# 0x6 Web3 Security Bulletin

*Crypto and web3 security insights, including tools, hacks, and regulations. *

By [W3SB](https://paragraph.com/@w3sb) · 2025-11-05

crypto, web3, security, hacks, exploits, regulations

---

Insightful
==========

**AI Agent Economy Infrastructure: ERC-8004 & A2A & MCP**

GoPlus Open Research has introduced a new framework for the AI Agent Economy, encompassing ERC-8004, A2A, and MCP. This initiative aims to enhance Web3 security by providing a decentralized security layer. The research focuses on addressing critical security concerns within the evolving AI and blockchain landscape, promoting transparency and collaboration to safeguard users and developers in the ecosystem. ([GoPlus Security via X](https://x.com/GoPlusSecurity/status/1982319160253399054))

**A Guide to Perpetual DEX Architecture & Security**

Good primer on the architectural and security considerations for Perpetual Decentralized Exchanges (DEXs). The blog outlines the mechanisms involved in DEX operation and highlights vulnerabilities DEXs have succumb to. ([QuillAudits](https://www.quillaudits.com/blog/smart-contract/perp-dex-architecture-and-security))

**House Of Cards (aka To Loop Or Not To Loop)**

Stream and Elixir faced issues with stablecoin backing, where Stream reportedly converted $1.9 million into $14.5 million xUSD through recursive minting. This incident highlights the risks associated with stablecoins backed by other stablecoins, emphasizing the potential for instability and financial manipulation within the DeFi ecosystem. ([Rekt](https://rekt.news/house-of-cards)) ([Chris Dior via X](https://x.com/chrisdior777/status/1985728597181472971))

Companies in the news
=====================

**Hacken Federation Network Welcomes Its First Partners**

Hacken has announced the initial partners joining its Federation Network, a collaborative initiative aimed at enhancing Web3 security. This network seeks to foster a more secure blockchain ecosystem through shared intelligence and collective defense strategies. ([Hacken](https://hacken.io/hacken-news/hacken-federation-network-first-partners/))

**Chainalysis and Chainlink Forge Strategic Compliance Partnership**

Chainalysis and Chainlink Labs have entered a partnership to develop advanced cross-chain compliance workflows, aiming to enhance security and transparency in multi-chain environments. The companies note, "users will be able to programmatically implement conditions around transfers, mints, redemptions, and withdrawals based on KYT alerts, with deterministic outcomes and audits." ([Chainalysis](https://www.chainalysis.com/blog/chainlink-strategic-partnership-power-advanced-cross-chain-compliance-workflows/))

**Hexagate Unveils Wallet Compromise Detection Kit**

Hexagate’s new Wallet Compromise Detection Kit is designed to preempt major wallet hacks by providing real-time threat intelligence and automated detection across the crypto ecosystem. The tool aims to raise protection standards for custodians and institutional investors. ([Chainalysis](https://www.chainalysis.com/blog/hexagate-wallet-compromise-detection-kit/))

Gimme the loot
==============

_A few notable hacks from_ [_Rekt_](https://rekt.news/) _and other sources…_

Many of the monthly hack reports noted October was a slow month for the attackers. Well November is starting off with a BANG!

**Hot Off the Press from the Source --> Balancer v2 Exploit: Preliminary Incident Report**

**(**[**Balancer on X**](https://x.com/Balancer/status/1986104426667401241)**)**

**$100 Million Balancer V2 Exploit**

Balancer V2 and its forks were breached across multiple chains, losing over $128M after attackers exploited a rounding error in batch swaps. The issue shows how minor precision flaws in smart contracts can be weaponized through large-scale, automated transactions. GoPlus Security detected and alerted users as the attack unfolded. ( [GoPlus Security on X](https://x.com/GoPlusSecurity/status/1985371222230884799))

**Balancer Con't...Or Was it a Contract Authorization Issue**

A flaw in Balancer V2’s vaults and liquidity pool contracts let attackers bypass key authorizations. A vulnerability in smart-contract authorization inside the Vault’s `manageUserBalance` function. This function did not strictly enforce that only the rightful owner or an explicitly authorized delegate could withdraw a user’s internal balance. ([OKcontract Chainwall](https://medium.com/coinmonks/balancer-v2s-overlooked-guard-a6847a49e0a4)) ([@AdiFlips](https://x.com/AdiFlips/status/1985279811011457363))

**Garden Finance Loses $11 Million in Solver Attack**

Garden Finance confirmed an $11 million loss after its solver was attacked. The team is investigating the root cause and collaborating with security partners to trace the incident. ([SlowMist](https://hacked.slowmist.io/en/))

**LayerZero’s $3M Griffin AI Peer Exploit**

LayerZero’s bridge protocol suffered from an exploit where an attacker minted billions of $GAIN tokens, dumping only a fraction for $3M in profit. The incident exposes the perils of admin key centralization and protocol misconfigurations in cross-chain infrastructure. ([Rekt](https://rekt.news/griffinai-rekt))

**Moonwell Suffers Oracle Attack**

Moonwell's lending contract was exploited due to an incorrect oracle price for wrst, leading to a $1 million loss. An attacker used a flash loan to repeatedly borrow wstETH, profiting from the distorted price. ([SlowMist](https://hacked.slowmist.io/en/))

[SlowMist stats this week](https://hacked.slowmist.io/statistics/?c=all&d=2025)
-------------------------------------------------------------------------------

Total 2025 hack events: 173

The total amount of money lost by blockchain hackers is about

$2,829,212,055

We must have regulations
========================

**Securing a Lithuanian Crypto License in 2025**

Hacken's guide outlines the process and requirements for obtaining a crypto license in Lithuania for 2025. It details the regulatory landscape, application procedures, and compliance obligations for businesses operating in the digital asset space. ([Hacken](https://hacken.io/discover/lithuania-crypto-license/))

---

*Originally published on [W3SB](https://paragraph.com/@w3sb/0x6-web3-security-bulletin)*
