Automated smart-contract auditing platform by @credshields

🚀 Big news! SolidityScan is now integrated with @soneium, bringing seamless smart contract security to your fingertips. Easily access security scores, gain real-time insights into vulnerabilities, and explore full threat reports — directly from verified contracts on Soneium.
19
13
441
12,069
✅ Audit Complete. We've successfully completed a smart contract audit on @DustLabsX. Dust rounds up onchain swaps and automatically invests the difference into a basket of tokenized blue chip stocks. Website: roundupdust.com
Audit complete, fixes verified. Dust v0.6.4 is live. The Dust contracts were audited by @CredShields , one of the most respected security firms in the space, with a long list of protocols behind them. Twelve findings, zero critical. We fixed every one, redeployed on new contracts, and @CredShields re reviewed and marked each fix confirmed. Withdrawals were never affected at any point. The full report is public, findings and fixes side by side: github.com/Credshields/audit… This is exactly what an audit is for. You don't bring in a second set of eyes to be told everything's perfect. You do it to find what you missed while it's still cheap to fix, fix it, and prove it. Every fix in this release ships with a test that replays the auditor's exact scenario. What it means for you: the contracts running your round-ups have been reviewed twice by a team whose job is breaking things, every keeper action is bounded on-chain, and your money can only move into your own vault or back to your wallet. Not a promise, that's what the code allows. New in v0.6.4: the audited contracts, a "Stop sweeps" switch, refunds shown on any partially filled purchase, and a cleaner funding screen. Used Dust before this week? Open app.roundupdust.com, connect, and the card at the top shows your balance on the old contracts. Withdraw in two clicks, then set your basket and cap again. The old contracts stay withdrawable forever, so no rush. Thanks to the @CredShields team for a thorough job and a fast retest.
9
9
26
1,146
Osmosis says an exploit on Nomic enabled a double-spend of nBTC and “false vouchers” sent to Osmosis. Flows for Nomic + Alloyed BTC were frozen; validators report 22.65 BTC frozen in the attacker address. #DeFi #Security
1
3
249
Amnext (AMC) on BNB Chain was reportedly exploited, with attacker mass-minting “Ticket AMC” and draining ~154.02 WBNB (~$116.1K) via PancakeSwap. #DeFi #exploit
4
294
SlowMist reports a BNB Chain DEX router exploit (~62.28 BNB) where an unauthenticated Uniswap V3 callback let an attacker abuse existing token approvals to drain user allowances. #DeFi #Security
4
1
332
SlowMist TI Alert: WealthManagementV2 reported a 26,414 USDT loss after suspected owner-privilege takeover (possibly leaked key). Attacker set extreme plan params (no timelock/bounds) and minted inflated interest via invest/redeem flow. #Web3Security #DeFi
2
356
Cozy Finance (Optimism) reportedly exploited for ~$160K. SlowMist says attacker abused UMA Optimistic Oracle “YES” responses to trigger payouts without independent verification of a real Aave/Curve incident. #DeFi #Security
1
334
Liquid Network says it paused activity after a ~4,000 BTC (~$320M) withdrawal/peg-out tied to a security incident. Liquid says it occurred via SideSwap’s PAK; an on-chain message claims “whitehats.” #CryptoSecurity #Bitcoin
1
426
✅ Audit Complete. We've successfully completed a smart contract audit on @axcess_finance. Axcess Finance is an onchain private credit platform where every loan is isolated per vault, pre underwritten before funding, and backed by a first loss buffer. Website: axcess.finance
1
7
742
Core DAO says some validators drew CORE rewards above intended issuance. Emergency hard fork planned (forward-only; no rollback), and the issue is reported contained. Some exchanges restricted CORE transfers. #Web3Security #DeFi
5
397
Solana AMM Aquifer reports a ~$2.5M exploit with attacker activity on Solana + Ethereum. Project posted an on-chain whitehat offer: return ≥80% by Sept 3 (14:00 UTC) and keep up to 20% as a bounty. #DeFi #Security
1
231
Injective reported a ~4-hour network pause after a binary options exploit (Sep 1). Reports cite a deprecated oracle + “no price refund” path, with ~ $4.9M allegedly stolen. Details remain partially unverified. #DeFi #Security
1
1
258
Ontology has paused mainnet block production for an emergency security review after spotting a potential issue. Team says no confirmed incident yet and no indication of user-asset loss; transactions won’t process until resumed. #Web3Security #Blockchain
340
Tectonic on Cronos was reportedly exploited via TONIC price manipulation, with ~$74M estimated losses. Cronos paused the entire chain; some funds were bridged out before the halt, while the rest is said to remain on Cronos. #DeFi #exploit
192
Blockaid reports an exploit on More Markets (Flow EVM): ~15.5M WFLOW drained from the mFlowWFLOW lending reserve (~$9.3M est.). More Markets says it’s investigating and hasn’t confirmed figures. #DeFi #Security
224
Avici reports a vuln in Rain’s Solana card-balance contract impacted 1,685 users ($500,859.22). Contract upgraded; Avici says self-custodial wallets weren’t affected. Refunds promised. #Web3Security #Solana
3
563
Cronos halted after an exploit hit Tectonic (its largest lending protocol). Onchain estimates put impact at ~US$75M, tied to TONIC price manipulation used as collateral. Tectonic says: do not interact until further notice. #DeFi #Security
1
237
Switchboard says its Move-based oracle implementations may be compromised. Services halted on Aptos, Sui, Iota & Movement; users advised to migrate temporarily while investigation continues. #Web3Security #DeFi
3
360
Fogo mainnet has been halted after the Fogo Foundation disclosed a compromise that sent 400M FOGO tokens to a bad actor. Validators are upgrading the network while movement of affected assets is restricted. #Web3 #Security
212