• bitcoinBitcoin (BTC) $ 62,803.00
  • ethereumEthereum (ETH) $ 3,112.83
  • tetherTether (USDT) $ 0.999865
  • bnbBNB (BNB) $ 591.54
  • solanaSolana (SOL) $ 135.89
  • usd-coinUSDC (USDC) $ 1.00
  • staked-etherLido Staked Ether (STETH) $ 3,111.70
  • xrpXRP (XRP) $ 0.513414
  • dogecoinDogecoin (DOGE) $ 0.144029
  • the-open-networkToncoin (TON) $ 5.22
  • cardanoCardano (ADA) $ 0.452495
  • shiba-inuShiba Inu (SHIB) $ 0.000024
  • avalanche-2Avalanche (AVAX) $ 33.87
  • tronTRON (TRX) $ 0.119933
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 62,827.00
  • bitcoin-cashBitcoin Cash (BCH) $ 468.27
  • polkadotPolkadot (DOT) $ 6.62
  • chainlinkChainlink (LINK) $ 14.02
  • nearNEAR Protocol (NEAR) $ 6.81
  • matic-networkPolygon (MATIC) $ 0.691627
  • litecoinLitecoin (LTC) $ 85.27
  • internet-computerInternet Computer (ICP) $ 12.87
  • uniswapUniswap (UNI) $ 7.61
  • leo-tokenLEO Token (LEO) $ 5.80
  • daiDai (DAI) $ 0.999826
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999062
  • ethereum-classicEthereum Classic (ETC) $ 26.46
  • hedera-hashgraphHedera (HBAR) $ 0.107369
  • aptosAptos (APT) $ 8.73
  • blockstackStacks (STX) $ 2.50
  • mantleMantle (MNT) $ 1.06
  • crypto-com-chainCronos (CRO) $ 0.123792
  • stellarStellar (XLM) $ 0.112189
  • cosmosCosmos Hub (ATOM) $ 8.18
  • okbOKB (OKB) $ 51.86
  • filecoinFilecoin (FIL) $ 5.72
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,053.51
  • render-tokenRender (RNDR) $ 7.79
  • immutable-xImmutable (IMX) $ 2.07
  • xtcom-tokenXT.com (XT) $ 2.98
  • pepePepe (PEPE) $ 0.000007
  • vechainVeChain (VET) $ 0.038414
  • bittensorBittensor (TAO) $ 415.37
  • arbitrumArbitrum (ARB) $ 1.04
  • makerMaker (MKR) $ 2,894.22
  • dogwifcoindogwifhat (WIF) $ 2.64
  • kaspaKaspa (KAS) $ 0.111632
  • wrapped-eethWrapped eETH (WEETH) $ 3,220.82
  • the-graphThe Graph (GRT) $ 0.258465
  • optimismOptimism (OP) $ 2.28
  • ethena-usdeEthena USDe (USDE) $ 0.998338
  • injective-protocolInjective (INJ) $ 25.23
  • theta-tokenTheta Network (THETA) $ 2.23
  • moneroMonero (XMR) $ 120.24
  • fetch-aiFetch.ai (FET) $ 2.08
  • arweaveArweave (AR) $ 31.32
  • coredaoorgCore (CORE) $ 2.21
  • fantomFantom (FTM) $ 0.682973
  • celestiaCelestia (TIA) $ 9.98
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,436.86
  • lido-daoLido DAO (LDO) $ 1.93
  • thorchainTHORChain (RUNE) $ 4.95
  • flokiFLOKI (FLOKI) $ 0.000170
  • bitget-tokenBitget Token (BGB) $ 1.16
  • bonkBonk (BONK) $ 0.000024
  • algorandAlgorand (ALGO) $ 0.192879
  • galaGALA (GALA) $ 0.044874
  • sei-networkSei (SEI) $ 0.555523
  • zebec-protocolZebec Protocol (ZBC) $ 0.030346
  • suiSui (SUI) $ 1.19
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,190.28
  • quant-networkQuant (QNT) $ 103.03
  • whitebitWhiteBIT Coin (WBT) $ 10.00
  • beam-2Beam (BEAM) $ 0.025909
  • jupiter-exchange-solanaJupiter (JUP) $ 0.977632
  • flowFlow (FLOW) $ 0.879847
  • aaveAave (AAVE) $ 88.61
  • bitcoin-svBitcoin SV (BSV) $ 64.82
  • bittorrentBitTorrent (BTT) $ 0.000001
  • neoNEO (NEO) $ 17.49
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,106.96
  • flare-networksFlare (FLR) $ 0.029847
  • ethenaEthena (ENA) $ 0.804380
  • singularitynetSingularityNET (AGIX) $ 0.860095
  • elrond-erd-2MultiversX (EGLD) $ 41.05
  • ondo-financeOndo (ONDO) $ 0.753592
  • dydx-chaindYdX (DYDX) $ 2.10
  • tokenize-xchangeTokenize Xchange (TKX) $ 12.93
  • axie-infinityAxie Infinity (AXS) $ 7.20
  • gatechain-tokenGate (GT) $ 7.63
  • wormholeWormhole (W) $ 0.566515
  • akash-networkAkash Network (AKT) $ 4.33
  • the-sandboxThe Sandbox (SAND) $ 0.448756
  • ribbon-financeRibbon Finance (RBN) $ 1.06
  • ecasheCash (XEC) $ 0.000051
  • chilizChiliz (CHZ) $ 0.111685
  • tezosTezos (XTZ) $ 0.992341
  • kucoin-sharesKuCoin (KCS) $ 9.98
  • eosEOS (EOS) $ 0.817929
  • safeSafe (SAFE) $ 2.20
  • havvenSynthetix Network (SNX) $ 2.83
  • worldcoin-wldWorldcoin (WLD) $ 4.68
  • conflux-tokenConflux (CFX) $ 0.233008
  • cheeleeCheelee (CHEEL) $ 15.96
  • mina-protocolMina Protocol (MINA) $ 0.819084
  • roninRonin (RON) $ 2.74
  • ordinalsORDI (ORDI) $ 41.11
  • jasmycoinJasmyCoin (JASMY) $ 0.017795
  • pyth-networkPyth Network (PYTH) $ 0.568113
  • gnosisGnosis (GNO) $ 325.31
  • decentralandDecentraland (MANA) $ 0.447501
  • msolMarinade staked SOL (MSOL) $ 160.90
  • starknetStarknet (STRK) $ 1.13
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,075.61
  • apecoinApeCoin (APE) $ 1.24
  • kavaKava (KAVA) $ 0.685067
  • iotaIOTA (IOTA) $ 0.227745
  • nervos-networkNervos Network (CKB) $ 0.016651
  • axelarAxelar (AXL) $ 1.11
  • usddUSDD (USDD) $ 0.977270
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.70
  • dexeDeXe (DEXE) $ 12.38
  • theta-fuelTheta Fuel (TFUEL) $ 0.104770
  • klay-tokenKlaytn (KLAY) $ 0.188422
  • nexoNEXO (NEXO) $ 1.22
  • swethSwell Ethereum (SWETH) $ 3,282.46
  • oasis-networkOasis Network (ROSE) $ 0.098505
  • aioz-networkAIOZ Network (AIOZ) $ 0.603888
  • heliumHelium (HNT) $ 3.99
  • dydxdYdX (ETHDYDX) $ 2.09
  • echelon-primeEchelon Prime (PRIME) $ 17.30
  • fraxFrax (FRAX) $ 0.998920
  • frax-etherFrax Ether (FRXETH) $ 3,101.49
  • lido-staked-solLido Staked SOL (STSOL) $ 160.36
  • blurBlur (BLUR) $ 0.396326
  • dymensionDymension (DYM) $ 3.65
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000104
  • fasttokenFasttoken (FTN) $ 1.93
  • venomVenom (VENOM) $ 0.364760
  • osmosisOsmosis (OSMO) $ 0.913611
  • illuviumIlluvium (ILV) $ 93.84
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000028
  • bitcoin-goldBitcoin Gold (BTG) $ 33.54
  • tether-goldTether Gold (XAUT) $ 2,343.18
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,319.92
  • wemix-tokenWEMIX (WEMIX) $ 1.60
  • aerodrome-financeAerodrome Finance (AERO) $ 1.34
  • golemGolem (GLM) $ 0.540875
  • astarAstar (ASTR) $ 0.099239
  • woo-networkWOO (WOO) $ 0.297944
  • mantra-daoMANTRA (OM) $ 0.676658
  • iotexIoTeX (IOTX) $ 0.058341
  • ocean-protocolOcean Protocol (OCEAN) $ 0.882977
  • corgiaiCorgiAI (CORGIAI) $ 0.001546
  • pendlePendle (PENDLE) $ 5.39
  • radixRadix (XRD) $ 0.050051
  • book-of-memeBOOK OF MEME (BOME) $ 0.009409
  • curve-dao-tokenCurve DAO (CRV) $ 0.431556
  • true-usdTrueUSD (TUSD) $ 0.998535
  • ankrAnkr Network (ANKR) $ 0.049703
  • 1inch1inch (1INCH) $ 0.430814
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,364.65
  • mx-tokenMX (MX) $ 4.93
  • altlayerAltLayer (ALT) $ 0.356180
  • apenftAPENFT (NFT) $ 0.00000049
  • xdce-crowd-saleXDC Network (XDC) $ 0.034549
  • project-galaxyGalxe (GAL) $ 4.49
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.94
  • aelfaelf (ELF) $ 0.637154
  • enjincoinEnjin Coin (ENJ) $ 0.319124
  • stepnGMT (GMT) $ 0.238057
  • memecoin-2Memecoin (MEME) $ 0.027506
  • zilliqaZilliqa (ZIL) $ 0.024637
  • skaleSKALE (SKL) $ 0.086002
  • livepeerLivepeer (LPT) $ 13.73
  • ravencoinRavencoin (RVN) $ 0.031548
  • rocket-poolRocket Pool (RPL) $ 21.30
  • pax-goldPAX Gold (PAXG) $ 2,338.50
  • celoCelo (CELO) $ 0.807029
  • manta-networkManta Network (MANTA) $ 1.72
  • holotokenHolo (HOT) $ 0.002421
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.03
  • 0x0x Protocol (ZRX) $ 0.496266
  • arkhamArkham (ARKM) $ 1.99
  • polymeshPolymesh (POLYX) $ 0.401153
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.004701
  • terra-luna-2Terra (LUNA) $ 0.603737
  • siacoinSiacoin (SC) $ 0.007254
  • superfarmSuperVerse (SUPER) $ 0.907559
  • qtumQtum (QTUM) $ 3.90
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.79
  • amp-tokenAmp (AMP) $ 0.007122
  • raydiumRaydium (RAY) $ 1.51
  • stader-ethxStader ETHx (ETHX) $ 3,192.57
  • ether-fiEther.fi (ETHFI) $ 3.34
  • basic-attention-tokenBasic Attention (BAT) $ 0.254544
  • compound-governance-tokenCompound (COMP) $ 55.43
  • compound-ethercETH (CETH) $ 62.55
  • popcatPopcat (POPCAT) $ 0.386321
  • jito-governance-tokenJito (JTO) $ 3.09

Blast dapp hack was an inside job, and it could have been worse

0 26

Blast dapp hack was an inside job, and it could have been worse

  blockworks.co 2 h

Blast dapp hack was an inside job, and it could have been worse

Munchables, a GameFi project built on Blast, reported late Tuesday that it was “compromised” to the tune of $62 million.

A further $25 million was spared in a related vault of Juice Finance due to an apparent typo.

By blacklisting the hacker’s address, the network was able to seal off the funds, and convince the attacker to give up the controlling private keys.

And that’s not all that’s unusual.

On-chain evidence provided by investigator ZachXBT indicates that the culprit went by a variety of pseudonyms.

“Four different devs hired by the Munchables team and linked to the exploiter are likely all the same person,” he wrote on X following the incident.

Users of Juice Finance, which designed a vault and bot system to play the game and earn valuable points at an accelerated rate, were also at risk, according to Chief Operating Officer Eric Ryklin.

The Juice team independently reviewed Munchables’ code, a prerequisite for launching its own product.

“The malicious exploit was not in their code,” Ryklin told Blockworks. “Nor is it in their actual audit itself.”

“This guy pushed an upgrade that no one could have seen — it was unverified — and it essentially gave him three wallets that had unlimited access to withdraw funds, plus he had the keys to the upgrader and the main deployer wallet,” he said.

Read more: Latest DeFi exploits show audits are no guarantee

Juice and Munchables shared several investors, and both teams were in touch with each other regularly in the runup to the theft, Ryklin said. The malicious actor, who worked for Munchables, was a member of a group chat that included the Juice team.

“They met this guy in a developer Discord somewhere across the space,” Ryklin recalled, and after the hack it emerged that the team was not the actual owner of their contracts.

“Someone from their HR team messed up big time,” blockchain security firm SlowMist said on X.

Ryklin described it as a “sleeper cell,” and ZachXBT pointed to North Korean hackers as likely responsible.

“This guy inserted three sleeper wallets into the actual contract that no one could find at first,” Ryklin said. “But the second that he would do a transaction, that sleeper wallet would become public, so the Blast sequencer could essentially blacklist him.”

ZachXBT declined to comment on how he arrived at that conclusion.

A spokesperson for security firm CertiK told Blockworks “it’s highly unusual that the funds were then returned to the project from a malicious DPRK affiliated worker” — referring to agents of the North Korean government — and that the firm assessed it could be “a rogue developer,” who, with their identity revealed, “decided to give the funds back after pressure from the Web3 community to prevent further backlash.”

“Obviously, seeing the funds returned is abnormal behavior,” ZachXBT told Blockworks.

In any case, quickly recognizing those wallets proved crucial to securing the return of the stolen funds.

Loading Tweet..

With the jig up, and no way to exfiltrate the funds, the attacker made it easier on the Blast team by handing over their private keys.

That avoided the need to employ more technical solutions.

“Blast could have definitely pushed a soft fork to literally just blacklist his wallet and pull the money out,” Ryklin said, “I think at that point, it’s like, ‘Why would he not give the keys back?’”

The hacker was not able to take 7349.99 wrapped ether, worth about $25 million at the time, as a result of an apparent typo. It was what Juice’s auditor, Trust Security, called “one of the weirdest side stories of the Munchables exploit.”

Instead of snatching all the wrapped ether, the attacker took just 73.49 wETH (about $267,000).

“The hacker was off by two 0s when inputting the amount! It is easy to confirm in a simulation that they could have indeed taken the whole vault,” Trust said. “It must have taken the hacker over eight minutes to realize their mistake, which is when the team paused withdrawals.”

CertiK confirmed to Blockworks this was the most plausible explanation for the data.

None of Juice’s other vaults or its own smart contracts were affected, the team said.

The hacker also missed the chance to grab an additional $7 million in USDB, Blast’s interest bearing stablecoin, which was secured before it could be stolen, Ryklin said.

“The bridges got closed, so the money was contained,” he said.

That meant that, unlike in other hacking cases, the thief had no leverage. The fact that Blast has multiple centralized components meant that there would be no chance to try to launder the proceeds.

That may trouble some “decentralization maxis,” but Ryklin finds it completely normal at this stage of the network’s development.

“I think the reason that you were able to successfully recover $97 million instead of everyone losing their money is because there are guardrails in place, and I don’t think those are the worst things in the world,” he said.

Source

Leave A Reply

Your email address will not be published.