🚨 UPDATE - the JaredFromSubway attacker just answered the 50% bounty offer… by laundering
~1,000 ETH hit Tornado in the last hour, from a wallet we traced straight to the attacker's hub
All 4 staging wallets are now empty. He's washing, not returning
🔔The hunter is negotiating with the hunted
JaredFromSubway , the sandwich bot drained for ~$7.5M , just sent the attacker an on-chain ultimatum:
"Well played. 50% white hat bounty if you return 2150 ETH in 48h , otherwise legal & law enforcement"
🚨 EXPLOIT - ATM token (BNB Chain), ~$950K drained
No flash loan - the attacker manipulated the ATM/WBNB PancakeSwap pair reserves via sync(), then swapped out the pool's entire WBNB liquidity (1,604 WBNB)
Attacker:
0x66DE38dA216D6fCC3F9Aa944f592546e3eae2dD0
🚨 $18.5M in dormant Hashflare fraud funds just woke up.
10,624 ETH moved from a Hashflare-linked wallet today (07:33 UTC) after ~3.5 years dormant ,now being laundered ETH→BTC via HiFiSwap & Near Intents
Flagged by @zachxbt & @CyversAlerts . We confirmed it on-chain 🧵
🔔The hunter is negotiating with the hunted
JaredFromSubway , the sandwich bot drained for ~$7.5M , just sent the attacker an on-chain ultimatum:
"Well played. 50% white hat bounty if you return 2150 ETH in 48h , otherwise legal & law enforcement"
@banteg I think the attacker was a rival who was familiar with the MEV ecosystem because Jared's MEV bot was closed source, and seeing the post-state allowance perspective in the bot is definitely the work of someone familiar with the MEV ecosystem
The 4 wallets depositing to Tornado:
0xe3Da36E4bd1a5738fa5D6Ef4F0e4dF40bDeB5f17 done (~1k ETH) Tornado
0x74Dc5b93586D248D5Aec64b3586736FF0A0D0e65 , 1,001 ETH
0xd8C125efCBc99408eC8723E9BBd81d1E8D39D845 , 1,001 ETH
0x71d4416A7A85e08a5Fe7227Ca3B44Fc639e94e97 , 1,423 ETH
@NoxosIntel The software I use is my own and does not rely on any third-party applications, I am always open to collaboration you can message me via DM
🚨 EXPLOIT - LABUBU/OLPC (BNB Chain), ~$1.1M drained
No flash loan , the attacker (EIP-7702 wallet) manipulated the token pools via transfer + sync() reserve desync, then swapped out ~1.12M USDT
Bridged to ETH → 633 ETH into Tornado Cash
🚨 @namada attacker identified
The ATOM drained over IBC landed here on Cosmos Hub:
cosmos1zw9weagzm2w4ud6w3ql7m7rvzpxhvkpt8kk4ff
~228,517 ATOM received from Namada (Jun 18), emptied within hours via IBC + sends. Fresh wallet, now dust
🚨 @namada (privacy chain) MASP drained ~$600K , and nobody noticed:
The indexer still shows the funds, but live RPC says 0
ATOM, USDC, OSMO, TIA, NYM all swept from the shielded pool (over IBC)
Privacy chain + stale indexer = invisible hack 🧵
@justcryptodefi@namada I'm pulling their data from RPC , you can check it from Defillama too if you want. They also pull from RPC, and while TVL was around 600k yesterday, it's now around $600
🚨 @namada (privacy chain) MASP drained ~$600K , and nobody noticed:
The indexer still shows the funds, but live RPC says 0
ATOM, USDC, OSMO, TIA, NYM all swept from the shielded pool (over IBC)
Privacy chain + stale indexer = invisible hack 🧵
@namada Providing proof from DefiLlama, it pulls data from the RPC in real-time, and while the TVL was showing around ~$600K yesterday, it has now dropped to nearly $600
6 Followers 68 FollowingAdvanced security scanning for Web3 applications and smart contracts. Scale your project securely with custom API key integration. Built for enterprise. 💻
1K Followers 5K FollowingSecurity Lead @LineaBuild | Prev @HalbornSecurity @Openfortxyz @CertiK and @NCCgroupplc | Teacher @LaSalleBCN University and @NuclioSchool
932 Followers 222 Following👽 UFOCAT — The cosmic meme taking over Solana.
Fueled by memes, community, and pure degen energy.
CA incoming. Stay abducted 🛸🐱
3 Followers 23 FollowingSenior ML Specialist @Anoxir_io
| Leading the design & optimization of 12+ ML models for blockchain risk intelligence. Addresses, graphs & smart contracts.