greg
47 posts





On January, 30 @GyroStable has been exploited for around 300.2 ETH (~$696k) A hacker exploited an arbitrary call vulnerability in the _ccipReceive() function of the GydL1CCIPEscrow contract. It allows the recipient field in the CCIP message to be any address, including the GYD token contract itself. Setting recipient = GYD and data = approve(attacker, max) effectively granted the attacker full allowance to the escrow's GYD holdings.




▪ More North Korean malware 🇰🇵 Unobfuscated Javascript (hosted on GitHub) + C2 server currently FUD on VT. When searching for the C2 on Google, I came across a very interesting post from yesterday. It's worth checking out for related IoCs and TTPs. - GitHub repository: https://github[.]com/Mangrovia-ORG/RWAHub/blob/main/public/fonts/fontawesome/fa-regular-400.woff2 - C2 server: 144.172.108.57 - REF: dev.to/danieltofan/a-… H/T @malwrhunterteam



🚨 Don’t face Web3 crime alone. Hacked? Rugged? Scammed? Struggling to report it to the police? Backed by Uppsala Security, ChainBounty is launching a Free Investigation Support Campaign. ✅ What We Provide: Tech support from Uppsala Security (Global Top-tier Firm) Professional investigators assigned to track funds Official Analysis Reports for law enforcement (Free) Investigation fee support (For selected cases) We track your assets with world-class security technology. Apply now. 👇 chainbounty.io/en/event/campa… #ChainBounty #CryptoRescue #ScamAlert #UppsalaSecurity


🚨 Don’t face Web3 crime alone. Hacked? Rugged? Scammed? Struggling to report it to the police? Backed by Uppsala Security, ChainBounty is launching a Free Investigation Support Campaign. ✅ What We Provide: Tech support from Uppsala Security (Global Top-tier Firm) Professional investigators assigned to track funds Official Analysis Reports for law enforcement (Free) Investigation fee support (For selected cases) We track your assets with world-class security technology. Apply now. 👇 chainbounty.io/en/event/campa… #ChainBounty #CryptoRescue #ScamAlert #UppsalaSecurity










