Posts

Showing posts with the label exploit

RWA platform Zoth suffers second hack this month — loses $8.4M

Zoth, a real-world asset (RWA) restaking layer, has been hacked for $8.4 million of staked USD0++ after someone tampered with its proxy contract.  X user @0xtroll first spotted the exploit today. Blockchain security analyst Cyvers deduced that somebody using a suspicious address was able to tweak Zoth’s “USD0PPSubVaultUpgradeable” contract.  The hacker then withdrew $8.45 million worth of USD0++ before swapping it for DAI and back into ether (ETH), where 4,223 ETH (worth $8.29 million) currently sits. SlowMist Security Alert We have detected that @zothdotio has been exploited, likely due to a leakage of Admin privileges, resulting in the logic contract being tampered with and replaced by a malicious contract. Btw, thanks to @0xtroll for the shout-out. As always, stay… pic.twitter.com/nQfHPYT2OV — SlowMist (@SlowMist_Team) March 21, 2025 Read more: ‘AI’ crypto trading agent, aixbt, hacked for $100K Crypto analysts SlowMist also suggested that Zoth...

US indicts Ethereum validators for exploiting MEV trader

Anton Peraire-Bueno and James Peraire-Bueno, two brothers who operate Ethereum validators, have been indicted in the Southern District of New York on charges of wire fraud, conspiracy to commit wire fraud, and conspiracy to commit money laundering. The charges related to a scheme that has been described as exploiting the ‘very integrity of the Ethereum Blockchain to fraudulently obtain approximately $25 million.’ The brothers allegedly worked together on a complex exploit that allowed them to take advantage of traders searching for ‘maximum extractable value’ (MEV) on Ethereum.  By operating multiple Ethereum validators, the brothers were allegedly able to submit blocks that included exploited transactions . Allegedly, once the brothers were aware that their validators would soon have opportunities to submit blocks, they would create ‘bait’ transactions that seemed to have significant upside for the MEV traders and wait for those traders to attem...

X users at risk as crypto scammers exploit new design flaw

Crypto scammers have found a new way to abuse X interface to propagate scams, fake giveaways, and deceptive Telegram channels. As reported by BleepingComputer, fraudsters have started actively taking advantage of what appears to be a user interface flaw, enabling them to create seemingly legitimate URLs containing malicious content. This flaw, initially identified by X user @rcwht_, empowers scammers to publish tweets that mimic those from authentic accounts. Interesting scam crypto-related tweets. Link looks like it should direct to binance, but actually direct to some scammy account. Been tagged in two of these and they both use https://t.co/2HhH3FW3nT – anyone know whats going on here? pic.twitter.com/NVtFkm12d6 — Rob White (@rcwht_) December 17, 2023 According to BleepingComputer, scammers can change the status_id field, while putting the legitimate tag in the account_name field. For instance: https://x.com/[account_name]/status/[status_id] would look like ...

Base project RocketSwap shares emergency plan following $865K exploit

RocketSwap Labs plans on reaching out to the exploiter on-chain, who stole an estimated $865,000 from the protocol on Aug. 14. Base project RocketSwap Labs has outlined its emergency programme to bounce back from a brute force hack which swiped $865,000 or 471 Ether (ETH) from the protocol on Aug. 14. The team explained on Aug. 15 that they plan on redeploying a new farm contract and open-source it on-chain, relinquish minting rights — presumably of RCKT — and will soon call on the hackers to return the assets, among other things: The emergency programme agreed upon by the team is as follows. 1. We plan to redeploy a new farm contract by dropping the proxy contract and open sourcing it on-chain. 2. The new farm will advance the production reduction plan by 0.075 per block. 3. The team relinquishes… — RocketSwap (@RocketSwap_Labs) August 15, 2023 On Aug. 14, a hacker stole approximately 471 ETH and bridged it from Base to Ethereum, according to blockchain security firm PeckShi...

Hedera confirms exploit on mainnet led to theft of service tokens

Image
Hedera said the smart contract exploit on Mar. 9 has not impacted the network or its consensus layer. Hedera, the team behind distributed ledger Hedera Hashgraph, has confirmed a smart contract exploit on the Hedera Mainnet that has led to the theft of several liquidity pool tokens. Hedera said the attacker targeted liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over to use on the Hedera Token Service. Today, attackers exploited the Smart Contract Service code of the Hedera mainnet to transfer Hedera Token Service tokens held by victims’ accounts to their own account. (1/6) — Hedera (@hedera) March 10, 2023 The Hedera team explained that the suspicious activity was detected when the attacker attempted to moved the stolen tokens across the Hashport bridge, which consisted of liquidity pool tokens on SaucerSwap, Pangolin and HeliSwap. However, operators then acted promptly to temporarily pause the bridg...

The 10 largest crypto hacks and exploits in 2022 saw $2.1B stolen

Just the top 10 major cryptocurrency exploits garnered over $2 billion for malicious actors in a year that was marred with bankruptcies and collapses. It's been a turbulent year for the cryptocurrency industry — market prices have taken a huge dip, crypto giants have collapsed and billions have been stolen in crypto exploits and hacks. It was not even halfway through October when Chainalysis declared 2022 to be the “biggest year ever for hacking activity.” As of Dec. 29, the 10 largest exploits of 2022 have seen $2.1 billion stolen from crypto protocols. Below are those exploits and hacks, ranked from smallest to largest. 10: Beanstalk Farms exploit — $76M Stablecoin protocol Beanstalk Farms suffered a $76 million exploit on April 18 from an attacker using a flash loan to buy governance tokens. This was used to pass two proposals that inserted malicious smart contracts. The exploit was initially thought to have cost around $182 million as Beanstalk was drained of all its collater...