Binenet (@binenetxyz) 's Twitter Profile
Binenet

@binenetxyz

Web3 Real-time Threat Intelligence (Hacks, NFT, Phishing, and more)

Smart contract auditing (telegram: t.me/binenetxyz)

📧 [email protected]

ID: 1621336448644550656

linkhttps://binenet.com calendar_today03-02-2023 02:35:30

107 Tweet

201 Followers

4 Following

Binenet (@binenetxyz) 's Twitter Profile Photo

🚨 According to community intelligence, the Bitcoin ecosystem restaking protocol Bedrock | BR is LIVE suffered a loss of $1.7M worth of uniBTC due to an exchange rate attack. The root cause was that the mint() function did not take into account the exchange rate difference between ETH

🚨 According to community intelligence, the Bitcoin ecosystem restaking protocol <a href="/Bedrock_DeFi/">Bedrock | BR is LIVE</a> suffered a loss of $1.7M worth of uniBTC due to an exchange rate attack. The root cause was that the mint() function did not take into account the exchange rate difference between ETH
Binenet (@binenetxyz) 's Twitter Profile Photo

🚨 An unknown suspicious address has obtained approximately 15K $fwdETH (worth $35 million) through a "consent" phishing signature method and sold it, causing the price of dETH to plummet rapidly. Due to the oracle's incorrect pricing of dETH, protocols such as Pac Finance and

Binenet (@binenetxyz) 's Twitter Profile Photo

🚨🚨 Morpho Labs 🦋 PAXG/USDC market was attacked, resulting in a loss of $230K. Our analysis indicates that due to a misconfiguration of the Oracle SCALE_FACTOR, it was unable to handle the difference in decimals between USDC (6 decimal places) and PAXG (18 decimal places). This

🚨🚨 <a href="/MorphoLabs/">Morpho Labs 🦋</a> PAXG/USDC market was attacked, resulting in a loss of $230K. Our analysis indicates that due to a misconfiguration of the Oracle SCALE_FACTOR, it was unable to handle the difference in decimals between USDC (6 decimal places) and PAXG (18 decimal places). This
Binenet (@binenetxyz) 's Twitter Profile Photo

🚨🚨 Our security monitoring system has detected a security breach in Tapioca Foundation , a cross-chain money market protocol based on LayerZero , resulting in a loss of approximately 29.6M TapTokens ($TAP). The attacker exchanged these for about 591 $ETH and around ~3M USDT,

🚨🚨 Our security monitoring system has detected a security breach in <a href="/tapioca_dao/">Tapioca Foundation</a> , a cross-chain money market protocol based on <a href="/LayerZero_Core/">LayerZero</a>  , resulting in a loss of approximately 29.6M TapTokens ($TAP). The attacker exchanged these for about 591 $ETH and around ~3M USDT,
Binenet (@binenetxyz) 's Twitter Profile Photo

🤔 Based on our team's research on previous security incidents, the vast majority are caused by permission management issues, such as the recent security incident involving the Radiant Capital lending protocol. In many protocol codes, functions with OnlyOwner permissions are

Binenet (@binenetxyz) 's Twitter Profile Photo

🚨🚨 According to our monitoring system, the private key of the SUNRAY·FINANCE on the Arbitrum chain may have been compromised. The attacker has gained control of the logical contracts for SUN and ARC tokens and minted a large number of tokens, which were then sold. Currently, they

🚨🚨 According to our monitoring system, the private key of the <a href="/SUNRAY_DEX/">SUNRAY·FINANCE</a> on the Arbitrum chain may have been compromised. The attacker has gained control of the logical contracts for SUN and ARC tokens and minted a large number of tokens, which were then sold. Currently, they
Binenet (@binenetxyz) 's Twitter Profile Photo

🚨🚨 According to community safety intelligence, DeltaPrime was just exploited on Avalanche and Arbitrum for a total of $4.75M. Preliminary analysis on the chain shows that the attacker obtained administrator privileges on SmartLoansFactory.

🚨🚨 According to community safety intelligence, <a href="/DeltaPrimeDefi/">DeltaPrime</a> was just exploited on Avalanche and Arbitrum for a total of $4.75M.
Preliminary analysis on the chain shows that the attacker obtained administrator privileges on SmartLoansFactory.
Binenet (@binenetxyz) 's Twitter Profile Photo

Regarding the asset theft incident at the DEXX trading platform, the main technical security issues include: 1. Improper Private Key Management: The DEXX platform has been criticized for mishandling private keys, leading to the leakage of official private keys. This indicates

Binenet (@binenetxyz) 's Twitter Profile Photo

🚨 Private key security management is always a necessary course for web3 project development teams, stay vigilant!

Binenet (@binenetxyz) 's Twitter Profile Photo

🚨🚨 According to community intelligence, the XT Exchange 🚀 #BeyondTrade hot wallet 0x4cb625 is suspected to have been attacked and lost ~461ETH ($1.67M). The official announcement has been made that all currencies will be temporarily withdrawn due to wallet maintenance. Stay alert, wait for

🚨🚨 According to community intelligence, the <a href="/XTexchange/">XT Exchange 🚀 #BeyondTrade</a> hot wallet 0x4cb625 is suspected to have been attacked and lost ~461ETH ($1.67M). The official announcement has been made that all currencies will be temporarily withdrawn due to wallet maintenance.
Stay alert, wait for
Binenet (@binenetxyz) 's Twitter Profile Photo

🤔 Another security incident caused by improper private key management highlights the importance of following private key security management standards. Key wallets should utilize multi-signature wallets or MPC wallets to prevent single point of failure attacks.

Binenet (@binenetxyz) 's Twitter Profile Photo

After analysis by our security engineers and in light of the official code fixes from Cetus, the core reason for the Cetus vulnerability was a calculation precision flaw in the smart contract. In the critical function get_delta_a, the overflow check in the checked_shlw function

After analysis by our security engineers and in light of the official code fixes from Cetus, the core reason for the Cetus vulnerability was a calculation precision flaw in the smart contract.

In the critical function get_delta_a, the overflow check in the checked_shlw function