SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.

🚨SlowMist TI Alert🚨 💸 MALT Loss: ~$72k 🔍 Root Cause: swap(uint256,uint256,address) records the caller’s input and pre-swap reserves, then invokes an external rebalanceHook before transferring the requested output. The hook withdraws DAI from the Capital Source and deposits it into the same pool. The swap subsequently validates its invariant against the pool’s final balances, treating this protocol-funded DAI as if it were supplied by the caller. Because the function does not isolate caller-funded input from hook-funded rebalancing capital, an attacker can provide negligible input, trigger treasury-funded liquidity injection, and withdraw a disproportionate amount of MALT. 📌 Attacker: 0x8F103B6A0aD705bcE6357842A5fefEB49e8D83Ef 📌 Victim: 0xF0d314849A3Bc9270a79110F25dBA2c8325A2AAC 📌 Vulnerable Contract: 0xfe6C096a2871337d4f6F7DD04Ebda733E94D7A13 Powered by SlowMist.AI Tx: polygonscan.com/tx/0x915eccb…
5
4
53
7,759
🚨SlowMist TI Alert🚨 💸 @Goldpesatoken Loss: ~$114.9k 🔍 Root Cause: GPXHooks' reBalance() performs liquidity operations through the shared, flash-accounted PositionManager inside an attacker-controlled PoolManager unlock without verifying that the PositionManager's GPX/USDC currency deltas are zero, so the hook's burn credit is not isolated from the caller's state. The attacker opens an unlock, mints a WETH/USDC position via MINT_POSITION without settling (leaving the shared PositionManager with a −114,999.999187 USDC delta), then swaps on the GPX pool to trigger the hourly rebalance: the hook burns its real position and earns a +148,868.602189 USDC credit, but TAKE_PAIR can only withdraw the net positive delta, so the hook receives just 33,868.603002 USDC while the attacker's phantom debt absorbs the difference. Burning its own position cancels that debt and the attacker takes 114,999.999186 USDC straight out of the PoolManager — a missing delta-isolation / zero-delta check on a shared PositionManager. 📌 Attacker: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F 📌 Victim: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8 📌 Vulnerable Contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8 Powered by SlowMist.AI Tx: basescan.org/tx/0x5c1febd504…
4
1
31
6,924
🚨SlowMist TI Alert🚨 💸 @aave v3 Loop Safe Module Loss: ~114.09 ETH 🔍 Root Cause: FlashLoopAdapter's open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then executes router.call with fully attacker-controlled router and calldata. Since the adapter is an enabled module of the victim Safes, the attacker set router=victim Safe and data=execTransactionFromModule to drain weETH and Aave collateral. 📌 Attacker: 0x42c2633438609881c8fBAb82414eb9A0c45F9353 📌 Victim: 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, 0xcfedf95a3653a128dfc2e4288758a1a1850d169f 📌 Vulnerable Contract: 0x16bb8b912da187870c23ec6756bb3fad061283d8 Impact: ~114.09 ETH stolen from two Safe multisigs via forged Safe authentication and arbitrary module execution; ~1300 WETH debt repaid to unlock collateral. Powered by SlowMist.AI Tx: etherscan.io/tx/0x75328f916b…
44
26
156
53,475
This is a third-party external adapter. The Aave V3 contracts are not affected.
Replying to @TheBlockCo
This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.
2
11
3,732
Before sending crypto, take a few seconds to check where you are and where your funds are going. #punycode Stay vigilant!
One letter. $20K gone. We broke down how Punycode phishing makes fake crypto sites look almost real — including a case flagged by @SlowMist_Team involving a fake ChangeNOW domain. See how to spot a trick. Read the full article on ChangeNOW blog 👇 changenow.io/blog/punycode-p…
2
3
25
9,137
👀🫡
🚨 UPDATE: SlowMist says malicious activity tied to Bitget’s $388M hack began Aug. 31 before draining hot wallets on Sept. 24. ct.com/news/bitget-hack-zero…
4
21
7,765
Congrats to @TokenPocket_TP — the Asset Inheritance feature has passed our security audit. 🎉 We appreciate TokenPocket’s commitment to security.👏 🔗Audit report: tokenpocket.pro/TokenPocket-…
Our Asset Inheritance feature has passed a security audit by @SlowMist_Team. The audit identified no critical or high-risk vulnerabilities, and all findings were acknowledged. View the full report: tokenpocket.pro/TokenPocket-…
4
1
19
8,389
🚨SlowMist TI Alert🚨 💸 MUS Loss: ~$36.9k 🔍 Root Cause: deposit() included the first-deposit bonus in both the immediate ETH refund and the user’s MUS allocation; withdraw() allowed same-transaction redemption without limiting total ETH returned to the amount deposited. Sixteen fresh addresses repeated the cycle to extract ETH from MUSystem. 📌 Attacker: 0x1a083ADf234a8f67ad65A9B9B616853ACf5998E5 📌 Victim: 0x9bdf81e6066d32764b7e75a1b5577237e06d9364 📌 Vulnerable Contract: 0x9bdf81e6066d32764b7e75a1b5577237e06d9364 Powered by SlowMist.AI Tx: etherscan.io/tx/0xfe28118e48… etherscan.io/tx/0xaa172fcaa4… etherscan.io/tx/0x905af4e8cd…
5
4
39
7,152
SlowMist retweeted
We are very grateful for SlowMist's quick response and professionalism in helping us investigate this incident thoroughly. They have shared their findings on the September 24 security incident. Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker to initiate unauthorized withdrawals. The findings align with the attack path we previously shared and add further detail on how the incident unfolded. Our focus is firmly on what comes next: applying these findings, continuing to strengthen our security controls and continuing to protect our users and their assets.
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft. As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly customized withdrawal tool used by the attacker. 🔎 Key findings include: 1. Malicious activity on a certain third-party product involving exploitation of a zero-day vulnerability. 2. Unauthorized access to a certain third-party products management platform on September 25 using an internal employee identity. 3. Recovery of a customized withdrawal tool designed to interact with the wallet system’s withdrawal logic. 4. On-chain activity begins at 02:31 on September 25, with transfers across multiple blockchains over approximately 2 hours and 52 minutes. 5. Subsequent attempts to manipulate withdrawal records and trigger additional BTC withdrawals. We are continuing to investigate how the attacker moved between the affected systems. All date references are to UTC+8. 📄 Read the details of the investigation: github.com/slowmist/Knowledg…
40
29
183
113,436
🚨SlowMist TI Alert🚨 💸 @MCNLabs Loss: ~$92.6k 🔍 Root Cause: LPBonus uses inconsistent reserve values in its reward accounting. AddFistFee divides newly acquired FIST by the MSN reserve when updating oneshareFIST, but CalcPendingUser later multiplies that index by a user weight calculated from the reserve at withdrawal. The attacker reduced the reserve to 89.327788899759978606 MSN during accrual, then raised it to 491.113095162589329323 MSN before triggering UserRemoveLp. This mismatch let one newly registered LP holder claim 1,442,165.713011 FIST even though the intervening reward increment was funded by only 940,041.612768 FIST. 📌 Attacker: 0xb6fff29dd2b5423a159e50877fc4af7a54e76f7a 📌 Victim: 0x52272524a22f941f5489c1233732797314bb054b 📌 Vulnerable Contract: 0x52272524a22f941f5489c1233732797314bb054b Powered by SlowMist.AI Tx: bscscan.com/tx/0xecac1563bbb…
6
2
35
5,760
🔎 One input. Structured on-chain investigation. @MistTrack_io Agent is now live on @FinchTechAI. Enter an address or tx hash to trace fund flows and assess on-chain risk automatically. ✨ Thanks @0xDarrenG for the walkthrough👇
🛡️ Powered by @SlowMist_Team! On-chain investigations done in a single step. Say goodbye to tedious manual checks and internal burnout! See how 0xDarren..._... (@0xDarrenG) uses the MistTrack Agent on Finch to handle on-chain risk control and fund tracking in just 10 seconds! Click the link to experience your exclusive on-chain security Agent 👇 finchtech.ai/market/chips/ag…
2
7
6,180
The @bitget exploiter tried to move the stolen funds through @Chainflip. Chainflip’s response? “Deposit rejected by the broker.” 👋 No freeze, but no luck either — the funds were refunded. 👍 Nice try. 😶 We’ll continue tracking the movement of the stolen funds. 🔗 scan.chainflip.io/channels/1…
5
15
73
101,708
🚨 Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution. As we previously reported, this update is highly relevant to the iOS attack activity we have been tracking. Apple confirmed that the vulnerability may have been exploited in highly sophisticated attacks targeting specific individuals on iOS versions before iOS 27. For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data. 🔐 Please: • Update your iPhone, iPad, Mac and other Apple devices to the latest available security updates. • Avoid installing apps from unknown or untrusted sources. • Do not open suspicious links in Safari or in-app browsers. • Treat unexpected files, links and app installation prompts with caution. Stay alert and keep your devices updated. Apple Security Update: support.apple.com/en-us/1492…
5
16
45
19,510
We’re working closely with @bitget on the ongoing investigation. For further details, please refer to Bitget’s official updates.
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
10
10
85
22,625
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
14
66
89,248
🚨 SlowMist TI Alert 🚨 MemTensor's AI memory tooling has been compromised: MemoryOS (PyPI), the company's open-source long-term memory library for LLM and AI agents, and memtensor/memos-cloud-openclaw-plugin (npm), the official plugin connecting it to the OpenClaw agent runtime. Affected versions bundle cross-platform Go binaries that execute when the package is loaded or imported: MemoryOS==2.0.34 on PyPI, and plugin versions 0.1.21, 0.1.23 and 0.1.25 on npm. You are affected if the PyPI version has been imported in your environment, or if the npm plugin is installed and the OpenClaw gateway has been started. Potential attacker actions include harvesting npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, environment secrets, and other developer credentials, with data sent to infrastructure under skyleen[.]fr. The affected npm plugin may also expose user prompt content. Users should remove or downgrade affected packages to known-good versions (0.1.20 for npm and 2.0.33 for PyPI), terminate sckit processes, block associated infrastructure, review network activity, and rotate credentials accessible from affected environments. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. Reference: aikido.dev/blog/supplychain-… As always, stay vigilant! enterprise.misteye.io/threat…
9
8
24
11,907
Thanks to @Cointelegraph for covering our investigation into the FomoPeek App Store poisoning and iOS kernel exploitation, conducted together with the @wallet security team. 🫡 We appreciate the opportunity to share our findings and help users better understand the risks and recommended response. 🌟 Read more 👉: cointelegraph.com/news/fomop…
7
4
22
10,094
📖 FATF Report | How to Understand and Address Risks in Gaming and Gambling FATF’s latest report examines the money laundering, terrorist financing, and proliferation financing risks across the gaming and gambling ecosystem. 🎰 As gambling platforms increasingly connect with online, cross-border operations and multiple payment methods, including virtual assets, related fund flows can extend beyond gambling platforms to exchanges, payment institutions, and other #VASPs. 🔍 For VASPs, identifying an address linked to gambling is only the starting point. A more meaningful risk assessment requires understanding where the funds come from, who they interact with, how they move, and whether the transaction behavior is consistent with historical activity. 🧩 In our latest article, SlowMist breaks down #FATF’s key risk indicators and explores how on-chain analysis can help institutions move from one-time screening to continuous risk management with @MistTrack_io . 🔗 Read the full analysis: slowmist.medium.com/fatf-rep…
2
3
10
7,915