Web3 Security Firm - Defending against Hacks & Scams on #BSC & More! 🛡️ Users stay safe with our Chrome Extension & Metamask Snaps! ⚙️ Links below 👇

BREAKING: Introducing our latest "HashDit Pro" Chrome Extension🎉🥳 The latest Extension will offer : 🔹 Powered up Threat Protection (stay SECURED against address poisoning / drainer + any other phishing attacks) 🔹 Smart Contract Simulation (preview balance changes and approval changes) 🔹 Supporting 7 popular wallets + all EVM chains 🔹 Website checker (Clear pop-up warning when visiting malicious websites) 🤔 What you should do if you are using the old Extension? Remove the old Extension and install our latest Extension for continuous improved protection! Download here NOW for FREE: chromewebstore.google.com/de… Stay safe with HashDit Pro! 🛡️
53
13
68
71,574
🚨 HashDit Alert! 🚨 As if Mid-Autumn Festival wasn’t eventful enough, following Bitget, payy_link, and Duelbits, another exploit has surfaced... We detected an exploit involving $YUNA on #BNBChain, resulting in an estimated $1.2M drain. The issue stemmed from the Pool contract’s claim() function, where staking rewards were priced using the YUNA/USDT pool. By manipulating the pool price, the attacker was able to claim significantly more YUNA than intended, then unwind the position for a large USDT profit. The stolen funds have since been bridged to Ethereum and remain in the attacker’s wallet. Detected by our Internal HashDit AI Triage Monitor. Stay safe!
1
542
🚨 HashDit Alert! 🚨 @bitget has been reported to be hacked for ~$351.6M! Withdrawals are temporarily paused and the platform has stated that users will be covered by their User Protection Fund. HashDit is following the incident closely. Stay Safe!
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
1
1
645
🚨 HashDit Alert! 🚨 Trezor's third-party e-mail provider has been compromised! Please be extra wary for any phishing emails even coming from the official trezor[.]io domain. Stay Safe!
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
1
2
826
Builders on @BNBCHAIN can now book HashDit's security services through the AvengerDAO marketplace. HashDit provides Security APIs, Web2/Web3 audits, monitoring, and incident handling to help teams catch vulnerabilities before launch, scan risky addresses/tokens/websites in real time, and respond faster when threats appear. Find us on the AvengerDAO marketplace 👇 avengerdao.org/marketplace
4
6,522
HashDit | now with Pro Extension retweeted
Shipping on BNB Chain? Security support just got easier to find. The AvengerDAO marketplace brings together 11 security teams covering audits, threat monitoring, risk scanning and incident response: @HashDit @CertiK @zokyo_io @salus_sec @Beosin_com @GoPlusSecurity @BlockSecTeam @pessimistic_io @sherlockdefi @getfailsafe @FirepanHQ Explore the marketplace: avengerdao.org/marketplace Learn how the AvengerDAO marketplace works in our blog 👇 bnbchain.org/en/blog/avenger…
34
24
152
52,323
HashDit | now with Pro Extension retweeted
Defimon detected a malicious governance proposal that attempts to drain @autonolas Treasury - $100K at risk Tornado-funded attacker registered ENS name "autonolas-deployer.eth" and submitted a proposal titled "Owner migration: transfer treasury ownership from old timelock to Safe updater". In fact proposal execution would move Treasury ownership away from the legit Autonolas Timelock to the attacker contract, who could then rebalance and withdraw all 40.196 ETH. There is 3 days to defeat the proposal. We have shared the alert in the community chat of the @autonolas project. TX: etherscan.io/tx/0xe435eed3f2… Attacker: etherscan.io/address/0xd4f8d… Victim: etherscan.io/address/0xa0da5…
4
4
41
5,704
HashDit | now with Pro Extension retweeted
An ongoing security incident has impacted users of the Cosmos EVM module. Cosmos Labs’ security and engineering teams have been proactively responding to this incident. We have advised the Cosmos EVM chains that are in contact with us to request that validators halt their chains. We thank the teams using Cosmos EVM for their rapid response. An incident report will be shared once the situation is resolved. If you are a team using Cosmos EVM and have questions, please contact security@cosmoslabs.io.
54
86
412
407,206
HashDit | now with Pro Extension retweeted
‼️ Rust supply chain attack hits three crates, including 245 million-download arrayref. A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation. Check your Cargo cache and pinned versions now: thehackernews.com/2026/08/ru…
6
56
189
59,451
HashDit | now with Pro Extension retweeted
🚨Every Ledger running the Ethereum app is vulnerable to signature substitution A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original Here's what you need to know:
38
85
343
323,205
Joining the alliance to help keep BNB Chain’s protocols and users safe 🛡️ Proud to be part of the next chapter of AvengerDAO and contribute to a more secure BNB Chain ecosystem 🤝
Every builder should have a clear path to strong security. AvengerDAO now brings 11 security firms, an official BNB Chain standard, and bug bounty support for builders, from development through launch and beyond. The goal is to raise the baseline for every project launching on BNB Chain 🧵👇
3
9
2,068
Stay wary! Official @BNBCHAIN members will never promote random CAs or platforms, and will never contact you directly.
seems like there was someone that impersonated me and made a github and launched a meme ai agent on BNB i did not do this fyi and do not endorse this.
3
1,266
🚨 HashDit Alert! 🚨 Another npm supply-chain attack! keyv (~154M weekly downloads) + related cacheable packages were compromised. Malicious versions contain a preinstall hook that: • Downloads & runs a Bun-based payload • Steals cloud/CI/GitHub/npm/Vault tokens • Self-propagates by publishing trojanized packages • Plants hooks in .claude & .vscode What should you do: → Check your lockfiles NOW → Avoid latest versions → Rotate tokens if you installed recently → Look for .claude and .vscode repo hooks Stay safe!
🔥 ALERT - A massive npm supply-chain attack is unfolding right now. It began with a poisoned Keyv release and spread across hundreds of packages. The worm: → Credential stealer via install scripts → npm, GitHub, cloud and CI secrets targeted → Claude Code and VS Code hooks in Keyv repo → Valid OIDC and SLSA provenance Read the full story: thehackernews.com/2026/08/ke…
1
1,440
🚨 HashDit Alert! 🚨 By now, many may have seen reports about @42dao_official being compromised. But 3 hours earlier, the same threat actor had already compromised 29 users on another platform, and there have been so reports yet! The threat actor drained $300k worth of $USDT and $BNB from an unknown exchange contract on BSC by abusing EIP-7702 account delegations. Attacker: 0x7b2e2dE172fd24c9158f6ECB77c05943CE47399D Victim Platform: 0x1Dd2235091c82862BCC7E9c25017ba9C409c0820 Detected by our Internal HashDit AI Triage Monitor. Stay safe!
🚨@42dao_official exploited for ~$912K. The attacker exploited an abnormal BTCB oracle price update, allowing multiple BTCB vault liquidations in a single transaction. Root cause: → Missing oracle price deviation checks → No liquidation delay or minimum price protection Attacker: 0x9d8dd9f2d734675e2bfcc142d1c7a45609ca213c
4
17
3,179
🚨 HashDit Alert! 🚨 We have monitored that VES Finance has been compromised and drained for roughly $109k worth of funds. The VECAndETH exposed a getReward() function. Internally, earned() -> calculateUSDTToETH(), which relied on PancakeRouter.getAmountsOut using a PancakeSwap liquidity pair price that had been manipulated via a flash-loan swap. As a result, the attacker’s legitimate reward of 17.14 USDT was mispriced as a payout worth 76.11 BNB, whereas the fair value should have been only about 0.0096 ETH. In total, the contract paid 68.50 ETH to the attacker, with the remainder taken as fees. Funds have been deposited into Tornado Cash. Detected by our Internal HashDit AI Triage Monitor. Stay safe!
2
5
26
4,321
🚨 HashDit Alert! 🚨 We have monitored that @corezcat as well as @GameStopfun have also rugged their community, in similar fashion, for a total of $93k worth of funds. Both Token Contracts likewise override the standard ERC-20 balanceOf() to delegate entirely to an external contract "EIP712" and "_cachedThis" which allowed the hacker to arbitrarily change the balances of the Pool + Hack Contract. Funds are still in the hackers' wallets. Detected by our Internal HashDit AI Triage Monitor. Stay safe!
🚨 HashDit Alert! 🚨 We have monitored that @xpepetrump project has rugged and drained $38.5k worth of funds from the LP.. Root cause: PEPEToken contract (0xc81688968Bd1E8Da313B8F2936852eC4307Cd17f) overrides the standard ERC-20 balanceOf() to delegate entirely to an external contract LockupContractFactory whose unverified code allowed the attacker to set arbitrary nonce values for the PancakePair address via function selector 0x801425e6. Before the hack, the LockupContractFactory logic contract was maliciously upgraded and changed to include the rug function selector. Funds are still in the hacker's wallet. Detected by our Internal HashDit AI Triage Monitor. Stay safe!
2
4
27
5,065
Projects that are using @chainlink Functions or Automations should take note!
Chainlink functions officially deprecated yesterday. Moving over to CRE for future usecases. Automation scheduled for 30 July deprecation too
5
1,262
Both Tokens were also previously flagged as High Risk prior to the incident. hashdit.io/token-scanner/bsc… hashdit.io/token-scanner/bsc…
407
🚨 HashDit Alert! 🚨 We have monitored that @xpepetrump project has rugged and drained $38.5k worth of funds from the LP.. Root cause: PEPEToken contract (0xc81688968Bd1E8Da313B8F2936852eC4307Cd17f) overrides the standard ERC-20 balanceOf() to delegate entirely to an external contract LockupContractFactory whose unverified code allowed the attacker to set arbitrary nonce values for the PancakePair address via function selector 0x801425e6. Before the hack, the LockupContractFactory logic contract was maliciously upgraded and changed to include the rug function selector. Funds are still in the hacker's wallet. Detected by our Internal HashDit AI Triage Monitor. Stay safe!
1
6
22
8,375
We have previously flagged this token as High Risk on our Token Scanner - hashdit.io/token-scanner/bsc…
523