GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
Blockaid

Blockaid

Active

Web3 security firm

News Heat Trend

Project Overview

Blockaid is a Web3 security tools stop malicious transactions before they happen, protecting web3 users from scams, phishing, and hacks.

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

Approximately $9.3 million in funds affected; More Markets suffers attack, attacker drains 15.5 million WFLOW

Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.

Lumi Finance Suspected to Be Attacked, Current Losses Approximately $270,000

According to Blockaid monitoring, the Lumi Finance protocol on Arbitrum is under attack, and approximately $270,000 in funds have been transferred out so far.

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

JaredFromSubway’s MEV Bot Attacked, Suffers $7.5 Million Loss

According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.

MILC Platform Cross-Chain Bridge Suffers Private Key Leak Attack, Sustaining ~$161,000 in Losses

According to on-chain security platform Blockaid (@blockaid_), the MILC Platform cross-chain bridge suffered a private key leak on both the BNB Chain and Ethereum networks. The attacker exploited a historical bridge administrator wallet to grant the DEFAULT_ADMIN_ROLE and MANAGER_ROLE permissions to the attacker’s address. Subsequently, assets were withdrawn from the bridge contract, and administrative control was transferred to the attacker’s wallet. Confirmed losses currently stand at approximately $97,003 USDT (on BNB Chain) and approximately 39.21 ETH (on Ethereum, transferred out via Rhino.fi), totaling roughly $161,000.

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

A user's Safe wallet on Ethereum was attacked, resulting in the loss of approximately $7.73 million worth of rsETH.

Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

Approximately $9.3 million in funds affected; More Markets suffers attack, attacker drains 15.5 million WFLOW

Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.

Moonwell on the Base chain suffers a suspicious attack, losing over $4 million in cbBTC

According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

Well-known MEV bot Jaredfromsubway.eth suffers reverse attack, losing over $7.5 million

Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)

MetaMask Launches AI Agent Wallet Supporting Cross-Chain DeFi Operations with Built-in Transaction Security Protection

According to MetaMask’s official blog, MetaMask has officially launched its first self-custodial wallet designed specifically for AI agents—MetaMask Agent Wallet—and will begin its Early Access Program on June 8, 2026. The wallet connects to AI agent frameworks via a command-line interface (CLI) and supports the full suite of DeFi functionalities—including token swaps, perpetual contracts, prediction markets, and liquidity provision—across all EVM-compatible chains (Ethereum, Arbitrum, Base, Avalanche, Optimism, Polygon, BSC, Linea, Sei) as well as Hyperliquid. On security, the wallet offers two operational modes: - Default “Guard Mode” allows users to set daily spending limits and protocol allowlists; transactions exceeding these rules require manual two-factor authentication (2FA) approval before execution. - “Beast Mode” grants advanced users greater autonomy, but malicious transaction detection and mandatory 2FA verification remain enforced. All transactions undergo transaction simulation, Blockaid threat scanning, and MEV protection. Secure transactions are backed by up to $10,000 per month in transaction protection. Users retain full control of their private keys and can export their seed phrase at any time. The full public release is expected this summer.

Related news

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

A user's Safe wallet on Ethereum was attacked, resulting in the loss of approximately $7.73 million worth of rsETH.

Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

Approximately $9.3 million in funds affected; More Markets suffers attack, attacker drains 15.5 million WFLOW

Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.

Moonwell on the Base chain suffers a suspicious attack, losing over $4 million in cbBTC

According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.