For teams serious about minimizing exploit risk, Firewall isn’t optional.
It’s the missing layer between passive detection and real enforcement.
📖 Read the full breakdown: hackenio.cc/extractor-fire…
📢 New from Extractor: Firewall
A tool for smart contract teams who want to stop exploits – not just study them after the fact.
It lets you set enforceable rules that block high-risk behavior before damage is done.
Here’s how it works 🧵
Two exploits tonight across two different projects – SwapNet and @ApertureFinance.
Both caused by unrestricted malicious arbitrary external calls, allowing anyone to drain wallets that had previously approved tokens to the Router.
Total losses: ~$17.2M
Recap & analysis 👇🧵
Uniswap V4 Liquidity Providers were beneficiaries and the Yield team has messaged to one of the LPs on-chain:
“You retain 10% as a bug bounty, return the rest.”
But no official statement has been posted on @yield’s socials yet.
On-chain msg: etherscan.io/tx/0x816cc2d41…
🚨Alert: @yield has lost ~$3.73M due to a slippage in Vault operation of swapping stkGHO to USDC.
3.84M GHO was swapped to only 112K USDC – a net loss of ≈$3.73M.
Swap Tx: etherscan.io/tx/0x6aff59e80…
More insights to follow 🧵
@Truebitprotocol Attack transaction: etherscan.io/tx/0xcd4755645…
Malicious contract was deployed right before the attack (in the same block) via private mempool with attack contract deployment at block position 3 and attack transaction at block position 4:
🚨 Alert 🚨 @Truebitprotocol was exploited for 8,535 ETH ($26.5M) due to vulnerability in smart contract Truebit Protocol: Purchase (etherscan.io/address/0x764c…)
Details in the thread below👇
TMX team have not yet made public announcement about the incident. However, they already actively upgrading vulnerable contracts and messaged exploiters on-chain, proposing 20% bounty and returning remaining 80%.
IDM tx: arbiscan.io/tx/0xb31a0e8b0…
🚨 Alert 🚨 @TMXTribe (GMX fork) was exploited on Arbitrum for $1.5M due to smart contract vulnerability. Seems that exploit was ongoing for about 36 hours and TMX have not taken any actions to contain it.
Funds were bridged to Ethereum and deposited to Tornado Cash.