Skip to content
HeyJared

Verichains

Leading finance security firm in APAC. Trusted by top blockchain customers such as Binance, Bullish, Bybit, Galaxy Digital, Polygon, BNB Chain, Aptos, Sui, Kakao, Line Corp, Abu Dhabi Blockchain Center (ADBC), as well as many banks and mobile wallets.

Newsletter · By Verichains · English · Official site

Indexed issues, last 90 days
9
Latest publication
Sep 25, 2026
Audience
Checking…
Earliest in this view
Jul 13, 2026

Latest issues

  1. Issue · Sep 25, 2026

    NIMIQ HACK ANALYSIS (opens the original)

    Excerpt · Critical tone

    Read excerpt

    Nimiq is a browser-based crypto payments ecosystem whose wallet lets users hold, send and swap NIM, BTC and stablecoins such as USDC and USDT. On Polygon, it runs its own smart contracts to power gas-free stablecoin transfers and in-wallet atomic swaps.On September 16, 2026, Nimiq’s swap contracts on Polygon were exploited, resulting in a loss of approximately $50,463 (26,130.64 USDC, 24,332.49 USDT0 and 0.66 USDC.e) drained from Nimiq’s swap-liquidity wallet. The

  2. Issue · Sep 7, 2026

    Rain Hack Analysis: Ed25519 Signature Forgery Drains $1.1M from Visa Card Vaults (opens the original)

    Excerpt

    Read excerpt

    On August 28, 2026, someone emptied about $1.1 million out of crypto card accounts run by a company called Rain. They started the day with none of the keys that were supposed to protect the funds. In under three hours, they walked away with $1,118,597.The strange part is how they did it. The winning move was a signature made entirely of the same repeated byte, basically a signature of garbage. It should have been rejected instantly. Instead, the system waved it through and counted it as approval

  3. Issue · Aug 21, 2026

    Harmony Cross-Shard Receipt Replay: The Mint of 3 Trillion ONE (opens the original)

    Excerpt · Critical tone

    Read excerpt

    On August 12, 2026, Harmony Protocol suffered an unauthorized mint of approximately 4B ONE (~26% of the ~15.01B supply) in the first confirmed wave - ~3.01T ONE forged in total across the reconstructed attack (@harmonyprotocol). At the pre-incident price (~$0.001183) the forged amount carries a nominal value of ~$3.56B, roughly 200x ONE’s total supply and far beyond its market cap - neither realizable nor a loss figure, and no verified realized USD loss exists: the team patched the flaw and roll

  4. Issue · Jul 31, 2026

    [PWN2OWN IRELAND 2025] Bypassing Authentication via Synology DS925+ SAML SSO (opens the original)

    Excerpt

    Read excerpt

    I. StoryGetting into Pwn2Own that time was a bit of a lucky break for me: I found the bug and bypassed the requirement right before the registration deadline. When I first started hunting, I didn’t know anything about pwn, so I collabed with my friend (@ngocquy0307) to help me out during the process, reversing the parts of the code I couldn’t understand, and making sure we didn’t miss any pwn bugs. As for me, I decided to focus on logic vulnerabilities.Not long before the competition, I happened

  5. Issue · Jul 28, 2026

    Lazy Summer Hack Analysis: Stale-Asset Donation and ERC-4626 Share-Price Manipulation (opens the original)

    Excerpt

    Read excerpt

    On July 6, 2026, the Lazy Summer Protocol suffered an exploit on Ethereum mainnet that resulted in approximately $6.04 million in losses across two USDC vaults. The attacker used flash-loan liquidity, but the flash loan was only the amplifier. The underlying vulnerability was an incomplete strategy-offboarding process that left an impaired Silo Ark active in the vault’s net asset value calculation.The attacker accumulated Silo “Varlamore USDC Growth” vault tokens whose onchain valuation had not

Publishing over time

Last 90 days. Choose a month to open its work.

Recurring subjects

Named in the text we hold. One piece can cover several.

Audience

No verified audience measurement yet.

About this data

Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.

Identity or attribution wrong? Suggest a correction.

See coverage about Verichains