxodexpool/</guid><description>OxODexPool suffered from a flash loan. ETH: 0x6128d5F7c64Dab48a1C66f9D62EaeFa1d5aA03ed. Approximately 40 ETH (~$61k) was lost. The stolen funds currently reside in the attacker&amp;rsquo;s wallet.</description></item><item><title>Base (TBA)</title><link>https://0xtracer.xyz/incidents/2023-09-11-base-tba/</link><pubDate>Mon, 11 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-11-base-tba/</guid><description>There is a large liquidity removal on the fake Base token. BSC: 0x2025273c4B985a00bc60E871a9031a12FF216F9B. Deployer 0x6d3503d16Bb93a7d9b47F510C7568868F2BFcCEf has profited ~$71.6k.</description></item><item><title>Milady</title><link>https://0xtracer.xyz/incidents/2023-09-11-milady/</link><pubDate>Mon, 11 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-11-milady/</guid><description>Milady founder Charlotte Fang said that a developer of Milady misappropriated approximately $1 million from the Bonkler treasury of Milady&amp;rsquo;s official project. The developer also seized the code base and asked the team&amp;hellip;</description></item><item><title>Paxos</title><link>https://0xtracer.xyz/incidents/2023-09-11-paxos/</link><pubDate>Mon, 11 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-11-paxos/</guid><description>Stablecoin issuer Paxos admitted in a statement that the account that paid out nearly 20 BTC in fees in a single transaction in the early hours of September 11 belonged to the company. Paxos claims that end users have&amp;hellip;</description></item><item><title>Witnet</title><link>https://0xtracer.xyz/incidents/2023-09-11-witnet/</link><pubDate>Mon, 11 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-11-witnet/</guid><description>On September 11, Witnet - the multichain decentralized oracle, tweeted that the Witnet Discord server has been compromised and deleted temporarily.</description></item><item><title>BFCToken</title><link>https://0xtracer.xyz/incidents/2023-09-10-bfctoken/</link><pubDate>Sun, 10 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-10-bfctoken/</guid><description>BFCToken suffered from a flash loan attack, resulting in losses of ~$38k. BSC: 0x595eac4a0ce9b7175a99094680fbe55a774b5464. The attacker was able to burn BFCTokens from the pool at no expense by exploiting the &amp;ldquo;_transf&amp;hellip;</description></item><item><title>LDO</title><link>https://0xtracer.xyz/incidents/2023-09-10-ldo/</link><pubDate>Sun, 10 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-10-ldo/</guid><description>On September 10, according to on-chain intelligence from the SlowMist security team, when the LDO token contract is processing a transfer operation, if the transfer amount exceeds the amount actually held by the user,&amp;hellip;</description></item><item><title>Vitalik Buterin</title><link>https://0xtracer.xyz/incidents/2023-09-10-vitalik-buterin/</link><pubDate>Sun, 10 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-10-vitalik-buterin/</guid><description>Ether co-founder Vitalik Buterin&amp;rsquo;s Twitter account is suspected to have been hacked and posted a link (actually a phishing link) to a free Proto Danksharding Memorial NFT pickup related to ConsenSys. ZachXBT says the&amp;hellip;</description></item><item><title>ACG WORLDS</title><link>https://0xtracer.xyz/incidents/2023-09-09-acg-worlds/</link><pubDate>Sat, 09 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-09-acg-worlds/</guid><description>A phishing link was posted in the announcements channel of ACG WORLDS discord server. Do not interact with hxxps://asusworlds.com/tcom/.</description></item><item><title>PEPE</title><link>https://0xtracer.xyz/incidents/2023-09-09-pepe/</link><pubDate>Sat, 09 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-09-pepe/</guid><description>On September 9, PEPE stated on Twitter that PEPE’s old Telegram account had been hacked and was no longer under official control. The Twitter account &amp;ldquo;lordkeklol&amp;rdquo; has been compromised and used to perpetrate scams and&amp;hellip;</description></item><item><title>Fake Patex</title><link>https://0xtracer.xyz/incidents/2023-09-07-fake-patex/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-07-fake-patex/</guid><description>We have seen a large liquidity removal on a fake Patex token. BSC: 0xbFDf31187Ea84651414545eDEA0a27104D514a70. Deployer gained ~$97.5k from removing liquidity on a honeypot token.</description></item><item><title>Fortress</title><link>https://0xtracer.xyz/incidents/2023-09-07-fortress/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-07-fortress/</guid><description>On September 7, crypto trust company Fortress said on twitter that its customers were affected by a &amp;ldquo;compromised third-party provider of cloud tools,&amp;rdquo; but that there was no loss of funds. On September 13, Fortress Tru&amp;hellip;</description></item><item><title>HCT Token</title><link>https://0xtracer.xyz/incidents/2023-09-07-hct-token/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-07-hct-token/</guid><description>We have detected a malicious flash loan on HCT token. BSC: 0x0FDfcfc398Ccc90124a0a41d920d6e2d0bD8CcF5. Approximately 30.5 BNB was lost. 30 BNB has been deposited into Tornado Cash by EOA 0xC89.</description></item><item><title>Ordinals Wallet</title><link>https://0xtracer.xyz/incidents/2023-09-07-ordinals-wallet/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-07-ordinals-wallet/</guid><description>Ordinals Wallet suffered a SIM Swap attack. The Twitter account was hacked and phishing links were posted. The attacker is PinkDrainer.</description></item><item><title>Victory Point</title><link>https://0xtracer.xyz/incidents/2023-09-07-victory-point/</link><pubDate>Thu, 07 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-07-victory-point/</guid><description>A phishing link has been posted in the major announcements channel of Victory Point Discord server. Do not interact with hxxps://victorypoints.xyz/airdrop/</description></item><item><title>Base</title><link>https://0xtracer.xyz/incidents/2023-09-06-base/</link><pubDate>Wed, 06 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-06-base/</guid><description>According to official sources, Base had previously experienced a block failure. The Base team immediately investigated, and a fix was subsequently deployed, and block production began to resume. At present, the team c&amp;hellip;</description></item><item><title>Big.B</title><link>https://0xtracer.xyz/incidents/2023-09-06-big-b/</link><pubDate>Wed, 06 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-06-big-b/</guid><description>Big.B Discord Server was hacked. The attacker posted a phishing link in Big.B Discord Server. Do not click on any links until the team has confirmed they’ve regained control of the server.</description></item><item><title>Fake Helio Protocol</title><link>https://0xtracer.xyz/incidents/2023-09-06-fake-helio-protocol/</link><pubDate>Wed, 06 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-06-fake-helio-protocol/</guid><description>There is a large liquidity removal on a fake Helio Protocol token. BSC:0x4C75a1f37a820376C74535f57e05C75052A3B077. Deployer profited ~$127k WBNB from this liquidity removal.</description></item><item><title>Gala Games</title><link>https://0xtracer.xyz/incidents/2023-09-06-gala-games/</link><pubDate>Wed, 06 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-06-gala-games/</guid><description>The token GALA of the blockchain gaming platform Gala Games underwent a major upgrade on May 15, 2023, and the token contract address was updated. As a result, there are now two tokens in circulation, both called GALA&amp;hellip;</description></item><item><title>Connext</title><link>https://0xtracer.xyz/incidents/2023-09-05-connext/</link><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-05-connext/</guid><description>According to a number of community users, there seems to be a problem in the Layer2 interoperability protocol Connext airdrop claim process. The NEXT tokens of some accounts were claimed to unexpected addresses. The d&amp;hellip;</description></item><item><title>Cyberport Hong Kong</title><link>https://0xtracer.xyz/incidents/2023-09-05-cyberport-hong-kong/</link><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-05-cyberport-hong-kong/</guid><description>According to reports, Cyberport Hong Kong was hacked and the information, company documents, identity documents and other information of start-up companies were obtained by hackers, totaling about 436 GB of company da&amp;hellip;</description></item><item><title>Fake Lybra Finance Token</title><link>https://0xtracer.xyz/incidents/2023-09-05-fake-lybra-finance-token/</link><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-05-fake-lybra-finance-token/</guid><description>A fake Lybra Finance token executed a exit scam on September 5th. Deployer added 60 WETH to LP and removed 83 WETH, profiting 23 WETH (~$37k).</description></item><item><title>GMBL COMPUTER</title><link>https://0xtracer.xyz/incidents/2023-09-05-gmbl-computer/</link><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-05-gmbl-computer/</guid><description>GMBL COMPUTER was attacked, and the attacker withdrew GMBL worth approximately US$815,000 from the contract. GMBL said: “We believe that the vulnerability is caused by a flaw in the platform’s recommendation system, w&amp;hellip;</description></item><item><title>Haribo</title><link>https://0xtracer.xyz/incidents/2023-09-05-haribo/</link><pubDate>Tue, 05 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-05-haribo/</guid><description>There is a large liquidity removal on Haribo. Owner removed ~24 ETH ($35.4k) from the tokens LP. Token appears to be a honeypot. Token Contract: 0x582992190976d9d96e5ABbB711259744A00e809e.</description></item><item><title>Saber DAO</title><link>https://0xtracer.xyz/incidents/2023-09-04-saber-dao/</link><pubDate>Mon, 04 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-04-saber-dao/</guid><description>Saber DAO, the automated market maker for stablecoins on Solana, tweeted that its Discord had been attacked and that it had blocked the attackers.</description></item><item><title>Stake.com</title><link>https://0xtracer.xyz/incidents/2023-09-04-stake-com/</link><pubDate>Mon, 04 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-04-stake-com/</guid><description>Stake.com hot wallet drained, FBI attributed to Lazarus Group</description></item><item><title>Paras</title><link>https://0xtracer.xyz/incidents/2023-09-03-paras/</link><pubDate>Sun, 03 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-03-paras/</guid><description>NFT marketplace Paras tweeted that its discord was under attack. Please do not click on the link, mint, or approve any transactions.</description></item><item><title>Balthazar</title><link>https://0xtracer.xyz/incidents/2023-09-02-balthazar/</link><pubDate>Sat, 02 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-02-balthazar/</guid><description>Balthazar tweeted that his Discord was under attack and please do not click on the link, mint, or approve any transactions.</description></item><item><title>CoredeFinance</title><link>https://0xtracer.xyz/incidents/2023-09-02-coredefinance/</link><pubDate>Sat, 02 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-02-coredefinance/</guid><description>The CoredeFinance project performed an exit scam and EOA (0x18500) made a profit of 27 ETH (~$43,900).</description></item><item><title>Gitcoin</title><link>https://0xtracer.xyz/incidents/2023-09-01-gitcoin/</link><pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-01-gitcoin/</guid><description>On September 1, community users discovered that Gitcoin’s official twitter account was suspected to have been stolen. The thief had used the account to post some phishing information. On September 9, Gitcoin tweeted t&amp;hellip;</description></item><item><title>Ivan Bianco</title><link>https://0xtracer.xyz/incidents/2023-09-01-ivan-bianco/</link><pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-01-ivan-bianco/</guid><description>A Brazilian YouTuber, Ivan Bianco, accidentally leaked the mnemonic of his cryptocurrency wallet during a live stream on his Fraternidade Crypto channel, resulting in the theft of nearly $60,000 worth of cryptocurrenc&amp;hellip;</description></item><item><title>Lamas Finance</title><link>https://0xtracer.xyz/incidents/2023-09-01-lamas-finance/</link><pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-09-01-lamas-finance/</guid><description>Lamas Finance&amp;rsquo;s Discord is under attack, phishing site is lamas[.]co/airdrop, please do not click on the link, mint or approve any transactions.</description></item><item><title>BabyShia</title><link>https://0xtracer.xyz/incidents/2023-08-31-babyshia/</link><pubDate>Thu, 31 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-31-babyshia/</guid><description>The BabyShia project implemented an exit scam. The deployer (0xCbcd8) has earned 133 ETH (about $226,000).</description></item><item><title>Starkware</title><link>https://0xtracer.xyz/incidents/2023-08-30-starkware/</link><pubDate>Wed, 30 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-30-starkware/</guid><description>For months, Ethereum layer 2 solution Starkware has repeatedly warned users that their funds would be lost if they did not take action before upgrading, but some users apparently did not see these notifications, which&amp;hellip;</description></item><item><title>BitBrowser</title><link>https://0xtracer.xyz/incidents/2023-08-26-bitbrowser/</link><pubDate>Sat, 26 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-26-bitbrowser/</guid><description>The private key of the BitBrowser browser user was suspected to be leaked, and many members of the encryption community reported that the private key was stolen. BitBrowser issued a notice, admitting that the cached d&amp;hellip;</description></item><item><title>PEPE</title><link>https://0xtracer.xyz/incidents/2023-08-26-pepe/</link><pubDate>Sat, 26 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-26-pepe/</guid><description>PEPE said on Twitter that 16 trillion pieces of PEPE were sold yesterday because three former members deleted the multi-signature permissions after stealing tokens. However, Jeremy Cahen, founder of the NFT market Not&amp;hellip;</description></item><item><title>SOL Big Brain</title><link>https://0xtracer.xyz/incidents/2023-08-26-sol-big-brain/</link><pubDate>Sat, 26 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-26-sol-big-brain/</guid><description>NFT collector SOL Big Brain lost about $1.5 million. Attackers compromised the Telegram account of a portfolio company founder and used it to send messages to SOL Big Brain, which double-checked that the sender was in&amp;hellip;</description></item><item><title>SVT</title><link>https://0xtracer.xyz/incidents/2023-08-26-svt/</link><pubDate>Sat, 26 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-26-svt/</guid><description>SVT tokens were attacked by flash loans, and the economic model loopholes of SVT transaction contracts were exploited. The attackers made approximately $400,000 in profit from repeated buying and selling operations. A&amp;hellip;</description></item><item><title>Kroll &amp; BlockFi</title><link>https://0xtracer.xyz/incidents/2023-08-25-kroll-and-blockfi/</link><pubDate>Fri, 25 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-25-kroll-and-blockfi/</guid><description>Bankruptcy claims agency Kroll experienced a cybersecurity incident that resulted in the disclosure of non-sensitive customer data of certain claimants in pending bankruptcy cases, FTX said on Twitter. FTX&amp;rsquo;s own syste&amp;hellip;</description></item><item><title>Magnate Finance</title><link>https://0xtracer.xyz/incidents/2023-08-25-magnate-finance/</link><pubDate>Fri, 25 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-25-magnate-finance/</guid><description>Base on-chain exit scam Magnate Finance has seen its TVL drop by ~$6.4M as the deployer modifies the price oracle provider and removes all assets. On-chain sleuth ZachXBT says the Magnate Finance deployer address is l&amp;hellip;</description></item><item><title>Balancer</title><link>https://0xtracer.xyz/incidents/2023-08-22-balancer/</link><pubDate>Tue, 22 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-22-balancer/</guid><description>Balancer says it has received reports of a critical vulnerability affecting multiple V2 pools. Emergency mitigation procedures have been implemented to secure the majority of TVL, but some funds remain at risk. Users&amp;hellip;</description></item><item><title>Fake "LayerZero" Token</title><link>https://0xtracer.xyz/incidents/2023-08-21-fake-layerzero-token/</link><pubDate>Mon, 21 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-21-fake-layerzero-token/</guid><description>A fake &amp;ldquo;LayerZero&amp;rdquo; token on the BSC chain has had a lot of liquidity removed. The deployer removed 4,827.99 WBNB worth about $1 million. The contract address of the fake token is 0x2266362f414Bf2476C5465dc2eA953Fe2A99&amp;hellip;</description></item><item><title>Thales</title><link>https://0xtracer.xyz/incidents/2023-08-20-thales/</link><pubDate>Sun, 20 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-20-thales/</guid><description>Derivatives marketplace Thales issued an announcement that a core contributor’s PC/Metamask had been hacked and that some hot wallets acting as casual deployers ($25k) or admin bots ($10k) had been compromised. Do not&amp;hellip;</description></item><item><title>Harbor Protocol</title><link>https://0xtracer.xyz/incidents/2023-08-19-harbor-protocol/</link><pubDate>Sat, 19 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-19-harbor-protocol/</guid><description>Harbor Protocol, the Cosmos ecological cross-chain stablecoin protocol, tweeted that Harbor Protocol was exploited, causing stablecoin minting and part of the funds in stOSMO, LUNA and WMATIC vaults to be depleted. Fr&amp;hellip;</description></item><item><title>Exactly Protocol</title><link>https://0xtracer.xyz/incidents/2023-08-18-exactly-protocol/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-18-exactly-protocol/</guid><description>Unvalidated market address in leveraging function allowed theft</description></item><item><title>Made by Apes</title><link>https://0xtracer.xyz/incidents/2023-08-16-made-by-apes/</link><pubDate>Wed, 16 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-16-made-by-apes/</guid><description>On-chain analyst ZachXBT tweeted that there was an issue with Made by Apes’ SaaSy Labs APl, an on-chain licensing application platform launched by BAYC, allowing access to personal details for MBA applications. This i&amp;hellip;</description></item><item><title>SwirlLend</title><link>https://0xtracer.xyz/incidents/2023-08-16-swirllend/</link><pubDate>Wed, 16 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-16-swirllend/</guid><description>The lending protocol SwirlLend team stole about $2.9 million in cryptocurrency from Base and $1.7 million worth of cryptocurrency from Linea, all of which were cross-chained to Ethereum. As of now, the deployer has tr&amp;hellip;</description></item><item><title>MetisDAO</title><link>https://0xtracer.xyz/incidents/2023-08-15-metisdao/</link><pubDate>Tue, 15 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-15-metisdao/</guid><description>The official Twitter account of Ethereum expansion solution Metis was stolen. According to officials, team members fell victim to a Sim Swap attack, resulting in malicious actors being able to take over the account fo&amp;hellip;</description></item><item><title>RocketSwap</title><link>https://0xtracer.xyz/incidents/2023-08-15-rocketswap/</link><pubDate>Tue, 15 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-15-rocketswap/</guid><description>The Base ecological project RocketSwap was attacked. The attacker cross-chained the stolen assets to Ethereum, resulting in a loss of 471 ETH (approximately $868,000). RocketSwap said: &amp;ldquo;The team needs to use offline s&amp;hellip;</description></item><item><title>Sei Network</title><link>https://0xtracer.xyz/incidents/2023-08-15-sei-network/</link><pubDate>Tue, 15 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-15-sei-network/</guid><description>The official Sei Network Discord server has been compromised, please do not click on any links until the team confirms that they have regained control of the server.</description></item><item><title>Fetch.ai</title><link>https://0xtracer.xyz/incidents/2023-08-13-fetch-ai/</link><pubDate>Sun, 13 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-13-fetch-ai/</guid><description>An admin on the Fetch discord server showing the username &amp;ldquo;Atari_buzz1kLL&amp;rdquo; has had their @discord account compromised. Please do not interact with any posts on our Discord until the issue has been resolved. There is n&amp;hellip;</description></item><item><title>Zunami Protocol</title><link>https://0xtracer.xyz/incidents/2023-08-13-zunami-protocol/</link><pubDate>Sun, 13 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-13-zunami-protocol/</guid><description>Price manipulation via large swap before add liquidity operation</description></item><item><title>MPC Wallets</title><link>https://0xtracer.xyz/incidents/2023-08-10-mpc-wallets/</link><pubDate>Thu, 10 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-10-mpc-wallets/</guid><description>Crypto infrastructure company Fireblocks has disclosed a series of vulnerabilities (collectively referred to as &amp;ldquo;BitForge&amp;rdquo;) affecting various popular crypto wallets that use multi-party computation (MPC) technology, C&amp;hellip;</description></item><item><title>Blockchain Capital</title><link>https://0xtracer.xyz/incidents/2023-08-09-blockchain-capital/</link><pubDate>Wed, 09 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-09-blockchain-capital/</guid><description>The Twitter account of Blockchain Capital, an encryption venture capital organization, was stolen this morning, and multiple tweets were posted to promote token claim scams. At present, the relevant fraudulent tweets&amp;hellip;</description></item><item><title>Earning.Farm</title><link>https://0xtracer.xyz/incidents/2023-08-09-earning-farm/</link><pubDate>Wed, 09 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-09-earning-farm/</guid><description>The DeFi project Earning.Farm suffered a reentrancy attack and lost 286 ETH (approximately $530,000). According to the analysis of SlowMist, the attacker re-enters the transfer function of LP to transfer LP tokens whe&amp;hellip;</description></item><item><title>Solar Techno Alliance</title><link>https://0xtracer.xyz/incidents/2023-08-08-solar-techno-alliance/</link><pubDate>Tue, 08 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-08-solar-techno-alliance/</guid><description>Legal authorities in the Indian state of Odisha have successfully busted a $120 million (Rs 1,000 crore) cryptocurrency Ponzi scheme. Two central figures in the fraudulent operation have been arrested. The project in&amp;hellip;</description></item><item><title>Steadefi</title><link>https://0xtracer.xyz/incidents/2023-08-08-steadefi/</link><pubDate>Tue, 08 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-08-steadefi/</guid><description>Steadefi, an automated yield leveraged strategy platform, tweeted: “Our protocol deployer wallet (which is also the owner of all vaults in the protocol) has been compromised. Attackers have transferred ownership of al&amp;hellip;</description></item><item><title>Cypher</title><link>https://0xtracer.xyz/incidents/2023-08-07-cypher/</link><pubDate>Mon, 07 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-07-cypher/</guid><description>​On August 7, 2023, Cypher, a Solana-based decentralized exchange, tweeted that it had been attacked. The attacker exploited a bug related to the mechanism involving segregated margin sub-accounts to attack Cypher&amp;rsquo;s m&amp;hellip;</description></item><item><title>Bitlord</title><link>https://0xtracer.xyz/incidents/2023-08-06-bitlord/</link><pubDate>Sun, 06 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-06-bitlord/</guid><description>Bitlord (BITLORD) A lot of liquidity has been removed. The deployer removed about 309 WETH from LP, worth about $567,000. The token project is suspected to be a honeypot scam.</description></item><item><title>Apache SalesRoom</title><link>https://0xtracer.xyz/incidents/2023-08-03-apache-salesroom/</link><pubDate>Thu, 03 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-03-apache-salesroom/</guid><description>A Rug Pull occurred on the Apache NFT SalesRoom (ASN) on the BNB Chain, and the deployer made a profit of about $680,000. The deployer transferred a large number of tokens to the address starting with 0xdc8, which has&amp;hellip;</description></item><item><title>Tim Beiko</title><link>https://0xtracer.xyz/incidents/2023-08-03-tim-beiko/</link><pubDate>Thu, 03 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-03-tim-beiko/</guid><description>The Twitter account of Tim Beiko, the core developer of Ethereum, was suspected of being stolen. He posted two tweets about &amp;ldquo;ETH airdrop&amp;rdquo; within half an hour with a phishing link(ether.fo). Users are asked not to clic&amp;hellip;</description></item><item><title>InsurAce</title><link>https://0xtracer.xyz/incidents/2023-08-02-insurace/</link><pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-02-insurace/</guid><description>InsurAce, a DeFi insurance protocol, tweeted: &amp;ldquo;Our Discord server experienced a security breach. Our team discovered an unauthorized access to the server earlier today. We take this incident very seriously and are wor&amp;hellip;</description></item><item><title>Uwerx network</title><link>https://0xtracer.xyz/incidents/2023-08-02-uwerx-network/</link><pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-02-uwerx-network/</guid><description>he Uwerx network was attacked and lost about 174.78 ETH. According to the analysis of SlowMist, the root cause is that when the receiving address is uniswapPoolAddress (0x01), it will burn off 1% more tokens of the tr&amp;hellip;</description></item><item><title>LeetSwap</title><link>https://0xtracer.xyz/incidents/2023-08-01-leetswap/</link><pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-08-01-leetswap/</guid><description>The axlUSD/WETH pool in LeetSwap, the largest DEX on the Base chain, suffered a price manipulation attack and has suspended trading for investigation. It appears that 342.5 ETH (~$624,000) was exploited. On August 3,&amp;hellip;</description></item><item><title>BALD</title><link>https://0xtracer.xyz/incidents/2023-07-31-bald/</link><pubDate>Mon, 31 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-31-bald/</guid><description>A MEME coin called BALD, built on the Coinbase Base test network, appears to have pulled in at least $25.6 million. Although the Base network was intended to be used for developer testing, an anonymous cryptocurrency&amp;hellip;</description></item><item><title>ZT Global</title><link>https://0xtracer.xyz/incidents/2023-07-31-zt-global/</link><pubDate>Mon, 31 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-31-zt-global/</guid><description>Some community users reported that the encrypted exchange named ZT Global was suspected of running away. Since the announcement of system upgrade and maintenance on July 28, transactions on the platform have been disa&amp;hellip;</description></item><item><title>Alchemix</title><link>https://0xtracer.xyz/incidents/2023-07-30-alchemix/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-30-alchemix/</guid><description>DeFi lending protocol Alchemix said on Twitter that after receiving notification from Curve Finance that the altH/ETH pool was attacked due to a Vyper bug, Alchemix quickly began removing AMO-controlled liquidity from&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/hacks/curve-finance/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/hacks/curve-finance/</guid><description>&lt;p>Multiple Curve pools were exploited due to a reentrancy vulnerability in Vyper compiler versions 0.2.15, 0.2.16, and 0.3.0. The compiler&amp;rsquo;s reentrancy guard was malfunctioning, allowing attackers to drain several pools.&lt;/p></description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2023-07-30-curve-finance/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-30-curve-finance/</guid><description>Vyper compiler reentrancy guard malfunction in v0.2.15-0.3.0</description></item><item><title>JPEG'd</title><link>https://0xtracer.xyz/incidents/2023-07-30-jpeg-d/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-30-jpeg-d/</guid><description>The NFT lending platform JPEG&amp;rsquo;d was hacked, and JPEG tokens fell by 40% in a short period of time, with a loss of at least about $10 million. The root cause is re-entry. When the attacker calls the remove_liquidity fu&amp;hellip;</description></item><item><title>Vyper</title><link>https://0xtracer.xyz/incidents/2023-07-30-vyper/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-30-vyper/</guid><description>On August 6, the Ethereum compiler Vyper released an analysis report on last week&amp;rsquo;s vulnerability incidents: Prior to July 30, due to potential vulnerabilities in the Vyper compiler, multiple Curve liquidity pools wer&amp;hellip;</description></item><item><title>Kannagi Finance</title><link>https://0xtracer.xyz/incidents/2023-07-29-kannagi-finance/</link><pubDate>Sat, 29 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-29-kannagi-finance/</guid><description>Kannagi Finance has rug pulled, making away with up to $2.13 million in investor funds. The platform runs o the zkSync Era, which is in the race for the best Ethereum Layer 2 network. The network has deleted its offic&amp;hellip;</description></item><item><title>DefiLabs</title><link>https://0xtracer.xyz/incidents/2023-07-28-defilabs/</link><pubDate>Fri, 28 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-28-defilabs/</guid><description>DefiLabs on the BNB chain has run away, taking about $1.6 million. The privileged address 0xee08 drains user funds by exploiting the backdoor function withdrawFunds() in the vPoolv6 contract. DeFiLabs claimed on Twitt&amp;hellip;</description></item><item><title>Pond0x</title><link>https://0xtracer.xyz/incidents/2023-07-28-pond0x/</link><pubDate>Fri, 28 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-28-pond0x/</guid><description>A serious flaw in Pond0x, the Pepe the Frog-branded MEME coin launched by Pauly0x, caused traders to lose at least $2.2 million after it was discovered that anyone could transfer tokens belonging to someone else. Peop&amp;hellip;</description></item><item><title>Carson</title><link>https://0xtracer.xyz/incidents/2023-07-27-carson/</link><pubDate>Thu, 27 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-27-carson/</guid><description>The BSC ecology Carson was attacked and lost about $145,000. At present, the price of Carson tokens has dropped by 96%, and the attacker has exchanged the stolen assets for 600 BNB and transferred them to Tornado Cash&amp;hellip;</description></item><item><title>IEGT</title><link>https://0xtracer.xyz/incidents/2023-07-26-iegt/</link><pubDate>Wed, 26 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-26-iegt/</guid><description>According to SlowMist, IEGT tokens were created on BSC on July 13. Its creators &amp;ldquo;secretly minted a large number of tokens in preparation for pulling the rug&amp;rdquo;. Although the project’s token supply is only 5 million toke&amp;hellip;</description></item><item><title>EraLend</title><link>https://0xtracer.xyz/incidents/2023-07-25-eralend/</link><pubDate>Tue, 25 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-25-eralend/</guid><description>Sync Swap pool read-only reentrancy exploited to drain funds</description></item><item><title>MetaLabz</title><link>https://0xtracer.xyz/incidents/2023-07-25-metalabz/</link><pubDate>Tue, 25 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-25-metalabz/</guid><description>MetaLabz tweeted: &amp;ldquo;In order to ensure the supply we hold, we deployed an unaudited contract (token locker), but the contract has been exploited. The situation was then exacerbated by the liquidity attack, resulting in&amp;hellip;</description></item><item><title>Palmswap</title><link>https://0xtracer.xyz/incidents/2023-07-25-palmswap/</link><pubDate>Tue, 25 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-25-palmswap/</guid><description>The Palmswap project on the BSC chain was attacked, and the attacker made a profit of more than 900,000 US dollars. According to the analysis of SlowMist, this attack was due to the fact that the authority control fun&amp;hellip;</description></item><item><title>Alphapo</title><link>https://0xtracer.xyz/incidents/2023-07-23-alphapo/</link><pubDate>Sun, 23 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-23-alphapo/</guid><description>Cryptocurrency payment service provider Alphapo&amp;rsquo;s hot wallet stolen, $23 million lost. Alphapo client HypeDrop has disabled withdrawals. The stolen funds were first exchanged for ETH on Ethereum and then cross-chained&amp;hellip;</description></item><item><title>CoinList</title><link>https://0xtracer.xyz/incidents/2023-07-23-coinlist/</link><pubDate>Sun, 23 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-23-coinlist/</guid><description>On July 23, the CoinList Twitter account was hacked. Previously, CoinList tweeted that it would launch native tokens, and then Neon EVM tweeted that the CoinList account was stolen and reminded users not to click on a&amp;hellip;</description></item><item><title>CoinsPaid</title><link>https://0xtracer.xyz/incidents/2023-07-22-coinspaid/</link><pubDate>Sat, 22 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-22-coinspaid/</guid><description>Recently, Estonian encrypted payment service provider CoinsPaid said it suffered a cyber attack and $37.3 million worth of cryptocurrency was stolen. Although the attack caused significant financial losses to the comp&amp;hellip;</description></item><item><title>Conic Finance</title><link>https://0xtracer.xyz/incidents/2023-07-22-conic-finance/</link><pubDate>Sat, 22 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-22-conic-finance/</guid><description>This second attack was unrelated to the ETH Omnipool&amp;rsquo;s re-entrancy exploit. The attacker was able to realize a profit of approximately $300k by exploiting the crvUSD Omnipool. We will share more updates as we continue&amp;hellip;</description></item><item><title>Conic Finance</title><link>https://0xtracer.xyz/incidents/2023-07-21-conic-finance/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-21-conic-finance/</guid><description>On July 21, Conic Finance ’s ETH omnipool was hit by a series of small hacks that cost around $3.2 million. Conic Finance issued an update on the attack, saying, “The root cause of the attack is due to an incorrect as&amp;hellip;</description></item><item><title>Hayden Adams</title><link>https://0xtracer.xyz/incidents/2023-07-21-hayden-adams/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-21-hayden-adams/</guid><description>The Twitter account of Uniswap founder Hayden Adams was hacked, and the account sent multiple tweets containing links to scam websites. &amp;ldquo;Hayden&amp;rsquo;s account has been hacked,&amp;rdquo; the Uniswap Foundation said in a tweet. &amp;ldquo;Do n&amp;hellip;</description></item><item><title>PleasrDAO</title><link>https://0xtracer.xyz/incidents/2023-07-19-pleasrdao/</link><pubDate>Wed, 19 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-19-pleasrdao/</guid><description>Nansen CEO Alex Svanevik tweeted that the Twitter account of PleasrDAO, a decentralized autonomous organization composed of DeFi leaders, early NFT collectors, and digital artists, has been stolen, reminding users not&amp;hellip;</description></item><item><title>Shell Protocol</title><link>https://0xtracer.xyz/incidents/2023-07-19-shell-protocol/</link><pubDate>Wed, 19 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-19-shell-protocol/</guid><description>The official Twitter account of the DeFi platform Shell Protocol on Arbitrum is suspected of being stolen. It posted false news about the application of SHELL tokens and closed the comment area. Please do not interact&amp;hellip;</description></item><item><title>APEDAO</title><link>https://0xtracer.xyz/incidents/2023-07-18-apedao/</link><pubDate>Tue, 18 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-18-apedao/</guid><description>APEDAO on the BNB chain was attacked and the loss was approximately $7,000. The attacker transferred APEDAO to the pair contract. The APEDAO contract mistook the attacker&amp;rsquo;s behavior as a selling operation and graduall&amp;hellip;</description></item><item><title>BNO</title><link>https://0xtracer.xyz/incidents/2023-07-18-bno/</link><pubDate>Tue, 18 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-18-bno/</guid><description>BNO suffered a flash loan attack on BNBChain, resulting in a loss of about $500,000 due to business logic problems. The root cause of the attack is a problem with the reward calculation mechanism in the pool that supp&amp;hellip;</description></item><item><title>GMETA</title><link>https://0xtracer.xyz/incidents/2023-07-18-gmeta/</link><pubDate>Tue, 18 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-18-gmeta/</guid><description>GMETA on BSC has been Rug Pulled, with a price drop of 96%, taking about $3.6 million. The contract creator is 0x9f02c29ad35fd20a51cd48250512a7b7feeb8ed1.</description></item><item><title>Ethscriptions.com</title><link>https://0xtracer.xyz/incidents/2023-07-13-ethscriptions-com/</link><pubDate>Thu, 13 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-13-ethscriptions-com/</guid><description>Ethscriptions.com was hacked, and about 123 individual addresses lost a total of about 202 Ethscriptions. In terms of value, it is unclear how much the attack caused. Based on the current lowest price of $14, the loss&amp;hellip;</description></item><item><title>Klever</title><link>https://0xtracer.xyz/incidents/2023-07-12-klever/</link><pubDate>Wed, 12 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-12-klever/</guid><description>Klever published a report on an external security incident on July 12. All wallets affected by the suspicious activity on July 12 were reported to be affected by a known vulnerability caused by low-entropy mnemonics&amp;hellip;.</description></item><item><title>Platypus</title><link>https://0xtracer.xyz/incidents/2023-07-12-platypus/</link><pubDate>Wed, 12 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-12-platypus/</guid><description>The Avalanche project Platypus has been attacked again. According to the analysis of SlowMist, since the price difference between the two pools was not taken into account during the token exchange via CoverageRatio, i&amp;hellip;</description></item><item><title>WGPT Token</title><link>https://0xtracer.xyz/incidents/2023-07-12-wgpt-token/</link><pubDate>Wed, 12 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-12-wgpt-token/</guid><description>On July 12th, WGPT Token suffered from a flash loan attack, resulting in losses of ~$82.5k. Address (BSC): 0x1f415255f7E2a8546559a553E962dE7BC60d7942.</description></item><item><title>LibertiVault</title><link>https://0xtracer.xyz/incidents/2023-07-11-libertivault/</link><pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-11-libertivault/</guid><description>The LibertiVault contract was attacked, losing about 123 ETH and 56,234 USDT on Polygon, worth about $290,000; 35 ETH and 96,223 USDT on Ethereum, worth about $160,000. Total damages exceeded $450,000. Attackers explo&amp;hellip;</description></item><item><title>Rodeo Finance</title><link>https://0xtracer.xyz/incidents/2023-07-11-rodeo-finance/</link><pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-11-rodeo-finance/</guid><description>The Arbitrum ecological leverage income agreement Rodeo Finance caused hackers to steal about $1.7 million due to price oracle manipulation, and currently about $816,000 has been recovered in the form of unshETH.</description></item><item><title>Arcadia Finance</title><link>https://0xtracer.xyz/incidents/2023-07-10-arcadia-finance/</link><pubDate>Mon, 10 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-10-arcadia-finance/</guid><description>Arcadia Finance has been attacked on Ethereum and Optimism, with total profits of $400K. The root cause is that in function vaultManagementAction, the attacker can first transfer all the asset to his own controlled co&amp;hellip;</description></item><item><title>CivFund</title><link>https://0xtracer.xyz/incidents/2023-07-09-civfund/</link><pubDate>Sun, 09 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-09-civfund/</guid><description>CivFund&amp;rsquo;s ETH contract was attacked and lost $180,000. The attacker calls uniswapV3MintCallback to transfer funds approved by other users. Please revoke approval for the contract under attack as soon as possible.</description></item><item><title>Aptos Foundation</title><link>https://0xtracer.xyz/incidents/2023-07-07-aptos-foundation/</link><pubDate>Fri, 07 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-07-aptos-foundation/</guid><description>The Aptos Foundation Twitter account (@Aptos_Network) has been hacked, with hackers directing people to a fraudulent website claiming to participate in a bogus airdrop. Aptos Labs also posted a warning on Twitter, rem&amp;hellip;</description></item><item><title>Gutter Cat Gang</title><link>https://0xtracer.xyz/incidents/2023-07-07-gutter-cat-gang/</link><pubDate>Fri, 07 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-07-gutter-cat-gang/</guid><description>An attacker has successfully compromised the Twitter accounts of popular NFT project Gutter Cat Gang and its co-founders, and used them to post phishing website airdrops claiming to be new NFTs. Instead of receiving t&amp;hellip;</description></item><item><title>Multichain</title><link>https://0xtracer.xyz/incidents/2023-07-06-multichain/</link><pubDate>Thu, 06 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-06-multichain/</guid><description>CEO arrested, MPC keys compromised, funds drained from bridge</description></item><item><title>Bryan Pellegrino</title><link>https://0xtracer.xyz/incidents/2023-07-05-bryan-pellegrino/</link><pubDate>Wed, 05 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-05-bryan-pellegrino/</guid><description>The cross-chain interoperability protocol LayerZero officially tweeted that its CEO Bryan Pellegrino&amp;rsquo;s Twitter account (@PrimordialAA) was stolen, reminding users not to click on any suspicious links or participate in&amp;hellip;</description></item><item><title>MIKE &amp; SID</title><link>https://0xtracer.xyz/incidents/2023-07-04-mike-and-sid/</link><pubDate>Tue, 04 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-04-mike-and-sid/</guid><description>Mike Wazowski Monsters Inc $MIKE and Sid Ice Age $SID on the Ethereum chain have been rugged via a backdoor function that allows unlimited minting of tokens. The scammer has profited 87.9 $ETH, equivalent to about $17&amp;hellip;</description></item><item><title>AzukiDao</title><link>https://0xtracer.xyz/incidents/2023-07-03-azukidao/</link><pubDate>Mon, 03 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-03-azukidao/</guid><description>After spending nearly $40 million on a new set of Azuki NFTs, the Azuki community was outraged that they were &amp;ldquo;diluting&amp;rdquo; a near-replica of the original Azuki collection. To counter what Azuki’s creators called a “blat&amp;hellip;</description></item><item><title>Encryption AI</title><link>https://0xtracer.xyz/incidents/2023-07-03-encryption-ai/</link><pubDate>Mon, 03 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-03-encryption-ai/</guid><description>Encryption project Encryption AI (0XENCRYPT) crashed 99% as the developers behind it performed a retreat. Losing a total of $2 million, the developer released a message citing his online gambling addiction.</description></item><item><title>NFT Trader</title><link>https://0xtracer.xyz/incidents/2023-07-03-nft-trader/</link><pubDate>Mon, 03 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-03-nft-trader/</guid><description>NFT Trader, a P2P digital asset trading protocol, said on Twitter that the website has been attacked, and users are asked to monitor their accounts and beware of phishing attacks. The NFT Trader website will be closed&amp;hellip;</description></item><item><title>Aave fork</title><link>https://0xtracer.xyz/incidents/2023-07-02-aave-fork/</link><pubDate>Sun, 02 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-02-aave-fork/</guid><description>The Aave fork project on the Pulse chain suffered a governance attack. The hacker first purchased a large number of Aave tokens to obtain the governance authority of the Aave fork project, and then created multiple co&amp;hellip;</description></item><item><title>Poly Network</title><link>https://0xtracer.xyz/incidents/2023-07-02-poly-network/</link><pubDate>Sun, 02 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-02-poly-network/</guid><description>The Poly Network, a cross-chain interoperability protocol, was attacked again. This attack affected 58 assets on 11 blockchains. According to SlowMist analysis, Poly Network hackers have profited over $10 million wort&amp;hellip;</description></item><item><title>Biswap</title><link>https://0xtracer.xyz/incidents/2023-07-01-biswap/</link><pubDate>Sat, 01 Jul 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-07-01-biswap/</guid><description>BiSwap, a BSC cross-chain trading platform, said: &amp;ldquo;The team detected and resolved the Migrator contract vulnerability. The assets on the Biswap V2 and V3 AMM protocols are safe. The team prevents access to the migrati&amp;hellip;</description></item><item><title>Smurfs Coin</title><link>https://0xtracer.xyz/incidents/2023-06-30-smurfs-coin/</link><pubDate>Fri, 30 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-30-smurfs-coin/</guid><description>The Smurfs Coin project is an exit scam, and the contract deployer sold the tokens on June 13 and removed a total of 227 ETH (approximately $423,000) of liquidity. The contract address is ETH: 0x5F250ed62CF3E5cF25F4F3&amp;hellip;</description></item><item><title>Manta Network</title><link>https://0xtracer.xyz/incidents/2023-06-28-manta-network/</link><pubDate>Wed, 28 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-28-manta-network/</guid><description>The Twitter account of Manta Network, a Poca eco-privacy project, which was previously stolen and posted false airdrops, has been restored.</description></item><item><title>Themis</title><link>https://0xtracer.xyz/incidents/2023-06-28-themis/</link><pubDate>Wed, 28 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-28-themis/</guid><description>Themis, a cryptographic lending protocol, has been subject to a prophecy machine manipulation attack, and the attackers have stolen approximately $370,000. The hack is due to a flawed oracle, exploited to inflate the&amp;hellip;</description></item><item><title>Chibi Finance</title><link>https://0xtracer.xyz/incidents/2023-06-27-chibi-finance/</link><pubDate>Tue, 27 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-27-chibi-finance/</guid><description>A suspected Rug Pull occurred on the Chibi Finance project on Arbitrum, and $1 million worth of cryptocurrency was drained. The stolen funds have been converted into approximately 555 ETH and transferred to Tornado Ca&amp;hellip;</description></item><item><title>Entangle Protocol</title><link>https://0xtracer.xyz/incidents/2023-06-27-entangle-protocol/</link><pubDate>Tue, 27 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-27-entangle-protocol/</guid><description>On June 27th, Entangle Protocol&amp;rsquo;s Discord was hacked.</description></item><item><title>ZigZag</title><link>https://0xtracer.xyz/incidents/2023-06-27-zigzag/</link><pubDate>Tue, 27 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-27-zigzag/</guid><description>ZK Rollup Order Book DEX Protocol ZigZag tweeted, &amp;ldquo;Our Discord has been hacked, please note that there is no airdrop activity at ZigZag at this time, please do not click on phishing links. We are working to resolve th&amp;hellip;</description></item><item><title>Blockchain for dog nose wrinkles</title><link>https://0xtracer.xyz/incidents/2023-06-25-blockchain-for-dog-nose-wrinkles/</link><pubDate>Sun, 25 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-25-blockchain-for-dog-nose-wrinkles/</guid><description>‘Blockchain for dog nose wrinkles’ Ponzi makes off with $127m. A South Korean company lured investors with its new technology: a blockchain app that can identify dogs by their nose wrinkles.The investigation found tha&amp;hellip;</description></item><item><title>Ichioka Ventures</title><link>https://0xtracer.xyz/incidents/2023-06-24-ichioka-ventures/</link><pubDate>Sat, 24 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-24-ichioka-ventures/</guid><description>The U.S. Commodity Futures Trading Commission (CFTC) recently filed a lawsuit in the U.S. District Court for the Northern District of California against William Koo Ichioka, an alleged digital asset and foreign exchan&amp;hellip;</description></item><item><title>Shido</title><link>https://0xtracer.xyz/incidents/2023-06-24-shido/</link><pubDate>Sat, 24 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-24-shido/</guid><description>Shido has been exploited for &lt;del>976 $BNB (&lt;/del>$238.5K). The exploiter transferred 1 $BNB to Tornado Cash and bridged the stolen funds to Ethereum, subsequently transferring 125 $ETH to Tornado Cash.</description></item><item><title>Astaria</title><link>https://0xtracer.xyz/incidents/2023-06-20-astaria/</link><pubDate>Tue, 20 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-20-astaria/</guid><description>Astaria, the NFT lending platform, tweeted: &amp;ldquo;At 12:42 BST on June 20, Astaria became aware of an issue with the basic execution of BeaconProxy.sol that allowed an attacker to manipulate the beacon to load a malicious&amp;hellip;</description></item><item><title>IPO</title><link>https://0xtracer.xyz/incidents/2023-06-20-ipo/</link><pubDate>Tue, 20 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-20-ipo/</guid><description>The project named &amp;ldquo;IPO&amp;rdquo; (Twitter handle @IPO_web3) is suspected to have suffered a Rug Pull, losing around 102,000 BSC-USD, the project&amp;rsquo;s tokens are down 32%, and the stolen funds are now located in addresses beginnin&amp;hellip;</description></item><item><title>Slingshot</title><link>https://0xtracer.xyz/incidents/2023-06-20-slingshot/</link><pubDate>Tue, 20 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-20-slingshot/</guid><description>The Twitter account of decentralized exchange Slingshot has been compromised by scammer Pink Drainer, who posted links to fake websites and claimed that users could claim airdrop tokens. Users are advised to be aware&amp;hellip;</description></item><item><title>Ara</title><link>https://0xtracer.xyz/incidents/2023-06-19-ara/</link><pubDate>Mon, 19 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-19-ara/</guid><description>The Ara project was attacked by a flash loan. The attackers are suspected to have made about $124,000 in BUSD. attacker address: 0xF84efA8a9F7E68855CF17EAaC9c2f97A9d131366.</description></item><item><title>VPANDA DAO</title><link>https://0xtracer.xyz/incidents/2023-06-19-vpanda-dao/</link><pubDate>Mon, 19 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-19-vpanda-dao/</guid><description>Seems like @VPandaCommunity rugged for ~265K $BSC-USD $VPC has dropped -97.4%, the stolen funds has already been transferred to 0x33d2a4&amp;hellip;af65</description></item><item><title>Midas Capital</title><link>https://0xtracer.xyz/incidents/2023-06-18-midas-capital/</link><pubDate>Sun, 18 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-18-midas-capital/</guid><description>Cross-chain money market solution Midas Capital has been hacked, causing losses of more than $600,000 after an integer rounding problem in its lending protocol (derived from a fork of the well-known Compound Finance v&amp;hellip;</description></item><item><title>DEP/USDT, LEV/USDC</title><link>https://0xtracer.xyz/incidents/2023-06-15-dep-usdt-lev-usdc/</link><pubDate>Thu, 15 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-15-dep-usdt-lev-usdc/</guid><description>DEP/USDT and LEV/USDC pools were stolen with 105,800 stablecoins worth (36,000 USDC and 69,960,000 USDT), and the attackers initially received 1 ETH of initial funding from Tornado Cash.</description></item><item><title>Hashflow</title><link>https://0xtracer.xyz/incidents/2023-06-15-hashflow/</link><pubDate>Thu, 15 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-15-hashflow/</guid><description>Decentralized trading platform Hashflow is suspected to have suffered an authorization-related attack, though this may be a white-hat hacking operation. The loss from the theft was approximately $600,000, and all affe&amp;hellip;</description></item><item><title>Move VM</title><link>https://0xtracer.xyz/incidents/2023-06-15-move-vm/</link><pubDate>Thu, 15 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-15-move-vm/</guid><description>Recently, a security firm discovered a stack overflow vulnerability in the Move VM that does not limit the depth of recursive calls, which can cause a total network shutdown, prevent new validator nodes from joining t&amp;hellip;</description></item><item><title>Sturdy</title><link>https://0xtracer.xyz/incidents/2023-06-12-sturdy/</link><pubDate>Mon, 12 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-12-sturdy/</guid><description>The DeFi lending protocol Sturdy is suspected to have been hacked, and information on the chain suggests that the attack may have been carried out through price manipulation. The attackers have transferred 442.6 ETH t&amp;hellip;</description></item><item><title>Atlantis Loans</title><link>https://0xtracer.xyz/incidents/2023-06-11-atlantis-loans/</link><pubDate>Sun, 11 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-11-atlantis-loans/</guid><description>A governance attack on the BSC eco-protocol Atlantis Loans, in which attackers gained control of the contract and replaced it with a contract containing backdoor functionality to transfer user assets, is currently cos&amp;hellip;</description></item><item><title>Ben Armstrong</title><link>https://0xtracer.xyz/incidents/2023-06-11-ben-armstrong/</link><pubDate>Sun, 11 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-11-ben-armstrong/</guid><description>ZenGo CEO Ouriel Ohayon tweeted that BitBoy Crypto founder Ben Armstrong&amp;rsquo;s Twitter account was hacked and used to promote a crypto scam to steal users&amp;rsquo; NFT assets, the same scam that hit garry tan, peter schiff and ot&amp;hellip;</description></item><item><title>FPG</title><link>https://0xtracer.xyz/incidents/2023-06-11-fpg/</link><pubDate>Sun, 11 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-11-fpg/</guid><description>A spokesperson for Floating Point Group (FPG), a trading platform for crypto institutions, said it was hit by a cyber attack on June 11 and has lost between $15 million and $20 million in cryptocurrency. fpg has taken&amp;hellip;</description></item><item><title>TrustTheTrident</title><link>https://0xtracer.xyz/incidents/2023-06-11-trustthetrident/</link><pubDate>Sun, 11 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-11-trustthetrident/</guid><description>TrustTheTrident ($SELLC) suffered an attack that resulted in approximately $95,000 in losses.</description></item><item><title>Franklin</title><link>https://0xtracer.xyz/incidents/2023-06-09-franklin/</link><pubDate>Fri, 09 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-09-franklin/</guid><description>NFT giant whale Franklin is suspected to have posted a warning on his Twitter handle @ElectionDayMad1 with text and video that his Twitter account @franklinisbored was stolen, please do not send any cryptocurrency or&amp;hellip;</description></item><item><title>Arbitrum</title><link>https://0xtracer.xyz/incidents/2023-06-08-arbitrum/</link><pubDate>Thu, 08 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-08-arbitrum/</guid><description>According to official sources, a bug in Arbitrum&amp;rsquo;s sequencer code previously caused a brief outage in the network&amp;rsquo;s batch transaction submission feature, which prevented transactions from being confirmed on the main c&amp;hellip;</description></item><item><title>USEA</title><link>https://0xtracer.xyz/incidents/2023-06-07-usea/</link><pubDate>Wed, 07 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-07-usea/</guid><description>A Rug Pull occurred on the USEA token on BNB Chain with a loss of about $1.1 million, and the deployer minted a total of 700 million USEAs via the mint function, then transferred them to EOA addresses and sold 1114468&amp;hellip;</description></item><item><title>Xverse</title><link>https://0xtracer.xyz/incidents/2023-06-07-xverse/</link><pubDate>Wed, 07 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-07-xverse/</guid><description>Ordinals eco-wallet Xverse tweeted: Xverse has fixed a bug that caused wallet helpers to be stored unencrypted on local devices, and all users should update the Chrome extension to the latest version. The risk of this&amp;hellip;</description></item><item><title>Cole</title><link>https://0xtracer.xyz/incidents/2023-06-06-cole/</link><pubDate>Tue, 06 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-06-cole/</guid><description>According to a tweet from MistTrack, the Twitter account of Cole, co-founder of the NFT project Pudgy Penguins, appears to have been attacked, seemingly by the PinkDrainer hacker group. Please do not click on suspicio&amp;hellip;</description></item><item><title>NFDAO</title><link>https://0xtracer.xyz/incidents/2023-06-06-nfdao/</link><pubDate>Tue, 06 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-06-nfdao/</guid><description>NFDAO (NFD) bulk liquidity has been removed. The deployer&amp;rsquo;s associated wallet removed the liquidity and made a profit of about $88,300. bsc address: 0xe1AFC0A3c9aA2537DEea233EF7dc0952ceEDfDA3.</description></item><item><title>Atomic Wallet</title><link>https://0xtracer.xyz/incidents/2023-06-03-atomic-wallet/</link><pubDate>Sat, 03 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-03-atomic-wallet/</guid><description>User private keys extracted across 5,500+ wallets, Lazarus Group attributed</description></item><item><title>CosmWasm</title><link>https://0xtracer.xyz/incidents/2023-06-02-cosmwasm/</link><pubDate>Fri, 02 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-02-cosmwasm/</guid><description>Jump Crypto, the digital asset trading arm of Jump Trading, said on Twitter that its security team discovered a stack overflow vulnerability in CosmWasm, a smart contract platform designed by the Cosmos ecosystem. The&amp;hellip;</description></item><item><title>Cellframe Network</title><link>https://0xtracer.xyz/incidents/2023-06-01-cellframe-network/</link><pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-01-cellframe-network/</guid><description>The Cellframe Network, a blockchain network based on sharding architecture, is suspected of being attacked by a flash loan. The attacker made a profit of 245 BNB (approximately 74,000 US dollars), and the token CELL h&amp;hellip;</description></item><item><title>DD Coin</title><link>https://0xtracer.xyz/incidents/2023-06-01-dd-coin/</link><pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-06-01-dd-coin/</guid><description>DD Coin was attacked and lost about 126,000 USDT. The attacker initially received 1 BNB of funds from Tornado Cash about 17 days ago. DD Coin has lost 21%.</description></item><item><title>Pixel Penguin</title><link>https://0xtracer.xyz/incidents/2023-05-31-pixel-penguin/</link><pubDate>Wed, 31 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-31-pixel-penguin/</guid><description>On-chain detective ZachXBT tweeted that a Rug Pull occurred on Pixel Penguin, a charity project created by Hopeexist1, which claimed to raise funds to help him fight cancer. At present, the social accounts of Hopeexis&amp;hellip;</description></item><item><title>Sashimi Swap</title><link>https://0xtracer.xyz/incidents/2023-05-31-sashimi-swap/</link><pubDate>Wed, 31 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-31-sashimi-swap/</guid><description>A MEV bot (0xb2…2B96 is the MEV bot call contract, 0xb4…0343 is the single-use MEV bot) borrowed 95,000 WETH (worth nearly $180 million) via flash loan to attack Sashimi Swap. The bot swept away the last remaining mon&amp;hellip;</description></item><item><title>unshETH</title><link>https://0xtracer.xyz/incidents/2023-05-31-unsheth/</link><pubDate>Wed, 31 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-31-unsheth/</guid><description>The LSDFi protocol unshETH stated that at around 22:00 on May 31, one of the deployment private keys of the unshETH contract was leaked. For the sake of caution, the official has urgently suspended the withdrawal of u&amp;hellip;</description></item><item><title>Waifu AI World</title><link>https://0xtracer.xyz/incidents/2023-05-31-waifu-ai-world/</link><pubDate>Wed, 31 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-31-waifu-ai-world/</guid><description>Twitter user @ChrisONCT cited on-chain data to expose a suspected scam Meme coin project Waifu AI World (WFAI). The token economics announced by the project stated that 95% of the supply was allocated to LPs. However,&amp;hellip;</description></item><item><title>BlockGPT</title><link>https://0xtracer.xyz/incidents/2023-05-30-blockgpt/</link><pubDate>Tue, 30 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-30-blockgpt/</guid><description>The Rug Pull of the BSC project BlockGPT occurred, involving assets of over 816 BNB (about 256,000 US dollars), and 800 BNB have been transferred to Tornado Cash so far.</description></item><item><title>EDE</title><link>https://0xtracer.xyz/incidents/2023-05-30-ede/</link><pubDate>Tue, 30 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-30-ede/</guid><description>The perpetual DEX El Dorado Exchange (EDE) is suspected to have been attacked with losses of about $580,000, and an address has been sending small amounts of money to Arbitrum&amp;rsquo;s ELP-1 pool and withdrawing large amount&amp;hellip;</description></item><item><title>TRON</title><link>https://0xtracer.xyz/incidents/2023-05-30-tron/</link><pubDate>Tue, 30 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-30-tron/</guid><description>DWallet Labs discovered a zero-day vulnerability in TRON multi-signature accounts that put more than $500 million in digital assets at risk. What about the threshold and number of signers defined in the account. The b&amp;hellip;</description></item><item><title>Aleo</title><link>https://0xtracer.xyz/incidents/2023-05-29-aleo/</link><pubDate>Mon, 29 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-29-aleo/</guid><description>Fede&amp;rsquo;s Intern, a contributor to the venture capital studio LambdaClass, said on Twitter that it found that Aleo, a programmable privacy network, had an inflation loophole and used the first loophole to stop block prod&amp;hellip;</description></item><item><title>Polygon zkEVM</title><link>https://0xtracer.xyz/incidents/2023-05-29-polygon-zkevm/</link><pubDate>Mon, 29 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-29-polygon-zkevm/</guid><description>Blockchain security researcher iczc tweeted that a vulnerability was found in Polygon zkEVM and received a bug bounty from Immunefi L2. The vulnerability prevents asset migration from L1 to L2 by preventing assets bri&amp;hellip;</description></item><item><title>Jimbos Protocol</title><link>https://0xtracer.xyz/incidents/2023-05-28-jimbos-protocol/</link><pubDate>Sun, 28 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-28-jimbos-protocol/</guid><description>Lack of slippage control on liquidity operations exploited via swap</description></item><item><title>Arthur Madrid</title><link>https://0xtracer.xyz/incidents/2023-05-26-arthur-madrid/</link><pubDate>Fri, 26 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-26-arthur-madrid/</guid><description>The Sandbox tweeted that the Twitter account of its CEO and co-founder Arthur Madrid was hacked, and the hackers posted a scam/phishing link for a fake SAND token airdrop. The Sandbox reminds users not to click on the&amp;hellip;</description></item><item><title>Patricia</title><link>https://0xtracer.xyz/incidents/2023-05-26-patricia/</link><pubDate>Fri, 26 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-26-patricia/</guid><description>Nigerian gift card and cryptocurrency trading platform Patricia revealed on May 26 that hackers compromised its retail trading app, resulting in an undisclosed amount of BTC and naira assets being compromised, News.bi&amp;hellip;</description></item><item><title>Multichain</title><link>https://0xtracer.xyz/incidents/2023-05-25-multichain/</link><pubDate>Thu, 25 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-25-multichain/</guid><description>Multichain tweeted that although most of the cross-chain routes of the Multichain protocol are operating normally, due to force majeure, some cross-chain routes cannot be used, and the time to restore services is unkn&amp;hellip;</description></item><item><title>Trezor</title><link>https://0xtracer.xyz/incidents/2023-05-25-trezor/</link><pubDate>Thu, 25 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-25-trezor/</guid><description>According to The Block, cybersecurity firm Unciphered claims it was able to hack into hardware-encrypted wallets powered by Trezor T models. In a YouTube demo, Unciphered showed exploiting the wallet vulnerability to&amp;hellip;</description></item><item><title>Celer Network</title><link>https://0xtracer.xyz/incidents/2023-05-24-celer-network/</link><pubDate>Wed, 24 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-24-celer-network/</guid><description>Cross-chain interoperability protocol Celer Network reported Wednesday that it has patched a code vulnerability first discovered by Jump Crypto, The Block reported. In a blog post published by Celer and Jump Crypto, a&amp;hellip;</description></item><item><title>CS Token</title><link>https://0xtracer.xyz/incidents/2023-05-24-cs-token/</link><pubDate>Wed, 24 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-24-cs-token/</guid><description>CS Token was hacked and a total of 714,000 USDT was stolen. The hacker initially transferred 1 BNB from Tornado Cash, and then transferred 383 ETH to Tornado Cash.</description></item><item><title>Fintoch</title><link>https://0xtracer.xyz/incidents/2023-05-24-fintoch/</link><pubDate>Wed, 24 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-24-fintoch/</guid><description>The team behind Fintoch, a blockchain financial platform, is suspected of being a Ponzi scheme. It defrauded users of 31.6 million USDT on BNB Chain, and the funds were bridged to multiple addresses on Tron and Ethere&amp;hellip;</description></item><item><title>LunaFi</title><link>https://0xtracer.xyz/incidents/2023-05-23-lunafi/</link><pubDate>Tue, 23 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-23-lunafi/</guid><description>Polygon ecological project LunaFi was attacked. The attacker obtained initial funds from TornadoCash on BSC, the root cause was a flaw in reward calculation, and many other issues in the contract.</description></item><item><title>Aave</title><link>https://0xtracer.xyz/incidents/2023-05-20-aave/</link><pubDate>Sat, 20 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-20-aave/</guid><description>About 110 million USD in WETH, USDT, WBTC, WMATIC in Aave V2 on Polygon cannot be withdrawn, nor can it be borrowed and repaid. This is because the interest rate strategy contract is only compatible with Ethereum, not&amp;hellip;</description></item><item><title>CoinDeal</title><link>https://0xtracer.xyz/incidents/2023-05-20-coindeal/</link><pubDate>Sat, 20 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-20-coindeal/</guid><description>A Nevada man has been charged in connection with his alleged involvement in CoinDeal, an investment fraud scheme that defrauded more than 10,000 victims of more than $45 million, the U.S. Department of Justice announc&amp;hellip;</description></item><item><title>Swap-LP</title><link>https://0xtracer.xyz/incidents/2023-05-20-swap-lp/</link><pubDate>Sat, 20 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-20-swap-lp/</guid><description>The Swap-LP contract on BNB Chain (0xe0c352c56af65772ac7c9ab45b858cb43d22f28f) has been attacked with a loss of approximately $1.1 million. The attacker (0xdead) transferred the stolen funds to Tornado Cash. specifica&amp;hellip;</description></item><item><title>Tornado Cash</title><link>https://0xtracer.xyz/incidents/2023-05-20-tornado-cash/</link><pubDate>Sat, 20 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-20-tornado-cash/</guid><description>At 15:25 on May 20, Tornado Cash encountered a governance attack. The attacker granted himself 1.2 million votes through a malicious proposal, exceeding the number of legal votes (about 700,000), and gained full gover&amp;hellip;</description></item><item><title>Stacks</title><link>https://0xtracer.xyz/incidents/2023-05-19-stacks/</link><pubDate>Fri, 19 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-19-stacks/</guid><description>On May 19, Blockworks Research stated on Twitter that the Bitcoin Layer 2 network Stacks has experienced several obstacles in the past few months: 1. There is a serious loophole in the STX &amp;ldquo;stacking&amp;rdquo; mechanism; 2. Con&amp;hellip;</description></item><item><title>Swaprum</title><link>https://0xtracer.xyz/incidents/2023-05-19-swaprum/</link><pubDate>Fri, 19 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-19-swaprum/</guid><description>The Arbitrum ecological Swaprum project has a Rug Pull, the price of SAPR has dropped by 100%, Swaprum has deleted the social account, and the scammer bridged 1628 ETH (about 2.94 million US dollars) to Ethereum and t&amp;hellip;</description></item><item><title>WDZD Swap</title><link>https://0xtracer.xyz/incidents/2023-05-19-wdzd-swap/</link><pubDate>Fri, 19 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-19-wdzd-swap/</guid><description>The DeFi protocol WDZD Swap on BSC was exploited and lost about $1.1 million. The attackers made nine malicious transactions that drained 609 Binance-Pegged ETH from contracts related to the WDZD project.</description></item><item><title>EOS EVM</title><link>https://0xtracer.xyz/incidents/2023-05-16-eos-evm/</link><pubDate>Tue, 16 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-16-eos-evm/</guid><description>The EOS Network Foundation tweeted that the EOS EVM has released version v0.4.2, which fixes a serious security vulnerability found in the EOS EVM. The EOS EVM contracts, EOS EVM nodes, and EOS EVM RPC components impl&amp;hellip;</description></item><item><title>Mirror</title><link>https://0xtracer.xyz/incidents/2023-05-16-mirror/</link><pubDate>Tue, 16 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-16-mirror/</guid><description>The Web3 content publishing platform Mirror application is currently experiencing an outage under load.</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2023-05-16-opensea/</link><pubDate>Tue, 16 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-16-opensea/</guid><description>Alexpf.eth, co-founder and CEO of NFT exchange EZswap, tweeted: &amp;ldquo;OpenSea is suspected of having a royalty loophole. Recently, OpenSea seems to have changed the owner&amp;rsquo;s identification standard, which means that NFT pro&amp;hellip;</description></item><item><title>land</title><link>https://0xtracer.xyz/incidents/2023-05-15-land/</link><pubDate>Mon, 15 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-15-land/</guid><description>The DeFi protocol land was suspected of being attacked and lost about 150,000 US dollars. The reason for the attack was the lack of mint permission control.</description></item><item><title>LW</title><link>https://0xtracer.xyz/incidents/2023-05-12-lw/</link><pubDate>Fri, 12 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-12-lw/</guid><description>The LW token on BSC was attacked, with a loss of 48,415 USDT, and the price of LW token plummeted by 69%. The attackers have transferred about 150 BNB to Tornado Cash.</description></item><item><title>FLOKI</title><link>https://0xtracer.xyz/incidents/2023-05-10-floki/</link><pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-10-floki/</guid><description>The ethereum-based meme cryptocurrency FLOKI has suffered a lightning loan attack with a loss of over $50,000. Stolen TX: &lt;a href="https://etherscan.io/tx/0x118b7b7c11f9e9bd630ea84ef267b183b34021b667f4a3061f048207d266437a">https://etherscan.io/tx/0x118b7b7c11f9e9bd630ea84ef267b183b34021b667f4a3061f048207d266437a&lt;/a></description></item><item><title>SNK</title><link>https://0xtracer.xyz/incidents/2023-05-10-snk/</link><pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-10-snk/</guid><description>The SNK project was attacked. The hacker used SNK&amp;rsquo;s invitation reward mechanism to make a profit of 190,000 US dollars.</description></item><item><title>DMAN</title><link>https://0xtracer.xyz/incidents/2023-05-09-dman/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-dman/</guid><description>Derpman ($DMAN) Rugged. The scammer initially obtained 4 ETH from Binance, added 3 ETH to liquidity, then exchanged 1,200T DMAN for 48.55 ETH ($89,611.09), and transferred these ETHs to 0x4d1f…915.</description></item><item><title>FREDDIE</title><link>https://0xtracer.xyz/incidents/2023-05-09-freddie/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-freddie/</guid><description>Freddie ($FREDDIE) has Rugged. The scammer initially obtained 2.96 ETH from Orbiter Finance Bridge and added 2 ETH liquidity, then exchanged 4,999T FREDDIE for 28 ETH ($52,344.4), and mortgaged 22.5 ETH to Lido.</description></item><item><title>GNS</title><link>https://0xtracer.xyz/incidents/2023-05-09-gns/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-gns/</guid><description>GeniusMeme ($GNS) has Rugged 33.6 ETH($62,180.81). The scammer initially received 4 ETH from Binance and added 3 ETH to liquidity.</description></item><item><title>HAKUNA</title><link>https://0xtracer.xyz/incidents/2023-05-09-hakuna/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-hakuna/</guid><description>Hakuna Matata ($HAKUNA) Rugged. The scammer initially obtained 2.76 ETH from Orbiter Finance Bridge and added 2 ETH liquidity, then exchanged 4,999T HAKUNA for 17 ETH ($31,683.11), and mortgaged 13.5 ETH to Lido.</description></item><item><title>HIS</title><link>https://0xtracer.xyz/incidents/2023-05-09-his/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-his/</guid><description>FTX ($HIS) Rugged. The scammer initially obtained 2.76 ETH from Orbiter Finance Bridge and added 2 ETH liquidity, then exchanged 4,999T HIS for 13 ETH ($24,568.11), and mortgaged 11.5 ETH to Lido.</description></item><item><title>MChainCapital</title><link>https://0xtracer.xyz/incidents/2023-05-09-mchaincapital/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-mchaincapital/</guid><description>MChainCapital suffered a flash loan attack and lost about $18,871. TX: &lt;a href="https://etherscan.io/tx/0xf72f1d10fc6923f87279ce6c0aef46e372c6652a696f280b0465a301a92f2e26">https://etherscan.io/tx/0xf72f1d10fc6923f87279ce6c0aef46e372c6652a696f280b0465a301a92f2e26&lt;/a></description></item><item><title>PEPG</title><link>https://0xtracer.xyz/incidents/2023-05-09-pepg/</link><pubDate>Tue, 09 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-09-pepg/</guid><description>Pepega ($PEPG) has Rugged 30 ETH ($55,609.2). The scammer initially received 3.58 ETH from Binance and added 2.8 ETH to liquidity.</description></item><item><title>Art Coin</title><link>https://0xtracer.xyz/incidents/2023-05-07-art-coin/</link><pubDate>Sun, 07 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-07-art-coin/</guid><description>The encrypted art platform Art Coin deployed a liquidity pool (LP pool) on Uniswap V3 on May 7. After a user discovered a loophole in the pre-sale process of Art Coin’s ART token Uniswap V3, he immediately sold the AR&amp;hellip;</description></item><item><title>DEI</title><link>https://0xtracer.xyz/incidents/2023-05-06-dei/</link><pubDate>Sat, 06 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-06-dei/</guid><description>The stablecoin DEI launched by the DeFi protocol DEUS has been hacked, and the loss has exceeded $6.3 million. Over $5 million was lost on Arbitrum and $1.3 million on the BSC chain. This appears to be a public destro&amp;hellip;</description></item><item><title>REI Network</title><link>https://0xtracer.xyz/incidents/2023-05-06-rei-network/</link><pubDate>Sat, 06 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-06-rei-network/</guid><description>The public chain REI Network stated in a telegram announcement that its official Twitter account was hacked, do not believe the airdrop information, and wait for further notice. After checking, the Twitter account has&amp;hellip;</description></item><item><title>YODA</title><link>https://0xtracer.xyz/incidents/2023-05-05-yoda/</link><pubDate>Fri, 05 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-05-yoda/</guid><description>YODA coin project happened Rug Pull, YODA token price fell 100%, @yodacoineth_ has deleted his social account/group. Scammers have transferred 68 ETH (~$130,000) to FixedFloat.</description></item><item><title>Neverfall protocol</title><link>https://0xtracer.xyz/incidents/2023-05-04-neverfall-protocol/</link><pubDate>Thu, 04 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-04-neverfall-protocol/</guid><description>Neverfall protocol Hacked, $75,000 Lost. The attackers have deposited funds into TornadoCash.</description></item><item><title>WSB Coin</title><link>https://0xtracer.xyz/incidents/2023-05-04-wsb-coin/</link><pubDate>Thu, 04 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-04-wsb-coin/</guid><description>A Rug Pull on the meme coin project WSB Coin, again involving an address on-chain marked “ZJZ.eth,” dumped most of the WSB team’s supply for $635,000 (334 ETH).</description></item><item><title>Daniel Alegre</title><link>https://0xtracer.xyz/incidents/2023-05-03-daniel-alegre/</link><pubDate>Wed, 03 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-03-daniel-alegre/</guid><description>Yuga Labs tweeted that the Twitter account of the company&amp;rsquo;s new CEO, Daniel Alegre, was hacked and is now under hacker control. Yuga Labs reminds users not to click on any minting links, nor to interact with any twitt&amp;hellip;</description></item><item><title>XIRTAM</title><link>https://0xtracer.xyz/incidents/2023-05-03-xirtam/</link><pubDate>Wed, 03 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-03-xirtam/</guid><description>XIRTAM, a project built on the Arbitrum ecology, is a reputation building platform that does not require KYC. It advocates building digital reputation step by step through the XIRTAM system in an anonymous and decentr&amp;hellip;</description></item><item><title>LEVEL Finance</title><link>https://0xtracer.xyz/incidents/2023-05-02-level-finance/</link><pubDate>Tue, 02 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-02-level-finance/</guid><description>LEVEL Finance, a project on BNB, was hacked and lost $1 million. The hackers created an unverified contract 7 days before the attack, used a delegate function to extract LVL tokens in 15,000 increments, converted 214,&amp;hellip;</description></item><item><title>pcash</title><link>https://0xtracer.xyz/incidents/2023-05-01-pcash/</link><pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-05-01-pcash/</guid><description>The EOS project pcash was attacked and lost about $2 million.</description></item><item><title>0VIX</title><link>https://0xtracer.xyz/incidents/2023-04-30-0vix/</link><pubDate>Sun, 30 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-30-0vix/</guid><description>DeFi protocol 0VIX on the Polygon chain was exploited for around $2 million. The attack was carried out by an attacker manipulating the oracle, who then performed a flash loan attack on the project. The agreement was&amp;hellip;</description></item><item><title>Merlin</title><link>https://0xtracer.xyz/incidents/2023-04-26-merlin/</link><pubDate>Wed, 26 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-26-merlin/</guid><description>Bobie, the founder of 0xScope, the Web3 knowledge graph protocol, tweeted that the liquidity of the zkSync ecological DEX Merlin was exhausted, and hackers stole $1.82 million in funds and bridged to Ethereum. Accordi&amp;hellip;</description></item><item><title>Ordinals Finance</title><link>https://0xtracer.xyz/incidents/2023-04-25-ordinals-finance/</link><pubDate>Tue, 25 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-25-ordinals-finance/</guid><description>Ordinals Finance has been identified as an exit scam project that caused $1 million in losses. The deployer withdraws OFI tokens from the OEBStaking contract, exchanges them for ETH and transfers them to the EOA addre&amp;hellip;</description></item><item><title>Kucoin</title><link>https://0xtracer.xyz/incidents/2023-04-24-kucoin/</link><pubDate>Mon, 24 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-24-kucoin/</guid><description>The crypto exchange Kucoin stated that its official Twitter account was stolen for about 45 minutes from 00:00 on April 24 (UTC+2) on the 24th, and the attacker posted false activities, causing multiple users to lose&amp;hellip;</description></item><item><title>UniSat Marketplace</title><link>https://0xtracer.xyz/incidents/2023-04-24-unisat-marketplace/</link><pubDate>Mon, 24 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-24-unisat-marketplace/</guid><description>UniSat Wallet tweeted: “Due to a vulnerability in our code base, the UniSat Marketplace that just launched has suffered a lot of double-spend attacks. In the test last week, we simulated different double-spend attack&amp;hellip;</description></item><item><title>FilDA</title><link>https://0xtracer.xyz/incidents/2023-04-23-filda/</link><pubDate>Sun, 23 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-23-filda/</guid><description>Multi-chain lending protocol FilDA released a vulnerability exploit statement saying that it was attacked earlier today on the Elastos Smart Chain (ESC) and REI networks, causing losses of approximately $700,000. No o&amp;hellip;</description></item><item><title>MEV Bot</title><link>https://0xtracer.xyz/incidents/2023-04-20-mev-bot/</link><pubDate>Thu, 20 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-20-mev-bot/</guid><description>Sealaunch, an NFT data and research platform, has monitored that the MEV Bot named jaredfromsubway.eth recently carried out &amp;ldquo;sandwich attacks&amp;rdquo; on buyers and sellers of Meme coins such as WOJAK and PEPE, earning more t&amp;hellip;</description></item><item><title>Tales of Elleria</title><link>https://0xtracer.xyz/incidents/2023-04-20-tales-of-elleria/</link><pubDate>Thu, 20 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-20-tales-of-elleria/</guid><description>Wayne, the co-founder of the NFT game Tales of Elleria, tweeted early this morning: &amp;ldquo;The bridge contract of Tales of Elleria was exploited, causing its LP to be depleted and losing more than $280,000. The attacker see&amp;hellip;</description></item><item><title>zkLink</title><link>https://0xtracer.xyz/incidents/2023-04-19-zklink/</link><pubDate>Wed, 19 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-19-zklink/</guid><description>The Discord server of the cross-chain trading platform zkLink has been hacked, and some hackers posted phishing links. Do not click on any links until the team confirms that they have regained control of the server.</description></item><item><title>Arbtomb</title><link>https://0xtracer.xyz/incidents/2023-04-18-arbtomb/</link><pubDate>Tue, 18 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-18-arbtomb/</guid><description>The Arbitrum ecological Arbtomb project is suspected of Rug Pull. The scammer has bridged 54 ETH (approximately $110,000) to Ethereum, then transferred 52 ETH to Tornado Cash, and transferred 2.4 ETH to Binance.</description></item><item><title>KyberSwap</title><link>https://0xtracer.xyz/incidents/2023-04-17-kyberswap/</link><pubDate>Mon, 17 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-17-kyberswap/</guid><description>KyberSwap, a DEX aggregator and liquidity platform, tweeted that they discovered a potential loophole in KyberSwap Elastic, and hoped that liquidity providers could extract liquidity as soon as possible. No user asset&amp;hellip;</description></item><item><title>Hundred Finance</title><link>https://0xtracer.xyz/incidents/2023-04-15-hundred-finance/</link><pubDate>Sat, 15 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-15-hundred-finance/</guid><description>Donated tokens to empty market to inflate exchange rate and drain</description></item><item><title>Bitrue</title><link>https://0xtracer.xyz/incidents/2023-04-14-bitrue/</link><pubDate>Fri, 14 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-14-bitrue/</guid><description>Bitrue tweeted: We have identified a brief exploit in one of our hot wallets on 07:18 (UTC), 14 April 2023. We were able to address this matter quickly and prevented the further exploit of funds. The attackers were ab&amp;hellip;</description></item><item><title>SyncDex</title><link>https://0xtracer.xyz/incidents/2023-04-13-syncdex/</link><pubDate>Thu, 13 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-13-syncdex/</guid><description>Zksync era mainnet SyncDex project has exited with a rugpull, resulting in over $370,000 USD in losses.</description></item><item><title>Yearn Finance</title><link>https://0xtracer.xyz/incidents/2023-04-13-yearn-finance/</link><pubDate>Thu, 13 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-13-yearn-finance/</guid><description>Old yvDAI vault misconfiguration exploited via price manipulation</description></item><item><title>MetaPoint</title><link>https://0xtracer.xyz/incidents/2023-04-12-metapoint/</link><pubDate>Wed, 12 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-12-metapoint/</guid><description>MetaPoint ($POT) on BSC was hacked with a loss of $920K. The root cause is that users will create a new contract to hold their funds each time they deposit $POT, but the contract has a public approve function to trans&amp;hellip;</description></item><item><title>Paribus</title><link>https://0xtracer.xyz/incidents/2023-04-11-paribus/</link><pubDate>Tue, 11 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-11-paribus/</guid><description>Paribus, the first cross-chain lending platform on Cardano, was attacked and lost about $100,000. The reason for the attack is that it uses a fork of an old version of Compound V2, which has a known reentrancy vulnera&amp;hellip;</description></item><item><title>Terraport</title><link>https://0xtracer.xyz/incidents/2023-04-10-terraport/</link><pubDate>Mon, 10 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-10-terraport/</guid><description>Terraport, a decentralized finance project launched by TerraCVita, an independent development team of Terra Classic, was hacked and all its liquidity was exhausted. Data shows that nearly $4 million worth of LUNC, UST&amp;hellip;</description></item><item><title>CoreHunter</title><link>https://0xtracer.xyz/incidents/2023-04-09-corehunter/</link><pubDate>Sun, 09 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-09-corehunter/</guid><description>On April 9th, a rug pull occurred on the ZkSync ecological project CoreHunter, and the scammers made a profit of about 510,000 US dollars.</description></item><item><title>GDAC Exchange</title><link>https://0xtracer.xyz/incidents/2023-04-09-gdac-exchange/</link><pubDate>Sun, 09 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-09-gdac-exchange/</guid><description>Korean exchange hot wallet drained, ~23% of total assets lost</description></item><item><title>SushiSwap</title><link>https://0xtracer.xyz/incidents/2023-04-09-sushiswap/</link><pubDate>Sun, 09 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-09-sushiswap/</guid><description>SUSHI RouteProcessor2 was attacked and lost about 1800 ETH, about $3.34 million. According to the analysis of SlowMist, the root cause is that ProcessRoute does not perform any checks on the route parameters passed in&amp;hellip;</description></item><item><title>Sentiment</title><link>https://0xtracer.xyz/incidents/2023-04-05-sentiment/</link><pubDate>Wed, 05 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-05-sentiment/</guid><description>The DeFi lending agreement Sentiment stated that the team discovered abnormal lending activities. This malicious use led to the theft of about $966,000 from Sentiment on the Arbitrum network. The root cause is the rea&amp;hellip;</description></item><item><title>MEV Bots</title><link>https://0xtracer.xyz/incidents/2023-04-03-mev-bots/</link><pubDate>Mon, 03 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-03-mev-bots/</guid><description>On April 3, MEV bots suffered a malicious sandwich attack that cost them around $25 million. Data on the chain shows that the malicious verifier who attacked the MEV bots today has been punished by Slash and kicked ou&amp;hellip;</description></item><item><title>Allbridge</title><link>https://0xtracer.xyz/incidents/2023-04-02-allbridge/</link><pubDate>Sun, 02 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-02-allbridge/</guid><description>The cross-chain bridge Allbridge was hacked and lost about $570,000 (including about 280,000 BUSD and about 290,000 USDT). The root cause appears to be manipulation of the Swap price of the pool. The hacker played the&amp;hellip;</description></item><item><title>Degen Zoo</title><link>https://0xtracer.xyz/incidents/2023-04-02-degen-zoo/</link><pubDate>Sun, 02 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-02-degen-zoo/</guid><description>According to a Telegram announcement, the DAO Maker project Degen Zoo is suspected to have been hacked on Binance Oracle. At present, the project team has suspended the game and launched an investigation. No loopholes&amp;hellip;</description></item><item><title>zkSync</title><link>https://0xtracer.xyz/incidents/2023-04-02-zksync/</link><pubDate>Sun, 02 Apr 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-04-02-zksync/</guid><description>According to official news, the zkSync team announced the cause of the downtime on Twitter. Block generation stopped due to a block queue database failure. Despite this, the server API was not affected. Transactions c&amp;hellip;</description></item><item><title>Patricio Worthalter</title><link>https://0xtracer.xyz/incidents/2023-03-30-patricio-worthalter/</link><pubDate>Thu, 30 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-30-patricio-worthalter/</guid><description>The address of Patricio Worthalter, founder of POAP, was attacked by phishing. The attacker transferred 85,898 RPL (approximately $3.83 million) from Worthalter’s address to DEX, and sold all RPL at a price of 1,802 E&amp;hellip;</description></item><item><title>SafeMoon</title><link>https://0xtracer.xyz/incidents/2023-03-28-safemoon/</link><pubDate>Tue, 28 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-28-safemoon/</guid><description>Upgrade introduced public burn function exploited to drain liquidity</description></item><item><title>EC token</title><link>https://0xtracer.xyz/incidents/2023-03-26-ec-token/</link><pubDate>Sun, 26 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-26-ec-token/</guid><description>EC token deployer addresses withdrew approximately $43,800 from the liquidity pool.</description></item><item><title>Kokomo Finance</title><link>https://0xtracer.xyz/incidents/2023-03-26-kokomo-finance/</link><pubDate>Sun, 26 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-26-kokomo-finance/</guid><description>Kokomo Finance conducted an exit scam and stole ~$4 million in user funds.</description></item><item><title>Swerve Finance</title><link>https://0xtracer.xyz/incidents/2023-03-25-swerve-finance/</link><pubDate>Sat, 25 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-25-swerve-finance/</guid><description>Defunct Swerve Finance still subject of $1.3 million live governance hack</description></item><item><title>FASTSWAP</title><link>https://0xtracer.xyz/incidents/2023-03-24-fastswap/</link><pubDate>Fri, 24 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-24-fastswap/</guid><description>The FASTSWAP (FAST) project on BNB Chain was attacked by a flash loan and lost 26.77 BNB</description></item><item><title>Archive of PEACEMINUSONE</title><link>https://0xtracer.xyz/incidents/2023-03-22-archive-of-peaceminusone/</link><pubDate>Wed, 22 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-22-archive-of-peaceminusone/</guid><description>According to news, the NFT series &amp;ldquo;Archive of PEACEMINUSONE&amp;rdquo; released by Korean singer Quan Zhilong has the previously disclosed CVE-2022-38217 general vulnerability, and the possibility of being used by hackers canno&amp;hellip;</description></item><item><title>Circle's Chief Strategy Officer</title><link>https://0xtracer.xyz/incidents/2023-03-22-circle-s-chief-strategy-officer/</link><pubDate>Wed, 22 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-22-circle-s-chief-strategy-officer/</guid><description>Circle tweeted that the Circle Chief Strategy Officer&amp;rsquo;s Twitter account (@ddisparte) has been taken over by a scammer. Any link to an offer is a scam. We are investigating this situation and taking appropriate action&amp;hellip;.</description></item><item><title>Indexed Finance</title><link>https://0xtracer.xyz/incidents/2023-03-21-indexed-finance/</link><pubDate>Tue, 21 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-21-indexed-finance/</guid><description>Indexed Finance&amp;rsquo;s ORCL5 Token contract was attacked by a flash loan and lost $9,925. Root cause preliminary analysis is that &amp;ldquo;calcSingleOutGivenPoolIn()&amp;rdquo; calculates wrong value of tokenAmountOut.</description></item><item><title>Harvest Keeper</title><link>https://0xtracer.xyz/incidents/2023-03-19-harvest-keeper/</link><pubDate>Sun, 19 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-19-harvest-keeper/</guid><description>According to news, the Harvest_Keeper project maliciously transferred user funds, involving an amount of about 933,000 US dollars. Through the data on the chain, it was found that the attacker used the owner authority&amp;hellip;</description></item><item><title>General Bytes</title><link>https://0xtracer.xyz/incidents/2023-03-17-general-bytes/</link><pubDate>Fri, 17 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-17-general-bytes/</guid><description>According to the official Twitter, the General Bytes encrypted currency ATM service was attacked on March 17 and 18. The attacker used the upload interface in the system to upload and run a malicious Java program, and&amp;hellip;</description></item><item><title>iEarn Bot</title><link>https://0xtracer.xyz/incidents/2023-03-17-iearn-bot/</link><pubDate>Fri, 17 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-17-iearn-bot/</guid><description>According to the BBC, a scam called iEarn Bot has affected thousands of victims in several countries. In the scam, victims were persuaded to sign up for an &amp;ldquo;AI intelligent quantitative trading robot&amp;rdquo; called iEarn Bot,&amp;hellip;</description></item><item><title>ParaSpace</title><link>https://0xtracer.xyz/incidents/2023-03-17-paraspace/</link><pubDate>Fri, 17 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-17-paraspace/</guid><description>ParaSpace is suspected to have been attacked and it appears that 2,900 WETH were transferred out, with many claiming inconsistent data on the number of loans, health factors and cAPE amounts. However, a security firm&amp;hellip;</description></item><item><title>Poolz Finance</title><link>https://0xtracer.xyz/incidents/2023-03-15-poolz-finance/</link><pubDate>Wed, 15 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-15-poolz-finance/</guid><description>Poolz Finance&amp;rsquo;s LockedDeal contract was hacked and lost about $500,000. The attacker called the vulnerable function CreateMassPools in the LockedDeal contract, and triggered an integer overflow vulnerability in the pa&amp;hellip;</description></item><item><title>Harvest</title><link>https://0xtracer.xyz/incidents/2023-03-14-harvest/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-harvest/</guid><description>Harvest said that USDC, USDT, and WETH Vault were affected because of the use of Idle. Currently Harvest has not explained how to deal with it, and reminds users not to interact with these vaults until the problem is&amp;hellip;</description></item><item><title>Idle Finance</title><link>https://0xtracer.xyz/incidents/2023-03-14-idle-finance/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-idle-finance/</guid><description>The DeFi protocol Idle Finance tweeted that after investigation, the estimated exposure of the Euler Finance vulnerability to the protocol Yield Tranches was $5.6628 million, and the estimated exposure of Best Yield v&amp;hellip;</description></item><item><title>Sense Finance</title><link>https://0xtracer.xyz/incidents/2023-03-14-sense-finance/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-sense-finance/</guid><description>Sense Finance is a fixed-rate lending protocol in which fixed-income assets such as Idle can be traded, which was indirectly affected by the Euler attack.</description></item><item><title>Sherlock</title><link>https://0xtracer.xyz/incidents/2023-03-14-sherlock/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-sherlock/</guid><description>Sherlock is a DeFi security provider that provides smart contract auditing and insurance services. When Euler first launched, it entered into a $10 million partnership with Sherlock, who was responsible for auditing E&amp;hellip;</description></item><item><title>Yearn Finance</title><link>https://0xtracer.xyz/incidents/2023-03-14-yearn-finance/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-yearn-finance/</guid><description>Yearn Finance tweeted: “While there is no direct exposure to Euler, some vaults are indirectly exposed to the hack. Vaults using the Idle and Angle strategies have a combined exposure of $1.38 million on yvUSDT and yv&amp;hellip;</description></item><item><title>Yield Protocol</title><link>https://0xtracer.xyz/incidents/2023-03-14-yield-protocol/</link><pubDate>Tue, 14 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-14-yield-protocol/</guid><description>Yield Protocol, a fixed-rate lending agreement, posted an update on Twitter saying: &amp;ldquo;All collateral deposited by borrowers on Yield Protocol appears to be safe. Collateral is not deposited into Euler, but is kept in Y&amp;hellip;</description></item><item><title>Angle Protocol</title><link>https://0xtracer.xyz/incidents/2023-03-13-angle-protocol/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-angle-protocol/</guid><description>Angle Protocol, a decentralized stablecoin protocol, tweeted: &amp;ldquo;Angle Protocol was affected by the Euler exploit, which deposited 17.6 million USDC into Euler. The protocol has been suspended, the debt ceiling has been&amp;hellip;</description></item><item><title>Balancer</title><link>https://0xtracer.xyz/incidents/2023-03-13-balancer/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-balancer/</guid><description>The decentralized exchange Balancer disclosed on Twitter that in the Euler Finance attack, about $11.9 million was sent to Euler from the bbeUSD liquidity pool, accounting for 65% of the liquidity pool TVL, and bbeUSD&amp;hellip;</description></item><item><title>Euler Finance</title><link>https://0xtracer.xyz/hacks/euler-finance/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/hacks/euler-finance/</guid><description>&lt;p>Euler Finance was exploited for ~$197M through a flash loan attack exploiting a vulnerability in the donation mechanism. The attacker manipulated the health factor calculation by donating funds to the reserve, allowing them to borrow more than their collateral.&lt;/p></description></item><item><title>Euler Finance</title><link>https://0xtracer.xyz/incidents/2023-03-13-euler-finance/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-euler-finance/</guid><description>donateToReserves() lacked health check, funds eventually returned</description></item><item><title>Inverse Finance</title><link>https://0xtracer.xyz/incidents/2023-03-13-inverse-finance/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-inverse-finance/</guid><description>Inverse Finance, a DeFi lending protocol, tweeted: “Euler attack impacted DOLA-bb-e-USD pool on Balancer. Despite quick action to mitigate 90% of the impact, DOLA Fed suffered up to 86% for this pool. million in losse&amp;hellip;</description></item><item><title>Opyn</title><link>https://0xtracer.xyz/incidents/2023-03-13-opyn/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-opyn/</guid><description>Opyn built the first decentralized option protocol, developed the perpetual option Opyn Squeeth, and built a variety of income strategies on Suqeeth. This time Opyn is affected by the Zen Bull strategy, which combines&amp;hellip;</description></item><item><title>SwissBorg</title><link>https://0xtracer.xyz/incidents/2023-03-13-swissborg/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-13-swissborg/</guid><description>SwissBorg is a crypto asset management platform that is regulated and licensed in Switzerland, France and Estonia. It has its own SwissBorg app and can earn money through this mobile wallet. SwissBorg stated that the&amp;hellip;</description></item><item><title>Hedera</title><link>https://0xtracer.xyz/incidents/2023-03-10-hedera/</link><pubDate>Fri, 10 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-10-hedera/</guid><description>Hedera tweeted to disclose the details of the attack. The attacker attacked the smart contract service code of the Hedera main network and transferred the Hedera Token Service tokens held by some user accounts to thei&amp;hellip;</description></item><item><title>SUCKR</title><link>https://0xtracer.xyz/incidents/2023-03-10-suckr/</link><pubDate>Fri, 10 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-10-suckr/</guid><description>The SUCKR project on the Aptos chain is suspected of being a rug pull. The hacker called the mint_SUCKR (admin privilege function) function to mint a large number of SUCKR tokens and exchange them for USDT. The price&amp;hellip;</description></item><item><title>Tender.fi</title><link>https://0xtracer.xyz/incidents/2023-03-07-tender-fi/</link><pubDate>Tue, 07 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-07-tender-fi/</guid><description>Tender.fi is suspected of being attacked by white hat hackers and lost $1.59 million. Hackers used Tender.fi’s misconfigured oracles to borrow $1.59 million worth of crypto assets with just $70 worth of GMX tokens as&amp;hellip;</description></item><item><title>PeopleDAO</title><link>https://0xtracer.xyz/incidents/2023-03-06-peopledao/</link><pubDate>Mon, 06 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-06-peopledao/</guid><description>When PeopleDAO’s community treasury multi-signature wallet on the digital asset management platform Safe (formerly Gnosis Safe) distributed monthly contributor rewards on March 6, 76 ETH (approximately $120,000) were&amp;hellip;</description></item><item><title>ArbiSwap</title><link>https://0xtracer.xyz/incidents/2023-03-02-arbiswap/</link><pubDate>Thu, 02 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-02-arbiswap/</guid><description>Arbitrum ecological DEX ArbiSwap is suspected of Rug Pull. ArbiSwap deployers minted 1 trillion ARBI before Rug Pull, and then converted ARBI into USDC, which caused a sharp drop in ARBI in the USDC/ARBI transaction p&amp;hellip;</description></item><item><title>iToken</title><link>https://0xtracer.xyz/incidents/2023-03-01-itoken/</link><pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-03-01-itoken/</guid><description>According to the official WeChat account of Ping An Xuhui, employees Zhang, Dong, and Liu from Company A decided in early March 2023 to insert a backdoor program into a certain cryptocurrency wallet software to obtain&amp;hellip;</description></item><item><title>MyAlgo</title><link>https://0xtracer.xyz/incidents/2023-02-28-myalgo/</link><pubDate>Tue, 28 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-28-myalgo/</guid><description>Algorand ecological wallet MyAlgo issued a reminder on Twitter that the hack occurred more than a week ago, and no other actions have taken place since then. The attacked users all had large amounts of funds on their&amp;hellip;</description></item><item><title>DungeonSwap</title><link>https://0xtracer.xyz/incidents/2023-02-27-dungeonswap/</link><pubDate>Mon, 27 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-27-dungeonswap/</guid><description>The DeFi project DND Token (DungeonSwap Token) on BSC has been utilized. The initial funds came from TornadoCash, and the attackers stole over 2,400 BNB (approximately $728,000) from Dungeonswap.</description></item><item><title>HideYoApes</title><link>https://0xtracer.xyz/incidents/2023-02-27-hideyoapes/</link><pubDate>Mon, 27 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-27-hideyoapes/</guid><description>@HideYoApes previously owned several expensive NFTs from Yuga Labs, including a Bored Ape, Mutant Ape, three Bored Ape Kennel Club NFTs, a SewerPass, and two Otherdeeds. The attacker sold all the NFTs for a profit of&amp;hellip;</description></item><item><title>LaunchZone</title><link>https://0xtracer.xyz/incidents/2023-02-27-launchzone/</link><pubDate>Mon, 27 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-27-launchzone/</guid><description>80% of the funds in the liquidity pool of the DeFi project LaunchZone were suddenly drained, the price of LZ tokens fell by more than 80% from the previous value of around US$0.15 to US$0.026, and the stolen funds wer&amp;hellip;</description></item><item><title>The Sandbox</title><link>https://0xtracer.xyz/incidents/2023-02-26-the-sandbox/</link><pubDate>Sun, 26 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-26-the-sandbox/</guid><description>According to the official blog, The Sandbox issued a security incident notice on February 26 that an unauthorized third party gained access to the computer of an employee of the team and used its permissions to send a&amp;hellip;</description></item><item><title>Solana</title><link>https://0xtracer.xyz/incidents/2023-02-25-solana/</link><pubDate>Sat, 25 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-25-solana/</guid><description>As Coindesk reported, the Solana network experienced a fork event that limited users’ ability to execute transactions. According to Solana Explorer, the network was processing about 93 transactions per second at aroun&amp;hellip;</description></item><item><title>Earning.farm</title><link>https://0xtracer.xyz/incidents/2023-02-24-earning-farm/</link><pubDate>Fri, 24 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-24-earning-farm/</guid><description>On February 24, 2023, Earning.farm’s USDC vault was exploited and lost about 5.15 million USDC.</description></item><item><title>Revert Finance</title><link>https://0xtracer.xyz/incidents/2023-02-20-revert-finance/</link><pubDate>Mon, 20 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-20-revert-finance/</guid><description>The AMM liquidity management protocol Revert Finance disclosed on Twitter that its v3utils contract was attacked, and 90% of the funds were stolen from a single account. The stolen assets included: 22983.235188 USDC,&amp;hellip;</description></item><item><title>BABYDOLL</title><link>https://0xtracer.xyz/incidents/2023-02-19-babydoll/</link><pubDate>Sun, 19 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-19-babydoll/</guid><description>The Baby Doll (BABYDOLL) project was hit by a flash loan attack, losing 25 BNB (~$7,900). BSC contract address is 0x449cfecbc8e8469eeda869fca6cccd326ece0c04a1cdd96b23d21f3b599adee2</description></item><item><title>Block Tower Capital</title><link>https://0xtracer.xyz/incidents/2023-02-18-block-tower-capital/</link><pubDate>Sat, 18 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-18-block-tower-capital/</guid><description>Hackers exploited a vulnerability in the Dexible smart contract code to withdraw funds from crypto wallets using funds approved for spending. The team added that &amp;ldquo;a small number of whales&amp;rdquo; lost 85% of the funds stolen&amp;hellip;</description></item><item><title>Dexible</title><link>https://0xtracer.xyz/incidents/2023-02-17-dexible/</link><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-17-dexible/</guid><description>The DEX tool Dexible was suspected of being attacked and lost about $2 million. According to the analysis, there is a logical loophole in the selfSwap function of the Dexible contract, which will call the fill functio&amp;hellip;</description></item><item><title>Platypus Finance</title><link>https://0xtracer.xyz/incidents/2023-02-16-platypus-finance/</link><pubDate>Thu, 16 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-16-platypus-finance/</guid><description>Solvency check order flaw in USP stablecoin exploited via flash loan</description></item><item><title>Multichain</title><link>https://0xtracer.xyz/incidents/2023-02-15-multichain/</link><pubDate>Wed, 15 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-15-multichain/</guid><description>Multichain&amp;rsquo;s AnyswapV4Router contract suffered a rush attack, and the attacker made a profit of about 87 Ethereum, about $130,000. After analysis, the attacker used the MEV contract (0xd050) to pre-emptively call the&amp;hellip;</description></item><item><title>Namecheap</title><link>https://0xtracer.xyz/incidents/2023-02-12-namecheap/</link><pubDate>Sun, 12 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-12-namecheap/</guid><description>The email account of domain name registrar Namecheap has been hacked and hackers are using the account to send phishing emails. According to a report by BleepingComputer, the phishing campaign originated from SendGrid&amp;hellip;</description></item><item><title>fcdep(EPMAX)</title><link>https://0xtracer.xyz/incidents/2023-02-11-fcdep-epmax/</link><pubDate>Sat, 11 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-11-fcdep-epmax/</guid><description>The project fcdep (EPMAX) on BSC was attacked by flash loan, and the loss was about 350,000 US dollars.</description></item><item><title>OneKey</title><link>https://0xtracer.xyz/incidents/2023-02-11-onekey/</link><pubDate>Sat, 11 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-11-onekey/</guid><description>Cybersecurity startup Unciphered has carried out an attack on encrypted hardware wallets made by OneKey. In a video on YouTube, Unciphered demonstrates a so-called &amp;ldquo;man-in-the-middle&amp;rdquo; wallet attack method that exploit&amp;hellip;</description></item><item><title>dForce</title><link>https://0xtracer.xyz/incidents/2023-02-10-dforce/</link><pubDate>Fri, 10 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-10-dforce/</guid><description>Read-only reentrancy on Curve pool price exploited on wstETH pools</description></item><item><title>SushiSwap</title><link>https://0xtracer.xyz/incidents/2023-02-10-sushiswap/</link><pubDate>Fri, 10 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-10-sushiswap/</guid><description>SushiSwap&amp;rsquo;s BentoBoxv1 contract was attacked, and the hacker made a profit of about $26,000. According to analysis, the attack is due to the Kashi Medium Risk ChainLink price update later than the mortgage/loan. In th&amp;hellip;</description></item><item><title>Umami Finance</title><link>https://0xtracer.xyz/incidents/2023-02-09-umami-finance/</link><pubDate>Thu, 09 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-09-umami-finance/</guid><description>Umami Finance, a DeFi protocol on Arbitrum, offers yield products to institutional clients. On January 31, they announced they were suspending yields, saying they were concerned about regulatory tactics. Soon after, t&amp;hellip;</description></item><item><title>Nostr</title><link>https://0xtracer.xyz/incidents/2023-02-08-nostr/</link><pubDate>Wed, 08 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-08-nostr/</guid><description>A fake token project named &amp;ldquo;Nostr&amp;rdquo; on the Ethereum chain has run away, and its funds have been transferred to a new EOA address 0xeeB8EB5CC144eDddDB204c3ABA499de6b6081696. In the end, the fraudsters made a profit of 2&amp;hellip;</description></item><item><title>LianGoPay</title><link>https://0xtracer.xyz/incidents/2023-02-07-liangopay/</link><pubDate>Tue, 07 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-07-liangopay/</guid><description>The LianGoPay project announced on February 7 that its assets in the LGTPool pledge contract on the BNB Chain were stolen, 6,148,859 LGT reward coins were stolen, and the loss was about 1.6 million US dollars. Accordi&amp;hellip;</description></item><item><title>SperaxUSD</title><link>https://0xtracer.xyz/incidents/2023-02-04-speraxusd/</link><pubDate>Sat, 04 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-04-speraxusd/</guid><description>SperaxUSD, the Arbitrum ecological stablecoin protocol, tweeted that an attacker increased the token balance of his address to 9.7 billion without providing the corresponding collateral, and before the Sperax team and&amp;hellip;</description></item><item><title>BonqDAO &amp; AllianceBlock</title><link>https://0xtracer.xyz/incidents/2023-02-02-bonqdao-and-allianceblock/</link><pubDate>Thu, 02 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-02-bonqdao-and-allianceblock/</guid><description>Non-custodial lending platform BonqDAO and crypto infrastructure platform AllianceBlock were hacked due to a bug in BonqDAO&amp;rsquo;s smart contracts, resulting in losses of approximately $120 million. Among them, hackers rem&amp;hellip;</description></item><item><title>Orion Protocol</title><link>https://0xtracer.xyz/incidents/2023-02-02-orion-protocol/</link><pubDate>Thu, 02 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-02-orion-protocol/</guid><description>Reentrancy via malicious token in atomic swap library</description></item><item><title>BonqDAO</title><link>https://0xtracer.xyz/incidents/2023-02-01-bonqdao/</link><pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-02-01-bonqdao/</guid><description>Tellor oracle manipulated with minimal cost to inflate collateral</description></item><item><title>BEVO</title><link>https://0xtracer.xyz/incidents/2023-01-30-bevo/</link><pubDate>Mon, 30 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-30-bevo/</guid><description>The BEVO NFT Art Token (BEVO) on BSC was exploited with a total loss of approximately $45,000. The root cause is that BEVO is a deflationary token, and the attacker calls the function deliver(), the value of _rTotal w&amp;hellip;</description></item><item><title>Azuki</title><link>https://0xtracer.xyz/incidents/2023-01-28-azuki/</link><pubDate>Sat, 28 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-28-azuki/</guid><description>According to official news, the NFT project Azuki confirmed that its Twitter account was hacked, and the team has regained control of the account. Hackers posted two tweets on Azuki&amp;rsquo;s Twitter account, prompting users&amp;hellip;</description></item><item><title>Kevin Rose</title><link>https://0xtracer.xyz/incidents/2023-01-26-kevin-rose/</link><pubDate>Thu, 26 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-26-kevin-rose/</guid><description>Kevin Rose, the founder of the NFT project Moonbirds, tweeted that his personal wallet was hacked and 25 Chromie Squiggles and other NFTs were lost, with an estimated loss of more than $1 million. Arran Schlosberg, vi&amp;hellip;</description></item><item><title>Robinhood</title><link>https://0xtracer.xyz/incidents/2023-01-26-robinhood/</link><pubDate>Thu, 26 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-26-robinhood/</guid><description>The Robinhood Twitter account was hacked and used to promote a fraudulent crypto project. The hackers announced the launch of a new token called $RBH, which they say will be priced at $0.0005 on Binance Smart Chain. A&amp;hellip;</description></item><item><title>Doglands</title><link>https://0xtracer.xyz/incidents/2023-01-21-doglands/</link><pubDate>Sat, 21 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-21-doglands/</guid><description>Dogechain ecological multi-purpose GameFi and DeFi agreement Doglands may have exit scams. The contract addresses on the project chain are 0x106E6a2D5433247441c1Cdf4E3e24a0696a46d0, 0x12b17 and 0x0e815, which drain al&amp;hellip;</description></item><item><title>FFF</title><link>https://0xtracer.xyz/incidents/2023-01-20-fff/</link><pubDate>Fri, 20 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-20-fff/</guid><description>It is reported that the FFF token deployed on the BSC has an abnormal additional issue event. This event is that the administrator of the original project party purchased the additional issue through the pre-set addit&amp;hellip;</description></item><item><title>Thoreum Finance</title><link>https://0xtracer.xyz/incidents/2023-01-19-thoreum-finance/</link><pubDate>Thu, 19 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-19-thoreum-finance/</guid><description>Thoreum Finance was hacked. According to analysis, because the transfer function of the non-open source contract 0x79fe created by the Thoreum Finance project party is suspected to have a loophole, when the from and t&amp;hellip;</description></item><item><title>OMNI Real Estate Token</title><link>https://0xtracer.xyz/incidents/2023-01-17-omni-real-estate-token/</link><pubDate>Tue, 17 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-17-omni-real-estate-token/</guid><description>The OMNI Real Estate Token (ORT) project on BSC was attacked. The cause of the attack is suspected to be a loophole in the contract code. The attacker’s address is: 0x9BbD94506398a1459F0Cd3B2638512627390255e, one of t&amp;hellip;</description></item><item><title>Midas Capital</title><link>https://0xtracer.xyz/incidents/2023-01-16-midas-capital/</link><pubDate>Mon, 16 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-16-midas-capital/</guid><description>Due to the read-only-reentrancy problem (read-only-reentrancy) when interacting with the Curve liquidity pool, the cross-chain money market solution Midas Capital was attacked and exploited in the Polygon liquidity po&amp;hellip;</description></item><item><title>NFT God</title><link>https://0xtracer.xyz/incidents/2023-01-14-nft-god/</link><pubDate>Sat, 14 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-14-nft-god/</guid><description>Encrypted KOL NFT God tweeted that due to hackers hacking into its Twitter, Substack, Gmail, Discord and wallets, it lost all its encrypted assets and NFTs, and the hackers also posted fraudulent links through the sto&amp;hellip;</description></item><item><title>LendHub</title><link>https://0xtracer.xyz/incidents/2023-01-12-lendhub/</link><pubDate>Thu, 12 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-12-lendhub/</guid><description>Old and new LHBTC markets listed simultaneously enabling price manipulation</description></item><item><title>RoeFinance</title><link>https://0xtracer.xyz/incidents/2023-01-12-roefinance/</link><pubDate>Thu, 12 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-12-roefinance/</guid><description>RoeFinance was attacked. The victim pool (0x574f) has just been emptied, with a total loss of about $80000. This is a typical price manipulation attack.</description></item><item><title>Google Chrome</title><link>https://0xtracer.xyz/incidents/2023-01-11-google-chrome/</link><pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-11-google-chrome/</guid><description>A vulnerability known as CVE-2022-3656 affects more than 2.5 billion users of Google Chrome and Chromium-engine-based browsers. This vulnerability allows the theft of sensitive files such as encrypted wallets and clou&amp;hellip;</description></item><item><title>BRA</title><link>https://0xtracer.xyz/incidents/2023-01-10-bra/</link><pubDate>Tue, 10 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-10-bra/</guid><description>The price of BRA token on BNB Chain is zero. According to the analysis, the token will be taxed during the transaction, and the tax collected will be directly sent to the transaction pair, and the tax will be added tw&amp;hellip;</description></item><item><title>Chimpers</title><link>https://0xtracer.xyz/incidents/2023-01-10-chimpers/</link><pubDate>Tue, 10 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-10-chimpers/</guid><description>The official Twitter account of Chimpers, the NFT project, was hacked and embezzled, and multiple links to fake websites were published to lure users to forge NFT through the links.</description></item><item><title>Sui Name Service</title><link>https://0xtracer.xyz/incidents/2023-01-10-sui-name-service/</link><pubDate>Tue, 10 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-10-sui-name-service/</guid><description>On January 10, Sui Name Service, an eco-domain name service provider, posted a message on social media that its Discord server was attacked by a former employee today, and the attacker posed as an administrator. At pr&amp;hellip;</description></item><item><title>Twity</title><link>https://0xtracer.xyz/incidents/2023-01-08-twity/</link><pubDate>Sun, 08 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-08-twity/</guid><description>The Web3 Twitter marketing platform Twity tweeted that there was a security vulnerability in its system, the Telegram account of the technician was leaked, and the chat record contained project information and wallet&amp;hellip;</description></item><item><title>CyberKongz</title><link>https://0xtracer.xyz/incidents/2023-01-07-cyberkongz/</link><pubDate>Sat, 07 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-07-cyberkongz/</guid><description>The official Twitter account of CyberKongz in the NFT project was attacked by hackers, who replaced the homepage links, etc. with phishing links and released false Mint information. At present, the account has been re&amp;hellip;</description></item><item><title>Mycelium</title><link>https://0xtracer.xyz/incidents/2023-01-07-mycelium/</link><pubDate>Sat, 07 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-07-mycelium/</guid><description>Mycelium, a perpetual agreement, tweeted that due to the oracle feeding problem of the ETH-USD trading pair, MLP suffered a loss of 4~6% from robot arbitrage (the current pool size is about $6.6 million, and the estim&amp;hellip;</description></item><item><title>Mutant Ape Planet</title><link>https://0xtracer.xyz/incidents/2023-01-06-mutant-ape-planet/</link><pubDate>Fri, 06 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-06-mutant-ape-planet/</guid><description>Aurelien Michel, developer of MAYC&amp;rsquo;s Mutant Ape Planet NFT series, has pleaded guilty after being arrested on charges of defrauding $2.9 million. Aurelien Michel and the other defendants marketed the Mutant Ape Planet&amp;hellip;</description></item><item><title>Nikhil Gopalani</title><link>https://0xtracer.xyz/incidents/2023-01-03-nikhil-gopalani/</link><pubDate>Tue, 03 Jan 2023 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2023-01-03-nikhil-gopalani/</guid><description>Nikhil Gopalani, chief operating officer of Nike&amp;rsquo;s encrypted fashion brand RTFKT, tweeted that he was attacked by a phisher and lost more than $173,000, including 19 CloneX NFTs, 18 RTKFT Space Pods, 11 CryptoKicks, e&amp;hellip;</description></item><item><title>DictumExchange</title><link>https://0xtracer.xyz/incidents/2022-12-31-dictumexchange/</link><pubDate>Sat, 31 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-31-dictumexchange/</guid><description>About a week ago, Arbitrum-based project DictumExchange announced an airdrop. It turned out to be a scam.</description></item><item><title>Luke Dashjr</title><link>https://0xtracer.xyz/incidents/2022-12-31-luke-dashjr/</link><pubDate>Sat, 31 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-31-luke-dashjr/</guid><description>Luke Dashjr, one of the original Bitcoin Core developers, claimed on Twitter that attackers had managed to compromise multiple wallets, with more than 216 BTC (approximately $3.6 million) stolen. Dashjr initially blam&amp;hellip;</description></item><item><title>Kevin O’Leary</title><link>https://0xtracer.xyz/incidents/2022-12-29-kevin-oleary/</link><pubDate>Thu, 29 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-29-kevin-oleary/</guid><description>The Twitter account of celebrity investor Kevin O’Leary was hacked on Thursday and used to promote a bitcoin and ethereum giveaway scam, Bitcoin.com reported. The hacker claims that Mr. Wonderful (Kevin O’Leary) is gi&amp;hellip;</description></item><item><title>BitKeep</title><link>https://0xtracer.xyz/incidents/2022-12-26-bitkeep/</link><pubDate>Mon, 26 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-26-bitkeep/</guid><description>Several users claimed that their funds were stolen in the official Telegarm group of BitKeep, a Web3 multi-chain wallet. BitKeep issued an announcement saying that after preliminary investigation by the team, it is su&amp;hellip;</description></item><item><title>LastPass</title><link>https://0xtracer.xyz/incidents/2022-12-25-lastpass/</link><pubDate>Sun, 25 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-25-lastpass/</guid><description>Password management platform LastPass said a hacker accessed a cloud-based storage environment using information previously obtained in an incident they disclosed in August 2022, and some source codes and technical in&amp;hellip;</description></item><item><title>Rubic</title><link>https://0xtracer.xyz/incidents/2022-12-25-rubic/</link><pubDate>Sun, 25 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-25-rubic/</guid><description>The multi-chain exchange protocol Rubic was hacked and lost more than $1.4 million. The attacker has transferred 1,100 ETH to the Tornado Cash mixing protocol. According to the analysis of the SlowMist security team,&amp;hellip;</description></item><item><title>Defrost Finance</title><link>https://0xtracer.xyz/incidents/2022-12-23-defrost-finance/</link><pubDate>Fri, 23 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-23-defrost-finance/</guid><description>Admin added fake collateral token and liquidated all users</description></item><item><title>mgnr</title><link>https://0xtracer.xyz/incidents/2022-12-19-mgnr/</link><pubDate>Mon, 19 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-19-mgnr/</guid><description>Quantitative trading company mgnr has deleted all tweets and quit some groups, leaving only 0.097 Ethereum in its wallet address. The address with the domain name mgnr.eth transferred 43.6 million USDC to Coinbase on&amp;hellip;</description></item><item><title>Raydium</title><link>https://0xtracer.xyz/incidents/2022-12-16-raydium/</link><pubDate>Fri, 16 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-16-raydium/</guid><description>In response to an attack, Raydium tweeted that a patch has been put in place so far to prevent further attacks. This attack has nothing to do with the escalated privileges of the program itself. The vulnerability seem&amp;hellip;</description></item><item><title>NimbusPlatform</title><link>https://0xtracer.xyz/incidents/2022-12-14-nimbusplatform/</link><pubDate>Wed, 14 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-14-nimbusplatform/</guid><description>The NimbusPlatform project on the BSC chain was attacked, and the attacker made a profit of about 278 BNB. According to the analysis of SlowMist, the main reason for this attack is that the calculation of rewards only&amp;hellip;</description></item><item><title>Polynomial Protocol</title><link>https://0xtracer.xyz/incidents/2022-12-12-polynomial-protocol/</link><pubDate>Mon, 12 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-12-polynomial-protocol/</guid><description>Polynomial Protocol has a loophole in optimism&amp;rsquo;s deposit contract. The problem stems from the swapAndDeposit() function, which has no restrictions on its input. Anyone can pass in an address and maliciously construct&amp;hellip;</description></item><item><title>3Commas</title><link>https://0xtracer.xyz/incidents/2022-12-11-3commas/</link><pubDate>Sun, 11 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-11-3commas/</guid><description>3Commas founder and CEO Yuriy Sorokin issued an investigative update on attacks on API keys and trading platforms after many users of Binance, OKX, FTX and some other trading platforms experienced unauthorized transac&amp;hellip;</description></item><item><title>Lodestar Finance</title><link>https://0xtracer.xyz/incidents/2022-12-11-lodestar-finance/</link><pubDate>Sun, 11 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-11-lodestar-finance/</guid><description>Arbitrum-based cryptocurrency lending platform Lodestar Finance was hacked and nearly $7 million in assets siphoned off, the attackers were able to manipulate the price of the plvGLP token, allowing them to use the in&amp;hellip;</description></item><item><title>PayPal</title><link>https://0xtracer.xyz/incidents/2022-12-06-paypal/</link><pubDate>Tue, 06 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-06-paypal/</guid><description>According to reports, PayPal notified the United States Attorney General&amp;rsquo;s Office of Maine (Maine), saying that they discovered that they had been hacked on December 20, 2022, and after investigation believed that the&amp;hellip;</description></item><item><title>BTC.com</title><link>https://0xtracer.xyz/incidents/2022-12-03-btc-com/</link><pubDate>Sat, 03 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-03-btc-com/</guid><description>BIT Mining reports that its subsidiary, cryptocurrency mining pool BTC.com, suffered a “cyber attack” on Dec. 3, in which the attackers stole approximately $700,000 in customer assets and $2.3 million in company asset&amp;hellip;</description></item><item><title>Helio</title><link>https://0xtracer.xyz/incidents/2022-12-02-helio/</link><pubDate>Fri, 02 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-02-helio/</guid><description>After the attack on Ankr’s aBNBc token, an address exchanged 10 BNB for 15.5 million BUSD with the help of the Ankr vulnerability, resulting in the emptying of the Hay liquidity pool. Another user made a profit throug&amp;hellip;</description></item><item><title>Ankr</title><link>https://0xtracer.xyz/incidents/2022-12-01-ankr/</link><pubDate>Thu, 01 Dec 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-12-01-ankr/</guid><description>Deployer key compromised, attacker minted 6Q aBNBc tokens</description></item><item><title>Ahad Shams</title><link>https://0xtracer.xyz/incidents/2022-11-26-ahad-shams/</link><pubDate>Sat, 26 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-26-ahad-shams/</guid><description>Trust Wallet, a multi-chain non-custodial wallet, tweeted that Ahad Shams, the co-founder of the Web3 metaverse game engine Webverse, said that he did not disclose the mnemonic and was only stolen $4 million worth of&amp;hellip;</description></item><item><title>Webaverse</title><link>https://0xtracer.xyz/incidents/2022-11-26-webaverse/</link><pubDate>Sat, 26 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-26-webaverse/</guid><description>For several weeks last year, Webaverse was targeted by a skilled scam gang posing as investors, Webaverse reported. The Webaverse team and the crooks met in Rome at the end of November 2022, and approximately $4 milli&amp;hellip;</description></item><item><title>Numbers Protocol</title><link>https://0xtracer.xyz/incidents/2022-11-23-numbers-protocol/</link><pubDate>Wed, 23 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-23-numbers-protocol/</guid><description>According to the intelligence of the SlowMist security team, the Numbers Protocol (NUM) token project on the ETH chain was attacked, and the attacker made a profit of about $13,836. The main reason for this attack is&amp;hellip;</description></item><item><title>Trust Wallet</title><link>https://0xtracer.xyz/incidents/2022-11-17-trust-wallet/</link><pubDate>Thu, 17 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-17-trust-wallet/</guid><description>Trust Wallet released an analysis report saying: &amp;ldquo;In November 2022, a vulnerability was discovered in the back-end module WebAssembly (WASM) at the core of the open source repository wallet. The vulnerability affected&amp;hellip;</description></item><item><title>SheepFarm</title><link>https://0xtracer.xyz/incidents/2022-11-16-sheepfarm/</link><pubDate>Wed, 16 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-16-sheepfarm/</guid><description>The SheepFarm project on the BNB chain was attacked by a vulnerability. After analysis, it was found that because the register function of the SheepFarm contract could be called multiple times, the attacker 0x2131c67e&amp;hellip;</description></item><item><title>Ranger</title><link>https://0xtracer.xyz/incidents/2022-11-15-ranger/</link><pubDate>Tue, 15 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-15-ranger/</guid><description>The Ranger project on the BSC chain was an exit scam, and the Ranger token fell by 95%. The contract deployer sent the tokens to an external account, which was then sold for a profit of about $77,000. Do not confuse t&amp;hellip;</description></item><item><title>DeFiAI</title><link>https://0xtracer.xyz/incidents/2022-11-14-defiai/</link><pubDate>Mon, 14 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-14-defiai/</guid><description>Rug pull occurred in the DeFiAI project, and the contract deployer made a profit of about 40 million US dollars. According to SlowMist MistTrack analysis, funds have been transferred to Fixedfloat and MEXC.</description></item><item><title>Flare</title><link>https://0xtracer.xyz/incidents/2022-11-14-flare/</link><pubDate>Mon, 14 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-14-flare/</guid><description>The price of the Flare project has dropped by more than 95%, which is suspected to be a Rug Pull scam project. Flare token deployers and associated addresses received approximately 4 billion Flare tokens. The scam has&amp;hellip;</description></item><item><title>DFXFinance</title><link>https://0xtracer.xyz/incidents/2022-11-11-dfxfinance/</link><pubDate>Fri, 11 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-11-dfxfinance/</guid><description>The DFX Finance project on the ETH chain was attacked, and the attackers made a profit of about $231,138. According to SlowMist analysis, the main reason for this attack is that the Curve contract flash loan function&amp;hellip;</description></item><item><title>FTX</title><link>https://0xtracer.xyz/incidents/2022-11-11-ftx/</link><pubDate>Fri, 11 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-11-ftx/</guid><description>In its official Telegram channel, FTX said it had been compromised, instructing users not to install any new upgrades and to remove all FTX apps. Over $600 million stolen from FTX&amp;rsquo;s crypto wallets.</description></item><item><title>brahTOPG</title><link>https://0xtracer.xyz/incidents/2022-11-10-brahtopg/</link><pubDate>Thu, 10 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-10-brahtopg/</guid><description>According to the monitoring of the SlowMist security team, the brahTOPG project on the ETH chain was attacked, and the attacker made a profit of about $89,879. The main reason for this attack is that the Zapper contra&amp;hellip;</description></item><item><title>MooCakeCTX</title><link>https://0xtracer.xyz/incidents/2022-11-07-moocakectx/</link><pubDate>Mon, 07 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-07-moocakectx/</guid><description>The MooCakeCTX project suffered a flash loan attack, and the attackers made a profit of $143,921. According to Fairyproof’s analysis, the suspected reason is that the contract reinvested (the earn function was not cal&amp;hellip;</description></item><item><title>Loopring</title><link>https://0xtracer.xyz/incidents/2022-11-05-loopring/</link><pubDate>Sat, 05 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-05-loopring/</guid><description>Ethereum L2 protocol Loopring tweeted that it was hit by a large-scale DDoS attack. While the funds were not at risk, the service was down for 11 hours. Currently, domain access on the mobile app side has been reconfi&amp;hellip;</description></item><item><title>pNetwork</title><link>https://0xtracer.xyz/incidents/2022-11-04-pnetwork/</link><pubDate>Fri, 04 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-04-pnetwork/</guid><description>An address on the BNB Chain minted more than $1 billion of pGALA tokens out of thin air, and sold them through PancakeSwap to make a profit. The pGALA contract hacker has made a profit of $4.3 million. One Smart Money&amp;hellip;</description></item><item><title>Rubic</title><link>https://0xtracer.xyz/incidents/2022-11-02-rubic/</link><pubDate>Wed, 02 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-02-rubic/</guid><description>The multi-chain exchange protocol Rubic tweeted that an administrator’s wallet address, which manages the RBC/BRBC cross-chain bridge and staking rewards, was stolen, and the team suspected that malware stole the priv&amp;hellip;</description></item><item><title>Skyward Finance</title><link>https://0xtracer.xyz/incidents/2022-11-02-skyward-finance/</link><pubDate>Wed, 02 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-02-skyward-finance/</guid><description>Treasury NEAR tokens drained by repeatedly buying with own tokens</description></item><item><title>Solend</title><link>https://0xtracer.xyz/incidents/2022-11-02-solend/</link><pubDate>Wed, 02 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-02-solend/</guid><description>Solend, a lending protocol on Solana, tweeted that an oracle attack against USDH affecting Stable, Coin98, and Kamino’s isolated pools was detected, resulting in $1.26 million in bad debt. Additionally, Solend claims&amp;hellip;</description></item><item><title>Deribit</title><link>https://0xtracer.xyz/incidents/2022-11-01-deribit/</link><pubDate>Tue, 01 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-01-deribit/</guid><description>Deribit hot wallet compromised, cold wallet unaffected</description></item><item><title>FITE</title><link>https://0xtracer.xyz/incidents/2022-11-01-fite/</link><pubDate>Tue, 01 Nov 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-11-01-fite/</guid><description>The FITE (FTE) project is suspected of Rug pull, its website fit[.]app has been shut down, and social media has been deleted. Scammers have transferred 1900 BNB to Tornado Cash.</description></item><item><title>Eden Network</title><link>https://0xtracer.xyz/incidents/2022-10-29-eden-network/</link><pubDate>Sat, 29 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-29-eden-network/</guid><description>The ownership of the MEV infrastructure Eden Network deployer address was hacked and took control of the EDEN token contract. The attacker claims that a new token contract will be deployed, and Eden Network can redeem&amp;hellip;</description></item><item><title>FriesDAO</title><link>https://0xtracer.xyz/incidents/2022-10-28-friesdao/</link><pubDate>Fri, 28 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-28-friesdao/</guid><description>FriesDAO was attacked and lost about $2.3 million. An attacker gained control of the FriesDAO protocol operator&amp;rsquo;s wallet through the Profanity wallet generator vulnerability, which would force the use of the private k&amp;hellip;</description></item><item><title>Opensea</title><link>https://0xtracer.xyz/incidents/2022-10-28-opensea/</link><pubDate>Fri, 28 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-28-opensea/</guid><description>Browser security plug-in Pocket Universe tweeted that a new vulnerability was discovered in Opensea’s old contracts that could be used to steal users’ NFTs, potentially emptying wallets once the transaction was signed&amp;hellip;</description></item><item><title>THORChain</title><link>https://0xtracer.xyz/incidents/2022-10-28-thorchain/</link><pubDate>Fri, 28 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-28-thorchain/</guid><description>The THORChain network of the cross-chain DeFi protocol was interrupted. The official said that the consensus problem has been identified and a patch will be released. The code pushes cosmos.Uint (instead of uint64) in&amp;hellip;</description></item><item><title>Team Finance</title><link>https://0xtracer.xyz/incidents/2022-10-27-team-finance/</link><pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-27-team-finance/</guid><description>Team Finance tweeted that the protocol’s management funds were hacked during the migration from Uniswap v2 to v3, with an identified loss of approximately $14.5 million worth of tokens. On October 31, the Team Finance&amp;hellip;</description></item><item><title>UvToken</title><link>https://0xtracer.xyz/incidents/2022-10-27-uvtoken/</link><pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-27-uvtoken/</guid><description>The UvTokenWallet Eco Staking mining pool contract was hacked. The key reason for the vulnerability is that the mining pool contract withdrawal function does not strictly judge the user input, so that the attacker can&amp;hellip;</description></item><item><title>FTX &amp; 3Commas</title><link>https://0xtracer.xyz/incidents/2022-10-23-ftx-and-3commas/</link><pubDate>Sun, 23 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-23-ftx-and-3commas/</guid><description>Several FTX users were hacked and stolen coins, which 3Commas said was due to phishing websites. In a collaborative investigation conducted by 3Commas and FTX, it was discovered that some API keys were associated with&amp;hellip;</description></item><item><title>Layer2DAO</title><link>https://0xtracer.xyz/incidents/2022-10-23-layer2dao/</link><pubDate>Sun, 23 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-23-layer2dao/</guid><description>The project Layer2DAO on Optimism was attacked by hackers. The hackers stole 49.95 million L2DAO tokens and sold some tokens by obtaining the multi-signature permission of Layer2DAO. Layer2DAO said it has repurchased&amp;hellip;</description></item><item><title>Blur</title><link>https://0xtracer.xyz/incidents/2022-10-22-blur/</link><pubDate>Sat, 22 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-22-blur/</guid><description>NFT platform Blur tweeted that it noticed a phishing account with the ID @Blur_DAO and reminded users not to click on fake links. The fake account tweeted that the BLUR token query was now open, and posted a phishing&amp;hellip;</description></item><item><title>Gate.io</title><link>https://0xtracer.xyz/incidents/2022-10-22-gate-io/</link><pubDate>Sat, 22 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-22-gate-io/</guid><description>SlowMist founder Cosine tweeted that Gate.io’s official Twitter account may have been hacked. Hackers sent phishing messages to trick users into visiting gąte[.]com. Once you click &amp;ldquo;Claim&amp;rdquo;, the eth_sign signature phis&amp;hellip;</description></item><item><title>Vivity</title><link>https://0xtracer.xyz/incidents/2022-10-22-vivity/</link><pubDate>Sat, 22 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-22-vivity/</guid><description>The Discord server of NFT project Vivity was attacked.</description></item><item><title>OlympusDAO</title><link>https://0xtracer.xyz/incidents/2022-10-21-olympusdao/</link><pubDate>Fri, 21 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-21-olympusdao/</guid><description>The redeem() function in OlympusDAO’s BondFixedExpiryTeller contract resulted in a loss of approximately $292,000 due to inability to properly validate inputs. The OlympusDAO hacker has returned the stolen funds to th&amp;hellip;</description></item><item><title>Ethereum Alarm Clock</title><link>https://0xtracer.xyz/incidents/2022-10-20-ethereum-alarm-clock/</link><pubDate>Thu, 20 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-20-ethereum-alarm-clock/</guid><description>According to Cointelegraph, a vulnerability in the Ethereum Alarm Clock service (Ethereum Alarm Clock) has been exploited, and the hacker has so far made about $260,000 in profit. According to the analysis, hackers ma&amp;hellip;</description></item><item><title>Mango INU</title><link>https://0xtracer.xyz/incidents/2022-10-20-mango-inu/</link><pubDate>Thu, 20 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-20-mango-inu/</guid><description>The Mango INU (MNGO) project has been confirmed to be an exit scam, and the currency price has dropped by more than 80%. This token project was deployed by attackers at Mango Market and has made a profit of about $48,&amp;hellip;</description></item><item><title>Petra</title><link>https://0xtracer.xyz/incidents/2022-10-20-petra/</link><pubDate>Thu, 20 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-20-petra/</guid><description>Aptos ecological wallet Petra tweeted that the Aptos Labs team discovered a vulnerability on Petra on October 20. The mnemonic is related to account creation in existing wallets, and the mnemonic displayed on the page&amp;hellip;</description></item><item><title>BitBTC</title><link>https://0xtracer.xyz/incidents/2022-10-19-bitbtc/</link><pubDate>Wed, 19 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-19-bitbtc/</guid><description>As reported by Cointelegraph, the BitBTC team has now fixed the bug after Twitter user @PlasmaPower0 disclosed a “fake minting” bug that existed in the cross-chain bridge between BitBTC and Optimism. It is reported th&amp;hellip;</description></item><item><title>Dataverse</title><link>https://0xtracer.xyz/incidents/2022-10-19-dataverse/</link><pubDate>Wed, 19 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-19-dataverse/</guid><description>Metaverse data platform Dataverse tweeted that it has detected hackers attacking the GEO BSC contract, and reminded users not to buy GEO in BSC, any code purchased on BNB Chian from October 19th to 22nd UTC Coins are&amp;hellip;</description></item><item><title>Bitkeep Swap</title><link>https://0xtracer.xyz/incidents/2022-10-18-bitkeep-swap/</link><pubDate>Tue, 18 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-18-bitkeep-swap/</guid><description>According to the official news of the wallet BitKeep, BitKeep Swap was attacked by hackers, and the development team has carried out urgent processing. The hacker&amp;rsquo;s attack has been stopped. The attack was concentrated&amp;hellip;</description></item><item><title>Moola Market</title><link>https://0xtracer.xyz/incidents/2022-10-18-moola-market/</link><pubDate>Tue, 18 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-18-moola-market/</guid><description>MOO token price pumped then used as collateral to drain reserves</description></item><item><title>PLTD</title><link>https://0xtracer.xyz/incidents/2022-10-18-pltd/</link><pubDate>Tue, 18 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-18-pltd/</guid><description>The PLTD project was attacked by hackers, all BUSD in its trading pool was sold out, and the attackers gained a total of 24,497 BUSD. This attack mainly exploits the code loopholes in the PLTD contract, reduces the PL&amp;hellip;</description></item><item><title>LiveArtX</title><link>https://0xtracer.xyz/incidents/2022-10-17-liveartx/</link><pubDate>Mon, 17 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-17-liveartx/</guid><description>The official wallet of NFT platform LiveArtX was stolen, and several reserved NFTs were sold. According to MistTrack analysis, the LiveArtX attacker (0x5f78&amp;hellip;A920) has transferred 7.3 ETH and 22.39 WETH to Bitkeep, t&amp;hellip;</description></item><item><title>MTDAO</title><link>https://0xtracer.xyz/incidents/2022-10-17-mtdao/</link><pubDate>Mon, 17 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-17-mtdao/</guid><description>The unopened contract 0xFaC064847aB0Bb7ac9F30a1397BebcEdD4879841 of the MTDAO project party was attacked by a flash loan, and the affected tokens were MT and ULM, with a total profit of 487,042.615 BUSD. The attacker&amp;hellip;</description></item><item><title>Earning.Farm</title><link>https://0xtracer.xyz/incidents/2022-10-15-earning-farm/</link><pubDate>Sat, 15 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-15-earning-farm/</guid><description>The EFLeverVault contract of Earning.Farm was attacked twice by flash loans. The first attack was intercepted by MEV bot, causing the contract to lose 480 ETH; the second hacker completed the attack, and the hacker ma&amp;hellip;</description></item><item><title>FTX</title><link>https://0xtracer.xyz/incidents/2022-10-13-ftx/</link><pubDate>Thu, 13 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-13-ftx/</guid><description>According to the X-explore blog, the hacker address starting with 0x1d37 is stealing GAS by exploiting the FTX vulnerability, minting XEN tokens 17,000 times at zero cost. The reason for this attack is that FTX does n&amp;hellip;</description></item><item><title>ATK</title><link>https://0xtracer.xyz/incidents/2022-10-12-atk/</link><pubDate>Wed, 12 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-12-atk/</guid><description>The Journey of Awakening (ATK) project suffered a flash loan attack. The attacker attacked the strategy contract of the ATK project (0x96bF2E6CC029363B57Ffa5984b943f825D333614) through a flash loan attack, and obtaine&amp;hellip;</description></item><item><title>Tulip Protocol</title><link>https://0xtracer.xyz/incidents/2022-10-12-tulip-protocol/</link><pubDate>Wed, 12 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-12-tulip-protocol/</guid><description>Tulip Protocol, a Solana ecological income aggregator and leveraged income farming platform, stated that its exposure to the Mango attack was limited to a portion of the USDC/RAY strategic treasury, namely 2,465,841.4&amp;hellip;</description></item><item><title>UXD Protocol</title><link>https://0xtracer.xyz/incidents/2022-10-12-uxd-protocol/</link><pubDate>Wed, 12 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-12-uxd-protocol/</guid><description>The total amount of funds affected by the Solana ecological algorithm stablecoin protocol UXD Protocol in the Mango attack is $19,986,134.9037. UXD Protocol stated: “Our insurance fund is sufficient to cover losses. U&amp;hellip;</description></item><item><title>Mango Markets</title><link>https://0xtracer.xyz/incidents/2022-10-11-mango-markets/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-mango-markets/</guid><description>Attacker pumped MNGO price then took massive under-collateralized loans</description></item><item><title>QANplatform</title><link>https://0xtracer.xyz/incidents/2022-10-11-qanplatform/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-qanplatform/</guid><description>Layer1 blockchain QANplatform (QANX), which is resistant to quantum computing attacks, tweeted that its smart contract cross-chain bridge was attacked, and the attacker managed to extract tokens, reminding users not t&amp;hellip;</description></item><item><title>Rabby</title><link>https://0xtracer.xyz/incidents/2022-10-11-rabby/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-rabby/</guid><description>DeBank plug-in wallet Rabby tweeted that its Rabby Swap smart contract has a vulnerability, and users who have used it should revoke Rabby Swap approvals on all chains as soon as possible. According to the analysis of&amp;hellip;</description></item><item><title>TempleDAO</title><link>https://0xtracer.xyz/incidents/2022-10-11-templedao/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-templedao/</guid><description>Stax contract lacked caller validation allowing unauthorized fund transfer</description></item><item><title>The Micro Elements</title><link>https://0xtracer.xyz/incidents/2022-10-11-the-micro-elements/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-the-micro-elements/</guid><description>The Micro Elements (TME) project is an exit scam, with a drop of more than 95%, and about $548,600 has been stolen. BSC address 0xd631464f596e2ff3b9fe67a0ae10f6b73637f71e.</description></item><item><title>TokenPocket</title><link>https://0xtracer.xyz/incidents/2022-10-11-tokenpocket/</link><pubDate>Tue, 11 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-11-tokenpocket/</guid><description>According to the official announcement of TokenPocket, the official website tokenpocket.pro is currently attacked by abnormal traffic, and the technical team is carrying out emergency maintenance. During the technical&amp;hellip;</description></item><item><title>Jumpnfinance</title><link>https://0xtracer.xyz/incidents/2022-10-09-jumpnfinance/</link><pubDate>Sun, 09 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-09-jumpnfinance/</guid><description>Jumpnfinance project Rugpull, involving an amount of about 1.15 million US dollars. The attacker first calls the 0x6b1d9018() function of the 0xe156 contract to extract the user assets in the contract and store them a&amp;hellip;</description></item><item><title>Xave Finance</title><link>https://0xtracer.xyz/incidents/2022-10-09-xave-finance/</link><pubDate>Sun, 09 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-09-xave-finance/</guid><description>The Xave Finance project was hacked, resulting in a 1000x increase in RNBW issuance. The attack transaction is 0xc18ec2eb7d41638d9982281e766945d0428aaeda6211b4ccb6626ea7cff31f4a. The attacker first creates the attack&amp;hellip;</description></item><item><title>BNB Bridge</title><link>https://0xtracer.xyz/incidents/2022-10-06-bnb-bridge/</link><pubDate>Thu, 06 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-06-bnb-bridge/</guid><description>IAVL proof verification bypass allowing fake deposits</description></item><item><title>Sex DAO</title><link>https://0xtracer.xyz/incidents/2022-10-05-sex-dao/</link><pubDate>Wed, 05 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-05-sex-dao/</guid><description>The Web3 social platform Sex DAO is suspected to have been Rug. The original white paper has been deleted. Over 220,000 USDT and 4.17 billion SED (SEXDAO Token) have been transferred on the chain. Currently, the Sex D&amp;hellip;</description></item><item><title>Sovryn</title><link>https://0xtracer.xyz/incidents/2022-10-05-sovryn/</link><pubDate>Wed, 05 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-05-sovryn/</guid><description>Bitcoin DeFi application Sovryn tweeted that it found a vulnerability affecting the lending pool and was attacked. The attacker used the abandoned lending protocol to withdraw 44.93 RBTC and 211,045 USDT. After the de&amp;hellip;</description></item><item><title>Transit Swap</title><link>https://0xtracer.xyz/incidents/2022-10-01-transit-swap/</link><pubDate>Sat, 01 Oct 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-10-01-transit-swap/</guid><description>Token transfer logic flaw allowed attacker to steal user approvals</description></item><item><title>BXH</title><link>https://0xtracer.xyz/incidents/2022-09-28-bxh/</link><pubDate>Wed, 28 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-28-bxh/</guid><description>The TokenStakingPoolDelegate contract updated by BXH after the last attack suffered another flash loan attack. The contract lost 40,085 USDT, and the attacker made a profit of 31,794 USDT after paying off the flash lo&amp;hellip;</description></item><item><title>MEV Bots</title><link>https://0xtracer.xyz/incidents/2022-09-28-mev-bots/</link><pubDate>Wed, 28 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-28-mev-bots/</guid><description>A bot named 0xbadc0de made a windfall when traders tried to sell 1.8 million cUSDC (USDC on the Compound protocol) ($1.85 million in nominal value), but only got $500 of the asset due to low liquidity in return. Howev&amp;hellip;</description></item><item><title>BXH</title><link>https://0xtracer.xyz/incidents/2022-09-21-bxh/</link><pubDate>Wed, 21 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-21-bxh/</guid><description>According to the SlowMist security team, according to the BXH Stupid Kids team’s announcement on September 23, a total of $2.5 million worth of assets and 38 million BXH tokens were stolen the night before yesterday (&amp;hellip;</description></item><item><title>Wintermute</title><link>https://0xtracer.xyz/incidents/2022-09-20-wintermute/</link><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-20-wintermute/</guid><description>Profanity vanity address generator vulnerability exploited</description></item><item><title>Dogechain</title><link>https://0xtracer.xyz/incidents/2022-09-11-dogechain/</link><pubDate>Sun, 11 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-11-dogechain/</guid><description>In a tweet, @0xCrumbs disclosed that Dogechain was hacked yesterday, and the attackers exploited the vulnerability to mint 9.7 million $Doge (about $600,000) and transfer $316,000 through a cross-chain bridge. Current&amp;hellip;</description></item><item><title>New Free Dao</title><link>https://0xtracer.xyz/incidents/2022-09-08-new-free-dao/</link><pubDate>Thu, 08 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-08-new-free-dao/</guid><description>The New Free Dao project on the BSC chain suffered a flash loan attack. According to SlowMist analysis, the main reason for this attack is that the way of calculating rewards in the contract is too simple, and it only&amp;hellip;</description></item><item><title>GERA</title><link>https://0xtracer.xyz/incidents/2022-09-07-gera/</link><pubDate>Wed, 07 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-07-gera/</guid><description>The security of the GERA token was compromised due to private key leakage. Hackers transferred the ownership of the smart contract deployer of GERA tokens to another address 0x510E4d61663bE6a24D600AaF90F892dd8c8C61dC.</description></item><item><title>Nereus</title><link>https://0xtracer.xyz/incidents/2022-09-06-nereus/</link><pubDate>Tue, 06 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-06-nereus/</guid><description>The project Nereus Finance on AVAX was attacked. The attacker made a profit of about 371,000 USDC by using the classic flash loan attack mode, namely &amp;ldquo;flash loan -&amp;gt; skew reserve -&amp;gt; fake LP token pricing -&amp;gt; repay the f&amp;hellip;</description></item><item><title>DaoSwap</title><link>https://0xtracer.xyz/incidents/2022-09-05-daoswap/</link><pubDate>Mon, 05 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-05-daoswap/</guid><description>On September 5th, DaoSwap lost 580,000 USDT in an attack that allowed users to set the inviter’s address as themselves due to mining rewards that were larger than the fees charged during the swap process and lack of v&amp;hellip;</description></item><item><title>Kyber Network</title><link>https://0xtracer.xyz/incidents/2022-09-02-kyber-network/</link><pubDate>Fri, 02 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-02-kyber-network/</guid><description>Decentralized liquidity protocol Kyber Network disclosed on Twitter that its users lost $265,000 in funds due to a front-end exploit. The vulnerability stems from malicious Google Tag Manager code in the KyberSwap web&amp;hellip;</description></item><item><title>ShadowFi</title><link>https://0xtracer.xyz/incidents/2022-09-02-shadowfi/</link><pubDate>Fri, 02 Sep 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-09-02-shadowfi/</guid><description>Privacy project ShadowFi suffered a hack, and its official TokenSDF fell 98.5%. The attacker exploited the vulnerability of SDF to allow anyone to burn the Token, making a profit of about 1078 BNB (about $300,000), an&amp;hellip;</description></item><item><title>CUPID</title><link>https://0xtracer.xyz/incidents/2022-08-31-cupid/</link><pubDate>Wed, 31 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-31-cupid/</guid><description>The attacker made a profit of $78,622 through a flash loan on BNB Chain, causing the token CUPID to plummet by more than 90%, and the token VENUS to rise by more than 300% and then fall back.</description></item><item><title>Bill Murray</title><link>https://0xtracer.xyz/incidents/2022-08-29-bill-murray/</link><pubDate>Mon, 29 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-29-bill-murray/</guid><description>Actor and comedian Bill Murray&amp;rsquo;s personal wallet was stolen, resulting in the loss of funds raised by the actor&amp;rsquo;s charity NFT, hackers stole about 112.05 wETH (worth about $174,000), which was then converted into ETH&amp;hellip;</description></item><item><title>DDC</title><link>https://0xtracer.xyz/incidents/2022-08-29-ddc/</link><pubDate>Mon, 29 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-29-ddc/</guid><description>DDC was exploited and lost $104,600. The cause of the event is the problem of arbitrarily deducting pool fees.</description></item><item><title>OptiFi</title><link>https://0xtracer.xyz/incidents/2022-08-29-optifi/</link><pubDate>Mon, 29 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-29-optifi/</guid><description>Solana’s ecological derivative OptiFi tweeted that at around 6:00 UTC on August 29th, team members tried to update and upgrade on Solana, but the OptiFi mainnet program was shut down due to an operation error and coul&amp;hellip;</description></item><item><title>Sui</title><link>https://0xtracer.xyz/incidents/2022-08-27-sui/</link><pubDate>Sat, 27 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-27-sui/</guid><description>Public chain project Sui tweeted that its Discord server had been hacked, and asked users not to click on any links posted on the Discord server in the past 8 hours. According to some replies to the tweet, some users&amp;hellip;</description></item><item><title>Kaoyaswap</title><link>https://0xtracer.xyz/incidents/2022-08-24-kaoyaswap/</link><pubDate>Wed, 24 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-24-kaoyaswap/</guid><description>Kaoyaswap on BSC appears to have been attacked, with hackers making 37,294 BUSD and 271.2 WBNB, caused by faulty logic in the Swap function.</description></item><item><title>PokémonFi</title><link>https://0xtracer.xyz/incidents/2022-08-24-pokemonfi/</link><pubDate>Wed, 24 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-24-pokemonfi/</guid><description>Pokémon piracy project PokémonFi has RugPull, the project and token first launched in April, the project recently deleted its Twitter account, but its website still exists.</description></item><item><title>Sudorare</title><link>https://0xtracer.xyz/incidents/2022-08-23-sudorare/</link><pubDate>Tue, 23 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-23-sudorare/</guid><description>Sudoswap imitation disk Sudorare is suspected to have a Rug Pull, and the Looks, WETH and XMON tokens in the contract address were transferred to the first 0xbb42 address (0xbb42f789b39af41b796f6C28D4c4aa5aCE389d8A),&amp;hellip;</description></item><item><title>Rainbow Bridge</title><link>https://0xtracer.xyz/incidents/2022-08-20-rainbow-bridge/</link><pubDate>Sat, 20 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-20-rainbow-bridge/</guid><description>Aurora Labs CEO Alex Shevchenko revealed that an attacker trying to steal funds from Rainbow Bridge was stopped in 31 seconds, losing 5 ETH in the process.</description></item><item><title>Celer</title><link>https://0xtracer.xyz/incidents/2022-08-18-celer/</link><pubDate>Thu, 18 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-18-celer/</guid><description>Celer said that cBridge&amp;rsquo;s front-end interface suffered from DNS cache poisoning attacks. This attack targeted third-party DNS providers. Celer&amp;rsquo;s own contract was not affected, and users who suffered losses in this inc&amp;hellip;</description></item><item><title>The Bribe Protocol</title><link>https://0xtracer.xyz/incidents/2022-08-18-the-bribe-protocol/</link><pubDate>Thu, 18 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-18-the-bribe-protocol/</guid><description>The Bribe Protocol promised a DAO infrastructure tool where &amp;ldquo;token holders get paid to govern&amp;rdquo;, and raised $5.5 million in funding in January to work on their extensive roadmap. However, the project leaders have effec&amp;hellip;</description></item><item><title>Acala</title><link>https://0xtracer.xyz/incidents/2022-08-14-acala/</link><pubDate>Sun, 14 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-14-acala/</guid><description>The Polkadot ecological project Acala caused an additional issuance of aUSD due to an error on the chain, allowing attackers to mint aUSD. The vulnerability caused aUSD to lose its peg to the US dollar, initially fall&amp;hellip;</description></item><item><title>Blur Finance</title><link>https://0xtracer.xyz/incidents/2022-08-10-blur-finance/</link><pubDate>Wed, 10 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-10-blur-finance/</guid><description>Yield aggregator Blur Finance withdrew more than $600,000 in assets from BNB Chain and Polygon before deleting websites and social media accounts. The project, which has only been active for about a month, has amassed&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2022-08-09-curve-finance/</link><pubDate>Tue, 09 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-09-curve-finance/</guid><description>The Curve Finance frontend was attacked, prompting users to grant token approvals to malicious smart contracts. The attackers moved the stolen funds to FixedFloat and Tornado Cash, with at least 362 ETH (~$620,000) st&amp;hellip;</description></item><item><title>EGD Finance</title><link>https://0xtracer.xyz/incidents/2022-08-08-egd-finance/</link><pubDate>Mon, 08 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-08-egd-finance/</guid><description>According to SlowMist, the EGD Finance project on BSC was attacked by hackers, resulting in the unexpected withdrawal of funds from its pool. The SlowMist security team analyzed this and said that this incident was be&amp;hellip;</description></item><item><title>Saxon James Musk</title><link>https://0xtracer.xyz/incidents/2022-08-07-saxon-james-musk/</link><pubDate>Sun, 07 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-07-saxon-james-musk/</guid><description>Saxon James Musk has Rug Pull. Project developers suddenly sold their token share for around 1355 WBNB (~$442,000), causing the token price to plummet by over 68%.</description></item><item><title>GenomesDAO</title><link>https://0xtracer.xyz/incidents/2022-08-06-genomesdao/</link><pubDate>Sat, 06 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-06-genomesdao/</guid><description>According to SlowMist, the GenomesDAO project on MATIC was attacked by hackers, resulting in the unexpected withdrawal of funds in its LPSTAKING contract. This incident is because the LPSTAKING contract of GenomesDAO&amp;hellip;</description></item><item><title>Steven Galanis</title><link>https://0xtracer.xyz/incidents/2022-08-06-steven-galanis/</link><pubDate>Sat, 06 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-06-steven-galanis/</guid><description>A hacker compromised the wallet belonging to Steven Galanis, the CEO of Cameo, an app that allows people to pay various celebrities to record short messages for them. The hacker took 9,457 ApeCoin (~$69,000), 2.3 ETH&amp;hellip;</description></item><item><title>Velodrome</title><link>https://0xtracer.xyz/incidents/2022-08-04-velodrome/</link><pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-04-velodrome/</guid><description>On August 4, Team at Velodrome, an AMM project built on Optimism, noticed that $350,000 had been taken from a team-operated wallet that was normally used for operational funds. They announced they were beginning an in&amp;hellip;</description></item><item><title>Slope Wallet</title><link>https://0xtracer.xyz/incidents/2022-08-03-slope-wallet/</link><pubDate>Wed, 03 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-03-slope-wallet/</guid><description>Slope mobile app logged seed phrases to centralized Sentry server</description></item><item><title>Solana</title><link>https://0xtracer.xyz/incidents/2022-08-03-solana/</link><pubDate>Wed, 03 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-03-solana/</guid><description>A large-scale incident of currency theft occurred on the Solana public chain, and a large number of users were transferred SOL and SPL tokens without their knowledge. According to SlowMist MistTrack statistics, more t&amp;hellip;</description></item><item><title>Reaper Farm</title><link>https://0xtracer.xyz/incidents/2022-08-02-reaper-farm/</link><pubDate>Tue, 02 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-02-reaper-farm/</guid><description>Reaper Farm&amp;rsquo;s ReaperVaultV2 contract was maliciously exploited, resulting in more than $1.6 million worth of damage. Attackers exploited a vulnerability in the ReaperVaultV2 contract that could destroy other users&amp;rsquo; va&amp;hellip;</description></item><item><title>Nomad Bridge</title><link>https://0xtracer.xyz/incidents/2022-08-01-nomad-bridge/</link><pubDate>Mon, 01 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-01-nomad-bridge/</guid><description>Zero-initialized trusted root allowed arbitrary message proving</description></item><item><title>ZB</title><link>https://0xtracer.xyz/incidents/2022-08-01-zb/</link><pubDate>Mon, 01 Aug 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-08-01-zb/</guid><description>The ZB exchange was hacked with a total loss of around $4.3 million. ZB has notified the community on August 2 that deposits and withdrawals will be suspended due to a &amp;ldquo;sudden failure&amp;rdquo;. The reason is &amp;ldquo;Sudden failure o&amp;hellip;</description></item><item><title>Nirvana</title><link>https://0xtracer.xyz/incidents/2022-07-28-nirvana/</link><pubDate>Thu, 28 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-28-nirvana/</guid><description>According to SlowMist Intelligence, Nirvana, a stablecoin project on the Solana chain, was attacked by a flash loan. The attacker used a flash loan to borrow 10,250,000 USDC from Solend by deploying a malicious contra&amp;hellip;</description></item><item><title>TBIS</title><link>https://0xtracer.xyz/incidents/2022-07-26-tbis/</link><pubDate>Tue, 26 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-26-tbis/</guid><description>CEO Michael Stollery of Titanium Blockchain Infrastructure Services (TBIS) pled guilty to securities fraud in connection to a $21 million cryptocurrency scam. The company promoted its BAR token during 2017–2018, and d&amp;hellip;</description></item><item><title>DRAC Network</title><link>https://0xtracer.xyz/incidents/2022-07-25-drac-network/</link><pubDate>Mon, 25 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-25-drac-network/</guid><description>DeFi project DRAC Network appeared Rug Pull, with the price of the token $TEDDY dropping 99.4%. 10,000 $BNB and 2 million $BUSD have been slowly transferred to Binance. It is said that the deployer deployed the contra&amp;hellip;</description></item><item><title>Audius</title><link>https://0xtracer.xyz/incidents/2022-07-24-audius/</link><pubDate>Sun, 24 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-24-audius/</guid><description>Web3 music streaming service platform Audius community treasury was hacked, losing 18.5 million AUDIO Tokens. The hackers exchanged the funds for about 705 ETH on Uniswap. Audius officially stated that the problem has&amp;hellip;</description></item><item><title>Neopets</title><link>https://0xtracer.xyz/incidents/2022-07-24-neopets/</link><pubDate>Sun, 24 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-24-neopets/</guid><description>The online game Neopets said it encountered a hack and is currently investigating a customer data breach. The Neopets hack may affect 69 million users, and a hacker named TarTarX sold the source of the Neopets website&amp;hellip;</description></item><item><title>My Big Coin</title><link>https://0xtracer.xyz/incidents/2022-07-21-my-big-coin/</link><pubDate>Thu, 21 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-21-my-big-coin/</guid><description>My Big Coin founder Crater has been found guilty of a cryptocurrency fraud scheme. Crater founded My Big Coin in 2013 to provide virtual payment services through the fraudulent digital currency &amp;ldquo;My Big Coins,&amp;rdquo; which h&amp;hellip;</description></item><item><title>Tableland</title><link>https://0xtracer.xyz/incidents/2022-07-21-tableland/</link><pubDate>Thu, 21 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-21-tableland/</guid><description>The Tableland Discord server was compromised by malicious actors, successfully impersonating moderators on the channel and leading community members to a fake Tableland domain that funneled targeted assets from member&amp;hellip;</description></item><item><title>Raccoon Network &amp; Freedom Protocol</title><link>https://0xtracer.xyz/incidents/2022-07-20-raccoon-network-and-freedom-protocol/</link><pubDate>Wed, 20 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-20-raccoon-network-and-freedom-protocol/</guid><description>Raccoon Network and Freedom Protocol are scam projects, scammers have transferred 20 million BUSD (IDO) to address 0xf800&amp;hellip;469336.</description></item><item><title>Tableland</title><link>https://0xtracer.xyz/incidents/2022-07-19-tableland/</link><pubDate>Tue, 19 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-19-tableland/</guid><description>The permissions of the relevant administrators of the Discord of the Tableland project party were stolen. It is understood that after joining an external Discord server, Tableland members clicked the verification step&amp;hellip;</description></item><item><title>PREMINT</title><link>https://0xtracer.xyz/incidents/2022-07-17-premint/</link><pubDate>Sun, 17 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-17-premint/</guid><description>The NFT access list tool PREMINT issued an alert through its official Twitter, because some users reminded that the tool&amp;rsquo;s website was hacked, and the collections of NFT collectors have been stolen. Subsequently, the&amp;hellip;</description></item><item><title>DeeKay</title><link>https://0xtracer.xyz/incidents/2022-07-16-deekay/</link><pubDate>Sat, 16 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-16-deekay/</guid><description>On July 16, hackers compromised the Twitter account of well-known NFT artist DeeKay. The 180,000 followers of DeeKay&amp;rsquo;s hacked Twitter account saw it post a link announcing a limited number of new airdrops, which direc&amp;hellip;</description></item><item><title>Impermax Finance</title><link>https://0xtracer.xyz/incidents/2022-07-16-impermax-finance/</link><pubDate>Sat, 16 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-16-impermax-finance/</guid><description>An official incident report from Impermax Finance stated that a hacker was able to steal approximately 9M IMX from several wallets controlled by the team. The IMX was not sold immediately after the hackers stole the f&amp;hellip;</description></item><item><title>Freeway</title><link>https://0xtracer.xyz/incidents/2022-07-14-freeway/</link><pubDate>Thu, 14 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-14-freeway/</guid><description>The pledge platform Freeway tweeted, “The price of its token FWT fluctuated violently on July 13 and is currently under investigation. Freeway’s blockchain bridging service provider Coffe was attacked, and a large num&amp;hellip;</description></item><item><title>SpaceGodzilla</title><link>https://0xtracer.xyz/incidents/2022-07-14-spacegodzilla/</link><pubDate>Thu, 14 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-14-spacegodzilla/</guid><description>SpaceGodzilla was attacked by price manipulation and lost approximately 25,000 USDT.</description></item><item><title>Citizen Finance</title><link>https://0xtracer.xyz/incidents/2022-07-12-citizen-finance/</link><pubDate>Tue, 12 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-12-citizen-finance/</guid><description>Multi-chain NFT protocol Citizen Finance claims to have been attacked by an outside party that gained access to the private keys of BNB and the Polygon chain. The attackers used their access to transfer 244 BNB (~$55,&amp;hellip;</description></item><item><title>Uniswap</title><link>https://0xtracer.xyz/incidents/2022-07-11-uniswap/</link><pubDate>Mon, 11 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-11-uniswap/</guid><description>More than 70,000 addresses connected to Uniswap were airdropped tokens that tricked users into approving transactions that would allow attackers to control their wallets. The airdrop links users to a phishing site tha&amp;hellip;</description></item><item><title>BiFi</title><link>https://0xtracer.xyz/incidents/2022-07-10-bifi/</link><pubDate>Sun, 10 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-10-bifi/</guid><description>BIFROST officially released a report saying that the BTC address registration server of the BiFi service was attacked. According to the analysis, the attack was limited to the BTC address registration server, and neit&amp;hellip;</description></item><item><title>Omni X</title><link>https://0xtracer.xyz/incidents/2022-07-10-omni-x/</link><pubDate>Sun, 10 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-10-omni-x/</guid><description>Decentralized NFT financialization protocol Omni X has been attacked and stolen funds have been transferred to Tornado.cash. The main reason for this attack is that the burn function will call the callback function ex&amp;hellip;</description></item><item><title>Shade Inu Token</title><link>https://0xtracer.xyz/incidents/2022-07-06-shade-inu-token/</link><pubDate>Wed, 06 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-06-shade-inu-token/</guid><description>A fake Shade Inu Token project deployer removed approximately $101,000 (424 BNB) of liquidity from the liquidity pool. After investigation, this Shade Inu Token was identified as a scam, the project launched a fake Sh&amp;hellip;</description></item><item><title>The British Army</title><link>https://0xtracer.xyz/incidents/2022-07-03-the-british-army/</link><pubDate>Sun, 03 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-03-the-british-army/</guid><description>According to Forbes, the official Twitter and YouTube accounts of the British Army were hacked and posted about cryptocurrencies and NFTs. The Twitter account retweeted posts promoting NFTs, and the YouTube account up&amp;hellip;</description></item><item><title>Crema Finance</title><link>https://0xtracer.xyz/incidents/2022-07-02-crema-finance/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-02-crema-finance/</guid><description>Flash loan via fake tick account to manipulate pool fee calculation</description></item><item><title>Polygon &amp; Fantom</title><link>https://0xtracer.xyz/incidents/2022-07-01-polygon-and-fantom/</link><pubDate>Fri, 01 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-01-polygon-and-fantom/</guid><description>Polygon Chief Information Security Officer Mudit Gupta tweeted that two remote procedure call (RPC) interfaces of Polygon and Fantom were affected by a Domain Name System (DNS) hijacking attack on Friday. The reason w&amp;hellip;</description></item><item><title>Quixotic</title><link>https://0xtracer.xyz/incidents/2022-07-01-quixotic/</link><pubDate>Fri, 01 Jul 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-07-01-quixotic/</guid><description>Quiuixotic, the largest NFT platform in the Optimism ecosystem, has a serious vulnerability, and a large number of user assets have been stolen. Users who have traded on this market should cancel their authorization a&amp;hellip;</description></item><item><title>MAD</title><link>https://0xtracer.xyz/incidents/2022-06-30-mad/</link><pubDate>Thu, 30 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-30-mad/</guid><description>$MAD was hacked, and the hacker transferred all $MAD in the contract by directly calling the transfer function of the contract holding the token, and finally made a profit of $556 BNB (worth about $115,681), which was&amp;hellip;</description></item><item><title>Quint</title><link>https://0xtracer.xyz/incidents/2022-06-30-quint/</link><pubDate>Thu, 30 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-30-quint/</guid><description>Metaverse project Quint was hacked and lost $130,000. The root cause of the attack is that when the reStake function executes the reStake reward reStake, the reward amount of the LP token is not updated, so that the a&amp;hellip;</description></item><item><title>XCarnival</title><link>https://0xtracer.xyz/incidents/2022-06-26-xcarnival/</link><pubDate>Sun, 26 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-26-xcarnival/</guid><description>Pledged NFT ID used repeatedly as collateral before withdrawal</description></item><item><title>ConvexFinance</title><link>https://0xtracer.xyz/incidents/2022-06-24-convexfinance/</link><pubDate>Fri, 24 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-24-convexfinance/</guid><description>ConvexFinance officially tweeted that a DNS attack caused users to approve malicious contracts on some interactions on the website, and the problem has been fixed.</description></item><item><title>Ribbon Finance</title><link>https://0xtracer.xyz/incidents/2022-06-24-ribbon-finance/</link><pubDate>Fri, 24 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-24-ribbon-finance/</guid><description>Ribbon Finance said in a tweet that the homepage of the URL suffered a DNS attack, causing 2 users to approve a malicious contract for vault deposits. At present, the team has solved the problem, and the funds in all&amp;hellip;</description></item><item><title>DeFiSaver</title><link>https://0xtracer.xyz/incidents/2022-06-23-defisaver/</link><pubDate>Thu, 23 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-23-defisaver/</guid><description>One-stop asset management solution DeFiSaver tweeted that it experienced an attempted DNS attack and, according to its analysis, no users were affected. DeFi Saver said that what the DNS attack has in common with Conv&amp;hellip;</description></item><item><title>Harmony Bridge</title><link>https://0xtracer.xyz/incidents/2022-06-23-harmony-bridge/</link><pubDate>Thu, 23 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-23-harmony-bridge/</guid><description>2 of 5 multisig keys compromised, Lazarus Group attributed</description></item><item><title>pandorachainDAO</title><link>https://0xtracer.xyz/incidents/2022-06-22-pandorachaindao/</link><pubDate>Wed, 22 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-22-pandorachaindao/</guid><description>The pandorachainDAO project suffered a flash loan attack, resulting in a loss of assets worth about $128,000.</description></item><item><title>DHE</title><link>https://0xtracer.xyz/incidents/2022-06-21-dhe/</link><pubDate>Tue, 21 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-21-dhe/</guid><description>A Rug Pull occurred in the DHE project, causing the price of DHE tokens to drop by more than 91%. Total losses are currently around $142,000.</description></item><item><title>LV PLUS</title><link>https://0xtracer.xyz/incidents/2022-06-21-lv-plus/</link><pubDate>Tue, 21 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-21-lv-plus/</guid><description>The LV PLUS (Token LVP) project has been identified as a Rug Pull project. So far, the project has resulted in losses of about $1.5 million. LV PLUS claims to be affiliated with the &amp;ldquo;LV Metaverse&amp;rdquo;, and the main reason&amp;hellip;</description></item><item><title>whaleswap.finance</title><link>https://0xtracer.xyz/incidents/2022-06-21-whaleswap-finance/</link><pubDate>Tue, 21 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-21-whaleswap-finance/</guid><description>The whaleswap.finance project was attacked, and at least 5946 BUSD and 5964 USDT were lost. The reason may be that there is a problem with the K value verification of the whaleswap.finance Pair contract. Whenever the&amp;hellip;</description></item><item><title>SNOOD</title><link>https://0xtracer.xyz/incidents/2022-06-20-snood/</link><pubDate>Mon, 20 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-20-snood/</guid><description>The SNOOD ERC-777 smart contract was attacked, causing the liquidity of the UniswapV2Pair token to be completely drained (104 ETH).</description></item><item><title>LACOSTE</title><link>https://0xtracer.xyz/incidents/2022-06-19-lacoste/</link><pubDate>Sun, 19 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-19-lacoste/</guid><description>Clothing brand LACOSTE&amp;rsquo;s Discord was hacked, and scammers posted phishing links on the announcement channel. Recently, the Discords of several projects have been attacked, including Clyde, Good Skellas, Duppies, Oak P&amp;hellip;</description></item><item><title>Babel Finance</title><link>https://0xtracer.xyz/incidents/2022-06-17-babel-finance/</link><pubDate>Fri, 17 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-17-babel-finance/</guid><description>Crypto Financial Services Provider Babel Finance Suspends Customer Withdrawals due to crypto market turmoil. In July, documents revealed that Babel Finance lost more than $280 million in bitcoin (BTC) and ether (ETH)&amp;hellip;</description></item><item><title>Inverse Finance</title><link>https://0xtracer.xyz/incidents/2022-06-16-inverse-finance/</link><pubDate>Thu, 16 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-16-inverse-finance/</guid><description>Second Inverse attack using DOLA price oracle manipulation on Curve</description></item><item><title>KnownOrigin</title><link>https://0xtracer.xyz/incidents/2022-06-14-knownorigin/</link><pubDate>Tue, 14 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-14-knownorigin/</guid><description>KnownOrigin officially tweeted that its discord had been attacked, and reminded users not to click on any links. Other servers hacked in recent days include those of Curiosity, Meta Hunters, Parallel, Goat Society, RF&amp;hellip;</description></item><item><title>ElonMVP</title><link>https://0xtracer.xyz/incidents/2022-06-13-elonmvp/</link><pubDate>Mon, 13 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-13-elonmvp/</guid><description>The ElonMVP token suffered a Rug Pull, the token price fell by 99%, and over 622 BNB were transferred to Tornado.Cash, with a loss of about $130,000.</description></item><item><title>Fswap</title><link>https://0xtracer.xyz/incidents/2022-06-13-fswap/</link><pubDate>Mon, 13 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-13-fswap/</guid><description>Fswap was attacked by a hacker on June 13. Fswap stated that the attack was a vulnerability incident of a non-attacked project and a malicious loan attack. Hackers borrowed money from BISWAP to FSWAP for transaction a&amp;hellip;</description></item><item><title>HEGE</title><link>https://0xtracer.xyz/incidents/2022-06-12-hege/</link><pubDate>Sun, 12 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-12-hege/</guid><description>On June 12, the price of the HEGE token plummeted by more than 97%. The current loss amount is approximately $429,000.</description></item><item><title>treasure swap</title><link>https://0xtracer.xyz/incidents/2022-06-11-treasure-swap/</link><pubDate>Sat, 11 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-11-treasure-swap/</guid><description>The treasure swap project was attacked. The attacker only used 0.000000000000000001 WETH to exchange all the WETH tokens in the transaction pool. The reverse of the source code found that the swap function of the atta&amp;hellip;</description></item><item><title>Optimism</title><link>https://0xtracer.xyz/incidents/2022-06-09-optimism/</link><pubDate>Thu, 09 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-09-optimism/</guid><description>Optimism and Wintermute both released announcements, disclosing to the community a loss of 20 million OP tokens. At the time of the release of OP tokens, Optimism entrusted Wintermute to provide liquidity services for&amp;hellip;</description></item><item><title>Osmosis</title><link>https://0xtracer.xyz/incidents/2022-06-09-osmosis/</link><pubDate>Thu, 09 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-09-osmosis/</guid><description>Osmosis, the decentralized exchange (DEX) built on the Cosmos network, was shut down just before 3 a.m. ET on Wednesday after attackers exploited a liquidity provider (LP) vulnerability to steal around 5 million Dolla&amp;hellip;</description></item><item><title>ApolloX</title><link>https://0xtracer.xyz/incidents/2022-06-08-apollox/</link><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-08-apollox/</guid><description>The ApolloX project was attacked due to a flaw in the ApolloX signature system. The attacker used the signature system flaw to generate 255 signatures, with a total of 53,946,802 $APX extracted from the contract, wort&amp;hellip;</description></item><item><title>Baby Elon</title><link>https://0xtracer.xyz/incidents/2022-06-08-baby-elon/</link><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-08-baby-elon/</guid><description>The Baby Elon project on BNBChain had a rug pull on June 8, and they took 623 BNB (~$179,000) and quickly moved the funds to Tornado Cash.</description></item><item><title>BabyElon</title><link>https://0xtracer.xyz/incidents/2022-06-08-babyelon/</link><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-08-babyelon/</guid><description>A Rug Pull occurred on the project BabyElon on BNB Chian, the token dropped 98%, and the scammers have transferred 623 BNB to Tornado Cash, with a loss of about $180,000.</description></item><item><title>Gym Network</title><link>https://0xtracer.xyz/incidents/2022-06-08-gym-network/</link><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-08-gym-network/</guid><description>GYM NETWORK Hacked, Lost $2.1M, Stolen Funds Moved to Tornado Cash. According to the official Twitter account, the attack was caused by an attack on the Claim &amp;amp; Pool function, which resulted in a significant price drop.</description></item><item><title>Osmosis</title><link>https://0xtracer.xyz/incidents/2022-06-08-osmosis/</link><pubDate>Wed, 08 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-08-osmosis/</guid><description>Cosmos ecosystem developer @TheJunonaut tweeted that a critical bug was discovered on Osmosis that could drain all liquidity pools. Anyone can add liquidity to any pool and get an additional 50% when removing it. Resp&amp;hellip;</description></item><item><title>Equalizer Finance</title><link>https://0xtracer.xyz/incidents/2022-06-07-equalizer-finance/</link><pubDate>Tue, 07 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-07-equalizer-finance/</guid><description>Equalizer Finance suffered flash loan attacks on four chains: Ethereum, BSC, Polygon and Optimism. The main reason for this attack is that the FlashLoanProvider contract of the Equalizer Finance protocol is not compat&amp;hellip;</description></item><item><title>Elrond</title><link>https://0xtracer.xyz/incidents/2022-06-05-elrond/</link><pubDate>Sun, 05 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-05-elrond/</guid><description>The blockchain network Elrond is suspected of having a security breach, and hackers &amp;ldquo;obtained&amp;rdquo; nearly 1.65 million $EGLD &amp;ldquo;out of thin air&amp;rdquo; and sold it through the decentralized exchange Maiar. On June 8, Elrond founde&amp;hellip;</description></item><item><title>BAYC&amp;Otherside</title><link>https://0xtracer.xyz/incidents/2022-06-04-bayc-and-otherside/</link><pubDate>Sat, 04 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-04-bayc-and-otherside/</guid><description>Discord servers for Yuga Lab projects Bored Ape Yacht Club (BAYC) and Otherside appear to have been affected by phishing attacks. The attackers allegedly stole more than 145 ethereum ($256,000) worth of tokens. It app&amp;hellip;</description></item><item><title>fomo-dao</title><link>https://0xtracer.xyz/incidents/2022-06-04-fomo-dao/</link><pubDate>Sat, 04 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-04-fomo-dao/</guid><description>The fomo-dao project is suspected of being attacked, and the attacker has made a profit of $110,000, which has been transferred to Tornado.cash.</description></item><item><title>Homeless Friends</title><link>https://0xtracer.xyz/incidents/2022-06-04-homeless-friends/</link><pubDate>Sat, 04 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-04-homeless-friends/</guid><description>The Discord of Homeless Friends NFT was attacked, homelessfriends[.]net is a phishing website.</description></item><item><title>Animoon</title><link>https://0xtracer.xyz/incidents/2022-06-02-animoon/</link><pubDate>Thu, 02 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-02-animoon/</guid><description>The work of Animoon with 9999 NFTs is taken from Pokémon. They claim to have signed a non-disclosure agreement (NDA) with Pokémon partner TopDeck. But with no evidence of an actual P2E game being developed, the Animoo&amp;hellip;</description></item><item><title>CoFiXProtocol</title><link>https://0xtracer.xyz/incidents/2022-06-02-cofixprotocol/</link><pubDate>Thu, 02 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-02-cofixprotocol/</guid><description>The project CoFiXProtocol on BNB Chian suffered a price manipulation attack, and the attackers made a profit of about $140,000.</description></item><item><title>StarMan</title><link>https://0xtracer.xyz/incidents/2022-06-02-starman/</link><pubDate>Thu, 02 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-02-starman/</guid><description>A Rug Pull occurred in StarMan, the coin price fell 99.5%, and the scammers have transferred about 640.4 BNB to Tornado Cash. Losses were valued at approximately $196,000.</description></item><item><title>Armadillo Coin</title><link>https://0xtracer.xyz/incidents/2022-06-01-armadillo-coin/</link><pubDate>Wed, 01 Jun 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-06-01-armadillo-coin/</guid><description>Rug Pull on Armadillo Coin on BNB Chian, scammers have transferred 663.4 BNB to Tornado.Cash.</description></item><item><title>Mirror Protocol</title><link>https://0xtracer.xyz/incidents/2022-05-31-mirror-protocol/</link><pubDate>Tue, 31 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-31-mirror-protocol/</guid><description>Mirror Protocol, a synthetic asset protocol built on Terra, has been attacked again, was attacked again, with more than $2 million in capital losses. The capital pools of Bitcoin, Ethereum and Polkadot have been exhau&amp;hellip;</description></item><item><title>Novo</title><link>https://0xtracer.xyz/incidents/2022-05-30-novo/</link><pubDate>Mon, 30 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-30-novo/</guid><description>DeFi project Novo is suspected of being attacked, and hackers have transferred 280 BNB (about $89,600) to Tornado.cash.</description></item><item><title>LUNC</title><link>https://0xtracer.xyz/incidents/2022-05-29-lunc/</link><pubDate>Sun, 29 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-29-lunc/</guid><description>On May 30, after the launch of the new Terra chain, the price of the oracle machine of LUNC (Luna Classic) reached $5, while the actual price was much lower than $5. An Anchor platform user noticed the vulnerability a&amp;hellip;</description></item><item><title>Mirror Protocol</title><link>https://0xtracer.xyz/incidents/2022-05-28-mirror-protocol/</link><pubDate>Sat, 28 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-28-mirror-protocol/</guid><description>Terra research forum member FatMan tweeted that the Mirror Protocol, a synthetic asset protocol developed by Terraform Labs, has a longstanding vulnerability. Since October 2021, attackers have exploited this vulnerab&amp;hellip;</description></item><item><title>Pokemoney</title><link>https://0xtracer.xyz/incidents/2022-05-28-pokemoney/</link><pubDate>Sat, 28 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-28-pokemoney/</guid><description>A Rug Pull occurred in the NFT metaverse game project Pokemoney on BNBChian, its Token PMY has dropped by 99.98%%, and about 11,800 BNB (about 3.5 million US dollars) have been withdrawn and transferred.</description></item><item><title>DecentraWorld</title><link>https://0xtracer.xyz/incidents/2022-05-25-decentraworld/</link><pubDate>Wed, 25 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-25-decentraworld/</guid><description>DecentraWorld’s DEWO token price plummeted, the founding team of DecentraWorld drained the project’s funds and stole 3,127 BNB (about $1 million), and the project’s official website and Twitter account were deleted.</description></item><item><title>bDollar</title><link>https://0xtracer.xyz/incidents/2022-05-21-bdollar/</link><pubDate>Sat, 21 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-21-bdollar/</guid><description>The first algorithmic stablecoin project on Binance Smart Chain, bDollar, suffered a price manipulation attack, and the attacker made a profit of 2,381 WBNB (worth about $730,000). This attack mainly exploits the desi&amp;hellip;</description></item><item><title>Llamascape</title><link>https://0xtracer.xyz/incidents/2022-05-20-llamascape/</link><pubDate>Fri, 20 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-20-llamascape/</guid><description>The project behind the Llamaverse, the Llamascape NFT series, was hacked. Hackers targeted their Discord server and scammers took around 30-40 ETH.</description></item><item><title>Kronos DAO</title><link>https://0xtracer.xyz/incidents/2022-05-19-kronos-dao/</link><pubDate>Thu, 19 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-19-kronos-dao/</guid><description>According to Pinpoint News, Klaytn-based DeFi project Kronos DAO misappropriated users’ DAI pledged in its vaults to invest in Kairos Cash and lost 6 million DAI. The 6 million DAI staked by users turned into 6 millio&amp;hellip;</description></item><item><title>Alien Frens</title><link>https://0xtracer.xyz/incidents/2022-05-18-alien-frens/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-alien-frens/</guid><description>NFT project Alien Frens tweeted that Discord had been attacked. Users are asked not to click on any MINT links.</description></item><item><title>Axie Infinity</title><link>https://0xtracer.xyz/incidents/2022-05-18-axie-infinity/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-axie-infinity/</guid><description>Axie Infinity says the Mee6 bot on its main server was hacked. Hackers use Mee6 bot to add permissions to fake Jiho account to post fake announcements about mint. MEE6 is a Discord bot that allows admins to automatica&amp;hellip;</description></item><item><title>Feminist Metaverse</title><link>https://0xtracer.xyz/incidents/2022-05-18-feminist-metaverse/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-feminist-metaverse/</guid><description>The Feminist Metaverse project on BNB Chain was attacked. The attackers have transferred 1838 BNB to Tornado.cash, about $540,000.</description></item><item><title>Lazy Lions</title><link>https://0xtracer.xyz/incidents/2022-05-18-lazy-lions/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-lazy-lions/</guid><description>Discord for NFT series Lazy Lions was hacked. Notably, this attack appears to infiltrate many other large NFT projects throughout the day, seemingly due to MEE6 staff being able to use MEE6 remotely to give themselves&amp;hellip;</description></item><item><title>QANX Bridge</title><link>https://0xtracer.xyz/incidents/2022-05-18-qanx-bridge/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-qanx-bridge/</guid><description>On May 18, QANX Bridge was attacked between 15:01:40 and 18:20:25 UTC. Developers can withdraw 100,450,000 QANX from QANX Bridge and sell it on Uniswap for 325 ETH, then transfer it to Tornado Cash. By May 26, the hac&amp;hellip;</description></item><item><title>SethGreen</title><link>https://0xtracer.xyz/incidents/2022-05-18-sethgreen/</link><pubDate>Wed, 18 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-18-sethgreen/</guid><description>The American actor SethGreen suffered from a phishing attack resulting in the loss of 4 NFTs. This includes 1 BAYC, 2 MAYC and 1 Doodle. The scammer sold all 4 NFTs for nearly 160 ETH (about $330,000).</description></item><item><title>FEG</title><link>https://0xtracer.xyz/incidents/2022-05-17-feg/</link><pubDate>Tue, 17 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-17-feg/</guid><description>The multi-chain DeFi protocol FEG was attacked again, and the flash loan attack suffered on the BNB chain lost about $1.3 million in assets. The subsequent flash loan attack on Ethereum caused a loss of about $590,000&amp;hellip;</description></item><item><title>天穹</title><link>https://0xtracer.xyz/incidents/2022-05-17/</link><pubDate>Tue, 17 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-17/</guid><description>There was an abnormality on the Tianqiong Digital Collection platform. The price of its collections on the secondary market skyrocketed thousands of times, and collections with a price of nearly 10 million yuan were s&amp;hellip;</description></item><item><title>FEG</title><link>https://0xtracer.xyz/incidents/2022-05-16-feg/</link><pubDate>Mon, 16 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-16-feg/</guid><description>The multi-chain DeFi protocol FEG was suspected of being attacked, and a total of 143 Ethereum and 32,747 BNB were lost, about $1.3 million.</description></item><item><title>Scream</title><link>https://0xtracer.xyz/incidents/2022-05-16-scream/</link><pubDate>Mon, 16 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-16-scream/</guid><description>Fantom-based DeFi lending protocol Scream caused $35 million in bad debt after failing to adjust the price of two de-pegged USD stablecoins. The two stablecoins are Fantom USD (FUSD) and Dei (DEI). Both stablecoins ar&amp;hellip;</description></item><item><title>CoinGecko&amp;Etherscan&amp;DeFi Pulse</title><link>https://0xtracer.xyz/incidents/2022-05-14-coingecko-and-etherscan-and-defi-pulse/</link><pubDate>Sat, 14 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-14-coingecko-and-etherscan-and-defi-pulse/</guid><description>Popular cryptocurrency websites including Etherscan, CoinGecko, and DeFi Pulse have reported incidents of malicious pop-ups prompting users to connect their MetaMask wallets. CoinGecko founder Bobby Ong said he believ&amp;hellip;</description></item><item><title>Quickswap</title><link>https://0xtracer.xyz/incidents/2022-05-14-quickswap/</link><pubDate>Sat, 14 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-14-quickswap/</guid><description>Decentralized exchange Quickswap has come under attack for a vulnerability in its hosting provider GoDaddy. The hijackers gained access to QuickSwap&amp;rsquo;s DNS through a vulnerability in GoDaddy, where QuickSwap domains we&amp;hellip;</description></item><item><title>SpiritSwap</title><link>https://0xtracer.xyz/incidents/2022-05-14-spiritswap/</link><pubDate>Sat, 14 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-14-spiritswap/</guid><description>SpiritSwap tweeted that the front-end server placed on AWS was compromised by hackers, the website was tampered with parameters, and $18,000 was currently stolen. According to official postmortem analysis, the attacke&amp;hellip;</description></item><item><title>Venus Protocol</title><link>https://0xtracer.xyz/incidents/2022-05-12-venus-protocol/</link><pubDate>Thu, 12 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-12-venus-protocol/</guid><description>Venus Protocol issued a statement saying that Chainlink’s suspension of LUNA price updates after extreme volatility in LUNA prices caused the price of LUNA on the Venus lending market to remain at $0.107, while the ma&amp;hellip;</description></item><item><title>X2Y2</title><link>https://0xtracer.xyz/incidents/2022-05-11-x2y2/</link><pubDate>Wed, 11 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-11-x2y2/</guid><description>Sentinel founder Serpent tweeted that the first search result of the NFT trading platform X2Y2 on the Google search page was a scam website. It used the loopholes in Google ads to make the real website and the scam UR&amp;hellip;</description></item><item><title>Blizz Finance</title><link>https://0xtracer.xyz/incidents/2022-05-10-blizz-finance/</link><pubDate>Tue, 10 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-10-blizz-finance/</guid><description>LUNA price collapse caused oracle manipulation enabling theft</description></item><item><title>OWNLY</title><link>https://0xtracer.xyz/incidents/2022-05-10-ownly/</link><pubDate>Tue, 10 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-10-ownly/</guid><description>The ownlyio project&amp;rsquo;s NFTStaking contract was attacked, with a total of 115 BNB stolen and a loss of about $36,418. The reason for this attack is that the unstake function of the pledge contract of the ownio project d&amp;hellip;</description></item><item><title>Cashera</title><link>https://0xtracer.xyz/incidents/2022-05-09-cashera/</link><pubDate>Mon, 09 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-09-cashera/</guid><description>Cashera is a project that claims to offer a &amp;ldquo;banking revolution&amp;rdquo; through its CSR crypto token. The project does a number of things to try to appear legitimate, including linking to government records showing a company&amp;hellip;</description></item><item><title>Fortress Protocol</title><link>https://0xtracer.xyz/incidents/2022-05-09-fortress-protocol/</link><pubDate>Mon, 09 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-09-fortress-protocol/</guid><description>Fortress Protocol, a lending protocol on BNB Chain, was suspected of being attacked. Token FTS fell by 42% in a short time. Currently, 1,048 Ethereum and 400,000 DAI have been transferred to Tornado.cash.</description></item><item><title>GOAT</title><link>https://0xtracer.xyz/incidents/2022-05-09-goat/</link><pubDate>Mon, 09 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-09-goat/</guid><description>The GOAT project claimed to be &amp;ldquo;the new standard in cryptocurrencies,&amp;rdquo; but one of the project&amp;rsquo;s developers abruptly sold their assets, taking $260,000 with them, and the token price fell to nearly $0.</description></item><item><title>Hunter</title><link>https://0xtracer.xyz/incidents/2022-05-08-hunter/</link><pubDate>Sun, 08 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-08-hunter/</guid><description>The DeFi project Hunter has been rug pull, and currently Telegram, Discord, and the website cannot be opened.</description></item><item><title>Fury of the Fur</title><link>https://0xtracer.xyz/incidents/2022-05-07-fury-of-the-fur/</link><pubDate>Sat, 07 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-07-fury-of-the-fur/</guid><description>The Fury of the Fur NFT project was a collection of 3D models that sort of resembled bears. However, the NFT rollout has not been smooth - out of a total supply of 9,671 NFTs, less than 2,800 NFTs have been minted. Th&amp;hellip;</description></item><item><title>Day of Defeat</title><link>https://0xtracer.xyz/incidents/2022-05-06-day-of-defeat/</link><pubDate>Fri, 06 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-06-day-of-defeat/</guid><description>Day of Defeat has rug pull, value has suddenly dropped by over 96%, and over $1.35 million in assets has been moved from BSC-based projects to external wallets. After the funds ran out, the project claimed they had be&amp;hellip;</description></item><item><title>Mining Capital Coin</title><link>https://0xtracer.xyz/incidents/2022-05-06-mining-capital-coin/</link><pubDate>Fri, 06 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-06-mining-capital-coin/</guid><description>The Justice Department released an indictment on May 5 showing that Mining Capital Coin CEO and founder Luiz Capuci Jr. was charged with orchestrating a $62 million investment fraud. Capuci allegedly misled investors&amp;hellip;</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2022-05-06-opensea/</link><pubDate>Fri, 06 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-06-opensea/</guid><description>Sentinel founder Serpent tweeted that OpenSea&amp;rsquo;s official Discord was attacked. Hackers used bot accounts to post fake links in the channel, and said that &amp;ldquo;OpenSea has reached a cooperation with YouTube. Click the link&amp;hellip;</description></item><item><title>Pragma Money</title><link>https://0xtracer.xyz/incidents/2022-05-06-pragma-money/</link><pubDate>Fri, 06 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-06-pragma-money/</guid><description>DeFi project Pragma Money on Fantom has announced that around $1.5 million in FTM has been drained from their treasury and project wallets. Appears to be done by a team member.</description></item><item><title>MM.finance</title><link>https://0xtracer.xyz/incidents/2022-05-04-mm-finance/</link><pubDate>Wed, 04 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-04-mm-finance/</guid><description>According to the official release, the MM.finance website was hit by a DNS attack, and the attacker managed to inject malicious contract addresses into the front-end code. The attacker exploited the DNS vulnerability&amp;hellip;</description></item><item><title>Rainbow Bridge</title><link>https://0xtracer.xyz/incidents/2022-05-02-rainbow-bridge/</link><pubDate>Mon, 02 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-02-rainbow-bridge/</guid><description>Rainbow Bridge was attacked by forged blocks. However, it was blocked by an automatic watchdog mechanism, depriving the attacker of 2.5 ETH.</description></item><item><title>Solana</title><link>https://0xtracer.xyz/incidents/2022-05-01-solana/</link><pubDate>Sun, 01 May 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-05-01-solana/</guid><description>Solana-based NFT team at Metaplex, a web application and deployment platform, discontinued the program section today, Solana shows the program deployment of its program section, when further stabilized, the Solana tea&amp;hellip;</description></item><item><title>Babylon Finance</title><link>https://0xtracer.xyz/incidents/2022-04-30-babylon-finance/</link><pubDate>Sat, 30 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-30-babylon-finance/</guid><description>In April, attackers exploited a vulnerability to steal $80 million from Rari Capital, and the asset management project Babylon Finance, Rari&amp;rsquo;s main lending pool, lost $3.4 million as a result. On Aug. 31, Babylon Fina&amp;hellip;</description></item><item><title>Rari Capital / Fuse</title><link>https://0xtracer.xyz/incidents/2022-04-30-rari-capital-fuse/</link><pubDate>Sat, 30 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-30-rari-capital-fuse/</guid><description>Cross-protocol reentrancy between Fuse and AAVE via callbacks</description></item><item><title>Saddle Finance</title><link>https://0xtracer.xyz/incidents/2022-04-30-saddle-finance/</link><pubDate>Sat, 30 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-30-saddle-finance/</guid><description>DeFi protocol Saddle Finance was attacked, causing the protocol to lose more than $10 million.</description></item><item><title>Deus Finance</title><link>https://0xtracer.xyz/incidents/2022-04-28-deus-finance/</link><pubDate>Thu, 28 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-28-deus-finance/</guid><description>DEI stablecoin minting oracle exploited via Solidly flash loan</description></item><item><title>BAYC</title><link>https://0xtracer.xyz/incidents/2022-04-25-bayc/</link><pubDate>Mon, 25 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-25-bayc/</guid><description>The official Instagram of the NFT project Bored Ape Yacht Club (BAYC) was hacked, and the attackers have stolen 91 NFTs including 4 BAYC, 7 MAYC, 3 BAKC, 1 CloneX, etc.</description></item><item><title>Wiener DOGE</title><link>https://0xtracer.xyz/incidents/2022-04-24-wiener-doge/</link><pubDate>Sun, 24 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-24-wiener-doge/</guid><description>The Wiener DOGE project was exploited maliciously, causing $30,000 in damages. Attackers exploited the inconsistency between WDODGE&amp;rsquo;s charging mechanism and swap pools to launch the attack. The root cause of the incid&amp;hellip;</description></item><item><title>Akutars</title><link>https://0xtracer.xyz/incidents/2022-04-23-akutars/</link><pubDate>Sat, 23 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-23-akutars/</guid><description>The Akutars (@AkuDreams) project auction contract was permanently unable to withdraw 11,539.5 ETH due to multiple code flaws. According to SlowMist analysis, even if the problem of users&amp;rsquo; inability to refund is solved&amp;hellip;</description></item><item><title>Terra</title><link>https://0xtracer.xyz/incidents/2022-04-21-terra/</link><pubDate>Thu, 21 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-21-terra/</guid><description>The SlowMist security team found that funds from about 52 addresses were maliciously transferred to terra1fz57nt6t3nnxel6q77wsmxxdesn7rgy0h27x30 from April 12 to April 21, with a total loss of about $4.31 million. The&amp;hellip;</description></item><item><title>ZEED</title><link>https://0xtracer.xyz/incidents/2022-04-21-zeed/</link><pubDate>Thu, 21 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-21-zeed/</guid><description>The DeFi ecological protocol ZEED was attacked and lost about $1 million. At present, the attacker&amp;rsquo;s gains are all in the attack contract.</description></item><item><title>MaxAPY Finance</title><link>https://0xtracer.xyz/incidents/2022-04-20-maxapy-finance/</link><pubDate>Wed, 20 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-20-maxapy-finance/</guid><description>A Rug Pull occurred in MaxAPY Finance, an automatic pledge protocol on BNB Chain, and its official Twitter account and Telegram group have been deleted. MaxAPY contract owners have transferred 1,042 BNB.</description></item><item><title>Beanstalk</title><link>https://0xtracer.xyz/incidents/2022-04-17-beanstalk/</link><pubDate>Sun, 17 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-17-beanstalk/</guid><description>Flash loan used to gain governance majority and drain funds</description></item><item><title>Ugly People</title><link>https://0xtracer.xyz/incidents/2022-04-17-ugly-people/</link><pubDate>Sun, 17 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-17-ugly-people/</guid><description>The Discord of NFT project Ugly People has been hacked, and attackers are spreading fake mint links.</description></item><item><title>FaceDAO</title><link>https://0xtracer.xyz/incidents/2022-04-16-facedao/</link><pubDate>Sat, 16 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-16-facedao/</guid><description>According to official sources, a large amount of FACE tokens were dumped on-chain, and the investigation turned out that one of the FACE tokens held by the team was transferred and sold by an unauthorized account.</description></item><item><title>Metaconz</title><link>https://0xtracer.xyz/incidents/2022-04-16-metaconz/</link><pubDate>Sat, 16 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-16-metaconz/</guid><description>The developer of Klaytn-based NFT project Metaconz tweeted that a malicious bot was installed on the administrator account of Metaconz’s Discord overseas team on Saturday, causing 79 users to lose 11.9 ETH (about $36,&amp;hellip;</description></item><item><title>Rikkei Finance</title><link>https://0xtracer.xyz/incidents/2022-04-15-rikkei-finance/</link><pubDate>Fri, 15 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-15-rikkei-finance/</guid><description>Metaverse DeFi protocol Rikkei Finance was attacked because the attacker changed the oracle machine to a malicious contract. Rikkei Finance said users affected by the exploit will be fully compensated, and the team sa&amp;hellip;</description></item><item><title>Elephant Money</title><link>https://0xtracer.xyz/incidents/2022-04-13-elephant-money/</link><pubDate>Wed, 13 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-13-elephant-money/</guid><description>Elephant Money was attacked, resulting in the loss of 27,416.46 BNB. The attacker first used WBNB to buy a large amount of ELEPHANT, and then used BUSD to mint the TRUNK stablecoin. During the minting process, the Ele&amp;hellip;</description></item><item><title>CF</title><link>https://0xtracer.xyz/incidents/2022-04-11-cf/</link><pubDate>Mon, 11 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-11-cf/</guid><description>There is a fundamental vulnerability in the CF token contract that allows anyone to transfer someone else&amp;rsquo;s CF balance. The losses so far are around $1.9 million, while the CF/USDT trading pair on pancakeswap has been&amp;hellip;</description></item><item><title>Marvin Inu</title><link>https://0xtracer.xyz/incidents/2022-04-11-marvin-inu/</link><pubDate>Mon, 11 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-11-marvin-inu/</guid><description>According to official news, Marvin Inu’s cross-chain bridge was hacked, and tokens worth 110 ETH were stolen and sold, causing a sharp drop in price. The project party has closed the cross-chain bridge and fixed the l&amp;hellip;</description></item><item><title>UGC</title><link>https://0xtracer.xyz/incidents/2022-04-10-ugc/</link><pubDate>Sun, 10 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-10-ugc/</guid><description>The Education Grants Council (UGC) of India was hacked, the hackers used the Twitter account to post a fake Azuki NFT airdrop link and changed the profile to the Azuki NFT co-creator, replacing the avatar with an Azuk&amp;hellip;</description></item><item><title>Starstream Finance &amp; Agora</title><link>https://0xtracer.xyz/incidents/2022-04-08-starstream-finance-and-agora/</link><pubDate>Fri, 08 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-08-starstream-finance-and-agora/</guid><description>Starstream Finance and Agora DeFi projects under attack. Attackers exploited a vulnerability in Starstream to siphon tokens from the protocol, then used the tokens as collateral to obtain large loans from Agora. The S&amp;hellip;</description></item><item><title>Vires Finance</title><link>https://0xtracer.xyz/incidents/2022-04-05-vires-finance/</link><pubDate>Tue, 05 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-05-vires-finance/</guid><description>In 2022, the DeFi protocol Vires Finance on the Waves blockchain suffered losses exceeding $530 million, with its founder Sasha Ivanov facing allegations of fraud. Research suggests that his wallet may have been linke&amp;hellip;</description></item><item><title>Inverse Finance</title><link>https://0xtracer.xyz/incidents/2022-04-02-inverse-finance/</link><pubDate>Sat, 02 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-02-inverse-finance/</guid><description>Keep3r oracle manipulated to borrow ETH/WBTC against inflated INV</description></item><item><title>Multiple NFT projects</title><link>https://0xtracer.xyz/incidents/2022-04-01-multiple-nft-projects/</link><pubDate>Fri, 01 Apr 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-04-01-multiple-nft-projects/</guid><description>According to the official news of each project, the Discord of NFT projects whose servers are currently under attack include BAYC, Doodles, Nyoki, Shamanz, Zooverse, Dreadfuls, Freaky Labs, and Kaijukingz. In addition&amp;hellip;</description></item><item><title>Ola Finance</title><link>https://0xtracer.xyz/incidents/2022-03-31-ola-finance/</link><pubDate>Thu, 31 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-31-ola-finance/</guid><description>Ola Finance on the Fuse chain published a blog post on the hacking incident, stating that the attack lost approximately $4.67 million, including 216,964.18 USDC, 507,216.68 BUSD, 200,000 fUSD, 550.45 WETH, 26.25 WBTC,&amp;hellip;</description></item><item><title>BasketDAOOrg</title><link>https://0xtracer.xyz/incidents/2022-03-30-basketdaoorg/</link><pubDate>Wed, 30 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-30-basketdaoorg/</guid><description>According to BasketDAOOrg&amp;rsquo;s official Twitter, there is a vulnerability in BMIZapper, which caused users to lose about 1.2 million US dollars.</description></item><item><title>Jet Protocol</title><link>https://0xtracer.xyz/incidents/2022-03-30-jet-protocol/</link><pubDate>Wed, 30 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-30-jet-protocol/</guid><description>Castle Finance developer Charlie You discovered a critical vulnerability in Solana&amp;rsquo;s ecological lending protocol, Jet Protocol, that could allow attackers to withdraw tokens from arbitrary accounts. It is reported tha&amp;hellip;</description></item><item><title>BNB DEFI</title><link>https://0xtracer.xyz/incidents/2022-03-29-bnb-defi/</link><pubDate>Tue, 29 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-29-bnb-defi/</guid><description>A Rug Pull occurred in BNB DEFI, and the DEFI token fell by 68% in a short time. At present, the project has closed the community, and DEFI tokens have been exchanged for about 255 BNB.</description></item><item><title>Ronin Network</title><link>https://0xtracer.xyz/incidents/2022-03-29-ronin-network/</link><pubDate>Tue, 29 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-29-ronin-network/</guid><description>Axie Infinity sidechain Ronin Network issued a community alert today. Ronin Network experienced a security breach. Ronin bridge 17.36w ETH and 25.5M USDC were stolen, with a loss of more than 610 million US dollars. A&amp;hellip;</description></item><item><title>BuccaneerFi</title><link>https://0xtracer.xyz/incidents/2022-03-28-buccaneerfi/</link><pubDate>Mon, 28 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-28-buccaneerfi/</guid><description>The project BuccaneerFi on the BNB Chain has a Rug Pull. At present, the project social media account and community have been deleted, and about 841 BNB have been transferred to Tornado Cash.</description></item><item><title>Cryptovoxel</title><link>https://0xtracer.xyz/incidents/2022-03-28-cryptovoxel/</link><pubDate>Mon, 28 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-28-cryptovoxel/</guid><description>According to reports, someone pretended to be a Cryptovoxels official to conduct a phishing attack, induced users to authorize, stole multiple NFTs (including Cryptovoxels Parcel Token, Art Blocks: BLOCKS Token, Mutan&amp;hellip;</description></item><item><title>Revest Finance</title><link>https://0xtracer.xyz/incidents/2022-03-27-revest-finance/</link><pubDate>Sun, 27 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-27-revest-finance/</guid><description>DeFi protocol Revest Finance has been hacked. Hackers stole nearly 7.7 million ECO, 579 LYXe, nearly 715 million BLOCKS, and over 350,000 RENA. According to SlowMist analysis, this attack is because the handleMultiple&amp;hellip;</description></item><item><title>InuSaitama</title><link>https://0xtracer.xyz/incidents/2022-03-26-inusaitama/</link><pubDate>Sat, 26 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-26-inusaitama/</guid><description>InuSaitama is suspected to have suffered an arbitrage attack. The attacker (0xAd0C834315Abfa7A800bBBB5d776A0B07b672614) Saitamask (0x00480b0abBd14F2d61Aa2E801d483132e917C18B) exchanged almost 10 times the value of SAI&amp;hellip;</description></item><item><title>Maison Ghost</title><link>https://0xtracer.xyz/incidents/2022-03-25-maison-ghost/</link><pubDate>Fri, 25 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-25-maison-ghost/</guid><description>Maison Ghost’s Discord was hacked, the hacker posted a fake minting link, and within minutes about 300 NFTs were stolen, including the Sandbox and 3landers NFTs, which were then sold for 128 ETH and eventually sent to&amp;hellip;</description></item><item><title>Cashio</title><link>https://0xtracer.xyz/incidents/2022-03-23-cashio/</link><pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-23-cashio/</guid><description>The stablecoin project Cashio on Solana has been hacked. According to the preliminary analysis of the SlowMist security team, hackers illegally issued 2 billion CASH tokens by bypassing an unverified account, and conv&amp;hellip;</description></item><item><title>MekaVerse</title><link>https://0xtracer.xyz/incidents/2022-03-23-mekaverse/</link><pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-23-mekaverse/</guid><description>NFT project MekaVerse tweeted that the official Discord was hacked. In addition, according to other users in the community, the wallets of hundreds of thousands of bots are suspected to have been stolen, and it seems&amp;hellip;</description></item><item><title>Ronin Bridge</title><link>https://0xtracer.xyz/hacks/ronin-bridge/</link><pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/hacks/ronin-bridge/</guid><description>&lt;p>The Ronin Bridge (Axie Infinity) was exploited for ~$624M after attackers compromised 5 of 9 validator private keys. The attacker used the compromised keys to forge fake withdrawals from the bridge contract.&lt;/p></description></item><item><title>Ronin Bridge</title><link>https://0xtracer.xyz/incidents/2022-03-23-ronin-bridge/</link><pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-23-ronin-bridge/</guid><description>5 of 9 validator keys compromised, used to forge withdrawals</description></item><item><title>VEVE</title><link>https://0xtracer.xyz/incidents/2022-03-23-veve/</link><pubDate>Wed, 23 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-23-veve/</guid><description>The NFT project VEVE officially tweeted that the system was exploited, resulting in a large number of gems being illegally obtained.</description></item><item><title>Arthur</title><link>https://0xtracer.xyz/incidents/2022-03-22-arthur/</link><pubDate>Tue, 22 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-22-arthur/</guid><description>Twitter user cr0ss.eth said Defiance Capital founder Arthur&amp;rsquo;s hot wallet was suspected to have been stolen. OpenSea data shows that in Arthur&amp;rsquo;s wallet address 0x4C53c32980ccE49aaA4bCc53Eef3f143Bc27E0aF, 60 NFTs includ&amp;hellip;</description></item><item><title>REALSWAK</title><link>https://0xtracer.xyz/incidents/2022-03-22-realswak/</link><pubDate>Tue, 22 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-22-realswak/</guid><description>The NFT project REALSWAK has a Rug Pull, and its official social account (@REALSWAK) has been cancelled. Scammers have transferred 1,300 BNB to the TornadoCash mixer.</description></item><item><title>OneRing</title><link>https://0xtracer.xyz/incidents/2022-03-21-onering/</link><pubDate>Mon, 21 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-21-onering/</guid><description>Fantom ecological Stablecoin revenue optimizer OneRing issued a document saying that hackers stole 1,454,672.244369 USDC through flash loan attacks, and the contract has been configured to self-destruct in a specific&amp;hellip;</description></item><item><title>Hubspot</title><link>https://0xtracer.xyz/incidents/2022-03-20-hubspot/</link><pubDate>Sun, 20 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-20-hubspot/</guid><description>Crypto lender BlockFi has confirmed a data breach at Hubspot, one of its third-party vendors, Cointelegragh reported. Hubspot stores BlockFi&amp;rsquo;s user data, including names, email addresses, and phone numbers. According&amp;hellip;</description></item><item><title>Li.finance</title><link>https://0xtracer.xyz/incidents/2022-03-20-li-finance/</link><pubDate>Sun, 20 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-20-li-finance/</guid><description>According to official reports, attackers exploited Li.finance’s smart contracts and managed to steal around $600,000 (currently worth $587,500 or 205 ETH) from 29 wallets. Attackers took various tokens from users’ wal&amp;hellip;</description></item><item><title>Umbrella Network</title><link>https://0xtracer.xyz/incidents/2022-03-20-umbrella-network/</link><pubDate>Sun, 20 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-20-umbrella-network/</guid><description>DeFi oracle Umbrella Network’s Ethereum and BNB Chain (formerly BSC) reward pools were hacked, resulting in the hackers earning around $700,000. The hacker was able to succeed because of an unchecked vulnerability in&amp;hellip;</description></item><item><title>APE</title><link>https://0xtracer.xyz/incidents/2022-03-17-ape/</link><pubDate>Thu, 17 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-17-ape/</guid><description>According to a report by Twitter user Will Sheehan, the arbitrage bot took out more than 6w APE Coins (worth $8 each) through flash loans. After analysis, it was found that this was related to a loophole in the airdro&amp;hellip;</description></item><item><title>Agave Finance</title><link>https://0xtracer.xyz/incidents/2022-03-15-agave-finance/</link><pubDate>Tue, 15 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-15-agave-finance/</guid><description>ERC-777 token callback reentrancy attack on Agave and Hundred Finance</description></item><item><title>Deus Finance</title><link>https://0xtracer.xyz/incidents/2022-03-15-deus-finance/</link><pubDate>Tue, 15 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-15-deus-finance/</guid><description>DeFi protocol Deus Finance was attacked by a flash loan, and hackers manipulated the price of the oracle machine and stole about $3 million, including 200,000 DAI and 1101.8 ETH through Tornado mixing.</description></item><item><title>Hundred Finance (Gnosis)</title><link>https://0xtracer.xyz/incidents/2022-03-15-hundred-finance-gnosis/</link><pubDate>Tue, 15 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-15-hundred-finance-gnosis/</guid><description>ERC-677 token callback reentrancy, attacked same day as Agave</description></item><item><title>NFTflow</title><link>https://0xtracer.xyz/incidents/2022-03-14-nftflow/</link><pubDate>Mon, 14 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-14-nftflow/</guid><description>Several NFT players posted on social media that a project called &amp;ldquo;NFTflow&amp;rdquo; had a Rug Pull, ran away without completing the pre-sale, and transferred the 92 ETHs from the sale to the Tornado mixer. According to the off&amp;hellip;</description></item><item><title>PulseDAO Finance</title><link>https://0xtracer.xyz/incidents/2022-03-14-pulsedao-finance/</link><pubDate>Mon, 14 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-14-pulsedao-finance/</guid><description>According to RugDoc on Twitter, PulseDAO Finance has rugpulled. Social and website are closed. 4342 FTM was removed by contract developer.</description></item><item><title>Paraluni</title><link>https://0xtracer.xyz/incidents/2022-03-13-paraluni/</link><pubDate>Sun, 13 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-13-paraluni/</guid><description>The metaverse financial project Paraluni on the BSC chain was hacked, and the hackers made more than $1.7 million in profits. The problem lies in the depositByAddLiquidity method of the MasterCheif contract of the pro&amp;hellip;</description></item><item><title>ActiveCampaign（AC）</title><link>https://0xtracer.xyz/incidents/2022-03-10-activecampaign-ac/</link><pubDate>Thu, 10 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-10-activecampaign-ac/</guid><description>ActiveCampaign (AC), an external email marketing provider used by Unchained, was hacked last week, according to Joe Kelly, CEO of Bitcoin financial services firm Unchained Capital. Information shared with AC, includin&amp;hellip;</description></item><item><title>Fantasm Finance</title><link>https://0xtracer.xyz/incidents/2022-03-10-fantasm-finance/</link><pubDate>Thu, 10 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-10-fantasm-finance/</guid><description>Fantom’s on-chain synthetic asset protocol, Fantasm Finance, posted on social media that its FTM collateral reserves had been exploited, and called on users to exchange their XFTM immediately. After exploiting the vul&amp;hellip;</description></item><item><title>Pirate X</title><link>https://0xtracer.xyz/incidents/2022-03-09-pirate-x/</link><pubDate>Wed, 09 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-09-pirate-x/</guid><description>The pledge contract (0x6912B19401913F1bd5020b3f59EE986c5792DA54) of the NFT adventure game Pirate X was attacked. When users deposit their PXP tokens into this contract, their tokens will be transferred to an EOA acco&amp;hellip;</description></item><item><title>TreasureDAO</title><link>https://0xtracer.xyz/incidents/2022-03-03-treasuredao/</link><pubDate>Thu, 03 Mar 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-03-03-treasuredao/</guid><description>The Arbitrum-based TreasureDAO NFT trading market was exposed and discovered a vulnerability. According to SlowMist analysis, the core of this vulnerability lies in the lack of judgment that the incoming _quantity par&amp;hellip;</description></item><item><title>Flurry Finance</title><link>https://0xtracer.xyz/incidents/2022-02-23-flurry-finance/</link><pubDate>Wed, 23 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-23-flurry-finance/</guid><description>Flurry Finance’s Vault contract was hit by a flash loan attack, resulting in the theft of approximately $293,000 worth of assets in the Vault contract.</description></item><item><title>MOX</title><link>https://0xtracer.xyz/incidents/2022-02-20-mox/</link><pubDate>Sun, 20 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-20-mox/</guid><description>MOX was hacked because transferFrom Function did not check the authorization limit.</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2022-02-20-opensea/</link><pubDate>Sun, 20 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-20-opensea/</guid><description>According to OpenSea&amp;rsquo;s official tweet, hackers sent phishing emails to all users&amp;rsquo; mailboxes at the same time as the OpenSea contract was upgraded. Many users mistakenly thought it was an official email and authorized&amp;hellip;</description></item><item><title>Gold Mine Finance</title><link>https://0xtracer.xyz/incidents/2022-02-19-gold-mine-finance/</link><pubDate>Sat, 19 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-19-gold-mine-finance/</guid><description>Rugdoc.io tweeted that the Fantom ecological project Gold Mine Finance has rug pull.</description></item><item><title>RigoBlock</title><link>https://0xtracer.xyz/incidents/2022-02-18-rigoblock/</link><pubDate>Fri, 18 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-18-rigoblock/</guid><description>RigoBlock has been hacked. All tokens in Dragos except ETH and USDT are at risk due to protocol vulnerabilities being exploited. The hacker, Whitehat, has returned funds to the affected RigoBlock pool, leaving only 10&amp;hellip;</description></item><item><title>TopGoal</title><link>https://0xtracer.xyz/incidents/2022-02-17-topgoal/</link><pubDate>Thu, 17 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-17-topgoal/</guid><description>Hot wallets operated by TopGoal were attacked and compromised. In this hack, only the hot wallet operated by TopGoal, which manages the distribution of TopPrize rewards, was affected. All user assets including NFTs an&amp;hellip;</description></item><item><title>Build Finance</title><link>https://0xtracer.xyz/incidents/2022-02-15-build-finance/</link><pubDate>Tue, 15 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-15-build-finance/</guid><description>The venture capital DAO organization Build Finance tweeted that the project suffered a malicious governance takeover. The malicious actors successfully controlled the Build token contract by getting enough votes, mint&amp;hellip;</description></item><item><title>Titano Finance</title><link>https://0xtracer.xyz/incidents/2022-02-14-titano-finance/</link><pubDate>Mon, 14 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-14-titano-finance/</guid><description>On February 14, the Titano Finance project on the BSC chain was attacked. The attackers made a total of 4,828.7 BNB, or about $190w. According to the official Titano Finance investigation, “The problem arose when we t&amp;hellip;</description></item><item><title>Gemini</title><link>https://0xtracer.xyz/incidents/2022-02-12-gemini/</link><pubDate>Sat, 12 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-12-gemini/</guid><description>IRA Financial Trust, South Dakota’s self-directed retirement account provider, has filed a lawsuit against crypto trading platform Gemini Trust Company (Gemini), alleging huge losses to the IRA as a result of Gemini’s&amp;hellip;</description></item><item><title>FutureSwap</title><link>https://0xtracer.xyz/incidents/2022-02-11-futureswap/</link><pubDate>Fri, 11 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-11-futureswap/</guid><description>Decentralized derivatives trading platform FutureSwap tweeted that an account with around 300,000 FST reward reserves (0.3% of supply) was compromised yesterday. The credentials for this account were compromised by hu&amp;hellip;</description></item><item><title>BabyMuskCoin</title><link>https://0xtracer.xyz/incidents/2022-02-10-babymuskcoin/</link><pubDate>Thu, 10 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-10-babymuskcoin/</guid><description>BabyMuskCoin plummeted 99%, 1,571 BNB (~$660,000) was dumped, and funds were moved to Tornado. The project team claimed to have been scammed through Telegram, but Twitter and the website were down, suspected of Rugpull.</description></item><item><title>Dego Finance</title><link>https://0xtracer.xyz/incidents/2022-02-10-dego-finance/</link><pubDate>Thu, 10 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-10-dego-finance/</guid><description>Dego Finance, an NFT and DeFi aggregator, announced that it was hacked, and now the DEGO liquidity on UniSwap and PancakeSwap has been exhausted.</description></item><item><title>PayBito</title><link>https://0xtracer.xyz/incidents/2022-02-08-paybito/</link><pubDate>Tue, 08 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-08-paybito/</guid><description>On February 8, the LockBit ransomware group claimed to have stolen substantial customer data from cryptocurrency exchange PayBito. PayBito is a cryptocurrency exchange operated by HashCash, a global blockchain, and IT&amp;hellip;</description></item><item><title>Superfluid</title><link>https://0xtracer.xyz/incidents/2022-02-08-superfluid/</link><pubDate>Tue, 08 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-08-superfluid/</guid><description>The QI Vesting contract on the streaming digital asset protocol Superfluid has been exploited by an attacker by passing in incorrect call data. This vulnerability allows the attacker to transfer funds from Superfluid&amp;hellip;</description></item><item><title>Meter.io</title><link>https://0xtracer.xyz/incidents/2022-02-06-meter-io/</link><pubDate>Sun, 06 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-06-meter-io/</guid><description>Meter.io&amp;rsquo;s cross-chain bridge was hacked, resulting in a loss of around $4.3 million ( 1391.24945169 ETH and 2.74068396 BTC). The hacker was able to exploit a vulnerability in the deposit function, which allowed them&amp;hellip;</description></item><item><title>KLAYswap</title><link>https://0xtracer.xyz/incidents/2022-02-03-klayswap/</link><pubDate>Thu, 03 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-03-klayswap/</guid><description>A South Korean DeFi project, KLAYswap stated it was hacked and lost over 2.2 billion won, or about $1.83 million, in the incident. The hacker modified the third-party JavaScript link on the front end of KLAYswap, caus&amp;hellip;</description></item><item><title>The Heart Project</title><link>https://0xtracer.xyz/incidents/2022-02-02-the-heart-project/</link><pubDate>Wed, 02 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-02-the-heart-project/</guid><description>The official Discord server of the NFT project The Heart Project was hacked. Scammers deleted most of The Heart Project&amp;rsquo;s Discord channels and posted scam links. According to The Heart Project, some users clicked on f&amp;hellip;</description></item><item><title>Wormhole</title><link>https://0xtracer.xyz/incidents/2022-02-02-wormhole/</link><pubDate>Wed, 02 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-02-wormhole/</guid><description>Guardian signature verification bypass via deprecated function</description></item><item><title>Bitbns</title><link>https://0xtracer.xyz/incidents/2022-02-01-bitbns/</link><pubDate>Tue, 01 Feb 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-02-01-bitbns/</guid><description>On March 1, ZachXBT, an on-chain data analyst, tweeted: &amp;ldquo;Indian cryptocurrency exchange Bitbns concealed a $7.5 million hack from its users on February 1, 2022, and informed users that it was system maintenance.&amp;rdquo; Acco&amp;hellip;</description></item><item><title>Qubit Finance</title><link>https://0xtracer.xyz/incidents/2022-01-28-qubit-finance/</link><pubDate>Fri, 28 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-28-qubit-finance/</guid><description>deposit() callable with zero ETH due to missing validation check</description></item><item><title>Wegrocoin</title><link>https://0xtracer.xyz/incidents/2022-01-27-wegrocoin/</link><pubDate>Thu, 27 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-27-wegrocoin/</guid><description>The project Wegrocoin (WEGRO) on BSC suffered a Rug Pull and lost more than 1000 BNB.</description></item><item><title>InfinityToken</title><link>https://0xtracer.xyz/incidents/2022-01-26-infinitytoken/</link><pubDate>Wed, 26 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-26-infinitytoken/</guid><description>Rug Pull occurred in the BSC ecological InfinityToken (INF), which lost more than 1390 WBNB.</description></item><item><title>Mercenary</title><link>https://0xtracer.xyz/incidents/2022-01-26-mercenary/</link><pubDate>Wed, 26 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-26-mercenary/</guid><description>The social media accounts of NFT project Mercenary have been deleted. Deployers spent over $760,000.</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2022-01-25-opensea/</link><pubDate>Tue, 25 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-25-opensea/</guid><description>An OpenSea user exploited a vulnerability in the non-fungible token (NFT) market to steal hundreds of ether (ETH) from the owners of well-known collectibles such as the Bored Ape Yacht Club (BAYC) and Cyber​​ Kongs of&amp;hellip;</description></item><item><title>Blockverse</title><link>https://0xtracer.xyz/incidents/2022-01-24-blockverse/</link><pubDate>Mon, 24 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-24-blockverse/</guid><description>Blockverse is a Minecraft-based NFT game. Through OpenSea, investors can buy Blockverse characters and a cryptocurrency called $Diamond. Unfortunately, investors withdrew all real money invested in Blockverse, shuttin&amp;hellip;</description></item><item><title>SolFire Finance</title><link>https://0xtracer.xyz/incidents/2022-01-23-solfire-finance/</link><pubDate>Sun, 23 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-23-solfire-finance/</guid><description>The SolFire Finance project owner stole all investor funds and moved them to the ETH chain via a cross-chain bridge. The project&amp;rsquo;s GitHub account and Twitter account have been deleted and the site is no longer accessi&amp;hellip;</description></item><item><title>Kingfund Finance</title><link>https://0xtracer.xyz/incidents/2022-01-20-kingfund-finance/</link><pubDate>Thu, 20 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-20-kingfund-finance/</guid><description>Kingfund Finance had a Rug Pull and lost over 300 WBNB. Upon inquiry, the official Twitter of the project has been cancelled.</description></item><item><title>MetaMask</title><link>https://0xtracer.xyz/incidents/2022-01-20-metamask/</link><pubDate>Thu, 20 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-20-metamask/</guid><description>@alxlpsc disclosed on medium that MetaMask has serious privacy leaks. The vulnerability mainly uses MetaMask to automatically load NFT image URLs. Basic attack idea: the attacker can set the URI of the NFT to a server&amp;hellip;</description></item><item><title>AFKSystem</title><link>https://0xtracer.xyz/incidents/2022-01-19-afksystem/</link><pubDate>Wed, 19 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-19-afksystem/</guid><description>According to Rugdoc, AFKSystem rug all of their vaults for a combined profit of around $12 million. Although AFKSystem has severely cut their governance authority. But they still retain an important privilege - changi&amp;hellip;</description></item><item><title>Crosswise</title><link>https://0xtracer.xyz/incidents/2022-01-18-crosswise/</link><pubDate>Tue, 18 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-18-crosswise/</guid><description>Decentralized trading platform Crosswise was attacked in nearly an hour, losing about $879,000. The hacker exploited a publicly exposed privileged function, which was then used to set trustedForwarder and further hija&amp;hellip;</description></item><item><title>Crypto.com</title><link>https://0xtracer.xyz/incidents/2022-01-18-crypto-com/</link><pubDate>Tue, 18 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-18-crypto-com/</guid><description>According to the Crypto.com investigation report, “On January 17, 2022, Crypto.com learned that a small number of users had made unauthorized withdrawals of cryptocurrencies on their accounts. Crypto.com immediately s&amp;hellip;</description></item><item><title>Multichain</title><link>https://0xtracer.xyz/incidents/2022-01-18-multichain/</link><pubDate>Tue, 18 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-18-multichain/</guid><description>The cross-chain bridge Multichain said that an important vulnerability affecting six tokens of WETH, PERI, OMT, WBNB, MATIC, and AVAX was officially discovered. Now the vulnerability has been successfully repaired, an&amp;hellip;</description></item><item><title>Crypto Burger</title><link>https://0xtracer.xyz/incidents/2022-01-17-crypto-burger/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-17-crypto-burger/</guid><description>There is a vulnerability in the Crypto Burger project, an NFT project on the BSC chain. &amp;ldquo;The attacker discovered a vulnerability related to the $BURG token contract, which managed to burn most of the tokens in the liq&amp;hellip;</description></item><item><title>wxBTRFLY</title><link>https://0xtracer.xyz/incidents/2022-01-16-wxbtrfly/</link><pubDate>Sun, 16 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-16-wxbtrfly/</guid><description>White hat hackers at @immunefi discovered a critical vulnerability in the wxBTRFLY Token contract. The transferFrom function in the contract did not update the recipient&amp;rsquo;s authorization correctly, and would incorrectl&amp;hellip;</description></item><item><title>CityDAO</title><link>https://0xtracer.xyz/incidents/2022-01-15-citydao/</link><pubDate>Sat, 15 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-15-citydao/</guid><description>CityDAO, an Ethereum-based community blockchain city project, has posted that the CityDAO Discord administrator account has been hacked. 29.67 ETH ($95,000) funds were stolen by hackers using stolen admin accounts to&amp;hellip;</description></item><item><title>Float Protocol</title><link>https://0xtracer.xyz/incidents/2022-01-15-float-protocol/</link><pubDate>Sat, 15 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-15-float-protocol/</guid><description>The attackers withdrew approximately 350 ETH (equivalent to $1.1 million) from Float Protocol’s Rari Capital pool. The reason is that Uniswap V3 FLOAT/USDC oracles lack liquidity, which allows attackers to manipulate&amp;hellip;</description></item><item><title>Frosties</title><link>https://0xtracer.xyz/incidents/2022-01-13-frosties/</link><pubDate>Thu, 13 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-13-frosties/</guid><description>The creator of the NFT project Frosties absconded with the money, causing investors to lose more than $1 million. According to available information, there are 8,888 NFTs in the series with a floor price of 0.04 ETH,&amp;hellip;</description></item><item><title>Multiple IDO Projects</title><link>https://0xtracer.xyz/incidents/2022-01-12-multiple-ido-projects/</link><pubDate>Wed, 12 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-12-multiple-ido-projects/</guid><description>7 IDO projects on BSC are suspected to be running, namely $GOTEM (gotEM), $ONEP (HarmonyPad), $HBARP (HbarPad), $MPLAY (MetaPlay), $ELIT (Electrinity) and $PEE (MicroPee) $QDrop (QuizDrop), swept away more than 5,744&amp;hellip;</description></item><item><title>LooksRare</title><link>https://0xtracer.xyz/incidents/2022-01-11-looksrare/</link><pubDate>Tue, 11 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-11-looksrare/</guid><description>NFT marketplace LooksRare suffered a DDoS attack hours after its launch, resulting in a brief offline. Some users reported that they could not connect their wallets and list their NFTs. The LooksRare team quickly rest&amp;hellip;</description></item><item><title>Lympo</title><link>https://0xtracer.xyz/incidents/2022-01-10-lympo/</link><pubDate>Mon, 10 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-10-lympo/</guid><description>Sports NFT platform Lympo suffered a hot wallet security breach, losing 165.2 million LMT tokens worth $18.7 million in the hack. Ten different project wallets were compromised in the attack. Quotes show that the LMT&amp;hellip;</description></item><item><title>Arbitrum One</title><link>https://0xtracer.xyz/incidents/2022-01-09-arbitrum-one/</link><pubDate>Sun, 09 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-09-arbitrum-one/</guid><description>According to the block explorer, the last block of the Arbitrum One network was generated at 18:29 Beijing time, and no new blocks and new transactions have been generated for more than 2 hours. At the same time, the&amp;hellip;</description></item><item><title>LCX</title><link>https://0xtracer.xyz/incidents/2022-01-09-lcx/</link><pubDate>Sun, 09 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-09-lcx/</guid><description>The LCX exchange tweeted that LCX&amp;rsquo;s technical team detected an unauthorized access on the LCX platform, nearly $8 million in encrypted assets were stolen, and about 60% were frozen.</description></item><item><title>DaoMetaland</title><link>https://0xtracer.xyz/incidents/2022-01-07-daometaland/</link><pubDate>Fri, 07 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-07-daometaland/</guid><description>Rug Pull occurred in the DaoMetaland project on BSC, and the current loss exceeds 640 BNB. DaoMetaland&amp;rsquo;s official Twitter has been deleted.</description></item><item><title>StoboxCompany</title><link>https://0xtracer.xyz/incidents/2022-01-07-stoboxcompany/</link><pubDate>Fri, 07 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-07-stoboxcompany/</guid><description>The digital asset service provider StoboxCompany was attacked by hackers, and its official statement that the private key had been leaked, affected by this, the token fell by 96.93%. StoboxCompany officially stated th&amp;hellip;</description></item><item><title>Bored Bunny</title><link>https://0xtracer.xyz/incidents/2022-01-06-bored-bunny/</link><pubDate>Thu, 06 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-06-bored-bunny/</guid><description>NFT project Bored Bunny is suspected of being a Rug Pull project. Some netizens said that 2,000 ETH raised have been transferred out, and some of them have been transferred to Binan. In addition, this address had simi&amp;hellip;</description></item><item><title>Arbix Finance</title><link>https://0xtracer.xyz/incidents/2022-01-04-arbix-finance/</link><pubDate>Tue, 04 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-04-arbix-finance/</guid><description>Arbix Finance ran away, taking away more than 10 million US dollars. Arbix Finance bills itself as an arbitrage project on BSC, where users can deposit funds in a single asset vault in order to &amp;ldquo;get the best return wi&amp;hellip;</description></item><item><title>Solana</title><link>https://0xtracer.xyz/incidents/2022-01-04-solana/</link><pubDate>Tue, 04 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-04-solana/</guid><description>Solana was down for 4 hours on January 4th, however, Solana.Status showed no problems with the network. The Solana blockchain suffered its third incident in just a few months, resulting in network congestion and faile&amp;hellip;</description></item><item><title>Tinyman Pools</title><link>https://0xtracer.xyz/incidents/2022-01-01-tinyman-pools/</link><pubDate>Sat, 01 Jan 2022 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2022-01-01-tinyman-pools/</guid><description>An attack occurred at Tinyman Pools on January 1 /2, algorand-based automated market maker (AMM) Tinyman tweeted. The attack exploits a previously unknown hole in the contract and allows the attacker to extract assets&amp;hellip;</description></item><item><title>Vesper Finance</title><link>https://0xtracer.xyz/incidents/2021-12-31-vesper-finance/</link><pubDate>Fri, 31 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-31-vesper-finance/</guid><description>Vesper Finance tweeted that its No. 23 lending pool Vesper Lend beta launched on the interest rate agreement Fuse has been attacked again. The attacker manipulated an oracle and depleted the beta test borrowing pool o&amp;hellip;</description></item><item><title>SashimiSwap</title><link>https://0xtracer.xyz/incidents/2021-12-30-sashimiswap/</link><pubDate>Thu, 30 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-30-sashimiswap/</guid><description>SashimiSwap was attacked due to a logic error in the swap function, and the attacker finally made a profit: 6,261.304 uni, 4,466,096 Sashimi and 63,762 usdt, nearly $200,000.</description></item><item><title>MASK Token</title><link>https://0xtracer.xyz/incidents/2021-12-28-mask-token/</link><pubDate>Tue, 28 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-28-mask-token/</guid><description>On December 28th, according to Twitter user coby.eth, a fake MetaMask governance token was created and launched on the DEXTools platform. The creator of the token used malicious code to make users browse the token inf&amp;hellip;</description></item><item><title>MetaDAO</title><link>https://0xtracer.xyz/incidents/2021-12-27-metadao/</link><pubDate>Mon, 27 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-27-metadao/</guid><description>MetaDAO took a Rug Pull, took away the funds (800 ETH, about 3.2 million US dollars), and has been transferred to Tornado.cash mixed currency. MetaDAO&amp;rsquo;s website is currently unavailable due to suspension.</description></item><item><title>MetaSwap</title><link>https://0xtracer.xyz/incidents/2021-12-27-metaswap/</link><pubDate>Mon, 27 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-27-metaswap/</guid><description>The assets of MetaSwap, a project on the BSC chain, were transferred. The total amount of stolen funds of 1100 BNB was transferred to the Tornado.cash wallet (BSC version), and the price of MGAS tokens fell by 46.99%&amp;hellip;.</description></item><item><title>Monkey Kindom</title><link>https://0xtracer.xyz/incidents/2021-12-23-monkey-kindom/</link><pubDate>Thu, 23 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-23-monkey-kindom/</guid><description>The NFT project Monkey Kindom stated that hackers stole $1.3 million in SOL from the community through a security breach in discord. The hacker first attacked Grape, the solution to authenticate users on Solana, and t&amp;hellip;</description></item><item><title>Visor Finance</title><link>https://0xtracer.xyz/incidents/2021-12-22-visor-finance/</link><pubDate>Wed, 22 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-22-visor-finance/</guid><description>Uniswap V3 liquidity management protocol Visor Finance was hacked again. Hackers took advantage of the loopholes to withdraw more than 8.8 million VISRs and sold them on Uniswap, causing the VISR tokens to plummet by&amp;hellip;</description></item><item><title>Bent Finance</title><link>https://0xtracer.xyz/incidents/2021-12-21-bent-finance/</link><pubDate>Tue, 21 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-21-bent-finance/</guid><description>The staking and yield farming platform Bent Finance tweeted that the Bent Deployer wallet upgraded the curve pool contract from November 30, 2021 to 2021 01:09:27 PM +UTC, and the exploiter added a malicious contract&amp;hellip;</description></item><item><title>Fractal</title><link>https://0xtracer.xyz/incidents/2021-12-21-fractal/</link><pubDate>Tue, 21 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-21-fractal/</guid><description>A Discord server run by Fractal in the recently launched game NFT market was hacked. The hacker defrauded 373 members of 800 Solana cryptocurrencies worth US$150,000. The startup said in its announcement that it will&amp;hellip;</description></item><item><title>Grim Finance</title><link>https://0xtracer.xyz/incidents/2021-12-18-grim-finance/</link><pubDate>Sat, 18 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-18-grim-finance/</guid><description>Reentrancy on deposit function via malicious token callback</description></item><item><title>CoinMarketCap</title><link>https://0xtracer.xyz/incidents/2021-12-15-coinmarketcap/</link><pubDate>Wed, 15 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-15-coinmarketcap/</guid><description>The data on CoinMarketCap&amp;rsquo;s website flashed bugs, and the quotes of multiple cryptocurrencies were wrong.</description></item><item><title>WePiggy</title><link>https://0xtracer.xyz/incidents/2021-12-15-wepiggy/</link><pubDate>Wed, 15 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-15-wepiggy/</guid><description>At 5:21 (UTC+8) on December 15, 2021, the WePiggy-OEC agreement made a short-term error in the CHE oracle, which caused the price of CHE in WePiggy to be much higher than the market price, resulting in abnormal liquid&amp;hellip;</description></item><item><title>Definer</title><link>https://0xtracer.xyz/incidents/2021-12-13-definer/</link><pubDate>Mon, 13 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-13-definer/</guid><description>On December 13, the DeFi platform Definer oracle was attacked. This incident was caused by the problem of Definer’s implementation of the oracle in OEC. It used the token balance of a single liquidity pool at a point&amp;hellip;</description></item><item><title>Dharma</title><link>https://0xtracer.xyz/incidents/2021-12-13-dharma/</link><pubDate>Mon, 13 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-13-dharma/</guid><description>Dharma Wallet officially tweeted that there was a downtime. After Dharma updated Twitter, it said that it has returned to normal and all funds are safe.</description></item><item><title>Vulcan Forged</title><link>https://0xtracer.xyz/incidents/2021-12-13-vulcan-forged/</link><pubDate>Mon, 13 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-13-vulcan-forged/</guid><description>Centralized key storage compromised, 96 user wallets drained</description></item><item><title>AscendEX</title><link>https://0xtracer.xyz/incidents/2021-12-12-ascendex/</link><pubDate>Sun, 12 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-12-ascendex/</guid><description>According to the official announcement, some ERC-20, BSC and Polygon tokens of AscendEX were abnormally transferred out of the hot wallet of the exchange, and the cold wallet of AscendEX was not affected by this incid&amp;hellip;</description></item><item><title>Gelato Network</title><link>https://0xtracer.xyz/incidents/2021-12-11-gelato-network/</link><pubDate>Sat, 11 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-11-gelato-network/</guid><description>Smart contract automation tool Gelato Network tweeted: &amp;ldquo;We have been alerted to a critical vulnerability in Sorbet Finance&amp;rsquo;s G-UNI router contract. This vulnerability only affects users interacting with the Sorbet UI&amp;hellip;.</description></item><item><title>ONUS</title><link>https://0xtracer.xyz/incidents/2021-12-11-onus/</link><pubDate>Sat, 11 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-11-onus/</guid><description>The payment system of ONUS, the largest cryptocurrency trading platform in Vietnam, running a vulnerable version of Log4j suffered a cyber attack. Cyclos notified ONUS to repair the system on December 13, but it was t&amp;hellip;</description></item><item><title>PIZZA</title><link>https://0xtracer.xyz/incidents/2021-12-08-pizza/</link><pubDate>Wed, 08 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-08-pizza/</guid><description>At 8 pm on December 8, the hacker account itsspiderman used an overflow vulnerability to issue additional tripool market-making certificates in eCurve out of thin air, pledged and loaned most of the tokens in the agre&amp;hellip;</description></item><item><title>8ight Finance</title><link>https://0xtracer.xyz/incidents/2021-12-07-8ight-finance/</link><pubDate>Tue, 07 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-07-8ight-finance/</guid><description>8ight Finance on the Harmony chain was hacked, and $1.75 million was stolen due to the leak of the private key due to google doc. The platform tweeted about the loss yesterday, and in its discord server provided an ex&amp;hellip;</description></item><item><title>BitMart</title><link>https://0xtracer.xyz/incidents/2021-12-05-bitmart/</link><pubDate>Sun, 05 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-05-bitmart/</guid><description>BitMart founder and CEO Sheldon Xia tweeted to admit that a large-scale security breach occurred on the platform, and hackers were able to extract assets worth about US$150 million. The affected ETH hot wallet and BSC&amp;hellip;</description></item><item><title>Polygon</title><link>https://0xtracer.xyz/incidents/2021-12-03-polygon/</link><pubDate>Fri, 03 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-03-polygon/</guid><description>On December 3, a group of white hat hackers notified Polygon’s vulnerability bounty agency Immunefi of a vulnerability in the Polygon PoS creation contract. The Polygon core team contacted the organization and Immunef&amp;hellip;</description></item><item><title>Badger DAO</title><link>https://0xtracer.xyz/incidents/2021-12-02-badger-dao/</link><pubDate>Thu, 02 Dec 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-12-02-badger-dao/</guid><description>Malicious script injected via Cloudflare API key compromise</description></item><item><title>MonoX</title><link>https://0xtracer.xyz/incidents/2021-11-30-monox/</link><pubDate>Tue, 30 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-30-monox/</guid><description>Token used as both input and output in swap, inflating its price</description></item><item><title>Snowdog DAO</title><link>https://0xtracer.xyz/incidents/2021-11-28-snowdog-dao/</link><pubDate>Sun, 28 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-28-snowdog-dao/</guid><description>This weekend, the biggest rug pull in Avalanche history shocked the network and its users. SDOG is the first meme coin launched on Avalanche, with a price of up to 10 million U.S. dollars, and the team admitted that t&amp;hellip;</description></item><item><title>Visor Finance</title><link>https://0xtracer.xyz/incidents/2021-11-28-visor-finance/</link><pubDate>Sun, 28 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-28-visor-finance/</guid><description>The malicious contract attacked Visor&amp;rsquo;s OHM-ETH 1% LP management contract. Funds in the targeted pool were recovered by Visor just hours after the attack. The funds deposited by users into Visor are not at risk.</description></item><item><title>dYdX</title><link>https://0xtracer.xyz/incidents/2021-11-27-dydx/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-27-dydx/</guid><description>DeFi Derivatives Agreement dYdX released an investigation report on the deposit contract accident on November 27, stating that there has been a serious loophole in the agent smart contract that has been handling depos&amp;hellip;</description></item><item><title>Lever</title><link>https://0xtracer.xyz/incidents/2021-11-27-lever/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-27-lever/</guid><description>Lever, a decentralized margin trading protocol based on AMM, was attacked by lightning loans. According to the official statement, Lever attacked contract A to borrow 2,100 BNB from PancakeSwap and deposit 2,000 BNB i&amp;hellip;</description></item><item><title>OlympusDAO</title><link>https://0xtracer.xyz/incidents/2021-11-23-olympusdao/</link><pubDate>Tue, 23 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-23-olympusdao/</guid><description>The administrator of OlympusDAO, a new algorithmic stablecoin protocol based on Ethereum, said on Discord, the administrator of Discord said that yesterday, someone bonds OHM/DAI bonds that are considered to be closed&amp;hellip;</description></item><item><title>Optics Bridge</title><link>https://0xtracer.xyz/incidents/2021-11-23-optics-bridge/</link><pubDate>Tue, 23 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-23-optics-bridge/</guid><description>Optics Bridge was attacked and ownership of the multi-signature wallet was transferred. cLabs engineer Tim Moreton said that the multi-signature permission of Optics, a cross-chain communication protocol on Celo, was&amp;hellip;</description></item><item><title>Ploutoz Finance</title><link>https://0xtracer.xyz/incidents/2021-11-23-ploutoz-finance/</link><pubDate>Tue, 23 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-23-ploutoz-finance/</guid><description>Ploutoz Finance, the BSC loan agreement, was attacked. Hackers made a profit of 365,000 US dollars, and the agreement suffered even greater losses. The hacker manipulated the oracle price of DOP tokens and used DOP as&amp;hellip;</description></item><item><title>Formation.Fi</title><link>https://0xtracer.xyz/incidents/2021-11-21-formation-fi/</link><pubDate>Sun, 21 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-21-formation-fi/</guid><description>DeFi protocol Formation.Fi was attacked by flash loans. The main reason for this incident is that the project party underestimated the impact of fee on totalTokens when designing the function swapIn, and ignored the i&amp;hellip;</description></item><item><title>Phantom Galaxies</title><link>https://0xtracer.xyz/incidents/2021-11-19-phantom-galaxies/</link><pubDate>Fri, 19 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-19-phantom-galaxies/</guid><description>According to blockchain game developer Animoca Brands, on November 19, hackers successfully accessed the Discord account of the science fiction NFT game Phantom Galaxies and took over its server. The hacker subsequent&amp;hellip;</description></item><item><title>Nerve</title><link>https://0xtracer.xyz/incidents/2021-11-15-nerve/</link><pubDate>Mon, 15 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-15-nerve/</guid><description>The Nerve cross-chain bridge MetaPool was attacked. This attack was an exploit of the logical vulnerabilities of fUSDT and UST MetaPool on the Nerve cross-chain bridge BSC, causing the fUSDT and UST liquidity in the N&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2021-11-11-curve-finance/</link><pubDate>Thu, 11 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-11-curve-finance/</guid><description>The stablecoin transaction protocol Curve caused losses to users who provided USDM liquidity due to the &amp;ldquo;governance attack&amp;rdquo; of the USDM stablecoin protocol Mochi. At present, Curve has dealt with urgently to avoid a w&amp;hellip;</description></item><item><title>MediaMarkt</title><link>https://0xtracer.xyz/incidents/2021-11-10-mediamarkt/</link><pubDate>Wed, 10 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-10-mediamarkt/</guid><description>According to a report from BleepingComputer on November 10, the electronic retail giant MediaMarkt suffered a ransomware attack. This attack affected many MediaMarkt retail stores throughout Europe, especially those i&amp;hellip;</description></item><item><title>Robinhood</title><link>https://0xtracer.xyz/incidents/2021-11-09-robinhood/</link><pubDate>Tue, 09 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-09-robinhood/</guid><description>Robinhood, a stock and cryptocurrency trading platform, stated that on the evening of November 3, an intruder entered the company’s system and stole the personal information of millions of users. The full names of the&amp;hellip;</description></item><item><title>Farmers World</title><link>https://0xtracer.xyz/incidents/2021-11-07-farmers-world/</link><pubDate>Sun, 07 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-07-farmers-world/</guid><description>According to reports, a currency stolen event occurred in Farmers World, a farm-type game on the WAX ​​chain, and the amount may exceed 100 million yuan. Some players have found that the game shows &amp;ldquo;Insufficient RAM&amp;rdquo;&amp;hellip;</description></item><item><title>Synapse Protocol</title><link>https://0xtracer.xyz/incidents/2021-11-06-synapse-protocol/</link><pubDate>Sat, 06 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-06-synapse-protocol/</guid><description>The asset cross-chain bridge launched by the cross-chain protocol Synapse Protocol is suspected to have loopholes, and the attacker manipulated the virtual price of nUSD Metapool, reducing it by about 12.5%. Ultimatel&amp;hellip;</description></item><item><title>bZx</title><link>https://0xtracer.xyz/incidents/2021-11-05-bzx/</link><pubDate>Fri, 05 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-05-bzx/</guid><description>The margin trading lending platform bZx tweeted that the private keys controlling Polygon and Binance Smart Chain (BSC) deployment appeared to have been leaked, resulting in a loss of funds. The bZx smart contract its&amp;hellip;</description></item><item><title>Vesper Finance</title><link>https://0xtracer.xyz/incidents/2021-11-03-vesper-finance/</link><pubDate>Wed, 03 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-03-vesper-finance/</guid><description>According to official sources, the No. 23 loan pool VesperLendbeta on the DeFi protocol RariFuse was attacked. The attacker consumed a large amount of VUSD liquidity in Uniswapv3, and created a VUSD/USDC liquidity poo&amp;hellip;</description></item><item><title>Chivo</title><link>https://0xtracer.xyz/incidents/2021-11-01-chivo/</link><pubDate>Mon, 01 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-01-chivo/</guid><description>Chivo Wallet is a national digital wallet issued by the government of El Salvador on September 7 for the implementation of the Bitcoin Act. To this end, El Salvador promised that users who download and authenticate th&amp;hellip;</description></item><item><title>SQUID</title><link>https://0xtracer.xyz/incidents/2021-11-01-squid/</link><pubDate>Mon, 01 Nov 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-11-01-squid/</guid><description>According to reports, the BSC project SQUID, which has the same name as the popular Korean drama &amp;ldquo;Squid Game&amp;rdquo;, is suspected of running off or being attacked, with an estimated loss of 12 million USDT. According to the&amp;hellip;</description></item><item><title>BXH</title><link>https://0xtracer.xyz/incidents/2021-10-30-bxh/</link><pubDate>Sat, 30 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-30-bxh/</guid><description>The decentralized transaction protocol BXH tweeted that the assets of the protocol on the Binance Smart Chain (BSC) chain were hacked.</description></item><item><title>AnubisDAO</title><link>https://0xtracer.xyz/incidents/2021-10-29-anubisdao/</link><pubDate>Fri, 29 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-29-anubisdao/</guid><description>According to Etherscan data, the OHM imitation project AnubisDAO, which was launched at Copper Launch, withdrew its liquidity pool one day after it went online. It is suspected that the volume of money went off the ro&amp;hellip;</description></item><item><title>AutoShark Finance</title><link>https://0xtracer.xyz/incidents/2021-10-29-autoshark-finance/</link><pubDate>Fri, 29 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-29-autoshark-finance/</guid><description>The DeFi protocol AutoShark Finance on the Binance Smart Chain was attacked by hackers in a series of transactions, and the hackers made a profit of US$2 million (the protocol loss may be even greater). Previously, Au&amp;hellip;</description></item><item><title>Cream Finance</title><link>https://0xtracer.xyz/incidents/2021-10-27-cream-finance/</link><pubDate>Wed, 27 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-27-cream-finance/</guid><description>Oracle manipulation via flash loan to drain lending pools</description></item><item><title>Saturnbeam</title><link>https://0xtracer.xyz/incidents/2021-10-24-saturnbeam/</link><pubDate>Sun, 24 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-24-saturnbeam/</guid><description>The IDO project SaturnBeam of MoonSwap, a decentralized exchange on the Moonriver chain, ran away, and MoonSwap tweeted a warning that SaturnBeam would refund the money within 24 hours.</description></item><item><title>Youtube channels</title><link>https://0xtracer.xyz/incidents/2021-10-24-youtube-channels/</link><pubDate>Sun, 24 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-24-youtube-channels/</guid><description>According to Cointelegraph reports, some Youtube channels were hacked and seized control. The original content and information of these channels were destroyed by hackers. Hackers pretended to be large technology comp&amp;hellip;</description></item><item><title>Alpha Finance</title><link>https://0xtracer.xyz/incidents/2021-10-23-alpha-finance/</link><pubDate>Sat, 23 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-23-alpha-finance/</guid><description>These implicit assumptions on Uniswap V2 resulted in 20 addresses on Alpha Homora V2 being impacted and lost a total of 40.93 ETH to miners who extracted this value. We have plans to compensate these 20 addresses. How&amp;hellip;</description></item><item><title>CoinMarketCap</title><link>https://0xtracer.xyz/incidents/2021-10-23-coinmarketcap/</link><pubDate>Sat, 23 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-23-coinmarketcap/</guid><description>Email addresses belonging to 3.1 million CoinMarketCap users were leaked last week, according to Have I Been Pwned.Have I Been Pwned says that the website’s database was breached on Oct. 12, 2021. Exactly 3,117,548 em&amp;hellip;</description></item><item><title>Avaterra Finance</title><link>https://0xtracer.xyz/incidents/2021-10-21-avaterra-finance/</link><pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-21-avaterra-finance/</guid><description>Avalanche ecological stability income aggregation agreement Avaterra Finance was attacked by hackers. The security company Rugdoc analyzed that the contract of the agreement is a fork of Goose, but their token contain&amp;hellip;</description></item><item><title>Polygon Plasma Bridge</title><link>https://0xtracer.xyz/incidents/2021-10-21-polygon-plasma-bridge/</link><pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-21-polygon-plasma-bridge/</guid><description>Bug bounty platform Immunefi says white hat hacker Gerhard Wagner submitted a critical vulnerability affecting the Polygon Plasma Bridge on October 5, 2021 that allows attackers to withdraw their burn transactions fro&amp;hellip;</description></item><item><title>Pancake Hunny</title><link>https://0xtracer.xyz/incidents/2021-10-20-pancake-hunny/</link><pubDate>Wed, 20 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-20-pancake-hunny/</guid><description>Pancake Hunny, the DeFi protocol on BSC, was attacked by lightning loans, and HUNNY tokens fell by about 70% in a short time. The hacked transactions included 513 transfers, and Gas consumption reached 19 million, of&amp;hellip;</description></item><item><title>Glide Finance</title><link>https://0xtracer.xyz/incidents/2021-10-18-glide-finance/</link><pubDate>Mon, 18 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-18-glide-finance/</guid><description>Glide Finance, a DeFi protocol built on the Elastos ecosystem, tweeted that a contract loophole was exploited to siphon money out of the matching contract for a loss of approximately $300,000 because the team changed&amp;hellip;</description></item><item><title>CryptoRom</title><link>https://0xtracer.xyz/incidents/2021-10-15-cryptorom/</link><pubDate>Fri, 15 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-15-cryptorom/</guid><description>The report released by Sophos stated that the crypto fraud application CryptoRom stole 1.4 million U.S. dollars through the use of &amp;ldquo;super signature service&amp;rdquo; and Apple&amp;rsquo;s developer enterprise plan. It is reported that f&amp;hellip;</description></item><item><title>Indexed Finance</title><link>https://0xtracer.xyz/incidents/2021-10-15-indexed-finance/</link><pubDate>Fri, 15 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-15-indexed-finance/</guid><description>Indexed Finance, a passive income agreement, was attacked, and the affected fund pools included DEFI5 and CC10. After the vulnerability was discovered, it triggered protection measures including DEGEN, NFTP, and FFF (&amp;hellip;</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2021-10-13-opensea/</link><pubDate>Wed, 13 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-13-opensea/</guid><description>According to news, the security research company discovered that there is a serious security vulnerability in OpenSea in the NFT market, which may cause hackers to steal the user&amp;rsquo;s entire encrypted wallet. Then OpenSe&amp;hellip;</description></item><item><title>StarkWare</title><link>https://0xtracer.xyz/incidents/2021-10-08-starkware/</link><pubDate>Fri, 08 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-08-starkware/</guid><description>Quantitative trading company mgnr stated on Twitter that StarkWare has an urgent security issue, but did not disclose the specific details. Louis Guthmann, the head of ecology of the StarkWare team, confirmed that the&amp;hellip;</description></item><item><title>Evolved Apes</title><link>https://0xtracer.xyz/incidents/2021-10-06-evolved-apes/</link><pubDate>Wed, 06 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-06-evolved-apes/</guid><description>The official Twitter account and website of the NFT project Evolved Apes, the project developer &amp;ldquo;Evil Ape&amp;rdquo; disappeared last week, and took away 798 ETH worth US$2.7 million.</description></item><item><title>My Farm Pet</title><link>https://0xtracer.xyz/incidents/2021-10-06-my-farm-pet/</link><pubDate>Wed, 06 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-06-my-farm-pet/</guid><description>My Farm Pet was suspected of being attacked by lightning loans, and today fell 79.86%.</description></item><item><title>Lido Finance</title><link>https://0xtracer.xyz/incidents/2021-10-05-lido-finance/</link><pubDate>Tue, 05 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-05-lido-finance/</guid><description>Staking liquidity solution Lido Finance discovered a loophole through the Lido vulnerability bounty program, which can be used by whitelisted node operators to steal a small portion of user funds. Approximately 20,000&amp;hellip;</description></item><item><title>Liquid Network</title><link>https://0xtracer.xyz/incidents/2021-10-05-liquid-network/</link><pubDate>Tue, 05 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-05-liquid-network/</guid><description>The Bitcoin sidechain Liquid Network launched by Blockstream encountered block signature-related issues after the recent upgrade, resulting in no block generation for more than 7 hours. According to Liquid Network&amp;rsquo;s b&amp;hellip;</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2021-10-04-compound/</link><pubDate>Mon, 04 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-04-compound/</guid><description>While the decentralized lending agreement Compound tried to fix the loopholes in the liquidity mining token distribution contract through the No. 63 or No. 64 community proposal, another COMP token worth US$68.8 milli&amp;hellip;</description></item><item><title>AutoShark Finance</title><link>https://0xtracer.xyz/incidents/2021-10-02-autoshark-finance/</link><pubDate>Sat, 02 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-02-autoshark-finance/</guid><description>The DeFi protocol AutoShark Finance on the Binance Smart Chain was attacked by lightning loans. The main reason was that the exchange mining function was used by hackers in a series of transactions. Hackers could use&amp;hellip;</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2021-10-02-compound/</link><pubDate>Sat, 02 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-02-compound/</guid><description>Proposal 63 bug caused excess COMP distribution to users</description></item><item><title>Coinbase</title><link>https://0xtracer.xyz/incidents/2021-10-01-coinbase/</link><pubDate>Fri, 01 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-01-coinbase/</guid><description>According to a notification letter submitted by Coinbase to the California Attorney General’s Office to affected customers, a vulnerability that allows hackers to bypass Coinbase’s multi-factor authentication SMS opti&amp;hellip;</description></item><item><title>Iconics</title><link>https://0xtracer.xyz/incidents/2021-10-01-iconics/</link><pubDate>Fri, 01 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-01-iconics/</guid><description>Iconics, an NFT project on Solana, was accused of being a “Rug pull.” The 17-year-old artist behind Iconics made about $140,000 before disappearing. The project developers also deleted Iconics’ Twitter account and dis&amp;hellip;</description></item><item><title>POAP</title><link>https://0xtracer.xyz/incidents/2021-10-01-poap/</link><pubDate>Fri, 01 Oct 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-10-01-poap/</guid><description>POAP, the proof of attendance badge protocol, stated that its minting system was hacked on September 29, and several POAPs of XCOPY and Polygonal Mind were fraudulently issued and sold. At the request of the artist, P&amp;hellip;</description></item><item><title>Bitfinex</title><link>https://0xtracer.xyz/incidents/2021-09-27-bitfinex/</link><pubDate>Mon, 27 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-27-bitfinex/</guid><description>The non-custodial exchange DeversiFi released a post-mortem analysis report for the previous gas transaction that included 7676.62 ETH, saying that the potential problems in the EthereumJS library are combined with th&amp;hellip;</description></item><item><title>Bitcoin.org</title><link>https://0xtracer.xyz/incidents/2021-09-23-bitcoin-org/</link><pubDate>Thu, 23 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-23-bitcoin-org/</guid><description>The Bitcoin.org website has activities to give back to the community, and it is suspected that the website has been hacked. The homepage of the website shows a Bitcoin address and states that any first 10,000 users wh&amp;hellip;</description></item><item><title>Vee Finance</title><link>https://0xtracer.xyz/incidents/2021-09-21-vee-finance/</link><pubDate>Tue, 21 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-21-vee-finance/</guid><description>Price oracle manipulation allowed over-borrowing against positions</description></item><item><title>pNetwork</title><link>https://0xtracer.xyz/incidents/2021-09-19-pnetwork/</link><pubDate>Sun, 19 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-19-pnetwork/</guid><description>Critical bug in codebase allowed 277 WBTC to be stolen</description></item><item><title>Defibox</title><link>https://0xtracer.xyz/incidents/2021-09-17-defibox/</link><pubDate>Fri, 17 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-17-defibox/</guid><description>Defibox discovered an abnormal exchange situation of the EOS-EMOON trading pair at 22:00 on September 16th. After an emergency investigation, the swap contract was suspended at 0:00 on September 17th, and it was reope&amp;hellip;</description></item><item><title>MISO</title><link>https://0xtracer.xyz/incidents/2021-09-17-miso/</link><pubDate>Fri, 17 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-17-miso/</guid><description>The DONA token auction of the Jay Pegs Auto Mart project on the SushiSwap Launchpad platform MISO was attacked. The attacker inserted malicious code into the MISO front end and changed the auction wallet address to hi&amp;hellip;</description></item><item><title>Nowswap</title><link>https://0xtracer.xyz/incidents/2021-09-15-nowswap/</link><pubDate>Wed, 15 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-15-nowswap/</guid><description>Nowswap, a decentralized exchange on Ethereum, was attacked by a flash loan. The attacker emptied Nowswap’s liquidity pool. The liquidity pool was reduced from US$1,069,197 to US$24.15. The attacker made a profit of 5&amp;hellip;</description></item><item><title>Secret Network</title><link>https://0xtracer.xyz/incidents/2021-09-15-secret-network/</link><pubDate>Wed, 15 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-15-secret-network/</guid><description>The private public chain Secret Network stated on Twitter that the main network has undergone an unplanned upgrade, from secret-2 to secret-3, to prevent major network security issues from causing financial losses. Th&amp;hellip;</description></item><item><title>Arbitrum One</title><link>https://0xtracer.xyz/incidents/2021-09-14-arbitrum-one/</link><pubDate>Tue, 14 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-14-arbitrum-one/</guid><description>The expansion of the Ethereum network, Arbitrum One, released a report on network failures. Beginning at 10:14 on September 14th, EST, Arbitrum One was out of service for 45 minutes, during which time the Arbitrum Seq&amp;hellip;</description></item><item><title>Klondike Finance</title><link>https://0xtracer.xyz/incidents/2021-09-14-klondike-finance/</link><pubDate>Tue, 14 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-14-klondike-finance/</guid><description>Klondike Finance was attacked by hackers, with a total loss of approximately 35,281.71 KXUSD (6.5629 WETH).</description></item><item><title>Solana</title><link>https://0xtracer.xyz/incidents/2021-09-14-solana/</link><pubDate>Tue, 14 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-14-solana/</guid><description>The beta version of the mainnet of the public chain Solana has been unstable since 19:52 Beijing time last night, and it has been 12 hours since the Solana chain application has not been able to operate normally. Acco&amp;hellip;</description></item><item><title>Zabu Finance</title><link>https://0xtracer.xyz/incidents/2021-09-12-zabu-finance/</link><pubDate>Sun, 12 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-12-zabu-finance/</guid><description>The Zabu Finance project on the Avalanche chain suffered a flash loan attack. Officially, the attackers withdrew 4.5 billion ZABU tokens from the Zabu Farm Contract, bringing the supply to 5 billion and dumping all of&amp;hellip;</description></item><item><title>OpenSea</title><link>https://0xtracer.xyz/incidents/2021-09-10-opensea/</link><pubDate>Fri, 10 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-10-opensea/</guid><description>A vulnerability in NFT marketplace OpenSea resulted in at least 42 NFTs being sent to a burn address, worth at least $100,000. The issue was first raised by Nick Johnson, lead developer of the Ethereum Name Service (E&amp;hellip;</description></item><item><title>dYdX</title><link>https://0xtracer.xyz/incidents/2021-09-09-dydx/</link><pubDate>Thu, 09 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-09-dydx/</guid><description>Twitter netizen &amp;ldquo;mhonkasalo&amp;rdquo; stated that there was a bug in the dYdX pledge contract. The user received 0 stkDYDX when pledged, the front end was disabled, and there were 64 affected addresses. Later, dYdX released th&amp;hellip;</description></item><item><title>Banksy</title><link>https://0xtracer.xyz/incidents/2021-09-04-banksy/</link><pubDate>Sat, 04 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-04-banksy/</guid><description>A user claimed on Twitter that he had mistakenly entered an NFT auction scam and was taken away by an art website worth 336,000 US dollars of Ethereum. However, the development of the story is somewhat unexpected, bec&amp;hellip;</description></item><item><title>DAO Maker</title><link>https://0xtracer.xyz/incidents/2021-09-04-dao-maker/</link><pubDate>Sat, 04 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-04-dao-maker/</guid><description>The Vesting contract of DAO Maker was attacked by hackers. DeRace Token (DERC), Coinspaid (CPD), Capsule Coin (CAPS), Showcase Token (SHO) all use Dao Maker&amp;rsquo;s distribution system, and the DAO Maker contract is attacke&amp;hellip;</description></item><item><title>ETC</title><link>https://0xtracer.xyz/incidents/2021-09-04-etc/</link><pubDate>Sat, 04 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-04-etc/</guid><description>Ethereum Classic (ETC) tweeted that the ETC mainnet was forked due to previous vulnerabilities in the Ethereum client Geth. At present, most of the computing power is on the mainnet. Core-geth node operators should up&amp;hellip;</description></item><item><title>OpenZeppelin</title><link>https://0xtracer.xyz/incidents/2021-09-03-openzeppelin/</link><pubDate>Fri, 03 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-03-openzeppelin/</guid><description>OpenZeppelin released a bug fix analysis. Whitehat Zb3 submitted a serious reentrant vulnerability in OpenZeppelin&amp;rsquo;s TimelockController contract on August 21, 2021, which affected a project hosted on the Immunefi vuln&amp;hellip;</description></item><item><title>Tomb Finance</title><link>https://0xtracer.xyz/incidents/2021-09-03-tomb-finance/</link><pubDate>Fri, 03 Sep 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-09-03-tomb-finance/</guid><description>The Tomb Finance token TOMB, an algorithmic stablecoin project linked to the Fantom ecosystem and FTM, had the biggest drop of 77% yesterday, and was suspected of being attacked by the community. In this regard, Tomb&amp;hellip;</description></item><item><title>Cream Finance</title><link>https://0xtracer.xyz/incidents/2021-08-31-cream-finance/</link><pubDate>Tue, 31 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-31-cream-finance/</guid><description>The mortgage lending platform Cream Finance had a flash loan attack. In its post-mortem analysis report on the flash loan attack, it stated that a total of 460 million AMP tokens and 2804 ETH (worth approximately US$3&amp;hellip;</description></item><item><title>Bilaxy</title><link>https://0xtracer.xyz/incidents/2021-08-29-bilaxy/</link><pubDate>Sun, 29 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-29-bilaxy/</guid><description>The Bilaxy exchange tweeted that the hot wallet was hacked and lost approximately 296 tokens (including ETH).</description></item><item><title>xToken</title><link>https://0xtracer.xyz/incidents/2021-08-29-xtoken/</link><pubDate>Sun, 29 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-29-xtoken/</guid><description>The DeFi pledge and liquidity strategy platform xToken, which suffered a lightning loan attack, released an analysis report on the vulnerability of the xSNX contract. At 4:43 UTC on August 29th, a vulnerability in the&amp;hellip;</description></item><item><title>Dot.Finance</title><link>https://0xtracer.xyz/incidents/2021-08-25-dot-finance/</link><pubDate>Wed, 25 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-25-dot-finance/</guid><description>Polkadot Eco DeFi revenue aggregator Dot.Finance suffered a lightning loan attack. Dot.Finance&amp;rsquo;s token PINK plummeted 35% in a short time, from 0.77 USD to approximately 0.5 USD. The attacker made a profit of 900.89 B&amp;hellip;</description></item><item><title>BitConnect</title><link>https://0xtracer.xyz/incidents/2021-08-21-bitconnect/</link><pubDate>Sat, 21 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-21-bitconnect/</guid><description>In May of this year, the SEC filed a lawsuit against five people suspected of promoting BitConnect. The SEC believes that BitConnect is an unregistered digital asset securities product, and the program has raised more&amp;hellip;</description></item><item><title>Sentinel</title><link>https://0xtracer.xyz/incidents/2021-08-21-sentinel/</link><pubDate>Sat, 21 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-21-sentinel/</guid><description>Sentinel, a Cosmos ecological dVPN project, stated on Twitter that the $40 million DVPN tokens were stolen due to the leak of the mnemonic phrase on the HitBTC exchange. Sentinel stated that the user&amp;rsquo;s own DVPN was sa&amp;hellip;</description></item><item><title>Finiko</title><link>https://0xtracer.xyz/incidents/2021-08-20-finiko/</link><pubDate>Fri, 20 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-20-finiko/</guid><description>The founder of one of Russia&amp;rsquo;s largest cryptocurrency scams has been in jail for allegedly defrauding US$100 million from its investors. Finiko was established in Kazan in 2019 and pretended to be a legitimate BTC inv&amp;hellip;</description></item><item><title>Liquid Exchange</title><link>https://0xtracer.xyz/incidents/2021-08-19-liquid-exchange/</link><pubDate>Thu, 19 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-19-liquid-exchange/</guid><description>Warm wallet infrastructure compromised across multiple chains</description></item><item><title>Luna Yield</title><link>https://0xtracer.xyz/incidents/2021-08-19-luna-yield/</link><pubDate>Thu, 19 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-19-luna-yield/</guid><description>The Solana chain has experienced its first carpet pull. Luna Yield ($LUNY) is a revenue aggregator launched through the Solana launchpad &amp;ldquo;SolPad&amp;rdquo;, which has disappeared and is a variety of digital currencies worth abo&amp;hellip;</description></item><item><title>Pinecone Finance</title><link>https://0xtracer.xyz/incidents/2021-08-19-pinecone-finance/</link><pubDate>Thu, 19 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-19-pinecone-finance/</guid><description>Pinecone launched the pledge pool of protocol token PCT at 09:00 UTC on August 18, 2021, and was attacked at 11:41:19 AM UTC. When the Pinecone PCT pledge pool went online, the front-end was processed to limit illegal&amp;hellip;</description></item><item><title>Solend</title><link>https://0xtracer.xyz/incidents/2021-08-19-solend/</link><pubDate>Thu, 19 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-19-solend/</guid><description>Solana Ecological Lending Agreement Solend tweeted that the agreement was hacked at 20:40 on August 19th, Beijing time. The attacker cracked the insecure identity check in the UpdateReserveConfig function, allowing it&amp;hellip;</description></item><item><title>XSURGE</title><link>https://0xtracer.xyz/incidents/2021-08-17-xsurge/</link><pubDate>Tue, 17 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-17-xsurge/</guid><description>On August 17, the DeFi project XSURGE on BSC suffered a lightning loan attack. On August 16, local time, XSURGE officially issued a statement about the SurgeBNB vulnerability before the attack. Since the SurgeBNB cont&amp;hellip;</description></item><item><title>Ref.Finance</title><link>https://0xtracer.xyz/incidents/2021-08-15-ref-finance/</link><pubDate>Sun, 15 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-15-ref-finance/</guid><description>The NEAR ecological decentralized exchange Ref.Finance team tweeted that at around 2 pm UTC on August 14th, the Ref team noticed the abnormal behavior of the REF-NEAR trading pair, and then discovered that the patch o&amp;hellip;</description></item><item><title>Fetch.ai</title><link>https://0xtracer.xyz/incidents/2021-08-14-fetch-ai/</link><pubDate>Sat, 14 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-14-fetch-ai/</guid><description>According to Reuters, a High Court judge in London granted artificial intelligence firm Fetch.ai’s request, ordering Binance to track down the hackers who stole $2.6 million in assets from Fetch.ai’s Binance account a&amp;hellip;</description></item><item><title>Neko Network</title><link>https://0xtracer.xyz/incidents/2021-08-13-neko-network/</link><pubDate>Fri, 13 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-13-neko-network/</guid><description>The Neko Network, a lending protocol on the Binance Smart Chain (BSC), was attacked. The attacker used vulnerabilities in the protocol to mortgage assets in the name of the user and sent the borrowed funds directly to&amp;hellip;</description></item><item><title>DAO Maker</title><link>https://0xtracer.xyz/incidents/2021-08-12-dao-maker/</link><pubDate>Thu, 12 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-12-dao-maker/</guid><description>DAO Maker issued an announcement stating that at around 1:00 UTC on August 12th, hackers maliciously used a DAO Maker wallet and obtained administrator rights. After initially testing this vulnerability and successful&amp;hellip;</description></item><item><title>Punk Protocol</title><link>https://0xtracer.xyz/incidents/2021-08-11-punk-protocol/</link><pubDate>Wed, 11 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-11-punk-protocol/</guid><description>Punk Protocol, the decentralized annuity protocol, stated that it encountered an attack during the fair launch process, causing a loss of 8.9 million US dollars. Later, the team recovered another 4.95 million US dolla&amp;hellip;</description></item><item><title>Poly Network</title><link>https://0xtracer.xyz/incidents/2021-08-10-poly-network/</link><pubDate>Tue, 10 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-10-poly-network/</guid><description>Cross-chain relay contract privilege escalation, funds mostly returned</description></item><item><title>Zerogoki</title><link>https://0xtracer.xyz/incidents/2021-08-08-zerogoki/</link><pubDate>Sun, 08 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-08-zerogoki/</guid><description>BachOnChain, a core member of Duet Protocol, a multi-chain synthetic asset protocol, tweeted that the Duet Protocol pioneer network Zerogoki experienced an oracle attack a few hours ago, and the wrong price led to unr&amp;hellip;</description></item><item><title>VERA</title><link>https://0xtracer.xyz/incidents/2021-08-04-vera/</link><pubDate>Wed, 04 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-04-vera/</guid><description>Some Twitter users reported receiving a token airdrop named VERA (The Vera) project, but the tokens in the wallet were stolen after the official website was authorized. After inquiry, it was found that the project was&amp;hellip;</description></item><item><title>Wault Finance</title><link>https://0xtracer.xyz/incidents/2021-08-04-wault-finance/</link><pubDate>Wed, 04 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-04-wault-finance/</guid><description>Wault Finance on the BSC chain was attacked, and the attacker made a profit of 930,000 US dollars. Attackers due to design flaws in the economic model can carry out arbitrage attacks on the pool of WaultSwapPair (BSC_&amp;hellip;</description></item><item><title>BSV</title><link>https://0xtracer.xyz/incidents/2021-08-03-bsv/</link><pubDate>Tue, 03 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-03-bsv/</guid><description>Starting at around 23:45 on August 3, Beijing time, BSV suffered a “large-scale” 51% attack, resulting in the simultaneous mining of three versions of the chain.</description></item><item><title>Popsicle Finance</title><link>https://0xtracer.xyz/incidents/2021-08-03-popsicle-finance/</link><pubDate>Tue, 03 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-03-popsicle-finance/</guid><description>Reward accounting bug exploited via flash loan to drain pools</description></item><item><title>Stazie</title><link>https://0xtracer.xyz/incidents/2021-08-02-stazie/</link><pubDate>Mon, 02 Aug 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-08-02-stazie/</guid><description>A crook named &amp;ldquo;cryptopunksbot&amp;rdquo; was published on CryptoPunk&amp;rsquo;s Discord server, providing NFT investors with the opportunity to win ten elusive NFT avatars. Stazie, the co-founder of the NFT game project Hedgie, accepted&amp;hellip;</description></item><item><title>Levyathan</title><link>https://0xtracer.xyz/incidents/2021-07-30-levyathan/</link><pubDate>Fri, 30 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-30-levyathan/</guid><description>Levyathan, the encryption index protocol on the BSC chain, was attacked. According to the official event update, the hacker minted 100,000,000,000,000,000,0 billion LEV tokens, which caused the price of LEV to return&amp;hellip;</description></item><item><title>PolyYeld Finance</title><link>https://0xtracer.xyz/incidents/2021-07-28-polyyeld-finance/</link><pubDate>Wed, 28 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-28-polyyeld-finance/</guid><description>The profit farming agreement PolyYeld Finance was attacked. The project contract was used to mint 4.9 trillion YELD tokens and dump them in the secondary market.</description></item><item><title>THORChain</title><link>https://0xtracer.xyz/incidents/2021-07-24-thorchain/</link><pubDate>Sat, 24 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-24-thorchain/</guid><description>THORChain (RUNE), a decentralized cross-chain transaction protocol, claims that hackers airdrop UniH tokens to Ethereum addresses as bait to steal RUNE tokens in users&amp;rsquo; wallets. Hackers have airdropped UniH tokens wit&amp;hellip;</description></item><item><title>Thorchain</title><link>https://0xtracer.xyz/incidents/2021-07-23-thorchain/</link><pubDate>Fri, 23 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-23-thorchain/</guid><description>Custom ETH router logic tricked into treating attacker contract as router</description></item><item><title>Sanshu Inu</title><link>https://0xtracer.xyz/incidents/2021-07-21-sanshu-inu/</link><pubDate>Wed, 21 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-21-sanshu-inu/</guid><description>Using the mechanism of deflation token KEANU to attack the reward vulnerabilities in the Memestake contract deployed by Sanshu Inu, the attacker finally made a profit of about 56 ETH.</description></item><item><title>Array Finance</title><link>https://0xtracer.xyz/incidents/2021-07-19-array-finance/</link><pubDate>Mon, 19 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-19-array-finance/</guid><description>The DeFi project Array Finance was attacked by a lightning loan. The attacker used Array Finance&amp;rsquo;s pricing mechanism to rely on aBPT&amp;rsquo;s totalSupply to attack Array Finance. Officials stated that the attacker made a pro&amp;hellip;</description></item><item><title>PancakeBunny</title><link>https://0xtracer.xyz/incidents/2021-07-16-pancakebunny/</link><pubDate>Fri, 16 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-16-pancakebunny/</guid><description>DeFi revenue aggregator PancakeBunny tweeted that its version on Polygon was attacked by outsiders and has suspended all Polygon Sushi Vaults. According to officials, Polygon vaults, BSC PancakeBunny vaults, and BUNNY&amp;hellip;</description></item><item><title>THORChain</title><link>https://0xtracer.xyz/incidents/2021-07-16-thorchain/</link><pubDate>Fri, 16 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-16-thorchain/</guid><description>The decentralized cross-chain transaction protocol THORChain (RUNE) updated the attack situation, claiming that the amount of lost assets was about 4000 ETH. The initial assessment is that the attack was a logical vul&amp;hellip;</description></item><item><title>T-Mobile</title><link>https://0xtracer.xyz/incidents/2021-07-15-t-mobile/</link><pubDate>Thu, 15 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-15-t-mobile/</guid><description>Mobile phone operator T-Mobile filed a lawsuit for failing to prevent the SIM exchange scam, which cost a customer $55,000 in Bitcoin. The plaintiff Richard Harris accused T-Mobile of improper behavior, including fail&amp;hellip;</description></item><item><title>ApeRocket Finance</title><link>https://0xtracer.xyz/incidents/2021-07-14-aperocket-finance/</link><pubDate>Wed, 14 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-14-aperocket-finance/</guid><description>ApeRocket, the DeFi revenue mining aggregator and optimizer, released the lightning loan attack details and compensation plan. ApeRocket&amp;rsquo;s BSC version and Polygon version encountered lightning loan attacks at 4:30 AM&amp;hellip;</description></item><item><title>Bondly Finance</title><link>https://0xtracer.xyz/incidents/2021-07-14-bondly-finance/</link><pubDate>Wed, 14 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-14-bondly-finance/</guid><description>The digital collectibles market platform Bondly Finance released an analysis report on the previous attack. Bondly Finance believes that the attacker obtained access to the password account belonging to Bondly CEO Bra&amp;hellip;</description></item><item><title>pSPACE</title><link>https://0xtracer.xyz/incidents/2021-07-14-pspace/</link><pubDate>Wed, 14 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-14-pspace/</guid><description>The Polygon Space Token (pSPACE) of the Polygon platform suffered a lightning loan attack. It is reported that this is a profit-inflation bug.</description></item><item><title>Rabbit Finance</title><link>https://0xtracer.xyz/incidents/2021-07-14-rabbit-finance/</link><pubDate>Wed, 14 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-14-rabbit-finance/</guid><description>Medium user Anonymous Dev published an article stating that there are a large number of loopholes in the BSC ecological Rabbit Finance code, which may be suspected of running away. The vulnerabilities include: 1. The&amp;hellip;</description></item><item><title>Axie Infinity</title><link>https://0xtracer.xyz/incidents/2021-07-13-axie-infinity/</link><pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-13-axie-infinity/</guid><description>The NFT project Axie Infinity tweeted that its market platform was attacked by DDoS and that someone was sending spam to its server in an attempt to make it unusable. Officials say the funds are currently safe.</description></item><item><title>DeFiPie</title><link>https://0xtracer.xyz/incidents/2021-07-13-defipie/</link><pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-13-defipie/</guid><description>DeFiPie (PIE), the lending protocol on the Ethereum and Binance smart chains, was hacked. It is recommended that all liquidity providers extract all liquidity from the application. PIE tokens fell by more than 66% in&amp;hellip;</description></item><item><title>helios</title><link>https://0xtracer.xyz/incidents/2021-07-12-helios/</link><pubDate>Mon, 12 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-12-helios/</guid><description>DeFi project helios on Polygon rug pull. (0x8eb6ead701b7d378cf62c898a0a7b72639a89201)</description></item><item><title>Chainswap</title><link>https://0xtracer.xyz/incidents/2021-07-11-chainswap/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-chainswap/</guid><description>The cross-chain bridge Chainswap announced the details of the stolen incident on its official blog. A total of 20 project assets were stolen, with a total value of approximately US$4 million. At present, the ChainSwap&amp;hellip;</description></item><item><title>DAFI Protocol</title><link>https://0xtracer.xyz/incidents/2021-07-11-dafi-protocol/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-dafi-protocol/</guid><description>According to official sources, DAFI Protocol, an on-chain incentive protocol, stated that DAFI worth 200,000 US dollars was sold due to the “cross-chain asset bridge ChainSwap attack”. DAFI Protocol requests the commu&amp;hellip;</description></item><item><title>DAO ventures</title><link>https://0xtracer.xyz/incidents/2021-07-11-dao-ventures/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-dao-ventures/</guid><description>According to official sources, the DeFi asset management platform DAO ventures was stolen 300,000 DVG tokens due to a loophole in the ChainSwap contract of the cross-chain asset bridge. DAOventures stated that it has&amp;hellip;</description></item><item><title>Dora Factory</title><link>https://0xtracer.xyz/incidents/2021-07-11-dora-factory/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-dora-factory/</guid><description>According to official sources, Dora Factory, a multi-chain service infrastructure based on Polkadot, suffered a contract vulnerability in the cross-chain asset bridge ChainSwap. The 7,872 DORA locked in the ChainSwap&amp;hellip;</description></item><item><title>OptionRoom</title><link>https://0xtracer.xyz/incidents/2021-07-11-optionroom/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-optionroom/</guid><description>According to official news, Polkadot&amp;rsquo;s ecological oracle and prediction protocol OptionRoom stated that it was affected by the &amp;ldquo;cross-chain asset bridge ChainSwap attack&amp;rdquo;, and many projects including OptionRoom were a&amp;hellip;</description></item><item><title>Umbrella Network</title><link>https://0xtracer.xyz/incidents/2021-07-11-umbrella-network/</link><pubDate>Sun, 11 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-11-umbrella-network/</guid><description>According to official sources, the DeFi oracle Umbrella Network was stolen over 3 million UMB tokens due to a loophole in the ChainSwap contract of the cross-chain asset bridge.</description></item><item><title>AnySwap</title><link>https://0xtracer.xyz/incidents/2021-07-10-anyswap/</link><pubDate>Sat, 10 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-10-anyswap/</guid><description>ECDSA nonce reuse in signing algorithm exposed private key</description></item><item><title>Chainswap</title><link>https://0xtracer.xyz/incidents/2021-07-10-chainswap/</link><pubDate>Sat, 10 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-10-chainswap/</guid><description>Node validation logic flaw allowed minting of arbitrary tokens</description></item><item><title>Android application</title><link>https://0xtracer.xyz/incidents/2021-07-09-android-application/</link><pubDate>Fri, 09 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-09-android-application/</guid><description>Lookout Threat Lab security researchers exposed more than 170 Android applications, and the number of deceived users exceeded 93,000. Among them, 25 applications managed to evade the Google Play Store detection and su&amp;hellip;</description></item><item><title>Circle</title><link>https://0xtracer.xyz/incidents/2021-07-09-circle/</link><pubDate>Fri, 09 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-09-circle/</guid><description>Circle Internet Financial, the issuer of the US dollar stable currency USDC, reported in a regulatory filing with the US Securities and Exchange Commission (SEC) that Circle Internet Financial lost US$2 million in ema&amp;hellip;</description></item><item><title>Bitcoin.org</title><link>https://0xtracer.xyz/incidents/2021-07-06-bitcoin-org/</link><pubDate>Tue, 06 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-06-bitcoin-org/</guid><description>Cobra, the anonymous creator and principal of Bitcoin.org, tweeted that the Bitcoin.org website is being subjected to an &amp;ldquo;absolutely large-scale&amp;rdquo; distributed denial of service (DDoS) attack, as well as a Bitcoin ranso&amp;hellip;</description></item><item><title>RAI Finance</title><link>https://0xtracer.xyz/incidents/2021-07-04-rai-finance/</link><pubDate>Sun, 04 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-04-rai-finance/</guid><description>RAI Finance, a cross-chain transaction protocol based on the Polkadot blockchain, issued a post stating that due to the vulnerability of the ChainSwap smart contract, the RAI access and payment permission addresses co&amp;hellip;</description></item><item><title>Saudi Aramco</title><link>https://0xtracer.xyz/incidents/2021-07-04-saudi-aramco/</link><pubDate>Sun, 04 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-04-saudi-aramco/</guid><description>A blackmailer with an ID of ZeroX is suspected of using a 0day vulnerability attack to steal 1TB of Saudi Aramco&amp;rsquo;s corporate data resources. According to the ID&amp;rsquo;s post on the dark web forum, the data leaked this time&amp;hellip;</description></item><item><title>DEXTools</title><link>https://0xtracer.xyz/incidents/2021-07-03-dextools/</link><pubDate>Sat, 03 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-03-dextools/</guid><description>The DEX trading tool DEXTools (DEXT) tweeted that it was recently hacked and affected some DEXT holders.</description></item><item><title>Haven Protocol</title><link>https://0xtracer.xyz/incidents/2021-07-03-haven-protocol/</link><pubDate>Sat, 03 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-03-haven-protocol/</guid><description>Based on Monero’s privacy-centric DeFi protocol Haven Protocol (XHV), it released analysis reports and measures for three serious attacks related to it in late June. The chain rollback plan will be initiated and a har&amp;hellip;</description></item><item><title>Chainswap</title><link>https://0xtracer.xyz/incidents/2021-07-02-chainswap/</link><pubDate>Fri, 02 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-02-chainswap/</guid><description>The cross-chain asset bridge Chainswap announced the details of the hacking incident today, saying that at 04:30 AM UTC on July 2nd, they noticed an abnormality on the cross-chain bridge. Some users reported that thei&amp;hellip;</description></item><item><title>XDX Swap</title><link>https://0xtracer.xyz/incidents/2021-07-02-xdx-swap/</link><pubDate>Fri, 02 Jul 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-07-02-xdx-swap/</guid><description>The XDX Swap (DDEX) on the Heco chain&amp;rsquo;s cross-chain decentralized exchange DDEX was attacked. The attacker made a profit of 85.17 ETH (approximately $176,000) and cross-chained it to Ethereum. The DDEX code appears to&amp;hellip;</description></item><item><title>THORChain</title><link>https://0xtracer.xyz/incidents/2021-06-29-thorchain/</link><pubDate>Tue, 29 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-29-thorchain/</guid><description>THORChain, a decentralized cross-chain transaction protocol, tweeted that a malicious attack against THORChain was discovered. THORChain nodes have responded and isolated defenses. The capital loss caused by this atta&amp;hellip;</description></item><item><title>Merlin Lab</title><link>https://0xtracer.xyz/incidents/2021-06-28-merlin-lab/</link><pubDate>Mon, 28 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-28-merlin-lab/</guid><description>The hacking of the revenue aggregator Merlin Lab stems from a logical loophole in MerlinStrategyAlpacaBNB. The contract mistakenly uses the BNB transferred by the beneficiary as mining revenue, which makes the contrac&amp;hellip;</description></item><item><title>SafeDollar</title><link>https://0xtracer.xyz/incidents/2021-06-28-safedollar/</link><pubDate>Mon, 28 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-28-safedollar/</guid><description>The algorithmic stablecoin project SafeDollar on Polygon is suspected of being hacked, and an unconfirmed contract seems to have taken away 250,000 USD in USDC and USDT.</description></item><item><title>Vitae</title><link>https://0xtracer.xyz/incidents/2021-06-28-vitae/</link><pubDate>Mon, 28 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-28-vitae/</guid><description>European Union legal body Europol has cracked down on the Belgian Ponzi scheme Vitae. Europol raided 17 locations associated with the site, which were advertised as social media sites with their own cryptocurrencies,&amp;hellip;</description></item><item><title>xWin Finance</title><link>https://0xtracer.xyz/incidents/2021-06-25-xwin-finance/</link><pubDate>Fri, 25 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-25-xwin-finance/</guid><description>The DeFi protocol xWin Finance based on Binance Smart Chain was attacked by lightning loans. The xWin Finance token XWIN has fallen by nearly 90% in 24 hours. The attacker used xWin Finance&amp;rsquo;s &amp;ldquo;reward mechanism&amp;rdquo; to con&amp;hellip;</description></item><item><title>SharedStake</title><link>https://0xtracer.xyz/incidents/2021-06-24-sharedstake/</link><pubDate>Thu, 24 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-24-sharedstake/</guid><description>The Ethereum 2.0 staking solution SharedStake released an attacked report, stating that the reason the SharedStake token was minted before the official launch was due to the use of vulnerabilities in time-locked contr&amp;hellip;</description></item><item><title>StableMagnet</title><link>https://0xtracer.xyz/incidents/2021-06-24-stablemagnet/</link><pubDate>Thu, 24 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-24-stablemagnet/</guid><description>The BSC on-chain project StableMagnet ran away and lost USD 24 million. On August 12, the Greater Manchester Police Department announced that it had arrested the suspects of the StableMagnet Finance team who had previ&amp;hellip;</description></item><item><title>Africrypt</title><link>https://0xtracer.xyz/incidents/2021-06-23-africrypt/</link><pubDate>Wed, 23 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-23-africrypt/</guid><description>According to Bloomberg News, the founder of the cryptocurrency investment platform Africrypt lost contact and 69,000 bitcoins (currently valued at approximately US$2.3 billion) on the platform were transferred. At 4 o&amp;hellip;</description></item><item><title>Eleven Finance</title><link>https://0xtracer.xyz/incidents/2021-06-23-eleven-finance/</link><pubDate>Wed, 23 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-23-eleven-finance/</guid><description>Nerve Finance, a stablecoin trading platform based on the Binance Smart Chain (BSC), tweeted that the Nerve-related machine gun pool in the revenue aggregator Eleven Finance have been attacked by sparks. After analysi&amp;hellip;</description></item><item><title>Fireblocks</title><link>https://0xtracer.xyz/incidents/2021-06-21-fireblocks/</link><pubDate>Mon, 21 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-21-fireblocks/</guid><description>According to Calcalist, the cryptocurrency company StakeHound has filed a lawsuit against the institutional security company Fireblocks, claiming that ETH worth 245.5 million Israeli new shekels (approximately US$75 m&amp;hellip;</description></item><item><title>Impossible Finance</title><link>https://0xtracer.xyz/incidents/2021-06-21-impossible-finance/</link><pubDate>Mon, 21 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-21-impossible-finance/</guid><description>Impossible Finance, the DeFi protocol on the BSC chain, was attacked by a lightning loan, and the attacker made a profit of 1,510.75 WBNB (a total of US$497,000). On June 25, the attackers refunded approximately $252,&amp;hellip;</description></item><item><title>PolyDEX</title><link>https://0xtracer.xyz/incidents/2021-06-20-polydex/</link><pubDate>Sun, 20 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-20-polydex/</guid><description>The Polygon ecological project PolyDEX had a hacking incident. The hackers carried out a reentry attack on the Token Locker smart contract and stole about $500,000 worth of funds from the project.</description></item><item><title>Visor Finance</title><link>https://0xtracer.xyz/incidents/2021-06-19-visor-finance/</link><pubDate>Sat, 19 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-19-visor-finance/</guid><description>The Visor Finance smart contract, a DeFi liquidity protocol based on Uniswap V3, was withdrawn with 230 ETH in an emergency, and the attacker gained access to an account that manages certain Hypervisor management func&amp;hellip;</description></item><item><title>Alchemix</title><link>https://0xtracer.xyz/incidents/2021-06-16-alchemix/</link><pubDate>Wed, 16 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-16-alchemix/</guid><description>The DeFi lending agreement Alchemix alETH pool is suspected to have a loophole, and users can raise collateralized ETH when they have outstanding alETH debts. Alchemix released an alETH pool accident report stating th&amp;hellip;</description></item><item><title>EvoDefi</title><link>https://0xtracer.xyz/incidents/2021-06-10-evodefi/</link><pubDate>Thu, 10 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-10-evodefi/</guid><description>EvoDefi, the project revenue farm on the BSC chain, was attacked, and the price of its token GEN dropped from US$2.1/piece to US$0.9/piece, a short-term drop of 57%. Loss of 455,576.85 GEN worth approximately USD 1 mi&amp;hellip;</description></item><item><title>JBS</title><link>https://0xtracer.xyz/incidents/2021-06-10-jbs/</link><pubDate>Thu, 10 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-10-jbs/</guid><description>JBS USA Holdings Inc. paid an $11 million ransom to cybercriminals last week that temporarily destroyed a plant that handles about a fifth of the nation&amp;rsquo;s meat supply, the chief executive said. . Andre Nogueira, CEO o&amp;hellip;</description></item><item><title>GainSwap</title><link>https://0xtracer.xyz/incidents/2021-06-08-gainswap/</link><pubDate>Tue, 08 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-08-gainswap/</guid><description>At around 4:00 a.m. on June 8, the GainSwap project, which had been online for less than 12 hours, suddenly swept away nearly $8 million in digital assets pledged by users, closed the website access, and then entered&amp;hellip;</description></item><item><title>BurgerSwap</title><link>https://0xtracer.xyz/incidents/2021-06-05-burgerswap/</link><pubDate>Sat, 05 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-05-burgerswap/</guid><description>BurgerSwap, an automated market maker on the Binance Smart Chain, was once again attacked by lightning loans. The attacker took advantage of the re-entry vulnerability in the contract, repeated the swap operation many&amp;hellip;</description></item><item><title>PolyButterfly</title><link>https://0xtracer.xyz/incidents/2021-06-05-polybutterfly/</link><pubDate>Sat, 05 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-05-polybutterfly/</guid><description>On June 5, 2021, PolyButterfly, a decentralized financial protocol based on Polygon, disappeared. Its website has been closed, and its Twitter account and Telegram chat history have been deleted. Before this mysteriou&amp;hellip;</description></item><item><title>Sia</title><link>https://0xtracer.xyz/incidents/2021-06-05-sia/</link><pubDate>Sat, 05 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-05-sia/</guid><description>Siastats tweeted that the Sia network, a decentralized storage project, has been under continuous DDoS attacks in the past two days. The targets of the attacks are network hosts and storage providers. The attacks have&amp;hellip;</description></item><item><title>PancakeHunny</title><link>https://0xtracer.xyz/incidents/2021-06-03-pancakehunny/</link><pubDate>Thu, 03 Jun 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-06-03-pancakehunny/</guid><description>According to official sources, PancakeHunny on BSC was attacked by hackers, and the hackers made 43 ETH (a total of more than 100,000 US dollars). PancakeHunny forked from PancakeBunny, and the attack suffered this ti&amp;hellip;</description></item><item><title>Belt Finance</title><link>https://0xtracer.xyz/incidents/2021-05-29-belt-finance/</link><pubDate>Sat, 29 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-29-belt-finance/</guid><description>Multiple flash loan transactions exploited strategy rebalancing logic</description></item><item><title>BurgerSwap</title><link>https://0xtracer.xyz/incidents/2021-05-28-burgerswap/</link><pubDate>Fri, 28 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-28-burgerswap/</guid><description>BurgerSwap, an automatic market maker on the BSC chain, suffered a lightning loan attack and lost nearly 7 million U.S. dollars. This attack is a problem in the BurgerSwap architecture. Since the Pair layer completely&amp;hellip;</description></item><item><title>JulSwap</title><link>https://0xtracer.xyz/incidents/2021-05-28-julswap/</link><pubDate>Fri, 28 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-28-julswap/</guid><description>The JulSwap of the DEX protocol and the automated liquidity protocol on the BSC chain was attacked by lightning loans, and $JULB fell more than 95% in a short time.</description></item><item><title>MerlinLabs</title><link>https://0xtracer.xyz/incidents/2021-05-26-merlinlabs/</link><pubDate>Wed, 26 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-26-merlinlabs/</guid><description>MerlinLabs, the DeFi revenue aggregator, was attacked. The attack method was similar to that of PancakeBunny, which was attacked by lightning loan 5 days ago, and lost US$6.8 million.</description></item><item><title>AutoShark Finance</title><link>https://0xtracer.xyz/incidents/2021-05-24-autoshark-finance/</link><pubDate>Mon, 24 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-24-autoshark-finance/</guid><description>The DeFi protocol AutoShark Finance on the Binance Smart Chain (BSC) was attacked by a lightning loan, and the currency price suffered a flash crash, with a drop of more than 99% at one time, loss of 750,000 USD.</description></item><item><title>Bogged Finance</title><link>https://0xtracer.xyz/incidents/2021-05-23-bogged-finance/</link><pubDate>Sun, 23 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-23-bogged-finance/</guid><description>The DeFi protocol Bogged Finance officially stated that hackers carried out a lightning loan attack on the staking function vulnerability of BOG token contracts and withdrew 3 million US dollars from the liquidity poo&amp;hellip;</description></item><item><title>DeFi100</title><link>https://0xtracer.xyz/incidents/2021-05-23-defi100/</link><pubDate>Sun, 23 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-23-defi100/</guid><description>The official website of the DeFi protocol DeFi100 on Binance Smart Chain (BSC) is no longer accessible. Previously, Twitter user &amp;ldquo;Mr. Whale&amp;rdquo; pointed out that the project may be a scam. &amp;ldquo;About 32 million US dollars of&amp;hellip;</description></item><item><title>Pancakebunny</title><link>https://0xtracer.xyz/incidents/2021-05-19-pancakebunny/</link><pubDate>Wed, 19 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-19-pancakebunny/</guid><description>Flash loan used to manipulate BNB/BUNNY price, exploiting minting logic</description></item><item><title>Venus</title><link>https://0xtracer.xyz/incidents/2021-05-18-venus/</link><pubDate>Tue, 18 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-18-venus/</guid><description>On the evening of May 18, the BSC-based DeFi lending platform Venus token XVS was doubled by the giant whale. After that, XVS was used as collateral to borrow and transfer BTC and ETH worth hundreds of millions of dol&amp;hellip;</description></item><item><title>FinNexus</title><link>https://0xtracer.xyz/incidents/2021-05-17-finnexus/</link><pubDate>Mon, 17 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-17-finnexus/</guid><description>According to an official statement from on-chain options protocol FinNexus, part of FinNexus’ hardware has been attacked by malware, and an unknown hacker infiltrated the FinNexus system and managed to recover the pri&amp;hellip;</description></item><item><title>bEarn Fi</title><link>https://0xtracer.xyz/incidents/2021-05-16-bearn-fi/</link><pubDate>Sun, 16 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-16-bearn-fi/</guid><description>The DeFi protocol bEarnFi stated that on May 16, its bVaults BUSD-Alpaca strategy was attacked, and nearly 10.86 million BUSD in the pool was exhausted. However, the remaining bvault and other pools of the platform ar&amp;hellip;</description></item><item><title>Sony Life</title><link>https://0xtracer.xyz/incidents/2021-05-15-sony-life/</link><pubDate>Sat, 15 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-15-sony-life/</guid><description>Ishii, an employee of Tokyo Sony Life Insurance Company (&amp;ldquo;Sony Life&amp;rdquo;), allegedly misappropriated US$154 million when attempting to transfer funds between the company’s financial accounts. According to court documents,&amp;hellip;</description></item><item><title>flash.sx</title><link>https://0xtracer.xyz/incidents/2021-05-14-flash-sx/</link><pubDate>Fri, 14 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-14-flash-sx/</guid><description>According to previous news, starting from 11:28 UTC on May 14th, the flash.sx flash loan smart contract suffered a reentry attack vulnerability, and approximately 1.2 million EOS and 462,000 USDT were stolen. Accordin&amp;hellip;</description></item><item><title>xToken</title><link>https://0xtracer.xyz/incidents/2021-05-12-xtoken/</link><pubDate>Wed, 12 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-12-xtoken/</guid><description>Price oracle manipulation via flash loan across two attacks</description></item><item><title>Rari Capital</title><link>https://0xtracer.xyz/incidents/2021-05-08-rari-capital/</link><pubDate>Sat, 08 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-08-rari-capital/</guid><description>DeFi robo-advisor agreement Rari Capital stated on Twitter that its ETH fund pool had a vulnerability caused by the integration of the Alpha Finance Lab protocol, which was attacked. The rebalancer has now removed all&amp;hellip;</description></item><item><title>Colonial Pipeline</title><link>https://0xtracer.xyz/incidents/2021-05-07-colonial-pipeline/</link><pubDate>Fri, 07 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-07-colonial-pipeline/</guid><description>On May 7, 2021, Colonial Pipeline, the largest oil and gas pipeline operator in the United States, was targeted by a ransomware attack. The ransomware attack involved national critical infrastructure, which caused glo&amp;hellip;</description></item><item><title>Value DeFi</title><link>https://0xtracer.xyz/incidents/2021-05-07-value-defi/</link><pubDate>Fri, 07 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-07-value-defi/</guid><description>DeFi protocol ValueDeFi is suspected of being hacked again after being hacked on the 5th. ValueDeFi reminds users in the community, &amp;ldquo;All non-50/50 transaction pools of the project have been used. Please stop purchasin&amp;hellip;</description></item><item><title>Hpool</title><link>https://0xtracer.xyz/incidents/2021-05-06-hpool/</link><pubDate>Thu, 06 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-06-hpool/</guid><description>In response to users reporting that the official website of Hpool could not be opened, Hpool officially responded that the front end of the official website was attacked by DDOS.</description></item><item><title>Value DeFi</title><link>https://0xtracer.xyz/incidents/2021-05-05-value-defi/</link><pubDate>Wed, 05 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-05-value-defi/</guid><description>Value DeFi stated that at 11:22 on May 5th, the attacker reinitialized the fund pool and set the operator role to himself, and _stakeToken was set to HACKEDMONEY. The attacker controlled the pool and called government&amp;hellip;</description></item><item><title>Mask Network</title><link>https://0xtracer.xyz/incidents/2021-05-04-mask-network/</link><pubDate>Tue, 04 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-04-mask-network/</guid><description>The Mask Network official stated that the contract address of the second round of ITO was attacked by robots, and the address has been officially blacklisted.</description></item><item><title>Fei Protocol</title><link>https://0xtracer.xyz/incidents/2021-05-02-fei-protocol/</link><pubDate>Sun, 02 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-02-fei-protocol/</guid><description>Fei Labs, the development team of the decentralized stablecoin project Fei Protocol, tweeted that a vulnerability involving the ETH joint curve contract was discovered and disclosed on May 2 and the contract was immed&amp;hellip;</description></item><item><title>Spartan Protocol</title><link>https://0xtracer.xyz/incidents/2021-05-02-spartan-protocol/</link><pubDate>Sun, 02 May 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-05-02-spartan-protocol/</guid><description>Inflated pool share calculation via flash loan before liquidity removal</description></item><item><title>Hotbit</title><link>https://0xtracer.xyz/incidents/2021-04-29-hotbit/</link><pubDate>Thu, 29 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-29-hotbit/</guid><description>Hotbit said that it suffered a serious cyber attack on April 29th, which caused a large number of basic services to be paralyzed. At the same time, the attacker tried to hack into Hotbit&amp;rsquo;s wallet, but this behavior wa&amp;hellip;</description></item><item><title>Uranium Finance</title><link>https://0xtracer.xyz/incidents/2021-04-28-uranium-finance/</link><pubDate>Wed, 28 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-28-uranium-finance/</guid><description>Swap function used wrong decimal constant, enabling massive drain</description></item><item><title>FTX</title><link>https://0xtracer.xyz/incidents/2021-04-24-ftx/</link><pubDate>Sat, 24 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-24-ftx/</guid><description>At 00:35 on April 24th, SBF, the co-founder of the FTX exchange, tweeted that the website suffered a small DDOS attack. User funds and core systems will not be affected, only the throughput of API and GUI will be affe&amp;hellip;</description></item><item><title>Thodex</title><link>https://0xtracer.xyz/incidents/2021-04-21-thodex/</link><pubDate>Wed, 21 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-21-thodex/</guid><description>Six siblings of Turkish exchange Thodex executives and CEO have been formally arrested, a Turkish court said. And Thodex CEO Faruk Fatih Özer disappeared, leaving behind a collapsed exchange with total losses estimate&amp;hellip;</description></item><item><title>EasyFi</title><link>https://0xtracer.xyz/incidents/2021-04-19-easyfi/</link><pubDate>Mon, 19 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-19-easyfi/</guid><description>Founder&amp;rsquo;s MetaMask seed phrase compromised via remote attack</description></item><item><title>Celsius</title><link>https://0xtracer.xyz/incidents/2021-04-16-celsius/</link><pubDate>Fri, 16 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-16-celsius/</guid><description>Encrypted lending service Celsius has discovered a data breach in one of its third-party service providers, which has exposed the personal information of its customers. According to the email, the hacker gained access&amp;hellip;</description></item><item><title>PancakeSwap</title><link>https://0xtracer.xyz/incidents/2021-04-12-pancakeswap/</link><pubDate>Mon, 12 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-12-pancakeswap/</guid><description>According to sources, since April 12, 2021, a person who has access to Binance Smart Chain account 0x35f16a46d3cf19010d28578a8b02dfa3cb4095a1 (PancakeSwap administrator account) has stolen 59,765 Cakes (approximately&amp;hellip;</description></item><item><title>Polkatrain</title><link>https://0xtracer.xyz/incidents/2021-04-05-polkatrain/</link><pubDate>Mon, 05 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-05-polkatrain/</guid><description>Polkatrain, an ecological IDO platform of Polkadot, had an accident this morning. According to SlowMist analysis, the contract in question is the POLT_LBP contract of the Polkatrain project. This contract has a swap f&amp;hellip;</description></item><item><title>Force DAO</title><link>https://0xtracer.xyz/incidents/2021-04-04-force-dao/</link><pubDate>Sun, 04 Apr 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-04-04-force-dao/</guid><description>The DeFi quantitative hedge fund Force DAO posted a blog stating that it was responsible for the previous attack and has implemented procedures to ensure that any such incidents are mitigated in the future. A total of&amp;hellip;</description></item><item><title>Acer</title><link>https://0xtracer.xyz/incidents/2021-03-20-acer/</link><pubDate>Sat, 20 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-20-acer/</guid><description>Renowned computer maker Acer has been hit by a ransomware gang, REvil, demanding up to $50 million in XMR to decrypt the company&amp;rsquo;s computers and not leak data on the dark web. The ransomware gang announced on their da&amp;hellip;</description></item><item><title>Turtle.dex</title><link>https://0xtracer.xyz/incidents/2021-03-20-turtle-dex/</link><pubDate>Sat, 20 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-20-turtle-dex/</guid><description>According to BSC news, Turtle.dex has run away, taking away about 9,000 BNB, worth more than 2 million U.S. dollars, and the website and telegram group have been deleted. BSC news refers to this as a well-thought-out&amp;hellip;</description></item><item><title>SIL.Finance</title><link>https://0xtracer.xyz/incidents/2021-03-18-sil-finance/</link><pubDate>Thu, 18 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-18-sil-finance/</guid><description>DeFi gathers reasonable financial services SIL.Finance contract has high-risk loopholes. Later, SIL.Finance issued an article saying that the incident was caused by a vulnerability in the smart contract permissions, w&amp;hellip;</description></item><item><title>Iron Finance</title><link>https://0xtracer.xyz/incidents/2021-03-16-iron-finance/</link><pubDate>Tue, 16 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-16-iron-finance/</guid><description>Recently, Iron Finance, a stablecoin mortgage platform based on Binance Chain, was attacked. Two vFarm liquidity pools (50% IRON—50% SIL pool; 50% IRON—50% BUSD pool) lost a total of 170,000 US dollars. Later, the off&amp;hellip;</description></item><item><title>Multiple DeFi protocols</title><link>https://0xtracer.xyz/incidents/2021-03-15-multiple-defi-protocols/</link><pubDate>Mon, 15 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-15-multiple-defi-protocols/</guid><description>Many DeFi protocol websites on BSC (Binance Smart Chain) were attacked by DNS, including Cream Finance and BSC header DEX PancakeSwap. The attacker requested users to submit personal private keys or mnemonics through&amp;hellip;</description></item><item><title>TSD</title><link>https://0xtracer.xyz/incidents/2021-03-15-tsd/</link><pubDate>Mon, 15 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-15-tsd/</guid><description>A cross-chain stablecoin (TSD) on ETH and BSC stated that malicious attackers used TSD DAO to mint 11.8 billion TSD tokens in their accounts and sold them all on Pancakeswap. The specific process is that True Seignior&amp;hellip;</description></item><item><title>TryRoll</title><link>https://0xtracer.xyz/incidents/2021-03-14-tryroll/</link><pubDate>Sun, 14 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-14-tryroll/</guid><description>The community token platform TryRoll was suspected of being attacked, and the tokens issued based on it were sold in a large amount on Uniswap. Among them, WHALE lost 1,362 ETH, FWB lost 797 ETH, KARMA lost 155 ETH, J&amp;hellip;</description></item><item><title>HSO</title><link>https://0xtracer.xyz/incidents/2021-03-10-hso/</link><pubDate>Wed, 10 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-10-hso/</guid><description>The oracle project HSO on the Huobi Eco-Chain HECO carried out IDO and ran away with 30,000 HT. The website and TELEGRAM could not be opened. Later, under the full promotion of HECO core code contribution team Star La&amp;hellip;</description></item><item><title>DODO</title><link>https://0xtracer.xyz/incidents/2021-03-09-dodo/</link><pubDate>Tue, 09 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-09-dodo/</guid><description>The decentralized exchange DODO announced the progress of the attack on some fund pools. The main reason for this attack was that the crowdfunding fund pool contract initialization function did not prevent repeated ca&amp;hellip;</description></item><item><title>CNA</title><link>https://0xtracer.xyz/incidents/2021-03-05-cna/</link><pubDate>Fri, 05 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-05-cna/</guid><description>CNA, one of the largest insurance companies in the United States, paid a ransom of US$40 million (approximately 257 million yuan) after being attacked by ransomware in March to regain control of its network. The compa&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2021-03-05-curve-finance/</link><pubDate>Fri, 05 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-05-curve-finance/</guid><description>Curve Finance tweeted that a vulnerability was found in the Pool Factory v1 version of the fund pool, and it is recommended that v1 users use crv.finance to withdraw funds immediately. Curve.fi and Pool Factory v2 fun&amp;hellip;</description></item><item><title>Meerkat Finance</title><link>https://0xtracer.xyz/incidents/2021-03-04-meerkat-finance/</link><pubDate>Thu, 04 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-04-meerkat-finance/</guid><description>Deployer modified vault contracts to drain funds one day after launch</description></item><item><title>Gab</title><link>https://0xtracer.xyz/incidents/2021-03-01-gab/</link><pubDate>Mon, 01 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-01-gab/</guid><description>The 70 GB data of Gab, a social networking platform that supports Bitcoin, was hacked. Gab has handed over the hacked data to the reporting website Distributed Denial of Secrets. Emma Best, founder of Distributed Deni&amp;hellip;</description></item><item><title>SeascapeNetwork</title><link>https://0xtracer.xyz/incidents/2021-03-01-seascapenetwork/</link><pubDate>Mon, 01 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-01-seascapenetwork/</guid><description>The game ecosystem platform SeascapeNetwork stated that the private key of an early investor was stolen after the token was released today, which led to hackers obtaining 18,750 CWS in the investor&amp;rsquo;s wallet. According&amp;hellip;</description></item><item><title>Tether</title><link>https://0xtracer.xyz/incidents/2021-03-01-tether/</link><pubDate>Mon, 01 Mar 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-03-01-tether/</guid><description>Tether officially tweeted that forged documents allegedly &amp;ldquo;between Tether personnel and representatives of Deltec Bank &amp;amp; Trust and other institutions&amp;rdquo; are circulating online. In addition, Tether officially received a&amp;hellip;</description></item><item><title>Armor</title><link>https://0xtracer.xyz/incidents/2021-02-28-armor/</link><pubDate>Sun, 28 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-28-armor/</guid><description>DeFi Insurance Agreement The Armor team claimed that some team members were scammed by OTC and were defrauded of 1.2 million ARMOR tokens. The scammers have already dumped all tokens for a profit of 600 ETH (approxima&amp;hellip;</description></item><item><title>Furucombo</title><link>https://0xtracer.xyz/incidents/2021-02-27-furucombo/</link><pubDate>Sat, 27 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-27-furucombo/</guid><description>Fake AAVE v2 implementation tricked proxy into stealing approvals</description></item><item><title>Yeld.finance</title><link>https://0xtracer.xyz/incidents/2021-02-27-yeld-finance/</link><pubDate>Sat, 27 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-27-yeld-finance/</guid><description>The DAI pool of Yeld.finance, the DeFi revenue aggregator, was attacked by a lightning loan, resulting in a loss of 160,000 DAI, involving more than 10 users. Tether, TrueUSD and USDC were not affected. According to r&amp;hellip;</description></item><item><title>Primitive Finance</title><link>https://0xtracer.xyz/incidents/2021-02-22-primitive-finance/</link><pubDate>Mon, 22 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-22-primitive-finance/</guid><description>A serious loophole has been discovered in the Primitive Finance smart contract on the Ethereum chain options agreement. Since the contract cannot be upgraded or suspended, the official chose to hack the smart contract&amp;hellip;</description></item><item><title>Cryptopia</title><link>https://0xtracer.xyz/incidents/2021-02-20-cryptopia/</link><pubDate>Sat, 20 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-20-cryptopia/</guid><description>According to Stuff.co.nz, hackers took approximately 62,000 New Zealand dollars (45,000 USD) worth of cryptocurrency from the troubled exchange. The investigation revealed that the hacker accessed a dormant wallet tha&amp;hellip;</description></item><item><title>F2Pool</title><link>https://0xtracer.xyz/incidents/2021-02-19-f2pool/</link><pubDate>Fri, 19 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-19-f2pool/</guid><description>F2Pool was attacked by DDos, and some addresses experienced short-term failures, which have been restored.</description></item><item><title>UL</title><link>https://0xtracer.xyz/incidents/2021-02-19-ul/</link><pubDate>Fri, 19 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-19-ul/</guid><description>UL LLC (commonly known as Underwriters Laboratories) suffered a ransomware attack that encrypted its server and caused the server to shut down the system when it recovered. To prevent the attack from spreading further&amp;hellip;</description></item><item><title>KMA</title><link>https://0xtracer.xyz/incidents/2021-02-18-kma/</link><pubDate>Thu, 18 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-18-kma/</guid><description>According to CryptoPotato, the ransomware group DoppelPaymer launched another attack, this time leaking sensitive data of KMA, the North American branch of automaker Kia Motors. Criminals demand Bitcoin to pay the ran&amp;hellip;</description></item><item><title>Verge</title><link>https://0xtracer.xyz/incidents/2021-02-15-verge/</link><pubDate>Mon, 15 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-15-verge/</guid><description>The privacy coin Verge (XVG) underwent a reorganization of 560,000 blockchains after a 51% attack on Monday. Lucas Nuzzi of CoinMetrics stated that the history of token transactions over 200 days has been deleted.</description></item><item><title>Alpha Finance</title><link>https://0xtracer.xyz/incidents/2021-02-13-alpha-finance/</link><pubDate>Sat, 13 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-13-alpha-finance/</guid><description>Cascading exploit via Alpha Homora and Iron Bank CREAM interaction</description></item><item><title>BT.Finance</title><link>https://0xtracer.xyz/incidents/2021-02-09-bt-finance/</link><pubDate>Tue, 09 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-09-bt-finance/</guid><description>DeFi revenue aggregator BT.Finance tweeted, &amp;ldquo;It was hacked. The attacked strategies include ETH, USDC and USDT. Other strategies are not affected. BT.Finance withdrawal fee protection has reduced the loss of this atta&amp;hellip;</description></item><item><title>KeepChange</title><link>https://0xtracer.xyz/incidents/2021-02-08-keepchange/</link><pubDate>Mon, 08 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-08-keepchange/</guid><description>Bitcoin trading market KeepChange stated that the exchange received a request for withdrawal from a customer&amp;rsquo;s account to an address belonging to the attacker, and a control subsystem of the platform suspended the req&amp;hellip;</description></item><item><title>ArmorFi</title><link>https://0xtracer.xyz/incidents/2021-02-05-armorfi/</link><pubDate>Fri, 05 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-05-armorfi/</guid><description>The DeFi insurance project ArmorFi has paid a $1.5 million bug bounty to the white hat hacker Alexander Schlindwein. Because the hacker discovered a &amp;ldquo;critical loophole&amp;rdquo; in the agreement, and may cause all the company&amp;rsquo;&amp;hellip;</description></item><item><title>YFI</title><link>https://0xtracer.xyz/incidents/2021-02-05-yfi/</link><pubDate>Fri, 05 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-05-yfi/</guid><description>Yearn v1 yDAI vault was attacked and the attackers stole 2.8 million US dollars. Banteg, the core developer of Yearn finance, subsequently stated that the attacker received 2.8 million US dollars and vault lost 11 mil&amp;hellip;</description></item><item><title>Multi Financial</title><link>https://0xtracer.xyz/incidents/2021-02-01-multi-financial/</link><pubDate>Mon, 01 Feb 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-02-01-multi-financial/</guid><description>According to feedback from Binance Smartchain investors, on February 1st, the BSC listed project Multi Financial ran away, and it only took about 5000 BNB in ​​one day. The compromised investor stated that it had repo&amp;hellip;</description></item><item><title>popcornswap</title><link>https://0xtracer.xyz/incidents/2021-01-31-popcornswap/</link><pubDate>Sun, 31 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-31-popcornswap/</guid><description>Another DeFi project popcornswap on Binance Smart Chain has gone. It is reported that some users said in the community that the project used cake&amp;rsquo;s LP, the contract was open source but there was no audit, and the LP w&amp;hellip;</description></item><item><title>refi.finance</title><link>https://0xtracer.xyz/incidents/2021-01-27-refi-finance/</link><pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-27-refi-finance/</guid><description>Weibo user “CryptoBlanker” broke the news: the refi.finance project party directly used the reserved setBoardroom() function to change the Boardroom address to the address it deployed. Light BAS was taken away 2,600,&amp;hellip;</description></item><item><title>SushiSwap</title><link>https://0xtracer.xyz/incidents/2021-01-27-sushiswap/</link><pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-27-sushiswap/</guid><description>On January 27, 2021, SushiSwap was attacked again. This attack took advantage of the fact that DIGG itself did not have a WETH trading pair, and the attacker created this trading pair and manipulated the initial trans&amp;hellip;</description></item><item><title>BuyUCoin</title><link>https://0xtracer.xyz/incidents/2021-01-25-buyucoin/</link><pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-25-buyucoin/</guid><description>User information of BuyUCoin, an Indian cryptocurrency exchange, was leaked, and personal data of more than 325,000 people appeared in the database of the hacker organization. According to Indian news media Inc42, a h&amp;hellip;</description></item><item><title>Firo</title><link>https://0xtracer.xyz/incidents/2021-01-20-firo/</link><pubDate>Wed, 20 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-20-firo/</guid><description>The privacy coin project Firo stated on Twitter that it is currently under 51% attacks and it is recommended that users do not trade during this period until the network returns to normal.</description></item><item><title>Gretchen Whitmer</title><link>https://0xtracer.xyz/incidents/2021-01-11-gretchen-whitmer/</link><pubDate>Mon, 11 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-11-gretchen-whitmer/</guid><description>On January 11, the Michigan state police claimed that an anonymous person mailed death threats to Governor Gretchen Whitmer and employees of the state in an attempt to collect $2 million worth of Bitcoin. The letter s&amp;hellip;</description></item><item><title>Tor</title><link>https://0xtracer.xyz/incidents/2021-01-11-tor/</link><pubDate>Mon, 11 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-11-tor/</guid><description>The Tor network was attacked and all v3 onion addresses were inaccessible. Darknetdaily posted that this seems to be a new type of attack that will affect the entire network and cause the consensus authorization node&amp;hellip;</description></item><item><title>ZKS</title><link>https://0xtracer.xyz/incidents/2021-01-06-zks/</link><pubDate>Wed, 06 Jan 2021 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2021-01-06-zks/</guid><description>The ZKSwap token ZKS, a decentralized exchange based on ZK Rollup, has problems due to Uniswap adding liquidity. ZKSwap officially stated that the reason for this phenomenon was that someone used scripts to brush tran&amp;hellip;</description></item><item><title>Cover Protocol</title><link>https://0xtracer.xyz/incidents/2020-12-28-cover-protocol/</link><pubDate>Mon, 28 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-28-cover-protocol/</guid><description>Blacksmith contract exploited to mint unlimited COVER tokens</description></item><item><title>Altilly</title><link>https://0xtracer.xyz/incidents/2020-12-26-altilly/</link><pubDate>Sat, 26 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-26-altilly/</guid><description>The Altilly Exchange platform was attacked by legally authorized access. According to the official weighing, the attacker gained access to 30 BTC and 12,000 USDT and stole them while controlling the server.</description></item><item><title>Livecoin</title><link>https://0xtracer.xyz/incidents/2020-12-24-livecoin/</link><pubDate>Thu, 24 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-24-livecoin/</guid><description>According to sources, the Russian cryptocurrency exchange Livecoin previously stated that it was attacked and lost control of its server. Later, Livecoin announced its closure on Twitter and provided a link to its new&amp;hellip;</description></item><item><title>EXMO</title><link>https://0xtracer.xyz/incidents/2020-12-21-exmo/</link><pubDate>Mon, 21 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-21-exmo/</guid><description>A major security breach in the British cryptocurrency exchange Exmo has caused the platform to freeze all withdrawals. Since EXMO has a separate server for each cryptocurrency, the hacking only affected six cryptocurr&amp;hellip;</description></item><item><title>Warp Finance</title><link>https://0xtracer.xyz/incidents/2020-12-18-warp-finance/</link><pubDate>Fri, 18 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-18-warp-finance/</guid><description>DeFi portal DefiPrime said on Twitter this morning that at 06:34 on December 18th, Beijing time, the liquidity LP token mortgage loan DeFi agreement Warp Finance suffered a lightning loan attack and about 8 million US&amp;hellip;</description></item><item><title>DeTrade Fund</title><link>https://0xtracer.xyz/incidents/2020-12-14-detrade-fund/</link><pubDate>Mon, 14 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-14-detrade-fund/</guid><description>According to reports, DeTrade Fund was the biggest scam on Friday, the platform allowing any user to profit by putting money into its arbitrage system and defrauding more than 1,400 ETH raised in a pre-sale. Twitter u&amp;hellip;</description></item><item><title>Nexus Mutual</title><link>https://0xtracer.xyz/incidents/2020-12-14-nexus-mutual/</link><pubDate>Mon, 14 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-14-nexus-mutual/</guid><description>DeFi insurance agreement Nexus Mutual stated on Twitter that the personal address of its founder Hugh Karp was attacked by a platform user, stolen 370,000 NXM and lost more than 8 million US dollars. The official said&amp;hellip;</description></item><item><title>OneCoin</title><link>https://0xtracer.xyz/incidents/2020-12-14-onecoin/</link><pubDate>Mon, 14 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-14-onecoin/</guid><description>On December 14th, the Procuratorate of Cordoba, Argentina prosecuted 12 scammers involved in the OneCoin cryptocurrency Ponzi scheme and ordered their arrests last Thursday. Eight of them have been arrested. It was pr&amp;hellip;</description></item><item><title>Aeternity</title><link>https://0xtracer.xyz/incidents/2020-12-08-aeternity/</link><pubDate>Tue, 08 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-08-aeternity/</guid><description>Aeternity (AE) was attacked by 51% yesterday. According to core members of the Aeternity community, the 51% attack caused a loss of more than 39 million AE tokens. The official team is solving the problem. The main da&amp;hellip;</description></item><item><title>Foxconn</title><link>https://0xtracer.xyz/incidents/2020-12-08-foxconn/</link><pubDate>Tue, 08 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-08-foxconn/</guid><description>Foxconn was attacked by ransomware, which temporarily caused problems in its production facilities in Mexico and resulted in the theft of data. It is reported that the ransomware attack occurred on Thanksgiving weeken&amp;hellip;</description></item><item><title>Poloniex</title><link>https://0xtracer.xyz/incidents/2020-12-05-poloniex/</link><pubDate>Sat, 05 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-05-poloniex/</guid><description>The cryptocurrency exchange Poloniex issued an announcement stating that since December 5th at 6:30 UTC (14:30 Beijing time), its service was interrupted due to a distributed denial of service (DDoS) attack. At presen&amp;hellip;</description></item><item><title>BTC Markets</title><link>https://0xtracer.xyz/incidents/2020-12-01-btc-markets/</link><pubDate>Tue, 01 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-01-btc-markets/</guid><description>On December 1, the Australian cryptocurrency exchange BTC Markets accidentally disclosed the full names and email addresses of all its customers in marketing emails sent to customers, which may expose all customers to&amp;hellip;</description></item><item><title>Compounder.Finance</title><link>https://0xtracer.xyz/incidents/2020-12-01-compounder-finance/</link><pubDate>Tue, 01 Dec 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-12-01-compounder-finance/</guid><description>At 3:00 pm on December 1st, Beijing time, the security technical team discovered through Skynet that the Compounder.Finance project located at the address of 0x0b283b107f70d23250f882fbfe7216c38abbd7ca has undergone mu&amp;hellip;</description></item><item><title>Rari Capital</title><link>https://0xtracer.xyz/incidents/2020-11-30-rari-capital/</link><pubDate>Mon, 30 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-30-rari-capital/</guid><description>DeFi robo-advisor Rari Capital released an official Twitter saying that contract vulnerabilities have been fixed with the cooperation of Quantstamp and no funds have been lost. Previously, due to loopholes in the RGT&amp;hellip;</description></item><item><title>Saffron Finance</title><link>https://0xtracer.xyz/incidents/2020-11-30-saffron-finance/</link><pubDate>Mon, 30 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-30-saffron-finance/</guid><description>DeFi asset mortgage platform Saffron Finance issued an announcement stating that Epoch 1 redemption errors caused by contract loopholes resulted in 50 million DAI deposits deposited by Epoch 1 being locked for 8 weeks&amp;hellip;</description></item><item><title>SushiSwap</title><link>https://0xtracer.xyz/incidents/2020-11-30-sushiswap/</link><pubDate>Mon, 30 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-30-sushiswap/</guid><description>The liquidity mining project SushiSwap (SUSHI) community governor 0xMaki announced in the Discord group that the SushiSwap vulnerability has been fixed, and the lost funds (approximately US$10,000) will be compensated&amp;hellip;</description></item><item><title>Compound</title><link>https://0xtracer.xyz/incidents/2020-11-26-compound/</link><pubDate>Thu, 26 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-26-compound/</guid><description>Compound&amp;rsquo;s price feed error caused the liquidation of $90 million in assets. According to DeBank founder, the huge liquidation of Compound was caused by the dramatic fluctuations in the DAI price of the oracle informa&amp;hellip;</description></item><item><title>Pickle Finance</title><link>https://0xtracer.xyz/incidents/2020-11-21-pickle-finance/</link><pubDate>Sat, 21 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-21-pickle-finance/</guid><description>Malicious jar used to drain DAI from Pickle strategy via unverified calls</description></item><item><title>88mph</title><link>https://0xtracer.xyz/incidents/2020-11-18-88mph/</link><pubDate>Wed, 18 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-18-88mph/</guid><description>On November 18th, an attacker exploited the vulnerability to obtain $100,000 in MPH tokens. After that, 88mph discovered a vulnerability in MPHinter, the MPH token minting contract, which could allow a potential attac&amp;hellip;</description></item><item><title>Origin Protocol</title><link>https://0xtracer.xyz/incidents/2020-11-17-origin-protocol/</link><pubDate>Tue, 17 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-17-origin-protocol/</guid><description>Flash loan reentrancy attack on OUSD stablecoin vault</description></item><item><title>Value DeFi</title><link>https://0xtracer.xyz/incidents/2020-11-14-value-defi/</link><pubDate>Sat, 14 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-14-value-defi/</guid><description>Multi-stablecoin vault flash loan attack despite anti-flashloan claims</description></item><item><title>Cheese Bank</title><link>https://0xtracer.xyz/incidents/2020-11-13-cheese-bank/</link><pubDate>Fri, 13 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-13-cheese-bank/</guid><description>Cheese Bank, a decentralized autonomous digital banking platform based on Ethereum, suffered a loss of USD 3.3 million due to a hacker attack. Hackers conducted a series of malicious lending operations on platforms su&amp;hellip;</description></item><item><title>Liquid</title><link>https://0xtracer.xyz/incidents/2020-11-13-liquid/</link><pubDate>Fri, 13 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-13-liquid/</guid><description>Mike Kayamori, CEO of cryptocurrency exchange Liquid, posted a notice on the official website that a data leakage security incident occurred on the exchange on November 13. A domain hosting provider that manages a cor&amp;hellip;</description></item><item><title>Akropolis</title><link>https://0xtracer.xyz/incidents/2020-11-12-akropolis/</link><pubDate>Thu, 12 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-12-akropolis/</guid><description>DAI savings pool reentrancy via ERC-777 callback on deposit</description></item><item><title>SharkTron</title><link>https://0xtracer.xyz/incidents/2020-11-10-sharktron/</link><pubDate>Tue, 10 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-10-sharktron/</guid><description>According to FXStreet, the community accused Daniel Wood of the DeFi project based on the Tron blockchain and the anonymous developer of the JustSwap whitelist project SharkTron for running away. Although the specific&amp;hellip;</description></item><item><title>ElectrumSV</title><link>https://0xtracer.xyz/incidents/2020-11-09-electrumsv/</link><pubDate>Mon, 09 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-09-electrumsv/</guid><description>On November 9th, a user named &amp;ldquo;aaron67&amp;rdquo; posted about his BSV theft experience, saying that please stop using the multisig accumulator multi-signature solution implemented by ElectrumSV immediately. The locking script&amp;hellip;</description></item><item><title>Grin</title><link>https://0xtracer.xyz/incidents/2020-11-08-grin/</link><pubDate>Sun, 08 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-08-grin/</guid><description>According to reports, the Grin network has recently suffered 51% attacks. An unknown entity controlled more than 57% of network computing power on Saturday. According to the Grin website, the team advises people to wa&amp;hellip;</description></item><item><title>Ledger</title><link>https://0xtracer.xyz/incidents/2020-11-06-ledger/</link><pubDate>Fri, 06 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-06-ledger/</guid><description>Phishing and scams targeting Ledger wallet owners are increasing, and one of the scam websites obtained more than 1,150,000 XRP from victims. This scam uses phishing emails to direct users to a fake Ledger website. On&amp;hellip;</description></item><item><title>PercentFinance</title><link>https://0xtracer.xyz/incidents/2020-11-04-percentfinance/</link><pubDate>Wed, 04 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-04-percentfinance/</guid><description>DeFi lending platform PercentFinance wrote in a blog on November 4 that some currency markets encountered problems that could cause users&amp;rsquo; funds to be permanently locked. The team frozen currency markets specifically&amp;hellip;</description></item><item><title>Axion Network</title><link>https://0xtracer.xyz/incidents/2020-11-02-axion-network/</link><pubDate>Mon, 02 Nov 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-11-02-axion-network/</guid><description>Cointelegraph reported that on November 2, a project called Axion Network launched the token AXN and was hacked a few hours after it was hacked. 79 billion AXN were minted and sold to the market. The token price was a&amp;hellip;</description></item><item><title>EtherCrash</title><link>https://0xtracer.xyz/incidents/2020-10-30-ethercrash/</link><pubDate>Fri, 30 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-30-ethercrash/</guid><description>Recently, AlonGal, the chief technology officer of the cybercrime intelligence company HudsonRock, tweeted that on October 27, the EtherCrash cold wallet that claimed to be &amp;ldquo;the most mature and largest gambling game i&amp;hellip;</description></item><item><title>Harvest Finance</title><link>https://0xtracer.xyz/incidents/2020-10-26-harvest-finance/</link><pubDate>Mon, 26 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-26-harvest-finance/</guid><description>Flash loan used to manipulate USDC/USDT Curve pool price</description></item><item><title>Electrum</title><link>https://0xtracer.xyz/incidents/2020-10-12-electrum/</link><pubDate>Mon, 12 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-12-electrum/</guid><description>An investigation by ZDNet revealed that hackers stole $22 million from users of Bitcoin wallet Electrum by enticing users to install fake software updates. And this technique was highest in 2018. Since this attack was&amp;hellip;</description></item><item><title>Curve Finance</title><link>https://0xtracer.xyz/incidents/2020-10-11-curve-finance/</link><pubDate>Sun, 11 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-11-curve-finance/</guid><description>Recently, a user suffered a phishing attack while visiting the Curve exchange website, and lost 20 Bitcoins. It is reported that the fraud group used the Google advertising system to purchase Google search ads, preten&amp;hellip;</description></item><item><title>WLEO</title><link>https://0xtracer.xyz/incidents/2020-10-11-wleo/</link><pubDate>Sun, 11 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-11-wleo/</guid><description>The WLEO contract of the Ethereum project was hacked, resulting in the theft of $42,000 worth of funds. The hackers stole Ethereum from the pool of the decentralized exchange Uniswap by casting WLEO to themselves and&amp;hellip;</description></item><item><title>UniCats</title><link>https://0xtracer.xyz/incidents/2020-10-10-unicats/</link><pubDate>Sat, 10 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-10-unicats/</guid><description>Encrypted wallet ZenGo researcher Alex Manuskin revealed that UniCats, a so-called &amp;ldquo;yield farming platform&amp;rdquo; based on the Ethereum network, is suspected of stealing at least $200,000 in encryption from several users, i&amp;hellip;</description></item><item><title>DeFi Saver</title><link>https://0xtracer.xyz/incidents/2020-10-08-defi-saver/</link><pubDate>Thu, 08 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-08-defi-saver/</guid><description>The decentralized wallet imToken tweeted that users reported that 310,000 DAI had been reduced, which conflicted with DeFi Saver Exchange. imToken recommends that the automated management system of collateralized bond&amp;hellip;</description></item><item><title>Coindaq.io</title><link>https://0xtracer.xyz/incidents/2020-10-05-coindaq-io/</link><pubDate>Mon, 05 Oct 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-10-05-coindaq-io/</guid><description>A user named Kazuo Kusunose posted on Google forums that he had lost $15,000 due to an encryption scam discovered in Google ads. Allegedly, the suspicious website named Coindaq.io tried to use the digital renminbi tha&amp;hellip;</description></item><item><title>Eminence Finance</title><link>https://0xtracer.xyz/incidents/2020-09-29-eminence-finance/</link><pubDate>Tue, 29 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-29-eminence-finance/</guid><description>Unaudited contract exploited within hours of deployment, partial refund</description></item><item><title>GemSwap</title><link>https://0xtracer.xyz/incidents/2020-09-26-gemswap/</link><pubDate>Sat, 26 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-26-gemswap/</guid><description>On September 26, the SushiSwap imitation project named GemSwap was exposed and LP was taken away. The query found that the project posted a tweet at around 15:00 today and revealed that it was attacked by the develope&amp;hellip;</description></item><item><title>KuCoin</title><link>https://0xtracer.xyz/incidents/2020-09-26-kucoin/</link><pubDate>Sat, 26 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-26-kucoin/</guid><description>KuCoin exchange issued an announcement stating that KuCoin detected large withdrawals of Bitcoin and ERC-20 tokens in multiple hot wallets in the early morning of the 26th, and the deposit and withdrawal services have&amp;hellip;</description></item><item><title>KuCoin</title><link>https://0xtracer.xyz/incidents/2020-09-25-kucoin/</link><pubDate>Fri, 25 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-25-kucoin/</guid><description>Exchange hot wallet private keys compromised, most funds recovered</description></item><item><title>LV Finance</title><link>https://0xtracer.xyz/incidents/2020-09-20-lv-finance/</link><pubDate>Sun, 20 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-20-lv-finance/</guid><description>According to the intelligence of the SlowMist Zone, the LV Finance project of the Ethereum mining project is suspected of running away within an hour and 4 million have been transferred away. Unlike previous projects,&amp;hellip;</description></item><item><title>Soda</title><link>https://0xtracer.xyz/incidents/2020-09-20-soda/</link><pubDate>Sun, 20 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-20-soda/</guid><description>The financial blogger &amp;ldquo;Super Bitcoin&amp;rdquo; stated on Weibo that Mr. Huai (weibo username &amp;ldquo;crash X&amp;rdquo;) participated in the liquidity mining project Soda, and suddenly discovered a loophole in which 20,000 ETH can be directly&amp;hellip;</description></item><item><title>Bantiample</title><link>https://0xtracer.xyz/incidents/2020-09-19-bantiample/</link><pubDate>Sat, 19 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-19-bantiample/</guid><description>The Bantiample team, a project on the Binance Smart Chain, has cashed out 3000 BNB to run away. At present, the main developer of the team has deleted the Telegram account, and the project token BMAP has fallen by mor&amp;hellip;</description></item><item><title>Arbistar</title><link>https://0xtracer.xyz/incidents/2020-09-16-arbistar/</link><pubDate>Wed, 16 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-16-arbistar/</guid><description>According to Spanish prosecutors, they are investigating Arbistar&amp;rsquo;s alleged manipulation of a Bitcoin trading scam. The disappearance of investor funds has affected 32,000 households who cannot use their savings inves&amp;hellip;</description></item><item><title>bZx</title><link>https://0xtracer.xyz/incidents/2020-09-14-bzx/</link><pubDate>Mon, 14 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-14-bzx/</guid><description>bZx officially tweeted that at 3:28 am Eastern time (15:30, September 13th, Beijing time), we began to study the decline in TVL of the agreement. By 6:18 AM EST (18:30, September 13th, Beijing time), we confirmed that&amp;hellip;</description></item><item><title>Coral</title><link>https://0xtracer.xyz/incidents/2020-09-10-coral/</link><pubDate>Thu, 10 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-10-coral/</guid><description>The wRAM of the EOS ecological DeFi liquidity mining project Coral was attacked by hackers and lost more than 120,000 EOS.</description></item><item><title>SYFI</title><link>https://0xtracer.xyz/incidents/2020-09-10-syfi/</link><pubDate>Thu, 10 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-10-syfi/</guid><description>Amplify, a user of DeFi, discovered a bug in SYFI, a smart contract for DeFi, and made 747 ETH on a single transaction, but from other users. The project crashed.</description></item><item><title>EMD</title><link>https://0xtracer.xyz/incidents/2020-09-09-emd/</link><pubDate>Wed, 09 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-09-emd/</guid><description>According to SlowMist Zone intelligence, EOS project EMD is suspected to be on the run. To date, EmeraldMine1 has transferred 780,000 USDT, 490,000 EOS and 56,000 DFS to Account SJI111111111, and 121,000 EOS has been&amp;hellip;</description></item><item><title>Soft Finance</title><link>https://0xtracer.xyz/incidents/2020-09-09-soft-finance/</link><pubDate>Wed, 09 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-09-soft-finance/</guid><description>A user with a Twitter account named Amplify revealed that he made a profit of US$250,000 from a system vulnerability in the new DeFi project Soft Finance.</description></item><item><title>Banco Estado</title><link>https://0xtracer.xyz/incidents/2020-09-08-banco-estado/</link><pubDate>Tue, 08 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-08-banco-estado/</guid><description>Banco Estado Bank, one of the three largest banks in Chile, had to shut down its nationwide business on the 7th due to a cyber attack by REvil ransomware.</description></item><item><title>ETERBASE</title><link>https://0xtracer.xyz/incidents/2020-09-08-eterbase/</link><pubDate>Tue, 08 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-08-eterbase/</guid><description>European encrypted exchange ETERBASE has been hacked, resulting in the theft of some hot wallets and the loss of more than $5.4 million in assets.</description></item><item><title>Argentine National Immigration Service</title><link>https://0xtracer.xyz/incidents/2020-09-07-argentine-national-immigration-service/</link><pubDate>Mon, 07 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-07-argentine-national-immigration-service/</guid><description>It is said that hackers used the encrypted virus NetWalker to enter the database and steal information from federal agencies. The dark web payment page linked in the ransomware description shows that the hacker initia&amp;hellip;</description></item><item><title>TSEM</title><link>https://0xtracer.xyz/incidents/2020-09-07-tsem/</link><pubDate>Mon, 07 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-07-tsem/</guid><description>Hackers carried out ransomware attacks against Tower Semiconductor Ltd (TSEM), a maker of wireless chips and camera sensors listed on the Israeli Nasdaq, and demanded hundreds of thousands of dollars in bitcoin ransom&amp;hellip;</description></item><item><title>CherryFi</title><link>https://0xtracer.xyz/incidents/2020-09-06-cherryfi/</link><pubDate>Sun, 06 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-06-cherryfi/</guid><description>The transfer logic of TRON&amp;rsquo;s DeFi project CherryFi calls the safeTransfer function to perform specific transfer operations. However, the USDT transfer logic does not return a value, which causes the safeTransfer call&amp;hellip;</description></item><item><title>Chainlink</title><link>https://0xtracer.xyz/incidents/2020-09-04-chainlink/</link><pubDate>Fri, 04 Sep 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-09-04-chainlink/</guid><description>Nine Chainlink node operators were subjected to so-called &amp;ldquo;spam attacks.&amp;rdquo; The attackers obtained approximately 700 ETH (worth approximately $335,000 at the time) from their &amp;ldquo;hot wallets&amp;rdquo;.</description></item><item><title>Electrum</title><link>https://0xtracer.xyz/incidents/2020-08-30-electrum/</link><pubDate>Sun, 30 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-30-electrum/</guid><description>GitHub user &amp;ldquo;1400 BitcoinStolen&amp;rdquo; said that a huge amount of his Bitcoin money had disappeared in the hack. This user uses a bitcoin purse Electrum, the user has no security update the software, so when he transfers th&amp;hellip;</description></item><item><title>Empire Market</title><link>https://0xtracer.xyz/incidents/2020-08-30-empire-market/</link><pubDate>Sun, 30 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-30-empire-market/</guid><description>The well-known darknet market Empire Market has closed its operations. When it exited, the website defrauded about 2638 bitcoins from 1.3 million users, worth nearly 30 million U.S. dollars.</description></item><item><title>ETC</title><link>https://0xtracer.xyz/incidents/2020-08-30-etc/</link><pubDate>Sun, 30 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-30-etc/</guid><description>Bitfly tweeted that another massive 51% attack on ETC today resulted in the restructuring of more than 7,000 blocks, equivalent to about two days of mining time. All missing blocks are removed from balances that have&amp;hellip;</description></item><item><title>Ledger</title><link>https://0xtracer.xyz/incidents/2020-08-30-ledger/</link><pubDate>Sun, 30 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-30-ledger/</guid><description>Encrypted wallet provider Ledger recently experienced database leaks and wallet vulnerabilities, putting users&amp;rsquo; bitcoins at risk. The chief technology officer of Ledger stated that in terms of database leakage, the at&amp;hellip;</description></item><item><title>Degen.Money</title><link>https://0xtracer.xyz/incidents/2020-08-28-degen-money/</link><pubDate>Fri, 28 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-28-degen-money/</guid><description>Twitter users reported that DeFi&amp;rsquo;s liquidity mining project Degen.Money exploited a double approval vulnerability to get users&amp;rsquo; Money. The first authorization gives the pledge contract, and the second authorization gi&amp;hellip;</description></item><item><title>NZX</title><link>https://0xtracer.xyz/incidents/2020-08-28-nzx/</link><pubDate>Fri, 28 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-28-nzx/</guid><description>The New Zealand Stock Exchange (NZX) went offline for two days in a row due to a cyber attack. NZX said on Tuesday it was first hit by a distributed denial of service (DDoS) attack from abroad. The emails threatening&amp;hellip;</description></item><item><title>BTC ERA</title><link>https://0xtracer.xyz/incidents/2020-08-25-btc-era/</link><pubDate>Tue, 25 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-25-btc-era/</guid><description>Some cybercriminals have been counterfeiting the BTC ERA trading platform in order to infect potential users with malware. The cybersecurity company discovered that the perpetrators had been sending emails allegedly f&amp;hellip;</description></item><item><title>Coinbit</title><link>https://0xtracer.xyz/incidents/2020-08-25-coinbit/</link><pubDate>Tue, 25 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-25-coinbit/</guid><description>South Korea’s third largest digital currency exchange, Coinbit, was seized and investigated by South Korean police. Its chairman and operator were suspected of internal transactions and manipulation of market prices&amp;hellip;.</description></item><item><title>Filecoin</title><link>https://0xtracer.xyz/incidents/2020-08-25-filecoin/</link><pubDate>Tue, 25 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-25-filecoin/</guid><description>The Filecoin space race started, and the CDSI alliance node &amp;ldquo;t02398&amp;rdquo; suffered a large number of malicious and illegal attacks. The attacker sent a large number of messages through the filtered whitelist to block the n&amp;hellip;</description></item><item><title>CryptoTrader.Tax</title><link>https://0xtracer.xyz/incidents/2020-08-24-cryptotrader-tax/</link><pubDate>Mon, 24 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-24-cryptotrader-tax/</guid><description>According to Coindesk, a hacker has stolen more than 1,000 user data from crypto-tax service provider CryptoTrader.Tax and is trying to sell information on dark web forums.</description></item><item><title>YFValue</title><link>https://0xtracer.xyz/incidents/2020-08-24-yfvalue/</link><pubDate>Mon, 24 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-24-yfvalue/</guid><description>The DeFi project YFValue (YFV) officially released an announcement stating that the team found a loophole in the YFV pledge pool yesterday, and malicious participants used the vulnerability to reset the YFV timer in t&amp;hellip;</description></item><item><title>KuCoin</title><link>https://0xtracer.xyz/incidents/2020-08-19-kucoin/</link><pubDate>Wed, 19 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-19-kucoin/</guid><description>KuCoin, a cryptocurrency exchange, warned of fraudulent websites using its brand to try to steal cryptocurrencies. The website provides false rewards to induce users to deposit digital assets.</description></item><item><title>OKEx</title><link>https://0xtracer.xyz/incidents/2020-08-18-okex/</link><pubDate>Tue, 18 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-18-okex/</guid><description>OKEx has confirmed that the latest 51% attack caused ETC losses of approximately $5.6 million. Out of concerns about the security of the ETC mainnet, it is considering removing ETC from the exchange. According to a re&amp;hellip;</description></item><item><title>Bitcoin ATM</title><link>https://0xtracer.xyz/incidents/2020-08-15-bitcoin-atm/</link><pubDate>Sat, 15 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-15-bitcoin-atm/</guid><description>The Hong Kong police arrested three men on suspicion of defrauding nearly 230,000 Hong Kong dollars (US$30,000) from Bitcoin ATMs. This is the first such case in Hong Kong. These exchanges suspect that criminals have&amp;hellip;</description></item><item><title>BASED</title><link>https://0xtracer.xyz/incidents/2020-08-14-based/</link><pubDate>Fri, 14 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-14-based/</guid><description>The DeFi liquidity farming anonymous project BASED officially announced that it would redeploy the pledge pool. The official tweeted that a hacker tried to freeze &amp;ldquo;Pool1&amp;rdquo; permanently, but the attempt failed, and &amp;ldquo;Pool&amp;hellip;</description></item><item><title>Ledger</title><link>https://0xtracer.xyz/incidents/2020-08-14-ledger/</link><pubDate>Fri, 14 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-14-ledger/</guid><description>A cryptocurrency trader tweeted that a hacker hacked into his Ledger crypto wallet and stole more than 100,000 ERC-20 tokens. In addition, the trader said his account was safe because he had just reset his password la&amp;hellip;</description></item><item><title>YAM</title><link>https://0xtracer.xyz/incidents/2020-08-13-yam/</link><pubDate>Thu, 13 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-13-yam/</guid><description>On August 13, 2020, the well-known Ethereum DeFi project YAM officially issued a post on Twitter indicating that there were loopholes in the contract. The price plummeted by 99% within 24 hours, resulting in the “perm&amp;hellip;</description></item><item><title>NUGS/NEXE</title><link>https://0xtracer.xyz/incidents/2020-08-11-nugs-nexe/</link><pubDate>Tue, 11 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-11-nugs-nexe/</guid><description>Two small-scale token projects, NUGS and NEXE, appeared to have committed &amp;ldquo;travel fraud&amp;rdquo; shortly after being launched on Uniswap. The NUGS project blamed this move on a &amp;ldquo;smart contract vulnerability&amp;rdquo;. On its official&amp;hellip;</description></item><item><title>Domestic cloud server</title><link>https://0xtracer.xyz/incidents/2020-08-07-domestic-cloud-server/</link><pubDate>Fri, 07 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-07-domestic-cloud-server/</guid><description>Tencent Security Threat Intelligence Center has detected a large number of attacks originating from overseas IP and some domestic IP against domestic cloud server tenants. The attacker blasted into the server through&amp;hellip;</description></item><item><title>ETC</title><link>https://0xtracer.xyz/incidents/2020-08-06-etc/</link><pubDate>Thu, 06 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-06-etc/</guid><description>Bitfly officially tweeted that ETC encountered another large-scale 51% attack today. The attack has resulted in the reorganization of more than 4000 blocks. Bitfly reminded that unless the official notified further, t&amp;hellip;</description></item><item><title>Jon Prosser</title><link>https://0xtracer.xyz/incidents/2020-08-05-jon-prosser/</link><pubDate>Wed, 05 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-05-jon-prosser/</guid><description>According to a tweet published by Jon Prosser on August 5, its YouTube channel with 262,000 subscribers was hacked, the channel name was changed to &amp;ldquo;NASA [news]&amp;rdquo;, and a live broadcast about SpaceX CEO Elon Ma Skr gave&amp;hellip;</description></item><item><title>Opyn</title><link>https://0xtracer.xyz/incidents/2020-08-04-opyn/</link><pubDate>Tue, 04 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-04-opyn/</guid><description>Opyn, an on-chain options platform, disclosed that its Ethereum put options were maliciously exploited by external participants. Opyn pointed out that all other Opyn contracts except Ethereum put options are not affec&amp;hellip;</description></item><item><title>CWT</title><link>https://0xtracer.xyz/incidents/2020-08-01-cwt/</link><pubDate>Sat, 01 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-01-cwt/</guid><description>CWT, the fifth largest travel company in the United States, agreed to pay $4.5 million worth of bitcoin to hackers who hijacked its computer systems.</description></item><item><title>ETC</title><link>https://0xtracer.xyz/incidents/2020-08-01-etc/</link><pubDate>Sat, 01 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-01-etc/</guid><description>Bitfly tweeted that today, the ETC blockchain has undergone a chain reorganization of 3693 blocks at a block height of 10904146. This causes all state construction nodes to stop synchronizing. The ETC blockchain did n&amp;hellip;</description></item><item><title>YYFI</title><link>https://0xtracer.xyz/incidents/2020-08-01-yyfi/</link><pubDate>Sat, 01 Aug 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-08-01-yyfi/</guid><description>YFII&amp;rsquo;s hard fork project YYFI has completely become an &amp;ldquo;exit scam&amp;rdquo; in the early morning of August 1. From the very beginning, this project seems to be determined to prepare for its own run.</description></item><item><title>2gether</title><link>https://0xtracer.xyz/incidents/2020-07-31-2gether/</link><pubDate>Fri, 31 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-31-2gether/</guid><description>Spanish cryptocurrency exchange 2gether has been maliciously hacked, affecting around 5,500 users who trade on the platform. According to a statement by Spanish police dated 22 February 2022, a team from the Ministry&amp;hellip;</description></item><item><title>Ledger</title><link>https://0xtracer.xyz/incidents/2020-07-25-ledger/</link><pubDate>Sat, 25 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-25-ledger/</guid><description>On July 25, 2020, there was unauthorized access to Ledger&amp;rsquo;s database, resulting in data leakage. The leaked data includes e-commerce and marketing data, but payment information and encrypted assets are safe. Ledger’s&amp;hellip;</description></item><item><title>Twitter</title><link>https://0xtracer.xyz/incidents/2020-07-16-twitter/</link><pubDate>Thu, 16 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-16-twitter/</guid><description>In the early hours of this morning, many celebrity politicians and some companies&amp;rsquo; Twitter accounts were attacked by hackers, and these Twitter accounts all published relevant digital currency phishing scam informatio&amp;hellip;</description></item><item><title>Cashaa</title><link>https://0xtracer.xyz/incidents/2020-07-11-cashaa/</link><pubDate>Sat, 11 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-11-cashaa/</guid><description>Cashaa, a UK-based cryptocurrency exchange, said hackers stole 336 Bitcoins from a wallet on the exchange. The company has now stopped all transactions related to cryptocurrency.</description></item><item><title>BitClub</title><link>https://0xtracer.xyz/incidents/2020-07-10-bitclub/</link><pubDate>Fri, 10 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-10-bitclub/</guid><description>From April 2014 to December 2019, the BitClub network was a fraudulent scheme that solicited funds from investors in exchange for stakes in so-called cryptocurrency mining pools and rewarded their investments, accordi&amp;hellip;</description></item><item><title>Bitcoin Gold</title><link>https://0xtracer.xyz/incidents/2020-07-10-bitcoin-gold/</link><pubDate>Fri, 10 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-10-bitcoin-gold/</guid><description>The team that developed Bitcoin Gold (BTG), a bifurcated project, has announced a 51% attack. According to the official disclosure, THE BTG network has been hit by 51% attacks lasting nearly 10 days. However, on July&amp;hellip;</description></item><item><title>Russian blockchain voting platform</title><link>https://0xtracer.xyz/incidents/2020-07-10-russian-blockchain-voting-platform/</link><pubDate>Fri, 10 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-10-russian-blockchain-voting-platform/</guid><description>In the recent referendum on constitutional reform, 1.14 million Russians voted through the blockchain platform, but their data has been made public on the Internet and can be accessed directly from state-owned servers&amp;hellip;</description></item><item><title>Ravencoin</title><link>https://0xtracer.xyz/incidents/2020-07-03-ravencoin/</link><pubDate>Fri, 03 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-03-ravencoin/</guid><description>Ravencoin&amp;rsquo;s community member CryptoScope team discovered that there are vulnerabilities in the Ravencoin blockchain, which has been cast by unknown people. 1.5% of the total RVN is 21 billion. Tron Black, the develope&amp;hellip;</description></item><item><title>VETH</title><link>https://0xtracer.xyz/incidents/2020-07-01-veth/</link><pubDate>Wed, 01 Jul 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-07-01-veth/</guid><description>Coingecko researcher Daryllautk tweeted that VETH suffered a hacker attack on the decentralized exchange Uniswap. The hacker stole 919,299 VETH (worth $900,000) using only 0.9ETH. After the attack, VETH officially sta&amp;hellip;</description></item><item><title>Balancer</title><link>https://0xtracer.xyz/incidents/2020-06-30-balancer/</link><pubDate>Tue, 30 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-30-balancer/</guid><description>According to DeBank Twitter, hackers once again used dYdX&amp;rsquo;s lightning loan to attack the COMP trading pair in Balancer&amp;rsquo;s part of the liquidity pool, and took away the unreceived COMP rewards from the pool to make a pr&amp;hellip;</description></item><item><title>Balancer</title><link>https://0xtracer.xyz/incidents/2020-06-29-balancer/</link><pubDate>Mon, 29 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-29-balancer/</guid><description>The Balancer liquidity pool was attacked by Lightning Loan and lost $500,000. The two losses suffered by Balacer are STA and STONK. At present, the liquidity of these two token pools has been exhausted. Both STA and S&amp;hellip;</description></item><item><title>Web3 DeFi</title><link>https://0xtracer.xyz/incidents/2020-06-25-web3-defi/</link><pubDate>Thu, 25 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-25-web3-defi/</guid><description>The malicious Web3 applications &amp;ldquo;phishing dapps&amp;rdquo; were discovered in a recent study, they pretend to be legitimate applications or services to steal cryptocurrencies. For example, since MakerDAO officially closed the s&amp;hellip;</description></item><item><title>Atomic Loans</title><link>https://0xtracer.xyz/incidents/2020-06-24-atomic-loans/</link><pubDate>Wed, 24 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-24-atomic-loans/</guid><description>Atomic Loans, issued a decision on vulnerability disclosure and suspension of new loan requests. The decision shows that the security researcher samczsun privately disclosed two vulnerabilities in the currently deploy&amp;hellip;</description></item><item><title>DDM</title><link>https://0xtracer.xyz/incidents/2020-06-23-ddm/</link><pubDate>Tue, 23 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-23-ddm/</guid><description>The official DeFi money market agreement DMM Twitter said that during $DMG public sale today, its telegram was unfortunately brigaded by malicious actors who impersonated the DMM Foundation with sole the intent of ste&amp;hellip;</description></item><item><title>Wirecard</title><link>https://0xtracer.xyz/incidents/2020-06-19-wirecard/</link><pubDate>Fri, 19 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-19-wirecard/</guid><description>About $2.13 billion worth of cash is missing from one of Wirecard&amp;rsquo;s trust accounts, and the crypto debit card provider cannot as yet account for the money. In a statement, the crypto debit card provider blamed &amp;ldquo;spurio&amp;hellip;</description></item><item><title>Bancor</title><link>https://0xtracer.xyz/incidents/2020-06-18-bancor/</link><pubDate>Thu, 18 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-18-bancor/</guid><description>Due to the unverified safeTransferFrom () function in the new Bancor network contract, user funds are about to be depleted. The Bancor team stated: 1. A security vulnerability was discovered in the new Bancor Network&amp;hellip;</description></item><item><title>DeversiFi</title><link>https://0xtracer.xyz/incidents/2020-06-10-deversifi/</link><pubDate>Wed, 10 Jun 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-06-10-deversifi/</guid><description>The new version of DeversiFi encountered a vulnerability in less than a week after it was launched. The official said that it would be fixed as soon as possible. The cause of this vulnerability was that a trader tried&amp;hellip;</description></item><item><title>Filecoin</title><link>https://0xtracer.xyz/incidents/2020-05-28-filecoin/</link><pubDate>Thu, 28 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-28-filecoin/</guid><description>6Block technical staff found a serious vulnerability in the Filecoin code, through which the unlimited issuance of Filecoin can be achieved. The 6Block stated that, for proving the effectiveness of the vulnerability,&amp;hellip;</description></item><item><title>LMEX</title><link>https://0xtracer.xyz/incidents/2020-05-27-lmex/</link><pubDate>Wed, 27 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-27-lmex/</guid><description>The LMEX Stock Exchange&amp;rsquo;s community issued a notice on the adjustment of exchange operations, stating that the platform was hacked and stolen and lost 150,000 USDT, which caused the platform to have a low debt. The de&amp;hellip;</description></item><item><title>TBTC</title><link>https://0xtracer.xyz/incidents/2020-05-18-tbtc/</link><pubDate>Mon, 18 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-18-tbtc/</guid><description>After about 48 hours of testing on both the Ethereum and Bitcoin mainnets, the Keep team decided to trigger the 10-day emergency deposit moratorium allowed by the TBTCSystem contract, the team found that deposits were&amp;hellip;</description></item><item><title>Loopring</title><link>https://0xtracer.xyz/incidents/2020-05-07-loopring/</link><pubDate>Thu, 07 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-07-loopring/</guid><description>Loopring has appeared a serious front-end error, the private key material is set within a range of 32-bit integer, you can find all user private key pairs by brute force method, due to the user&amp;rsquo;s EdDSA key pair is act&amp;hellip;</description></item><item><title>Youbi</title><link>https://0xtracer.xyz/incidents/2020-05-06-youbi/</link><pubDate>Wed, 06 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-06-youbi/</guid><description>According to the official news from Youbi Exchange, Youbi has encountered heavy network-traffic DDoS attacks for three consecutive days since the platform coin subscription was launched on May 06, which caused the ser&amp;hellip;</description></item><item><title>BitSG</title><link>https://0xtracer.xyz/incidents/2020-05-01-bitsg/</link><pubDate>Fri, 01 May 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-05-01-bitsg/</guid><description>-The official announcement of BitSG Exchange stated that its websites bitsg and app suffered from uninterrupted DDOS continues attacks, resulting in the inability to log in normally during certain periods.</description></item><item><title>Felix</title><link>https://0xtracer.xyz/incidents/2020-04-30-felix/</link><pubDate>Thu, 30 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-30-felix/</guid><description>EOS gambling DApp suffered fake EOS attack</description></item><item><title>Hegic</title><link>https://0xtracer.xyz/incidents/2020-04-25-hegic/</link><pubDate>Sat, 25 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-25-hegic/</guid><description>Hegic: There are 152.2 ETH (about 28,537 USD) permanently locked in the contract pool of unexercised put / call options. Out of the 19 contracts, 16 are put options (DAI is locked) and 3 are call options (ETH is locke&amp;hellip;</description></item><item><title>Lendf.Me</title><link>https://0xtracer.xyz/incidents/2020-04-19-lendf-me/</link><pubDate>Sun, 19 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-19-lendf-me/</guid><description>DeFi lending protocol Lendf.Me was hacked.</description></item><item><title>Uniswap</title><link>https://0xtracer.xyz/incidents/2020-04-18-uniswap/</link><pubDate>Sat, 18 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-18-uniswap/</guid><description>The attacker used a reentrancy attack to steal funds (containing approximately 1,278 ETH) from Uniswap&amp;rsquo;s ETH-imBTC Uniswap liquidity pool.</description></item><item><title>Bisq</title><link>https://0xtracer.xyz/incidents/2020-04-08-bisq/</link><pubDate>Wed, 08 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-08-bisq/</guid><description>Hacker Exploits Flaw in Decentralized Bitcoin Exchange Bisq to Steal $250K.</description></item><item><title>Cocos-BCX</title><link>https://0xtracer.xyz/incidents/2020-04-03-cocos-bcx/</link><pubDate>Fri, 03 Apr 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-04-03-cocos-bcx/</guid><description>Cocos-BCX has verified with the exchange, conducted internal investigations and concluded that asset loss and malicious selling that occurred are due to the malicious theft of the mapping wallet information. After ver&amp;hellip;</description></item><item><title>Ledger Chrome</title><link>https://0xtracer.xyz/incidents/2020-03-25-ledger-chrome/</link><pubDate>Wed, 25 Mar 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-03-25-ledger-chrome/</guid><description>Attacker creates malicious Ledger Chrome extensions and tricks users into downloading malicious Ledger Chrome extensions through Google search ad serving and other methods to steal users&amp;rsquo; cryptocurrency. So far, it is&amp;hellip;</description></item><item><title>MakerDao</title><link>https://0xtracer.xyz/incidents/2020-03-12-makerdao/</link><pubDate>Thu, 12 Mar 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-03-12-makerdao/</guid><description>Due to the congestion of Ethereum, the gas soared, and the liquidated ETH was sold at a price of 0 US dollars using the MakerDao auction loophole.</description></item><item><title>Trident Crypto Fund</title><link>https://0xtracer.xyz/incidents/2020-03-05-trident-crypto-fund/</link><pubDate>Thu, 05 Mar 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-03-05-trident-crypto-fund/</guid><description>The crypto fund Trident Crypto Fund was hacked and the data of 266,000 users was leaked. The database containing email addresses, mobile numbers, encrypted passwords and IP addresses was uploaded to various file-shari&amp;hellip;</description></item><item><title>Josh Jones</title><link>https://0xtracer.xyz/incidents/2020-02-22-josh-jones/</link><pubDate>Sat, 22 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-22-josh-jones/</guid><description>Josh Jones, founder of Bitcoin Builder and Mt.Gox&amp;rsquo;s second largest creditor, has had $45 million worth of digital currency stolen.</description></item><item><title>bZx</title><link>https://0xtracer.xyz/incidents/2020-02-18-bzx/</link><pubDate>Tue, 18 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-18-bzx/</guid><description>bZx was attacked again with an estimated loss of $645,000 of ETH</description></item><item><title>FCoin</title><link>https://0xtracer.xyz/incidents/2020-02-17-fcoin/</link><pubDate>Mon, 17 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-17-fcoin/</guid><description>The FCoin exchange claimed that due to funding difficulties, the fund reserves could not be redeemed for user withdrawals, and the estimated amount of funds that could not be redeemed was between 7,000-13,000 BTC.</description></item><item><title>VBITEX</title><link>https://0xtracer.xyz/incidents/2020-02-17-vbitex/</link><pubDate>Mon, 17 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-17-vbitex/</guid><description>VBITEX platform was hacked, resulting in malicious manipulation of platform data and theft of virtual assets.</description></item><item><title>bZx</title><link>https://0xtracer.xyz/incidents/2020-02-15-bzx/</link><pubDate>Sat, 15 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-15-bzx/</guid><description>DeFi lending protocol bZx exploited, may lose up to $350,000.</description></item><item><title>IOTA</title><link>https://0xtracer.xyz/incidents/2020-02-12-iota/</link><pubDate>Wed, 12 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-12-iota/</guid><description>IOTA has shut down its entire network this week after hackers exploited a vulnerability in the official IOTA wallet app to steal user funds.Estimated loss of 850000 MIOTA (valued at us $2.3 million).</description></item><item><title>Altsbit</title><link>https://0xtracer.xyz/incidents/2020-02-05-altsbit/</link><pubDate>Wed, 05 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-05-altsbit/</guid><description>The Italian cryptocurrency exchange Altsbit was hacked. As of now, the value of stolen Bitcoin and Ether is about 70,000 U.S. dollars. The website stated that it will be closed after partial refund of client funds.</description></item><item><title>LuckLambo104</title><link>https://0xtracer.xyz/incidents/2020-02-03-lucklambo104/</link><pubDate>Mon, 03 Feb 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-02-03-lucklambo104/</guid><description>The hacker at the beginning of the TKnzni address continued to launch a transaction rollback attack on the LuckLambo104 contract address beginning with TGsyJF by creating an attack contract, and profited 6,588 TRX. Th&amp;hellip;</description></item><item><title>Bitcoin Gold</title><link>https://0xtracer.xyz/incidents/2020-01-23-bitcoin-gold/</link><pubDate>Thu, 23 Jan 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-01-23-bitcoin-gold/</guid><description>Last week, BTG encountered two 51% computing power attacks, and both recharge transactions to exchanges were cancelled, involving about 1,900 BTG and 5267 BTG, which was close to 90,000 US dollars.</description></item><item><title>Electrum</title><link>https://0xtracer.xyz/incidents/2020-01-19-electrum/</link><pubDate>Sun, 19 Jan 2020 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2020-01-19-electrum/</guid><description>Electrum suffers from &amp;ldquo;Update Phishing&amp;rdquo; theft. (The &amp;ldquo;Update Phishing&amp;rdquo; attack continues, and the older version (less than 3.3.4) is still under threat.)</description></item><item><title>NULS</title><link>https://0xtracer.xyz/incidents/2019-12-23-nuls/</link><pubDate>Mon, 23 Dec 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-12-23-nuls/</guid><description>The well-known public chain NULS suffered a hacker attack and lost nearly $480,000 worth of NULS tokens. The SlowMist security team analyzed and found that the reason for the attack was that there was a loophole in th&amp;hellip;</description></item><item><title>VeChain</title><link>https://0xtracer.xyz/incidents/2019-12-14-vechain/</link><pubDate>Sat, 14 Dec 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-12-14-vechain/</guid><description>The VeChain Foundation, a non-profit organization supporting the VeChain public blockchain platform, announced that their repurchase address was leaked at 12:27 PM Eastern Time on Friday (ie 1:27 AM Beijing time) . Th&amp;hellip;</description></item><item><title>Tron Lounge</title><link>https://0xtracer.xyz/incidents/2019-12-06-tron-lounge/</link><pubDate>Fri, 06 Dec 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-12-06-tron-lounge/</guid><description>The hacker at the beginning of the TFNsSk address initiated a transaction rollback attack on the Tron Lounge DApp contract beginning with TRON TR3n2D through a self-created contract, and has made a profit of 54,653 TR&amp;hellip;</description></item><item><title>Vertcoin</title><link>https://0xtracer.xyz/incidents/2019-12-02-vertcoin/</link><pubDate>Mon, 02 Dec 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-12-02-vertcoin/</guid><description>The chief maintainer of Vertcoin James Lovejoy revealed in an attack report on December 2 that a malicious entity targeted the cryptocurrency exchange Bittrex to manipulate the Vertcoin blockchain. The hacker paid at&amp;hellip;</description></item><item><title>Upbit</title><link>https://0xtracer.xyz/incidents/2019-11-27-upbit/</link><pubDate>Wed, 27 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-27-upbit/</guid><description>34.2M ETH drained from Upbit hot wallet</description></item><item><title>Dice</title><link>https://0xtracer.xyz/incidents/2019-11-21-dice/</link><pubDate>Thu, 21 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-21-dice/</guid><description>The hackers launched a trade rollback attack on TRON&amp;rsquo;s Dice contracts through self-created contracts, and have gained 18,808 TRX to date.</description></item><item><title>GateHub</title><link>https://0xtracer.xyz/incidents/2019-11-20-gatehub/</link><pubDate>Wed, 20 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-20-gatehub/</guid><description>Gatehub Crypto Wallet Data Breach Compromises Passwords of 1.4M Users.</description></item><item><title>VinDAX</title><link>https://0xtracer.xyz/incidents/2019-11-08-vindax/</link><pubDate>Fri, 08 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-08-vindax/</guid><description>Vietnamese cryptocurrency exchange VinDAX has been hacked, losing at least $500,000 in cryptocurrency.</description></item><item><title>BetHash</title><link>https://0xtracer.xyz/incidents/2019-11-07-bethash/</link><pubDate>Thu, 07 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-07-bethash/</guid><description>BetHash&amp;rsquo;s betting game mechanism allows players to guess the ratio of the number between 0-100 and the random number given by the system to win the bonus of the corresponding odds. The smaller the bet number, the grea&amp;hellip;</description></item><item><title>BitMEX</title><link>https://0xtracer.xyz/incidents/2019-11-01-bitmex/</link><pubDate>Fri, 01 Nov 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-11-01-bitmex/</guid><description>BitMEX Compromises User Data in Email Gaffe.</description></item><item><title>BitDice</title><link>https://0xtracer.xyz/incidents/2019-10-12-bitdice/</link><pubDate>Sat, 12 Oct 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-10-12-bitdice/</guid><description>Hackers launched a &amp;ldquo;fake EOS&amp;rdquo; attack on BitDice, a guessing game, earning more than 4,000 EOS and transferring it to EXMO, ChangeNOW and other exchanges.</description></item><item><title>Safuwallet</title><link>https://0xtracer.xyz/incidents/2019-10-11-safuwallet/</link><pubDate>Fri, 11 Oct 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-10-11-safuwallet/</guid><description>ZenGo co-founder Ouriel Ohayon reported on Twitter that the wallet extension SAFU Wallet apparently steals large amounts of money by injecting malicious code into users. A white hat hacker said that by inspecting the&amp;hellip;</description></item><item><title>WOTOKEN</title><link>https://0xtracer.xyz/incidents/2019-10-08-wotoken/</link><pubDate>Tue, 08 Oct 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-10-08-wotoken/</guid><description>WOTOKEN, involved in a cryptocurrency pyramid selling case involving more than 7.7 billion yuan, has opened court and completed the trail in public and at Binhai County People&amp;rsquo;s Court in Yancheng City, in which six ma&amp;hellip;</description></item><item><title>Fusion</title><link>https://0xtracer.xyz/incidents/2019-09-28-fusion/</link><pubDate>Sat, 28 Sep 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-09-28-fusion/</guid><description>Fusion released According to an official announcement, the Fusion transaction wallet (0x8e6bDa71f3f0F49dDD29969De79aFCFac4457379) was attacked on September 28, resulting in the theft of 10 million native FSN and 3.5 m&amp;hellip;</description></item><item><title>Coinhouse</title><link>https://0xtracer.xyz/incidents/2019-09-14-coinhouse/</link><pubDate>Sat, 14 Sep 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-09-14-coinhouse/</guid><description>Coinhouse Suffers Phishing Attack, User Names and Emails Accessed.</description></item><item><title>skreosladder</title><link>https://0xtracer.xyz/incidents/2019-09-02-skreosladder/</link><pubDate>Mon, 02 Sep 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-09-02-skreosladder/</guid><description>&amp;ldquo;skreosladder&amp;rdquo; has been attacked again by hackers, who have earned thousands of EOS. The hacker has attacked the game several times and has been blacklisted by the project side, but the hacker still used the trumpet t&amp;hellip;</description></item><item><title>CoinTiger</title><link>https://0xtracer.xyz/incidents/2019-08-17-cointiger/</link><pubDate>Sat, 17 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-17-cointiger/</guid><description>The cold wallet of the CoinTiger exchange was stolen, and the 400 million PTT of the Proton chain disappeared. According to the exchange announcement, they discovered that the cold wallet storing PTT was hacked during&amp;hellip;</description></item><item><title>Bitstamp</title><link>https://0xtracer.xyz/incidents/2019-08-13-bitstamp/</link><pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-13-bitstamp/</guid><description>There is a vulnerability in Bitstamp, which can be used by attackers to view a large number of sensitive information such as user IDs and bank CARDS, seriously threatening the information security of users.</description></item><item><title>SKR EOS</title><link>https://0xtracer.xyz/incidents/2019-08-13-skr-eos/</link><pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-13-skr-eos/</guid><description>SKR EOS games have again been attacked by hackers, who have now earned about 4,000 EOS. After analysis, hackers still use the transaction congestion attack, operating multiple trumpet attacks on the game in turn.</description></item><item><title>SKReos</title><link>https://0xtracer.xyz/incidents/2019-08-10-skreos/</link><pubDate>Sat, 10 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-10-skreos/</guid><description>The skreosladder game has been attacked by hackers again, and hackers have now profited thousands of EOS. After preliminary analysis, hackers still use transaction crowding attacks, but the difference is that hackers&amp;hellip;</description></item><item><title>Royale</title><link>https://0xtracer.xyz/incidents/2019-08-04-royale/</link><pubDate>Sun, 04 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-04-royale/</guid><description>EOS Royale has been attacked by hackers, who have gained around 18,000 EOS.</description></item><item><title>LuckyClover</title><link>https://0xtracer.xyz/incidents/2019-08-02-luckyclover/</link><pubDate>Fri, 02 Aug 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-08-02-luckyclover/</guid><description>Multiple hackers have launched a series of attacks on the EOS game LuckyClover, earning thousands of EOS.</description></item><item><title>MULTI.TODAY</title><link>https://0xtracer.xyz/incidents/2019-07-27-multi-today/</link><pubDate>Sat, 27 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-27-multi-today/</guid><description>The attacker adopted a &amp;ldquo;card position&amp;rdquo; rollback betting method for the game mechanics: the first gameplay investment of the game is profitable early, and the &amp;ldquo;player&amp;rdquo; deploys the contract to invest at the beginning of&amp;hellip;</description></item><item><title>7Tron</title><link>https://0xtracer.xyz/incidents/2019-07-26-7tron/</link><pubDate>Fri, 26 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-26-7tron/</guid><description>The attackers launched a roll back attack on the contracts, which so far has yielded a total of 67,695 TRX.</description></item><item><title>7Tron</title><link>https://0xtracer.xyz/incidents/2019-07-25-7tron/</link><pubDate>Thu, 25 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-25-7tron/</guid><description>The attackers launched a trade rollback attack on the contracts, which so far has yielded a total of 113,913 TRX.</description></item><item><title>YouHodler</title><link>https://0xtracer.xyz/incidents/2019-07-25-youhodler/</link><pubDate>Thu, 25 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-25-youhodler/</guid><description>The cryptocurrency lending company YouHodler was affected by a data leak that contained information about users on its platform. Some of the data that was released to the market includes bank accounts, passport number&amp;hellip;</description></item><item><title>QuickBit</title><link>https://0xtracer.xyz/incidents/2019-07-24-quickbit/</link><pubDate>Wed, 24 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-24-quickbit/</guid><description>According to QuickBit, the breach resulted in data of users such as names, emails, physical addresses and even card information was exposed. The exchange has said it has estimated about 2% user data was left unprotect&amp;hellip;</description></item><item><title>TronCity</title><link>https://0xtracer.xyz/incidents/2019-07-24-troncity/</link><pubDate>Wed, 24 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-24-troncity/</guid><description>There was an unusually large transaction in the game contract of the TronCity project. The total balance of 257,112 TRX in the game contract was emptied at one time.</description></item><item><title>TronChip</title><link>https://0xtracer.xyz/incidents/2019-07-23-tronchip/</link><pubDate>Tue, 23 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-23-tronchip/</guid><description>Hackers launched a series of attacks on TronChip, earning a total of 61,867 TRX.</description></item><item><title>BitPoint</title><link>https://0xtracer.xyz/incidents/2019-07-12-bitpoint/</link><pubDate>Fri, 12 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-12-bitpoint/</guid><description>On July 12, Japan&amp;rsquo;s BitPoint Japan (BPJ) exchange was hacked, and 3.5 billion yen (32 million U.S. dollars) worth of cryptocurrency in the hot wallet was stolen. After that, BPJ shut down all services of the exchange&amp;hellip;.</description></item><item><title>My Dash Wallet</title><link>https://0xtracer.xyz/incidents/2019-07-11-my-dash-wallet/</link><pubDate>Thu, 11 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-11-my-dash-wallet/</guid><description>My Dash Wallet has been embedded with a malicious script, the malicious script will upload the user&amp;rsquo;s DASH currency account balance, keystore, private key, seed and other key information to &lt;a href="https://api.dashcoinanalyti">https://api.dashcoinanalyti&lt;/a>&amp;hellip;</description></item><item><title>Trezor</title><link>https://0xtracer.xyz/incidents/2019-07-10-trezor/</link><pubDate>Wed, 10 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-10-trezor/</guid><description>An attacker with a stolen device can extract the seed from the device. It takes less than 5 minutes and the necessary materials cost around 100$. This vulnerability affects Trezor One, Trezor T, Keepkey and all other&amp;hellip;</description></item><item><title>Bitmarket</title><link>https://0xtracer.xyz/incidents/2019-07-08-bitmarket/</link><pubDate>Mon, 08 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-08-bitmarket/</guid><description>On July 8, the Polish-based exchange Bitmarket abruptly shut down due to liquidity issues. The shutdown allegedly cost users a total of 2300 bitcoin (approximately $23 million) according to Polish prosecutors. The exc&amp;hellip;</description></item><item><title>Soxex</title><link>https://0xtracer.xyz/incidents/2019-07-04-soxex/</link><pubDate>Thu, 04 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-04-soxex/</guid><description>Soxex exchange has been exposed to abscond with the funds. At present, the website of the exchange has been unable to open, and hundreds of millions of funds of investors have been swept away, involving BTC, ETH, HT,&amp;hellip;</description></item><item><title>TKjoHFN</title><link>https://0xtracer.xyz/incidents/2019-07-04-tkjohfn/</link><pubDate>Thu, 04 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-04-tkjohfn/</guid><description>The hackers launched an attack by rolling back the transaction, and so far, the attack has been profitable.</description></item><item><title>HiGold Game</title><link>https://0xtracer.xyz/incidents/2019-07-03-higold-game/</link><pubDate>Wed, 03 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-03-higold-game/</guid><description>The hacker launched a continuous attack on the HiGold Game and realized the profit.</description></item><item><title>TLGUt5</title><link>https://0xtracer.xyz/incidents/2019-07-02-tlgut5/</link><pubDate>Tue, 02 Jul 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-07-02-tlgut5/</guid><description>The attacker launched multiple roll back attacks on the DApp contract address beginning with TLGUt5. So far, it has gained 45,200 TRX, and the contract balance of the attacked contract is almost zero.</description></item><item><title>Waltonchain</title><link>https://0xtracer.xyz/incidents/2019-06-30-waltonchain/</link><pubDate>Sun, 30 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-30-waltonchain/</guid><description>The mainnet of Waltonchain was suffered coordinated attack, and the problem has been solved through the upgrade of the mainnet.</description></item><item><title>波场超级社区（TRX·μTORRENT SUPER COMMUNITY）</title><link>https://0xtracer.xyz/incidents/2019-06-30-trxtorrent-super-community/</link><pubDate>Sun, 30 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-30-trxtorrent-super-community/</guid><description>At 1:00 am on June 30, the App of Torrent super community was shut down. All of the wallet assets were moved out two weeks ago, and investors are currently unable to cash out.</description></item><item><title>PlusToken</title><link>https://0xtracer.xyz/incidents/2019-06-29-plustoken/</link><pubDate>Sat, 29 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-29-plustoken/</guid><description>PlusToken collapsed. Currently, PlusToken wallets can only be transferred in and cannot be withdrawn. Some investors said that 35 hours after the withdrawal of the coin, the account has not yet arrived. It is suspecte&amp;hellip;</description></item><item><title>SPOKpark</title><link>https://0xtracer.xyz/incidents/2019-06-28-spokpark/</link><pubDate>Fri, 28 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-28-spokpark/</guid><description>Hackers have made a profit of 50,845 TRX by creating multiple contracts to launch a trade rollback attack on SPOKpark, a Tron DApp game. The SPOKpark website is no longer accessible.</description></item><item><title>Bitrue</title><link>https://0xtracer.xyz/incidents/2019-06-27-bitrue/</link><pubDate>Thu, 27 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-27-bitrue/</guid><description>At approximately 1am June 27 (GMT+8), a hacker exploited a vulnerability in Bitrue&amp;rsquo;s Risk Control team&amp;rsquo;s 2nd review process to access the personal funds of about 90 Bitrue users. The hacker used what they learned from&amp;hellip;</description></item><item><title>Bitsane</title><link>https://0xtracer.xyz/incidents/2019-06-27-bitsane/</link><pubDate>Thu, 27 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-27-bitsane/</guid><description>According to Forbes on June 27, Bitsane, an Irish cryptocurrency exchange, disappeared without a trace last week, had lied to as many as 246000 users.</description></item><item><title>Synthetix</title><link>https://0xtracer.xyz/incidents/2019-06-25-synthetix/</link><pubDate>Tue, 25 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-25-synthetix/</guid><description>Synthetix, a synthetic asset issuance platform built on Ethereum, experienced an oracle attack which netted the attacker over 37 million sETH, according to Etherscan. However, the true dollar value is difficult to cal&amp;hellip;</description></item><item><title>yizeslotsbet</title><link>https://0xtracer.xyz/incidents/2019-06-24-yizeslotsbet/</link><pubDate>Mon, 24 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-24-yizeslotsbet/</guid><description>EOS contract yizeslotsbet suffers transfer error prompt, the attacker has already obtained 1,0000 FB token.</description></item><item><title>SKR EOS</title><link>https://0xtracer.xyz/incidents/2019-06-14-skr-eos/</link><pubDate>Fri, 14 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-14-skr-eos/</guid><description>Continuous attack by hackers to SKR EOS, earning thousands of EOS.</description></item><item><title>MGC</title><link>https://0xtracer.xyz/incidents/2019-06-12-mgc/</link><pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-12-mgc/</guid><description>MGC wallet is exposed to carry user assets disappear, users&amp;rsquo; digital assets are aggregated to 0x4f9cxx, 0x2b29xx beginning two addresses in a short time.</description></item><item><title>Roulette</title><link>https://0xtracer.xyz/incidents/2019-06-12-roulette/</link><pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-12-roulette/</guid><description>The hacker has gained 27,000 TRX by launching a trade rollback attack on the DappRoulette contract with a self-created contract.</description></item><item><title>BETX</title><link>https://0xtracer.xyz/incidents/2019-06-11-betx/</link><pubDate>Tue, 11 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-11-betx/</guid><description>The 600 million BETX tokens held by BETX managers were stolen by hacker and sold on the Newdex exchange. Preliminary analysis shows that the cause of this attack is that the private key of BETX project is stolen, and&amp;hellip;</description></item><item><title>TokenStore</title><link>https://0xtracer.xyz/incidents/2019-06-11-tokenstore/</link><pubDate>Tue, 11 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-11-tokenstore/</guid><description>The TokenStore wallet was exposed as a &amp;ldquo;runaway&amp;rdquo;, which swept away billions of investors&amp;rsquo; money, involving BTC, XRP, ETH and other mainstream currencies.</description></item><item><title>Coinroom</title><link>https://0xtracer.xyz/incidents/2019-06-03-coinroom/</link><pubDate>Mon, 03 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-03-coinroom/</guid><description>Polish cryptocurrency exchange Coinroom suddenly shut down its service in April, suspected of defrauding customers and running away with funds. Although the exact amount involved in the fraud is unclear.</description></item><item><title>Kraken</title><link>https://0xtracer.xyz/incidents/2019-06-02-kraken/</link><pubDate>Sun, 02 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-02-kraken/</guid><description>On June 2, Bitcoin flash-crashed on a major Bitcoin trading platform Kraken. The near vertical drop from $11,200 CAD to $100 CAD within moments initially appeared to have resulted from a technical glitch or a fat-fing&amp;hellip;</description></item><item><title>GateHub</title><link>https://0xtracer.xyz/incidents/2019-06-01-gatehub/</link><pubDate>Sat, 01 Jun 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-06-01-gatehub/</guid><description>The attacker controls some of the GateHub database account API permissions, but the user&amp;rsquo;s private key is secure. GateHub officials have identified 103 wallets that were compromised and a total of 18,473 accounts that&amp;hellip;</description></item><item><title>Remitano</title><link>https://0xtracer.xyz/incidents/2019-05-29-remitano/</link><pubDate>Wed, 29 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-29-remitano/</guid><description>Due to the failure to take effective measures against user complaints, XRP buyers have suffered a lot of losses. The cryptocurrency exchange Remitano has announced that it has suspended all XRP deposits and withdrawal&amp;hellip;</description></item><item><title>Poker EOS</title><link>https://0xtracer.xyz/incidents/2019-05-24-poker-eos/</link><pubDate>Fri, 24 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-24-poker-eos/</guid><description>EOS game Poker EOS appears abnormal, which is confirmed to be caused by the disclosure of the private key of the game. The hackers made more than 20,000 EOS in total, and more than 10,000 of them have been transferred&amp;hellip;</description></item><item><title>Coinbase</title><link>https://0xtracer.xyz/incidents/2019-05-22-coinbase/</link><pubDate>Wed, 22 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-22-coinbase/</guid><description>Hackers steal $100,000+ worth of BTC from engineering manager at Crypto Custodian BitGo. Sean Coonce, engineering manager at cryptocurrency custodian BitGo. According to the post, Coonce had over $100,000 siphoned out&amp;hellip;</description></item><item><title>DiceGame</title><link>https://0xtracer.xyz/incidents/2019-05-13-dicegame/</link><pubDate>Mon, 13 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-13-dicegame/</guid><description>The DiceGame game suffered a roll back attack, and the hackers at the TYUcGmi address gained a total of 5,150 TRX.</description></item><item><title>Binance</title><link>https://0xtracer.xyz/incidents/2019-05-08-binance/</link><pubDate>Wed, 08 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-08-binance/</guid><description>Binance has discovered a large scale security breach today, May 7, 2019 at 17:15:24 (UTC). Hackers were able to obtain a large number of user API keys, 2FA codes, and potentially other info. The hackers used a variety&amp;hellip;</description></item><item><title>Binance CEX</title><link>https://0xtracer.xyz/incidents/2019-05-07-binance-cex/</link><pubDate>Tue, 07 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-07-binance-cex/</guid><description>7,000 BTC stolen via phishing, viruses, and API key compromise</description></item><item><title>TronBank</title><link>https://0xtracer.xyz/incidents/2019-05-03-tronbank/</link><pubDate>Fri, 03 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-03-tronbank/</guid><description>At 4:12 AM on May 3, Beijing time, a contract call transferred 26.73 million TRX (valued at RMB 4.27 million) from the TronBank contract, and the contract balance returned to zero. About two hours after the theft, woj&amp;hellip;</description></item><item><title>BitoPro</title><link>https://0xtracer.xyz/incidents/2019-05-02-bitopro/</link><pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-02-bitopro/</guid><description>Taiwan exchange BitoPro&amp;rsquo;s XRP suffered an attack that caused a price crash and is thought to have lost about 7m XRPS.</description></item><item><title>Wheel Of Fortune</title><link>https://0xtracer.xyz/incidents/2019-05-02-wheel-of-fortune/</link><pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-05-02-wheel-of-fortune/</guid><description>The TRON Wheel Of Fortune DApp is being attacked by a transaction rollback, with a total loss of 7,856 TRX, and the attack is still ongoing. Previously, security personnel found that the hacker continued to conduct tr&amp;hellip;</description></item><item><title>eosblue.one</title><link>https://0xtracer.xyz/incidents/2019-04-29-eosblue-one/</link><pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-29-eosblue-one/</guid><description>The attacker constructed the malicious memo, which caused the eosblue.one server parsing exceptions, thus continuously winning prizes or leading to unusually large refunds.</description></item><item><title>Bitfinex</title><link>https://0xtracer.xyz/incidents/2019-04-26-bitfinex/</link><pubDate>Fri, 26 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-26-bitfinex/</guid><description>Bitfinex is accused of sending 850 million U.S. dollars to Crypto Capital Corp, a payment processor believed to be located in Panama, without informing customers, and withdrawing at least 700 million U.S. dollars from&amp;hellip;</description></item><item><title>TronBank</title><link>https://0xtracer.xyz/incidents/2019-04-11-tronbank/</link><pubDate>Thu, 11 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-11-tronbank/</guid><description>Tron Dapp TronBank was attacked by Fake token attack at 1 am, about 170 million BTT were stolen in 1 hour (worth about 850,000 yuan). Monitoring showed that the hacker created a fake token BTTx to initiate the &amp;ldquo;invest&amp;hellip;</description></item><item><title>TronWow</title><link>https://0xtracer.xyz/incidents/2019-04-11-tronwow/</link><pubDate>Thu, 11 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-11-tronwow/</guid><description>The hacker launched 1,203 attacks on the TronWow, made a total of 2,167,377 TRX profits.</description></item><item><title>IseriCoin</title><link>https://0xtracer.xyz/incidents/2019-04-10-isericoin/</link><pubDate>Wed, 10 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-10-isericoin/</guid><description>Hacker has used contract vulnerabilities to send a huge amount of IseriCoin tokens to his account.</description></item><item><title>DEOS Games</title><link>https://0xtracer.xyz/incidents/2019-04-03-deos-games/</link><pubDate>Wed, 03 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-03-deos-games/</guid><description>Attackers continue to make continuous profits by creating new accounts and calling the luckydraw method of the EOS quiz game DEOS Games contract. Currently, over 300 accounts have been created and thousands of EOS hav&amp;hellip;</description></item><item><title>EOSlots</title><link>https://0xtracer.xyz/incidents/2019-04-03-eoslots/</link><pubDate>Wed, 03 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-03-eoslots/</guid><description>The attacker launched continuously attacks and profit from the EOSlots, and the game has been suspended operations.</description></item><item><title>EosNow</title><link>https://0xtracer.xyz/incidents/2019-04-01-eosnow/</link><pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-04-01-eosnow/</guid><description>The attacker once again launched an attack on the EOS quiz game eosnowbetext. After preliminary analysis, the attacker still manipulated multiple trumpets to attack the game through transaction squeeze, and has alread&amp;hellip;</description></item><item><title>Bithumb</title><link>https://0xtracer.xyz/incidents/2019-03-29-bithumb/</link><pubDate>Fri, 29 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-29-bithumb/</guid><description>According to a report from CoinDesk Korea, the exchange was hacked for a total of 3.1 million EOS, which was withdrawn from the exchange’s “hot” (internet connected) wallet through a series of transactions. Based on t&amp;hellip;</description></item><item><title>TronCrush</title><link>https://0xtracer.xyz/incidents/2019-03-29-troncrush/</link><pubDate>Fri, 29 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-29-troncrush/</guid><description>The transfer does not determine that to and from cannot be the same address, resulting in an attack that can create more than 15w TCC tokens without foundation.</description></item><item><title>ZION</title><link>https://0xtracer.xyz/incidents/2019-03-28-zion/</link><pubDate>Thu, 28 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-28-zion/</guid><description>ZION.games sustained attack by malicious users ggggggggggxx, profits of more than 2849 EOS, and transferred to the Binance Exchange. The attack is similar to the attack on TGON, suspected to be the same group.</description></item><item><title>TGON</title><link>https://0xtracer.xyz/incidents/2019-03-27-tgon/</link><pubDate>Wed, 27 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-27-tgon/</guid><description>The attacker controlled multiple accounts to launch continuously attacks on the TGON, made thousands of EOS in profit from the TGON, and transferred to the Binance Exchange.</description></item><item><title>BiKi</title><link>https://0xtracer.xyz/incidents/2019-03-26-biki/</link><pubDate>Tue, 26 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-26-biki/</guid><description>BiKi.com announced that at 0:08:23 on March 26, the BiKi.com community received a user feedback that his password has been tampered with and need to bind the new Google verification code.At around 5 in the morning, 28&amp;hellip;</description></item><item><title>CoinBene</title><link>https://0xtracer.xyz/incidents/2019-03-26-coinbene/</link><pubDate>Tue, 26 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-26-coinbene/</guid><description>Crypptocurrency expert Nick Schteringard said on Twitter yesterday, that the hacker appears to have stolen roughly $6 million in Coinbene Coin and $39 million in Maximine Coin, which it later dumped on the market.</description></item><item><title>DragonEx</title><link>https://0xtracer.xyz/incidents/2019-03-24-dragonex/</link><pubDate>Sun, 24 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-24-dragonex/</guid><description>DragonEx announced the news on its official Telegram channel on Monday, stating that, on Sunday, March 24, it had suffered a cyberattack that saw cryptocurrency funds owned by users and the exchange “transferred and s&amp;hellip;</description></item><item><title>Etbox</title><link>https://0xtracer.xyz/incidents/2019-03-24-etbox/</link><pubDate>Sun, 24 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-24-etbox/</guid><description>The Etbox platform wallet was hacked, causing the platform’s digital assets to be stolen.</description></item><item><title>dBet Games</title><link>https://0xtracer.xyz/incidents/2019-03-20-dbet-games/</link><pubDate>Wed, 20 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-20-dbet-games/</guid><description>The attacker launch continuously attacks and profit from the dBet Games.</description></item><item><title>EOS Cube</title><link>https://0xtracer.xyz/incidents/2019-03-18-eos-cube/</link><pubDate>Mon, 18 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-18-eos-cube/</guid><description>The attacker justjiezhan1 launched an attack on the EOS game &amp;ldquo;cubecontract&amp;rdquo; and has already made a profit. Prior to this, the attacker justjiezhan1 started deploying the attack contract at around 12:00:41 on the same&amp;hellip;</description></item><item><title>EOSVegas</title><link>https://0xtracer.xyz/incidents/2019-03-18-eosvegas/</link><pubDate>Mon, 18 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-18-eosvegas/</guid><description>The attacker launched continuously attacks and profit from the EOSVegas. The analysis found that the attack mean used by the attacker was transaction congestion attack. The account is extremely active. It just attacke&amp;hellip;</description></item><item><title>Mercatox</title><link>https://0xtracer.xyz/incidents/2019-03-15-mercatox/</link><pubDate>Fri, 15 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-15-mercatox/</guid><description>The attacker launched a hard_fail attack on the exchange and profited thousands of EOS.</description></item><item><title>YUM.games</title><link>https://0xtracer.xyz/incidents/2019-03-15-yum-games/</link><pubDate>Fri, 15 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-15-yum-games/</guid><description>The attacker justjiezhan1 launched an attack on the EOS game &amp;ldquo;YUM.games&amp;rdquo; and has already made a profit. After analysis, it is suspected that the attacker calls &amp;ldquo;gamestart&amp;rdquo; and draws the prize directly without betting&amp;hellip;</description></item><item><title>LuckyGo</title><link>https://0xtracer.xyz/incidents/2019-03-14-luckygo/</link><pubDate>Thu, 14 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-14-luckygo/</guid><description>The attacker launched continuously attacks on the LuckyGo, profiting hundreds of EOS.</description></item><item><title>dBet Games</title><link>https://0xtracer.xyz/incidents/2019-03-12-dbet-games/</link><pubDate>Tue, 12 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-12-dbet-games/</guid><description>The attacker launched continuously attacks on the dBet Games, profiting hundreds of EUSD which stablecoins issued on EOS. And has sold through the decentralized exchange Newdex.</description></item><item><title>nkpaymentcap</title><link>https://0xtracer.xyz/incidents/2019-03-11-nkpaymentcap/</link><pubDate>Mon, 11 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-11-nkpaymentcap/</guid><description>The attacker launched continuous attacks on EOS DApp nkpaymentcap and successfully profited 50,000 EOS. After analysis, it was found that the attacker used a fake transfer notification attack to obtain a large number&amp;hellip;</description></item><item><title>Vegas Town</title><link>https://0xtracer.xyz/incidents/2019-03-10-vegas-town/</link><pubDate>Sun, 10 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-10-vegas-town/</guid><description>The attacker launched a continuous attack on the EOS quiz game Vegas Town, profited thousands of EOS, and has been transferred to the ZB exchange. Preliminary analysis found that hackers used the failed (hard_fail) tr&amp;hellip;</description></item><item><title>Gamble EOS</title><link>https://0xtracer.xyz/incidents/2019-03-09-gamble-eos/</link><pubDate>Sat, 09 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-09-gamble-eos/</guid><description>The attacker launched a continuous attack on the EOS quiz game Gamble EOS, successfully profited thousands of EOS, and has been transferred to the Huobi exchange. After analysis, it was found that the attack method us&amp;hellip;</description></item><item><title>Fishing Joy</title><link>https://0xtracer.xyz/incidents/2019-03-08-fishing-joy/</link><pubDate>Fri, 08 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-08-fishing-joy/</guid><description>The attacker launched a series of attacks on the EOS quiz game Fishing Joy, profiting hundreds of EOS. According to analysis, the attacker used the transaction crowding attack to trigger the game&amp;rsquo;s refund mechanism, r&amp;hellip;</description></item><item><title>ExtremeLoto</title><link>https://0xtracer.xyz/incidents/2019-03-06-extremeloto/</link><pubDate>Wed, 06 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-06-extremeloto/</guid><description>The attacker co****op launched continuous attacks on the EOS quiz game contract xlo*****io and has already profited hundreds of EOS. After preliminary analysis, the attacker used the logic defect of the game contract&amp;hellip;</description></item><item><title>OnePlay</title><link>https://0xtracer.xyz/incidents/2019-03-05-oneplay/</link><pubDate>Tue, 05 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-05-oneplay/</guid><description>The attacker launched continuously attacks on the OnePlay, getting almost all EOS of the game contract. And use the same attack mean to bet the game token ONE, profit nearly one million game tokens, and then transfer&amp;hellip;</description></item><item><title>EOS 欢乐谷(Happy Pool)</title><link>https://0xtracer.xyz/incidents/2019-03-04-eos-happy-pool/</link><pubDate>Mon, 04 Mar 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-03-04-eos-happy-pool/</guid><description>Hackers launched continuous attacks on the EOS quiz game EOS Happy Valley, and they have profited hundreds of EOS. The game party has transferred the account balance away. Attackers still use transaction crowding out&amp;hellip;</description></item><item><title>超级节点(BP)games.eos</title><link>https://0xtracer.xyz/incidents/2019-02-22-bp-games-eos/</link><pubDate>Fri, 22 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-22-bp-games-eos/</guid><description>Tracking the blacklist account gm3dcnqgenes found that its associated account newdexmobapp received 2.09 million EOS, and has now transferred 50,000 EOS to its associated account guagddoefdqu. And in batches of hundre&amp;hellip;</description></item><item><title>Coinbin</title><link>https://0xtracer.xyz/incidents/2019-02-20-coinbin/</link><pubDate>Wed, 20 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-20-coinbin/</guid><description>Coinbin, a south Korean cryptocurrency exchange, is filing for bankruptcy with losses equivalent to more than $26 million after its debts grew after employees embezzled money.</description></item><item><title>Gameboy</title><link>https://0xtracer.xyz/incidents/2019-02-15-gameboy/</link><pubDate>Fri, 15 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-15-gameboy/</guid><description>Gameboy, a EOS game was attacked. Attacker cont****inop deployed a contract and attacked by calling launch function. According to the analysis of SlowMist security team and confirmed with project side by communication&amp;hellip;</description></item><item><title>EOSPlaystation</title><link>https://0xtracer.xyz/incidents/2019-02-05-eosplaystation/</link><pubDate>Tue, 05 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-05-eosplaystation/</guid><description>The attacker launched an attack on the EOS game EOSPlaystation.</description></item><item><title>EOSreel</title><link>https://0xtracer.xyz/incidents/2019-02-04-eosreel/</link><pubDate>Mon, 04 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-04-eosreel/</guid><description>The attacker deploys the attack contract con******nop and combines multiple accounts to attack the project contract eosreeladmin.</description></item><item><title>QuadrigaCX</title><link>https://0xtracer.xyz/incidents/2019-02-04-quadrigacx/</link><pubDate>Mon, 04 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-04-quadrigacx/</guid><description>Canada&amp;rsquo;s largest cryptocurrency exchange is seeking creditor protection after losing about $190 million worth of cryptocurrency after the sudden death of its founder and chief executive in December.</description></item><item><title>WinDice</title><link>https://0xtracer.xyz/incidents/2019-02-04-windice/</link><pubDate>Mon, 04 Feb 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-02-04-windice/</guid><description>The attacker deploys the attack contract rep******net to attack the project party contract windiceadmin.</description></item><item><title>EOSlots</title><link>https://0xtracer.xyz/incidents/2019-01-31-eoslots/</link><pubDate>Thu, 31 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-31-eoslots/</guid><description>The attacker launched continuous attacks on the EOS game EOSlots.</description></item><item><title>Fastwin</title><link>https://0xtracer.xyz/incidents/2019-01-31-fastwin/</link><pubDate>Thu, 31 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-31-fastwin/</guid><description>The attacker is the same batch of accounts that previously attacked BETX.</description></item><item><title>FASTWIN</title><link>https://0xtracer.xyz/incidents/2019-01-31-fastwin-2/</link><pubDate>Thu, 31 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-31-fastwin-2/</guid><description>The attacker deployed multiple attack contracts to attack the EOS game FASTWIN.</description></item><item><title>EOSABC</title><link>https://0xtracer.xyz/incidents/2019-01-30-eosabc/</link><pubDate>Wed, 30 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-30-eosabc/</guid><description>This is the third attack on the contract, not a transaction congestion attack, but the real purpose of the attack is the transaction rollback attack.</description></item><item><title>BETX</title><link>https://0xtracer.xyz/incidents/2019-01-28-betx/</link><pubDate>Mon, 28 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-28-betx/</guid><description>The attacker launched continuously attacks on the TGON.</description></item><item><title>EOSlots</title><link>https://0xtracer.xyz/incidents/2019-01-27-eoslots/</link><pubDate>Sun, 27 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-27-eoslots/</guid><description>The attacker controlled multiple accounts to launch continuously attacks on the EOSlots.</description></item><item><title>EOSABC</title><link>https://0xtracer.xyz/incidents/2019-01-26-eosabc/</link><pubDate>Sat, 26 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-26-eosabc/</guid><description>It is consistent with the previous principles of attacking EOS.Win, FarmEOS, etc., but the technique has changed.</description></item><item><title>LocalBitcoins</title><link>https://0xtracer.xyz/incidents/2019-01-26-localbitcoins/</link><pubDate>Sat, 26 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-26-localbitcoins/</guid><description>LocalBitcoins has detected a security vulnerability - an unauthorised source was able to access and send transactions from a number of affected accounts.It was related to a feature powered by a third party software, a&amp;hellip;</description></item><item><title>Crazy Dice</title><link>https://0xtracer.xyz/incidents/2019-01-23-crazy-dice/</link><pubDate>Wed, 23 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-23-crazy-dice/</guid><description>It is consistent with the previous principles of attacking EOS.Win, FarmEOS, etc., but the method has changed. The attacker controls multiple accounts to cooperate to complete the transaction congestion attack.</description></item><item><title>EOSLuck</title><link>https://0xtracer.xyz/incidents/2019-01-22-eosluck/</link><pubDate>Tue, 22 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-22-eosluck/</guid><description>The attacker is targeting the game&amp;rsquo;s random number algorithm, and his winning percentage is much higher than other ordinary players.</description></item><item><title>idicefungame</title><link>https://0xtracer.xyz/incidents/2019-01-21-idicefungame/</link><pubDate>Mon, 21 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-21-idicefungame/</guid><description>The attacker launched continuously attacks on idicefungame and has already made a profit, and transferred to the bitfinex exchange.</description></item><item><title>21Dice</title><link>https://0xtracer.xyz/incidents/2019-01-17-21dice/</link><pubDate>Thu, 17 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-17-21dice/</guid><description>The attacker used the transaction congestion attack to attack the game contract and ultimately profit.</description></item><item><title>idice(影骰)</title><link>https://0xtracer.xyz/incidents/2019-01-16-idice/</link><pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-16-idice/</guid><description>The attacker useed the transaction congestion attack to attack the game contract and ultimately profit.</description></item><item><title>LuckBet</title><link>https://0xtracer.xyz/incidents/2019-01-16-luckbet/</link><pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-16-luckbet/</guid><description>The attacker uses the trade crowding attack to attack the game contract and ultimately profit.</description></item><item><title>playgames</title><link>https://0xtracer.xyz/incidents/2019-01-16-playgames/</link><pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-16-playgames/</guid><description>The game playgames has been continuously attacked by malicious user niyoubudou33. It has been attacked 295 times as of press time, which is consistent with the previous attacks on EOS.Win, FarmEOS, idice, LuckBet, Gam&amp;hellip;</description></item><item><title>FarmEOS</title><link>https://0xtracer.xyz/incidents/2019-01-15-farmeos/</link><pubDate>Tue, 15 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-15-farmeos/</guid><description>The attacker made a profit of nearly 2000 EOS through the Dice game by deploying the attack contract flo*****now in just a few minutes.</description></item><item><title>GameBet</title><link>https://0xtracer.xyz/incidents/2019-01-14-gamebet/</link><pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-14-gamebet/</guid><description>The attacker used transaction congestion attack to exploit vulnerability in the old-version BP nodeos.</description></item><item><title>Cryptopia</title><link>https://0xtracer.xyz/incidents/2019-01-13-cryptopia/</link><pubDate>Sun, 13 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-13-cryptopia/</guid><description>From January 13th to 14th, a huge amount of unauthorized cryptocurrency transfer occurred in Cryptopia, which was suspected of being stolen. On January 15, the exchange posted a tweet claiming that it was hacked and 2&amp;hellip;</description></item><item><title>FarmEOS</title><link>https://0xtracer.xyz/incidents/2019-01-13-farmeos/</link><pubDate>Sun, 13 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-13-farmeos/</guid><description>After the attack contract sil******day places a bet on FarmEOS, and when the attack contract receives a transfer notification, it initiates a large number of defer transactions, which delays the subsequent lottery dra&amp;hellip;</description></item><item><title>Fishing</title><link>https://0xtracer.xyz/incidents/2019-01-13-fishing/</link><pubDate>Sun, 13 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-13-fishing/</guid><description>The attacker used transaction congestion attack to exploit vulnerability in the old-version BP nodeos.</description></item><item><title>BetDoge</title><link>https://0xtracer.xyz/incidents/2019-01-12-betdoge/</link><pubDate>Sat, 12 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-12-betdoge/</guid><description>The attacker launched continuous attacks on the EOS game BetDoge and has successfully profited hundreds of EOS.</description></item><item><title>EOS.WIN</title><link>https://0xtracer.xyz/incidents/2019-01-12-eos-win/</link><pubDate>Sat, 12 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-12-eos-win/</guid><description>The attacker loveforlover launched an attack on EOS.WIN and has already made a profit.</description></item><item><title>uugame</title><link>https://0xtracer.xyz/incidents/2019-01-10-uugame/</link><pubDate>Thu, 10 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-10-uugame/</guid><description>The random number was cracked.</description></item><item><title>ETC</title><link>https://0xtracer.xyz/incidents/2019-01-06-etc/</link><pubDate>Sun, 06 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-06-etc/</guid><description>The attacker launched a 51% attack through the rental power, and the exchanges such as Gate.io, Yobit, and Bitrue were affected, and after a week, the attacker returned all the ETC.</description></item><item><title>HotDice</title><link>https://0xtracer.xyz/incidents/2019-01-04-hotdice/</link><pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-04-hotdice/</guid><description>Developers have not been able to effectively detect, block, and isolate accounts which is contract high risk or marked as blacklisted.</description></item><item><title>EOS BUFF</title><link>https://0xtracer.xyz/incidents/2019-01-01-eos-buff/</link><pubDate>Tue, 01 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-01-eos-buff/</guid><description>The attacker launched continuous attacks on the EOS BUFF and has successfully profited hundreds of EOS.</description></item><item><title>ggeos</title><link>https://0xtracer.xyz/incidents/2019-01-01-ggeos/</link><pubDate>Tue, 01 Jan 2019 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2019-01-01-ggeos/</guid><description>The contract was attacked by a transaction rollback.</description></item><item><title>Tronwin</title><link>https://0xtracer.xyz/incidents/2018-12-31-tronwin/</link><pubDate>Mon, 31 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-31-tronwin/</guid><description>Tron DApp Tronwin is hacked because of overflow and 2 million TRX were stolen.</description></item><item><title>LuckBet</title><link>https://0xtracer.xyz/incidents/2018-12-29-luckbet/</link><pubDate>Sat, 29 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-29-luckbet/</guid><description>The random number was attacked by the attacker for the second time.</description></item><item><title>GameBet</title><link>https://0xtracer.xyz/incidents/2018-12-28-gamebet/</link><pubDate>Fri, 28 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-28-gamebet/</guid><description>The attacker launched an attack on the GameBet game contract gamebetdices, and transfer most of the acquired EOS to the FreeWallet wallet account.</description></item><item><title>LuckyMe</title><link>https://0xtracer.xyz/incidents/2018-12-28-luckyme/</link><pubDate>Fri, 28 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-28-luckyme/</guid><description>The attacker continued to attack the LuckyMe game contract luckymedice1 and had benefited thousands of EOS.</description></item><item><title>Fountain(FTN)</title><link>https://0xtracer.xyz/incidents/2018-12-27-fountain-ftn/</link><pubDate>Thu, 27 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-27-fountain-ftn/</guid><description>Fountain (FTN) has an overflow vulnerability, the attacker performs an overflow attack by calling batchTransfers.</description></item><item><title>Lucky Nuts</title><link>https://0xtracer.xyz/incidents/2018-12-26-lucky-nuts/</link><pubDate>Wed, 26 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-26-lucky-nuts/</guid><description>The attacker continued to attack the Lucky Nuts game contract nutsgambling and continues to profit from it. Eventually most of the stolen EOS was transferred to the Binance exchange account binancecleos.</description></item><item><title>FastWin</title><link>https://0xtracer.xyz/incidents/2018-12-25-fastwin/</link><pubDate>Tue, 25 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-25-fastwin/</guid><description>The hacker mastered and modified FAST&amp;rsquo;s token contract, deliberately created a vulnerability that can be used for multiple &amp;ldquo;additional&amp;rdquo; tokens for free.</description></item><item><title>Pickown</title><link>https://0xtracer.xyz/incidents/2018-12-23-pickown/</link><pubDate>Sun, 23 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-23-pickown/</guid><description>&amp;ldquo;Transfer Error Prompt&amp;rdquo;, as the game contract does not filter the false notifications provided by the game player.</description></item><item><title>LuckBet</title><link>https://0xtracer.xyz/incidents/2018-12-22-luckbet/</link><pubDate>Sat, 22 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-22-luckbet/</guid><description>The attacker snowredgreen attacked the LuckBet game contract luckbetadmin and transfers most of the acquired EOS to the Huobi exchange account huobideposit</description></item><item><title>EosDice</title><link>https://0xtracer.xyz/incidents/2018-12-21-eosdice/</link><pubDate>Fri, 21 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-21-eosdice/</guid><description>The attacker binaryfunxxx attacked the EosDice&amp;rsquo;s game contract bocai.game and transfers most of the acquired EOS to the Binance exchange account binancecleos.</description></item><item><title>BetDice</title><link>https://0xtracer.xyz/incidents/2018-12-19-betdice/</link><pubDate>Wed, 19 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-19-betdice/</guid><description>Rollback transaction attack.</description></item><item><title>Big.game</title><link>https://0xtracer.xyz/incidents/2018-12-19-big-game/</link><pubDate>Wed, 19 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-19-big-game/</guid><description>Big.game is suspected of being attacked by hacker eykkxszdrnnc. Big.game officially stated that the actual loss was about 8,000 EOS, and the balance of the dice prize pool has been transferred to a secure account.</description></item><item><title>EOS Max</title><link>https://0xtracer.xyz/incidents/2018-12-19-eos-max/</link><pubDate>Wed, 19 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-19-eos-max/</guid><description>The attacker (eykkxszdrnnc) launched an attack on the EOS MAX game contract (eosmaxiodice), an EOS quiz game, earning a total of 55,526.05 EOS. The game party has suspended the game operation at 6:40 am on the 19th, a&amp;hellip;</description></item><item><title>ToBet</title><link>https://0xtracer.xyz/incidents/2018-12-19-tobet/</link><pubDate>Wed, 19 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-19-tobet/</guid><description>The attacker rolls back the transaction when placing a bet. From the time the bet is placed until the transaction is rolled back, the betting data will temporarily exist in the database of the current node; and Tobet&amp;hellip;</description></item><item><title>TRUSTBET</title><link>https://0xtracer.xyz/incidents/2018-12-19-trustbet/</link><pubDate>Wed, 19 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-19-trustbet/</guid><description>The attacker (panming12345) launched an attack on the EOS quiz game TRUSTBET game contract (trustbetgame), profiting a total of 11,501 EOS, and then transferred the EOS obtained from the attack to the Huobideposit acc&amp;hellip;</description></item><item><title>kittyfishing</title><link>https://0xtracer.xyz/incidents/2018-12-12-kittyfishing/</link><pubDate>Wed, 12 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-12-kittyfishing/</guid><description>The attacker helookitiqas launched attacks on the EOS game kittyfishing, which launched a total of 91 attacks in two hours.</description></item><item><title>Vertcoin</title><link>https://0xtracer.xyz/incidents/2018-12-12-vertcoin/</link><pubDate>Wed, 12 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-12-vertcoin/</guid><description>Vertcoin suffered a major attack in which hackers stole funds worth $100,000.</description></item><item><title>Fastwin</title><link>https://0xtracer.xyz/incidents/2018-12-05-fastwin/</link><pubDate>Wed, 05 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-05-fastwin/</guid><description>The attacker ha4tsojigyge launched 124 attacks on the Fastwin game contract fastwindice3.</description></item><item><title>Dice3D</title><link>https://0xtracer.xyz/incidents/2018-12-03-dice3d/</link><pubDate>Mon, 03 Dec 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-12-03-dice3d/</guid><description>Similar to the previous attack on EOS.WIN on November 11, multiple contract accounts were used to send transaction requests at the same time, and the front feint account was used to implement small bets. After ensurin&amp;hellip;</description></item><item><title>Atidium</title><link>https://0xtracer.xyz/incidents/2018-11-30-atidium/</link><pubDate>Fri, 30 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-30-atidium/</guid><description>EOS Atidium&amp;rsquo;s official account wwwatidiumio was abnormal. A total of 6 tokens including ATD tokens 337,759,004 were transferred to account b4jmqvvktgjx. The account then transferred 130 million ATD tokens to Newdex Ex&amp;hellip;</description></item><item><title>nutsgambling</title><link>https://0xtracer.xyz/incidents/2018-11-28-nutsgambling/</link><pubDate>Wed, 28 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-28-nutsgambling/</guid><description>Hacker ybdzmtgouwxn launched an attack on nutsgambling, an EOS quiz game. In less than an hour, a total of 144 attacks were launched, and a total of 1,141.71 EOS was obtained. In order to prevent the flow of funds fro&amp;hellip;</description></item><item><title>BitPay Copay</title><link>https://0xtracer.xyz/incidents/2018-11-27-bitpay-copay/</link><pubDate>Tue, 27 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-27-bitpay-copay/</guid><description>American Bitcoin payment processor BitPay stated that the company&amp;rsquo;s Copay wallet was attacked by hackers. Bitpay announced on Monday that it learned of this issue from a report on Copay GitHub. The report showed that&amp;hellip;</description></item><item><title>vegasgame111</title><link>https://0xtracer.xyz/incidents/2018-11-21-vegasgame111/</link><pubDate>Wed, 21 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-21-vegasgame111/</guid><description>The attacker (kuybupeykieh) launched an attack on the EOS quiz game contract (vegasgame111), making a total of hundreds of EOS. The data on the tracking chain found that, in order to prevent the flow of funds from bei&amp;hellip;</description></item><item><title>EOS Lelego</title><link>https://0xtracer.xyz/incidents/2018-11-19-eos-lelego/</link><pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-19-eos-lelego/</guid><description>The attacker malisringho continually initiated 35 game requests to the EOS Lelego contract llgcontract1., eventually guessing 27 times, making a total profit of 6,282.5 EOS, and then successfully transferring 6,500 EO&amp;hellip;</description></item><item><title>LuckyGo</title><link>https://0xtracer.xyz/incidents/2018-11-15-luckygo/</link><pubDate>Thu, 15 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-15-luckygo/</guid><description>EOS game contract LuckyGo has been off the line and the attacker iloveloveeos (malicious contract) was exposed in September because of attack on FairDice.</description></item><item><title>AurumCoin</title><link>https://0xtracer.xyz/incidents/2018-11-12-aurumcoin/</link><pubDate>Mon, 12 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-12-aurumcoin/</guid><description>According to a report by Finder on November 12, AurumCoin (AU), a new digital currency based on the monetary gold standard system (the US dollar operation method), has recently suffered a 51% attack and lost 15,752.26&amp;hellip;</description></item><item><title>HireVibes &amp; AirDropsDAC</title><link>https://0xtracer.xyz/incidents/2018-11-12-hirevibes-and-airdropsdac/</link><pubDate>Mon, 12 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-12-hirevibes-and-airdropsdac/</guid><description>A large number of HVTs in the AirDropsDAC contract account were transferred to the sym111111add account under abnormal operation, the account was then exchanged for 2,514 EOS at Newdex, which was subsequently transfer&amp;hellip;</description></item><item><title>EOS.WIN</title><link>https://0xtracer.xyz/incidents/2018-11-11-eos-win/</link><pubDate>Sun, 11 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-11-eos-win/</guid><description>The game contract was attacked by the attacker lockonthecha.</description></item><item><title>EOSDice</title><link>https://0xtracer.xyz/incidents/2018-11-10-eosdice/</link><pubDate>Sat, 10 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-10-eosdice/</guid><description>The well-known DApp EOSDice was hacked again due to random number issues. The attacker was a hacker who previously attacked EOSDice and FFGame DApp. The project side wrongly add a controlled seed in random algorithm w&amp;hellip;</description></item><item><title>MyEosVegas</title><link>https://0xtracer.xyz/incidents/2018-11-10-myeosvegas/</link><pubDate>Sat, 10 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-10-myeosvegas/</guid><description>The hacker has launched a total of 700 attacks on the MyEosVegas game contract eosvegasjack.</description></item><item><title>FFgame</title><link>https://0xtracer.xyz/incidents/2018-11-08-ffgame/</link><pubDate>Thu, 08 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-08-ffgame/</guid><description>By deploying the attack contract and using the same algorithm as FFgame to calculate the random number in the contract, the attacker immediately uses the random number attack contract in inline_action after generating&amp;hellip;</description></item><item><title>GATE.IO</title><link>https://0xtracer.xyz/incidents/2018-11-07-gate-io/</link><pubDate>Wed, 07 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-07-gate-io/</guid><description>Hackers successfully sandwiched crypto-stealing code into the middle of a popular web traffic-measuring plugin from StatCounter, which is now used on more than two million websites, including government sites. They ha&amp;hellip;</description></item><item><title>EOSDice</title><link>https://0xtracer.xyz/incidents/2018-11-04-eosdice/</link><pubDate>Sun, 04 Nov 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-11-04-eosdice/</guid><description>Random number was cracked by attacker.</description></item><item><title>EOSCast</title><link>https://0xtracer.xyz/incidents/2018-10-31-eoscast/</link><pubDate>Wed, 31 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-31-eoscast/</guid><description>The hacker &amp;ldquo;refundwallet&amp;rdquo; tried to attack the EOSCast game contract &amp;ldquo;eoscastdmgb1&amp;rdquo;. The hacker first used the &amp;ldquo;fake EOS&amp;rdquo; attack method to conduct 8 transfer attacks, but failed, and then successfully attacked 9 times&amp;hellip;</description></item><item><title>MapleChange</title><link>https://0xtracer.xyz/incidents/2018-10-28-maplechange/</link><pubDate>Sun, 28 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-28-maplechange/</guid><description>MapleChange, based in Canada, announced on Twitter the exchange &amp;ldquo;sustained a hack&amp;rdquo; and was investigating the issue. The post also said the exchange had turned off users&amp;rsquo; accounts temporarily. About refunding its custo&amp;hellip;</description></item><item><title>EosRoyale</title><link>https://0xtracer.xyz/incidents/2018-10-26-eosroyale/</link><pubDate>Fri, 26 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-26-eosroyale/</guid><description>Vulnerability of the random number generator, the attacker can try to calculate the future number of random number generator algorithms by using the information of the previous block and stolen $60,000 from the EosRoy&amp;hellip;</description></item><item><title>TRADE.IO</title><link>https://0xtracer.xyz/incidents/2018-10-20-trade-io/</link><pubDate>Sat, 20 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-20-trade-io/</guid><description>Trade.io confirmed via their Medium blog that someone or some entity gained access to the assets, resulting in over 50 million in Trade (TIO) tokens being stolen from the firm’s cold storage wallets. The 50 million to&amp;hellip;</description></item><item><title>WORLD CONQUEST</title><link>https://0xtracer.xyz/incidents/2018-10-16-world-conquest/</link><pubDate>Tue, 16 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-16-world-conquest/</guid><description>RatingToken, a third-party big data platform owned by Cheetah, has detected that DAPP World Conquest developed based on EOS was hacked. Subsequently, the official issued an announcement on its Discord to confirm the f&amp;hellip;</description></item><item><title>EOSBet</title><link>https://0xtracer.xyz/incidents/2018-10-15-eosbet/</link><pubDate>Mon, 15 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-15-eosbet/</guid><description>The attacker exploited the vulnerabilities in the EOSBet contract to falsify the transfer prompt.</description></item><item><title>SpankChain</title><link>https://0xtracer.xyz/incidents/2018-10-09-spankchain/</link><pubDate>Tue, 09 Oct 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-10-09-spankchain/</guid><description>The attacker created a malicious contract masquerading as an ERC20 token, and the &amp;ldquo;transfer&amp;rdquo; function re-invokes the payment channel contract repeatedly, each time exhausting some ETH.</description></item><item><title>EOS.Win</title><link>https://0xtracer.xyz/incidents/2018-09-14-eos-win/</link><pubDate>Fri, 14 Sep 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-09-14-eos-win/</guid><description>The attacker exchanged true EOS token with fake token within the vulnerability in the code,winning without betting</description></item><item><title>EOSBet</title><link>https://0xtracer.xyz/incidents/2018-09-14-eosbet/</link><pubDate>Fri, 14 Sep 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-09-14-eosbet/</guid><description>The game contract does not check the transfer action must initiated by eosio.token or token contract of the game itself.</description></item><item><title>Newdex</title><link>https://0xtracer.xyz/incidents/2018-09-14-newdex/</link><pubDate>Fri, 14 Sep 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-09-14-newdex/</guid><description>After EOSBet broke the security vulnerability of hackers using counterfeit currency bets to win real coins, at 2 o&amp;rsquo;clock in the afternoon, EOS contract account oo1122334455 issued a token named &amp;ldquo;EOS&amp;rdquo;, and allocated on&amp;hellip;</description></item><item><title>ZAIF</title><link>https://0xtracer.xyz/incidents/2018-09-14-zaif/</link><pubDate>Fri, 14 Sep 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-09-14-zaif/</guid><description>Hackers with unauthorized access to the exchange’s hot wallets had stolen roughly $60 million in bitcoin, bitcoin cash, and MonaCoin. That being said, the exact amount of bitcoin cash stolen remains unknown.</description></item><item><title>DEOSBET</title><link>https://0xtracer.xyz/incidents/2018-09-10-deosbet/</link><pubDate>Mon, 10 Sep 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-09-10-deosbet/</guid><description>The law of the random number generated by DEOSBET was cracked by hackers.</description></item><item><title>EOSBET</title><link>https://0xtracer.xyz/incidents/2018-08-26-eosbet/</link><pubDate>Sun, 26 Aug 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-08-26-eosbet/</guid><description>RAM was swallowed up by the malicious contract, and the game party failed to check the caller of transfer action, which led to the exchange of real token with fake token and &amp;ldquo;Transfer Error Prompt&amp;rdquo; vulnerability</description></item><item><title>Fomo 3D</title><link>https://0xtracer.xyz/incidents/2018-08-01-fomo-3d/</link><pubDate>Wed, 01 Aug 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-08-01-fomo-3d/</guid><description>Ethereum Fomo 3D was hacked and hacker used special attack techniques to take the bonus.</description></item><item><title>Fomo 3D</title><link>https://0xtracer.xyz/incidents/2018-07-31-fomo-3d/</link><pubDate>Tue, 31 Jul 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-07-31-fomo-3d/</guid><description>Ethereum Fomo 3D was hacked, Fomo 3D website 24-hour access reduced 21.95 percent, 24-hour flow decreased 38.32%</description></item><item><title>KICKICO</title><link>https://0xtracer.xyz/incidents/2018-07-26-kickico/</link><pubDate>Thu, 26 Jul 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-07-26-kickico/</guid><description>KICKICO has experienced a security breach, which resulted in the attackers gaining access to the account of the KICK smart contract — tokens of the KICKICO platform. The team learned about this incident after the comp&amp;hellip;</description></item><item><title>狼人游戏(EOS Fomo3D)</title><link>https://0xtracer.xyz/incidents/2018-07-25-eos-fomo3d/</link><pubDate>Wed, 25 Jul 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-07-25-eos-fomo3d/</guid><description>The EOS Fomo3D game contract suffered an overflow attack and the cash pooling became negative.</description></item><item><title>Bancor</title><link>https://0xtracer.xyz/incidents/2018-07-10-bancor/</link><pubDate>Tue, 10 Jul 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-07-10-bancor/</guid><description>The Bancor platform theft was related to the BancorConverter contract, and the attacker (hacker/mole) is very likely to get the private key of the 0x009bb5e9fcf28e5e601b7d0e9e821da6365d0a9c.</description></item><item><title>Bithumb</title><link>https://0xtracer.xyz/incidents/2018-06-21-bithumb/</link><pubDate>Thu, 21 Jun 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-06-21-bithumb/</guid><description>The attacker stole $30 million worth of cryptocurrency from Bithumb, Korea&amp;rsquo;s largest cryptocurrency exchange. According to Japanese Cointelegraph, the attackers hijacked Bithumb&amp;rsquo;s popular (online) wallet.</description></item><item><title>Coinrail</title><link>https://0xtracer.xyz/incidents/2018-06-10-coinrail/</link><pubDate>Sun, 10 Jun 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-06-10-coinrail/</guid><description>Coinrail acknowledged the existence of “network intrusion” in its system and estimated that 40 billion won ($37.2 million) worth of coins were stolen. The police are investigating violations but have not announced fur&amp;hellip;</description></item><item><title>Litecoin Cash</title><link>https://0xtracer.xyz/incidents/2018-06-08-litecoin-cash/</link><pubDate>Fri, 08 Jun 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-06-08-litecoin-cash/</guid><description>According to the official news of Litecoin Cash (LCC), LCC has been attacked by 51% recently. The LCC team has contacted the exchange and increased the number of confirmed blocks to 100 to prevent attacks.</description></item><item><title>ZenCash</title><link>https://0xtracer.xyz/incidents/2018-06-02-zencash/</link><pubDate>Sat, 02 Jun 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-06-02-zencash/</guid><description>The ZenCash encountered a 51% cyber attack or double-spend attack at around 8:26 PM on June 2nd (June 3rd 00:26 UTC). This attack resulted in the loss of Zen encrypted tokens worth approximately US $550,000. The ZenCa&amp;hellip;</description></item><item><title>Verge</title><link>https://0xtracer.xyz/incidents/2018-05-29-verge/</link><pubDate>Tue, 29 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-29-verge/</guid><description>The last repair was bypassed, resulting in another 51% attack and a loss of approximately US$4.82 million.</description></item><item><title>BAI Token</title><link>https://0xtracer.xyz/incidents/2018-05-24-bai-token/</link><pubDate>Thu, 24 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-24-bai-token/</guid><description>According to the SlowMist Zone disclosure, the BAI smart contract has the same vulnerabilities as the EDU, and can transfer the BAI Token in any account. There are also a large number of robbery.</description></item><item><title>EDU Token</title><link>https://0xtracer.xyz/incidents/2018-05-24-edu-token/</link><pubDate>Thu, 24 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-24-edu-token/</guid><description>EDU smart contract has critical vulnerability , and can transfer the EDU Token in any account.</description></item><item><title>Verge</title><link>https://0xtracer.xyz/incidents/2018-05-22-verge/</link><pubDate>Tue, 22 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-22-verge/</guid><description>The attacker discovers and manipulates errors in the Verge code, causing false timestamps to be set on the block and then dig out new blocks quickly. The protocol of Verge is uses five mining algorithms in turn, and t&amp;hellip;</description></item><item><title>TAYLOR</title><link>https://0xtracer.xyz/incidents/2018-05-21-taylor/</link><pubDate>Mon, 21 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-21-taylor/</guid><description>TAYLOR’ve been hacked and all of our funds have been stolen. Not only the balance in ETH (2,578.98 ETH), but also the TAY tokens from the Team and Bounty pools. The only tokens that were not stolen are the ones from t&amp;hellip;</description></item><item><title>Monacoin</title><link>https://0xtracer.xyz/incidents/2018-05-18-monacoin/</link><pubDate>Fri, 18 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-18-monacoin/</guid><description>On May 18, a Reddit netizen posted that Monacoin suffered a 51% computing power attack, a selfish mining attack, and a time stamp attack. The exact time occurred from May 13 to May 15. Some exchanges that support Mona&amp;hellip;</description></item><item><title>Bitcoin Gold</title><link>https://0xtracer.xyz/incidents/2018-05-16-bitcoin-gold/</link><pubDate>Wed, 16 May 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-05-16-bitcoin-gold/</guid><description>Bitcoin Gold was 51% attacked by an unknown attacker. This type of attack allows an attacker to manipulate the blockchain ledger that records transactions. During the attack, 388,000 BTG (worth approximately US$18 mil&amp;hellip;</description></item><item><title>MyEtherWallet</title><link>https://0xtracer.xyz/incidents/2018-04-25-myetherwallet/</link><pubDate>Wed, 25 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-25-myetherwallet/</guid><description>After logging in to the website for 10s, the user&amp;rsquo;s wallet is emptied, the hacker hijacks the DNS server, and the user logs in to MyEtherWallet to force a redirect to the malicious website. The user was forced to redi&amp;hellip;</description></item><item><title>SmartMesh</title><link>https://0xtracer.xyz/incidents/2018-04-25-smartmesh/</link><pubDate>Wed, 25 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-25-smartmesh/</guid><description>SmartMesh has a significant security like BEC.</description></item><item><title>BeautyChain</title><link>https://0xtracer.xyz/incidents/2018-04-22-beautychain/</link><pubDate>Sun, 22 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-22-beautychain/</guid><description>Hacker exploited the data overflow to attack the smart contract of BeautyChain, successfully transferred the BEC token to the two addresses resulted in the massive BEC being sold in the market, and the value of the di&amp;hellip;</description></item><item><title>COINSECURE</title><link>https://0xtracer.xyz/incidents/2018-04-12-coinsecure/</link><pubDate>Thu, 12 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-12-coinsecure/</guid><description>A failed cold storage restoration exercise seems to have exposed private keys intended for offline storage (effectively making them online). However, the CEO has expressed an insider’s involvement. Police found privat&amp;hellip;</description></item><item><title>Verge</title><link>https://0xtracer.xyz/incidents/2018-04-04-verge/</link><pubDate>Wed, 04 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-04-verge/</guid><description>The Verge network was attacked by 51% for the first time. According to Bitcointalk forum user ocminer, a malicious miner can use forged timestamps to mine blocks, thereby tricking the network into thinking that the ne&amp;hellip;</description></item><item><title>Electroneum</title><link>https://0xtracer.xyz/incidents/2018-04-02-electroneum/</link><pubDate>Mon, 02 Apr 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-04-02-electroneum/</guid><description>The attacker has a large amount of computing power to launch 51% attack</description></item><item><title>Binance</title><link>https://0xtracer.xyz/incidents/2018-03-07-binance/</link><pubDate>Wed, 07 Mar 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-03-07-binance/</guid><description>Binance security incident occurred in March 2018 when a phishing campaign impacted a large number of Binance users. At the time, Binance offered a $250,000 reward for any information that would have led to the arrest&amp;hellip;</description></item><item><title>Blockchain.info</title><link>https://0xtracer.xyz/incidents/2018-02-19-blockchain-info/</link><pubDate>Mon, 19 Feb 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-02-19-blockchain-info/</guid><description>A hacking organization in Ukraine has stolen cryptocurrencies worth more than $50 million from the Blockchain.info by purchasing keyword advertisements related to cryptocurrencies in the Google search engine and masqu&amp;hellip;</description></item><item><title>BitGrail</title><link>https://0xtracer.xyz/incidents/2018-02-09-bitgrail/</link><pubDate>Fri, 09 Feb 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-02-09-bitgrail/</guid><description>NANO tokens stolen, exchange owner disputed responsibility</description></item><item><title>Coincheck</title><link>https://0xtracer.xyz/incidents/2018-01-26-coincheck/</link><pubDate>Fri, 26 Jan 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-01-26-coincheck/</guid><description>NEM tokens held in unprotected hot wallet drained</description></item><item><title>BlackWallet</title><link>https://0xtracer.xyz/incidents/2018-01-13-blackwallet/</link><pubDate>Sat, 13 Jan 2018 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2018-01-13-blackwallet/</guid><description>User orbit84 posted on Reddit that a hacker entered his hosting provider account and changed the DNS settings to his own hosted version of BlackWallet. The attacker&amp;rsquo;s wallet seems to have accumulated about $400,000 wo&amp;hellip;</description></item><item><title>YOUBIT</title><link>https://0xtracer.xyz/incidents/2017-12-19-youbit/</link><pubDate>Tue, 19 Dec 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-12-19-youbit/</guid><description>In the wee hours of December 19, Youbit was dealt a death blow in the form of another hack. The exchange, which was also hit in April, is closing down in the fallout of the most recent attack. As revealed on its websi&amp;hellip;</description></item><item><title>Nicehash</title><link>https://0xtracer.xyz/incidents/2017-12-08-nicehash/</link><pubDate>Fri, 08 Dec 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-12-08-nicehash/</guid><description>Nicehash appears to have shuttered their website with a notice saying “a security breach involving NiceHash website” and “our payment system was compromised and the contents of the NiceHash Bitcoin wallet have been st&amp;hellip;</description></item><item><title>Tether</title><link>https://0xtracer.xyz/incidents/2017-11-19-tether/</link><pubDate>Sun, 19 Nov 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-11-19-tether/</guid><description>Tether, the issuer of USDT, issued a statement stating that its system was hacked by an external attacker on the 19th of this month and stolen USDT tokens worth approximately $31 million from its Tether Treasury wallet.</description></item><item><title>Control-Finance</title><link>https://0xtracer.xyz/incidents/2017-09-10-control-finance/</link><pubDate>Sun, 10 Sep 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-09-10-control-finance/</guid><description>On June 18,2019, the US Commodity Futures Trading Commission (CFTC) announced it had initiated a civil enforcement action against a now-defunct cryptocurrency trading and investment company for misappropriating $147 m&amp;hellip;</description></item><item><title>BTC-e</title><link>https://0xtracer.xyz/incidents/2017-07-26-btc-e/</link><pubDate>Wed, 26 Jul 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-07-26-btc-e/</guid><description>According to internet rumors, 66,000 bitcoins were suspected to have been stolen from the BTC-e exchange. The user inquired on the blockchain that the block with a block height of 477472 was transferred out of 66163.4&amp;hellip;</description></item><item><title>Coindash</title><link>https://0xtracer.xyz/incidents/2017-07-19-coindash/</link><pubDate>Wed, 19 Jul 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-07-19-coindash/</guid><description>Hacker steals $7.4 million in ethereum during CoinDash ICO launch. At the time of the ICO, in which CoinDash posted a string of characters which represented its wallet address for investors to send funds to, it appear&amp;hellip;</description></item><item><title>Parity Wallet</title><link>https://0xtracer.xyz/incidents/2017-07-19-parity-wallet/</link><pubDate>Wed, 19 Jul 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-07-19-parity-wallet/</guid><description>Uninitialized wallet library exploited to steal from multisig wallets</description></item><item><title>Bithumb</title><link>https://0xtracer.xyz/incidents/2017-06-21-bithumb/</link><pubDate>Wed, 21 Jun 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-06-21-bithumb/</guid><description>Bithumb is one of the five largest bitcoin exchanges in the world. Hackers succeeded in grabbing the personal information of 31,800 Bithumb website users, including their names, mobile phone numbers and email addresse&amp;hellip;</description></item><item><title>Yapizon</title><link>https://0xtracer.xyz/incidents/2017-04-27-yapizon/</link><pubDate>Thu, 27 Apr 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-04-27-yapizon/</guid><description>Yapizon, a South Korean Bitcoin exchange, announced last week it lost 3831 Bitcoin (over $5.5 million) after an unknown hacker breached its system and stole funds from its server.</description></item><item><title>Stellar</title><link>https://0xtracer.xyz/incidents/2017-04-01-stellar/</link><pubDate>Sat, 01 Apr 2017 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2017-04-01-stellar/</guid><description>Messari, a cryptocurrency research organization, announced on the 27th that Stellar&amp;rsquo;s blockchain protocol had an inflation loophole in April 2017. An attacker used the loophole to create 2.25 million XLM (worth about&amp;hellip;</description></item><item><title>Bitfinex</title><link>https://0xtracer.xyz/incidents/2016-08-03-bitfinex/</link><pubDate>Wed, 03 Aug 2016 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2016-08-03-bitfinex/</guid><description>Bitfinex suffered a cyber attack in August 2016. 2,072 Bitcoin transactions were transferred out without Bitfinex&amp;rsquo;s authorization, and then the funds were scattered and stored in 2,072 wallet addresses. Statistics sho&amp;hellip;</description></item><item><title>The DAO</title><link>https://0xtracer.xyz/incidents/2016-06-17-the-dao/</link><pubDate>Fri, 17 Jun 2016 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2016-06-17-the-dao/</guid><description>First major smart contract exploit, led to Ethereum hard fork</description></item><item><title>Gatecoin</title><link>https://0xtracer.xyz/incidents/2016-05-14-gatecoin/</link><pubDate>Sat, 14 May 2016 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2016-05-14-gatecoin/</guid><description>Gatecoin experienced a cyberattack on its hot wallets that resulted in the loss of funds. A new update from the exchange team indicated that as much as $2m was lost, confirming rumors that circulated soon after the ha&amp;hellip;</description></item><item><title>KipCoin</title><link>https://0xtracer.xyz/incidents/2015-02-18-kipcoin/</link><pubDate>Wed, 18 Feb 2015 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2015-02-18-kipcoin/</guid><description>KipCoin announced that the attacker gained access to the server in 2014 and downloaded the wallet.dat file. A few months later, the attacker stole more than 3,000 BTC.</description></item><item><title>BTER</title><link>https://0xtracer.xyz/incidents/2015-02-17-bter/</link><pubDate>Tue, 17 Feb 2015 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2015-02-17-bter/</guid><description>BTER announced that it lost 7,170 BTC (then worth $1.75 million). The company claims that BTC was stolen from a cold wallet.</description></item><item><title>Bitstamp</title><link>https://0xtracer.xyz/incidents/2015-01-05-bitstamp/</link><pubDate>Mon, 05 Jan 2015 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2015-01-05-bitstamp/</guid><description>Bitstamp reported that multiple operating wallets were damaged, resulting in the loss of 19,000 bitcoins. The company was hacked by multiple phishing attacks in the months before the attack. An employee downloaded a m&amp;hellip;</description></item><item><title>MintPal</title><link>https://0xtracer.xyz/incidents/2014-07-14-mintpal/</link><pubDate>Mon, 14 Jul 2014 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2014-07-14-mintpal/</guid><description>MintPal announce that the attacker stole 8 million VeriCoins ($1.8 million) from the company&amp;rsquo;s hot wallet. The attacker exploited a vulnerability in its system that allowed them to bypass the security controls to with&amp;hellip;</description></item><item><title>Poloniex</title><link>https://0xtracer.xyz/incidents/2014-03-04-poloniex/</link><pubDate>Tue, 04 Mar 2014 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2014-03-04-poloniex/</guid><description>Digital currency exchange Poloniex, which trades bitcoin and other popular digital currencies such as litecoin, namecoin and dogecoin, has lost 12.3% of its total bitcoin supply in an attack. The exchange took to Bitc&amp;hellip;</description></item><item><title>MtGox</title><link>https://0xtracer.xyz/incidents/2014-02-07-mtgox/</link><pubDate>Fri, 07 Feb 2014 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2014-02-07-mtgox/</guid><description>MtGox was hacked. Losses totalled 850,000 BTC, worth $470m at the time.</description></item><item><title>Feathercoin</title><link>https://0xtracer.xyz/incidents/2013-06-08-feathercoin/</link><pubDate>Sat, 08 Jun 2013 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2013-06-08-feathercoin/</guid><description>On June 8, Feathercoin was attacked by 51%. Before the attack, Feathercoin&amp;rsquo;s total computing power was 0.2GH/s, and during the time of the attack, the computing power doubled 7 times to 1.5GH/s. Thirty-one hours later&amp;hellip;</description></item><item><title>Bitfloor</title><link>https://0xtracer.xyz/incidents/2012-09-05-bitfloor/</link><pubDate>Wed, 05 Sep 2012 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2012-09-05-bitfloor/</guid><description>Bitcoin exchange Bitfloor suspended operations after the theft of $250,000. The founder Roman Shtylman explained in a post on the Bitcoin Forum that an attacker obtained an unencrypted backup of exchange wallet keys a&amp;hellip;</description></item><item><title>Bitcoinica</title><link>https://0xtracer.xyz/incidents/2012-05-14-bitcoinica/</link><pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2012-05-14-bitcoinica/</guid><description>Bitcoinica was hacked twice in 2012. Hackers stole a total of 61,000 BTC, leading to the bankruptcy of Bitcoinica.</description></item><item><title>Coiledcoin</title><link>https://0xtracer.xyz/incidents/2012-01-06-coiledcoin/</link><pubDate>Fri, 06 Jan 2012 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/incidents/2012-01-06-coiledcoin/</guid><description>The attacker has a lot of computing power to launch a 51% attack. The interesting thing about the Coiledcoin attack is that it is not economically driven, but purely political. Although this move has caused some prote&amp;hellip;</description></item><item><title>About</title><link>https://0xtracer.xyz/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/about/</guid><description>about</description></item><item><title>Hack Dashboard</title><link>https://0xtracer.xyz/dashboard/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://0xtracer.xyz/dashboard/</guid><description>DeFi/Web3 hack incidents database</description></item></channel></rss>