CertiK Skynet Rating Profile picture
Skynet by @CertiK delivers Web3's most comprehensive security scores for 10,000 projects. Follow us here too ⬇️ 🕵 @CertiK 🚨 @CertiKAlert
2 subscribers
Feb 22, 2022 10 tweets 4 min read
#CommunityAlert 🚨

@FlurryFi’s Vault contracts were attacked leading to around $293K worth of assets being stolen from Vault contracts

Incident Analysis 👇 The attacker deployed a malicious token contract, which is also used as the attack contract, and created a PancakeSwap pair for the token and $BUSD.

Attacker: bscscan.com/address/0x0f3c…

Malicious token contract: bscscan.com/address/0xb7a7…

PancakeSwap pair: bscscan.com/address/0xca95…
Feb 5, 2022 5 tweets 3 min read
#CommunityAlert🚨

@Meter_IO's Bridge, Meter Passport, has been exploited

Please be cautious if interacting! $MTRG

More info/Analysis coming soon #IncidentAnalysis

1. The attacker address:
etherscan.io/address/0x8d3d…

$4.3M in funds were moved to Tornado Cash including 1400 ETH (~$4.2M) and 2 WBTC (~$83k)

One of the exploited tx’s👇
bscscan.com/tx/0xc4d7e160c…
Jan 28, 2022 6 tweets 4 min read
#CommunityAlert 🚨

@QubitFin's bridge contract, QBridge, has experience an exploit and minted 77,162 $qXETH worth $80M

QBridge contract on #ETH 👇
etherscan.io/address/0x9930…

Use caution if interacting!

Incident Analysis coming soon @QubitFin Incident Analysis

The hacker called `deposit()` in the QBridge #eth contract w/o really making any deposit and emitted the Deposit event

The exploit was caused by `tokenAddress.safeTransferFrom` in QBridgeHandler.sol which didn't revert the tx when the tokenAddress is the 0x0.
Jan 4, 2022 5 tweets 4 min read
#CommunityAlert 🚨

#Arbix Finance has been identified as #rugpull. Privileged functionalities appear in the identified smart contracts.

The team is looking into it.

DO NOT interact with the project! Incident Analysis👇

1. $ARBX contract has mint() with onlyOwner function

2. 10M $ARBX were minted to 8 addresses

3. ~4.5M ARBX were minted to: 0x161262d172699cf0a5e09b6cdfa5fee7f32c183d

4. The 4.5M ARBX were then dumped