2026-08-27
This monthNew Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
The last 48 hours show a continued emphasis on Web3 security tooling and threat intelligence rather than new critical CVE disclosures. A significant coordinated disclosure playbook for Web3 projects w…
RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
Summary
The last 48 hours show a continued emphasis on Web3 security tooling and threat intelligence rather than new critical CVE disclosures. A significant coordinated disclosure playbook for Web3 projects was published, outlining best practices for handling vulnerabilities. Community-reported incidents include a $2M address-poisoning attack on Bofur Capital and a $3M exploit leading to BounceBit's migration to BNB Chain. The NVD remains the authoritative source for CVE tracking, while GitHub's web3-security topic shows active development of security tools.
Key Developments
- 2026-08-22 — Bofur Capital reportedly lost $2M in an address-poisoning attack following a Compound withdrawal; the phisher sent a 0.0002 USDC dust transaction to spoof the address. Web3 Security.AI
- 2026-08-21 — BounceBit announced plans to sunset its blockchain and migrate to BNB Chain following a $3 million exploit. Web3 Security.AI
- 2026-08-19 — Maya Protocol exploit drained Bitcoin and other assets, with pool value dropping $11 million. Web3 Security.AI
- 2026-08-17 — Harmony planned a pre-attack rollback after an exploiter forged 3 trillion ONE tokens. Web3 Security.AI
- 2026-08-24 — phishdestroy/destroylist, a real-time phishing and scam domain blocklist with 208k+ curated threats and 1M+ community contributions, updated on GitHub. GitHub Topics
- 2026-08-22 — Z-Bra0/Tx2Poc, a tool for tracing EVM exploit transactions into Foundry fork PoCs, updated on GitHub. GitHub Topics
- 2026-08-20 — security-alliance/frameworks, the official repository for SEAL Security Frameworks with battle-tested Web3 security best practices, updated on GitHub. GitHub Topics
- 2026-08-22 — gameworkerkim/CYBER-THREAT-INTELLIGENCE-REPORT, an independent OSINT CTI archive covering supply-chain, zero-day, DPRK/APT, and Web3 threats, updated. GitHub Topics
- 2026-04-18 — KelpDAO LayerZero suffered a $292M exploit on Arbitrum due to compromised RPC infrastructure feeding data into a single verifier setup (confirmed). Web3 Security.AI
- 2026-04-01 — Drift Protocol experienced a $285M exploit on Solana through social engineering and oracle manipulation (confirmed). Web3 Security.AI
- 2026-03-22 — Venus suffered a $2.18M exploit on BNB Chain via a combined on-chain and off-chain attack (confirmed). Web3 Security.AI