Greetings!
More than $1.5M were stolen this week across 7 incidents. Let’s dive into some of the more notable hacks, but first a note from our sponsors Audit Wizard! With tools like AI-generated PoCs, rapid Foundry testing, code graphing, function tracing this all-in-one smart-contract security platform can really supercharge your auditing powers. Check it out!
Audit Wizard enables developers and auditors to find bugs in smart contracts. Import a project to scan for vulnerabilities, visualize functions, chat with AI about security concerns, and more.
Built by security engineers, Audit Wizard is an easy, one-click solution for finding bugs in web3 code. Sign up for free here!
Nirvana and Crema Finance hacker was sentenced to 3 years in prison after pleading guilty to stealing combined $12M from the two DeFi projects. This is the first in the series of trials reaffirming that weaknesses in smart contracts do not excuse illegal actions. Law is Law.
Most of the DeFi losses came from the Zest Protocol reward manipulation exploit which marks the first publicly recorded hack on Stacks, a Bitcoin L2 chain.
xBlast compromise is unfortunate since it was caused by bad devops: private key committed to the Github repo. While the total amount stolen was <$100K, the compromise should still be a reminder to watch what you commit and how you store deployment keys.
The premium version of the newsletter includes additional coverage and indicators for the hacks mentioned above as well as Sumer Money, SQUID Game Coin, UPS Token, and others.
To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.
Let’s dive into the news!
News
FBI subpoenaed Bitcoin core developer names as well as their github usernames and email addresses.
$26 million in 'unnecessary liquidations' hit Blast-based lender Pac Finance.
A Vigilante Hacker Took Down North Korea’s Internet. Now He’s Taking Off His Mask. If governments around the world are incapable or not interested in stopping North Korean, will the job fall onto vigilante hackers like P4x?
Personal data is being spied on by Web3 scam detection tools.
Binance decries ‘outrageous’ decision to send exec Tigran Gambaryan to prison in Nigeria.
Highlights from the UN Security Council's 2023 report on DPRK by Tay. The complete report contains detailed accounts of crypto-related exploits.
Crime
Former Security Engineer Sentenced To Three Years In Prison For Hacking Two Decentralized Cryptocurrency Exchanges. Shakeeb Ahmed previously was found guilty for stealing $12M from Nirvana and Crema Finance on Solana.
Policy
Uniswap Lab received a Wells notice from SEC alleging securities violations.
BingX exchange openly supports Iranian users, defying sanctions.
Phishing
Reports of a phishing attack involving synced malicious Chrome extension using a compromised Google account.
Scams
Leaper Finance rugpull alert by ZachXBT. The same bad actors were previously responsible for Magnate, Kokomo, Lendora, Solfire, and other scams.
1 in 6 new Base meme coins are scams, 91% have vulnerabilities.
Media
Blockchain Security Series Episode 4: Ryan Lackey (Chief Security Officer @ Evertas).
Scraping Bits
Ethereum Zurich 2024
Damian Rusinek - Secrets of Uniswap V4: A Deep Dive into Hooks Security.
Pietro Carta - Reentrancy in Cancun hardfork: the curious case of EIP1153 (transient storage).
Nebojsa Urosevic - Breaking the Code: Ethdebug format for Smart Contract Debugging.
Georgy Kobakhize - Dangerous Decimals: how rounding issues haunt DeFi.
Arthur Gervais - Speculative Denial-of-Service Attacks in Ethereum.
Research
Blockchain Security Library by 0xNazgul.
Understanding the Function Selector in Solidity by Jeffrey Scholz (RareSkills).
How to Use Phalcon Fork to Play and Learn Ethernaut CTF 2024 by BlockSec.
A hidden war on Solana between big players thread by Duo Nine.
Automated Attack Synthesis for Constant Product Market Makers.
The Devil Behind the Mirror: Tracking the Campaigns of Cryptocurrency Abuses on the Dark Web.
Tools
Smart Contract Inspector - Inspect the source code of a Smart Contract with your preferred Web IDE with just one click (or keyboard shortcut) by StErMi.
Bounty Hunter - A cli to help you navigate bounty programs by Joran Honig.
Tweak for Foundry - allows users/developers to alter the code of an on-chain contract with the on-chain state untouched by EtherDebug.
Simbolik - Next-Generation Smart Contract Debugging.
Slither 0.10.2 adds first class support for Foundry and improved mutation testing.
Enjoy reading BlockThreat? Consider sponsoring the next edition or becoming a paid subscriber to unlock the premium section with detailed information on hacks, vulnerability, indicators, special reports, and searchable newsletter archives.
Premium Content
The content presented below is intended for personal, non-commercial use only and is protected by copyright laws. Any unauthorized distribution, reproduction, or inclusion of this content in public or commercial products, databases, publications, and other mediums is strictly prohibited without the express written permission of the author.
Keep reading with a 7-day free trial
Subscribe to Blockchain Threat Intelligence to keep reading this post and get 7 days of free access to the full post archives.