The most material incident is a CertiK-reported breach on XDC Network for $860M via access control. Additional losses include a $47M infostealer takedown and a $7.5M sandwich attack. Dominant vectors are smart-contract bugs, supply-chain attacks, and access-control failures. Items are slightly thin due to one source failing, but multiple high-impact events occurred.
New on @MetaMask: Chonky, our AI-powered audit framework, and its core method - vulnerability mining. Built on three years of AI security work and 100k+ vulnerability findings from across Ethereum, Chonky is code- and process-agnostic. It mines a high volume of candidates to [Protocols: across]
@ConsensysAudits: New on @MetaMask: Chonky, our AI-powered audit framework, and its core method - vulnerability mining.
Sam: “Okay team. We all agree the Mythos name alone was begging to be drone stiked by the USG. We need names for these new models that….isn’t that.” Intern: “Cupcakes? Everyone loves cupcakes!” Intern: “Puppies?” Intern: “Rainbows? Unicorns!” Greg: “Gay.” Sam: “….” Greg: https://t.co/retv30qvow
@tayvano_: Sam: “Okay team. We all agree the Mythos name alone was begging to be drone stiked by the USG. We need names for these…
🔍A 32-byte omission. A multi-million-dollar lesson. The root cause of the SecondFi wallet incident: the secret prefix used in Ed25519 nonce generation was dropped during implementation, allowing the private key to be mathematically recovered from a single on-chain signature. https://t.co/L3a4eMQogR
@Beosin_com: 🔍A 32-byte omission. A multi-million-dollar lesson.
dear god why please put the nerds back in their silo thank you https://t.co/TSi0XF0Ryk [Protocols: silo]
@tayvano_: dear god why
nontechnical vibecoder chain https://t.co/3ZuduAszU0
@spreekaway: nontechnical vibecoder chain https://t.co/3ZuduAszU0
🧵1/3 🧯Old contract exploits keep happening — how should projects respond? Recently, smart contract vulnerability attacks have been occurring frequently. In particular, legacy contracts deployed years ago are being increasingly exploited as attackers leverage AI techniques to https://t.co/1txrdXwlxc
@GoPlusSecurity: 🧵1/3
🚨 SlowMist TI Alert 🚨 The Mini Shai-Hulud, Miasma, and Hades malware family, now expanding beyond npm into the Go module ecosystem. Affected Go modules: https://t.co/CRRD64BbZv https://t.co/wFOScxyaxw https://t.co/dt2Som48vx is a Cosmos SDK-based Layer 1 blockchain project https://t.co/2Rft5D5ugG
@SlowMist_Team: 🚨 SlowMist TI Alert 🚨
🚨GoPlus Security Alert: #Polymarket suffered a supply chain attack, with multiple users losing approximately $3 million @Polymarket Due to a compromise of a third-party vendor, malicious code was injected into the frontend. Around 15 user accounts collectively lost https://t.co/j0Ol2wY0VK https://t.co/La1aKILSwX [Loss ~$3,000,000]
@GoPlusSecurity: 🚨GoPlus Security Alert:
the good news: this makes slightly more sense than SBF's bet the bad news: they still don't know what log(0) is https://t.co/rcX2H3WGEg
@spreekaway: the good news: this makes slightly more sense than SBF's bet
Even the DAO extractoooors are capitulating https://t.co/vjTvQSRcjb
@spreekaway: Even the DAO extractoooors are capitulating https://t.co/vjTvQSRcjb
Genuinely what the fuck do you want the govt to do about this? This framing is so constant with these fucktards and it’s absolutely why the USG is now blocking access to the latest models. 🤬 “We control the most powerful shit but can’t detect or prevent it from getting in the https://t.co/BMWGNfwLAL
@tayvano_: Genuinely what the fuck do you want the govt to do about this?
Completely insane to let the fucking government control your product, release processes, and, ultimately, your profits. What the fuck are you guys doing. https://t.co/naHqtROAu3
@tayvano_: Completely insane to let the fucking government control your product, release processes, and, ultimately, your profits.
One of my 4am tweets mentions nonce reuse. I was speaking casually bc I was flabbergasted by just how fucking stupid this is. And nonce reuse is historically the stupidest thing so they got crossed in my heads. I got the other one right, so I'll repeat it now: These guys rolled https://t.co/kSnep3Z9YC
@tayvano_: One of my 4am tweets mentions nonce reuse. I was speaking casually bc I was flabbergasted by just how fucking stupid th…
AI agents move funds on-chain at machine speed. One compromised compliance oracle can push them into a sanctions violation. 🚨 The fix is layered: multiple oracles, default-deny on outages, reject stale data, on-chain logs, circuit breakers. 👇 https://t.co/YDTMzTNIFQ
@HalbornSecurity: AI agents move funds on-chain at machine speed. One compromised compliance oracle can push them into a sanctions violat…
#PeckShieldAlert @apyx_fi's $apxUSD has dropped below $0.8. https://t.co/YUYPIEuRDF [Loss ~$0.8]
@PeckShieldAlert: #PeckShieldAlert @apyx_fi's $apxUSD has dropped below $0.8. https://t.co/YUYPIEuRDF
Most RWAs are Treasuries. @XDCNetwork is different. Over $860M in tokenized real-world credit, including debentures, receivables, and business loans, settles on XDC. CertiK now helps secure that infrastructure as an XDC validator. Learn more below. https://t.co/wnqTci2Ktk [Loss ~$860,000,000]
@CertiK: Most RWAs are Treasuries. @XDCNetwork is different.
the latest tornado cash proposal 67 is _malicious_: https://bafybeie5hxovqc4ifcnrnhvmjbefxgeix6oqvzaspyytdxiyscji22v5pu[.]ipfs[.]inbrowser[.]link/governance/67 decompilation of the proposal: https://t.co/bfGfEkb1o3 the try to set the governance address to a vanity address that https://t.co/0VbG4KO9Yc https://t.co/rny5WWdd8M
@pcaversaccio: the latest tornado cash proposal 67 is _malicious_: https://bafybeie5hxovqc4ifcnrnhvmjbefxgeix6oqvzaspyytdxiyscji22v5pu…
Sources unavailable: Immunefi (Invalid character in tag name Line: 34 Column: 49 Char: @)
Generated by GM Security · automated digest, verify before acting.