π Welcome to the August Edition
We joined Sherlock's new Audit Engine, putting QuillShield's multi-agent review inside one of the industry's most-used audit platforms. And we went live on multisig security, breaking down how $1.7B has left secure wallets through hidden delegatecalls and drifting thresholds.
$144.1M stolen in August. One Cronos lending market lost more to a manipulated spot price than the other 21 incidents of the month combined. Full story in Hack Watch below.
On research, we mapped the freeze authority hiding inside neobank stablecoins, the habits that actually keep a multisig safe, and audit checklists for three RWA standards.
Here's the full August roundup.
From the Quill Research Desk
August's research kept landing on the same conclusion. The risk in every one of these systems sits in the privileged control surface, not the happy path, whether that's a Safe's module list, a stablecoin's freeze key, a token's admin role, or a vault's share price.
βHow to Check Your Safe Wallet's Security in 60 Seconds A hands-on walkthrough of Safe Inspector on a live Safe: 7 owners, a 4-of-7 threshold, and one module absent from the known registry. The scan scored 78 out of 100, an unrecognized module flagged for review, not assumed malicious.
βSomeone Else Controls the Neobank Dollars Over 11,000 USDT freeze actions across Ethereum and Tron have locked roughly $5.85 billion, with more than $1.4 billion permanently destroyed. Freeze, mint, and upgrade authority sit outside a neobank's control plane entirely, a risk no reserve attestation ever surfaces.
βMultisig Security Habits That Actually Matter Most multisig failures trace back to a habit nobody wrote down, not the code. Dedicated signing devices, thresholds that can't collapse to one compromise, out-of-band confirmation, and scheduled Safe reviews matter more than any dashboard number suggests.
βERC-3643 (T-REX) Security Audit Checklist A structural checklist for T-REX tokens, where every transfer clears an identity check and a compliance check before it settles, and privileged roles can freeze, force, mint, burn, and recover holdings entirely.
βERC-7518 (DyCIST) Security Audit Checklist A checklist for DyCIST's partitioned tokens, where each tokenId carries its own lockups and compliance rules, and eligibility often rests on a signed EIP-712 voucher. Get the voucher validation wrong and the entire compliance gate falls open.
βERC-4626 Vault Security Audit Checklist A checklist built around one number, the vault's share price, and every way an attacker can bend it. Inflation attacks and donation-based price spikes remain the standard's signature failure mode, preventable with virtual shares or dead-share seeding.
Hack Watch
August totals 22 incidents, $144.1M stolen, across 16 chains. The first three weeks stayed quiet at roughly $42.6M combined, then one contract call in the final week turned August into the third-worst month of the year.
βTectonic $75M Cronos, Aug 30, Oracle Manipulation. The attacker moved the spot price a Tectonic market trusted, then borrowed against the inflated collateral. No key leaked, no bridge failed, no access control broke. The feed alone moved $75 million in one call, more than the rest combined.
βMoonwell Lending $8.7M Base, Aug 27, Oracle Manipulation. An attacker donated MAMO tokens directly into the mMAMO contract, inflating the exchange rate 3.68 times without minting a share, then pushed MAMO's thin-liquidity price higher. A small deposit became $23 million of paper collateral, worth $11 million in borrows.
βTerm Labs $8.5M Ethereum, Aug 23, Governance Takeover. Almost nobody had wrapped their shares into Term's governance token, so half an ETH became the majority. A proposal disguised as a routine parameter veto disabled the vault's transaction delay, then drained six vaults for $8.5 million once voting closed.
βHarmony Bridge $3.2M Harmony, Aug 11, Cross-Shard Receipt Replay. A legacy check validated spent receipts using two unauthenticated fields, not the signed header, letting a used receipt replay as new with no debit on the source shard. Forged ONE ballooned to 3.01 trillion before a rollback, losses near $3.2M.
βMayaChain $1.7M Mayachain, Aug 18, Slash Subsidy Pool Inflation. A batched deposit's final message overwrote a shared voter record, tricking theft detection into slashing an uncapped subsidy into a pool with almost no liquidity. That credited 49 million CACAO the pool never had, withdrawn before the funding transfer failed.
Oracle manipulation was the month's real story. Lending markets alone absorbed $84.5M across three hits, and Cronos absorbed more in losses than every other chain combined, entirely on the back of one incident. Track the live incident log on QuillMonitor.
If a market reads a spot price, assume someone will eventually move it. If a foundation key is hot, assume it is already gone. If quorum is cheap to buy, the treasury is the prize. This month's lesson is to audit the feed, not just the contract.
QuillAudits Stats
A quick look at our August audit activity and how we helped secure the Web3 ecosystem.
Community Highlights
QuillShield joins Sherlock Audit Engine, putting multi-agent AI review inside one of the industry's most trusted audit platforms.
$1.7B has walked out of secure multisigs in 18 months, not from broken code but from what signers didn't see, and we went live to break down exactly how.
August's losses didn't require sophistication. They required a spot price nobody defended. $1.32B already lost this year. The baseline isn't improving.
We'll see you in September. Stay paranoid. Audit everything.
Wanna partner up w/ us or want to get your project audited? |
|
|
Have a great day,
Team QuillAudits