Register and share your invite link to earn from video plays and referrals.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
408 Following    88.8K Followers
🚨 SlowMist TI Alert 🚨 MistEye has detected a large-scale npm supply chain compromise impacting the Keyv/Cacheable ecosystem. Attackers published over 2,000 malicious package versions across the affected ecosystem, including keyv@6.0.0. Keyv, a widely used key-value storage abstraction with adapters for Redis, SQLite, PostgreSQL, MongoDB, and other backends, has roughly 127 million weekly downloads, leading to significant downstream supply chain exposure. The attackers' tradecraft closely mirrors techniques previously observed in the Shai-Hulud npm worm campaign, pointing to a highly automated and scalable supply chain attack. Potential attacker actions include credential theft, environment variable exfiltration, CI/CD secret compromise, remote payload delivery, and lateral propagation through compromised development environments. Security teams should immediately identify and remove affected package versions, upgrade to verified safe releases, review dependency lockfiles and build logs, monitor for suspicious outbound connections, rotate exposed credentials, and rebuild impacted environments from trusted sources if compromise is suspected. You can also visit to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. As always, stay vigilant!
Show more
🔥We’re glad to share that @evilcos, founder of @SlowMist_Team, will be a keynote speaker at the Cypher Asia Summit on August 28 in Hong Kong. Looking forward to an insightful discussion with industry leaders on Web3 security and the future of intelligent finance. 📅August 28, 2026 📍Cyberport, Hong Kong
Show more
🚨 Speaker Announcement We're thrilled to welcome COS (@evilcos ), Founder of @SlowMist_Team and one of the most respected white-hat hackers in the blockchain industry, as a keynote speaker at the Cypher Asia Summit. As a leading authority in Web3 security, COS has dedicated years to advancing blockchain security research and strengthening the digital asset ecosystem. His expertise spans on-chain security, threat intelligence, incident response, and digital asset risk management. At Cypher Asia, COS will join industry leaders from Crypto, AI, RWA, and institutional finance to discuss the evolving security landscape of Web3, the future of digital asset protection, and how robust security infrastructure will underpin the next generation of intelligent financial systems. 📍 Hong Kong 📅 August 28, 2026 Join us as we explore the future of secure, intelligent finance. See you at #CypherAsia#! #Crypto# #Web3# #BlockchainSecurity# #AI# #RWA# #DigitalAssets# #FinTech# #HongKong# #SlowMist#
Show more
🎉 SlowMist and @AgentON_ have officially announced a strategic partnership! Together we'll advance: AI Agent security capability building Security assessment & certification frameworks AI Agent security ecosystem development 🤝 Combining SlowMist's expertise in blockchain security, threat intelligence, and risk detection with AgentOn's open AI Agent Marketplace, we're jointly advancing the AI Agent ecosystem toward greater security and trust. Let's build a more secure future for AI Agents! 🚀
Show more
🚨SlowMist TI Alert🚨 💸 Loss: ~16.623 WETH 🔍 Root Cause: Selector 0x42be3129 of unverified contract 0xa317...c170 exposes an unrestricted low-level CALL, lacking access control & target/calldata validation. Attacker exploited the contract's existing ERC20 allowance to execute unauthorized transferFrom from victim. 📌 Attacker: 0xbdce6bdd52baceadd1fc91bf01f3bc6ab24df17a 📌 Victim: 0x386218744a2053d949a1cafae0b7b49a35e03f53 📌 Vulnerable Contract: 0xa31722ca2a32695280d0e7e325b3dd6d699fc170 Impact: The attacker drained the full WETH allowance (16.623 WETH) by abusing the arbitrary external call mechanism and bypassing the owner check. Powered by Tx:
Show more
🙌 Proud to co-host Cypher Asia | AI Crypto Finance Summit. 📅 Aug 28, 2026 📍 Cyberport, Hong Kong 🔗 Register: See you at #CypherAsia#! 🔥
Cypher Asia | AI Crypto Finance Summit is Coming! The convergence of AI × Crypto × RWA × Institutional Finance is accelerating faster than ever. we'll bring together leading voices from AI, Web3, traditional finance, and cybersecurity at Cyberport, Hong Kong, to explore the future of intelligent financial infrastructure and the next era of digital capital markets. Organizers: @fxh_crypto · @MEeventEN · @TenwingsAccelevator Co-hosts: @FosunWealthHK · @Sansec · @exSatNetwork · @SlowMist_Team Media Partners: @PANewsCN · @Foresight_News · @1783Dao · @broadchain_info 📅 August 28, 2026 📍 Hong Kong Whether you're a builder, investor, institution, AI innovator, or Web3 entrepreneur, we look forward to welcoming you to join the conversation shaping the future of finance. See you at #CypherAsia#! #AI# #Crypto# #Web3# #RWA# #Tokenization# #FinTech# #HongKong# #AgenticAI# #InstitutionalFinance#
Show more
🚀 SlowMist Hacking Time | Exploring High-Quality AI Agent Design Today, SlowMist held an internal Hacking Time session, with Mr. A sharing his thoughts on “High-Quality AI Agent Design” and how to build more reliable AI Agent systems. The session explored how to move beyond long prompts and design AI Agents with structured workflows, clear execution processes, and verifiable outcomes — making Agent behavior more transparent and easier to validate. As AI Agents move closer to real-world adoption, reliability and security will become essential foundations for their future development. SlowMist will continue exploring AI Agent technologies and security challenges, contributing to a safer and more reliable AI ecosystem.🫡
Show more
🚨SlowMist TI Alert🚨 💸 @SetProtocol Loss: ~9.6K USD 🔍 Root Cause: Index Coop `ExchangeIssuance.issueSetForExactToken` trusted arbitrary SetToken state without locking. The function read components and units for quoting, but allowed a malicious manager pre-issue hook to inflate `positionMultiplier` via NAV `issue`/`redeem` with a fake valuation. `BasicIssuanceModule.issue` then read inflated real units from `ExchangeIssuance` via `transferFrom`, causing TOCTOU-based asset drain. 📌 Attacker: 0x0736930ae35eafefa789f11edf41d7b799e7c99d 📌 Victim: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance) 📌 Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948 📌 Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58 📌 Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802 ⚠️ Impact: ExchangeIssuance lost real assets after attacker issued BHSET with 0.05 WETH, then abused hook to inflate component units ~93.66x, allowing excessive `transferFrom` during issue. Powered by Tx:
Show more
🚨 Job Scam Alert: Interview Software Used to Deliver Info-Stealing Malware MistEye has identified a job scam campaign targeting Web3 professionals. Threat actors are impersonating recruiters and luring victims into installing a malicious application disguised as an AI meeting tool called “Relay”. The malware targets both macOS and Windows users, attempting to steal sensitive data including browser credentials, wallet-related information, Keychain data, Telegram sessions, and more. We analyzed the samples and revealed how this attack chain was built. Please remain cautious when installing software during online interviews or recruitment processes. Avoid executing unverified applications and carefully review unexpected installation requests or system password prompts. Read the full analysis 👇
Show more
🚀 SlowMist has officially released MistEye DNS Guard, a lightweight local DNS relay and threat observation tool built with Rust for macOS and Linux. By turning DNS into an observation point, MistEye DNS Guard helps detect malicious domains, public IPs, and outbound process connections — while keeping normal DNS resolution unaffected through asynchronous threat detection. 🌟 Key capabilities: 🔹DNS relay & system DNS takeover 🔹Domain and public IP threat detection 🔹Outbound process monitoring 🔹Malicious event retention & Webhook alerts 🔹Lightweight deployment with built-in SQLite persistence, no external database required ⚡ No complex infrastructure required — download the precompiled binary, configure the TOML file, and start monitoring. 📄 Learn more about MistEye DNS Guard: 🛠️ Explore the open-source project:
Show more
Threats are evolving beyond code — targeting users, infrastructure, and AI systems. Proud to collaborate with OKX @wallet and @osec_io on the H1 2026 Web3 Security Report, sharing insights on emerging threats and why security must move from response to prevention. 👏
Show more
In H1 2026, we blocked 10M+ risky site visits and flagged 4M high-risk signatures. Our Web3 Security Report with @SlowMist_Team and @osec_io shows how threats are evolving, and how protection starts before you sign. Read it here:
Show more
Thank you @Foresight_News for the in-depth coverage and citation. Several major incidents in H1 2026 reinforce an important trend: today's attack surface extends far beyond code. Security shouldn't stop at audits—it must include operational security.
Show more
🧐最大的漏洞,始终是人 最典型的案例就是 Solana 链上的永续合约交易平台 Drift Protocol 被盗案件。 2025 年秋天,一群自称来自量化交易公司的人开始接触 Drift 团队。 他们投入超过 100 万美元真金白银在 Drift 上交易,参与社区讨论,用 6 个月时间建立信任。2026 年 4 月 1 日,他们诱导多签签名者(控制合约资金的多个授权人之一)在一笔看似正常的交易中预签了隐藏授权。 12 分钟内,约 2.85 亿美元用户资产被转走。 事后调查将攻击归因于与朝鲜政府关联的攻击组织 UNC4736,该组织自 2018 年起持续针对加密货币和金融科技行业,通过供应链攻击、社会工程学、恶意软件投递等方式窃取数字资产。 其已知的大型攻击事件包括 2023 年 3CX 供应链攻击、2024 年 Radiant Capital 约 5000 万美元被盗,以及本次 Drift 约 2.85 亿美元被盗,根据可统计数据计算该组织共盗取资金约 3.35 亿美元。 Drift 是社会工程的极端案例,但运营安全的漏洞有多种形态,上半年,密钥管理和基础设施层面的失败密集出现。 🔸Kelp DAO 的攻击者入侵了项目依赖的第三方 RPC 基础设施,通过伪造跨链消息验证转走约 2.91 亿美元; 🔸Resolv Labs 做了 18 次安全审计,最终因为 AWS 云端密钥管理服务被突破损失约 2685 万美元; 🔸7 月中旬, @Ostium 损失超过 2375 万美元的安全事件也是源自于管理员账户私钥泄露,黑客入侵了与协议价格系统相关的链下基础设施。 社会工程、基础设施入侵、云端密钥泄露、代码仓库暴露,攻击面已经扩展到有人存在的每一个环节。 慢雾 @SlowMist_Team @evilcos @im23pds 追踪朝鲜相关攻击组织多年,观察到一个明确的战术转变,社工手法正从快速获取权限演变为长期经营信任,攻击周期更长、投入资源更多、隐蔽性更强。 作为防守方,加密行业至今没有通用的运营安全标准,慢雾在采访中提到,很多团队仍然把安全等同于上线前做一次代码审计,对密钥管理、权限隔离、员工安全意识的投入严重不足。 一些成熟项目已经建立了比较完善的安全体系,现实是,大量中小项目连基本的多签配置和密钥轮换都没有。 慢雾安全团队把密钥管理放在 DeFi 项目运营安全最低标准的第一位,关键资产和管理权限应采用多签架构,建立规范的密钥生成、存储、备份和轮换机制。 其认为,「运营安全本质上也是人的安全,上半年 Web3 安全最本质的变化,是攻击的重心正在从找代码漏洞转向攻破人和流程」,当社会工程攻击不断升级,项目团队需要持续开展安全培训和攻防演练,提升成员对钓鱼、AI 生成内容等新型攻击手法的识别能力。
Show more
🚨SlowMist TI Alert🚨 💸 @LienFinance Loss: ~542k USD 🔍 Root Cause: The `exchangeEquivalentBonds` function in BondMakerCollateralizedEth lacks proper multiset integrity checks. It only counts total exception occurrences instead of verifying each bondID's appearance per group. By repeating a single exception bondID in the output group, attackers consumed the exception count twice, masking a missing input exception. This allowed minting new non-exception BondTokens without burning the corresponding input bonds, which were then sold for USDC from a pre-approved victim address. 📌 Attacker: 0x0d7d9023531ad1a88414e216ee2715f63561808a 📌 Victim: 0xa961684a3a654fb2cca8f8991226c0cefc514d80 📌 Vulnerable Contract: 0xda6fc5625e617bb92f5359921d43321cebc6bef0, 0x843225cf6e663e4454732d6b551a737ac7b47de0 Attackers exploited the flawed exception-counting logic to mint unbacked bond tokens, swapped them for USDC via three pre-authorized endpoints, and drained 542,144.628604 USDC from the victim. Powered by Tx:
Show more
🚨 SlowMist TI Alert 🚨 💸 @VerusCoin Loss: ~$7.5M ⚠️ Unlike the prior 0x6990…b321 exploit, which decoupled the validated proof from the executed transfer payload, this attack hash-bound the transfers to the CCE but failed to validate the CCE’s economic backing; both exploit flawed cross-chain import validation. 🔍 Root Cause: `VerusProof.checkExportAndTransfers` verified selected CCE fields—including `hashReserveTransfers` against attacker-supplied serialized transfers and the source/destination IDs—but did not enforce the CCE’s accounting semantics. It failed to parse or validate `totalamounts`, `totalfees`, `totalburned`, CTxOut `nValue`, or whether the prior CCE outpoint carried sufficient value and assets to cover the claimed transfers. As a result, a matching transfer hash was incorrectly treated as authorization to release bridge assets, rather than merely a commitment to the requested transfers. 📌 Attacker EOA: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c 📌 Victim Bridge: 0x71518580f36feceffe0721f06ba4703218cd7f63 📌 Vulnerable Contract: 0x54e03a1682fd0bb065b669f6296f97028dcfd4ce 📌 Fund Receiver: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54 Impact: The attacker submitted a successor CCE anchored to an accepted Verus state root, containing a hash commitment to eight attacker-defined reserve transfers. Because the bridge did not verify whether the CCE’s economic fields backed those transfers, it executed eight payouts from bridge custody to the attacker-controlled receiver—releasing ETH, DAI, USDC, USDT, and four additional tokens without enforced cross-chain asset backing. Powered by Tx:
Show more
✍️ From Having Controls to Effective Controls | Risk Control Insights from the FATF’s Latest Report FATF’s latest report highlights a key challenge for the virtual asset industry: having #AML# controls is no longer enough — they must be effective. As stablecoins, unhosted wallets, and cross-chain transactions reshape on-chain fund flows, traditional blacklist-based screening is becoming insufficient. Effective risk management requires deeper visibility into fund flows, transaction relationships, entity attribution, and risk exposure across complex on-chain environments. In our latest article, we explore the key risk scenarios highlighted by FATF and how virtual asset businesses can strengthen on-chain risk identification and analysis with tools such as @MistTrack_io . 📖 Read more:
Show more
🚨SlowMist TI Alert🚨 💸 @42dao_official Loss: ~ 912k USD 🔍 Root Cause: Attackers exploited an abnormally low BTCB oracle price from Median Oracle via Spotter `poke` and Dog `bark`. The spotter lacked price deviation checks, max drawdown limits, and minimum price protections, allowing immediate write of the low spot into Vat. The dog module then used this updated spot without any liquidation delay or oracle price validation, enabling instant liquidation of multiple BTCB vaults. 📌 Attacker: 0x9d8dd9f2d734675e2bfcc142d1c7a45609ca213c 📌 Victim: 0x973a722fd8bcd4b81f4c5c1ac687073e44aa9a0c 📌 Vulnerable Contract: 0x849dc2416cbe54995a1d725afe526c0e38829228 (Spotter) & 0x00101ae4467d72e83ef68df447c41de0c71f634e (Dog) Impact: A single-transaction combo exploited the missing price protection and liquidation delay in Maker-style system, allowing an attacker to liquidate multiple BTCB vaults using an abnormally low oracle price and profit from the arbitrage. Powered by Tx:
Show more
🚨 Threat Intelligence | On-Chain Backdoor in a Malicious TRAE Extension Following @Will42W’s warning about TRAE IDE extension supply chain risks, SlowMist investigated the malicious extension juannegro.solidity. Although removed from Open VSX, the extension was still available through the TRAE marketplace as of July 18, 2026. It impersonated a legitimate Solidity plugin and acted as a cross-platform malware dropper. Our analysis found that it: 🔹 Impersonates a legitimate Solidity extension and uses the marketplace as the initial malware delivery channel 🔹 Automatically executes after IDE startup and establishes persistence across platforms 🔹 Uses an Ethereum smart contract to store and retrieve dynamic C2 configurations 🔹 Allows attackers to update C2 endpoints and payload delivery without republishing the extension This incident highlights how extension marketplaces can become initial infection vectors, while blockchain infrastructure can be abused for dynamic C2 management. Users who installed juannegro.solidity should remove the extension and check their systems for potential compromise. Full analysis👇
Show more
Previously, we analyzed Grok CLI’s data upload behavior and found that its repository upload mechanism could send git bundles containing sensitive files such as .env files and RSA private keys. Following that analysis, we continued auditing Grok Build CLI’s security model after it was open-sourced. Within 24 hours, we identified two attack chains that can lead to arbitrary code execution without explicit user approval. The root cause is not a single bug, but a fragmented trust model: project-level files can influence AI Agent instructions and permission decisions without sufficient validation. Key findings: 🔹 cargo check was incorrectly classified as a safe command. Combined with malicious AGENTS.md instructions, attackers can trigger execution and achieve code execution. 🔹 .claude/settings.json with bypassPermissions can override permission checks and enable unrestricted tool execution. 🔹 Grok Build CLI inherits Claude Code CLI’s permission configuration model, exposing similar risks. 🔹 .mcp.json introduces additional project-level attack surfaces through MCP configuration. These findings highlight a broader issue: When #AI# coding agents trust project-level files too much, opening a project can become equivalent to granting shell access. 📖 Full technical analysis: 👉 Previous analysis:
Show more
🚨 Threat Intelligence | Fake Recruitment Campaign Delivers Malware via GitHub Repository MistEye recently detected a malicious campaign targeting developers through fake Web3 recruitment. Attackers impersonated recruiters on LinkedIn, built trust through discussions about work experience and interviews, then sent a GitHub repository disguised as an “interview MVP” and tricked developers into running the project. Our analysis found that the malicious repository hid theme/js/auron-core.min.js as a Tailwind plugin. When developers ran the project’s development or build commands, the hidden Node.js loader was triggered and deployed multiple payloads for: 🔹 Browser credential & wallet data theft 🔹 Sensitive file collection and exfiltration 🔹 Remote command execution and interactive Shell access 🔹 Clipboard monitoring This campaign shows how trusted development workflows can become attack vectors. Developers should always inspect project scripts, dependencies, and build configurations before running unknown repositories. Full analysis👇
Show more
🚀 SlowMist has joined Cyberport’s Web4.0 & Agentic AI Security Alliance as a founding member! Together with alliance partners, SlowMist will contribute our expertise in AI Agent security, advance security standards and best practices, and help build a secure and trusted Web4.0 ecosystem. #AgenticAI# #Cybersecurity# #SlowMist# Read More👇
Show more
🚨SlowMist TI Alert🚨 💸 @Ostium Loss: ~11,862,445 USDC 🔍 Root Cause: An authorized oracle signer was used to submit malicious price reports through a registered forwarder. The attacker provided validly signed but manipulated oracle data, which was accepted by the oracle verification mechanism. By repeatedly opening and closing trades with artificially favorable prices, the attacker generated artificial profits and drained funds from the OstiumVault. 📌 Attacker Address: 0xd1794196f0fc99c7f27970e661597d77d9a85869 📌 Victim Address: 0x20d419a8e12c45f88fda7c5760bb6923cee27f98 (vault) 📌 Vulnerable Contract: 0x0aebc4094b60ea4e21e937e80dafdd58c07c5ebb (OstiumPrivatePriceUpKeep impl) & 0xd456939e54f68ef9b0be62abb2ec4a37397cb814 (OstiumVerifier) Impact: The attacker exploited compromised oracle privileges to submit manipulated price reports and execute repeated profitable trades, draining ~11.86M USDC from the vault. Powered by Tx:
Show more