MANTRA Chain Delays Restart as v8.4.0 Patch Faces Testing
The team says user funds were insulated from the pause, but the asset impact of the attacker's activity remains unconfirmed.
Every Zipp story tagged #Exploit, newest first.
The team says user funds were insulated from the pause, but the asset impact of the attacker's activity remains unconfirmed.
Maya has committed to replacing the ~20 BTC stolen. That covers a fraction of the $11M in pool damage, with the bulk sitting in CACAO repricing and arbitrage losses no one has publicly agreed to…
The attacker walked away with $1.7M, but the $11M hit to Maya's liquidity pools and an 89% wipeout in $CACAO are what liquidity providers are now reckoning with.
Second major breach in three years, after the $100M Horizon bridge heist linked to North Korean hackers. The bigger question is whether a rollback restores trust or deepens the credibility hit.
A rollback on a major L1 would test whether on-chain accountability trumps immutability and could set a precedent for similar bridge and minting exploits.
About 26% of ONE's circulating supply minted from thin air is the structural blow; the rest of the market is coiled ahead of July U.S. CPI at 12:30 UTC that could reset the risk-asset tone.
The seed-randomness flaw had lurked in firmware since March 2021 and went unnoticed for years, exposing the practical ceiling of single-device self-custody for serious BTC holders.
If the contracts weren't touched, the question is how the keys, servers, or operational layer were, and whether LP recovery hinges on a counterparty the protocol doesn't control.
The 5,280 ETH is already in motion, but the lasting damage from a wallet exploit is rarely the theft itself, with secondary fallout that can stretch for months after the coins leave.
A second attacker drained the bridge using the identical contract and entry path as the May exploit, meaning the patch either shipped late or did not actually close the vulnerability class.
The macro overhang is piling up on BTC while a fresh $24M bridge exploit and a stablecoin collapse remind the market that idiosyncratic risk hasn't gone anywhere.
The attacker netted under $1M, but the mechanism (an unguarded oracle write with no liquidation delay) is the real warning for every BTC-collateralized lending book.
BTC dominance is climbing toward 57% and the Fear & Greed Index is sitting in 'Fear' territory while Allbridge becomes the latest protocol hit by an exploit.
The exploit hit Edel but the bug lives in credit markets built on tokenized equities, where 1:1 stock backing is meaningless if the wrapper, vault and exchange rate can be manipulated.
The attacker converted the full haul into 12,084 ETH at ~$1,966 and routed most of it through Tornado Cash, the laundering pattern that keeps drawing OFAC's attention.
The attacker weaponized a registered forwarder and future-dated oracle reports to mint artificial trading profits, draining the OLP Vault before the team froze trading.
An onchain attacker drained an estimated $18M from Ostium vaults before the protocol halted trading, the latest in a string of DeFi derivatives incidents testing offchain risk engines.
A zeroed oracle signature was the entire vulnerability: one byte in the wrong place let a single attacker borrow against collateral the system could not price, draining the Bonzo money market on…
The exploit is already six weeks old, but the wallet's swelling ETH balance turns the case into a live tracking exercise for every researcher watching the funds.
Bridge hacks and flash-loan drains are fading, but a single logic flaw in an AI-driven DeFi protocol can now cascade across six chains at once.