{"id":47463,"date":"2023-04-04T04:12:08","date_gmt":"2023-04-04T08:12:08","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=47463"},"modified":"2023-04-04T04:13:30","modified_gmt":"2023-04-04T08:13:30","slug":"allbridge-hacker-returns-most-of-stolen-crypto-loot","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/allbridge-hacker-returns-most-of-stolen-crypto-loot\/","title":{"rendered":"Allbridge Hacker returns Most of Stolen Crypto Loot"},"content":{"rendered":"\n<p>A significant part of the $573,500 that was stolen from the <a href=\"https:\/\/coinscreed.com\/staging\/how-to-maximize-profit-with-low-risk-using-multichain.html\" target=\"_blank\" rel=\"noreferrer noopener\">multichain token bridge <\/a>Allbridge has been returned after the exploiter accepted the project's offer of a white hat bounty and no legal reprisal.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-1.png\" alt=\"Allbridge Hacker returns Most of Stolen Crypto Loot\" class=\"wp-image-47467\" width=\"610\" height=\"365\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-1.png 412w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-1-300x180.png 300w\" sizes=\"(max-width: 610px) 100vw, 610px\" \/><figcaption class=\"wp-element-caption\">Allbridge Hacker returns Most of Stolen Crypto Loot<\/figcaption><\/figure>\n\n\n\n<p>On April 3, Allbridge tweeted that it had received a message from a user who returned 1,500 BNB, worth around $465,000.<\/p>\n\n\n\n<p>&#8220;The remaining funds will be considered a white hat bounty to this person,&#8221; Allbridge said.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Update on the exploit<br><br>1\/ Our team was contacted by the owner of <a href=\"https:\/\/t.co\/EW1uxXBQpD\" target=\"_blank\">https:\/\/t.co\/EW1uxXBQpD<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>. <br><br>1500 BNB was returned to our team. The remaining funds will be considered a white hat bounty to this person.<\/p>&mdash; Allbridge (@Allbridge_io) <a href=\"https:\/\/twitter.com\/Allbridge_io\/status\/1642923759127461890?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 3, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>It was explained that all &#8220;received BNB&#8221; was converted to Binance USD, a stablecoin, and utilized as compensation.<\/p>\n\n\n\n<p>The blockchain security startup Peckshield was the first to identify the April 1 hack, tweeting to Allbridge that the <a href=\"https:\/\/coinscreed.com\/staging\/bnb-chain-defi-ecosystem-has-nearly-fully-recovered.html\" target=\"_blank\" rel=\"noreferrer noopener\">BNB Chain pools <\/a>swap price was being manipulated by a liquidity provider and swapper.<\/p>\n\n\n\n<p>Following the exploit, Allbridge offered the attacker a reward and the opportunity to avoid legal repercussions.<\/p>\n\n\n\n<p>Allbridge has not yet disclosed how much was taken, however, blockchain security firm CertiK estimates the amount to be close to $550,000, and PeckSheild estimates the exploit netted $282,889 in Bitcoin BUSD and $290,000 in Tether USDT, for a total of approximately $573,000.<\/p>\n\n\n\n<p>Allbridge also disclosed that a second address utilized the same vulnerability and provided a link to a wallet containing 0.97 BNB, presently worth approximately $300.<\/p>\n\n\n\n<p>&#8220;We ask the second exploiter to reach out and discuss the return,&#8221; Allbridge said.<\/p>\n\n\n\n<p>Following the initial intrusion, Allbridge made it known that they were hot on the trail of the stolen funds and were collaborating with a vast array of organizations to recover the treasure.<\/p>\n\n\n\n<p>BNB Chain was among those who responded to the call to arms, tweeting on April 2 that it had identified at least one of the perpetrators through on-chain analysis.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">BNB Chain has identified the Allbridge attacker following on-chain analysis. We are actively supporting the Allbridge team on the fund recovery. The Allbridge team has offered the hacker a bounty.<br><br>We&#39;d like to recognize the effort of AvengerDAO in this recovery effort.<\/p>&mdash; BNB Chain (@BNBCHAIN) <a href=\"https:\/\/twitter.com\/BNBCHAIN\/status\/1642598129139695619?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 2, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>According to BNB Chain, it is &#8220;actively aiding the Allbridge team on the <a href=\"https:\/\/www.google.com\/search?q=Allbridge+Hacker+returns+Most+of+Stolen+Crypto+Loot&rlz=1C1SQJL_enNG889NG889&oq=Allbridge+Hacker+returns+Most+of+Stolen+Crypto+Loot&aqs=chrome..69i57.535j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">fund recovery<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>&#8221; and praised AvengerDAO for its recovery efforts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A significant part of the $573,500 that was stolen from the multichain token bridge Allbridge has been returned after the exploiter accepted the project&#8217;s offer of a white hat bounty and no legal reprisal. On April 3, Allbridge tweeted that it had received a message from a user who returned 1,500 BNB, worth around $465,000. [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":47467,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[13996,132,2118],"class_list":["post-47463","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-allbridge","tag-crypto","tag-hacker"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=47463"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47463\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/47467"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=47463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=47463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=47463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}