DeFi Exchange Users Drained by DNS Hijacking Front-End Attack
DNS infrastructure compromise redirected users to a malicious frontend, enabling the theft of over $1M via fraudulent unlimited token approvals.
Web3 Users Targeted by Evolving Social Engineering Malware Campaign
The attack leverages sophisticated social engineering to trick high-value users into installing a malicious binary, fundamentally bypassing smart contract security.
Phishing Airdrop Tricked Users into Malicious Token Approval Theft
Malicious airdrop claims weaponized token approvals, bypassing private key security to execute authorized asset draining across multiple chains.
Malicious Chrome Extension Skims Solana User Swaps via Hidden Transaction Instruction
Browser extension supply chain risk is high; hidden transaction instructions execute perpetual, low-volume asset skimming from user trades.
Malicious Signature Phishing Drains User Wallets across Web3 Ecosystem
The systemic risk is shifting from smart contract flaws to user-signed malicious approvals, enabling rapid, irreversible wallet-draining attacks.
Website Supply Chain Attack Drains User Wallets via Malicious Script
Third-party resource compromise injected a malicious JavaScript drainer, weaponizing a trusted front-end to steal user token approvals.
New Delegation Flaw Exploited by Wallet Drainers to Steal User Assets
EIP-7702-style delegation is weaponized to bypass traditional `approve` checks, granting malicious contracts persistent, batch execution authority over user assets.
Web3 Users Compromised by New Eleven Drainer Phishing-as-a-Service
Eleven Drainer is the latest DaaS threat, leveraging social engineering to trick users into signing malicious token approvals, bypassing smart contract security.
Chromium V8 Zero-Day Flaw Enables Private Key Theft and Wallet Draining
A critical V8 engine zero-day (CVE-2025-10585) permitted remote code execution, exposing user private keys and draining hot wallets.
