{"id":10117,"date":"2021-09-17T20:35:09","date_gmt":"2021-09-17T19:35:09","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=10117"},"modified":"2021-09-17T20:35:19","modified_gmt":"2021-09-17T19:35:19","slug":"miso-sushiswaps-token-launchpad-hacked-for-3-million","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/miso-sushiswaps-token-launchpad-hacked-for-3-million\/","title":{"rendered":"MISO, SushiSwap&#8217;s token launchpad, hacked for $3 million"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">After receiving no response from the suspected hacker, SushiSwap's <a href=\"https:\/\/coinscreed.com\/staging\/uspis-audit-reveals-postal-inspectors-needs-cryptocurrency-training.html\" data-type=\"post\" data-id=\"9019\">CTO <\/a>will instruct their lawyer to &#8220;file an IC3 complaint with the FBI.&#8221;<\/h5>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1019\" height=\"509\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-147.png\" alt=\"MISO, SushiSwap's token launchpad, hacked for $3 million\" class=\"wp-image-10128\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-147.png 1019w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-147-300x150.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-147-768x384.png 768w\" sizes=\"(max-width: 1019px) 100vw, 1019px\" \/><\/figure>\n\n\n\n<p>A hacker gained access to the supply chain of<a href=\"https:\/\/www.google.com\/search?q=MISO%2C+SushiSwap%27s+token+launchpad%2C+hacked+for+%243+million&oq=MISO%2C+SushiSwap%27s+token+launchpad%2C+hacked+for+%243+million&aqs=chrome..69i57.1405j0j7&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=MISO%2C+SushiSwap%27s+token+launchpad%2C+hacked+for+%243+million&oq=MISO%2C+SushiSwap%27s+token+launchpad%2C+hacked+for+%243+million&aqs=chrome..69i57.1405j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\"> SushiSwap's token launchpad platform, MISO,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> according to Joseph Delong, chief technology officer of the decentralized finance (DeFi) platform.<\/p>\n\n\n\n<p>&#8220;An anonymous contractor with the GH handle AristoK3 introduced malicious code into the Miso front end,&#8221; according to Delong, replacing the auction wallet address with their own and thereby amassing 865 Ether (ETH), which is worth approximately $3 million. EtherScan can be used to confirm the accuracy of this information.<\/p>\n\n\n\n<p>In the Jay Pegs Auto Mart token auction, a parody <a href=\"https:\/\/coinscreed.com\/staging\/following-steve-cohen-backed-fundraiser-nft-firm-recur-is-now-valued-at-333m.html\" data-type=\"post\" data-id=\"9820\">NFT <\/a>project imitating the value of a 2007 Kia Sedona, the hacker targeted and exploited a single target.<\/p>\n\n\n\n<p>Former senior software engineer at <a href=\"https:\/\/coinscreed.com\/staging\/monetary-authority-of-singapore-shortlists-15-companies-to-develop-retail-cbdc.html\" data-type=\"post\" data-id=\"8898\">ConsenSys<\/a> claims to have received little support from leading cryptocurrency exchanges FTX and <a href=\"https:\/\/coinscreed.com\/staging\/hermitage-museum-raises-440k-from-da-vincis-artwork-nft-auction-on-binance.html\" data-type=\"post\" data-id=\"9425\">Binance<\/a> in his pursuit of the funds on what he described as the &#8220;hardest day of my life so far.&#8221;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>We have asked @FTX_Official and @Binance to turn over the attackers KYC information, but they have resisted on this time sensitive matter. <\/p><p>The attacker(s) has done work with @Yearn and has approached many other projects. I urge you to check your own front ends for exploits. <\/p><cite>\u2014 Joseph Delong (@josephdelong) September 17, 2021<\/cite><\/blockquote>\n\n\n\n<p>Delong publicly expressed his concerns about the hacker's identity, which he identified as blockchain and web developer Eratos, in a statement. The individual has not yet responded to the allegations leveled against him.<\/p>\n\n\n\n<p>Recent events include the miraculous rescue of the <a href=\"https:\/\/coinscreed.com\/staging\/sushiswap-narrowly-escapes-becoming-the-latest-defi-hack-victim.html\" data-type=\"post\" data-id=\"8176\">SushiSwap <\/a>protocol from another potentially disastrous $350-million hack, this time through the <a href=\"https:\/\/coinscreed.com\/staging\/fractionalized-dog-nft-from-pleasrdao-now-worth-336-million.html\" data-type=\"post\" data-id=\"9374\">MISO <\/a>token launchpad platform. The programmer had discovered a severe vulnerability within the auction contract of the BitDAO token sale, and had used his white hat security skills to patch it.<\/p>\n\n\n\n<p>Fortunately, the exploit was not discovered by any loitering <a href=\"https:\/\/coinscreed.com\/staging\/japanese-crypto-exchange-liquid-loses-almost-100m-to-hackers.html\" data-type=\"post\" data-id=\"8367\">hackers<\/a>, and the sale was able to continue without interruption. The event did, however, highlight what the white hat described as a &#8220;obvious misstep&#8221; made by the team's security operation during the preparations.<\/p>\n\n\n\n<p>In July of this year, the <a href=\"https:\/\/coinscreed.com\/staging\/estonian-defi-platform-minterest-protocol-raises-6-5m.html\" data-type=\"post\" data-id=\"10077\">DeFi<\/a> platform released its highly anticipated \u201c7\/20\u201d project update, which revealed the upcoming launch of a new automated market maker called Trident, which is intended to be the most capital-efficient market maker on the market by 2020.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After receiving no response from the suspected hacker, SushiSwap&#8217;s CTO will instruct their lawyer to &#8220;file an IC3 complaint with the FBI.&#8221; A hacker gained access to the supply chain of SushiSwap&#8217;s token launchpad platform, MISO, according to Joseph Delong, chief technology officer of the decentralized finance (DeFi) platform. &#8220;An anonymous contractor with the GH [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":10128,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[326,4458,147,853],"class_list":["post-10117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-binance","tag-miso","tag-nft","tag-sushiswap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-147.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/10117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=10117"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/10117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/10128"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=10117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=10117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=10117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}