1inch suffers $5M hack due to smart contract vulnerability

1inch suffers $5M hack due to smart contract vulnerability


Decentralized exchange aggregator 1inch lost $5 million in cryptocurrency when a hacker exploited a smart contract vulnerability, the platform confirmed.

On March 5, 1inch identified a vulnerability affecting resolvers — entities that fill orders — using the outdated Fusion v1 implementation, which was made public a day later.

Source: 1inch Network

Tracing the $5 million 1inch hack

On March 7, blockchain security firm SlowMist found through an onchain investigation that the 1inch hacker made away with 2.4 million USDC (USDC) and 1276 Wrapped Ether (WETH) tokens.

Source: SlowMist

According to 1inch, the hack stole funds only from resolvers using Fusion v1 in their own contracts, and end-user funds were safe:

coinbase

“We’re actively working with affected resolvers to secure their systems. We urge all resolvers to audit and update their contracts immediately.”

The platform announced bug bounty programs to secure any other underlying system vulnerabilities and recover the stolen funds. 

Related: $1.5B crypto hack losses expose bug bounty flaws

1inch’s attempt to recoup the stolen funds is slim unless the hacker agrees to return them. Previously, compromised crypto protocols have managed to recover funds after attackers have agreed to retain 10% of the funds as white hat bounties, as seen in the case of crypto lender Shezmu.

Still, the North Korean hackers behind the $1.5 billion Bybit hack — dubbed crypto’s largest-ever heist — were successful in siphoning the entire amount despite coordinated efforts by the crypto community to recover the losses.

The hackers stole various amounts of liquid-staked Ether (STETH), Mantle Staked ETH (mETH) and other ERC-20 tokens from Bybit. 

Bybit on the slow road to recovery

Despite the sudden loss of funds, Bybit managed to allow its users seamless withdrawal of their funds by quickly taking loans from other crypto companies, which were repaid at a later date.

It took 10 days for the Bybit hackers to launder $1.4 billion worth of stolen cryptocurrencies. Some of the laundered funds may still be traceable despite the asset swaps, according to Deddy Lavid, co-founder and CEO of blockchain security firm Cyvers:

“While laundering through mixers and crosschain swaps complicates recovery, cybersecurity firms leveraging onchain intelligence, AI-driven models, and collaboration with exchanges and regulators still have small opportunities to trace and potentially freeze assets.”

THORChain, a crosschain swap protocol, which was reportedly extensively used by the hackers to siphon funds, experienced a surge in activity post-Bybit hack.

Magazine: Mystery celeb memecoin scam factory, HK firm dumps Bitcoin: Asia Express



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest

XLM Stellar
Bybit
XLM Stellar
1inch suffers $5M hack due to smart contract vulnerability
undefined
coinbase
Fiverr
Robinhood beats Q1 estimates despite revenue, crypto trading dip
Growth of crypto poses risks to investors, financial stability — Bank of Italy
Tether still dominates stablecoins despite competition — Nansen
The cost of innovation — Regulations are Web3’s greatest asset
Solana's Loopscale pauses lending after $5.8M hack
BlackRock, five others account for 88% of all tokenized treasury issuance
bitcoin
ethereum
bnb
xrp
cardano
solana
dogecoin
polkadot
shiba-inu
dai
Ledger
Analysts raise red flags on ALPACA’s 1,000% rally after delisting news
Bloomberg Intelligence boosts Solana ETF approval odds to 90%
Why Circle Rejected Ripple’s Bold $5 Billion Acquisition Bid?
TikTok Meets Crypto Trading in Token.com’s Plan to Onboard the Next Billion Users
trading desk
Analysts raise red flags on ALPACA’s 1,000% rally after delisting news
Bloomberg Intelligence boosts Solana ETF approval odds to 90%
Why Circle Rejected Ripple’s Bold $5 Billion Acquisition Bid?
TikTok Meets Crypto Trading in Token.com’s Plan to Onboard the Next Billion Users
bitcoin
ethereum
tether
xrp
bnb
solana
usd-coin
dogecoin
cardano
tron
bitcoin
ethereum
tether
xrp
bnb
solana
usd-coin
dogecoin
cardano
tron