source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
MONDAY, SEPTEMBER 28, 2026
X 主题热门3658Hacker News3604CNBC72YahooFinance65aihot62Verge56IGN469to5Mac39MacRumors36Engadget329to5Google28TechCrunch28Kotaku27Eurogamer23AndroidAuthority21PushSquare19NintendoLife18Guardian18TechPowerUp17ArsTechnica16FoxBusiness16Investor'sBusinessDaily15Polygon15Wccftech15Mashable14Fortune13BusinessInsider12Gematsu10Gizmodo10NBC10SeekingAlpha10AndroidPolice9CBS9NPR9NewYorkPost9PureXbox9USAToday9VideoGamesChronicle9bgr8CNN8MotleyFool8CNET7GameGPU7GSMArena7NintendoEverything7Notebookcheck7VideoCardz7AlJazeera6BleepingComputer6Fox6Tom'sGuide6ABC5DroidLife5GamesIndustry.biz5Jalopnik5XBOXWire5TechSpot5WIRED5Yahoo5AndroidCentral4AppleInsider4CoinDesk4Draftsim4GameInformer4GAMINGbible4HollywoodReporter4InsiderGaming4NYT4PlayStationLifeStyle4PokeBeach4RockPaperShotgun4Conversation4Hacker4UploadVR4WarhammerCommunity4Aftermath3ChromeUnboxed3Electrek3EventHubs3GameRant3Lifehacker3Motor13Nature3PetaPixel3SouthChinaMorningPost3TimeExtension3WhatHi-Fi?324/7WallSt.2404Media26abcPhiladelphia2Autonocion2AZFamily2Benzinga2BostonGlobe2BuzzFeed2Currently2DCRainmaker2Deadline2Futurism2GearPatrol2Hackaday2MP1st2mtgrocks2MyNintendo2CrudeOilPricesToday2OregonPublicBroadcasting2PCMag2Pokemon2politico.eu2RoadtoVR2RPGSite2SamMobile2SFGATE2SimsCommunity2SlashGear2Slate2YahooTech2Register2TODAY2Variety2WindowsCentral280Level1WXLV1ABC7LosAngeles1ageofempires1airlive1AndroidHeadlines1Anthropic1Apple1AVClub1AviationWeek1BoingBoing1BusinessTimes1Yahoo!FinanceCanada1YahooLifestyleCanada1CarandDriver1CineD1ClaimDepot1CnEVPost1comicbookmovie1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1DailyKos1DaringFireball1DarkHorizons1Deseret1Designboom1Dezeen1DigitalCameraWorld1DigitalFoundry1DSOGaming1Finbold1ForexFactory1FOX13Seattle1franchisetimes1Futurity1GameWorldObserver1garymarcus.substack1GeekWire1GeekyGadgets1GosuGamers1Gothamist1Hackster.io1HoustonChronicle1iLovetheUpperWestSide1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1I/OFund1iPhoneinCanada1KCRA1LosAngelesTimes1MacObserver1Magic:Gathering1MakeUseOf1Mashed1MLive1MortgageDaily1Motorsport1NBCBayArea1NBC5Chicago1NBC7SanDiego1BloombergLaw1Newser1SemiAnalysis1Newsweek1NintendoWire1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1Psyche1qz1Realtor1RichmondTimes-Dispatch1Richmonder1Road&Track1ScienceDaily1ScreenRant1SeattleRed1SanFranciscoChronicle1YahooFinanceSingapore1Yahoo1SimpleFlying1GhostHowls1SlowBoring1SoraNews241Space1SpaceNews1statnews1svg1TampaBayTimes1the5krunner1DailyBeast1DailyMeal1Drive1Intercept1NextWeb1https://tipswatch.com/1TMZ1TopGear1TweakTown1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1WrestlingInc.1YGOrganization1
  1. 001X 主题热门SEP · 27English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-27 16:54 UTC

    A Twitter discussion notes that CoinGecko recorded 245 smart contract exploits from early 2025 through July 2026, with approximately 60% of exploited projects having undergone third-party audits. The post emphasizes that while audits provide a layer of security, they do not protect against all vulnerabilities such as leaked private keys, phishing attacks on staff, frontend compromises, or admin permission issues.

  2. 002Hacker NewsSEP · 27English

    The secretive cyberweapons company that won over Israel's intelligence elite

    An investigation reveals that Dataflow Security, an Italian cyberweapons company founded in 2019 by hacker Luca Todesco, has developed close ties with Israel's intelligence establishment. Since late 2025, the company's Israeli subsidiaries have been led by Eyal Tsir Cohen, a former senior Mossad official who was previously shortlisted to lead Shin Bet, raising questions about the independence of these operations.

    By Gabriele Ciraolo
  3. 003X 主题热门SEP · 27English

    protocol exploit · X 热门 · 2026-09-27 11:55 UTC

    GoPlus Security challenges THORChain's decentralization claims, arguing the protocol could block DPRK-linked illicit funds using existing emergency mechanisms. A developer built NOCK, a risk detection tool for DeFi that monitors unusual capital flows across lending platforms and vaults, demonstrating early detection of contagion risks like the Kelp bridge exploit.

  4. 004X 主题热门SEP · 27English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-27 02:05 UTC

    A crypto analyst argues that smart contract audits provide false security, as most 2026 exploits ($823.7M total) stem from compromised infrastructure and operational failures rather than code flaws. Major incidents like the Bitget hack ($351.6M) exploited backend vulnerabilities and key management weaknesses, while physical attacks and bridge exploits add further risk, shifting focus from protocol audits to custody and infrastructure security.

  5. 005X 主题热门SEP · 27English

    protocol exploit · X 热门 · 2026-09-27 01:32 UTC

    A blockchain security analyst argues that smart contract audits provide false security, citing $823.7 million in exploits in September 2026 where most losses stemmed from compromised infrastructure and key management failures rather than code vulnerabilities. The post warns institutions to prioritize custody risk assessment and hardware-enforced security over audited protocols, while predicting capital rotation toward decentralized execution environments like Solana and Base.

  6. 006X 主题热门SEP · 27English

    stablecoins · X 热门 · 2026-09-27 01:31 UTC

    A social media post lists 12 cryptocurrency platforms and waitlists available in September 2026, followed by analysis of crypto security breaches totaling $823.7 million. The author argues that smart contract audits provide false security, with major exploits stemming from infrastructure vulnerabilities, key management failures, and physical attacks rather than code flaws.

  7. 007X 主题热门SEP · 26English

    bridge exploit · X 热门 · 2026-09-26 15:09 UTC

    ZKX Wallet discusses a Field Manual on security defenses against exploits, covering practices like verification, signature review, and flash loan protection. The post emphasizes applying these habits in practice and previews remaining topics including oracle trust, bridge research, and MEV protection.

  8. 008X 主题热门SEP · 26English

    oracle exploit · X 热门 · 2026-09-26 03:07 UTC

    A crypto wallet service explains that individual users don't need to understand flash loan exploit mechanics to protect themselves, as the defense must occur at the protocol level through oracle design and testing rather than personal practices. The key strategy is selecting trustworthy protocols rather than attempting direct mechanism defense.

  9. 009X 主题热门SEP · 25English

    crypto wallet drainer · X 热门 · 2026-09-25 12:22 UTC

    A detailed post explains how crypto wallet approvals—permissions granted to smart contracts to move tokens and NFTs—pose ongoing security risks because they rarely expire and persist even after apps shut down. The author documents multiple real incidents across DeFi and NFT platforms where attackers exploited forgotten approvals to drain millions in assets, and advises users to regularly revoke these permissions.

  10. 010X 主题热门SEP · 25English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-25 11:49 UTC

    A Twitter discussion thread documents major smart contract exploits and approval vulnerabilities in crypto. Examples include the $351.6M Bitget exchange breach, Magic Eden NFT marketplace drains via forgotten approvals, and multiple DeFi protocol hacks (SushiSwap, Li.Fi, BarnBridge) where users lost funds through infinite token approvals that were never revoked.

  11. 011X 主题热门SEP · 22English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-22 11:33 UTC

    A weekly DeFi incident report covering multiple security breaches and hacks across blockchain protocols in September 2026, including smart contract exploits at Balancer, Safe, Nomic, ChainFlip, Ether Fi, and Yam Finance, plus a major phishing campaign via compromised Trezor email infrastructure that reached 347k addresses.

  12. 012X 主题热门SEP · 22English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-22 07:41 UTC

    A retired Microsoft engineer explains how a Grok AI wallet transferred 3 billion tokens via a tweet encoded in Morse code, exploiting the wallet's agentic design that lacked human confirmation steps. The incident demonstrates 'authority laundering'—where untrusted input passes through multiple systems and appears trusted by the time it reaches execution, similar to SQL injection or prompt injection attacks.