2026-08-25

This month

New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)

The last 48 hours showed no Web3-specific CVEs published in the NVD, with the most recent scored entries focused on Google Chrome (CVE-2026-76039 through CVE-2026-76046) and Oracle Helidon middleware.…

RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)

Summary

The last 48 hours showed no Web3-specific CVEs published in the NVD, with the most recent scored entries focused on Google Chrome (CVE-2026-76039 through CVE-2026-76046) and Oracle Helidon middleware. However, the Web3 security community remains active with unverified exploit reports of address-poisoning attacks targeting Bofur Capital and a Maya Protocol exploit draining Bitcoin and other assets. Confirmed major incidents from April and March 2026 include the KelpDAO LayerZero compromise with $292M at risk and the Drift Protocol social engineering attack on Solana.

Key Developments

  • 2026-08-22 — Bofur Capital reported to have lost $2M in an address-poisoning attack following a Compound withdrawal; the phisher sent a 0.0002 USDC dust transaction to spoof the recipient address Web3 Security.AI
  • 2026-08-21 — BounceBit announced it will sunset its blockchain and migrate to BNB Chain after suffering a $3 million exploit Web3 Security.AI
  • 2026-08-19 — Maya Protocol exploit drained Bitcoin and other assets as its pool value dropped by $11 million Web3 Security.AI
  • 2026-08-17 — Harmony plans a pre-attack rollback after an exploiter forged 3 trillion ONE tokens Web3 Security.AI
  • 2026-08-18 — NVD published eight Google Chrome CVEs (CVE-2026-76039 through CVE-2026-76046) addressing high-severity vulnerabilities including use-after-free, buffer overflow, and race condition issues; no Web3-specific CVEs were published in this window NVD - Home
  • 2026-08-18 — NVD published multiple Oracle Helidon CVEs (CVE-2026-71110, CVE-2026-73892 through CVE-2026-73901, CVE-2026-73939) affecting versions 3.2.x and 4.5.x of the Oracle Fusion Middleware component NVD - Home
  • 2026-08-11 — CVE-2026-19579 published for Snipe-IT before 8.6.0, an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint NVD - Home
  • 2026-08-24 — The GitHub topic "web3-security" lists 197 public repositories, including phishdestroy/destroylist with 1.6k stars tracking 208k+ phishing threats, and toby-bridges/api-relay-audit with 801 stars for AI API relay security audits web3-security · GitHub Topics · GitHub
  • 2026-08-22 — Z-Bra0/Tx2Poc repository updated, providing tooling to trace EVM exploit transactions into Foundry fork PoCs for security researchers web3-security · GitHub Topics · GitHub
  • 2026-08-20 — security-alliance/frameworks repository updated with official SEAL security frameworks for crypto/web3 best practices web3-security · GitHub Topics · GitHub
  • 2026-07-07 — Confirmed incident: KelpDAO LayerZero compromise via compromised RPC infrastructure feeding data into a single verifier setup on Arbitrum, affecting $292M Web3 Security.AI
  • 2026-04-01 — Confirmed incident: Drift Protocol exploited via social engineering and oracle manipulation on Solana, affecting $285M Web3 Security.AI
  • 2026-03-22 — Confirmed incident: Venus protocol exploited via on-chain and off-chain attack vectors on BNB Chain, totaling $2.18M Web3 Security.AI
  • 2026-08-15 — toby-bridges/api-relay-audit updated, a Python tool for local security audits of AI API relays detecting prompt injection, model substitution, and Web3 wallet risks web3-security · GitHub Topics · GitHub
  • 2026-08-22 — gameworkerkim/CYBER-THREAT-INTELLIGENCE-REPORT updated with independent OSINT CTI archive covering supply-chain, zero-day, DPRK/APT, AI/LLM threats, and Web3 web3-security · GitHub Topics · GitHub
  • 2026-07-15 — PlamenTSV/plamen updated, an autonomous Web3 security audit agent for Claude Code supporting Ethereum, Solana, Sui, and Aptos web3-security · GitHub Topics · GitHub
  • 2026-05-27 — Raiders0786/web3-security-resources repository hosts a curated Web3 security learning hub with roadmaps, audit tools, and public reports; maintained by DigiBastion with 430 stars and 68 forks GitHub - Raiders0786/web3-security-resources
  • 2026-08-21 — CVE Tools database shows 360.6K total CVEs tracked with 45.7K critical, 65.4K with public exploits, and 1.7K in CISA KEV; the top trending vulnerability is CVE-2026-19478, a GitLab code injection flaw with 9.4 CVSS score CVE Tools

Sources