• bitcoinBitcoin (BTC) $ 66,376.00
  • ethereumEthereum (ETH) $ 3,032.70
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 577.03
  • solanaSolana (SOL) $ 168.09
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.519905
  • staked-etherLido Staked Ether (STETH) $ 3,030.54
  • the-open-networkToncoin (TON) $ 6.67
  • dogecoinDogecoin (DOGE) $ 0.153118
  • cardanoCardano (ADA) $ 0.482156
  • shiba-inuShiba Inu (SHIB) $ 0.000025
  • avalanche-2Avalanche (AVAX) $ 36.54
  • tronTRON (TRX) $ 0.124255
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 66,345.00
  • polkadotPolkadot (DOT) $ 7.24
  • chainlinkChainlink (LINK) $ 16.54
  • bitcoin-cashBitcoin Cash (BCH) $ 473.62
  • nearNEAR Protocol (NEAR) $ 8.22
  • matic-networkPolygon (MATIC) $ 0.708956
  • litecoinLitecoin (LTC) $ 83.22
  • internet-computerInternet Computer (ICP) $ 12.87
  • fetch-aiFetch.ai (FET) $ 2.27
  • uniswapUniswap (UNI) $ 7.43
  • leo-tokenLEO Token (LEO) $ 5.92
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000010
  • hedera-hashgraphHedera (HBAR) $ 0.117012
  • ethereum-classicEthereum Classic (ETC) $ 28.34
  • render-tokenRender (RNDR) $ 10.08
  • aptosAptos (APT) $ 8.55
  • immutable-xImmutable (IMX) $ 2.45
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,150.33
  • cosmosCosmos Hub (ATOM) $ 8.63
  • crypto-com-chainCronos (CRO) $ 0.123742
  • filecoinFilecoin (FIL) $ 5.89
  • mantleMantle (MNT) $ 0.992321
  • arweaveArweave (AR) $ 48.38
  • stellarStellar (XLM) $ 0.107804
  • blockstackStacks (STX) $ 2.06
  • okbOKB (OKB) $ 49.65
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,976.68
  • the-graphThe Graph (GRT) $ 0.310785
  • kaspaKaspa (KAS) $ 0.121104
  • dogwifcoindogwifhat (WIF) $ 2.85
  • arbitrumArbitrum (ARB) $ 1.01
  • optimismOptimism (OP) $ 2.53
  • vechainVeChain (VET) $ 0.036037
  • bittensorBittensor (TAO) $ 381.15
  • makerMaker (MKR) $ 2,720.54
  • suiSui (SUI) $ 1.06
  • moneroMonero (XMR) $ 134.79
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • thorchainTHORChain (RUNE) $ 6.93
  • injective-protocolInjective (INJ) $ 24.56
  • fantomFantom (FTM) $ 0.803999
  • theta-tokenTheta Network (THETA) $ 2.23
  • flokiFLOKI (FLOKI) $ 0.000208
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,357.38
  • celestiaCelestia (TIA) $ 9.15
  • jupiter-exchange-solanaJupiter (JUP) $ 1.22
  • sei-networkSei (SEI) $ 0.557977
  • coredaoorgCore (CORE) $ 1.83
  • lido-daoLido DAO (LDO) $ 1.79
  • bonkBonk (BONK) $ 0.000024
  • galaGALA (GALA) $ 0.044399
  • bitget-tokenBitget Token (BGB) $ 1.10
  • algorandAlgorand (ALGO) $ 0.179456
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,133.40
  • whitebitWhiteBIT Coin (WBT) $ 9.86
  • quant-networkQuant (QNT) $ 94.77
  • ondo-financeOndo (ONDO) $ 0.950771
  • akash-networkAkash Network (AKT) $ 5.79
  • flowFlow (FLOW) $ 0.882885
  • aaveAave (AAVE) $ 87.54
  • bitcoin-svBitcoin SV (BSV) $ 64.57
  • beam-2Beam (BEAM) $ 0.024603
  • singularitynetSingularityNET (AGIX) $ 0.947592
  • bittorrentBitTorrent (BTT) $ 0.000001
  • dydx-chaindYdX (DYDX) $ 2.03
  • flare-networksFlare (FLR) $ 0.027518
  • neoNEO (NEO) $ 15.58
  • elrond-erd-2MultiversX (EGLD) $ 40.52
  • cheeleeCheelee (CHEEL) $ 18.93
  • zebec-protocolZebec Protocol (ZBC) $ 0.021025
  • axie-infinityAxie Infinity (AXS) $ 7.33
  • chilizChiliz (CHZ) $ 0.119225
  • worldcoin-wldWorldcoin (WLD) $ 4.90
  • ethenaEthena (ENA) $ 0.707466
  • gatechain-tokenGate (GT) $ 7.89
  • msolMarinade Staked SOL (MSOL) $ 199.97
  • the-sandboxThe Sandbox (SAND) $ 0.442675
  • wormholeWormhole (W) $ 0.549050
  • jasmycoinJasmyCoin (JASMY) $ 0.020019
  • tokenize-xchangeTokenize Xchange (TKX) $ 12.06
  • safeSafe (SAFE) $ 2.26
  • ecasheCash (XEC) $ 0.000049
  • eosEOS (EOS) $ 0.817389
  • kucoin-sharesKuCoin (KCS) $ 9.79
  • aioz-networkAIOZ Network (AIOZ) $ 0.852416
  • tezosTezos (XTZ) $ 0.940157
  • conflux-tokenConflux (CFX) $ 0.220322
  • mina-protocolMina Protocol (MINA) $ 0.804167
  • havvenSynthetix Network (SNX) $ 2.70
  • roninRonin (RON) $ 2.69
  • starknetStarknet (STRK) $ 1.13
  • decentralandDecentraland (MANA) $ 0.434705
  • book-of-memeBOOK OF MEME (BOME) $ 0.011581
  • ribbon-financeRibbon Finance (RBN) $ 0.818143
  • ordinalsORDI (ORDI) $ 37.73
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,024.81
  • heliumHelium (HNT) $ 4.73
  • lido-staked-solLido Staked SOL (STSOL) $ 199.36
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,059.21
  • apecoinApeCoin (APE) $ 1.22
  • dexeDeXe (DEXE) $ 12.93
  • usddUSDD (USDD) $ 0.996033
  • nexoNEXO (NEXO) $ 1.31
  • kavaKava (KAVA) $ 0.664781
  • gnosisGnosis (GNO) $ 275.06
  • iotaIOTA (IOTA) $ 0.216535
  • pendlePendle (PENDLE) $ 4.59
  • axelarAxelar (AXL) $ 1.05
  • theta-fuelTheta Fuel (TFUEL) $ 0.106360
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.64
  • nervos-networkNervos Network (CKB) $ 0.015120
  • pyth-networkPyth Network (PYTH) $ 0.433537
  • fraxFrax (FRAX) $ 0.998702
  • echelon-primeEchelon Prime (PRIME) $ 16.26
  • klay-tokenKlaytn (KLAY) $ 0.176141
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000108
  • bitcoin-goldBitcoin Gold (BTG) $ 35.35
  • ocean-protocolOcean Protocol (OCEAN) $ 0.951018
  • frax-etherFrax Ether (FRXETH) $ 3,015.36
  • oasis-networkOasis Network (ROSE) $ 0.090562
  • fasttokenFasttoken (FTN) $ 1.94
  • livepeerLivepeer (LPT) $ 18.80
  • mantra-daoMANTRA (OM) $ 0.729394
  • blurBlur (BLUR) $ 0.369371
  • tether-goldTether Gold (XAUT) $ 2,384.30
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000027
  • dydxdYdX (ETHDYDX) $ 2.03
  • swethSwell Ethereum (SWETH) $ 3,196.76
  • osmosisOsmosis (OSMO) $ 0.857254
  • jito-governance-tokenJito (JTO) $ 4.66
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,244.78
  • woo-networkWOO (WOO) $ 0.293374
  • wemix-tokenWEMIX (WEMIX) $ 1.51
  • xdce-crowd-saleXDC Network (XDC) $ 0.036304
  • golemGolem (GLM) $ 0.539131
  • illuviumIlluvium (ILV) $ 83.03
  • curve-dao-tokenCurve DAO (CRV) $ 0.428747
  • arkhamArkham (ARKM) $ 2.36
  • astarAstar (ASTR) $ 0.090641
  • true-usdTrueUSD (TUSD) $ 1.00
  • pepecoin-2PepeCoin (PEPECOIN) $ 4.29
  • aerodrome-financeAerodrome Finance (AERO) $ 1.08
  • raydiumRaydium (RAY) $ 1.85
  • apenftAPENFT (NFT) $ 0.00000049
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,282.93
  • iotexIoTeX (IOTX) $ 0.050008
  • dymensionDymension (DYM) $ 2.71
  • radixRadix (XRD) $ 0.044169
  • memecoin-2Memecoin (MEME) $ 0.025387
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.66
  • venomVenom (VENOM) $ 0.277165
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.08
  • magaMAGA (TRUMP) $ 9.70
  • mx-tokenMX (MX) $ 4.59
  • superfarmSuperVerse (SUPER) $ 0.996957
  • enjincoinEnjin Coin (ENJ) $ 0.309313
  • celoCelo (CELO) $ 0.834283
  • 1inch1inch (1INCH) $ 0.387262
  • polymeshPolymesh (POLYX) $ 0.423726
  • stepnGMT (GMT) $ 0.220647
  • ankrAnkr Network (ANKR) $ 0.044404
  • popcatPopcat (POPCAT) $ 0.449156
  • pax-goldPAX Gold (PAXG) $ 2,367.18
  • zilliqaZilliqa (ZIL) $ 0.023530
  • altlayerAltLayer (ALT) $ 0.312027
  • 0x0x Protocol (ZRX) $ 0.499269
  • nosanaNosana (NOS) $ 5.06
  • ravencoinRavencoin (RVN) $ 0.029450
  • siacoinSiacoin (SC) $ 0.007121
  • terra-luna-2Terra (LUNA) $ 0.586930
  • holotokenHolo (HOT) $ 0.002255
  • project-galaxyGalxe (GAL) $ 3.46
  • arcblockArcblock (ABT) $ 4.07
  • manta-networkManta Network (MANTA) $ 1.59
  • paypal-usdPayPal USD (PYUSD) $ 0.999635
  • amp-tokenAmp (AMP) $ 0.007086
  • biconomyBiconomy (BICO) $ 0.516451
  • compound-wrapped-btccWBTC (CWBTC) $ 1,331.83
  • rocket-poolRocket Pool (RPL) $ 19.38
  • corgiaiCorgiAI (CORGIAI) $ 0.001152
  • ether-fiEther.fi (ETHFI) $ 3.38
  • qtumQtum (QTUM) $ 3.70
  • compound-governance-tokenCompound (COMP) $ 56.31
  • zetachainZetaChain (ZETA) $ 1.63

Blackmail thwarts $90K ‘hostile governance attack’ on DAO

0 83

Blackmail thwarts $90K ‘hostile governance attack’ on DAO

  blockworks.co 5 h

Blackmail thwarts $90K ‘hostile governance attack’ on DAO

Blackmail was all that stood between the remaining funds in Indexed Finance’s crypto treasury and a devastating governance token attack.

When a watcher of the neglected Indexed Finance DAO noticed a malicious proposal meant to drain the DAO’s remaining $90,000, they demanded a share of the proposer’s profits to avoid outing the exploiter.

The proposer apparently declined, leading the blackmailer to alert former Indexed contributor Laurence Day, who then told his 30,000 followers on social media platform X of the attack.

Hours later, the governance proposal was narrowly defeated.

Indexed Finance launched in 2020 as an index fund for crypto but has seen activity mostly end in the time since a 2021 flash loan attack drained $15.8 million from the DAO’s coffers.

Since the attack, Day and developer Dillon Kellar stopped working on the protocol, and before last week, Indexed governance hadn’t seen a vote since mid-2022 when the treasury was recouping investor losses and funding a class-action lawsuit.

But in DeFi, protocols remain operational regardless of whether users exist. And as Indexed’s NDX governance token slid to a fraction of a cent, someone spied an opportunity.

400,000 NDX ($4,000 at the time) was needed to reach a governance quorum and pass a proposal. The exploiter made a nameless proposal with a two-day voting window containing code to drain Indexed’s depleted-but-still-existent treasury — containing some $92,000, per DeepDAO.

With the required NDX, the exploiter reached a quorum of votes in favor.

In the proposal’s waning hours, Day, the former Indexed contributor, learned of the exploit and made a plea to his followers on X.

“In keeping with the principle of ‘no, you shouldn’t get to raid the protocols of inactively developed projects for profit by leveraging governance’, I’d appreciate it if anyone who still happens to hold NDX that is delegated to themselves or another wallet they control to vote Against,” Day wrote.

“Against” votes flowed in and the proposal was defeated by a margin of about $90 in NDX.

Day alleges the person who tipped him off to the attack had first blackmailed the exploiter asking for 40% of the funds. On-chain sleuth ZachXBT linked the wallet address of the attempted exploit to a second attack on an inactive crypto project earlier this month.

Attacks on the treasuries of decrepit DAOs are becoming more common as failed projects accumulate but immutable code keeps funds sitting on-chain. A Solana-based DAO was exploited for $230,000 last month when a malicious proposal went unnoticed.

“The unintended side effect of having code governed by token holders that executes forever is that there [are] typically no plans for end of life,” Jeremiah Smith, CEO of DeFi security service OpenCover, said in a Telegram message. “The ‘space trash’ problem of onchain applications has only begun.”

Source

Leave A Reply

Your email address will not be published.