#PeckShieldAlert# @THORChain has been exploited for ~$10M worth of crypto, including 36.75 $BTC ($3M) and ~$7M worth of assets from #BNBChain#, #Ethereum#, and #Base#.
The stolen funds mainly sit in:
bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37
0xd477b69551f49C0519F9B18c55030676138890Bd
After liquidating the KelpDAO exploiter's aave position, previously-affected ethereum:0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2 core market on Ethereum now has available liquidity of ~$177m !
It seems the 0x1f4c_Kelp DAO Exploiter on ethereum is being liquidated (w/ ~$123m debt) in @aave
Here is the related tx:
The arbitrum position is also liquidated:
It seems the admin key of @wasabi_protocol has been compromised with the estimated loss of $5.5m across multiple chains, including ETH, BASE, BLAST, and BERA chains.
Here is the related tx to add the malicious admin:
We're aware of an issue and are actively investigating.
As a precaution, please do not interact with Wasabi contracts until further notice.
We'll share an update as soon as we have more information. Thanks for your patience.
A victim just lost a Alchemix Yearn yvVault position $yvWETH (estimated $~1m), from an earlier approval to an unverified contract ( This unverified contract, created 10 days ago, turns out to be buggy and can be exploited for arbitrary call execution.
Here is the vulnerable logic from the decompiled contract, affected in the following exploit tx:
It seems the @KelpDAO exploiter moved stolen funds via @LayerZero_Core to Tron for laundering.
Related steps:
1: Transfers on Ethereum:
Kelp DAO Exploiter1
-> 0xF9802c5EB6b972Ba686aFa7CA615910Ea8310b85
-> 0x42a71A7ED12582378d4A4567A1af6Bad4f03dF84
-> 0x0BA9e88059c85fBD76b0C025F00C8B8Ebb0AddDf
2: Cross-chain: Ethereum -> Arbitrum:
0x0BA9e88059c85fBD76b0C025F00C8B8Ebb0AddDf (Ethereum)
-> 0x4D5A08A96D644d7CA7F4541E1512a53D55aA5842 (Arbitrum)
3: Swap on Arbitrum from ETH -> USDT
4: Cross-chain: Arbitrum -> Tron
0x4D5A08A96D644d7CA7F4541E1512a53D55aA5842 (Arbitrum)
-> TLTCf565jGgSeCsUhBpWuPhrrHcGGX9ekT (Tron)
Today's @KelpDAO exploiter deposited the stolen $rsETH into various lending protocols (AaveV3, CompoundV3, Euler) and and borrowed massive $WETHs w/ >$236m debt.