

Hexagate
643 posts

@hexagate_
Hexagate prevents exploits, hacks, and risks for protocols, chains, exchanges and asset managers. Acq. by Chainalysis. Get access today: https://t.co/n9UkoC25wH



We are aware of a smart contract exploit on the IPOR USDC optimizer on Arbitrum, in total it looks like $369K asset affected Thanks to @hexagate_ and @blockaid_ for the notification and assistance, and @_SEAL_Org for support The issue and it appears to be restricted to a specific set of conditions related to Pectra incompatibility and the oldest vault construction (this should not be an issue with newer vaults) Other vaults appear to be unaffected, we will publish a post-mortem later



A Venus Protocol user was targeted by a phishing attack for $13M—but early alerts from Hexagate and a swift community response enabled an ultra-fast response, total fund recovery, and governance action that actually cost the attacker $3M. Security wins when tech, community, and process work together. chainalysis.com/blog/hexagate-…

Today, a user suffered a devastating phishing attack, and @VenusProtocol has responded swiftly and responsibly by proposing an Emergency Vote — a commendable step to ensure Venus resumes safely while working to recover the user’s stolen funds. Here is the vote details: snapshot.box/#/s:venus-xvs.… Please vote to force-liquidate the hacker's position and recover the stolen funds. 🙏🙏🙏

We also updated our grants page to include all partner programs: → Gaming Accelerator Program with @HelikaGaming → Developer Credits Program with @spaceandtime → Hexgate Security Program with @chainalysis Explore ⤵️ build.avax.network/grants






Posting this message in hopes of connecting with the individual responsible for the GMX V1 exploit. You've successfully executed the exploit; your abilities in doing so are evident to anyone looking into the exploit transactions. The white-hat bug bounty of $5 million continues to be available. It's likely already clear to you that the decision between accepting this bounty and keeping the exploited funds is the difference between being able to spend the funds freely versus taking additional risks to access them. We would like to reiterate that the option of the white-hat bug bounty would lead to an outcome where this $5 million can be freely spent right now. We can assist with providing proof of source of funds if that is ever needed. If we can come to an agreement on this, the $5 million would be legitimately categorised as a white hat bounty. GLP users would be made whole, with the $5 million difference covered by the Treasury's allocated bug bounty funds, so there would be no basis for any further action. Please contact us: Email: security@gmx.io On-chain: (GMX Deployer: 0x5F799f365Fa8A2B60ac0429C48B153cA5a6f0Cf8) Immunefi: (immunefi.com/bug-bounty/gmx…)




We are continuing to investigate yesterday’s incident, and as soon as we have complete and thoroughly validated information we will publish the official post-mortem report. Thank you for your patience, and we appreciate everyone who has reached out to offer support.


Builders on @base get free onchain monitoring and real-time threat detection. We want you to focus on building the future, not fighting off bad actors, so partnered with @hexagate_ to provide their threat prevention to builders who need it. Apply here: hexagateforbase.typeform.com/to/ZbvkRdhM



This was a clear and preventable L, and I'll own it. All Plaza deposits are safe, and the 5 users who lost funds were made whole out of the Plaza treasury. Here are some things that I'm impressed by: -Monitoring from @hexagate_ (paid for by @base) immediately notified the Plaza Core Devs of a suspicious transaction. ✅ - The Plaza Emergency Committee paused the protocol within 20 minutes of notice of a suspicious transaction. ✅ - The Plaze core devs dissected the exploit vector and shipped a fix in under an hour. ✅ - The Plaza Governance Committee approved deployment of the fix in 10 minutes. ✅ -Plaza reimbursed 100% of the losses out of the treasury, so everyone is whole. ✅ - Plaza communicated with the community every step of the way and was 100% transparent. ✅ - The Plaza Community has rallied around Plaza to continue to drive growth. ✅ There will be setbacks. No one said building a new, free, and fair financial system would be easy, but we'll do it anyway, and the Plaza Community will do it together 🤝 So bullish for the next leg of growth 📈