Mmehveteroinmehvetero.com·Sep 15 · 6 min readThe Hacker Who Lost $7.73M to a Bot — rsETH Safe Module ExploitOn September 15, 2026, someone found a bug in a custom router module attached to a Gnosis Safe holding over $7.73 million in Aave-wrapped rsETH. They built the exploit, submitted it to the mempool — a01M
Mmehveteroinmehvetero.com·Sep 15 · 7 min read$500 vs the 1inch DAO Treasury — Anatomy of a Live Governance AttackOn September 14, 2026, a fresh wallet with six transactions submitted two governance proposals against 1inch DAO's treasury Safe. One of the two can actually execute. This post breaks down exactly wha00
Mmehveteroinmehvetero.com·Aug 27 · 9 min readHow $951 Bought a $8.5M Vote: The Term Finance Governance ExploitZero bugs. Zero hacks. Just a vote. On August 23, 2026, at 06:25 UTC, an attacker executed a single parameterless function call on Ethereum and walked away with $8.5 million from Term Finance's vaults42H
Mmehveteroinmehvetero.com·Aug 16 · 3 min readMy first competitive audit. Submitted as HIGH, came back as LOW. That stung for about ten minutes — then I re-read the judge's reasoning and they were right.SweepUnclaimedBonus_Drains_Attacker Summary A permissionless sweepUnclaimedBonus() between a moderator's SURVIVED flag and a corrective CORRUPTED re-flag irreversibly drains the bonus to recoveryAdd00
Mmehveteroinmehvetero.com·Aug 11 · 12 min readBlueMove Was Not an Overflow Bug — How a Cross-Version Reserve Desync Drained 714,000 SUIOn July 11, 2026, at 22:13 UTC, an attacker began draining liquidity pools on BlueMove DEX, a Sui-based AMM. Within 23 minutes, approximately 714,000 SUI — roughly $528,000 at the time — had crossed a00