SlowMist2026-09-22 09:03:30SlowMist says DoinGud contract flaw let attacker replay transactions and net about 35,380 USDCSlowMist disclosed a logic flaw in a DoinGud smart contract that allowed an attacker to replay the same transaction data and withdraw funds multiple times. The issue was tied to the contract’s acceptOffer function, where the security firm said protections against duplicate transactions were missing and required state-cleanup checks were not in place. According to the disclosure, the attacker used two replayed transactions to drain all 70,973.871434 USDC held in the contract’s escrow account, ending with a profit of about 35,380 USDC. SlowMist also said the attack was funded with a flash loan, and that the attacker supplied neither any NFT nor any principal of their own. The vulnerable contract address was identified as 0x123aafc8d0a07ce1a146e53aa899e77f21a2dde1, while the attacker address was listed as 0xb8c717239bcace558c3a8dc471c16e07bf57a1eb. The disclosure was cited by Techub News and attributed to @SlowMist_Team.420
SlowMist2026-09-11 07:53:52SlowMist says BeatXswap on BSC lost about $77,500 in price manipulation attackBeatXswap, a project on BNB Smart Chain (BSC), was hit by a price manipulation attack that led to a loss of about 2.985 million BTX, or roughly $77,500, according to SlowMist. The security firm said the attacker borrowed 6 million BTX through a flash loan and sold the tokens into a Uniswap V3 pool to push the quoted price lower. The attacker then exploited a contract design flaw in which the protocol relied solely on the pool’s spot price as its pricing source. SlowMist said the contract had no time-weighted average price, or TWAP, protection, and no deviation limit. After moving the price, the attacker deposited USDT in two separate transactions, which triggered liquidity minting and allowed BTX to be withdrawn from the LP position. The incident adds to the list of attacks tied to spot-price oracle weaknesses and missing guardrails in on-chain pricing logic.860
BeatXswap2026-09-11 05:12:50BeatXswap contract hit by oracle manipulation attack, losing about $63,700Defimon Alerts said a BeatXswap-related contract on BNB Chain was exploited in an oracle manipulation attack on Sept. 9, with losses estimated at about $63,700. The affected contract, LiquidityVestingConvert, reportedly pulled live pricing directly from a PancakeSwap V3 pool and did not include protections such as time-weighted pricing. According to the alert, the attacker used a flash loan to push down the pool price and then called the deposit function, allowing the contract to inject roughly 3.07 million of the attacker’s own BTX into a liquidity position at a distorted valuation. The attacker then reversed the trade and made about 63,700 USDT in profit. Defimon Alerts added that BTX in two attributed pools was drained in the process.860
Secured Finan2026-09-07 07:22:51Secured Finance Lending Market Hit by Hack, Loses ~$104KDecentralized lending protocol Secured Finance suffered an attack on September 5, losing approximately $104,000. The exploit exploited a collateral pricing flaw, using self-trading and flash loans to manipulate prices and drain USDC. The initial attack failed due to insufficient gas fees; about 48 seconds later, the front-running bot coffeebabe seized ~0.9 WBTC (~$72,000), transferring part of the ETH to the ultra sound money builder.840
Secured Finan2026-09-07 07:15:18Secured Finance hit in exploit with about $104,000 lost as bots intercept part of fundsDecentralized lending protocol Secured Finance was exploited on Sept. 5, with losses of about $104,000, according to monitoring account Defimon Alerts. The issue stemmed from how collateral was priced: the protocol used the average execution price of the order book within the current block, which allowed an attacker to manipulate that reference through self-trading and have fake borrowing positions recognized as valid collateral. Defimon Alerts said the attacker deployed a contract first but did not execute right away. The exploit was carried out later using a flash loan and self-trading to push up the valuation before withdrawing USDC. The original attack wallet then failed to complete its first attempt because the transaction reverted due to insufficient gas. Roughly 48 seconds later, a general-purpose frontrunning bot identified as coffeebabe captured about 0.9 WBTC, worth around $72,000 based on the figures cited in the alert. It then sent about 28.8 ETH to the builder of ultra sound money and kept only about $29 for itself. After that, another bot withdrew part of the remaining USDC.830
SlowMist2026-08-23 11:16:24SlowMist details Allbridge exploit involving forged CCTP-style message and flash loanSlowMist said cross-chain bridge project Allbridge was exploited on Aug. 19, 2026, with losses of about $190,000. The security firm said the attack was prepared weeks in advance rather than executed in a single move. According to its analysis, the attacker first called Circle’s MessageTransmitterV2.sendMessage on Polygon on July 26 to craft a message that looked like a CCTP transfer for 1 million USDC, even though no USDC burn ever took place. Circle then issued a valid attestation for that complete message under its normal process. Roughly 24 days later, after the Base Router received a real CCTP deposit and its balance rose to about 191,000 USDC, the attacker moved within six seconds. Using the forged message and attestation, the attacker called Allbridge’s receiveCctpMessage function. SlowMist said missing checks caused the protocol to treat the fake cross-chain message as a real deposit and book a 1 million USDC credit. The attacker then borrowed about 809,000 USDC through an Aave flash loan, matched the Router balance to the forged amount, and used the internal credit record to transfer out about 999,000 USDC after a 0.1% fee. After repaying the flash loan and fees, net profit was about $189,800.1100
Atomic Protoc2026-08-08 10:56:55Atomic Protocol Loses ~29,984 USDC in Signature Replay AttackChainCatcher has relayed a monitoring update from SlowMist, a blockchain security firm, stating that Atomic Protocol, a decentralized exchange, was attacked due to a signature replay vulnerability. The attack resulted in a loss of approximately 29,984 USDC. The vulnerability is attributed to contract 0xa806010f, where the signature digest does not bind the position ID, the position manager, the caller, the nonce, the deadline, and the chain ID. Due to this oversight, a single manager signature can be replayed across as many as 21 different position identifiers. The attacker combined this flaw with flash loan price manipulation to perform an unauthorized full destruction of LP tokens. Furthermore, the contract lacks TWAP (time-weighted average price) and slippage checks, meaning the protocol had no built-in mechanism to counteract manipulated prices during the transaction. The incident was reported by SlowMist and brought to public attention via ChainCatcher.1800
WEMIX2026-07-30 10:53:00WEMIX says public smart contract flaw, not key leak, caused WEMIX$ security incidentWEMIX has released a fresh update on the WEMIX$ security incident, saying the breach stemmed from a vulnerability in publicly visible on-chain smart contracts rather than an intrusion into internal systems or a leak of administrator private keys. According to the company, ownership of two contracts, DIOS and AMA, was transferred to an unauthorized third party on July 26. DIOS is designed to help maintain WEMIX$ price stability, while AMA supports 1:1 exchanges between WEMIX$ and collateral assets. WEMIX said the attacker deployed a malicious contract in a single transaction, took control of both contracts, and then carried out nine rounds of flash loans and swap transactions. The result was the unauthorized minting of 5,225,524.9997 WEMIX$. The attacker then moved roughly 723,244 USDC.e and 34,752 WEMIX. WEMIX said transactions involving game tokens linked to WEMIX$ are still under review, and more details will be shared once the scope of impact and compensation amount are confirmed. The team has revoked WEMIX$ minting authority, identified the attacker’s address, asked exchanges that received the funds to blacklist it, and filed a formal report with law enforcement. Earlier reports said the funds had been bridged to Ethereum and BSC.1860