BlockThreat - Week 4, 2025

Phemex | NoOnes | AdsPower | Paribus | Thetanuts | Odos | AST | BPL | Bebop

BlockThreat - Week 4, 2025

Greetings!

We’ve been dreading weeks like this for a while. Nearly $100 million stolen across 10 attacks—a brutal reminder of the relentless pace of crypto exploits. Multiple hot wallet compromises, wallet supply chain attacks, and an exhausting number of price oracle exploits. Let’s start with the worst hack of the year.

The Phemex Heist: A Masterclass in Coordination

Alarm bells rang on January 23rd at 11:55 AM UTC when PeckShield detected large outflows—one token after another—on Ethereum, all within seconds. As the Ethereum drains unfolded, Solana, Bitcoin, Sui, Ripple, and others were hit just minutes later. In total, 16 blockchains were drained in parallel, a staggering display of coordination that pointed to a well-prepared, professional actor.

Then came the laundering—executed with the same speed and precision as the exploit itself. The attacker rapidly hopped between chains, swapping and obfuscating assets, prioritizing the liquidation of freezable tokens first.

Kudos to Phemex for maintaining transparency throughout the incident—an approach that will help elevate industry security standards. Two key timestamps from the preliminary report stand out:

• The attack was detected 25 minutes before draining began at 11:30 AM UTC.

• Deposits and withdrawals were halted at 3:13 PM UTC.

That’s 25 minutes to assemble a war room, triage the incident, assess severity, and initiate containment—longer than the average 15-minute response time for most DeFi projects, yet still not enough. It’s frustrating, but I hope Phemex rebuilds and fortifies their security program to better protect their hot wallets in the future.

As for threat actor attribution, only North Korean-linked groups have executed such a coordinated and devastating attack in the past. But we’ll need more data points to confirm.

More Hacks & A Glimmer of Hope

There were many more incidents this week—details of which you’ll find in the premium section—including:

• $8M NoOnes hot wallet hack

• $4.7M AdsPower wallet supply chain attack

• A clever Odos exploit

• …and many others.

But I want to leave you on a more positive note.

Deep inside the dark forest of blockchain security, it’s not just the predators who lurk. The good guys are there too—turning the same techniques against careless attackers.

On January 18th, Bitfinding, a group specializing in intercepting hacks in progress, noticed storm clouds forming over Paribus on Arbitrum. Without hesitation, they deployed an exploit in just 3.2 seconds—executing a white-hat attack to safeguard funds until their rightful owners could reclaim them.

A rare win in the battle for blockchain security. Hats off to the heroes! Maybe there’s still hope for the future of intrusion prevention after all.

To gain access to comprehensive vulnerability write-ups, post-mortems, exploit proof of concepts (PoCs), attacker addresses, and additional data regarding this week’s compromises, please subscribe to the premium plan below.

Let’s dive into the news!

News

Crime

Policy

Phishing

Scams

Malware

Media

Research

Hacks

Paribus

Date: January 20, 2025
Attack Vector: Price Oracle Manipulation
Impact: $86,000 (Recovered $86,000)
Chain: Arbitrum

References:

https://bitfinding.com/blog/paribus-hack-interception

https://x.com/BitFinding/status/1882880682512527516

https://x.com/paribus_io/status/1881423579625271472

Exploit:

https://arbiscan.io/tx/0xf5e753d3da60db214f2261343c1e1bc46e674d2fa4b7a953eaf3c52123aeebd2

https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2025-01/Paribus_exp.sol

AdsPower

Date: January 21, 2025
Attack Vector: Supply Chain
Impact: $4,700,000

References:

https://x.com/AdsPowerBrowser/status/1882983731419570220

https://x.com/exvulsec/status/1883029289278546008

https://x.com/AdsPowerBrowser/status/1883016162617016670

Exploit:

Base Price Pool

Date: January 21, 2025
Attack Vector: Price Oracle Manipulation
Impact: $23,000
Chain: BSC

References:

https://x.com/TikkalaResearch/status/1881819155923620308

https://x.com/TenArmorAlert/status/1881710739477446670

Exploit:

https://bscscan.com/tx/0x4f7a403b8e8fda312ffcfb86384005dfd280a219076b03aeabe9caa425ee9a26

https://bscscan.com/tx/0xe7bf0e2f9c824b3112b836780c3dba3395fa1eac6af2d38f84b9d088162f188e

AST

Date: January 21, 2025
Attack Vector: Logic Error
Impact: $65,000
Chain: BSC

References:

https://x.com/SlowMist_Team/status/1881874569042317610

https://x.com/TenArmorAlert/status/1881740709843079629

https://nickfranklin.site/2025/01/22/ast-token-hacked/

https://blog.solidityscan.com/ast-token-hack-analysis-7a2f0400436a

Exploit:

https://bscscan.com/tx/0x80dd9362d211722b578af72d551f0a68e0dc1b1e077805353970b2f65e793927

Thetanuts Finance

Date: January 21, 2025
Attack Vector: Function Parameter Validation
Impact: $125,300
Chain: Base

References:

https://x.com/TenArmorAlert/status/1881919586930422034https://x.com/CertiKAlert/status/1881941856264855973https://x.com/ThetanutsFi/status/1881970929812832556

Exploit:

https://basescan.org/tx/0x521b19706d414473c55052b71d037cc546546e9863c2a7566f0313205983397a

Bebop

Date: January 22, 2025
Attack Vector: Insufficient Function Access Control
Impact: $4,000
Chain: Ethereum

References:

https://x.com/TikkalaResearch/status/1882136981217640941

Exploit:

https://etherscan.io/tx/0x6dc1412ef2f711f28442b9b4bc2769425a3f92dbb8cac84af8377e779c763980

Unkn_c8b9

Date: January 22, 2025
Attack Vector: Uninitialized Contract
Impact: Assets Stolen
Chain: BSC

References:

https://x.com/TikkalaResearch/status/1882134209009185106

Exploit:

https://bscscan.com/tx/0x9b04d02861b3f0f21238c566d930e36774538066a10527166367d4a602284e3d

Phemex

Date: January 23, 2025
Attack Vector: Hot Wallet Compromise
Impact: $85,000,000

References:

https://x.com/kaiphemex/status/1882416271536595044

https://www.bleepingcomputer.com/news/security/hackers-steal-85-million-worth-of-cryptocurrency-from-phemex/

https://x.com/tayvano_/status/1883711887256485915

https://phemex.com/announcements/phemex-hot-wallet-security-incident-update-and-timeline

https://x.com/PeckShieldAlert/status/1882776555312869830

https://rekt.news/phemex-rekt/

https://www.theblock.co/post/336754/north-korea-hack-group-possibly-behind-70-million-phemex-exploit-experts-say

Odos

Date: January 23, 2025
Attack Vector: Function Parameter Validation
Impact: $98,000
Chain: Base, Ethereum, BSC, Optimism, Avalanche

References:

https://x.com/Phalcon_xyz/status/1882630151583981787

https://x.com/TenArmorAlert/status/1882623431167934611

https://x.com/SlowMist_Team/status/1882634308067934264

https://x.com/TikkalaResearch/status/1882508654278234198

https://nickfranklin.site/2025/01/24/odos-router-hacked/

https://x.com/odosprotocol/status/1882668362045821146

https://x.com/milotruck/status/1882881352581906635

Exploit:

https://basescan.org/tx/0xd10faa5b33ddb501b1dc6430896c966048271f2510ff9ed681dd6d510c5df9f6

NoOnes

Date: January 24, 2025
Attack Vector: Hot Wallet Compromise
Impact: $8,000,000
Chain: Ethereum, Tron, Solana, BSC

References:

https://t.me/investigations/202

https://x.com/tayvano_/status/1882715603196346486

https://www.theblock.co/post/337004/noones-ceo-ray-youssef-8-million-exploit-crypto-sleuth-zachxbt-investigation