SlowMist2026-10-04 01:59:40SlowMist says Goldpesa exploit caused about $114,900 in lossesSlowMist said Goldpesa was exploited, with losses estimated at about $114,900. According to the security firm, the root cause was in GPXHooks' reBalance() logic. When it performed liquidity operations through a shared PositionManager, it failed to verify whether the GPX/USDC currency delta was zero, leaving the hook's burn credit unisolated from the caller's state. SlowMist said the attacker used an unlock action together with an unsettled MINT_POSITION operation to create a negative delta, then triggered rebalance so the hook generated positive credit. Because TAKE_PAIR could only withdraw the net amount, the hook actually received only about 33,900 USDC, while the difference was offset by what SlowMist described as phantom debt. The attacker then burned their own position, canceled out the debt, and withdrew about 115,000 USDC from PoolManager.20
SlowMist2026-10-03 16:22:27SlowMist says MALT protocol was exploited through rebalance hook flaw, with about $72,000 lostSlowMist said the MALT protocol was attacked because of a flaw tied to the rebalanceHook used in its swap function, with losses estimated at about $72,000. According to the security firm, the attacker was able to put in only a very small amount of capital, trigger the protocol treasury to inject liquidity, and then withdraw a disproportionately large amount of MALT tokens. SlowMist said the issue stemmed from the way the swap(uint256,uint256,address) function recorded user input and pre-swap reserves before calling an external rebalance hook. That hook pulled DAI from a funding source and deposited it into the same liquidity pool. The swap function then checked invariants against the pool’s final balance and mistakenly treated the protocol-injected DAI as if it had been supplied by the caller. SlowMist also disclosed the attacker address, victim address, and the vulnerable contract address.20
NEAR Intents2026-10-02 14:13:10NEAR Intents exploiter sends 1 BNB to recovery wallet, says willing to cooperateOn Oct. 2, BlockBeats reported that SlowMist chief information security officer 23pds said NEAR Intents general manager Alex Shevchenko disclosed a new transfer tied to the recent exploit. According to Shevchenko, the exploiter sent 1 BNB to a recovery wallet and left a message saying they were willing to cooperate, while asking the team to provide a Signal contact. Shevchenko said the transfer came from the same address that had previously moved about $3.8 million in funds. Roughly an hour earlier, that address also sent 0.295 ETH on the Ethereum network and attached the same message. The update points to direct on-chain communication from the address linked to the exploit, based on statements cited by 23pds.20
Aave2026-10-02 09:30:49Aave founder says V3 untouched after third-party adapter exploit drains about $305,000Aave founder Stani Kulechov said Aave V3 was not affected by an exploit that drained roughly $305,000 from two Safe multisig wallets. According to Kulechov, the issue did not involve the Aave V3 core contract, but a third-party external adapter built on top of the lending protocol. Blockchain security firm SlowMist said the attacker targeted a module used to open and close leveraged Aave V3 positions through Safe wallets. The flaw was an access-control issue that let a fake Safe contract pass the adapter’s authorization check. SlowMist also said the adapter let the caller choose the router and transaction data used for swaps, which the attacker used to execute transactions through the victim wallets and remove weETH and collateral. During the attack, about 1,300 WETH in debt was repaid to unlock collateral, SlowMist said. The attacker ultimately stole around 114.09 ETH, worth about $305,000, from the two Safe multisigs. SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet, and said it found no losses to Aave V3 itself.20
Aave2026-10-02 06:31:29Stani Kulechov says FlashLoopAdapter bug did not affect Aave v3Aave founder Stani Kulechov said the contract hit by the FlashLoopAdapter exploit was not part of Aave v3, but a third-party external adapter built on top of Aave. His comment came after an incident that led to losses of about 114 ETH from two Safe multisig wallets. Earlier, SlowMist disclosed that FlashLoopAdapter had an access control flaw. According to the security firm, the attacker used the weakness to bypass permission checks and transfer assets out of two Safe multisigs that had the module enabled. The incident resulted in losses of about 114.09 ETH. The statement draws a line between the affected adapter and Aave v3 itself, with Kulechov saying the core Aave v3 protocol was not impacted by the vulnerability.20
Bitget2026-10-02 06:26:53Bitget CEO says little of $388 million hack may be recovered as protection fund is replenishedBitget CEO Gracy Chen said only about $1.1 million of the nearly $388 million stolen in last week’s hack has been frozen, and she does not expect much of the money to be recovered. Speaking on CNBC’s Squawk Box Europe, Chen said frozen funds have not yet been returned to the exchange and declined to say how much has actually been recovered. She also said user account balances were not affected. Chen said Bitget has restored its protection fund with the company’s own capital rather than passing losses on to users. The fund had been worth more than $464 million before the incident. CNBC, citing Bloomberg calculations based on the fund’s public wallet addresses, said it had briefly fallen below $200 million after the hack and has since been brought back above $300 million. A Mandiant investigation published by Bitget said attackers gained unauthorized privileged access to two third-party security devices on Sept. 24, planted a web shell on one of them, established remote control access, and later moved into a production wallet operations server. The report said there was no sign of private key theft and that cold wallets were not affected. Bitget has already resumed BTC, ETH and USDT withdrawals, with remaining tokens, fiat and P2P services scheduled to return on Oct. 2 at 08:00 UTC.20
SlowMist2026-10-02 03:06:46SlowMist flags Aave V3 Loop Safe Module flaw after about 114.09 ETH stolenSlowMist issued a security alert saying the Aave V3 Loop Safe Module contained a vulnerability that was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the alert, the attacker forged Safe authentication by using a fake Safe that always returned a true value, which let the exploit bypass the module’s verification checks. The attacker then abused arbitrary module execution through a controllable router and calldata to carry out module transactions. During the attack, weETH and Aave collateral were moved out of the affected wallets. SlowMist also said the attacker repaid about 1,300 WETH in debt, which unlocked the collateral before the assets were transferred. The alert focuses on the exploit path and the mechanics of the theft, without providing additional details on recovery or mitigation in the cited notice.20
SlowMist2026-10-02 03:06:33SlowMist says Aave V3 Loop Safe Module flaw led to theft of about 114.09 ETH from two Safe multisig walletsSlowMist issued a security alert saying a vulnerability in the Aave V3 Loop Safe Module was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the security firm, the attacker forged Safe authentication and then abused arbitrary Module execution to move funds. The exploit path involved a fake Safe that always returned a true value, which allowed the attacker to bypass verification checks. SlowMist said the attacker also used a router and calldata that could be controlled arbitrarily to execute module transactions, transferring weETH and Aave collateral out of the affected wallets. After that, the attacker repaid about 1,300 WETH in debt, which unlocked the collateral. The alert identifies the affected component as the Aave V3 Loop Safe Module and ties the loss to two Safe multisig wallets.20