1834 hack event(s)
Description of the event: The leading lending platform on the Starknet chain, zkLend, has suffered an attack. The core reason for this breach lies in the fact that the value of the accumulator in an empty market can be manipulated and amplified using a unique mechanism in flash loans. Additionally, the market contract's use of the SafeMath library performs division using direct division, allowing the attacker to exploit the amplified accumulator to trigger a rounding-down vulnerability for profit.
Amount of loss: $ 9,600,000 Attack method: Contract Vulnerability
Description of the event: According to monitoring by the SlowMist security team, Cashverse appears to have been attacked on BSC.
Amount of loss: $ 107,900 Attack method: Contract Vulnerability
Description of the event: According to monitoring by the SlowMist security team, BankX appears to have been attacked on BSC, ETH, and Optimism.
Amount of loss: $ 43,000 Attack method: Contract Vulnerability
Description of the event: The X account of Tanzanian businessman and entrepreneur Mohammed Dewji MO (@moodewji) was compromised. The hacker falsely announced the launch of a TANZANIA token and sold it to investors.
Amount of loss: - Attack method: Account Compromise
Description of the event: JupiterDAO confirmed on X that the official Jupiter X account (@JupiterExchange) has been compromised. Users are advised not to click on any links or copy-paste any contract addresses.
Amount of loss: - Attack method: Account Compromise
Description of the event: The ionic platform on Mode was hacked, with the attacker using an unofficial fake LBTC (Lombard BTC) as collateral to borrow funds, resulting in a loss of approximately $8.8 million.
Amount of loss: $ 8,800,000 Attack method: Social Engineering
Description of the event: According to a post by SlowMist founder Cos on X, the X account of former Malaysian Prime Minister Dr Mahathir Mohamad (@chedetofficial) was compromised and used to promote a fake token. The creator of the associated contract address (CA) has ties to a previously known malicious group.
Amount of loss: - Attack method: Account Compromise
Description of the event: The official TIME Magazine X account was allegedly compromised and posted about the TIME token.
Amount of loss: - Attack method: Account Compromise
Description of the event: The Tor Project X account has been compromised. The hacker is using the account to promote a fake token. Users should stay vigilant.
Amount of loss: - Attack method: Account Compromise
Description of the event: According to DL News, Dean Norris, the actor who played Hank Schrader in Breaking Bad, became the target of a hack on the X platform for the second time in six months. The attack started with a tweet from Norris' account announcing his decision to launch his own cryptocurrency called Dean, along with the contract address. The attackers even shared a manipulated photo of Norris holding a notebook with the token's symbol and date hastily written on it. Within hours, the meme coin's market value surged to $7 million, but after Norris confirmed the scam, its value plummeted by 90%.
Amount of loss: - Attack method: Account Compromise
Description of the event: The X account of former Brazilian President Jair Messias Bolsonaro was hacked and used to promote the token. The original post has since been deleted.
Amount of loss: - Attack method: Account Compromise
Description of the event: The AdsPower security team discovered a breach in which hackers distributed malicious code, resulting in the compromise of some third-party browser extensions.
Amount of loss: $ 4,700,000 Attack method: Supply Chain Attack
Description of the event: According to monitoring by the SlowMist security team, due to a lack of input validation in @odosprotocol, the vulnerability has been exploited across multiple chains, resulting in approximately $100,000 in losses. ODOS stated in a post that the attack exploited a vulnerability in its audited executor contract, allowing the theft of revenue stored within the contract but not affecting any user funds.
Amount of loss: $ 100,000 Attack method: Contract Vulnerability
Description of the event: The Singapore-based Phemex cryptocurrency exchange's hot wallets were hacked, resulting in a loss of approximately $70 million.
Amount of loss: $ 70,000,000 Attack method: Unknown
Description of the event: According to The Block, Nasdaq's official X account was hacked, and the attackers used it to promote fraudulent meme coins.
Amount of loss: - Attack method: Account Compromise
Description of the event: According to monitoring by the SlowMist security team, AST was allegedly attacked on BSC.
Amount of loss: $ 64,700 Attack method: Contract Vulnerability
Description of the event: MetaMask posted on X: “This morning, our co-founder Dan Finlay's Farcaster account was compromised and used to promote a memecoin. We are in touch with the Farcaster team to help investigate the incident."
Amount of loss: - Attack method: Account Compromise
Description of the event: A Twitter account named @TrumpDailyPosts, with over 1.3 million followers, not only automatically crossposts Donald Trump's Truth Social posts to Twitter but also shares Trump-related news and other tweets. This X account promoted at least four meme coins, with the posts being deleted within minutes after sharing, resulting in approximately $1.25 million in losses.
Amount of loss: $ 1,250,000 Attack method: Unknown
Description of the event: Stability AI's official X account posted information related to the STAI token contract, which appears to have been compromised. Be cautious to avoid falling victim to a scam.
Amount of loss: - Attack method: Account Compromise
Description of the event: The ZKsync team tweeted that the @ZKsyncIgnite account has been compromised. Do not interact with the account or click any links. Wait for the @zksync account to confirm when the account has been reclaimed.
Amount of loss: - Attack method: Account Compromise