{"id":31869,"date":"2022-07-11T03:31:54","date_gmt":"2022-07-11T07:31:54","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=31869"},"modified":"2022-07-11T03:31:59","modified_gmt":"2022-07-11T07:31:59","slug":"re-entrancy-exploit-hits-nft-platform-omni-losing-1-4m-in-eth","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/re-entrancy-exploit-hits-nft-platform-omni-losing-1-4m-in-eth\/","title":{"rendered":"Re-Entrancy Exploit Hits NFT Platform OMNI, Losing $1.4M in ETH"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">The NFT company, OMNI has temporarily paused all of its services and informed users that no consumer monies were stolen.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"614\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-1024x614.jpg\" alt=\"Re-Entrancy Exploit Hits NFT Platform OMNI, Losing $1.4M in ETH\" class=\"wp-image-31873\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-1024x614.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-300x180.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-768x460.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-150x90.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-750x450.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack-1140x683.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack.jpg 1201w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Re-Entrancy Exploit Hits NFT Platform OMNI, Losing $1.4M in ETH<\/figcaption><\/figure>\n\n\n\n<p>A re-entrancy attack caused OMNI, an NFT financial company that lends out cryptocurrencies in exchange for staked NFTs, to lose roughly 1,300 ETH, which was worth $1.4 million at the time.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">It seems a reentrancy-related hack. <a href=\"https:\/\/twitter.com\/ParallelFi?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@ParallelFi<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>  <a href=\"https:\/\/twitter.com\/omni_xyz?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@OMNI_xyz<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> The stolen funds were just mixed via <a href=\"https:\/\/twitter.com\/TornadoCash?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@TornadoCash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/Nyunlkk3rr\" target=\"_blank\">https:\/\/t.co\/Nyunlkk3rr<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/XxxVyX80Fq\" target=\"_blank\">pic.twitter.com\/XxxVyX80Fq<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; PeckShield Inc. (@peckshield) <a href=\"https:\/\/twitter.com\/peckshield\/status\/1546096506159058947?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 10, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Bad Debts from Poor Code<\/h2>\n\n\n\n<p>After staking NFTs from the Doodle collection in bad faith, the enterprise in question lost the money. The attacker first deposited Doodles as security for a loan of <a href=\"https:\/\/www.google.com\/search?q=Re-Entrancy+Exploit+Hits+NFT+Platform+OMNI%2C+Losing+%241.4M+in+ETH&oq=Re-Entrancy+Exploit+Hits+NFT+Platform+OMNI%2C+Losing+%241.4M+in+ETH&aqs=chrome..69i57.1254j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">wrapped ETH<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> before launching the hack (wETH). After the loan was confirmed, the exploiter had access to all Doodles but one, which allowed a callback function to cancel the debt that had been obtained by buying wETH.<\/p>\n\n\n\n<p>The Doodle that was still on the platform after completing these two stages was insufficient to pay out the loan. The system then liquidated the situation and gave the remaining Doodles back to the attacker.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">White Hat Appeal Has No Chance<\/h2>\n\n\n\n<p>Following recent attacks on<a href=\"https:\/\/coinscreed.com\/staging\/bitcoin-and-lightning-network-can-protect-defi-michael-saylor.html\" target=\"_blank\" rel=\"noreferrer noopener\"> DeFi, <\/a>recently attacked developers have frequently made direct appeals to the hackers, promising to accept them as a white-hat event in exchange for the majority of all of the monies taken.<\/p>\n\n\n\n<p>This has occasionally gone out well; for instance, the Optimism exploiter refunded the majority of the cash after seeking Vitalik Buterin's counsel. When the devs at Harmony recently attempted the same strategy, they were blatantly disregarded as the stolen tokens were being laundered.<\/p>\n\n\n\n<p>The attacker in this instance transmitted his freshly appropriated <a href=\"https:\/\/coinscreed.com\/staging\/hackers-steal-100m-from-harmonys-horizon-bridge.html\" target=\"_blank\" rel=\"noreferrer noopener\">wETH <\/a>right away to Tornado, a mixing service that hides the source of funds, so the appeal was never given an opportunity to be made. Due to this feature, fraudsters frequently use it when trying to launder illicit gains.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-suspended-omni-protocol\">Suspended OMNI Protocol<\/h2>\n\n\n\n<p>The developers in charge have suspended the <a href=\"https:\/\/coinscreed.com\/staging\/fdic-investigates-voyagers-deposit-insurance-claims-report.html\" target=\"_blank\" rel=\"noreferrer noopener\">OMNI protocol<\/a>, which is currently in beta, while they conduct audits and apply security updates. Additionally, OMNI developers stated that the hack did not affect any client payments, proving that the stolen wETH were &#8220;internal testing monies.&#8221;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\" id=\"h-omni-is-still-in-testing-beta-no-customer-funds-were-lost-only-internal-testing-funds-were-affected-we-have-suspended-the-omni-protocol-until-we-completed-the-investigation-and-have-everything-reviewed-again-by-external-security-and-auditing-firms\"><p>\u201cOMNI is still in testing (beta). No customer funds were lost, only internal testing funds were affected! We have suspended the OMNI protocol until we completed the investigation and have everything reviewed again by external security and auditing firms.\u201d<\/p><\/blockquote>\n\n\n\n<p>Unfortunately, it appears that OMNI may have to stay in beta for a bit longer than initially anticipated, which is bad news for the project's developers and supporters.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The NFT company, OMNI has temporarily paused all of its services and informed users that no consumer monies were stolen. A re-entrancy attack caused OMNI, an NFT financial company that lends out cryptocurrencies in exchange for staked NFTs, to lose roughly 1,300 ETH, which was worth $1.4 million at the time. Bad Debts from Poor [&hellip;]<\/p>\n","protected":false},"author":38,"featured_media":31873,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10921],"class_list":["post-31869","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-omni"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/07\/Omni_Hack.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=31869"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/31869\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/31873"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=31869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=31869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=31869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}