BlockThreat - Week 3, 2025

Sony | UniLend | The Idols NFT | PIKA | BIGO | GraFun

BlockThreat - Week 3, 2025

Greetings!

This week saw a handful of hacks totaling just under $700K in losses. A notable trend is emerging in on-chain exploitation: the BSC chain has essentially become a hunting ground for bad actors targeting small TVL projects. These attackers even send messages congratulating one another for being the first to discover and exploit vulnerabilities.

Despite this trend, the majority of losses still originate from the Ethereum mainnet, which continues to attract serial exploiters. For example, the $200K UniLend hack not only caused significant damage but also inspired several copycat attacks.

In other news, Sony experienced a hard lesson in decentralization. Their attempt to censor tokens and transactions on their sequencer backfired when it became evident that transactions could still be submitted directly through L1.

Oh and be sure to check out a great new podcast for bug hunters in the Media section below. Let’s dive into the news!

News

Crime

Policy

Phishing

Malware

Research

Media

  • Bountyhunt3rz Podcast - Episode 2 - 100proof. riptide & 100proof discuss bounty negotiation tactics, human behavior, incentives, acting in good faith, and why bounty hunters must be paid. 100proof treats listeners to a detailed walkthrough of a juicy bug he found in Morpho.
  • Bountyhunt3rz Podcast - Episode 1 - deadrosesxyz. riptide & deadrosesxyz discuss hunting for bugs on the blockchain including techniques, secrets and tools of the trade, integrating LLMs into your workflow, getting paid, traits of a bounty hunter, and how bulgarian teenagers are taking over the space

Tools

Hacks

UniLend

Date: January 13, 2025
Attack Vector: Price Oracle Manipulation
Impact: $197,000
Chain: Ethereum

References:

https://x.com/SlowMist_Team/status/1878651772375572573

https://nickfranklin.site/2025/01/13/unilend-hacked/

https://x.com/theRaz0r/status/1881737256773538066

https://blog.solidityscan.com/unilend-finance-hack-analysis-5ac7bb71850d

https://slowmist.medium.com/analysis-of-the-unilend-hack-90022fa35a54

https://medium.com/coinmonks/how-a-200k-exploit-unfolded-at-unilend-04fb4918292d

https://x.com/UniLend_Finance/status/1878805205254340844

PIKA

Date: January 13, 2025
Attack Vector: Price Oracle Manipulation
Impact: $44,700
Chain: BSC

References:

https://x.com/TenArmorAlert/status/1878823497155461399

The Idols NFT

Date: January 14, 2025
Attack Vector: Logic Error
Impact: $340,000
Chain: Ethereum

References:

https://x.com/Phalcon_xyz/status/1879368962539917681

https://x.com/TheIdolsNFT/status/1879256089784635690

https://blog.solidityscan.com/the-idols-nft-hack-analysis-95f3abdd0deb

https://rekt.news/theidolsnft-rekt/

BIGO

Date: January 14, 2025
Attack Vector: Reward Manipulation
Impact: $18,000
Chain: BSC

References:

https://x.com/0xNickLFranklin/status/1879168885800493438

https://nickfranklin.site/2025/01/14/bigo-token-exploit/

GraFun

Date: January 16, 2025
Attack Vector: Reentrancy
Impact: $100,000
Chain: BSC

References:

https://x.com/certikalert/status/1880103898574385670

https://x.com/TenArmorAlert/status/1880079258267050334