Source:
https://vxtwitter.com/PeckShieldAlert/status/1727286692489679360It's crazy the frequency with which Justin Sun's owned services are getting hacked these days.
It was only a little more than a week ago that Sun's exchange Poloniex also got hacked.
What's going on here. Do you think this is suspicious from Justin Sun's part?
Definitely another warning to never keep funds in exchanges!
I do have many questions on my head with Defi protocols, like do they test this protocols and subject them to stress? Like I don't understand why any person can create a bridge that will contain millions of dollars and will not make it open protocol for people to go through and maybe invite some ethical hackers to run test them before they even make it available for everyone. Making it even a beta platform will caution people of how much they should put so that with time, they can upgrade it and also see potential bugs.
Another wormhole in the mud, but not as large as that of the $300m but I don't know why this didn't make news, could it be that there will be form of compensation from Heco chain foundation. I am also flabbergasted with how this guy's stole funds that cannot be spend. Stolen funds will remain vulnerable to the public without been unable to spend them, why steal it in the first place.
Normally, when a DeFi protocol is launched, they do actually pay a hefty fee to external auditing firms to look through their smart contracts and provide advice on resolving potential security issues.
However, these audits are expensive. Checking even a single contract can cost up to 10k if it's a large one. Bridges have hundreds of contracts.
But in Huobi Bridge case, the compromise doesn't seem to be a very dedicated one in terms of smart contract security. Somebody probably just got backroom access and abused it to drain the funds. It's not unlikely that the security at the organization managing these addresses slipped and they got hacked in a more traditional way. For example malware being installed through social engineering or a rogue employee.
As of the hacker being unable to move the funds, where did that come from? So far I've seen the huobi bridge compromiser moving a lot of funds.