BTC $82,928.53 -0.56%
ETH $2,655.51 +0.14%
BNB $755.32 -2.12%
XRP $1.48 -1.67%
SOL $116.90 -2.81%
TRX $0.3343 +0.27%
DOGE $0.0922 -2.89%
ADA $0.2404 -4.55%
BCH $303.43 -3.50%
LINK $15.00 +6.12%
HYPE $86.37 -4.28%
AAVE $146.63 -3.29%
SUI $1.10 -11.12%
XLM $0.2247 +4.84%
ZEC $1,376.66 -12.27%
AAPL $337.86 -0.71%
AMZN $246.26 -0.96%
GOOGL $342.17 +0.07%
MSFT $508.56 -1.57%
META $716.37 -2.38%
NVDA $228.46 +1.95%
TSLA $357.28 -3.47%
SNDK $1,698.78 -2.08%
INTC $114.25 -4.31%
SPCX $145.76 -2.14%
MU $1,050.54 -1.39%
AMD $606.59 -1.95%
BTC $82,928.53 -0.56%
ETH $2,655.51 +0.14%
BNB $755.32 -2.12%
XRP $1.48 -1.67%
SOL $116.90 -2.81%
TRX $0.3343 +0.27%
DOGE $0.0922 -2.89%
ADA $0.2404 -4.55%
BCH $303.43 -3.50%
LINK $15.00 +6.12%
HYPE $86.37 -4.28%
AAVE $146.63 -3.29%
SUI $1.10 -11.12%
XLM $0.2247 +4.84%
ZEC $1,376.66 -12.27%
AAPL $337.86 -0.71%
AMZN $246.26 -0.96%
GOOGL $342.17 +0.07%
MSFT $508.56 -1.57%
META $716.37 -2.38%
NVDA $228.46 +1.95%
TSLA $357.28 -3.47%
SNDK $1,698.78 -2.08%
INTC $114.25 -4.31%
SPCX $145.76 -2.14%
MU $1,050.54 -1.39%
AMD $606.59 -1.95%

xpos

All
Article
Flash

first_img Cross-chain trading platform Relay API exposes pending transactions, which will compensate approximately $312,000

Co-founder and Chief Operating Officer of the cross-chain trading platform Relay, Jason Maier, stated that the team discovered an issue with the Relay API over the weekend, which exposed pending transaction information before trade execution. MEV seekers exploited the pending routing status to infer on-chain paths and front-run trades before order execution, resulting in worse execution prices for users trading through Relay.This activity occurred from September 12 to September 26, primarily concentrated from September 23 to 26. Seekers profited approximately $136,000 from this, affecting around 5,600 users, with a median impact of $11.88. Relay will pay a $50,000 bounty to Outputlayer for reporting the issue and will automatically compensate affected users without the need for applications; funds will be directly sent to wallets, with a total compensation amount of approximately $312,000.Jason Maier stated that MEV can arise through public mempool exposure, order detail inference, malicious participation in auctions, or data gaps between service providers, and protecting a single link in the transaction path is not sufficient. He mentioned that the team will continue to enhance the execution quality and privacy of the entire transaction path and called on security researchers to report vulnerabilities when discovered.

GoPlus: Robinhood Chain exposes the Meme coin RUG factory again, with a flow exceeding 9 million USD

The GoPlus security team disclosed that a high-risk fraudulent Meme factory was recently discovered on the Robinhood Chain, with a transaction volume exceeding 9 million dollars in the past 30 days, involving hundreds of fraudulent Memes. The asset aggregation address is 0x8c3Bad30cc7563A2D0357F49509FFd063666bb00. As of September 28, 2026, the address balance is approximately 56.0635 ETH, equivalent to about 148,000 dollars; the address has a total of about 1,385 transactions, with the latest 400 transactions generating approximately 1,728.02 ETH in income and transferring out approximately 1,861.12 ETH; the two-way transaction volume is about 3,589.14 ETH, equivalent to about 9.49 million dollars.Direct evidence of "authorizing or selling tokens ---> liquidating ETH ---> transferring to the same aggregation address" was found in the high-risk associated Memes. The amount is the gross amount transferred into the aggregation system from the same project batch and does not represent net profit. The fraudulent Meme factory model mainly includes "new accounts shipping out ---> layered aggregation ---> fund recycling: 1. Creating Tokens based on industry hotspots; 2. Allocating Tokens to a large number of new EOAs with only 4 to 11 transactions; 3. Selling in segments through PonsV2Helper / UniversalRouter; 4. Emptying ETH to local aggregators or the main aggregation address (0x8c3bad); 5. Providing funds for the next round of projects, new wallets, and trading operations. The key to this fraud model is: 1. Using a large number of new wallets to hide the actual concentration of chips; 2. Segmentally selling by these wallets to create the illusion of multiple independent traders; 3. After the shipment is completed, funds flow into the same aggregation system; 4. Reinvesting the profits from old projects into the next round.On-chain researcher Wazz recently disclosed that a suspected continuous Rug gang initiated at least 53 Robinhood Chain Memes within about two months and extracted approximately 18.43 million dollars from them. Their main tactic is to control most of the token supply using 70 to 200 wallets, then reinvest the profits from the previous round into the next round. This case is similar to the fraudulent model in this case, but there is currently no evidence to indicate that it is the same gang.

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.
app_icon
ChainCatcher Building the Web3 world with innovations.