Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Microsoft Warns of New USB-Based Malware Targeting Crypto Users

June 21, 2026

JaredFromSubway MEV bot gets drained in $7.5m approval trap

June 21, 2026

Solana Transactions Surge as Social Buzz Fades — What Does It Mean for SOL’s Next Rally?

June 21, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Blockchain

Fireblocks Thwarts SWEAT and HOT Exploits on NEAR, Protecting Millions

By WebDeskJune 16, 20263 Mins Read
Fireblocks Thwarts SWEAT and HOT Exploits on NEAR, Protecting Millions
Share
Facebook Twitter LinkedIn Pinterest Email


Ted Hisokawa
Jun 16, 2026 17:58

Fireblocks detected and mitigated critical zero-day flaws in SWEAT and HOT contracts on NEAR, safeguarding 22M users from potential multi-million dollar losses.





Fireblocks has revealed its role in identifying and mitigating two critical zero-day vulnerabilities that could have cost NEAR Protocol users millions of dollars. The flaws were discovered in the contracts of SWEAT, a token powering the Sweat Economy ecosystem, and HOT, a Web3 governance token with over 22 million holders.

In late April 2026, Fireblocks’ blockchain monitoring flagged unusual transactions on NEAR involving SWEAT tokens. Attackers were draining wallets without requiring private keys, phishing links, or user signatures. One victim alone lost 8.5 million SWEAT tokens in a single exploit, valued at $170,000 to $250,000. The problem stemmed from a missing security guard in the ft_resolve_transfer callback function, which refunded token balances without verifying the caller’s identity.

The exploit leveraged NEAR’s token standard (NEP-141), which uses ft_resolve_transfer to refund unused balances. In SWEAT’s implementation, this function lacked NEAR’s #[private] macro, leaving it exposed to public calls. Attackers exploited the flaw by crafting a malicious contract that tricked the system into issuing refunds directly to their wallets. The result: millions of tokens drained from victims’ accounts.

HOT Contract Flaw Uncovered

After patching SWEAT’s vulnerability, Fireblocks launched a broader investigation across NEAR’s ecosystem. Their proactive search uncovered the same flaw in HOT, a governance token with over 22 million holders. The potential consequences were severe—attackers could have exploited the same “empty refund” logic to mint unlimited HOT tokens or drain user balances. Fireblocks reported the issue to HOT’s maintainers, who deployed a patch the same day.

The stakes were enormous. HOT’s ecosystem supports over 35 million users and hundreds of millions of token transfers. A successful exploit could have triggered massive financial losses and eroded confidence in NEAR’s infrastructure.

Broader Implications for Web3 Security

Fireblocks’ swift action highlights the rising stakes in blockchain security. As AI tools accelerate the pace of code analysis, attackers can identify vulnerabilities in live contracts faster than ever. The same tools, however, can empower defenders to find and fix flaws before exploits occur.

For protocols like SWEAT, the consequences of such vulnerabilities are not just financial. SWEAT is a cornerstone of Sweat Economy, a move-to-earn ecosystem that incentivizes physical activity through token rewards. The April 2026 exploit, which drained 13.71 billion SWEAT tokens (65% of supply), underscored the need for robust contract security. Although user balances were restored, the incident highlighted the fragility of token ecosystems reliant on smart contract integrity.

As of June 16, 2026, SWEAT trades at $0.00071807, reflecting a 0.04481% decline in the last 24 hours. Its market cap stands at $8.93 million, underscoring the token’s recovery efforts post-exploit. HOT, meanwhile, avoided a similar catastrophe thanks to Fireblocks’ intervention, preserving its ecosystem’s stability.

For Web3 builders, the lesson is clear: security cannot be an afterthought. As the arms race between attackers and defenders intensifies, proactive measures and rigorous audits are critical to safeguarding user assets and ecosystem trust.

Image source: Shutterstock



Credit: Source link

Previous ArticleMoonPay Trade Integration Brings Swaps to Ledger Wallet
Next Article XRP Price Prediction For June 17

Related Posts

Binance’s MiCA Licensing in Greece Faces ECB Interference Allegations

June 20, 2026

Bitcoin Transactions Near Record Highs as Microtransactions Dominate

June 20, 2026

BOJ deputy warns on inflation as Polymarket puts 2026 Fed hike odds at 66%

June 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Microsoft Warns of New USB-Based Malware Targeting Crypto Users

June 21, 2026

JaredFromSubway MEV bot gets drained in $7.5m approval trap

June 21, 2026

Solana Transactions Surge as Social Buzz Fades — What Does It Mean for SOL’s Next Rally?

June 21, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Web3 Casinos With Verifiable Payouts: Wallet-Based Play Explained

Trusted Anonymous Casinos: How No-Account Crypto Gaming Works in 2026

Sending Money to Family Abroad Without a Bank: A Stablecoin Wallet Guide

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$63,893.000.61%
  • ethereumEthereum(ETH)$1,724.400.07%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$587.780.38%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • rippleXRP(XRP)$1.14-0.33%
  • solanaSolana(SOL)$73.212.75%
  • tronTRON(TRX)$0.3270401.46%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • HyperliquidHyperliquid(HYPE)$67.87-3.53%
  • dogecoinDogecoin(DOGE)$0.082958-1.18%
  • USDSUSDS(USDS)$1.00-0.01%
  • RainRain(RAIN)$0.014409-0.23%
  • leo-tokenLEO Token(LEO)$9.48-1.62%
  • zcashZcash(ZEC)$453.91-3.37%
  • stellarStellar(XLM)$0.212351-1.16%
  • whitebitWhiteBIT Coin(WBT)$52.450.24%
  • CantonCanton(CC)$0.1552941.64%
  • moneroMonero(XMR)$319.812.31%
  • cardanoCardano(ADA)$0.160755-1.42%
  • chainlinkChainlink(LINK)$7.93-0.12%
  • USD1USD1(USD1)$1.000.04%
  • LABLAB(LAB)$14.9521.54%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.674.64%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • daiDai(DAI)$1.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$197.63-0.77%
  • MemeCoreMemeCore(M)$2.84-0.14%
  • hedera-hashgraphHedera(HBAR)$0.079768-0.35%
  • litecoinLitecoin(LTC)$44.751.44%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • nearNEAR Protocol(NEAR)$2.255.19%
  • suiSui(SUI)$0.71-1.37%
  • Global DollarGlobal Dollar(USDG)$1.00-0.02%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • shiba-inuShiba Inu(SHIB)$0.000005-0.97%
  • avalanche-2Avalanche(AVAX)$6.271.34%
  • crypto-com-chainCronos(CRO)$0.0587960.50%
  • tether-goldTether Gold(XAUT)$4,143.98-0.04%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • BittensorBittensor(TAO)$234.281.46%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.06%
  • worldcoin-wldWorldcoin(WLD)$0.600.37%
  • pax-goldPAX Gold(PAXG)$4,153.010.01%
  • uniswapUniswap(UNI)$2.990.00%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.058174-0.86%
  • mantleMantle(MNT)$0.530.22%
  • AsterAster(ASTER)$0.64-0.28%
  • OndoOndo(ONDO)$0.336099-3.79%
  • polkadotPolkadot(DOT)$0.96-0.30%