THORChain defends its permissionless protocol design following a $10.7M exploit in May 2026, arguing that cryptocurrency networks are neutral tools like Bitcoin and Ethereum that cannot selectively censor transactions without blocking legitimate activity. The debate centers on whether decentralized protocols should prevent stolen funds from being swapped.
A social media post discusses a security vulnerability related to sandboxing, suggesting the issue extends beyond sandbox limitations.
A post discussing the Civilization Test Suite was trending on X on September 28, 2026, related to smart contract security issues.
X users discuss Solana token trading and giveaways on September 27-28, 2026. Posts include a trader offering $10,000 giveaway after losses on $PAID token, Solana airdrops, and commentary on NFT community responses to exploits and security issues.
DYORSWAP issued an official update regarding a fake GIWA Chain 9134 incident on September 27, 2026. The post generated significant engagement on X with 25 likes, 2 retweets, and 25 comments.
A security researcher discovered a critical remote code execution vulnerability in luarocks.org, a major Lua package repository, that could be exploited by regular users to gain root access and potentially execute a supply chain attack affecting millions of machines. The vulnerability stems from unsafe handling of rockspec files, which are Lua scripts that can execute arbitrary system commands if not properly sandboxed.
A Magic Eden and Limit Break smart contract exploit resulted in thousands of NFTs being at risk, but white hat hackers managed to secure them before malicious actors could drain them. The incident highlights that users leaving active approval permissions on retired contracts is a significant security vulnerability, and users should regularly audit and revoke unused wallet approvals.
A Twitter discussion highlights that 60% of exploited crypto projects in 2025-2026 had undergone third-party audits, illustrating that smart contract audits provide important but incomplete protection against losses from private key leaks, phishing, frontend hacks, and admin issues. Separately, crypto markets show Bitcoin ETF inflows of $2.4B weekly, researchers propose privacy enhancements for Bitcoin, Block adds Lightning support for AI agent payments, and Ethena expands stablecoin backing to tokenized equities.
Two flagship LLMs, Claude Opus 5.5 and Kimi K3, were compared in building network worms for Pokémon Emerald by finding novel vulnerabilities and exploits. Both models discovered the same link-cable vulnerability and created game-breaking worms, though they took different approaches, found different bugs, and had varying responses to ethical guardrails around piracy and malware creation.
A developer built NOCK, a risk detection system for DeFi protocols, during the Nansen Meridian Buildathon. NOCK monitors vaults and lending markets across multiple blockchains to detect unusual capital outflows and collateral contagion, alerting users and enabling automated fund recovery. The tool demonstrated effectiveness in identifying risks from major 2026 exploits including Drift, Kelp's bridge drain, and Bitget's wallet breach.
A discussion on X contrasts halting an entire blockchain protocol during an active exploit versus selectively blacklisting addresses after a centralized exchange hack, arguing the former protects the network while the latter determines user access.
KelpDAO is suing LayerZero over a $292M bridge exploit from April 2026. The attack exploited a single verifier controlled by LayerZero with no independent verification. Both parties dispute responsibility, though LayerZero later admitted allowing solo verifier operation for high-value transactions was a security mistake.
A user criticizes an unnamed organization for coordinating secret updates, maintaining arbitrary rug-pull and ban functionality since 2019, using a master admin key to exploit users in 2025, and failing to disclose details about a security hack that left them offline for months without proper incident response or post-mortem analysis.
Anndy Lian defends THORChain's technical limitations in blocking stolen funds, explaining that while nodes can halt trading via consensus, implementing surgical per-address blacklisting would require either halting all swaps or deploying code upgrades—constraints inherent to decentralized, permissionless protocols. The discussion follows reports that Bitget exploit funds were routed through THORChain for cross-chain transfers, raising questions about the protocol's responsibility toward known stolen assets.
Ethereum community members debate blockchain governance and market valuations on X. Discussion centers on whether decentralized exchanges should reverse transactions for stolen funds, with comparisons to past Ethereum rollbacks, alongside market analysis suggesting major cryptocurrencies remain significantly below all-time highs.
A $292 million exploit affected LayerZero protocol in 2026, reportedly discovered through AI scanning. KelpDAO has filed suit against LayerZero, alleging the protocol's security weaknesses were not disclosed, highlighting the tension between decentralized systems and traditional legal recourse.
Bitget CEO Gracy Chen formally requested that THORChain reject transactions from addresses linked to recent exploits, arguing that decentralization should not shield protocols from handling known stolen funds. MistTrack reported that proceeds from Bitget and prior Bybit exploits were routed through THORChain for cross-chain transfers, sparking debate over protocol responsibility.
A threat actor group UNC6240/ShinyHunters is exploiting CVE-2026-35273 in Oracle PeopleSoft by using URL-encoded characters to bypass Web Application Firewalls, deploying web shells and post-exploitation tools including SIDEEYE across multiple systems.
Address poisoning attacks exploit cryptocurrency users copying wallet addresses by displaying lookalike addresses with matching first and last characters, with a USENIX study documenting 270 million attempts across Ethereum and BNB Chain causing $83.8 million in confirmed losses. Americanfort.io's Send-to-Name protocol addresses this by replacing address copy-paste with name-based payments that generate one-time stealth addresses only sender and recipient can derive, eliminating the vulnerability window.
A MagicEden protocol exploit occurred on September 26, 2026, affecting users. Discussion centers on flash loan vulnerabilities and the importance of understanding protocol-level security risks rather than relying solely on personal security practices when choosing where to deposit cryptocurrency assets.