Register and share your invite link to earn from video plays and referrals.

SunSec
@1nf0s3cpt
CISO @xrexinc | Founder @DeFiHackLabs Web3 Security Community | AiSecLabs | Contributor @SEAL_911
1.4K Following    14.2K Followers
🔥From Black Hat Asia 2017 as a Speaker to Black Hat USA 2026 at Arsenal. Nine years later, still building, still breaking, still learning. #BlackHatUSA# #Arsenal# #AISecurity# #Web3Security#
Show more
I think security researchers should give the @exvulsec decompiler a try. Its code reconstruction quality is exceptionally high. like this:
🔥I’ll be presenting at Black Hat USA 2026, then joining DEF CON 34 at the AI Village and Cryptocurrency Village. Want an exclusive DeFiHackLabs T-shirt? DM me. limited quantities available. See you in Las Vegas—let’s connect in person!
Show more
🚨 The Verus–Ethereum Bridge has been exploited again. Same contract. Same vulnerability. Same attack method. • May 17: ~$11.6M stolen • July 23: ~$7.5M stolen The same root cause remained exploitable for 66 days, bringing the combined loss to approximately $19.1M. How did the attack work? The attacker submitted a maliciously crafted Verus-side import containing an unbacked payout request. The bridge successfully verified the notary-signed state root, Merkle proof, and transaction hashes—but failed to confirm that the amount requested on Ethereum matched the amount actually exported or locked on Verus. In other words, the cryptography worked, but it authenticated the wrong thing: It proved that the import had been notarized—not that the payout was fully backed. Once the crafted import passed verification, the bridge treated it as legitimate and released assets from its own reserves, including ETH, tBTC, MKR, USDC, USDT, EURC, and scrvUSD. The DAI path went even further: the bridge accessed its MakerDAO collateral position and minted approximately 220,357 DAI to satisfy the fraudulent payout. The attack flow was: Malicious Verus import → Valid notary and proof verification → Missing source-amount validation → Unbacked Ethereum payout → Bridge reserves drained Victim contract: 0x71518580f36feceffe0721f06ba4703218cd7f63 Attacker: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c Payout recipient: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54 TX: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
Show more
🚨 $24.15M USDC drained from an Arbitrum bridge — — 5 compromised keys 5 hot-validator signatures carried 7,142/10,000 power (>2/3 quorum). The contract did exactly what it was told — the keys were the weak point. Two-phase attack, both traced on-chain: 1⃣ Propose (carries the 5 sigs + full 7-validator set, powers sum to 10,000) 2⃣ 200s dispute window → Execute (releases 24.15M USDC, bridged out via CCTP) Sigs are in the propose tx, not the withdrawal tx 👇 Propose: Execute: Stolen funds: 0x627654B2782bfC57580ecD11d40869b350B6ebAC now on ETH chain. 12,467.43703738 ETH
Show more
DeFiHackLabs funding update 🛡️ We raised $2,918.27 in donations + 11.0526 ETH in matching through Ethereum Security QF. Funds support open tools/data, AI security research & rewards for builders, submissions and hackathons. Thanks @TheDAOfund, @Giveth, @wintermute_t & every donor! We’re putting the support to work. Our open resources now include: • 734 root-cause cases (from 611) • 822 incidents (from 622) • 827 reproducible PoCs (from 715) • A daily Web2 & Web3 security digest The funds will help us keep these public goods accurate, accessible, and useful: maintaining datasets, improving the Incident Explorer, adding reproducible exploit PoCs, and covering the infrastructure needed to keep them open to the community. We’ll also support builders and white hats applying AI to Web3 security—including AI credits for projects that create practical security public goods. One result we’re proud to share: Black Hat USA 2026—and it was accepted into Arsenal. We’ll present it in Las Vegas this August. We’ll dedicate funding to community incentives, including rewards for open-source development, technical research and write-ups, security hackathon participation, and submissions to international conferences. We’ll keep publishing progress and outcomes. Thank you for helping us make Ethereum safer. 🛡️
Show more
DeFiHackLabs & Unphishable have been selected for the @thedaofund Ethereum Security Quadratic Funding round on @Giveth! 🚀 Our third project, AiSec Labs, is coming soon — and will be a key focus for us this year. 🚀 Support us and help strengthen Ethereum security 👇
Show more