Protect Your Every Transaction. User App: chromewebstore.google.com/se… 🛡️ Dev Integration: Security Intelligence & SafeToken Protocol 🛡️

On-Chain
Based in Japan
⚠️ Another meme rug factory just lit up on Robinhood Chain. 30-day flow: $9M+. On-chain researcher Wazz recently flagged a suspected serial-rug crew that spun up at least 53 Robinhood Chain memes in ~2 months and pulled about $18.43M. Playbook: 70–200 wallets sit on most of the supply, then recycle last-round proceeds into the next launch. #GoPlus just caught a separate high-risk meme factory on the same chain. Last 30 days: $9M+ in flow across hundreds of scam memes. Consolidation wallet: 0x8c3Bad30cc7563A2D0357F49509FFd063666bb00 As of Sept 28, 2026: ▪️ Balance: 56.0635 ETH ($148K) ▪️ 1,385 txs total ▪️ Last 400 txs: In ~1,728.02 ETH Out ~1,861.12 ETH Two-way flow ~3,589.14 ETH ($9.49M) High-risk related memes The attached memes all show the same trail: approve/sell → dump ETH → same sweep wallet. Figures are gross inflows from that project’s batch into the consolidation cluster. Not net PnL. The factory loop Fresh-wallet dumps → layered consolidation → capital recycle. 1) Spin a token off whatever narrative is hot 2) Seed a pile of fresh EOAs with only 4–11 txs 3) Sell in tranches via PonsV2Helper / UniversalRouter 4) Sweep ETH to a local sweep wallet or the main consolidation wallet (0x8c3bad) 5) Bankroll the next ticker, the next wallets, the next ops This is not “you can’t sell.” The real trick: 1) Hide concentration behind a swarm of fresh wallets 2) Stagger the dumps so it looks like many independent sellers 3) After the exit, sweep everything into one consolidation cluster 4) Reload the next launch with last round’s take Comparing the Two Scams Same DNA: ▪️ Heavy Pons V2 usage ▪️ Wallet batches used to mask real supply concentration ▪️ Coordinated flow, unified sweep, profit recycle ▪️ Not a classic LP pull or sell-block rug ▪️ Prior-round proceeds look like next-round seed capital Different shape: ▪️ Wazz’s case: 70–200 wallets sniping and sitting on 70%+ supply, anti-snipe tax exemptions, plus a cross-project funding key ▪️ This case: mass fresh EOAs, then consolidation and reuse Same class of fraud. No proof it’s the same crew.
I just uncovered the biggest serial Rugpulling and Extraction operation on Robinhood The same operation is linked 53 launches within a 2 month period Total Extracted: $18.43 MILLION very likely more this is just what I could directly link 🧵
4
5
15
4,144
❗️ #THORChain has never been strictly decentralized @THORChain comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds. 1️⃣ Custody: TSS vaults ≠ base-layer consensus On BTC/ETH, users control assets with their own keys. Miners/validators order and include txs. They never hold user funds. The worst a single miner can do is refuse to include your tx. They cannot send your coins. Every THORChain outbound (vault → user/attacker) has to be actively produced by the current active set via a GG20 TSS threshold signature. During a swap, funds sit in a TSS vault jointly controlled by those nodes. Releasing stolen funds is an active signing event, not “neutral ordering we cannot stop.” As @star_okx put it: from a custody view it is an intermediary between users and native chains. Distributed centralized custody is not decentralization. 2️⃣ Validator set: small, and it can coordinate Official docs: THORNodes bond RUNE to join. Active-set cap is ~100 (can scale to 250+), with a churn about every 3 days that drops the oldest, slowest, lowest-bond nodes. Nodes coordinate in real time on Dev Discord’s #mainnet channel — anonymous relays, votes (Mimir / node votes). That is an organization with a comms channel, a voting process, and execution tools. Not BTC/ETH’s globally anonymous set with no coordination path. 3️⃣ Intervention is designed in. There are runbooks. There are precedents. make pause: one node can halt the network (720 blocks per trigger, stackable). Slogan: “Halt Earn, Halt Often!” Standard is “an abundance of caution.” False trips can be undone with make resume. Per-chain signing halt: node votes can pause outbound signing on one chain only — the tool needed to stop ETH/BNB → BTC exits without taking the whole network down. Mimir governance: nodes can vote live to change params, halt trading, halt signing. Precedent: when THORChain itself was drained in May 2026, they paused and ran a controlled halt to stop further movement. 4️⃣ Inaction pays In the Bybit case, the attacker washed all 499K ETH in 10 days, mostly through THORChain into BTC. That printed ~$5.9B volume and ~$5.5M fees for THORChain. In the Bitget case, ~101.5 BTC (≈$8.5M) has already gone out via THORChain, with another ~27.63M XRP (≈$43M) mid-swap into BTC. Potential fee take: hundreds of thousands of dollars. In Feb 2025, validators voted to intercept DPRK-linked funds, then reversed. Core contributor Pluto, who pushed the intercept, left after that. 5️⃣ “THORChain is just like BTC” mixes up two different systems. See the comparison screenshot. ⚠️ A per-chain halt / outbound reject on FBI- and OFAC-attributed DPRK addresses and funds fits THORChain’s own “funds-at-risk” emergency framework. THORChain should do the job. Do not put the industry at risk for the fee line.
Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.
21
7
61
17,364
⚠️ Bitget $387.5M hack: status update and security analysis Bitget now puts the theft at about $387.5M, up from the first $351.6M figure. The increase adds Zcash and TRON. It is not a second raid. Compromised wallets were some of Bitget Exchange’s hot and warm wallets. Bitget says cold storage and the separately operated Bitget Wallet self-custody product were not hit. This was not a private-key leak. It was another break in the transaction-signing trust chain. Attackers got Bitget’s own signing stack to produce valid signatures for transfers the exchange never meant to send, then those transfers confirmed. Same structural risk as the 2025 Bybit hack ($1.5B, Safe signing UI tampered): one signing pipeline, one trust root, an obvious target. GoPlus has blacklisted attacker-linked addresses and shared the set with ecosystem partners to help freeze flows and cut residual loss. I. Timeline Sept 24, 18:31 — attacker receive address funded with 0.84 ETH for gas. The gas came from a Bitget hot wallet already under attacker control. Bitget says unauthorized transfers were detected the same minute. 18:58 — first large out: ~$34.75M USDT to the same address funded 27 minutes earlier. 19:16 — largest wave: ~$185M withdrawn in about a minute, including 13,966 ETH on Ethereum, ~91.4M XRP on XRPL, and 20.6M TRX on TRON. 18:58–21:23 — 2h 25m multi-chain drain window: ETH / USDT / USDC / AVAX / BNB / XAUt / XRP / TRX. From 19:00 — attacker swapped stables to ETH via DEX and bridged the pile onto Ethereum. ~21:30 — Bitget CEO Gracy Chen posted the security notice and paused withdrawals. ~22:00 — ~$155M on EVM (ETH/AVAX) split into multiple “dormant vault” addresses. Sept 25, 02:13 onward — continued splitting and movement. Trace: trace.bgblockchain.xyz/v2#ex… Sept 26 — Bitget said root-cause work and system fixes were done and began reopening withdrawals. II. Root Cause Analysis Official update Gracy Chen: attackers compromised a critical backend system in the wallet infrastructure, forged transaction data, and drove Bitget’s own authorized signing flow to move funds. Key leak ruled out. Full technical report and the exact intrusion path are still unpublished. Structural root cause: signing pipeline trusts a single backend Typical CEX withdrawal path: user request → backend checks (balance / risk / whitelist) → build unsigned tx → MPC / multisig / HSM signs → broadcast. What broke: attackers bypassed backend checks and built unsigned txs that risk controls never stopped. The signer — MPC or multisig — cannot judge what it should sign. It signs whatever the backend hands it. They did not take the key layer. They took the risk-decision layer. Once the “what to sign” data source was poisoned, every control sitting on that same backend — rules, limits, approvals — was skipped. Supporting detail: the 0.84 ETH gas on the receive address came from Bitget’s own compromised hot wallet. Before the main drain, they could already drive the signing path. That was a dry run. Forged data also explains the ~3-hour gap: “detected” at 18:31, last out at 21:23. Those transfers likely looked legitimate to internal monitoring, or the signing pipeline had no remotely triggerable kill switch. That delay needs a postmortem as much as the intrusion itself. Possible initial paths (speculation, pending the official report) ▪️ Direct tampering / fake rows in the withdrawal database ▪️ Forged or replayed internal API calls (weak request-level auth / no replay protection between backend and signer) ▪️ Injection into the backend → signer message queue ▪️ Whitelist / address-map swap (user withdrawal address replaced with the attacker’s) Compared with the 2025 Bybit hack Bybit: Safe frontend injected with a malicious script. Signers saw one thing, signed another. Bitget: backend data forged. No human “see” step. Automated signing just ran. Same WYSIWYS failure, front-end vs back-end. Both incidents are being tied to DPRK clusters. III. Attacker addresses and attribution Bitget and the industry published primary attacker / first-hop receive addresses early, including: 0xA6dD3F218B65E32Ccc37BE30f74884133c655545 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2 0x94A43df7687A8494948Be937400e9d5D33135DA0 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C They have kept splitting and hopping to slow tracing and freezes. Related addresses are now near 900. More: trace.bgblockchain.xyz/v2#ex… “Highly likely DPRK-linked,” on three layers: ▪️ On-chain links — researcher Specter tied bridged stolen XRP to proceeds from the July 2026 $24M AFX attack. Elliptic further linked this case to Bybit 2025 laundering addresses. ▪️ Off-chain signals — Bitget investigators matched IPs to a VPN pattern used by a known DPRK cluster (disclosed by Gracy Chen on an X live). ▪️Laundering pattern — stables / non-native assets swapped to native gas tokens within minutes to dodge issuer freezes. Classic DPRK playbook. Funds on Arbitrum were also jumped to Ethereum L1 fast, after the KelpDAO lesson: Arbitrum’s Security Council froze 30,766 ETH; Ethereum L1 cannot. Note: Bitget has not published the technical basis for the DPRK attribution. Chen’s wording is “very likely.” High-confidence assessment, not a closed case. IV. What CEXs should do now 1️⃣ Stand up an independent pre-sign risk engine The failure mode: every control that trusted the business backend died with it. A separate system should simulate and score every tx before sign — size, outflow velocity, first-seen receive address, threat-intel denylist. “Tens of millions in one shot, brand-new receive address, several hot wallets firing in the same window” should have tripped any independent rule. 2️⃣ Circuit breakers and rate limits Detected 18:31, last send 21:23. Almost three hours with no halt. If the first $34.75M had tripped a breaker, about 90% of the funds stay in the house. 3️⃣ People and supply chain DPRK clusters live on social engineering, fake recruiting, and vendor compromise. Treat staff security, operational risk, and software supply chain as first-class controls, and reassess them on a schedule.
9
11
58
14,737
🚨 GoPlus Security Alert 🚨 Bitget officially confirmed that its hot and warm wallets were compromised. Estimated loss: $351.6M. Withdrawals are paused pending a full security review.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
2
16
10,005
⚠️ Exploit breakdown: Neutron governance attack On Sept 22, an attacker used a @neutron_org governance proposal to take admin on @astroport_fi and @dropdotmoney contracts, then moved funds. Notional loss $9.4M (~$1.96M already bridged out). 🔍 Root cause Neutron’s wasmd lets chain governance execute MsgUpdateAdmin and rewrite a contract’s admin. App-level multisigs were not the final authority. Neutron chain governance sat above them and could take the contracts. It also exposed a broken economic-security ratio. At incident-time prices, staked NTRN was worth about $113K, while that same governance power controlled ~$9.4M in contract assets. Decisive voting power was cheaper than the funds it secured. 🔗 Attack flow 1. Malicious proposal Proposal #9, “AIATO: AI Agent Takeover”: neutron.celat.one/neutron-1/… Sold as an AI governance research experiment. The payload was 11 MsgUpdateAdmin messages. Expedited process: 3-day vote, 67% threshold, 1M NTRN deposit. 2. Cheap votes ~$113K of staked NTRN was guarding ~$9.4M. The attacker first voted with ~100 NTRN, then 11 minutes before tally bought 31.62M NTRN with $20,199 USDC and delegated it. 3. Drain One hour before voting closed, they uploaded code_id 5399 with a malicious withdraw_all { recipient } entrypoint. Within 24 minutes of execution they ran MsgMigrateContract ({"migrate_to_v2":{}}) on 10 contracts and called withdraw_all on each. 📌 Attacker addresses Neutron: neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605 Cosmos Hub: cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n Noble / Axelar / dYdX / Osmosis — same private key: noble1dd25c4… / axelar1dd25c4… / dydx1dd25c4… / osmo1dd25c4… Ethereum: 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c 0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54
We're aware of a security incident on Neutron that may have exposed admin control of Astroport contracts. Neutron has halted the chain to investigate. As a precaution, withdraw your liquidity from Astroport on all chains until further notice. Updates to follow here.
6
1
16
8,203
📢 GoPlus Security API now supports @arc. As a Web3 security infrastructure provider, GoPlus brings token security, transaction risk detection, and DeepScan AI-powered security audits to the #Arc ecosystem — real-time detection of honeypots, mint risks, blacklists, and more, plus AI contract security audits, continuous security monitoring, and a full suite of capabilities. To support #Arc builders, sign up for an API key with a free quota. Integrate now 👉console.gopluslabs.io/
7
5
24
6,211
⚠️ Update: The same attacker exploited the @SingularityNET bridge to illicitly mint $AGIX and$WMTx. The attacker's bag has swelled to ~$16.77M on paper, with ~$2.2M already cashed out. This is an ecosystem-wide ops key cluster compromise, not an isolated private key leak. Impacted protocols now include @Fetch_ai, @nunet_global, @SingularityNET, and @wmchain. 🛡️ Security Action Plan: Users: Beware of fake support, refund/claim pages, and "token migration" phishing links. Trust official channels only. Exchanges: Freeze all attacker-linked wallets and halt deposits for the illicitly minted tokens. Projects: Rotate ops keys immediately, audit mint/authorizer roles, and enforce hard caps + cross-chain burn proofs on all bridge functions.
🚨 GoPlus Security Alert: On Sept 20, @Fetch_ai and @nunet_global contracts were exploited. The attacker drained 8,721,530 ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 from TokenConversionManagerV3 and illicitly minted 408,532,878 $NTX. The attacker walked away with about $2M. 🔍 Root cause A leaked @Fetch_ai conversion-authorizer private key, plus conversionIn() with no hard cap and no counterparty lock/burn proof. The contract ran as designed: it verified a valid ECDSA signature, then flushed every FET in the bridge to the attacker. The @nunet_global Deployer sat in the same compromised ops key cluster, so NTX was minted straight to the max cap. Attacker 0x1572F2af7696b39c85E3221CDE8EFb640F86c362 Compromised @Fetch_ai conversion authorizer 0x69e5446b07b23de0a76730062c3252152216c85c Compromised @nunet_global NuNet Deployer 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Exploited @Fetch_ai contract (FET) 0xab424A430CC09864fA1277A38193111705ADF3A3 Exploited @nunet_global contract (NTX) 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935 Payout wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE Attack txs etherscan.io/tx/0xfe12c63b32… etherscan.io/tx/0xe14442f617…
2
3
17
9,684
🚨 GoPlus Security Alert: On Sept 20, @Fetch_ai and @nunet_global contracts were exploited. The attacker drained 8,721,530 ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 from TokenConversionManagerV3 and illicitly minted 408,532,878 $NTX. The attacker walked away with about $2M. 🔍 Root cause A leaked @Fetch_ai conversion-authorizer private key, plus conversionIn() with no hard cap and no counterparty lock/burn proof. The contract ran as designed: it verified a valid ECDSA signature, then flushed every FET in the bridge to the attacker. The @nunet_global Deployer sat in the same compromised ops key cluster, so NTX was minted straight to the max cap. Attacker 0x1572F2af7696b39c85E3221CDE8EFb640F86c362 Compromised @Fetch_ai conversion authorizer 0x69e5446b07b23de0a76730062c3252152216c85c Compromised @nunet_global NuNet Deployer 0x863F13e5B505f1Eb17803b94EC9d3DaF80092165 Exploited @Fetch_ai contract (FET) 0xab424A430CC09864fA1277A38193111705ADF3A3 Exploited @nunet_global contract (NTX) 0xF0d33BeDa4d734C72684b5f9abBEbf715D0a7935 Payout wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE Attack txs etherscan.io/tx/0xfe12c63b32… etherscan.io/tx/0xe14442f617…
We're aware of reports of an exploit involving a Fetch.ai token conversion contract. Our team is investigating and will share an update soon. Please rely only on official Fetch.ai channels. We will never DM you or ask you to move your tokens.
9
3
28
19,166
🚨 Low-liquidity token alert: In Season 2 of Community Nominations, @Jimmyfestz nominated robinhood:0x77b0aa38451ccdc1b42587e2f80b9879a7f82356 on #RobinhoodChain: 0x77b0AA38451ccDC1b42587E2f80B9879A7f82356 Extremely thin liquidity with heavy wash-trading risk. Stay away to avoid losses. 🔍 #GoPlus review: reported market cap is ~$13.7M, with ~$1.34M nominal liquidity. Real exit depth in the LP is only about 0.28 #ETH. Inside the $1.39M of 24h volume, we found: 1. Wallet 0xef75…5bae bought 1,692,795.2348 DOGO with 9.383 ETH robin.etherscan.io/tx/0xc237… 2. The exact same amount of DOGO was sent to 0x54ff…6edc robin.etherscan.io/tx/0x503c… 3. 41 seconds later, the second wallet sold that same batch back to the pool and received 9.382981234 ETH robin.etherscan.io/tx/0xcc4b… The Result: Net cost was only ~0.0000188 ETH + gas, but it printed 18.766 ETH in two-sided volume and logged two active wallets. Dozens of similar wallet pairs were spotted doing one-off ~1.6M buys and sells over the last 24h. Sells match buys almost perfectly — blatant wash trading designed to fake volume and bait buyers. 📌 A #DeepScan audit of this token contract will be published in a later report. Keep the nominations coming.
1/2 The first "DeepScan Community Nomination" campaign has wrapped up — huge thanks to everyone who nominated 🙌 📢 Round 2 is now live — here's how to join: 1️⃣ Follow @GoPlusSecurity 2️⃣ Comment below: I nominate [Token Name] [Chain] [Contract Address] #DeepScanAudit 3️⃣ Nomination window: Sep 16 – Sep 23 (UTC) 🎁 Rewards: 10 lucky nominators will win 10U each Selected projects will receive a full three-dimensional DeepScan audit — contract, token security, and liquidity — with the report published for all. Good or bad, on-chain data has the final say.
6
2
20
7,996
Got drained. Staring at an empty wallet. You tweet for help. DM KOLs. Google guides. Ask AI. In that panic, a lot of people get hit a second time. Stop scrambling. Stop guessing. GoPlus just shipped Wallet Theft Detective — a local, read-only Skill that lets your AI Agent hunt down the root cause of the drain. Built specifically for theft forensics. Covers 20+ common off-chain attack vectors: • Clipboard hijacks & address swaps • Infostealers • Malicious browser extensions • npm / PyPI / software supply-chain poisoning • Malicious IDE plugins & fake SDKs • Fake support, fake job offers, fake meetings & upgrade phishing • Drainers, malicious approvals, Permit, blind signing & address poisoning • Seed / private key storage leaks • Fake wallets & mobile permission abuse … Open source. Get your Agent ready before you need it: github.com/GoPlusSecurity/wa…
3
5
21
5,825
2/2 Three highlights from Round 1 : 🚨 We exposed a pig-butchering scam ($JINQIAN) 📉 A perfect-scoring contract still crashed 99% ($LAPTOP) 🔍 Serial token deployments aren't always a red flag (ethereum:0xcf0c122c6b73ff809c693db761e7baebe62b6a2e) Other audit results are as follows:
1
4
1,725
1/2 The first "DeepScan Community Nomination" campaign has wrapped up — huge thanks to everyone who nominated 🙌 📢 Round 2 is now live — here's how to join: 1️⃣ Follow @GoPlusSecurity 2️⃣ Comment below: I nominate [Token Name] [Chain] [Contract Address] #DeepScanAudit 3️⃣ Nomination window: Sep 16 – Sep 23 (UTC) 🎁 Rewards: 10 lucky nominators will win 10U each Selected projects will receive a full three-dimensional DeepScan audit — contract, token security, and liquidity — with the report published for all. Good or bad, on-chain data has the final say.
423
346
404
22,882
🚨 GoPlus Security Alert: Watch out for copycat rugs on Arc Arc Chain's launch is hot — day-one volume passed $144M. While most users are still figuring out how to bridge, copycat rugs of high-cap Launchpad tokens $ARGUS and $TOLLY are already popping up. ⚠️ Stay sharp. Double-check the CA before you trade.
3
8
40
12,856
3/4 3. From there, the attacker had arbitrary execution as the Safe itself — approve, transfer, drain. etherscan.io/tx/0x0e7680b06c…
1
701
2/4 (2) Now acting as a "trusted executor," the strategy executor routed a call through the victim Safe’s enabled module 0xDcDc4ef8C992E75bb0F300536CD93E601c8882AB to invoke execTransactionFromModuleReturnData, with operation = 1 (DELEGATECALL). etherscan.io/tx/0x0e7680b06c…
1
762
1/4 ⚠️ Exploit Breakdown On Sep 15, 2026, a whale’s #Safe wallet was drained via an auth bypass in its strategy executor. Loss: ~$7.8M. ❓ Root Cause Any caller could set the target to `address(this)` and skip both authorization checks, then `DELEGATECALL` through an already-enabled Safe Module — running arbitrary logic in the Safe’s own context. The attacker dumped ~2,900 aEthrsETH into a Uniswap v4 pool paired against a worthless PAT token, leaving the victim Safe with nothing but junk LP NFTs. The original exploit tx was front-run by MEV bot "Yoink", which walked away with the entire rsETH stack. 🔍 Attack Flow The bug sits in this unverified strategy executor: 0x4f0055926c839D1d960a82CBF84E2eE933958ebC Not in Safe core. Not in Aave. Not in rsETH. (1) Intended path: the target must be an allowlisted Safe, and `msg.sender` must be a Module enabled by that Safe. Set the target to `address(this)` — the executor itself — and both the allowlist check and the Module auth check get skipped.
8
10
62
12,458
🚨 GoPlus Security Alert: active proposal attack on #Ampleforth On Sept 12, a freshly funded EOA submitted a malicious proposal on @AmpleforthOrg. Masked as a completed-work grant for SPOT ecosystem analytics tools, it asks to send 2,500,000 USDC from the treasury to the proposer — nearly all liquid treasury funds. Proposal: tally.xyz/gov/ampleforth/pro… Status: Pending. No votes. Funds have not moved. The pass threshold is the risk. 75,000 FORTH to propose, 600,000 FORTH to pass. At the alert-time price of $0.27, ~$160k of voting power could clear $2.5M USDC. Stay sharp. Proposer / payout 0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82 87,238.546 FORTH voting power Delegator 0x38cAaa5782BF8afF646403D567D76b016d5c24D8 Same 87,238.546 FORTH. Delegated to the proposer 19 minutes before submission. Relay / funder 0x92fc19271fce6d48cd41a0eff6f5dd40f1090d72 Sent 87,238 FORTH + 0.005 ETH gas to the delegator.
3
18
8,192
More, deeper, more comprehensive AI security audits 🔍 — GoPlus #DeepScan
5
3
16
6,140
$LAPTOP crashed 99% after launch. Still worth aping? An on-chain and smart contract security breakdown. Token: Hunter Biden’s Laptop ($LAPTOP) Base contract: 0xB095274743941e953c746F9C228DA9c18Bb6ec29 Snapshot: Sep 10, 2026 ⚠️ Overall risk: Extremely high liquidity risk. Ownership remains highly concentrated. Closely monitor fund movements by the founding team and market makers, watch for new disclosures, and adjust your trading strategy accordingly. Ⅰ. Price action: From launch to a 99% drawdown • Sep 9 launch: ~$0.40. A sniper bought 2,268.56 tokens for 900 USDC. • Sep 9, 12:09: ATH of $199.50. GMGN briefly showed a $257.9B market cap after a 7,716% five-minute spike. • The initial pool was razor-thin, allowing a single buy to send the price vertical. • Later that day, the sniper fully exited at an average of ~$111, booking $250K+ in profit—a 278x return. • Sep 10, 01:14: ATL of $0.7234, down 99.64% from ATH. • Current range: $0.72–$1.02, showing early signs of stabilization. • Nominal market cap: ~$335M. FDV: ~$1.02B. Ⅱ. Liquidity and trading activity 24-hour volume was approximately $36.7M on CoinGecko, with $17.4M routed through Aerodrome. Liquidity is migrating to Aerodrome: • Aerodrome liquidity: ~$1.62M • Share of total on-chain liquidity: ~74% • Total tradable liquidity: only ~$2.2M • Uniswap-based liquidity: ~$550K spread across roughly 380 pools • Liquidity/market-cap ratio: ~0.65% Any sell order above $50K could cause significant price impact. The volume-to-liquidity ratio is approximately 17x. That is elevated, but still explainable during a highly speculative launch phase. It is too early to call this wash trading—continued monitoring is needed. Ⅲ. Holder concentration • Holders: 31K+ • Largest holder: 30%, identified as the founder allocation under lock • Nominal Top 10 concentration: 96.32% • Adjusted Top 10 concentration after excluding custodians, pools, and confirmed locked allocations: ~27.8% Ⅳ. Contract security: No vulnerabilities or backdoors detected GoPlus DeepScan AI audit: No vulnerabilities detected. Full report: deepscan.gopluslabs.io/audit… GoPlus Token Security: No backdoors detected. Full report: deepscan.gopluslabs.io/token… A clean contract does not eliminate liquidity, concentration, governance, or market-manipulation risk. Ⅴ. Five critical signals to monitor—in priority order ① Multisig outflows Watch all outbound transfers from: `0xd81bf90a` `0x296f38f1` `0xeff4d820` `0x8aeaffde` `0xcb92b4cb` Pay particular attention to any movement from the 30% founder allocation before the publicly stated lock expires in March 2027. Any such movement would breach that commitment. ② Upgradeable distribution contract Monitor implementation changes to `0x38e33d04`, which holds 7.92% of supply. Its admin, `0x9fc64850`, is a single EOA. Because the contract is upgradeable, the allocation rules could be changed. ③ Aerodrome LP movements Aerodrome currently holds 74% of total on-chain liquidity. A major LP withdrawal could create an immediate liquidity cliff. ④ Dynamic-fee hook pools Track whether fees are increased as trading volume grows. ⑤ Prediction-event allocation Monitor whether the 30% allocation is released according to the announced schedule—or whether its distribution rules are deployed and enforced on-chain. Ⅵ. Hunter’s public statement vs. on-chain activity After the crash, Hunter stated on X that: • The team allocation was locked. • Nobody on their side had sold. • He personally had not made a single dollar. • The crash was mainly caused by thin liquidity, technical issues, and sniper bots. What the chain shows: • The 30% founder allocation does appear to be locked. Those 300M team tokens were not directly sold. • Before launch, a project multisig—`0x8aeaFfdE02E751C04D96cec90D93f93C50Bcc530`—received 100M $LAPTOP, equal to 10% of total supply. • Its current balance is 57,499,200 tokens, implying net outflows of approximately 42,500,800 tokens. • Transfers went to addresses associated with GSR (15.5M), G20 (5M), Wintermute (2.5M), and other wallets. Important distinction: 42.5M tokens transferred does not mean 42.5M tokens were sold. What can currently be established: • The project multisig moved approximately 42.5M tokens to market-making, operational, and unlabeled addresses. • Those tokens were capable of entering the market around launch. • Wintermute sold at least approximately 466,300 tokens, receiving around $2.08M. • An unlabeled address holding 14.5M tokens still retained them at the snapshot time, so they should not be counted as sold. • Transfers to GSR, G20, or exchange deposit addresses do not prove that every transferred token was sold on the open market.
10
7,417
🚨 URGENT: PHISHING ALERT If you got an email from help@trezor.io titled “Critical Security Alert: STM32 Entropy Vulnerability” telling you to click a link and run a “device check” — stop. Do not click anything. That mail is not from Trezor. Their third-party email provider got compromised, and attackers used it to send a fake entropy/RNG advisory. Same vendor-email blast is also hitting CoinTracking and BitBox users. Treat every “security update” link as hostile. No downloads. No xPub. No seed.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
1
1
12
7,264
🚨 GoPlus Security Alert: Beware of phishing sites impersonating the $LAPTOP airdrop and same-name copycat tokens with security risks such as unverified contract source code and high taxes. The $LAPTOP meme coin associated with @HunterBiden is expected to launch with an airdrop soon. Numerous phishing sites are already appearing on X, posing as $LAPTOP airdrop whitelist registrations, eligibility checkers, and claim pages. Meanwhile, copycat tokens using the same $LAPTOP ticker are being traded across multiple chains. Their contracts may carry risks including unverified source code, high transaction taxes, and the ability to pause trading. 🛡️GoPlus Security Recommendations: 1. Rely only on information from the official website and official X accounts. Verify updates through @HunterBiden and @Laptoptoken. 2. Exercise caution when trading copycat tokens. Always use GoPlus Token Security to check the contract before interacting. 3. Remember the #GoPlus “Four Don’ts” for phishing prevention:don’t click, don’t install, don’t sign, and don’t transfer. Don’t click unfamiliar links. Don’t install software from unknown sources. Don’t sign wallet transactions you don’t fully understand. Don’t transfer funds to unverified addresses.
16
7,980
📢 They’re still haggling onchain. Liquid attacker sent back 3,400 #BTC. Still holding 598.49 BTC (15%). Return tx: mempool.space/tx/a6d697a2526… That 15% is the attacker’s cut, taken unilaterally. Team has not signed off on it. ~7 hours after the refund, the project pinged the attacker address with an encrypted note only they can decrypt. Almost certainly still haggling over the leftover 598.5 BTC. On-chain ping: mempool.space/tx/9a041c868fc…
⚠️ Exploit breakdown: Sept 6: @Liquid_BTC got hit through an Elements consensus / asset-validation bug. Attacker minted ~4,000 unbacked L-BTC, then used SideSwap’s normal peg-out flow to cash out 3,996.01834922 BTC from the Liquid Federation reserve. They called it whitehat and said funds come back after every node is patched. Still sitting. No return. 📌 IOCs Attacker: mempool.space/address/bc1qgs… Collection wallet: mempool.space/address/bc1ql4… Hit reserve: mempool.space/address/bc1qdl… 🔍 How it played out 1. Phantom L-BTC Liquid block 4,050,336 (2026-09-06 21:53:10 CST) was accepted by Federation / Blockstream nodes. mempool.space’s independent Liquid node rejected it and stalled on the prior block. Clean consensus split. Suspect mint: blockstream.info/liquid/tx/c… 2. Peg-out via SideSwap 3,996.01834922 BTC paid to bc1qgsls...c6wt7p blockstream.info/liquid/tx/c… Blockstream later said the L-BTC came from an Elements bug. SideSwap PAK + infra were not compromised. nitter.net/side_swap/status/20967… 3. Federation pays on Bitcoin L1 mempool.space/tx/8db751a650a… 4. Funds swept mempool.space/tx/85d2ca15bea… 5. On-chain note OP_RETURN: “we are whitehats. contact us on chain.” Also told Liquid to patch first, then they’d return funds — and even sent the project fix details. Comedy/taunt meter is maxed. Whitehat claim is shaky. Reads more like buying time. mempool.space/tx/83825b2135d… 🧠 Impact ▪️ Hit: Liquid Network / Federation BTC reserve ▪️ Loss: 3,996.01834922 BTC (~$320M at the time) ▪️ Reserve left: ~197.4719 BTC. ~95% of the stack walked ▪️ Bitcoin L1: not exploited. Mainnet just executed a Federation-signed payout ▪️ SideSwap: used as the peg-out rail. Official word is PAK + systems were not breached ▪️ Other Liquid assets: USDT, DePix, RWAs were not weirdly minted, but the pause still froze transfers + liquidity ▪️ Recovery: principal still sits on the collection address. No CEX, no mixer, no bridge. Better recovery odds than a washed drain — until it’s actually returned, treat it as unrealized loss ▪️ Attacker label: self-claimed whitehat, unknown actor. Parking nine figures and then asking to talk is not standard responsible disclosure.
2
1
8
10,993
⚠️ Exploit breakdown: Sept 6: @Liquid_BTC got hit through an Elements consensus / asset-validation bug. Attacker minted ~4,000 unbacked L-BTC, then used SideSwap’s normal peg-out flow to cash out 3,996.01834922 BTC from the Liquid Federation reserve. They called it whitehat and said funds come back after every node is patched. Still sitting. No return. 📌 IOCs Attacker: mempool.space/address/bc1qgs… Collection wallet: mempool.space/address/bc1ql4… Hit reserve: mempool.space/address/bc1qdl… 🔍 How it played out 1. Phantom L-BTC Liquid block 4,050,336 (2026-09-06 21:53:10 CST) was accepted by Federation / Blockstream nodes. mempool.space’s independent Liquid node rejected it and stalled on the prior block. Clean consensus split. Suspect mint: blockstream.info/liquid/tx/c… 2. Peg-out via SideSwap 3,996.01834922 BTC paid to bc1qgsls...c6wt7p blockstream.info/liquid/tx/c… Blockstream later said the L-BTC came from an Elements bug. SideSwap PAK + infra were not compromised. nitter.net/side_swap/status/20967… 3. Federation pays on Bitcoin L1 mempool.space/tx/8db751a650a… 4. Funds swept mempool.space/tx/85d2ca15bea… 5. On-chain note OP_RETURN: “we are whitehats. contact us on chain.” Also told Liquid to patch first, then they’d return funds — and even sent the project fix details. Comedy/taunt meter is maxed. Whitehat claim is shaky. Reads more like buying time. mempool.space/tx/83825b2135d… 🧠 Impact ▪️ Hit: Liquid Network / Federation BTC reserve ▪️ Loss: 3,996.01834922 BTC (~$320M at the time) ▪️ Reserve left: ~197.4719 BTC. ~95% of the stack walked ▪️ Bitcoin L1: not exploited. Mainnet just executed a Federation-signed payout ▪️ SideSwap: used as the peg-out rail. Official word is PAK + systems were not breached ▪️ Other Liquid assets: USDT, DePix, RWAs were not weirdly minted, but the pause still froze transfers + liquidity ▪️ Recovery: principal still sits on the collection address. No CEX, no mixer, no bridge. Better recovery odds than a washed drain — until it’s actually returned, treat it as unrealized loss ▪️ Attacker label: self-claimed whitehat, unknown actor. Parking nine figures and then asking to talk is not standard responsible disclosure.
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message. What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others. Exchanges have been notified and have already paused (or will pause) LBTC deposits and withdrawals. Other Liquid assets such as USDT, DePix, and RWAs are unaffected by this security incident. Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. Effectively, the Liquid sidechain is paused until this issue is resolved. Liquid wallets will be impacted, and we're sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity. You can monitor the situation via @mempool's liquid.network site below: mempool.space/address/bc1qdl…
1
14
20,924
2/3 Once the long fCash matured, it settled into a DAI/USDC cash balance and walked out of Escrow. The matching short stayed as naked cash debt. No real ERC20 came back in to pay it down. That’s the extraction. etherscan.io/tx/0xc3f3e318f7…
1
1
1,251
1/3 ⚠️ Exploit breakdown: Sept 4, @NotionalFinance on Ethereum got hit. ~$1.72M drained from the escrow contracts. Attacker abused the fCash pair mint path in Notional V2: ERC1155Trade.safeTransferFrom → Portfolios.mintfCashPair() They spun up extreme cross-maturity long/short fCash across wallets they controlled. freeCollateral only checks solvency at the account level — it never stopped the attacker from isolating risk across accounts and maturities. Result: a massive near-term credit, a massive future hole. etherscan.io/tx/0xe1589a19fe…
6
1
41
10,065
3/4 The attacker ignored the offer entirely, instead posting several taunting messages onchain.
1
1
891
2/4 Fund recovery attempts & hacker taunts Just minutes before the chain halt, an onchain message was sent to the attacker offering a bounty for the return of funds: etherscan.io/tx/0xe2d56a8869… Unconfirmed whether Telegram handle @ckhbtc belongs to official team members.
1
1
1,468
1/4 ⚠️ Exploit Breakdown: #Injective binary options settlement bug On Sept 1, @Injective was exploited via a binary options settlement flaw and drained of ~$4.8M. The attacker bridged funds to Ethereum and swapped into$ETH:0x9137a6b20b083b07b84294d51ebc04a326787a2d Triple-bug combo. Chain halted. Patch shipped. 1. Unbounded market_id string concat → ID collision. An INJ-denominated insurance fund could share the same market_id as a USDC binary options market. github.com/InjectiveFoundati… github.com/InjectiveFoundati… 2. Self-trades minted a fake settlement deficit. Attacker-controlled subaccounts crossed Long/Short orders against themselves to fabricate a non-existent funding gap. github.com/InjectiveFoundati… github.com/InjectiveFoundati… 3. Decimal mismatch. INJ wei (18 decimals) was compared directly against USDC (6 decimals), causing remainingDeficit to round to zero. The haircut was completely bypassed, and positions were refunded at full face value. withdrawalAmount := absoluteDeficitAmount.Ceil().RoundInt() // USDC, 6 decimals if insuranceFund.Balance.LT(withdrawalAmount) { ... } // INJ base units, 18 decimals 4. Following the attack, Injective halted the chain and deployed a patch: github.com/InjectiveFoundati… validateInsuranceFundDenom now strictly enforces that the insurance fund’s DepositDenom matches the market’s QuoteDenom across PayDeficitFromInsuranceFund, TransferFullInsuranceFundBalance, and MoveCoinsIntoInsuranceFund—effectively plugging the exploit vector. This upgrade is a post-exploit fix. Not a coincidence.
2
2
41
23,523
Which Meme/DeFi project do you want audited for free? "You Nominate, We Audit" — weekly: Community nominates → DeepScan runs a free AI audit → results drop every Thursday on Space. Rewards: 🎁 10 random nominators get 10U each, every week 🎙️ Interact with our Thursday Space (tune in / repost / comment), 5 more people get 10U each How to join: comment below I nominate [Project Name] [Contract Address] #DeepScanAudit Only #BNBChain #Base #RobinhoodChain. Contract address required. If a nominated project has questions about the audit results, come join the Space.
164
141
191
18,616
cbZEC and cbHYPE have landed on @Base, verified and checked by #GoPlus . Our full‑suite Web3 security infrastructure powers token risk screening across the #Base ecosystem. Builders and users gain transparent risk intelligence before interacting with on‑chain assets.
cbZEC and cbHYPE are live on Base Now you can unlock liquidity and put your ZEC and HYPE to work across Base's DeFi ecosystem
1
6
14,430
🚨 GoPlus Security Alert Aug 31: #Solana Prop AMM aquiferdex[.]io just got exploited for ~$2.5M. Root cause:A logic flaw at the account/instruction level in the Aquifer program allowed the attacker to bypass settlement constraints and drain assets directly from the protocol's liquidity vaults. Attacker: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 Exploit Program: DMBpPMaMpGM2mWiUMaqcHx9FwhPg9Ys7qg1X59NRgb68 Victim Program: AQU1FRd7papthgdrwPTTq5JacJh8YtwEXaBfKU3bTz45 Drained Vaults: $USDC: GtwzYxBQcPFNFQcYbdELuaKzb4DGJpGVU2ehLhzbffCw $USDT: 7C7Y3fyPYeAYqpc29uahDUQ84PQ255Avj2YEP9KpvyKx solana:EUgEFNdBB2MPf64RuQqupZ7iWk9BUZZTKFkMNThgpump: AwtZZUJsRGLje9c5wE9q7zMNjA9ZkEuxTk8awBza14kr WETH: DKCGgPdyLcPFJGTZzkhYeenEUWXPu5VED5ourTrW8PAM solana:2zMMhcVQEXDtdE6vsFS7S7D5oUodfJHE8vd1gnBouauv: 2wz6vj1T4RPy7H1mgLgYJEeodgLktP7D2oFpxzbtPxyz solana:JUPyiwrYJFskUPiHa7hkeR8VUtAeFoSYbKedZNsDvCN: 9zsMX2AWGqF8Ap2Kwv46nTPsLyuX8XAv4yeyQ2CfUbTP solana:6p6xgHyF7AeE6TZkSmFsko444wqoP15icUSqi2jfGiPN: 2gveWAEyCGKe5NBvwmk7LM2EjW9gMAtjj6Kfg3PJewgN solana:9BB6NFEcjBCtnNLFko2FqVQBq8HHM13kCyYcdQbgpump: FeGa8LDVeeRpHCqofgFqz6zZvpwrL4jcPJTX73BvbGij Sample Exploit Txs: solscan.io/tx/3e49j85iRkULxS… solscan.io/tx/or8xzebiePZxah…
3
4
26
15,651
Same trap, new victim. Revoke old / unused allowances on a schedule❗️ 🚨 A user signed a malicious Permit 779 days ago and got drained for ~100k USDC. Never revoked it. Phisher came back and hit them again — another ~$62k USDC gone. Victim: 0xdFC1497EF2Ca6D884EC90d2fC4FB816a5ea735f2 Phish wallets: 0x0000db5c8B030ae20308ac975898E09741e70000 0xfd9d1975C68bDA1B454Ef3451C4b59e41d9cB5E1 0x7FBd9d1714E17787d80F925219213bF312275bb0 Related tx: etherscan.io/tx/0x430f4949d3…
🚨 GoPlus Security Alert A user signed a malicious #Permit tx 922 days ago, then got drained for ~97k $SYN. Never revoked the allowance. Phisher came back and hit them again — another ~$122k in $SYN gone. Victim: 0x686618aBb3730079601a5abEAD6eC24549c5Ce34 Phish wallets: 0x0000db5c8B030ae20308ac975898E09741e70000 0x9EC9ca0c7846E8726D5d734EFd291f855ea03447 🛡 Security Tips: 1. Follow the #GoPlus Anti-Phishing “4 Don’ts”: 🚫 Don’t click unknown links 🚫 Don’t install unverified software 🚫 Don’t sign transactions you don’t fully understand 🚫 Don’t send funds to unverified addresses 2. Install the GoPlus Security extension to block phishing links, risky signatures, malicious approvals, and suspicious transactions in real time 👉 chromewebstore.google.com/se… 3. Approve only what you need. Never infinite allowance. Revoke stale approvals on a schedule.
4
4
37
12,708
🚨 GoPlus Security Alert A user signed a malicious #Permit tx 922 days ago, then got drained for ~97k $SYN. Never revoked the allowance. Phisher came back and hit them again — another ~$122k in $SYN gone. Victim: 0x686618aBb3730079601a5abEAD6eC24549c5Ce34 Phish wallets: 0x0000db5c8B030ae20308ac975898E09741e70000 0x9EC9ca0c7846E8726D5d734EFd291f855ea03447 🛡 Security Tips: 1. Follow the #GoPlus Anti-Phishing “4 Don’ts”: 🚫 Don’t click unknown links 🚫 Don’t install unverified software 🚫 Don’t sign transactions you don’t fully understand 🚫 Don’t send funds to unverified addresses 2. Install the GoPlus Security extension to block phishing links, risky signatures, malicious approvals, and suspicious transactions in real time 👉 chromewebstore.google.com/se… 3. Approve only what you need. Never infinite allowance. Revoke stale approvals on a schedule.
1
3
17
21,580
🚨 GoPlus Security Alert: @TectonicFi just got hit with a price-manipulation + over-borrow attack on @CronosNetwork. ~$75M gone. ~$6M already bridged to Ethereum and swapped into ~2,600 ETH. Cronos is halted so the rest can’t keep moving. tectonic:native is getting wrecked. Playbook: thin-liq tectonic:native. Loop collateral and borrows, pump the mark in minutes, then size up. At a ~20% collateral factor, that bag printed ~$375M in collateral value and ~$75M in borrow power. Then they vacuumed USDT and other assets. Attacker: 0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652 Attack contracts: 0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3 0x2dc6a36f4e5eeefe112c01569de96dea496bb618 Cronos aggregation wallets: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc ETH profit wallet: etherscan.io/address/0xc4041… Example attack txs: explorer.cronos.com/tx/0x0fc… explorer.cronos.com/tx/0xddc… etherscan.io/tx/0xf1b9a3e6ac…
4
7
32
10,349
🚨 GoPlus Security Alert: A fraud ring seized realtrumpcoins[.]com and the @realtrumpcoins1 account, then maliciously launched $GOLD(EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS). They pumped mcap to $60M, dumped, and rugged — profit $8.2M+. Dev seed money traces to #KuCoin. 15 operator wallets were seeded from #Binance. Same crew also deployed $PLATINUM, a malicious token that can drain any holder’s balance. On-chain trail: Token mint: EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS Dev wallet: 3pQA1ZCaAuFgVJPmkxUGhBaDQjRpt88CXaXmoVy3fRsr Operator wallet: 3odTMNgv5ViWXYoiZCwXuMbk8FTdJkpwvEHJfosuATos Dev funder (KuCoin-linked hot wallet): BmFdpraQhkiDQE6SnfG5omcA1VwzqfXrwtNYBwWTymy6 Dev funding tx: solscan.io/tx/39D3QXZinyYJvb… Funder of the 15 insider wallets (Binance-linked hot wallet): 5tzFkiKscXHK5ZXCGbXZxdw7gTjjD1mBwuoFbhUvuAi9 Insider funding tx example: solscan.io/tx/3Npt9doDJs2EFF… Malicious routing contract: FLASHX8DrLbgeR8FcfNV1F5krxYcYMUdBkrP1EPBtxB9 (all 15 insider wallets traded through it) They also deployed another malicious meme — Trump Digital Platinum ($PLATINUM): AuzcYsvKsYs1DFkQVzpm6tLzWb2fFSfZGxLHyubWY4jM Do not buy. The contract can sweep any holder’s full balance at will. Token security check 👉 console.gopluslabs.io/token-…
3
4
30
10,581
⚠️ Exploit Breakdown: Aug 28: the card-balance collateral program behind #Solana crypto neobank @avici took a sustained hit. Avici says 1,685 users were affected, ~$500K drained. Full refunds promised. Attacker abused a signature-verification / auth-logic bug in Rain’s legacy Solana card contract, then ran the same 3-step loop across a pile of user collateral accounts: (1) Submit a crafted signature bundle — SubmitSignatures (2) Register themselves as admin — AddCollateralAdmin (3) Pull the collateral — WithdrawCollateralAsset Stolen USDC/USDT was periodically swapped to SOL and moved out. One tx: solscan.io/tx/2KSnVfVHbiJVWx… Root cause is not a stolen upgrade key, and not a Solana L1 bug. The program mis-parsed / mis-bound the Ed25519 verify result, so the attacker’s own signature could pass as a legit admin authorization. Attacker: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj Hit program: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a Example attack tx: solscan.io/tx/4X1QZUFx4xAUbN… solscan.io/tx/7Z6LHshn1pGw2C… solscan.io/tx/4X1QZUFx4xAUbN… solscan.io/tx/2KSnVfVHbiJVWx…
UPDATE: All affected card balances will be refunded in full Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed. Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control. When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected. Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected. Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances. Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely. Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.
5
3
29
12,352
⚠️Oracle Manipulation Analysis: Aug 27: @MoonwellDeFi ’s $MAMO collateral oracle got manipulated. ~$8M drained. Attacker extracted real liquidity from the $mcbBTC market. Root cause: thin-liq $MAMO was listed as Moonwell collateral. Attacker pumped the oracle print from ~$0.0105 to ~$0.088 — about 8x — so the mMAMO position’s book value went wildly oversized. Then they looped borrows of real cbBTC out of Moonwell’s cbBTC Core Market (mcbBTC). basescan.org/tx/0xafb6f0fa25… Attacker: 0x719eae70d4A83f35bF82A2740699F5db84BE919D Attack contract: 0xAbDA3Cfe3ce2668b7829AAccBE594Abb326BCe4F Hit contracts: 0xF877ACaFA28c19b96727966690b2f44d35aD5976 (mcbBTC) 0xEdc817A28E8B93B03976FBd4a3dDBc9f7D176c22 (mUSDC) 0x627Fe393Bc6EdDA28e99AE648fD6fF362514304b (mwstETH) Example attack txs: basescan.org/tx/0xafb6f0fa25… basescan.org/tx/0xee2b75648c… basescan.org/tx/0x2d1c356e8e…
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged. We will share another update as soon as we have more information.
5
2
27
9,769
6/7 Chains potentially exposed to the same class of risk (partial list — every cosmos/evm project should self-check immediately):
1
2
632
4/7 Fixed version:
1
1
1
433
3/7 Root Cause Full attack chain: Inject vesting identity → Delegate to trigger underflow → Fake balance becomes real funds. StateDB.SubBalance had no underflow protection. Balance subtraction on the EVM state object was pure uint256 math. Insufficient balance? No revert. Just wraps around to ~2²⁵⁶.
1
1
5
736
⚠️Exploit Breakdown: Cosmos EVM exploits hit in rapid succession, draining $17M+ Between Aug 20–23, a cluster of bugs involving the staking precompile + vesting accounts in cosmos/evm got weaponized. Three chains fell in three days: MANTRA, TAC, and KiiChain. Nominal losses >$17M. (Note: This is not the same as ASA-2026-002 from Jan 2026 — the ICS20 nested execution issue that cost Saga EVM ~$7M. Different code paths, different exploit methods, different patches. Some media mixed them up. Bad analysis.) Full breakdown in the thread 🧵
10
10
66
13,015
4/5 Six days later on execution, the same executeProposal zeroed Zodiac Delay’s cooldown/expiration → instantly add_strategy + update_debt → vacuumed the vault’s WETH straight into a pre-deployed malicious strategy → out to the attacker. etherscan.io/tx/0xd354a15b15…
2
4
700
3/5 Next move: self-submitted + self-voted proposalId=5 etherscan.io/tx/0x284fc544f3… etherscan.io/tx/0x6e73533304…
1
3
747
2/5 Then dumped that 0.485 tmvETH into the Yearn/Governance wrapper and minted 0.485 gtmvETH — instant voting power unlocked. etherscan.io/tx/0x7876693645…
2
5
1,291
1/ 5 ⚠️Exploit Breakdown: The Term Labs governance attack Aug 23, @term_labs got absolutely rekt in a gov attack — ~$8.5M drained. Root cause? Voting power was paper-thin. Attacker bought absolute control with just 0.5 ETH. Here’s how it went down: Attacker swapped ~0.5 ETH → 0.485 tmvETH etherscan.io/tx/0x724e377f05…
4
3
40
13,440
🚨 GoPlus Security Alert Aug 21, 23:42 UTC — attackers hijacked the delegate permissions on @TheSandboxGame’s SAND OFT (LayerZero Omnichain Fungible Token) contract on Base. They forged cross-chain messages and started infinitely minting unbacked $SAND. The exploit ran for hours. Trillions of tokens got printed. Liquidity + reserve limits kept the damage to ~$670k. Attacker-linked wallets: 0x67624bfadee937c9281b4f98ce18af1bee01257e 0x07bc449e85d9b66899425df8c8ab49cfb44a5f1e 0xAbE09907D2038181FC5Fb0ff0c961C147CdA4D22 0x638Ccb18370eE228378a565c1d4D0F9620d7F296 0x53eda2e80E46B804C5a47260cE04642e82d004cA 0xac76b04397c9296dfc00e25c96d8e51b4edfaf29 Compromised contract: 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF Example attack tx: basescan.org/tx/0xbddb102a5d… 🛡️ GoPlus Security Notes 1️⃣ Projects: Strip or hard-disable any generic approveAndCall / paidCall style arbitrary-call functions on OFTs. At minimum, block calls to LayerZero Endpoint, MessageLib, and other privileged contracts. Set the delegate to a multisig + Timelock. Actively monitor DelegateChanged, ConfigSet, PeerSet events. Audits must specifically test the cross-contract combo risk: “ERC20 extension functions × Endpoint relying on msg.sender auth.” Auditing them in isolation isn’t enough. 2️⃣Users: Do not trade $SAND on Base or BSC — both chains’ liquidity is already polluted. If you provided SAND liquidity on Base/BSC, sit tight for the official snapshot + compensation plan. Watch for fake support / phishing links in replies and socials. Stay sharp.
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply. SAND tokens on Ethereum and Polygon are NOT affected. No user wallets were compromised, and no action is required from holders and liquidity pool (LP) providers on those networks. The SAND locked on Ethereum, which backs all bridged SAND, is fully intact. An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed. ⚠️ Do not buy, sell, or trade SAND on Base or BSC. Liquidity on those networks is compromised. We are taking a pre-incident snapshot and preparing a compensation plan for the qualified users of the impacted LPs. Affected users can reach out to official support via contact@sandbox.game. We continue to monitor the situation and are actively investigating its scope, and we will share a full incident report and detailed technical post-mortem soon. We apologize for the inconvenience this has caused and deeply appreciate the continued patience and support of The Sandbox community. ⚠️ Reminder: Our team will NEVER DM you first. Please beware of scam links in the replies.
5
8
57
14,228
All 18 skills in the Skill Hub on @binance #AgentOS have been fully listed by @SafuSkill. → None of the 18 skills were found to have high-risk issues. → Average security score: 97.4/100, with 15 skills at a perfect 100 Skills that could use further security hardening: → #p2p: one high-severity data upload request pattern → #binance-wallet-tracker: three low-severity Unicode confusable characters → #fiat: one info-level advisory Always run a security check before installing a skill: Is the source official? Does it contain malicious behavior? What high-privilege actions does it perform? Go Agentic. Stay Safu!
Meet Agent OS - a new way to build, deploy and use AI agents on Binance. Bring Binance market intelligence, payment, on-chain, data and trading capabilities directly into your AI workflow. Build. Analyze. Trade. With AI. 🫡 Experience it ↠ binance.com/agent-os
5
1
14
5,666
🚀 The GoPlus Web3 Security Agent is now live on CreaoAI Discover @CreaoAI . Powered by GoPlus Security MCP, it analyzes Token Security, NFT Security, Malicious Address, Malicious Approvals, and Phishing sites—then presents the risk signals in a visual dashboard. Watch the demo to see a token contract scan in action: agent.creao.ai/discover If prompted for credentials, create an API Key / Secret at console.gopluslabs.io/
3
2
13
5,728