BlockThreat - Week 4, 2025
Phemex | NoOnes | AdsPower | Paribus | Thetanuts | Odos | AST | BPL | Bebop
Greetings!
We’ve been dreading weeks like this for a while. Nearly $100 million stolen across 10 attacks—a brutal reminder of the relentless pace of crypto exploits. Multiple hot wallet compromises, wallet supply chain attacks, and an exhausting number of price oracle exploits. Let’s start with the worst hack of the year.
The Phemex Heist: A Masterclass in Coordination
Alarm bells rang on January 23rd at 11:55 AM UTC when PeckShield detected large outflows—one token after another—on Ethereum, all within seconds. As the Ethereum drains unfolded, Solana, Bitcoin, Sui, Ripple, and others were hit just minutes later. In total, 16 blockchains were drained in parallel, a staggering display of coordination that pointed to a well-prepared, professional actor.

Then came the laundering—executed with the same speed and precision as the exploit itself. The attacker rapidly hopped between chains, swapping and obfuscating assets, prioritizing the liquidation of freezable tokens first.
Kudos to Phemex for maintaining transparency throughout the incident—an approach that will help elevate industry security standards. Two key timestamps from the preliminary report stand out:
• The attack was detected 25 minutes before draining began at 11:30 AM UTC.
• Deposits and withdrawals were halted at 3:13 PM UTC.
That’s 25 minutes to assemble a war room, triage the incident, assess severity, and initiate containment—longer than the average 15-minute response time for most DeFi projects, yet still not enough. It’s frustrating, but I hope Phemex rebuilds and fortifies their security program to better protect their hot wallets in the future.
As for threat actor attribution, only North Korean-linked groups have executed such a coordinated and devastating attack in the past. But we’ll need more data points to confirm.
More Hacks & A Glimmer of Hope
There were many more incidents this week—details of which you’ll find in the premium section—including:
• $8M NoOnes hot wallet hack
• $4.7M AdsPower wallet supply chain attack
• A clever Odos exploit
• …and many others.
But I want to leave you on a more positive note.
Deep inside the dark forest of blockchain security, it’s not just the predators who lurk. The good guys are there too—turning the same techniques against careless attackers.
On January 18th, Bitfinding, a group specializing in intercepting hacks in progress, noticed storm clouds forming over Paribus on Arbitrum. Without hesitation, they deployed an exploit in just 3.2 seconds—executing a white-hat attack to safeguard funds until their rightful owners could reclaim them.

A rare win in the battle for blockchain security. Hats off to the heroes! Maybe there’s still hope for the future of intrusion prevention after all.
To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.
Let’s dive into the news!
News
- Kidnapped co-founder of Ledger released as French police hunt for perpetrators. Interestingly kidnappers accepted ransom in USDT which was quickly frozen with the help of SEAL 911.
- Trump Frees Silk Road Creator Ross Ulbricht After 11 Years in Prison. Ross may still have access to $47M worth of BTC not seized from the Silk Road.
- ZachXBT's address cashes out nearly $4 million on memecoin.
- ThorChain paused lending and savers withdrawals due to failed design.
- Web3 Hack Postmortem 2024 by ChainLight. A detailed look at major security incidents in the past year, post-incident responses, money laundering, and other critical lessons.
- Remedy CTF 2025 is over. Congratulations Chainlight, A-Team, and Kimchi Premium!
Crime
- Understanding the Use of Cryptocurrencies By Cartels by TRM.
- Crypto market maker CLS Global admits to wash trading on Uniswap after FBI investigation.
- US Sentences Indian Man For Laundering Cryptocurrency Worth $20 Million.
Policy
- OFAC ‘overstepped’ on Tornado Cash sanctions, court orders reversal.
- Unpacking Trump's Executive Order on Digital Financial Technology by TRM.
Phishing
- Analysis of Web3 Phishing Techniques by SlowMist.
- Blockchain Sleuth ZachXBT Uncovers $29 Million SUI Token Exploit.
- Nasdaq’s official X account was seemingly hacked to promote a fake memecoin.
Scams
- Crypto Mining Scams: A Multi-Billion Industry.
- Trump Casino by Rekt.
- The pastor who gave the benediction at Trump’s inauguration just launched his own memecoin.
Malware
Media
- Learn how to debug bytecode with huff and forge! by libevm.
- Solidity Development with Foundry: Cast, Anvil, Chisel, and Forge by Ethereum Engineering Group.
Research
- DeFi Liquidation Vulnerabilities by Dacian.
- What is a Smart Contract Audit: Lessons from OpenZeppelin’s 1000+ Audits.
- OWASP Smart Contract Top 10.
- Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform by hackermondev.
- Solana: Signature Verification Flow (Part-1) by BountyHunt3r.
- Learn Yul by andreitoma8.
- Yul Puzzles by RareSkills.
- Reduce The Risk of Cyber Attacks: Isolated Dev Environments by Patrick Collins (Cyfrin).
- BotDetect: A Decentralized Federated Learning Framework for Detecting Financial Bots on the EVM Blockchains.
- Formal Model Guided Conformance Testing for Blockchains.
- BRC20 Snipping Attack.
- Blockchain Security Risk Assessment in Quantum Era, Migration Strategies and Proactive Defense.
- Mapping the DeFi crime landscape: an evidence-based picture.
- Using slither to identify contract entry points by nisedo.
- Bug bounty hunter mindset by Daniel Von Fange. Focus on the “impact”.
- Ethereum Validator Lifecycle: A Deep Dive by Sergey Boogerwooger, Dmitry Zakharov.
Hacks
Paribus
Date: January 20, 2025
Attack Vector: Price Oracle Manipulation
Impact: $86,000 (Recovered $86,000)
Chain: Arbitrum
References:
https://bitfinding.com/blog/paribus-hack-interception
https://x.com/BitFinding/status/1882880682512527516
https://x.com/paribus_io/status/1881423579625271472
Exploit:
https://arbiscan.io/tx/0xf5e753d3da60db214f2261343c1e1bc46e674d2fa4b7a953eaf3c52123aeebd2
https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2025-01/Paribus_exp.sol
AdsPower
Date: January 21, 2025
Attack Vector: Supply Chain
Impact: $4,700,000
References:
https://x.com/AdsPowerBrowser/status/1882983731419570220
https://x.com/exvulsec/status/1883029289278546008
https://x.com/AdsPowerBrowser/status/1883016162617016670
Exploit:
Base Price Pool
Date: January 21, 2025
Attack Vector: Price Oracle Manipulation
Impact: $23,000
Chain: BSC
References:
https://x.com/TikkalaResearch/status/1881819155923620308
https://x.com/TenArmorAlert/status/1881710739477446670
Exploit:
https://bscscan.com/tx/0x4f7a403b8e8fda312ffcfb86384005dfd280a219076b03aeabe9caa425ee9a26
https://bscscan.com/tx/0xe7bf0e2f9c824b3112b836780c3dba3395fa1eac6af2d38f84b9d088162f188e
AST
Date: January 21, 2025
Attack Vector: Logic Error
Impact: $65,000
Chain: BSC
References:
https://x.com/SlowMist_Team/status/1881874569042317610
https://x.com/TenArmorAlert/status/1881740709843079629
https://nickfranklin.site/2025/01/22/ast-token-hacked/
https://blog.solidityscan.com/ast-token-hack-analysis-7a2f0400436a
Exploit:
https://bscscan.com/tx/0x80dd9362d211722b578af72d551f0a68e0dc1b1e077805353970b2f65e793927
Thetanuts Finance
Date: January 21, 2025
Attack Vector: Function Parameter Validation
Impact: $125,300
Chain: Base
References:
https://x.com/TenArmorAlert/status/1881919586930422034https://x.com/CertiKAlert/status/1881941856264855973https://x.com/ThetanutsFi/status/1881970929812832556
Exploit:
https://basescan.org/tx/0x521b19706d414473c55052b71d037cc546546e9863c2a7566f0313205983397a
Bebop
Date: January 22, 2025
Attack Vector: Insufficient Function Access Control
Impact: $4,000
Chain: Ethereum
References:
https://x.com/TikkalaResearch/status/1882136981217640941
Exploit:
https://etherscan.io/tx/0x6dc1412ef2f711f28442b9b4bc2769425a3f92dbb8cac84af8377e779c763980
Unkn_c8b9
Date: January 22, 2025
Attack Vector: Uninitialized Contract
Impact: Assets Stolen
Chain: BSC
References:
https://x.com/TikkalaResearch/status/1882134209009185106
Exploit:
https://bscscan.com/tx/0x9b04d02861b3f0f21238c566d930e36774538066a10527166367d4a602284e3d
Phemex
Date: January 23, 2025
Attack Vector: Hot Wallet Compromise
Impact: $85,000,000
References:
https://x.com/kaiphemex/status/1882416271536595044
https://x.com/tayvano_/status/1883711887256485915
https://phemex.com/announcements/phemex-hot-wallet-security-incident-update-and-timeline
https://x.com/PeckShieldAlert/status/1882776555312869830
https://rekt.news/phemex-rekt/
Odos
Date: January 23, 2025
Attack Vector: Function Parameter Validation
Impact: $98,000
Chain: Base, Ethereum, BSC, Optimism, Avalanche
References:
https://x.com/Phalcon_xyz/status/1882630151583981787
https://x.com/TenArmorAlert/status/1882623431167934611
https://x.com/SlowMist_Team/status/1882634308067934264
https://x.com/TikkalaResearch/status/1882508654278234198
https://nickfranklin.site/2025/01/24/odos-router-hacked/
https://x.com/odosprotocol/status/1882668362045821146
https://x.com/milotruck/status/1882881352581906635
Exploit:
https://basescan.org/tx/0xd10faa5b33ddb501b1dc6430896c966048271f2510ff9ed681dd6d510c5df9f6
NoOnes
Date: January 24, 2025
Attack Vector: Hot Wallet Compromise
Impact: $8,000,000
Chain: Ethereum, Tron, Solana, BSC
References:
https://t.me/investigations/202