InfyniSec

63 posts

InfyniSec banner
InfyniSec

InfyniSec

@InfyniSec

Safeguarding onchain assets by keeping your favourite protocol off https://t.co/RvbEHuUoMc

Offchain-Onchain sequence mode Katılım Temmuz 2025
43 Takip Edilen35 Takipçiler
InfyniSec
InfyniSec@InfyniSec·
The $50M to $36K Aave Swap Disaster: A Brutal DeFi Lesson On March 12, 2026, a trader attempted to swap ~$50.4 million in aEthUSDT (Aave's yield-bearing USDT) for AAVE tokens via the official Aave interface. Result? They received just ~324–327 AAVE tokens worth roughly $36,000 — a ~99.9% loss in seconds. No hack. No exploit. The transaction executed exactly as signed. Here's what happened: The swap routed through CoW Swap → redeemed USDT → swapped to WETH on Uniswap (fine) → then dumped into a SushiSwap AAVE/WETH pool with only ~$73K–$75K liquidity. The massive order crushed the price in that thin pool. Multiple red-flag warnings appeared: "extraordinary slippage," ~99% price impact, manual confirmation required. The user (on mobile) set low slippage tolerance (1.21%) and approved anyway. MEV bots pounced — one reportedly extracted millions in profit by back-running the distorted trade. Aave's post-mortem confirmed: everything worked as designed. They’re refunding ~$600K in fees and rolled out Aave Shield — auto-blocks swaps with >25% price impact (users can disable it). Key takeaways for DeFi users & builders: Your keys, your responsibility — even slick UIs can't stop bad decisions. Warnings exist for a reason; size matters more than interfaces suggest. Shallow liquidity + large orders = catastrophe. MEV turns mistakes into someone else's payday. DeFi offers freedom — but zero safety nets when you ignore the math. One click. $50M gone. $36K left. Always simulate big trades first. DYOR. Stay vigilant.
English
0
0
2
21
InfyniSec retweetledi
ddimitrov22
ddimitrov22@ddimitrovv22·
How to get hacked in 3 steps (100% guaranteed): 1. Use AI to write your smart contracts 2. Use AI to audit your project 3. Deploy without verification, thinking that raw EVM code is hard to decompile and exploit Congrats! You made more people think that web3 is a pure scam 👏
English
3
3
55
2K
Kann Audits
Kann Audits@KannAudits·
We’re hiring Security Researcher Interns for Kann Audits! Interns will be paid weekly and should know at least one of Solidity, Rust, or Move. We’re looking for highly motivated hustlers eager to grow. Given how hard it is for new talent to get recognized, we’re launching our first official internship program to help interns build real portfolios, collaborate with others, and level up their skills. Apply here:docs.google.com/forms/d/e/1FAI… After applying, comment ‘Applied!’ below 👇
English
173
45
464
29.2K
InfyniSec retweetledi
chrisdior.eth
chrisdior.eth@chrisdior777·
The best security tip out there: BE SUSPICIOS of everything. Assume every call or email you receive is a scam by default. Thats it.
English
5
3
64
1.7K
InfyniSec retweetledi
ddimitrov22
ddimitrov22@ddimitrovv22·
Bridges are still one of the weakest spots in DeFi and have been exploited many times. Here is a 4-part mini-series that will help you learn all the risks and improve your bridge security. 1/ Message and signature replay - calibersec.com/blockchain-bri… 2/ Cross-chain signature replay and variations - calibersec.com/blockchain-bri… 3/ Arbitrary call execution - calibersec.com/blockchain-bri… 4/ Chain ID spoofing and Hash collision - calibersec.com/blockchain-bri…
English
2
10
100
4.6K
InfyniSec
InfyniSec@InfyniSec·
GM 2026. A humble reminder that Hackers take no holidays. Stay Vigilant with your passwords, passkeys, seals, patterns, codebases, private keys and everything else susceptible to the meekest of social engineering attacks. @0xFlint_ @arsen @RealJohnnyTime @0xSimao
English
1
1
2
32
InfyniSec retweetledi
InfyniSec
InfyniSec@InfyniSec·
As we wind down 2025, lets look at some of our H2 stats. - 12+ audits completed both custom & Private. - 50+ mediums discovered - 15+ crits discovered and patched. - 100s of lows,informational and gas issues highlighted and corrected. - 5 blockchain ecosystem projects covered. - 8 War rooms participated in. - 4 partnerships launched in Q4 alone. - and so much more... Looking charged and laser focused on the next year. @GuardianAudits @sherlockdefi @base @Starknet @arbitrum @shafu0x @arsen
English
0
2
4
80