GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Yuga Labs Vice President: PPv2 Exploit Ongoing, Urges Users to Revoke Token Approvals Immediately

Yuga Labs Blockchain Vice President Quit (0xQuit) warns that the security vulnerability associated with PPv2 remains actively exploited, leaving even previously unaffected users at risk. Monitoring shows that an address was drained within a single block after accepting a quote and receiving 0.15246 WETH; attackers directed 99% of the illicit proceeds to block builders (Titan Builder), making conventional fund recovery via frontrunning extremely difficult.

Attack ongoing, Yuga Labs VP reminds users to revoke PPV2-related approvals immediately

— According to Quit monitoring, the Payment Processor V2 (PPV2) exploit attack is still ongoing. Even if users were not affected in the September 25 incident, as long as they have not revoked the relevant approvals, their assets may still be at risk. Users are advised to revoke approvals immediately.About 1 hour ago, an address lost 0.15246 WETH in the next block after accepting a quote and receiving funds. The attacker paid 99% of it as a tip to Titan Builder and kept only about 0.0015 ETH, making it nearly impossible to rescue the funds through frontrunning.Quit suggests that OpenSea could check whether a user still has risky approvals before they accept a quote and require them to revoke them first; when transferring NFTs, it should also check whether the receiving address has any related approvals remaining.

JaredfromSubway.eth sandwich attack bot has extracted $295 million in total, with $7.5 million stolen in June

Odaily News: The sandwich attack bot operated by JaredfromSubway.eth has extracted a cumulative total of 117,007 ETH since March 2023, worth approximately $295 million at current prices. In June 2026, an anonymous attacker deployed 66 counterfeit token contracts, exploiting the bot's automated trading logic to steal at least $7.5 million in ETH and stablecoins, and funneled the funds into Tornado Cash. The stolen assets have not yet been recovered.Sandwich attacks are a form of Maximal Extractable Value (MEV): the bot monitors large transactions in Ethereum's public mempool, buys ahead of the target transaction, and sells after the transaction pushes the price up, capturing profits from the spread. The bot's primary contract had received a cumulative total of 117,007 ETH as of August 28.MEV-Boost block construction is centralized among a small group of participants, with relay.ultrasound.money, Titan Relay, and bloXroute regulated relays collectively forwarding approximately 85% to 88% of related blocks within a 24-hour window; Titan's builder independently assembled 50.3% of the blocks. Monthly sandwich attack extraction amounts have declined from approximately $10 million in late 2024 to roughly $2.5 million in October 2025. (Bitcoin.com News)