{"id":30829,"date":"2022-06-24T05:16:20","date_gmt":"2022-06-24T09:16:20","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=30829"},"modified":"2022-06-24T07:41:43","modified_gmt":"2022-06-24T11:41:43","slug":"hackers-steal-100m-from-harmonys-horizon-bridge","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hackers-steal-100m-from-harmonys-horizon-bridge\/","title":{"rendered":"Hackers steal $100M from Harmony&#8217;s Horizon Bridge"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-a-100-million-worth-of-altcoins-have-been-obtained-through-harmony-s-horizon-bridge-and-are-being-exchanged-for-ether-eth\">A $100 million worth of altcoins have been obtained through Harmony's Horizon Bridge and are being exchanged for ether (ETH).<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-1024x683.jpeg\" alt=\"Hackers steals $100M from Harmony's Horizon bridge\" class=\"wp-image-30852\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-1024x683.jpeg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-300x200.jpeg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-768x512.jpeg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-150x100.jpeg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-750x500.jpeg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge-1140x760.jpeg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge.jpeg 1500w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Hackers steal $100M from Harmony's Horizon bridge<\/figcaption><\/figure>\n\n\n\n<p>The hack might prove the community's earlier worries about the reliability of the two of four multisig that purportedly safeguard the bridge to be unfounded.<\/p>\n\n\n\n<p>There were 11 transactions conducted from the bridge for<a href=\"https:\/\/coinscreed.com\/staging\/binance-seizes-5-8m-from-axie-infinity-hackers.html\" target=\"_blank\" rel=\"noreferrer noopener\"> different tokens<\/a> between 7:08 and 7:26 ET. Since then, they have started transferring tokens to an alternative wallet in order to exchange them for ETH on the Uniswap decentralized exchange (DEX), then transferring the ETH back to the original wallet.<\/p>\n\n\n\n<p>Frax (FRAX), Wrapped Ether, and so far (WETH). Sushi (SUSHI), AAG (AAG), Aave (AAVE), Frax Share (FXS), and Binance USD (BUSD). Through this vulnerability, Dai (DAI), Tether (USDT), Wrapped BTC (WBTC), and USD Coin (USDC) have all been taken off the bridge.<\/p>\n\n\n\n<p>Token transfers between Harmony and the Ethereum network, Binance Chain, and Bitcoin are made possible by the Horizon Bridge. The bridge has been stopped, <a href=\"https:\/\/www.google.com\/search?q=Hacker+steals+%24100M+from+Harmony%27s+Horizon+Bridge&oq=Hacker+steals+%24100M+from+Harmony%27s+Horizon+Bridge&aqs=chrome..69i57.2593j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">according to Harmony<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the bridge's operator, who made the announcement late on June 23. The BTC bridge and its assets, according to the statement, were unaffected by the attack.<\/p>\n\n\n\n<p>The Harmony team added that it was collaborating with &#8220;national authorities and forensic experts&#8221; to identify the culprit. There will undoubtedly be a postmortem.<\/p>\n\n\n\n<p>Requests for a response from Harmony's developers and co-founder Nick White went unanswered.<a href=\"https:\/\/coinscreed.com\/staging\/list-of-top-10-blockchain-explorers.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Layer-1 blockchain Harmony<\/a> uses proof-of-stake consensus. One is its native token.<\/p>\n\n\n\n<p>The reliability of Horizon's multisig wallet on Ethereum, which only required two of the four signers to drain the cash, has previously been questioned. The low number of required signers would leave the bridge exposed for &#8220;another 9-figure hack,&#8221; said Chainstride Capital CEO Ape Dev on Twitter on April 2.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ The Harmony team has identified a theft occurring this morning on the Horizon bridge amounting to approx. $100MM. We have begun working with national authorities and forensic specialists to identify the culprit and retrieve the stolen funds.<br><br>More \ud83e\uddf5<\/p>&mdash; Harmony \ud83d\udc99 (@harmonyprotocol) <a href=\"https:\/\/twitter.com\/harmonyprotocol\/status\/1540110924400324608?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">June 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Given that the bridge's assets are currently down by $100 million, Ape Dev's prediction seems to have come true.<\/p>\n\n\n\n<p>He is not the only cryptocurrency engineer who has concerns about the safety of token bridges.<\/p>\n\n\n\n<p>In a Reddit post this past January, Vitalik Buterin outlined the problems with token bridges. According to his theory, when bridges are misused, the liquidity of each chain that is impacted is put in jeopardy. The prospect of a 51 percent attack on one chain could pose a bigger risk of spreading to other chains as the number of token bridges rises, he continued.<\/p>\n\n\n\n<p>Since he made his prediction, the Wormhole Bridge, Ronin Bridge, and Meter's Token Bridge have all been used for approximately $1 billion in total.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">The security of the bridge is currently predicated on a multisig wallet deployed at 0x715CdDa5e9Ad30A0cEd14940F9997EE611496De6. It has four owners, two of which are required to consent in order to execute an arbitrary transaction (i.e. drain the $330m). <a href=\"https:\/\/t.co\/sgYmyPrYgf\" target=\"_blank\">pic.twitter.com\/sgYmyPrYgf<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Ape Dev (@_apedev) <a href=\"https:\/\/twitter.com\/_apedev\/status\/1510007665400950791?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 1, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Attacks continue to pose a security risk due to multisignature. Only five of the nine validators on the Ronin Bridge were necessary to confirm a transaction. Over $600 million in assets were taken by the attacker when he gained control of the necessary five validators.<\/p>\n\n\n\n<p>The prices of all the affected coins and tokens have not changed significantly, suggesting that the market has not yet reacted to the attack. However, over the previous 24 hours, ONE has decreased by 7.4%, with the most of the decline occurring in the last 5 hours. According to CoinGecko, it is currently trading at $0.024.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A $100 million worth of altcoins have been obtained through Harmony&#8217;s Horizon Bridge and are being exchanged for ether (ETH). The hack might prove the community&#8217;s earlier worries about the reliability of the two of four multisig that purportedly safeguard the bridge to be unfounded. There were 11 transactions conducted from the bridge for different [&hellip;]<\/p>\n","protected":false},"author":38,"featured_media":30852,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10768],"class_list":["post-30829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-horizon-bridge"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/Hackers-steals-100M-from-Harmonys-Horizon-bridge.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/30829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=30829"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/30829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/30852"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=30829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=30829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=30829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}