On-Chain Shadow

Independent blockchain security research. In-depth investigations into DeFi exploits, rug pulls, phishing campaigns, and on-chain fraud.

13
Investigations
6+
Chains Covered
$2M+
Funds Traced
2026-06-05 north-korea

Drift Protocol $285M: North Korean APT Attack via HUMINT & Solana Nonce

$285M drained in 12 minutes by DPRK state-sponsored UNC6862 using 6-month HUMINT operation and Solana durable nonce exploit. The largest DeFi hack of 2026.

north-koreaaptsolanadefi-hackhumint
2025-05-27 sybil-attack

CWU Token Investigation: Sybil Attack & Wallet Farming Analysis

Deep-dive investigation into CWU Token revealing coordinated Sybil attack patterns and wallet farming schemes on BSC.

sybil-attacktoken-farmingbsc
2025-05-27 flash-loan

Echo Protocol Investigation: Flash Loan Exploit Analysis

Investigation of Echo Protocol flash loan exploit, tracing attacker wallets and fund movements across chains.

flash-loandefi-exploitarbitrum
2025-05-27 stablecoin

StablR Exploit Investigation: Stablecoin Depegging Attack

Analysis of the StablR stablecoin depegging exploit, including attack vector reconstruction and fund tracing.

stablecoindepegexploit
2025-05-28 phishing

Uniswap Phishing via Google Ads: Campaign Tracking & Wallet Analysis

Tracking a phishing campaign using Google Ads to target Uniswap users, with victim wallet analysis and fund tracing.

phishinggoogle-adsuniswapethereum
2025-05-28 bridge

Squid Router Module Investigation: Cross-Chain Bridge Vulnerability

Investigation of a vulnerability in the Squid Router module affecting cross-chain bridge operations.

bridgecross-chainsquid-routervulnerability
2025-05-28 governance

StakeDAO vsdCRV Investigation: Governance Exploit Analysis

Analysis of the StakeDAO vsdCRV governance exploit, including attack reconstruction and loss assessment.

governancestakedaocurveexploit
2025-05-28 sybil

WUSD Sybil Investigation: Airdrop Farming & Sybil Network Exposé

Comprehensive exposé of WUSD airdrop farming through coordinated Sybil networks spanning multiple chains.

sybilairdrop-farmingwusdmulti-chain
2025-06-03 rug-pull

DxSale Investigation: Rug Pull Pattern & Fund Diversion Analysis

Investigation of DxSale revealing rug pull patterns through fund diversion and liquidity manipulation on BSC.

rug-pulldxsalebscfund-diversion
2025-06-03 nft

TesseraDAO Investigation: NFT Fractionalization Exploit

Analysis of the TesseraDAO NFT fractionalization exploit, tracing stolen funds and identifying attack vectors.

nftfractionalizationexploittesseradao
2025-06-03 bridge

Gravity Bridge Investigation: Cross-Chain Bridge Exploit Analysis

Investigation of the Gravity Bridge cross-chain exploit, analyzing the attack on Cosmos IBC bridge infrastructure.

bridgecosmosgravity-bridgeexploit
2025-05-29 rug-pull

CATFI Rug Pull Investigation: Korean Crypto Scam Network

Investigation of the CATFI rug pull targeting Korean crypto investors, tracing stolen funds across exchanges.

rug-pullkoreacatfiscam
2025-05-29 phishing

Uniswap Phishing Ads: Google Ad Campaign Targeting DeFi Users

Detailed tracking of Google Ads phishing campaigns targeting Uniswap and DeFi users with fake interfaces.

phishinggoogle-adsdefiuniswap
2025-05-30 thorchain

THORChain Investigation: Protocol Vulnerability & Fund Loss Analysis

Analysis of THORChain protocol vulnerability leading to fund losses, with attack reconstruction and risk assessment.

thorchainprotocolvulnerabilityfund-loss