
Albert|Open to work
84 posts

Albert|Open to work
@iavlAlbert
寻求岗位中,欢迎联系 Telegram https://t.co/oMzvrcITqF Blockchain Engineer | L2 & Rollups Smart Contracts | Solidity/EVM | Rust/Anchor (Solana) |



🦊 x 🔻打破次元壁 MetaMask现已上线 #TRON,两界交汇,共启未来。


🚨 RWT Token - Loss ~$118K (2026-07-19) Token: $RWT @ $0.00144 Network: BNB Chain Type: Logic Error (deflationary burn-from-pair price manipulation + Flash Loan) An unverified "sell" contract (0x8812) exposes an unprotected sell() that, each call, swaps RWT→USDT into the RWT/USDT PancakePair, adds liquidity, then burns ~72M RWT directly out of the pair's reserves (RWT.burn is onlyOwner and the sell contract holds that role) and sync()s. Repeatedly burning the pool's RWT collapses its reserve and inflates RWT's USDT price, letting the caller extract USDT from the LP far above fair value. The attacker flash-loaned 1M USDT and looped the routine 18×, draining the PancakePair (−158.6K USDT / −110M RWT) and netting ~118K USDT. TX: bscscan.com/tx/0x22300140e… Attacker: bscscan.com/address/0x84dd… Victim: bscscan.com/address/0xc1c2… ⏱️ Real-time alerts: defimon.xyz



🚨SlowMist TI Alert🚨 💸 @edeldotfinance Loss: ~ $350k 🔍 Root Cause: `latestAnswer()` in price source reads `convertToAssets()` from ERC4626 vault. Vault's `totalAssets()` directly uses underlying asset balance, allowing attacker to donate assets via direct transfer to inflate share price. No TWAP, rate cap, or donation protection. 📌 Attacker EOA: 0x58428161bb55c14a413945f06cbdec157f411c76 📌 Victim: Aave Pool 0x3eeeb3cd20f844a578807fc457388ceb9a67faa6 📌 Vulnerable Contracts: - Price Source: 0x4c2c9df4559d80e0a7aa3c7f281704a7992f4ce2 - ERC4626 Vault: 0x14f37168ab9eafcd94d5b142a00e6e9b261bad48 (WrappedBackedTokenImplementation) Flash loan + donation attack on ERC4626 vault manipulates oracle, enabling attacker to drain ~$350k and other reserves. Powered by #SlowMist.AI


🚨 JUDAO (T3 JUDAO) - Loss ~$464K (2026-04-28) Token: $JUDAO @ $0.3957 (DeBank) MC: Unknown (not on CoinGecko) TVL: $22.3M (PancakeSwap JUDAO/USDT LP) Type: Deflationary Token LP Drain The JUDAOToken contract has a custom _update() transfer function that drains tokens directly from the PancakeSwap LP pair on every sell. Two mechanisms cause the drain: (1) the "isBurnPair" check (JUDAO.sol:373-379) burns/redistributes an amount of JUDAO equal to the sell size directly from the pair's reserves when price hasn't risen >5% from the previous day, and (2) the sync() mining mechanism (JUDAO.sol:590-603) drains ~2% of the pair's JUDAO reserves to dead address and mining rewards on each sell. The attacker flash-loaned ~2.3M USDT from Moolah, bought ~5.5M JUDAO to build a position, then sold a portion triggering both drain mechanisms. The combined drains skewed the pair's reserves, allowing the attacker to swap remaining JUDAO back for significantly more USDT than originally spent. Profit: ~205K USDT + 36 BNB (~$22.6K). TX: bscscan.com/tx/0x956e38b8d… Victim: bscscan.com/address/0xf55D… (JUDAOToken) LP Pair: bscscan.com/address/0x5d7b…

🚨On May 12, 2026 at 10:11:11 UTC, the #SQ protocol on #BNB Chain was exploited for 346,137.034345 USDT after the attacker abused a hardcoded owner backdoor🚪in the verified Staking contract at 0x404404a845fff0201f3a4d419b4839fc419c99f7. The attacker sent a type-0x4 transaction with an authorizationList entry that delegated their EOA to helper code at 0x0ecadd99b6a2f5b18a9e05c29074471a5970dd0d, letting the entire exploit execute as the attacker EOA while still batching many calls in one transaction. Once inside Staking, the attacker used the embedded owner bypass to take ownership, set stakeDays to zero, mint 388,100 fake SQ Token staking claims to themselves with stakeOwner(), redeem ten of those claims immediately through repeated unstake() calls for 296,500 USDT, then sweep 2,000,039.407501 SQi from the staking contract and dump it into the SQi/USDT Pancake pair for another 49,637.034345 USDT. The total realized proceeds approximately $346.1K.




$ATOHOOK 被攻击,损失25k。 漏洞原理: ATOHook.getReward() 的 nonReentrant 会先把 Solady ReentrancyGuard 的固定 storage slot 写成哨兵值,而 ATOHook._updateReward() / rewards[msg.sender] 对特定碰撞地址会把这个 guard 值误读成可领取奖励。结果是攻击者用碰撞地址调用 getReward() 时,即使没有真实奖励,也能反复从 Hook 里提走固定数额的 ETH

#CertiKInsight 🚨 We have seen an exploit of ~$243K on ATM token. The transferFrom() includes logic to swap 20% transfer amount of ATM for BSC-USD, so the attacker can repeatedly swap out extra after transfer. skylens.certik.com/tx/bsc/0x37b90… Stay vigilant!



Haven't posted interesting Solidity findings in a while, but this one seems pretty nasty! 👇





