Fun

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits

News Feed - 2021-07-27 08:07:46

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits


Thorchain, a popular defi protocol, has been compromised twice in the last two weeks, resulting in losses of over $10,000,000. The hacker responsible for the latest exploit left behind a message detailing the measures that should be undertaken to protect users. Hacker Returns to the Scene to Lecture on Security


In another blow against the Thorchain protocol, the defi network has found itself the victim of another hack after the equivalent of 4,000 ethereum (ETH) was stolen just days earlier. Thorchain, which features an automated market maker (AMM) and decentralized exchange (dex), is known for its liquidity pooling, with total value locked (TVL) currently around $101.75 million.


This time, the attack was perpetrated against the ETH Router contract to target the Thorchain Bifrost component, resulting in more than $8 million in losses for the protocol. According to the hacker allegedly behind the move, the vulnerability was known before the latest attack and was entirely preventable.


When using Solidity, the Ethereum smart contract coding language used in the protocol, programmers advise developers against using certain coding methods to transfer funds. However, this was allegedly overlooked by the team in charge, leading to an issue within the protocol’s native RUNE token’s contract code.


The hacker behind the exploit was not quick to leave the crime scene. Instead, the malicious actor left behind a message effectively trolling the protocol. In tx input data, the hacker pointed out the following:



The hacker laid bare all the steps that were required to engage the exploit, highlighting the protocol’s decision not to issue bounties or engage auditors to check code that currently oversees a nine-figure TVL. While the protocol developers initially believed the hack cost them only $800,000 and was the work of a whitehat hacker, the following amounts were actually stolen: 966.620 ACLX 20,866,664.530 XRUNE 1,672,794.010 USDC 56,104.000 SUSHI 6.910 YFI 990,137.460 USDT


RUNE tokens have continued their decline after dipping close to 25% following the breach, with tokens currently trending around $4.17. While Thorchain has since issued a recovery plan to restore user funds lost to the attack, the more significant development was the decision to hire security firms to audit the code and defend the defi protocol against future, preventable exploits.


What do you think of this “honest hacker”? Let us know in the comments section below. Kubernetes Clusters Used to Mine Monero by Attackers NEWS | 15 hours ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story Blockchain security, cryptocurrency stolen, DeFi, Hacking, Solidity, Thorchain


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Iran to Pilot ‘National Cryptocurrency,’ Amend Central Bank Law
Iran to Pilot ‘National Cryptocurrency,’ Amend Central Bank Law The central bank of Iran is gearing up to begin the pilot phase of its digital currency project in the near futu
Trend Forecaster Gerald Celente Says World War 3 Has Begun — ‘If the People Don’t Unite for Peace, We Are Finished’
Trend Forecaster Gerald Celente Says World War 3 Has Begun — ‘If the People Don’t Unite for Peace, We Are Finished’ This week Bitcoin.com News spoke with Gerald Celente, th
Bitcoin Trader Robbed During an In-Person Transaction, Kicked Out of Car in Hong Kong
Bitcoin Trader Robbed During an In-Person Transaction, Kicked Out of Car in Hong Kong An unnamed 37-year-old man was a victim of a theft from a gang of robbers w
$2.7T general insurance industry meets tokenized RWAs: Nayms joins Cointelegraph Accelerator
Cointelegraph Accelerator6 hours ago$2.7T general insurance industry meets tokenized RWAs: Nayms joins Cointelegraph AcceleratorNayms, a blockchain-based tokenized insurance marketplace, has become the latest participant
Grayscale Bitcoin Trust Buys Over 1.5 Times Total BTC Mined Since Halving
Grayscale Bitcoin Trust Buys Over 1.5 Times Total BTC Mined Since HalvingGrayscale Investments has purchased more than 1.5 times the number of bitcoins mined since the third Bitcoin
Biggest Movers: XRP Hits 2-Month High, Despite Crypto Consolidation
Biggest Movers: XRP Hits 2-Month High, Despite Crypto Consolidation Xrp rose to a two-month high on March 21, despite crypto markets mostly consolidating in today’s session.
Advocacy groups warn of ‘adverse repercussions’ for crypto in case against Tornado Cash co-founder
Turner Wright1 hour agoAdvocacy groups warn of ‘adverse repercussions’ for crypto in case against Tornado Cash co-founderThe Blockchain Association, Coin Center and DeFi Education Fund supported a motion for the U.S.
Ezra Reguerra14 hours agoCircle weighs in on SEC vs. Binance case, argues stablecoins are not securitiesCircle noted that assets pegged to the U.S. dollar are not securities, partly because users are not expecting any pr
Biggest Movers: DASH, CVX and ALGO Lead Monday’s Gainers, APE Falls Further
Biggest Movers: DASH, CVX and ALGO Lead Monday"s Gainers, APE Falls Further CVX was the biggest crypto gainer to start the week, as both DASH and ALGO also climbed higher. Despite
Derek Andersen6 hours agoSEC plans scrutiny of crypto dealer-brokers, transfer agents, per 2024 exam guideThe SEC sets examination priorities based on feedback from examiners and input from investors and the industry.105
Ripple faces securities suit in California over CEO’s ‘misleading statement’
Jesse Coghlan5 hours agoRipple faces securities suit in California over CEO’s ‘misleading statement’Judge Phyllis Hamilton found XRP could be a security when sold in the retail market and gave the go-ahead to a law
UK Court Denies Maduro Access to $1 Billion of Venezuela’s Gold
UK Court Denies Maduro Access to $1 Billion of Venezuela"s GoldThe UK is denying Nicolas Maduro access to Venezuela’s gold worth about $1 billion, stored at the Bank of Englan