Web3 Daily Exploits — 29 Sep 2026: Reality.eth XSS, $0 Drain

First-report this window: DefimonAlerts flagged a stored XSS in the reality.eth question renderer; the project confirmed a 2022-era reality-eth-lib bug, shipped v3.4.32, and reported no confirmed drain. Bitget reopened ETH rails with a net inflow and thanked NEAR Intents SHIELD for a $503k mid-swap freeze. Limit Break whitehat mail continued.

Web3 Daily Exploits — 29 Sep 2026: Reality.eth XSS, $0 Drain

After the required-monitor sweep for this 29 Sep America/Panama window, first-report protocol-drain dollars are still zero. CertiKAlert, Phalcon_xyz, PeckShieldAlert, BlockSecTeam, and CyversAlerts published no in-window smart-contract drain. Lookonchain prints were whale and CEX flow. Immunefi traffic was social. rekt.news had no fresh incident page. The one first-report item is a frontend library exploit, not a vault empty: DefimonAlerts documented a stored XSS on the reality.eth question renderer, and @RealityEth confirmed a bug in reality-eth-lib that had sat since 2022, called this the first known exploitation, and published v3.4.32. No required-monitor desk attached a confirmed theft total. Card live-loss for new incidents is therefore $0 and the first-report incident count is 1.

The rest of the window is UPDATE traffic on already-scored clusters. Bitget opened the 29 Sep ETH withdrawal window at 08:00 UTC and later posted that ETH inflows were about 9,674 against outflows of about 9,023 ETH as of 09:00 UTC. CEO Gracy Chen separately thanked NEAR Intents / SHIELD for flagging more than $50 million in attempted Bitget-linked laundering flow, freezing $503k mid-execution, and waiving a bounty share. Those figures are attempted routing and a mid-swap freeze, not a new CEX drain and not added to the card. Limit Break / Magic Eden Payment Processor V2 victim and whitehat mail continued, including a Defimon-relayed notice that recovered funds would be returned after rescue costs with a cited Ethereum transaction. Apple’s iOS/iPadOS 26.7.1 patch for CVE-2026-86950, highlighted by SlowMist, is client-side telemetry with no confirmed wallet theft in the posts used here.

Reality.eth / reality-eth-lib — Ethereum frontend — stored XSS — $0 confirmed

What happened: DefimonAlerts posted that a stored XSS via governance-proposal text on the reality.eth dApp poisons app-global localStorage with attacker-controlled RPC URLs, hooks window.ethereum.request, and rewrites the displayed answer. The write-up said curators, arbitrators, or keepers answering any live question could be silently flipped to “yes” on attacker-fed data, which would enable forced execution of malicious Zodiac Reality Module transactions if those operators signed what the poisoned UI showed.

The injection path described in that post does not start in a production DAO treasury. A fresh EOA used permissionless addProposal() on Potion DAO’s abandoned Zodiac Reality Module as a delivery tube: the module asks its question on the shared reality.eth oracle, so the payload lands in the global question index. The proposal’s question JSON supplied title_html directly with an payload. Defimon wrote that reality.eth’s DOMPurify path only sanitizes markdown, while direct title_html is trusted and rendered through jQuery .html('.question-title'), so any visitor whose feed includes that question can hit the payload. The attached screenshot shows the payload sitting inside the question-title node on a reality.gwei.site question page. Defimon linked a malicious question URL with an explicit “do not open with a wallet” warning, plus t.co wrappers for a transaction and an attacker address. Those wrappers are not expanded in the text copy this desk captured; this brief does not invent the destination hashes.

@RealityEth quoted that alert overnight and confirmed the underlying defect: a bug in the reality-eth-lib JavaScript library that affects web pages using the library to render reality.eth questions. A follow-up said the bug had been present since 2022, that this was the first known exploitation pending further investigation, and that a fixed library had been published as v3.4.32. Maintainers of any frontend that embeds the library were told to upgrade. The project said the old dapp also contained the bug but was probably harder to exploit, that both the old frontend and the current reality.eth site had been patched, and that users should fully refresh so a cached insecure bundle is not reused. A later note said the new build wipes existing indexer and RPC settings in localStorage because an attacker may have written hostile values there.

Protocol / chain / asset: Ethereum mainnet oracle questions rendered by reality.eth frontends and any third-party page that embeds reality-eth-lib. No required-monitor post named a drained ERC-20 or a stolen ETH balance. Potion DAO appears in the Defimon write-up only as an abandoned module used for injection, not as a confirmed treasury victim.

Loss: $0 confirmed. Neither DefimonAlerts nor @RealityEth published a USD or ETH theft figure. Card scores the first-report incident at zero live-loss. If later tracing shows a signed module execution against a live Safe, that is a later window.

Attack type: Stored XSS in question rendering. On-chain permissionless proposal text is the persistence layer; the vulnerability is in the client library’s HTML trust boundary, not in RealityETH contract settlement math. This desk does not reproduce payload construction.

Explorer URLs: Primary transaction hash and attacker EOA were published by DefimonAlerts only as t.co links in the captured post text (https://x.com/DefimonAlerts/status/2104554770295828945). Those destinations are not invented here. Official project thread: https://x.com/RealityEth/status/2104731225684590970.

Status: Confirmed client-library bug and confirmed in-the-wild use, per the project. Library patched to v3.4.32. Official sites patched. Further investigation promised. No confirmed asset drain.

Sources: https://x.com/DefimonAlerts/status/2104554770295828945, https://x.com/RealityEth/status/2104731225684590970, https://x.com/RealityEth/status/2104731517616586906, https://x.com/RealityEth/status/2104731808277671949, https://x.com/RealityEth/status/2104731984320954588

UPDATE — Bitget Exchange — multi-chain CEX hot/warm wallets — ~$387.5M already scored

What happened (this window): No new unauthorized-transfer wave was confirmed. The scheduled ETH withdrawal reopen ran. Bitget posted that after ETH withdrawals resumed on 29 Sep, ETH inflows were about 9,674 and outflows about 9,023 ETH as of 09:00 UTC. Gracy Chen quoted that post and wrote that the desk saw a net inflow after the UTC 08:00 ETH window. Those numbers are user deposit and withdrawal flow on a reopened rail, not attacker outflows, and are not added to live-loss.

The same 28–29 Sep slice added the first operator-adjacent recovery print that is new relative to yesterday’s RCA brief. Gracy Chen thanked NEAR Intents / SHIELD for stepping up on the Bitget incident: the post said the service flagged more than $50 million in attempted laundering flows, froze $503k mid-execution, and waived its own bounty share. That language matches the NEAR Intents general manager write-up circulating with those same three figures: more than $50 million attempted, about $166k passed through, about $503k frozen pending a legal return process, with estimates described as possibly off by around 10 percent after de-duplication. The $50 million figure is attempted routing that was mostly rejected, not recovered principal, and is not subtracted from the $387.5 million recount. The $503k freeze is restricted mid-swap inventory, not a closed return to Bitget users.

Yesterday’s operator RCA is unchanged in this window: a third-party security product yielded high-level internal credentials; fraudulent withdrawal commands bypassed risk controls; private keys were not compromised; cold wallets were not affected; Mandiant and SlowMist remain on independent forensics. The third-party product is still unnamed in the official posts used here. BTC rails were already open in the prior window. Remaining published calendar from that thread still points at 30 Sep 08:00 UTC for USDT (Ethereum, BSC, Solana, Tron) and 2 Oct 08:00 UTC for other tokens / fiat / P2P.

Protocol / chain / asset: Centralized exchange custody. Prior briefs already carry the operator receiving addresses: EVM 0x770b10b273fc44fe9197d6bf20f145c2e98463ee, XRP rwNhefsz1UQEusxhCvHip3RANinWi4CTck, ZEC t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG, TRON TBWNguTTgezw9dVorX441C6nDrZpRxYwKD.

Loss: Not re-scored. Operator recount remains ~$387.5 million for the original 24 Sep window. ETH reopen volume and the SHIELD $503k freeze are not new drains.

Attack type: Unchanged. Unauthorized hot/warm transfers through stolen internal credentials from a third-party security product, per Bitget. DPRK / TraderTraitor attribution remains unlabeled as confirmed.

Explorer URLs: Arkham cluster https://arkm.com/explorer/entity/a4845a2d-0aca-4d28-b0fe-fb986c3370ac. Bitget EVM first-hop https://etherscan.io/address/0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee.

Status: Confirmed prior incident. BTC and ETH rails open per operator posts. USDT and remaining rails still on the published calendar. Vendor unnamed. Full written technical report still unpublished.

Sources: https://x.com/bitget/status/2104884112549191939, https://x.com/GracyBitget/status/2104886024979816508, https://x.com/GracyBitget/status/2104602301503816040, https://x.com/AlexAuroraDev/status/2104554958754357482

UPDATE — Limit Break payment processors / Magic Eden users — Ethereum and ApeChain

What happened (this window): No required-monitor post published a new official USD total. DefimonAlerts relayed a fresh cluster of onchain messages around a front-run / rescue path on the 24–25 Sep Payment Processor V2 event. One message told a victim that a bot had front-run an attacker transaction, still held the WETH, and would return 90 percent after about 10 percent MEV and execution costs, or 85 percent with an optional 5 percent bounty, after the victim revoked WETH allowance to 0x9a1d00bed7cd04bcda516d721a596eb22aac6834. A later message said affected addresses had been notified on-chain and that recovered funds would be returned after rescue costs, citing https://etherscan.io/tx/0x7ce920ec34e8aed944f7ed7cde707b92aa56fa35f7b25085fafec1eeb6a98595. Separate victim replies in the same slice accepted an 85 percent return plus optional bounty and published return addresses. Those are recovery correspondence, not a new protocol RCA and not a new loss print.

Loss: Not re-scored. Prior window ~660 WETH (~$1.7M) plus listed NFT inventory.

Explorer URLs: Ethereum processor https://etherscan.io/address/0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834. Cited rescue notice transaction https://etherscan.io/tx/0x7ce920ec34e8aed944f7ed7cde707b92aa56fa35f7b25085fafec1eeb6a98595. Prior cited theft https://etherscan.io/tx/0x54bd37ca945aad1fb18aead696a3e65188a4a148070115ff0ac755ec4c464fcf.

Status: Active user-side revoke. Redistribution of rescued inventory still in process via prior-window channels including nftsaresafu.xyz.

Sources: https://x.com/DefimonAlerts/status/2104843300758798718, https://x.com/DefimonAlerts/status/2104858191746027898, https://x.com/DefimonAlerts/status/2104865342539329804

Also noted

  • Required-monitor silence on new protocol drains: CertiKAlert, Phalcon_xyz, PeckShieldAlert, BlockSecTeam, and CyversAlerts had no in-window first-report smart-contract drain posts. PeckShieldAlert’s visible hit was a Solana meme-token price print, not an exploit hash. Lookonchain returned CEX withdrawals, whale ZEC and QNT flow, and Strategy BTC movement — market prints, not scored incidents.
  • GoPlus / Robinhood Chain meme factories (not a protocol drain): GoPlusSecurity wrote that it had flagged a separate high-risk meme factory on Robinhood Chain with more than $9 million of 30-day flow through consolidation wallet 0x8c3Bad30cc7563A2D0357F49509FFd063666bb00, and compared that pattern to an earlier Wazz thread on a 53-launch, ~$18.43 million serial-rug cluster. Those are alleged launch-and-dump factories, not a newly drained protocol. Not scored. Source: https://x.com/GoPlusSecurity/status/2104542109105606827.
  • SlowMist / Apple CVE-2026-86950: SlowMist_Team posted that Apple’s iOS/iPadOS 26.7.1 update addresses an out-of-bounds write that may lead to arbitrary code execution and that Apple said the issue may have been exploited in highly sophisticated attacks on versions before iOS 27. SlowMist tied the patch to previously reported iOS activity against wallet-adjacent targets. No confirmed crypto theft total was attached. Not scored. Source: https://x.com/SlowMist_Team/status/2104767900376826188.
  • DPRK / TraderTraitor attribution on Bitget (unverified): Unchanged as a closed finding. ZachXBT’s 28 Sep alias list remains investigator attribution. Bitget’s RCA still names a third-party credential path and does not name a nation-state actor.
  • Payy RollupV1 (~$1.83M) and DYORSWAP fake GIWA (766.25 ETH official): No new first-report hash this slice. Payy drain remains https://etherscan.io/tx/0xf43abdac5422087f645d77923eb1c825178bff3eb86d17d40fa18d89701e1814. DYORSWAP recovery address remains https://etherscan.io/address/0xdf25f88aa6cde9937fdcfcf10fa349528c79dbf9.
  • SHIELD $50M figure: Attempted flow flagged and mostly rejected, per NEAR Intents / Bitget thank-you language. Not treated as recovered principal and not treated as a new incident.

Sources & references

Editor’s note: First-report live-loss on this card is $0. Reality.eth is a confirmed client-library XSS with no published theft total. Bitget ETH reopen and the SHIELD $503k freeze are UPDATEs on the 24 Sep CEX event. Limit Break mail is recovery traffic. No how-to or exploit reproduction steps. Stay tuned or stay rekt.

Read more

Web3 Daily Exploits — 26 Sep 2026: Bitget $387.5M Recount, No New Drain

Web3 Daily Exploits — 26 Sep 2026: Bitget $387.5M Recount, No New Drain

No first-report protocol drain in this 26 Sep window after the required-monitor sweep. Bitget revised the 24 Sep hot/warm wallet incident from $351.6M to $387.5M (Zcash and TRON added; operator says not a second raid). GoPlus published a signing-pipeline analysis. Lookonchain flagged a $1.23M Binance withdrawal into the Bitget cluster. Limit Break / Magic Eden remains an UPDATE with victim outreach onchain. Payy and Duelbits stay prior-window.

By Jacobo Avariento
Web3 Daily Exploits — 25 Sep 2026: Bitget $351.6M Hot Wallet Drain

Web3 Daily Exploits — 25 Sep 2026: Bitget $351.6M Hot Wallet Drain

First-report live-loss this window: Bitget confirmed unauthorized transfers from hot and warm wallets at 18:31 UTC on 24 Sep, estimated $351.6M. Lookonchain tracked multi-chain composition and ETH consolidation. Second scored item: Limit Break payment processors used by Magic Eden — GoPlus cites 660 WETH (~$1.7M) plus listed NFT collections. Duelbits ~$6M outflows remain unverified. Payy carried as UPDATE.

By Jacobo Avariento