{"id":17748,"date":"2022-02-03T05:57:22","date_gmt":"2022-02-03T04:57:22","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=17748"},"modified":"2022-02-03T10:57:12","modified_gmt":"2022-02-03T09:57:12","slug":"hackers-steal-321m-from-wormhole-token-bridge-platform","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hackers-steal-321m-from-wormhole-token-bridge-platform\/","title":{"rendered":"Hackers steal $321M from Wormhole token bridge platform"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"wormhole-a-token-bridge-between-ethereum-and-solana-has-witnessed-the-latest-defi-hack-resulting-in-the-loss-of-120-000-weth-tokens-321-million-from-the-platform-this-is-the-biggest-hack-in-2022-and-second-after-polynetwork-s-610m-in-2021\">Wormhole a token bridge between Ethereum and Solana has witnessed the <a href=\"https:\/\/coinscreed.com\/staging\/sushiswap-narrowly-escapes-becoming-the-latest-defi-hack-victim.html\" data-type=\"post\" data-id=\"8176\">latest DeFi hack<\/a> resulting in the loss of 120,000 wETH tokens ($321 million) from the platform. This is the biggest hack in 2022 and second after PolyNetwork's $610M in 2021<\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-30.png\" alt=\"Hackers steal $321M from Wormhole token bridge platform\" class=\"wp-image-17755\" width=\"791\" height=\"440\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-30.png 670w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-30-300x167.png 300w\" sizes=\"(max-width: 791px) 100vw, 791px\" \/><\/figure><\/div>\n\n\n\n<p>Wormhole is a token bridge that allows users to send and receive crypto without using a <a href=\"https:\/\/www.google.com\/search?q=Hackers+steal+%24321M+from+Wormhole+token+bridge+platform&rlz=1C1SQJL_enNG889NG889&oq=Hackers+steal+%24321M+from+Wormhole+token+bridge+platform&aqs=chrome..69i57.774j0j9&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Hackers+steal+%24321M+from+Wormhole+token+bridge+platform&rlz=1C1SQJL_enNG889NG889&oq=Hackers+steal+%24321M+from+Wormhole+token+bridge+platform&aqs=chrome..69i57.774j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">centralized exchange <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>across Ethereum, Solana, BSC, Polygon, Avalanche, Oasis, and Terra (CEX).<br>This is the second-biggest DeFi attack to date and the largest crypto hack of 2022 thus far. The Wormhole team has offered a $10 million bug bounty in exchange for the monies' recovery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"about-the-hack\">About the hack<\/h2>\n\n\n\n<p>The hack occurred on the Solana side of the bridge, and there are concerns that Wormhole's bridge to <a href=\"https:\/\/coinscreed.com\/staging\/terra-alerts-its-community-of-a-scam-poll-on-mirror-protocol.html\" data-type=\"post\" data-id=\"15627\">Terra<\/a> may be vulnerable as well.<\/p>\n\n\n\n<p>The Wormhole team has promised that its ETH supply would be replenished to &#8220;guarantee wETH is backed 1:1,&#8221; but no details on where that money will come from or when they will arrive have been released.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"503\" height=\"339\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-29.png\" alt=\"\" class=\"wp-image-17754\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-29.png 503w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-29-300x202.png 300w\" sizes=\"(max-width: 503px) 100vw, 503px\" \/><\/figure>\n\n\n\n<p>On February 2, at 6:24 p.m. UTC, a hack took occurred. At 6:28 p.m. UTC, the attacker created 120,000 wETH (WETH) on Solana, then redeemed 93,750 WETH for ETH worth $254 million on the Ethereum network. Since then, the hacker has purchased SportX (SX), Meta Capital (MCAP), Finally Usable Crypto Karma (FUCK), and Bored Ape Yacht Club Token with some of his funds (APE).<\/p>\n\n\n\n<p>On Solana, the remaining WETH was exchanged for SOL and USDC. The hacker currently has 432,662 SOL ($44 million) in his Solana wallet.<\/p>\n\n\n\n<p>There have been no reports of additional Wormhole assets or chains being harmed, but smart contract auditing firm Certik noted today that &#8220;it is plausible that Wormhole's bridge to the Terra blockchain shares the same vulnerability as their <a href=\"https:\/\/coinscreed.com\/staging\/hackers-steal-321m-from-wormhole-token-bridge-platform.html\" data-type=\"post\" data-id=\"17748\">Solana bridge<\/a>.&#8221;<\/p>\n\n\n\n<p>The Wormhole team contacted the hacker via Ethereum and offered to let them keep $10 million in stolen assets in exchange for the other cash being restored.<\/p>\n\n\n\n<p>&#8220;This is the Wormhole Deployer,&#8221; says the narrator. We discovered that you were able to use the Solana VAA verification and mint tokens to your advantage. We'd like to offer you a whitehat agreement, as well as a $10 million bug bounty for exploit details and the wETH you've earned. Please contact us at contact@certus.one.&#8221;<\/p>\n\n\n\n<p>While the Wormhole team works to solve the exploit, wETH tokens sent across the bridge are still not redeemable at the time of writing.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-28.png\" alt=\"\" class=\"wp-image-17753\" width=\"646\" height=\"87\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-28.png 576w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-28-300x41.png 300w\" sizes=\"(max-width: 646px) 100vw, 646px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"defi-hack-in-2022\">DeFi Hack in 2022<\/h2>\n\n\n\n<p>This is the second token bridge smart contract exploit in a week. Qubit Finance's QBridge was abused for $80 million on BSC on January 28. It's also similar of the Poly Network theft, which saw $610 million in cryptocurrency taken from the site in August. In one scenario, the whitehat hacker refunded nearly all of the monies.<\/p>\n\n\n\n<p>The high frequency of smart contract hacks on token bridges backs up Vitalik Buterin's warning on January 7 that &#8220;fundamental security limits of bridges&#8221; exist.<\/p>\n\n\n\n<p>Although the Ethereum co-advise founder's came in the context of a 51 percent attack on Ethereum, it was timely since it pointed out the general vulnerability that exists on bridges that transmit tokens over layer-1 blockchains.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wormhole a token bridge between Ethereum and Solana has witnessed the latest DeFi hack resulting in the loss of 120,000 wETH tokens ($321 million) from the platform. This is the biggest hack in 2022 and second after PolyNetwork&#8217;s $610M in 2021 Wormhole is a token bridge that allows users to send and receive crypto without [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":17755,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[73],"tags":[5555,6115,5675,5822,7020,7021],"class_list":["post-17748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi-news","tag-ethereum-3","tag-hackers-2","tag-solana-2","tag-terra","tag-wormhole","tag-token-bridge"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-30.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/17748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=17748"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/17748\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/17755"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=17748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=17748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=17748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}