
InfyniSec
63 posts

InfyniSec
@InfyniSec
Safeguarding onchain assets by keeping your favourite protocol off https://t.co/RvbEHuUoMc
Offchain-Onchain sequence mode Katılım Temmuz 2025
43 Takip Edilen35 Takipçiler

The $50M to $36K Aave Swap Disaster: A Brutal DeFi Lesson
On March 12, 2026, a trader attempted to swap ~$50.4 million in aEthUSDT (Aave's yield-bearing USDT) for AAVE tokens via the official Aave interface.
Result? They received just ~324–327 AAVE tokens worth roughly $36,000 — a ~99.9% loss in seconds.
No hack. No exploit. The transaction executed exactly as signed.
Here's what happened:
The swap routed through CoW Swap → redeemed USDT → swapped to WETH on Uniswap (fine) → then dumped into a SushiSwap AAVE/WETH pool with only ~$73K–$75K liquidity.
The massive order crushed the price in that thin pool.
Multiple red-flag warnings appeared: "extraordinary slippage," ~99% price impact, manual confirmation required.
The user (on mobile) set low slippage tolerance (1.21%) and approved anyway.
MEV bots pounced — one reportedly extracted millions in profit by back-running the distorted trade.
Aave's post-mortem confirmed: everything worked as designed. They’re refunding ~$600K in fees and rolled out Aave Shield — auto-blocks swaps with >25% price impact (users can disable it).
Key takeaways for DeFi users & builders:
Your keys, your responsibility — even slick UIs can't stop bad decisions.
Warnings exist for a reason; size matters more than interfaces suggest.
Shallow liquidity + large orders = catastrophe.
MEV turns mistakes into someone else's payday.
DeFi offers freedom — but zero safety nets when you ignore the math.
One click. $50M gone. $36K left.
Always simulate big trades first. DYOR. Stay vigilant.
English
InfyniSec retweetledi

@rkukiriza @UnlockProtocol @AnalyticSages @dev3pack @_one_dev @TheSafariDAO @InfyniSec The energy continues.. with responsible defi
Uganda 🇺🇬 English

Its actually starting. AI built bugs are multiplying by the day.
Shieldify Security@ShieldifySec
The era of smart contract auditors is not over 🫡
English
InfyniSec retweetledi

All these attacks hit like they happened yesterday.
chrisdior.eth@chrisdior777
Flash loans were used to execute these exploits, letting hackers borrow huge capital instantly, manipulate protocol logic & drain funds in 1 tx Study these 5: rekt.news/inverse-rekt2 rekt.news/deus-dao-rekt rekt.news/jimbo-rekt rekt.news/platypus-finan… rekt.news/beanstalk-rekt
English

The kind of wins that remind us that Web3 security is for those top 1% who demand perfection.
Cc: @shafu0x @CDSecurity_io @hexensio @HalbornSecurity

English

We’re hiring Security Researcher Interns for Kann Audits!
Interns will be paid weekly and should know at least one of Solidity, Rust, or Move. We’re looking for highly motivated hustlers eager to grow.
Given how hard it is for new talent to get recognized, we’re launching our first official internship program to help interns build real portfolios, collaborate with others, and level up their skills.
Apply here:docs.google.com/forms/d/e/1FAI…
After applying, comment ‘Applied!’ below 👇
English

A deep analysis of the recent TrueBit attack.
Arithmetic bugs ushered in 2026 relying on TrueBit's vintage code.
medium.com/p/a-deep-analy…
English
InfyniSec retweetledi

Anyone can learn Smart Contract Security for free.
Resources:
@CodeHawks first flights are free
@SoloditOfficial findings are free
@trailofbits publications are free
@CyfrinUpdraft courses are free
@RareSkills_io articles are free
@immunefi write-ups are free
@OpenZeppelin docs are free
@pashov findings are public
@CryptoZombiesHQ is free
Just learn, practice, and find bugs.
English
InfyniSec retweetledi

Invite us to audit it once its done...
Brian Armstrong@brian_armstrong
At some point you will get an urge to vibe code an app. It’s very important that you listen to that urge and just get started.
English
InfyniSec retweetledi

Bridges are still one of the weakest spots in DeFi and have been exploited many times.
Here is a 4-part mini-series that will help you learn all the risks and improve your bridge security.
1/ Message and signature replay - calibersec.com/blockchain-bri…
2/ Cross-chain signature replay and variations - calibersec.com/blockchain-bri…
3/ Arbitrary call execution - calibersec.com/blockchain-bri…
4/ Chain ID spoofing and Hash collision - calibersec.com/blockchain-bri…
English

@chrisdior777 Sure enough, this is a gold roadmap thank you @chrisdior777
English

Become an absolute Web3 Security beast in 2026!!
Resources:
1. Owen Thurm - Web3 Security 101 playlist (Youtube)
2. Past audit reports - solodit.xyz
3. DeFi bible - github.com/OffcierCia/ult…
4. Books & Blog - rareskills.io/blog
5. Use AI to your advantage

English
InfyniSec retweetledi

As we wind down 2025, lets look at some of our H2 stats.
- 12+ audits completed both custom & Private.
- 50+ mediums discovered
- 15+ crits discovered and patched.
- 100s of lows,informational and gas issues highlighted and corrected.
- 5 blockchain ecosystem projects covered.
- 8 War rooms participated in.
- 4 partnerships launched in Q4 alone.
- and so much more...
Looking charged and laser focused on the next year.
@GuardianAudits @sherlockdefi @base @Starknet @arbitrum @shafu0x @arsen
English