
Secure Trace Lab
12.5K posts

Secure Trace Lab
@SecureTrace_Lab
Crypto scam awareness & fund tracing. We break down exploits, phishing, and wallet drains. Transparency first. Victims deserve clarity.
















How to avoid getting phished? ⚠️ Be cautious of phishing attempts in these common scenarios and familiarize yourself with common phishing signatures that can lead to the theft of your assets.


We flagged a suspicious tx tied to @summerfinance_ with ~$6M in losses. An address funded via FixedFloat on Base exploited a share accounting flaw through price manipulation on ETH. Funds were swapped to DAI and moved to attacker wallets. Reach out for expert help.

Dug into the BonkDAO treasury drain for 20M+ Config made it a sitting duck, SPL governance did exactly what the passed vote told it to through a single malicious governance proposal Quorum - 1% of supply Timelock - 0 Proposal creation threshold - 100M BONK Voting power - liquid BONK, not staked or locked Direct treasury transfer execution via Realms Proposer/executor - 8xxRdtzsw1CJWfEahViqNjZwh5dYJAdSbBctWwcbycVo Voter - CyEE7oHVDaFJ5xZLbXY3h2Z2uk1VwhTkdy72kPUEtypQ Timeline (UTC) June 30 08:25 - proposer creates BIP #76, inserts 4 instructions (2x metadata as cover, create recipient account & the SPL token transfer) signs off and voting opens July 4-5 - voter acquires 882.3B BONK from exchanges. 530,397,045,677.94 from Binance and 351,888,204,104.41 from a second CEX hot wallet (reportedly Bybit) July 5 04:46 - voter locks 882,285,249,588.801 BONK into governance July 5 06:56 - voter casts the deciding yes 882.38B over the community's 710.85M no. About 1240x the real voters July 6 08:25:39 - voting closes July 6 08:26:03-08:26:28 - proposer finalises the vote and executes all 4 instructions. Drain completes at 08:26:28, 49 seconds after close July 6 08:45 - voter pulls the vote and withdraws their 882,285,249,588.801 BONK Proposal was live for 6 days without any intervention The drain was a single token transfer. Once the vote passed, Realms governance sent 4,426,104,450,305.966 BONK from the treasury (F8FqZuUKfoy58aHLW6bfeEhfW9sTtJyqFTqnxVmGZ6dU) to the attacker (9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ). Total fee = 0.000105 SOL to move over $20M TLDR Fronted $4M of BONK (882.3B), a fraction over the 1% quorum Fully refundable - withdrawn 19 minutes after the drain Profit - effectively the entire treasury (20M+). Net cost - gas (0.000105 SOL) What would have prevented it A new proposal alert. A proposal carrying a treasury transfer sat live for 6 days. One alert the moment it was created catches it An execution timelock (1-3 days) as a failsafe, so a malicious proposal can't fire the second voting ends (basically instant execution like Drift) A higher quorum + vote escrow (staked/locked, not liquid), so voting power can't be rented for a day and handed back solgov flags exactly this type of setup in real time via the telegram bot with push alerts and a live activity feed on the website. You'd think with there being 600M+ in hacks since April there would be more urgency to tighten things up. Need to start taking this stuff more seriously as it's just embarrassing at this point



Today we are publishing the first Ill Bloom findings: affected-address checker + on-chain analysis to help users identify exposed addresses and protect their assets. 🔗 illbloom.org ⚠️ We will never ask for seed phrases, private keys, signatures, or approvals, or ask users to send funds to "recover" or protect a wallet.


