Fun

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits

News Feed - 2021-07-27 08:07:46

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits


Thorchain, a popular defi protocol, has been compromised twice in the last two weeks, resulting in losses of over $10,000,000. The hacker responsible for the latest exploit left behind a message detailing the measures that should be undertaken to protect users. Hacker Returns to the Scene to Lecture on Security


In another blow against the Thorchain protocol, the defi network has found itself the victim of another hack after the equivalent of 4,000 ethereum (ETH) was stolen just days earlier. Thorchain, which features an automated market maker (AMM) and decentralized exchange (dex), is known for its liquidity pooling, with total value locked (TVL) currently around $101.75 million.


This time, the attack was perpetrated against the ETH Router contract to target the Thorchain Bifrost component, resulting in more than $8 million in losses for the protocol. According to the hacker allegedly behind the move, the vulnerability was known before the latest attack and was entirely preventable.


When using Solidity, the Ethereum smart contract coding language used in the protocol, programmers advise developers against using certain coding methods to transfer funds. However, this was allegedly overlooked by the team in charge, leading to an issue within the protocol’s native RUNE token’s contract code.


The hacker behind the exploit was not quick to leave the crime scene. Instead, the malicious actor left behind a message effectively trolling the protocol. In tx input data, the hacker pointed out the following:



The hacker laid bare all the steps that were required to engage the exploit, highlighting the protocol’s decision not to issue bounties or engage auditors to check code that currently oversees a nine-figure TVL. While the protocol developers initially believed the hack cost them only $800,000 and was the work of a whitehat hacker, the following amounts were actually stolen: 966.620 ACLX 20,866,664.530 XRUNE 1,672,794.010 USDC 56,104.000 SUSHI 6.910 YFI 990,137.460 USDT


RUNE tokens have continued their decline after dipping close to 25% following the breach, with tokens currently trending around $4.17. While Thorchain has since issued a recovery plan to restore user funds lost to the attack, the more significant development was the decision to hire security firms to audit the code and defend the defi protocol against future, preventable exploits.


What do you think of this “honest hacker”? Let us know in the comments section below. Kubernetes Clusters Used to Mine Monero by Attackers NEWS | 15 hours ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story Blockchain security, cryptocurrency stolen, DeFi, Hacking, Solidity, Thorchain


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Terra Proposal Seeks to Expand UST Stablecoin to 5 Different Defi Protocols
Terra Proposal Seeks to Expand UST Stablecoin to 5 Different Defi Protocols On January 6, Terra Research announced a proposal to expand the network’s stablecoin asset terrau
IMF Report on El Salvador’s Bitcoin Adoption: Risks Averted, but Transparency Needed
IMF Report on El Salvador"s Bitcoin Adoption: Risks Averted, but Transparency Needed According to a recent mission statement published by the International Monetary Fund (IMF), El
China to Crack Down on Copyright Infringement Through NFTs
China to Crack Down on Copyright Infringement Through NFTs Authorities in China are going after creators of digital collectibles based on other people’s works of art, the us
MoonPay and Christie’s dip into AI-generated art with new ‘Web3 Tools’
Savannah Fortis9 hours agoMoonPay and Christie’s dip into AI-generated art with new ‘Web3 Tools’More bridges between Web3 and generative AI are being built as the luxury art auctioneer Christie’s and MoonPay unve
Ezra Reguerra25 minutes agoPolkadot community PolkaWorld halts operations after failed funding bidBrushfam founder Markian Ivanichok claimed that the Polkadot ecosystem "doesn"t care about users" and expressed
Zhiyuan Sun6 hours agoElon Musk kickstarts new AI company to ‘understand the universe’"The goal of xAI is to understand the true nature of the universe," the company wrote.1116 Total views13 Total sharesLis
Worldcoin tightens privacy checks, allows users to unverify World ID
Helen Partz11 hours agoWorldcoin tightens privacy checks, allows users to unverify World IDSam Altman’s Worldcoin is taking measures to improve the protection of user data and ensure that its platform is available only
Mastercard Views Crypto More as Asset Class Than Form of Payment
Mastercard Views Crypto More as Asset Class Than Form of Payment Mastercard sees cryptocurrency as more of an asset class than a means of payment, according to the payments giant&#
Trump Buries Fed Chair Jerome Powell After ‘Gutless’ Policy Decision
The Federal Reserve’s quarter-point rate cut on Wednesday was met with hostility by President Trump, who blasted Chairman Jerome Powell for lacking vision and being totally ‘gutless’ about helping the
Ripple Labs Is ‘Interested’ in Bankrupt Crypto Lender Celsius and Its Assets, Company Spokesperson Says
Ripple Labs Is "Interested" in Bankrupt Crypto Lender Celsius and Its Assets, Company Spokesperson Says According to a Ripple Labs spokesperson, the distributed ledger company is i
Amaka Nwaokocha13 hours agoRipple CTO seeks community consensus for XRPL AMM feature adoptionDavid Schwartz stated that the changes could be implemented in as little as two weeks if a majority supports the amendment.2946
Financial Bazookas Revealed – Market Strategists Believe the Fed Will Purchase Stocks Soon
Financial Bazookas Revealed - Market Strategists Believe the Fed Will Purchase Stocks Soon Bitcoin and cryptocurrencies may be the only free-market assets left not manipulated by