{"id":60256,"date":"2023-09-27T07:17:04","date_gmt":"2023-09-27T11:17:04","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=60256"},"modified":"2023-09-27T07:17:07","modified_gmt":"2023-09-27T11:17:07","slug":"mixin-network-offers-20m-bug-bounty-following-200m-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/mixin-network-offers-20m-bug-bounty-following-200m-hack\/","title":{"rendered":"Mixin Network Offers $20M Bug Bounty Following $200M Hack"},"content":{"rendered":"\n<p>Following the $200 million exploit on September 23, <a href=\"https:\/\/coinscreed.com\/staging\/mixin-network-hack-200m-drained-from-mainnet-assets.html\">Mixin Network<\/a> has sent a message to the hacker responsible, offering a bug bounty of $20 million to return the remaining funds.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"624\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-1024x624.png\" alt=\"Mixin Network Offers $20M Bug Bounty Following $200M Hack\" class=\"wp-image-60266\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-1024x624.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-300x183.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-768x468.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-18x12.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81-750x457.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81.png 1045w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Mixin Network Offers $20M Bug Bounty Following $200M Hack<\/figcaption><\/figure>\n\n\n\n<p>As most of the stolen funds were user assets, Mixin Network encrypts the message accompanying the exploiter transaction, requesting the return of the funds.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cMost of our platform assets were users, and we hope you can refund them. You can keep $20M of the assets as a BUG Bounty Reward for the BUG.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Mixin Network confirmed the exploit on September 25, stating that the exploiters breached a third-party<a href=\"https:\/\/cloud.google.com\/learn\/what-is-a-cloud-service-provider#:~:text=started%20for%20free-,Cloud%20service%20provider%20definition,%2C%20platform%2C%20and%20application%20services.\" target=\"_blank\" rel=\"noreferrer noopener\"> cloud service provider<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, resulting in the seizure of nearly $200 million worth of assets from the platform.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">[Announcement] In the early morning of September 23, 2023 Hong Kong time, the database of Mixin Network&#39;s cloud service provider was attacked by hackers, resulting in the loss of some assets on the mainnet. We have contacted Google and blockchain security company <a href=\"https:\/\/twitter.com\/SlowMist_Team?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@SlowMist_Team<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>\u2026<\/p>&mdash; Mixin Kernel (@MixinKernel) <a href=\"https:\/\/twitter.com\/MixinKernel\/status\/1706139175018529139?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 25, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Feng Xiaodong, the founder of Mixin, stated that the company would reimburse affected users up to a &#8220;maximum of 50 percent,&#8221; with the remaining amount returned in bond tokens that the company would repurchase with its earnings.<\/p>\n\n\n\n<p>An on-chain analytic platform revealed a history of the hacker's interactions with Mixin Network before Mixin disclosed the complete circumstances surrounding the exploit. In 2022, the address 0x1795 associated with a fraudster, received 5 Ether from Mixin.<\/p>\n\n\n\n<p><a href=\"https:\/\/coinscreed.com\/staging\/circle-launches-cross-chain-transfer-protocol-for-usdc.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cross-chain protocols<\/a> in the decentralized finance (DeFi) space have been the target of some of the most prominent exploits in crypto history.<\/p>\n\n\n\n<p>However, how the exploiters stole $200 million worth of assets via a data compromise is still being determined. One report indicates that over half of all DeFi exploits involve cross-chain protocols, resulting in over $2.5 billion in losses.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"412\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80-750x412.png\" alt=\"\" class=\"wp-image-60265\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80-750x412.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80-300x165.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80-768x422.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80-18x10.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-80.png 942w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Bridge exploits account for more than 50% of DeFi losses. Source: Token Terminal<\/figcaption><\/figure>\n\n\n\n<p>Cross-chain protocols facilitate interoperability between chains and enable users to transfer assets from one blockchain to another. Consequently, these cross-chain protocols frequently hold many assets from multiple chains, rendering them susceptible to such attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following the $200 million exploit on September 23, Mixin Network has sent a message to the hacker responsible, offering a bug bounty of $20 million to return the remaining funds. As most of the stolen funds were user assets, Mixin Network encrypts the message accompanying the exploiter transaction, requesting the return of the funds. \u201cMost [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":60266,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[6115,8812,16562],"class_list":["post-60256","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hackers-2","tag-bug-bounty","tag-mixin-network-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/image-81.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=60256"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60256\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/60266"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=60256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=60256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=60256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}