
Sign up to save your podcasts
Or


In this episode of the CoinSec Podcast we talked about the $190 million Nomad bridge hack. Users of the Solana wallet Slope found that their tokens were being sent without authorization resulting in $6 million in losses across 9000 wallets. ZBExchange was drained for nearly $5 million. We discussed critical vulnerabilities discovered in Moonbeam and Strips finance. Our CoinSec Discord has new bots that are for assisting in blockchain threat intel.
In this episode we talked about a $3.5 million theft from the Solana stablecoin Nirvana via a flash loan attack. The music-related token Audius was hit by a governance takeover. Premint's website suffered an issue where it appeared that malicious JavaScript was being injected into the site, causing malicious wallet requests to visitors of the site. A sophisticated phishing attack targeting Uniswap users was discussed. Metamask has updated their browser extension to display the implications of token approval transactions.
In this episode we are joined by special guest Steven Walbroehl from Halborn Security to discuss a critical wallet vulnerability they discovered. A law firm served a hacker with a restraining order via NFT. ApolloX had a bug in their network's trading rewards contract that resulted in an attacker stealing $2.8 million. Inverse Finance was hit for a 2nd time this year via an Oracle Manipulation attack. GYM Network had a function that lacked caller verification that resulted in a hack of $2.1 million. Osmosis Exchange was hacked for $5 million. Maiar Exchange was brought offline after a $113 million hack of the Elrond virtual machine. Wintermute made a mistake when attempting to receive airdropped Optimism governance tokens that resulted in the loss of around $27.6 million.
In this episode we discussed Solana network downtime due to a bug that led to non-determinism resulting in a lack of consensus. A former OpenSea employee was arrested after being accused of using his knowledge of which NFTs would be featured on the site's home page to make financial gain. Mirror Protocol was hacked for $90 million. Internet sleuth ZachXBT posted a thread allegedly revealing that the Animoon NFT project was a rug pull. The World of Solana team was able to recover some NFTs that were stolen via scams. We discussed crypto-related puzzles including the ongoing Phrazeboard puzzle as well as an amazing, augmented reality game puzzle created by the SheetFighter NFT project.
A phishing attack targeting users of popular crypto data sites like Etherscan and CoinGecko was found that uses CoinZilla ad networks. Two lending platforms, Venus Protocol on BSC and Blizz Finance on Avalanche, have been drained of $13.5 and $8.3M, respectively. NeorderDAO had a private key compromise. The popular Mee6 Discord bot was compromised and used to post scam messages in high profile Discord servers.
In this episode we discussed the $UST (Terra Luna) depeg issue that is ongoing. Multiple hacks were discussed this week including FEI Rari, Saddle Finance, Deus DAO, MMFinance, and Fortress protocol. An Internet sleuth helped track down stolen funds for person. A vulnerability was discovered in Everscale wallet. OpenSea's Discord was hacked. NiceHash found a way to bypass Nvidia's LHR protection that prevents miners from leveraging the hardware to its full capabilities.
In this episode we discuss Axie Infinity's Ronin Bridge hack and how it has been tied to the North Korean Lazarus group. An Ethereum developer has been imprisoned for helping North Korea evade sanctions. Tornado Cash has implemented a measure to help block OFAC-sanctioned addresses. Elephant Money and Beanstalk Farms were both hacked. Metamask has issued a warning regarding iCloud backups. A critical Cross-Site Scripting (XSS) bug was found in Rarible's website.
In this episode we covered hacks against Agave, Hundred, Deus Finance, and Paraluni. The Bitcoin mixing tool CoinJoin announced that it will block transactions associated or flagged as illegal. Malicious NPM packages are being used to compromise Discord servers. $APE token was dropped and immediately an attacker performed a flash loan attack.
In episode 58 we discussed an executive order signed by U.S. president Joe Biden calling on the government to examine the risks and benefits of cryptocurrencies. Bacon Protocol reportedly lost $1 million due to a reentrancy vulnerability. Fantasm Finance was hacked for $2.7 million. The Pirate X staking contract was attacked. Fake Nvidia GPU mining software turned out to be malware.
In episode 57 we discussed how some investigative journalism was performed in which the potential identity of the DAO hacker was discovered. An OpenSea-based phishing attack was successful in stealing $1.7 million worth of NFTs. Canada attempted to freeze at least 34 crypto accounts related to the Freedom Convoy protests. We covered crypto issues related to Russia's war against Ukraine. Bitmex founders pleaded guilty to bank secrecy act violations.
From the publisher's feed