Fun

Harmony’s $100M Hack Was Due to a Compromised Multi-Sig Scheme, Says Analyst

News Feed - 2022-06-27 03:06:36

Harmony"s $100M Hack Was Due to a Compromised Multi-Sig Scheme, Says Analyst


On June 23, 2022, the Harmony development team announced that $100 million was siphoned from the Horizon bridge, and the organization explained it was working with national authorities and forensic specialists. According to an account published Polygon’s chief information security officer, Mudit Gupta, the Horizon bridge attacker allegedly took control of the multi-signature wallet leveraged in Harmony’s bridge. Harmony’s Multi-Sig Exploited Polygon’s CSO Says, Harmony Protocol’s Founder Found Evidence That ‘Private Keys Were Compromised’


Three days ago, Harmony explained that it was attacked and the team witnessed $100 million siphoned from the Horizon bridge. “The Harmony team has identified a theft occurring this morning on the Horizon bridge amounting to approx. $100 [million],” Harmony tweeted on Thursday. “We have begun working with national authorities and forensic specialists to identify the culprit and retrieve the stolen funds,” the Harmony team added.


Following the exploit, the very next day, Polygon’s chief information security officer, Mudit Gupta, said that the bridge was a 2 of 5 multi-signature scheme, and anyone with two of the addresses can take control of it. “The hacker compromised 2 addresses and made them drain the money,” Gupta added. Gupta said while the details aren’t public yet he summarized what he believes took place during the hack. “The two addresses were likely hot wallets used to listen for and process legit bridging transactions,” Gupta explained.


“The attacker compromised the server(s) that these hot wallets were running on,” the Polygon CSO wrote on Friday. “Once inside the server, they could access the keys that were kept in plaintext for signing legit transactions. The server exploit was likely either SSH key compromise or social engineering. This is eerily similar to how Ronin was hacked.” The analyst further added: This was not a ‘Blockchain Hack.’ It was a ‘Traditional Hack.’ I’ve been begging protocols to focus on traditional security too alongside blockchain security for months now…


Furthermore, an incident report written by the Harmony Protocol’s founder says “the team has found evidence that private keys were compromised, leading to the breach of our Horizon bridge — Funds were stolen from the Ethereum side of the bridge.” The Harmony founder also noted that “confidentiality is key to maintain integrity as part of this ongoing investigation — The omission of specific details is to protect sensitive data in the interest of our community.” Tags in this story 100 million, 2 of 5 multi-signature scheme, Confidentiality, decentralized finance, DeFi, defi hacks, Harmony Hack, Harmony Protocol, Harmony Protocol’s founder, Horizon Bridge, Horizon bridge Exploit, incident report, Mudit Gupta, Multi-signature, Polygon CSO, Ronin Exploit, sensitive data, Stolen funds


What do you think about the Harmony exploit for $100 million? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. Yuga Labs Sues Artist Ryder Ripps for "Scamming Consumers" and Misusing Bored Ape Trademarks NEWS | 3 hours ago Crypto Firm Voyager Digital Secures a $500M Line of Credit From Alameda Ventures to Cope With 3AC Exposure NEWS | 8 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleCrypto Firm Voyager Digital Secures a $500M Line of Credit From Alameda Ventures to Cope With 3AC Exposure Next articleYuga Labs Sues Artist Ryder Ripps for ‘Scamming Consumers’ and Misusing Bored Ape Trademarks Show comments More Popular NewsIn Case You Missed ItTony Hawk"s Latest NFTs to Come With Signed Physical Skateboards


Last December, the renowned professional skateboarder Tony Hawk released his “Last Trick” non-fungible token (NFT) collection via the NFT marketplace Autograph. Next week, Hawk will be auctioning the skateboards he used during his last tricks, and each of the NFTs ... read more.SEC Risks Violating Admin Procedure Act by Rejecting Spot Bitcoin ETFs, Says Grayscale Bill ‘On Digital Currency’ Caps Crypto Investments for Russians, Opens Door for Payments Goldman Predicts US Recession Odds at 35% in 2 Years, John Mauldin Wouldn"t Be Surprised if Stocks Fell 40% Terra"s Algorithmic Dollar-Pegged Crypto UST Is Now the Third-Largest Stablecoin

News Feed

Crypto Analyst Sets 3 Major Targets For XRP Price, Going As High As 4,800% Return
Este artículo también está disponible en español. Renowned crypto analyst, ‘Egrag Crypto’ took to X (formerly Twitter) to unveil three critical price targets for XRP
Bitcoin miner Riot Platforms miss estimates with wider Q2 loss
Brayden Lindrea8 hours agoBitcoin miner Riot Platforms miss estimates with wider Q2 lossRiot managed to increase its revenue from Bitcoin mining despite reporting a staggering 340% increase in costs to mine a Bitcoin.48
Dogecoin Breakout Coming? Analyst Identifies Key Price Level
Este artículo también está disponible en español. In his latest technical breakdown posted on X, analyst Kevin (@Kev_Capital_TA) highlighted a pivotal threshold on Dogeco
BTC trades at ‘deep discount’ after halving — 5 things to know in Bitcoin this week
William Suberg14 hours agoBTC trades at ‘deep discount’ after halving — 5 things to know in Bitcoin this weekBitcoin has a new countdown after the halving as the days of a sub-$100,000 BTC price are “numbered,”
1,000 Bitcoin From 2010 Worth $68M — Mystery Whale Returns Moving a String of 20 Decade-Old BTC Block Rewards
1,000 Bitcoin From 2010 Worth $68M — Mystery Whale Returns Moving a String of 20 Decade-Old BTC Block Rewards 154 days ago, a mystery bitcoin mining entity spent a string of 20 b
Securing your crypto funds: Exchanges add support for hardware 2FA
Rachel Wolfson10 hours agoSecuring your crypto funds: Exchanges add support for hardware 2FAAs phishing attacks rise, crypto exchanges tell users to keep their funds safe by using YubiKey devices and Passkeys, along with
London’s ‘Joe Rogan’ and crypto advocate Brian Rose makes bid for mayor
Robert D. Knight10 hours agoLondon’s ‘Joe Rogan’ and crypto advocate Brian Rose makes bid for mayorThe former Wall Street and City of London banker is making his second bid to become mayor of London.4369 Total view
IOTA Network Down for 11 Days – Devs Claim Mainnet Will Be Operational Next Month
IOTA Network Down for 11 Days - Devs Claim Mainnet Will Be Operational Next Month The IOTA network has been down for approximately 11 days and the IOTA Foundation doesn’t e
Bitcoin As A Strategic Asset? CryptoQuant CEO Questions US’s Next Move
Este artículo también está disponible en español. Since President-elect Donald Trump raised the possibility of establishing a US Bitcoin Strategic Reserve, many advocates
NY Attorney General Urges Congress to Ban Crypto in Retirement Accounts
NY Attorney General Urges Congress to Ban Crypto in Retirement Accounts New York Attorney General Letitia James has urged Congress to pass a law prohibiting crypto investments in r
Bitcoin traders warn BTC price can still dip to $62K or ‘even lower’
William Suberg55 minutes agoBitcoin traders warn BTC price can still dip to $62K or ‘even lower’BTC price action resembles Deja vu from last week, as a trip toward range highs precedes Donald Trump’s Bitcoin confer
Price analysis 7/24: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIB
Rakesh Upadhyay6 hours agoPrice analysis 7/24: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, AVAX, SHIBBitcoin bulls are trying to protect the $65,500 level, but if they fail, a drop to $62,000 is possible.2202 Total views3 T