This weekend, even hackers didn’t get a break
From Friday evening to now, three security incidents have occurred back-to-back—here are the key points:

Incident 1: Magic Eden’s old EVM listing order vulnerability.
The Limit Break vulnerability impacted old listing orders. White-hat hackers urgently came to the rescue and protected 23,000 NFTs, but 660 WETH (about $2 million+) still hasn’t been recovered.

Incident 2: Nostra oracle manipulation.
Someone manipulated oracle prices, causing the protocol to incur $3.5 million in bad debt—DeFi’s old habit, and once again it reared its head.

Incident 3: Bitget follow-up. (The previous post covered it—won’t repeat.)

Three incidents, three types:
One is an old code debt (unmaintained legacy listing orders).
One is a long-standing mechanism flaw (oracles are always DeFi’s Achilles’ heel).
One is a backend process vulnerability (Bitget).

Security doesn’t have new stories—only new versions of old lessons.
$BTC $ETH $BNB