TGViewer
Channel Public Channel
Defimon Alerts

Defimon Alerts

@defimon_alerts

⚠️ DeFi security alerts by @DecurityHQ
💎 Instant alerts @defimon_subscription_bot
defimon.xyz
Subscribers
4.65K
Photos
180
Videos
1
Links
2.7K
Recent Posts 20 shown
Post #3319 658

Forwarded from Defimon Signals

🚨 rarible.com (RARI Foundation DAO) - Attempted governance takeover (2026-09-20)

Token: $RARI @ $0.1066
Network: Ethereum

Type: Access Control (malicious governance proposal / DAO takeover)

Attacker "Falcon" (0x94223fcC…F04Ca, ~132.5K veRARI votes, above the 5,000 proposalThreshold) submitted proposal 3648869205…835338 to RariGovernor (0x859e1c00…2edca). The single action calls the DAO's delegatecall-executor 0xb23BCD4F…C5b5 with execute(0x36224b869…a722, write(slot,1)). Contract 0x36224 is a 4-line backdoor whose only function e2e52ec1 (write(uint256,uint256)) does a raw SSTORE; invoked via the executor's DELEGATECALL it writes 1 into an AccessControl role slot of the executor — granting Falcon a privileged role and full control of the DAO. The proposal text openly states YES "grants full control of the DAO to the activist investor group Falcon." No funds moved yet (vote open); execution would hand the DAO/treasury to the proposer.

TX: https://etherscan.io/tx/0xeaef75813cd1d89d681669b687d838a0e3e16b1cd4292c566e411697759763fa
Attacker: https://etherscan.io/address/0x94223fcC4705CF0EBcE95d79072616A2A74F04Ca
Victim: https://etherscan.io/address/0x859e1c00ed6d4b4e649c7a38918e982653b2edca
X: https://x.com/rarible

@defimon_subscription_bot
  • 😱 3
  • ❤ 1
Post #3318 745

Forwarded from Defimon Signals

🚨 theinternettoken.com - Loss ~764M INT + 5.85 WETH (2026-09-21)

Token: $INT @ $0.000328
Network: Base

Type: Access Control / Logic Error (arbitrary mint via unvalidated pool callback)

The INT LiquidityUnifier (0x837dbabc…2032), which holds the reward token's MINTER_ROLE, exposes swapV3(token, pool) that accepts an attacker-supplied pool. Validation only checks the pool has code and that its token0()/token1() equal INT. The attacker deployed a fake "pool" returning INT for both tokens; swapV3 calls pool.swap(), which re-enters uniswapV3SwapCallback and mints an attacker-chosen amount to currentPoolV3. Using a Convertor round-trip to defeat the validateSupply check, the attacker freely minted ~925M INT, dumped part into the real INT/WETH Uniswap V3 pool for 5.85 WETH and walked away with ~764M INT + 5.85 WETH.

TX: https://basescan.org/tx/0xed62bb27bd1058d3d7cc93d55421d6d0001ced8cb4529b02773f5126a4edb08b
Attacker: https://basescan.org/address/0x5f7ce6395818857ac20730dc990f614356d1ec68
Victim: https://basescan.org/address/0x837dbabc4f5fa78baf177597edbda09645822032
X: https://x.com/internet_token

@defimon_subscription_bot
  • 👍 2
Post #3317 746
💌 Onchain message:

To the recipient of my 2.07 ETH:

I am writing these words from the bottom of my heart, not out of anger, but out of pure, overwhelming desperation. I am currently unemployed and going through the darkest and most difficult chapter of my life.

That 2.07 ETH was never speculative money — it was my entire family's life savings, meant to put food on our table and help us survive through this devastating economic crisis.

I understand the nature of the crypto world and I do not expect you to walk away empty-handed. I sincerely and willingly offer you 0.5 ETH as a bounty and token of appreciation.

Please return the remaining ~1.57 ETH to my safe address:
0xF90367a5F4D24E720D5b810AA0AD5E35Cc70968c

I promise to consider this matter completely resolved and hold no grievance. Behind our computer screens, we are all human beings with families to care for. I truly pray that you understand my family's desperate situation and show mercy. Thank you.


📤 From: 0xf90367a5f4d24e720d5b810aa0ad5e35cc70968c
📥 To: 0xd7c2aa10758f62b40a6df1757f59e15c8a47bf26
🌎 Network: mainnet

Etherscan
  • 😢 5
  • 🕊 1
  • 🌭 1
Post #3316 718
💌 Onchain message:

Unauthorized token drain. 6,731.96 USDC taken from 0xD427aBC74a276005ed3043Fa7243FfAa96b887a6 on Base without my signature.

Drain: https://basescan.org/tx/0x19ab00603f485a1e807e18511b0f31a73058c4c3b86f865ab49d972c717ba294
Your inbound: https://etherscan.io/tx/0x8e5c262649f407ae97c83508087ed73e8a4deacdef4ec8ec9171e93c0385ffdb

Please return 2.574902 ETH on Ethereum to 0xD427aBC74a276005ed3043Fa7243FfAa96b887a6


📤 From: 0xd427abc74a276005ed3043fa7243ffaa96b887a6
📥 To: 0x20effa2eb532dd0e60ddab45c14344c474703b29
🌎 Network: mainnet

Etherscan
Post #3314 800
💌 Onchain message:

G'day mate

To the address that exploited the RISEx XLP Vault on the 3rd of August: we see the funds started moving today. Before this goes any further, we are improving our offer.

Keep 20% (134,566 USDC). Return the remaining 80% (538,265 USDC, or the equivalent in ETH) to 0x83047f3D7Ed7998D841C8F364897b74C4a3273C5 on Ethereum or Base. If you do so before 12pm AEST on Wednesday 23 September, we treat this as a whitehat disclosure.


📤 From: 0x52513d80a424138118ee0a6e8331289d62c5533f
📥 To: 0x8e7f31665213d38d0c74291197523cbdf811b33a
🌎 Network: mainnet

Etherscan
  • 👍 2
  • 🥰 2
  • 👏 2
  • 🤣 1
Post #3313 799
💌 Onchain message:

hello goodday
this seems to be 0xcccc640018f8c2b00fa45F56017AD2378Eb3447 wallet, i couldn't send an idm to your main address so i had to send it here

You recently drained the Arche arUSD vault on 13th of june and i was unfortunately one of the victims lossing about $1,132
I am an just an individual user, not a whale or a protocol .
These funds represent a huge portion of my life savings, and losing them completely devastates my family and livelihood.

I am begging you to show mercy and return the funds to my adress 0x6b9E250f1cB14a78F0870b0b35A42507adF6A082 .
Keep a portion as a lesson fee if you must, but please give me back the ability to recover from this.
The shady team have since ran away witout reimbursing us as promised

Thank you for reading this. Please help


📤 From: 0x6b9e250f1cb14a78f0870b0b35a42507adf6a082
📥 To: 0xddddd01e33c4dcf91bb0bddda40788dfacd52c24
🌎 Network: mainnet

Etherscan
  • 🤣 2
  • 👍 1
  • 😐 1
Post #3312 754
💌 Onchain message:

You received assets stolen from my compromised wallets.

The relevant transactions, addresses, malware sample, and evidence have been preserved.

We have identified the MEXC account associated with the receiving address, and MEXC has already placed a temporary freeze on that account.

Return the stolen assets to the original addresses.

If you cooperate and return the funds, this can still be resolved directly. Otherwise, I will continue pursuing recovery through MEXC and the relevant investigation channels.


📤 From: 0x4214d8e81e81b6fd776cc0db0a7e0c835c77dcde
📥 To: 0x502a006bb8f7a39c1d23302720542e3033779c13
🌎 Network: mainnet

Etherscan
  • 🤣 1
Post #3310 786
🚨 Nimiq.com exploited for $50.4K on Polygon (Sep 16, 2026)

Nimiq's swap contracts serve as both the OpenGSN paymaster and the forwarder. Their execute() checks never verifies the user's signature. It relies on the contract's own preRelayedCall to do that. OpenGSN's RelayHub lets any relay choose any paymaster and forwarder.

Exploit contract was detected by Defimon 19 minutes before the attack. The attacker staked 1 POL, registered their EIP-7702 EOA as the relay manager, worker and paymaster (an accept-everything paymaster), and set forwarder = the HTLC handlers. Signature checks were skipped, so forged open() requests "from" a swap-liquidity wallet with unlimited approvals to the handlers opened HTLCs for its entire USDC, USDT0 and USDC.e balance. Each HTLC named the attacker's precomputed CREATE2 contract as recipient and used hashlock sha256(0x01). The exploit tx deploys that contract and redeems all three HTLCs with secret 0x01. About $50.4K was taken and consolidated as USDC.

TX: https://polygonscan.com/tx/0xb2ca76dfbfe571742b4b66465b777ab1e06988a8632be1631bef9654cc64d169
Setup TX: https://polygonscan.com/tx/0xb067efae73637f3564f58af7f6027afc497e81e47624b0048636085c678858c0
Attacker: https://polygonscan.com/address/0x2258491525c21f334c5a2dc22ce55e55023fc45d
Victim: https://polygonscan.com/address/0x0cfd862be942846cebad797d7c1bc6e47714959b
Victim: https://polygonscan.com/address/0xf615bd7ea00c4cc7f39faad0895db5f40891359f
Drained wallet: https://polygonscan.com/address/0x24cb173ae221aea93369f34bdcf0ddb35b436773
X: https://x.com/nimiq

@defimon_subscription_bot
  • ❤ 3
  • 🤣 1
Post #3309 847
Defimon Alerts 💌 Onchain message: PRIMEFI RECOVERY REQUEST | Incident tx: 0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243 | Please return 318.961630241143730359 HYPE (80% of the 398.702037801429662948 HYPE proceeds) to: | 0xF2e2A49631927108086268c68C559c63c3C8f73d…
🚨 Primefi.xyz - Loss ~$33.4K (2026-09-16)

Network: HyperEVM

Type: Oracle Manipulation

Prime's PRFI price feed is exploitable. DataStreamConsumer.verifyReport() is permissionless and, after checking the Chainlink Data Streams signature, blindly overwrites the stored price for a feedId with no check that the report is newer/fresher than the one already stored.

The attacker pushed a favorable signed PRFI report, inflating PRFI's oracle price to ~$0.11 (vs ~$0.0021 real, ~52x). Using a Morpho flash loan they bought PRFI cheaply from the thin WHYPE/PRFI pool, deposited it as over-valued collateral into the lending pool, and borrowed ~425.5 WHYPE (~$33.4K) far exceeding the collateral's true value, draining the WHYPE reserve.

TX: https://hyperevmscan.io/tx/0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243
Attacker: https://hyperevmscan.io/address/0x19bc1c7fd4aa93f540498499b8f5b4fc3dde5a52
Victim: https://hyperevmscan.io/address/0xb339448e13e273f6f46e3390e0932ab7ff9f113f

⚡️ Detected by Defimon at 12:37:37 UTC
⏱️ Real-time alerts: @defimon_subscription_bot
  • 🦄 5
  • ❤ 1
  • 😁 1
Post #3308 777
💌 Onchain message:

PRIMEFI RECOVERY REQUEST | Incident tx: 0xff990876d863a61732779c341991215856c89420b84daaf31eece7ecd5ff4243 | Please return 318.961630241143730359 HYPE (80% of the 398.702037801429662948 HYPE proceeds) to: | 0xF2e2A49631927108086268c68C559c63c3C8f73d | You may retain 79.740407560285932589 HYPE (20%) as a white-hat bounty upon return. | PrimeFi is a small protocol and this loss materially affects our users. | Reply with a zero-value transaction containing contact details to 0xF2e2A49631927108086268c68C559c63c3C8f73d. | This request does not waive any legal rights or remedies.


📤 From: 0xf2e2a49631927108086268c68c559c63c3c8f73d
📥 To: 0x19bc1c7fd4aa93f540498499b8f5b4fc3dde5a52
🌎 Network: hyperliquid

Etherscan
  • 🤣 3
Post #3307 738

Forwarded from Defimon Signals

🚨 Flamincome.finance - Loss ~$346K (2026-09-16)

Token: $USDT
Network: Ethereum

Type: Oracle Manipulation (Curve virtual-price / share-price inflation)

Flamincome's USDT Strategy (0xb8d6...68a5) values its Convex/Curve position in impl.deposited() from BaseRewardPool.balanceOf(Strategy) × the Curve USDP metapool get_virtual_price plus its aUSDT reserves. Using a Morpho USDT flash loan the attacker bought USDP cheaply and imbalance-minted a large amount of the USDP metapool LP, deposited it into Convex and staked it FOR the Strategy (stakeFor), inflating balanceOfY()/per-share value. Redeeming YUSDT via VaultYUSDT.withdrawAll then forced the Strategy to pull ~544K aUSDT from Aave and pay out at the inflated price, netting ~$346K (victim strategy lost ~$595K in aUSDT+USDT).

TX: https://etherscan.io/tx/0x5ff8150482f5473bff16b4a142a98a7f72b159df5e9dd38afd90470551640d37
Attacker: https://etherscan.io/address/0x83381e7f7232775735169d72d237b858ffc36871
Victim: https://etherscan.io/address/0xb8d6471ca573c92c7096ab8600347f6a9fe268a5
X: https://x.com/flamincome

@defimon_subscription_bot
  • ❤ 1
Post #3306 821

Forwarded from Defimon Signals

🚨 Bonfire (BonfireSwap) - Loss ~$47K (2026-09-15)

Token: $BONFIRE
Network: BNB Chain

Type: Access Control / Approval Drain

The BonfireSwap router (0x17e8...03d3) exposes transfer(address to, uint amountAIn, address beneficiary, uint deadline) which calls _safeTransferFrom(tokenAddress, to, pancakePair, amountAIn) with no check that msg.sender owns or is authorized to spend `to`'s tokens. Any caller can therefore spend the BONFIRE approval any holder previously granted to the router: the attacker looped this (and skimPool) over ~65 holders who had approved BonfireSwap, force-selling their tokens into the Pancake pair and skimming the WBNB proceeds to their own contract (0x28E9...2127), extracting ~66 BNB (~$47K). Same arbitrary-source flaw exists in loggedTransfer/simpleTransfer.

TX: https://bscscan.com/tx/0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f
Attacker: https://bscscan.com/address/0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a
Victim: https://bscscan.com/address/0x17e801e17cefc6334059189c178d4783830e03d3
X: https://x.com/bonfiretoken

@defimon_subscription_bot
  • ❤ 1
Post #3305 871
💌 Onchain message:

To the holder of this wallet.

This is regarding 825,015 USDT taken on 2 June 2026. The 50,000 USDT you tried to convert at FixedFloat are frozen and will not be released. The remaining 427.78 ETH on this address is under continuous monitoring. Tor and VPN will not protect you 100%. Court orders have been obtained and law enforcement is engaged. We are analysing your behaviour and every move you make from here.

There is one way to close this: return the funds. Contact us at investigations@amlcrypto.io within 3 days of this message. Full return will be treated as a whitehat resolution with a 10% bounty, on terms to be agreed.


📤 From: 0x47e278095b9228c70873fe1421197c357a4ee5d3
📥 To: 0x1d41e249a450166c154d49c6cabd63c6a664c0e8
🌎 Network: mainnet

Etherscan
  • 🤣 9
  • 😭 3
Post #3304 850
💌 Onchain message:

I remain willing to resolve this matter amicably and return the relevant funds. Since you have declined to enter into a written settlement agreement, I propose that you publish a statement from your official X account confirming that, upon receipt of the funds, you will consider the matter fully and finally resolved, withdraw any existing claims and complaints to the extent legally possible, and have no further claims against me in connection with this incident. Once this statement is published, I will proceed with the return of the funds.


📤 From: 0x2010d3043ea5418e8f5f955fe4c349dbd387f433
📥 To: 0x0eda14a4cf98235624871409aa2b28dfd8319339
🌎 Network: mainnet

Etherscan
  • 👍 1
Post #3303 1.06K
🚨 MEV bot "yoink" front-runs a ~$7.81M rsETH exploit on Ethereum

An attacker deployed "Permissionless Attacker Token" and launched the exploit straight into the mempool where it was front-run by yoink capturing the entire ~$7.8M for itself.

Root cause: whale 0x40E9's leveraged rsETH funds sat in a Gnosis Safe whose strategy executor was a whitelisted Safe module. That module exposed a recipe entrypoint that forwarded fully caller-supplied calldata into the Safe's execTransactionFromModuleReturnData with operation=1 (DELEGATECALL) and no gating on the external caller. Because the module is already an authorized Safe module, anyone who could reach the entrypoint could execute arbitrary code in the Safe's own context - full control over its assets.

TX: https://etherscan.io/tx/0x0e7680b06cb8a6f86c149d9ba90d98e3d334e7b072dde03909d43fcfd98a8705
Victim (whale 0x40E9): https://etherscan.io/address/0x40e93a52f6af9fcd3b476aedadd7feabd9f7aba8
Original exploiter: https://etherscan.io/address/0x0dC2c5D6b05A317076CF501f7E7be36a5dfe9b66
Frontrunner (yoink MEV bot): https://etherscan.io/address/0xfde0d1575ed8e06fbf36256bcdfa1f359281455a

⏱️ Real-time alerts: @defimon_subscription_bot
  • 🙉 6
  • ❤ 2
  • 🔥 1
Post #3302 888
💌 Onchain message:

To the holder of this wallet.

On 14 September you deposited 0.5015 ETH into the Bridgeless bridge (tx 0x922878e8...) and submitted it 52 times under different spellings of the hash, minting 26 ETHX on Zano. You then burned 11.6 ETHX toward withdrawals to this address. The bridge is paused, those withdrawals will not be paid, and 14.41 ETHX remains in your Zano wallet. We have also identified the wallets that funded this one.

We would rather close this as a whitehat case, and we will make it simple. Within 48 hours, burn 9.409691 ETHX on Zano as a plain public burn, no bridge attachment. Keep the remaining 5 ETHX as your bounty. When the bridge resumes we will honour a withdrawal of those 5 ETHX to this address.

After the deadline the offer is withdrawn.


📤 From: 0x9ac248c0222d45590e046005b618bf09577a3eaf
📥 To: 0x8d8565f7b0403e474246961fb3295d8308b80687
🌎 Network: mainnet

Etherscan
Post #3301 917
Defimon Alerts Community alert: Defimon detected a governance takeover attempt of Yam.finance Attacker self-delegated ~504K $YAM (~3.3% of supply, just over the quorum) and submitted YamGovernorAlpha proposal #45 with an empty description ("0x"). The single action calls…
Update on Yam.finance governance takeover

The attacker executed proposal #45 and took Timelock admin. They then cut the Timelock delay from 5 days to 12 hours and made themselves gov of Yam's old UMA farming contracts. Calling _settleExpired() released the WETH collateral from their expired uGAS positions. The attacker then pulled everything out with the gov-only masterFallback function, which lets the gov make any call from the contract.

Extracted (~$121K):
• UMAFarmingMar (uGAS-MAR21): 23.50 WETH + 763 UMA
https://etherscan.io/address/0xffb607418dBEaB7A888e079A34Be28A30d8E1DE2
• UMAFarmingFeb (uGAS-FEB21): 24.59 WETH
https://etherscan.io/address/0xc0AE1e1e172ECD4C56fD8043FD5Afe5a473E9835

The proceeds (48.15 ETH) were cashed out via FixedFloat.
  • 🔥 6
  • ❤ 3
  • 😱 2
  • 🤣 1
Post #3300 853

Forwarded from Defimon Signals

🚨 ampleforth.org - Treasury at risk $2.5M (2026-09-12)

Token: $FORTH @ $0.22
Network: Ethereum

Type: Access Control (Malicious Governance Proposal)

A fresh EOA (2 txns) created proposal #54 on Ampleforth Governor Bravo (0x8a994C6F...). Its single action transfers 2,500,000 USDC — essentially the ENTIRE treasury (timelock holds 2.538M USDC) — to the proposer 0x730C97E7..., dressed up as an unsolicited "Observatory for SPOT completed-work grant." The proposer discloses it wrote the proposal and will self-vote via a delegate holding just 87,238 FORTH (~0.57%), barely clearing the 75k threshold. Quorum is only 600k FORTH; at $0.22 that is ~$132k to corner — cheap against a $2.5M prize.

TX: https://etherscan.io/tx/0x06ef1e7165a1316e167cb6bd5040de74cfaeceb249b78043bbf2277213ce32f2
Attacker: https://etherscan.io/address/0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82
Victim: https://etherscan.io/address/0x8a994C6F55Be1fD2B4d0dc3B8f8F7D4E3a2dA8F1
X: https://x.com/AmpleforthOrg

@defimon_subscription_bot
Post #3299 832
💌 Onchain message:

SAFETY ALERT chainId 788988 (Arbitrum Orbit, AnyTrust). Your bridge 0xC82dd3713f5eB5053D5A1a47f456435054ec77Dc holds 3.4018 ETH of user deposits and is being drained. Attacker 0x4428BE9125AE4e476514776a72ceDF2d5ce269C2 already opened the validator-AFK whitelist (tx 0xeb171e9af3318549c1ab313f3848945f46b1a1f1750ae7bb9651ef1339ec4ee5) and staked a forged node 716 (tx 0xbf303c72fcc4f47a12622b1a19fa3fbba58501ea4af7449fa574bc3089f7b93b). They can confirm after L1 block 26005988 (~2026-09-18) and then withdraw the escrow. FIX (no stake needed): Safe 4-of-11 -> UpgradeExecutor 0x1AA00161Fe7381af1Fc4C45cB8895E3901b844Bd .executeCall(rollup 0xe58A48B6d03cCbcb0c5B8e8BB76682564EF02899, setValidatorWhitelistDisabled(false)). Same exposure on your other chains 7889 and 78898. Full analysis + PoC available on request.


📤 From: 0xf826683060f021fc438eb8800a07a1b7bc844feb
📥 To: 0x81175155d85377c337d92f1fa52da166c3a4e7ac
🌎 Network: arbitrum

Etherscan
Older posts →

About this channel

How can I read @defimon_alerts without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Defimon Alerts: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Defimon Alerts have?
Defimon Alerts (@defimon_alerts) has 4.65K subscribers on Telegram, refreshed roughly every 30 minutes.
Does Defimon Alerts know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →