Malicious Chrome Extension Skims Solana User Swaps via Hidden Transaction Instruction
Browser extension supply chain risk is high; hidden transaction instructions execute perpetual, low-volume asset skimming from user trades.
DeFi Protocol Drained via Oracle Manipulation and Flash Loan Attack
Insecure authorization combined with oracle price manipulation created a critical arbitrage window for a $50M flash loan exploit.
Tornado Cash Total Value Locked Hits Record $1.5 Billion
A massive, concentrated capital injection into the privacy primitive validates its essential function as an on-chain anonymity layer for high-value actors.
Kame Aggregator Suffers $1.32 Million Swap Function Exploit
A critical design flaw in Kame Aggregator's `swap()` function allowed unauthorized token transfers, enabling attackers to drain $1.32 million.
Bunni Protocol Suffers $2.3 Million Exploit via Access Control Flaw
An unpatched access control vulnerability in the `sweepToken()` function allowed unauthorized token transfers, exposing liquidity pools to significant loss.
