Moneycontrol PRO
HomeNewsBusinessCryptocurrencyCrema exploit: Hacker returns stolen funds

Crema exploit: Hacker returns stolen funds

The hacker, on June 3, had stolen 69,422.9 SOL and 6,497,738 USDC stablecoin, worth about $9 million at the time of the hack.

July 07, 2022 / 19:24 IST
Representative Image
-
Open Trading A/c
-
0 (0%)
Todays L/H
0
0

Days after it suffered a major exploit—cryptospeak for someone takes advantage of a security flaw—that resulted in over $9 million being stolen, concentrated liquidity pool Crema Finance on Thursday announced that after intense negotiations, the hacker agreed to return most of the funds for a $1.6-million bounty.

The hacker, on June 3, had stolen 69,422.9 SOL and 6,497,738 USDC stablecoin, worth about $9 million at the time of the hack.

Modus operandi

According to the company, the hacker lent a flash loan on Solend, the lending and borrowing decentralised finance protocol of Solana platform, to add liquidity on Crema to positions.

The hacker then replaced authentic transaction fee data with forged data to claim a huge fee of about 9 million from the pool to which the loan was lent. To minimise the impact, Crema suspended its smart contract after the exploit.

Hacker about to be unmasked

Crema, along with agencies, then initiated an investigation to ascertain the hacker’s identity. The original gas (jargon for the fee paid to make a cryptocurrency transaction) source of the hacker was traced, their discord handles identified and the movement of funds closely monitored.

Simultaneously, Crema sent an on-chain message to the hacker and offered them to become a “white hat” (ethical hacker) and accept a bounty or face legal action.

Stolen funds returned

“After a long negotiation, the hacker agreed to take 45,455 SOL as the white hat bounty. Now we have confirmed the receipt of 6064 ETH (ethereum) + 23967.9 SOL (Solana’s cryptocoin) in four transactions,” Crema stated.

The company is unlikely to take legal action against the hacker since the stolen money has been returned.

Cross-chain bridges under attack

Recently, Layer 1 blockchain protocol Harmony Protocol suffered a theft on the Horizon bridge amounting to around $100 million in which tokens including Wrapped Ethereum (WETH), AAVE, SUSHI, DAI, Tether (USDT), and USD Coin were stolen.

The hacker rejected a $1-million bounty offered as part of negotiations.

Cross-chain bridges (which enable the exchange of data between blockchain networks) have recently been attacked a number of times by hackers. In January this year, Qubit Finance’s bridge was hacked for $80 million and a month later, bad actors stole $320 million from the Wormhole bridge. In March, $622 million worth of Ethereum and USDC were stolen from Axie Infinity’s Ronin bridge.

Murtuza Merchant is a senior journalist and an avid follower of blockchain and cryptocurrencies.
first published: Jul 7, 2022 07:23 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advertisement

Crypto Basket
Powered By Mudrex

Bitcoin
Current Price ₹ 8,132,044.97 1D returns 3.46%
Buy Now
Ethereum
Current Price ₹ 265,853.14 1D returns 4.26%
Buy Now
Ripple
Current Price ₹ 191.65 1D returns 7.45%
Buy Now
BNB
Current Price ₹ 79,523.19 1D returns 3.41%
Buy Now
USD Coin
Current Price ₹ 93.74 1D returns 0.00%
Buy Now
Solana
Current Price ₹ 12,285.01 1D returns 4.20%
Buy Now
AI Tracker
1W returns-5.16%
Invest Now
Crypto Blue Chip - 5
1W returns-7.80%
Invest Now
BTC 50 :: ETH 50
1W returns-8.09%
Invest Now
DeFi Tracker
1W returns-10.37%
Invest Now
Web3 Tracker
1W returns-15.43%
Invest Now

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347