BlockThreat - Week 37, 2025

SwissBorg, Kiln, NPM, Yala, ThorSwap, Evoq, Request, Shibarium, Kame, Degen

BlockThreat - Week 37, 2025

Greetings!

This week was a bloodbath. More than $57.5M was stolen across nine incidents with breached custodial staking providers, hacked frontends, backdoored supply chains, phished of individuals, chain reorged, bridges exploited, and plenty of DeFi protocol drained. All elements of our ecosystem were hit in one of the worst weeks this year.

But one exploit in particular could have caused losses in the billions were it not for an early discovery by the community. An NPM supply chain attack that compromised several extremely popular packages (billions of downloads per week) allowed attackers to inject a backdoor designed to drain users’ wallets. By sheer luck and plenty of onchain mockery the attack was detected early enough and community mobilized which left attackers with under $1k in profit from what could easily have been a Safe/Bybit-scale exploit. The biggest takeaway is that they will be back. So please implement proper package freezing and review into your dev pipelines.

Speaking of near catastrophes, the massive $41.5M Kiln/SwissBorg compromise is a stark reminder of the risks of trusting a third-party managed treasury or staking provider. In general, it’s sensible to let professional teams manage assets; however, it does not absolve one of prudent monitoring and in depth discussions about what security controls can be added to minimize risk. Since the incident, Kiln initiated an exit of all of its Ethereum validators.

Another interesting exploit this week was the Yala LayerZero OFT bridge hijack, which took advantage of a temporary deployment that used a known “local key.” Attackers raced to configure a recently deployed bridge on Solana to a malicious OFT contract on Polygon and started minting legitimate $YU tokens.

The last but not least, mass bridge compromises are back with the $3M Shibarium Bridge hack. One positive outcome was that a large portion of the attackers’ funds were blacklisted or locked out. However, how do you compromise 10(!) of 12 signer keys unless they’re stored and managed in the same place defeating the whole point?

Amid all these stories of hacks, it’s worth highlighting the unsung heroes and sponsors of this week’s edition - ChainPatrol. The good folks at ChainPatrol are doing simply amazing work protecting protocols’ brands, fighting the barrage of X phishing attacks, and quickly taking down scammers before they can do real damage.



Let’s dive into the news!

News

Crime

Policy

Phishing

Scams

Malware

Media

Research

Tools

Hacks

Kiln, SwissBorg

Date: September 08, 2025
Attack Vector: API Key Theft
Impact: $41,500,000
Chain: Solana

References:

https://x.com/SolanaFloor/status/1965116689907089782
https://x.com/swissborg/status/1965123506477359471
https://x.com/CertiKAlert/status/1965122507687755803
https://x.com/shoucccc/status/1965126091334713838
https://swissborg.com/blog/joint-statement-kiln-x-swissborg-regarding-sol-incident
https://www.kiln.fi/post/kiln-responds-to-infrastructure-issue-with-validator-exit-funds-remain-protected
https://protos.com/swissborg-ceo-blames-41m-loss-on-staking-partner-kiln/
https://www.theblock.co/post/370141/kiln-exits-ethereum-validators
https://rekt.news/swissborg-rekt

NPM Phishing

Date: September 08, 2025
Attack Vector:
Impact:
$66

References:

https://x.com/SlowMist_Team/status/1965236512448282713
https://x.com/CertiKAlert/status/1965235082823958620
https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
https://www.securityalliance.org/news/2025-09-npm-supply-chain
https://krebsonsecurity.com/2025/09/18-popular-code-packages-hacked-rigged-to-steal-crypto/
https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack
https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
https://slowmist.medium.com/threat-intelligence-analysis-of-the-large-scale-npm-package-poisoning-incident-7c806ab4e202

Evoq Finance

Date: September 09, 2025
Attack Vector: Key/Signer Compromise
Impact: $420,000
Chain: BSC

References:

https://x.com/Evoq_Finance/status/1965691948939014408
https://x.com/GoPlusSecurity/status/1965805930504974515

Request Finance

Date: September 10, 2025
Attack Vector: Multisig Hijacking
Impact: $3,047,000
Chain: Ethereum

References:

https://x.com/realScamSniffer/status/1966389479016677873
https://x.com/RequestFinance/status/1966414484962160741
https://help.request.finance/en/articles/12275459-incident-report-september-10th-isolated-frontend-compromise-now-contained
https://drive.google.com/file/d/19UujuD3r8UDu6LWr4uB9eNvZc_T9SO_V/view

Degen Token

Date: September 11, 2025
Attack Vector: Key/Signer Compromise
Impact: $500,000
Chain: Base

References:

https://x.com/degentokenbase/status/1966420300205089035

Rescue:

https://x.com/pcaversaccio/status/1966441193941737632
https://basescan.org/tx/0x344237ab211385caa2db08a9bb20a012bf0c0c0c4c6919005dd28fb18d08625a

Shibarium, Shibarium Bridge

Date: September 12, 2025
Attack Vector: Key/Signer Compromise
Impact: $3,000,000
Chain: Shibarium, Polygon, Solana

References:

https://x.com/TikkalaResearch/status/1966610862149665126
https://x.com/0xZilayo/status/1966785029968724351
https://x.com/kaaldhairya/status/1966758608940515671
https://x.com/Shibizens/status/1966765953888198702
https://protos.com/on-chain-ransom-negotiations-show-shibaswap-hacker-wont-be-low-balled/
https://x.com/0xdefiturtle/status/1966590028621975845
https://rekt.news/shibarium-rekt

Attribution:

https://x.com/Whistleblowe007/status/1968481833672167587

Kame

Date: September 13, 2025
Attack Vector: Arbitrary External Calls
Impact: $1,320,000 (Recovered $946,000)
Chain: Sei

References:

https://x.com/SuplabsYi/status/1966894700310524088
https://x.com/kame_agg/status/1966673964484489378
https://x.com/kame_agg/status/1966765239275581759
https://kameagg.substack.com/p/post-mortem-kame-aggregator-exploit

Unkn_D9f4a3

Date: September 13, 2025
Attack Vector: Insufficient Function Access Control
Impact: $90,000
Chain: Base

References:

https://x.com/Phalcon_xyz/status/1967090244349841676
https://x.com/shoucccc/status/1966993289212817518

Yala

Date: September 14, 2025
Attack Vector: Misconfiguration
Impact: $7,640,000

References:

https://x.com/yalaorg/status/1967071910845649348
https://x.com/yalaorg/status/1968026376491110701
https://x.com/lookonchain/status/1967181490510520581
https://x.com/yalaorg/status/1967160350362542242
https://blog.yala.org/yala-post-mortem-september-14/