Payy's bridge contract was exploited on September 24, 2026, with an attacker submitting an invalid burn proof that the Noir/Barretenberg verifier accepted, draining approximately 1.9 million USDC. The vulnerability appears to stem from the proving-system in Aztec's verifier, and Payy has paused all network transactions while investigating.
Payy's bridge contract was exploited on September 24, 2026, when an attacker submitted an invalid burn proof that the Noir/Barretenberg verifier accepted, draining approximately 1.9 million USDC. The vulnerability appears to stem from the proving-system in Aztec's Noir/Barretenberg verifier, and Payy has paused all network transactions pending investigation.
A post about giving an agent a pulse, shared on X (formerly Twitter) on September 29, 2026. The content appears to reference smart contract security concerns based on the search keywords, but specific details are not provided in the body.
Hackers discovered the "Relapse" jailbreak exploit that works on all PS5 firmware versions except the latest (14.00.00), released September 16, 2026. The exploit affects retail PS5 consoles and older games like Marvel's Wolverine, potentially enabling widespread piracy since it can be implemented in under a minute.
Social media discussion about Ethereum price movements and technical analysis, with mentions of a PPV2 exploit affecting token approvals. Traders discuss ETH price levels around $2,550-$2,800 and potential breakout zones, with attention to upcoming ISM economic data.
A PlayStation 5 jailbreak exploit supporting firmware versions 7.00 through 13.60 has been released. The exploit uses webkit vulnerabilities and kernel race conditions to achieve read-write access, with instructions for local deployment and payload execution via an ELF loader.
CVE-2026-49869 is an authentication bypass vulnerability in Kestra OSS that allows unauthenticated remote code execution. The defect exploits AuthenticationFilter treating any path ending in /configs as public, enabling attackers to create and execute workflows with shell tasks in the worker container. Users should upgrade to version 1.0.45 or 1.3.21 and restrict API access until patched.
At Exploit Summit in Montreal on September 29, 2026, speakers discussed advances in distributed AI computing, subnet incentives, and open-source infrastructure across Bittensor's ecosystem. Earlier, the Bitget exploiter's attempt to route stolen funds through Chainflip was blocked when the protocol rejected the transaction at the broker interface and refunded the deposit.
CVE-2026-85706 is a critical vulnerability (CVSS 10.0) in GitLab that allows unauthenticated attackers to read arbitrary files from the server by URL-encoding a single character in API requests, bypassing authentication entirely. The flaw has been exploited in the wild and is tracked in CISA's KEV catalog. Self-hosted GitLab installations must update to versions 19.1.8, 19.2.6, or 19.3.2 immediately.
During a May 2026 exploit on THORChain, attackers stole $10.7M from liquidity pools. A protocol halt was used as an emergency security measure rather than selectively freezing specific funds or preventing the attackers from swapping, reflecting THORChain's design as a permissionless, non-censoring protocol.
A $387 million Bitget exploit sparked debate over whether THORChain should blacklist the attacker's addresses, raising fundamental questions about whether decentralized protocols should prioritize immutability and neutrality or intervene to protect victims and prevent theft.
A social media post discusses Jevscan, a continuous on-chain monitoring tool, shared in the context of smart contract exploits and security incidents.
OpenSecurityTraining2 is a collection of security training courses covering architecture, debugging, reverse engineering, vulnerability analysis, exploit development, secure development, and other defensive security topics.
A $387M theft from Bitget exchange was routed through THORChain, prompting CEO Gracy Chen to request the protocol blacklist the stolen funds. THORChain declined, citing decentralization principles, but critics note the protocol previously halted operations for a month during its own $10.7M exploit, suggesting selective application of emergency powers.
Users report drained Farcaster in-app wallets with transactions signed by the wallet's own key and funds bridged to Solana, though the cause remains unconfirmed. The incident highlights risks of embedded wallets where users may not control their keys directly. Security researchers advise moving funds to self-custodied wallets as a precaution.
A post from Tashi Network discussing robots, chains, and emerging technologies, trending on X as of September 28, 2026.
A developer created a method to hijack the PS5's RTMP streaming protocol by spoofing DNS records, allowing them to stream PS5 gameplay to Discord without purchasing an expensive capture card. The solution uses dnsmasq and nginx-rtmp to redirect the PS5's stream from Twitch's servers to a local Mac, bypassing Sony's streaming restrictions.
X discussions analyze a protocol exploit affecting THORChain, comparing its security vulnerabilities and inconsistent decentralization principles to NEAR Protocol's more stable infrastructure approach. A $1.7M exploit in May 2026 prompted network intervention, contradicting the protocol's permissionless philosophy, while stolen Bitget funds now flow through THORChain's fee mechanisms to cover past losses.
A $292M bridge exploit has triggered litigation between KelpDAO and LayerZero over security risk disclosure, while Hedera demonstrates strong institutional adoption through its Governing Council of Fortune 500 companies, enterprise applications on IBM Cloud, and contribution of its cross-ledger protocol to the Linux Foundation, though its token trades below its 2018 ICO price.
THORChain declined Bitget's request to block addresses associated with attackers from a $387.5 million September security breach, citing its permissionless design and network halt mechanism's purpose to protect the protocol rather than freeze individual addresses.