> ## Content Index
> Fetch the complete content index at: https://web3-daily-exploits.ghost.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Web3 Daily Exploits: Realio webapp signing-key, ENJ DELEGATECALL, Comet AMM, ...
- URL: https://web3-daily-exploits.ghost.io/web3-daily-exploits-26-august-2026-realio-enjin-comet-morpho/
- Published: 2026-08-26T12:19:37.000Z
- Updated: 2026-08-26T12:19:37.000Z
- Description: Realio webapp key compromise swept 124M+ RIO across five chains; Enjin Crypto Items proxy takeover minted a manager and melted ~5.24M ENJ; Comet AMM on Stellar was drained ~$750K; a Pendle TWAP nudge forced ~$36M in Morpho PT-reUSD liquidations.
- Author: Jacobo Avariento
- Tags: Exploits, Web3 Security, Crypto Hacks, DeFi, News, web3

**Two-line summary:** In the last 24 hours the largest live incident is a Realio webapp signing-key compromise that moved 124M–128M RIO across Ethereum, BNB Chain, Algorand, Stellar and Realio’s native chain, while Enjin’s legacy Ethereum Crypto Items stack lost \~5.24M ENJ after a DELEGATECALL storage-collision manager takeover. Alongside those, Comet AMM on Stellar was drained of roughly $750K via a same-asset swap accounting bug, and a 15-minute Pendle TWAP move forced about $36.4M of Morpho PT-reUSD liquidations without creating protocol bad debt.

*Coverage window: approximately 25 August 2026 07:00 ET through 26 August 2026 07:00 ET. Figures are as reported by on-chain monitors and may be revised. This is an incident briefing, not investment advice.*

## What matters this cycle

The day was not dominated by a single nine-figure smart-contract bug. It was dominated by three different failure classes landing at once:

- **Operational key / webapp compromise** at Realio, still producing second-wave transfers hours after the first public acknowledgment.
- **Classic Solidity proxy hygiene** on Enjin’s legacy Ethereum Crypto Items deployment: storage-layout collision under `DELEGATECALL`, then a malicious transfer adapter.
- **Market-structure / oracle-window risk** on Morpho, where a thin Pendle YT book moved a 15-minute TWAP just far enough to liquidate looped PT-reUSD at 90%+ LTV.

Stellar’s Comet AMM / Blend backstop pool and a small BNB Chain tax-token drain sit underneath those headlines. YieldBlox’s security council is already on-chain offering a 15% white-hat split on the Comet proceeds.

## 1\. Realio: webapp key compromise, five chains, still not fully contained

**Type:** compromised platform signing keys (not a published smart-contract 0-day)  
**First sweep:** 03:31 UTC, 25 August 2026  
**Second wave:** from 22:39 UTC 25 August into the morning of 26 August  
**Nominal take:** \~124.4M to \~127.9M RIO (\~$5.9M–$6.3M at then-spot)  
**Realized cash-out so far:** on the order of $230K–$265K, because the books are thin

Realio confirmed that [realio.fund](https://realio.fund/?ref=web3-daily-exploits.ghost.io) was attacked, halted platform access, told users to abandon that webapp in favor of Freehold, declared Algorand and Stellar RIO “dead assets,” and said Freehold and Districts were not impacted. Independent community forensics at [realiostats.com](https://realiostats.com/incident.html?ref=web3-daily-exploits.ghost.io) is the most detailed public ledger of the sweeps.

### What the chain shows

This does not look like a user-side drainer campaign. Sampled Algorand source accounts sit at the 0.20 ALGO rent-plus-opt-in floor typical of automatically generated custodial sub-accounts. No mass rekeying is visible. The Stellar receiving account was created and funded by the Realio treasury itself at 03:31 UTC, before the treasury was emptied. Deposits into platform-controlled accounts continued during the drain and were swept again. That combination is the fingerprint of a signing capability the webapp still held, not of 2,000 users independently approving a malicious spender.

Approximate split from the community report (totals moved slightly as the second wave ran):

- **Algorand:** \~43.85M RIO from the ASA reserve plus user dust; receiving account still holds tens of millions.
- **Stellar:** \~69.87M RIO from treasury plus user balances; selling continued on the Stellar DEX after the public post.
- **Realio native chain:** \~5.73M RIO from 2,374 holder accounts, then a halt at height **19,573,265** (10:38 UTC, 25 August).
- **BNB Chain:** two waves, first \~2.2M RIO / 163 accounts, then \~2.98M RIO / 1,574 accounts into the morning of the 26th.
- **Ethereum:** two waves across hundreds of accounts; the same collector kept moving balances after the official halt notice.

Most of the headline token count was treasury/reserve that had not been counted in circulating supply. The user-facing slice is smaller in tokens but worse in principle: the same key that could move reserves could move holder balances the webapp custodied.

Clawback is not available where it would matter most. Stellar issuer flags reported by researchers include `auth_clawback_enabled: false` and an immutable issuer. Algorand likewise has no practical clawback on the swept ASA. A native-chain restart from a pre-incident height could theoretically unwind the 5.73M RIO on Realio L1; nothing equivalent exists for Stellar or Algorand.

### Addresses and explorers

- EVM collector (Ethereum and BNB Chain): [0xbe827abf934cf7f4547e3285f100c39bf690a404](https://etherscan.io/address/0xbe827abf934cf7f4547e3285f100c39bf690a404?ref=web3-daily-exploits.ghost.io) · [BscScan](https://bscscan.com/address/0xbe827abf934cf7f4547e3285f100c39bf690a404?ref=web3-daily-exploits.ghost.io)
- Stellar receiver: [GBDMMICWFVSSU5YIKIVWG6EP3U65R2GIF7BICN3JIBES5NVGFZFLWXKZ](https://stellar.expert/explorer/public/account/GBDMMICWFVSSU5YIKIVWG6EP3U65R2GIF7BICN3JIBES5NVGFZFLWXKZ?ref=web3-daily-exploits.ghost.io)
- Algorand receiver: [RCES4II33PXVDX4ISQ3TWUZN5DP7JM6ZTDBJLARYQH53O4OLN5QTNYUJ6A](https://allo.info/account/RCES4II33PXVDX4ISQ3TWUZN5DP7JM6ZTDBJLARYQH53O4OLN5QTNYUJ6A?ref=web3-daily-exploits.ghost.io)
- Native collector: `realio1uzkdrfnjv53rt0cf4ltszffpd7mvkpd2cv794j`
- Stellar asset Realio now calls dead: [RIO-GBNLJIYH34UWO5YZFA3A3HD3N76R6DOI33N4JONUOHEEYZYCAYTEJ5AK](https://stellar.expert/explorer/public/asset/RIO-GBNLJIYH34UWO5YZFA3A3HD3N76R6DOI33N4JONUOHEEYZYCAYTEJ5AK?ref=web3-daily-exploits.ghost.io)
- Algorand ASA: [asset 2751733](https://allo.info/asset/2751733/token?ref=web3-daily-exploits.ghost.io)

MEXC and KuCoin suspended Algorand RIO deposits after community warnings. Realio says it identified attacker deposits at those venues and separately pinged Binance on a suspected deposit. CEXs were told BNB Chain RIO rails could reopen; Algorand and Stellar bridges stay closed.

**Operational takeaway:** a multi-chain RWA issuer that signs user and treasury movements from one webapp plane has a single secret that is economically equivalent to a hot-wallet cluster. Compromising that secret is enough. No Solidity bug is required.

Primary sources: [Realio acknowledgment](https://x.com/realio%5Fnetwork/status/2092288120918044688?ref=web3-daily-exploits.ghost.io) · [dead-asset warning](https://x.com/realio%5Fnetwork/status/2092315965891465233?ref=web3-daily-exploits.ghost.io) · [Binance freeze request](https://x.com/realio%5Fnetwork/status/2092339791509717163?ref=web3-daily-exploits.ghost.io) · [Crypto Times write-up](https://www.cryptotimes.io/2026/08/26/realio-web-app-compromised-as-attacker-moves-124m-rio-across-five-chains/?ref=web3-daily-exploits.ghost.io)

## 2\. Enjin Crypto Items: DELEGATECALL slot collision, then melt()

**Type:** proxy storage collision + malicious ERC-1155 transfer adapter  
**Chain:** Ethereum (legacy Crypto Items deployment; Enjin L1 itself is not the drained surface)  
**Time:** 25 August 2026, 18:41:59 UTC  
**Loss:** \~5.24M ENJ redeemed from the platform reserve, \~$142K at \~$0.027; SlowMist later tagged the incident \~$162K

Defimon flagged the economic path first. SlowMist published the privilege-escalation path a few hours later. They describe the same job from two layers.

### Layer A — how the attacker became manager

Enjin’s Managed Delegate Proxy executes registered adapters in the proxy’s storage context via `DELEGATECALL`. That is only safe if every adapter shares the proxy’s storage layout. SlowMist says a registered adapter exposed a public `initialize(uint256)` that writes adapter slot 1, while the proxy already uses slot 1 for `pendingManager`.

Call that initializer through the proxy and the attacker’s address lands in `pendingManager`. `acceptManager()` finishes the takeover. After that, the attacker can register any adapter they want.

This is the same family as historical initializer / storage-collision incidents (Audius is the comparison SlowMist’s thread drew). The bug is not “ERC-1155 is unsafe.” The bug is “an upgradeable proxy executed foreign bytecode against its own slots.”

### Layer B — how manager rights became ENJ

Crypto Items route transfers through a per-item adapter so creators can attach custom logic. The attacker registered or invoked an adapter that omitted the owner-approval check. From the exploit contract they called `transferFrom(holder, attacker, 1)` against \~52 unrelated wallets. None of those wallets had set `setApprovalForAll`, signed a permit, or otherwise authorized the attacker. The resulting `TransferSingle` events look like ordinary transfers because, at the token layer, they were.

Each stolen item was then `melt()`ed. Melt burns the item and pays out the 500 ENJ backing from the platform reserve. Across the batch that is \~5.24M ENJ, forwarded to the attacker EOA. Holders lose the item; the reserve loses the backing. Defimon noted there is no sign Enjin’s core ERC-1155 implementation, the Substrate Enjin L1, or arbitrary user EOAs were compromised — only items whose routing went through the bad adapter after the proxy was seized.

At the time of writing Enjin had not posted a public incident note. That silence is itself part of the story: the drained surface is a pre-cutover Ethereum deployment, but the ticker and the brand are the same.

### Addresses and explorers

- Exploit transaction: [0xd4a382da03c99ce3084661b913b50b525a4b283f66f510bcf1040152830b2a7e](https://etherscan.io/tx/0xd4a382da03c99ce3084661b913b50b525a4b283f66f510bcf1040152830b2a7e?ref=web3-daily-exploits.ghost.io)
- Attacker EOA: [0x5ec1ba7892d11059c39557b762a97dd695778ca5](https://etherscan.io/address/0x5ec1ba7892d11059c39557b762a97dd695778ca5?ref=web3-daily-exploits.ghost.io)
- Attack contract: [0x7083ddece38216c7741fa76c75326bea744ed321](https://etherscan.io/address/0x7083ddece38216c7741fa76c75326bea744ed321?ref=web3-daily-exploits.ghost.io)
- Compromised proxy: [0x268c039a3127d3107c014f0dc6c390a53e6db27f](https://etherscan.io/address/0x268c039a3127d3107c014f0dc6c390a53e6db27f?ref=web3-daily-exploits.ghost.io)
- Platform reserve (melt source): [0x4e643a25a64952895f553f20252861258727174e](https://etherscan.io/address/0x4e643a25a64952895f553f20252861258727174e?ref=web3-daily-exploits.ghost.io)

Primary sources: [Defimon alert](https://x.com/DefimonAlerts/status/2092331652882002208?ref=web3-daily-exploits.ghost.io) · [SlowMist TI](https://x.com/SlowMist%5FTeam/status/2092455321654694355?ref=web3-daily-exploits.ghost.io) · [Crypto Times](https://www.cryptotimes.io/2026/08/26/enjin-crypto-items-exploit-drains-5-24m-enj-from-52-wallets/?ref=web3-daily-exploits.ghost.io)

## 3\. Comet AMM / Blend backstop on Stellar: same-asset swap wrecks reserves

**Type:** AMM accounting bug (same-asset swap), flash-loan amplified  
**Chain:** Stellar  
**Window:** \~03:51–04:44 UTC, 25 August 2026 (white-hat / council messages posted later the same day)  
**Loss:** \~$717K–$750K from the BLND-USDC Comet pool used in Blend’s backstop

The pool accepted a USDC→USDC swap. That should be a no-op. Instead it corrupted reserve accounting, so a subsequent withdraw paid out more than the attacker had deposited. Researchers describe \~36 iterations through four throwaway contracts funded by a wallet created minutes earlier. Pattern per run:

1. Flash-loan \~530,000 USDC from a Blend pool.
2. Hit the CometDEX pool with the same-asset swap.
3. Withdraw the inflated excess.
4. Repay the flash loan in the same transaction.

Per-run profit decayed from the mid-five-figures down toward \~$6K as the pool emptied. Roughly 747,801 USDC then left Stellar via Allbridge. BLND printed an ugly candle against XLM (reports in the 85–90% range on the local pair) because the backstop pool is where Blend’s insurance math lives.

This is not an oracle attack and not a “dump the token” attack, even though a large BLND print hit the book. The invariant broke first. Price followed.

As of community notes later on the 25th, the pool contract had not been patched and still held residual USDC and BLND. Whitehats were discussing pulling remaining liquidity. Do not provide liquidity to `CAS3FL6T…VEAM` until a patched implementation is deployed and the old pool is explicitly retired.

### White-hat channel

YieldBlox Security Council posted an on-chain message offering 15% of the stolen amount if 85% is returned within 72 hours, with a Stellar proof-of-control transaction and contact paths:

- Email: gm@script3.io
- Ethereum messenger: [0x456c2F5F3536b1D9238F4654D5242B0dF8f978AF](https://etherscan.io/address/0x456c2F5F3536b1D9238F4654D5242B0dF8f978AF?ref=web3-daily-exploits.ghost.io)
- Stellar council: [GBCAS7XIGDRZY4BMABJMGGW7J3YTITRRV5BTEMFQE5ZZSSVWHHX2ZSS4](https://stellar.expert/explorer/public/account/GBCAS7XIGDRZY4BMABJMGGW7J3YTITRRV5BTEMFQE5ZZSSVWHHX2ZSS4?ref=web3-daily-exploits.ghost.io)
- Proof tx: [8e5e682eed6e478e9814be485332e5369c75fa861f78b9e519034eaf414eba09](https://stellar.expert/explorer/public/tx/8e5e682eed6e478e9814be485332e5369c75fa861f78b9e519034eaf414eba09?ref=web3-daily-exploits.ghost.io)

### Addresses and explorers

- Comet pool: [CAS3FL6TLZKDGGSISDBWGGPXT3NRR4DYTZD7YOD3HMYO6LTJUVGRVEAM](https://stellar.expert/explorer/public/contract/CAS3FL6TLZKDGGSISDBWGGPXT3NRR4DYTZD7YOD3HMYO6LTJUVGRVEAM?ref=web3-daily-exploits.ghost.io)
- Stellar attacker account reported in community threads: [GCENJ4XBLXCPENO7HOIKD2DBAOBUOFZWS2DRHMCCDKC3PQYNSSGHWYHC](https://stellar.expert/explorer/public/account/GCENJ4XBLXCPENO7HOIKD2DBAOBUOFZWS2DRHMCCDKC3PQYNSSGHWYHC?ref=web3-daily-exploits.ghost.io)
- Related EVM address flagged by Defimon: [0x0ff9ebafc1ef4a0aa479533dff8ecb10492df7da](https://etherscan.io/address/0x0ff9ebafc1ef4a0aa479533dff8ecb10492df7da?ref=web3-daily-exploits.ghost.io)

Primary sources: [Defimon / council quote-tweet](https://x.com/DefimonAlerts/status/2092344641534271648?ref=web3-daily-exploits.ghost.io) · [on-chain bounty message](https://x.com/DefimonAlerts/status/2092322053911155117?ref=web3-daily-exploits.ghost.io)

## 4\. Morpho × Pendle: 15-minute TWAP, $36.4M of liquidations, no bad debt

**Type:** oracle-window / market-structure liquidation cascade (not a Morpho contract exploit)  
**Time:** 04:28–04:51 UTC, 25 August 2026  
**Forced volume:** \~$36.1M–$36.39M repaid across 33 Morpho liquidations  
**Liquidator extract:** on the order of \~$360K by public estimates  
**Protocol bad debt:** none reported

PeckShield flagged wallet `0x854e…690d` market-buying YT-reUSD, driving implied APY through \~20%, then dumping the YT. Pendle identity: buying YT dumps PT into the same AMM. The PT-reUSD pool that prices the Morpho collateral is only \~$9M deep. The Morpho market that accepts that PT as collateral had \~$67.5M collateral against \~$52.2M borrows at a 91.5% liquidation LTV. That ratio is the entire story.

Steakhouse’s feed for the market takes the *lower of* (a) a 15-minute Pendle TWAP and (b) a fixed discount curve (\~6% annual) that accretes to $1 at the 10 December 2026 maturity. When the spot PT print fell \~2.8%, the 15-minute window became the min and marked looped accounts underwater. Morpho’s API recorded 33 liquidation events between 04:37:47 and 04:51:23 UTC, seizing \~38.6M PT and repaying \~$35.19M USDC plus \~$0.96M USDT. Largest single accounts sat near $13.0M, $11.0M and $6.8M.

Pendle and Steakhouse both said the oracle did what it was configured to do. That is technically true and operationally unsatisfying. A 15-minute window on a long-dated, thin PT pool is an invitation to spend six figures moving a book that is an order of magnitude smaller than the lending market stacked on top of it. LlamaRisk has already floated a slower, gated PT oracle design (multi-day smoothing, drift caps, maturity-aware LT) for Aave; expect every PT-as-collateral curator to be asked the same question this week.

Note on taxonomy: this is an economic attack on a configuration, not a stolen-funds exploit. Lenders were kept whole. Borrowers who looped PT-reUSD to a 1.03 health factor paid the bill.

Primary sources: [PeckShield alert](https://x.com/PeckShieldAlert/status/2092160761087082572?ref=web3-daily-exploits.ghost.io) · [The Defiant](https://x.com/DefiantNews/status/2092288449227436383?ref=web3-daily-exploits.ghost.io) · [Crypto Times](https://www.cryptotimes.io/2026/08/25/morphos-15-minute-twap-oracle-exploited-in-36-4m-liquidation-attack/?ref=web3-daily-exploits.ghost.io) · [The Defiant article](https://thedefiant.io/news/defi/pendle-oracle-move-liquidates-usd36-million?ref=web3-daily-exploits.ghost.io)

## 5\. FHToken on BNB Chain: sell-tax burns the pool, then sync()

**Type:** deflationary / sell-tax reserve desync  
**Chain:** BNB Chain  
**Loss:** \~$20K USDT from the FH/USDT PancakeSwap V2 pair  
**Reported:** SlowMist, 26 August 2026 03:33–03:41 UTC

FHToken’s `_transfer` treats sells as a special case: 80% of a tax is burned, 20% goes to treasury, and the pair is `sync()`ed *before* the seller’s net tokens arrive. Burning and syncing against the pair’s own balance moves reserves without a matching swap input. Loop buy → sell a few times and USDT walks out of the pool.

This class is old. Every taxed token that mutates pair balances inside `_transfer` and then calls `sync()` or `skim()` is one rounding error away from the same drain. The dollar figure is small. The pattern is not.

- Attacker: [0x7fa3bc0d5667ffd14d7acd6ce5f2432ac13a6fda](https://bscscan.com/address/0x7fa3bc0d5667ffd14d7acd6ce5f2432ac13a6fda?ref=web3-daily-exploits.ghost.io)
- Victim pair: [0x8f2d1a3992856a860304f1b86534b6b129cc4df7](https://bscscan.com/address/0x8f2d1a3992856a860304f1b86534b6b129cc4df7?ref=web3-daily-exploits.ghost.io)
- Token: [0xdcf0dfe0053677a67610c6d08ea1f5c78df8ca37](https://bscscan.com/token/0xdcf0dfe0053677a67610c6d08ea1f5c78df8ca37?ref=web3-daily-exploits.ghost.io)

Source: [SlowMist TI](https://x.com/SlowMist%5FTeam/status/2092457395666751707?ref=web3-daily-exploits.ghost.io)

## 6\. Adjacent items security desks were still working overnight

### Personal EOA drain, $391K, on-chain ransom/white-hat offer

Defimon relayed an on-chain message from the owner of [0x9170975AAd82bA5d73d51537EA3B64CB62CF84A4](https://etherscan.io/address/0x9170975AAd82bA5d73d51537EA3B64CB62CF84A4?ref=web3-daily-exploits.ghost.io). They say that on 23 August the holder of [0x928Ce4a552f0b3152770509F55884A442859dC60](https://etherscan.io/address/0x928Ce4a552f0b3152770509F55884A442859dC60?ref=web3-daily-exploits.ghost.io) took 149.32 stETH, 1,066 LINK and 4.06 ETH (\~$391K) in 31 seconds — framed as one household’s savings, not a fund. The offer on the table: return 80% to [0x37Fe5783915DDeCCF5fF90CC7382eda2eC4C0a0C](https://etherscan.io/address/0x37Fe5783915DDeCCF5fF90CC7382eda2eC4C0a0C?ref=web3-daily-exploits.ghost.io), keep 20% (\~$78K) as a bounty, before a Lido withdrawal finalizes. FBI IC3 `9abe96a677d547499c3f6d99e3007ea3`, FTC `205900025` and Chainabuse `CA-2026-371815` are cited, plus notices to Binance, Coinbase, Kraken, OKX, Bybit, HTX and Gate.

Signed proof of ownership: [Etherscan verifySig 335999](https://etherscan.io/verifySig/335999?ref=web3-daily-exploits.ghost.io) · related tx [0x233b0b57285201bbb37159e345c7a9ec601dace9f7d46f6a9cb65438ad472bf3](https://etherscan.io/tx/0x233b0b57285201bbb37159e345c7a9ec601dace9f7d46f6a9cb65438ad472bf3?ref=web3-daily-exploits.ghost.io)

Sources: [message](https://x.com/DefimonAlerts/status/2092383846352183316?ref=web3-daily-exploits.ghost.io) · [signature](https://x.com/DefimonAlerts/status/2092385304556564886?ref=web3-daily-exploits.ghost.io)

### $KYLIE and a 39.5M-follower X account

On 24 August the verified Kylie Jenner account posted a Pump.fun link and Solana mint [6b7KQsXqb6JR5Nmeer5zGRmo51dwDfttM5b5Nu2rpump](https://solscan.io/token/6b7KQsXqb6JR5Nmeer5zGRmo51dwDfttM5b5Nu2rpump?ref=web3-daily-exploits.ghost.io), then deleted. Market cap printed \~$1.2M and dumped more than 90%. On-chain work circulating 25–26 August (relayed by The Block) says the token operators held \~40% of supply at the moment of the post, took no profit until the tweets landed, then pulled \~2,425 SOL through a coordinated wallet set. No public on-chain link from those wallets to Jenner or her team has been shown. Jenner has not commented. Treat it as an account-takeover-to-memecoin pattern, not as a protocol exploit — and not as confirmed attribution.

Sources: [The Block](https://x.com/TheBlockCo/status/2092430239943283155?ref=web3-daily-exploits.ghost.io) · [Cryptonews](https://cryptonews.net/news/security/33345257/?ref=web3-daily-exploits.ghost.io)

### Cosmos EVM v0.7.2 and the notification gap

BlockSec Phalcon spent 25 August amplifying KiiChain’s post-mortem: Cosmos EVM v0.7.2 quietly shipped fixes for critical bugs while some affected chains say they were not promptly notified. Public acknowledgment from Cosmos Labs came after multiple chains had already been exploited (TAC’s late-August drain sits in that cluster). This is not a new hash from the last 24 hours. It is the systemic aftershock: a shared precompile layer means one patch disclosure policy is now a multi-chain incident-response policy, whether vendors like that framing or not.

Sources: [Phalcon](https://x.com/Phalcon%5Fxyz/status/2092110994076238291?ref=web3-daily-exploits.ghost.io) · [weekly roundup (17–23 Aug, \~$10.26M)](https://x.com/Phalcon%5Fxyz/status/2092538466257227909?ref=web3-daily-exploits.ghost.io)

### Term Finance, still parked

PeckShield noted the labeled Term Labs exploiter deposited 300 ETH (\~$741K) into Tornado Cash. The 23 August governance drain (\~$8.5M from vaults whose electorates were empty enough that a few dollars of vault shares bought the vote) is outside this 24-hour window, but the cash-out is not finished.

Source: [PeckShield](https://x.com/PeckShieldAlert/status/2092047363162673357?ref=web3-daily-exploits.ghost.io)

## What to do if you touch these surfaces

- **RIO holders who used realio.fund:** stop using that webapp. Move to an external wallet / Freehold as the team instructed, rekey if the chain supports it, and assume any balance the webapp could sign for is hostile until proven otherwise. Do not buy Algorand or Stellar RIO.
- **ENJ Crypto Items on Ethereum:** treat per-item adapters and the Managed Delegate Proxy as tainted until Enjin publishes a patched manager and a list of affected token IDs. Melting through the old path is how the reserve was emptied.
- **Stellar Blend / Comet LPs:** do not deposit into the flagged pool. Watch for an official patched pool address from YieldBlox / Blend, not a lookalike contract.
- **Anyone looping Pendle PTs on Morpho or elsewhere:** a 15-minute TWAP plus a 91% LT on a book smaller than the loan book is a liquidation product, not a peg. Size the buffer to the cost of moving the YT side, not to yesterday’s implied APY.
- **Tax-token LPs on Pancake V2:** if `_transfer` can burn pair balance and call `sync()`, you are the exit liquidity.

## Method and monitors

This briefing is compiled from public X alerts and corroborating write-ups in the coverage window, principally [@DefimonAlerts](https://x.com/DefimonAlerts?ref=web3-daily-exploits.ghost.io), [@SlowMist\_Team](https://x.com/SlowMist%5FTeam?ref=web3-daily-exploits.ghost.io), [@Phalcon\_xyz](https://x.com/Phalcon%5Fxyz?ref=web3-daily-exploits.ghost.io), [@PeckShieldAlert](https://x.com/PeckShieldAlert?ref=web3-daily-exploits.ghost.io), [@realio\_network](https://x.com/realio%5Fnetwork?ref=web3-daily-exploits.ghost.io), plus [realiostats](https://realiostats.com/incident.html?ref=web3-daily-exploits.ghost.io), Crypto Times, The Defiant and BlockSec’s weekly note. CertiKAlert did not publish a matching item in this exact window. Dollar figures move with oracle prints and with how much of a treasury token you count as “lost” versus “repriced.” Where those disagree we show both.

*Not legal advice. Addresses are provided for investigation and defensive blocking; do not send funds to attacker accounts.*