BTC $64,762.30 +0.86%
ETH $1,919.00 +0.50%
BNB $595.13 +4.17%
XRP $1.08 +0.04%
SOL $74.50 +0.50%
TRX $0.3288 +1.10%
DOGE $0.0706 -0.34%
ADA $0.1722 +2.88%
BCH $219.11 +4.04%
LINK $8.48 +1.09%
HYPE $54.96 +0.21%
AAVE $99.24 -0.24%
SUI $0.6997 +1.00%
XLM $0.1721 -0.28%
ZEC $472.17 +0.99%
BTC $64,762.30 +0.86%
ETH $1,919.00 +0.50%
BNB $595.13 +4.17%
XRP $1.08 +0.04%
SOL $74.50 +0.50%
TRX $0.3288 +1.10%
DOGE $0.0706 -0.34%
ADA $0.1722 +2.88%
BCH $219.11 +4.04%
LINK $8.48 +1.09%
HYPE $54.96 +0.21%
AAVE $99.24 -0.24%
SUI $0.6997 +1.00%
XLM $0.1721 -0.28%
ZEC $472.17 +0.99%

incident

All
Article
Flash

Ostium releases an update on the attack incident, price data was attacked, but traders' collateral and positions were not affected

Ostium released an update on the attack incident. Its liquidity provider fund was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that provides price data to the protocol and submitted disguised illegal price reports, extracting artificially generated profits from the fund by quickly opening and closing multiple large positions.Ostium stated that traders' collateral is stored in independently isolated smart contracts and was not affected by this incident, with all trading positions remaining open. The team paused trading and froze all trading contracts within 60 minutes after the first attack transaction occurred. Currently, Ostium is collaborating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, coordinating with trading platforms, bridging contracts, and stablecoin issuers to advance the investigation. The engineering team is focused on repairing and strengthening the relevant infrastructure to support the secure resumption of trading.Ostium indicated that it will notify at least 24 hours in advance before unfreezing the trading contracts. After trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the pause. Addressing the affected liquidity providers and securely resuming trading remains the current top priority.

Axelar responds to security incident: Axelar and IBC are unaffected, the vulnerability originates from a third-party token contract's "infinite minting" issue

The cross-chain protocol Axelar Network released a statement regarding the recent security incident related to Secret Network, stating that there is a misunderstanding within the community about the event. Both Axelar and the Inter-Blockchain Communication Protocol (IBC) were not attacked or compromised. The affected token smart contracts were neither developed, deployed, nor maintained by Axelar, and Axelar's firewall mechanism also prevented the impact from spreading to other chains.It is reported that the exploited contract is a forked version based on CW20-ICS20, but the developers removed two core security checks, resulting in an "infinite minting" vulnerability. By deleting the verification mechanisms originally used to prevent such issues, this fork altered the original trust model of the contract and did not undergo a new security audit.Axelar Network explained that anyone can deploy contracts for cross-chain asset wrapping through IBC, and similar contracts have also been used to wrap tokens from other chains into Secret Network. However, the Secret side fork version in this incident has vulnerabilities due to the removal of key security checks. This incident is not a unique logical flaw, nor is it an issue with the IBC protocol itself, but rather a security risk introduced by modifications to third-party contracts.
app_icon
ChainCatcher Building the Web3 world with innovations.