exvulsec Profile Banner
ExVul Profile
ExVul

@exvulsec

Followers
4K
Following
433
Media
299
Statuses
670

State-of-the-art Web3 security services (audits, pentest etc). We are trusted by OKX, Bitget, Stacks, Aptos, Sui, Core, Suiet, etc @exvuldefender

Web3 World
Joined September 2023
Don't wanna be here? Send us removal request.
@exvulsec
ExVul
16 hours
RT @BuildwithSei: ExVul has secured $2.3B+ in assets and detected 10,000+ onchain incidents. Now, they are supporting builders on Sei, who….
0
3
0
@exvulsec
ExVul
23 hours
We’re proud to support @SeiNetwork, the fastest layer 1 blockchain with rails purpose-built for high performance digital asset markets. ⚡️. As a global leader in blockchain security, ExVul has secured $2.3B+ in assets and detected 10,000+ on-chain incidents, trusted by top
Tweet media one
6
20
124
@exvulsec
ExVul
3 days
It’s our great pleasure to work with @AimonicaBrands team!. Security is always a dark forest, but luckily we got partners to walk it through 🫡🫡.
@AimonicaBrands
Aimonica 🩵 🫧
3 days
In the shadows of Web3, only code tells the truth as trust needs to be encrypted. Before our next major evolution @exvulsec, trusted by Sui, Aptos, Bitget, and other top-tier players, inspected my new code line by line, soul to soul. We don’t take launches lightly. This one
Tweet media one
2
5
18
@exvulsec
ExVul
4 days
RT @u2u_xyz: That’s a wrap on @gmvn_official – and U2U Network showed UP. U2U Network came in HOT as Platinum Sponsor – and the numbers do….
0
7
0
@exvulsec
ExVul
14 days
New smart contract audit report is out, this time for @MangoOS_Network 🥭. Mango is a blazing-fast, multi-VM Layer 1 integrating +MoveVM, +EVM, and +SVM — aiming to solve liquidity fragmentation at the root with an architecture built on Move, OPStack & ZK Rollups 🔁🧠. We found 1
Tweet media one
0
2
5
@exvulsec
ExVul
15 days
our great pleasure to support @u2u_xyz chain! . The one and the only layer 1 backed by The Vietnam government. Come join us at 8.2 in Hanoi for the GM Vietnam after party!.
@u2u_xyz
U2U Network
15 days
Gold Sponsor alert: @exvulsec just locked in for the GM Vietnam After Party. Scanned thousands of contracts, stopped 10K+ attacks, and helped recover $2.3B. From deep audits to high-stakes pentests, ExVul is the security squad trusted by the top chains – ETH, BNB, Aptos, U2U &
Tweet media one
0
2
9
@exvulsec
ExVul
15 days
congrats folks being successfully live on mainnet!. our pleasure to secure the first botanix-native prep dex!.Let's have fun!.
0
0
1
@exvulsec
ExVul
16 days
RT @u2u_xyz: Security check ✅. U2U Network passed the test with THREE elite Web3 security squads: @exvulsec, @Hashlock_ & @SlowMist_Team. →….
0
15
0
@exvulsec
ExVul
16 days
🚀 @MangoOS_Network × ExVul. Securing the next-gen omnichain Layer 1 infrastructure 🛡️. We’re proud to announce our smart contract audit partnership with Mango Network — a high-performance, multi-VM Layer 1 integrating MoveVM, EVM, and SVM. With groundbreaking architecture that
Tweet media one
2
1
5
@exvulsec
ExVul
16 days
Big congrats on our partner @DelphinusLab being listed on the Binance alpha! 🏆🏆. We have partnered for a long run and it's our honor to see more and more of our clients get to known by the world. Once again, congrats guys! From here only upward!
Tweet media one
0
0
3
@exvulsec
ExVul
24 days
🚨 ALERT: @ArcadiaFi Exploited on Base for ~$2.5 Million 🚨. @ArcadiaFi has been exploited on the Base network, resulting in a loss of approximately $2.5 million. The attacker swapped the stolen tokens for ETH and subsequently bridged them from Base to the Ethereum . All of the
Tweet media one
1
1
7
@exvulsec
ExVul
25 days
At ExVul we treat recruiting 🪧like vulnerability hunting: the real prizes🏆 are rarely sitting in plain sight. We scour hackathons, contest leaderboards, and obscure Git commits for sharp minds—and they often track us down first. The result? A crew built on curiosity, not.
1
0
7
@exvulsec
ExVul
28 days
ExVul IOP Victory Lap🏆. Back-to-back @immunefi IOP wins! . ExVul ranked Top 2 in both the Paradex @tradeparadex and Term Structure Institutional (TSI) @TermMaxFi IOPs, proving our researchers can duel it out with the best. Scoreboard. • Paradex: 1 Critical.• TSI: 2.
2
3
11
@exvulsec
ExVul
29 days
The moral. Design can fail louder than code. A single misplaced .call plus a generous accounting rule turned GMX’s vault into an ATM. If your protocol mints or redeems against “book value,” remember: attackers can rewrite the books faster than you can say commit. Stay safe.
0
0
1
@exvulsec
ExVul
29 days
Anatomy of the failure. • External .call with no guard.• Leverage flag flipped after the call—state not atomic.• AUM formula vulnerable to instant, unpriced P/L swings.
1
0
0
@exvulsec
ExVul
29 days
Finish line at 12 : 42 UTC. Final haul: ≈ 11 700 ETH routed to fresh wallets. Vault short $40–42 M. Runtime? About a coffee break.
Tweet media one
1
0
0
@exvulsec
ExVul
29 days
Eight spins of the wheel. The contract loops this dance eight times, cycling tokens to dodge slippage limits. Every round mints GLP, spikes AUM, redeems, repays the flash-loan, pockets the surplus.
1
0
0
@exvulsec
ExVul
29 days
Why the math prints money. In GMX, unrealised losses from global shorts are counted as vault assets. Open a huge short → AUM spikes → each GLP now redeems for a fatter slice. The attacker simply cashes the delta.
Tweet media one
1
0
0
@exvulsec
ExVul
29 days
A flash-loan symphony. Within that callback the attacker:. 1️⃣ Borrows USDC via Uniswap V3 flash-loan. 2️⃣ mintAndStakeGlp()—adds fresh GLP. 3️⃣ increasePosition()—opens a massive short, instantly inflating the vault’s AUM. 4️⃣ unstakeAndRedeemGlp()—asks for WBTC (or
Tweet media one
2
0
1