logo

DeFied Expectations — Examining Web3 Heists

ID: 9eb81c6a-8304-5b75-819b-c22073a4febb

STIX ID: report--9eb81c6a-8304-5b75-819b-c22073a4febb

Feed Name: Google Cloud Threat Intelligence

Threat Score
70/100

Date Published: 2024-09-03

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report explains how smart contract vulnerabilities—particularly reentrancy issues—are exploited to steal large sums from blockchain services and exchanges, citing historical cases such as the 2016 DAO theft (~$55M) and the 2023 Curve Finance exploit (~$70M). It outlines how smart contract external calls and improper state updates enable recursive withdrawals, notes long attacker dwell times (up to 12 months) in exchange attacks, and emphasizes the need for improved detection and secure smart contract development practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.