Posts

Showing posts with the label hacks

Base project RocketSwap shares emergency plan following $865K exploit

RocketSwap Labs plans on reaching out to the exploiter on-chain, who stole an estimated $865,000 from the protocol on Aug. 14. Base project RocketSwap Labs has outlined its emergency programme to bounce back from a brute force hack which swiped $865,000 or 471 Ether (ETH) from the protocol on Aug. 14. The team explained on Aug. 15 that they plan on redeploying a new farm contract and open-source it on-chain, relinquish minting rights — presumably of RCKT — and will soon call on the hackers to return the assets, among other things: The emergency programme agreed upon by the team is as follows. 1. We plan to redeploy a new farm contract by dropping the proxy contract and open sourcing it on-chain. 2. The new farm will advance the production reduction plan by 0.075 per block. 3. The team relinquishes… — RocketSwap (@RocketSwap_Labs) August 15, 2023 On Aug. 14, a hacker stole approximately 471 ETH and bridged it from Base to Ethereum, according to blockchain security firm PeckShi...

On-chain sleuth ZachXBT sued for libel after claiming plaintiff drained funds from project

Plaintiff Jeffrey Huang claims his reputation was damaged when ZachXBT allegedly falsely accused him of embezzlement. Blockchain investigator ZachXBT has been sued for libel by one of the people he accused of fraud, according to a June 16 social media post. According to the post, Jeffrey Huang, known as “MachiBigBrother” on Twitter, has accused ZachXBT of damaging his reputation through false allegations. MachiBigBrother also posted an announcement stating that he is suing the on-chain sleuth. A year ago, @zachxbt published a Medium article about me that damaged my reputation. Today, I have filed a defamation lawsuit against him in the United States District Court for the Western District of Texas. — Machi Big Brother (@machibigbrother) June 16, 2023 ZachXBT responded to the lawsuit by calling it “baseless” and “an attempt to chill free speech.” He pledged to “fight back” against it. In a thread responding to his own post, ZachXBT linked to the Medium post that is accused of being l...

Hedera confirms exploit on mainnet led to theft of service tokens

Image
Hedera said the smart contract exploit on Mar. 9 has not impacted the network or its consensus layer. Hedera, the team behind distributed ledger Hedera Hashgraph, has confirmed a smart contract exploit on the Hedera Mainnet that has led to the theft of several liquidity pool tokens. Hedera said the attacker targeted liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over to use on the Hedera Token Service. Today, attackers exploited the Smart Contract Service code of the Hedera mainnet to transfer Hedera Token Service tokens held by victims’ accounts to their own account. (1/6) — Hedera (@hedera) March 10, 2023 The Hedera team explained that the suspicious activity was detected when the attacker attempted to moved the stolen tokens across the Hashport bridge, which consisted of liquidity pool tokens on SaucerSwap, Pangolin and HeliSwap. However, operators then acted promptly to temporarily pause the bridg...

Scammers are targeting crypto users with new ‘zero value TransferFrom’ trick

Image
The trick allows the attacker to confirm zero-value transactions from the victim’s wallet, hijacking the user’s transaction history. Data from Etherscan shows that some crypto scammers are targeting users with a new trick that allows them to confirm a transaction from the victim’s wallet, but without having the victim’s private key. The attack can only be performed for transactions of 0 value. However, it may cause some users to accidentally send tokens to the attacker as a result of cutting and pasting from a hijacked transaction history. Blockchain security firm SlowMist discovered the new technique in December and revealed it in a blog post. Since then, both SafePal and Etherscan have adopted mitigation techniques to limit its effect on users, but some users may still be unaware of its existence. Recently we have received reports from the community of a new type of scam: Zero Transfer Scam. Be careful if you see suspicious 0 transfer in your wallet record: 1/10 — Veronica (@V_...

The 10 largest crypto hacks and exploits in 2022 saw $2.1B stolen

Just the top 10 major cryptocurrency exploits garnered over $2 billion for malicious actors in a year that was marred with bankruptcies and collapses. It's been a turbulent year for the cryptocurrency industry — market prices have taken a huge dip, crypto giants have collapsed and billions have been stolen in crypto exploits and hacks. It was not even halfway through October when Chainalysis declared 2022 to be the “biggest year ever for hacking activity.” As of Dec. 29, the 10 largest exploits of 2022 have seen $2.1 billion stolen from crypto protocols. Below are those exploits and hacks, ranked from smallest to largest. 10: Beanstalk Farms exploit — $76M Stablecoin protocol Beanstalk Farms suffered a $76 million exploit on April 18 from an attacker using a flash loan to buy governance tokens. This was used to pass two proposals that inserted malicious smart contracts. The exploit was initially thought to have cost around $182 million as Beanstalk was drained of all its collater...