{"id":45604,"date":"2023-02-21T08:15:10","date_gmt":"2023-02-21T12:15:10","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=45604"},"modified":"2023-02-21T08:15:12","modified_gmt":"2023-02-21T12:15:12","slug":"hope-finance-loses-2m-in-recent-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hope-finance-loses-2m-in-recent-exploit\/","title":{"rendered":"Hope Finance loses $2M in recent exploit"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/layer-2-networks-optimism-arbitrum-witness-high-combined-transaction-volume.html\" target=\"_blank\" rel=\"noreferrer noopener\">Arbitrum-based decentralized finance<\/a> (DeFi) project Hope Finance has lost users' funds worth about $2 million as a result of a recent smart contract exploit.  <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53.png\" alt=\"Hope Finance loses $2M in recent exploit\" class=\"wp-image-45609\" width=\"970\" height=\"289\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53.png 939w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53-300x89.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53-768x229.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53-150x45.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53-750x224.png 750w\" sizes=\"(max-width: 970px) 100vw, 970px\" \/><figcaption class=\"wp-element-caption\">Hope Finance loses $2M in recent exploit<\/figcaption><\/figure>\n\n\n\n<p>On February 21, the issue was reported by Web3 security company CertiK in response to a tweet from the <a href=\"https:\/\/www.google.com\/search?q=Hope+Finance+loses+%242M+in+recent+exploit&rlz=1C1SQJL_enNG889NG889&oq=Hope+Finance+loses+%242M+in+recent+exploit&aqs=chrome..69i57.455j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">Hope Finance account<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> warning customers of the fraud.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/CommunityAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#CommunityAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> \ud83d\udea8<a href=\"https:\/\/twitter.com\/Hope_fin?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@hope_fin<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> have announced the community has been scammed for ~$2m making this the largest <a href=\"https:\/\/twitter.com\/hashtag\/exitscam?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#exitscam<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> on Arbitrum in 2023.<br><br>$1.86m was transferred to <a href=\"https:\/\/twitter.com\/TornadoCash?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@TornadoCash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>.<br><br>Hope_fin have posted steps for user&#39;s to withdraw their staked LP<a href=\"https:\/\/t.co\/hJbFXiKujt\" target=\"_blank\">https:\/\/t.co\/hJbFXiKujt<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; CertiK Alert (@CertiKAlert) <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1627950776579420163?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 21, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>It is challenging to find specifics on the project. The platform announced its intentions for an algorithmic stablecoin dubbed Hope token (HOPE), which dynamically regulates its supply in relation to the price of Ether, on Twitter in January 2023.<\/p>\n\n\n\n<p>Entries on the account claim that immediately after the site became online on February 20, a Nigerian citizen allegedly carried out the fraud and transferred more than $1.86 million to<a href=\"https:\/\/coinscreed.com\/staging\/exploited-nomad-bridge-wallet-transfers-1-5m-to-tornado-cash.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Tornado Cash<\/a>.<\/p>\n\n\n\n<p>According to a member of the CertiK team, the fraudster altered the smart contract's specifications, which caused money to be taken out of the Hope Finance genesis protocol:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cIt appears that the scammer changed the TradingHelper contract which meant that when 0x4481 calls OpenTrade on the GenesisRewardPool the funds are transferred to the scammer.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>A Cognitos representative audited the Hope Finance smart contract, according to a tweet from February 13th. The audit report was evaluated by Cointelegraph, which identified two significant contract function weaknesses.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"578\" height=\"599\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-51.png\" alt=\"\" class=\"wp-image-45607\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-51.png 578w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-51-289x300.png 289w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-51-150x155.png 150w\" sizes=\"(max-width: 578px) 100vw, 578px\" \/><figcaption class=\"wp-element-caption\">Cognitos audit of Hope Finance\u2019s smart contract. Source: Cognitos<\/figcaption><\/figure>\n\n\n\n<p>This includes an improper modifier and reentrancy assaults as potential threats. Cognitos discovered that the smart contract code had passed the audit successfully despite indicating these vulnerabilities.<\/p>\n\n\n\n<p>After the fraud, Hope Finance informed users of a tool that would allow them to immediately remove staked liquidity from the system.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Steps to withdraw your staked LP from the this fucking scam protocol<br><br>1. Go on this link<a href=\"https:\/\/t.co\/HjuvQyxbUX\" target=\"_blank\">https:\/\/t.co\/HjuvQyxbUX<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>2. connect your wallet<br>3. click on emergency withdraw<br><br>Enter 0000000000000000000000000000000000000000000000000000000000000002 <a href=\"https:\/\/t.co\/5RxtgKXgoo\" target=\"_blank\">pic.twitter.com\/5RxtgKXgoo<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Hope Finance (\ud83d\udc99,\ud83e\udde1) (@Hope_fin) <a href=\"https:\/\/twitter.com\/Hope_fin\/status\/1627941848206516224?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 21, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Ugwoke Pascal Chukwuebuka, a citizen of Nigeria, is the fraudster, Hope Finance said on its Twitter account. The scammer's name and image have been made public. A few procedures for customers to withdraw their staked LP were also revealed by Hope Finance.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"817\" height=\"372\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52.png\" alt=\"\" class=\"wp-image-45608\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52.png 817w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52-300x137.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52-768x350.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52-150x68.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-52-750x341.png 750w\" sizes=\"(max-width: 817px) 100vw, 817px\" \/><\/figure>\n\n\n\n<p>Ugwoke Pascal Chukwuebuka, a citizen of Nigeria, is the fraudster, Hope Finance said on its Twitter account. The scammer's name and image have been made public. A few procedures for customers to withdraw their staked LP were also revealed by Hope Finance.<\/p>\n\n\n\n<p>The layer 2 roll-up network called Arbitrum on Ethereum allows for the exponential scalability of smart contracts. The two layer-2 protocols continue to handle an increasing number of transactions inside the Ethereum ecosystem alongside Optimist.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Arbitrum-based decentralized finance (DeFi) project Hope Finance has lost users&#8217; funds worth about $2 million as a result of a recent smart contract exploit. On February 21, the issue was reported by Web3 security company CertiK in response to a tweet from the Hope Finance account warning customers of the fraud. It is challenging to [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":45609,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[4579,11230,1496,13423],"class_list":["post-45604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-arbitrum","tag-defi-protocol","tag-hack","tag-hope-finance"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/image-53.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/45604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=45604"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/45604\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/45609"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=45604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=45604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=45604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}