#CertiKInsight Insights, crypto hacks, crypto scams, flashloans. Turn on notifications for automatic alerts 🕵🏼 @CertiK 🤝 @CertiKCommunity

Web3
#CertiKStatsAlert 🚨 Combining all the incidents in August we’ve confirmed ~$214.7M lost to exploits with ~$41.5M of the total attributed to phishing. 2026 has already seen more exploits due to code vulnerabilities than previous years' totals. More details below 👇
3
13
50
44,160
#CertiKInsight 🚨 In the last few hours there has been ~$6M of suspicious outflows from @Duelbits wallets A similar incident involving Duelbits wallets occurred in 2024 👇
#CertiKSkynetAlert 🚨 Last night @Duelbits was exploited and assets worth ~$4.6m were taken in a possible private key compromise (PKC). All assets were swapped for ETH which currently sits in EOA 0x0428 👇
6
6
22
7,234
BSC / ETH: 0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76 BTC: bc1qhtu84kz3y94lvgl2t05zk84tqh57grvd82zvcl SOL: A3EBrhMBEGzcPgmbwywSPhW39G6PFGrorU8ib99T6yKw Tron: TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK
2
1,455
#CertiKInsight 🚨 @nostrafinance's money market suffered a price-manipulation attack, allowing an attacker to borrow ~$3.5 million in ETH, STRK, USDC, USDT, WBTC, and DAIv1 against NSTR collateral on Starknet. voyager.online/contract/0x06… Stay Vigilant!
On September 17, a manipulated NSTR oracle price enabled one account to borrow approximately $3.5 million worth of ETH, STRK, USDC, USDT, WBTC and DAIv1 against NSTR collateral in the Nostra money market on Starknet. The Nostra money market is paused: lending, borrowing, withdrawals and liquidations are currently unavailable. We are reconciling the impact on each asset and tracing the funds. The final loss and potential recoveries are not yet known. We are working with relevant parties on recovery and will share verified updates, including a detailed post-mortem. Beware of impersonators. Nostra will never DM you or ask you to connect a wallet as part of recovery. Ongoing updates will be posted in our Discord.
12
9
32
13,771
CertiK Alert retweeted
Web3 security data, now easier to explore. Introducing the CertiK Report Security Dashboard — an interactive view of the latest losses, incidents, attack vectors, chain-level trends, and more. Explore the data behind Web3 security ↓ certik.com/certik-report/das…
3
9
42
10,357
#CertiKInsight 🚨 Trezor's third-party e-mail provider has been breached. Please do not click any links in phishing emails. Stay Vigilant!
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
5
2
14
17,022
1/ The malicious activity trace to a security incident that allowed an attacker to access 120 Brevo accounts.
Replying to @brevo_official
The full post-mortem of the 10 September security incident is available here: status.brevo.com/incidents/0…
1
1
8,049
#CertiKInsight 🚨 We have seen unauthorized withdrawal via SideSwap PAK of ~4K BTC (~$320M) from @Liquid_BTC at bc1qdlld6antmv4xug242ed83q7k4rqw50cwfns38szx4qu2f4jwaxxsuhwxxr Hacker left a message: we are whitehats. contact us on chain. nitter.net/Liquid_BTC/status/2096… Stay VIgilant!
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message. What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others. Exchanges have been notified and have already paused (or will pause) LBTC deposits and withdrawals. Other Liquid assets such as USDT, DePix, and RWAs are unaffected by this security incident. Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. Effectively, the Liquid sidechain is paused until this issue is resolved. Liquid wallets will be impacted, and we're sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity. You can monitor the situation via @mempool's liquid.network site below: mempool.space/address/bc1qdl…
5
7
34
13,917
#CertiKInsight 🚨 We have seen an ~$1.7M exploit on @NotionalFinance. skylens.certik.com/tx/eth/0x… The attacker used two mintfCashPair() calls to create a -2^128 liability, which was truncated to 0 by an unsafe uint128() downcast in free-collateral valuation. Stay Vigilant!
9
11
45
14,020
1/ The first mintfCashPair(1) succeeds due to a rounding error in which the -1 liability is rounded down to 0 in DAI→ETH free-collateral conversion. The second mintfCashPair(2^256-1) aggregates correctly to -2^128 in int256, but is truncated to 0 in uint128(balance.abs()).
2
1
2
4,421
#CertiKInsight 🚨 We have detected a deposit of 2658.9 ETH (~$6.65M) into Tornado Cash from etherscan.io/address/0xc4041…. The fund traces back to the @TectonicFi exploiter who created ~$120M in bad debt (rolled back) via inflated collateral and bridged out ~$6.65M. Stay Vigilant!
4
13
52
13,954
CertiK Alert retweeted
One trend stands out: 2026 has already recorded more exploits linked to code vulnerabilities than previous years’ annual totals. A clear reminder of why identifying vulnerabilities before they can be exploited remains critical to security.
#CertiKStatsAlert 🚨 Combining all the incidents in August we’ve confirmed ~$214.7M lost to exploits with ~$41.5M of the total attributed to phishing. 2026 has already seen more exploits due to code vulnerabilities than previous years' totals. More details below 👇
2
5
28
11,726
#CertiKInsight 🚨 We have seen a price manipulation exploit on @TectonicFi on Cronos. ~$75M is now at three addresses: debank.com/profile/0x7d4e7e5… debank.com/profile/0x215adfc… debank.com/profile/0x7d4e7e5… Please do not interact with it till safe. Stay Vigilant!
We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.
5
12
37
15,345
#CertiKInsight 🚨 @avici is currently being exploited, resulting in a ~$1.02M loss.
We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation. We’re working directly with all relevant partners to resolve it and will share updates as soon as we have more information.
9
6
30
15,998
2/ - The attacker FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj transferred 10k SOL to MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu. - Swapped the SOL for ~$1.02M USDC. - Bridged and swapped through 0x2cE21E4921d3Eb116526c3651Dac0257657338D5 to get ~418 ETH.
1
1
3
7,206
#CertiKInsight 🚨 We have seen an exploit of @MoonwellDeFi lending market on Base. Attacker manipulated relatively illiquid MAMO’s collateral price, then borrowed real cbBTC eg. basescan.org/tx/0xafb6f0fa25… ~$8.7M has now been aggregated at etherscan.io/address/0xD71dD… Stay Vigilant!
10
18
61
18,078