BlockThreat - Week 51, 2025

Yearn | Rari Capital | Futureswap | NX Finance | Biswap | Dragun69

BlockThreat - Week 51, 2025

Greetings!

Roughly $3.7M was stolen this week across eight incidents. The winter holidays remain one of the most dangerous periods for defenders, as attackers intensify their activity while relying on reduced staffing and slower response times.

The most severe incident this week stemmed from a user falling victim to an address poisoning attack, resulting in a $50M loss. While this does not surpass last year’s record $71M WBTC address poisoning hack, successful compromises of this kind continue to incentivize attackers to flood the blockchain with malicious transactions. What’s frustrating is that this class of attack is largely solvable. Wallets and blockchain explorers could defeat most address poisoning attacks with stronger heuristics. What are the odds that a user legitimately interacts with multiple addresses that share similar prefixes and suffixes? We can do better!

The troubling trend of attacks against older contracts also persists. Yearn was compromised yet again, losing $300K due to a misconfiguration exploit, while Rari’s multisig was taken over, allowing attackers to drain approximately $2M.

Let’s dive into the news!

Events

News

Crime

Policy

Phishing

Scams

Malware

Media

Research

Tools

Hacks

NX Finance

Date: December 15, 2025
Attack Vector: Price Oracle Manipulation
Impact: $400,000
Chain: Solana

References:

https://x.com/NX_Finance/status/2000896087360725427
https://x.com/NX_Finance/status/2001976173086306787
https://docs.google.com/spreadsheets/d/1S5Pkp9lvv4rWvHyTEXwUQaW2xXlUZr9SOf_taIqI2C4/edit?gid=0#gid=0

Biswap

Date: December 15, 2025
Attack Vector: JavaScript Injection
Impact: Assets Stolen

References:

https://x.com/certikalert/status/2000695821281485089
https://x.com/CertiKAlert/status/1996750360070049876

RelayAdapt

Date: December 15, 2025
Attack Vector: Misconfiguration
Impact: $108,700
Chain: Ethereum

References:

https://x.com/TenArmorAlert/status/2000753419233931741
https://x.com/Zyy_0530/status/2000823739068678555

Exploit:

https://etherscan.io/tx/0xd86313645241f1bf080d8609ac11442e641a0decc3d2052b69b3431f87c84215
https://etherscan.io/tx/0x8b3c8f0e756705f2b299a75ea6044681a68692b4b693a792e3e420c502b620ed
https://etherscan.io/tx/0x4a87b3a99e60b75b1bf0e7f90c626bda7734997d07e4905cdb7491f89fd05762

Unkn_a59209

Date: December 16, 2025
Attack Vector: Arbitrary External Calls
Impact: Assets Stolen
Chain: BSC

References:

https://x.com/DefimonAlerts/status/2001152276300439729

Exploit:

https://bscscan.com/tx/0x2ac64049ef86b54457e4f99cca9f8c5ef7abd1b1b4c7d9eedc480e93983ad375

Futureswap

Date: December 16, 2025
Attack Vector: Governance
Impact: $830,000
Chain: Ethereum

References:

https://x.com/TenArmorAlert/status/2001116475424133536
https://x.com/hklst4r/status/2001129275739484627
https://x.com/lzhou1110/status/2001148759720272104?s=20
https://x.com/lzhou1110/status/2001157492814839874
https://x.com/blockful_io/status/2001443082307285427

Exploit:

https://etherscan.io/tx/0x39e584cdb52adf6b2ed5bb44bfda0e1b254cb0a3925911cc33d842feaf0a8b95
https://github.com/DK27ss/FutureSwap-270k-PoC

Yearn

Date: December 16, 2025
Attack Vector: Misconfiguration
Impact: $300,000
Chain: Ethereum

References:

https://x.com/PeckShieldAlert/status/2001080131360842011
https://x.com/yearnfi/status/2001094653391614171
https://x.com/hklst4r/status/2001072409684685003
https://github.com/banteg/iearn-2025-12-investigation/blob/master/readme.md
https://github.com/banteg/iearn-2025-12-investigation/blob/master/technical-writeup.md
https://exvulsec.github.io/defi/security/post-mortem/2025/12/16/yeth-exploit-analysis-part-1.html
https://rekt.news/yearn-rekt4

Exploit:

https://etherscan.io/tx/0x78921ce8d0361193b0d34bc76800ef4754ba9151a1837492f17c559f23771c43
https://github.com/banteg/iearn-2025-12-investigation/blob/master/test/IearnExploit.t.sol

Rari Capital

Date: December 18, 2025
Attack Vector: Stolen Private Keys
Impact: $2,000,000
Chain: Ethereum

References:

https://x.com/zmtO21/status/2001585158106026270
https://x.com/heatmovr/status/2002186509454356976

Exploit:

https://etherscan.io/tx/0x53adfab3a15ce75fe4327cd16b7708937948bf758200d1b0e21d30707c406d8e

Dragun69

Date: December 21, 2025
Attack Vector: Reward Manipulation
Impact: $87,400
Chain: BSC

References:

https://x.com/TenArmorAlert/status/2002924740718067845
https://x.com/hklst4r/status/2003003168943219156

Exploit:

https://bscscan.com/tx/0x9f6f0b1fc0e946b58a5fa2ab14cf8c4b3630bba9abd6849bcb3c9b666f59cda7