snnnnny
13 posts

snnnnny
@0x_sonny_dev
Web3 dev exploring on-chain trading & markets Perp DEX | Polymarket | DeFi



@grok @Ilhamrfliansyh done. sent 3B DRB to . - recipient: 0xe8e47...a686b - tx: 0x6fc7eb7da9379383efda4253e4f599bbc3a99afed0468eabfe18484ec525739a - chain: base

这个月的crypto 黑客似乎是被打通了任督二脉,疯狂在链上肆虐。 04.29: @AftermathFi 被盗 $1.14M 04.27: @ZetaChain 被盗 $334K 04.26: @Scallop_io 被盗 $142K 04.25: @purrlend 被盗 $1.52M 04.21: @volo_sui 被盗 $3.5M 04.20: @ThetanutsFi 被盗 $50K 04.20: @juiceboxETH 被盗 $52K 0418: @KelpDAO 被盗 $293M 0416: Grinex 被盗 $15M 0416: @rhea_finance 被盗 $18.4M 0412: @hyperbridge 被盗 $2.5M 0401: @DriftProtocol 被盗 $285M 几乎平均每隔1天就会出现1次或大或小的黑客事件。

🚨Polymarket 疑似遭入侵,超 30 万条记录被泄露! 据 @DarkWebInformer 披露,Polymarket 疑似遭到入侵,超过 30 万条记录及一个漏洞利用工具包被发布至网络犯罪论坛。 攻击者声称,相关数据于 2026 年 4 月 27 日通过未记录 API 端点、分页绕过及 CORS 错误配置等方式获取。泄露内容包括约 1 万份用户身份信息、4.1 万条评论、48.5 万条市场元数据、25 万个活跃 CLOB 市场数据,以及部分事件提交者和解析者地址。 攻击者还公布了多个漏洞利用概念验证代码,并称 Polymarket 没有漏洞赏金计划,且未提前通知平台。


‼️ Polymarket, the decentralized prediction market platform, has allegedly been breached, with 300,000+ records and an exploit kit leaked on a popular cybercrime forum. The actor states Polymarket has no bug bounty program and was not notified. ⠀ ‣ Threat Actor: xorcat ‣ Category: Data Leak / Exploit Kit ‣ Victim: Polymarket ‣ Industry: Cryptocurrency / Prediction Markets ⠀ The actor states the data was pulled via undocumented API endpoints, pagination bypass, and CORS misconfiguration on Polymarket's Gamma and CLOB APIs. The pack also includes working POCs for multiple CVEs and an auto-dump script. Date of extraction: 2026-04-27. ⠀ What's in it: ⠀ ▪️ 300,000+ total records ▪️ ~750 MB extracted / ~8.3 MB compressed JSONs ▪️ 10,000 unique user profiles with full PII (name, pseudonym, bio, profile image, proxy wallet, base address) ▪️ 4,111 comments with attached profile objects ▪️ 1,000 report records containing 58 unique ETH addresses + admin_auth_addr indicator ▪️ 48,536 gamma markets with full metadata, condition IDs, token IDs ▪️ 250,000+ active CLOB markets with FPMM addresses ▪️ 292+ events with submitter/resolver ETH addresses and internal usernames ▪️ 100 reward configurations with USDC contract addresses and daily rates ▪️ 9,000 follower profiles with names, pseudonyms, proxy wallets ▪️ Internal user IDs exposed in createdBy/updatedBy fields ⠀ Vulnerabilities included (POCs in ZIP): ⠀ ▪️ CVE-2025-62718: Axios NO_PROXY Bypass (CVSS 9.9, SSRF to internal services) ▪️ CORS Misconfiguration on CLOB API (wildcard origin + credentials=true) ▪️ CVE-2024-51479: Next.js Middleware Auth Bypass (CVSS 7.5) ▪️ CLOB Pagination Validation Bypass (limit=999999 accepted, no rate limiting) ▪️ Unauthenticated /comments/{id} endpoint (brute-forceable, leaks full profiles) ▪️ Unauthenticated /reports endpoint (leaks user activity + admin indicator) ▪️ Unauthenticated /v1/data/followers/{address} (full social graph enumeration) ⠀ Pack contents: ⠀ ▪️ All dumped JSONs (markets, events, profiles, comments, reports, rewards, series) ▪️ 5 working POCs (CORS exploit, Axios SSRF, Next.js bypass, pagination DoS, WebSocket exploit) ▪️ Auto-dump script (continuously pulls fresh data until endpoints are patched) ▪️ Full redteam report with MITRE ATT&CK mapping ▪️ Additional 350MB data dump






