Binance Square
#exploit

exploit

86,277 مشاهدات
165 يقومون بالنقاش
Misty Carrousal Feiq
·
--
مقالة
Цифрове пограбування десятиліття: як Kelp DAO втратив $300 млн за лічені хвилини20 квітня 2026 року увійде в історію кібербезпеки як день одного з найбільш зухвалих зламів у світі децентралізованих фінансів. Хакерам вдалося викрасти понад 300 мільйонів доларів, поставивши під удар стабільність усього крипторинку. Зловмисники виявили критичну вразливість у кросчейн-інфраструктурі, яку використовував протокол Kelp DAO. Через помилку в коді мосту на базі технології LayerZero, хакери змогли скомпрометувати систему перевірки транзакцій. Це дозволило їм випустити фіктивні підтвердження та вивести приблизно 116 500 rsETH (ліквідних токенів рестейкінгу). За поточним курсом ринкова вартість втрачених активів оцінюється у $293,7 млн. Паніка на ринку Оскільки токени rsETH широко використовувалися як застава в інших DeFi-сервісах, удар відчув увесь сектор: Криза ліквідності: Інвестори почали масово виводити кошти з найбільших платформ. Тільки з протоколу Aave за лічені години було виведено понад $9 млрд.Падіння суміжних проектів: Щонайменше 9 інших DeFi-протоколів, інтегрованих з Kelp DAO, зафіксували аномальні збитки або технічні збої.Блокування операцій: Команда Kelp DAO була змушена екстрено призупинити дію смарт-контрактів, щоб зупинити подальший витік коштів. Хто за цим стоїть? Провідні компанії з блокчейн-безпеки, такі як Chainalysis та PeckShield, вже зафіксували характерний "почерк" транзакцій. Більшість доказів вказує на північнокорейське угруповання Lazarus Group, відоме своїми масштабними атаками на криптобіржі та мости. На цей час операції з rsETH заморожені. Експерти радять: Не панікувати та не намагатися проводити обмін активів на неперевірених DEX-майданчиках через величезні прослизання ціни.Відкликати дозволи (Revoke) для смарт-контрактів, які можуть бути скомпрометовані.Стежити за офіційними каналами Kelp DAO щодо плану компенсації збитків. Цей інцидент знову піднімає гостре питання безпеки кросчейн-мостів, які залишаються найбільш вразливою ланкою сучасної криптоекономіки. #Hacked #KelpDAO #exploit #SecurityAlert #news

Цифрове пограбування десятиліття: як Kelp DAO втратив $300 млн за лічені хвилини

20 квітня 2026 року увійде в історію кібербезпеки як день одного з найбільш зухвалих зламів у світі децентралізованих фінансів. Хакерам вдалося викрасти понад 300 мільйонів доларів, поставивши під удар стабільність усього крипторинку.

Зловмисники виявили критичну вразливість у кросчейн-інфраструктурі, яку використовував протокол Kelp DAO. Через помилку в коді мосту на базі технології LayerZero, хакери змогли скомпрометувати систему перевірки транзакцій.
Це дозволило їм випустити фіктивні підтвердження та вивести приблизно 116 500 rsETH (ліквідних токенів рестейкінгу). За поточним курсом ринкова вартість втрачених активів оцінюється у $293,7 млн.
Паніка на ринку
Оскільки токени rsETH широко використовувалися як застава в інших DeFi-сервісах, удар відчув увесь сектор:
Криза ліквідності: Інвестори почали масово виводити кошти з найбільших платформ. Тільки з протоколу Aave за лічені години було виведено понад $9 млрд.Падіння суміжних проектів: Щонайменше 9 інших DeFi-протоколів, інтегрованих з Kelp DAO, зафіксували аномальні збитки або технічні збої.Блокування операцій: Команда Kelp DAO була змушена екстрено призупинити дію смарт-контрактів, щоб зупинити подальший витік коштів.
Хто за цим стоїть?
Провідні компанії з блокчейн-безпеки, такі як Chainalysis та PeckShield, вже зафіксували характерний "почерк" транзакцій. Більшість доказів вказує на північнокорейське угруповання Lazarus Group, відоме своїми масштабними атаками на криптобіржі та мости.
На цей час операції з rsETH заморожені. Експерти радять:
Не панікувати та не намагатися проводити обмін активів на неперевірених DEX-майданчиках через величезні прослизання ціни.Відкликати дозволи (Revoke) для смарт-контрактів, які можуть бути скомпрометовані.Стежити за офіційними каналами Kelp DAO щодо плану компенсації збитків.
Цей інцидент знову піднімає гостре питання безпеки кросчейн-мостів, які залишаються найбільш вразливою ланкою сучасної криптоекономіки.

#Hacked #KelpDAO #exploit #SecurityAlert #news
مقالة
🚨 DeFi bajo presión: el exploit de KelpDAO que puso en alerta a AaveEn menos de 48 horas, un incidente en KelpDAO generó tensiones visibles en $AAVE y dejó una pregunta clave sobre la mesa: 👉 ¿Qué tan seguro es usar LRT como colateral en DeFi? Si operas o inviertes en este ecosistema, esto no es ruido: es una señal. 🧠 Qué pasó realmente El mecanismo fue relativamente simple, pero con efectos amplificados por la composabilidad DeFi: Se manipuló el bridge de KelpDAOSe generaron ~116,500 rsETH sin respaldo verificableSe usaron como colateral en AaveSe pidió prestado $ETH real contra ese colateral Resultado inmediato Pools de ETH, USDT y USDC alcanzaron alta utilización (cerca del 100%)Retiros limitados temporalmente por falta de liquidez disponibleExposición de Aave a colateral potencialmente débil 👉 No es solo un exploit: es un test de estrés real para el modelo DeFi actual. 📉 Por qué esto importa ahora Los efectos fueron rápidos: TVL en DeFi: de ~$99.5B → a ~$86.3BAave: salida de ~$8.45B en 48hPresión en liquidez de pools clave Pero el dato más importante no es la caída, sino esto: 👉 El mercado está reevaluando qué considera colateral “seguro”. No todo lo que sigue el precio de ETH tiene el mismo nivel de riesgo. 🧩 Cambio de narrativa La narrativa está evolucionando: Antes: “Restaking = rendimiento adicional relativamente seguro” Ahora: “Restaking = eficiencia de capital con riesgo estructural” Lo que el mercado empieza a descontar: Los LRT pueden introducir riesgo no evidente, Bridges y derivados aumentan la complejidad, los protocolos de lending pueden estar sobreexpuestos y el rendimiento ya no compensa automáticamente el riesgo 👉 Estamos viendo un ajuste en la percepción de riesgo. 📊 Métricas clave a seguir Para traders e inversores: Health Factor promedio en AaveParidad rsETH / ETHCambios en LTV para LRTNivel de utilización en pools Ahí aparecerán las próximas señales relevantes. ⚙️ El punto crítico: colateral derivado El rsETH forma parte de la narrativa de restaking: Está diseñado para representar ETH en staking pero es dependiente de múltiples capas (validadores, bridges, contratos) 👉 En términos prácticos: Es un derivado, no el activo base. El problema no es su existencia, sino cómo se valora dentro del sistema. ⏳ Qué esperar a partir de aquí Corto plazo Ajustes de riesgo en Aave (LTV, colaterales permitidos)Volatilidad en activos relacionados con ETHPosibles desviaciones de precio en LRT Mediano plazo Revisión de modelos de riesgo en lendingMayor foco en auditorías y diseño de protocolos Largo plazo Cambio estructural en cómo se evalúa el colateral en DeFi ⚠️ Riesgos a considerar Liquidaciones en cascada si hay pérdida de paridadPosible bad debt en protocolosContagio hacia otros LRT 👉 Escenario a vigilar: eventos similares a stETH 2022, pero en un entorno más complejo. 🧠 Conclusión Este evento deja una lección clara: El problema no fue solo el exploit, sino cómo el sistema trató activos derivados como colateral equivalente al activo base. Eso introduce riesgo… y el mercado ya empezó a ajustarlo. 🎯 Enfoque para traders e inversores Este tipo de eventos suele marcar puntos de inflexión: Repricing de riesgoMenor apalancamientoMayor selectividad en colaterales 👉 La clave ahora no es reaccionar con pánico, sino entender dónde está la exposición real. #KelpDAOFacesAttack #AAVE #rsETH #exploit #BinanceSquareTalks $RAVE {future}(AAVEUSDT) {future}(ETHUSDT) {future}(BTCUSDT)

🚨 DeFi bajo presión: el exploit de KelpDAO que puso en alerta a Aave

En menos de 48 horas, un incidente en KelpDAO generó tensiones visibles en $AAVE y dejó una pregunta clave sobre la mesa:
👉 ¿Qué tan seguro es usar LRT como colateral en DeFi?
Si operas o inviertes en este ecosistema, esto no es ruido: es una señal.

🧠 Qué pasó realmente
El mecanismo fue relativamente simple, pero con efectos amplificados por la composabilidad DeFi:
Se manipuló el bridge de KelpDAOSe generaron ~116,500 rsETH sin respaldo verificableSe usaron como colateral en AaveSe pidió prestado $ETH real contra ese colateral
Resultado inmediato
Pools de ETH, USDT y USDC alcanzaron alta utilización (cerca del 100%)Retiros limitados temporalmente por falta de liquidez disponibleExposición de Aave a colateral potencialmente débil
👉 No es solo un exploit: es un test de estrés real para el modelo DeFi actual.

📉 Por qué esto importa ahora
Los efectos fueron rápidos:
TVL en DeFi: de ~$99.5B → a ~$86.3BAave: salida de ~$8.45B en 48hPresión en liquidez de pools clave
Pero el dato más importante no es la caída, sino esto:
👉 El mercado está reevaluando qué considera colateral “seguro”.
No todo lo que sigue el precio de ETH tiene el mismo nivel de riesgo.

🧩 Cambio de narrativa
La narrativa está evolucionando:
Antes:
“Restaking = rendimiento adicional relativamente seguro”
Ahora:
“Restaking = eficiencia de capital con riesgo estructural”

Lo que el mercado empieza a descontar:
Los LRT pueden introducir riesgo no evidente, Bridges y derivados aumentan la complejidad, los protocolos de lending pueden estar sobreexpuestos y el rendimiento ya no compensa automáticamente el riesgo
👉 Estamos viendo un ajuste en la percepción de riesgo.

📊 Métricas clave a seguir
Para traders e inversores:
Health Factor promedio en AaveParidad rsETH / ETHCambios en LTV para LRTNivel de utilización en pools
Ahí aparecerán las próximas señales relevantes.

⚙️ El punto crítico: colateral derivado
El rsETH forma parte de la narrativa de restaking:
Está diseñado para representar ETH en staking pero es dependiente de múltiples capas (validadores, bridges, contratos)
👉 En términos prácticos:
Es un derivado, no el activo base.
El problema no es su existencia, sino cómo se valora dentro del sistema.

⏳ Qué esperar a partir de aquí
Corto plazo
Ajustes de riesgo en Aave (LTV, colaterales permitidos)Volatilidad en activos relacionados con ETHPosibles desviaciones de precio en LRT

Mediano plazo
Revisión de modelos de riesgo en lendingMayor foco en auditorías y diseño de protocolos

Largo plazo
Cambio estructural en cómo se evalúa el colateral en DeFi

⚠️ Riesgos a considerar
Liquidaciones en cascada si hay pérdida de paridadPosible bad debt en protocolosContagio hacia otros LRT
👉 Escenario a vigilar: eventos similares a stETH 2022, pero en un entorno más complejo.

🧠 Conclusión
Este evento deja una lección clara:
El problema no fue solo el exploit, sino cómo el sistema trató activos derivados como colateral equivalente al activo base.
Eso introduce riesgo… y el mercado ya empezó a ajustarlo.

🎯 Enfoque para traders e inversores
Este tipo de eventos suele marcar puntos de inflexión:
Repricing de riesgoMenor apalancamientoMayor selectividad en colaterales
👉 La clave ahora no es reaccionar con pánico, sino entender dónde está la exposición real.

#KelpDAOFacesAttack #AAVE #rsETH #exploit #BinanceSquareTalks $RAVE

Kelp DAO, a liquid restaking protocol connected to EigenLayer, was exploited on April 18, 2026. Around $292 million worth of $RSETH was drained through its LayerZero cross-chain bridge. The attacker forged a cross-chain message that the system accepted as valid, even though no real deposit happened on the source chain. This allowed them to mint or unlock about 116,500 rsETH without any actual ETH backing it. The stolen rsETH was then sent to Aave, a major DeFi lending protocol, where it was used as collateral to borrow large amounts of real ETH and wrapped ETH. By the time protocols responded, much of the borrowed ETH had already moved. A second attack was nearly executed that could have drained another $100M, but a rapid blacklist response stopped it just before it went through. Kelp DAO paused rsETH contracts across mainnet and several Layer-2 chains. Aave froze the $RSETH markets. Compound, Euler Labs, and Venus Protocol also reviewed and adjusted their exposure. The failure is reported to have happened in the Decentralized Verifier Network layer, which is responsible for confirming cross-chain messages, not in the core smart contracts themselves. This points to a configuration weakness in how external validation was trusted. The exploit was first reported by the blockchain investigator ZachCBT and is now considered one of the largest DeFi incidents of 2026, showing how a single bridge failure can spread risk across the entire DeFi ecosystem within minutes. #KelpDAO #security #Hack #Hacked #exploit
Kelp DAO, a liquid restaking protocol connected to EigenLayer, was exploited on April 18, 2026. Around $292 million worth of $RSETH was drained through its LayerZero cross-chain bridge.

The attacker forged a cross-chain message that the system accepted as valid, even though no real deposit happened on the source chain. This allowed them to mint or unlock about 116,500 rsETH without any actual ETH backing it.

The stolen rsETH was then sent to Aave, a major DeFi lending protocol, where it was used as collateral to borrow large amounts of real ETH and wrapped ETH. By the time protocols responded, much of the borrowed ETH had already moved.

A second attack was nearly executed that could have drained another $100M, but a rapid blacklist response stopped it just before it went through.

Kelp DAO paused rsETH contracts across mainnet and several Layer-2 chains. Aave froze the $RSETH markets. Compound, Euler Labs, and Venus Protocol also reviewed and adjusted their exposure.

The failure is reported to have happened in the Decentralized Verifier Network layer, which is responsible for confirming cross-chain messages, not in the core smart contracts themselves. This points to a configuration weakness in how external validation was trusted.

The exploit was first reported by the blockchain investigator ZachCBT and is now considered one of the largest DeFi incidents of 2026, showing how a single bridge failure can spread risk across the entire DeFi ecosystem within minutes.

#KelpDAO #security #Hack #Hacked #exploit
A $290M exploit just cracked $LAYERZERO’s trust premium 🧨 This isn’t just a hack; it’s a liquidity shock to the whole cross-chain narrative. A single-node weakness in the verifier design turned $rsETH into a stress point, and traders are now pricing in more scrutiny, wider spreads, and a faster rotation out of exposed DeFi names. Not financial advice. Manage your risk and protect your capital. #Crypto #DeFi #Exploit #LayerZero #Altcoins ✦
A $290M exploit just cracked $LAYERZERO’s trust premium 🧨

This isn’t just a hack; it’s a liquidity shock to the whole cross-chain narrative. A single-node weakness in the verifier design turned $rsETH into a stress point, and traders are now pricing in more scrutiny, wider spreads, and a faster rotation out of exposed DeFi names.

Not financial advice. Manage your risk and protect your capital. #Crypto #DeFi #Exploit #LayerZero #Altcoins
A $290M exploit just cracked $LAYERZERO’s trust premium 🧨 This isn’t just a hack; it’s a liquidity shock to the whole cross-chain narrative. A single-node weakness in the verifier design turned $rsETH into a stress point, and traders are now pricing in more scrutiny, wider spreads, and a faster rotation out of exposed DeFi names. Not financial advice. Manage your risk and protect your capital. #Crypto #DeFi #Exploit #LayerZero #Altcoins ✦
A $290M exploit just cracked $LAYERZERO’s trust premium 🧨

This isn’t just a hack; it’s a liquidity shock to the whole cross-chain narrative. A single-node weakness in the verifier design turned $rsETH into a stress point, and traders are now pricing in more scrutiny, wider spreads, and a faster rotation out of exposed DeFi names.

Not financial advice. Manage your risk and protect your capital. #Crypto #DeFi #Exploit #LayerZero #Altcoins
#Zcash patched four critical bugs disclosed April 4, including an Orchard tx #exploit that could instantly crash nodes and a turnstile accounting flaw in zcashd v5.10.0. Major pools like ViaBTC and AntPool applied fixes ahead of public release. $ZEC
#Zcash patched four critical bugs disclosed April 4, including an Orchard tx #exploit that could instantly crash nodes and a turnstile accounting flaw in zcashd v5.10.0. Major pools like ViaBTC and AntPool applied fixes ahead of public release. $ZEC
😱 Напечатал 1 млрд токенов и сразу слил в рынок Похоже, в экосистеме Polkadot снова нашли слабое место. Хакер провернул грязный трюк: просто создал 1 млрд DOT из воздуха и не стал тянуть — слил всё одной транзакцией. На выходе получил около 108.2 ETH (примерно $237k). 💬 Что здесь важно: это не классический взлом кошельков. Это удар по логике токена или контракта, где появилась возможность “минтить” лишние монеты. Такие истории обычно заканчиваются одинаково: цена летит вниз, ликвидность страдает, а держатели остаются крайними. ⚠️ Но главный момент — такие кейсы часто касаются не всей сети, а отдельных токенов/контрактов внутри экосистемы. Так что паниковать рано, но повод задуматься есть. #Polkadot #crypto #exploit #defi 👀 Подписывайся, чтобы не пропускать такие разборы и не ловить подобные сюрпризы на своём депозите
😱 Напечатал 1 млрд токенов и сразу слил в рынок

Похоже, в экосистеме Polkadot снова нашли слабое место.

Хакер провернул грязный трюк:
просто создал 1 млрд DOT из воздуха и не стал тянуть — слил всё одной транзакцией.

На выходе получил около 108.2 ETH (примерно $237k).

💬 Что здесь важно:
это не классический взлом кошельков.
Это удар по логике токена или контракта, где появилась возможность “минтить” лишние монеты.

Такие истории обычно заканчиваются одинаково:
цена летит вниз,
ликвидность страдает,
а держатели остаются крайними.

⚠️ Но главный момент — такие кейсы часто касаются не всей сети, а отдельных токенов/контрактов внутри экосистемы.

Так что паниковать рано, но повод задуматься есть.

#Polkadot #crypto #exploit #defi

👀 Подписывайся, чтобы не пропускать такие разборы и не ловить подобные сюрпризы на своём депозите
Bakubb:
2 fake newsy w 1 poście od bota
🚨 $AAVE e Under Pressure: $292M Kelp DAO Exploit Triggers Liquidity Shock Across DeFi Aave is facing intense market stress following a major incident involving Kelp DAO’s rsETH, which reportedly resulted in a $292 million exploit and triggered widespread panic across the DeFi ecosystem.$ETH {spot}(ETHUSDT) According to reports, the attacker managed to drain approximately 116,500 rsETH from the LayerZero bridge connected to Kelp DAO. These assets were then deposited into Aave V3 as collateral, allowing the borrowing of nearly $236 million in WETH. The critical issue now is that the deposited rsETH is no longer properly backed, leaving these positions effectively unliquidatable. This has left Aave exposed to an estimated $280 million in bad debt that the protocol may struggle to recover. As fear spread across the market, a wave of withdrawals followed, pushing total ETH outflows to around $5.4 billion. Notably, Justin Sun alone reportedly withdrew 65,584 ETH (worth roughly $154 million). The situation escalated further as $ETH ETH utilization on Aave hit 100%, meaning liquidity for withdrawals is now extremely limited. This event is being described as one of the first real stress tests for Aave’s Umbrella safety module, and potentially the largest DeFi exploit observed in 2026 so far. The situation is still developing, and the full impact on Aave and the broader DeFi market remains uncertain. #DeFi #Aave #CryptoNews #Ethereum #Exploit
🚨 $AAVE e Under Pressure: $292M Kelp DAO Exploit Triggers Liquidity Shock Across DeFi

Aave is facing intense market stress following a major incident involving Kelp DAO’s rsETH, which reportedly resulted in a $292 million exploit and triggered widespread panic across the DeFi ecosystem.$ETH

According to reports, the attacker managed to drain approximately 116,500 rsETH from the LayerZero bridge connected to Kelp DAO. These assets were then deposited into Aave V3 as collateral, allowing the borrowing of nearly $236 million in WETH.

The critical issue now is that the deposited rsETH is no longer properly backed, leaving these positions effectively unliquidatable. This has left Aave exposed to an estimated $280 million in bad debt that the protocol may struggle to recover.

As fear spread across the market, a wave of withdrawals followed, pushing total ETH outflows to around $5.4 billion. Notably, Justin Sun alone reportedly withdrew 65,584 ETH (worth roughly $154 million).
The situation escalated further as $ETH ETH utilization on Aave hit 100%, meaning liquidity for withdrawals is now extremely limited.

This event is being described as one of the first real stress tests for Aave’s Umbrella safety module, and potentially the largest DeFi exploit observed in 2026 so far.
The situation is still developing, and the full impact on Aave and the broader DeFi market remains uncertain.

#DeFi #Aave #CryptoNews #Ethereum #Exploit
·
--
$DOT nuked after exploit headlines hit the market. Hyperbridge on Ethereum got abused, about 1B bridged DOT was minted, transfer suspensions followed, and panic took over. Native DOT was not compromised, but traders did not wait to sort the details. Price got slammed into the $1.15 zone on heavy volume. If DOT does not reclaim $1.20 fast, bears stay in full control. #exploit
$DOT nuked after exploit headlines hit the market. Hyperbridge on Ethereum got abused, about 1B bridged DOT was minted, transfer suspensions followed, and panic took over.

Native DOT was not compromised, but traders did not wait to sort the details.

Price got slammed into the $1.15 zone on heavy volume.

If DOT does not reclaim $1.20 fast, bears stay in full control. #exploit
🚨 DOT SHOCKWAVE: $DOT just got slammed as reports of a bridged DOT exploit on Ethereum triggered a brutal sell-off. Price snapped lower within minutes, roughly $728K in long liquidations hit the board, and traders were rattled by claims that an attacker minted 1 billion bridged DOT and dumped it for just 108.2 ETH — around $237K. That is not normal market weakness, that is a direct hit to confidence, liquidity, and short-term sentiment. The key detail: the reports point to bridged DOT on Ethereum, not confirmed damage to native Polkadot itself. Still, panic is spreading fast, and until the facts fully settle, this is trading like a trust event, not just another dip. ⚠️📉 #DOT #Polkadot #Crypto #Exploit
🚨 DOT SHOCKWAVE:

$DOT just got slammed as reports of a bridged DOT exploit on Ethereum triggered a brutal sell-off. Price snapped lower within minutes, roughly $728K in long liquidations hit the board, and traders were rattled by claims that an attacker minted 1 billion bridged DOT and dumped it for just 108.2 ETH — around $237K. That is not normal market weakness, that is a direct hit to confidence, liquidity, and short-term sentiment. The key detail: the reports point to bridged DOT on Ethereum, not confirmed damage to native Polkadot itself. Still, panic is spreading fast, and until the facts fully settle, this is trading like a trust event, not just another dip.

⚠️📉 #DOT #Polkadot #Crypto #Exploit
Balancer Hack: $128M Lost, DeFi Shaken Balancer suffered a $128.6M exploit, triggering fear across the DeFi space. Liquidity pools, LP tokens, and yield strategies are under stress. ShadowCrown Hint: DeFi isn’t dead — but risk management matters more than ever. Avoid overexposure to vulnerable protocols until audits and fixes are confirmed. Follow ShadowCrown | DYOR #DeFi #Hack #Exploit #CryptoSecurity #ShadowCrown
Balancer Hack: $128M Lost, DeFi Shaken

Balancer suffered a $128.6M exploit, triggering fear across the DeFi space.

Liquidity pools, LP tokens, and yield strategies are under stress.

ShadowCrown Hint:
DeFi isn’t dead — but risk management matters more than ever.

Avoid overexposure to vulnerable protocols until audits and fixes are confirmed.

Follow ShadowCrown | DYOR

#DeFi #Hack #Exploit #CryptoSecurity #ShadowCrown
مقالة
¿Realmente estamos seguros usando Ledger?Hoy día se empezó a detectar un #exploit en donde varias #DApps que utilizan el conector de #Ledger fueron comprometidas. Dentro de estas dapps se incluyen a Sushiswap , revokecash, zapper entre otras.Pero ¿cómo sucedió este hecho y que acciones tomar? Exploremos. Reportado el incidente , el director técnico de Sushiswap , Mathew Lilley , dio a conocer que un conector web 3 de uso común se ha visto comprometido , el cual permite la inyección de un código malicioso en diversas dapps. Este problema está muy relacionado con una biblioteca de software del proveedor de la billetera Ledger en las que confiaba las Dapps. En la "imagen 1"podemos observar la alerta temprana . ¿Cómo funciona este exploit? si tú visitas la página web de la dapp, no sucede nada con tus fondos, sin embargo, una vez en la página aparece automáticamente un mensaje para conectar tu billetera, el cual si das permiso, entregará tus activos a los actores maliciosos. Ledger ya tiene conocimiento de esto y está tratando de solucionarlo. En la "imagen 2" podemos observar la doble interface mostrada en la página web. Tras este incidente se reporta que el hacker ha logrado drenar billeteras por un total de $ 484,000 dólares en activos aproximadamente . En la "imagen 3" podemos observar el valor de los activos robados. Asi mismo se conoce que Tether ha bloqueado la idrección de la billetera del hacker . En la "Imagen 4" podemos observar esta acción. Por consiguiente se recomienda a usuarios de Ledger puedan tomar las precauciones del caso como : Evitar interactuar con las dappsMantenerse vigilante de sus fondos Actualizar y verificar (En cado exista una nueva actualización para el hardware)Medidas de seguridad (cambio de contraseñas y revisar cualquier transacción sin autorización ) Mientras tanto , Ledger y metamask se mantienen investigando este incidente, ante cualquier actualización verificar las redes oficiales . En mi opinión, pienso que este tipo de incidentes tienen que ser reportados y anunciados rápidamente , solo imaginar que por interactuar con una dapp a través de su página "web oficial" puedan drenar mis fondos es algo inconcebible. Uno como usuario a veces solo hace click y autoriza permisos , sin saber que estamos firmando. Por otra parte , nosotros mismos también tenemos que tomar las medidas del caso y estar atento ante cualquier anomalía que pueda existir en nuestros fondos. Estar alerta. ✏️¿Quieres seguir aprendiendo sobre el mundo cripto ? Comparte y sigueme para más 👈😎 $ETH

¿Realmente estamos seguros usando Ledger?

Hoy día se empezó a detectar un #exploit en donde varias #DApps que utilizan el conector de #Ledger fueron comprometidas. Dentro de estas dapps se incluyen a Sushiswap , revokecash, zapper entre otras.Pero ¿cómo sucedió este hecho y que acciones tomar? Exploremos.

Reportado el incidente , el director técnico de Sushiswap , Mathew Lilley , dio a conocer que un conector web 3 de uso común se ha visto comprometido , el cual permite la inyección de un código malicioso en diversas dapps.
Este problema está muy relacionado con una biblioteca de software del proveedor de la billetera Ledger en las que confiaba las Dapps. En la "imagen 1"podemos observar la alerta temprana .

¿Cómo funciona este exploit? si tú visitas la página web de la dapp, no sucede nada con tus fondos, sin embargo, una vez en la página aparece automáticamente un mensaje para conectar tu billetera, el cual si das permiso, entregará tus activos a los actores maliciosos. Ledger ya tiene conocimiento de esto y está tratando de solucionarlo. En la "imagen 2" podemos observar la doble interface mostrada en la página web.

Tras este incidente se reporta que el hacker ha logrado drenar billeteras por un total de $ 484,000 dólares en activos aproximadamente . En la "imagen 3" podemos observar el valor de los activos robados.

Asi mismo se conoce que Tether ha bloqueado la idrección de la billetera del hacker . En la "Imagen 4" podemos observar esta acción.

Por consiguiente se recomienda a usuarios de Ledger puedan tomar las precauciones del caso como :
Evitar interactuar con las dappsMantenerse vigilante de sus fondos Actualizar y verificar (En cado exista una nueva actualización para el hardware)Medidas de seguridad (cambio de contraseñas y revisar cualquier transacción sin autorización )
Mientras tanto , Ledger y metamask se mantienen investigando este incidente, ante cualquier actualización verificar las redes oficiales .
En mi opinión, pienso que este tipo de incidentes tienen que ser reportados y anunciados rápidamente , solo imaginar que por interactuar con una dapp a través de su página "web oficial" puedan drenar mis fondos es algo inconcebible. Uno como usuario a veces solo hace click y autoriza permisos , sin saber que estamos firmando. Por otra parte , nosotros mismos también tenemos que tomar las medidas del caso y estar atento ante cualquier anomalía que pueda existir en nuestros fondos. Estar alerta.

✏️¿Quieres seguir aprendiendo sobre el mundo cripto ?
Comparte y sigueme para más 👈😎
$ETH
Market Alert: $CETUS & $SUI Plunge Amid Major Exploit — $11M Drained from Cetus Protocol Chaos strikes the Sui ecosystem as both $CETUS and SUI experience sharp crashes following a suspected exploit targeting the Cetus Protocol, the network’s flagship decentralized exchange (DEX) and liquidity provider. What Just Happened? Cetus, a critical pillar of the Sui DeFi landscape, was reportedly exploited in the past few hours. Over $11 million in SUI tokens were allegedly siphoned from the SUI/USDC liquidity pool, triggering a liquidity crisis and widespread panic across the network. Impact on $CETUS: • Price collapsed from $0.2572 to $0.1465 — over -40% in minutes • Mass exodus of liquidity providers and traders • Confidence in the DEX’s integrity severely damaged Impact on $SUI: • Dropped from $4.20 to $3.65, a -15%+ decline • Heavy sell pressure as users exit Sui-linked assets • Volatility surges amid fears of broader systemic risk Why This Matters: In decentralized finance, trust in protocol security is everything. An exploit in a core DEX like Cetus ripples through the entire ecosystem. As many Sui-based projects rely on Cetus for trading and liquidity, this breach threatens to destabilize the broader network. What to Watch: • Official statement from the Cetus team confirming the breach and outlining next steps • Emergency measures or compensation plans to stabilize affected pools • Whether confidence and liquidity return — or continue to bleed out Final Word: This incident is a sobering reminder that security and audits are non-negotiable in DeFi. With uncertainty still swirling, both CETUS and SUI remain in high-risk territory. Traders: stay alert, use tight risk controls, and monitor updates in real time. #CryptoNews #Exploit #BinanceUpdate #MarketCrash {spot}(SUIUSDT)
Market Alert: $CETUS & $SUI Plunge Amid Major Exploit — $11M Drained from Cetus Protocol

Chaos strikes the Sui ecosystem as both $CETUS and SUI experience sharp crashes following a suspected exploit targeting the Cetus Protocol, the network’s flagship decentralized exchange (DEX) and liquidity provider.

What Just Happened?

Cetus, a critical pillar of the Sui DeFi landscape, was reportedly exploited in the past few hours.
Over $11 million in SUI tokens were allegedly siphoned from the SUI/USDC liquidity pool, triggering a liquidity crisis and widespread panic across the network.

Impact on $CETUS :
• Price collapsed from $0.2572 to $0.1465 — over -40% in minutes
• Mass exodus of liquidity providers and traders
• Confidence in the DEX’s integrity severely damaged

Impact on $SUI :
• Dropped from $4.20 to $3.65, a -15%+ decline
• Heavy sell pressure as users exit Sui-linked assets
• Volatility surges amid fears of broader systemic risk

Why This Matters:

In decentralized finance, trust in protocol security is everything. An exploit in a core DEX like Cetus ripples through the entire ecosystem. As many Sui-based projects rely on Cetus for trading and liquidity, this breach threatens to destabilize the broader network.

What to Watch:
• Official statement from the Cetus team confirming the breach and outlining next steps
• Emergency measures or compensation plans to stabilize affected pools
• Whether confidence and liquidity return — or continue to bleed out

Final Word:

This incident is a sobering reminder that security and audits are non-negotiable in DeFi. With uncertainty still swirling, both CETUS and SUI remain in high-risk territory.
Traders: stay alert, use tight risk controls, and monitor updates in real time.

#CryptoNews #Exploit #BinanceUpdate #MarketCrash
BREAKING: $223M Exploit Hits Protocol (Sui) – DeFi Shaken 🚨 Date: June 4, 2025 Impact: One of the largest Sui ecosystem exploits to date. 🔴 What Happened? A smart contract exploit targeting Cetus Protocol Attackers drained ~$223M across $SUI, $USDC, and multiple tokens Exploit stemmed from a combo of smart contract bugs — not just a single point of failure 📉 Market Fallout: price plunged 40% $SUI dropped between 7–14% depending on pair CETUS 0.1362 +1.49% Sui’s total DeFi TVL dropped by $330M almost instantly ⏸️ Protocol Response: Cetus paused all activity for containment Ongoing investigation with help from top security auditors Funds tracking underway — attacker wallets flagged 🧠 Key Takeaways: Smart contract security is still a critical weak point in emerging DeFi ecosystems Even with new chains like Sui, vulnerabilities persist Trust in Cetus and Sui’s DeFi layer has been severely dented — recovery may take time 🔍 What to Watch Next: Will Cetus offer refunds or grants for victims? How Sui Foundation responds (audit funding, new dev standards?) Reentry opportunities for or post-panic? 📌 Caution: If you're exposed to Sui-based DeFi — review all positions, revoke contract permissions, and stay alert for phishing follow-ups. #CETUS #SUI #DeFiHack#CryptoSecurity #smartcontracts. #TVL #Exploit #Web3Risk $CETUS {future}(CETUSUSDT) $SUI {future}(SUIUSDT)
BREAKING: $223M Exploit Hits Protocol (Sui) – DeFi Shaken 🚨
Date: June 4, 2025
Impact: One of the largest Sui ecosystem exploits to date.
🔴 What Happened?
A smart contract exploit targeting Cetus Protocol
Attackers drained ~$223M across $SUI , $USDC, and multiple tokens
Exploit stemmed from a combo of smart contract bugs — not just a single point of failure
📉 Market Fallout:
price plunged 40%
$SUI dropped between 7–14% depending on pair
CETUS
0.1362
+1.49%
Sui’s total DeFi TVL dropped by $330M almost instantly
⏸️ Protocol Response:
Cetus paused all activity for containment
Ongoing investigation with help from top security auditors
Funds tracking underway — attacker wallets flagged
🧠 Key Takeaways:
Smart contract security is still a critical weak point in emerging DeFi ecosystems
Even with new chains like Sui, vulnerabilities persist
Trust in Cetus and Sui’s DeFi layer has been severely dented — recovery may take time
🔍 What to Watch Next:
Will Cetus offer refunds or grants for victims?
How Sui Foundation responds (audit funding, new dev standards?)
Reentry opportunities for or post-panic?
📌 Caution: If you're exposed to Sui-based DeFi — review all positions, revoke contract permissions, and stay alert for phishing follow-ups.
#CETUS #SUI #DeFiHack#CryptoSecurity #smartcontracts. #TVL #Exploit #Web3Risk
$CETUS
$SUI
·
--
صاعد
During tough market situations, especially the rising competition between perp decentralized exchanges, $GMX is still the safest option to trade perp in decentralized and secure manner with organic trading volumes and risk managed liquidity pools. Also, it's one of the most profitable protocols with high cash flow and real yield to their token holders. With upcoming multichain and $BTC L2 expansion aligned with a huge Arbitrum market share and $SOL new platform, GMX will be the king of perp dexs. {future}(BTCUSDT) {future}(SOLUSDT) {future}(GMXUSDT) #StaySafeInTheCryptoWorld #InvestSmart #TradeWisely #HackerAlert #exploit
During tough market situations, especially the rising competition between perp decentralized exchanges, $GMX is still the safest option to trade perp in decentralized and secure manner with organic trading volumes and risk managed liquidity pools.

Also, it's one of the most profitable protocols with high cash flow and real yield to their token holders.

With upcoming multichain and $BTC L2 expansion aligned with a huge Arbitrum market share and $SOL new platform, GMX will be the king of perp dexs.

#StaySafeInTheCryptoWorld
#InvestSmart
#TradeWisely

#HackerAlert
#exploit
Ihtisham_Ul Haq
·
--
🚨KiloEX has suspended usage of its platform and is tracing stolen funds after suffering a $7.5 million exploit.

KiloEX team said it is collaborating with BNB Chain, Manta Network, and cybersecurity firms Seal-911, SlowMist and Sherlock to investigate the exploit and confirmed the stolen assets are currently being routed through zkBridge and Meson.
$8M GONE: Yearn Exploit SHOCKS Market Yearn just got hit! An attacker drained over $8M from the yETH pool. This wasn't some minor glitch. Another $900,000 vanished from the yETH-WETH pool on Curve. V2 and V3 vaults remain secure, but the damage is done. The team is scrambling, investigating with top security firms. This is a critical moment for $ETH and $CRV holders. Protect your bags. The market is reacting. Act now. Not financial advice. Trade at your own risk. #CryptoNews #Yearn #Exploit #DeFi #MarketAlert 🚨 {future}(CRVUSDT)
$8M GONE: Yearn Exploit SHOCKS Market

Yearn just got hit! An attacker drained over $8M from the yETH pool. This wasn't some minor glitch. Another $900,000 vanished from the yETH-WETH pool on Curve. V2 and V3 vaults remain secure, but the damage is done. The team is scrambling, investigating with top security firms. This is a critical moment for $ETH and $CRV holders. Protect your bags. The market is reacting. Act now.

Not financial advice. Trade at your own risk.
#CryptoNews #Yearn #Exploit #DeFi #MarketAlert
🚨
The 8,000,000 Hole That Just Swallowed DeFi Alarm bells are ringing across the decentralized ecosystem. Yearn Finance confirmed a massive exploit on their yETH pool late last night, with over $8 million liquidated by an attacker using a custom minting contract. Another $900,000 was simultaneously drained from the $CRV pool. While the Yearn team asserts that the V2/V3 vaults remain isolated and safe, this is a serious security breach hitting a major platform. The market is watching $ETH closely for knock-on contagion effects. Security teams are now in full investigation mode. Not financial advice. Trade safe. #DeFi #Exploit #Security #ETH 🚨 {future}(CRVUSDT) {future}(ETHUSDT)
The 8,000,000 Hole That Just Swallowed DeFi

Alarm bells are ringing across the decentralized ecosystem. Yearn Finance confirmed a massive exploit on their yETH pool late last night, with over $8 million liquidated by an attacker using a custom minting contract. Another $900,000 was simultaneously drained from the $CRV pool. While the Yearn team asserts that the V2/V3 vaults remain isolated and safe, this is a serious security breach hitting a major platform. The market is watching $ETH closely for knock-on contagion effects. Security teams are now in full investigation mode.

Not financial advice. Trade safe.
#DeFi
#Exploit
#Security
#ETH
🚨
·
--
🚨 $FLOW Blockchain Suffers $3.9M Exploit — What Happened? The $FLOW blockchain has reportedly faced a $3.9 million exploit, raising fresh concerns around smart contract security and on-chain risk management. Early reports suggest the issue stemmed from a vulnerability in a smart contract, allowing attackers to drain funds before the exploit was detected. The Flow team has acknowledged the incident and is actively investigating the root cause while working on mitigation steps. 🔍 Key Takeaways: Exploit size: ~$3.9M Cause: Smart contract vulnerability Status: Investigation & security review ongoing User funds: Being assessed by the team This incident is another reminder that even well-known blockchains are not immune to exploits. Strong audits, rapid response, and transparency will be critical for maintaining community trust going forward. ⚠️ For users: Always manage risk, avoid panic moves, and wait for official updates before taking action. What’s your take — temporary setback or long-term impact for $FLOW ? 👇 {spot}(FLOWUSDT) #FLOW #CryptoSecurity #DeFi #Exploit #BinanceSquare
🚨 $FLOW Blockchain Suffers $3.9M Exploit — What Happened?

The $FLOW blockchain has reportedly faced a $3.9 million exploit, raising fresh concerns around smart contract security and on-chain risk management.

Early reports suggest the issue stemmed from a vulnerability in a smart contract, allowing attackers to drain funds before the exploit was detected. The Flow team has acknowledged the incident and is actively investigating the root cause while working on mitigation steps.

🔍 Key Takeaways:

Exploit size: ~$3.9M

Cause: Smart contract vulnerability

Status: Investigation & security review ongoing

User funds: Being assessed by the team

This incident is another reminder that even well-known blockchains are not immune to exploits. Strong audits, rapid response, and transparency will be critical for maintaining community trust going forward.

⚠️ For users: Always manage risk, avoid panic moves, and wait for official updates before taking action.

What’s your take — temporary setback or long-term impact for $FLOW ? 👇


#FLOW #CryptoSecurity #DeFi #Exploit #BinanceSquare
FLOW EXPLOIT SHOCKER: BILLIONS AT RISK NOW! Flow Foundation is sounding the alarm. A single account dumped 150 MILLION $FLOW tokens, 10% of supply. They cashed out millions in $BTC before the network even blinked. This highlights major exchange AML/KYC failures. Your funds are NOT safe. Users unknowingly bought fraudulent tokens. Deviations from normal market behavior are massive. Exchanges are SILENT. Act NOW. Disclaimer: This is not financial advice. #FLOW #CryptoNews #Exploit #FOMO 🚨 {future}(FLOWUSDT) {future}(BTCUSDT)
FLOW EXPLOIT SHOCKER: BILLIONS AT RISK NOW!

Flow Foundation is sounding the alarm. A single account dumped 150 MILLION $FLOW tokens, 10% of supply. They cashed out millions in $BTC before the network even blinked. This highlights major exchange AML/KYC failures. Your funds are NOT safe. Users unknowingly bought fraudulent tokens. Deviations from normal market behavior are massive. Exchanges are SILENT. Act NOW.

Disclaimer: This is not financial advice.

#FLOW #CryptoNews #Exploit #FOMO 🚨
🚨 TRUE Token Crashes 99.9% After Major Exploit The TrueBit (TRU) token collapsed nearly 99.9% after an exploit drained 8,535 $ETH (~$26.6M) from its protocol. According to reports, the attacker abused a flaw in TrueBit’s smart contract logic, allowing them to manipulate the protocol’s accounting and pull out a large amount of $ETH . Once the drain happened, confidence collapsed and TRU’s price plummeted almost to zero. #Crypto #DeFi #Exploit #TRU #Ethereum 🚨📉
🚨 TRUE Token Crashes 99.9% After Major Exploit

The TrueBit (TRU) token collapsed nearly 99.9% after an exploit drained 8,535 $ETH (~$26.6M) from its protocol.

According to reports, the attacker abused a flaw in TrueBit’s smart contract logic, allowing them to manipulate the protocol’s accounting and pull out a large amount of $ETH .

Once the drain happened, confidence collapsed and TRU’s price plummeted almost to zero.

#Crypto #DeFi #Exploit #TRU #Ethereum 🚨📉
سجّل الدخول لاستكشاف المزيد من المُحتوى
انضم إلى مُستخدمي العملات الرقمية حول العالم على Binance Square
⚡️ احصل على أحدث المعلومات المفيدة عن العملات الرقمية.
💬 موثوقة من قبل أكبر منصّة لتداول العملات الرقمية في العالم.
👍 اكتشف الرؤى الحقيقية من صنّاع المُحتوى الموثوقين.
البريد الإلكتروني / رقم الهاتف