September 4, 2026
Web3 Security Weekly
Welcome to the second edition of this newsletter!
By Heavywt
4 min read
This week was busy. There were quite a few attacks on protocols, spread across all major ecosystems. In total, ~$14 million was stolen.
This week's tool is Plamen by @p_tsanev, a full AI auditor.
I am also trying out a new section this week, a "hot take" section. Let me know your opinions on it in the comments!
Exploits and post-mortems
August 28th
Ajna V2 lost roughly $775k across seven pools on Ethereum. Ajna is a lending protocol that auctions off bad debt/loans. The exact breakdown of this attack is not fully confirmed at the point of writing this. It seems the attacker found a "bad loan" that had no bidders for it, while an internal price variable was sitting at its minimum value, and used a weak point in the internal accounting to buy the collateral for essentially nothing. Since the contracts are actually decentralized, no pause or admin action was available to stop this exploit or reverse the damage.
Full breakdown: https://www.cryptotimes.io/2026/08/29/ajna-v2-loses-775k-on-ethereum-after-attacker-exploits-liquidation-math/
August 28th
The crypto-based neobank Avici, which provides crypto-backed debit cards, was exploited for ~$500k through an outdated Rain contract they were using. The hack also affected other companies for a combined total of $1.1 million. The core issue allowing this exploit seems to have been a simple signature replay, allowing the attacker to set themselves as admin for many collateral accounts. All affected users will be refunded.
August 29th
The DEX Full Sail, based on Sui, was hit by a $91k exploit, which sadly led to the protocol shutting down. In this case, the attackers were able to exploit a flaw in Switchboard that allowed them to set themselves as a trusted source for oracle price updates. Switchboard has paused all oracle services on all affected chains.
August 30th
The largest exploit of the week took place on Tectonic. The lending market was targeted by a price manipulation attack. The attacker inflated the price of an asset (TONIC) with low liquidity of only $1.3 million, then used the now 100x inflated price of TONIC to provide it as collateral to borrow $75 million of actual valuable tokens. They then extracted about $6 million of it by bridging to Ethereum; the rest of the stolen funds were rescued through a chain rollback of ~10k blocks.
Some more info: https://crypto.news/tectonics-75m-dollars-exploit-not-an-oracle-failure/
August 31st
Another exploit (why are there so many…? We really need to step up our game so I don't have to write so much) occurred on the More Markets/Ankr protocol, where a liquid staking contract was used to somehow (root cause not public/known yet) mint unbackedankrFLOW, which is the protocol's liquid staking token. This was then used to borrow against and allowed the attacker to exploit $410k, of which they then lost a large chunk to slippage, with ~$246k left.
Report: https://cryptobriefing.com/more-markets-9m-lending-reserve-exploit-blockaid/
Further hacks
Aquifer, a Solana AMM, was hit for $2.47 million on the 31st. The vector is still unconfirmed.
Fogo, an L1, lost 400 million FOGO (~$3 million, around 10% of circulating supply) from foundation wallets on the 28th and 29th. The vector has not been disclosed. They halted the mainnet about 15 hours after disclosure and shipped an upgrade to restrict the attacker's addresses.
Virtue, a CDP protocol on IOTA, lost ~$894k to the same Switchboard compromise on the 28th, after the attacker set the IOTA price feed to $10 million, minted ~4.94 million VUSD, and triggered 47 liquidations affecting 45 users.
Also this week: Balancer V1 ($234k, Ethereum, 30 Aug); Float Protocol ($28k, Ethereum, 31 Aug, spot price manipulation).
Contests and Bounties
Aerodrome
The Aerodrome contest has launched on Sherlock's audit engine, with a pot between 100k and 400k. The contest will end on the 17th of September. This one is definitely a big chance for everyone who got accepted to show what they've got.
Currently live
ENS on Immunefi is still running with its $70,000 pot and closes on September 14th at 11:00 UTC. KYC is required, scope is 137,845 nSLOC across the Manager and Explorer applications, and there are separate $14,000 All Stars and $7,000 Podium pools on top of the main distribution. If you were planning to look at it, you now have ten days.
Zendex on HackenProof is still live, up to $2,000, closing September 9th. It sat at 145 submissions when I checked, so the pot is going to be thin.
Alberich Token on HackenProof opened on September 1st and runs to September 8th, up to $3,000. Small, short, and it had 9 submissions when I looked, which makes it one of the better ratios currently on the board if you want a quick one.
Hot take of the week
One of this week's exploits (Tectonic) once again caused a debate to come up that we have all seen before: are chain rollbacks and pauses acceptable measures to reverse exploits or reduce the harm they caused?
My opinion might be controversial for some of you cypherpunks out there, but I would say yes, with a big if attached.
My reasoning for this is that these exploits affect real people. Years of savings, years of hard work are often lost. If we put idealism and ideas of a great decentralized system ahead of real people and the safety of their savings, crypto will never go full mainstream. People need to know that the systems they put their money in will always do the best they can to keep their funds safe. With the current regulatory pushes, it's only a matter of time till the first banks, pensions and unions start depositing part of their funds on-chain. At that point, we are no longer talking about risk-savvy investors losing money but everyday hard-working people losing their pension or life savings. Now the big if: chain rollbacks need to stay a democratic decision, either by a democratically elected security council or users casting their vote directly using their own stake.
I would love to hear some of your opinions in the comments; I'm sure a lot of you have different opinions on the matter.
Tool of the week
This week I want to highlight @p_tsanev's tool "Plamen". This one is a real end-to-end automated audit pipeline that is completely open source. The tool is maintained and regularly updated by @p_tsanev and features a fully automated AI auditor, including a scouting phase, phases for improving, and chaining found issues together to elevate the severity, a report writer, and quite a lot more steps.
I have tried out Plamen and found it provides great general coverage and finds some really interesting bugs and exploits from time to time. Plamen also offers multiple modes depending on the resources you have available, providing more or less coverage depth.
Overall, a great tool; thanks for open-sourcing this one @p_tsanev!
Link: https://github.com/PlamenTSV/plamen
Final thoughts
Thank you to all who got this far for checking out the newsletter again! As mentioned last week, any feedback (positive or negative) is welcome, and I'm always looking for new sections or ideas to add to the newsletter. To those who already commented or DMed me some new ideas last week, I will be getting to those throughout the next couple of weeks.
Best, Heavyw8t