BTC $77,542.98 +0.44%
ETH $2,511.79 -0.40%
BNB $722.64 -0.59%
XRP $1.37 +0.71%
SOL $101.00 -0.72%
TRX $0.3385 -0.22%
DOGE $0.0839 -0.93%
ADA $0.2064 -0.41%
BCH $223.54 -0.91%
LINK $11.37 -1.09%
HYPE $80.25 +1.39%
AAVE $126.23 -0.62%
SUI $0.7171 -0.78%
XLM $0.1816 +1.00%
ZEC $1,117.55 -2.04%
AAPL $329.21 -1.15%
AMZN $254.52 -0.90%
GOOGL $335.79 -1.51%
MSFT $493.51 -0.32%
META $640.71 -1.08%
NVDA $214.95 -1.16%
TSLA $360.50 -1.73%
SNDK $1,566.11 -3.58%
INTC $98.62 -2.76%
SPCX $148.77 -1.00%
MU $939.73 -2.72%
AMD $498.93 -2.68%
BTC $77,542.98 +0.44%
ETH $2,511.79 -0.40%
BNB $722.64 -0.59%
XRP $1.37 +0.71%
SOL $101.00 -0.72%
TRX $0.3385 -0.22%
DOGE $0.0839 -0.93%
ADA $0.2064 -0.41%
BCH $223.54 -0.91%
LINK $11.37 -1.09%
HYPE $80.25 +1.39%
AAVE $126.23 -0.62%
SUI $0.7171 -0.78%
XLM $0.1816 +1.00%
ZEC $1,117.55 -2.04%
AAPL $329.21 -1.15%
AMZN $254.52 -0.90%
GOOGL $335.79 -1.51%
MSFT $493.51 -0.32%
META $640.71 -1.08%
NVDA $214.95 -1.16%
TSLA $360.50 -1.73%
SNDK $1,566.11 -3.58%
INTC $98.62 -2.76%
SPCX $148.77 -1.00%
MU $939.73 -2.72%
AMD $498.93 -2.68%

stolen

All
Article
Flash

first_img Cronos rolled back the blockchain to recover 111 million USD in stolen funds

Cronos confirmed in a post-mortem report that the attack on the lending platform Tectonic on August 30 involved $120.4 million in borrowing activities. The validators made the "difficult decision" to roll back the on-chain history, successfully recovering approximately $111.2 million (about 92% of the affected funds), while about $9.19 million flowed out before the network was paused and could not be recovered. The attacker leveraged weak DEX liquidity to inflate the price of Tectonic token TONIC by about 100 times within minutes and borrowed $120.4 million through a single transaction across nine markets. The validators paused the network about two hours later, restoring the chain to the last block before the suspicious activity, with block production resuming approximately 11 hours after the attack. The rollback involved reversing 1 hour and 54 minutes of on-chain history, totaling 10,961 blocks, with all transactions within that window being canceled, regardless of whether they were involved in the attack. Cronos stated that the alternative would have been to restart the network without restoring the previous state, which would have left the stolen assets in the hands of the attacker. This rollback closely followed Harmony's announcement of a similar plan, while Flow abandoned its rollback proposal last December due to community opposition. The validator cap for Cronos is 100, which facilitated quick coordination for the pause and restart, but also indicated that the network's finality in emergencies depends on validator consensus.

Galaxy Research: Coldcard attackers continue to transfer funds, approximately 45% of the stolen assets have entered mixing or cross-chain pathways

Galaxy Research published that the attackers in the Coldcard "Wave 3" attack are still continuously transferring the stolen funds. During this phase, the attackers created 293 2-of-2 multi-signature wallets for each victim's assets. The first batch of funds was transferred across chains to Ethereum via THORChain; the latest round of transfers has begun entering the CoinJoin mixing process.Currently, the Wave 3 attackers are processing the largest amounts of stolen funds in order of the stolen amount, having sequentially transferred the funds from wallets ranked 1 to 11. The next 10 wallets that have not yet been transferred hold a total of 30.81 BTC, while wallets ranked 61 to 293 hold a total of 33.77 BTC. So far, the attackers have transferred about 45% of the stolen assets from this exploit, with funds flowing to Ethereum (via THORChain) or entering CoinJoin mixing transactions. Additionally, this fund transfer has revealed a previously unknown wallet: 58 addresses jointly spent in a 2-of-2 multi-signature format identical to that of Wave 3, and these were further transferred by the Wave 3 attackers to a jump address that funds CoinJoin.The on-chain analysis team currently marks this wallet as "cause = open," but believes it likely also belongs to Coldcard victims, which means the number of wallets involved in Wave 3 may increase to 294, raising the previously reported total amount stolen from the Coldcard vulnerability to approximately 1806 BTC. Currently, about 82% of the stolen BTC remains in addresses initially controlled by the attackers, while about 18% has been transferred, with the flow of funds indicating that it may be undergoing laundering processes.

Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million

The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.

153 stolen addresses contain 132.95 BTC, and researchers are still unable to reproduce the Coldcard attacker's seed

According to monitoring by Bitcoin News, new research published by @PraveenPerera shows that Coldcard attackers seem to first identify addresses with vulnerabilities, then sort them by the amount of Bitcoin held, starting to transfer in batches from the addresses with the highest holdings. The transfer software used was relatively crude.One address had 225 spendable UTXOs, and the attackers extracted exactly the latest 200, leaving the earliest 25, which included a UTXO worth 0.16 BTC. This aligns perfectly with the limitation of a blockchain API investigated by researchers, which defaults to returning 200 records, indicating that the attackers may have failed to load the next page of data. The software even spent a UTXO of 294 satoshis, reportedly increasing the transaction fee by about 2040 satoshis, with the spent amount significantly higher than the value of the UTXO itself.The authors of the study believe that the builders of this tool may have a better understanding of the account balance system than of the Bitcoin UTXO model. Although the attackers seem to have obtained the complete seed of the victims, at least 75 BTC still remain in other addresses derived from the same seed. The biggest suspicion currently is that among the 153 stolen addresses, there are still 132.95 BTC, and researchers have been unable to reproduce the seed behind these addresses, so it cannot be ruled out that the attackers obtained undisclosed private device data or candidate data.
app_icon
ChainCatcher Building the Web3 world with innovations.