BlockThreat - Week 43, 2025

Doodi Pals | Sharwa Finance | LuckyCode | ETH Strategy | Zap

BlockThreat - Week 43, 2025

Greetings!

A relatively quiet week with under $1 million in losses is a welcome relief. Weeks like these often keep me up at night as calm often precedes big events, so let us hope that pattern does not repeat. To help you enjoy the lull, I have assembled a curated collection of research, with a focus on off-chain and multisig security, interviews with industry leaders, and the latest entries in the criminal chronicles.

Paid subscribers will get the deep dives on the price oracle exploit at Sharwa Finance, the key compromise at Doodi Pals, and other incidents. I am also tracking an attacker probing older contracts across multiple chains, which has pulled a handful of five-figure wins here and there.

Let’s dive into the news!

Events

  • Ultimate Security Games by RareSkills. November 20, 2025. The Ultimate Security Games brings the world of smart contract auditing to the main stage turning web3 security into an esport.

News

Crime

Phishing

Scams

Malware

Media

Research

Tools

  • Ethereum Context Copilot - a purpose trained LLM on all aspects of Ethereum code, operations, bugs, etc.
  • Local Safe by Patrick Collins. A completely local version of Safe UI.
  • Solana VS Code Extension - security-focused development tools by Ackee.
  • Jetstreamer - a high-throughput Solana backfilling and research toolkit designed to stream historical chain data live over the network from Project Yellowstone’s Old Faithful archive, which is a comprehensive open source archive of all Solana blocks and transactions from genesis to the current tip of the chain.

Hacks

Sharwa Finance

Date: October 20, 2025
Attack Vector: Price Oracle Manipulation
Impact: $147,000 (Recovered $40,000)
Chain: Arbitrum

References:

https://x.com/DecurityHQ/status/1980159991991738793
https://x.com/Phalcon_xyz/status/1980220633335349598
https://x.com/SharwaFinance/status/1980152746373238990
https://x.com/sharwafinance/status/1980535243875463639
https://x.com/hklst4r/status/1980157251550670992

Reappeared bug:

https://x.com/DecurityHQ/status/1980211713870811213
https://github.com/pashov/audits/blob/master/team/pdf/SharwaFinance-security-review.pdf

Recovery:

https://x.com/De_FiSecurity/status/1981742701528670610

Doodi Pals

Date: October 20, 2025
Attack Vector: Key/Signer Compromise
Impact: $171,000
Chain: Solana

References:

https://x.com/evilcos/status/1980443998461608427
https://x.com/DoodiPals/status/1980286066201600109
https://x.com/DoodiPals/status/1980547087390392409

Zap

Date: October 24, 2025
Attack Vector:
Impact:
$16,804
Chain: Base

References:

https://x.com/DefimonAlerts/status/1981655692957335627

Unkn_2cc409

Date: October 24, 2025
Attack Vector:
Impact:
$28,760
Chain: Base

References:

https://x.com/DefimonAlerts/status/1981659673452491002

LuckyCode

Date: October 24, 2025
Attack Vector: Bad Randomness
Impact: $56,000
Chain: Ethereum

References:

https://x.com/DefimonAlerts/status/1981671353674846591

Unkn_D9f4a3

Date: October 24, 2025
Attack Vector:
Impact:
$7,671
Chain: Base

References:

https://x.com/DefimonAlerts/status/1981722712637911417

ETH Strategy

Date: October 24, 2025
Attack Vector: Insufficient Function Access Control
Impact: $31,544
Chain: Ethereum

References:

https://x.com/DefimonAlerts/status/1981670261352230929
https://www.notion.so/Post-Incident-Review-Redemption-Facilitator-Contract-1-29643c3c083480a282c5eab8c4bf21b3