<?xml version="1.0" encoding="utf-8"?>
            <?xml-stylesheet type="text/xsl" href="/preview.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
<atom:link href="https://rsseverything.com/zh/feed/622.xml" rel="self" type="application/rss+xml" />
    <title>Rekt</title>
    <link>https://rekt.news/</link>
    <description><![CDATA[DeFi / Crypto - Investigative journalism &amp;amp; creative commentary]]></description>
    <lastBuildDate>Sun, 03 May 2026 14:40:22 -0400</lastBuildDate>
    <generator>Rss Everything</generator>
    <ttl>360</ttl>



<item>




<guid isPermaLink="false">f9c52b662f921d5e9e0d318c17e62ff1</guid>
<pubDate>Thu, 30 Apr 2026 11:40:05 -0400</pubDate>
<title>The Stack Nobody Checked</title>
<link>https://rekt.news/stack-nobody-checked</link>
<description><![CDATA[The AI protocol wired to your org has been exploited a dozen times since 2025. The creator called the flaw expected behavior. One hacker used Claude to breach nine Mexican agencies. Crypto firms on this stack could be exposing on-chain operations and internal comms.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">46f8e246dc55811250be26faef3e60c5</guid>
<pubDate>Thu, 30 Apr 2026 10:13:57 -0400</pubDate>
<title>Volo - Rekt</title>
<link>https://rekt.news/volo-rekt</link>
<description><![CDATA[$3.5 million drained from Volo on Sui after an admin private key was compromised, likely via social engineering. Three vaults hit - WBTC, XAUm, USDC. Volo self-disclosed first, and recovered nearly all of it, with a net loss of just $60K.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">047f1f58e2d397be420f11d41a796830</guid>
<pubDate>Thu, 30 Apr 2026 10:13:49 -0400</pubDate>
<title>KelpDao - Rekt</title>
<link>https://rekt.news/kelpdao-rekt</link>
<description><![CDATA[DPRK breached LayerZero's infrastructure, forged a bridge message, and walked $290 million out of KelpDAO in one transaction. Aave is holding hundreds of millions in bad debt. The dominoes are still falling. DeFi United is scrambling to catch them.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">4e48141cd4077c7de3eb41ea4dc7f467</guid>
<pubDate>Thu, 30 Apr 2026 10:13:41 -0400</pubDate>
<title>Rhea Finance - Rekt</title>
<link>https://rekt.news/rhea-finance-rekt</link>
<description><![CDATA[NEAR Protocol's Rhea Finance lost $18.4 million after an attacker exploited a margin parser that counted fake swap route minimums as real collateral. $9 million frozen or recovered. $4 million in ZEC routed into Zcash's shielded pool, cryptographically unrecoverable.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ad843f76dfd672f525e84d63f422cc5e</guid>
<pubDate>Thu, 30 Apr 2026 10:13:35 -0400</pubDate>
<title>Hyperbridge - Rekt</title>
<link>https://rekt.news/hyperbridge-rekt</link>
<description><![CDATA[On April 13, 2026, a missing bounds check in Hyperbridge's MMR proof verifier allowed forged proofs to pass. 1 billion DOT minted. Two attacks, combined with opportunistic withdrawals from drained pools, leading to $2.5 million in losses according to Hyperbridge.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3f97bd4b387d80838d4e9ad3521da44c</guid>
<pubDate>Thu, 30 Apr 2026 10:13:28 -0400</pubDate>
<title>Who Vets the Vetters?</title>
<link>https://rekt.news/who-vets-vetters</link>
<description><![CDATA[KYC giant Sumsub verifies millions of users for over 4,000 clients, but who verified Sumsub? Opaque ownership, unnamed investors, 18 months of undetected breach. The questions nobody thought to ask are still unanswered.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">25a8f8fdbf9390b36588c913c640fd39</guid>
<pubDate>Thu, 30 Apr 2026 10:13:25 -0400</pubDate>
<title>Drift Protocol - Rekt</title>
<link>https://rekt.news/drift-protocol-rekt</link>
<description><![CDATA[DPRK hackers spent 6 months sending proxies to befriend Drift Protocol. Conferences, trust, $1 million deposited. $285 million later, those friends vanished. No code broken. No bug found. Just a six-month con, a fake token, and a culture that never saw it coming.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b4db31bc451fc5759a5ca9a079480c94</guid>
<pubDate>Thu, 30 Apr 2026 10:13:17 -0400</pubDate>
<title>Resolv Labs - Rekt</title>
<link>https://rekt.news/resolv-labs-rekt</link>
<description><![CDATA[On March 22, Resolv Labs lost $25 million when a compromised private key handed an attacker unlimited USR minting power. No oracle check. No mint cap. 80 million tokens printed. Hardcoded oracles and automated liquidity kept feeding broken markets long after the damage was done.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f43e10e9796769c5dedb6c866e76768c</guid>
<pubDate>Thu, 30 Apr 2026 10:13:15 -0400</pubDate>
<title>Venus Protocol - Rekt IV</title>
<link>https://rekt.news/venus-protocol-rekt4</link>
<description><![CDATA[An attacker spent 9 months building a position, bypassed Venus Protocol's supply cap via a known donation exploit, and extracted $3.7 million, leaving $2.15 million in bad debt on a protocol that has now been rekt four times in five years.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">6cec8fd2cff8442f948d939209856430</guid>
<pubDate>Thu, 30 Apr 2026 10:13:06 -0400</pubDate>
<title>Price Impact Kills</title>
<link>https://rekt.news/price-impact-kills</link>
<description><![CDATA[Price impact kills. $50 million in, 327 AAVE out. Aave's interface routed through CoWSwap, a solver picked a $73K pool for a $50 million trade. Every warning fired. Every contract performed. The dark forest cleaned up the next block. Full fee refund planned.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0878737138f050d0bf6896c9171c3a3d</guid>
<pubDate>Thu, 30 Apr 2026 10:13:04 -0400</pubDate>
<title>Aave - Rekt</title>
<link>https://rekt.news/aave-rekt</link>
<description><![CDATA[A misconfigured oracle cap triggered $27.78 million in healthy wstETH liquidations on Aave on March 10. 34 accounts liquidated for a configuration error they had no part in. No attacker, no hack, no market crash. Full reimbursement planned.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3ac74831b7939d806d0c52bf591b35fe</guid>
<pubDate>Thu, 30 Apr 2026 10:12:55 -0400</pubDate>
<title>Solv - Rekt</title>
<link>https://rekt.news/solv-rekt</link>
<description><![CDATA[$2.73 million drained from Solv's BRO vault, a callback fired before the books balanced, minting the same deposit twice across 22 loops and turning 135 BRO into 567 million, all inside a single transaction. An unaudited contract with no bug bounty coverage, losses covered by the team, attacker exited to Tornado Cash.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>

  </channel>
</rss>

