Web3 Daily Exploits — 03 Sep 2026: Quiet window with governance alert and small drain
No major new exploits confirmed in the last 24 hours. Smaller alerts include a Yam Finance governance takeover attempt and a ~6 ETH GebProxyActions drain on Ethereum.

No major new exploits were confirmed in the last 24 hours after checks of DefimonAlerts, CertiKAlert, Phalcon, GoPlus, SlowMist, PeckShield, BlockSec, Lookonchain, ZachXBT and related feeds. Activity centered on a dormant-protocol governance alert and one small confirmed drain.
The window remains relatively quiet following the late-August cluster of larger incidents including Tectonic, Injective and Term Finance.
Yam Finance governance takeover attempt (unconfirmed outcome)
Defimon Alerts flagged a governance proposal on the dormant Yam Finance protocol. An attacker self-delegated approximately 504k YAM (roughly 3.3% of supply, sufficient for quorum) and submitted YamGovernorAlpha proposal #45 with an empty description. The sole action sets the pending admin of the YAM Timelock to the attacker address. If the proposal passes and executes, the attacker can accept admin and control protocol contracts and the DAO treasury.
Approximately $337k remains at risk in related pools. The protocol is largely inactive. Holders of delegated YAM were urged to vote against before the relevant block. Status: proposal live at time of alerts; no confirmed execution or successful takeover reported in the window. Confirmed alert by Defimon; outcome unverified as of this brief.
Relevant: https://x.com/DefimonAlerts/status/2095019159847313766
GebProxyActions / Reflexer-related drain (~5.94 ETH)
SlowMist reported a loss of approximately 5.9436 ETH linked to the GebProxyActions contract. The root cause was missing caller access control on quitSystem. A prior user call made directly (instead of via DSProxy delegatecall) recorded the GebProxyActions contract itself as owner of certain SAFEs. The attacker then called quitSystem directly, bypassing the safeAllowed check in GebSafeManager and transferring collateral.
Attacker: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896. Victim collateral positions on CollateralJoin1. Confirmed small loss by SlowMist monitoring. No broader protocol impact reported. Live loss remains the drained ETH (approximate USD value under $15k at prevailing prices).
Relevant: https://x.com/SlowMist_Team/status/2094986310683705835
Also noted
- Full Sail (Sui) announced shutdown and user reimbursement following an earlier ~$91k Switchboard oracle exploit; update circulated in the window.
- Continued discussion and technical breakdowns of the Injective binary-options settlement incident from late August (approx. $4.8–4.9M bridged), with chain-halt and patch details.
- Coldcard-related funds movement noted in secondary reporting.
Sources & references
- https://x.com/DefimonAlerts/status/2095019159847313766
- https://x.com/SlowMist_Team/status/2094986310683705835
- https://x.com/GoPlusSecurity/status/2095119564409651639 (Injective breakdown)
- Additional corroboration from SlowMist, Defimon and secondary aggregators.
Editor’s note: Strict 24-hour window applied. No major new confirmed multi-million losses first reported in this period. Always verify on-chain and official channels. This is a site post only.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

