RSS Amplifier

Podcast

Verichains

Leading security firm trusted by top fintech customers including Binance, Bullish, Bybit, Galaxy Digital, Vantage FX, Polygon, BNB Chain, Aptos, Sui, Kakao, Line, Abu Dhabi Blockchain Center, as well as many traditional banks and fintech companies!

blog.verichains.ioSource feed ↗20 episodes

Live Last read · last published · next check

Written by

Latest episodes

[PWN2OWN IRELAND 2025] Bypassing Authentication via Synology DS925+ SAML SSO

Bypassing Authentication via Synology DS925+ SAML SSO

Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation

On July 6, 2026, the Lazy Summer Protocol suffered an exploit on Ethereum mainnet that resulted in approximately $6.04 million in losses across two USDC vaults. The attacker used flash-loan liquidity,

LIEN FINANCE HACK ANALYSIS

Lien Finance is a decentralized finance (DeFi) protocol deployed on Ethereum, offering structured bond products through its BondMaker architecture - a system that lets users create, exchange, and redeem collateralized “bond groups” representing different tranches of an underlying asset’s payoff.

Drips Network: When Giving Became Receiving

Drips Network Exploit

Lumi Finance Exploit: ERC-1271 Bypass and Unauthorized Token Approvals in Sodium Smart Accounts

On July 13, 2026, an attacker drained approximately $270,000 in tokens from Sodium smart accounts associated with Lumi Finance on Arbitrum.

BFB Token Exploit Analysis

On July 8, 2026, the BFB token on BNB Smart Chain was exploited through a flaw in its custom "price-defense" deflationary logic, resulting in the loss of approximately 350.6 WBNB (~$198,000) drained from the PancakeSwap BFB/WBNB liquidity pool.

Gnosis Pay Exploit: The Devs Discovered the Bug, So Why Did the Attack Still Happen?

TL;DR: On June 1, 2026, Gnosis Pay lost about $265,000 to a hacker.

Two bytes to RCE: chaining rift + PoolSlip into an ASLR-independent nginx 1.30.0 exploit

Chaining nginx PoolSlip (CVE-2026-9256) + Rift (CVE-2026-42945) into an ASLR-independent RCE on the stock nginx:1.30.0 image; leak + 2-byte partial overwrite to system().

How Renouncing Ownership Opened a $98K Backdoor on ONTR Token

On May 28, 2026, the ONTR token on Ethereum was drained of approximately $98,315 in a matter of minutes.

Aurellion Labs Hack Analysis: Diamond Proxy Uninitialized Facet Exploit

On May 12, 2026, Aurellion Labs, an Arbitrum-based DeFi protocol, suffered a security incident resulting in a loss of approximately $456K USDC.

TrustedVolumes Exploit Analysis

On May 7, 2026, TrustedVolumes, an independent DeFi liquidity provider and RFQ market maker, was exploited, resulting in a loss of approximately $6.7M on-chain.

JUDAO HACK ANALYSIC

JUDAO is a decentralized finance (DeFi) project deployed on the BNB Smart Chain (BSC), offering token-based financial services through its on-chain liquidity and trading ecosystem.

Denaria Finance Exploit: When divCeil Meets an Unsafe Cast

On April 5, 2026, the decentralized perpetual exchange Denaria Finance on the Linea blockchain fell victim to an exploit that resulted in a loss of approximately $165,618 USDC.

When Signing Is Not Secure

GiddyDefi Exploit

How a Missing Bounds Check Led to $237K Exploit on Hyperbridge

On April 13, 2026, an attacker minted 1 billion bridged DOT tokens out of thin air on Ethereum - and dumped them for roughly $237,000 in ETH. The target was Hyperbridge, Polytope Labs’ trust-minimized interoperability protocol connecting Polkadot to EVM chains.

Deep Dive into the dTRINITY cbBTC Exploit

On March 17, 2026, the DeFi protocol dTRINITY, a lending protocol on Ethereum, suffered a security incident resulting in an estimated loss of ~$257.3K.

DBXen Exploit Analysis

On March 11, 2026, DBXen was exploited through a vulnerability on the custom logic, resulting in the loss of approximately $149,000.

Solv Protocol Hack Analysis

Solv Protocol (SOLV) is a Bitcoin DeFi platform that allows users to stake BTC or liquid staking tokens (LSTs) in exchange for SolvBTC.

LAXO Token Exploit: AMM Reserve Manipulation via Burn Mechanism

On February 22, 2026, the LAXO token on Binance Smart Chain (BSC) was exploited through a flaw in its token transfer logic and burn mechanism.

Solidity's Hidden Flexibility: How ABI Encoding Assumptions Led to an Exploit

UniswapV4Router04 Exploit