{"id":29395,"date":"2022-06-09T05:46:29","date_gmt":"2022-06-09T09:46:29","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=29395"},"modified":"2022-06-09T05:46:40","modified_gmt":"2022-06-09T09:46:40","slug":"attackers-steal-5-million-from-osmosis-in-lp-theft-2-million-returned-soon-after","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/attackers-steal-5-million-from-osmosis-in-lp-theft-2-million-returned-soon-after\/","title":{"rendered":"Attackers Steal $5 Million From Osmosis In LP Theft, $2 Million Returned Soon After"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Attackers took advantage of a bug in the <a href=\"https:\/\/coinscreed.com\/staging\/this-blockchain-was-suspended-after-it-loses-5-million-due-to-bug.html\">Osmosis<\/a> exchange to steal $5 million.<\/h5>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"29396\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-1024x576.jpg\" alt=\"\" class=\"wp-image-29396\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>Osmosis, a decentralized exchange built on the Cosmos network, was shut down just before 3 a.m. ET on June 8 after attackers stole $5 million by exploiting a liquidity provider (LP) bug.<\/p>\n\n\n\n<p>The bug was first <a href=\"https:\/\/twitter.com\/TheJunonaut\/status\/1534402698556190726\" target=\"_blank\" rel=\"noreferrer noopener\">identified<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> in a Reddit post on the official Cosmos Network page. Straight-Hat3855 alerted the community to a &#8220;serious problem&#8221; with Osmosis (OSMO), which allowed users to arbitrarily grow LPs by 50% simply by adding and removing liquidity. The Reddit post was quickly removed, but not before malicious actors exploited the bug, causing $5 million to be removed from liquidity pools on the <a href=\"https:\/\/coinscreed.com\/staging\/osmosis-dex-faces-hack-resulting-in-5m-loss.html\">Osmosis exchange<\/a>.<\/p>\n\n\n\n<p><a href=\"https:\/\/notice.mintscan.io\/osmosis\/218\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> to an announcement from Osmosis block explorer Mintscan, the Osmosis exchange was halted at a block height of 4,713,064, following the exploit and identification of the LP bug.<\/p>\n\n\n\n<p>Project moderator RoboMcGobo detailed how the bug worked in a series of posts on the Osmosis Discord, detailing how the flaw allowed attackers to add liquidity to any Osmosis LP and then immediately withdraw it for a 150 percent return on their initial deposit: &#8220;Essentially, the function would give 50% too many LP shares for a join,&#8221; RoboMcGobo wrote shortly after 4 p.m. on Wednesday, adding, &#8220;If one should have received 10 LP shares, 15 would be achieved out.&#8221;<\/p>\n\n\n\n<p>According to RoboMcGobo, the bug was &#8220;exploited intentionally by a small number of users&#8221; and &#8220;apparently unintentionally by a few others.&#8221;<\/p>\n\n\n\n<p>According to an Osmosis Twitter thread, four attackers were responsible for 95% of the total amount exploited, with two of the attackers voluntarily stepping forward to return stolen funds.<\/p>\n\n\n\n<p>Approximately one hour after Osmosis' tweet about the attack, FireStake, a validator in the Cosmos ecosystem, posted a Twitter thread admitting that &#8220;a temporary lapse in good judgment&#8221; resulted in two members of its team exploiting the bug to the tune of $2 million.<\/p>\n\n\n\n<p>When Firestake continued to exploit the bug, they told their 1,700 Twitter followers that they were &#8220;thinking about [their] family's future.&#8221; They decided to voluntarily return the funds and &#8220;set things straight&#8221; after admitting to &#8220;stressing through the night&#8221; about the event.<\/p>\n\n\n\n<p>The other two hackers responsible for the theft, <a href=\"https:\/\/commonwealth.im\/osmosis\/discussion\/5359-discussion-thread-osmosis-halt-20220608\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">according<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> to Osmosis co-founder Sunny Aggarwal, made a series of transactions to centralized exchanges, which Aggarwal believes will make it easier to track them down.<\/p>\n\n\n\n<p>In the project's Discord, RoboMcGobo said, &#8220;Funds have been linked to CEX accounts.&#8221; The authorities have been notified\u2026 We're hoping that the exploiters will do the right thing here and that no aggressive action is required.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers took advantage of a bug in the Osmosis exchange to steal $5 million. Osmosis, a decentralized exchange built on the Cosmos network, was shut down just before 3 a.m. ET on June 8 after attackers stole $5 million by exploiting a liquidity provider (LP) bug. The bug was first identified in a Reddit post [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":29396,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10474,10444],"class_list":["post-29395","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-lp-bug","tag-osmosis"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-2022-04-27-105623.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/29395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=29395"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/29395\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/29396"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=29395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=29395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=29395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}