Security Intelligence
In-depth breakdowns of real security incidents — what happened, why it happened, and what the industry can learn.
Offside Wallet Theft Factory: 40 Malicious Firefox Extensions Stealing Wallet Seeds via Supabase, Cloudflare Workers, and Silent Update Conversion
Socket identified 77 linked Firefox extensions — 40 confirmed malicious, 37 deceptive shells — active since at least March 2026. The campaign impersonated OKX, Rabby Wallet, and TronLink using four distinct theft methods: Supabase-controlled phishing loaders, Cloudflare Worker exfiltration of recovery phrases, pre-encryption keyring interception, and clipboard/credential harvesting. Nine extensions were published as sports-score apps and later silently converted to wallet stealers via update.
Term Finance's $8.5M Governance Exploit: How a Vault Authority Attack Forced a Permanent Protocol Shutdown
An attacker exploited the governance mechanism controlling Term Finance's Meta Vaults, draining approximately $8.5 million in assets. Term Finance permanently shut down all vaults and revoked DAO governance authority in response. The core lending protocol was not compromised. Withdrawals remain open while external security firms work to trace and recover the stolen funds.
The Sandbox's 329-Trillion SAND Mint: How an approveAndCall Exploit Hijacked LayerZero Delegate Permissions and Drained the Bridge Reserve
An attacker exploited The Sandbox's approveAndCall function to hijack LayerZero delegate permissions on Base, then manufactured 329.24 trillion unbacked SAND tokens across 703 minting events. The face-value headline of $49 billion was misleading — real losses were bounded by the Ethereum OFT Adapter's reserve of ~14.75 million SAND, putting the actual drain at approximately $675,000. The Sandbox's multisig severed the bridge by zeroing LayerZero trusted peers for Base and BNB Chain. Ethereum and Polygon were unaffected.
Keeta Network's $3.64M Bridge Exploit: How a Single Component Vulnerability Put a Payment Mainnet into Read-Only Mode
An attacker exploited an isolated vulnerability in a single Keeta Network component to bridge 9.3 million KTA and 2 billion GALA tokens to a fresh wallet, then liquidated both positions for approximately 1,902 ETH (~$3.64 million). Keeta placed its payment public mainnet in read-only mode, confirmed anchoring systems were unaffected, and issued a 72-hour deadline for the attacker to return the funds.
BounceBit Chain's $3.1M Exploit: How a Wrong-Principal Authorization Check in the Evmos Vesting Module Forced a Permanent Chain Shutdown
An attacker exploited a two-part authorization failure in the Evmos vesting module inherited by BounceBit Chain, draining 286,543,148 BB tokens (~$3.1 million) from nine accounts across 14 transactions in roughly five hours. BounceBit halted block production and permanently sunset its Layer 1 chain. BB tokens are being reissued as BEP-20 on BNB Chain with pre-attack balances restored from a snapshot.
Allbridge's $191K CCTP Exploit: How a 24-Day-Old Forged Circle Message and a Flash Loan Drained a Base Router
An attacker constructed a forged Circle CCTP-style message on Polygon on July 25–26, waited 24 days for Allbridge's Base router to accumulate funds, then executed the exploit six seconds after 191,156 USDC arrived. Allbridge's receiveCctpMessage function treated Circle's message attestation as settlement proof — crediting a fictitious 999,000 USDC deposit — while a flash loan from Aave filled the gap to make the payout possible. Net loss: approximately 191,156 USDC.
Maya Protocol's $11M Exploit: How Six Chained Bugs Turned a Ghost Transaction Into a $CACAO Money Printer
Maya Protocol halted MAYAChain on August 19, 2026 after an attacker exploited a chain of six discrete software vulnerabilities to manufacture 49 million $CACAO tokens from thin air, drain pools of Bitcoin and other assets, and trigger an 89% collapse in the token's price — causing $10.9M in total losses across liquidity providers, arbitrageurs, and token holders.
550,000 USDC Lost to a Fake Google Ad: Inside the Inferno Drainer Phishing Campaign Targeting Hyperliquid Users
A Hyperliquid user lost 550,019 USDC after clicking a paid Google advertisement that led to a counterfeit Hyperliquid interface. After connecting their wallet and signing a malicious approval, the Inferno Drainer backend automatically transferred funds across three transactions and split proceeds 80/15/5 among operation addresses. Hyperliquid's protocol was not compromised. Security firm Salus linked the infrastructure to $52.74 million in aggregate losses across multiple campaigns.
Harmony's $ONE Plunges 40% After Attacker Mints Four Billion Tokens Equal to a Quarter of Supply
An attacker exploited the Harmony blockchain to mint four billion $ONE tokens without authorisation — roughly 25% of the circulating supply — causing the token price to fall 40%. Harmony paused its token bridge, requested exchange freezes on four attacker addresses, and raised the possibility of a full blockchain rollback, reviving an ongoing debate about immutability versus incident recovery in public blockchains.
Ravencoin's KAWPOW Consensus Flaw: How a Single Unchecked Header Field Put Four Days of Transactions at Risk
A critical gap in Ravencoin's KAWPOW proof-of-work validation allowed an attacker to insert invalid blocks from height 4,487,776, splitting the network and threatening to reverse nearly four days of transactions. Major mining pools deployed an emergency patch and began rebuilding a clean chain from the last known-good block while exchanges suspended RVN flows to limit double-spend exposure.