BlockThreat - Week 35, 2025

Better Bank | Cozy Finance | Panoptic | Eigenlayer | Whatsapp

BlockThreat - Week 35, 2025

Greetings!

Almost $5.5M was stolen this week across five incidents. Better Bank suffered a $5M exploit that abused a flaw in its reward mechanism when interacting with fake liquidity pools. Cozy Finance lost $427K in a single case by allowing redemptions without properly verifying source addresses.

Beyond the exploits, the week also underscored the resilience of the ecosystem through the efforts of whitehats and bug bounty programs. Panoptic conducted a whitehat rescue with support from Cantina and SEAL911, while Eigenlayer deployed an emergency patch after a critical bug was disclosed via Immunefi.

On the phishing front, we saw early signs of emerging attack vectors as wallets begin integrating with social media apps and agentic browsers. These trends will open new avenues for exploitation, but also give defenders a chance to start preparing countermeasures today.

A special thanks to this week’s sponsor Coinspect.


Coinspect’s Wallet Security Ranking is an objective, transparent, and regularly updated evaluation of leading cryptocurrency wallets. It focuses on critical security features like anti-phishing defenses, transaction clarity, and protection against blind signing, helping users choose wallets that prioritize their safety.

Link: https://www.coinspect.com/wallets/

Let’s dive into the news!

News

Crime

Policy

Phishing

Scams

Malware

Media

Research

Tools

  • Web3 Vulnerabilities Repository by Lyuboslav Lyubenov. A comprehensive collection of clustered smart contract vulnerabilities discovered through security audits, organized by severity and frequency of occurrence. 29k+ unique vulnerabilities across 461 clusters ranked by frequency of occurence.
  • Hound by Bernhard Mueller is a a security audit automation pipeline for AI-assisted code review that mirrors how expert auditors think, learn, and collaborate. See Unleashing the Hound: How AI Agents Find Deep Logic Bugs in Any Codebase for additional details.
  • ScaBench: Smart Contract Audit Benchmark by Bernhard Mueller. A comprehensive framework for evaluating security analysis tools and AI agents on real-world smart contract vulnerabilities. ScaBench provides curated datasets from recent audits and official tooling for consistent evaluation.
  • EvmCast - Foundry Cast in your browser. Execute blockchain commands, query contracts, and interact with EVM networks directly from a web terminal.
  • Osiris Lite by Enigma Dark is a clean, plug and play CLI tool for managing remote fuzzing jobs. More details here.
  • Halmos Log Parser automatically convert Halmos Tests into Foundry Repros.
  • Solana Indexer CLI - A powerful command-line tool for real-time Solana blockchain monitoring, account tracking, and data indexing with advanced caching and gRPC streaming capabilities by senzenn.
  • EvmTools - essential blockchain development tools for Ethereum and EVM-compatible networks.

Hacks

Better Bank

Date: August 26, 2025
Attack Vector: Reward Manipulation
Impact: $5,000,000 (Recovered $2,700,000)
Chain: Pulse

References:

https://x.com/CertiKAlert/status/1960512848171557018
https://x.com/shoucccc/status/1960534610485633369
https://x.com/CertiKAlert/status/1960693173589569978
https://x.com/BetterBank_io/status/1960409389627793474 https://x.com/BetterBank_io/status/1960661185226744109
https://rekt.news/betterbank-rekt

Exploit:

https://otter.pulsechain.com/tx/0x9c7237a00fa276c5f10ca1c61d6821869a7fdcd1ade8059729cdc35c9ff7689a

Unkn_f340bd

Date: August 27, 2025
Attack Vector: Insufficient Function Access Control
Impact: $4,000
Chain: Ethereum

References:

https://t.me/defimon_alerts/1733

Exploit:

https://etherscan.io/tx/0x103b4550a1a2bdb73e3cb5ea484880cd8bed7e4842ecdd18ed81bf67ed19e03c
https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2025-08/0xf340_exp.sol

Cozy Finance

Date: August 29, 2025
Attack Vector: Insufficient Function Access Control
Impact: $427,000
Chain: Optimism

References:

https://x.com/DecurityHQ/status/1961810726164533602

Exploit:

https://optimistic.etherscan.io/tx/0x71e72cae2149920bc89ae3287edf8c7e65d454d7fd5e24b590c1b4ea36c0a517
https://optimistic.etherscan.io/tx/0x454470871cdf3ad782bc4f89c5e7c4d596d54d2f9c2c3490728cbfcd3a851933

Hexotic

Date: August 31, 2025
Attack Vector: Function Parameter Validation
Impact: $500
Chain: Ethereum

References:

https://t.me/defimon_alerts/1757

Exploit:

https://etherscan.io/tx/0x23b69bef57656f493548a5373300f7557777f352ade8131353ff87a1b27e2bb3
https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2025-08/Hexotic_exp.sol