DeFi security monitoring • $ 2M+ rescued ⚠️ Alerts: t.me/defimon_alerts 💎 Signals: t.me/+m9BMRKlMuW5iMGFi

Onchain
Early detection alerts are now included in Defimon WebSocket feed - we track attacker's first steps to determine a potential victim and amount at risk before an exploit executes. Subscribe at defimon.xyz or in Telegram via t.me/defimon_subscription_bo…
1
9
6,598
💬 Onchain Message: Hi there, i pray to god that this message is received by a whitehat. Last night i lost almost all of my money and it was one of the worst nights of my life. My friend messaged me saying that this address is owned by a white hat and perhaps there is a chance that my money can be returned. I believe i have revoked all compromised permissions on my wallet. Please, if this message is received, tell me anything I need to do and i will do it. etherscan.io/tx/0xbb0f0c83c5…
275
🚨 @rarible - Attempted governance takeover (2026-09-20) Token: $RARI @ $0.1066 Network: Ethereum Type: Access Control (malicious governance proposal / DAO takeover) Attacker "Falcon" (0x94223fcC…F04Ca, ~132.5K veRARI votes, above the 5,000 proposalThreshold) submitted proposal 3648869205…835338 to RariGovernor (0x859e1c00…2edca). The single action calls the DAO's delegatecall-executor 0xb23BCD4F…C5b5 with execute(0x36224b869…a722, write(slot,1)). Contract 0x36224 is a 4-line backdoor whose only function e2e52ec1 (write(uint256,uint256)) does a raw SSTORE; invoked via the executor's DELEGATECALL it writes 1 into an AccessControl role slot of the executor — granting Falcon a privileged role and full control of the DAO. The proposal text openly states YES "grants full control of the DAO to the activist investor group Falcon." No funds moved yet (vote open); execution would hand the DAO/treasury to the proposer. TX: etherscan.io/tx/0xeaef75813c… Attacker: etherscan.io/address/0x94223… Victim: etherscan.io/address/0x859e1… ⏱️ Real-time alerts: defimon.xyz
4
6
33
7,733
🚨 @internet_token - Loss ~764M INT + 5.85 WETH (2026-09-21) Token: $INT @ $0.000328 Network: Base Type: Access Control / Logic Error (arbitrary mint via unvalidated pool callback) The INT LiquidityUnifier (0x837dbabc…2032), which holds the reward token's MINTER_ROLE, exposes swapV3(token, pool) that accepts an attacker-supplied pool. Validation only checks the pool has code and that its token0()/token1() equal INT. The attacker deployed a fake "pool" returning INT for both tokens; swapV3 calls pool.swap(), which re-enters uniswapV3SwapCallback and mints an attacker-chosen amount to currentPoolV3. Using a Convertor round-trip to defeat the validateSupply check, the attacker freely minted ~925M INT, dumped part into the real INT/WETH Uniswap V3 pool for 5.85 WETH and walked away with ~764M INT + 5.85 WETH. TX: basescan.org/tx/0xed62bb27bd… Attacker: basescan.org/address/0x5f7ce… Victim: basescan.org/address/0x837db… ⏱️ Real-time alerts: defimon.xyz
2
2
14
3,603
💬 Onchain Message: To the recipient of my 2.07 ETH: I am writing these words from the bottom of my heart, not out of anger, but out of pure, overwhelming desperation. I am currently unemployed and going through the darkest and most difficult chapter of my life. That 2.07 ETH was never speculative money — it was my entire family's life savings, meant to put food on our table and help us survive through this devastating economic crisis. I understand the nature of the crypto world and I do not expect you to walk away empty-handed. I sincerely and willingly offer you 0.5 ETH as a bounty and token of appreciation. Please return the remaining ~1.57 ETH to my safe address: 0xF90367a5F4D24E720D5b810AA0AD5E35Cc70968c I promise to consider this matter completely resolved and hold no grievance. Behind our computer screens, we are all human beings with families to care for. I truly pray that you understand my family's desperate situation and show mercy. Thank you. etherscan.io/tx/0xee5ef683bb…
7
5
30
7,052
💬 Onchain Message: Unauthorized token drain. 6,731.96 USDC taken from 0xD427aBC74a276005ed3043Fa7243FfAa96b887a6 on Base without my signature. Drain: basescan.org/tx/0x19ab00603f… Your inbound: etherscan.io/tx/0x8e5c262649… Please return 2.574902 ETH on Ethereum to 0xD427aBC74a276005ed3043Fa7243FfAa96b887a6 basescan.org/tx/0x19ab00603f…
1
9
3,059
💬 Onchain Message: G'day mate To the address that exploited the RISEx XLP Vault on the 3rd of August: we see the funds started moving today. Before this goes any further, we are improving our offer. Keep 20% (134,566 USDC). Return the remaining 80% (538,265 USDC, or the equivalent in ETH) to 0x83047f3D7Ed7998D841C8F364897b74C4a3273C5 on Ethereum or Base. If you do so before 12pm AEST on Wednesday 23 September, we treat this as a whitehat disclosure. etherscan.io/tx/0xddd2b155b0…
3
19
3,390
Today at 07:21 UTC an unauthorized withdrawal occurred from the RWA strategy associated with the XLP vault. The issue has been patched and XLP depositors have been made whole, with the full amount covered by a portion of the fees generated in July on RISEx. XLP depositors’ funds are not affected by this event. RISEx is entirely independent and is operating as normal. More below: The withdrawal of 673,011.56 USDC was caused by a misconfiguration in the RWA strategy, present since its deployment on July 13. We detected the issue within minutes of the withdrawal, patched it by 08:09 UTC, and covered the full amount. This was not a novel attack or a dependency failure. Transaction in question: explorer.risechain.com/tx/0x… We have reviewed every transaction and deployment and this is the only unauthorized withdrawal in that period. We have also reviewed the configuration of every other strategy in the vault and found no equivalent issue. A postmortem will be published. The RISE bridge, RISEx and the XLP vault each have withdrawal throttles to reduce the impact in an exploit event. However, in this circumstance the amount was below the throttling thresholds. We are engaging SEAL 911 and tracing is underway. We are attempting to make contact with the address involved regarding a return of funds. @risextrade is the only official source of information. We will never DM you first. There is no recovery form and no claim process. Do not connect your wallet to any link about this incident.
1
1,060
💬 Onchain Message: hello goodday this seems to be 0xcccc640018f8c2b00fa45F56017AD2378Eb3447 wallet, i couldn't send an idm to your main address so i had to send it here You recently drained the Arche arUSD vault on 13th of june and i was unfortunately one of the victims lossing about $1,132 I am an just an individual user, not a whale or a protocol . These funds represent a huge portion of my life savings, and losing them completely devastates my family and livelihood. I am begging you to show mercy and return the funds to my adress 0x6b9E250f1cB14a78F0870b0b35A42507adF6A082 . Keep a portion as a lesson fee if you must, but please give me back the ability to recover from this. The shady team have since ran away witout reimbursing us as promised Thank you for reading this. Please help etherscan.io/tx/0x39475cc55f…
3
18
4,509
💬 Onchain Message: You received assets stolen from my compromised wallets. The relevant transactions, addresses, malware sample, and evidence have been preserved. We have identified the MEXC account associated with the receiving address, and MEXC has already placed a temporary freeze on that account. Return the stolen assets to the original addresses. If you cooperate and return the funds, this can still be resolved directly. Otherwise, I will continue pursuing recovery through MEXC and the relevant investigation channels. etherscan.io/tx/0x29c86ec22a…
3
2,910
💬 Onchain Message: You recently transferred tokens illegally from our smart contract. Please return them back for 10% as a bounty reward. Thanks! etherscan.io/tx/0x11121d2e98…
1
8
2,837
🚨 @nimiq exploited for $50.4K on Polygon (Sep 16, 2026) Nimiq's swap contracts serve as both the OpenGSN paymaster and the forwarder. Their execute() checks never verifies the user's signature. It relies on the contract's own preRelayedCall to do that. OpenGSN's RelayHub lets any relay choose any paymaster and forwarder. Exploit contract was detected by Defimon 19 minutes before the attack. The attacker staked 1 POL, registered their EIP-7702 EOA as the relay manager, worker and paymaster (an accept-everything paymaster), and set forwarder = the HTLC handlers. Signature checks were skipped, so forged open() requests "from" a swap-liquidity wallet with unlimited approvals to the handlers opened HTLCs for its entire USDC, USDT0 and USDC.e balance. Each HTLC named the attacker's precomputed CREATE2 contract as recipient and used hashlock sha256(0x01). The exploit tx deploys that contract and redeems all three HTLCs with secret 0x01. About $50.4K was taken and consolidated as USDC. TX: polygonscan.com/tx/0xb2ca76d… Setup TX: polygonscan.com/tx/0xb067efa… Attacker: polygonscan.com/address/0x22… Victim: polygonscan.com/address/0x0c… Victim: polygonscan.com/address/0xf6… Drained wallet: polygonscan.com/address/0x24…
We are currently investigating an OpenGSN-related security issue that may also affect Gas Abstraction. As a precaution, all Stablecoin transactions using Gas Abstraction have been temporarily disabled across the Nimiq ecosystem, including Nimiq Pay and Nimiq Wallet. We’re sorry for any inconvenience this may cause. The security of Nimiq users comes first. We will share further updates as soon as they are available.
2
5
35
5,570
🚨 @primefixyz - Loss ~$33.4K (2026-09-16) Network: HyperEVM Type: Oracle Manipulation Prime's PRFI price feed is exploitable. DataStreamConsumer.verifyReport() is permissionless and, after checking the Chainlink Data Streams signature, blindly overwrites the stored price for a feedId with no check that the report is newer/fresher than the one already stored. The attacker pushed a favorable signed PRFI report, inflating PRFI's oracle price to ~$0.11 (vs ~$0.0021 real, ~52x). Using a Morpho flash loan they bought PRFI cheaply from the thin WHYPE/PRFI pool, deposited it as over-valued collateral into the lending pool, and borrowed ~425.5 WHYPE (~$33.4K) far exceeding the collateral's true value, draining the WHYPE reserve. TX: hyperevmscan.io/tx/0xff99087… Attacker: hyperevmscan.io/address/0x19… Victim: hyperevmscan.io/address/0xb3… ⚡️ Detected by Defimon at 12:37:37 UTC ⏱️ Real-time alerts: defimon.xyz
💬 Onchain Message: PRIMEFI RECOVERY REQUEST | Incident tx: 0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243 | Please return 318.961630241143730359 HYPE (80% of the 398.702037801429662948 HYPE proceeds) to: | 0xF2e2A49631927108086268c68C559c63c3C8f73d | You may retain 79.740407560285932589 HYPE (20%) as a white-hat bounty upon return. | PrimeFi is a small protocol and this loss materially affects our users. | Reply with a zero-value transaction containing contact details to 0xF2e2A49631927108086268c68C559c63c3C8f73d. | This request does not waive any legal rights or remedies. hyperevmscan.io/tx/0x1d00634…
3
3
43
7,353
💬 Onchain Message: PRIMEFI RECOVERY REQUEST | Incident tx: 0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243 | Please return 318.961630241143730359 HYPE (80% of the 398.702037801429662948 HYPE proceeds) to: | 0xF2e2A49631927108086268c68C559c63c3C8f73d | You may retain 79.740407560285932589 HYPE (20%) as a white-hat bounty upon return. | PrimeFi is a small protocol and this loss materially affects our users. | Reply with a zero-value transaction containing contact details to 0xF2e2A49631927108086268c68C559c63c3C8f73d. | This request does not waive any legal rights or remedies. hyperevmscan.io/tx/0x1d00634…
5
10,079
🚨 @flamincome - Loss ~$346K (2026-09-16) Token: $USDT Network: Ethereum Type: Oracle Manipulation (Curve virtual-price / share-price inflation) Flamincome's USDT Strategy (0xb8d6...68a5) values its Convex/Curve position in impl.deposited() from BaseRewardPool.balanceOf(Strategy) × the Curve USDP metapool get_virtual_price plus its aUSDT reserves. Using a Morpho USDT flash loan the attacker bought USDP cheaply and imbalance-minted a large amount of the USDP metapool LP, deposited it into Convex and staked it FOR the Strategy (stakeFor), inflating balanceOfY()/per-share value. Redeeming YUSDT via VaultYUSDT.withdrawAll then forced the Strategy to pull ~544K aUSDT from Aave and pay out at the inflated price, netting ~$346K (victim strategy lost ~$595K in aUSDT+USDT). TX: etherscan.io/tx/0x5ff8150482… Attacker: etherscan.io/address/0x83381… Victim: etherscan.io/address/0xb8d64… ⏱️ Real-time alerts: defimon.xyz
1
2
18
7,218
🚨 @bonfiretoken - Loss ~$47K (2026-09-15) Token: $BONFIRE Network: BNB Chain Type: Access Control / Approval Drain The BonfireSwap router (0x17e8...03d3) exposes transfer(address to, uint amountAIn, address beneficiary, uint deadline) which calls _safeTransferFrom(tokenAddress, to, pancakePair, amountAIn) with no check that msg.sender owns or is authorized to spend `to`'s tokens. Any caller can therefore spend the BONFIRE approval any holder previously granted to the router: the attacker looped this (and skimPool) over ~65 holders who had approved BonfireSwap, force-selling their tokens into the Pancake pair and skimming the WBNB proceeds to their own contract (0x28E9...2127), extracting ~66 BNB (~$47K). Same arbitrary-source flaw exists in loggedTransfer/simpleTransfer. TX: bscscan.com/tx/0xb4c00e8f3ba… Attacker: bscscan.com/address/0x2b5bf7… Victim: bscscan.com/address/0x17e801… ⏱️ Real-time alerts: defimon.xyz
1
3
27
3,321
💬 Onchain Message: To the holder of this wallet. This is regarding 825,015 USDT taken on 2 June 2026. The 50,000 USDT you tried to convert at FixedFloat are frozen and will not be released. The remaining 427.78 ETH on this address is under continuous monitoring. Tor and VPN will not protect you 100%. Court orders have been obtained and law enforcement is engaged. We are analysing your behaviour and every move you make from here. There is one way to close this: return the funds. Contact us at investigations@amlcrypto.io within 3 days of this message. Full return will be treated as a whitehat resolution with a 10% bounty, on terms to be agreed. etherscan.io/tx/0x3af3b04d13…
3
2
27
6,645
X account in question is @RCKTFoundation ($287K loss after exploit)
💬 Onchain Message: I remain willing to resolve this matter amicably and return the relevant funds. Since you have declined to enter into a written settlement agreement, I propose that you publish a statement from your official X account confirming that, upon receipt of the funds, you will consider the matter fully and finally resolved, withdraw any existing claims and complaints to the extent legally possible, and have no further claims against me in connection with this incident. Once this statement is published, I will proceed with the return of the funds. etherscan.io/tx/0xa97b515024…
2
5
3,146
💬 Onchain Message: I remain willing to resolve this matter amicably and return the relevant funds. Since you have declined to enter into a written settlement agreement, I propose that you publish a statement from your official X account confirming that, upon receipt of the funds, you will consider the matter fully and finally resolved, withdraw any existing claims and complaints to the extent legally possible, and have no further claims against me in connection with this incident. Once this statement is published, I will proceed with the return of the funds. etherscan.io/tx/0xa97b515024…
4
5,789