BlockThreat - Week 2, 2025

Moby | Orange Finance | Unilend | IPC | Mosca | Alienbase | FortuneWheel | WTO

BlockThreat - Week 2, 2025

Greetings!

We’re kicking off the second week of 2025 with nearly a dozen exploits that have collectively netted attackers around $2.7M. Low-TVL, unaudited projects on BSC continue to fall victim to hacks, often losing $10K at a time. However, it’s the two private key compromises that deserve additional discussion—and even a bit of celebration.

On January 8, Moby Trade protocol on Arbitrum suffered a significant breach when an attacker used stolen private keys to upgrade several vaults. Just as the attacker was preparing to drain $2.5M, Tony Ke from SEAL 911 intervened. Exploiting a vulnerability in the attacker’s own unprotected contract, Ke managed to recover nearly $1.5M. While the attacker still escaped with $1M and any funds collected via user approvals, this incident highlights the growing importance of proactive incident response. Whitehats and their bots are increasingly playing a crucial role in mitigating the impact of exploits.

Orange Finance faced a similar attack on the same day. Despite having its upgrade admin account protected by a multisig, a misconfiguration allowed a single compromised key to perform an unauthorized upgrade. The fact that two Arbitrum-based projects were compromised on the same day using the same vector raises questions: coincidence or a coordinated effort?

To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.

This week brings an intriguing collection of research articles, including a Cosmos engineer’s simulation of an alleged exploit linked to the Terra downfall, insights into 0-day vulnerabilities in a popular wallet and a hashing algorithm implementation, and a wealth of audit tips from some of the industry’s top security researchers.

On the phishing front, scammers and wallet security apps are locked in a cat-and-mouse game to outwit transaction simulation mechanisms. One such successful bypass led to a $460K theft from an unfortunate user who didn’t receive adequate warnings.

In other news, the U.S. government arrested operators of Sinbad and Blender, multiple DeFi security companies announced acquisitions, more regulators departed their posts, and the relentless wave of drainers continues to plague the ecosystem.

Let’s dive into the news!

News

Crime

Policy

Phishing

Scams

Malware

Research

Tools

Hacks

Mosca

Date: January 06, 2025
Attack Vector: Reward Manipulation
Impact: $19,000
Chain: BSC

References:

https://x.com/0xNickLFranklin/status/1876884383736430821

https://nickfranklin.site/2025/01/08/mosca-hacked/

https://x.com/SlowMist_Team/status/1876156823637770441

https://x.com/TenArmorAlert/status/1876142779564277971

https://blog.solidityscan.com/mosca-hack-analysis-85485d0e6bb2

https://nickfranklin.site/2025/01/08/mosca-hacked/

Orange Finance

Date: January 07, 2025
Attack Vector: Stolen Private Keys
Impact: $830,000
Chain: Arbitrum

References:

https://x.com/0xOrangeFinance/status/1876863611458801890

https://x.com/0xOrangeFinance/status/1877008796293468274

https://x.com/TenArmorAlert/status/1877236394999034015

https://mirror.xyz/0x6FA2aF9a4d6fFe654361F713780963C10412e7c3/gN17YMrLhKKg9YT9a391U74pWr9IhqBUDWUqDyDamjE

https://rekt.news/orange-finance-rekt/

IPC

Date: January 07, 2025
Attack Vector: Price Oracle Manipulation
Impact: $590,000
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1876663900663370056

https://x.com/CertiKAlert/status/1876838123281223997

HORS

Date: January 08, 2025
Attack Vector:
Impact:
$10,300
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1877032470098428058

WTO

Date: January 08, 2025
Attack Vector: Price Oracle Manipulation
Impact: $24,200
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1877030261067571234

Moby

Date: January 08, 2025
Attack Vector: Stolen Private Keys
Impact: $1,000,000
Chain: Arbitrum

References:

https://x.com/shoucccc/status/1877036766776967459

https://x.com/BeosinAlert/status/1877180521710596452

https://x.com/Moby_trade/status/1877096336140677458

https://x.com/Moby_trade/status/1877157836230373823

https://x.com/TenArmorAlert/status/1877329787078979940

https://rekt.news/mobytrade-rekt/

https://revoke.cash/exploits/moby?chainId=42161

https://medium.com/moby-trade/moby-post-mortem-report-growth-plan-504ad5b0dd35

Whitehat Hack:

https://x.com/tonykebot/status/1877240684266295373

LPMine

Date: January 08, 2025
Attack Vector: Reward Manipulation
Impact: $24,000
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1877030261067571234

AlienBase, BunniHub, Timeless

Date: January 09, 2025
Attack Vector: Insufficient Function Access Control
Impact: $38,000
Chain: Base

References:

https://x.com/TenArmorAlert/status/1877583399050739869

https://x.com/SlowMist_Team/status/1877545774856417400

https://x.com/Phalcon_xyz/status/1877559609776640019

https://x.com/CertiKAlert/status/1877562720205287675

https://x.com/TikkalaResearch/status/1877769482191675554

FortuneWheel

Date: January 10, 2025
Attack Vector: Price Oracle Manipulation
Impact: $21,600
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1877654447540592952

https://x.com/TikkalaResearch/status/1877776767907463222

Unilend

Date: January 12, 2025
Attack Vector: Incorrect Reward Calculation
Impact: $200,000
Chain: Ethereum

References:

https://nickfranklin.site/2025/01/13/unilend-hacked/