Binance Square
#exploit

exploit

106,541 views
350 Discussing
abobka
·
--
9,100 USDT in, 1,979.8 $ETH out That's the whole Injective trade, if the researchers have it right Build your own binary options markets Trade against yourself Lean on a bug in the insurance fund that lets you pull out more than you ever put in, over and over 299 markets, 7,100+ transactions, and a chain that sat still for 3 hours 42 minutes while it happened Still unconfirmed by the team, and that's the part that bothers me. The official account has had time to post marketing, just not an explanation🤡 Just say what broke Money hasn't touched a mixer or an exchange yet. Watching that $INJ holders, you good? Not financial advice. {spot}(ETHUSDT) #exploit
9,100 USDT in, 1,979.8 $ETH out

That's the whole Injective trade, if the researchers have it right

Build your own binary options markets
Trade against yourself
Lean on a bug in the insurance fund that lets you pull out more than you ever put in, over and over

299 markets, 7,100+ transactions, and a chain that sat still for 3 hours 42 minutes while it happened

Still unconfirmed by the team, and that's the part that bothers me. The official account has had time to post marketing, just not an explanation🤡

Just say what broke

Money hasn't touched a mixer or an exchange yet. Watching that

$INJ holders, you good?

Not financial advice.
#exploit
·
--
Bearish
💸 $1.1m drained from crypto neobank users — and it wasn't even a blockchain bug Rain's card infrastructure got exploited, not the Rain chain, and the numbers are ugly ▪ 1,685 Avici customers on Solana lost about $500k ▪ 636 Tria customers lost $430k+ ▪ AVICI down 49%, fresh all-time low everyone keeps auditing the L1, NOBODY stress-tests the card rails bolted on top of it weekend part two: Fogo Foundation got hit for 400m FOGO (~$3m), about 4% of total supply team had to halt the entire network just to block addresses linked to the attacker you can harden the chain all you want, the money still walks out the side door still calling this space "battle-tested"?🤡 $FOGO $SOL {spot}(SOLUSDT) #drained #exploit
💸 $1.1m drained from crypto neobank users — and it wasn't even a blockchain bug

Rain's card infrastructure got exploited, not the Rain chain, and the numbers are ugly

▪ 1,685 Avici customers on Solana lost about $500k
▪ 636 Tria customers lost $430k+
▪ AVICI down 49%, fresh all-time low

everyone keeps auditing the L1, NOBODY stress-tests the card rails bolted on top of it

weekend part two: Fogo Foundation got hit for 400m FOGO (~$3m), about 4% of total supply
team had to halt the entire network just to block addresses linked to the attacker

you can harden the chain all you want, the money still walks out the side door

still calling this space "battle-tested"?🤡
$FOGO $SOL
#drained #exploit
🚨 Cronos halted after $75M Tectonic exploit — here’s the risk Cronos ($CRO) froze block production after an attacker manipulated the price of Tectonic’s illiquid $TONIC governance token ~100x in just 20 minutes, then borrowed against the inflated collateral to drain an estimated $66–75M from the chain’s largest lending protocol. Validators halted the entire chain to stop the bleeding, with only ~$6M reaching Ethereum before the freeze . Crypto.com’s exchange and app itself were unaffected — this hit DeFi infrastructure on Cronos, not custodial funds. This is a classic Mango Markets-style oracle exploit: thin liquidity + collateral-backed borrowing = a token that can be pumped and used as fake-value collateral. It’s a reminder that chain security is only as strong as the weakest liquidity pool sitting on top of it. Why rotate to $SOL / $NEAR / $LINK instead: •Deeper, more battle-tested DeFi liquidity — harder for a single actor to manipulate an oracle price 100x in minutes •Larger, more decentralized validator sets vs. Cronos’s capped ~100-validator Tendermint setup •Established track record without a governance-token collateral vulnerability like this DYOR — this isn’t financial advice, just a reminder that chain-level halts like this are a real tail risk worth pricing in. 🧵 #Cronos #DeFiSecurity #Exploit #solana #NEARProtocol
🚨 Cronos halted after $75M Tectonic exploit — here’s the risk

Cronos ($CRO) froze block production after an attacker manipulated the price of Tectonic’s illiquid $TONIC governance token ~100x in just 20 minutes, then borrowed against the inflated collateral to drain an estimated $66–75M from the chain’s largest lending protocol. Validators halted the entire chain to stop the bleeding, with only ~$6M reaching Ethereum before the freeze . Crypto.com’s exchange and app itself were unaffected — this hit DeFi infrastructure on Cronos, not custodial funds.

This is a classic Mango Markets-style oracle exploit: thin liquidity + collateral-backed borrowing = a token that can be pumped and used as fake-value collateral. It’s a reminder that chain security is only as strong as the weakest liquidity pool sitting on top of it.

Why rotate to $SOL / $NEAR / $LINK instead:

•Deeper, more battle-tested DeFi liquidity — harder for a single actor to manipulate an oracle price 100x in minutes
•Larger, more decentralized validator sets vs. Cronos’s capped ~100-validator Tendermint setup
•Established track record without a governance-token collateral vulnerability like this

DYOR — this isn’t financial advice, just a reminder that chain-level halts like this are a real tail risk worth pricing in. 🧵

#Cronos #DeFiSecurity #Exploit #solana #NEARProtocol
🚨 Depletion of lending reserve of $9.3 million from the More Markets platform Blockaid, a blockchain security company, reported that an attacker used Ankr’s liquid staking token and the E-mode pattern to exploit the More Markets lending protocol. The attack resulted in the withdrawal of approximately $9.3 million worth of WFLOW from the platform’s lending reserve. ━━━━━━━━━━━━━━ 📊 Impact: 📈 High 🏷️ DEFI #DeFiSecurity #Exploit #MoreMarkets #Blockchain 📰 Source: cointelegraph.com
🚨 Depletion of lending reserve of $9.3 million from the More Markets platform

Blockaid, a blockchain security company, reported that an attacker used Ankr’s liquid staking token and the E-mode pattern to exploit the More Markets lending protocol. The attack resulted in the withdrawal of approximately $9.3 million worth of WFLOW from the platform’s lending reserve.

━━━━━━━━━━━━━━
📊 Impact: 📈 High
🏷️ DEFI

#DeFiSecurity #Exploit #MoreMarkets #Blockchain

📰 Source: cointelegraph.com
🚨 NEW LAYER-1 $FOGO HALTS MAINNET AFTER ATTACKER DRAINS 10% CIRCULATING SUPPLY 🔻 Fresh off its high-performance pitch to challenge $SOL , $FOGO took a devastating hit as exploiters siphoned $3M, wiping out a staggering 10% of the entire circulating float. 🚨 Validators were forced into a manual network shutdown, exposing severe early-stage fragility before liquidity could even settle. With 4% of genesis supply compromised and rumors of a controversial chain rollback brewing, market confidence hangs by a thin thread. 📊 Exploits on emerging chains are becoming a brutal baptism of fire for capital chasing unproven execution layers. When chain activity reopens, will order flow aggressively sell into the bids or absorb the damage? 💬 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #FOGO #Layer1 #CryptoSecurity #Exploit 🐻 🚨
🚨 NEW LAYER-1 $FOGO HALTS MAINNET AFTER ATTACKER DRAINS 10% CIRCULATING SUPPLY 🔻

Fresh off its high-performance pitch to challenge $SOL , $FOGO took a devastating hit as exploiters siphoned $3M, wiping out a staggering 10% of the entire circulating float. 🚨 Validators were forced into a manual network shutdown, exposing severe early-stage fragility before liquidity could even settle.

With 4% of genesis supply compromised and rumors of a controversial chain rollback brewing, market confidence hangs by a thin thread. 📊 Exploits on emerging chains are becoming a brutal baptism of fire for capital chasing unproven execution layers.

When chain activity reopens, will order flow aggressively sell into the bids or absorb the damage? 💬

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #FOGO #Layer1 #CryptoSecurity #Exploit

🐻 🚨
🚨 $AVICI CRASHES 40% AS SMART CONTRACT EXPLOIT DRAINS MILLIONS FROM VAULTS! 🚨 A severe smart contract vulnerability exposed $AVICI card collateral vaults, triggering a rapid 40% repricing down to $0.24. 📉 Institutional flow immediately fled as crafted signature exploits bypassed administrative escrow permissions. The exploit drained over a fifth of its total market value, driving massive sell pressure through thin order books. 📊 On-chain tracking highlights how smart contract flaws dismantle structural confidence faster than market mechanics. 🔍 With active drain risks unresolved, structural support remains completely unanchored. 💬 Are you stepping aside until smart contract audits reset, or watching for a speculative liquidity sweep? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #AVICI #DeFi #Exploit #Crypto ⚠️ 📉
🚨 $AVICI CRASHES 40% AS SMART CONTRACT EXPLOIT DRAINS MILLIONS FROM VAULTS! 🚨

A severe smart contract vulnerability exposed $AVICI card collateral vaults, triggering a rapid 40% repricing down to $0.24. 📉 Institutional flow immediately fled as crafted signature exploits bypassed administrative escrow permissions.

The exploit drained over a fifth of its total market value, driving massive sell pressure through thin order books. 📊 On-chain tracking highlights how smart contract flaws dismantle structural confidence faster than market mechanics. 🔍

With active drain risks unresolved, structural support remains completely unanchored. 💬 Are you stepping aside until smart contract audits reset, or watching for a speculative liquidity sweep? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #AVICI #DeFi #Exploit #Crypto

⚠️ 📉
Alert on #exploit en #Avici Massive crypto debit card drain nears one million dollars and sends the AVICI token plummeting The Avici crypto card protocol and issuer are facing an apparent real-time security breach after a continuous outflow of funds from its users’ balances was confirmed. Following the incident, the price of its native token (AVICI) suffered a severe drop in the markets, while on-chain data shows the steady movement of capital toward a direction linked to the attacker. Active vulnerability in cards: Avici cardholders have begun reporting the draining of their balances. The attacker-attributed wallet address compiles countless on-chain transactions and accumulates a balance close to one million dollars. Immediate impact on the token: On the market charts, the price of AVICI recorded a sharp plunge of more than 44% within hours, after experiencing massive sell-offs driven by investor panic. Official statement from the team: Through a post on its official X account, Avici acknowledged the flaw, stating: "We are aware of an issue affecting card balance withdrawals and we are closely monitoring the situation". Investigation ongoing: The company said it is working directly with its strategic partners and issuing intermediaries to contain the problem and promised to provide updates as soon as the investigation progresses. #solana #sol $SOL {future}(SOLUSDT)
Alert on #exploit en #Avici
Massive crypto debit card drain nears one million dollars and sends the AVICI token plummeting

The Avici crypto card protocol and issuer are facing an apparent real-time security breach after a continuous outflow of funds from its users’ balances was confirmed.
Following the incident, the price of its native token (AVICI) suffered a severe drop in the markets, while on-chain data shows the steady movement of capital toward a direction linked to the attacker.

Active vulnerability in cards: Avici cardholders have begun reporting the draining of their balances. The attacker-attributed wallet address compiles countless on-chain transactions and accumulates a balance close to one million dollars.

Immediate impact on the token: On the market charts, the price of AVICI recorded a sharp plunge of more than 44% within hours, after experiencing massive sell-offs driven by investor panic.

Official statement from the team: Through a post on its official X account, Avici acknowledged the flaw, stating: "We are aware of an issue affecting card balance withdrawals and we are closely monitoring the situation".

Investigation ongoing: The company said it is working directly with its strategic partners and issuing intermediaries to contain the problem and promised to provide updates as soon as the investigation progresses.
#solana #sol
$SOL
·
--
Bullish
OneKey just publicly reproduced a Ledger exploit, start to finish - the claim: Ledger's Ethereum app (v1.22.1) could sign a transaction different from the one shown on screen - you approve transaction A - the device actually signs transaction B, the one you never saw - reproduced end to end, no theory Ledger patched it in 1.22.3, update or stay exposed can't verify this myself, but a rival naming an exact version number in public is not nothing. Drop your Ledger firmware version below — let's see how many of you already updated. already checked mine) #oneKey #Ledger #exploit $ETH
OneKey just publicly reproduced a Ledger exploit, start to finish

- the claim: Ledger's Ethereum app (v1.22.1) could sign a transaction different from the one shown on screen
- you approve transaction A
- the device actually signs transaction B, the one you never saw
- reproduced end to end, no theory

Ledger patched it in 1.22.3, update or stay exposed

can't verify this myself, but a rival naming an exact version number in public is not nothing.

Drop your Ledger firmware version below — let's see how many of you already updated.

already checked mine)
#oneKey #Ledger #exploit
$ETH
·
--
Bearish
Moonwell: - hit: roughly $8.7m - who flagged it: PeckShield that's the whole incident, honestly. audited, live for a while, still got drained. the pattern doesn't get old, i just get numb to the headline. i don't avoid DeFi because of posts like this. i size around the assumption that this is the normal outcome, not the rare one. if a pool's yield looks too clean, either nobody's found the hole yet, or someone has and isn't telling you. lessons i keep re-learning on repeat: - check who can move the funds, not just who audited the code - don't confuse "still running" with "checked" - size for the exploit, not for the apy no idea which pool is next. never do.$BTC $ETH $SOL #exploit #PeckShieldAlert #moonwellDefi
Moonwell:
- hit: roughly $8.7m
- who flagged it: PeckShield

that's the whole incident, honestly.

audited, live for a while, still got drained. the pattern doesn't get old, i just get numb to the headline.
i don't avoid DeFi because of posts like this. i size around the assumption that this is the normal outcome, not the rare one.

if a pool's yield looks too clean, either nobody's found the hole yet, or someone has and isn't telling you.
lessons i keep re-learning on repeat:
- check who can move the funds, not just who audited the code
- don't confuse "still running" with "checked"
- size for the exploit, not for the apy

no idea which pool is next. never do.$BTC $ETH $SOL
#exploit #PeckShieldAlert #moonwellDefi
Term Finance faced an $8.5M vault governance exploit, leading to the permanent closure of its Meta Vaults and loss of Ethereum deposits. This incident is another stark reminder of DeFi's persistent security risks. #DeFi #Exploit ‎
Term Finance faced an $8.5M vault governance exploit, leading to the permanent closure of its Meta Vaults and loss of Ethereum deposits. This incident is another stark reminder of DeFi's persistent security risks.

#DeFi #Exploit
BounceBit just erased its own Layer-1: 286.5M BB (~$3M) drained in 14 transactions over 4h52m starting Aug 19 -- and the fix is shutting the whole chain down. The news: BounceBit (backed by YZi Labs, formerly Binance Labs) confirmed a protocol-level authorization flaw in its Evmos-based L1 let an attacker pull BB from 9 mainnet accounts starting 21:02 UTC Aug 19 -- no private keys, wallets, or exchange accounts touched, a smart-contract logic bug, not a user-side hack. Since the Evmos stack it ran on is now discontinued anyway, BounceBit is permanently sunsetting BounceBit Chain and reissuing BB as a BEP-20 token on BNB Chain from a pre-attack snapshot (block 20,697,260, 21:02:35 UTC Aug 19). The stolen 286.5M BB is excluded; legitimate holders, including staked/unbonding positions, get automatic reissuance -- no claim needed. BB printed a record low of $0.0079 on Aug 20 before bouncing ~16%. The catch: this isn't a routine bridge patch -- BounceBit is abandoning the L1 its entire "BTC restaking chain" thesis was built on, effectively admitting the core infrastructure was the weak point. A full chain-to-chain migration is operationally fragile: exchange re-listings, wallet contract updates, and DeFi integrations all have to catch up cleanly, and any gap during that window is exactly where the next loss happens. This is ongoing execution risk, not a resolved incident. Our read: a real structural admission dressed up as a clean fix. Falsifiable watch-point: does the BNB Chain migration complete without a second incident, and does CEX/DeFi liquidity actually follow? Does abandoning your own Layer-1 restore confidence in a "BTC restaking" thesis, or does it confirm the infrastructure was never solid? Not financial advice. DYOR. $BB #BounceBit #CryptoNews #Exploit
BounceBit just erased its own Layer-1: 286.5M BB (~$3M) drained in 14 transactions over 4h52m starting Aug 19 -- and the fix is shutting the whole chain down.

The news: BounceBit (backed by YZi Labs, formerly Binance Labs) confirmed a protocol-level authorization flaw in its Evmos-based L1 let an attacker pull BB from 9 mainnet accounts starting 21:02 UTC Aug 19 -- no private keys, wallets, or exchange accounts touched, a smart-contract logic bug, not a user-side hack. Since the Evmos stack it ran on is now discontinued anyway, BounceBit is permanently sunsetting BounceBit Chain and reissuing BB as a BEP-20 token on BNB Chain from a pre-attack snapshot (block 20,697,260, 21:02:35 UTC Aug 19). The stolen 286.5M BB is excluded; legitimate holders, including staked/unbonding positions, get automatic reissuance -- no claim needed. BB printed a record low of $0.0079 on Aug 20 before bouncing ~16%.

The catch: this isn't a routine bridge patch -- BounceBit is abandoning the L1 its entire "BTC restaking chain" thesis was built on, effectively admitting the core infrastructure was the weak point. A full chain-to-chain migration is operationally fragile: exchange re-listings, wallet contract updates, and DeFi integrations all have to catch up cleanly, and any gap during that window is exactly where the next loss happens. This is ongoing execution risk, not a resolved incident.

Our read: a real structural admission dressed up as a clean fix. Falsifiable watch-point: does the BNB Chain migration complete without a second incident, and does CEX/DeFi liquidity actually follow?

Does abandoning your own Layer-1 restore confidence in a "BTC restaking" thesis, or does it confirm the infrastructure was never solid?

Not financial advice. DYOR.

$BB #BounceBit #CryptoNews #Exploit
Another protocol gets absolutely nuked. Total carnage for MAYAChain. A $1.7M exploit used six chained bugs to drain CACAO, sending the token down 89%. This is a brutal reminder that security is still a massive weak point. #MAYAChain #Exploit ‎
Another protocol gets absolutely nuked.

Total carnage for MAYAChain. A $1.7M exploit used six chained bugs to drain CACAO, sending the token down 89%. This is a brutal reminder that security is still a massive weak point.

#MAYAChain #Exploit
Harmony is rolling back its entire chain to Aug 11 after an exploiter forged roughly 4 billion ONE -- discarding over 109,000 legitimate transactions in the process. The news: Harmony confirmed Aug 12 that an attacker exploited a cross-shard receipt-validation flaw to illegitimately mint ~4 billion ONE (~26% of circulating supply), sending price sharply lower. On Aug 17, the core team announced a full network rollback to the Aug 11, 11:25pm UTC checkpoint -- discarding 109,126 regular transactions and 315 staking transactions, forged and legitimate alike. The catch: a rollback erases every real user transaction in that window along with the fraudulent ones, and it can't claw back tokens already cashed out through exchanges before any freeze -- so the real economic damage may be largely irreversible regardless of the rollback. This also echoes Harmony's 2022 bridge hack, undercutting any "problem solved" framing. Some outlets cite far larger forged-balance figures (trillions via repeated replay) not independently confirmed against Harmony's official 4B number -- we're treating 4B as the reliable baseline. Our read: the rollback addresses the on-chain supply distortion, but rewriting chain history is a controversial precedent, and off-chain damage already done can't be reversed by it. Falsifiable watch-point: does Harmony publish a full post-mortem accounting for exactly how much reached exchanges before any freeze, or does that number stay contested? Should a chain ever roll back its own history to undo an exploit, or does that break the point of a blockchain? Not financial advice. DYOR. $ONE #Harmony #Exploit #CryptoNews #Security
Harmony is rolling back its entire chain to Aug 11 after an exploiter forged roughly 4 billion ONE -- discarding over 109,000 legitimate transactions in the process.

The news: Harmony confirmed Aug 12 that an attacker exploited a cross-shard receipt-validation flaw to illegitimately mint ~4 billion ONE (~26% of circulating supply), sending price sharply lower. On Aug 17, the core team announced a full network rollback to the Aug 11, 11:25pm UTC checkpoint -- discarding 109,126 regular transactions and 315 staking transactions, forged and legitimate alike.

The catch: a rollback erases every real user transaction in that window along with the fraudulent ones, and it can't claw back tokens already cashed out through exchanges before any freeze -- so the real economic damage may be largely irreversible regardless of the rollback. This also echoes Harmony's 2022 bridge hack, undercutting any "problem solved" framing. Some outlets cite far larger forged-balance figures (trillions via repeated replay) not independently confirmed against Harmony's official 4B number -- we're treating 4B as the reliable baseline.

Our read: the rollback addresses the on-chain supply distortion, but rewriting chain history is a controversial precedent, and off-chain damage already done can't be reversed by it. Falsifiable watch-point: does Harmony publish a full post-mortem accounting for exactly how much reached exchanges before any freeze, or does that number stay contested?

Should a chain ever roll back its own history to undo an exploit, or does that break the point of a blockchain?

Not financial advice. DYOR.

$ONE #Harmony #Exploit #CryptoNews #Security
Another protocol getting rekt. Harmony just got hit hard. An attacker allegedly minted 4 billion $ONE, sending the price into a 26% nuke. This is a massive red flag for the chain's security. Pure chaos. #Exploit ‎
Another protocol getting rekt.

Harmony just got hit hard. An attacker allegedly minted 4 billion $ONE , sending the price into a 26% nuke. This is a massive red flag for the chain's security. Pure chaos.

#Exploit
Article
"The ecosystem's original sin"The #exploit of $130M in #Coldcard exposes the lethal danger of private keys Not even the most hardened 'cold wallets' are safe from the new wave of cyberattacks. The millionaire hack of Coldcard reopens an existential debate in the industry. Does single private-key-based custody remain a viable model, or is it a systemic risk on the verge of collapsing with the arrival of Artificial Intelligence? The CEO of Blockaid, Ido Ben-Natan, warned that the recent security breach in Coldcard has exposed the most serious structural flaw in cryptocurrencies: absolute dependence on private keys. By acting as a single, unsupported access point, any failure in their generation or storage turns the key into a single point of failure (single point of failure).

"The ecosystem's original sin"

The #exploit of $130M in #Coldcard exposes the lethal danger of private keys
Not even the most hardened 'cold wallets' are safe from the new wave of cyberattacks. The millionaire hack of Coldcard reopens an existential debate in the industry. Does single private-key-based custody remain a viable model, or is it a systemic risk on the verge of collapsing with the arrival of Artificial Intelligence?
The CEO of Blockaid, Ido Ben-Natan, warned that the recent security breach in Coldcard has exposed the most serious structural flaw in cryptocurrencies: absolute dependence on private keys. By acting as a single, unsupported access point, any failure in their generation or storage turns the key into a single point of failure (single point of failure).
$OST SUFFERS $23.7M EXPLOIT - TRADERS' FUNDS SAFE 🔥 On July 15th, Ostium's liquidity treasury was hit for 23.7 million USDC — attacker faked price reports through off-chain infrastructure. But here's the key: trader collateral sits in a separate smart contract and was untouched. All positions remain open and trading was frozen within 60 minutes of the first attack. The team is working with Mandiant, zeroShadow, and law enforcement to chase the funds. Opened positions will be marked to market when trading resumes, unaffected by the suspension period. How do you see this impacting DeFi protocol trust going forward? Not financial advice. Always manage your risk. #Ostium #Exploit #DeFi #SecurityAlert 🔥
$OST SUFFERS $23.7M EXPLOIT - TRADERS' FUNDS SAFE 🔥

On July 15th, Ostium's liquidity treasury was hit for 23.7 million USDC — attacker faked price reports through off-chain infrastructure. But here's the key: trader collateral sits in a separate smart contract and was untouched. All positions remain open and trading was frozen within 60 minutes of the first attack.

The team is working with Mandiant, zeroShadow, and law enforcement to chase the funds. Opened positions will be marked to market when trading resumes, unaffected by the suspension period. How do you see this impacting DeFi protocol trust going forward?

Not financial advice. Always manage your risk.

#Ostium #Exploit #DeFi #SecurityAlert

🔥
Article
Let Me Calm You Down About $GUA: Why Yesterday's 75% Drop Is a Hidden Gem and a Gift for Buyers!Yesterday, the community held its breath as they watched the SUPERFORTUNE (GUA) token cascade down to an extreme bottom around $0.2630. Many panicked, but those who know how to read charts and analyze on-chain data understood: this was a classic force majeure that opened up the perfect entry point. - Right now, the price has already bounced back above $0.61, confidently securing its position above key moving averages! Let's break down why this project is fundamentally strong and why the panic is officially over. 👇🚨 Incident Breakdown: What Actually Happened? - The brutal sell-off was not caused by a team rug pull or a vulnerability in the app's smart contract. It was a simple human error (an exploit during a multisig transaction): the project accidentally sent an airdrop to an address that was hijacked by a hacker. - The attacker had no intention of holding the asset and immediately market-dumped all the tokens straight into the order book. The result: the hacker completely emptied their wallets, the panic selling pressure vanished, and diamond hands alongside market makers instantly started scooping up the token back. The main product remains completely secure! 🧠 Fundamentals: Why SUPERFORTUNE Is an InfoFi Giant. The project operates in a highly lucrative and wildly popular niche at the intersection of Web3, AI, and Chinese metaphysics (AI-powered astrology and Feng Shui forecasts). - Market Potential: In Asia, this market is valued at over $390 billion! The app already boasts a massive active user base. - Powerful Incubation: The project was launched and is fully backed by the Manta Labs team (creators of Manta Network). They provide substantial budgets, liquidity, and top-tier crypto industry connections. 🗺️ Roadmap & Tight Tokenomics: Only Growth Ahead. Many were worried about sell pressure, but let’s look at the facts: 1. Dump Protection: The global token unlock for the team and major investors is locked until the end of May 2027! The current circulating supply is strictly controlled. 2. Super App & Deflation: The team is preparing for the full launch of their mobile Super App with Apple Pay integration. A portion of the GUA tokens spent inside for AI reports will be permanently burned. 3. Tier-1 Listings: Given the direct connection to Manta, the project is actively preparing to launch on major first-tier exchanges, including Binance and Bybit. 📈 Technical Analysis: The Bottom Is In. Take a look at the 15-minute chart right now: - The price has confidently broken above MA(7) [$0.5732] and MA(30) [$0.4031] from the bottom up. - The $0.2633 level is protected by a thick wall of buyers. - The YTD (Year-to-Date) return sits at +401%, confirming its status as one of the strongest AI assets on the BNB Chain. Conclusion: The panic surrounding the transaction mistake has been completely neutralized. The project has proven its resilience. Such sudden drops in strong projects are always an opportunity you shouldn't miss. Let's watch the development and wait for the march toward $1.00! 🚀 #gua #SUPERFORTUNE #exploit $GUA {future}(GUAUSDT) $BTC {future}(BTCUSDT) $BNB {future}(BNBUSDT)

Let Me Calm You Down About $GUA: Why Yesterday's 75% Drop Is a Hidden Gem and a Gift for Buyers!

Yesterday, the community held its breath as they watched the SUPERFORTUNE (GUA) token cascade down to an extreme bottom around $0.2630. Many panicked, but those who know how to read charts and analyze on-chain data understood: this was a classic force majeure that opened up the perfect entry point.
- Right now, the price has already bounced back above $0.61, confidently securing its position above key moving averages! Let's break down why this project is fundamentally strong and why the panic is officially over.
👇🚨 Incident Breakdown: What Actually Happened?
- The brutal sell-off was not caused by a team rug pull or a vulnerability in the app's smart contract. It was a simple human error (an exploit during a multisig transaction): the project accidentally sent an airdrop to an address that was hijacked by a hacker.
- The attacker had no intention of holding the asset and immediately market-dumped all the tokens straight into the order book. The result: the hacker completely emptied their wallets, the panic selling pressure vanished, and diamond hands alongside market makers instantly started scooping up the token back. The main product remains completely secure!
🧠 Fundamentals: Why SUPERFORTUNE Is an InfoFi Giant.
The project operates in a highly lucrative and wildly popular niche at the intersection of Web3, AI, and Chinese metaphysics (AI-powered astrology and Feng Shui forecasts).
- Market Potential: In Asia, this market is valued at over $390 billion! The app already boasts a massive active user base.
- Powerful Incubation: The project was launched and is fully backed by the Manta Labs team (creators of Manta Network). They provide substantial budgets, liquidity, and top-tier crypto industry connections.
🗺️ Roadmap & Tight Tokenomics: Only Growth Ahead.
Many were worried about sell pressure, but let’s look at the facts:
1. Dump Protection: The global token unlock for the team and major investors is locked until the end of May 2027! The current circulating supply is strictly controlled.
2. Super App & Deflation: The team is preparing for the full launch of their mobile Super App with Apple Pay integration. A portion of the GUA tokens spent inside for AI reports will be permanently burned.
3. Tier-1 Listings: Given the direct connection to Manta, the project is actively preparing to launch on major first-tier exchanges, including Binance and Bybit.
📈 Technical Analysis: The Bottom Is In.
Take a look at the 15-minute chart right now:
- The price has confidently broken above MA(7) [$0.5732] and MA(30) [$0.4031] from the bottom up.
- The $0.2633 level is protected by a thick wall of buyers.
- The YTD (Year-to-Date) return sits at +401%, confirming its status as one of the strongest AI assets on the BNB Chain.
Conclusion: The panic surrounding the transaction mistake has been completely neutralized. The project has proven its resilience. Such sudden drops in strong projects are always an opportunity you shouldn't miss. Let's watch the development and wait for the march toward $1.00! 🚀
#gua #SUPERFORTUNE #exploit
$GUA
$BTC
$BNB
Thetanuts Finance was exploited on June 15 after an attacker targeted a legacy Ethereum vault and drained assets valued at about $2.1 million. According to Blockaid, ExVul, and PeckShield, the attack exploited a low-supply accounting flaw in the vault's minting and redemption calculations. The attacker used flash-loaned capital to reduce token supply to an extremely low level, then reminted tokens at a discounted rate due to rounding behavior in the contract logic. ExVul's analysis found that the vault's redemption formula became vulnerable when the total supply approached near-zero levels. This allowed the attacker to generate inflated redemption values and repeatedly execute mint-and-claim transactions that withdrew more assets than were deposited. Initial estimates placed losses near $105,500 in USDC. A later analysis by PeckShield reported a total impact of $2.1 million. PeckShield also stated that about $2 million worth of option tokens were secured by whitehat actors. The attacker converted about $105,000 in USDC into ETH and continued to hold additional assets linked to the exploit. Thetanuts Finance said the affected vault was a deprecated product that had been migrated years ago and was not connected to any current contracts or active products. The team plans to release a full post-mortem after completing its investigation. The incident serves as another reminder that legacy DeFi infrastructure can remain vulnerable even after protocols migrate users to newer systems. #exploit #SecurityAlert #Thetanuts #CryptoNews #CryptocurrencyNews
Thetanuts Finance was exploited on June 15 after an attacker targeted a legacy Ethereum vault and drained assets valued at about $2.1 million.
According to Blockaid, ExVul, and PeckShield, the attack exploited a low-supply accounting flaw in the vault's minting and redemption calculations. The attacker used flash-loaned capital to reduce token supply to an extremely low level, then reminted tokens at a discounted rate due to rounding behavior in the contract logic.
ExVul's analysis found that the vault's redemption formula became vulnerable when the total supply approached near-zero levels. This allowed the attacker to generate inflated redemption values and repeatedly execute mint-and-claim transactions that withdrew more assets than were deposited.
Initial estimates placed losses near $105,500 in USDC. A later analysis by PeckShield reported a total impact of $2.1 million.
PeckShield also stated that about $2 million worth of option tokens were secured by whitehat actors. The attacker converted about $105,000 in USDC into ETH and continued to hold additional assets linked to the exploit.
Thetanuts Finance said the affected vault was a deprecated product that had been migrated years ago and was not connected to any current contracts or active products. The team plans to release a full post-mortem after completing its investigation.
The incident serves as another reminder that legacy DeFi infrastructure can remain vulnerable even after protocols migrate users to newer systems.

#exploit #SecurityAlert #Thetanuts #CryptoNews #CryptocurrencyNews
⚠️ Security Alert Balance Coin has plummeted 99% following a reported $915,000 exploit. The attacker successfully liquidated multiple Bitcoin-backed vaults, swapping assets for profit and triggering the massive price crash. #Security #Exploit ‎
⚠️ Security Alert

Balance Coin has plummeted 99% following a reported $915,000 exploit. The attacker successfully liquidated multiple Bitcoin-backed vaults, swapping assets for profit and triggering the massive price crash.

#Security #Exploit
🚨 $AFX EXPLOIT – $24M DRAINED, ATTACKER FLOODS ETH WITH FRESH LIQUIDITY! 💣 📌 AFX Trade just got gutted for 24.15M USDC – attacker bridged it straight to Ethereum and swapped into 12,467 ETH at $1,937 average. This isn't random – it's a classic exit play 💡 💥 The moment those USDC hit the order books, buyer pressure on ETH spiked. Smart money? No – this is forced demand from stolen capital. The same pattern we've seen after every major DeFi heist – sell the stablecoins, buy the blue chip token of choice, then wash out through mixers or CEXs. 📊 ⚠️ No official recovery update yet. If the attacker dumps those ETH in chunks, we could see local resistance near $1,950 get tested. But for now, ETH is absorbing a 24M injection. 💬 Do you think this buy pressure gets absorbed cleanly or does the hacker unwind it into a cascade? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #AFX #ETH #DeFi #Exploit #Crypto 🛡️ 🔍
🚨 $AFX EXPLOIT – $24M DRAINED, ATTACKER FLOODS ETH WITH FRESH LIQUIDITY! 💣

📌 AFX Trade just got gutted for 24.15M USDC – attacker bridged it straight to Ethereum and swapped into 12,467 ETH at $1,937 average. This isn't random – it's a classic exit play 💡

💥 The moment those USDC hit the order books, buyer pressure on ETH spiked. Smart money? No – this is forced demand from stolen capital. The same pattern we've seen after every major DeFi heist – sell the stablecoins, buy the blue chip token of choice, then wash out through mixers or CEXs. 📊

⚠️ No official recovery update yet. If the attacker dumps those ETH in chunks, we could see local resistance near $1,950 get tested. But for now, ETH is absorbing a 24M injection. 💬 Do you think this buy pressure gets absorbed cleanly or does the hacker unwind it into a cascade? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #AFX #ETH #DeFi #Exploit #Crypto

🛡️ 🔍
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number