Decentralized Exchange Bunni Drained $8.4 Million Exploiting Custom Liquidity Logic
Custom liquidity distribution functions with subtle rounding errors create critical arithmetic vulnerabilities that enable catastrophic flash-loan exploits.
Stablecoin Protocol Drained by Malicious Proxy Contract Deployment Logic Flaw
A pre-staged deployment flaw granted an attacker administrative control, enabling a malicious proxy upgrade that drained $1 million in user assets.
Exchange Hot Wallet Private Key Inferred via Signature Flaw
Predictable cryptographic nonces in the signing infrastructure allowed a sophisticated actor to derive the hot wallet's private key, leading to a catastrophic asset drain.
DeFi Protocol USPD Drained by Hidden Proxy Contract Admin Key Compromise
A compromised proxy initialization allowed a threat actor to plant a malicious implementation for a delayed, seven-figure asset drain.
Stablecoin Protocol USPD Drained via Stealth Proxy Initialization Attack
A novel Clandestine Proxy In the Middle attack compromised USPD's deployment, enabling the stealthy minting of 98M tokens and a $1M collateral drain.
Balancer V2 Stable Pools Drained Exploiting Compounded Precision Rounding Flaw
A catastrophic arithmetic precision flaw in ComposableStablePools allowed batch-swap manipulation, enabling the systematic draining of $128M in liquidity.
Balancer V2 Stable Pools Drained via Compounded Precision Rounding Flaw
Precision loss in Balancer's core invariant math was weaponized via atomic batch swaps, compromising pool integrity and draining $128M.
High-Profile Web3 Social Accounts Compromised, Leading to User Wallet Drains
Supply chain failure via compromised employee accounts weaponizes trusted social channels, tricking users into malicious token approvals.
Stablecoin Protocol Drained via Compromised Proxy Implementation Attack
A deployment-phase flaw allowed an attacker to seize proxy admin rights, enabling unauthorized token minting and a $1M liquidity drain.
