Smart Contract Audit | Security Monitoring | AML/CFT (KYA/KYT) | Crypto Investigation | @Phalcon_xyz @MetaSleuth @MetaDockTeam 馃憠TG: t.me/BlockSecTeam
A user-friendly version: https://blocksec.com/blog/coldcard-entropy-failure-seed-recovery?utm_source=X&utm_content=security_insights Key Insight COLDCARD's losses trace to a single silent build-and-integration error, not a broken cryptographic algorithm: a guard checked whether an
TL;DR: The $290M KelpDAO exploit exposed a decentralization dilemma at every layer. A single-point DVN dependency enabled the attack; composability cascaded it into a $6.7B WETH freeze across 5
On August 25, 2025, with the assistance of Cantina and Seal911, Panoptic conducted a white hat rescue operation, securing approximately $400K in at-risk funds [1]. The root cause was a flaw in the
On March 5, 2025, a third-party resolver contract integrated with the 1inch's Fusion V1 protocol suffered a coordinated exploit that resulted in total losses of over $5 million. The root cause was an
On September 2, 2025, the Bunni V2 protocol suffered a sophisticated exploit [1]. An attacker leveraged a critical vulnerability in its liquidity accounting mechanism to extract approximately 8.4
On December 25, 2025, Trust Wallet suffered a critical security breach in its Chrome extension (v2.68), resulting in the theft of approximately $8.5 million in user funds. The root cause was a
On May 28, 2025, the Cork Protocol on Ethereum was exploited, resulting in approximately $12 million in losses. The root cause was a combination of expiration-time HIYA price manipulation and missing
馃摉 This is a condensed version. For the full technical analysis with detailed simulations and code traces, read the complete article on our blog: https://blocksec.com/blog/yearn-finance-incident-unsafe-arithmetic-in-the-invariant-solver-earns-its-name On November 30, 2025, Yearn
On July 9, 2025, the decentralized perpetual platform GMX experienced an exploit [1, 2] targeting their V1 contract on the Arbitrum network, resulting in a loss of approximately $42 million. The
On November 3, 2025, Balancer V2's Composable Stable Pools, along with several forked projects across multiple chains, suffered a coordinated exploit that resulted in total losses of over $125
On February 21, 2025, Bybit lost approximately $1.5 billion after an attacker compromised a Safe{Wallet} developer's machine through social engineering. The attacker injected malicious JavaScript into
On May 22, 2025, Cetus Protocol, the largest concentrated-liquidity DEX on Sui, suffered a major exploit that drained liquidity across multiple pools [1], resulting in an estimated ~$223 million in