Register and share your invite link to earn from video plays and referrals.

Cos(余弦)😶‍🌫️
@evilcos
Founder of @SlowMist_Team // 分身一号/捉虫大师/救火运动员 // 🕖灾备频道
1.5K Following    125.3K Followers
🚨SlowMist TI Alert🚨 💸 @Fetch_ai Loss: ~$2M 🔍 Root Cause: TokenConversionManagerV3's conversionIn() leaves single-EOA ECDSA signature as the sole authorization check. It lacks the checkLimits(amount) modifier present in conversionOut(), and does not verify any on-chain burn/lock proof. Using the leaked authorizer private key, the attacker signed a fresh message for their own address, passed the check, and drained the bridge's entire FET balance in one call. 📌 Attacker: 0x1572f2af7696b39c85e3221cde8efb640f86c362 📌 Recipient: 0x2dcc1085fdcf418b421e45e86e4e54637cc21dfe 📌 Victim/Vulnerable Contract: 0xab424a430cc09864fa1277a38193111705adf3a3 Powered by Tx:
Show more
⚠️ Security Advisory | iPhone Users: Check Whether You’ve Ever Installed the FomoPeek App Binance is aware of a security incident recently disclosed by the community. According to security firms including SlowMist, the third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, files, and more. Please note that this type of malware targets the device itself. If an attack succeeds, data from all apps on the affected device may be accessed. Please check the following: 1. Are you using an iPhone or iPad running iOS 26.x or earlier? 2. Have you ever installed the FomoPeek app? If both apply to you, we recommend taking the following steps immediately: 1. Delete the FomoPeek app and do not reinstall it. 2. Update your iOS to the latest available version. 3. For self-custody wallet users: On a device that has never had the app installed, create a new wallet and transfer your assets to the new wallet address. 4. If you notice any unusual asset activity, preserve the affected device and relevant evidence, and contact Binance Customer Support for further investigation. We also remind all users: Do not install apps from untrusted sources, and keep your device software up to date.
Show more
🚨SlowMist TI Alert🚨 💸 @likwid_fi Loss: 74.31 BNB 🔍 Root Cause: LikwidMarginPosition._executeAddCollateralAndBorrow (leverage=0 branch) never assigns delta.pairDelta, so the borrow path leaves pairReserves untouched. getAmountOut(pairReserves,...) returns the same 4.7857 BNB quote on every call — the attacker repeated the margin/borrow cycle 14 times, settling 211.8M TOKEN at the first-trade marginal price with no AMM price impact. 📌 Attacker EOA: 0x90bde1e0bb16b3deeb9d638acf8d01f19fd2f31e 📌 Attack Contract: 0xc63fb27f52ed8d06673c60c3075b2d3bd26cf4aa 📌 Vulnerable Contract: 0x6bec0c1dc4898484b7f094566ddf8bc82ed7abe8 (LikwidMarginPosition) 📌 Victim Contract: 0x065d449ec9d139740343990b7e1cf05fa830e4ba (LikwidVault) Powered by Tx:
Show more
🚨 SlowMist TI Alert 🚨 @DCENTWALLETS has reported abnormal asset transfers involving its App Wallet. Users should update the DCENT app to the latest version before making any transfers. Stay alert for #phishing# and impersonation attempts. Never share your recovery phrase/private key or send assets to any address for “recovery” or “compensation.” Please refer to DCENT’s official announcement for details and further updates.
Show more
Important Update Regarding the DCENT App Wallet To date, abnormal asset transfer cases have been identified involving the DCENT App Wallet. So far, we have not confirmed any impact originating from DCENT Hardware Wallets themselves. Please follow the guidance below based on how you use the DCENT app. If you hold assets in the DCENT App Wallet, or if the same recovery phrase is used for both your DCENT App Wallet and a hardware wallet: Please update the DCENT app to the latest version before transferring any assets to a secure hardware wallet or another trusted wallet address. • Update the DCENT app before transferring any assets. • Do not initiate transactions through the DCENT App Wallet before updating the app. • If the same recovery phrase is used in the DCENT App Wallet, action is required regardless of where that recovery phrase was originally generated. If you only use your DCENT Hardware Wallet with the DCENT app: No additional action is required for your hardware wallet if you have never entered or restored that hardware wallet’s recovery phrase in the DCENT App Wallet. ⚠️ Please remain vigilant against impersonation and phishing attempts. • DCENT will never ask for your recovery phrase or private key, nor will we ask you to send assets to a separate wallet address for recovery or compensation. • Do not follow recovery or compensation instructions, wallet addresses, or links sent through DMs, email, social media, or other unofficial channels. We are prioritizing the investigation into the related cases and will provide further updates through our official channels as soon as the cause, scope of impact, and additional response measures are confirmed. Official X accounts (We have no support X accounts) @DCENTWALLETS @DCENTWALLETS_KR @DCENTWALLETS_JP Customer Support
Show more
🚨SlowMist TI Alert🚨 💸 Unknown Gnosis Safe wallet Loss: ~$7.73M 🔍 Root Cause: In the `multicall(address, bytes[])` function of the Router contract (address `0x4f005592…`), the `_contract` parameter could be set to `address(this)`. Consequently, the `_isAuthorized` function—used for internal permission checks—would unconditionally return true. This allowed the victim Safe module contract to execute attacker-crafted malicious call data via `DelegateCall`, injecting aEthrsETH into an attacker-created liquidity pool equipped with a hook; the assets were subsequently swapped and redeemed for profit. 📌 Attacker: 0x2f7e143e27f2fa26ef3b8ac72698f1d321422f67 📌 Victim: 0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8 📌 Vulnerable Contract: 0x4f0055926c839d1d960a82cbf84e2ee933958ebc Txs: Powered by
Show more
🚨 On September 6, 2026, @Liquid_BTC was affected by a cache key collision vulnerability in rangeproof verification. An attacker minted ~3,998.5 L-BTC with no corresponding peg-in. Within minutes, the unbacked L-BTC was pegged out into real BTC on the Bitcoin mainnet. About 3,400 BTC was later returned to the federation peg wallet, while ~598.5 BTC remains under the attacker’s control. The SlowMist Security Team traced the fund flows on the #Bitcoin# side using @MistTrack_io and fully analyzed the incident. 🧩 Attack flow: 1️⃣ Two setup transactions first landed valid rangeproofs and commitments, while embedding a crafted payload in the locking script to seed node caches. 2️⃣ A follow-up minting output reused a colliding cache key — the same raw concatenation of proof, commitment, asset commitment, and scriptPubKey, but with different field boundaries. 3️⃣ On a cache hit, nodes skipped secp256k1_rangeproof_verify and min-value checks, accepted an unbacked commitment, and minted ~3,998.5 L-BTC. The fake UTXOs were consolidated and pegged out within minutes. ⚙️ Root Cause: The Elements rangeproof cache key concatenated variable-length fields without length prefixes. Distinct argument tuples could hash to the same key, so a positive cache hit meant skipping cryptographic verification. 🛡️ SlowMist Insight: A positive-result cache in a consensus verification path is itself a cryptographic primitive. Every field the verifier reads — and every field boundary — must be unambiguously bound into the key. Treat cache-key integrity as a mandatory item in consensus-layer audits. Full analysis👇
Show more
🚨SlowMist TI Alert🚨 We first reached out to the team privately to responsibly disclose the issue before making any public statement. 💸 @ether_fi Loss: ~15.45 ETH 🔍 Root Cause: `AtomicQueue.solve()` lacks access control on the caller-supplied `solver` — there is no `solver == msg.sender` check, nor any signature, registration, or consent verification. The attacker first created a maliciously crafted `AtomicRequest` using the `updateAtomicRequest()` function, then forced a victim address to act as the `solver`. AtomicQueue subsequently called `finishSolve` on the victim and executed `want.transferFrom(solver, users[i], assetsToUser)`, abusing the victim's pre-existing ERC-20 allowance to drain funds. 📌 Attacker: `0xa5cc6e490bce9185fa47b421f2eac677a83b64ea` 📌 Vulnerable Contract (AtomicQueue): `0xd45884b592e316eb816199615a95c182f75dea07` Powered by Tx:
Show more
🚨SlowMist TI Alert🚨 💸 @BeatXswap Loss: 2,984,557 BTX (~$77,512) 🔍 Root Cause: The `LiquidityVestingConvert` contract calculates BTX quotes via `_calculateQuote()`, which reads `IUniswapV3Pool.slot0()` spot price as the sole oracle. No TWAP protection, no sanity check, no deviation limit. An attacker borrowed 6,000,000 BTX via flash loan, dumped it into the V3 pool to crash `sqrtPriceX96`, then called `deposit()` twice (10,000 + 2,000 USDT), triggering `POSITION_MANAGER.mint()` at the manipulated spot price and draining BTX from LP positions. 📌 Attacker: 0x67B2f08683A735cfE6f6E57fA86909b62218C2a1 📌 Victim: 0x1e647FAADb05f2124BFCcFC003EDc06D1A90bf5D 0x9a7A92240FBAc4030b65A6E61239928d6Bcc716F 📌 Vulnerable Contract: 0x1e647FAADb05f2124BFCcFC003EDc06D1A90bf5D Powered by Tx:
Show more
‼️ BREAKING: Trezor’s email provider has been breached. Customers are receiving a non-spoofed email, it’s real, just not sent by the real company. This follows shortly after the breach of their logistics provider, which left 80k+ customers’ data exposed.
Show more
🚨SlowMist TI Alert🚨 💸 @EnsoBuild Loss: ~5.6 ETH 🔍 Root Cause: An oracle price calculation error occurred in the Enso Finance / DPI Strategy Vault. In `Controller.deposit()`, the EnsoOracle's `estimateStrategy()` is called before and after the user tokens are transferred, and shares are minted on the difference: `mint = amountAdded * totalSupply / valueBefore`. The valuation chain — EnsoOracle → ItemEstimator → `ProtocolOracle.consult()` — prices tokens via UniV3 `pool.observe()`, but the registry's `fee` field is reused as `secondsAgo`, producing a near-spot TWAP window. Due to the absence of TWAP consistency checks or price range validation—combined with the fact that the liquidity in the Uniswap v3 pool used for price calculation was inherently imbalanced—an attacker was able to swap 0.683 WETH for 268.42 FARM tokens on Uniswap v2 in a single transaction, while the imbalanced v3 pool incorrectly valued that amount at 6.3 WETH (~ 9.2x). Subsequently, an excessive number of shares were minted at an incorrect price and redeemed for profit. 📌 Attacker: `0x3196398321D77a2511d369DCB6eCa9d2aD87b73A` 📌 Victim (Strategy): `0x890ed1ee6d435a35d11051d9ed97ff457ce53b5942` 📌 Vulnerable contract: Controller impl: `0xd8D22509C1fe47516D8F82A28CFd728111F57Ef1` Oracle: `0xAb7505eB360cE0D63e8E88f7853677EcD5537DC0` Powered by Tx:
Show more
Hours ago, Tether froze approximately 39,273,713 USDT across 10 TRON addresses linked to Xinbi Guarantee新币担保. Following its freeze of 汇旺担保Huione-linked funds, this appears to mark another crackdown on illicit Telegram-based escrow platforms.
Show more
🚨 On September 4, 2026, the well-known decentralized lending protocol @NotionalFinance was attacked, resulting in a loss of approximately $1.73 million. The SlowMist Security Team has fully analyzed the incident. 🧩 Attack flow: 1️⃣ In a preceding transaction, the attacker deployed auxiliary contracts and called setApprovalForAll on ERC1155Trade to authorize them, after querying two CashMarket maturities and the required AssetIds. 2️⃣ First safeTransferFrom: minted an fCash pair with amount 1 (maturity Sep 4, 2026). The position was too small and rounded to 0 in ETH terms, so the free-collateral check passed. 3️⃣ Second safeTransferFrom: minted an fCash pair with amount uint128.max at a different maturity (Dec 3, 2026), so the two liabilities would not be added in the same bucket and revert under SafeMath. 4️⃣ mintfCashPair then checked free collateral. The two liabilities summed to -2^128, overflowed to 0 when converted to ETH, and the protocol treated the account as healthy. 5️⃣ Receiving contract 2 split the large claim to two auxiliary contracts. The payer was now contract 2, which already held a positive claim, so the check passed and the two contracts received receiver fCash. 6️⃣ In a second transaction, the attacker settled those two positions, increasing the cash balances in Escrow, then called withdraw to realize the profit. ⚙️ Root Cause: ExchangeRate._convertToETH does uint128(balance.abs()) on Solidity 0.6.x with no range check. When the liability is -2^128, 2^128 truncates to 0, so mintfCashPair only sees free collateral ≥ 0 and allows an unbacked position. 🔒 SlowMist Insight: A successful cast is not a successful valuation. Reject any abs() result above type(uint128).max, use SafeCast, and test extremes such as uint128.max and -2^128. Collateral ≥ 0 is not the same as collateral that is real. Full analysis👇
Show more
🚨SlowMist TI Alert🚨 💸 @cozyfinance Loss: ~$160k 🔍 Root Cause: The contract will automatically consider any undisputed YES = 1e18 price proposal submitted by any address via the UMA Optimistic Oracle as an external attack event. The trigger does not independently verify the authenticity of the Aave/Curve event; Cozy PToken's compensation eligibility is not tied to a snapshot of holdings prior to the event/UMA proposal. An attacker-controlled executor submitted YES = 1e18 to two permissionless UMA Optimistic Oracle requests. The triggers accepted the affirmative proposals, and after settlement the markets transitioned to TRIGGERED, enabling CPT redemption. 📌 Attacker: Tx sender 0x003FE7359A4E03C85Ac2f521eC699ED84C7c5ccB 📌 Victim: 0x17705474203f7ff7ba8a940c433ab43d1f58e249 📌 Vulnerable Contract: 0xeb6613fac35fed17c276e3fe45d67da67685f1ef, 0xacd105feea362d5c27caaba0b45f53d91b92de27, and payout implementation 0x17aff89bf88b4eb56a1bcb256ff49fa1910e8410. Transactions: Powered by
Show more
🚨SlowMist TI Alert🚨 💸 @SetProtocol Loss: ~9.6K USD 🔍 Root Cause: Index Coop `ExchangeIssuance.issueSetForExactToken` trusted arbitrary SetToken state without locking. The function read components and units for quoting, but allowed a malicious manager pre-issue hook to inflate `positionMultiplier` via NAV `issue`/`redeem` with a fake valuation. `BasicIssuanceModule.issue` then read inflated real units from `ExchangeIssuance` via `transferFrom`, causing TOCTOU-based asset drain. 📌 Attacker: 0x0736930ae35eafefa789f11edf41d7b799e7c99d 📌 Victim: 0xc8c85a3b4d03fb3451e7248ff94f780c92f884fd (ExchangeIssuance) 📌 Malicious SetToken: 0xf7c2d0a2bf81bf803ed6e1d97c89fe3b30b06948 📌 Malicious Manager/Hook: 0x8f449d85f728c1dd6596880ba28a0b80b6a26c58 📌 Malicious Valuer: 0x388a3da33825e1f44ac71b8fd543523cdf994802 ⚠️ Impact: ExchangeIssuance lost real assets after attacker issued BHSET with 0.05 WETH, then abused hook to inflate component units ~93.66x, allowing excessive `transferFrom` during issue. Powered by Tx:
Show more
🚨 Job Scam Alert: Interview Software Used to Deliver Info-Stealing Malware MistEye has identified a job scam campaign targeting Web3 professionals. Threat actors are impersonating recruiters and luring victims into installing a malicious application disguised as an AI meeting tool called “Relay”. The malware targets both macOS and Windows users, attempting to steal sensitive data including browser credentials, wallet-related information, Keychain data, Telegram sessions, and more. We analyzed the samples and revealed how this attack chain was built. Please remain cautious when installing software during online interviews or recruitment processes. Avoid executing unverified applications and carefully review unexpected installation requests or system password prompts. Read the full analysis 👇
Show more
🚨SlowMist TI Alert🚨 💸 @42dao_official Loss: ~ 912k USD 🔍 Root Cause: Attackers exploited an abnormally low BTCB oracle price from Median Oracle via Spotter `poke` and Dog `bark`. The spotter lacked price deviation checks, max drawdown limits, and minimum price protections, allowing immediate write of the low spot into Vat. The dog module then used this updated spot without any liquidation delay or oracle price validation, enabling instant liquidation of multiple BTCB vaults. 📌 Attacker: 0x9d8dd9f2d734675e2bfcc142d1c7a45609ca213c 📌 Victim: 0x973a722fd8bcd4b81f4c5c1ac687073e44aa9a0c 📌 Vulnerable Contract: 0x849dc2416cbe54995a1d725afe526c0e38829228 (Spotter) & 0x00101ae4467d72e83ef68df447c41de0c71f634e (Dog) Impact: A single-transaction combo exploited the missing price protection and liquidation delay in Maker-style system, allowing an attacker to liquidate multiple BTCB vaults using an abnormally low oracle price and profit from the arbitrage. Powered by Tx:
Show more
🚨 Threat Intelligence | On-Chain Backdoor in a Malicious TRAE Extension Following @Will42W’s warning about TRAE IDE extension supply chain risks, SlowMist investigated the malicious extension juannegro.solidity. Although removed from Open VSX, the extension was still available through the TRAE marketplace as of July 18, 2026. It impersonated a legitimate Solidity plugin and acted as a cross-platform malware dropper. Our analysis found that it: 🔹 Impersonates a legitimate Solidity extension and uses the marketplace as the initial malware delivery channel 🔹 Automatically executes after IDE startup and establishes persistence across platforms 🔹 Uses an Ethereum smart contract to store and retrieve dynamic C2 configurations 🔹 Allows attackers to update C2 endpoints and payload delivery without republishing the extension This incident highlights how extension marketplaces can become initial infection vectors, while blockchain infrastructure can be abused for dynamic C2 management. Users who installed juannegro.solidity should remove the extension and check their systems for potential compromise. Full analysis👇
Show more
Previously, we analyzed Grok CLI’s data upload behavior and found that its repository upload mechanism could send git bundles containing sensitive files such as .env files and RSA private keys. Following that analysis, we continued auditing Grok Build CLI’s security model after it was open-sourced. Within 24 hours, we identified two attack chains that can lead to arbitrary code execution without explicit user approval. The root cause is not a single bug, but a fragmented trust model: project-level files can influence AI Agent instructions and permission decisions without sufficient validation. Key findings: 🔹 cargo check was incorrectly classified as a safe command. Combined with malicious AGENTS.md instructions, attackers can trigger execution and achieve code execution. 🔹 .claude/settings.json with bypassPermissions can override permission checks and enable unrestricted tool execution. 🔹 Grok Build CLI inherits Claude Code CLI’s permission configuration model, exposing similar risks. 🔹 .mcp.json introduces additional project-level attack surfaces through MCP configuration. These findings highlight a broader issue: When #AI# coding agents trust project-level files too much, opening a project can become equivalent to granting shell access. 📖 Full technical analysis: 👉 Previous analysis:
Show more
⚠️ALERT: SlowMist warns new malware targeting Apple Mac users can steal Telegram accounts, passwords and crypto. The security firm found a macOS malware that allows hackers to steal Telegram sessions, encrypted wallet databases, and passwords saved in Apple Keychain, browsers and Notes. They can then access chats, unlock wallets offline, and show fake wallet apps (Ledger and Trezor) to steal recovery phrases.
Show more