<?xml version="1.0" encoding="utf-8"?>
            <?xml-stylesheet type="text/xsl" href="/preview.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
<atom:link href="https://stephenslab.top/zh/feed/622.xml" rel="self" type="application/rss+xml" />
    <title>Rekt</title>
    <link>https://rekt.news/</link>
    <description><![CDATA[DeFi / Crypto - Investigative journalism &amp;amp; creative commentary]]></description>
    <lastBuildDate>Tue, 16 Jun 2026 09:45:53 +0000</lastBuildDate>
    <generator>Rss Everything</generator>
    <ttl>360</ttl>



<item>




<guid isPermaLink="false">e9c038b8ee0996e7b973f2959b6a8313</guid>
<pubDate>Thu, 11 Jun 2026 14:53:26 +0000</pubDate>
<title>Syscoin - Rekt</title>
<link>https://rekt.news/syscoin-rekt</link>
<description><![CDATA[5 billion SYS minted from a malformed SPV proof that slipped past Syscoin’s bridge relay parser. The team published the receipts, coordinated a whitehat recovery, and the funds came back. No public audit record for the relay path that failed.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a454770eb9d1888146118b6985dcaae5</guid>
<pubDate>Tue, 09 Jun 2026 15:13:37 +0000</pubDate>
<title>TesseraDao - Rekt</title>
<link>https://rekt.news/tesseradao-rekt</link>
<description><![CDATA[One key held everything. TesseraDAO lost $2.49 million - minted from nothing, dumped, and gone through Tornado Cash. No multisig, no real audit, not even an acknowledgment that they were exploited. Just hollow men, straw governance, and a Telegram full of bots.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8ac6c642d6de9c775ffc10a359a2058d</guid>
<pubDate>Thu, 04 Jun 2026 17:13:40 +0000</pubDate>
<title>Gravity Bridge - Rekt</title>
<link>https://rekt.news/gravity-bridge-rekt</link>
<description><![CDATA[$5.4 million gone from Gravity Bridge after an attacker minted worthless tokens on Osmosis, poisoned the token registry with a fabricated denom string, and walked out with real assets. The attacker didn't break the code. They just found where it stopped asking questions.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b6662a57e7cbe9c18826fe68b7e8dc01</guid>
<pubDate>Tue, 02 Jun 2026 15:53:34 +0000</pubDate>
<title>DxSale - Rekt</title>
<link>https://rekt.news/dxsale-rekt</link>
<description><![CDATA[A 2021 DxSale locker, an unprotected admin key, $7.3 million gone. Decurity flagged the risk in 2023 for $500. Two compromised contracts holding $15.5 million remains untouched, for now.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f9eb8e83e0da30ad43b89970d9f797e1</guid>
<pubDate>Fri, 29 May 2026 12:01:01 -0400</pubDate>
<title>Poisoned Pipeline</title>
<link>https://rekt.news/poisoned-pipeline</link>
<description><![CDATA[One poisoned VS Code extension silently auto-updated to 2.2 million developers, and TeamPCP walked out with 3,800 GitHub internal repositories in eleven minutes, the culmination of eight months spent climbing the developer supply chain one trusted tool at a time.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">03b3d2202409c71741e1778b8152dea8</guid>
<pubDate>Thu, 28 May 2026 10:08:51 -0400</pubDate>
<title>New Market Trading - Rekt</title>
<link>https://rekt.news/newmarkettrading-rekt</link>
<description><![CDATA[$3.98 million drained from 88 Gnosis Safes across three chains on New Market Trading. A third-party Safe module trusted caller-supplied data over msg.sender. One missing require check. Anyone who read the source code could drain every wallet.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c0160786dabb532933b6261ab01346ce</guid>
<pubDate>Thu, 21 May 2026 13:48:01 -0400</pubDate>
<title>THORChain - Rekt III</title>
<link>https://rekt.news/thorchain-rekt3</link>
<description><![CDATA[A malicious node is believed to have exploited THORChain’s GG20 TSS signing stack to leak vault key material, reconstructed the private key offline, and drained $10.7 million across multiple chains. The network halted itself. The attacker was already gone.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">09e9f793f79b5f4679511233e2098925</guid>
<pubDate>Mon, 18 May 2026 14:13:37 -0400</pubDate>
<title>Paranoid By Default</title>
<link>https://rekt.news/paranoid-by-default</link>
<description><![CDATA[They told you to connect everything. You wrote the explainer. They sent you to a conference. On May 11, someone else did the checking - 170 packages, 518 million downloads, OpenAI's signing certificates. The unaudited stack is the attack surface. Be paranoid by default.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a061515613a062dfc371459e03529f76</guid>
<pubDate>Thu, 14 May 2026 16:00:53 -0400</pubDate>
<title>TrustedVolumes - Rekt</title>
<link>https://rekt.news/trustedvolumes-rekt</link>
<description><![CDATA[$5.87 million gone in one transaction. A permissionless signer function, a broken authorization check, and unlimited approvals did the rest. TrustedVolumes' contract was never open-sourced. The team hadn't posted in over a year. The bug bounty line is open.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7a3ad9cad2c5a200eef916fdded9450f</guid>
<pubDate>Tue, 12 May 2026 07:45:11 -0400</pubDate>
<title>Is Age Verification a Trap?</title>
<link>https://rekt.news/is-age-verification-a-trap</link>
<description><![CDATA[Is Age Verification a Trap? Every bill in this wave invokes children. Every system gets breached. Every jurisdiction that builds it never repeals it. The ratchet only turns one direction. And no one asked if you wanted it built.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">caacdfb56773fbeb080a3b0fa28d4559</guid>
<pubDate>Mon, 04 May 2026 14:52:58 -0400</pubDate>
<title>Wasabi Protocol - Rekt</title>
<link>https://rekt.news/wasabi-protocol-rekt</link>
<description><![CDATA[Admin key compromised, UUPS upgrades pushed to over a dozen vaults across four chains - Wasabi Protocol lost $5.9 million before most users saw a single alert. No multisig. No timelock. April 2026 was DeFi's worst month on record. Are we April Fools?


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f9c52b662f921d5e9e0d318c17e62ff1</guid>
<pubDate>Thu, 30 Apr 2026 11:40:05 -0400</pubDate>
<title>The Stack Nobody Checked</title>
<link>https://rekt.news/stack-nobody-checked</link>
<description><![CDATA[The AI protocol wired to your org has been exploited a dozen times since 2025. The creator called the flaw expected behavior. One hacker used Claude to breach nine Mexican agencies. Crypto firms on this stack could be exposing on-chain operations and internal comms.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>

  </channel>
</rss>

