Pages:
Author

Topic: DeFi hacks [history] (Read 19110 times)

legendary
Activity: 1610
Merit: 1026
April 24, 2024, 07:29:50 AM
Mango Markets Exploiter Avi Eisenberg Found Guilty of Fraud and Manipulation
Eisenberg faces up to 20 years in prison for his $110 million heist.
A Manhattan jury has found crypto trader Avi Eisenberg guilty of fraud and market manipulation for his $110 million heist from decentralized finance protocol Mango Markets in October 2022.
Eisenberg was arrested in Puerto Rico in December 2022 and charged with commodities fraud, commodities manipulation, and wire fraud for the scheme. He will be sentenced on July 29 by New York District Court Judge Arun Subramanian. Eisenberg faces up to 20 years in federal prison for his crimes.
“This ground-breaking prosecution epitomizes this office’s ability to employ innovative methods and cutting-edge law enforcement tools to continue to protect all financial markets," said Damian Williams, U.S. Attorney for the Southern District of New York, in a Thursday press statement. "The career prosecutors of this office continue their expertise in prosecuting financial fraud, one of our core priorities, and would-be financial criminals should think twice before daring to engage in illicit conduct on our watch.”

https://www.coindesk.com/policy/2024/04/18/mango-markets-exploiter-avi-eisenberg-found-guilty-of-fraud-and-manipulation/
legendary
Activity: 1736
Merit: 4270
April 17, 2024, 10:13:55 AM
https://www.msn.com/en-us/money/companies/prosecutors-rest-case-in-mango-markets-fraud-trial/ar-BB1lxgoP
"The government on Friday rested in its case against cryptocurrency trader Avraham Eisenberg, who is facing fraud charges.

Driving the news: Prosecutors presented very strong arguments that the defendant had a good idea he was committing a crime over a year ago, when he managed to extract over $100 million from Mango Markets.

Why it matters: In a fraud case, the government has to not only show that the defendant committed a crime, but that they were aware that what they were doing was against the law.

Catch up fast: Eisenberg is on trial in Federal Court in Manhattan for engaging in a trade where he was able to withdraw all the capital on Solana-based Mango Markets on October 11, 2022, using a derivate of the mango (MNGO) token as collateral.

After inflating the token with strategic purchases on various exchanges, he used the inflated value of a MNGO derivative as collateral to borrow all the available deposits on the platform, over $100 million worth.
Then he withdrew those funds to a wallet he controlled, and let his loan default."

https://www.sec.gov/news/press-release/2023-13
SEC Charges Avraham Eisenberg with Manipulating Mango Markets’ “Governance Token” to Steal $116 Million of Crypto Assets
legendary
Activity: 1610
Merit: 1026
April 10, 2024, 01:33:28 PM
Prisma Finance Hacked; Hacker Demands Apology and Offers to Return $11M

Following a hack of Prisma Finance that caused an $11 million loot from this prominent liquid staking protocol, a hacker in the decentralized finance (defi) division has made some stunning proposals. This person called themselves to be white-hat hackers since they are good ethical hackers who try to find bugs and fix them. Under certain conditions, the money they stole can be returned according to this incident that took place on March 28.

https://www.msn.com/en-us/money/technology/prisma-finance-hacked-hacker-demands-apology-and-offers-to-return-11m/ar-BB1kOp7O
legendary
Activity: 1736
Merit: 4270
April 03, 2024, 05:43:30 AM
https://www.theblock.co/post/284883/web3-gaming-platform-munchables-loses-62-5-million-in-exploit-zachxbt
Web3 gaming platform Munchables loses $62.5 million in exploit: ZachXBT
"Munchables, a web3 gaming platform based on the Ethereum Layer 2 Blast, lost $62.5 million in one of the biggest exploits of the year.
The exploiter’s wallet address contained nearly 17,411 ETH, crypto sleuth ZachXBT found.
Munchables reported that the platform had been compromised on the social media platform X. "

legendary
Activity: 1736
Merit: 4270
March 22, 2024, 09:27:45 AM
https://twitter.com/Cointelegraph/status/1770933644242169997
"The SSS_HQ token faced a near-total value loss after a double-spending flaw was exploited, despite efforts to save funds."

https://twitter.com/Cointelegraph/status/1770941171411386475
"According to @CertiK, this glitch was rooted in the contracts’ _update() function, which failed to accurately update token balances under specific conditions, enabling users to double their $SSS token balance by transferring it to themselves."

legendary
Activity: 1610
Merit: 1026
March 20, 2024, 08:23:28 AM
Binance-Incubated UGC Platform NFPrompt Discloses Significant Losses from Latest Hack
NFPrompt (Non-Fungible Prompt), an AI-powered User Generated Content (UGC) Platform, recently disclosed significant losses resulting from a hack. According to a post on X, NFPrompt revealed that it had fallen victim to cyber intrusion, resulting in the loss of funds from its platform, including a part of NFP treasury and ecosystem fund.
https://www.coinspeaker.com/nfprompt-losses-latest-hack/
legendary
Activity: 1610
Merit: 1026
March 06, 2024, 01:32:05 PM
WOOFi Lost $8 Million in Hack on Its Arbitrum Lending Market

"WOOFi, a decentralized exchange, suffered significant financial losses due to an exploit in its Arbitrum lending market, as revealed by the company on Wednesday.

The exploit, identified by several blockchain security firms, including PeckShield, Hypernative, and Chainalysis, involved flash loan attacks targeting WOOFi Swap on Arbitrum around 15:49 UTC on March 5.
In response, WOOFi swiftly halted the affected contracts at approximately 16:02 UTC and initiated an investigation revealed in a report detailing the incident, which was subsequently released on March 6.

The hacker manipulated the sPMM algorithm, which is responsible for setting prices on Arbitrum-based WOOFiSwaps. This manipulation occurred after borrowing 7.7 million WOO tokens and “some other assets.”

The company stated, “At this point WOOFi’s sPMM incorrectly adjusted WOO to an extreme price which was close to zero, and the exploiter then swapped out 10M WOO in the same transaction with almost no cost. The exploiter repeated this attack 3 times within a very short period of time, which netted about $8.75m in profits after returning the flash loans.”"

https://www.cryptotimes.io/2024/03/06/woofi-lost-8-million-in-hack-on-its-arbitrum-lending-market/
legendary
Activity: 1736
Merit: 4270
March 06, 2024, 06:18:55 AM
https://unchainedcrypto.com/ordizk-team-allegedly-steals-1-4-million-in-exit-scam/
OrdiZK Team Allegedly Steals $1.4 Million in Exit Scam
"The team behind cross-chain bridging protocol OrdiZK appear to have stolen $1.4 million worth of ether from users, after allegedly draining tokens from the project contract and deleting its website and social media accounts."
legendary
Activity: 1610
Merit: 1026
March 02, 2024, 02:32:08 PM
@SenecaUSD exploited for 1,900 $ETH (worth ~$6.5M).
The attacker used constructed calldata parameters to call transferfrom and transfer tokens that were approved to the project's contracts to the attacker's address.
The stolen funds are now held across 3 addresses.
Revoke approvals🔽

https://twitter.com/BeosinAlert/status/1763024503452611038


Dear Whitehat,
Please return the funds to the following Ethereum wallet address: 0xb7aF0Aa318706D94469d8d851015F9Aa12D9c53a
We are collaborating with third-party security providers and law enforcement to trace the funds and identify recipient wallets. Acting promptly is crucial, so we kindly request that you return the funds as soon as possible to avoid any further legal action.
A 20% bounty may be kept as per whitehat efforts.

https://twitter.com/SenecaUSD/status/1762999045109248461



We're happy to see 80% of funds have been returned.
Transaction link: https://etherscan.io/address/0xb7aF0Aa318706D94469d8d851015F9Aa12D9c53a
The exploit involved assets held in users' wallets. The exploit didn't involve funds directly deposited into Seneca (Seneca's TVL).
The recovery of funds through a whitehat request was an extremely optimistic scenario.
It's important to note that Seneca's Chamber contract was audited prior to deployment (@HalbornSecurity).

https://twitter.com/SenecaUSD/status/1763181438113865960
legendary
Activity: 1736
Merit: 4270
February 28, 2024, 05:18:19 AM
https://cointelegraph.com/news/microstrategy-x-account-hacked-phishing-scam
"MicroStrategy’s X account hacked, shilling Ethereum token phishing scam
Hackers took over the official MicroStrategy X account, posting a series of malicious links to a fake airdrop for a so-called Ethereum-based MSTR token.
Scam Sniffer said just one user had lost over $420,000 to the phishing scam at approximately 12:43 am UTC, only several minutes after the first malicious link was posted to MicroStrategy’s account on X. "
legendary
Activity: 1708
Merit: 1615
#SWGT CERTIK Audited
February 23, 2024, 02:56:16 PM
Sky Mavis Co-Founder Jeffrey Zirlin’s wallets hacked for $9.7 million in ETH
Zirlin wrote on X that he had a “tough morning” as two of his addresses were compromised.

Jeffrey Zirlin, co-founder of Sky Mavis that created the Axie Infinity game, said that two of his wallets were hacked on Friday morning Asia time and that Ronin was not affected, according to his X post.

Blockchain security firm PeckShield identified that a “whale wallet” had been compromised with about 3,248 Ether, worth around $9.7 million, withdrawn from the Ronin Bridge and moved to crypto mixer Tornado Cash.

“The attack is limited to my personal accounts, and has nothing to do with validation or operations of the Ronin chain,” Zirlin said on X. “Additionally, the leaked keys have nothing to do with Sky Mavis operations.”
legendary
Activity: 1736
Merit: 4270
January 25, 2024, 08:32:08 AM
john1010,this is the price of freedom.
___
https://beincrypto.com/gamee-loses-millions-to-hack/
How This Crypto Gaming Project Lost $7 Million to Hackers
Gamee, a subsidiary of Animoca Brands, lost $7 million in a hacking attack involving unauthorized access to its token contracts.
The hackers stole 600 million GMEE tokens, converted them into Ethereum and Polygon, causing a 45% drop in GMEE's price.
In response, Gamee transferred token contracts ownership to a secure address, halted liquidity provisioning, and initiated legal proceedings.
hero member
Activity: 2072
Merit: 562
January 24, 2024, 11:30:31 AM
Observing the numerous incidents you've shared within the DeFi space, it's evident that security remains a significant challenge. The frequency and scale of these hacks highlight the vulnerabilities inherent in the current decentralized financial ecosystem. As the space continues to evolve, addressing these security concerns and implementing robust measures to safeguard users' funds will be crucial for the sustained growth and adoption of DeFi. The community's response and ability to learn from these incidents will play a pivotal role in shaping a more secure and resilient decentralized financial landscape.
legendary
Activity: 1610
Merit: 1026
January 24, 2024, 06:33:01 AM
DeFi protocol Concentric.fi suffered a hacker attack and lost approximately US$1.6 million, reminding not to interact for now
CertiK Alert monitors that the DeFi protocol Concentric Finance platform built based on the Camelot v3 protocol has been attacked by vulnerabilities, and the initial loss is estimated to be US$1.6 million. Concentric Finance reminds you not to interact with this protocol for the time being.

https://www.coinlive.com/news-flash/424934
legendary
Activity: 1736
Merit: 4270
January 17, 2024, 07:49:45 AM
https://coingape.com/socket-loses-3-3-million-in-hack-due-to-input-validation-flaw/

Socket Loses $3.3 Million in Hack Due to Input Validation Flaw

"Blockchain interoperability protocol Socket reported a security breach on Tuesday that resulted in over $3.3 million in losses. The incident impacted wallets that had granted infinite approvals to Socket contracts. It was attributed to a vulnerability in user input validation.

The exploit was linked to a specific route in the system that had been added just three days before the attack. As per blockchain security firm PeckShield, the problematic route has since been deactivated to prevent further misuse."
newbie
Activity: 12
Merit: 0
January 04, 2024, 05:07:25 PM
Great topic, love this list! Thanks

I hope DeFi will have less and less of those as DEX improves.
legendary
Activity: 1736
Merit: 4270
January 04, 2024, 05:10:15 AM
First hack in 2024
https://ambcrypto.com/radiant-capital-falls-prey-to-this-security-hack-details-here/
Radiant Capital falls prey to this security hack.

"Radiant Capital faced a cyber attack, resulting in a loss of over $4.4 million.
The breach prompts a temporary pause, leading to a decline in sentiment for both Radiant Capital and Arbitrum.
Radiant Capital [RDNT] is a platform that seeks to unify fragmented liquidity across various lending protocols and chains in the decentralized finance (DeFi) space. However, recent events have cast a shadow on its integrity as the platform fell victim to a malicious attack."
legendary
Activity: 1610
Merit: 1026
January 03, 2024, 10:25:30 AM
Levana Protocol, a platform known for its blockchain-based perpetual futures swap protocol, has fallen victim to a devastating crypto hack.
The exploit led to the loss of more than $1 million worth of cryptocurrency tokens from Levana's liquidity pools. This incident highlights the growing challenges blockchain platforms face in ensuring the security of user funds and the need for robust security measures.

https://www.econotimes.com/Blockchain-Based-Levana-Protocol-Falls-Victim-to-1-Million-Crypto-Hack-1668721
legendary
Activity: 1736
Merit: 4270
January 03, 2024, 05:25:24 AM
https://www.theblock.co/post/269809/orbit-chains-bridge-reportedly-hacked-for-81-5-million
Orbit Chain's bridge reportedly hacked for $81.5 million

"Orbit Chain’s cross-chain bridge has reportedly been hacked for $81.5 million in cryptocurrencies and stablecoins.
The exact nature of the hack is unknown.

Orbit Bridge, a cross-chain bridge protocol, has seen unusual outflows of $81.5 million in several cryptocurrencies in what appears to be a major hack.

In five separate transactions, each to a fresh wallet, the Orbit Bridge sent $50 million in stablecoins (30 million Tether, 10 million DAI, and 10 million USDC), 231 wBTC (about $10 million), and 9,500 eth (about $21.5 million). The hack was first noticed by X user Kgjr. "
legendary
Activity: 1708
Merit: 1615
#SWGT CERTIK Audited
December 28, 2023, 06:34:20 AM
Scammers stole $880k via fake Discord server for Across Protocol
Crypto sleuth ZachXBT warned in a Telegram channel that Across Protocol’s documentation was linked to a fake Discord server.
In a Telegram post on Dec. 26, crypto sleuth ZachXBT raised concerns about a potential security breach related to Across Protocol’s documentation.

The warning highlighted a link within the protocol’s documentation leading users to a fake Discord server, suggesting the protocol’s vanity invite address might have been compromised. The incident reportedly led to a loss of $880,000 worth of crypto tied to one unknown blockchain entity.
Pages:
Jump to: