A critical signature verification flaw drained $5.9 million from Trusted Volumes, exposing a design risk class affecting every RFQ protocol in DeFi. Today's briefing also covers npm supply-chain trojans, a CoW Swap DNS hijack, AI-assisted exploit discovery, and what the Ethereum ETH Rangers program can and cannot fix.
Audio is available on Spreaker — see link below.
A five-point-nine million dollar exploit just exposed one of the quietest vulnerabilities in decentralized finance: the signature verification layer that most RFQ protocols treat as settled infrastructure. Trusted Volumes, an OTC-style decentralized trading protocol, lost one thousand two hundred and ninety-one ETH, nearly seventeen WBTC, and a significant stack of stablecoins to an attacker who found a critical flaw in the protocol's fillOrder function.
The broader implication is that this isn't an isolated implementation error. It's a design risk class.
Separate from the Trusted Volumes breach, two malicious versions of the axios npm library were found bundling remote-access trojans targeting crypto developers. The signal here is the target: not users, but the developers building the tools users depend on.
On the frontend side, CoW Swap suffered a DNS hijack on April fourteenth that redirected users to a phishing site, costing one-point-two million dollars before the protocol shut down and launched a reimbursement program. A fake Ledger Live app persisted on the App Store long enough to drain nine-point-five million dollars from more than fifty users.
One development that shifts the timeline assumptions: Anthropic's Mythos model demonstrated the ability to discover sandbox-escape vulnerabilities and chain exploits in a proof-of-concept setting. Access is restricted.
The Ethereum ETH Rangers program just concluded, rewarding seventeen contributors for public-goods security work. That's a genuinely positive signal about community investment in defense.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.