{"id":46347,"date":"2023-03-08T04:00:06","date_gmt":"2023-03-08T08:00:06","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=46347"},"modified":"2023-03-08T04:00:09","modified_gmt":"2023-03-08T08:00:09","slug":"tender-fi-hacker-returns-stolen-funds-gets-6-bounty-reward","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/tender-fi-hacker-returns-stolen-funds-gets-6-bounty-reward\/","title":{"rendered":"Tender.fi hacker returns stolen funds, gets 6% bounty reward"},"content":{"rendered":"\n<p>Tender.fi <a href=\"https:\/\/coinscreed.com\/staging\/aave-closes-lending-markets-to-stop-attacks.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized lending platform <\/a>hacker has returned the exploit back to the platform in exchange for an Ether bounty of $97,000 which is approximately 6% of the initial stolen funds.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"953\" height=\"345\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20.png\" alt=\"Tender.fi hacker returns stolen funds, gets 6% bounty reward\" class=\"wp-image-46350\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20.png 953w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20-300x109.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20-768x278.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20-150x54.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20-750x272.png 750w\" sizes=\"(max-width: 953px) 100vw, 953px\" \/><figcaption class=\"wp-element-caption\">Tender.fi hacker returns stolen funds, gets 6% bounty reward<\/figcaption><\/figure>\n\n\n\n<p>On March 7, at 10:28 AM UTC, the exploit occurred. Shortly after, Tender.fi confirmed the event on Twitter, noting &#8220;an unusual quantity of borrows&#8221; and adding that it has suspended all borrowing.<\/p>\n\n\n\n<p>By depositing 1 <a href=\"https:\/\/coinscreed.com\/staging\/gmx-tokens-serve-as-proxy-for-ethereum-layer-2-solution.html\" target=\"_blank\" rel=\"noreferrer noopener\">GMX token<\/a>, which is worth about $71, the exploiter utilized a price oracle bug to borrow $1.59 million in assets from the protocol.<\/p>\n\n\n\n<p>&#8220;It appears that your oracle was improperly configured. Please get in touch with me to resolve this, the hacker stated in an on-chain post.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"557\" height=\"70\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-19.png\" alt=\"\" class=\"wp-image-46349\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-19.png 557w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-19-300x38.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-19-150x19.png 150w\" sizes=\"(max-width: 557px) 100vw, 557px\" \/><figcaption class=\"wp-element-caption\">Message sent to Tender.fi from the price oracle exploiter. Source: Arbiscan<\/figcaption><\/figure>\n\n\n\n<p>The <a href=\"https:\/\/www.google.com\/search?q=Tender.fi+hacker+returns+stolen+funds%2C+gets+6%25+bounty+reward&rlz=1C1SQJL_enNG889NG889&oq=Tender.fi+hacker+returns+stolen+funds%2C+gets+6%25+bounty+reward&aqs=chrome..69i57j33i21.979j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">&#8220;White Hat&#8221; exploiter had reached an agreement with the DeFi protocol<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> eight hours later, according to which the hacker would refund all debts less a 62.16 ETH &#8220;bounty,&#8221; which is currently worth about $97,000.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We have come to an agreement with the White Hat, an on chain transaction was sent with an attached message that contains the terms of this agreement.  <a href=\"https:\/\/t.co\/9a5IsgID0Q\" target=\"_blank\">https:\/\/t.co\/9a5IsgID0Q<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; GLend (@GemachLend) <a href=\"https:\/\/twitter.com\/GemachLend\/status\/1633170112718188549?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 7, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>One more hour later, Tender.fi tweeted a confirmation that the exploiter had finished repaying the loan. It stated, &#8220;Funds are officially SaFu, post mortem on the way.<\/p>\n\n\n\n<p>Cross-chain Nomad Bridge issued a call to exploiters who took part in a smart contract exploit that took $190 million in money out of the bridge in less than three hours last August.<\/p>\n\n\n\n<p>Only hours later, $32.6 million worth of payments had already been returned, indicating that some of the exploiters may have been white hat hackers looking to steal money for a later, safe return.<\/p>\n\n\n\n<p>A &#8220;Whitehat Award&#8221; in the form of an NFT was even made available later in the month by the <a href=\"https:\/\/coinscreed.com\/staging\/okhotshot-states-truths-about-nonfungible-tokens.html\" target=\"_blank\" rel=\"noreferrer noopener\">nonfungible token<\/a> company Metagame to anyone who could demonstrate that they had restored at least 90% of the money they had stolen from the protocol.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ Our friends at <a href=\"https:\/\/twitter.com\/Metagame?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@metagame<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> created an earned NFT as a thank you to whitehats who returned funds from the Nomad Bridge Hack. Head over <a href=\"https:\/\/t.co\/TWwuJwnRXj\" target=\"_blank\">https:\/\/t.co\/TWwuJwnRXj<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> to claim it! <a href=\"https:\/\/t.co\/V87rkGhBEE\" target=\"_blank\">pic.twitter.com\/V87rkGhBEE<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Nomad (\u292d\u26d3\ud83c\udfdb) (@nomadxyz_) <a href=\"https:\/\/twitter.com\/nomadxyz_\/status\/1562097376214388736?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">August 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Since then, monies have continued to be sent to the recovery account, with the most recent transaction for $7,868 in Covalent Query Tokens being logged on February 18 according to blockchain data from the Official Nomad Funds Recovery Address (CQT).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tender.fi decentralized lending platform hacker has returned the exploit back to the platform in exchange for an Ether bounty of $97,000 which is approximately 6% of the initial stolen funds. On March 7, at 10:28 AM UTC, the exploit occurred. Shortly after, Tender.fi confirmed the event on Twitter, noting &#8220;an unusual quantity of borrows&#8221; and [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":46350,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[1514,2118,4451,13704,13705],"class_list":["post-46347","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-bounty","tag-hacker","tag-lending-platform","tag-tender-fi","tag-white-hat-hacker"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/03\/image-20.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/46347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=46347"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/46347\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/46350"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=46347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=46347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=46347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}