GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Gnosis Safe Wallet Hacked, $7.8M Worth of rsETH Stolen

According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.

A user's Safe wallet on Ethereum was attacked, resulting in the loss of approximately $7.73 million worth of rsETH.

Blockaid stated that its vulnerability detection system identified that a Safe wallet belonging to an unidentified user on Ethereum was compromised, resulting in confirmed losses of approximately $7.73 million in rsETH. The attacker leveraged a public keeper's multi-call to route the custom Uni V4 LP Safe module to a hook-enabled liquidity pool they created, causing the associated hook to unwrap aEthrsETH into rsETH. The exploit was extracted via MEV within the block.

Hacker Exploits Symbiosis Bitcoin Bridge Vulnerability to Mint ~$46.1 Billion in Face Value syBTC, Cashes Out Only $336,000

Odaily News: On-chain security platform Blockaid has discovered a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The attacker minted approximately 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion calculated at 8 decimal places, and sold approximately 4.39 WBTC on Uniswap V4 on Ethereum, realizing a cash-out of about $336,000.Symbiosis stated that the attack occurred at around 4:28 AM on September 11. The team has paused the BTC route, while other routes remain operational and unaffected. The team has recovered approximately 15 BTC and deposited them into a multisig wallet controlled by the team. They have also offered the attacker a 20% white-hat bounty, with a deadline of September 13.In recent weeks, Liquid Network, Nomic, and Symbiosis have all experienced security incidents involving the inflation of supply through the minting of tokens without real asset backing. As of September 13, Symbiosis has not yet publicly released a BridgeV2 technical post-mortem, the final loss amount, or confirmation of whether the attacker has accepted the bounty. (Bitcoin.com News)

Cozy Finance Suffers Ongoing Attack on Optimism, Approximately $170,000 in Assets Stolen

Odaily News DeFi risk management protocol Cozy Finance is currently facing an ongoing attack on its Optimism deployment, with attackers having stolen approximately $170,000 in assets so far. Blockaid has subsequently released preliminary attack information and flagged the attacking transactions along with related attacker addresses. Multiple attacker addresses have now been confirmed, along with a token address suspected to have been exploited in the attack. It remains unclear whether the attack is still ongoing, and users should exercise caution when interacting with contracts associated with Cozy Finance.

Approximately $9.3 million in funds affected; More Markets suffers attack, attacker drains 15.5 million WFLOW

Odaily News: According to blockchain security firm Blockaid's monitoring, More Markets (More Labs) on Flow EVM has been exploited. The attacker leveraged Ankr's liquid staking tokens and the E-Mode mechanism to drain More Markets' WFLOW lending reserves, transferring approximately 15.5 million WFLOW from the mFlowWFLOW reserve. The detected impact amount is approximately $9.3 million, and the related attack transaction cluster also includes post-exploit fund transfer operations. At present, the specific losses and the destination of the attacker's funds are still under further confirmation.

Moonwell on the Base chain suffers a suspicious attack, losing over $4 million in cbBTC

According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.

Crypto DAO's Pro token suffered an attack, with the attacker and profit addresses holding approximately 8.2 million USDT.

According to Blockaid monitoring, Crypto DAO's Pro token was attacked. As of 00:23 early this morning, the attacker and related profit addresses currently hold a combined total of approximately 8.2 million USDT.

In the first half of 2026, crypto hack losses exceeded $1 billion, with Ethereum and Solana leading the losses.

: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

Arbitrum ecosystem protocol AFX cross-chain bridge attacked, approximately 24.15 million USDC lost

据 Blockaid 监测,Arbitrum 生态协议 AFX 于北京时间 7月 23日 5:30 遭攻击。此次攻击针对 AFX 运营的跨链桥,迄今已导致协议约 2415 万枚 USDC 被转移。Blockaid 称,正与 Arbitrum 团队协作响应事件,并协助相关协议控制被盗资金风险。

Ostium Halts Trading; Oracle Vulnerability Causes Tens of Millions of Dollars in Losses

Decentralized trading protocol Ostium paused trading due to suspected exploitation of its oracle system, with security firms Blockaid and CertiK estimating losses between $18 million and $22 million.

Ostium Attacked, Losses Approximately $18 Million

Blockaid stated that it detected a vault exploit incident involving Ostium on Arbitrum. The attacker fabricated false trading profits through registered PriceUpKeep Forwarders and authorized oracle reports with future timestamps, triggering a payout of approximately 18 million USDC from the vault.

Lumi Finance Suspected to Be Attacked, Current Losses Approximately $270,000

According to Blockaid monitoring, the Lumi Finance protocol on Arbitrum is under attack, and approximately $270,000 in funds have been transferred out so far.

Summer.fi 遭受攻击,损失约 600 万美元资金

According to Blockaid monitoring, Summer.fi was attacked, resulting in a loss of approximately $6 million in funds.

Yield Yak Suffers Frontend Attack; Malicious Code Injected into Subdomain

According to Blockaid’s monitoring, the Yield Yak website has suffered a front-end attack. The website’s subdomain currently contains code from eleven drainers. This attack method is similar to the one previously used against Gitcoin.

Taiko bridge attack may result in losses up to $1.7 million

Ethereum Layer 2 blockchain Taiko has stated its chain state verification mechanism has been compromised, and the security assumptions of all bridges deployed on Taiko can no longer be relied upon. It urges users to immediately withdraw funds from the relevant bridges. Taiko says it is coordinating with partners to control the incident and has suspended the affected systems.Crypto security firm Blockaid stated that the root cause appears to be a flaw in the way Taiko's bridge validates source signals. Attackers can submit message proofs on Ethereum that lack legitimate proof from the Taiko chain, thereby registering and withdrawing fraudulent bridge messages. This leads to the unauthorized release of assets from the ERC20 treasury. Blockaid estimates at least $1 million was stolen, while Lookonchain and PeckShield believe the value of stolen assets could be as high as $1.7 million.PeckShield reported that the attacker has transferred approximately 1.99 million TAIKO tokens to MEXC, valued at around $189,000. Data from blockchain intelligence firm Arkham shows that the Taiko attacker's wallet holds approximately $1.5 million in assets, primarily in Ether. (Cointelegraph)

Taiko ERC20 Vault Attacked, Loss Exceeds $1 Million

Blockaid monitoring reported that Taiko’s ERC-20 treasury on Ethereum was attacked, resulting in losses exceeding $1 million. Preliminary analysis suggests the issue may stem from a vulnerability in Taiko’s cross-chain bridge proof verification, enabling the attacker to forge cross-chain messages and withdraw assets—causing unauthorized release of treasury funds.

Gitcoin Subdomain Suffers Frontend Attack Containing Eleven Drainer Malicious Code

According to security firm Blockaid (@blockaid_), its monitoring engine detected a front-end attack targeting the @gitcoin subdomain files[.]gitcoin[.]co, which contains malicious Eleven drainer code. Blockaid advises users to refrain from any interaction with this website while the issue is under investigation and remediation.

Well-known MEV bot Jaredfromsubway.eth suffers reverse attack, losing over $7.5 million

Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has been attacked by hackers exploiting a vulnerability in its automated execution system, resulting in losses exceeding $7.5 million.Security firm Blockaid stated that the incident was not a traditional phishing attack or smart contract vulnerability, but rather an "anti-MEV honeypot attack" specifically targeting the decision-making logic of the MEV bot. Over several weeks, the attacker deployed 66 fake token contracts and false liquidity pools, masquerading as assets such as WETH, USDC, and USDT, luring the bot into executing seemingly profitable trades and authorizing auxiliary contracts controlled by the attacker.Ultimately, in a single transaction, the attacker invoked all backdoor permissions to transfer the ETH, USDC, and USDT held by the bot's address. Data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% of them linked to Jaredfromsubway.eth. (Cointelegraph)

JaredFromSubway’s MEV Bot Attacked, Suffers $7.5 Million Loss

According to on-chain analyst Blockaid (@blockaid_), the well-known Ethereum MEV bot JaredFromSubway (@jaredsmev) has been attacked, resulting in losses of approximately $7.5 million. The attacker constructed a deceptive MEV arbitrage path to trick the bot into automatically approving token transfers. Leveraging these open approvals—before they were revoked—the attacker drained WETH, USDC, and USDT from the bot’s contract. The stolen funds ultimately flowed to the attacker’s wallet address. Blockaid noted that this attack was not a conventional phishing attempt or smart contract vulnerability, but rather a targeted exploitation of the bot’s automated execution mechanism.