SlowMist2026-10-04 01:59:40SlowMist says Goldpesa exploit caused about $114,900 in lossesSlowMist said Goldpesa was exploited, with losses estimated at about $114,900. According to the security firm, the root cause was in GPXHooks' reBalance() logic. When it performed liquidity operations through a shared PositionManager, it failed to verify whether the GPX/USDC currency delta was zero, leaving the hook's burn credit unisolated from the caller's state. SlowMist said the attacker used an unlock action together with an unsettled MINT_POSITION operation to create a negative delta, then triggered rebalance so the hook generated positive credit. Because TAKE_PAIR could only withdraw the net amount, the hook actually received only about 33,900 USDC, while the difference was offset by what SlowMist described as phantom debt. The attacker then burned their own position, canceled out the debt, and withdrew about 115,000 USDC from PoolManager.20
NEAR Intents2026-10-03 11:59:10NEAR Intents recovers full $3.8 million after 48-hour ultimatum to exploiterNEAR Intents said it has recovered the roughly $3.8 million stolen in a Thursday security breach after identifying the exploiter and giving them 48 hours to return the funds under a "responsible disclosure" process. Later on Friday, general manager Alex Shevchenko said the money had been returned in full and that the investigation would stop. The project had previously paused services after finding what it described as a bug involving the Omni deposit and withdrawal infrastructure’s interaction with the NEAR Intents smart contract. NEAR’s preliminary review said $3.8 million in user funds had been taken and that affected users would be made whole. Blockchain investigator ZachXBT also said the stolen funds were moved to KuCoin and bridged to Bitcoin.20
Drift2026-10-02 09:41:30Drift opens DFX claims and redemptions for users hit by more than $290 million exploit lossDrift Foundation has opened claims and redemptions for DFX, a Solana-based recovery token created for users who lost funds in the perpetuals exchange’s April 1 exploit. Under the process, each 1 USDT in verified losses gives a wallet 1 DFX. Based on Drift’s current figures, each token redeems for about 0.0104 USDT, which works out to roughly one cent back for every dollar lost so far. The rate is tied to the Recovery Pool balance, which launched at about 3.1 million USDT, divided by the roughly 299.5 million DFX outstanding. Drift said in a Sept. 30 update that more than $290 million was taken from users, and that forensic firm Mandiant identified the attacker as a North Korean group. The pool is designed to grow through revenue sharing from Velocity, the rebuilt exchange rebranded in July, plus pledged support from Tether and strategic partners, and any stolen funds later recovered or frozen.40
NEAR Intents2026-10-02 14:13:10NEAR Intents exploiter sends 1 BNB to recovery wallet, says willing to cooperateOn Oct. 2, BlockBeats reported that SlowMist chief information security officer 23pds said NEAR Intents general manager Alex Shevchenko disclosed a new transfer tied to the recent exploit. According to Shevchenko, the exploiter sent 1 BNB to a recovery wallet and left a message saying they were willing to cooperate, while asking the team to provide a Signal contact. Shevchenko said the transfer came from the same address that had previously moved about $3.8 million in funds. Roughly an hour earlier, that address also sent 0.295 ETH on the Ethereum network and attached the same message. The update points to direct on-chain communication from the address linked to the exploit, based on statements cited by 23pds.20
NEAR2026-10-02 07:00:00NEAR Intents loses about $3.8 million in exploit while NEAR mainnet remains unaffectedNEAR ecosystem protocol NEAR Intents was hit by an exploit on Oct. 1, with roughly $3.8 million drained from its underlying treasury. The incident triggered a sharp intraday drop in NEAR, which briefly fell from around $5.5 to about $4.74, according to the source article. NEAR founder Illia said the issue affected NEAR Intents, a cross-chain intents protocol built on NEAR, rather than the NEAR Layer 1 consensus layer, and that the core protocol and native token security were not compromised. The report said the attacker exploited a logic flaw in the interaction between Omni deposit-and-withdrawal infrastructure and NEAR Intents contracts. The attack was limited to a USDT pool on BNB Chain, where about 3.87 million USDT was withdrawn and then moved to exchanges and swapped into Bitcoin. The team said it identified the vulnerability and deployed a hotfix within one hour, while suspending deposit and withdrawal functions across 11 networks tied to the Omni fix for about 12 hours. It also said affected users would be reimbursed in full. The article also highlighted the contrast with an earlier case in which NEAR Intents’ SHIELD monitoring layer detected and blocked most attempts to move more than $50 million in illicit funds linked to the Bitget hack.20
Aave2026-10-02 09:30:49Aave founder says V3 untouched after third-party adapter exploit drains about $305,000Aave founder Stani Kulechov said Aave V3 was not affected by an exploit that drained roughly $305,000 from two Safe multisig wallets. According to Kulechov, the issue did not involve the Aave V3 core contract, but a third-party external adapter built on top of the lending protocol. Blockchain security firm SlowMist said the attacker targeted a module used to open and close leveraged Aave V3 positions through Safe wallets. The flaw was an access-control issue that let a fake Safe contract pass the adapter’s authorization check. SlowMist also said the adapter let the caller choose the router and transaction data used for swaps, which the attacker used to execute transactions through the victim wallets and remove weETH and collateral. During the attack, about 1,300 WETH in debt was repaid to unlock collateral, SlowMist said. The attacker ultimately stole around 114.09 ETH, worth about $305,000, from the two Safe multisigs. SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet, and said it found no losses to Aave V3 itself.20
Aave2026-10-02 06:31:29Stani Kulechov says FlashLoopAdapter bug did not affect Aave v3Aave founder Stani Kulechov said the contract hit by the FlashLoopAdapter exploit was not part of Aave v3, but a third-party external adapter built on top of Aave. His comment came after an incident that led to losses of about 114 ETH from two Safe multisig wallets. Earlier, SlowMist disclosed that FlashLoopAdapter had an access control flaw. According to the security firm, the attacker used the weakness to bypass permission checks and transfer assets out of two Safe multisigs that had the module enabled. The incident resulted in losses of about 114.09 ETH. The statement draws a line between the affected adapter and Aave v3 itself, with Kulechov saying the core Aave v3 protocol was not impacted by the vulnerability.20
Aave2026-10-02 06:25:00Aave founder says third-party adapter was affected, not Aave v3 contractsAave founder Stani Kulechov said the incident flagged in a SlowMist report did not involve an attack on Aave v3 contracts themselves. The issue, he said, was tied to a third-party external adapter built on top of Aave v3, and had no impact on the core Aave v3 protocol. The response came after reports that a Safe module used in an Aave v3 looping strategy was exploited, leading to losses of about 114.09 ETH, or roughly $310,000. Earlier reporting cited an access control flaw in FlashLoopAdapter’s open() and close() functions. According to that account, the attacker forged Safe authorization and executed arbitrary modules, stealing around 114.09 ETH from two Safe multisig addresses. The attacker also repaid about 1,300 WETH in debt to unlock collateral.20