World Mobile is shifting Ethereum token recovery, exchange support, and liquidity to Base following a recent bridge exploit, while Cardano continues operating. The move signals Base's growing role in the company's infrastructure strategy.
MultiversX's EGLD network experienced an attempted exploit but is now back online. The community awaits a post-mortem report and clarification on accusations against the MultiversX codebase during the incident.
A user recounts losing millions in a smart contract exploit despite the project having a security audit, arguing that audit credentials alone don't guarantee trustworthiness. They advocate for GenLayer's approach of using randomly selected independent validators to evaluate outcomes, especially as AI agents gain decision-making power in financial systems.
X discussions on Ethereum from September 24, 2026 cover market movements, a security incident where Payy's bridge contract was exploited, bullish sentiment about Ethereum's Layer 2 ecosystem advantages, and ARK Invest launching a tokenized venture fund on Ethereum.
A Kasplex exploit has reignited criticism of Kaspa's ecosystem governance, with the project targeting 100 blocks per second by 2027 through technologies like DAGKnight and ZK bridges.
MultiversX experienced an exploit involving vulnerable code from the previous year, occurring shortly after a launch. The community hopes for a transparent post-mortem and recalibration, acknowledging the project's significance for Romania in cryptocurrency.
A review of Pera Wallet for Algorand staking, comparing native consensus (requiring 30,000 ALGO minimum) with liquid staking options. The author found no reported exploits of Pera itself, though a different Algorand wallet (MyAlgo) was hacked for $9.6M in 2023. Current staking rewards are around 4.75%, with security features including non-custodial keys and local encryption, though the author notes a lack of recent third-party audit reports.
Payy Network's Ethereum L1 rollup bridge (RollupV1) was exploited and drained of approximately $1.83 million in USDC through a forged withdrawal hidden in a valid batch. The attack exploited the absence of deposit accounting, withdrawal caps, or pause mechanisms in the contract, with the attacker depositing only $10 while withdrawing $1.83 million using a compromised prover or validator key.
A novel technique exploits SQLite's sqlite_dbpage virtual table to achieve arbitrary file writes and remote code execution by bypassing database header restrictions. By directly manipulating raw database pages via SQL queries and relocating the ELF Program Header Table, attackers can craft and load malicious shared objects, circumventing protections in strict runtimes like Python and Ruby.
A Kaspa KRC 20 exploit involved fraudulent transfers of 186.4 million ZEAL and 54.4 billion NACHO tokens through a Kasplex indexer vulnerability. Approximately 1 million iKAS from the attacker may be frozen during an Igra exit process, potentially preventing their withdrawal to Kaspa L1.
Check Point disclosed CVE-2026-85102, a critical pre-authentication remote code execution vulnerability in its Security Gateway VPN product that allows attackers to execute arbitrary code via malicious certificates. Threat actors are actively exploiting the flaw in the wild, and the company has released patches urging immediate updates to prevent widespread data breaches and system compromise.
A malicious proposal exploited Neutron's governance process, granting the attacker admin control over smart contracts including Astroport and Drop Money, enabling asset drainage. Cosmos Hub validators coordinated a security halt to restrict stolen ATOM movement, and block production has since resumed as the ecosystem investigates the incident.
A Neutron protocol exploit enabled attackers to gain admin control over smart contracts, including those of Astroport and Drop Money, and drain assets through a malicious governance proposal. The Cosmos ecosystem coordinated a security response by halting affected networks and restricting stolen asset movement, with Cosmos Hub resuming normal operations after the incident.
Neutron protocol was exploited through a malicious governance proposal that granted attackers admin control over smart contracts including Astroport and Drop, allowing asset drainage. Cosmos Hub and other validators coordinated a security halt to contain damage, and block production has since resumed while investigation into the full scope continues.
Hacking group ShinyHunters claimed to have breached FBI systems using a zero-day Oracle PeopleSoft exploit, stealing data on all FBI employees and applicants including names, addresses, and phone numbers. The group defaced the FBI's jobs website and demanded the FBI retract or remove a 2026 Q2 report about their tactics within one week, stating their motivation is coercion rather than financial extortion.
A user analyzes eHYUSD, a DeFi protocol on Solana that offers 23% APY by having staked hyUSD holders act as the system's stability layer. The yield increases when collateral ratios exceed 165%, but holders face risks including smart contract exploits, volatile crypto collateral backing, and potential losses if the protocol fails to liquidate in time.
A security researcher flagged multiple DeFi applications with critical vulnerabilities, including direct fund theft risks in DeFiSaver and 1inch Wallet, a liquidity bridge exploit in Rootstock, and a double spending vulnerability in Stacks. The post warns that exploits may be released imminently.
Containers are no longer a reliable security boundary as AI-accelerated kernel vulnerability discovery has dramatically lowered the barrier to container escape attacks. Researchers demonstrated this by exploiting CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem discovered using an AI model. Organizations should migrate sensitive workloads to stronger isolation technologies like Firecracker or Kata Containers.
Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.
RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP race condition in the strparser that affects multiple major Linux distributions including CentOS Stream 9 and Ubuntu 26.04 LTS. The timing-sensitive exploit uses x86 prefetch side-channel attacks to leak kernel base addresses and reclaims freed memory to achieve unprivileged privilege escalation.