Filter
Exclude
Time range
-
Minimum likes
Replying to @larry0x
any other distro? not really. openSUSE using Tumbleweed/Leap with btrfs Fedora with btrfs Ubuntu with Btrfs CachyOS/Garuda with snapper + btrfs ...all have snapshot and rollback. used it many times, works fine.
1
80
the more important question is: If the staff who are paid (staking rewards) to secure your bank hand over other customers' account access to someone just because they deposited $20K, who's at fault? Bigger question: do you keep employing that staff? Validators be socializing Ls
2
17
Si el personal, al que se le paga (con recompensas de staking) por proteger tu banco, entrega las llaves de las cuentas de otros clientes a alguien solo porque depositó $20K, ¿quién tiene la culpa? La pregunta más importante: ¿sigues empleando a ese personal?
1
1
28
Ray Raspberry retweeted
Neutron / Astroport exploit: what happened when the Cosmos Hub restarted. The 1.2M cosmos:native sweep worked. The 168,990 ATOM THORChain refund didn't get caught. It landed on the attacker a minute after the restart, and he sold all of it for about 100 ETH. Correction first In my last post I said the refund couldn't move once it landed, because the Hub had blocked the attacker's address. That turned out to be wrong, it appears the developers of the hub failed to correctly block the attackers address, when they had a ~6 hour window to act. What worked The Hub restarted at 10:06 pm AEST on v28.3.0. In the first block (33,086,741), the upgrade moved 1,227,121.37 ATOM off the attacker's address to cosmos1z8pq5cn7tdrwwzlwm0e44fgq07e43ner6vph64. It's still there, untouched. That's about $2.2M kept from him. What didn't 10:07:38 pm, block 33,086,748. THORChain's vault sent the refund, 168,990.898794 ATOM, to the attacker's address. 10:09:29 pm, block 33,086,761. He signed a 500,000 ATOM IBC transfer to Osmosis. It was included in a block, he paid the fee, and his account sequence went from 8 to 9. It failed only because he asked for more than he had. That transaction should never have reached a block if the address block was working. 3:54:58 am, block 33,090,325. He tried again with the right amount. It went through. Where it went He sold it on Osmosis in chunks of about 20,000 ATOM between 3:58 and 4:48 am, for 266,841 USDC, an average of $1.58. 188,832 USDC went through Noble and Circle's CCTP to 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c and was swapped to $ETH within minutes. +70.84 ETH. 50,000 ATOM went to a new key first. 30,000 of it made a round trip Osmosis → Hub → Terra → Hub → Osmosis. He then sold it and sent 78,010 USDC through Axelar to a new wallet, 0x9bfcca13b4ac907433ac68766e96309ac867f819. 29.22 ETH, never sent. 53 minutes from the Hub to ETH. Root cause: two gaps The refund arrived after the sweep. The upgrade moved what was on the address at block 33,086,741. The refund came seven blocks later. THORChain had GAIA halted (HALTGAIACHAIN = 1), but signing for GAIA was never halted (HALTSIGNINGGAIA = 0). My reading is that the halt stops THORChain watching the Hub, not signing for it. The vault's refund went out as soon as the Hub produced blocks. THORNode still shows the refund as "not signed" because it can't see the Hub. The ante-handler block didn't reject him. A transaction the ante-handler rejects never reaches execution. His reached the bank module and paid a fee. I can't see the v28.3.0 code (only v28.0.0 is public), so I can't say why. The chain shows it wasn't enforced for his address on an IBC transfer. Both gaps were visible on-chain by 10:09 pm. The refund sat on his address for 5 hours 47 minutes before he moved it. Where the attacker's funds are now 0xEF6c5A31df984c8569236a0AbC1f27580E2a5D54: 671.0 ETH 0xe149310eB8b1b3D9C471CcD81819D393621fBA5c: 94.43 ETH 0x9bfcca13b4ac907433ac68766e96309ac867f819: 29.22 ETH New Cosmos-side addresses from last night: osmo1erq7tre6nk0jfx203z8ey75g4m7yfrckl3qx87 cosmos1erq7tre6nk0jfx203z8ey75g4m7yfrckh2nk3v terra1utez3t0nvg34d9xfswn8058kypney2c3pkx883 Worth taking from this A sweep in an upgrade handler only covers what's on the address at that block. Anything still in flight needs its own plan. Test an address block with a real transaction as well as a simulated one, and watch the account sequence right after restart. Halting a chain in THORChain doesn't stop outbound signing for that chain. @cosmoshub @THORChain @Osmosis_Zone @Neutron_org @astroport_fi
8
7
53
5,602
Ray Raspberry retweeted
Neutron / Astroport exploit, update. The attacker's 1,227,121 ATOM on the Cosmos Hub is being moved to a new multisig when the chain restarts. One more piece still needs dealing with after restart: a 168,990 ATOM refund on its way back to him. What's already on his address When the Hub halted at block 33,086,740, the attacker's address held 1,227,121.37 cosmos:native (~$2.22M). The new Hub binary does two things. The upgrade handler moves that balance to a new multisig, and the ante-handler blocks his address from signing anything. The refund nobody could see His last THORChain swap was 200,000 ATOM streamed into $ETH. Only 15.5% had filled when the Hub stopped. THORChain paid that part out as 19.92 ETH and closed the swap. The other 168,990.898794 ATOM is queued as a refund to his Hub address. His wallet shows nothing pending, and the swap looks finished once the ETH arrives. I found the refund by reading THORChain's outbound queue (thorchain-thornode-lb-1.thor…) directly and matching it on the swap's inbound hash: REFUND:02DABD55C0A3EBEA3271763484542CB59A22E968402F91690471B7D2589B04A7 168,990.898794 ATOM → cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n It's scheduled but not signed, and was still in the queue at 23:43 UTC on 22 Sep. It hasn't gone out because THORChain has GAIA halted (HALTGAIACHAIN = 1). When that lifts, the vault signs and the ATOM lands on the attacker's address. That will be after the Hub upgrade has already run, so the refund misses the multisig move. Can he get around the block? Before the restart I checked whether he has any other way to move funds from that address. He doesn't. It's a plain account with one key. No authz grants in either direction, no fee grants, no delegations, unbonding or rewards, not a validator, no contracts, gov deposits or IBC transfers. If that key can't sign, nothing moves. That's why the ante-handler block works here. What still needs doing after restart The 168,990 ATOM (~$306k) needs one of two things: a second sweep once it lands, or THORChain node operators holding or redirecting that outbound before they unhalt GAIA. The block stops him moving it. It still needs to be moved to the multisig. Totals at $1.81 ATOM 1,227,121.37 ATOM on the address → multisig at upgrade 168,990.90 ATOM refund → needs a sweep after restart 1,396,112.27 ATOM, about $2.53M, kept from the attacker.
8
15
91
15,653
the last one. 50D41B97A698B62E02A1FE1E1260C758D75E1E82FCB9735BBD5BBC6381400B9E
215
It wasn't an exploit. @neutron_org Validators passed the prop. Two likely situations are: Validators understood the proposal (handing over admin control of contracts) and were indifferent or didn't read the substance of the proposal to begin with. Either way is negligence.
The Cosmos Hub validators have temporarily halted the network to mitigate ATOM losses from a governance exploit on @neutron_org. The Hub itself is not affected. The community is identifying and isolating wallets with impacted funds and will decide what to do with them before resuming operations. Please stay tuned for further updates.
6
2
32
3,322
Replying to @Reecepbcups_
Did you pay your $100 submission fee and file it with @immunefi ?
Man I was forwarded to Immunefi to pay $100 just to submit my report on that sieve. I ain't droppin' a 100 bucks for the privilege of helping them fix the Module. Now think about about how many times someone else has shown up at the door to report on a problem just to be told that'll be a 100 bucks to come in. No one can seriously believe that I'm the first to come knocking.
1
13
1,770
what is the value proposition to encourage someone to bridge assets into an ecosystem who's biggest headline of 2026 has been a string of 6 and 7 figure exploits?
3
26
Replying to @AirdropGlideApp
Is there a doctor in the ecosystem?
2
213
Make of it what you will when @cosmos and @cosmoslabs_io blocks a forensic investigator prior to posting about their security advisories regarding the latest round of exploits. I guess they didn't like being asked about partnering with that @0xZeeve self-proclaimed "doctor"
3
1
62
2,619
Replying to @TacBuild
Investigation complete.
.@TacBuild halted after an exploit. I traced it on-chain, it's the same bug that hit MANTRA two days earlier, and someone has turned it into a reusable tool. The attacker drained the bonded_tokens_pool. The escrow holding every staked $TAC on the chain. 2,985,651,403.40 TAC, 28.6% of supply, gone in one transaction. Then bridged it to BNB Chain via LayerZero in 95 seconds. The chain halted 4h11m later. Far too late. The mechanism: a MsgCreateVestingAccount sending 1 utac to the attacker's own contract, used exactly once in the chain's entire history, seven seconds before the theft, then a one-wei delegation through the staking precompile. MANTRA's version had the victim baked in as an immutable; TAC's takes victim and beneficiary as calldata parameters. Supply never moved. The mint sits two wei below the burn. Across the 4,976 blocks before the halt, checked in exact integer wei, every transaction has mint == burn. What's broken isn't supply, it's staking: validator records claim 2,985,651,403 TAC and the pool holds zero. 100% shortfall. 1,662,322,352 TAC is sitting on BNB Chain right now, 68.7% of BSC-side supply, in the attacker's wallet, dormant ~25h. The halt cannot reach it. Verify it yourself: Theft tx → explorer.tac.build/tx/0xae4e… Bridge 1 (500M) → explorer.tac.build/tx/0xa058… Bridge 2 (2.486B) → explorer.tac.build/tx/0xce24… Attacker on TAC → explorer.tac.build/address/0… Same address on BSC → bscscan.com/address/0xecb0af… Third chain in this family: Oraichain (9 Aug), MANTRA (20 Aug), TAC (22 Aug). Any chain on cosmos/evm with x/auth/vesting enabled and the staking precompile active should check today.
2
451
Replying to @Fyveonit
when that wells fargo chain going live?

ALT Animated GIF

2
55
Future of RWA right here.
4
141
Replying to @AirdropGlideApp
the purchase seems like some blend of busy work and golden parachutes for exit
4
354