2026-08-28
This monthNew Web3 Security Vulnerability Disclosures and CVEs — Last 48 Hours
The last 48 hours saw no newly confirmed Web3-specific CVE disclosures in the provided sources, though the GitHub Advisory Database continues to track open-source vulnerabilities with several new mode…
RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs — Last 48 Hours
Summary
The last 48 hours saw no newly confirmed Web3-specific CVE disclosures in the provided sources, though the GitHub Advisory Database continues to track open-source vulnerabilities with several new moderate-severity advisories published. The broader Web3 security landscape remains active, with community-reported exploit incidents (address-poisoning, chain migrations after exploits) circulating alongside established tooling and audit firm directories. Notable infrastructure updates include new security tool repositories and continued curation of threat intelligence resources.
Key Developments
2026-08-24 — Community security feed reports Bofur Capital losing $2M in an address-poisoning attack following a Compound withdrawal, with the phisher sending a 0.0002 USDC dust transaction to spoof the legitimate address. Web3 Security.AI
2026-08-21 — BounceBit announced plans to sunset its blockchain and migrate to BNB Chain following a $3 million exploit, as reported in community security channels. Web3 Security.AI
2026-08-20 — GitHub Advisory Database published two new moderate-severity advisories for Mailpit (Go): CVE-2026-67448 (WebSocket origin check bypass via percent-encoded path, a regression of CVE-2026-22689, credited to arpitjain099) and CVE-2026-67447 (SMTP DATA line reader buffers over-limit input before size enforcement, credited to rexpository). GitHub Advisory Database
2026-08-19 — Maya Protocol experienced an exploit that drained Bitcoin and other assets as pool value dropped $11 million, per community security reports. Web3 Security.AI
2026-08-17 — Harmony protocol planned a pre-attack rollback after an exploiter forged 3 trillion ONE tokens, according to community security channels. Web3 Security.AI
2026-08-15 — The toby-bridges/api-relay-audit repository (801 stars) was updated, providing local security audits for AI API relays and LLM proxies — detecting prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks. GitHub Topics — web3-security
2026-08-13 — The phishdestroy/destroylist repository (1.6k stars) was updated, offering a real-time phishing and scam domain blocklist with 208k+ curated threats and 1M+ community-contributed entries. GitHub Topics — web3-security
2026-08-22 — The gameworkerkim/CYBER-THREAT-INTELLIGENCE-REPORT repository (64 stars) was updated, an independent OSINT CTI archive (TLP:GREEN) covering supply-chain, zero-day, DPRK/APT, AI/LLM threats, Web3, and Korea breach/policy reports. GitHub Topics — web3-security
2026-08-22 — The Z-Bra0/Tx2Poc repository (22 stars) was updated, providing tooling to trace EVM exploit transactions into Foundry fork PoCs. GitHub Topics — web3-security
2026-08-20 — The security-alliance/frameworks repository (89 stars) was updated, serving as the official repository for SEAL Security Frameworks — curated and battle-tested security best practices focused on crypto/web3. GitHub Topics — web3-security
2026-07-07 — Web3 Security.AI published its research roundup page citing confirmed incidents including KelpDAO LayerZero (Apr 18, compromised RPC infrastructure feeding data into a single verifier setup on Arbitrum, $292M), Drift Protocol (Apr 1, social engineering + oracle manipulation on Solana, $285M), and Venus (Mar 22, on-chain + off-chain exploit on BNB Chain, $2.18M). Web3 Security.AI
Sources
- Web3 Security.AI — Research Page
- GitHub Topics — web3-security
- GitHub Advisory Database
- GitHub — Raiders0786/web3-security-resources
- Vulnerabilities — NVD — NIST
- NVD — Search and Statistics — NIST
- GitHub — gmh5225/awesome-web3-security
- Common Vulnerabilities and Exposures (CVE) — GitHub Topic
- The Hacker News — GitHub CVE-2026-3854 RCE Flaw
- Vulnerability Disclosure PR for Web3 and Crypto Security Projects — Shilika Jain