News

Global security awareness — not only PulseChain.

Industry incidents in plain English. Shareable cards that link back here. Not an audit.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highBSCdefi

CryptoDAO Pro (BSC): Blockaid flags ongoing Pro-token exploit

Developing (28 Jul 2026 ~16:23 UTC): Blockaid reported an ongoing exploit on CryptoDAOGlobal’s Pro token on BNB Smart Chain and said ~$8.2M USDT sat with the exploiter plus three “winning” wallets at alert time. Token 0x8d657445…df0e2 (Pro Token); exploiter 0x427671b2…F45D; example tx hits Pancake Pro/USDT and Pro/CDAO pools. Our ~1h spot-check found only ~$1.0M USDT still on those four EOAs (BSC+ETH) — bags already moving, so treat $8.2M as the alert-time headline, not a final loss. Owner looks renounced; root cause not confirmed. No Pulse footprint. Do not ape into “recovery” DMs.

369 take: Renounced ERC20 + audit sticker ≠ safe if pool/prize/related mechanics can still yank USDT. Pulse lesson: high-hype “DAO/Pro” branding does not replace reading where liquidity actually sits. Not a Pulse deep — cross-chain awareness only.

mediumSupraoracle

Solido Cash (Supra): oracle misassignment — CASH mint / SUPRA out

23 Jul 2026 (verified chase 28 Jul): Solido Cash on Supra (Move) was hit via an oracle misassignment that valued collateral near ~$1 while market was a fraction of that. Attacker minted CASH against the bad price, sold for SUPRA. Solido forensic (via AMBCrypto 27 Jul): two waves — one atomic, then five wallets — minted ~809k CASH and ~293.7M SUPRA net proceeds; ~84% traced to CEX infrastructure; containment disabled the mint path. DeFiLlama hacks table lists ~$73.4k USD (Protocol Logic / Oracle Misconfiguration). Grok daily’s ~$900k figure is overstated vs Llama — prefer forensic token totals + Llama USD. Distinct from Bonzo Lend / Supra Hedera ~$9M (11 Jul) zero-signature verifier bug.

369 take: Oracle config / assignment errors print money the same way bad feeds do. Pulse CDP/lending lesson: wrong collateral mark + weak mint caps = loaded gun. Do not merge with the separate Supra-on-Hedera verifier bug that hit Bonzo.

highMulti-chainbridge

GardenFi: ~$450k USDT — HTLC alert, then solver off-chain DB clarification

Developing (26–27 Jul 2026): Blockaid flagged an exploit on @gardenfi HTLC rails — ~$450k USDT across Ethereum, Base, Arbitrum, and BSC. Exploiter EOA 0x25b224c05f6cc5e132165c1621de1a4c3b316999 (~$425k / ~20 txs at alert). Update (26 Jul 18:10 UTC): Garden posted that they identified unusual activity, took the app offline for a full investigation, and will share more when they have it. App shows “Garden Maintenance / under maintenance.” No official loss figure or root-cause post yet; blog has no incident article. Not the Oct 2025 ~$11M+ solver compromise — do not merge the two. Updated (28 Jul 2026): Garden told Cointelegraph (story revised 27 Jul 02:16 UTC) that protocol + HTLC contracts were not compromised; an independent solver’s off-chain database was breached and fraudulent swap records inserted, causing that solver to release funds for unbacked swaps. Team line: solver-owned assets only, no user funds at risk; still confirming totals; working with zeroShadow, Quantstamp, Blockaid. Keep Oct 2025 ~$11M+ solver-environment hit as a separate incident.

369 take: Original Blockaid HTLC drain alert still stands as the on-chain symptom. Garden’s later line shifts root cause to an independent solver’s off-chain DB — still a fund-release path you have to trust. Pulse/ramp lesson: treat every off-chain solver/keeper/DB that can trigger release as adversarial, even when “core contracts are fine.” Not the Oct 2025 hit.

highWEMIXadmin

WEMIX: ~$724k via linked WEMIX$ contract ownership — bridges paused

26 Jul 2026: WEMIX said ownership of a contract linked to its WEMIX$ stablecoin path was compromised. Attacker unauthorized-issued ~5.23M WEMIX$, swapped into ~30.7k WEMIX + ~724k USDC.e, then bridged proceeds toward Ethereum and BNB. Team suspended WEMIX3.0 bridges (incl. CCIP / PLAY), affected LPs, and related modules. Preliminary figures may change; bridge itself was not framed as the entry — the linked / ownership surface was.

369 take: Classic peripheral gun: a non-core Ownable that can still mint or authorize issuance. Pulse lesson for stables / migrations — inventory every linked contract with mint or owner powers, not just the “main” bridge. Not a Pulse deep; pattern card only.

highUser surfacephishing

Google Ads phishing: fake Hyperliquid is not a protocol hack

We reviewed a 24 Jul X amplification (@CryptocapoOO) claiming Hyperliquid was being “hacked” via Google: search the brand → top Sponsored result → clone site → connect wallet → funds gone, “hundreds” emptied. Our check: the Google Ads → pixel-clone → approve/permit drain pattern is real and well documented for Hyperliquid (and Uniswap/Aave/Jupiter-class brands) across 2025–2026, with brand-impersonation domains still flagged in Jul 2026. Framing it as an Hyperliquid L1/app exploit is wrong — users are phished; contracts are not the breach. “Hundreds emptied this week” stays unverified without a firm address table. Official app to bookmark only: app.hyperliquid.xyz — never open from Sponsored results.

369 take: Sponsored search is not the official site. Same gun hits Pulse dApps and wallets — bookmark the canonical URL, ignore ads, and read every approval. If you already connected a fake front end, revoke allowances and move funds from a clean bookmark only. This is phishing, not “the protocol got hacked.”

highMulti-chaincustody

Triple-A / TripleH hot wallets: ~5,228 ETH sitting in consolidation EOA

Specter flagged multi-chain hot-wallet drains linked to @TripleH / @TripleAHQ (Triple-A payment rails). He reported >$9.3M drained/swapped/bridged to Ethereum. We independently confirmed the listed consolidation address 0x01F83B5d…253b1 holds ~5,228 ETH (~$9.72M) with no outbound sends — matching the ~5,227 ETH headline. Other listed ETH addrs are empty now. TRON/Solana addresses are listed but not re-balanced here. Update (26–27 Jul): Desk reporting (The Block via Specter) revised the multi-chain sweep toward ~$11.8M as new deposits kept landing in compromised wallets; some trackers say ~$12M. We still do not invent a 369 dollar total beyond investigator ranges. Team said they are investigating and that customer funds are not impacted — formal map still thin. Consolidation ETH bag thesis for the listed EOA unchanged pending a full address table.

369 take: Payment-gateway hot wallets are custodial: you send to their address. If those keys move, many checkouts die together. Self-custody seedless wallets are a different product. Until the team freezes deposits and publishes a full map, treat Triple-A / TripleH deposit addresses as high risk.

highUser devicesmalware

WARDEN stealer advertised: crypto extensions + clipboard address swap

Kraken Security Labs flagged a new underground offer: WARDEN (actor WardenStealer) — a Windows x64 stealer, clipper, and loader sold with a control panel (~$349/mo). Seller claims include Chromium/Gecko credential theft, 200+ cryptocurrency browser extensions, clipboard replacement of BTC/ETH addresses, App-Bound Encryption bypass, and secondary payload delivery. Kraken notes these are threat-actor marketing claims and have not been independently verified.

369 take: Extension wallets are the advertised target. Treat unknown Windows installs and “free crack” tools as hostile. Seedless / hardware-unlock wallets raise the bar against seed dump, but clippers still hit any pasted receive address — verify last characters before you send. Never download “samples” from underground ads.

highEthereumdefi

Lien Finance BondMaker: ~$542k USDC via bond equivalence logic

SlowMist reported ~542k USDC lost after attackers abused Lien’s bond exchange path. We verified live BondMakerCollateralizedEth contracts on Ethereum expose exchangeEquivalentBonds(exceptionBonds[]) and permissionless registerNewBondGroup — matching both the multiset-validation and open-registration narratives. Victim address still holds residual USDC after the event. Same BondMaker family as the 2020 white-hat save; this time funds left.

369 take: Open bond/ticket registration plus soft equivalence or OTC pricing is a loaded gun. Before you LP into structured “bond” pools, ask whether anyone can mint paper the pool will buy without hard collateral checks.

criticalArbitrumbridge

AFX deposit bridge drained ~$24M USDC on Arbitrum

A third-party deposit rail for the AFX perp DEX was emptied of about 24.15 million USDC. Arbitrum’s own native bridge was not hit. Offchain Labs confirmed the bad transaction targeted AFX’s contract, not chain infrastructure.

369 take: “On Arbitrum” often means a custom deposit bridge, not the canonical bridge. Short dispute windows and hot-validator-signed withdrawals are a full trust surface — treat them like mint authority before you deposit.

highUser devicesmalware

OkoBot malware: fake hardware-wallet recovery screens steal seeds

Kaspersky researchers detailed OkoBot, a modular malware platform. Its SeedHunter module detects popular hardware-wallet software and shows fake recovery screens to harvest seed phrases. Delivery often uses social-engineering “fix this error” prompts and trojanized installers.

369 take: Never type a seed phrase into any on-screen prompt — not even one that looks like Ledger or Trezor. Hardware recovery stays offline. Seedless wallets remove that Notes/Keychain target, but malware can still abuse unlocked sessions — keep devices clean and ignore “run this command” fixes.