WebSocket access to Defimon's real-time feed of onchain attacks is now easier to get.
We've enabled a self-service checkout at defimon.xyz and in Telegram via t.me/defimon_subscr…
Yesterday we reported a governance attack to @ZKPanther which drained 5.12M $ZKP.
Attacker submitted a governance proposal named "zkp-reexploit" to upgrade each ZKP proxy to the drainer impl. Then they posted a "yes" answer with the 0.5
🚨 Arbitrary Call Injection in @unistreetsx on Ethereum - Loss ~$17750
LaunchpadFactoryAuto's launch() forwards attacker-supplied initCalldata/modifyCalldata verbatim into PositionManager.multicall() with the factory as msg.sender and no validation. The factory custodies every
Security Incident & Migration — please read in full
We owe you complete transparency about a serious security incident, and what we've done to fix it.
WHAT HAPPENED
Our launch factory contract had a critical flaw: it accepted transaction data supplied by the caller and
💬 Onchain Message:
Hello Whitehat, We've seen that you've exploited an vulnerability in us and rescued the user funds from us. We are looking forward you to send back us the funds for little bounty amount as reward. We've texted you on blockscan with the same address. Please
💬 Onchain Message:
Hi,
I am the victim of the phishing attack (wallet: 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c).
You stole approximately 500,000 USDC from me on Base. Attack transaction: 0xd2324b49161b53218651eae2852f8684fa68015cfcada94e5c0ad14030fc62ba
I have identified