2026-08-28

This month

New Web3 Security Vulnerability Disclosures and CVEs — Last 48 Hours

The last 48 hours saw no newly confirmed Web3-specific CVE disclosures in the provided sources, though the GitHub Advisory Database continues to track open-source vulnerabilities with several new mode…

RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs — Last 48 Hours

Summary

The last 48 hours saw no newly confirmed Web3-specific CVE disclosures in the provided sources, though the GitHub Advisory Database continues to track open-source vulnerabilities with several new moderate-severity advisories published. The broader Web3 security landscape remains active, with community-reported exploit incidents (address-poisoning, chain migrations after exploits) circulating alongside established tooling and audit firm directories. Notable infrastructure updates include new security tool repositories and continued curation of threat intelligence resources.

Key Developments

  • 2026-08-24 — Community security feed reports Bofur Capital losing $2M in an address-poisoning attack following a Compound withdrawal, with the phisher sending a 0.0002 USDC dust transaction to spoof the legitimate address. Web3 Security.AI

  • 2026-08-21 — BounceBit announced plans to sunset its blockchain and migrate to BNB Chain following a $3 million exploit, as reported in community security channels. Web3 Security.AI

  • 2026-08-20 — GitHub Advisory Database published two new moderate-severity advisories for Mailpit (Go): CVE-2026-67448 (WebSocket origin check bypass via percent-encoded path, a regression of CVE-2026-22689, credited to arpitjain099) and CVE-2026-67447 (SMTP DATA line reader buffers over-limit input before size enforcement, credited to rexpository). GitHub Advisory Database

  • 2026-08-19 — Maya Protocol experienced an exploit that drained Bitcoin and other assets as pool value dropped $11 million, per community security reports. Web3 Security.AI

  • 2026-08-17 — Harmony protocol planned a pre-attack rollback after an exploiter forged 3 trillion ONE tokens, according to community security channels. Web3 Security.AI

  • 2026-08-15 — The toby-bridges/api-relay-audit repository (801 stars) was updated, providing local security audits for AI API relays and LLM proxies — detecting prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks. GitHub Topics — web3-security

  • 2026-08-13 — The phishdestroy/destroylist repository (1.6k stars) was updated, offering a real-time phishing and scam domain blocklist with 208k+ curated threats and 1M+ community-contributed entries. GitHub Topics — web3-security

  • 2026-08-22 — The gameworkerkim/CYBER-THREAT-INTELLIGENCE-REPORT repository (64 stars) was updated, an independent OSINT CTI archive (TLP:GREEN) covering supply-chain, zero-day, DPRK/APT, AI/LLM threats, Web3, and Korea breach/policy reports. GitHub Topics — web3-security

  • 2026-08-22 — The Z-Bra0/Tx2Poc repository (22 stars) was updated, providing tooling to trace EVM exploit transactions into Foundry fork PoCs. GitHub Topics — web3-security

  • 2026-08-20 — The security-alliance/frameworks repository (89 stars) was updated, serving as the official repository for SEAL Security Frameworks — curated and battle-tested security best practices focused on crypto/web3. GitHub Topics — web3-security

  • 2026-07-07 — Web3 Security.AI published its research roundup page citing confirmed incidents including KelpDAO LayerZero (Apr 18, compromised RPC infrastructure feeding data into a single verifier setup on Arbitrum, $292M), Drift Protocol (Apr 1, social engineering + oracle manipulation on Solana, $285M), and Venus (Mar 22, on-chain + off-chain exploit on BNB Chain, $2.18M). Web3 Security.AI

Sources