Pages:
Author

Topic: DeFi hacks [history] - page 3. (Read 19555 times)

hero member
Activity: 700
Merit: 577
Enjoy 500% bonus + 70 FS
November 24, 2023, 10:24:08 AM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.
Most of them are hacked by closed friends and also careless or improper security caused by the developer. When a project is launched the developer should put the security of the site in his mind first and always and if it is not enough they should buy more security space for the site so that when a hacker visit the site it would bounced back but whereby you only develop the site and dump it like that without any extra security measures to prevent and protect the site then hackers will be very happy to penetrate.

In sometimes, co-workers, or a mistake of the owner of the DeFi caused the hack. And this has happened to me before. I mistakenly send a code that was sent to me in Facebook and it used to hacked my Facebook account, they are some emails DeFi received and they were trying to quote those messages by replying them and a code which was secretly sent was forwarded to them and the site was hacked.
full member
Activity: 1554
Merit: 101
November 24, 2023, 07:06:14 AM
What do you think is the reason why this case always happens every year? If you look at history, there will always be things like this.
Is it that easy to hack or is the security of each project different, or is this a game of the people closest to it, because they are the ones who can reach it the easiest, and there are many other possibilities.
legendary
Activity: 2016
Merit: 4765
November 24, 2023, 05:22:53 AM
https://www.msn.com/en-us/news/technology/infstones-to-implement-key-rotations-following-vulnerability-disclosure-in-lido-protocol/ar-AA1kqfJR
InfStones to Implement Key Rotations Following Vulnerability Disclosure in Lido Protocol
"Addressing the Tailon library vulnerability
The vulnerability, which was discovered in the open-source Tailon library, posed a potential risk to the Lido Finance protocol. Lido Finance, known for being the largest liquid staking protocol on Ethereum, oversees a substantial amount of ether, amounting to 9.23 million with a market value exceeding $19 billion. The protocol allows users to deposit ETH and participate in network staking through validator nodes. These nodes issue a derivative token to users, representing their staked deposit. A network of contributors, known as operators, is responsible for running these ETH validator nodes."
legendary
Activity: 1876
Merit: 1138
November 23, 2023, 09:39:24 AM
Data shared by blockchain security platform PeckShield shows that more than $86.6 million in digital assets were transferred from the HECO Chain bridge to suspicious addresses. The security firm suggests that the bridge is compromised and an exploit is ongoing.

In response to the incident, Tron founder Justin Sun announced that HTX will fully compensate users for any losses incurred in the hack. The company has also temporarily suspended deposits and withdrawals as they investigate the incident. The executive said services will resume after the investigation is completed.


https://cointelegraph.com/news/heco-chain-bridge-hack-86-million-lost

HTX and Heco Cross-Chain Bridge Undergo Hacker Attack.
https://twitter.com/justinsuntron/status/1727304656622326180?
legendary
Activity: 2016
Merit: 4765
November 23, 2023, 04:54:24 AM
https://cryptonews.com/news/kyberswap-hacked-for-48-million-hackers-suggest-negotiations.htm
"KyberSwap Hacked for $48 Million, Hackers Suggest Negotiations
KyberSwap, a decentralized exchange, has been compromised in a hack resulting in the theft of $48 million, prompting the platform to advise users to withdraw their funds while the attackers hint at entering negotiations.

On-chain data indicates that the hack on KyberSwap resulted in significant losses of $48 million across several blockchain networks, including 20 million from Arbitrum, $15 million from Optimism and $7 million from Ethereum.

The stolen funds were primarily deposited in Ethereum (ETH), Wrapped Ethereum (wETH), and USD Coin (USDC). The analysis of the incident indicates a direct attack on the exchange’s liquidity pools instead of a vulnerability in the platform’s code."
legendary
Activity: 2016
Merit: 4765
November 15, 2023, 09:40:11 AM
Raft Suffers $3.3M Exploit That Drove Down Stablecoin 50%, but Hacker Likely Lost Money on Attack
https://www.coindesk.com/tech/2023/11/10/defi-platform-raft-suffers-33m-exploit-but-hacker-likely-takes-a-loss-on-the-attack/
"Decentralized finance (DeFi) platform Raft lost some $3.3 million in ether (ETH) after being hacked Friday afternoon – but the attacker may have suffered a loss on the heist.
On-chain data shows that the attacker drained 1,577 ETH from Raft, then sent 1,570 ETH to a burn address – destroying most of the stolen assets and leaving only 7 ETH for themselves. The hacker's address received 18 ETH via crypto mixer service Tornado Cash before the attack, blockchain data on Arkham shows, likely to fund transactions.
After executing the transfers and paying the blockchain fees, the exploiter's crypto wallet was left with only 14 ETH, fewer funds than the initial 18 ETH.
This means that they face a 4 ETH loss on the whole maneuver."

TrustPad Attack Post-Mortem
https://trustpad.medium.com/trustpad-attack-post-mortem-c09ccc01e0ef
exploit to one of TrustPad’s staking contracts
legendary
Activity: 2016
Merit: 4765
November 08, 2023, 05:43:37 AM
https://twitter.com/AstridFinance/status/1718236380009230406
"Unfortunately our smart contract was exploited due to a fix recommended by our auditor.

We have paused the contract.

We have taken a snapshot of all holders and will offer full refund and make everyone whole. Please wait as our team work out the refund process.

We truly apologize for what happened and will make sure everyone is refunded accordingly "

Damage approximately 245 000 dollars  AstridFinance

https://twitter.com/AstridFinance/status/1718563845323866383
"Hacker has decided to return our funds (minus 20% as per the bounty), as such we consider this as settled amicably."
https://etherscan.io/tx/0x27cbd5f2f12067bcc9be3bafa9140b849ee1ee68ae5329c2a4ba789685111ad7
legendary
Activity: 2002
Merit: 1689
November 06, 2023, 10:43:31 AM
FixedFloat blocked coins from hacker group Lazarus
Thanks to the coordinated efforts of our team over the past three days, an attempt to launder stolen funds associated with the hacker group Lazarus from the DPRK has been successfully thwarted.✔️

The total amount of funds subject to blocking amounted to about two million dollars. 💵

We will continue to work towards enhancing the security and reliability of our services. 🚀

Source:
https://twitter.com/FixedFloat/status/1720448805303161327
legendary
Activity: 2016
Merit: 4765
November 01, 2023, 12:18:15 PM
https://cointelegraph.com/news/onyx-protocol-exploiter-siphon-2-1-m-loot-tornado-cash
"Decentralized peer-to-peer lending platform Onyx Protocol lost roughly $2.1 million in an exploit of a market with no liquidity that was deployed on Oct. 27.

The Onyx Protocol hacker exploited a known bug, a rounding issue behind the popular CompoundV2 fork, explained blockchain investigator PeckShield soon after alerting about the hack that went unnoticed by the protocol."
legendary
Activity: 2016
Merit: 4765
October 26, 2023, 06:52:21 AM
https://twitter.com/DeDotFiSecurity/status/1717327912410456355

"🚨 ~$743,000 Exit Scam Alert 🚨

Fake $LINEA token has been rug pulled earlier today, previously flagged with a Rug Pull High Risk issue

@DeDotFi
 Scanner also identified token as a Honeypot

All the stolen funds were transferred to Tornado Cash"
legendary
Activity: 1876
Merit: 1138
October 25, 2023, 08:34:18 AM
How Hackers Attacked Telegram Trading Bot to Steal $500,000
Hackers exploited a vulnerability in the Maestro Router 2 smart contract, stealing 280 ETH ($500,000) from Telegram trading bot Maestro.
The Maestro attack resulted in a 30% drop in JOE tokens' price due to lack of liquidity. The stolen ETH was transferred to Railgun, a crypto privacy tool.
Despite the hack, Maestro refunded all affected users by purchasing and returning the lost tokens. The bot has earned over $20 million in fees in 2

https://beincrypto.com/maestro-refunds-after-attack/
legendary
Activity: 2016
Merit: 4765
October 18, 2023, 09:25:09 AM
https://cointelegraph.com/news/stars-arena-recovers-stolen-funds-after-offering-bounty-exploit

Stars Arena recovers 90% of stolen funds after offering $257K bounty
"The exploiter of the Web3 social media platform agreed to keep a 10% bounty in exchange for returning the remainder of the stolen funds.
Web3 social media platform Stars Arena said it has recovered nearly all of the crypto stolen from an Oct. 7 exploit, minus a 10% bounty to the person responsible.

In an Oct. 11 X (Twitter) post, Stars Arena said around 90% of the 266,000 Avalanche exploited, at the time worth around $3 million, was returned after reaching an agreement to give a 27,610-AVAX bounty worth nearly $257,000 to the exploiter.

The bounty also included compensation for 1,000 AVAX worth over $9,000 seemingly lost by the exploiter in a bridge."
newbie
Activity: 28
Merit: 0
October 18, 2023, 08:58:50 AM
MEV bot earned $1.5 million thanks to a $4 attack
https://wixi.exchange/en/news/3479042.html
legendary
Activity: 2016
Merit: 4765
October 12, 2023, 06:46:24 AM
https://cryptonews.com/news/defi-protocol-platypus-finance-hacked-for-over-2-million-avalanche-heres-what-happened.htm

DeFi Protocol Platypus Finance Hacked for Over $2 Million on Avalanche

"Decentralized finance (DeFi) protocol Platypus Finance has fallen victim to a security breach resulting in the loss of over $2 million.

In a recent blog post on X (formerly Twitter), security firm PeckShield noted that the Avalanche-based project has been exploited.

Following the alert, Platypus Finance confirmed that there had been suspicious activities in the protocol, prompting the project to take "the proactive measure of temporarily suspending all pools.""
sr. member
Activity: 1456
Merit: 326
Eloncoin.org - Mars, here we come!
October 11, 2023, 01:44:40 PM
Star arena ,a best social platform experience defi hacking. The hackers able to access their contract and exploit a reentrancy vulnerability within the code which allowed them to inflate the share's value, reaching approximately $274K per share. Hackers steal almost 2.9 million worth of AVAX token. This hacks happened in October 2023.
Defi hacking is increased so much in 2023 and most of hacker target contract address and this hacks also is part of it. Need lot of protection and audit check everytime.

SOURCE

https://www.halborn.com/blog/post/explained-the-stars-arena-hack-october-2023

legendary
Activity: 1876
Merit: 1138
October 11, 2023, 11:59:54 AM
Galxe platform experiences DNS attack, losses top $150K
The Web3 platform’s website has been restored, but the company still warns against using it. The hack may be linked to September’s attack on Balancer.

The website of Web3 community platform Galxe was offline for about an hour on Oct. 6. Galxe reported on X (formerly Twitter) that its website was down at 14:44 UTC, confirming 40 minutes later that it had experienced a security breach affecting its Domain Name System (DNS) record. It warned against visiting the domain until the situation was remedied.

At the time of writing, Galxe had not confirmed that its website was safe to use again. After the website was restored, some X posters were reporting that it was blocked by Google.



https://cointelegraph.com/news/galxe-protocol-experiences-dns-attack-october-6
legendary
Activity: 2016
Merit: 4765
October 04, 2023, 12:22:55 PM
https://russia.postsen.com/local/484395/Fraudsters-began-to-take-advantage-of-the-departure-of-the-Binance-crypto-exchange-from-Russia.html
"The largest cryptocurrency platform Binance announced its final departure from Russia a week ago. However, cyber fraudsters are already trying to make money from this. “In the first five days, several fake groups were created on Telegram, eight fake tokens, one of which had a daily trading volume of $130,000, and, of course, a classic scam began on the P2P marketplace,” the CEO of CommEX (the buyer of the Russian business Binance) told Forbes ) for the development of the region and the CIS Anton Toroptsev"
legendary
Activity: 1876
Merit: 1138
October 04, 2023, 05:28:37 AM
Combining all the incidents in September we’ve confirmed ~$332M lost to exploits, hacks and scams.

Exit scams were ~$1.9M

Flash loans were ~$0.4M

Exploits were ~$329.8M

Picture and graphics

https://twitter.com/CertiKAlert/status/1708094695832682893

Cumulative losses since the beginning of the year amount to approximately 1.34 billion dollars, including various hacks for 925.4 million.
https://bitcointalksearch.org/topic/m.62936942

legendary
Activity: 2016
Merit: 4765
September 28, 2023, 03:51:25 AM
https://dune.com/21co/lazarus-group-crypto-holdings
"This dashboard tracks the crypto holdings of the cybercrime unit Lazarus Group (also known as APT38), which has conducted multiple hacks on behalf of the North Korean government. In total, we track 295 wallets identified by the U.S. Federal Bureau of Investigation (FBI) and Office of Foreign Assets Control (OFAC). For context, these are the largest hacks conducted by the Lazarus Group, as confirmed by the FBI:

March 29, 2022: ~$620 million theft from Sky Mavis’ Ronin Bridge.
June 22, 2022: ~$100 million Harmony’s Horizon Bridge hack.
June 2023: ~$100 million theft from Atomic Wallet.
July 22, 2023: ~$60 million theft from Alphapo.
July 22, 2023: ~$37 million theft from CoinsPaid.
September 4, 2023: ~$41 million theft from Stake.com.
We should note that this is a lower-bound estimation of Lazarus Group’s crypto holdings based on publicly available information. If you have identified or are aware of any other hacks that have been disclosed, please get in touch with us so we can track the assets here.

Find the reports of the FBI disclosing the wallet addresses here: January 23, 2023, August 22, 2023, September 6, 2023."
legendary
Activity: 1876
Merit: 1138
September 27, 2023, 12:19:50 PM
Amazing Korean exchange upbit incident today

1. The Largest S.Korean exchange 
@Official_Upbit
 , abruptly halted Aptos' deposits and withdrawals, citing a wallet system maintenance without any specific reason

2. Various Korean users have posted authentication claiming that they received $APT without sending themselves

3. Reports have emerged that the Upbit customer center has been making phone calls to users who sold the deposited FAKE-APT tokens, requesting refunds.

4. What's so fucked up about this situation is that the deposited tokens are not the native
@Aptos_Network
 coin but a scam token called ClaimAPTGift
The only explanation for this situation is that Upbit's wallet system only checked the type and data and processed deposits and withdrawals


Scam token's address
https://apscan.io/account/0xc4f4e73e689b13799d6a1a52a9db1e0099de2e16967ca9bff97e9946dbedc4e9

https://twitter.com/definalist/status/1705900412208029894
Pages:
Jump to: