Web3 Daily Exploits — 1 Sep 2026: Injective drain, Aquifer emptied, Tectonic rollback
Injective halted nearly four hours after a likely binary-options settlement bug; bridged proceeds near $4.9 million in ETH have not moved. Aquifer on Solana was emptied for about $2.47 million, and Cronos finished rolling back the August 30 Tectonic attack.

Injective halted nearly four hours after a likely binary-options settlement bug; bridged proceeds near $4.9 million in ETH have not moved. Aquifer on Solana was emptied for about $2.47 million, and Cronos finished rolling back the August 30 Tectonic attack.
The last 24 hours mixed a new application-layer drain on Injective, a confirmed Solana vault empty at Aquifer, and the operational aftermath of Sunday's Tectonic incident on Cronos. PeckShield's August recap, published this morning, put monthly exploit losses at about $136.3 million across 50 major incidents, with Tectonic listed as the month's largest single event. Several widely repeated dollar figures from Monday were revised overnight. This brief uses primary on-chain posts, official chain accounts, and security-firm writeups only. Items without a full hash or official confirmation are marked.
1. Injective — binary-options settlement bug, chain halt (likely)
Protocol / chain / asset: Injective L1 exchange module; USDC, USDT, Noble-USDC, and ATOM extracted on-chain; proceeds bridged and swapped to ETH.
Estimated loss: About $4.8 to $4.9 million in bridged ETH is the figure repeated by PeckShield and Defimon Alerts. Researcher ErthlingPaddy later summed net withdrawals across four assets at about $6.5 million. Treat $4.8 to $4.9 million as likely and the $6.5 million sum as unverified pending an official accounting. Injective itself has not published a loss figure as of this writing.
Attack type: Likely application-module logic bug in permissionless binary-options market creation and the no-price refund / insurance-fund settlement path. Not a bridge compromise and not a private-key theft of the chain.
What happened: On 31 August 2026 an attacker launched a large set of instant binary-options markets on Injective, pointed them at a still-registered but dormant oracle provider named Frontrunner (empty relayer set), and self-matched both sides of short-dated markets. When the oracle returned no price, settlement took a refund path that, on the attacker's own deposit and withdraw flow, paid out more than was deposited — on the order of 1.5 to 2 times per cycle. The loop ran through the afternoon UTC until validators stopped producing blocks.
ErthlingPaddy's public reconstruction, which Defimon Alerts amplified, is the most detailed source available. Key timestamps and identifiers from that reconstruction:
- Attacker Injective account: inj10ykxh78wvp8da6q8xfck3tufl0ux8sp8rulp7p
- Linked Ethereum signer used to derive the exchange subaccounts: 0x792c6bf8ee604edee807327168af89fbf863c027
- Halt: block 181027005 at 16:09:59 UTC on 31 August 2026. Independent reports put the outage at about 3 hours 42 minutes. The chain resumed without a rollback.
- Proceeds moved via CCTP to Ethereum and were swapped to ETH. Defimon and PeckShield put the bridged stack near $4.9 million / $4.8 million. ErthlingPaddy described a fresh wallet holding about 1,861 ETH shortly after the halt, later referring to about 1,980 ETH.
About 30 minutes after the halt, an on-chain bounty note was sent to the Ethereum proceeds wallet: 0xe2d56a88696ed1b72f6421875eb6bb1278373fbab589fef67e477b430f7eda24. Decoded input asked the controller to get in touch for a bounty. Defimon says those ETH balances had not moved as of its 1 September alert.
The same Ethereum wallet later published two input-data messages naming the researcher and claiming the researcher showed them the vulnerability. ErthlingPaddy denied that, noting the first public thread went up at 18:27 UTC, more than two hours after the halt. Cited message transactions were posted only as prefixes and are not expanded here.
Status: Chain is producing blocks again. No official Injective incident post was found in the research window. PeckShield included Injective at $4.8 million in its 1 September August recap. Funds on Ethereum are reported unmoved. No confirmed freeze or return.
Sources: Defimon Alerts; ErthlingPaddy reconstruction; halt note; PeckShield August recap.
2. Aquifer (Solana prop AMM) — fake token-program swap (confirmed)
Protocol / chain / asset: Aquifer, a Solana proprietary AMM. Vaults holding USDC, USDT, HYPE, cbBTC, WETH and other SPL assets.
Estimated loss: About $2.47 million at 1 September prices (Bitquery reconstruction of 212 successful swaps across 18 tokens). Defimon and PeckShield round to $2.5 million / $2.47 million. Confirmed at that order of magnitude.
Attack type: Caller-controlled input-side token program. The program was not pinned to the canonical SPL Token Program. Aquifer trusted a CPI success flag instead of checking the actual tokenIn balance delta.
What happened: Shortly after 03:35 UTC on 31 August the attacker deployed a program that accepted SPL Token Transfer-shaped instructions and returned success without moving tokens. From about 03:41 to 04:21 UTC the attacker ran a burst of swaps that looked like USDC-for-asset buys. Balance traces show the output vault paid real tokens and the input vault received nothing.
BlockSec Phalcon published a preliminary trace on 1 September. Because Aquifer source is not public, Phalcon framed the root cause as likely rather than proven from source, but the on-chain pattern is consistent across firms: the caller supplied tokenProgramA, the malicious program was DMBpPMaMpGM2mWiUMaqcHx9FwhPg9Ys7qg1X59NRgb68, and real output moved via the canonical token program.
Key addresses and transactions:
- Aquifer program: AQU1FRd7papthgdrwPTTq5JacJh8YtwEXaBfKU3bTz45
- Attacker Solana: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J
- Attacker Ethereum (proceeds): 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746
- Fake program deploy: 5Qv9U9Xya2CP5wvyp1HPvhQGcNko6qGipTyxYunCaxc4JcCLW943Qpfz5vR42ZSKWMT91qvLtbQVy3PHJskY5Z1L
- Example swap: 2BANKvZf8qop1BcZuEH766h3JzfNFMndF8dzzWmk8uJ2ecgDDWCcH6PfaG3KgDWicC9qqNyCGUHZ5JMeh7z55Siy
- First SOL-to-ETH bridge leg: nWV5EZQ3jDukgFTR2X2ddmadfTa8gG4e8aqoqQdi5f6fLEKnhdBcxVidfCaZpyg9asNV9ciGzsNe9pTh1shnQ5V
- ETH arrival example: 0x5085bbe50677e41d1d395e9063b358efb6008c70dd3c08fd33770d728d91396b
Bitquery followed three SOL-to-ETH transfers totaling about 1,000.8 ETH into the Ethereum address above. As of its 1 September check the wallet had not sent a transaction. Aquifer vaults were left near dust; Bitquery put remaining vault value around $70 and said program traffic collapsed after the drain.
At 16:43:27 UTC on 31 August Aquifer's Solana upgrade authority published an on-chain whitehat offer: u1hoSUTzhe3hhnGiUiwvjtzd9Ji8EQPxjnTSKtW2hHDqY9ukYySftNp9eMHsBHsYezBKFcNyoZapYHYu4XaaZbQ. Terms: return at least 80 percent by 3 September 2026, 14:00 UTC; retain up to 20 percent; no civil claims if the terms are met. The offer does not bind law enforcement. Recovery addresses named in the message:
- Solana: 8af8RnAgyKzNt4fjDaP8w8pBekYVux1ja4AofavRyjox
- Ethereum: 0xb7EAA8cd5dFAD8021d9fB19c8a21613679f268F5
- Authorized Ethereum comms: 0x09dA08045830492B24b3b8A0022375e662bbE91d
- Upgrade authority: 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA
Some secondary writeups called this a wallet compromise. That reading is not supported by Phalcon or Bitquery. The observed path is a swap-program trust failure, not a leaked admin key moving vault tokens directly.
Status: Funds on Ethereum reported unmoved. Whitehat deadline is 3 September 14:00 UTC. No confirmed return as of this brief.
Sources: Defimon Alerts; BlockSec Phalcon; Bitquery investigation.
3. UPDATE — Tectonic on Cronos: chain restarted, most of the borrow reversed, about $6 million still off-chain
Protocol / chain / asset: Tectonic lending market on Cronos. TONIC used as manipulated collateral; borrows in liquid assets. About $6 million reached Ethereum before the halt.
Estimated loss (live, after rollback): Widely reported affected amount on 30 August was about $74 to $75 million. Cronos validators halted at block 90907150 (14:32:47 UTC, 30 August) and later restored state to before the exploit. Official restart: blocks again as of 2026-08-30 23:49:01 UTC from block 90896189. TRM Labs put the reversed on-Cronos portion near $68.7 million and the Ethereum escape near $6 million. PeckShield this morning still lists the incident as about $74 million and says the exploiter has started moving the escaped stack, including bridging toward BTC (about $200k cited). Treat the $74 million headline as the pre-rollback drain and about $6 million as the funds that survived the rollback. One analysis cited by TRM put the raw borrow as high as $119.5 million; that figure is not independently confirmed here.
Attack type: Thin-liquidity oracle / mark-price manipulation plus over-borrow against TONIC collateral (collateral factor cited at 20 percent).
What happened in this window: The exploit itself is a 30 August event. Material updates in the last 24 hours are operational:
- 31 August 13:31 UTC — Cronos Network said the chain was producing blocks again, state restored to before the Tectonic exploit, nodes should restart on v1.7.8, postmortem coming.
- 31 August 14:56 UTC — Tectonic said it would reopen in phases, starting with withdraw and repay, keeping borrow and deposit paused.
- 31 August — TRM Labs published a long-form note on the incident and on 2026 price-manipulation volume.
- 1 September 03:38 UTC — PeckShield August recap: Tectonic as the 4th-largest theft of 2026 year-to-date behind Drift, KelpDAO/LayerZero, and Coldcard.
Addresses published by GoPlus on 31 August (Cronos):
- Attacker: 0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652
- Attack contracts: 0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3, 0x2dc6a36f4e5eeefe112c01569de96dea496bb618
- Aggregation wallets: 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc, 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc
PeckShield's 31 August alert placed about $60 million at the first aggregation wallet and about $8 million at the second before the rollback, with about $6 million already on Ethereum. Lookonchain coverage of the Ethereum leg cited about $6.29 million swapped into about 2,592 ETH. The full Ethereum profit address was only posted by GoPlus as a shortened link; it is not reproduced here as a guessed hex.
Tectonic TVL was reported down from about $121.7 million on 26 August to about $3 million by 31 August. Crypto.com's exchange and app were stated separately as not compromised.
Status: Cronos online under observation. Tectonic withdraw/repay first, borrow and deposit still paused. Official postmortem promised, not yet published. Escaped Ethereum funds are the live loss; on-Cronos borrows were reversed by the state restore.
Sources: Cronos Network restart; Tectonic phased reopen; GoPlus alert; PeckShield recap; TRM Labs.
Also noted
More Markets / ankrFLOW on Flow EVM — figure revised
Blockaid's first detector print of about $9.3 million leaving More Markets' WFLOW reserve on Flow EVM was walked back on 31 August. Update: 15.5 million WFLOW left the reserve, about $410k at spot FLOW; realized attacker profit about $250k after slippage. Path described as Ankr bonded LST (ankrFLOW) plus E-mode borrowing. More Markets said its own contracts were not compromised. The original $9.3 million tweet was deleted. Treat $9.3 million as withdrawn; use $410k / $250k.
Source: Blockaid update.
Float Protocol — about $28,000 (10.71 ETH)
SlowMist flagged a Uniswap V3 slot0 spot-price distortion against Hypervisor-style LP share pricing. Critical paths lacked TWAP or slippage checks. Loss about $28,000. Attacker 0xaea29218262dc6b0904ca077f6527c49dfd426d9. Attack contract 0xb46655eb5b77de277063a75586d1883e951b6c54. Vulnerable contracts 0x85cbed523459b7f6f81c11e710df969703a8a70c and 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153.
Source: SlowMist TI Alert.
Stale Permit drains
GoPlus reported two victims drained after years-old malicious Permit signatures were reused. One wallet lost about 97k SYN earlier and another about $122k SYN in the new hit (0x686618aBb3730079601a5abEAD6eC24549c5Ce34). A second victim lost about 100k USDC earlier and about $62k USDC in the follow-up (0xdFC1497EF2Ca6D884EC90d2fC4FB816a5ea735f2). Shared phish cluster includes 0x0000db5c8B030ae20308ac975898E09741e70000. These are user-side approval leftovers, not protocol exploits.
Sources: GoPlus SYN case; GoPlus USDC case.
Endpoint malware
GoPlus amplified a user report of about $47k stolen after a Google-ad impersonation of a Homebrew install on a new Mac. Out of scope as a smart-contract incident.
Source: GoPlus.
Not in this brief
- Kelp DAO / LayerZero rsETH drain, Moonwell, Term Labs, Coinsbuy, TAC, MANTRA, BounceBit, Cosmos Labs — listed in PeckShield's August table but not first reported in this 24-hour window.
- Balancer V1 about $234k BPT mint — SlowMist timestamp is 31 August 03:54 UTC, before this brief's 24-hour cut.
- GTA 6 / CYBERLEEK memecoin cash-out and the fake Trump GOLD token — older than the window.
Sources and references
- https://x.com/DefimonAlerts/status/2094629845321892170
- https://x.com/DefimonAlerts/status/2094470292642976178
- https://x.com/ErthlingPaddy/status/2094506159344406623
- https://x.com/ErthlingPaddy/status/2094546772701958607
- https://x.com/Phalcon_xyz/status/2094654751581610363
- https://x.com/PeckShieldAlert/status/2094631045845164273
- https://x.com/CronosNetwork/status/2094417832394301499
- https://x.com/TectonicFi/status/2094439214133993487
- https://x.com/GoPlusSecurity/status/2094268398662537542
- https://x.com/SlowMist_Team/status/2094373942291026287
- https://x.com/blockaid_/status/2094518648123842712
- https://bitquery.io/investigations/aquifer-solana-hack-2-5-million
- https://www.trmlabs.com/resources/blog/number-of-price-manipulation-attacks-hits-all-time-high-as-usd-75-million-is-stolen-from-tectonic
- https://etherscan.io/tx/0xe2d56a88696ed1b72f6421875eb6bb1278373fbab589fef67e477b430f7eda24
Editor's note
Required monitor accounts checked for 31 August to 1 September 2026: DefimonAlerts, CertiKAlert, Phalcon_xyz, GoPlusSecurity, SlowMist_Team, plus PeckShieldAlert, BlockSec/Phalcon, Lookonchain (no matching exploit posts in the operator search), ZachXBT (Tectonic look-into note only), Blockaid, Cronos Network, Tectonic, and Aquifer on-chain messages. CertiKAlert's window post was an August totals card, not a new incident. Injective still lacks an official incident thread; treat mechanism and dollar figures there as researcher-led until the foundation posts. Aquifer's whitehat text is an on-chain negotiation, not a recovery. Cronos's restart is confirmed by the chain account; the full Tectonic postmortem is not out. This desk does not publish exploit recipes. Nothing here is financial advice.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

