




Morph🧬
307 posts

@0xMorph
Everyday @SpearbitDAO @Cantinaxyz








We released a full report on the Batch amendment issue from last week. The bug revolved around the signature validation logic of the Batch amendment. It was caught before the amendment was activated by the autonomous AI agent Apex at @cantinaxyz. Thank you to all validators and community members for the collaboration and swift response. More details in the blog post here: xrpl.org/blog/2026/vuln…


The latest @ribbonfinance attack appears to be a oracle configuration fault. 6 days ago, the owners updated the oracle pricer which uses 18 decimals price for stETH, PAXG, LINK and AAVE. However, other assets like USDC price still at 8 decimals. creation of OToken is not a root cause because everything is LEGAL. The underlying tokens need to be whitelisted before they are used in an OToken as collateral/strike asset. The attack flow: (1) create new option market (e.g., LINK/USDC option market) that will expire in several minutes. (2) deposit LINK as collateral and buy LINK call option. (3) wait for expiry and execute the option to profit.





From bronze to 💰 $200,000 and straight into our Top-20! Congrats to @bronze_pickaxe for this massive critical find. 👏

🚨 BREAKING: The DuckDB npm account was compromised. Malicious versions of duckdb, duckdb-wasm, and more were published early this morning with the same wallet-drainer malware seen in yesterday’s supply-chain attack. Check your dependencies! socket.dev/blog/duckdb-np… #NodeJS

