Exchange Hot Wallet Private Key Inferred via Signature Flaw
Predictable cryptographic nonces in the signing infrastructure allowed a sophisticated actor to derive the hot wallet's private key, leading to a catastrophic asset drain.
Goldfinch User Wallet Drained via Legacy Contract Share Price Manipulation
A legacy contract approval flaw was weaponized by an attacker to manipulate share price and drain $330K, underscoring systemic risk in stale permissions.
Yearn Legacy Pool Drained Exploiting Stale Storage Value Arithmetic Flaw
A critical logic flaw in gas-saving state caching allowed an attacker to mint infinite tokens, demonstrating the systemic risk of legacy contract arithmetic.
Balancer V2 Pools Drained across Multiple Chains Exploiting Rounding Flaw
A critical rounding error in the Balancer V2 Composable Stable Pool logic allowed an attacker to drain $128 million across seven blockchains.
