{"id":44854,"date":"2023-02-07T05:36:01","date_gmt":"2023-02-07T09:36:01","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=44854"},"modified":"2023-02-07T05:36:08","modified_gmt":"2023-02-07T09:36:08","slug":"hacker-steals-over-550-bnb-from-cow-swap","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hacker-steals-over-550-bnb-from-cow-swap\/","title":{"rendered":"Hacker steals over 550 BNB from CoW Swap"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-dex-protocol-cow-swap-has-lost-over-550-bnb-worth-around-181-600-to-hackers-according-to-reports-by-blockchain-security-firm-peckshield\">DEX protocol CoW Swap has lost over 550 BNB worth around $181,600 to hackers according to reports by <a href=\"https:\/\/coinscreed.com\/staging\/rare-bear-discord-phishing-attack-steals-800k-in-nfts.html\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain security firm PeckShield <\/a><\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-11.png\" alt=\"Hacker steals over 550 BNB from CoW Swap \" class=\"wp-image-44877\" width=\"672\" height=\"401\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-11.png 437w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-11-300x179.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-11-150x90.png 150w\" sizes=\"(max-width: 672px) 100vw, 672px\" \/><figcaption class=\"wp-element-caption\">Hacker steals over 550 BNB from CoW Swap <\/figcaption><\/figure>\n\n\n\n<p>In a recent assault, the decentralized exchange (DEX) protocol <a href=\"https:\/\/www.google.com\/search?q=Hacker+steals+over+550+BNB+from+CoW+Swap&rlz=1C1SQJL_enNG889NG889&oq=Hacker+steals+over+550+BNB+from+CoW+Swap&aqs=chrome..69i57.347j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">CoW Swap lost at least 550 BNB <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>due to a contract vulnerability that permitted money transfers from the platform.<\/p>\n\n\n\n<p>MevRefund, a blockchain surveyor, noted the occurrence and noticed that the cash seemed to be departing from CoW Swap. The DEX and its users were alerted to the attack in a discussion on Twitter by the maximum extractable value (MEV) searcher.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/CoWSwap?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@CoWSwap<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> your funds appear to be moooving away &#8230;<a href=\"https:\/\/t.co\/li1NkXNeUp\" target=\"_blank\">https:\/\/t.co\/li1NkXNeUp<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; MevRefund (@MevRefund) <a href=\"https:\/\/twitter.com\/MevRefund\/status\/1622793836291407873?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 7, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>BlockSec, a company that audits smart contracts, claims that a multisig inserted wallet address is a &#8220;solver&#8221; of CoW Swap. Invoking the transaction to approve DAI DAI to SwapGuard, the address thereafter transferred DAI to other addresses through SwapGuard by invoking the CoW Swap settlement contract's transaction.<\/p>\n\n\n\n<p>According to blockchain security company PeckShield, 551 BNB were lost, which at the time of writing was valued $181,600. The hacker sent the monies to the notorious <a href=\"https:\/\/coinscreed.com\/staging\/cryptocurrency-mixer-tornado-cash-open-sources-ui-code.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency mixer Tornado Cash<\/a> after taking the assets.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-10.png\" alt=\"\" class=\"wp-image-44876\" width=\"715\" height=\"255\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-10.png 675w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-10-300x107.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-10-150x54.png 150w\" sizes=\"(max-width: 715px) 100vw, 715px\" \/><figcaption class=\"wp-element-caption\">Flowchart showing the movement of stolen funds from CoW Swap. Source: PeckShield<\/figcaption><\/figure>\n\n\n\n<p>Some community members pushed users to cancel DEX approvals during the incident out of fear. The decentralized finance (DeFi) protocol asserted that this is not required.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We are aware of an issue that has impacted the fees that CoW Protocol has collected over the past week. <br><br>We have mitigated the issue and are conducting an investigation. <br><br>Traders are in no way affected. <br><br>More details to follow.<\/p>&mdash; CoW DAO (@CoWSwap) <a href=\"https:\/\/twitter.com\/CoWSwap\/status\/1622835089263718402?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 7, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The abused settlement contract, according to CoW Swap, only has access to the fees that the protocol accrued over the course of a week. The team said that without direct instruction from users, it is impossible to access user cash.<\/p>\n\n\n\n<p>According to research from DappRadar, the DeFi space has had a successful start in 2023 despite the hacks that have surrounded it. Data indicated that protocols' overall value locked in January increased significantly.<\/p>\n\n\n\n<p>In related news, the UN said that compared to previous years, <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-hackers-use-500-phishing-domains-to-steal-nfts.html\" target=\"_blank\" rel=\"noreferrer noopener\">North Korean hackers<\/a> stole more cryptocurrency in 2022. According to the research, hackers with North Korean ties stole between $630 million and $1 billion worth of cryptocurrency last year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DEX protocol CoW Swap has lost over 550 BNB worth around $181,600 to hackers according to reports by blockchain security firm PeckShield In a recent assault, the decentralized exchange (DEX) protocol CoW Swap lost at least 550 BNB due to a contract vulnerability that permitted money transfers from the platform. MevRefund, a blockchain surveyor, noted [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":44877,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[173,13254,937,10782],"class_list":["post-44854","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-bnb","tag-cow-swap","tag-hackers","tag-tornado-cash-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-11.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/44854","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=44854"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/44854\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/44877"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=44854"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=44854"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=44854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}