Wormhole cryptocurrency platform hacked for $325 million after error on GitHub (2024)

On Wednesday, the decentralized finance (DeFi) platform Wormhole became the victim of the largest cryptocurrency theft this year — andamong the top five largest crypto hacksof all time — when an attacker exploited a security flaw to make off with close to $325 million.

The attack seems to have resulted from a recent update to the project’s GitHub repository, which revealed a fix to a bug that had not yet been deployed to the project itself.

The attack took place on February 2nd and was noticed when a post from the Wormhole Twitter account announced that the network was beingtaken “down for maintenance”while a potential exploit was investigated. Alater postfrom Wormhole confirmed the hack and the amount stolen.

Shortly after the attack, the Wormhole team also offered the hacker a $10 million bounty to return the funds, which was embedded as text in atransactionsent to the attacker’s Ethereum wallet address.

Wormhole provides a service known as a “bridge” between blockchains, essentially an escrow system that allows one type of cryptocurrency to be deposited in order to create assets in another cryptocurrency. This allows a person or entity with holdings in one cryptocurrency to make trades and purchases using another, somewhat like being able to fund a bank account in dollars and then use a bank card to buy something priced in euros.

To carry out the attack, the attacker managed to forge a valid signature for a transaction that allowed them to freely mint 120,000 wETH — a“wrapped” Ethereumequivalent on the Solana blockchain, with value equivalent to $325 million at the time of the theft — without first inputting an equivalent amount. This was then exchanged foraround $250 million in Ethereum that was sent from Wormhole to the hackers’ account, effectively liquidating a large amount of the platform’s Ethereum funds that were being held as collateral for transactions on the Solana blockchain.

Open-source code commits show that code that would have fixed this vulnerability was written as early as January 13th anduploaded to the Wormhole GitHub repositoryon the day of the attack. Just hours later, the vulnerability was exploited by the hacker, suggesting that the updates had not yet been applied to the production application.

As software developer Matthew Garrett observed on Twitter, the code upload was described as if it were a run-of-the-mill version update but actually contained extensive changes — a fact that could have tipped off the attacker to the fact that it was a disguised security fix.

Another file available through the Wormhole Github page alsodetails a security auditconducted by security research company Neodyme between July and September 2021. It is not clear whether the vulnerability was present during the audit period, and Neodyme did not respond to a request for comment.

Due to the nature of cross-chain applications, the attack temporarily left a huge deficit between the amount of wrapped Ethereum and regular Ethereum held in the Wormhole bridge — as if the collateral asset backing a loan had suddenly disappeared. According to Forbes, the attackcaused a 10 percent dropin the value of the Solana cryptocurrency in the aftermath of the hack.

The Wormhole team has announced that more Ethereum will be added to the bridge to replace the stolen collateral funds, effectively meaning that the company will need to find $325 million in assets to plug the gap.

At this stage, it is unclear where the funds will come from. Questions sent to Jump Crypto, parent company of the developers of the Wormhole application, had not received a response at time of publication.

Wormhole cryptocurrency platform hacked for $325 million after error on GitHub (2024)
Top Articles
American University Admission Requirements
Pros and Cons of Microsoft Intune 2024
Omega Pizza-Roast Beef -Seafood Middleton Menu
Fernald Gun And Knife Show
Automated refuse, recycling for most residences; schedule announced | Lehigh Valley Press
Artem The Gambler
Palm Coast Permits Online
Jefferey Dahmer Autopsy Photos
Coindraw App
877-668-5260 | 18776685260 - Robocaller Warning!
Otis Department Of Corrections
The Best Classes in WoW War Within - Best Class in 11.0.2 | Dving Guides
Heska Ulite
Student Rating Of Teaching Umn
7 Low-Carb Foods That Fill You Up - Keto Tips
Animal Eye Clinic Huntersville Nc
Dexter Gomovies
Crossword Nexus Solver
Razor Edge Gotti Pitbull Price
Bj Alex Mangabuddy
Northeastern Nupath
Inter-Tech IM-2 Expander/SAMA IM01 Pro
Ruben van Bommel: diepgang en doelgerichtheid als wapens, maar (nog) te weinig rendement
Publix Super Market At Rainbow Square Shopping Center Dunnellon Photos
Ezel Detailing
Miltank Gamepress
Ice Dodo Unblocked 76
Marion City Wide Garage Sale 2023
Boise Craigslist Cars And Trucks - By Owner
Gs Dental Associates
2011 Hyundai Sonata 2 4 Serpentine Belt Diagram
Harbor Freight Tax Exempt Portal
Dal Tadka Recipe - Punjabi Dhaba Style
Dr Seuss Star Bellied Sneetches Pdf
Rek Funerals
Darknet Opsec Bible 2022
Used 2 Seater Go Karts
Craigslist Central Il
Most popular Indian web series of 2022 (so far) as per IMDb: Rocket Boys, Panchayat, Mai in top 10
Montrose Colorado Sheriff's Department
Überblick zum Barotrauma - Überblick zum Barotrauma - MSD Manual Profi-Ausgabe
Anhedönia Last Name Origin
Academy Sports New Bern Nc Coupons
Lcwc 911 Live Incident List Live Status
Lake Kingdom Moon 31
Giovanna Ewbank Nua
Lyndie Irons And Pat Tenore
Laura Houston Wbap
Naomi Soraya Zelda
Edict Of Force Poe
Land of Samurai: One Piece’s Wano Kuni Arc Explained
San Pedro Sula To Miami Google Flights
Latest Posts
Article information

Author: Lilliana Bartoletti

Last Updated:

Views: 5540

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Lilliana Bartoletti

Birthday: 1999-11-18

Address: 58866 Tricia Spurs, North Melvinberg, HI 91346-3774

Phone: +50616620367928

Job: Real-Estate Liaison

Hobby: Graffiti, Astronomy, Handball, Magic, Origami, Fashion, Foreign language learning

Introduction: My name is Lilliana Bartoletti, I am a adventurous, pleasant, shiny, beautiful, handsome, zealous, tasty person who loves writing and wants to share my knowledge and understanding with you.