Hackers have exploited a vulnerability in the Wormhole cross-chain crypto platform and $326 million in cryptocurrency were stolen.
Wormhole is a platform that allows users to transfer cryptocurrency across different blockchains. It does this by locking the original token in a smart contract and then minting a wrapped version of the stored token that can be transferred to another blockchain.
The platform supports the Avalanche, Oasis, Binance Smart Chain, Ethereum, Polygon, Solana, and Terra blockchains.
Wormhole had shut down their platform while they are investigating the exploit on their network. By using the exploit, a threat actor minted and stole 120k wrapped Ether tokens on the Solana blockchain. Of these 120k tokens, the threat actors converted 80,000 to Ethereum and left the rest on the Solana blockchain, where they began to sell it.
Wormhole confirmed that a hacker stole 120k wrapped Ethereum (wEth) and that they were adding Ethereum to their platform to ensure all wETh is properly backed.
According to blockchain analytics company Elliptic, a Wormhole representative sent a message to the address owned by the hacker offering a $10 million bug bounty under a “whitehat agreement.”
This agreement requires the return of all stolen funds and details on the vulnerability and the exploit that was used. It is not sure whether the hacker has replied to the message or not.
The Wormhole attack is now the second-largest attack on DeFi services, wherein the largest being Poly Network, that was hacked for over $600 million in August.
Image credits : SensorsTechForum














Comments