Mmehveteroinmehvetero.com·Aug 27 · 9 min readHow $951 Bought a $8.5M Vote: The Term Finance Governance ExploitZero bugs. Zero hacks. Just a vote. On August 23, 2026, at 06:25 UTC, an attacker executed a single parameterless function call on Ethereum and walked away with $8.5 million from Term Finance's vaults42H
Mmehveteroinmehvetero.com·Aug 16 · 3 min readMy first competitive audit. Submitted as HIGH, came back as LOW. That stung for about ten minutes — then I re-read the judge's reasoning and they were right.SweepUnclaimedBonus_Drains_Attacker Summary A permissionless sweepUnclaimedBonus() between a moderator's SURVIVED flag and a corrective CORRUPTED re-flag irreversibly drains the bonus to recoveryAdd00
Mmehveteroinmehvetero.com·Aug 11 · 12 min readBlueMove Was Not an Overflow Bug — How a Cross-Version Reserve Desync Drained 714,000 SUIOn July 11, 2026, at 22:13 UTC, an attacker began draining liquidity pools on BlueMove DEX, a Sui-based AMM. Within 23 minutes, approximately 714,000 SUI — roughly $528,000 at the time — had crossed a00
Mmehveteroinmehvetero.com·Aug 1 · 8 min readHow a Missing `assert!` Drained $3.44M From Typus Finance — and Why the Code Looked CorrectOn October 15, 2025, at 13:05 UTC, an attacker began draining Typus Finance's TLP liquidity pool on the Sui network. Thirty-four minutes later, the contracts were paused — but the pool was already emp00
Mmehveteroinmehvetero.com·Jul 27 · 7 min readThree Sui Exploits, One Disease — Why "The Math Looked Fine" Keeps Costing Hundreds of MillionsCetus lost $223M to a shift overflow. Aftermath lost $1.14M to a negative fee. Bucket Protocol ships a decimal scaling bug today. All three passed audits. All three have the same root cause. I've spe00