<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: qanzhi111</title>
    <description>The latest articles on DEV Community by qanzhi111 (@qanzhi111).</description>
    <link>https://dev.to/qanzhi111</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3969609%2F1a8a629b-321b-44cb-b95f-7ac3add5d48d.png</url>
      <title>DEV Community: qanzhi111</title>
      <link>https://dev.to/qanzhi111</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/qanzhi111"/>
    <language>en</language>
    <item>
      <title>Uniswap Google Ad Phishing - Systematic Crypto Theft</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 11:08:09 +0000</pubDate>
      <link>https://dev.to/qanzhi111/uniswap-google-ad-phishing-systematic-crypto-theft-1hia</link>
      <guid>https://dev.to/qanzhi111/uniswap-google-ad-phishing-systematic-crypto-theft-1hia</guid>
      <description>&lt;h1&gt;
  
  
  Uniswap Google Ad Phishing Attack - Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; May 29, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Case ID:&lt;/strong&gt; ONCHAIN-2026-0529-001&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Active - Ongoing Scam  &lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;Google's advertising platform has been weaponized by scammers to drain crypto wallets through fake Uniswap phishing sites. Over &lt;strong&gt;$400,000&lt;/strong&gt; has been stolen from users searching for Uniswap on Google, with two primary attacker wallets identified holding approximately &lt;strong&gt;146 ETH&lt;/strong&gt; (~$306,000).&lt;/p&gt;




&lt;h2&gt;
  
  
  Incident Timeline
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;May 25, 2026&lt;/td&gt;
&lt;td&gt;On-chain investigator @b_block_oficial identifies attack&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;May 26, 2026&lt;/td&gt;
&lt;td&gt;Community alerts spread via Twitter/X&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;May 27, 2026&lt;/td&gt;
&lt;td&gt;Multiple news outlets report the incident&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ongoing&lt;/td&gt;
&lt;td&gt;Scam continues - Google has not taken action&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attacker Wallet Addresses
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Primary Drain Wallet 1: 0x37925684BA178821b4436E06e67f5dBD6cfA49Bb
Primary Drain Wallet 2: 0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Current Holdings (as of May 26):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Wallet 1 + Wallet 2: ~146 ETH (~$306,000)&lt;/li&gt;
&lt;li&gt;Additional tokens (unspecified)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Total estimated theft: ≥$400,000&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Attack Methodology
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Phase 1: Ad Placement
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Scammers purchase Google sponsored ads for "Uniswap" keyword&lt;/li&gt;
&lt;li&gt;Outbid legitimate Uniswap protocol to secure top position&lt;/li&gt;
&lt;li&gt;Use hacked or fraudulently obtained Google advertiser accounts&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 2: Cloaking &amp;amp; Evasion
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Phishing URLs use authentic-looking domains&lt;/li&gt;
&lt;li&gt;Hidden secondary element loads malicious code&lt;/li&gt;
&lt;li&gt;Advanced infrastructure includes:

&lt;ul&gt;
&lt;li&gt;Cloudflare Workers&lt;/li&gt;
&lt;li&gt;Arweave-hosted payloads&lt;/li&gt;
&lt;li&gt;Traffic redirection systems&lt;/li&gt;
&lt;li&gt;Proxy layers monitoring user RPC requests&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;Techniques bypass Google's automated review systems&lt;/li&gt;

&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 3: Wallet Drain
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Victims land on convincing Uniswap replica&lt;/li&gt;
&lt;li&gt;Malicious site intercepts Ethereum RPC requests&lt;/li&gt;
&lt;li&gt;Silent drain of connected wallets&lt;/li&gt;
&lt;li&gt;No seed phrase needed - one wrong signature drains everything&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Scale of the Problem
&lt;/h2&gt;

&lt;h3&gt;
  
  
  SEAL Organization Findings
&lt;/h3&gt;

&lt;p&gt;The Security Alliance (SEAL) has been tracking this pattern:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Sharp rise in March 2026:&lt;/strong&gt; $1.27 million stolen (March 13-30)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;356+ malicious Google ad URLs blocked&lt;/strong&gt; (typical weekly volume)&lt;/li&gt;
&lt;li&gt;Pattern has sustained for over a year&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Uniswap accounts for 41%&lt;/strong&gt; of tracked malicious websites&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Other Targeted Platforms
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Morpho Finance&lt;/li&gt;
&lt;li&gt;PancakeSwap&lt;/li&gt;
&lt;li&gt;Hyperliquid&lt;/li&gt;
&lt;li&gt;CoW Swap&lt;/li&gt;
&lt;li&gt;1inch&lt;/li&gt;
&lt;li&gt;Ledger (phishing emails post-data breach)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Drainer Families Identified
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Inferno Drainer&lt;/li&gt;
&lt;li&gt;Vanilla Drainer&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Community Response
&lt;/h2&gt;

&lt;h3&gt;
  
  
  @b_block_oficial Alert
&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;"Two scammers have already stolen ~$400,000 from users through a phishing @Uniswap ad on Google. It's insane that Google has ignored this issue for years while fake links keep getting pushed above real ones and users keep getting drained."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  @StacyMuur (GREEND0TS Founder)
&lt;/h3&gt;

&lt;p&gt;Shared screenshots of malicious ads appearing as top sponsored results. Confirmed scam site closely replicates official Uniswap interface.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;a class="mentioned-user" href="https://dev.to/defillama"&gt;@defillama&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;Echoed concerns, calling fake Google ads a "common and recurring source of phishing attacks targeting the crypto community."&lt;/p&gt;




&lt;h2&gt;
  
  
  Regulatory &amp;amp; Legal Context
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Google Responsibility
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Google has been aware of crypto phishing ads for over a year&lt;/li&gt;
&lt;li&gt;No effective prevention measures implemented&lt;/li&gt;
&lt;li&gt;Continues to profit from ad purchases by bad actors&lt;/li&gt;
&lt;li&gt;No statement or remediation announced&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Victim Protection Guidelines
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Only use official links:&lt;/strong&gt; Verify via official channels (defillama.com, coinmarketcap.com)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check URLs carefully:&lt;/strong&gt; Even slight misspellings indicate phishing&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Use hardware wallets:&lt;/strong&gt; For significant holdings&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Review approvals regularly:&lt;/strong&gt; Use revoke.cash to check/remove suspicious approvals&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Never sign blind transactions:&lt;/strong&gt; Read all transaction details before signing&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Be skeptical of search results:&lt;/strong&gt; Sponsored = Paid, not verified&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  On-Chain Evidence Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Original alert tweet with wallet addresses: &lt;a href="https://twitter.com/b_block_oficial" rel="noopener noreferrer"&gt;Twitter/X Link&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;SEAL Report: Phishing campaign analysis&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  ZachXBT Angle
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;This case is NOT suitable for ZachXBT coverage&lt;/strong&gt; because:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Attack methodology is well-documented by other analysts&lt;/li&gt;
&lt;li&gt;No new unique investigative angle&lt;/li&gt;
&lt;li&gt;Attack is ongoing rather than concluded&lt;/li&gt;
&lt;li&gt;However, Google's complicity in perpetuating this scam deserves wider exposure&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;This incident highlights the ongoing failure of Google to protect users from cryptocurrency phishing scams on its advertising platform. Despite repeated warnings from the security community, fake Uniswap ads continue to appear as top search results, resulting in ongoing losses exceeding $400,000.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Takeaway:&lt;/strong&gt; Google profits from ads while users lose life-changing money. The platform has shown no willingness to implement meaningful safeguards despite over a year of documented attacks.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Investigation conducted by on-chain-shadow&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;Report generated: May 29, 2026&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;GitHub Pages: &lt;a href="https://onchain-shadow.github.io/on-chain-investigations/" rel="noopener noreferrer"&gt;https://onchain-shadow.github.io/on-chain-investigations/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>phishing</category>
    </item>
    <item>
      <title>GitHub NPM Supply Chain Attack - Crypto Wallet Targeting</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 11:01:54 +0000</pubDate>
      <link>https://dev.to/qanzhi111/github-npm-supply-chain-attack-crypto-wallet-targeting-m8b</link>
      <guid>https://dev.to/qanzhi111/github-npm-supply-chain-attack-crypto-wallet-targeting-m8b</guid>
      <description>&lt;h1&gt;
  
  
  GitHub NPM Supply Chain Attack - Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; May 29, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Case ID:&lt;/strong&gt; ONCHAIN-2026-0529-002&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Threat Names:&lt;/strong&gt; Megalodon, Mini Shai-Hulud&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Active - Ongoing Crisis  &lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;A massive supply chain attack campaign dubbed "Megalodon" and "Mini Shai-Hulud" is targeting GitHub tokens and NPM packages. Malicious code injected into npm packages steals developers' GitHub Personal Access Tokens (PATs), allowing attackers to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Access private repositories&lt;/li&gt;
&lt;li&gt;Steal API keys and secrets&lt;/li&gt;
&lt;li&gt;Inject malicious code into legitimate projects&lt;/li&gt;
&lt;li&gt;Drain Web3/DeFi user wallets through compromised front-ends&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Impact:&lt;/strong&gt; Affects Grafana Labs, GitHub itself, and thousands of open-source projects with millions of daily downloads.&lt;/p&gt;




&lt;h2&gt;
  
  
  Threat Timeline
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Late May 2026&lt;/td&gt;
&lt;td&gt;Security researchers discover attack campaign&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;May 27-28, 2026&lt;/td&gt;
&lt;td&gt;Internet buzz reaches maximum levels&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ongoing&lt;/td&gt;
&lt;td&gt;New variants appearing every few hours&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attack Chain Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Step 1: Initial Compromise
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Malicious NPM Package → Developer Downloads → Trojan Activates
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Attackers inject trojan code into popular npm packages. When developers install or update these packages, the hidden malware activates silently on their computers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: Token Harvest
&lt;/h3&gt;

&lt;p&gt;The trojan specifically searches for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GitHub Personal Access Tokens (PATs)&lt;/li&gt;
&lt;li&gt;Browser-stored credentials&lt;/li&gt;
&lt;li&gt;IDE/saved passwords&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 3: Automated Exploitation
&lt;/h3&gt;

&lt;p&gt;Once a token is stolen, automated bot scripts:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Log into victim's GitHub account immediately&lt;/li&gt;
&lt;li&gt;Bypass 2FA/authentication&lt;/li&gt;
&lt;li&gt;Inject same trojan into all managed repositories&lt;/li&gt;
&lt;li&gt;Spread across thousands of projects in hours&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Step 4: Downstream Attack
&lt;/h3&gt;

&lt;p&gt;Compromised repositories lead to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Malicious website code updates&lt;/li&gt;
&lt;li&gt;Fake "Connect Wallet" buttons&lt;/li&gt;
&lt;li&gt;Phishing smart contracts&lt;/li&gt;
&lt;li&gt;Mass wallet draining of end users&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Technical Details
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why GitHub Tokens Are Valuable
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Capability&lt;/th&gt;
&lt;th&gt;Without Token&lt;/th&gt;
&lt;th&gt;With Token&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;2FA Required&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Password Required&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Access Private Repos&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Push Malicious Code&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Steal API Keys&lt;/td&gt;
&lt;td&gt;Difficult&lt;/td&gt;
&lt;td&gt;Instant&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Attack Speed
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Traditional hack: Days to weeks&lt;/li&gt;
&lt;li&gt;This attack: Hours to days&lt;/li&gt;
&lt;li&gt;Automated propagation infects thousands of repos in 24 hours&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Confirmed Victims
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Enterprise Platforms
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Grafana Labs&lt;/strong&gt; - Internal code stolen&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub&lt;/strong&gt; - Internal systems compromised&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multiple enterprise platforms&lt;/strong&gt; - Under investigation&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Open Source Impact
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Thousands of independent developers affected&lt;/li&gt;
&lt;li&gt;Millions of daily downloads potentially compromised&lt;/li&gt;
&lt;li&gt;GitHub audit logs show suspicious midnight commits&lt;/li&gt;
&lt;li&gt;npm registry deleting malicious packages (but new variants every few hours)&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Web3/DeFi Specific Risk
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why Crypto Is Extra Vulnerable
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Heavy npm dependency:&lt;/strong&gt; DEX, DeFi, and meme coin websites rely heavily on public npm packages&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Small teams:&lt;/strong&gt; Limited security audit capabilities&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Irreversible transactions:&lt;/strong&gt; One bad signature = total wallet loss&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anonymity:&lt;/strong&gt; Attack attribution is difficult&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Attack Surface for Web3 Users
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User visits crypto website 
→ Website uses compromised npm package
→ Developer token was stolen
→ Malicious code pushed to production
→ "Connect Wallet" button now drains wallet
→ User clicks → Wallet emptied
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Community Response
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Industry Actions
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;GitHub Security:&lt;/strong&gt; Tracking known hacker IP addresses&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;npm Registry:&lt;/strong&gt; Working around clock to delete malicious packages&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Major tech firms:&lt;/strong&gt; Advising employees to stop installing unverified updates&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security firms:&lt;/strong&gt; Emergency response mode&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Developer Warnings
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Check GitHub audit logs for unauthorized commits&lt;/li&gt;
&lt;li&gt;Run &lt;code&gt;npm audit&lt;/code&gt; on all projects&lt;/li&gt;
&lt;li&gt;Look for unknown background processes sending data externally&lt;/li&gt;
&lt;li&gt;Revoke ALL active GitHub PATs immediately&lt;/li&gt;
&lt;li&gt;Change main account passwords&lt;/li&gt;
&lt;li&gt;Alert community if project may be compromised&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Mitigation Recommendations
&lt;/h2&gt;

&lt;h3&gt;
  
  
  For Developers
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;✅ Review GitHub audit logs immediately&lt;/li&gt;
&lt;li&gt;✅ Scan code with &lt;code&gt;npm audit&lt;/code&gt; or specialized tools&lt;/li&gt;
&lt;li&gt;✅ Check for unauthorized midnight commits&lt;/li&gt;
&lt;li&gt;✅ Monitor for unknown external data connections&lt;/li&gt;
&lt;li&gt;✅ &lt;strong&gt;Revoke ALL GitHub PATs&lt;/strong&gt; - regenerate new ones&lt;/li&gt;
&lt;li&gt;✅ Use environment variables, never hardcode secrets&lt;/li&gt;
&lt;li&gt;✅ Enable 2FA on all accounts&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  For Crypto Users
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;✅ Use hardware wallets for significant holdings&lt;/li&gt;
&lt;li&gt;✅ Verify website URLs carefully before connecting&lt;/li&gt;
&lt;li&gt;✅ Check project's social media for security announcements&lt;/li&gt;
&lt;li&gt;✅ Don't trust "Connect Wallet" buttons on meme coin sites&lt;/li&gt;
&lt;li&gt;✅ Use reputable platforms when possible&lt;/li&gt;
&lt;li&gt;✅ Consider CEX for trading until supply chain stabilizes&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  Industry Expert Opinion
&lt;/h2&gt;

&lt;h3&gt;
  
  
  OpenZeppelin Founder's Warning
&lt;/h3&gt;

&lt;p&gt;Manuel Aráoz, co-founder of OpenZeppelin, stated:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"I now consider &lt;em&gt;all&lt;/em&gt; of DeFi unsafe. Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;He reportedly advised friends and family to pull funds from Aave, MakerDAO, and Compound.&lt;/p&gt;




&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;The Megalodon/Mini Shai-Hulud supply chain attack represents a significant escalation in Web3 security threats. Unlike traditional smart contract exploits, this attack vector:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Exploits human/developer security&lt;/li&gt;
&lt;li&gt;Circumvents all technical safeguards&lt;/li&gt;
&lt;li&gt;Has massive blast radius&lt;/li&gt;
&lt;li&gt;Spreads autonomously&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Key Takeaway:&lt;/strong&gt; Web3 security is no longer just about smart contract audits. The entire development infrastructure - from developer machines to npm packages to GitHub - is now an attack surface.&lt;/p&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;WEEX Security Report (&lt;a href="https://www.weex7.com/wiki/article/github-token-leak-and-npm-malware-what-web3-traders-need-to-know" rel="noopener noreferrer"&gt;https://www.weex7.com/wiki/article/github-token-leak-and-npm-malware-what-web3-traders-need-to-know&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Industry security researchers&lt;/li&gt;
&lt;li&gt;GitHub/npm official statements&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;Investigation conducted by on-chain-shadow&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;Report generated: May 29, 2026&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;GitHub Pages: &lt;a href="https://onchain-shadow.github.io/on-chain-investigations/" rel="noopener noreferrer"&gt;https://onchain-shadow.github.io/on-chain-investigations/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>npm</category>
    </item>
    <item>
      <title>THORChain $10.7M Proposer-Forgery Attack</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 11:00:52 +0000</pubDate>
      <link>https://dev.to/qanzhi111/thorchain-107m-proposer-forgery-attack-2jlo</link>
      <guid>https://dev.to/qanzhi111/thorchain-107m-proposer-forgery-attack-2jlo</guid>
      <description>&lt;h1&gt;
  
  
  THORChain $10.7M Proposer-Forgery Attack Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date of Incident:&lt;/strong&gt; May 30, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Total Loss:&lt;/strong&gt; ~$10.7 million USD&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Affected Assets:&lt;/strong&gt; Ethereum, Bitcoin, BNB Chain vault funds&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Network:&lt;/strong&gt; THORChain (Cross-Chain)&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;On May 30, 2026, THORChain suffered a $10.7 million exploit targeting its cross-chain vault transfer mechanism. The attack exploited a &lt;strong&gt;proposer-forgery bug&lt;/strong&gt; in THORChain's Bifrost Attestation Gossip system, allowing attackers to intercept and modify inbound deposit observations into fraudulent outbound payment requests.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The most alarming detail:&lt;/strong&gt; THORChain developers had already developed a fix for this exact vulnerability, which would have prevented the attack. The fix was scheduled for deployment earlier in May, but the automated testing and distribution system failed to implement it.&lt;/p&gt;

&lt;p&gt;This represents a case of &lt;strong&gt;operational failure rather than technical failure&lt;/strong&gt;—the security knowledge existed, the fix was ready, but deployment infrastructure let the protocol down.&lt;/p&gt;




&lt;h2&gt;
  
  
  Attack Vector Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Technical Mechanism
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Vulnerability:&lt;/strong&gt; Proposer-forgery bug in THORChain's Bifrost Attestation Gossip&lt;/p&gt;

&lt;p&gt;The Bifrost protocol enables cross-chain communication within THORChain. The vulnerability existed in how validators observe and attest to transactions:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Normal Flow:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Users deposit assets into THORChain vaults&lt;/li&gt;
&lt;li&gt;Validators observe the inbound deposit&lt;/li&gt;
&lt;li&gt;Validators collectively approve outbound withdrawals&lt;/li&gt;
&lt;li&gt;Funds are released from shared vaults&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Attack Flow:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Attacker initiates legitimate inbound deposit&lt;/li&gt;
&lt;li&gt;Attacker intercepts the inbound observation&lt;/li&gt;
&lt;li&gt;Modifies observation into fake outbound payment request&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Critical flaw:&lt;/strong&gt; Validator signatures did not cover the inbound/outbound bit&lt;/li&gt;
&lt;li&gt;This allowed proposers to "flip" a real inbound observation into a fraudulent outbound instruction&lt;/li&gt;
&lt;li&gt;Validators approved what appeared to be legitimate withdrawal&lt;/li&gt;
&lt;li&gt;Funds drained to attacker-controlled addresses across ETH, BTC, and BNB&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  The Preventable Failure
&lt;/h3&gt;

&lt;p&gt;According to Blockaid's analysis:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Blockaid says Thorchain developers had already developed a fix for this specific vulnerability, which would have thwarted the attack. The fix was meant to be implemented earlier this month, but the automated system that tests and distributes software updates on Thorchain reportedly failed."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is a critical lesson in DeFi security: &lt;strong&gt;knowing about a vulnerability and having a fix is meaningless if deployment infrastructure fails.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Market Impact
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;RUNE Price (Pre-Attack)&lt;/td&gt;
&lt;td&gt;$0.585&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RUNE Price (2hr Post-Attack)&lt;/td&gt;
&lt;td&gt;$0.501 (-14%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RUNE Price (Press Time)&lt;/td&gt;
&lt;td&gt;$0.514&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol TVL Impact&lt;/td&gt;
&lt;td&gt;Significant&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The RUNE token experienced an immediate 14% dip following public disclosure of the exploit.&lt;/p&gt;




&lt;h2&gt;
  
  
  THORChain's Controversial Role in the Ecosystem
&lt;/h2&gt;

&lt;h3&gt;
  
  
  A Platform Built to Avoid Bridges—Now Critical to Bridge Hackers
&lt;/h3&gt;

&lt;p&gt;THORChain was architecturally designed to enable native cross-chain swaps without the security risks associated with wrapped tokens or bridge protocols. The irony is profound:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;In the KelpDAO $292M exploit (April 2026), the hacker used THORChain as the primary laundering route for stolen funds.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;According to Chainalysis and TRM Labs data:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;THORChain processed the majority of laundering volume from both the Bybit ($1.5B, February 2025) and KelpDAO ($292M, April 2026) hacks&lt;/li&gt;
&lt;li&gt;The protocol's operators have publicly refused to consider freezing or screening transactions, treating any such intervention as contrary to decentralization principles&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  North Korea's Preferred Laundering Infrastructure
&lt;/h3&gt;

&lt;p&gt;The crypto.news investigation detailed how THORChain has become a load-bearing pillar of the laundering pipeline used by North Korea's Lazarus Group:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Stolen ETH swapped into BTC or stablecoins&lt;/li&gt;
&lt;li&gt;Routed through cross-chain bridges (including THORChain) for obfuscation&lt;/li&gt;
&lt;li&gt;Further routed through Russian crypto exchanges and Chinese OTC desks&lt;/li&gt;
&lt;li&gt;Converted to fiat and channeled into procurement networks&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;The uncomfortable truth:&lt;/strong&gt; THORChain's principled stance on decentralization and non-custodial operation has made it the preferred infrastructure for state-sponsored cryptocurrency theft.&lt;/p&gt;




&lt;h2&gt;
  
  
  Historical Attack Context
&lt;/h2&gt;

&lt;p&gt;THORChain has a documented history of security incidents:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Attack&lt;/th&gt;
&lt;th&gt;Loss&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;July 2021&lt;/td&gt;
&lt;td&gt;Multiple exploits (days apart)&lt;/td&gt;
&lt;td&gt;~$15 million&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Various&lt;/td&gt;
&lt;td&gt;Ongoing exploits&lt;/td&gt;
&lt;td&gt;Over $8 million total (2021)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;April 2026&lt;/td&gt;
&lt;td&gt;KelpDAO hacker used THORChain for laundering&lt;/td&gt;
&lt;td&gt;$292M laundered&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;May 30, 2026&lt;/td&gt;
&lt;td&gt;Proposer-forgery vault drain&lt;/td&gt;
&lt;td&gt;$10.7 million&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Total historical losses from THORChain-related incidents exceed $15 million in direct exploits, with the protocol now processing hundreds of millions in state-sponsored hacking proceeds.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Automation Failure Problem
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What Went Wrong
&lt;/h3&gt;

&lt;p&gt;The THORChain exploit exposes a critical vulnerability in how DeFi protocols manage security updates:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Developer Response:&lt;/strong&gt; Fix was identified, code written, ready for deployment&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scheduled Deployment:&lt;/strong&gt; Meant to be implemented earlier in May&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;System Failure:&lt;/strong&gt; Automated CI/CD pipeline for testing and distributing updates failed&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Result:&lt;/strong&gt; Fix never reached production validators, exploit succeeded&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Lessons for DeFi Security
&lt;/h3&gt;

&lt;p&gt;This incident highlights three systemic issues:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Over-reliance on automation:&lt;/strong&gt; Critical security patches cannot depend entirely on automated systems without human oversight&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;The deployment gap:&lt;/strong&gt; Security fixes in staging are useless if production infrastructure fails to receive them&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Defense in depth failure:&lt;/strong&gt; Multiple layers (code review ✓, fix development ✓, deployment automation ✗) must all succeed&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;As OpenZeppelin founder Manuel Aráoz noted:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"I now consider &lt;em&gt;all&lt;/em&gt; of DeFi unsafe," citing AI's growing ability to identify smart contract vulnerabilities—and by extension, the industry's inability to rapidly deploy fixes.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Blockaid Security Analysis&lt;/li&gt;
&lt;li&gt;Arkham Intelligence&lt;/li&gt;
&lt;li&gt;crypto.news Investigation Report&lt;/li&gt;
&lt;li&gt;Chainalysis / TRM Labs Attribution Data&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Investigator Commentary
&lt;/h2&gt;

&lt;p&gt;The THORChain $10.7M exploit is not a story about a clever hacker finding an unknown vulnerability. It is a story about &lt;strong&gt;organizational failure&lt;/strong&gt; in the face of known risk.&lt;/p&gt;

&lt;p&gt;The attacker's technique—proposer-forgery in the Bifrost attestation layer—was understood by THORChain's own developers. A fix existed. The vulnerability had a name, a description, and a remediation. What failed was the operational machinery between "fix ready" and "fix deployed."&lt;/p&gt;

&lt;p&gt;This has implications for the entire DeFi industry:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Security is not just about code audits.&lt;/strong&gt; It's about deployment pipelines, update mechanisms, and fail-safes.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Automation must have human oversight.&lt;/strong&gt; The most sophisticated smart contract security is worthless if your CI/CD pipeline silently fails.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;THORChain's ideological stance creates systemic risk.&lt;/strong&gt; Their refusal to screen transactions is consistent with stated principles—and also makes them complicit in state-sponsored terrorism funding, whether intended or not.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The uncomfortable question that the DeFi industry needs to answer: &lt;strong&gt;Can protocols that refuse to implement basic AML/KYC controls on their infrastructure claim to be "just following the technology"?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;At what point does principled decentralization become willful blindness?&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Investigator: Onchain Shadow&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Report Date:&lt;/strong&gt; May 30, 2026&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclaimer: This report is based on publicly available on-chain data and media reports for security research purposes only.&lt;/em&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>defi</category>
    </item>
    <item>
      <title>Gravity Bridge Key Compromise - $5.4M Validator Leak</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:54:23 +0000</pubDate>
      <link>https://dev.to/qanzhi111/gravity-bridge-key-compromise-54m-validator-leak-h80</link>
      <guid>https://dev.to/qanzhi111/gravity-bridge-key-compromise-54m-validator-leak-h80</guid>
      <description>&lt;h1&gt;
  
  
  Gravity Bridge Key Compromise Incident Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; May 30, 2026 (Publicly Disclosed June 1)&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Loss Amount:&lt;/strong&gt; ~$5.4M&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Attack Type:&lt;/strong&gt; Validator Signing Key Leak (Not Smart Contract Vulnerability)&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Team Suspended Operations&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;Gravity Bridge is a cross-chain protocol connecting Ethereum and Cosmos ecosystems. On May 30, 2026, attackers extracted approximately $5.4 million in digital assets using leaked validator signing keys.&lt;/p&gt;

&lt;p&gt;This is the fourth major cross-chain security incident in the first week of June 2026, once again highlighting the &lt;strong&gt;fatal risks of centralized signing key management&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Asset Loss Breakdown
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Asset Type&lt;/th&gt;
&lt;th&gt;Quantity&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;USDC&lt;/td&gt;
&lt;td&gt;~$4,300,000&lt;/td&gt;
&lt;td&gt;$4.3M&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WETH&lt;/td&gt;
&lt;td&gt;274 tokens&lt;/td&gt;
&lt;td&gt;~$553,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;USDT&lt;/td&gt;
&lt;td&gt;~$434,000&lt;/td&gt;
&lt;td&gt;$434K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PAXG&lt;/td&gt;
&lt;td&gt;14.16 tokens&lt;/td&gt;
&lt;td&gt;~$64,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;~$5,400,000&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attack Characteristics Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Key Findings
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Not Smart Contract Vulnerability&lt;/strong&gt;: On-chain analysts confirmed this was a &lt;strong&gt;validator signing key leak&lt;/strong&gt;, not a contract code issue&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bridge Operations Suspended&lt;/strong&gt;: Team has instructed all validators to stop running validators and coordinators&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Staggering TVL Ratio&lt;/strong&gt;: Pre-incident TVL was approximately $11.5M, with nearly half lost in this incident&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Fund Flow Tracking
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Stage&lt;/th&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attacker Retention&lt;/td&gt;
&lt;td&gt;~2,102 ETH (~$4.23M)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Money Laundering Channels&lt;/td&gt;
&lt;td&gt;ChangeNow, Binance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Timeline&lt;/td&gt;
&lt;td&gt;May 30 attack → June 1 public disclosure&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Cross-Chain Bridge Attack Trends: 2026 Data
&lt;/h2&gt;

&lt;p&gt;According to PeckShield statistics, 2026 has seen &lt;strong&gt;14 major cross-chain bridge attacks&lt;/strong&gt; with cumulative losses of &lt;strong&gt;$340.7M&lt;/strong&gt;:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Rank&lt;/th&gt;
&lt;th&gt;Project&lt;/th&gt;
&lt;th&gt;Amount&lt;/th&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;KelpDAO&lt;/td&gt;
&lt;td&gt;$293M&lt;/td&gt;
&lt;td&gt;April&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;Drift Protocol&lt;/td&gt;
&lt;td&gt;$285M&lt;/td&gt;
&lt;td&gt;April&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;DxSale&lt;/td&gt;
&lt;td&gt;$7.3M&lt;/td&gt;
&lt;td&gt;June&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;Gravity Bridge&lt;/td&gt;
&lt;td&gt;$5.4M&lt;/td&gt;
&lt;td&gt;May&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Alephium Bridge&lt;/td&gt;
&lt;td&gt;$815K&lt;/td&gt;
&lt;td&gt;May&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Gravity Bridge vs Other Bridge Attacks Comparison
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Dimension&lt;/th&gt;
&lt;th&gt;Gravity Bridge&lt;/th&gt;
&lt;th&gt;Typical Smart Contract Attack&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Vulnerability Type&lt;/td&gt;
&lt;td&gt;Key Leak&lt;/td&gt;
&lt;td&gt;Code Vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Method&lt;/td&gt;
&lt;td&gt;Traditional Security (HSM, MPC)&lt;/td&gt;
&lt;td&gt;Formal Verification, Code Audit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Responsible Party&lt;/td&gt;
&lt;td&gt;Centralized Operator&lt;/td&gt;
&lt;td&gt;Smart Contract Code&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact Scope&lt;/td&gt;
&lt;td&gt;Controllable (suspend operations)&lt;/td&gt;
&lt;td&gt;Difficult to modify after deployment&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Security Warnings
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Key Management is the Fatal Weakness of Cross-Chain
&lt;/h3&gt;

&lt;p&gt;Gravity Bridge incident proves:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;MPC/HSM is Not a Silver Bullet&lt;/strong&gt;: Even with multi-signature schemes, key management processes can still be compromised&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Insufficient Validator Decentralization&lt;/strong&gt;: "Validator signing keys" suggest relatively centralized signing mechanisms may exist&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;TVL and Security Mismatch&lt;/strong&gt;: $11.5M TVL supporting $5.4M in key assets creates disproportionate risk exposure&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  User Self-Protection Recommendations
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Be cautious when using bridges where bridge TVL &amp;gt; protocol TVL&lt;/li&gt;
&lt;li&gt;Do not store long-term held assets in bridge contracts&lt;/li&gt;
&lt;li&gt;Monitor protocol validator count and governance structure&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Sina Finance: &lt;a href="https://finance.sina.com.cn/stock/usstock/summary/2026-06-01/doc-inhzwpyp8549134.shtml" rel="noopener noreferrer"&gt;https://finance.sina.com.cn/stock/usstock/summary/2026-06-01/doc-inhzwpyp8549134.shtml&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Crypto Gazette: &lt;a href="https://cryptogazette.com/crypto-bridge-hacks-340-million-2026/" rel="noopener noreferrer"&gt;https://cryptogazette.com/crypto-bridge-hacks-340-million-2026/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Event Progress
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;✅ Team confirmed key leak (ruled out contract vulnerability)&lt;/li&gt;
&lt;li&gt;✅ All bridge operations suspended&lt;/li&gt;
&lt;li&gt;⚠️ Validators have stopped working&lt;/li&gt;
&lt;li&gt;⚠️ Asset tracking in progress, ChangeNow and Binance may assist with freezing&lt;/li&gt;
&lt;li&gt;❌ Full incident report not yet published&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>cosmos</category>
    </item>
    <item>
      <title>TesseraDao Security Incident - $2.5M USDT Lost</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:53:21 +0000</pubDate>
      <link>https://dev.to/qanzhi111/tesseradao-security-incident-25m-usdt-lost-813</link>
      <guid>https://dev.to/qanzhi111/tesseradao-security-incident-25m-usdt-lost-813</guid>
      <description>&lt;h1&gt;
  
  
  TesseraDAO Security Incident Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; June 2, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Loss Amount:&lt;/strong&gt; ~$2.5M USDT&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Project Team Unresponsive&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;On June 1, 2026, TesseraDAO was attacked on BNB Chain. The attacker minted approximately 99 million TSR tokens and quickly dumped them, causing the token price to crash 99%, dropping from normal price to approximately $0.0002. The project team has not released any official statement to date.&lt;/p&gt;




&lt;h2&gt;
  
  
  Attack Vector Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Attack Path
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Minting Phase&lt;/strong&gt;: Attacker minted 99,000,000 TSR tokens through the project's smart contract&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exchange Phase&lt;/strong&gt;: Swapped TSR for approximately 2.5 million USDT on decentralized exchanges&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-Chain Phase&lt;/strong&gt;: Bridged stolen funds from BNB Chain to Ethereum&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Money Laundering Phase&lt;/strong&gt;: Obfuscated 1,285.5 ETH transactions through Tornado Cash&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Technical Details
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Data&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attacker Address&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8&lt;/code&gt; (BSC)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Minted Token Amount&lt;/td&gt;
&lt;td&gt;99,000,000 TSR&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Illicit Gains&lt;/td&gt;
&lt;td&gt;~2,500,000 USDT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tornado Cash Laundering&lt;/td&gt;
&lt;td&gt;1,285.5 ETH&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Key Suspicion: Likely Rug Pull
&lt;/h2&gt;

&lt;p&gt;On-chain analysts strongly suspect this was not an external hack but &lt;strong&gt;insider involvement or privilege abuse&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Minting privileges and MultiTransfer functionality are exclusively controlled by deployer-related addresses&lt;/li&gt;
&lt;li&gt;Attacker address has connections to the project deployer&lt;/li&gt;
&lt;li&gt;Project team remains silent—a typical Rug Pull characteristic&lt;/li&gt;
&lt;li&gt;Not discovered and publicly disclosed by security firms until 19 hours later&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  2026 BNB Chain Attack Pattern Comparison
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Project&lt;/th&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Loss&lt;/th&gt;
&lt;th&gt;Pattern&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DxSale&lt;/td&gt;
&lt;td&gt;Early June&lt;/td&gt;
&lt;td&gt;$7.3M&lt;/td&gt;
&lt;td&gt;Legacy architecture + ownership transfer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TesseraDAO&lt;/td&gt;
&lt;td&gt;June 2&lt;/td&gt;
&lt;td&gt;$2.5M&lt;/td&gt;
&lt;td&gt;Mint+dump+suspected insider&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Specter&lt;/td&gt;
&lt;td&gt;May&lt;/td&gt;
&lt;td&gt;~$2M&lt;/td&gt;
&lt;td&gt;Token contract vulnerability&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;PeckShieldAlert: &lt;a href="https://x.com/PeckShieldAlert/status/2061713210210988434" rel="noopener noreferrer"&gt;https://x.com/PeckShieldAlert/status/2061713210210988434&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;CryptoCompass: &lt;a href="https://cryptocompass.com/articles/tesseradao-hack-drains-2-5-million-as-tsr-token-crashes-nearly-99-on-bnb-chain" rel="noopener noreferrer"&gt;https://cryptocompass.com/articles/tesseradao-hack-drains-2-5-million-as-tsr-token-crashes-nearly-99-on-bnb-chain&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;BSCScan: &lt;a href="https://bscscan.com/address/0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8" rel="noopener noreferrer"&gt;https://bscscan.com/address/0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Risk Warnings
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Beware of "Centralized Mint Authority"&lt;/strong&gt;: If projects retain single-point minting capability, user funds are never safe&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pay Attention to Project Silence&lt;/strong&gt;: Projects that don't respond after an attack are often心虚 (guilty) Rug Pulls&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DeFi Security Requires Systematic Auditing&lt;/strong&gt;: Pre-launch audits alone are insufficient for long-term security&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>dao</category>
    </item>
    <item>
      <title>DxSale Legacy Vulnerability - $7.3M Loss 1400+ Victims</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:47:06 +0000</pubDate>
      <link>https://dev.to/qanzhi111/dxsale-legacy-vulnerability-73m-loss-1400-victims-25p9</link>
      <guid>https://dev.to/qanzhi111/dxsale-legacy-vulnerability-73m-loss-1400-victims-25p9</guid>
      <description>&lt;h1&gt;
  
  
  DxSale Legacy Architecture Vulnerability Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; June 2, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Loss Amount:&lt;/strong&gt; ~$7.3M&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Affected Users:&lt;/strong&gt; 1,400+ Liquidity Providers&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Status:&lt;/strong&gt; Team Blaming BSC New Features&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;In early June 2026, DxSale—a DeFi Launchpad project—suffered an attack on its legacy liquidity vault (deployed in 2021), with approximately $7.3 million drained from over 1,400 locked liquidity pools.&lt;/p&gt;

&lt;p&gt;This is a classic case of &lt;strong&gt;"Sleeping Vulnerability Awakening"&lt;/strong&gt;—code lying dormant for 3 years, becoming catastrophic once discovered.&lt;/p&gt;




&lt;h2&gt;
  
  
  Attack Vector Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Key Findings
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Legacy Architecture&lt;/strong&gt;: First-generation vault from 2021 was never properly audited or deprecated&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ownership Transfer&lt;/strong&gt;: Contract ownership was secretly transferred &lt;strong&gt;269 days ago&lt;/strong&gt;, never publicly announced by the team&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fee-Modification Abuse&lt;/strong&gt;: Administrators can use the fee modification mechanism to convert "locked" assets into withdrawable funds&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Fund Flow
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Stage&lt;/th&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attacker Address&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;0xC457...FA69&lt;/code&gt; (full address requires further investigation)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Main Fund Vaults&lt;/td&gt;
&lt;td&gt;Two wallets, each receiving ~$1.87M BNB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Money Laundering Channel&lt;/td&gt;
&lt;td&gt;Multiple deposits into Binance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Initial Gas Source&lt;/td&gt;
&lt;td&gt;Attacker obtained initial gas fees through &lt;strong&gt;Bybit&lt;/strong&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Team Response: The Blame Game
&lt;/h2&gt;

&lt;p&gt;DxSale Official Statement:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"The vulnerability only affects the first-generation vault from 2021, related to BSC's new atomic transaction feature. The new contracts are completely safe."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Problems with This Narrative
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Secretly transferred permissions 269 days ago, now blaming BSC's new features?&lt;/li&gt;
&lt;li&gt;If new contracts are safe, why was the old vault completely drained?&lt;/li&gt;
&lt;li&gt;"First Generation Vaults" were essentially a &lt;strong&gt;backdoor&lt;/strong&gt; planted by the team that was never cleaned up&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Legacy Architecture Risk Matrix
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vulnerability Type&lt;/th&gt;
&lt;th&gt;Impact&lt;/th&gt;
&lt;th&gt;Affected Architecture&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Fee-Modification Privilege Abuse&lt;/td&gt;
&lt;td&gt;Locked assets can be arbitrarily withdrawn&lt;/td&gt;
&lt;td&gt;First Generation Vaults (2021)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Atomic Transaction Manipulation&lt;/td&gt;
&lt;td&gt;Cross-chain execution exploited&lt;/td&gt;
&lt;td&gt;BSC Interface&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Secret Ownership Transfer&lt;/td&gt;
&lt;td&gt;Permission chain tracking difficult&lt;/td&gt;
&lt;td&gt;All Historical Contracts&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Community Response
&lt;/h2&gt;

&lt;p&gt;Blockchain analyst Tahax discovered:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Malicious wallet only appeared shortly before the attack&lt;/li&gt;
&lt;li&gt;Attacker obtained gas fees through Bybit deposit&lt;/li&gt;
&lt;li&gt;Some funds passed through obfuscation infrastructure&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Coinsult Analysis Conclusion:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Fee-Modification mechanism + Legacy Asset Locking Function = Lethal Combination"&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  2026 DeFi Security Data
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Month&lt;/th&gt;
&lt;th&gt;Attack Count&lt;/th&gt;
&lt;th&gt;Loss Amount&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;April&lt;/td&gt;
&lt;td&gt;~30&lt;/td&gt;
&lt;td&gt;$634M (Annual High)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;May&lt;/td&gt;
&lt;td&gt;~60&lt;/td&gt;
&lt;td&gt;$59M&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Early June&lt;/td&gt;
&lt;td&gt;Ongoing&lt;/td&gt;
&lt;td&gt;Multiple &amp;gt; $1M&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;PeckShieldAlert: &lt;a href="https://x.com/PeckShieldAlert/status/2060188553079054351" rel="noopener noreferrer"&gt;https://x.com/PeckShieldAlert/status/2060188553079054351&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Tahax Analysis: &lt;a href="https://x.com/Tahax1/status/2060003698651087205" rel="noopener noreferrer"&gt;https://x.com/Tahax1/status/2060003698651087205&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Coinsult: &lt;a href="https://x.com/CoinsultAudits/status/2060015934153146757" rel="noopener noreferrer"&gt;https://x.com/CoinsultAudits/status/2060015934153146757&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;DxSale Response: &lt;a href="https://x.com/dxsale/status/2060739439744237912" rel="noopener noreferrer"&gt;https://x.com/dxsale/status/2060739439744237912&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Meterpreter Analysis: &lt;a href="https://meterpreter.org/dxsale-liquidity-pool-exploit/" rel="noopener noreferrer"&gt;https://meterpreter.org/dxsale-liquidity-pool-exploit/&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Risk Warnings
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;2021 Code = Time Bomb&lt;/strong&gt;: Features considered "innovative" at the time may now be vulnerabilities&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Regular Audits&lt;/strong&gt;: Projects need continuous monitoring after launch, especially legacy contracts&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Permission Transparency&lt;/strong&gt;: Ownership transfers must publicly notify the community&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Locked ≠ Safe&lt;/strong&gt;: If "lockup" functionality has admin backdoors, there's no actual lock&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
    </item>
    <item>
      <title>WUSD.fi GLOVE Sybil Farming Attack - $207K Onchain</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:46:01 +0000</pubDate>
      <link>https://dev.to/qanzhi111/wusdfi-glove-sybil-farming-attack-207k-onchain-45k1</link>
      <guid>https://dev.to/qanzhi111/wusdfi-glove-sybil-farming-attack-207k-onchain-45k1</guid>
      <description>&lt;h1&gt;
  
  
  WUSD.fi GLOVE Sybil Farming Attack - Onchain Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Report Date&lt;/strong&gt;: May 28, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Event Type&lt;/strong&gt;: Sybil Farming Attack&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Loss Amount&lt;/strong&gt;: ~$207,000 USD&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Attack Time&lt;/strong&gt;: May 25, 2026 06:07 UTC&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Affected Chain&lt;/strong&gt;: Ethereum Mainnet&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Starting Block&lt;/strong&gt;: 25,170,426&lt;/p&gt;


&lt;h2&gt;
  
  
  I. Executive Summary
&lt;/h2&gt;

&lt;p&gt;On May 25, 2026, the WUSD.fi protocol suffered a meticulously planned Sybil farming attack. The attacker exploited a design flaw in the protocol's reward mechanism, using EIP-7702 technology to batch-create wallet addresses for farming GLOVE token rewards, ultimately stealing approximately $207,000 from Uniswap V3 liquidity pools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Findings&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;This is the &lt;strong&gt;first large-scale attack using EIP-7702&lt;/strong&gt;, marking the maturation of a new attack technique&lt;/li&gt;
&lt;li&gt;The core vulnerability lies in the lack of Sybil resistance mechanism in the &lt;code&gt;WUSD._englove()&lt;/code&gt; function&lt;/li&gt;
&lt;li&gt;The attacker converted funds to 98 ETH and transferred them to the Railgun privacy protocol to increase tracing difficulty&lt;/li&gt;
&lt;li&gt;As of the report date, the WUSD.fi team has not issued any official statement&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;
  
  
  II. Event Overview
&lt;/h2&gt;
&lt;h3&gt;
  
  
  2.1 Project Background
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Project Information&lt;/th&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Project Name&lt;/td&gt;
&lt;td&gt;WUSD.fi / GLOVE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Token Type&lt;/td&gt;
&lt;td&gt;ERC-20 (WUSD, GLOVE)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deployment Network&lt;/td&gt;
&lt;td&gt;Ethereum Mainnet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol Type&lt;/td&gt;
&lt;td&gt;Stablecoin Wrapper Protocol + Incentive Reward System&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLOVE Utility&lt;/td&gt;
&lt;td&gt;Protocol incentive token, distributed via wrap fee buybacks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Core Mechanism&lt;/td&gt;
&lt;td&gt;WUSD._englove() + Glove.mintCreditless()&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;GLOVE Token Economics&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;WUSD protocol charges 1% fee on each wrap operation&lt;/li&gt;
&lt;li&gt;Fee revenue is used to purchase GLOVE tokens on the open market&lt;/li&gt;
&lt;li&gt;GLOVE is distributed as rewards to protocol participants&lt;/li&gt;
&lt;li&gt;GLOVE has a "utility credit" system where users must accumulate internal credits to sell GLOVE holdings&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;
  
  
  2.2 Attacker Profile
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Attribute&lt;/th&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Main EOA Address&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x88329A09428778F62BC0C8BAac0997864E5a57f8&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDC Pool Extraction Address&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xB89F65D6c7d33A35Da7C01934e310a6f40E18A1f&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDT Pool Extraction Address&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xa2Bd1A142ff49131B8CC70A332bdA0125018c324&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operation Mode&lt;/td&gt;
&lt;td&gt;Automated batch operations, EIP-7702 contract-driven&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Current Fund Status&lt;/td&gt;
&lt;td&gt;Converted to 98 ETH, deposited in Railgun&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;


&lt;h2&gt;
  
  
  III. Vulnerability Analysis
&lt;/h2&gt;
&lt;h3&gt;
  
  
  3.1 Vulnerability Mechanism: WUSD._englove() Design Flaw
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Vulnerable Code Logic&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Condition 1: Wallet is a fresh wallet (new wallet)
Condition 2: wrap ≥ 100 WUSD
Condition 3: Holdings &amp;lt; 2 GLOVE
→ Can call Glove.mintCreditless() to receive 2 GLOVE
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Triple Absence&lt;/strong&gt;:&lt;br&gt;
| Protection Measure | Status |&lt;br&gt;
|-------------------|--------|&lt;br&gt;
| Identity Check | ❌ Missing |&lt;br&gt;
| Rate Limit | ❌ Missing |&lt;br&gt;
| Sybil Detection | ❌ Missing |&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Attack Viability&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Any new wallet address meeting the conditions can claim 2 GLOVE tokens&lt;/li&gt;
&lt;li&gt;Attackers can farm rewards infinitely by batch-creating addresses&lt;/li&gt;
&lt;li&gt;The contract code logic is completely correct, but the economic incentive design has fundamental flaws&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;
  
  
  3.2 Deep Analysis of EIP-7702 Attack Mechanism
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What is EIP-7702&lt;/strong&gt;:&lt;br&gt;
EIP-7702 is a new feature introduced in the Ethereum Pectra upgrade, allowing Externally Owned Accounts (EOAs) to &lt;strong&gt;temporarily delegate execution rights to smart contracts&lt;/strong&gt;, enabling regular wallets to operate as contracts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Role in the Attack&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Traditional Method: Each new wallet address creation requires:
                   1. Generate private key
                   2. Deploy wallet contract (or use EOA)
                   3. Fund transfer
                   4. Contract call
                   → High cost and low efficiency per operation

EIP-7702 Method:
                   1. Deploy single helper contract
                   2. Batch-delegate multiple EOA addresses via EIP-7702
                   3. Automated execution of all operations within the contract
                   → Significantly reduces batch operation costs, enabling scalable attacks
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Technical Breakthrough&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The attacker only needed to deploy one EIP-7702 helper contract&lt;/li&gt;
&lt;li&gt;This contract could delegate unlimited EOA addresses to execute smart contract logic&lt;/li&gt;
&lt;li&gt;Each delegated address appeared as a "fresh wallet" to the protocol&lt;/li&gt;
&lt;li&gt;Achieved &lt;strong&gt;single contract, multiple addresses, large-scale&lt;/strong&gt; Sybil farming attack&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;EIP-7702 Security Warning&lt;/strong&gt;:&lt;br&gt;
This is another case of EIP-7702 being used for malicious purposes since the Pectra upgrade in May 2025. Phishing attacks had previously exploited this technology, resulting in $1.54M in losses.&lt;/p&gt;


&lt;h2&gt;
  
  
  IV. Attack Path Reconstruction
&lt;/h2&gt;
&lt;h3&gt;
  
  
  4.1 Complete Attack Flowchart
&lt;/h3&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;┌─────────────────────────────────────────────────────────────────────┐
│                         MORPHO USDT FLASH LOAN                       │
│                           ($100,000+ USDT)                          │
└──────────────────────────────┬──────────────────────────────────────┘
                               │
                               ▼
┌─────────────────────────────────────────────────────────────────────┐
│                    Deploy EIP-7702 Helper Contract                   │
│               Contract address temporarily gains                      │
│               smart contract execution capability                    │
└──────────────────────────────┬──────────────────────────────────────┘
                               │
                               ▼
┌─────────────────────────────────────────────────────────────────────┐
│                     Batch Create Fresh Wallet Cluster               │
│                    (Hundreds to thousands of new addresses)          │
└──────────────────────────────┬──────────────────────────────────────┘
                               │
              ┌────────────────┼────────────────┐
              ▼                ▼                ▼
        ┌──────────┐    ┌──────────┐     ┌──────────┐
        │Wallet #1 │    │Wallet #2 │     │Wallet #N │
        │ wrap 100 │    │ wrap 100 │     │ wrap 100 │
        │   WUSD   │    │   WUSD   │     │   WUSD   │
        └────┬─────┘    └────┬─────┘     └────┬─────┘
             │               │               │
             ▼               ▼               ▼
        ┌─────────────────────────────────────────┐
        │       Call Glove.mintCreditless()        │
        │         Each address claims 2 GLOVE      │
        └─────────────────────────────────────────┘
                               │
                               ▼
        ┌─────────────────────────────────────────┐
        │          Batch Dump GLOVE to             │
        │          Uniswap V3 Liquidity Pools      │
        │  (GLO-USDC Pool + GLO-USDT Pool)         │
        └─────────────────────────────────────────┘
                               │
              ┌────────────────┼────────────────┐
              ▼                ▼                ▼
        ┌──────────┐    ┌──────────┐     ┌──────────┐
        │-11,702   │    │ -8,079   │     │  Profit  │
        │  USDC    │    │  USDT    │     │ Aggregation
        └──────────┘    └──────────┘     └────┬─────┘
                                               │
                                               ▼
                                      ┌─────────────────┐
                                      │   Repay Morpho  │
                                      │   Flash Loan    │
                                      └─────────────────┘
                                               │
                                               ▼
                                      ┌─────────────────┐
                                      │   Convert to ETH│
                                      │   (~98 ETH)     │
                                      └─────────────────┘
                                               │
                                               ▼
                                      ┌─────────────────┐
                                      │    Railgun      │
                                      │  (Privacy)      │
                                      └─────────────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h3&gt;
  
  
  4.2 Detailed Timeline
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time (UTC)&lt;/th&gt;
&lt;th&gt;Block Height&lt;/th&gt;
&lt;th&gt;Event Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;06:07:59&lt;/td&gt;
&lt;td&gt;25,170,426&lt;/td&gt;
&lt;td&gt;Attacker initiates first Morpho USDT flash loan&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:08-06:15&lt;/td&gt;
&lt;td&gt;~25,170,426-&lt;/td&gt;
&lt;td&gt;EIP-7702 contract deployment, batch wallet creation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:08-06:15&lt;/td&gt;
&lt;td&gt;~25,170,426-&lt;/td&gt;
&lt;td&gt;Loop wrap/unwrap operations, mass mintCreditless calls&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:08-06:15&lt;/td&gt;
&lt;td&gt;~25,170,426-&lt;/td&gt;
&lt;td&gt;GLOVE tokens batch minted and sold&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:08-06:15&lt;/td&gt;
&lt;td&gt;~25,170,426-&lt;/td&gt;
&lt;td&gt;GLO-USDC pool loses 11,702 USDC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:08-06:15&lt;/td&gt;
&lt;td&gt;~25,170,426-&lt;/td&gt;
&lt;td&gt;GLO-USDT pool loses 8,079 USDT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:15&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;Repay Morpho flash loan principal + interest&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:15&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;Profit aggregation to attacker main address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:15&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;Converted to ~98 ETH&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;06:54:52&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;ExVul security researcher first public warning&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;08:38:05&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;PeckShield confirms attack, publishes complete analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;08:38+&lt;/td&gt;
&lt;td&gt;~&lt;/td&gt;
&lt;td&gt;98 ETH transferred to Railgun privacy protocol&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;h3&gt;
  
  
  4.3 Fund Flow Tracking
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Initial Fund Source&lt;/strong&gt;:&lt;br&gt;
| Source | Amount | Nature |&lt;br&gt;
|--------|--------|--------|&lt;br&gt;
| Morpho USDT Flash Loan | $100,000+ | Flash loan (repaid within single transaction) |&lt;br&gt;
| Attacker Own Funds | Small amount of ETH | Initial Gas fees |&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lost Asset Details&lt;/strong&gt;:&lt;br&gt;
| Asset | Amount | Source Pool | Extraction Address |&lt;br&gt;
|-------|--------|-------------|-------------------|&lt;br&gt;
| USDC | 11,702.083968 | Uniswap V3 GLO-USDC | &lt;code&gt;0xB89F65D6c7d33A35Da7C01934e310a6f40E18A1f&lt;/code&gt; |&lt;br&gt;
| USDT | 8,079.161526 | Uniswap V3 GLO-USDT | &lt;code&gt;0xa2Bd1A142ff49131B8CC70A332bdA0125018c324&lt;/code&gt; |&lt;br&gt;
| &lt;strong&gt;Total&lt;/strong&gt; | &lt;strong&gt;~19,781.24&lt;/strong&gt; | Stablecoin Value | - |&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Fund Aggregation and Mixing&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;GLO-USDC Pool Extraction Address ─┐
                                   ├──▶ Attacker Main EOA ──▶ Convert to 98 ETH ──▶ Railgun
GLO-USDT Pool Extraction Address ─┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Railgun Transfer Records&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Amount: ~98 ETH (worth approximately $207,000)&lt;/li&gt;
&lt;li&gt;Time: Shortly after PeckShield confirmation&lt;/li&gt;
&lt;li&gt;Purpose: Anonymize transactions via zero-knowledge proofs, sever chain tracking&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  V. Sybil Wallet Network Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  5.1 Attack Scale Estimation
&lt;/h3&gt;

&lt;p&gt;Based on attack revenue and single reward (2 GLOVE) estimation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Total Loss ≈ $207,000
Single Wrap Fee ≈ 1% × 100 WUSD = 1 WUSD ≈ $1
Per Cycle Cost ≈ gas fees + wrap fee
Per Cycle Revenue ≈ 2 GLOVE × GLOVE price

Conservative estimate: Hundreds to thousands of Fresh Wallet addresses involved
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  5.2 Wallet Cluster Characteristics
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Characteristic&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Address Type&lt;/td&gt;
&lt;td&gt;EIP-7702 Delegated EOA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Creation Time&lt;/td&gt;
&lt;td&gt;Within attack window (~06:07-06:15 UTC)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lifecycle&lt;/td&gt;
&lt;td&gt;Single-use (abandoned after attack)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLOVE Holdings&lt;/td&gt;
&lt;td&gt;All sold after attack&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Correlation&lt;/td&gt;
&lt;td&gt;Shared same EIP-7702 helper contract&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  5.3 EIP-7702 Contract Address
&lt;/h3&gt;

&lt;p&gt;Based on public onchain analysis, the attacker's deployed EIP-7702 helper contract:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Function: Batch management of delegated EOA addresses&lt;/li&gt;
&lt;li&gt;Permissions: Temporarily obtained EOA execution rights&lt;/li&gt;
&lt;li&gt;Status: Possibly abandoned or destroyed after attack&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  VI. Flash Loan Path Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  6.1 Morpho USDT Flash Loan Mechanism
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Morpho Protocol Features&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Optimization lending market based on Aave V3&lt;/li&gt;
&lt;li&gt;Supports flash loans, no collateral required&lt;/li&gt;
&lt;li&gt;Atomic transaction guarantee&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Flash Loan Workflow&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. Attack contract borrows USDT from Morpho
         ↓
2. Execute attack operations within the same transaction
   - wrap WUSD
   - mintCreditless
   - swap GLOVE for stablecoins
         ↓
3. Repay USDT principal + fees
         ↓
4. Transaction succeeds, profit goes to attacker
   OR
   Transaction fails/rolls back, Morpho funds untouched
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  6.2 Complete Attack-Repayment Path
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Step&lt;/th&gt;
&lt;th&gt;Operation&lt;/th&gt;
&lt;th&gt;Amount&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Borrow Morpho USDT&lt;/td&gt;
&lt;td&gt;+$100,000+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;wrap WUSD (loop N times)&lt;/td&gt;
&lt;td&gt;-$N WUSD&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;mintCreditless (loop N times)&lt;/td&gt;
&lt;td&gt;+2N GLOVE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;swap GLOVE → USDC/USDT&lt;/td&gt;
&lt;td&gt;Sell all GLOVE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Extract liquidity from GLO pools&lt;/td&gt;
&lt;td&gt;+$207,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;Repay Morpho USDT + fee&lt;/td&gt;
&lt;td&gt;-$100,000+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;Net profit aggregation&lt;/td&gt;
&lt;td&gt;+$207,000-$100,000&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  VII. GLOVE Token Economic Impact
&lt;/h2&gt;

&lt;h3&gt;
  
  
  7.1 Immediate Market Impact
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Impact Dimension&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Price Impact&lt;/td&gt;
&lt;td&gt;GLOVE token price pressured by massive selling&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Liquidity Impact&lt;/td&gt;
&lt;td&gt;GLO-USDC and GLO-USDT pool liquidity significantly decreased&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;LP Loss&lt;/td&gt;
&lt;td&gt;Liquidity provider positions damaged by impermanent loss + pool draining&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol Trust&lt;/td&gt;
&lt;td&gt;Reward mechanism vulnerability exposed, protocol credibility damaged&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  7.2 Long-term Token Economics Impact
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Assessment&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;GLOVE Token Price&lt;/td&gt;
&lt;td&gt;Faces selling pressure short-term, depends on protocol fix long-term&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol TVL&lt;/td&gt;
&lt;td&gt;Liquidity providers may withdraw funds&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Incentive Mechanism&lt;/td&gt;
&lt;td&gt;Requires redesign with Sybil resistance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Community Trust&lt;/td&gt;
&lt;td&gt;WUSD.fi non-responsive as of report date affects trust recovery&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  7.3 Industry Trend Correlation
&lt;/h3&gt;

&lt;p&gt;2026 DeFi Security Landscape:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;As of report date, DeFi exploit cumulative losses: ~$770M+&lt;/li&gt;
&lt;li&gt;May became a high-incident period for liquidity layer attacks&lt;/li&gt;
&lt;li&gt;Incentive paths and internal accounting becoming new attack vectors&lt;/li&gt;
&lt;li&gt;Traditional code audits cannot cover economic incentive design flaws&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  VIII. Security Warnings and Recommendations
&lt;/h2&gt;

&lt;h3&gt;
  
  
  8.1 Vulnerability Root Cause Summary
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Dimension&lt;/th&gt;
&lt;th&gt;Issue&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Code Level&lt;/td&gt;
&lt;td&gt;Contract logic correct, no typical vulnerabilities&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Design Level&lt;/td&gt;
&lt;td&gt;WUSD._englove() lacks Sybil resistance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Economic Level&lt;/td&gt;
&lt;td&gt;mintCreditless has no frequency limit/identity verification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit Level&lt;/td&gt;
&lt;td&gt;Routine audits don't test economic incentive paths&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  8.2 Protocol Security Recommendations
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Immediate Actions&lt;/strong&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Pause Glove.mintCreditless() functionality&lt;/li&gt;
&lt;li&gt;Implement wallet history correlation detection&lt;/li&gt;
&lt;li&gt;Add per-address claim frequency limits&lt;/li&gt;
&lt;li&gt;Introduce onchain identity verification (e.g., WorldID)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Long-term Improvements&lt;/strong&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Economic incentive design requires special audits&lt;/li&gt;
&lt;li&gt;Introduce TWAP price oracle to prevent flash loan manipulation&lt;/li&gt;
&lt;li&gt;Establish real-time anomaly monitoring and alerting system&lt;/li&gt;
&lt;li&gt;Consider decentralized emergency pause mechanism&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  8.3 User Risk Warnings
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Risk Type&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;LP Risk&lt;/td&gt;
&lt;td&gt;Liquidity providers in attacked pools lost assets&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exposure Risk&lt;/td&gt;
&lt;td&gt;Users holding GLOVE tokens face selling pressure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Trust Risk&lt;/td&gt;
&lt;td&gt;Protocol non-response may indicate Rug Pull&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Recovery Risk&lt;/td&gt;
&lt;td&gt;Funds have entered Railgun, recovery extremely unlikely&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  IX. Evidence Sources
&lt;/h2&gt;

&lt;h3&gt;
  
  
  9.1 Onchain Data Sources
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;th&gt;Link/Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Etherscan&lt;/td&gt;
&lt;td&gt;API Key: 2WASDAKWI6H5S1HJNS4V4RYZNBHW2QUCFA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PeckShield Alert&lt;/td&gt;
&lt;td&gt;&lt;a href="https://twitter.com/PeckShieldAlert" rel="noopener noreferrer"&gt;https://twitter.com/PeckShieldAlert&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ExVul Research&lt;/td&gt;
&lt;td&gt;&lt;a href="https://twitter.com/ExVul_" rel="noopener noreferrer"&gt;https://twitter.com/ExVul_&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lookonchain&lt;/td&gt;
&lt;td&gt;&lt;a href="https://m.lookonchain.com/feeds/57616" rel="noopener noreferrer"&gt;https://m.lookonchain.com/feeds/57616&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  9.2 Security Company Confirmations
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Company&lt;/th&gt;
&lt;th&gt;Status&lt;/th&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ExVul&lt;/td&gt;
&lt;td&gt;First public warning&lt;/td&gt;
&lt;td&gt;X/Twitter&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PeckShield&lt;/td&gt;
&lt;td&gt;Confirmed and tracking&lt;/td&gt;
&lt;td&gt;X/Twitter Alert&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SlowMist&lt;/td&gt;
&lt;td&gt;Added to hack database&lt;/td&gt;
&lt;td&gt;Hack Archives&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  9.3 News Sources
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;th&gt;Link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Live Bitcoin News&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.livebitcoinnews.com/wusd-fi-sybil-farming-attack-drains-200k-from-glove-pools/" rel="noopener noreferrer"&gt;https://www.livebitcoinnews.com/wusd-fi-sybil-farming-attack-drains-200k-from-glove-pools/&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CoinAlert News&lt;/td&gt;
&lt;td&gt;&lt;a href="https://coinalertnews.com/news/2026/05/27/defi-exploits-glove-stakedao" rel="noopener noreferrer"&gt;https://coinalertnews.com/news/2026/05/27/defi-exploits-glove-stakedao&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CoinFi&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.coinfi.com/news/1812793/wusdfi-sybil-farming-attack-drains-200k-from-glove-pools" rel="noopener noreferrer"&gt;https://www.coinfi.com/news/1812793/wusdfi-sybil-farming-attack-drains-200k-from-glove-pools&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Crypto Adventure&lt;/td&gt;
&lt;td&gt;&lt;a href="https://coinstats.app/news/21f76ad1f0bcf1a49e26ef5b33f5a896986db9aaaef63be7d0f8ca08f952adc1_WUSDGLOVE-Exploit-Drains-207K-Before-Funds-Move-Into-Railgun" rel="noopener noreferrer"&gt;https://coinstats.app/news/21f76ad1f0bcf1a49e26ef5b33f5a896986db9aaaef63be7d0f8ca08f952adc1_WUSDGLOVE-Exploit-Drains-207K-Before-Funds-Move-Into-Railgun&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OurCryptoTalk&lt;/td&gt;
&lt;td&gt;&lt;a href="https://ourcryptotalk.com/news/glove-exploit-wusd-fi-200k-sybil-attack" rel="noopener noreferrer"&gt;https://ourcryptotalk.com/news/glove-exploit-wusd-fi-200k-sybil-attack&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  X. Appendices
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Appendix A: Key Address Summary
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Address Purpose&lt;/th&gt;
&lt;th&gt;Address&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attacker Main EOA&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x88329A09428778F62BC0C8BAac0997864E5a57f8&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDC Pool Extraction&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xB89F65D6c7d33A35Da7C01934e310a6f40E18A1f&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDT Pool Extraction&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xa2Bd1A142ff49131B8CC70A332bdA0125018c324&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Target Contract&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x068e3563b1c19590f822c0e13445c4fa1b9eefa5&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Appendix B: Attack Statistics
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attack Duration&lt;/td&gt;
&lt;td&gt;~8 minutes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Attack Block Range&lt;/td&gt;
&lt;td&gt;25,170,426+&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDC Pool Loss&lt;/td&gt;
&lt;td&gt;11,702.083968 USDC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GLO-USDT Pool Loss&lt;/td&gt;
&lt;td&gt;8,079.161526 USDT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Total Stablecoin Loss&lt;/td&gt;
&lt;td&gt;~19,781.24&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ETH Equivalent&lt;/td&gt;
&lt;td&gt;~98 ETH&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Final Loss&lt;/td&gt;
&lt;td&gt;~$207,000&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: This report is based on publicly available on-chain data and third-party sources for informational purposes only. The analysis and recommendations in this report should not be construed as legal or investment advice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Report Generation Date&lt;/strong&gt;: May 28, 2026&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>defi</category>
    </item>
    <item>
      <title>Fake Uniswap Google Ads Phishing - $400K+ Stolen</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:35:46 +0000</pubDate>
      <link>https://dev.to/qanzhi111/fake-uniswap-google-ads-phishing-400k-stolen-34on</link>
      <guid>https://dev.to/qanzhi111/fake-uniswap-google-ads-phishing-400k-stolen-34on</guid>
      <description>&lt;h1&gt;
  
  
  Fake Uniswap Google Ads Phishing Scam Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Investigation Date&lt;/strong&gt;: May 26, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Incident Type&lt;/strong&gt;: Google Ads Phishing Scam&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Loss Amount&lt;/strong&gt;: $400,000+&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Attacker Wallets&lt;/strong&gt;: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;0x37925684BA178821b4436E06e67f5dBD6cfA49Bb&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📋 Executive Summary
&lt;/h2&gt;

&lt;p&gt;On May 25, 2026, on-chain analyst b_block discovered that attackers were purchasing Google sponsored advertisements to impersonate the official Uniswap website, luring users to connect their wallets and sign malicious transactions, thereby stealing user assets.&lt;/p&gt;

&lt;p&gt;As of this report, the two attacker wallets collectively hold approximately 146 ETH (valued at approximately $306,000 at the time), with total losses exceeding $400,000.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔍 Attack Vector Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Attack Flow
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Ad Placement&lt;/strong&gt;: Attackers purchased sponsored ads for "Uniswap" keyword on Google Search platform&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Phishing Website&lt;/strong&gt;: Users clicking the ad are directed to a meticulously crafted phishing website with an interface nearly identical to the official site&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malicious Authorization&lt;/strong&gt;: When users connect their wallet and sign transactions, they are actually granting access permissions to a malicious contract&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fund Transfer&lt;/strong&gt;: The drainer contract automatically transfers user assets to wallets controlled by the attacker&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Attack Tools
&lt;/h3&gt;

&lt;p&gt;Security researchers identified that the phishing website utilized the &lt;strong&gt;AngelFerno drainer&lt;/strong&gt; tool, a Phishing-as-a-Service (PhaaS) malware.&lt;/p&gt;

&lt;p&gt;Attackers also employed the following techniques to evade detection:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Punycode URL&lt;/strong&gt;: Utilizing Cyrillic characters to make phishing domains visually indistinguishable from legitimate domains&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hidden iframe&lt;/strong&gt;: Loading malicious code while remaining invisible to Google's automated review systems&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Traffic Redirection&lt;/strong&gt;: Secretly routing all user network traffic to attacker-controlled servers&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Attacker Infrastructure
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Phishing websites utilized Google trusted services (sites.google.com, docs.google.com) to bypass detection&lt;/li&gt;
&lt;li&gt;Advanced infrastructure including Cloudflare Workers, Arweave hosting for payloads, and proxy layers&lt;/li&gt;
&lt;li&gt;Capable of intercepting Ethereum RPC requests and monitoring user activity in real-time&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📊 Fund Flow Analysis
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Wallet Address&lt;/th&gt;
&lt;th&gt;Held Assets&lt;/th&gt;
&lt;th&gt;Estimated Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;0x37925684...A49Bb&lt;/td&gt;
&lt;td&gt;~73 ETH + tokens&lt;/td&gt;
&lt;td&gt;~$153,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;0x2fC25F46c...c5E2&lt;/td&gt;
&lt;td&gt;~73 ETH + tokens&lt;/td&gt;
&lt;td&gt;~$153,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;~146 ETH&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;~$306,000&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  ⚠️ Systemic Risk Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Google Ads Platform Responsibility
&lt;/h3&gt;

&lt;p&gt;According to Security Alliance (SEAL) reports:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;During March 2026, Google Ads phishing attacks stole approximately &lt;strong&gt;$1.27 million&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;SEAL blocks over &lt;strong&gt;356&lt;/strong&gt; malicious Google ad links weekly&lt;/li&gt;
&lt;li&gt;This attack pattern has persisted for over &lt;strong&gt;one year&lt;/strong&gt; with no signs of slowing&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Notable Victims
&lt;/h3&gt;

&lt;p&gt;Uniswap founder Hayden Adams has publicly criticized Google's failure to effectively combat counterfeit advertisements:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"These scams are absolutely terrible, and we have been fighting them for years. Counterfeit scam apps impersonating our Uniswap keep appearing, despite our continuous applications to the Apple App Store, which took months to get approved."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  FBI Data
&lt;/h3&gt;

&lt;p&gt;According to FBI's "2025 Internet Crime Report":&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cryptocurrency-related complaints: &lt;strong&gt;181,565&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Total losses: &lt;strong&gt;$11.36 billion&lt;/strong&gt; (22% year-over-year increase)&lt;/li&gt;
&lt;li&gt;Average loss per victim: &lt;strong&gt;$62,604&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🛡️ Community Protection Recommendations
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Bookmark Verification&lt;/strong&gt;: Manually bookmark DeFi platform URLs rather than relying on search&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Manual URL Entry&lt;/strong&gt;: Directly type official domain names into the browser&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verify Channels&lt;/strong&gt;: Use trusted aggregators like DeFiLlama to verify protocol information&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Regular Revocation&lt;/strong&gt;: Use revoke.cash to regularly clean up unnecessary token approvals&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hardware Wallet&lt;/strong&gt;: Use hardware wallets and carefully review each transaction&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ad Blocking&lt;/strong&gt;: Consider using ad-blocking plugins and anti-phishing browser extensions&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  📝 Unique Analytical Perspective
&lt;/h2&gt;

&lt;p&gt;This case reveals the &lt;strong&gt;contradiction between centralized platforms and decentralized finance&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;DeFi protocols themselves are secure&lt;/strong&gt;: Uniswap smart contracts have never been compromised&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The problem lies at the entry point&lt;/strong&gt;: Google search results have become accomplices for attackers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Irreversibility&lt;/strong&gt;: Blockchain transactions cannot be reversed; once malicious transactions are signed, funds cannot be recovered&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This differs fundamentally from traditional cybersecurity—users cannot "call customer service" or "request a refund," relying only on prevention rather than remediation.&lt;/p&gt;




&lt;h2&gt;
  
  
  📚 Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://x.com/b_block_oficial/status/2058874189164040664" rel="noopener noreferrer"&gt;b_block Original Alert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://x.com/stacy_muur/status/2058889644935442468" rel="noopener noreferrer"&gt;Stacy Muur Warning&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://radar.securityalliance.org/malicious-google-ads-targeting-crypto/" rel="noopener noreferrer"&gt;SEAL Malicious Google Ads Report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.coindesk.cc/scammers-steal-over-400k-through-fake-uniswap-ads-on-google-search-53675.html" rel="noopener noreferrer"&gt;CoinDesk Coverage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://beincrypto.com/fake-uniswap-drainer-400k-phishing/" rel="noopener noreferrer"&gt;BeInCrypto Coverage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;strong&gt;Investigator&lt;/strong&gt;: Onchain Shadow&lt;br&gt;&lt;br&gt;
&lt;strong&gt;OPSEC Statement&lt;/strong&gt;: This report is based on publicly available on-chain data and media reports, all information sourced from publicly available sources.&lt;/p&gt;

&lt;p&gt;Disclaimer: This report is based on publicly available on-chain data and media reports for security research purposes only.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>phishing</category>
    </item>
    <item>
      <title>StablR Stablecoin Hack - EURR/USDR Admin Key Attack</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:34:44 +0000</pubDate>
      <link>https://dev.to/qanzhi111/stablr-stablecoin-hack-eurrusdr-admin-key-attack-cgo</link>
      <guid>https://dev.to/qanzhi111/stablr-stablecoin-hack-eurrusdr-admin-key-attack-cgo</guid>
      <description>&lt;h1&gt;
  
  
  StablR Stablecoin Hack Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date&lt;/strong&gt;: May 27, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Event&lt;/strong&gt;: StablR EURR/USDR Stablecoin Admin Key Attack&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Attack Time&lt;/strong&gt;: May 24, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Investigator&lt;/strong&gt;: Onchain Shadow&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;MiCA-compliant stablecoin issuer StablR suffered a major security incident. Attackers compromised a 1-of-3 multisig private key, obtained minting permissions, and minted approximately $13.5 million in unbacked stablecoins (8.35M USDR + 4.5M EURR), cashing out approximately $2.8 million (1,115 ETH) through DEX dumping.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Core Irony&lt;/strong&gt;: StablR holds a Maltese Financial Regulator license, claims MiCA compliance, but minting permissions were protected by only a 1-of-3 multisig—one private key compromised and the entire system fell.&lt;/p&gt;




&lt;h2&gt;
  
  
  Key Metrics
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Fake Token Face Value&lt;/td&gt;
&lt;td&gt;~$13.5M (8.35M USDR + 4.5M EURR)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Actual Cash-Out Amount&lt;/td&gt;
&lt;td&gt;~$2.8M (1,115 ETH)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EURR Depeg Extent&lt;/td&gt;
&lt;td&gt;-23% ($1.15 → $0.88)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;USDR Depeg Extent&lt;/td&gt;
&lt;td&gt;-30% ($1.00 → $0.40 low)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Multisig Configuration&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;1-of-3&lt;/strong&gt; (one signature suffices)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Attack Duration&lt;/td&gt;
&lt;td&gt;&amp;gt;3 hours (slow team response)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attacker Addresses
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;th&gt;Address&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Primary Attack Wallet&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xD4677B5A8B1b97EA213Fdb876b0FcBAB3f9F6CD1&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Added as multisig owner, then executed minting&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Secondary Wallet&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x482aC1a69A41e7657DE6B420B7346FB09DA09115&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Replaced original compromised owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tertiary Wallet&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xbC631Daf86611f32FAA63E7EC8c9c9571F2F5BB3&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Replaced legitimate owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compromised Owner&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xC73fD562de86d7860EE636C20813Bcb2cF4D550d&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Private key stolen&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 1&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xea480c23d7b29a515856aafe0dc86f7519965a04&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Via CCTP/Noble deposit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x09BE1A36c2d7f9909eb3D6F9184c6e46A12B0ACA&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 3&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x6283558eB6948CA50A2bE942D98A41ca4d1Def40&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 4&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xf1f70d7461356f32b97ddc2cd54a490d4363340e&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x74b4621b82eb31c5fd9fbad5729bef1813e26dcf&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 6&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x8aaa93d06bf8de94c282f66a16effe6d9d94d038&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZachXBT Tagged Address 7&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x5D2184d84b82B67c1818Bbec8ce81E7Df14F6bAb&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Associated address&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Affected Contracts
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Contract&lt;/th&gt;
&lt;th&gt;Address&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;USDR Token&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x7B43E3875440B44613DC3bC08E7763e6Da63C8f8&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;EURR Token&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x50753CfAf86c094925Bf976f218D043f8791e408&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Multisig Wallet&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xF45392bd2D6e6b8C5Dc26BA6c8a12889419B82F3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Key Transaction Hashes
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Transaction&lt;/th&gt;
&lt;th&gt;Hash&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ownership Change 1&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0x1f8a6764f66bb5a2438dc62f89bfe52080dbca782444c3757dbf1e1ce3a11bec&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Attacker replaced legitimate owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ownership Change 2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xde5bc3b7b80576f894fbc7e2c8fea5f8829503bae75dcf30a27725cd95a05f16&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Attacker replaced original compromised owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Minting Transaction&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0xa720...24ed&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Minted USDR/EURR&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attack Timeline (UTC)
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Time&lt;/th&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Before 5/24&lt;/td&gt;
&lt;td&gt;Attacker deposited funds to wallet via CCTP/Noble&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/24 Attack Start&lt;/td&gt;
&lt;td&gt;Attacker used compromised private key to operate multisig&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 1&lt;/td&gt;
&lt;td&gt;Added &lt;code&gt;0xD467...6CD1&lt;/code&gt; as multisig new owner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 2&lt;/td&gt;
&lt;td&gt;Replaced legitimate owner &lt;code&gt;0xD4b6...aD40&lt;/code&gt; → &lt;code&gt;0xbC63...5BB3&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 3&lt;/td&gt;
&lt;td&gt;Replaced compromised owner &lt;code&gt;0xC73f...550d&lt;/code&gt; → &lt;code&gt;0x482a...9115&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 4&lt;/td&gt;
&lt;td&gt;Minted 8.35M USDR + 4.5M EURR via &lt;code&gt;0xD467...6CD1&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 5&lt;/td&gt;
&lt;td&gt;Dumped on Uniswap and other DEXs for ETH&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Step 6&lt;/td&gt;
&lt;td&gt;Used admin privileges to blacklist/burn 2.7M EURR from legitimate users&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3+ hours&lt;/td&gt;
&lt;td&gt;StablR team unresponsive; ZachXBT helped freeze 6-figure funds&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8 hours later&lt;/td&gt;
&lt;td&gt;Attack stopped; StablR issued statement&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Technical Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Root Cause: 1-of-3 Multisig = Single Point of Failure
&lt;/h3&gt;

&lt;p&gt;StablR's minting multisig was configured at &lt;strong&gt;1-of-3 threshold&lt;/strong&gt;, meaning any 1 of 3 signers could authorize transactions. This degraded the entire stablecoin system's security to a single private key.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Comparison&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Harmony Horizon Bridge (2022, $100M hack): At least 2-of-5&lt;/li&gt;
&lt;li&gt;Industry Standard: 2-of-3 or 3-of-5 + hardware wallets + geographic distribution&lt;/li&gt;
&lt;li&gt;StablR: &lt;strong&gt;1-of-3&lt;/strong&gt; — weaker than a bridge hacked two years ago&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Attack Method Breakdown
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Key Acquisition&lt;/strong&gt;: Attacker obtained private key of owner &lt;code&gt;0xC73f...550d&lt;/code&gt; (method undisclosed; possible phishing/malware/supply chain attack)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Permission Takeover&lt;/strong&gt;: Using 1-of-3 threshold, just one signature enabled:

&lt;ul&gt;
&lt;li&gt;Adding attacker address as new owner&lt;/li&gt;
&lt;li&gt;Removing legitimate owners&lt;/li&gt;
&lt;li&gt;Obtaining 100% multisig control&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Unlimited Minting&lt;/strong&gt;: Called mint function via compromised multisig&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DEX Cash-Out&lt;/strong&gt;: Dumped newly minted tokens on Uniswap and other DEXs; shallow liquidity pools resulted in significant discounts&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Countering Legitimate Users&lt;/strong&gt;: Used admin privileges to blacklist+burn legitimate user tokens, preventing redemption&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Why Only $2.8M Cash-Out from $13.5M Face Value?
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;USDR/EURR DEX liquidity pools extremely shallow (EURR market cap only $14M; USDR market cap $11M)&lt;/li&gt;
&lt;li&gt;Large dumps caused massive slippage&lt;/li&gt;
&lt;li&gt;Depeg triggered panic selling, further deteriorating prices&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Background &amp;amp; Impact
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Who is StablR?
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Malta-registered EMI (Electronic Money Institution) license holder&lt;/li&gt;
&lt;li&gt;Uses Tether's Hadron tokenization infrastructure&lt;/li&gt;
&lt;li&gt;Received Tether strategic investment in December 2024&lt;/li&gt;
&lt;li&gt;Received Kraken investment in July 2025&lt;/li&gt;
&lt;li&gt;Claims EURR/USDR trading volume exceeded €3 billion in H1 2025&lt;/li&gt;
&lt;li&gt;MiCA compliant; reserve funds held in segregated accounts&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2026 DeFi Attack Pattern Shift
&lt;/h3&gt;

&lt;p&gt;According to DefiLlama data:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;70%+ of 2026 large DeFi losses stem from key/management permission theft&lt;/strong&gt;, not smart contract vulnerabilities&lt;/li&gt;
&lt;li&gt;April single month lost $634 million across 28+ incidents, worst month on record&lt;/li&gt;
&lt;li&gt;LayerZero bridge exploits (18%), admin key theft (16%), fake tokens (14%), private key leaks (11%)&lt;/li&gt;
&lt;li&gt;This case belongs to the same attack pattern as Echo Protocol and Drift Protocol&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Irony of European Stablecoin Regulation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Attack occurred as ECB pushed for tighter euro stablecoin liquidity rules&lt;/li&gt;
&lt;li&gt;ECB President Lagarde just stated euro stablecoins pose potential financial stability risks&lt;/li&gt;
&lt;li&gt;EURR accounts for only 0.24% of Ethereum fiat stablecoin total&lt;/li&gt;
&lt;li&gt;MiCA compliance ≠ Technical Security&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Pending Deep Investigation Areas
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Attacker Identity Tracing&lt;/strong&gt;: Trace KYC information at CCTP/Noble deposit source&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Compromised Key Acquisition Method&lt;/strong&gt;: Phishing/insider/supply chain?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ZachXBT's 7 Tagged Associated Addresses&lt;/strong&gt;: Complete fund flow mapping&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Burned 2.7M EURR&lt;/strong&gt;: Whose assets were destroyed? Legal consequences?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tether/Kraken Investor Responsibility&lt;/strong&gt;: Did they conduct adequate technical due diligence?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fund Freeze Progress&lt;/strong&gt;: Was 6-figure freeze successful? Where did remaining funds go?&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://beincrypto.com/autopsy-of-the-echo-protocol-hack/" rel="noopener noreferrer"&gt;BeInCrypto - Echo Protocol Hack Autopsy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cointelegraph.com/news/scammers-make-400k-through-fake-uniswap-ads-on-google" rel="noopener noreferrer"&gt;Cointelegraph - StablR EURR USDR depeg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cryptocompass.com/articles/stablr-stablecoin-exploit-full-technical-analysis-of-the-13-5m-multisig-attack" rel="noopener noreferrer"&gt;CryptoCompass - StablR Technical Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cryptowisser.com/news/stablr-stablecoins-lose-peg-after-multisig-breach-mints-millions-in-unathorized-tokens/" rel="noopener noreferrer"&gt;CryptoWisser - StablR Stablecoins Lose Peg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blockonomi.com/zachxbt-flags-possible-10m-stablr-exploit-as-eurr-and-usdr-stablecoins-sink-20/" rel="noopener noreferrer"&gt;Blockonomi - ZachXBT Flags StablR Exploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ZachXBT Telegram/X posts (May 24, 2026)&lt;/li&gt;
&lt;li&gt;Blockaid real-time exploit detection&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;Investigator: Onchain Shadow&lt;/p&gt;

&lt;p&gt;Disclaimer: This report is based on publicly available on-chain data and media reports for security research purposes only.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>defi</category>
    </item>
    <item>
      <title>Echo Protocol eBTC Admin Key Attack Investigation</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:27:04 +0000</pubDate>
      <link>https://dev.to/qanzhi111/echo-protocol-ebtc-admin-key-attack-investigation-4oc7</link>
      <guid>https://dev.to/qanzhi111/echo-protocol-ebtc-admin-key-attack-investigation-4oc7</guid>
      <description>&lt;h1&gt;
  
  
  Echo Protocol eBTC Admin Key Attack Investigation Report
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Date&lt;/strong&gt;: May 27, 2026&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Event&lt;/strong&gt;: Echo Protocol eBTC Admin Key Attack&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Attack Time&lt;/strong&gt;: May 18, 2026 ~17:55 ET&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Investigator&lt;/strong&gt;: Onchain Shadow&lt;/p&gt;




&lt;h2&gt;
  
  
  Executive Summary
&lt;/h2&gt;

&lt;p&gt;BTCFi protocol Echo Protocol's eBTC deployment on Monad suffered an admin key attack. The attacker obtained DEFAULT_ADMIN_ROLE, self-granted MINTER_ROLE, minted 1,000 units of unbacked eBTC (face value $76.7M), and cashed out approximately $816K in real assets through Curvance lending protocol before laundering through Tornado Cash. Due to insufficient liquidity in Monad DeFi ecosystem, 955 eBTC remained illiquid and were ultimately destroyed by the Echo team.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Lesson&lt;/strong&gt;: A $254M+ TVL protocol with management permissions tied to a single EOA private key—one key is the entire line of defense.&lt;/p&gt;




&lt;h2&gt;
  
  
  Key Metrics
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Fake Token Face Value&lt;/td&gt;
&lt;td&gt;~$76.7M (1,000 eBTC)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Actual Cash-Out Amount&lt;/td&gt;
&lt;td&gt;~$816K (384 ETH → Tornado Cash)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Face Value to Actual Ratio&lt;/td&gt;
&lt;td&gt;94:1 (due to liquidity insufficiency)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Destroyed Fake Tokens&lt;/td&gt;
&lt;td&gt;955 eBTC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Echo Aptos TVL&lt;/td&gt;
&lt;td&gt;~$254M&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECHO Token Decline&lt;/td&gt;
&lt;td&gt;-11% (after news broke)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Attack Flow Breakdown
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Step 1: Obtain Admin Privileges
&lt;/h3&gt;

&lt;p&gt;Attacker obtained control of eBTC contract's DEFAULT_ADMIN_ROLE. This permission was tied to a &lt;strong&gt;single EOA address&lt;/strong&gt; (regular wallet, single private key) with no multisig protection, no timelock, and no rate limiting.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: Self-Grant Minter Role
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;grantRole(MINTER_ROLE, attacker_wallet)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Used admin privileges to grant themselves the minter role.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Mint Fake eBTC
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;mint(attacker_wallet, 1000e8)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;1,000 eBTC凭空出现。Face value $76.7M, real BTC backing: 0.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: Cover Tracks
&lt;/h3&gt;

&lt;p&gt;Attacker &lt;strong&gt;revoked their own admin privileges&lt;/strong&gt;, making on-chain traces less obvious. This was premeditated—the attacker knew investigators would first scan role authorization records.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 5: Cash Out via Curvance
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Deposited 45 fake eBTC (face value $3.45M) into Curvance as collateral&lt;/li&gt;
&lt;li&gt;Curvance had &lt;strong&gt;zero verification&lt;/strong&gt; to distinguish real from fake eBTC—from the contract's perspective, eBTC is just eBTC&lt;/li&gt;
&lt;li&gt;Borrowed 11.29 WBTC (~$867,700)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 6: Cross-Chain Laundering
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Bridged WBTC to Ethereum mainnet&lt;/li&gt;
&lt;li&gt;Swapped to ETH&lt;/li&gt;
&lt;li&gt;Approximately 384 ETH ($821,700) deposited to Tornado Cash&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 7: Remaining Fake Tokens Stranded
&lt;/h3&gt;

&lt;p&gt;955 eBTC remained in attacker's Monad wallet, unable to cash out further due to liquidity exhaustion. Echo team subsequently destroyed these tokens.&lt;/p&gt;




&lt;h2&gt;
  
  
  Dual Failure Analysis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Failure 1: Echo Protocol — Single Private Key Managing $254M+ Protocol
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DEFAULT_ADMIN_ROLE tied to an EOA&lt;/li&gt;
&lt;li&gt;No multisig, no timelock, no minting cap, no rate limit&lt;/li&gt;
&lt;li&gt;Entire Monad deployment security equivalent to single private key security&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure 2: Curvance — No Collateral Source Verification
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Accepted newly minted eBTC as collateral without verifying BTC backing&lt;/li&gt;
&lt;li&gt;Lending protocols should implement post-mint cooldown periods or whitelist mechanisms&lt;/li&gt;
&lt;li&gt;Isolated market design limited contagion but did not prevent single-asset exploitation&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  2026 DeFi Security Trends
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Trend&lt;/th&gt;
&lt;th&gt;Percentage&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Admin key/private key theft&lt;/td&gt;
&lt;td&gt;70%+&lt;/td&gt;
&lt;td&gt;Primary attack vector in 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;LayerZero bridge exploits&lt;/td&gt;
&lt;td&gt;18%&lt;/td&gt;
&lt;td&gt;Cross-chain infrastructure risk&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fake/deception tokens&lt;/td&gt;
&lt;td&gt;14%&lt;/td&gt;
&lt;td&gt;Like the fake eBTC in this case&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Smart contract vulnerabilities&lt;/td&gt;
&lt;td&gt;&amp;lt;10%&lt;/td&gt;
&lt;td&gt;Traditional attack vectors declining&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Major May 2026 Events
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Project&lt;/th&gt;
&lt;th&gt;Loss&lt;/th&gt;
&lt;th&gt;Cause&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;5/24&lt;/td&gt;
&lt;td&gt;StablR&lt;/td&gt;
&lt;td&gt;$2.8M&lt;/td&gt;
&lt;td&gt;1-of-3 multisig key compromised&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/22&lt;/td&gt;
&lt;td&gt;Polymarket&lt;/td&gt;
&lt;td&gt;$600K+&lt;/td&gt;
&lt;td&gt;Exploitation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/22&lt;/td&gt;
&lt;td&gt;Verus Bridge&lt;/td&gt;
&lt;td&gt;$8.5M (returned)&lt;/td&gt;
&lt;td&gt;Malicious nodes + GG20 exploit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/21&lt;/td&gt;
&lt;td&gt;Map Protocol&lt;/td&gt;
&lt;td&gt;96% crash&lt;/td&gt;
&lt;td&gt;10 trillion tokens minted&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/19&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Echo Protocol&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$816K&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Admin key compromised&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5/15&lt;/td&gt;
&lt;td&gt;THORChain&lt;/td&gt;
&lt;td&gt;$10M&lt;/td&gt;
&lt;td&gt;Malicious nodes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;April&lt;/td&gt;
&lt;td&gt;Drift&lt;/td&gt;
&lt;td&gt;$285M&lt;/td&gt;
&lt;td&gt;CCTP exploit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;April&lt;/td&gt;
&lt;td&gt;KelpDAO&lt;/td&gt;
&lt;td&gt;$292M&lt;/td&gt;
&lt;td&gt;Protocol attack&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Defense Recommendations
&lt;/h2&gt;

&lt;h3&gt;
  
  
  For Protocols
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Multisig Management&lt;/strong&gt;: Minimum 2-of-3, recommended 3-of-5 + hardware wallets&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timelock&lt;/strong&gt;: Ownership changes require 24-48 hour delay&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Minting Cap&lt;/strong&gt;: Single/daily minting limits&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate Limiting&lt;/strong&gt;: Large mints trigger alerts and delays&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Role Separation&lt;/strong&gt;: Admin/minter/pauser use different controllers&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  For Lending Protocols
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Collateral Source Verification&lt;/strong&gt;: Newly minted tokens require cooldown before serving as collateral&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Minting Monitoring&lt;/strong&gt;: Real-time monitoring of abnormal token supply growth&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Isolated Markets&lt;/strong&gt;: Curvance's isolated market design limited contagion—well done&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  Pending Deep Investigation Areas
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Admin Key Compromise Method&lt;/strong&gt;: Phishing/insider/supply chain/malware?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Attacker On-Chain Footprint&lt;/strong&gt;: Fund destinations after Tornado Cash deposit&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Curvance Bad Debt Handling&lt;/strong&gt;: How are bad debts from 45 fake eBTC handled?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-Chain Bridge Security&lt;/strong&gt;: WBTC bridging path from Monad to Ethereum&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Echo Aptos Deployment Comparison&lt;/strong&gt;: Is aBTC management permissions equally vulnerable?&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  Data Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://beincrypto.com/autopsy-of-the-echo-protocol-hack/" rel="noopener noreferrer"&gt;BeInCrypto - Echo Protocol Hack Autopsy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://piglobalinvestments.com/bitcoin/echo-protocol-hack-on-monad/" rel="noopener noreferrer"&gt;PIGlobalInvestments - Echo Protocol Hack on Monad&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cointelegraph.com/tags/hacks" rel="noopener noreferrer"&gt;Cointelegraph - Echo Protocol eBTC exploited&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bingx.com/id/news/post/echo-token-slides-after-echo-protocol-admin-key-exploit-mints-m-in-ebtc" rel="noopener noreferrer"&gt;BingX - ECHO token slides&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thearabianpost.com/echo-breach-exposes-bitcoin-defi-risks/" rel="noopener noreferrer"&gt;The Arabian Post - Echo breach exposes Bitcoin DeFi risks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;@dcfgod X post (initial exploit alert)&lt;/li&gt;
&lt;li&gt;@keoneHD (Monad co-founder) confirmation&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;Investigator: Onchain Shadow&lt;/p&gt;

&lt;p&gt;Disclaimer: This report is based on publicly available on-chain data and media reports for security research purposes only.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
      <category>defi</category>
    </item>
    <item>
      <title>CWU Token On-Chain Investigation - $7.3M Commonwealth Rug Pull</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:26:57 +0000</pubDate>
      <link>https://dev.to/qanzhi111/cwu-token-on-chain-investigation-73m-commonwealth-rug-pull-4il0</link>
      <guid>https://dev.to/qanzhi111/cwu-token-on-chain-investigation-73m-commonwealth-rug-pull-4il0</guid>
      <description>&lt;h1&gt;
  
  
  CWU Token On-Chain Investigation Report
&lt;/h1&gt;

&lt;h2&gt;
  
  
  🚨 Case Summary
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Token Name&lt;/strong&gt;: Commonwealth (CWU)&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Blockchain&lt;/strong&gt;: Solana&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Contract Address&lt;/strong&gt;: &lt;code&gt;CmVUoJUt7hMGc9ze7s8zYdnA7enMfCAFdQCggxcbACWU&lt;/code&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Investigation Date&lt;/strong&gt;: 2026-05-27&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Risk Level&lt;/strong&gt;: 🔴 Extremely High — Classic Slow-Motion Rug Pull&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Current Status&lt;/strong&gt;: Insiders still dumping; 85% of supply controlled by associated wallets  &lt;/p&gt;




&lt;h2&gt;
  
  
  📊 Key Metrics
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Project Claim&lt;/th&gt;
&lt;th&gt;On-Chain Reality&lt;/th&gt;
&lt;th&gt;Discrepancy&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Circulation Ratio&lt;/td&gt;
&lt;td&gt;90% "in circulation"&lt;/td&gt;
&lt;td&gt;10-15% actual circulation&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;75-80% gap&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Project Treasury&lt;/td&gt;
&lt;td&gt;10%&lt;/td&gt;
&lt;td&gt;85-90% in associated wallets&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;8-9x inflated&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Holder Distribution&lt;/td&gt;
&lt;td&gt;Wide distribution&lt;/td&gt;
&lt;td&gt;200+ new wallets batch-claiming&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Single entity control&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Insider Dumping&lt;/td&gt;
&lt;td&gt;Undisclosed&lt;/td&gt;
&lt;td&gt;~$600,000 already sold&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Ongoing&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Price Trajectory (CoinGecko Real-Time Data, 2026-05-27)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Current Price&lt;/strong&gt;: $0.02425 (24h +37.6%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ATH&lt;/strong&gt;: $0.03663 (2026-04-14)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ATL&lt;/strong&gt;: $0.01141 (2026-04-10)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Market Cap&lt;/strong&gt;: $21,836,596 (#801)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;FDV&lt;/strong&gt;: $24,249,481&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;24h Volume&lt;/strong&gt;: $2,519,129 (+307%)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Primary Exchange&lt;/strong&gt;: Meteora DAMM V2 (CWU/SOL, 100% volume)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;⚠️ Rugcheck.xyz Warning&lt;/strong&gt;: "Risk of market manipulation with significant token concentration in one or more unidentified wallets"&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Trend&lt;/strong&gt;: Short-term bounce, but continuous insider selling; long-term pressure&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🔍 On-Chain Evidence Chain
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Supply Concentration (Bubblemaps Analysis)
&lt;/h3&gt;

&lt;p&gt;From &lt;a href="https://intel.bubblemaps.io/cases/96/bundled-supply-in-cwu" rel="noopener noreferrer"&gt;Bubblemaps Case Analysis&lt;/a&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;200+ newly created wallets&lt;/strong&gt; were batch-funded around token launch&lt;/li&gt;
&lt;li&gt;These wallets &lt;strong&gt;simultaneously claimed the vast majority of CWU supply&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Inter-wallet transfers and connections indicate they are &lt;strong&gt;controlled by a single entity or coordinated organization&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;These associated wallets currently hold approximately &lt;strong&gt;85-90% of total supply&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Insider Dumping Pattern
&lt;/h3&gt;

&lt;p&gt;Bubblemaps real-time monitoring:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Associated address cluster has sold approximately &lt;strong&gt;$600,000&lt;/strong&gt; in CWU tokens&lt;/li&gt;
&lt;li&gt;Dumping occurred during price increases (classic "sell into strength" strategy)&lt;/li&gt;
&lt;li&gt;After dumping, still control &lt;strong&gt;85% of supply&lt;/strong&gt;, meaning massive inventory remains available&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3. Marketing Claims vs. On-Chain Reality
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;CWU Official Statement&lt;/strong&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"90% of the token's total supply is 'in circulation' and only 10% is reserved for the project treasury"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;On-Chain Reality&lt;/strong&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;200+ associated wallets control 87-90% of supply; truly free-floating tokens only 10-15%&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is a &lt;strong&gt;textbook false statement&lt;/strong&gt; — the project distributed to 200+ wallets to create the illusion of "wide ownership," while a single entity maintains control.&lt;/p&gt;




&lt;h2&gt;
  
  
  🏛️ Political Endorsement Risk
&lt;/h2&gt;

&lt;h3&gt;
  
  
  John Agyekum Kufuor's Role
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Ghana's 10th President (2001-2009)&lt;/li&gt;
&lt;li&gt;Described as "Official Advisor" in CWU marketing materials&lt;/li&gt;
&lt;li&gt;MEXC exchange listing states CWU "registered under the endorsement of John Agyekum Kufuor"&lt;/li&gt;
&lt;li&gt;This political endorsement grants the token &lt;strong&gt;false legitimacy&lt;/strong&gt;, attracting retail investors&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Dangerous Combination: Political Endorsement × Memecoin
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Trust Transfer&lt;/strong&gt;: Retail investors assume "implicit backing" from a former head of state&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Regulatory Vacuum&lt;/strong&gt;: Political figure endorsements of crypto projects lack clear regulation in many jurisdictions&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-Border Complexity&lt;/strong&gt;: Ghanaian politician + Solana chain + global traders = jurisdictional chaos&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deniability&lt;/strong&gt;: Kufuor can claim "just an advisor," disclaiming responsibility for investment losses&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Key Unanswered Questions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Did Kufuor &lt;strong&gt;actually receive&lt;/strong&gt; CWU tokens or fiat payment?&lt;/li&gt;
&lt;li&gt;Was Kufuor &lt;strong&gt;aware&lt;/strong&gt; of the 200+ wallet concentration?&lt;/li&gt;
&lt;li&gt;Could the former president's name be &lt;strong&gt;misused&lt;/strong&gt;?&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🧩 Rug Pull Mechanics Breakdown
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Phase 1: Preparation (Pre-Launch)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Create 200+ new wallets&lt;/li&gt;
&lt;li&gt;Fund in batches (avoid single large transfer triggering alerts)&lt;/li&gt;
&lt;li&gt;Prepare marketing materials (political endorsement, MEXC listing narrative)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 2: Launch
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;200+ wallets simultaneously claim vast majority of supply&lt;/li&gt;
&lt;li&gt;Create illusion of "fair distribution"&lt;/li&gt;
&lt;li&gt;Use political endorsement to attract retail entry&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 3: Pump
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Extremely low float (85% locked in associated wallets) → scarcity drives price up&lt;/li&gt;
&lt;li&gt;Market cap surges from $0 to $120M&lt;/li&gt;
&lt;li&gt;Exchange listings (MEXC, etc.) add liquidity&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 4: Dump — Current Phase
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Associated wallets continuously dump at price highs&lt;/li&gt;
&lt;li&gt;Already cashed out ~$600,000&lt;/li&gt;
&lt;li&gt;Still hold 85% supply, can continue dumping&lt;/li&gt;
&lt;li&gt;32% decline is just the beginning&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Phase 5: Crash — Predicted
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;When insiders complete exit, price approaches zero&lt;/li&gt;
&lt;li&gt;Retail investors lose everything&lt;/li&gt;
&lt;li&gt;Project may deny association with wallets&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  ⚠️ Risk Assessment
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Risk Dimension&lt;/th&gt;
&lt;th&gt;Score&lt;/th&gt;
&lt;th&gt;Explanation&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Rug Pull Risk&lt;/td&gt;
&lt;td&gt;🔴 10/10&lt;/td&gt;
&lt;td&gt;85% supply concentration + continuous dumping&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;False Statement Risk&lt;/td&gt;
&lt;td&gt;🔴 9/10&lt;/td&gt;
&lt;td&gt;"90% circulating" vs actual 10-15%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Political Endorsement Misuse&lt;/td&gt;
&lt;td&gt;🟡 7/10&lt;/td&gt;
&lt;td&gt;Former president's endorsement potentially abused&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Regulatory Recourse&lt;/td&gt;
&lt;td&gt;🟡 5/10&lt;/td&gt;
&lt;td&gt;Cross-border + anonymous team = enforcement difficulty&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Retail Loss Risk&lt;/td&gt;
&lt;td&gt;🔴 10/10&lt;/td&gt;
&lt;td&gt;85% supply can crash price at any time&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  🔬 Next Steps for Deep Investigation (Pending API Key)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;[ ] Trace funding sources of 200+ associated wallets (Solana RPC)&lt;/li&gt;
&lt;li&gt;[ ] Identify funding patterns and timeline of associated wallets&lt;/li&gt;
&lt;li&gt;[ ] Track post-dumping fund destinations (CEX? Mixer?)&lt;/li&gt;
&lt;li&gt;[ ] Analyze whether Kufuor directly received CWU tokens&lt;/li&gt;
&lt;li&gt;[ ] Contact MEXC exchange to confirm CWU listing review process&lt;/li&gt;
&lt;li&gt;[ ] Compare patterns with other politically-endorsed memecoins&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📝 Information Sources
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;a href="https://intel.bubblemaps.io/cases/96/bundled-supply-in-cwu" rel="noopener noreferrer"&gt;Bubblemaps CWU Case Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://crypto.news/ghana-ex-president-linked-cwu-token-accused-of-rug-pull-as-insiders-dump-still-hold-85/" rel="noopener noreferrer"&gt;Crypto.news Report&lt;/a&gt; (2026-05-26)&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://bitcoinworld.co.in/cwu-token-rug-pull-allegations-bubblemaps/" rel="noopener noreferrer"&gt;Bitcoinworld Report&lt;/a&gt; (2026-05-26)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.coincarp.com/currencies/commonwealth/" rel="noopener noreferrer"&gt;CoinCarp CWU Data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Bubblemaps X Post: &lt;a href="https://twitter.com/bubblemaps/status/2059277036779356587" rel="noopener noreferrer"&gt;@bubblemaps 2026-05-26&lt;/a&gt;
&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;This report is for research and educational purposes only and does not constitute investment advice. On-chain data is based on publicly available information; conclusions require further verification.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Investigator: Onchain Shadow&lt;/p&gt;

&lt;p&gt;Disclaimer: This report is based on publicly available on-chain data and media reports for security research purposes only.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔒 Protect Your Crypto with ChainSentinel
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;ChainSentinel&lt;/strong&gt; — AI-powered on-chain risk intelligence platform:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time Risk Scanning&lt;/strong&gt; — Check any address for rug pulls, phishing, and exploit risks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-Chain Monitoring&lt;/strong&gt; — Ethereum, BSC, and more&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-Powered Analysis&lt;/strong&gt; — Gemini-driven risk engine&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;👉 &lt;strong&gt;&lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try ChainSentinel Free&lt;/a&gt;&lt;/strong&gt; | &lt;a href="https://qanzhi111.github.io/chainsentinel/#pricing" rel="noopener noreferrer"&gt;Pro Plan - $29/month&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay safe on-chain. Get alerts before the next exploit.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
    </item>
    <item>
      <title>Echo Protocol eBTC Admin Key Attack</title>
      <dc:creator>qanzhi111</dc:creator>
      <pubDate>Fri, 05 Jun 2026 10:21:56 +0000</pubDate>
      <link>https://dev.to/qanzhi111/echo-protocol-ebtc-admin-key-attack-5478</link>
      <guid>https://dev.to/qanzhi111/echo-protocol-ebtc-admin-key-attack-5478</guid>
      <description>&lt;h1&gt;
  
  
  Echo Protocol eBTC Attack
&lt;/h1&gt;

&lt;p&gt;Investigation of the admin key attack on Echo Protocol eBTC.&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;The attack exploited an admin key vulnerability resulting in significant fund losses.&lt;/p&gt;




&lt;h2&gt;
  
  
  ChainSentinel
&lt;/h2&gt;

&lt;p&gt;AI-powered on-chain risk intelligence. &lt;a href="https://qanzhi111.github.io/chainsentinel/" rel="noopener noreferrer"&gt;Try Free&lt;/a&gt;&lt;/p&gt;

</description>
      <category>web3</category>
      <category>security</category>
    </item>
  </channel>
</rss>
