{"id":31716,"date":"2022-07-07T04:32:02","date_gmt":"2022-07-07T08:32:02","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=31716"},"modified":"2022-07-07T04:32:31","modified_gmt":"2022-07-07T08:32:31","slug":"crema-hacker-returns-8-million-keeps-1-6-million-in-bounty","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/crema-hacker-returns-8-million-keeps-1-6-million-in-bounty\/","title":{"rendered":"Crema Hacker Returns $8 Million, Keeps $1.6 Million In Bounty"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-as-a-white-hat-bounty-the-crema-finance-team-gave-the-hacker-who-stole-almost-10-million-from-the-protocol-16-7-percent-of-the-stolen-money\">As a &#8220;white hat bounty,&#8221; the Crema Finance team gave the hacker who stole almost $10 million from the protocol 16.7 percent of the stolen money.<\/h5>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"705\" height=\"434\" data-id=\"31718\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Crypto-Theft-Insurance-min.jpg\" alt=\"\" class=\"wp-image-31718\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Crypto-Theft-Insurance-min.jpg 705w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Crypto-Theft-Insurance-min-300x185.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Crypto-Theft-Insurance-min-150x92.jpg 150w\" sizes=\"(max-width: 705px) 100vw, 705px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>The hacker who hacked the Solana-based liquidity protocol Crema Finance on July 2 was allowed to keep $1.6 million as a white hat prize.<\/p>\n\n\n\n<p>The reward, 45,455 Solana (<a href=\"https:\/\/coinscreed.com\/staging\/solana-sol-tumbles-15-during-outage-will-there-be-more-losses.html\">SOL<\/a>), is worth a hefty 16.7 percent of the initial $9.6 million Crema loss, which led the protocol to cease services.<\/p>\n\n\n\n<p>Crema's crew started looking for the hacker by tracking their Discord <a href=\"https:\/\/twitter.com\/Crema_Finance\/status\/1543929401842098177\" target=\"_blank\" rel=\"noreferrer noopener\">handle<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> and <a href=\"https:\/\/twitter.com\/Crema_Finance\/status\/1544172448265908224\" target=\"_blank\" rel=\"noreferrer noopener\">tracing<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> the initial gas source for the hacker's address. Just as it appeared that the team had discovered the hidden identity, it announced that it had been negotiating with the hacker. The hacker returned 6,064 Ether (ETH) and 23,967 SOL worth around $8 million on July 6.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"750\" height=\"720\" data-id=\"31720\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/IMG-20220707-WA0002.jpg\" alt=\"\" class=\"wp-image-31720\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/IMG-20220707-WA0002.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/IMG-20220707-WA0002-300x288.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/IMG-20220707-WA0002-150x144.jpg 150w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>The funds were refunded in a sequence of transactions on the Ethereum and Solana networks by the hacker. The initial transaction on each network was a test with a small number of coins, while the subsequent transaction was worth the majority of the monies transmitted.<\/p>\n\n\n\n<p>Crema users and the team can breathe easier now that the finances have been secured, but there is still work to be done. Before the agreement was reached, the team declared on July 5 that it had submitted a fresh code for auditing to ensure that the same issue did not occur again.<\/p>\n\n\n\n<p>Although the community is still waiting for an official post-mortem on the attack, the Crema team detailed what happened in a July 3 Twitter <a href=\"https:\/\/twitter.com\/Crema_Finance\/status\/1543638844410499073\" target=\"_blank\" rel=\"noreferrer noopener\">thread<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>. The attacker obtained a flash loan through the Solend decentralized finance (<a href=\"https:\/\/coinscreed.com\/staging\/bitcoin-and-lightning-network-can-protect-defi-michael-saylor.html\">DeFi<\/a>) lending protocol, which was then used to fund a Crema pool.<\/p>\n\n\n\n<p>The hacker then falsified price data to appear to be owed a far larger reward than they were. This enabled them to withdraw &#8220;a significant fee amount&#8221; of approximately $9.6 million from the pool to which they added the flash loan.<\/p>\n\n\n\n<p>According to the team's tweet, the Crema protocol will be operational after the audit is completed. By July 8, the team will also release a compensation plan for affected users.<\/p>\n\n\n\n<p>Crema is fortunate to have recovered as much money as it did, given the disaster that struck the Horizon Bridge on Harmony last month. A hacker stole $100 million in cryptocurrency from Harmony's token bridge and turned down a $1 million white hat reward to restore the assets.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a &#8220;white hat bounty,&#8221; the Crema Finance team gave the hacker who stole almost $10 million from the protocol 16.7 percent of the stolen money. The hacker who hacked the Solana-based liquidity protocol Crema Finance on July 2 was allowed to keep $1.6 million as a white hat prize. The reward, 45,455 Solana (SOL), [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":31719,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10908],"class_list":["post-31716","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-crema-hacker"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Crypto-Theft-Insurance-min-1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=31716"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31716\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/31719"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=31716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=31716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=31716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}