<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>YFarmX Crypto Exploit Tracker</title><description>New incidents on the YFarmX Crypto Exploit Tracker: what was hit, how much was lost and how the attack worked, with on-chain references and sources on every record.</description><link>https://yfarmx.com/</link><language>en-GB</language><item><title>Liquid reserve withdrawal and partial Bitcoin recovery</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0132/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0132/</guid><description>Liquid acknowledged a roughly 4,000 BTC withdrawal, valued at about $320m at the time. SideSwap says the L-BTC used for the peg-out was created through an Elements bug. On 7 September, 3,400 BTC returned to the federation address; the return transaction sent 598.49955894 BTC back to the actor. The dollar figure here is the initial gross withdrawal estimate, before recovery.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>Software Bug</category><category>Liquid / Bitcoin</category><category>Bridge</category></item><item><title>Aquifer AMM Exploit on Solana</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0004/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0004/</guid><description>Aquifer, an automated market maker on Solana, was exploited on 31 August 2026. DefiLlama records the loss at $2,469,729 and classifies it as an access-control incident involving an arbitrary external call.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>Solana</category><category>AMM</category></item><item><title>More Markets Lending Reserve Drain on Flow EVM</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0003/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0003/</guid><description>Security firm Blockaid flagged a suspected exploit on More Markets, a lending protocol on Flow EVM, on 31 August 2026, saying an attacker combined Ankr’s liquid staking token ankrFLOW with Aave V3 efficiency mode to overborrow against the mFlowWFLOW reserve. More Markets said the same day that it was investigating a claim it had been exploited. DefiLlama records the loss at $410,000, an unbacked mint.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Smart Contract Bug</category><category>Flow</category><category>Lending</category></item><item><title>Ontology Mainnet Halt After Malicious Attack Activity</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0002/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0002/</guid><description>Ontology’s core development team paused mainnet block production on 31 August 2026 after what it first described as a potential security concern found during a routine check. A follow-up on 1 September confirmed it had identified malicious attack activity targeting the network. The chain resumed on 2 September, with every sync node required to upgrade to v3.1.5.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Other</category><category>Ontology</category><category>Layer 1</category></item><item><title>Injective Binary-Options Exploit and Emergency Upgrade</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0001/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0001/</guid><description>An attacker exploited Injective’s binary-options settlement and insurance-fund logic on 31 August 2026. Block production stopped for 3 hours 42 minutes while an emergency release, v1.20.3-safeharbor.1, was deployed. Injective’s official account described the incident on 1 September as an accelerated network upgrade and said the blockchain and INJ remained secure throughout. Co-founder Eric Chen said Injective users were not affected and that the team had helped with recovery.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Smart Contract Bug</category><category>Injective</category><category>Derivatives</category></item><item><title>Tectonic Oracle Manipulation and Cronos Halt</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0006/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0006/</guid><description>Cronos&apos;s post-mortem puts Tectonic&apos;s 30 August collateral-manipulation incident at approximately $120.4m in affected borrowing. A validator-coordinated rollback reversed about $111.2m; Cronos says $9.19m had left the chain before the halt and remained unrecovered. The headline figure records gross affected borrowing, before the restoration.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Oracle Manipulation</category><category>Cronos</category><category>Lending</category></item><item><title>Balancer V1 Legacy Pool Rounding Error</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0005/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0005/</guid><description>An attacker exploited a rounding error in an unmaintained legacy Balancer V1 pool on Ethereum on 30 August 2026. DefiLlama, filing it under the Balancer parent protocol, records the loss at $234,000 and classifies it as a token and share accounting rounding error.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Smart Contract Bug</category><category>Ethereum</category><category>AMM</category></item><item><title>Avici Card Contract Drain</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0007/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0007/</guid><description>On 28 August 2026, Avici, a Solana-based neobank, said its card-issuing partner Rain had identified a vulnerability in an outdated version of a Solana card contract holding user card balances. Avici puts the amount drained at $500,859.22 across 1,685 affected users, all of whom it says will be refunded in full. The contract was upgraded across all programs, no further unauthorised activity has been observed, and a report was filed with the FBI&apos;s IC3.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>Solana</category><category>Payments</category></item><item><title>Moonwell MAMO Market Exploit</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0008/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0008/</guid><description>On 27 August 2026, between 06:09:45 and 09:46:25 UTC, an attacker inflated the price of MAMO on Moonwell&apos;s Base deployment and borrowed against the inflated collateral, taking 71.36 cbBTC, 623.60 WETH, 2,560,000 USDC and 368 wstETH, $11,028,762 in all. PeckShield and CertiK put the attacker&apos;s proceeds at about $8.7m, aggregated in DAI on Ethereum; the postmortem by Anthias Labs estimates the net gain at $6,784,655 against roughly $1.947m of capital deployed, seeded from about 799 ETH, with residual bad debt of about $9.131m.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>Oracle Manipulation</category><category>Base</category><category>Borrowing</category></item><item><title>CometDEX Backstop Pool Drain</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0009/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0009/</guid><description>On 25 August 2026, an accounting bug in the Comet AMM&apos;s BLND-USDC pool on Stellar, the backstop for the Blend lending protocol, allowed same-asset swaps of USDC for USDC that corrupted the pool&apos;s reserve calculations. SlowMist logs the drain at $717,518.92. Blend&apos;s operators paused the backstop; Blend said its own contracts were not at fault and lending-pool deposits were not at risk, but backstop depositors holding Comet BLND-USDC LP shares took the loss.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>Smart Contract Bug</category><category>Stellar</category><category>AMM</category></item><item><title>Term Finance Vault Governance Takeover</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0010/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0010/</guid><description>On 23 August 2026, an attacker took governance control of Term Finance&apos;s Strategy and Meta Vaults, built on Yearn v3, and drained about 2,843 ETH plus 1.68m USDC, roughly $8.5m in all, swapping the stablecoins to DAI. The takeover cost about $951: the attacker bought 0.4852 tmvETH for roughly 0.5 ETH and staked it, and because the pre-drain staked supply was just 0.5352 gtmvETH, that stake carried about 90.66 per cent of all votes, per GoPlus Security&apos;s breakdown.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>Governance Attack</category><category>Ethereum</category><category>Lending</category></item><item><title>TAC Cosmos EVM Balance Underflow Drain</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0011/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0011/</guid><description>On 22 August 2026, TAC, a Cosmos-based EVM chain bridging the TON ecosystem, was drained of about $7.5m from a custodial account through a flaw in the shared Cosmos EVM module, and validators halted the chain at block 24,671,475. The same day KiiChain lost 148,326,583.15 KII to 18 repeats of the technique and halted at block 9,355,723, and MANTRA halted for roughly 30 hours before restarting.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>Other</category><category>TAC</category><category>Layer 1</category></item><item><title>The Sandbox OFT Bridge Mint</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0012/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0012/</guid><description>From 23:41 UTC on 21 August 2026, an attacker used a call-on-behalf convenience feature in SAND&apos;s omnichain token contract on Base to register itself as bridge administrator, reconfigured the LayerZero verification settings so it alone could authorise mints, and minted unbacked SAND on Base and BNB Smart Chain. The sums extracted were far smaller than the mint: 14,742,341.84 SAND, about $697,000, was withdrawn from the Ethereum vault, and a further 93,415,334.86 SAND was sold on Base for 327.59 WETH, for a total attacker capture of about $987,000. The Sandbox&apos;s own post-mortem puts the total economic impact at about $1,496,784, and that is the figure logged here.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>Multichain</category><category>Gaming</category></item><item><title>BounceBit Authorisation Exploit and L1 Shutdown</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0013/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0013/</guid><description>Between 21:02 UTC on 19 August and 01:54 UTC on 20 August 2026, an attacker moved 286,543,148 BB in 14 transactions from nine BounceBit mainnet accounts over four hours and 52 minutes; block production was halted at height 20,702,857 at 02:36:37 UTC, 42 minutes after the final unauthorised transfer. BounceBit&apos;s own account states no dollar figure; at market prices the sum was near $3m, and that conversion is the figure logged here. The flaw sat in the Evmos stack the BTC-restaking chain was built on: a caller could name an arbitrary account as the funding source, with no check that the account had authorised it.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>BounceBit</category><category>Restaking</category></item><item><title>Coldcard Mk3 Seed Entropy Sweep</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0014/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0014/</guid><description>On 30 July 2026, bitcoin began draining out of Coldcard-generated addresses in waves, the first taking about 594 BTC from roughly 500 wallets in 25 minutes. TRM Labs&apos; 5 August analysis puts the running total at about 1,816 BTC, roughly $116m, from more than 5,200 addresses across at least four waves, making it the largest hardware-wallet exploit of 2026 by TRM&apos;s accounting. Coinkite had disclosed the same day the draining began that a build flag set to zero in March 2021 replaced the hardware random number generator with a software fallback, cutting Mk3 seeds to roughly 40 bits of real randomness against a 128-bit target. No device was touched: the seeds were guessable.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>Private Key Compromise</category><category>Bitcoin</category><category>Wallet</category></item><item><title>Crypto DAO Vault Drain</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0015/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0015/</guid><description>On 28 July 2026, an attacker exploited missing access control on the vault behind Crypto DAO&apos;s Pro token, calling a state-changing exec() function that had been left publicly callable in a single flash-loan-assisted transaction. Per GoPlus Security&apos;s analysis, carried in SlowMist&apos;s database, the attacker&apos;s actual profit was about $52,000, with the contract losing around 167,200 Pro tokens.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>BNB Chain</category><category>DeFi</category></item><item><title>WEMIX$ Stablecoin Contract Takeover</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0016/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0016/</guid><description>On 26 July 2026 an attacker compromised ownership of a contract behind WEMIX$, the dollar stablecoin of the WEMIX gaming chain, and issued 5,225,525 tokens without authorisation. WEMIX says those were converted into 30,736 WEMIX and 724,198.27 USDC.e, which was bridged to Ethereum and BNB Smart Chain, swapped into ETH and USDT and spread across wallets, with some deposited at centralised exchanges.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>WEMIX3.0</category><category>Stablecoin</category></item><item><title>Triple-A Hot Wallet Drain</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0017/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0017/</guid><description>On 25 July 2026, wallets belonging to Triple-A, a licensed digital payments company, were drained of more than $9.7M across TRON, Ethereum, Polygon and Arbitrum. The attacker bridged the proceeds to Ethereum and consolidated about 5,227 ETH into a single address. The analyst who flagged it reported that deposits had not been disabled, so each new deposit was being taken as it arrived.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate><category>Other</category><category>Multichain</category><category>Payments</category></item><item><title>B² Network Staking Exploit</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0020/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0020/</guid><description>On 23 July 2026, B² Network, a Bitcoin layer-2, lost about $3.86M after an attacker seized the upgrade authority on its staking contract. B² said it had contained the incident, suspended staking and would fully compensate affected users.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Access Control</category><category>Bitcoin L2</category><category>Staking</category></item><item><title>Verus Ethereum Bridge Exploit (second)</title><link>https://yfarmx.com/tools/exploit-tracker/exploit-0019/</link><guid isPermaLink="true">https://yfarmx.com/tools/exploit-tracker/exploit-0019/</guid><description>On 23 July 2026, the Verus Ethereum bridge was drained of about $7.54M through the same contract flaw as its May 2026 hack. An attacker forged the cross-chain proof the bridge failed to verify and triggered unbacked payouts, taking ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>Bridge</category><category>Ethereum</category><category>Bridge</category></item></channel></rss>