Defimon Alerts

812 posts

Defimon Alerts banner
Defimon Alerts

Defimon Alerts

@DefimonAlerts

DeFi security monitoring ⚠️ Alerts: https://t.co/p5MHTe5S0Q 💎 Signals: https://t.co/70vuWap7y0

Onchain Katılım October 2025
8 Takip Edilen3K Takipçiler

2026 Yıllık Özeti

@DefimonAlerts hesabının Twitter yılını gör

Sabitlenmiş Tweet
Defimon Alerts
Defimon Alerts@DefimonAlerts·
WebSocket access to Defimon's real-time feed of onchain attacks is now easier to get. We've enabled a self-service checkout at defimon.xyz and in Telegram via t.me/defimon_subscr…
Defimon Alerts tweet media
English
0
0
9
12.2K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
🚨 NEX (on PancakeSwap) - Loss ~$19K (2026-08-03) Token: $NEX Network: BNB Chain Type: Logic Error (double-spend in token _transfer) The NEX token's _transfer has a fall-through bug: the router branch calls super._transfer(from,to,amount) and then execution continues to a second unconditional super._transfer(from,to,amount), so any transfer to/from the PancakeSwap router moves tokens TWICE. The attacker flash-borrowed AIC, bought NEX, donated NEX into the NEX/AIC pair, then called pair.skim(router). Because skim sends to the router, the double-spend drained the pair's entire NEX balance (reserve collapsed to 1) while AIC stayed at ~83M. With the pool massively skewed, the attacker bought out the whole AIC reserve for a few NEX and dumped AIC → WBNB, netting ~32.36 WBNB (~$19K). TX: bscscan.com/tx/0x905cc861b… Attacker: bscscan.com/address/0xc3cb… Victim: bscscan.com/address/0x974c… (NEX/AIC pair) Token: bscscan.com/address/0xae04… ⏱️ Real-time alerts: defimon.xyz
English
0
0
2
398
Defimon Alerts
Defimon Alerts@DefimonAlerts·
🚨 LpdFi - Loss ~$690K (2026-08-02) Token: $LPD Network: BNB Chain Type: Oracle / Price Manipulation (flash-loan) LpdFi's Lpd.price() derives the LPD price straight from the spot reserves of the PancakeSwap LPD/USDC pair, with no TWAP or manipulation guard. The attacker flash-borrowed USDC, skewed the pair reserves (donate + sync), which let an order's uAmount value the "interest" far above what its LPD collateral is worth. claimInterest() then pays that inflated interest by calling removeLp(), burning the protocol's own PancakeSwap LP position to withdraw USDC and forwarding 99% to the caller. The whole LpdFi LP stack (~1.68M LP) was pulled and ~693.5K USDC handed to the attacker in a single tx. TX: bscscan.com/tx/0x70bbe0aa3… Attacker: bscscan.com/address/0x5d28… Victim: bscscan.com/address/0xce6a… ⏱️ Real-time alerts: defimon.xyz
English
6
7
46
5.2K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: This wallet drained funds on Jul 21, 2026 via a phishing site and its activity is being tracked by blockchain forensics firms and has been reported to FBI IC3, Chainalysis, and every major exchange compliance team. Any attempt to move, swap, or cash out these funds will be flagged and frozen at the exchange or bridge level. You have 48 hours to return 80% of the funds to this address. Keep 20% and this ends here. After 48 hours, the offer is withdrawn and full legal pursuit begins, including subpoenas to any exchange or mixer you touch these funds with. etherscan.io/tx/0x0ea169b9a…
English
1
2
9
3.3K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
🚨 Private MEV/Arb Bot (0xa317…c170) - Loss ~$31.7K (2026-07-30) Token: $WETH @ $1904.74 Network: Base Type: Access Control (unprotected arbitrary-call function) A Uniswap V3 arbitrage bot (deployed & owned by EOA 0x3862…3f53) exposes function 0x42be3129 with NO access control — it executes a caller-supplied target+calldata and forwards the output to msg.sender. Only 0x23a69e75 is onlyOwner-gated. The attacker deployed a helper contract and called 0x42be3129 passing data = WETH.transferFrom(owner, bot, 16.62 WETH), abusing the 16.62 WETH allowance the owner had pre-granted the bot, then swept it out. ~16.62 WETH drained in a single tx. TX: basescan.org/tx/0xe831f3991… Attacker: basescan.org/address/0xbdce… Victim: basescan.org/address/0xa317… (unverified) ⏱️ Real-time alerts: defimon.xyz
English
3
2
33
5.4K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: ChainConnect confirms that the controller of 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 has fulfilled the agreed return terms for the ChainConnect bridge incident of 26 July 2026. We confirm receipt of 280 ETH to 0x840B3De19e3FAB72fa9A168bD8Dd71B678c57989 in tx 0xe78bfae09b6b8fab1057f472f605044dea8d066b73e5012837050a5bc6d6eb00. The retained amount is acknowledged as the agreed whitehat bounty. ChainConnect considers its commitments under the agreement fulfilled and the matter resolved with the controller of 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5. ChainConnect, 31 July 2026 etherscan.io/tx/0xf5dc5e590…
English
1
0
4
2.9K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
🚨 @SwanTreasurpaj - Loss ~$625K (2026-07-30) Token: $STY @ $2.87 Network: BNB Chain Type: Private Key Compromise (signer key leak) The protocol's off-chain signer key (0xdEb4...8284, hardcoded as _signer in ZhaiquanBuy) was compromised. buy() sells STY at a signed discount: buyamount = getBuyamount() * 100 / discount. The attacker crafted valid signatures for their own address with discount=1, buying STY at a 100x discount (~687K STY for ~19.7K USDT via a PancakeSwap flash loan), plus forged claim()/transfer signatures on sibling contracts. Dumping the STY into the STY/USDT pool netted ~$625K USDT. Every ecrecover in the tx resolves to the exact hardcoded signer, confirming the key itself was compromised rather than a signature-logic flaw. TX: bscscan.com/tx/0xc8c3325ba… Attacker: bscscan.com/address/0x840f… Victim: bscscan.com/address/0x27af… ⏱️ Real-time alerts: defimon.xyz
English
1
6
28
4.3K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: Glad you choose to do the needful. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA on Ethereum. Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x9c961a0dDC3dF10456b05EBEc5138737aF28B1eA is not authorised by ChainConnect. ChainConnect, 29 July 2026 etherscan.io/tx/0xa6df21e27…
English
1
1
8
2.5K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: To the party who executed the exploit of the Wanchain Bridge on Cardano on July 20, 2026, resulting in the theft of NIGHT tokens: We are opening a channel to resolve this as a white-hat matter. The offer: return 90% of the exploited NIGHT tokens to the addresses below and retain 10% as a white-hat bounty. If the returned funds are received by August 6, 2026 at UTC 12:00, Wanchain will treat this as a white-hat recovery and will not pursue civil claims against you. This offer expires at the deadline above. Blockchain analytics firms and relevant exchanges have been engaged, and the addresses involved are being monitored and flagged. Please return the funds to: Cardano Address: addr1q8jqrqz0t2vzy5yvl88wtyjgurvhwauw0sqpe698mq04p0ham3clyk6mg6gctwsfuc8hsgqdt0s9laxl585uwu3xvx2s2pglww Ethereum Address: 0xfCeAAaEB8D564a9D0e71Ef36f027b9D162bC334e To communicate, send an on-chain message from the exploit address or contact whitehat@wanchain.org. etherscan.io/tx/0x305784dab…
English
0
1
2
2.1K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: This address is under investigation in connection with the compromise of this wallet. However, an opportunity remains to resolve this matter through voluntary cooperation. If you wish to discuss a resolution, please respond via an on-chain message by 23:59 UTC on August 4, 2026. We will treat your identity with strict confidence throughout this process. If no response is received by that time, we will assume that you are not interested in pursuing a cooperative resolution, and the investigation will continue accordingly. etherscan.io/tx/0xa9c2ecb7f…
English
0
0
2
2.2K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: We are zeroShadow, a leading blockchain intelligence and investigation firm retained by the client. We can appreciate the skills involved in you to hack the funds from our client’s wallet, and would like to discuss the possibility of you returning a proportion of the funds. If you would like to discuss this opportunity with us then please reply to this message before 2359 UTC on August 4th 2026. If we do not hear from you before this time we will assume that you are unwilling to consider this request. Please be aware that this matter is currently being investigated by multiple parties, including Japanese authorities, the FBI, and us. This offer is made in the spirit of cooperation and with the assurance that we will not pursue any legal claims against you. Upon the successful return of the agreed funds, we will notify all relevant authorities and investigative firms that the matter has been resolved and request that any further investigative efforts be discontinued, to the fullest extent legally and practically possible. We are prepared to resolve this matter confidentially and will not take any action on our part to identify or pursue you once the agreed resolution has been completed. etherscan.io/tx/0x23398ea38…
English
0
1
8
2.9K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: Hello, reaching out to you again as this address is still being monitored by me and Zach and others, you exploited 95eth and 53582 usdc, kindly do the needful and return the 95eth to this address, as you can keep the usdc as bounty fee. Everything is on chain you are still being watched after 2 years+. Do the needful. Refund address: 0xdcFc48E72376563c2e01ba1F7eff71C6Cb3011dA etherscan.io/tx/0x6a50a6d5b…
English
0
1
14
4.1K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x840B3De19e3FAB72fa9A168bD8Dd71B678c57989 on Ethereum. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 is not authorised by ChainConnect. Sender 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30, the bridge deployer signatory. ChainConnect, 28 July 2026 etherscan.io/tx/0xbfb0873f6…
English
0
0
1
2.3K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: Test message: Addressed to the party controlling 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5 and the funds associated with the ChainConnect.com bridge incident of 26 July 2026. We are writing to you directly because we would prefer to resolve this matter without further escalation. Our proposal is as follows: you may retain 15% of the recovered funds as a whitehat bounty. Please return the remaining 85% to 0x840B3De19e3FAB72fa9A168bD8Dd71B678c57989 on Ethereum. Upon receipt of the returned funds, ChainConnect will acknowledge you publicly and in writing as a whitehat, recognise the retained 15% as a bounty for the vulnerability you identified, and will not pursue civil claims or undertake independent identity-attribution efforts in connection with this incident, subject to applicable law and the rights of third parties. If the funds are not returned, ChainConnect will pursue all lawful recovery options available to it, including notifying law-enforcement authorities and engaging specialist blockchain-investigation firms. The relevant addresses have been identified and circulated to exchanges and analytics providers, and tracing efforts are ongoing. We would prefer the first outcome and believe it is the reasonable one for both sides. The decision is yours. Please reply on-chain from 0xd86cbc1892bfda05f3d7e6c17c71709b6ae957a5. We will correspond only with a party that demonstrates control of that address by signing a message. Any offer sent from an address other than 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 is not authorised by ChainConnect. ChainConnect, 28 July 2026 etherscan.io/tx/0xa25fabe02…
English
0
1
1
2.1K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
🚨 Projekt (GREEN/GOLD) reward vault - Loss ~$560K (25 Jul 2026) Network: Ethereum Type: Logic Error (buy-to-earn reward/allocation manipulation) An unverified "buy-to-earn" reward vault (0x574f...42cb) credits an ETH allocation via the permissionless trackPurchase(buyer), which reads the buyer's token balance delta to size the reward, then pays it out with massWithdraw() → msg.sender.transfer(alloc). The attacker flash-loaned ~14K WETH from Morpho, pushed it into dozens of Uniswap V2 memecoin pairs (Kirby Inu, ROTTSCHILD, etc.) and skim()'d the tokens to its own contract, registering huge fake "purchase" allocations for near-zero net cost (the flash loan is repaid in the same tx). It then drained ~301.7 ETH (~$560K) from the vault's reward pool via massWithdraw. trackPurchase never verifies real ETH spent, so self-dealing skims inflate the payout arbitrarily. TX: etherscan.io/tx/0x90f40d3c3… Attacker: etherscan.io/address/0x61e7… Victim: etherscan.io/address/0x574f… (unverified) ⏱️ Real-time alerts: defimon.xyz
English
0
7
62
7.8K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: AFX is extending a white hat settlement offer to the party responsible for the recent bridge incident. Return 70% of the stolen assets to the following address: 0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1B You may retain the remaining 30% as a white hat bounty. Our priority is the recovery of user assets and a swift resolution for the community. We encourage you to act in good faith. This offer is available for a limited time. Best regards, Contract creator of the AFX bridge. etherscan.io/tx/0x788e331d6…
English
0
0
5
2.3K
Defimon Alerts
Defimon Alerts@DefimonAlerts·
💬 Onchain Message: This is the second notification and warning. Funds received through exploitation of relayer 0x394311A6Aaa0D8E3411D8b62DE4578D41322d1bD are fully traced. Return 13.28498 ETH to that address by 2026-07-26 22:30 UTC. Prompt return will be treated as voluntary remediation. Relay and relevant service providers have been notified. etherscan.io/tx/0x229a074dd…
English
0
0
5
2.6K