Resupply Lending Protocol Exploited via Oracle Price Manipulation Vulnerability
An integer division flaw in a newly deployed vault allowed attackers to manipulate exchange rates, enabling undercollateralized borrowing and significant asset drain.
Shibarium Bridge Drained via Validator Key Compromise and Flash Loan
A critical vulnerability in validator key management combined with flash loan manipulation enabled a $2.4 million asset drain from the Shibarium bridge, underscoring systemic risks in L2 security models.
Cetus DEX on Sui Network Exploited via Price Oracle Manipulation
A critical flaw in Cetus Protocol's price oracle allowed attackers to inject fake liquidity, compromising asset integrity and draining $260 million.
Kinto Ethereum Layer 2 Suffers Smart Contract Exploit, Halts Operations
A critical smart contract vulnerability on Kinto's lending pools enabled the unauthorized minting of fake tokens, leading to a $1.55 million asset drain and platform insolvency.
UPCX Payment Platform Suffers $70 Million Private Key Compromise
A compromised private key enabled an attacker to maliciously upgrade a smart contract, facilitating unauthorized withdrawal of $70 million from management accounts.
Yala Stablecoin Depegs after Unauthorized Bridge Deployment Exploit
A critical bridge deployment key compromise enabled an attacker to depeg Yala's stablecoin, highlighting severe risks in key management.
Odin.fun Suffers $7 Million Bitcoin Loss via AMM Liquidity Manipulation
A critical flaw in Odin.fun's Automated Market Maker allowed price spoofing, enabling attackers to drain significant Bitcoin liquidity.
GMX V1 Suffers $40 Million Reentrancy Exploit on Arbitrum
A critical reentrancy vulnerability in GMX V1's GLP pricing mechanism allowed attackers to manipulate asset valuations, enabling unauthorized token minting and liquidity drain.
Venus Protocol Recovers $13.5 Million from Lazarus Group Phishing Attack
A targeted phishing exploit against a high-value user's delegated account control enabled asset drain, underscoring critical off-chain vulnerability.
