Fun

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits

News Feed - 2021-07-27 08:07:46

Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits


Thorchain, a popular defi protocol, has been compromised twice in the last two weeks, resulting in losses of over $10,000,000. The hacker responsible for the latest exploit left behind a message detailing the measures that should be undertaken to protect users. Hacker Returns to the Scene to Lecture on Security


In another blow against the Thorchain protocol, the defi network has found itself the victim of another hack after the equivalent of 4,000 ethereum (ETH) was stolen just days earlier. Thorchain, which features an automated market maker (AMM) and decentralized exchange (dex), is known for its liquidity pooling, with total value locked (TVL) currently around $101.75 million.


This time, the attack was perpetrated against the ETH Router contract to target the Thorchain Bifrost component, resulting in more than $8 million in losses for the protocol. According to the hacker allegedly behind the move, the vulnerability was known before the latest attack and was entirely preventable.


When using Solidity, the Ethereum smart contract coding language used in the protocol, programmers advise developers against using certain coding methods to transfer funds. However, this was allegedly overlooked by the team in charge, leading to an issue within the protocol’s native RUNE token’s contract code.


The hacker behind the exploit was not quick to leave the crime scene. Instead, the malicious actor left behind a message effectively trolling the protocol. In tx input data, the hacker pointed out the following:



The hacker laid bare all the steps that were required to engage the exploit, highlighting the protocol’s decision not to issue bounties or engage auditors to check code that currently oversees a nine-figure TVL. While the protocol developers initially believed the hack cost them only $800,000 and was the work of a whitehat hacker, the following amounts were actually stolen: 966.620 ACLX 20,866,664.530 XRUNE 1,672,794.010 USDC 56,104.000 SUSHI 6.910 YFI 990,137.460 USDT


RUNE tokens have continued their decline after dipping close to 25% following the breach, with tokens currently trending around $4.17. While Thorchain has since issued a recovery plan to restore user funds lost to the attack, the more significant development was the decision to hire security firms to audit the code and defend the defi protocol against future, preventable exploits.


What do you think of this “honest hacker”? Let us know in the comments section below. Kubernetes Clusters Used to Mine Monero by Attackers NEWS | 15 hours ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story Blockchain security, cryptocurrency stolen, DeFi, Hacking, Solidity, Thorchain


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Soccer Superstar Lionel Messi Gets Part of His Contract Paid in Cryptocurrency
Soccer Superstar Lionel Messi Gets Part of His Contract Paid in Cryptocurrency Lionel Messi, the Argentinian soccer superstar, has opted to receive cryptocurrenc
Bitcoin, Ethereum Technical Analysis: BTC, ETH Surge to Start the Weekend, Following Friday’s Payrolls
Bitcoin, Ethereum Technical Analysis: BTC, ETH Surge to Start the Weekend, Following Friday’s Payrolls Bitcoin moved closer to the $17,000 level to start the weekend, as traders
CoinEx Celebrates Third Anniversary With Overall System and Product Upgrade
CoinEx Celebrates Third Anniversary With Overall System and Product Upgrade PRESS RELEASE. CoinEx, a global and professional cryptocurrency exchange service prov
Tom Blackstone6 hours agoCrypto fund outflows reach nearly half a billion over 9 weeks — CoinSharesCrypto investment products have seen over $450 million in cumulative outflows over the past nine weeks.737 Total views5
Effective Altruism: Former FTX CEO’s Alleged $40M Penthouse Listed for Sale, Report Says Firm Spent $74M on Real Estate
Effective Altruism: Former FTX CEO"s Alleged $40M Penthouse Listed for Sale, Report Says Firm Spent $74M on Real Estate In light of a recently published real estate listing, former
Bitcoin Bears Lose Control As BTC Net-Taker Volume Shifts Positive
Este artículo también está disponible en español. Bitcoin has been on an impressive surge since early September, rising by 31% from local lows around $53,000. However, af
Bankruptcy judge signs off on $450M FTX-Voyager settlement
Turner Wright4 hours agoBankruptcy judge signs off on $450M FTX-Voyager settlementAccording to the terms of the deal, FTX will “relinquish any and all rights” to $450 million Voyager Digital has claimed from the cryp
Public blockchain ledgers ‘not fit for purpose,’ says JPMorgan exec
Zoltan Vardai9 hours agoPublic blockchain ledgers ‘not fit for purpose,’ says JPMorgan execDespite the criticism, TradFi institutions still prefer using public blockchains for real-world asset tokenization.1503 Total
Ethereum’s Dencun upgrade to launch in 2 days: Here’s why it matters
Zoltan Vardai12 hours agoEthereum’s Dencun upgrade to launch in 2 days: Here’s why it mattersDencun — the most-anticipated upgrade since the Merge — is set to ship in two days, promising to significantly reduce l
NFT Marketplace Opensea Raises $100 Million — Firm Becomes a Blockchain Unicorn
NFT Marketplace Opensea Raises $100 Million — Firm Becomes a Blockchain Unicorn Opensea has become the latest non-fungible token (NFT)-focused firm to raise fu
David Attlee14 hours agoSingapore High Court rules crypto personal property, compares it to fiat moneyThe judge didn’t see any difference between crypto, fiat money or shells as long as all those objects, physical or n
Daylight secures $9M funding for distributed energy, testnet launch
Ana Paula Pereira8 hours agoDaylight secures $9M funding for distributed energy, testnet launchDaylight’s testnet will allow users to plug in distributed energy devices such as smart thermostats, solar inverters, batte