Web3 Daily Exploits — 13 Sep 2026: Ampleforth $2.5M Gov Alert + Orb3 Bridge Window

No confirmed new protocol drain in the last 24 hours. Defimon flagged Ampleforth Governor Bravo proposal #54 aiming 2.5M USDC at a fresh proposer, and an Orb3 Orbit L1-bridge assertion that can confirm after block 26,005,988.

Web3 Daily Exploits — 13 Sep 2026: Ampleforth $2.5M Gov Alert + Orb3 Bridge Window

Required monitors were checked through the 13 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. No new confirmed protocol drain with funds already outside the victim’s control landed in this slice. Two first-report items are live and unfinished: an Ampleforth Governor Bravo proposal that would send 2,500,000 USDC to a fresh proposer, and an Orb3 / chainId 788988 Orbit-bridge assertion that can confirm after L1 block 26,005,988. Combined live loss scored on this card is $0. At-risk figures named by the alerting desk — $2.5M USDC on Ampleforth and 3.4018 ETH still in the Orb3 escrow — stay off the live-loss box until a withdrawal or treasury transfer is cited.

Yesterday’s Zentra (~$140k official / ~$143k Defimon) and ORB (~$32,610.72) items stay on the 12 Sep brief. They are not re-scored. Material updates in this window: Zentra set interest rates to zero and re-paused after an initial mitigation; the ctUSD bounty clock still runs to 14 Sep 12:00 UTC. Symbiosis’s 20% white-hat window was written through 13 Sep; no new return hash was published in this cutoff. Edgeless node 228 and Liquid’s unpaid ~598.5 BTC are unchanged. A T0 Trade / RaindexInventory on-chain message on Base described an 11 Sep off-chain pricing bug and asked for a bounty return without publishing a dollar print. All dollar figures below are amounts still outside the affected party’s control unless a return transaction is cited.

Ampleforth / Governor Bravo proposal #54 — Ethereum — Pending / not executed

What happened: At 04:23 UTC on 13 Sep 2026, Defimon flagged Ampleforth Governor Bravo proposal #54 as an access-control / malicious-governance alert dated 12 Sep. The single action would transfer 2,500,000 USDC — described as essentially the entire treasury — to the proposer. The write-up is dressed as an unsolicited “Observatory for SPOT completed-work grant.” Funds have not moved. Independent coverage from Odaily / BlockBeats / KuCoin Flash in the same hour repeated the Defimon print and the “not yet transferred” status. A later reply on the Defimon thread claimed a cancel transaction suggested team awareness; that claim is unverified against an official Ampleforth account in this window. Tally’s Ampleforth board at cutoff still listed “Observatory for SPOT - Completed-Work Treasury Grant” as pending, with voting not yet open, alongside a separately canceled item titled “Peach” and a pending “Ecosystem Growth & USDaf Liquidity Initiative.”

Protocol / chain / asset: Ampleforth DAO on Ethereum. Governance token cited by Defimon: FORTH at 0x77fba179c79de5b7653f68b5039af940ada60ce0, marked $0.22 in the alert. Asset targeted: USDC held behind the Governor Bravo / timelock stack. Defimon: the timelock holds 2.538M USDC.

Loss: $0 live on this card. $2.5M USDC at risk if proposal #54 is passed, queued, and executed. Do not add it to the live-loss box.

Attack type: Malicious governance proposal against a low-threshold Governor Bravo. Not a smart-contract drain in this window.

Technical details: Defimon: a fresh EOA (two transactions) created proposal #54 on Governor Bravo 0x8a994C6F55Be1fD2B4d0dc3B8f8F7D4E3a2dA8F1. The proposer is 0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82. The proposer disclosed that it wrote the proposal and will self-vote via a delegate holding 87,238 FORTH (~0.57% of supply), just over the 75,000 FORTH proposal threshold. Quorum is 600,000 FORTH; Defimon priced that stack at ~$132k at $0.22 per FORTH against a $2.5M prize. Proposal transaction resolved from Defimon’s shortlink: 0x06ef1e7165a1316e167cb6bd5040de74cfaeceb249b78043bbf2277213ce32f2. No official @AmpleforthOrg statement was located in the required-monitor set before cutoff. No execution or treasury-outflow hash was located.

Explorer links:

Status: Confirmed as a submitted proposal by Defimon and visible as pending on Tally at cutoff. Treasury transfer not reported. No official project containment note located on @AmpleforthOrg in this window. A reply claiming a cancel exists is flagged unverified.

Sources: https://x.com/DefimonAlerts/status/2098990897924821329

Orb3 / chainId 788988 L1 bridge — forged Orbit assertion — Ethereum — Pending / not withdrawn

What happened: At 04:05 UTC on 13 Sep 2026, Defimon relayed an on-chain safety alert against an Arbitrum Orbit AnyTrust stack at chainId 788988. The L1 bridge was described as holding 3.4018 ETH of user deposits and “being drained” in the sense that an attacker had already opened a validator-AFK whitelist and staked a forged node (node 716). Confirmation is gated on L1 block 26,005,988, estimated around 18 Sep 2026. At 04:47 UTC Defimon addressed the same thread to @Orb3Tech. No project statement from that account was located before cutoff. This is the same dormant-Orbit pattern as yesterday’s Edgeless item, against a different chain and bridge.

Protocol / chain / asset: Orb3 / chainId 788988 Orbit rollup, AnyTrust configuration, with L1 contracts on Ethereum. Asset in the named escrow: 3.4018 ETH. Defimon also named the same exposure class on chainIds 7889 and 78898 without a separate ETH print for those two.

Loss: $0 live on this card. 3.4018 ETH remains in the named bridge until an Outbox withdrawal after the confirmation block. Do not convert or add it to the $0 live-loss box.

Attack type: Forged rollup assertion against a permissioned-validator Orbit stack after the whitelist was opened. Fraud-proof / confirmation window still open at the alert.

Technical details: Addresses and hashes published in the on-chain message: bridge 0xC82dd3713f5eB5053D5A1a47f456435054ec77Dc; attacker 0x4428BE9125AE4e476514776a72ceDF2d5ce269C2; whitelist-open transaction 0xeb171e9af3318549c1ab313f3848945f46b1a1f1750ae7bb9651ef1339ec4ee5; forged-node stake transaction 0xbf303c72fcc4f47a12622b1a19fa3fbba58501ea4af7449fa574bc3089f7b93b (node 716). Rollup and UpgradeExecutor addresses were named in the same message. The desk also described a Safe 4-of-11 containment path; that operational note is not reproduced here. No Outbox withdrawal hash was located. No second required monitor independently reprinted the 3.4018 ETH figure in this cutoff.

Explorer links:

Status: Confirmed as a published on-chain alert by Defimon. Withdrawal not reported complete. Confirmation window open until the named L1 block. No official Orb3 containment note located at cutoff.

Sources: https://x.com/DefimonAlerts/status/2098986314670502077, https://x.com/DefimonAlerts/status/2098996982773620875

Also noted

  • T0 Trade / RaindexInventory on Base (first public desk message; no dollar print): At 15:15 UTC on 12 Sep, Defimon relayed an on-chain message signed as T0 Trade. The operator of RaindexInventory 0x10e4db39275C3b128C01bA1194D45D19aE1520d9 on Base said an 11 Sep off-chain cross-chain pricing bug published incorrect Base quotes. Trades routed through 0x74513519689b1FB427747624a4Dd87b3849d39CD filled against those quotes. The message asked the receiving address to keep an agreed bounty and return the rest; a second signed accounting message was promised and was not located before cutoff. Representative transaction: 0x2fea0ee6ce91f219240c93f22bffd3c86a3657cf2637020121ac3221cb464f3d. Affected OrderBook resolved from the shortlink: 0xe522cB4a5fCb2eb31a52Ff41a4653d85A4fd7C9D. No loss figure was published by a required monitor. Not scored. Sources: https://x.com/DefimonAlerts/status/2098792733011816766, https://basescan.org/tx/0x2fea0ee6ce91f219240c93f22bffd3c86a3657cf2637020121ac3221cb464f3d.
  • Zentra Finance (UPDATE, not re-scored): First-report ctUSD reserve drain remains on the 12 Sep brief. At 22:25 UTC on 12 Sep, Zentra said an initial mitigation had been implemented, interest rates set to 0, and the protocol paused again while a broader patch is reviewed. The 14 Sep 12:00 UTC bounty reply deadline on the traced proceeds was not extended or closed in this window. Source: https://x.com/ZentraFinance/status/2098900882423263315.
  • Symbiosis Bitcoin Bridge (UPDATE, not re-scored): First-report mint-and-dump remains on the 11 Sep brief. The 20% white-hat window cited through 13 Sep 2026 had no new return hash in this cutoff. A 12 Sep 07:09 UTC reply from the project (“We don’t have solvers”) is not a loss update.
  • Edgeless Network L1 bridge (UPDATE, not re-scored): Fake assertion node 228, first reported 12 Sep, still cannot confirm before L1 block 25,999,225 (~17–18 Sep). No Outbox withdrawal in this cutoff.
  • Liquid Network (UPDATE, not re-scored): ~598.5 BTC remains with the 6 Sep actor. No new return hash in this cutoff.
  • CertiKAlert, PeckShieldAlert, Phalcon, BlockSecTeam, GoPlusSecurity, SlowMist_Team, Lookonchain, ZachXBT, CyversAlerts, Immunefi, rekt.news: no new first-report smart-contract drain with a fresh loss figure after the 12 Sep brief cutoff. SlowMist’s ORB ~$32.6k print is already scored on yesterday’s brief.

Sources & references

Editor’s note: Card live-loss is this window’s confirmed new protocol drains only ($0). Ampleforth #54 and the Orb3 node-716 assertion are scored as pending incidents with $0 live loss. T0 Trade is recorded without a dollar print. Zentra rate-zero and the Symbiosis 13 Sep bounty clock are updates, not new drains. White-hat and bounty claims are recorded as claims. No how-to or exploit reproduction steps. Verify explorers and official channels before acting on any alert.

Read more