BlockThreat - Week 17, 2025

Ripple | VOXEL | Loopscale | BTCM | Term Labs | Impermax | LIFE | Aventa

BlockThreat - Week 17, 2025

Greetings!

Almost $9M was stolen this week across 14 incidents! We saw price oracle manipulation, key theft, precision loss, arbitrary external calls, and even the rarer storage manipulation vulnerabilities—all making an appearance.

But let’s focus on a ticking time bomb: the rise in supply chain attacks. These are becoming disturbingly frequent and have the potential to wreck the entire ecosystem. This week, it was Ripple’s turn. The xrpl.js Node package was backdoored by what appears to be a compromised employee. Fortunately, the change was caught early and flagged by Aikido.

Last month, Coinbase’s Agent Kit repo was similarly targeted through a compromised contributor who inserted key-stealing code. In December 2024, Solana’s NPM library was backdoored. We may feel lucky that damage was limited in those cases—but tell that to AdsPower users who lost $4.7M just months ago.

We’ve already witnessed our first >$1B breach due to poor key management practices—Bybit. Unless we begin to seriously lock down our code repositories and dependencies, it’s only a matter of time before another wallet or exchange gets wiped out.

Let’s learn from the infamous XZ Utils/OpenSSH incident, which nearly led to mass compromise of internet-facing servers via a sophisticated supply chain backdoor. Here are some essential controls you should implement now:

  • Pin dependency versions to prevent silent, backdoored updates.
  • Continuously monitor and test dependencies using tools like GitHub Dependabot, OSS Review Toolkit, and similar.
  • Require peer reviews for all commits and deploys.
  • Harden your CI/CD pipelines with automated tests and anomaly scanning—both in your code and in your dependencies.
  • Minimize the number of privileged admins who can push packages outside the regular process. Treat them with the same caution as your key-signing infrastructure.

I get it—it’s not the glamorous side of blockchain security. But you must lock down your code repos and dependencies. Starting now!

Speaking of locking things down and staying paranoid, BlockThreat is proud to have a very special sponsor and a friend this week: Opsek. Pablo and Louis are exactly who you should be talking to if you want to tune up not just your operational security—but the most critical, vulnerable layer of your organization: your people.


Is your team safe from sophisticated threat actors?

More than 98% of stolen funds in the Web3 ecosystem are hacked without breaking code but by breaking people. Opsek will train your team to become paranoid, and harden your complete operational security stack.

You are already a target, don't get rekt.

Link: https://opsek.io/


For detailed post-mortems, indicators on this week’s smart contract exploits including Loopscale, BTCM, Term Labs, Impermax, LIFE, Aventa, and others see the premium section below.

Let’s dive into the news!

News

Crime

Policy

Phishing

Scams

Malware

Media

Research

Tools

Hacks

USDBIT

Date: April 21, 2025
Attack Vector: Rounding Error
Impact: $5,000
Chain: BSC

References:

https://x.com/TikkalaResearch/status/1914484898855051328

Unkn_92d09d

Date: April 22, 2025
Attack Vector: Storage Manipulation
Impact: $40,000
Chain: Ethereum

References:

https://x.com/Phalcon_xyz/status/1914631419432665216

BTCM

Date: April 22, 2025
Attack Vector: Logic Error
Impact: $1,000,000
Chain: Arbitrum

References:

https://x.com/blockaid_/status/1914680881823822083

Ripple

Date: April 22, 2025
Attack Vector: Supply Chain
Impact: Assets Stolen

References:

https://x.com/guardrailai/status/1914760244019839478

Oxya

Date: April 23, 2025
Attack Vector: Stolen Private Keys
Impact: $45,000
Chain: Ethereum

References:

https://x.com/CyversAlerts/status/1915118805740638687

https://x.com/OxyaOrigin/status/1915109745553289434

https://x.com/AaronBaylo/status/1915114342905000153

ACB

Date: April 24, 2025
Attack Vector: Price Oracle Manipulation
Impact: $84,000
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1915324379757502727

https://x.com/SlowMist_Team/status/1915239816486412697

Zora

Date: April 24, 2025
Attack Vector: Arbitrary External Calls
Impact: $140,800
Chain: Base

References:

https://x.com/TenArmorAlert/status/1915649260499910854

https://x.com/CyversAlerts/status/1915407845899596090

Impermax Finance

Date: April 26, 2025
Attack Vector: Price Oracle Manipulation
Impact: $152,000
Chain: Base

References:

https://x.com/TenArmorAlert/status/1916089811770675312

https://x.com/hklst4r/status/1916164701597089826

Term Labs

Date: April 26, 2025
Attack Vector: Incorrect Price Oracle
Impact: $1,500,000
Chain: Ethereum

References:

https://x.com/TenArmorAlert/status/1916149115630604341

https://x.com/term_labs/status/1916941405173485897

Unkn_8393f7

Date: April 26, 2025
Attack Vector: Function Parameter Validation
Impact: $34,000
Chain: BSC

References:

https://x.com/TikkalaResearch/status/1916279683093827629

Loopscale

Date: April 26, 2025
Attack Vector: Price Oracle Manipulation
Impact: $5,800,000
Chain: Solana

References:

https://x.com/LoopscaleLabs/status/1916183179469246626

https://x.com/LoopscaleLabs/status/1916230435291713786

https://x.com/greyswan_/status/1916227201067872263

https://www.theblock.co/post/352083/solana-defi-protocol-loopscale-hit-with-5-8-million-exploit-two-weeks-after-launch

Audit:

https://x.com/greyswan_/status/1916227204075180385

Negotiations:

https://x.com/suppvalen/status/1916597817541382564

Unkn_4bbb53

Date: April 27, 2025
Attack Vector: Insufficient Function Access Control
Impact: $1,300
Chain: BSC

References:

https://x.com/TikkalaResearch/status/1916879978878370216

Aventa

Date: April 27, 2025
Attack Vector: Reward Manipulation
Impact: $8,000
Chain: Ethereum

References:

https://x.com/SlowMist_Team/status/1916405508833218995

https://x.com/TikkalaResearch/status/1916884429374701793

LIFE

Date: April 27, 2025
Attack Vector: Price Oracle Manipulation
Impact: $51,000
Chain: BSC

References:

https://x.com/SlowMist_Team/status/1916391258664174045

https://x.com/TenArmorAlert/status/1916312483792408688

https://x.com/TikkalaResearch/status/1916269436035862898