Mapping Web3 hacks, exploit mechanics and onchain fund flows. Evidence first: transactions, postmortems, recoveries and open questions.

World
A big number gets attention. The mechanism tells the truth. I track how Web3 hacks happen, where the money moves and whether the fix actually fixes anything. Plus new networks and onchain markets worth watching.
1
8
| BlockCartographer | 🦅 retweeted
Year One.
125
77
750
288,750
| BlockCartographer | 🦅 retweeted
🚨 SlowMist TI Alert 🚨 MemTensor's AI memory tooling has been compromised: MemoryOS (PyPI), the company's open-source long-term memory library for LLM and AI agents, and memtensor/memos-cloud-openclaw-plugin (npm), the official plugin connecting it to the OpenClaw agent runtime. Affected versions bundle cross-platform Go binaries that execute when the package is loaded or imported: MemoryOS==2.0.34 on PyPI, and plugin versions 0.1.21, 0.1.23 and 0.1.25 on npm. You are affected if the PyPI version has been imported in your environment, or if the npm plugin is installed and the OpenClaw gateway has been started. Potential attacker actions include harvesting npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, environment secrets, and other developer credentials, with data sent to infrastructure under skyleen[.]fr. The affected npm plugin may also expose user prompt content. Users should remove or downgrade affected packages to known-good versions (0.1.20 for npm and 2.0.33 for PyPI), terminate sckit processes, block associated infrastructure, review network activity, and rotate credentials accessible from affected environments. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. Reference: aikido.dev/blog/supplychain-… As always, stay vigilant! enterprise.misteye.io/threat…
8
8
23
7,656
| BlockCartographer | 🦅 retweeted
Securities finance handles tens of trillions of dollars a year, and that value is now moving onchain. We published a blog post that details how Aave V4 is positioned to be the credit layer. Read it below ↓
33
35
213
27,107
| BlockCartographer | 🦅 retweeted
Chance’s STRK20 integration is live on Starknet. Chance checks each transfer against a signed mandate and returns a receipt showing it was authorised. STRK20 keeps the sender, recipient and amount confidential. Privacy that works for crypto.
Chance integrated STRK20! Verify first. Then let it go stealth. @Starknet's STRK20 hides the sender, receiver, and amount. That removes the last obvious safety net for AI agents moving money. Nobody can watch what an agent does once it goes private. So verification has to move up a layer: to intent. Chance verifies every transfer against the mandate you signed, then returns a receipt proving it was authorized, without revealing who paid whom. STRK20 hides the transfer. Chance proves the behavior.
33
35
231
17,274
| BlockCartographer | 🦅 retweeted
See a ticker on 𝕏. Tap the Cashtag. Trade it on Coinbase.
timeline. ticker. trade.
127
99
787
221,534
Three Web3 stories today, one pattern: • WMTx: mint-authority risk • MultiversX: recovery and rollback risk • STAMP/ZIP227: verified mechanics vs future promises Markets price features first and trust boundaries later. Always ask: who can mint, pause, roll back or reinterpret state?
1
82
| BlockCartographer | 🦅 retweeted
Nick Ducoff, Head of Institutional Growth, on internet capital markets "The vision for Solana is this idea of internet capital markets, connecting the world's internet users, of which there are five and a half, six billion, with the world's global productive assets. That's anything that can be tokenized, from commodities like gold and silver to stocks." @nickducoff @FINTECHTVglobal
167
110
807
140,733
| BlockCartographer | 🦅 retweeted
All the leverage. None of the games. Today we're publishing the Saphyre Manifesto. In 48 hours, the waitlist opens for Saphyre Perps on web testnet. Here's what we're building 🧵
19
16
84
57,165
| BlockCartographer | 🦅 retweeted
Security Notice ⚠️ We have identified an exploit of the @SingularityNET bridge that has resulted in the unauthorised minting of $WMTx on Ethereum. This had led to recent price action across all exchanges that $WMTx is listed on. Our team is actively responding: • We are in contact with exchanges and relevant third parties to freeze affected deposits. • We are working with our security partners to revoke all minting authorities. • We are continuing to monitor the situation closely and will share verified updates as they are confirmed. Please be aware that incidents of this nature are frequently targeted by bad actors. Do not engage with unsolicited DMs, "support" accounts, recovery services, claim portals, or token migration links. This account, @wmchain, is the only official source for updates on this matter. We appreciate your patience and will report back as soon as we have more to share.
89
89
274
81,357
One leaked signer drained Fetch’s bridge; the same actor hit NuNet and SingularityNET contracts. Bigger than key rotation: if one EOA can release or mint without onchain burn/lock proof, the bridge is a centralized issuer. Publish signer scope, revocations and unbacked supply.
24
Shared liquidity is the right architecture. But $7B in volume is the opening metric, not the conclusion. Durable, non-incentivized flow and user retention will show whether this is a market—or a campaign.
$7B+ traded on @DecibelTrade. $1B+ of it through Builder Codes. Different apps, one shared orderbook. Wallets, frontends, and bots plug in directly. Every order is settled onchain on Aptos, where every trade burns $APT. Liquidity that doesn't fragment.
10
| BlockCartographer | 🦅 retweeted
Privacy is choice, agency and human dignity
Connaugh 🛡️
66
59
432
25,270
A short squeeze can move price. It cannot prove adoption. The real ZEC test begins after leverage leaves: do shielded balances, transactions and users continue growing?
Garrett Jin (@GarrettBullish), the largest $ZEC short, is now sitting on a $33.66M unrealized loss! Liquidation price: $4,792.01 But his 1,333 $BTC ($108.57M) long is now up $4.5M. hypurrscan.io/address/0x92ea…
14
ZEC is up ~170% in 30 days, and the timeline is debating targets. Wrong question. At ~$1.5K, ZEC is priced like the privacy thesis already won—while only ~29% of issued supply is shielded. Bull case: the market is early. Bear case: adoption is late. Which is it?
19
| BlockCartographer | 🦅 retweeted
Sept 18 Update: #Bitcoin ETFs: 1D NetFlow: +1,955 $BTC(+$154.39M)🟢 7D NetFlow: -6,715 $BTC(-$530.42M)🔴 #Ethereum ETFs: 1D NetFlow: -28,356 $ETH(-$71.75M)🔴 7D NetFlow: -42,976 $ETH(-$108.74M)🔴
36
15
126
55,195
| BlockCartographer | 🦅 retweeted
🚨SlowMist TI Alert🚨 💸 @nimiq Loss: ~$50,463 🔍 Root Cause: ERC20PermitHTLCHandler's `execute()` discards all five calldata parameters (including signature & nonce) and performs no EIP-712 signature, nonce, or business pre-check. The only signature/nonce validation lived in its `preRelayedCall()`, but GSN RelayHub calls `preRelayedCall` on the attacker-specified paymaster. So the attacker set himself as paymaster, fully bypassing that check, used 1 MATIC GSN relay registration to pass `onlyRelayHub` and forged `request.from = victim`, causing `openPrivate()` to call `token.transferFrom(victim, handler, full balance)`. Finally, the attacker directly called the `redeem` function to withdraw these funds using the hosted secret they had crafted. 📌 Attacker: 0x2258491525C21f334c5a2dc22CE55e55023FC45D 📌 Victim: 0x24Cb173Ae221AeA93369f34bdcF0Ddb35b436773 📌 Vulnerable Contract: 0x0cFD862bE942846Cebad797d7c1BC6e47714959b, 0xf615bd7eA00C4Cc7F39fAAD0895Db5f40891359f Powered by SlowMist.AI Tx: polygonscan.com/tx/0xb067efa… polygonscan.com/tx/0xb2ca76d…
2
3
23
7,173
| BlockCartographer | 🦅 retweeted
MIR’s Mainnet launch is imminent, and we are currently awaiting the completion and full review of the contract security audits. Once all audits are complete, we will confirm and share the official Mainnet launch date. More details to come soon.
29
21
177
27,452
| BlockCartographer | 🦅 retweeted
Manual borrows are live on Hyperliquid Portfolio margin and manual borrows use the same underlying HyperCore infrastructure, with $269M in assets borrowed today. Users can supply HYPE and BTC as collateral to borrow quote assets (USDC and USDT). Borrowed quote assets pay interest, and supplied quote assets earn interest, with rates set by utilization.
275
299
1,875
501,376
BTC recovered above $76K, but crypto equities sold off harder: COIN closed -4.4% and MSTR about -3% after the Fed hike. Equity beta is pricing more than spot BTC—rates, operating leverage and financing risk. Until COIN/MSTR stabilize, the bounce needs confirmation.
19