Seeyuh Security

37 posts

Seeyuh Security banner
Seeyuh Security

Seeyuh Security

@versatilitylab

On-chain security infra.

NYC شامل ہوئے Ağustos 2023
7 فالونگ35 فالوورز
Seeyuh Security
Seeyuh Security@versatilitylab·
Sweat Economy (@SweatEconomy) Security Incident Report Report Date: April 30, 2026 Severity: High (Contract Vulnerability Exploitation – Mitigated) 1. Executive Summary On April 29, 2026, at approximately 13:36 UTC, the SWEAT token contract of Sweat Economy (a Move-to-Earn project on @NEARProtocol) was exploited. The attacker drained approximately 13.71 billion SWEAT (roughly 65% of total supply, valued at approximately $2.5M–$3.5M at the time of the incident) from the project’s Foundation wallet and top holder addresses within 30 seconds. Blockaid provided real-time detection and alerts. The team responded swiftly: the token contract was paused, external user balances were fully restored, and operations have since returned to normal. No permanent loss was incurred by external users. 2. Impact - Direct Loss: ~13.71 billion SWEAT (65% of total supply). - User Impact: Zero permanent loss — all external user balances were fully restored. - Project Impact: Temporary contract pause and Foundation wallet depletion; short-term reputational and market sentiment effects, though $SWEAT price remained relatively stable. - Broader Context: This incident is part of the ongoing 2026 DeFi security wave, which has seen total losses exceed $800M. 3. Project Response and Recovery - Immediate contract pause to prevent further drainage. - Coordination with exchanges and liquidity providers to freeze attacker funds. - Rapid deployment of a patched contract and full restoration of user balances. - Ongoing actions include formal incident reporting to law enforcement, comprehensive forensic analysis, and a full post-mortem audit. 4. Root Cause Analysis (Preliminary) The vulnerability stemmed from the April 27 contract redeployment, which introduced the refund_first and refund_second functions without sufficient security review. This represents a classic case of zero-day vulnerability introduced during contract upgrade combined with centralized control of the Foundation wallet. 5. How Seeyuh Can Prevent Incidents Like Sweat Economy Seeyuh is the production evolution of the OpenAI Hackathon Champion project SEEYUH, an Agentic Zero-Day Vulnerability Guardian powered by the OpenAI Agents SDK. Unlike traditional static analyzers, Seeyuh functions as an AI-powered Red Team that thinks and simulates attacks like a real adversary. In the context of the Sweat Economy incident, Seeyuh delivers proactive defense through: - Pre-deployment Scanning: Before any contract redeployment (such as the April 27 update), Seeyuh’s agents automatically analyze new functions (refund_first/refund_second), simulate drain/refund attack paths, and surface zero-day risks with executable PoC. - Attack Chain Simulation: One-click reproduction of the full exploit sequence — “malicious refund call → mass drainage → exchange laundering” — enabling teams to identify and fix issues prior to mainnet deployment. - Real-time Monitoring: Post-deployment surveillance of Foundation wallets and token contract calls, with instant alerts on anomalous patterns. - Rapid Forensic Analysis: Input a transaction hash to automatically reconstruct the attack path, identify the root cause, and generate remediation recommendations. Seeyuh’s Core Positioning: We transform DeFi security from reactive firefighting to proactive defense. By leveraging agentic intelligence, Seeyuh helps projects like Sweat Economy eliminate zero-day vulnerabilities — such as those arising from contract upgrades — before they result in multi-million-dollar incidents. Ready to safeguard your protocol? Scan your contracts for free today at Seeyuh.com Seeyuh — Turning passive audits into active, intelligent protection.
Seeyuh Security tweet media
English
0
0
2
36
OpenAI
OpenAI@OpenAI·
Want to secure an early ticket to OpenAI DevDay? Build something with GPT-5.5 and Image Gen. Each week, we’ll select 2–3 favorites to win free tickets to OpenAI DevDay 2026. Codex will help us find the best submissions and our team will select the winners. Reply with #OpenAIDevDay2026, a playable link, and a quick note on how you built it.
OpenAI@OpenAI

OpenAI DevDay is back. San Francisco September 29

English
288
178
2.3K
544.4K
Seeyuh Security ری ٹویٹ کیا
OpenAI
OpenAI@OpenAI·
OpenAI DevDay is back. San Francisco September 29
Română
215
214
3.7K
1.5M
Seeyuh Security ری ٹویٹ کیا
Aave
Aave@aave·
After discussions with several stakeholders, Aave service providers, @Ether_fi, @KelpDAO, @LayerZero_Core, @compound_xyz, and others have submitted a governance proposal to the @arbitrum DAO requesting the release of ETH frozen by the Arbitrum Security Council following the April 18 rsETH incident. If released, the funds will be directed into DeFi United, a coordinated cross-protocol recovery effort aimed at restoring rsETH backing and remediating impairment of rsETH for users. This contribution would meaningfully advance the path to resolution as others confirm their commitments. The proposal is open for review, and we welcome feedback from the Arbitrum community. forum.arbitrum.foundation/t/constitution…
English
94
198
1.1K
169.2K
Seeyuh Security
Seeyuh Security@versatilitylab·
@AlexAuroraDev @litecoin A clear reminder that lower-hashrate chains remain vulnerable to deep reorgs, especially when cross-chain protocols assume fast finality.
English
1
0
0
1.3K
Alex Shevchenko 🇺🇦
Alex Shevchenko 🇺🇦@AlexAuroraDev·
10h ago @litecoin experienced a coordinated attack on the chain that resulted in 13 blocks reorg that took more than 3h to generate. During this time attackers were performing double spend attacks on multiple cross-chain swapping protocols. We are investigating the situation.
English
212
425
2.3K
1.2M
Seeyuh Security
Seeyuh Security@versatilitylab·
This zero-day + invalid MWEB peg-out incident is exactly why we built Seeyuh. Our agentic system proactively scans for and simulates these kinds of edge-case exploits in bridges, peg mechanisms, and consensus code — before they hit production. Kelp/Aave-style collateral exploits and now Litecoin’s MWEB zero-day show how fast these attacks move. Real-time agentic red-teaming is no longer optional. Glad Litecoin recovered cleanly. Respect for the transparency.
Litecoin@litecoin

Litecoin update: • A zero-day bug caused a DoS attack that disrupted major mining pools. • Non-updated mining nodes allowed an invalid MWEB transaction allowing them to peg out coins to third party DEX’s • A 13-block reorg reversed those invalid transactions — they will not be included in the main chain • All valid transactions during that period remain unaffected • The bug is now fully patched, and the network continues to operate normally

English
0
0
1
56
Seeyuh Security
Seeyuh Security@versatilitylab·
Sorry to see the $113k drain @esotericpigeon — private key leaks from "trusted" connected tools like Axiom and J7Tracker are brutal because they often happen silently without a classic malicious signature. This is exactly the kind of sophisticated, permission-based exposure that Seeyuh was built to catch early. Our agentic system proactively scans and simulates attack paths across the dApps and protocols you connect to, surfacing zero-day risks before funds walk. Hot wallet opsec in the trenches is getting harder every month. Tools that actively red-team your connections (instead of just reacting) are quickly becoming table stakes. Wishing you a fast bounce-back and stronger security setup going forward.
Esoteric@esotericpigeon

Wallet just got drained HYWo71Wk9PNDe5sBaRKazPnVyGnQDiwgXCFKvgAQ1ENp I think it was something I was already connected to, looking into it now, any help is appreciated.

English
0
0
0
138
Seeyuh Security
Seeyuh Security@versatilitylab·
True resilience requires cryptographic guarantees: immutable onchain provenance for model weights, and ZK-verifiable safety audits to avoid single points of failure.
Seeyuh Security@versatilitylab

@sama Using frontier models to harden critical open-source software and infrastructure is the right direction.

English
0
0
1
85
Seeyuh Security
Seeyuh Security@versatilitylab·
@sama Using frontier models to harden critical open-source software and infrastructure is the right direction.
English
0
0
1
964
Seeyuh Security ری ٹویٹ کیا
Sam Altman
Sam Altman@sama·
"post-AGI, no one is going to work and the economy is going to collapse" "i am switching to polyphasic sleep because GPT-5.5 in codex is so good that i can't afford to be sleeping for such long stretches and miss out on working"
English
1.2K
606
11.2K
1.6M
Seeyuh Security ری ٹویٹ کیا
Cursor
Cursor@cursor_ai·
GPT-5.5 is now available in Cursor! It's currently the top model on CursorBench at 72.8%. We've partnered with OpenAI to offer it for 50% off through May 2.
English
173
269
5.7K
503K