Possible ‘white hat hacker’ exploits THORchain for $8M, proposes 10% bounty

The white-hat hacker claims to have mercifully minimized the damage of their $8 million exploit in a bid to teach THORChain a lesson.

Cross-chain decentralized exchange THORChain has suffered its second multi-million-dollar hack in as many weeks, with $8 million worth of Ether impacted.

However, the attack appears to have been carried out by a white-hat hacker, with THORChain announcing the perpetrator had requested a 10% bounty. ETH will be halted until the code has been audited.

Liquidity providers impacted by the exploit will be subsidized using the project’s treasury funds

The exchange — which is still in the middle of a staged beta launch called Chaosnet — conceded that the “complexity” of its state machine comprises THORChain’s “Archille’s heel,” however asserted that its issues “can be solved with more eyes on, as well as a re-think in developer procedures and peer-review.”

A screenshot shared from the project’s Discord forum appears to show a message forwarded to the project by the hack via transaction data.

The hacker claims they deliberately minimized the damage from the exploit in a bid to teach THORChain a lesson, stating: “Do not rush code that controls 9 figures,” and “Disable until audits are complete.”

The hacker adds that they could have stolen Ether, Bitcoin, Binance Coin, Lycancoin, and many BEP-20 tokens if they had wanted to, asserting that “multiple critical issues” were found and that a 10% bug bounty could have prevented the incident.

On July 16, Cointelegraph reported that THORChain had been halted after 4,000 Ether worth $7.6 million was drained from the protocol. The protocol unsuccessfully proposed a bug bounty to the hacker in exchange for returning the stolen funds.

Related: ChainSwap announces compensation and ‘deep audit’ plan after $8M exploit

The decentralized exchange also lost $140,000 in a separate exploit suffered last month.

THORChain entered into its guarded “Chaosnet” launch in April, enabling cross-chain swaps across the Bitcoin, Ethereum, Litecoin, Bitcoin Cash, and Binance Chain networks.

Read Entire Article


Add a comment

  • bitcoinBitcoin(BTC)$26,051.000.02%
  • ethereumEthereum(ETH)$1,652.21-0.04%
  • tetherTether(USDT)$1.00-0.08%
  • binancecoinBNB(BNB)$217.290.72%
  • rippleXRP(XRP)$0.521.75%
  • usd-coinUSD Coin(USDC)$1.00-0.04%
  • cardanoCardano(ADA)$0.260196-0.85%
  • dogecoinDogecoin(DOGE)$0.0631641.33%
  • tronTRON(TRX)$0.0774861.09%
  • polkadotPolkadot(DOT)$4.501.99%
  • litecoinLitecoin(LTC)$65.301.07%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$26,065.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$189.59-0.41%
  • uniswapUniswap(UNI)$4.58-0.60%
  • stellarStellar(XLM)$0.1229001.01%
  • moneroMonero(XMR)$141.101.34%
  • aaveAave(AAVE)$56.961.06%
  • havvenSynthetix Network(SNX)$2.06-0.07%
  • tezosTezos(XTZ)$0.701.39%
  • eosEOS(EOS)$0.581.13%
  • theta-tokenTheta Network(THETA)$0.641.26%
  • bitcoin-cash-svBitcoin SV(BSV)$29.94-1.07%
  • nemNEM(XEM)$0.025210-0.32%
  • bitcoinBitcoin(BTC)$26,051.000.02%
  • ethereumEthereum(ETH)$1,652.21-0.04%
  • tetherTether(USDT)$1.00-0.08%
  • binancecoinBNB(BNB)$217.290.72%
  • rippleXRP(XRP)$0.521.75%
  • usd-coinUSD Coin(USDC)$1.00-0.04%
  • cardanoCardano(ADA)$0.260196-0.85%
  • dogecoinDogecoin(DOGE)$0.0631641.33%
  • tronTRON(TRX)$0.0774861.09%
  • polkadotPolkadot(DOT)$4.501.99%
  • litecoinLitecoin(LTC)$65.301.07%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$26,065.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$189.59-0.41%
  • uniswapUniswap(UNI)$4.58-0.60%
  • stellarStellar(XLM)$0.1229001.01%
  • moneroMonero(XMR)$141.101.34%
  • aaveAave(AAVE)$56.961.06%
  • havvenSynthetix Network(SNX)$2.06-0.07%
  • tezosTezos(XTZ)$0.701.39%
  • eosEOS(EOS)$0.581.13%
  • theta-tokenTheta Network(THETA)$0.641.26%
  • bitcoin-cash-svBitcoin SV(BSV)$29.94-1.07%
  • nemNEM(XEM)$0.025210-0.32%