Protect Your Every Transaction. User App: chromewebstore.google.com/se… 🛡️ Dev Integration: Security Intelligence & SafeToken Protocol 🛡️

On-Chain
❗️ #THORChain has never been strictly decentralized @THORChain comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds. 1️⃣ Custody: TSS vaults ≠ base-layer consensus On BTC/ETH, users control assets with their own keys. Miners/validators order and include txs. They never hold user funds. The worst a single miner can do is refuse to include your tx. They cannot send your coins. Every THORChain outbound (vault → user/attacker) has to be actively produced by the current active set via a GG20 TSS threshold signature. During a swap, funds sit in a TSS vault jointly controlled by those nodes. Releasing stolen funds is an active signing event, not “neutral ordering we cannot stop.” As @star_okx put it: from a custody view it is an intermediary between users and native chains. Distributed centralized custody is not decentralization. 2️⃣ Validator set: small, and it can coordinate Official docs: THORNodes bond RUNE to join. Active-set cap is ~100 (can scale to 250+), with a churn about every 3 days that drops the oldest, slowest, lowest-bond nodes. Nodes coordinate in real time on Dev Discord’s #mainnet channel — anonymous relays, votes (Mimir / node votes). That is an organization with a comms channel, a voting process, and execution tools. Not BTC/ETH’s globally anonymous set with no coordination path. 3️⃣ Intervention is designed in. There are runbooks. There are precedents. make pause: one node can halt the network (720 blocks per trigger, stackable). Slogan: “Halt Earn, Halt Often!” Standard is “an abundance of caution.” False trips can be undone with make resume. Per-chain signing halt: node votes can pause outbound signing on one chain only — the tool needed to stop ETH/BNB → BTC exits without taking the whole network down. Mimir governance: nodes can vote live to change params, halt trading, halt signing. Precedent: when THORChain itself was drained in May 2026, they paused and ran a controlled halt to stop further movement. 4️⃣ Inaction pays In the Bybit case, the attacker washed all 499K ETH in 10 days, mostly through THORChain into BTC. That printed ~$5.9B volume and ~$5.5M fees for THORChain. In the Bitget case, ~101.5 BTC (≈$8.5M) has already gone out via THORChain, with another ~27.63M XRP (≈$43M) mid-swap into BTC. Potential fee take: hundreds of thousands of dollars. In Feb 2025, validators voted to intercept DPRK-linked funds, then reversed. Core contributor Pluto, who pushed the intercept, left after that. 5️⃣ “THORChain is just like BTC” mixes up two different systems. See the comparison screenshot. ⚠️ A per-chain halt / outbound reject on FBI- and OFAC-attributed DPRK addresses and funds fits THORChain’s own “funds-at-risk” emergency framework. THORChain should do the job. Do not put the industry at risk for the fee line.
Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.
17
6
53
13,373
⚠️ Bitget $387.5M hack: status update and security analysis Bitget now puts the theft at about $387.5M, up from the first $351.6M figure. The increase adds Zcash and TRON. It is not a second raid. Compromised wallets were some of Bitget Exchange’s hot and warm wallets. Bitget says cold storage and the separately operated Bitget Wallet self-custody product were not hit. This was not a private-key leak. It was another break in the transaction-signing trust chain. Attackers got Bitget’s own signing stack to produce valid signatures for transfers the exchange never meant to send, then those transfers confirmed. Same structural risk as the 2025 Bybit hack ($1.5B, Safe signing UI tampered): one signing pipeline, one trust root, an obvious target. GoPlus has blacklisted attacker-linked addresses and shared the set with ecosystem partners to help freeze flows and cut residual loss. I. Timeline Sept 24, 18:31 — attacker receive address funded with 0.84 ETH for gas. The gas came from a Bitget hot wallet already under attacker control. Bitget says unauthorized transfers were detected the same minute. 18:58 — first large out: ~$34.75M USDT to the same address funded 27 minutes earlier. 19:16 — largest wave: ~$185M withdrawn in about a minute, including 13,966 ETH on Ethereum, ~91.4M XRP on XRPL, and 20.6M TRX on TRON. 18:58–21:23 — 2h 25m multi-chain drain window: ETH / USDT / USDC / AVAX / BNB / XAUt / XRP / TRX. From 19:00 — attacker swapped stables to ETH via DEX and bridged the pile onto Ethereum. ~21:30 — Bitget CEO Gracy Chen posted the security notice and paused withdrawals. ~22:00 — ~$155M on EVM (ETH/AVAX) split into multiple “dormant vault” addresses. Sept 25, 02:13 onward — continued splitting and movement. Trace: trace.bgblockchain.xyz/v2#ex… Sept 26 — Bitget said root-cause work and system fixes were done and began reopening withdrawals. II. Root Cause Analysis Official update Gracy Chen: attackers compromised a critical backend system in the wallet infrastructure, forged transaction data, and drove Bitget’s own authorized signing flow to move funds. Key leak ruled out. Full technical report and the exact intrusion path are still unpublished. Structural root cause: signing pipeline trusts a single backend Typical CEX withdrawal path: user request → backend checks (balance / risk / whitelist) → build unsigned tx → MPC / multisig / HSM signs → broadcast. What broke: attackers bypassed backend checks and built unsigned txs that risk controls never stopped. The signer — MPC or multisig — cannot judge what it should sign. It signs whatever the backend hands it. They did not take the key layer. They took the risk-decision layer. Once the “what to sign” data source was poisoned, every control sitting on that same backend — rules, limits, approvals — was skipped. Supporting detail: the 0.84 ETH gas on the receive address came from Bitget’s own compromised hot wallet. Before the main drain, they could already drive the signing path. That was a dry run. Forged data also explains the ~3-hour gap: “detected” at 18:31, last out at 21:23. Those transfers likely looked legitimate to internal monitoring, or the signing pipeline had no remotely triggerable kill switch. That delay needs a postmortem as much as the intrusion itself. Possible initial paths (speculation, pending the official report) ▪️ Direct tampering / fake rows in the withdrawal database ▪️ Forged or replayed internal API calls (weak request-level auth / no replay protection between backend and signer) ▪️ Injection into the backend → signer message queue ▪️ Whitelist / address-map swap (user withdrawal address replaced with the attacker’s) Compared with the 2025 Bybit hack Bybit: Safe frontend injected with a malicious script. Signers saw one thing, signed another. Bitget: backend data forged. No human “see” step. Automated signing just ran. Same WYSIWYS failure, front-end vs back-end. Both incidents are being tied to DPRK clusters. III. Attacker addresses and attribution Bitget and the industry published primary attacker / first-hop receive addresses early, including: 0xA6dD3F218B65E32Ccc37BE30f74884133c655545 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2 0x94A43df7687A8494948Be937400e9d5D33135DA0 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C They have kept splitting and hopping to slow tracing and freezes. Related addresses are now near 900. More: trace.bgblockchain.xyz/v2#ex… “Highly likely DPRK-linked,” on three layers: ▪️ On-chain links — researcher Specter tied bridged stolen XRP to proceeds from the July 2026 $24M AFX attack. Elliptic further linked this case to Bybit 2025 laundering addresses. ▪️ Off-chain signals — Bitget investigators matched IPs to a VPN pattern used by a known DPRK cluster (disclosed by Gracy Chen on an X live). ▪️Laundering pattern — stables / non-native assets swapped to native gas tokens within minutes to dodge issuer freezes. Classic DPRK playbook. Funds on Arbitrum were also jumped to Ethereum L1 fast, after the KelpDAO lesson: Arbitrum’s Security Council froze 30,766 ETH; Ethereum L1 cannot. Note: Bitget has not published the technical basis for the DPRK attribution. Chen’s wording is “very likely.” High-confidence assessment, not a closed case. IV. What CEXs should do now 1️⃣ Stand up an independent pre-sign risk engine The failure mode: every control that trusted the business backend died with it. A separate system should simulate and score every tx before sign — size, outflow velocity, first-seen receive address, threat-intel denylist. “Tens of millions in one shot, brand-new receive address, several hot wallets firing in the same window” should have tripped any independent rule. 2️⃣ Circuit breakers and rate limits Detected 18:31, last send 21:23. Almost three hours with no halt. If the first $34.75M had tripped a breaker, about 90% of the funds stay in the house. 3️⃣ People and supply chain DPRK clusters live on social engineering, fake recruiting, and vendor compromise. Treat staff security, operational risk, and software supply chain as first-class controls, and reassess them on a schedule.
8
11
58
14,293
🚨 GoPlus Security Alert: Magic Eden Users — Revoke Limit Break Approvals Immediately Magic Eden once used Limit Break’s payment processor as its Ethereum settlement layer. Vulnerabilities have now been found in Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain. With an unrevoked approval, an attacker can move #NFTs and #WETH without a new signature. Confirmed stolen or unrecovered assets so far: 10 Meebits 50 Otherdeeds 10 World of Women (WoW) 235 Desperate ApeWives 660 $WETH ($1.7M) ⚠️ Any wallet that used @MagicEden on ETH, or approved the contracts below, is at risk. Revoke now: Ethereum Payment Processor V2 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 ApeChain Payment Processor V3 0x9a1D00000000fC540e2000560054812452eB5366
REVOKE APPROVALS TO THESE ASAP: Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366 use revoke.cash or similar.
6
2
12
8,197
🚨 GoPlus Security Alert 🚨 Bitget officially confirmed that its hot and warm wallets were compromised. Estimated loss: $351.6M. Withdrawals are paused pending a full security review.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
2
16
9,883
CZ reposted the open-source fruit-fly experiment, then Fruit Fly / Immortal Fruit Fly memes took off. Most contracts aren’t honeypots or backdoored, but supply is concentrated and liquidity is dead ($10–$1,500). 0x225a Dev held 80% at launch and made $30K.
Article

Security Analysis: BNB Chain “Fruit Fly” Copycat Token

I. The “Fruit Fly” meta Origin (early Sept 2026): Google Research & HHMI Janelia open-sourced a whole-brain fruit-fly connectome (~166,700 neurons). Developers immediately spun up “digital fly”

1
1
8
4,380
⚠️ Exploit breakdown: Neutron governance attack On Sept 22, an attacker used a @neutron_org governance proposal to take admin on @astroport_fi and @dropdotmoney contracts, then moved funds. Notional loss $9.4M (~$1.96M already bridged out). 🔍 Root cause Neutron’s wasmd lets chain governance execute MsgUpdateAdmin and rewrite a contract’s admin. App-level multisigs were not the final authority. Neutron chain governance sat above them and could take the contracts. It also exposed a broken economic-security ratio. At incident-time prices, staked NTRN was worth about $113K, while that same governance power controlled ~$9.4M in contract assets. Decisive voting power was cheaper than the funds it secured. 🔗 Attack flow 1. Malicious proposal Proposal #9, “AIATO: AI Agent Takeover”: neutron.celat.one/neutron-1/… Sold as an AI governance research experiment. The payload was 11 MsgUpdateAdmin messages. Expedited process: 3-day vote, 67% threshold, 1M NTRN deposit. 2. Cheap votes ~$113K of staked NTRN was guarding ~$9.4M. The attacker first voted with ~100 NTRN, then 11 minutes before tally bought 31.62M NTRN with $20,199 USDC and delegated it. 3. Drain One hour before voting closed, they uploaded code_id 5399 with a malicious withdraw_all { recipient } entrypoint. Within 24 minutes of execution they ran MsgMigrateContract ({"migrate_to_v2":{}}) on 10 contracts and called withdraw_all on each. 📌 Attacker addresses Neutron: neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605 Cosmos Hub: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n Noble / Axelar / dYdX / Osmosis — same private key: noble1dd25c4… / axelar1dd25c4… / dydx1dd25c4… / osmo1dd25c4… Ethereum: 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c 0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54
We're aware of a security incident on Neutron that may have exposed admin control of Astroport contracts. Neutron has halted the chain to investigate. As a precaution, withdraw your liquidity from Astroport on all chains until further notice. Updates to follow here.
6
1
16
8,169
📢 GoPlus Security API now supports @arc. As a Web3 security infrastructure provider, GoPlus brings token security, transaction risk detection, and DeepScan AI-powered security audits to the #Arc ecosystem — real-time detection of honeypots, mint risks, blacklists, and more, plus AI contract security audits, continuous security monitoring, and a full suite of capabilities. To support #Arc builders, sign up for an API key with a free quota. Integrate now 👉console.gopluslabs.io/
7
5
24
6,184
⚠️ Update: The same attacker exploited the @SingularityNET bridge to illicitly mint $AGIX and$WMTx. The attacker's bag has swelled to ~$16.77M on paper, with ~$2.2M already cashed out. This is an ecosystem-wide ops key cluster compromise, not an isolated private key leak. Impacted protocols now include @Fetch_ai, @nunet_global, @SingularityNET, and @wmchain. 🛡️ Security Action Plan: Users: Beware of fake support, refund/claim pages, and "token migration" phishing links. Trust official channels only. Exchanges: Freeze all attacker-linked wallets and halt deposits for the illicitly minted tokens. Projects: Rotate ops keys immediately, audit mint/authorizer roles, and enforce hard caps + cross-chain burn proofs on all bridge functions.
🚨 GoPlus Security Alert: On Sept 20, @Fetch_ai and @nunet_global contracts were exploited. The attacker drained 8,721,530 ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 from TokenConversionManagerV3 and illicitly minted 408,532,878 $NTX. The attacker walked away with about $2M. 🔍 Root cause A leaked @Fetch_ai conversion-authorizer private key, plus conversionIn() with no hard cap and no counterparty lock/burn proof. The contract ran as designed: it verified a valid ECDSA signature, then flushed every FET in the bridge to the attacker. The @nunet_global Deployer sat in the same compromised ops key cluster, so NTX was minted straight to the max cap. Attacker 0x1572F2af7696b39c85E3221CDE8EFb640F86c362 Compromised @Fetch_ai conversion authorizer 0x69e5446b07b23de0a76730062c3252152216c85c Compromised @nunet_global NuNet Deployer 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Exploited @Fetch_ai contract (FET) 0xab424A430CC09864fA1277A38193111705ADF3A3 Exploited @nunet_global contract (NTX) 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935 Payout wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE Attack txs etherscan.io/tx/0xfe12c63b32… etherscan.io/tx/0xe14442f617…
2
3
17
9,659
🚨 GoPlus Security Alert: On Sept 20, @Fetch_ai and @nunet_global contracts were exploited. The attacker drained 8,721,530 ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 from TokenConversionManagerV3 and illicitly minted 408,532,878 $NTX. The attacker walked away with about $2M. 🔍 Root cause A leaked @Fetch_ai conversion-authorizer private key, plus conversionIn() with no hard cap and no counterparty lock/burn proof. The contract ran as designed: it verified a valid ECDSA signature, then flushed every FET in the bridge to the attacker. The @nunet_global Deployer sat in the same compromised ops key cluster, so NTX was minted straight to the max cap. Attacker 0x1572F2af7696b39c85E3221CDE8EFb640F86c362 Compromised @Fetch_ai conversion authorizer 0x69e5446b07b23de0a76730062c3252152216c85c Compromised @nunet_global NuNet Deployer 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Exploited @Fetch_ai contract (FET) 0xab424A430CC09864fA1277A38193111705ADF3A3 Exploited @nunet_global contract (NTX) 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935 Payout wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE Attack txs etherscan.io/tx/0xfe12c63b32… etherscan.io/tx/0xe14442f617…
We're aware of reports of an exploit involving a Fetch.ai token conversion contract. Our team is investigating and will share an update soon. Please rely only on official Fetch.ai channels. We will never DM you or ask you to move your tokens.
9
3
28
19,128
🚨 Low-liquidity token alert: In Season 2 of Community Nominations, @Jimmyfestz nominated robinhood:0x77b0aa38451ccdc1b42587e2f80b9879a7f82356 on #RobinhoodChain: 0x77b0AA38451ccDC1b42587E2f80B9879A7f82356 Extremely thin liquidity with heavy wash-trading risk. Stay away to avoid losses. 🔍 #GoPlus review: reported market cap is ~$13.7M, with ~$1.34M nominal liquidity. Real exit depth in the LP is only about 0.28 #ETH. Inside the $1.39M of 24h volume, we found: 1. Wallet 0xef75…5bae bought 1,692,795.2348 DOGO with 9.383 ETH robin.etherscan.io/tx/0xc237… 2. The exact same amount of DOGO was sent to 0x54ff…6edc robin.etherscan.io/tx/0x503c… 3. 41 seconds later, the second wallet sold that same batch back to the pool and received 9.382981234 ETH robin.etherscan.io/tx/0xcc4b… The Result: Net cost was only ~0.0000188 ETH + gas, but it printed 18.766 ETH in two-sided volume and logged two active wallets. Dozens of similar wallet pairs were spotted doing one-off ~1.6M buys and sells over the last 24h. Sells match buys almost perfectly — blatant wash trading designed to fake volume and bait buyers. 📌 A #DeepScan audit of this token contract will be published in a later report. Keep the nominations coming.
1/2 The first "DeepScan Community Nomination" campaign has wrapped up — huge thanks to everyone who nominated 🙌 📢 Round 2 is now live — here's how to join: 1️⃣ Follow @GoPlusSecurity 2️⃣ Comment below: I nominate [Token Name] [Chain] [Contract Address] #DeepScanAudit 3️⃣ Nomination window: Sep 16 – Sep 23 (UTC) 🎁 Rewards: 10 lucky nominators will win 10U each Selected projects will receive a full three-dimensional DeepScan audit — contract, token security, and liquidity — with the report published for all. Good or bad, on-chain data has the final say.
6
2
20
7,975
⚠️ Exploit breakdown: oracle manipulation on Nostra Finance On Sept 17, the @nostrafinance money market on #Starknet was hit with an oracle price-manipulation attack. About $3.5M was borrowed out against inflated collateral. The attacker pumped the NSTR oracle from ~$0.006 to $49.5 — roughly 8,000x — then used the overvalued NSTR as collateral to drain other assets. The money market is fully paused. Supply, borrow, and liquidations are all offline. 🔍 Attack flow ▪️ Months earlier (Mar / Aug): accumulated NSTR and pre-positioned collateral 0x06d48ef7 ▪️ Sept 17, 05:23: created a fake NSTR/SolvBTC pool with 1.5 SolvBTC one-sided liquidity and hijacked GeckoTerminal’s pool selection 0x3aa300d2 ▪️ 05:27–05:47: wash traded the pool and pulled liquidity from the market-making range 0x2d9fb4ed ▪️ 05:47–05:48: swapped through the thin pool and spiked the price to $49.5 0x2d9fb4ed ▪️ 05:48–05:50: borrowed out ETH / STRK / USDC / USDT / WBTC / DAI, ~$3.5M 0x06d48ef7 ▪️ 05:51–07:08: dumped via AVNU / Ekubo / JediSwap; 2.2M STRK left the chain through NEAR Intents 0x06d48ef7 ▪️ Around Sept 18: funds consolidated 0xa059aaab 💡 This is a classic low-liquidity oracle failure: 1️⃣ A illiquid token was accepted as collateral 2️⃣ The price feed relied on a third-party source — the attacker appears to have added surface liquidity so GeckoTerminal picked the rigged NSTR pool 3️⃣ Cost of attack: ~1.5 SolvBTC plus NSTR stacked months earlier at cheap prices 📌 Attacker wallets ▪️ Borrow account 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 6 borrows + ~80 sells. Interacted with NSTR contracts in Mar and Aug 2026 — this was staged months ahead. ▪️ Manipulation account 0x2d9fb4edec9d5c015c43514ca5a309aab1b2638c3a45ad750d09ee971d0da23 Ran the pump/dump flow. ▪️ Transit wallets 0x0285b4bf99e227c4baed7f9a8c7c673771fe0b75e897f7350729e3e13021321d — received 1.2M STRK 0x074f5318f8d60ad0832068dc0430d0a0e2f9dd0c2e710fb8c032945a3804b57e — received 1.0M STRK Both immediately bridged out via NEAR Intents. ▪️ Ethereum consolidation 0xA059Aaab82773CAf622DE9d9A0F2dBF9Aa7F3c37 — ~$1.9M Another ~$1.5M is still sitting in the borrow account. ▪️ Sample txs voyager.online/tx/0x2460fde6… voyager.online/tx/0x79005742…
On September 17, a manipulated NSTR oracle price enabled one account to borrow approximately $3.5 million worth of ETH, STRK, USDC, USDT, WBTC and DAIv1 against NSTR collateral in the Nostra money market on Starknet. The Nostra money market is paused: lending, borrowing, withdrawals and liquidations are currently unavailable. We are reconciling the impact on each asset and tracing the funds. The final loss and potential recoveries are not yet known. We are working with relevant parties on recovery and will share verified updates, including a detailed post-mortem. Beware of impersonators. Nostra will never DM you or ask you to connect a wallet as part of recovery. Ongoing updates will be posted in our Discord.
8
3
24
10,227
Got drained. Staring at an empty wallet. You tweet for help. DM KOLs. Google guides. Ask AI. In that panic, a lot of people get hit a second time. Stop scrambling. Stop guessing. GoPlus just shipped Wallet Theft Detective — a local, read-only Skill that lets your AI Agent hunt down the root cause of the drain. Built specifically for theft forensics. Covers 20+ common off-chain attack vectors: • Clipboard hijacks & address swaps • Infostealers • Malicious browser extensions • npm / PyPI / software supply-chain poisoning • Malicious IDE plugins & fake SDKs • Fake support, fake job offers, fake meetings & upgrade phishing • Drainers, malicious approvals, Permit, blind signing & address poisoning • Seed / private key storage leaks • Fake wallets & mobile permission abuse … Open source. Get your Agent ready before you need it: github.com/GoPlusSecurity/wa…
3
5
21
5,814
1/2 The first "DeepScan Community Nomination" campaign has wrapped up — huge thanks to everyone who nominated 🙌 📢 Round 2 is now live — here's how to join: 1️⃣ Follow @GoPlusSecurity 2️⃣ Comment below: I nominate [Token Name] [Chain] [Contract Address] #DeepScanAudit 3️⃣ Nomination window: Sep 16 – Sep 23 (UTC) 🎁 Rewards: 10 lucky nominators will win 10U each Selected projects will receive a full three-dimensional DeepScan audit — contract, token security, and liquidity — with the report published for all. Good or bad, on-chain data has the final say.
423
347
405
22,820
2/2 Three highlights from Round 1 : 🚨 We exposed a pig-butchering scam ($JINQIAN) 📉 A perfect-scoring contract still crashed 99% ($LAPTOP) 🔍 Serial token deployments aren't always a red flag (ethereum:0xcf0c122c6b73ff809c693db761e7baebe62b6a2e) Other audit results are as follows:
1
4
1,707
🚨 GoPlus Security Alert: Watch out for copycat rugs on Arc Arc Chain's launch is hot — day-one volume passed $144M. While most users are still figuring out how to bridge, copycat rugs of high-cap Launchpad tokens $ARGUS and $TOLLY are already popping up. ⚠️ Stay sharp. Double-check the CA before you trade.
3
8
40
12,845
According to GoPlus security research: Of 324,000 token issuances on Robinhood, the main risks that have appeared include business fraud, technical risks, contract vulnerabilities, trading security, and social engineering fraud.
Article

Robinhood Chain Risk Analysis Report

The fastest-growing Ethereum L2 of 2026 compressed two years of ecosystem risk into two months. This report maps the incidents, the market structure that produced them, and a working security

3
2
10
5,390
1/4 ⚠️ Exploit Breakdown On Sep 15, 2026, a whale’s #Safe wallet was drained via an auth bypass in its strategy executor. Loss: ~$7.8M. ❓ Root Cause Any caller could set the target to `address(this)` and skip both authorization checks, then `DELEGATECALL` through an already-enabled Safe Module — running arbitrary logic in the Safe’s own context. The attacker dumped ~2,900 aEthrsETH into a Uniswap v4 pool paired against a worthless PAT token, leaving the victim Safe with nothing but junk LP NFTs. The original exploit tx was front-run by MEV bot "Yoink", which walked away with the entire rsETH stack. 🔍 Attack Flow The bug sits in this unverified strategy executor: 0x4f0055926c839D1d960a82CBF84E2eE933958ebC Not in Safe core. Not in Aave. Not in rsETH. (1) Intended path: the target must be an allowlisted Safe, and `msg.sender` must be a Module enabled by that Safe. Set the target to `address(this)` — the executor itself — and both the allowlist check and the Module auth check get skipped.
8
10
62
12,445
3/4 3. From there, the attacker had arbitrary execution as the Safe itself — approve, transfer, drain. etherscan.io/tx/0x0e7680b06c…
1
699
4/4 📌 Key Addresses & Transactions Original attacker EOA — funded via Railgun `0x0dC2c5D6b05A317076CF501f7E7be36a5dfe9b66` Original exploit contract — deployed PAT, received aTokens, redeemed from Aave `0x10605eE48Ff962952C966277A5D2dac0A0705Cb1` Worthless PAT token — Permissionless Attacker Token `0x8762788ba3ecEe7B61Fc7578A3533433E20461F5` Front-runner EOA — MEV Yoink `0xFDe0d1575Ed8E06FBf36256bcdfA1F359281455A` Front-running contract — MEV Bot: Yoink `0x80BF7Db69556D9521c03461978B8fC731DBBD4e4` Vulnerable strategy executor `0x4f0055926c839D1d960a82CBF84E2eE933958ebC` Abused Safe Module `0xDcDc4ef8C992E75bb0F300536CD93E601c8882AB` Victim Safe — Gnosis Safe v1.3.0 `0x40E93a52F6Af9fCD3b476aeDADD7FeABD9f7AbA8` Final profit address — still holding 2,882.37 rsETH `0xC70f00CD7E461686b04B0E912E309becA8b80ea0` Original exploit tx: etherscan.io/tx/0x16b9ddf976… MEV front-run tx: etherscan.io/tx/0x0e7680b06c…
522