{"data":[{"id":"294449","source":"thatsrekt","sourceId":"thatsrekt-base-5","chainId":8453,"chainSlug":"base","onchainId":"5","title":"Moonwell Base MAMO/mMAMO Donation Exploit","description":"On August 27, 2026, Moonwell Base experienced an exploit related to its MAMO/mMAMO donation mechanism. An unauthorized actor manipulated the mMAMO price on the Base network.\n\nThe exploit involved inflating the value of mMAMO by donating MAMO to a specific contract, which altered the exchange rate. This allowed the actor to borrow approximately $11M worth of assets, including cbBTC and USDC, from various lending markets within Moonwell Base.\n\nThe incident resulted in an estimated loss of $11M, with approximately $8.7M transferred and bridged to DAI on the Ethereum network. The residual bad debt on Moonwell Base is estimated at $9.13M. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x719eae70d4a83f35bf82a2740699f5db84be919d","0xd71dd9b6e634412713c47fe7ae02c628e338c384"],"victims":["0x2f90bb22eb3979f5ffad31ea6c3f0792ca66da32","0xf877acafa28c19b96727966690b2f44d35ad5976","0x7300b37dfdfab110d83290a29dfb31b1740219fe","0xfbb21d0380bee3312b33c4353c8936a0f13ef26c"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":11000000,"severity":"Critical","txHash":"0x09687d741d92a2607a1d63014104bbad663347a79d7949d0f3073c84a395593e","nativeUrl":"https://thatsrekt.com/post/base/5","links":[{"url":"https://thatsrekt.com/post/base/5","label":"thatsRekt"},{"url":"https://x.com/officer_secret/status/2092909985613185517","label":"Source"},{"url":"https://x.com/officer_secret/status/2092909798207434762","label":"Source"},{"url":"https://x.com/blockaid_/status/2092912022555902094","label":"Source"},{"url":"https://x.com/blockaid_/status/2092912575797190689","label":"Source"},{"url":"https://x.com/exvulsec/status/2092912846036402674","label":"Source"},{"url":"https://x.com/officer_secret/status/2092913621709779174","label":"Source"},{"url":"https://x.com/blockaid_/status/2092912743732937094","label":"Source"},{"url":"https://x.com/officer_secret/status/2092914010018472124","label":"Source"},{"url":"https://x.com/blockaid_/status/2092914508666753081","label":"Source"},{"url":"https://x.com/CertiKAlert/status/2092917519946539061","label":"Source"},{"url":"https://x.com/officer_secret/status/2092950111449985184","label":"Source"}],"affectsTrackedUniverse":true,"attackedAt":"2026-08-27T00:00:00.000Z","promotedEventId":null},{"id":"147034","source":"thatsrekt","sourceId":"thatsrekt-bsc-7","chainId":56,"chainSlug":"bsc","onchainId":"7","title":"PancakeSwap LP Mistake Resulted in ~$950K BNB Extraction","description":"On June 22, 2026, a user mistakenly transferred LP tokens directly to the PancakeSwap V2 pair contract for the ATM token on the BSC chain. This action created an imbalance that was exploited by a monitoring bot.\n\nOn-chain data shows that a bot utilized the imbalance to extract approximately 1,571 BNB. This exploit was facilitated by a bribe to a BlockRazor builder for priority transaction inclusion.\n\nThe incident resulted in a loss of approximately $950,000 USD. The root cause is under investigation, but initial analysis suggests it was an exploitation of user error via pair mechanics rather than a protocol vulnerability.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x66de38da216d6fcc3f9aa944f592546e3eae2dd0"],"victims":["0xbe8351c14e5108a57a545dfa8669fa31aa6adc68"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":950000,"severity":"Warning","txHash":"0x5c27edc326e38641d8ce6093cd7f15ae5fca039f5fb988b7f10cb432e6e3a056","nativeUrl":"https://thatsrekt.com/post/bsc/7","links":[{"url":"https://thatsrekt.com/post/bsc/7","label":"thatsRekt"},{"url":"https://x.com/TenArmorAlert/status/2068993748936151209","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-22T09:23:00.000Z","promotedEventId":null},{"id":"141337","source":"thatsrekt","sourceId":"thatsrekt-ethereum-26","chainId":1,"chainSlug":"ethereum","onchainId":"26","title":"Taiko Vault Exploit","description":"On June 21, 2026, Taiko experienced an exploit affecting its ERC20 Vault proxy on the Ethereum network. Unauthorized access resulted in the transfer of funds from the vault.\n\nOn-chain data shows that forged bridge proofs were utilized to facilitate the unauthorized access. The exploit involved transactions that transferred USDC from the vault and subsequently withdrew ETH. The root cause is under investigation.\n\nThe incident resulted in a loss of approximately $1.7M. The affected vault is identified as 0x996282cA11E5DEb6B5D122CC3B9A1FcAAD4415Ab. The remediation status is currently unresolved.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x7506dea0c38ca0b55364b22424374c5a1ae1b76a","0x3cc936b795a188f0e246cbb2d74c5bd190aecf18","0x9108828e30f2de407aadb0af677b4a9228e4acd4"],"victims":["0x996282ca11e5deb6b5d122cc3b9a1fcaad4415ab","0xd60247c6848b7ca29eddf63aa924e53db6ddd8ec"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":1700000,"severity":"Critical","txHash":"0x017292a7de5fef52a3274e37dda5ace4c4d0cdafe91b7b4ac9c700f02fae35ee","nativeUrl":"https://thatsrekt.com/post/ethereum/26","links":[{"url":"https://thatsrekt.com/post/ethereum/26","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2068831451852816861","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-21T22:07:23.000Z","promotedEventId":null},{"id":"127913","source":"thatsrekt","sourceId":"thatsrekt-ethereum-25","chainId":1,"chainSlug":"ethereum","onchainId":"25","title":"JaredFromSubway MEV Bot Unauthorized Access","description":"On June 20, 2026, the JaredFromSubway MEV Bot on the Ethereum network experienced an unauthorized access event. The incident involved the transfer of funds from the bot's contract to attacker-controlled addresses.\n\nOn-chain data and analysis from Blockaid indicate that the unauthorized access occurred through the use of fake fWETH, fUSDC, and fUSDT wrapped token routes. These fake routes were utilized to trick the MEV bot into granting persistent approvals to helper contracts, which were then used to facilitate the fund extraction.\n\nThe incident resulted in a loss of approximately $7.5M in WETH, USDC, and USDT. The affected funds were transferred from the bot contract 0x1f2f10d1c40777ae1da742455c65828ff36df387 to attacker addresses. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x5af38735b215b00aa7c9f93fed7ee415cecb36e1","0xb84db016324e8f2bfdd8dd9c260338aee0a8df52","0x3e37f4a10d771ba9de44b6d301410b1bedea65d0"],"victims":["0x4ee0b6e9f9c4886beeef2ebd7fc27223169531ce","0x1f2f10d1c40777ae1da742455c65828ff36df387","0xae2fc483527b8ef99eb5d9b44875f005ba1fae13"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":7500000,"severity":"Critical","txHash":"0x85609286d68bd47065772c21fd9542c4343348ff8c7c2e6d63d0692be5781915","nativeUrl":"https://thatsrekt.com/post/ethereum/25","links":[{"url":"https://thatsrekt.com/post/ethereum/25","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2068433948447736163","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-20T20:40:00.000Z","promotedEventId":null},{"id":"127861","source":"thatsrekt","sourceId":"thatsrekt-ethereum-24","chainId":1,"chainSlug":"ethereum","onchainId":"24","title":"JaredSMEV MEV Bot Drained ~$7.5M via Fake MEV Routes","description":"Attacker created fake fWETH/fUSDC/fUSDT + fCAP pools/routes tricking MEV bot into approving helpers (e.g. 0x4ee0b6e9f9c4886beeef2ebd7fc27223169531ce). Open approvals drained via sweep to attacker 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0 from bot contract 0x1f2f10d1c40777ae1da742455c65828ff36df387 (jaredfromsubway.eth 0xae2fc483527b8ef99eb5d9b44875f005ba1fae13). Blockaid confirmed; example approval tx 0x85609286d68bd47065772c21fd9542c4343348ff8c7c2e6d63d0692be5781915.\n\nAttacked chains: [1]\n\nExploit txs:\n  0x2be8704f5a59b69e0b71f64aefdb99eb0e8ae9fb3926147c581910d71bcf3e65\n  0x85609286d68bd47065772c21fd9542c4343348ff8c7c2e6d63d0692be5781915\n\nSources:\n  https://x.com/blockaid_/status/2068433798757577198","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x3e37f4a10d771ba9de44b6d301410b1bedea65d0","0x4ee0b6e9f9c4886beeef2ebd7fc27223169531ce"],"victims":["0x1f2f10d1c40777ae1da742455c65828ff36df387","0xae2fc483527b8ef99eb5d9b44875f005ba1fae13"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":7500000,"severity":"Critical","txHash":"0x85609286d68bd47065772c21fd9542c4343348ff8c7c2e6d63d0692be5781915","nativeUrl":"https://thatsrekt.com/post/ethereum/24","links":[{"url":"https://thatsrekt.com/post/ethereum/24","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2068433798757577198","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-20T18:49:11.000Z","promotedEventId":null},{"id":"124136","source":"thatsrekt","sourceId":"thatsrekt-ethereum-23","chainId":1,"chainSlug":"ethereum","onchainId":"23","title":"PancakeSwap V2 OLPC/LABUBU Pair Exploit","description":"On June 20, 2026, an exploit affected the PancakeSwap V2 OLPC/LABUBU pair on the BNB Chain. The exploit involved a desynchronization between burn-on-transfer operations and the pair's reserves.\n\nOn-chain data indicates that the exploiter utilized a vulnerability in the burn-on-transfer mechanism, which resulted in reserves being burned to a dead address. This desynchronization allowed the exploiter to sweep LABUBU tokens. These tokens were then routed through listed pools to exit via USDT.\n\nThe incident resulted in a loss of approximately $1.11M USD. The exploiter transferred funds to various destinations, including Tornado Cash on the Ethereum network. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x18d6c39ae9e537f948aa2212d44d8c23944fc188"],"victims":["0xedb7dcb4cdfec957f8df5cbf5e94229a6cc9f365","0x58815cdf9955121a6274680ab396a36fc9e00000","0x3494dfe19b721dac6c5c8d7470c8f89548177777","0xdfacdc33e913710ead31ee40f9c5363ea673c421","0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":1110000,"severity":"Critical","txHash":null,"nativeUrl":"https://thatsrekt.com/post/ethereum/23","links":[{"url":"https://thatsrekt.com/post/ethereum/23","label":"thatsRekt"},{"url":"https://x.com/exvulsec/status/2068308334512365924","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-20T12:00:00.000Z","promotedEventId":null},{"id":"123824","source":"thatsrekt","sourceId":"thatsrekt-bsc-6","chainId":56,"chainSlug":"bsc","onchainId":"6","title":"PancakeSwap OLPC/LABUBU V2 Pool Exploit","description":"On June 20, 2026, a PancakeSwap V2 liquidity pool for OLPC and LABUBU tokens on BNB Chain was affected by an exploit. An unauthorized transfer of OLPC tokens through an attacker contract initiated a desynchronization of reserves by causing massive burns of OLPC and LABUBU tokens to a dead address. The attacker then extracted LABUBU tokens from the pool and routed them through other pools, resulting in a total loss of approximately $1.11M USD.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x18d6c39ae9e537f948aa2212d44d8c23944fc188"],"victims":["0xedb7dcb4cdfec957f8df5cbf5e94229a6cc9f365","0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae","0x3494dfe19b721dac6c5c8d7470c8f89548177777","0x58815cdf9955121a6274680ab396a36fc9e00000","0xdfacdc33e913710ead31ee40f9c5363ea673c421"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":1110000,"severity":"Critical","txHash":"0x8dabb60a94e5124462e5f494a25c14bcd52f6f4d1f7c665a249496f4c6c24764","nativeUrl":"https://thatsrekt.com/post/bsc/6","links":[{"url":"https://thatsrekt.com/post/bsc/6","label":"thatsRekt"},{"url":"https://x.com/exvulsec/status/2068308334512365924","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-20T11:31:03.000Z","promotedEventId":null},{"id":"99676","source":"thatsrekt","sourceId":"thatsrekt-ethereum-22","chainId":1,"chainSlug":"ethereum","onchainId":"22","title":"Aztec Connect Deprecated Bridge — ~$2.15M Drained via EscapeHatch (Ethereum)","description":"Confirmed real exploit June 14 2026 on Ethereum. Attacker EOA 0x0f18d8b44a740272f0be4d08338d2b165b7edd17 (via intermediate contract) exploited ZK proof verification flaw in immutable deprecated contracts (incl. RollupProcessorV3 at 0xff1f...0455) using crafted rollup/escape hatch ops for unauthorized withdrawals of ETH/DAI/wstETH/etc. No admin control by Aztec Labs. Example exploit tx: 0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1. Current Aztec Network safe.\n\nAttacked chains: [1]\n\nExploit txs:\n  0xab306cd2184d23b6ba3e151b10b3b9a0b81f211cc16f4f3b0c79f0b17a59c2b5\n  0x5c196c37a109d74c9797254287a0331f30e0daa637af241bd28fdc43774705c3\n  0x9e1d6ab7c20ae235409d7dd3a9cd47c04f07293585b3498b8beed82d6f6b03ca\n  0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1\n\nSources:\n  https://x.com/CertiKAlert/status/2067497629127410058","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x6952d9246e9afe8b887b2877225163436f78e97f","0x0f18d8b44a740272f0be4d08338d2b165b7edd17"],"victims":["0x737901bea3eeb88459df9ef1be8ff3ae1b42a2ba","0xff1f2b4adb9df6fc8eafecdcbf96a2b351680455"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":2150000,"severity":"Critical","txHash":"0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1","nativeUrl":"https://thatsrekt.com/post/ethereum/22","links":[{"url":"https://thatsrekt.com/post/ethereum/22","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2067497629127410058","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-17T18:34:00.000Z","promotedEventId":null},{"id":"97422","source":"thatsrekt","sourceId":"thatsrekt-bsc-5","chainId":56,"chainSlug":"bsc","onchainId":"5","title":"Little Boy Plus (LBP) Exploit on BSC","description":"On June 17, 2026, Little Boy Plus (LBP) experienced an unauthorized access event affecting its LBP/USDT liquidity pool on the Binance Smart Chain (BSC). The incident resulted in a loss of approximately $378,000.\n\nOn-chain data shows that exploit transactions involved the deployment of contracts that interacted with the PancakeSwap V2 pool. These contracts executed large transfers of LBP tokens, USDT, and BNB, leading to the extraction of funds from the pool.\n\nThe incident impacted the LBP/USDT pool on BSC, resulting in a total loss of $378,000. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0xb26dfe6b6180a30e2a2d9826867cc7e06631825a","0x202ba7498c65f9f5c49b9c90953b562f9e0538fb"],"victims":["0x00e3ea08fd8cbad955ec5d2292ad637670c31524","0x5449ded887576f43fc339851e942ebc1e6f8118b","0x238a358808379702088667322f80ac48bad5e6c4","0x88886f0fd371dff856291badced45922bc888888","0x8f73b65b4caaf64fba2af91cc5d4a2a1318e5d8c","0x5e3cbc82d020be91a989eb747934104e9ab585fe","0x16b9a82891338f9ba80e2d6970fdda79d1eb0dae"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":378000,"severity":"Warning","txHash":"0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c","nativeUrl":"https://thatsrekt.com/post/bsc/5","links":[{"url":"https://thatsrekt.com/post/bsc/5","label":"thatsRekt"},{"url":"https://x.com/TenArmorAlert/status/2067421120186490970","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-17T08:35:38.000Z","promotedEventId":null},{"id":"87975","source":"thatsrekt","sourceId":"thatsrekt-bsc-3","chainId":56,"chainSlug":"bsc","onchainId":"3","title":"PancakeSwap V2 AIC-USDC pool unauthorized access","description":"On June 16, 2026, an unauthorized access occurred affecting the PancakeSwap V2 AIC-USDC pool on the Binance Smart Chain. On-chain data indicates that an external address interacted with a contract labeled \"ContractTest\" to perform token swaps and transfers.\n\nThis interaction resulted in the extraction of approximately 111,100 USDC. The DIP token contract involved in the transaction exhibits standard taxed token logic. The root cause is under investigation.\n\nThe incident resulted in a financial loss of $111,100. The affected entities include the PancakeSwap V2 AIC-USDC pool. The remediation status is currently unresolved.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x0d4024cd27538350a911d9b7ee90811fa4875ba3","0xddef10a85a5c67a9af8398d297aa51f8716383c7"],"victims":["0x6c60bf5db0670ae94489d3dde2c60f271625db50","0xf8331a897c5f32b57eab394af8adf0d00003cae1"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":111100,"severity":"Warning","txHash":"0x1c09395848a87069c9d6ddbe5adc6249510aba7a2a83479a74b4280cafb5fb29","nativeUrl":"https://thatsrekt.com/post/bsc/3","links":[{"url":"https://thatsrekt.com/post/bsc/3","label":"thatsRekt"},{"url":"https://x.com/TenArmorAlert/status/2067059314519417163","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-16T16:28:38.000Z","promotedEventId":null},{"id":"75791","source":"thatsrekt","sourceId":"thatsrekt-ethereum-20","chainId":1,"chainSlug":"ethereum","onchainId":"20","title":"Thetanuts Finance Legacy Index Vault Exploit","description":"On June 15, 2026, Thetanuts Finance confirmed a security incident affecting a deprecated legacy index vault. The incident involved unauthorized access to the vault's redemption mechanism. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x30498e4466789e534c72e03b52a16c978655b41e"],"victims":["0xc2c3ae0a7b405058558c9b4a63b373486cb86ac7"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":105000,"severity":"Warning","txHash":"0xbba9f138fe39503bfd1aa62932dbd6ab35d37d23d48e4b7bf2988a9d5dc39fec","nativeUrl":"https://thatsrekt.com/post/ethereum/20","links":[{"url":"https://thatsrekt.com/post/ethereum/20","label":"thatsRekt"},{"url":"https://x.com/exvulsec/status/2066536104187322669","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-15T14:00:00.000Z","promotedEventId":null},{"id":"68159","source":"thatsrekt","sourceId":"thatsrekt-ethereum-19","chainId":1,"chainSlug":"ethereum","onchainId":"19","title":"Aztec Connect Unauthorized Access to Deprecated Contract","description":"On June 14, 2026, an unauthorized access event occurred involving the legacy Aztec Connect / RollupProcessor proxy contract. The event allowed for the withdrawal of residual funds from the deprecated contract.\n\nOn-chain data shows that a transaction executed against the immutable proxy contract enabled public withdrawals of funds. The mechanism involved batched `processRollup` calls, which were exploited to extract funds that were not included in the contract's intended final state.\n\nThe incident resulted in a loss of approximately $2.19M, primarily in ETH, DAI, and wstETH. The affected contract was confirmed by Aztec Labs to be deprecated with no administrative control. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x0f18d8b44a740272f0be4d08338d2b165b7edd17"],"victims":["0xff1f2b4adb9df6fc8eafecdcbf96a2b351680455"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":2190000,"severity":"Critical","txHash":"0x074ec9317d8336db37e8c348fbdd7515573ff4088239c77ab429f522509aeeb1","nativeUrl":"https://thatsrekt.com/post/ethereum/19","links":[{"url":"https://thatsrekt.com/post/ethereum/19","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2066156825666543871","label":"Source"},{"url":"https://x.com/BlockSecTeam/status/2066172917235474615","label":"Source"},{"url":"https://x.com/exvulsec/status/2066347829191139829","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-14T13:00:00.000Z","promotedEventId":null},{"id":"39435","source":"thatsrekt","sourceId":"thatsrekt-ethereum-18","chainId":1,"chainSlug":"ethereum","onchainId":"18","title":"MILC/MLT Cross-Chain Bridge Unauthorized Access of Admin Key","description":"On June 10, 2026, an unauthorized access to a historical admin key occurred, affecting the MILC/MLT Cross-Chain Bridge. The compromised key granted administrative roles to an externally owned account, enabling the transfer of MLT tokens from bridge contracts on the BSC and Ethereum chains.\n\nOn-chain data and Blockaid reporting indicate that the compromised historical admin key was used to obtain the DEFAULT_ADMIN_ROLE and MANAGER_ROLE. This allowed the attacker's address (0x2A09414451dFeF72d1fBd84169c5189f7A950a38) to interact with the bridge contracts and withdraw MLT tokens.\n\nThe incident resulted in a loss of approximately $161,000 USD. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x2a09414451dfef72d1fbd84169c5189f7a950a38"],"victims":["0xcdccc91c9a3310566035dd831cf7d6810fb013e1","0x262fbcb8dc672fd4a8471d9e25367e5eb4901974","0x84ba8f08529b6072979734b310bf0c71f06978fb"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":161000,"severity":"Warning","txHash":"0x6364bc6305384f6d7832d47f0de6b95e81af4968e948e6246918c6f6e9630961","nativeUrl":"https://thatsrekt.com/post/ethereum/18","links":[{"url":"https://thatsrekt.com/post/ethereum/18","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2064626846277185869","label":"Source"},{"url":"https://x.com/blockaid_/status/2064626848345014407","label":"Source"},{"url":"https://x.com/blockaid_/status/2064626841227321623","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-09T23:49:04.000Z","promotedEventId":null},{"id":"39434","source":"thatsrekt","sourceId":"thatsrekt-bsc-2","chainId":56,"chainSlug":"bsc","onchainId":"2","title":"MILC/MLT Cross-Chain Bridge Unauthorized Access of Admin Key","description":"On June 10, 2026, the MILC/MLT Cross-Chain Bridge experienced an incident where a compromised historical admin key was utilized. This key granted the attacker the DEFAULT_ADMIN_ROLE and MANAGER_ROLE.\n\nThe unauthorized access allowed the attacker to initiate withdrawals of MLT tokens from the bridge contracts deployed on both the BSC and Ethereum networks. On-chain data and Blockaid reporting identified the exploiter's address and key transactions.\n\nThe incident resulted in a loss of approximately $161,000 USD. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x2a09414451dfef72d1fbd84169c5189f7a950a38"],"victims":["0xcdccc91c9a3310566035dd831cf7d6810fb013e1","0x262fbcb8dc672fd4a8471d9e25367e5eb4901974","0x84ba8f08529b6072979734b310bf0c71f06978fb"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":161000,"severity":"Warning","txHash":"0x6364bc6305384f6d7832d47f0de6b95e81af4968e948e6246918c6f6e9630961","nativeUrl":"https://thatsrekt.com/post/bsc/2","links":[{"url":"https://thatsrekt.com/post/bsc/2","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2064626846277185869","label":"Source"},{"url":"https://x.com/blockaid_/status/2064626848345014407","label":"Source"},{"url":"https://x.com/blockaid_/status/2064626841227321623","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-09T23:49:04.000Z","promotedEventId":null},{"id":"33161","source":"thatsrekt","sourceId":"thatsrekt-ethereum-17","chainId":1,"chainSlug":"ethereum","onchainId":"17","title":"Token of Power Governance Takeover and WETH Extraction","description":"On June 9, 2026, Token of Power (TOP) experienced a governance takeover. An exploiter utilized an Aragon proposal to mint a large quantity of tokens, which were then used to extract WETH from a Balancer pool.\n\nOn-chain data shows the exploiter used a contract to execute an Aragon proposal that allowed for the minting of over 10 billion tokens due to a misconfiguration in the MiniMeToken's low-supply setting. This action did not include a timelock, enabling the immediate use of the newly minted tokens.\n\nThe incident resulted in a loss of approximately $1.585M in WETH. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0xff8ef7bc455a57e5893232203052ce0232b39fa2"],"victims":["0x0ebd5ec91680d3b0cedbb1d5bb61851154d3edb6","0x0fa3e014fa2e751f78e53dca766fac2223327329","0x25c68c44a96518294f5b47d758f98309c6729a21"],"netScore":2,"confirmations":2,"disconfirmations":0,"lossAmountUsd":1585000,"severity":"Critical","txHash":"0x967aa34c69b7775c718545c7f94d92e965eb5fc553c0f27f6f1a9c65c93ac156","nativeUrl":"https://thatsrekt.com/post/ethereum/17","links":[{"url":"https://thatsrekt.com/post/ethereum/17","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2064333059059581233","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-09T13:05:00.000Z","promotedEventId":null},{"id":"30234","source":"thatsrekt","sourceId":"thatsrekt-ethereum-14","chainId":1,"chainSlug":"ethereum","onchainId":"14","title":"Humanity Protocol Exploit","description":"On June 8-9, 2026, Humanity Protocol experienced an unauthorized access event that resulted in a loss of approximately $36M. The incident affected the protocol's bridge functionality.\n\nOn-chain data indicates that the exploit involved unauthorized control over the bridge's ProxyAdmins, which was reportedly due to compromised multisig keys from an employee's laptop. This allowed for the transfer of 141M+ H tokens on Ethereum and the minting of 200M+ H tokens on Binance Smart Chain.\n\nThe incident resulted in a significant loss of funds and a sharp decline in the H token price. The root cause is attributed to key management failure, not a smart contract vulnerability. The remediation status is currently unresolved.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x456cb73b35022e4b524e5510807776453d984aef","0xee4b6b8967aa947ac3aef540ee07ea6099c566f7","0xaf2a4989922299eb14a29e332dad1012a8aad3a0","0x1dfe5cf3ed5a0ac82fdd0bfcdac7b6c6323f844a","0xd1ea823d421e0c829ee11f772af487fd352678ea","0x6aa22cb8420e94fc2119364b4c7885710ae753bb"],"victims":["0x44f161ae29361e332dea039dfa2f404e0bc5b5cc","0xcf5104d094e3864cfcbda43b82e1cefd26a016eb"],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":36000000,"severity":"Critical","txHash":"0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb","nativeUrl":"https://thatsrekt.com/post/ethereum/14","links":[{"url":"https://thatsrekt.com/post/ethereum/14","label":"thatsRekt"},{"url":"https://x.com/CyversAlerts/status/2065018662151442690","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-08T22:00:00.000Z","promotedEventId":null},{"id":"25394","source":"thatsrekt","sourceId":"thatsrekt-ethereum-13","chainId":1,"chainSlug":"ethereum","onchainId":"13","title":"Ambient Finance Exploit on Ethereum","description":"On 2026-06-08, Ambient Finance experienced an incident on the Ethereum network. The event resulted in unauthorized access to funds within the protocol.\n\nOn-chain data indicates that an exploit occurred, affecting specific smart contract interactions. The precise technical vulnerability is under investigation.\n\nThe incident resulted in a loss of $110.6K. The remediation status is currently unresolved as the root cause is under investigation.","poster":"0xe0396d6d738e726d39f96099b8f6a55d11184374","attackers":[],"victims":[],"netScore":1,"confirmations":1,"disconfirmations":0,"lossAmountUsd":110600,"severity":"Warning","txHash":null,"nativeUrl":"https://thatsrekt.com/post/ethereum/13","links":[{"url":"https://thatsrekt.com/post/ethereum/13","label":"thatsRekt"},{"url":"https://t.co/CwWRxGgSRI","label":"Source"},{"url":"https://x.com/TenArmorAlert/status/2063816231023427861","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-08T02:51:47.000Z","promotedEventId":null},{"id":"13159","source":"thatsrekt","sourceId":"thatsrekt-ethereum-12","chainId":1,"chainSlug":"ethereum","onchainId":"12","title":"securitize — Crypto neobanks are complex financial products in Web3. They inherit attack surfaces from traditional banki","description":"Crypto neobanks are complex financial products in Web3.\n\nThey inherit attack surfaces from traditional banking AND crypto infrastructure simultaneously. Most founders audit the smart contract and call it done.\n\nThat covers 1 of 11 attack surfaces.\n\nInfini learned this the hard way. $49.5M gone in two transactions. No zero-day. Just an admin key that was never revoked.\n\nThe neobank stack is six layers deep. KYC pipeline. Core banking ledger. Card issuing stack. Crypto custody. Mobile layer. On-chain settlement.\n\nA standard audit covers the bottom one.\n\nWe mapped all 11 attack surfaces across all six layers. If you are building a card-issuing neobank, read this before your next audit 👇\nhttps://x.com/QuillAudits_AI/status/2062875399441481803","poster":"0xe0396d6d738e726d39f96099b8f6a55d11184374","attackers":[],"victims":[],"netScore":-2,"confirmations":0,"disconfirmations":2,"lossAmountUsd":49500000,"severity":"Critical","txHash":null,"nativeUrl":"https://thatsrekt.com/post/ethereum/12","links":[{"url":"https://thatsrekt.com/post/ethereum/12","label":"thatsRekt"},{"url":"https://x.com/QuillAudits_AI/status/2062875399441481803","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-05T12:33:16.000Z","promotedEventId":null},{"id":"6307","source":"thatsrekt","sourceId":"thatsrekt-bsc-1","chainId":56,"chainSlug":"bsc","onchainId":"1","title":"ATM Token Exploit via Flawed transferFrom() Logic","description":"On June 4, 2026, the ATM Token protocol experienced an incident on the Binance Smart Chain. On-chain data indicates that an unauthorized party exploited a vulnerability in the transferFrom() logic.\n\nThe exploit involved repeated transfers of ATM/USDT and subsequent swaps on PancakeSwap, leveraging the flawed logic to extract value. The specific vulnerability has not been fully detailed.\n\nThe incident resulted in a loss of approximately $243,000 USD. The root cause is under investigation, and the remediation status is currently unresolved.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x7e7c1f0d567c0483f85e1d016718e44414cdbafe"],"victims":["0xece23b485c38110b7a50b5067b7d4b644f897dc9","0x986058ec93756e57b4e55b406dd0bee24bcd95e3","0x007e6df4c9ab9fe72e0d68f462caf508640b6bfe","0x05b1ff0725094405473e9309c6002813db1bf962","0x097f5fdbb3ae1161bcad68c87414140a388ad311","0x15f7197203d5c0058f2b213ceaf16acf3b4daba3","0x168b370c833694d286a08bd83a80f98aedb9e278","0x34fa1c6181519163d23c3965f3db57b24ed22d2f","0x3f857bb8e7eeffa360c0dc6b0ba3429fef6a919a","0x4e5b258dc3bf21aa23760950d696e6a3c1f87300","0x55dba7aca55062d928d850ce61fdb25662ce712f","0x55da04b75b7c8e905e672281c5414ae10dc1427f","0x64976c1259eb3fe467c8d8b644f1d0183fea7a03","0x7f5012a11e9794ac0acc7bd6cef3f65a0aec71fa","0x82dd0626bb982bf67fe2afaef4e4ec3d6fbfa523","0x8fbeef088b3a7322370c92c37de3bdfe14ed5821","0x92027964d6fd6d557b43153cbc1a458f6310a3e8","0x9317164a26e75e631b2e3332be6b085984ce67b8","0x933d0264f1e9189dfc7a5f0fd962070ee923a714","0x94f7420549d28c4f323e65929347edb170e5d54a","0xb055ac5817bfdfb4c535e92015f84f1922220ba1","0xb2bc8bae8d910ea1a05c0d0276bc3d281fd27fdc","0xc15d8313e80ff3f1ab7c4aa2acd648b2077eb52a","0xde55b4f9191d9bcc9266ad66a7ecc95e716c0690","0xf3905e36032634fbb8c13aef85cadc179882e18d","0xac904a40a80d0f92c67cbc762b5f44267e59e435","0xb40c72bba81030aef1bf67ae941091d8a96a7ccc","0xbb4644ef051b826b0532497422bfa5aa39c05307","0xbbe72dc0b2f0557fb2bd90fba1ae3c0acc641409","0xdeb53352ee65263bed0ad3819a221a2912555d42","0xe3ef365e3affdb5421ccf538f299e047db49b6c1","0xe45e60e33c9c07ccdee453abce8e479ace513d1e"],"netScore":2,"confirmations":2,"disconfirmations":0,"lossAmountUsd":243000,"severity":"Warning","txHash":"0x37b90a337075cd2feea93b12780abe9f953dad476e1c1418a02447aaa6dcfd86","nativeUrl":"https://thatsrekt.com/post/bsc/1","links":[{"url":"https://thatsrekt.com/post/bsc/1","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2062363549213896819","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-06-04T02:39:21.000Z","promotedEventId":null},{"id":"1","source":"thatsrekt","sourceId":"thatsrekt-ethereum-9","chainId":1,"chainSlug":"ethereum","onchainId":"9","title":"Alephium TokenBridge Unauthorized Access","description":"On May 30, 2026, the Alephium TokenBridge on Ethereum experienced an unauthorized access event. The incident involved the compromise of guardian keys, which were subsequently used to sign forged VAAs.\n\nOn-chain data indicates that 3 out of 4 guardian keys were compromised. This allowed for the creation of forged Verifiable Action Approvals (VAAs), which were then used to mint new tokens.\n\nThe event resulted in a loss of approximately $815,000 USD. The bridge's Ethereum custody was affected, with 13.76M wrapped ALPH tokens being minted and transferred. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x6681ebc82551fe52fdb48e65872e85a3ae06921d","0xb80a7d612480d121696be6dfe062f5e6d984bfd4"],"victims":["0x579a3bde631c3d8068cbfe3dc45b0f14ec18dd43","0x590f820444fa3638e022776752c5eef34e2f89a6"],"netScore":2,"confirmations":2,"disconfirmations":0,"lossAmountUsd":815000,"severity":"Critical","txHash":"0x06cc0f36159d7094359d88fe1d43cda601e8644282ba305c5ffbd013b524c6b4","nativeUrl":"https://thatsrekt.com/post/ethereum/9","links":[{"url":"https://thatsrekt.com/post/ethereum/9","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2060682200861831327","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-05-30T09:17:59.000Z","promotedEventId":null},{"id":"11027","source":"thatsrekt","sourceId":"thatsrekt-ethereum-11","chainId":1,"chainSlug":"ethereum","onchainId":"11","title":"Gravity Bridge — $5.4M drained (May 30)","description":"Multiple on-chain analysts (PeckShield, Specter, CertiK, GoPlus) and news outlets confirmed the drain from the verified Gravity Bridge contract (0xa4108aa1ec4967f8b52220a4f7e94a8201f2d906) via compromised validator signing keys (or possible denom mapping issue). Attacker addresses: 0x7B582033061b96cC3F9421e73a749ED7C62da1F9 and 0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47. Bridge operations halted for investigation. Specific exploit txs identified (e.g., 0xfce883a8f9a4f3479cce1368b99287973ab40451ac092f5a41e1e09eecab5044 and others). Funds continue moving as described in the hint.\n\nAttacked chains: [1]\n\nExploit txs:\n  0xfce883a8f9a4f3479cce1368b99287973ab40451ac092f5a41e1e09eecab5044\n  0xd3cdfa10be4f0cde6b3f294856a8bdd840983dcef29a5dc24c70c36e2d7f9ef0\n  0x59e52302c53e862fcf833b61eb851ff66e098e3d29db19fd66e5a04734eeb84b\n\nSources:\n  https://x.com/CertiKAlert/status/2062727560161792500","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x7b582033061b96cc3f9421e73a749ed7c62da1f9","0x4d3ca32e687e871a58b78acac73be59ac37c7a47","0x73e95ae5f3b87e02d4547afe86d0d466e9450d6b"],"victims":["0xa4108aa1ec4967f8b52220a4f7e94a8201f2d906"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":5400000,"severity":"Critical","txHash":"0xfce883a8f9a4f3479cce1368b99287973ab40451ac092f5a41e1e09eecab5044","nativeUrl":"https://thatsrekt.com/post/ethereum/11","links":[{"url":"https://thatsrekt.com/post/ethereum/11","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2062727560161792500","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-05-30T00:00:00.000Z","promotedEventId":null},{"id":"2","source":"thatsrekt","sourceId":"thatsrekt-ethereum-8","chainId":1,"chainSlug":"ethereum","onchainId":"8","title":"Gravity Bridge Unauthorized Access","description":"On May 30, 2026, Gravity Bridge experienced an unauthorized access event. The incident resulted in the transfer of approximately $5.4 million worth of assets. The affected assets included USDC, USDT, and PAYG, in addition to ETH.\n\nOn-chain data indicates that the unauthorized access occurred on the Ethereum mainnet. The specific technical mechanism leading to the unauthorized access is currently under investigation. The perpetrator consolidated the extracted funds, holding approximately 2,000 ETH.\n\nThe measured financial impact was a loss of approximately $5.4 million. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x7b582033061b96cc3f9421e73a749ed7c62da1f9","0x4d3ca32e687e871a58b78acac73be59ac37c7a47","0x73e95ae5f3b87e02d4547afe86d0d466e9450d6b"],"victims":["0xa4108aa1ec4967f8b52220a4f7e94a8201f2d906"],"netScore":2,"confirmations":2,"disconfirmations":0,"lossAmountUsd":5400000,"severity":"Critical","txHash":null,"nativeUrl":"https://thatsrekt.com/post/ethereum/8","links":[{"url":"https://thatsrekt.com/post/ethereum/8","label":"thatsRekt"},{"url":"https://x.com/CyversAlerts/status/2060639281354260555","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-05-30T00:00:00.000Z","promotedEventId":null},{"id":"4","source":"thatsrekt","sourceId":"thatsrekt-optimism-2","chainId":10,"chainSlug":"optimism","onchainId":"2","title":"SquidRouter Exploit Affecting Gnosis Safes","description":"On 2026-05-25, an exploit occurred involving the SquidRouter, affecting 86 Gnosis Safes on the Ethereum and Base networks. The incident resulted in the unauthorized transfer of funds.\n\nOn-chain data shows the attacker utilized the SquidRouter to extract assets from the Gnosis Safes. The stolen funds were subsequently swapped to DAI through attacker-controlled Uniswap V3 pools.\n\nThe incident resulted in a loss of approximately $3M. The root cause is under investigation, and remediation efforts are ongoing.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x9bdc730183821b6bb2b51be30b77c964fa645b91","0x7c82cb4b2909c50c7c0f2b696eee7565e0a23bb8"],"victims":[],"netScore":2,"confirmations":2,"disconfirmations":0,"lossAmountUsd":3000000,"severity":"Critical","txHash":"0xd29d1c8d9a1b424d4e0f472bd7b4a994028d35e9737c591eae51d917543bb854","nativeUrl":"https://thatsrekt.com/post/optimism/2","links":[{"url":"https://thatsrekt.com/post/optimism/2","label":"thatsRekt"},{"url":"https://x.com/blockaid_/status/2058875782810726556","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-05-25T06:00:00.000Z","promotedEventId":null},{"id":"75825","source":"thatsrekt","sourceId":"thatsrekt-polygon-1","chainId":137,"chainSlug":"polygon","onchainId":"1","title":"Huma V1 BaseCreditPool Unauthorized Access on Polygon","description":"On May 11, 2026, Huma V1 BaseCreditPool experienced an incident on the Polygon network. A logic flaw in deprecated V1 BaseCreditPool proxies was identified.\n\nThis vulnerability allowed an attacker-controlled borrower to bypass approval checks, resulting in the advancement of unapproved credit lines and the drawdown of treasury and fee balances. The exploit affected three contracts within the V1 BaseCreditPool.\n\nThe incident resulted in a loss of approximately $101,000 in USDC and USDC.e. User deposits and the Solana V2 protocol were not affected. The Huma team has paused the affected V1 contracts.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x13b44e416e0f66359502e843af2e1191f1260daf","0x44d4a434ae1529106e4b801315e22721978022a3","0xef8a13797b009228f6e4a25112ea114b7ba6e1b2"],"victims":["0x3ebc1f0644a69c565957ef7ceb5aeafe94eb6fce","0x95533e56f397152b0013a39586bc97309e9a00a7","0xe8926adbfadb5da91cd56a7d5acc31aa3fdf47e5"],"netScore":-2,"confirmations":0,"disconfirmations":2,"lossAmountUsd":101000,"severity":"Warning","txHash":"0xbba9f138fe39503bfd1aa62932dbd6ab35d37d23d48e4b7bf2988a9d5dc39fec","nativeUrl":"https://thatsrekt.com/post/polygon/1","links":[{"url":"https://thatsrekt.com/post/polygon/1","label":"thatsRekt"},{"url":"https://x.com/exvulsec/status/2066536104187322669","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2026-05-11T14:19:25.000Z","promotedEventId":null},{"id":"92671","source":"thatsrekt","sourceId":"thatsrekt-arbitrum-2","chainId":42161,"chainSlug":"arbitrum","onchainId":"2","title":"UXLINK Multi-Sig Delegatecall Compromise","description":"On September 22, 2025, UXLINK experienced an incident involving its multi-sig wallet. The event resulted in unauthorized access to administrative functions.\n\nAn exploit occurred through a delegatecall vulnerability, which allowed an unauthorized party to take control of the multi-sig wallet. This access enabled the modification of owner addresses and the minting of a significant quantity of unauthorized tokens.\n\nThe incident affected treasury assets, with an estimated loss of $28M. The funds were transferred across the Ethereum and Arbitrum networks. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x2ef43c1d0c88c071d242b6c2d0430e1751607b87","0x64ab9377a2b3bbb61dd79f8997e7f8c1cc1a4de8","0xafb2423f447d3e16931164c9907b9741aab1723e","0xb819e6ae5a6668bb0ce02d64d130deca9ff83691"],"victims":["0x4457d81a97ab6074468da95f4c0c452924267da5"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":28000000,"severity":"Critical","txHash":"0x35edac40767f65d4d1382f0f55cda2f4db321313e16fe059079f0113f9cb5696","nativeUrl":"https://thatsrekt.com/post/arbitrum/2","links":[{"url":"https://thatsrekt.com/post/arbitrum/2","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2067248722287747408","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2025-09-22T00:00:00.000Z","promotedEventId":null},{"id":"92670","source":"thatsrekt","sourceId":"thatsrekt-bsc-4","chainId":56,"chainSlug":"bsc","onchainId":"4","title":"UXLink Exploit and Fund Laundering","description":"On September 22, 2025, UXLink experienced an unauthorized access event. The exploit involved a multisig takeover, unauthorized token mints, and treasury drains across the Arbitrum, Ethereum, and Binance Smart Chain networks.\n\nOn-chain data indicates the exploit mechanism included a delegatecall function, leading to the minting of a large quantity of tokens and subsequent extraction of funds from the treasury. Several transaction hashes have been identified as part of this operation.\n\nThe incident resulted in a loss of approximately $42 million USD. The exploiter has been observed laundering funds through Tornado Cash. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0x2ef43c1d0c88c071d242b6c2d0430e1751607b87","0x64ab9377a2b3bbb61dd79f8997e7f8c1cc1a4de8"],"victims":[],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":42000000,"severity":"Critical","txHash":"0x35edac40767f65d4d1382f0f55cda2f4db321313e16fe059079f0113f9cb5696","nativeUrl":"https://thatsrekt.com/post/bsc/4","links":[{"url":"https://thatsrekt.com/post/bsc/4","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2067248722287747408","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2025-09-22T00:00:00.000Z","promotedEventId":null},{"id":"92630","source":"thatsrekt","sourceId":"thatsrekt-ethereum-21","chainId":1,"chainSlug":"ethereum","onchainId":"21","title":"UXLINK Multi-Sig Delegatecall Compromise","description":"On September 22, 2025, UXLINK experienced an incident involving its multi-sig wallet. The protocol was affected by a delegatecall vulnerability that allowed unauthorized control over administrative functions.\n\nOn-chain data indicates the vulnerability enabled the modification of multi-sig owners, including the removal of existing owners and the addition of the exploiter. This allowed for the minting of unauthorized tokens and the subsequent extraction of treasury assets. The exploit involved approximately $28M worth of assets, including USDT, USDC, WBTC, and ETH.\n\nThe incident resulted in a loss of approximately $28M. Affected assets were transferred across the Ethereum and Arbitrum networks, with subsequent activity observed on Tornado Cash. The root cause is under investigation.","poster":"0xfe6b4dff18d741e725c7c6922ccf69121b2fffdb","attackers":["0xb819e6ae5a6668bb0ce02d64d130deca9ff83691","0x64ab9377a2b3bbb61dd79f8997e7f8c1cc1a4de8","0x2ef43c1d0c88c071d242b6c2d0430e1751607b87","0xafb2423f447d3e16931164c9907b9741aab1723e"],"victims":["0x4457d81a97ab6074468da95f4c0c452924267da5"],"netScore":0,"confirmations":0,"disconfirmations":0,"lossAmountUsd":28000000,"severity":"Critical","txHash":"0x35edac40767f65d4d1382f0f55cda2f4db321313e16fe059079f0113f9cb5696","nativeUrl":"https://thatsrekt.com/post/ethereum/21","links":[{"url":"https://thatsrekt.com/post/ethereum/21","label":"thatsRekt"},{"url":"https://x.com/CertiKAlert/status/2067248722287747408","label":"Source"}],"affectsTrackedUniverse":false,"attackedAt":"2025-09-22T00:00:00.000Z","promotedEventId":null}],"meta":{"page":1,"limit":50,"hasMore":false}}