# "smart contract" (exploit OR hacked OR drained) — X 热门讨论 (2026-09-25 18:23 UTC)

## @EthanElvberg (Ethan / 6529) · 09-25 16:38 · ♥135 ↻0 💬34 from what oracle digged out the bitget situation was not a smart contract exploit.

multiple hot and cold wallets signed normal transfers and moved funds into fresh wallets across several chains. the blockchain did exactly what it was told to do. the failure was likely higher up: custody infrastructure, signer access, the mpc approval system, the withdrawal backend, or someone with internal authority.

the exact entry point is still unknown, but the damage could have been limited with isolated signers, destination allowlists, strict outflow caps, withdrawal cooldowns, independent approval quorums and automatic velocity checks across every chain.

cold wallets should also never share the same control path as hot wallets.

if multiple wallets suddenly start sending millions to one fresh address across six chains, the entire signing system should automatically freeze before the second transfer not keep going until more funds are drained. https://x.com/EthanElvberg/status/2103524463358722216

## @HatomProtocol (Hatom Labs) · 09-25 16:59 · ♥71 ↻22 💬2 Postmortem on Mex Money Market Exploit : https://x.com/HatomProtocol/status/2103529959482409115

## @Cardano (Cardano) · 09-25 16:39 · ♥36 ↻9 💬0 Join us Monday, September 28 at 15:00 UTC for Roundtable Talk: Smart Contract Security - Why One Check Is No Longer Enough

The blockchain industry has seen a rise in smart contract exploits. AI models have not only become smarter and more advanced, but they can now analyze code, find vulnerabilities, and generate exploit code.

With this vastly changing landscape, how should projects rethink security when Ai can find and exploit flaws in minutes? And what does this mean for trust in the ecosystem?

This Roundtable brings together experienced auditors to discuss continuous AI-driven monitoring, how auditing firms are adapting their business models, and practical steps DApp developers can take to protect their code and strengthen user trust.

Confirmed speakers:

- Alexander Vershilov - Senior security researcher @Tweag - @santicarmuega- CEO, @txpipe_tools - @phil_uplc - CEO, @AnastasiaLabs - Benjamin Hart - CTO & Technical Architect, @MLabs10

Additional speakers pending confirmation.

Set a reminder and tune in: https://t.co/DuZtAFFisN https://x.com/Cardano/status/2103524709035847967