0x10 Web3 Security Bulletin

Crypto and web3 security insights, including tools, hacks, and regulations.

Insightful

AI Agents Discover $4.6M in Smart Contract Exploits, Raising Autonomous Hacking Concerns

Researchers at Anthropic and MATS evaluated frontier AI models on SCONE-bench, a new benchmark of 405 historically exploited smart contracts. Claude Opus 4.5, Sonnet 4.5, and GPT-5 successfully developed exploits worth $4.6 million on contracts compromised after their training cutoff. Critically, both Sonnet 4.5 and GPT-5 uncovered two novel zero-day vulnerabilities worth $3,694 in live simulations, demonstrating that profitable autonomous exploitation is now technically feasible. (Anthropic)

Slither-MCP: LLM-Augmented Smart Contract Analysis

Trail of Bits released Slither-MCP, a new tool that enhances large language models with Slither's advanced static analysis capabilities. This integration enables more sophisticated vulnerability detection by combining LLM reasoning with proven contract analysis methodologies, improving auditing workflows. (Trail of Bits)

SlowMist Flags Low-Risk Issues in Binance Wallet Extension

SlowMist’s security team reports that Binance’s browser wallet extension, audited in October 2025, shows low overall risk after fixes to one high-, three medium-, and several low-severity issues across key management, access control, and XSS surfaces. Remaining concerns center on sandboxing, user interaction safeguards, and MPC key-share handling, which SlowMist labels as non-critical enhancements slated for future hardening. (SlowMist via Github)

Europol Leads €700M Crypto Fraud Takedown

Europol announces the dismantling of a large-scale cryptocurrency fraud and money laundering network that laundered over EUR 700 million through fake investment platforms targeting victims across multiple European countries. Coordinated raids in at least nine jurisdictions led to nine arrests and the seizure of cash, crypto, bank assets, and luxury goods, with a second phase hitting the marketing infrastructure behind deepfake and fake-ad campaigns. (Europol)

Companies in the news

Cantina × Euler 2025: Modular Lending, Secured

Euler's 2025 architecture introduction of modular security represents a significant shift in permissionless lending protocol design. Cantina's analysis demonstrates how this new modular approach maintains security integrity while enabling increased flexibility and scalability for DeFi lending platforms. (Cantina)

Web3 Antivirus Updates: MetaMask Snap & Enhanced Threat Detection

Web3 Antivirus released major extensions featuring MetaMask Snap integration alongside 20+ new threat detections, bringing real-time security assessment directly into MetaMask's 30-million-monthly users. The update emphasizes honeypot scam detection, token approval risks, and transaction simulation, equipping users with immediate fraud prevention before signing on-chain actions. (Web3 Antivirus)

Gimme the loot

A few notable hacks from Rekt and other sources…

$9M Yearn yETH Infinite Mint Exploit

Yearn Finance suffered a third major exploit when attackers exploited minting logic in its yETH StableSwap pool, creating 235 trillion tokens out of thin air and draining $8 million in a single transaction. The incident mirrors Balancer's attack in showing how legacy code and custom vault mechanisms enable precision attacks, despite prior audits from multiple top-tier security firms. (Rekt)

Total 2025 hack events: 188

The total amount of money lost by blockchain hackers is about

$2,912,699,055

We must have regulations

EU MiCA Licensing Phase Begins January 2025; Grandfathering Period Extends Through July 2026

As the European Union's Markets in Crypto-Assets (MiCA) regulation becomes fully operational on January 1, 2025, crypto asset service providers (CASPs) must begin licensing applications. Member states may offer grandfathering periods of up to 18 months, allowing existing providers to continue operating while transitioning to compliance—with some jurisdictions granting relief through July 1, 2026. MiCA introduces harmonized EU-level definitions, consumer protections, and anti-market abuse rules for crypto-asset issuers and service providers. (Legal Nodes)

Citadel Securities Responds to SEC Crypto Task Force Inquiry

Citadel Securities submits a detailed written statement to the SEC’s Crypto Assets and Cyber Unit, outlining its views on market structure, regulatory priorities, and the role of high-frequency trading in digital asset markets. The firm emphasizes data-driven oversight, alignment of crypto rules with existing securities regulation, and the need to preserve liquidity and price efficiency while addressing risks like fraud and market manipulation. (SEC)

Research corner

Zero-Knowledge Secret Santa Protocol Enables Privacy-Preserving Gift Exchange on Ethereum

Researchers propose ZKSS, a three-step cryptographic protocol leveraging zero-knowledge proofs to conduct Secret Santa games on-chain while preserving participant anonymity. The system uses Sparse Merkle Trees, ECDSA signatures, and nullifiers to prevent double participation and self-gifting, eliminating the need for trusted intermediaries. Integration with transaction relayers ensures sender confidentiality during randomness submission, while RSA encryption enables secure delivery address sharing—demonstrating how ZKPs solve Ethereum's privacy and randomness constraints for decentralized social protocols. (Ethresearch)

Web3 Software Supply Chain Security Research Identifies Critical Attack Vectors Across Blockchain Layers

Martin Monperrus published a comprehensive threat model examining Web3 supply chain security, identifying vulnerabilities across blockchain nodes, smart contract dependencies, frontend libraries, and development tools. The research highlights the 2025 Bybit attack ($1.5B loss via compromised JavaScript frontend), demonstrating how immutability and finality amplify consequences of supply chain compromises. The paper proposes defense-in-depth mitigation combining dependency verification, reproducible builds, specialized audits, and continuous monitoring for both frontend and on-chain components. (ArXiv)