Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions _posts/2022-11-14-deribit-hot-wallet.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
layout: post
title: Deribit Hot Wallet
date: 2022-11-01 23:59 -0800
categories: server_hot_wallet_breach
link: https://twitter.com/DeribitExchange/status/1587701883778523136
---
Hot wallet compromised, accounting to $28M in losses

> Deribit hot wallet compromised, but client funds are safe and loss is covered by company reserves. Our hot wallet was hacked for USD 28m earlier this evening just before midnight UTC on 1 November 2022.
> Client assets, Fireblocks or any of the cold storage addresses are not affected. It's company procedure to keep 99% of our user funds in cold storage to limit the impact of these type of events. The hack is isolated & quarantined to our BTC, ETH and USDC hot wallets.
15 changes: 15 additions & 0 deletions _posts/2022-11-14-lightning-consensus-bug.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
layout: post
title: Lightning Network Consensus Bug
date: 2022-11-01 10:44 -0800
categories:
- protocol_vulnerability
link: https://github.com/btcsuite/btcd/issues/1906
---
Consensus conflict between btcd and core.

> I owe this statement to the community: 1. I love breaking things 2. I broke LND for fun and will break it again if I can 3. I’m not sponsored by @Blockstream 4. I ❤️ @roasbeef @RyanTheGentry @sputn1ck 5. I’m in favor of multiple implementations 6. OP_RETURN was for trolling

- [Rogue Actor Disrupts Lightning Network With a Single Transaction](https://www.coindesk.com/tech/2022/11/02/rogue-actor-disrupts-lightning-network-with-a-single-transaction)
- [Exploit TX](https://blockstream.info/tx/73be398c4bdc43709db7398106609eea2a7841aaf3a4fa2000dc18184faa2a7e)
- [Twitter thread by hacker](https://twitter.com/brqgoo/status/1587397646125260802)
15 changes: 15 additions & 0 deletions _posts/2022-11-14-rubik-wallet.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
layout: post
title: Rubik Wallet
date: 2022-11-02 01:47 -0800
categories: cold_storage
link: https://twitter.com/CryptoRubic/status/1587704890800889858
---
(Alleged) cold wallet exploit on Rubik's admin wallet resulting in $212k lost.

> Rubicans, One of our admin’s wallet addresses was compromised. This wallet managed the RBC/BRBC bridge and staking rewards. We suspect it was malicious software that was used to get access to the admin wallet's private keys.
> Around 34M of RBC/BRBC were sold on Uniswap and PancakeSwap.


- [Exploit TX](https://etherscan.io/tx/0x75cade00bc191f059826aa77fe5104bccea622b0f4c844147cdb3d64cacee4e3)
- [Hacker Address](https://etherscan.io/address/0xD2D113d7b5c4F8FB4A68cEDa26F894F0fE25F24a)
13 changes: 13 additions & 0 deletions _posts/2022-11-14-skyward-finance.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
layout: post
title: Skyward Finance
date: 2022-11-01 05:04 -0800
categories: smart_contract
link: https://twitter.com/BlockSecTeam/status/1587998109648683010
---
Insufficient parameter validation. $3.2M lost. Smart contracts in Near blockchain.

> The root cause is in function redeem_skyward (https://github.com/skyward-finance/contracts/blob/master/skyward/src/treasury.rs#L158), which is used to redeem the treasury from the protocol.
> However, the function does not check whether the provided token_account_ids are duplicated. In this case, the attacker is able to redeem the treasury tokens multiple times with the same skyward share withdrawn once.

- [Exploit TX](https://explorer.near.org/transactions/92Gq7zehKPwSSnpoZ7LGGtSmgmBb4wP2XNDVJqUZRGqz)
11 changes: 11 additions & 0 deletions _posts/2022-11-14-solend-oracle-manipulation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
layout: post
title: Solend Price Manipulation
date: 2022-11-02 00:00 -0800
categories: smart_contract
link: https://twitter.com/solendprotocol/status/1587671511137398784
---
Price oracle manipulation attack in Solana lending protocol. Resulted in $1.26M in bad debt.

> An oracle attack on USDH affecting the Stable, Coin98, and Kamino isolated pools was detected, resulting in $1.26M in bad debt. All other pools including the Main pool are safe.
> Note that the attack did not involve Pyth.
18 changes: 18 additions & 0 deletions _posts/2022-11-14-vecrv-brive-v2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
layout: post
title: veCRV Brive V2
date: 2022-10-27 06:45 -0800
categories: smart_contract
link: https://github.com/yearn/yearn-security/blob/master/disclosures/2022-11-01.md
---
Reward manipulation logic error.

> Disclaimer: The Yearn team did not write or deploy the original BribeV2 contract. However, as a heavy user of it, decided to act quickly to deploy a new contract so that operations could resume.
> During a routine check, irregularities were discovered in the amount of SPELL bribes being claimed by some users of the BribeV2 contract. Following analysis, it was determined to be an attacker exploiting a flaw in the way the contract calculates bribe allocations.
> The flaw causes bribes to be allocated based on each user's locked amount of CRV rather than allocating based on their veCRV balance.
> The attacker was found to have exploited this since September 2021, tricking the contract into awarding them higher allocations than they should deserve for the actual weight they contributed to a gauge.
> Other BribeV2 users were unknowingly subject to faulty bribe calculations due to the fact that lock time was not taken into account.
> Yearn developers patched the vulnerability and deployed a new version of the contract (yBribe) which properly allocates bribes to users.

- [Yearn's Bilateral Responsible Disclosure Agreements](https://github.com/yearn/yearn-security/blob/master/SECURITY.md#bilateral-responsible-disclosure-agreements)
- [Suspect TX](https://etherscan.io/tx/0x47e10eebda1b9afbabe622d3deece757d6d49a0510081635fc7dc21efe50aeeb)
17 changes: 17 additions & 0 deletions _posts/2022-11-15-contract-0xf8f8.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
layout: post
title: Smart Contract 0xf8f8
date: 2022-11-05 02:01 -0800
categories:
- smart_contract
link: https://twitter.com/AnciliaInc/status/1588727453815492611
---
Insufficent access control. $100k lost in smart contract deployed in Binance Smart Chain

> Seems contract https://bscscan.com/address/0xf8f8925e96f1abe977fe3d096bf935d9da7d879c has been attacked. There are a lots of wallets have granted allowance to contract 0xf8f8. Please revoke the allowance! Attacker has been moving out multiple tokens from 0xf8f8.
> There are two tx related to this attack: https://bscscan.com//tx/0x0a969282f3659d56dfda335122b5fa76b51efe2617bb45cb55cabe8f9abaf0ad https://bscscan.com//tx/0xcd0a3708f16e29f09b6056e1f74de44c815ba3c34a359c9bd43112df1c67ed4a contract 0xf8f8 does not have permission check and it relies on user input. Attacker could just call the vulnerable function in f8f8 many times to move user's token out.
> 4/ the attacker started to move money to Tornado. :(

- [Contract Address](https://bscscan.com/address/0xf8f8925e96f1abe977fe3d096bf935d9da7d879c)
- [Attacker Address](https://bscscan.com/address/0x656887a96b6e462c48ac37da32855e9d3f4a6bed)
- [Suspect TX](https://bscscan.com//tx/0x0a969282f3659d56dfda335122b5fa76b51efe2617bb45cb55cabe8f9abaf0ad)
14 changes: 14 additions & 0 deletions _posts/2022-11-15-gate-hot-wallet.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
layout: post
title: Gate Hot Wallet
date: 2018-04-21 00:00 -0700
categories:
- server_hot_wallet_breach
link: https://twitter.com/1A1zP1/status/1591911832809349120
---
Unauthorized access to private keys. $234M stolen, allegedly, by North Korea. Gate kept it hidden to the public.

> You talk about the importance of security but how about you finally disclose @gate_io was quietly hacked by NK for $230m on April 21 2018 & how you actively kept this hidden from customers/public
> If you go to the DOJ press release, one of the addresses listed is 0xc49 which is a deposit address for Bittrex. Two hope away from it is an address that received 31,600 ETH on April 21 2018 from the Old @gate_io hot wallet 0x05e.

- [zachxbt thread](https://twitter.com/zachxbt/status/1592337921922994177)
15 changes: 15 additions & 0 deletions _posts/2022-11-15-loopring-ddos.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
layout: post
title: Loopring DDoS
date: 2022-11-04 21:00 -0800
categories:
- cloud_infrastructure_breach
link: https://loopring.org/#/post/loopring-ddos-attack-post-mortem
---
DDoS attack on Loopring L2 chain. The Loopring gateway on AWS was targeted.

> On November 4 (GMT+8) at 21:00 hrs Loopring was targeted with an aggressive DDoS attack. During the incident, the rate per second (RPS) was significantly increased. The Loopring gateway was unable to handle such an overwhelming volume of requests resulting in the unavailability of the services.
> 22:07 Nov 4th Loopring contacted AWS security engineers for additional support.
> This DDoS attack only prevented Loopring from providing external services; it had no impact on the security of assets on Loopring. During the attack, the Loopring relayer continued to generate ZKP blocks and submitted them to the Ethereum blockchain.
> This event served as a good reminder to devote additional resources and layers of protection by leveraging AWS services. Loopring, in coordination with AWS, will implement a more robust security architecture for future challenges.
> The majority of Loopring's external services are built on AWS. Loopring will leverage AWS's security capability to better mitigate future potential security threats. Following this incident, Loopring will work more closely with AWS to identify risks and deploy improved shielding and protection, ensuring that our customers receive a robust service.
15 changes: 15 additions & 0 deletions _posts/2022-11-15-moocake.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
layout: post
title: Moo Cake smart contract
date: 2022-11-06 09:30 -0800
categories:
- smart_contract
link: https://twitter.com/BeosinAlert/status/1589501207181393920
---
Insufficent access control via a flash loan. $140k lost. Smart contract in Binance Smart Chain.

> Beosin EagleEye monitored a flashloan attack on MooCakeCTX contract. The loss is ~$140K. There is no time restrictions on collateral and rewards, and the prevention of caller is not comprehensive enough, enabling the attacker to increase dividends via flashloan.
> The attacker executed two more attacks and returned the flashloan with a profit of 424 $BNB (~ $140,000).
> Suggestion: When developing contracts, pay attention to flashloan attack scenario, the security of the way rewards are issued, and the secure use of library functions.

- [Suspect TX](https://bscscan.com/tx/0x03d363462519029cf9a544d44046cad0c7e64c5fb1f2adf5dd5438a9a0d2ec8e)
16 changes: 16 additions & 0 deletions _posts/2022-11-15-pando-rings.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
layout: post
title: Pando Rings
date: 2022-11-05 07:19 -0800
categories:
- smart_contract
link: https://pando.im/news/2022/2022-11-06-alert-to-pando-community-hack-of-pando-rings/
---
Price oracle manipulation. $21.8M assets stolen.

> Pando Rings suffered from a hack yesterday on November 5th, 2022. The attacker exploited a vulnerability in Pando Rings price oracle and manipulated the price of sBTC-WBTC (liquidity provider token of the trading pair BTC-WBTC on 4swap) to attempt a theft of approximately $70 million worth of crypto assets.
> $21,877,098.03 worth of crypto assets including ETH, EOS and BTC were unfortunately transferred out from the attacker's two perpetrating Mixin wallets before measures could be taken. Though fortunately, among the transferred funds, Pando team was able to get support and assistance from our community and the transferred 2,022,662.9979 EOS (valuing at approximately $2,362,761.24) has now been frozen.
> And for the larger rest of the hacked funds (approximately at the value of $50 million) that are still in the hacker's wallets, we took as promptly measures as could be done, got assistance from Mixin Network and have had the funds frozen

- [Twitter Announcement](https://twitter.com/pando_im/status/1589045252413100032)
- [Exploit Address](https://etherscan.io/address/0xd3f04ce2d37b182432e2f804f9913a02071cea54)
16 changes: 16 additions & 0 deletions _posts/2022-11-15-peakdefi.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
layout: post
title: Peak DeFi
date: 2022-11-04 09:18 -0800
categories:
- smart_contract
link: https://twitter.com/AnciliaInc/status/1588646551684988928
---
Insufficent access control. $40k lost in smart contract deployed in Ethereum network.

> @AnciliaInc We detected an attack on ETH contract https://etherscan.io/address/0x07cdb44fa1e7eceb638c12a3451a3dc9ce1400e4, it lost about 32k Matic tokens and hacker gained around ~300k.
> The root cause is that the contract does not have permission check on its sellLeftoverToken() function.
> Seems like the fund belongs to @PEAKDEFI PeakDeFiFund. @PEAKDEFI you might need to check this up.

- [Contract Address](https://etherscan.io/address/0x07cdb44fa1e7eceb638c12a3451a3dc9ce1400e4)
- [Suspect TX](https://etherscan.io//tx/0x0faa90b780a7939bfbeb3d7c8dfb1c8a318219f7be60c4a698991fd635e95813)
19 changes: 19 additions & 0 deletions _posts/2022-11-15-pnetwork-bridge.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
layout: post
title: pNetwork Bridge
date: 2022-11-03 08:27 -0800
categories:
- protocol_vulnerability
- bridge_vulnerability
link: https://twitter.com/hackenclub/status/1588307631529041920
---
Bridge misconfiguration resulted in $4.3M stolen. Binance Smart Chain network.

> As it can be seen from BSC explorer, an attacker minted ≈27.8 billions of $GALA tokens twice in Binance Smart Chain (@BNBCHAIN) network
> Then, the attacker started to sell the $GALA tokens via PancakeSwap (@PancakeSwap), dumping the price by more than 99%
> pGALA on BSC Notice: A misconfiguration of the http://p.Network bridge necessitated the redeployment of pGALA. We’re working directly w/the Gala team and w/ exchanges to provide the necessary pGALA balances to restore functionality of pGALA deposits & withdrawals.
> All GALA tokens on Ethereum as well as the underlying bridge collateral are SAFE.

- [Official Announcement](https://twitter.com/pNetworkDeFi/status/1588266897061031936)
- [Attacker Address](https://bscscan.com/address/0x6891a233bca9e72a078bcb71ba02ad482a44e8c1)
- [Suspect TX](https://bscscan.com/tx/0x439aa6f526184291a0d3bd3d52fccd459ec3ea0a8c1d5bf001888ef670fe616d)
13 changes: 13 additions & 0 deletions _posts/2022-11-16-abracadabra-oracle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
layout: post
title: Abracadabra Price Oracle Manipulation
date: 2022-11-08 10:27 -0800
categories: smart_contract
link: https://twitter.com/spreekaway/status/1590118020319354880
---
Price oracle manipulation attack in Abracadabra protocol in Ethereum network. $110k lost to the attacker.

> seems MIM just ate a bunch of bad debt from someone depositing xSUSHI when the oracle was far above current price, self updating the oracle, and then liquidating themself.
> attacker profited 110,911 MIM

- [Attacker Address](https://debank.com/profile/0xb7ea0f0f8c6df7a61bf024db21bbe85ac5688005/history)
14 changes: 14 additions & 0 deletions _posts/2022-11-16-brahTopg.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
layout: post
title: Abracadabra Price Oracle Manipulation
date: 2022-11-09 04:55 -0800
categories: smart_contract
link: https://twitter.com/SlowMist_Team/status/1590685173477101570
---
Insufficient function parameter validation in TopGear Brahma vault in Ethereum network. $90k stolen.

> On November 9, 2022, the brahTOPG project on the ETH chain was attacked, leading to the loss of $89,879.
> The root cause of this attack is that the Zapper contract is rigorously checking for incoming user data, leading to an arbitrary external call issue. The attackers exploit this vulnerability to steal funds from users who are still authorized to the contract.

- [Suspect TX](https://etherscan.io/tx/0xeaef2831d4d6bca04e4e9035613be637ae3b0034977673c1c2f10903926f29c0)
- [Neptune Post](https://medium.com/neptune-mutual/decoding-brahma-brahtopg-smart-contract-vulnerability-7b7c364b79d8)
18 changes: 18 additions & 0 deletions _posts/2022-11-16-ftx-wallet.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
layout: post
title: FTX Wallet
date: 2018-11-12 02:30 -0700
categories:
- server_hot_wallet_breach
link: https://twitter.com/zachxbt/status/1591276687228035074
---
FTX wallet compromised. $380M stolen. Insider? Hot vs Cold wallet? TBD

> Multiple former FTX employees confirmed to me they do not recognize these transfers for ~$383m
> Update: $31.4m USDT blacklisted by Tether
> Appears a portion was “whitehat” funds. Would assume this is the 0x97 & 0xd8 address.
> Update: Paxos seems frozen now for 0x59 attacker

- [Twitter thread](https://twitter.com/0xfoobar/status/1591261359152705538)
- [FTX US TX](https://etherscan.io/tx/0x9c9065a994e2c9dfb21c9c853ea9cf6b7b1829a8bd2258058d80161847f8000e)
- [FTX TX](https://etherscan.io/tx/0x6580bf69c1ee28a1d8a4dec9b949272a449b1c58d91e6692ef34d9ea40fd9653)
17 changes: 17 additions & 0 deletions _posts/2022-11-20-dappnode-profanity.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
layout: post
title: Dappnode Profanity
date: 2022-10-29 00:00 -0700
categories:
- cryptography
- brute_force
network:
- Ethereum
amount: 300_000
link: https://twitter.com/DAppNode/status/1586769313872101376
---
Address compromised through profanity attack vector.

> The hacker/s ran away with 57.72 ETH and 552.61 GNO (aprox. 165,000 USD)

-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c)
18 changes: 18 additions & 0 deletions _posts/2022-11-20-friesdao.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
layout: post
title: Fries DAO
date: 2022-10-27 05:58 -0700
categories:
- cryptography
- brute_force
network:
- Ethereum
amount: 2_300_000
link: https://docs.google.com/document/d/1xKZmj1aeM9iFrdQ7sieUNvh0_UI60worl1lfs5ImXk0/
---
Deployer addresses compromised through profanity attack vector.

> On October 27th, 5:58PM UTC, friesDAO contracts were exploited by an attacker taking control of our own deployer address through a profanity attack vector.
> The hacker was able to drain the treasury of its USDC through the refund contract, drain the FRIES tokens in the staking contract, subsequently selling it all into the Uniswap pool.

-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c)
19 changes: 19 additions & 0 deletions _posts/2022-11-20-giveth-profanity.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
layout: post
title: Giveth Profanity
date: 2022-10-30 15:00 -0700
categories:
- cryptography
- brute_force
network:
- Ethereum
amount: 50_000
link: https://twitter.com/Givethio/status/1586511169975623682
---
Address used to control rewards compromised through profanity attack vector.

> An attacker exploited our GIVfarm today at about 15:00 UTC.
> This was not a smart contract exploit. Rather, the keys we used to control the rate of rewards to our GIVfarms were compromised.
> The attacker used the compromised keys to change the reward rate for our Mainnet farms to a very large number & then quickly claimed the rewards.

-[Profanity Disclosure 1inch](https://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c)
17 changes: 17 additions & 0 deletions _posts/2022-11-20-melody.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
layout: post
title: Melody Wallet
date: 2022-10-24 04:54 -0700
categories:
- server_hot_wallet_breach
network:
- BSC
amount: 610_000
link: https://blog.neptunemutual.com/decoding-melody-vulnerability/
---
Melody offchain signing service compromised. 2225 $BNB tokens lost.

> On October 25, 2022, Melody was hacked due to a vulnerability that allowed the application's token address to be compromised, resulting in the loss of approximately 2225 $BNB tokens.
> The root cause of the attack is that the application's token address was compromised which allowed the hacker to bypass the access control.
> Following the incident, another attacker address repeated the attack, earning 2,450 $SGS and exchanging proceeds for 560 $WBNB.
> The team took the contract to maintenance mode and restarted the withdrawal function after the bug was fixed.
17 changes: 17 additions & 0 deletions _posts/2022-11-20-noodleswap-reentrancy.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
layout: post
title: NoodleSwap
date: 2022-10-25 16:49 -0700
categories:
- smart_contract
- reentrancy
network:
- Ethereum
amount: 29_000
link: https://twitter.com/BlockSecTeam/status/1584959295829180416
---
Reentrancy vulnerability. $29k loss.

> Looks @n00dleSwap has an ERC777-based reentrancy issue and is being attacked, causing a loss of $29K.

- [Exploit TX](https://phalcon.blocksec.com/tx/eth/0x8037b3dc0bf9d5d396c10506824096afb8125ea96ada011d35faa89fa3893aea)
Loading