{"id":65438,"date":"2023-11-24T08:27:20","date_gmt":"2023-11-24T12:27:20","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=65438"},"modified":"2023-11-24T08:27:21","modified_gmt":"2023-11-24T12:27:21","slug":"kyberswap-offers-10-bounty-to-hackers-for-return-of-46m-loot","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/kyberswap-offers-10-bounty-to-hackers-for-return-of-46m-loot\/","title":{"rendered":"KyberSwap Offers 10% Bounty to Hackers for Return of $46M Loot"},"content":{"rendered":"\n<p>Following the November 22 exploit of $46 Million from the <a href=\"https:\/\/coinscreed.com\/staging\/how-decentralized-exchanges-are-upping-their-security-game.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized exchange<\/a> KyberSwap,  a 10% bounty reward worth $4.6M has been offered to the hackers in return for the loot. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1004\" height=\"560\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png\" alt=\"KyberSwap Offers 10% Bounty to Hackers for Return of $46M Loot\" class=\"wp-image-65446\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png 1004w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-300x167.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-768x428.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-18x10.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-750x418.png 750w\" sizes=\"(max-width: 1004px) 100vw, 1004px\" \/><figcaption class=\"wp-element-caption\">KyberSwap Offers 10% Bounty to Hackers for Return of $46M Loot<\/figcaption><\/figure>\n\n\n\n<p>KyberSwap informed users on November 23 that KyberSwap Elastic, its liquidity solution, had been compromised and recommended that they withdraw their funds. <\/p>\n\n\n\n<p>Subsequently, on November 22, the intruder acquired approximately $4 million in Arbitrum (ARB), $7 million in wrapped Lido-staked Ether (wstETH), and $20 million in <a href=\"https:\/\/coinscreed.com\/staging\/coinbase-launches-wrapped-staked-eth-on-ethereum-network.html\" target=\"_blank\" rel=\"noreferrer noopener\">Wrapped Ether<\/a> (wETH). Arbitrum, Optimism, Ethereum, Polygon, and Base were among the chains through which the hacker subsequently siphoned the wealth.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"222\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96-750x222.png\" alt=\"\" class=\"wp-image-65441\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96-750x222.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96-300x89.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96-768x227.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96-18x5.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-96.png 1007w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>KyberSwap\u00a0hacker shared his openness to negotiate a compromise. Source:\u00a0etherscan.io<\/em><\/figcaption><\/figure>\n\n\n\n<p>The hacker wrote an on-chain message to KbyerSwap Developers, Employees, DAO members, and LPs, &#8220;Negotiations will commence in a few hours, once I have fully rested,&#8221; after concealing the stolen funds.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"170\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97-750x170.png\" alt=\"\" class=\"wp-image-65442\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97-750x170.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97-300x68.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97-768x174.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97-18x4.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-97.png 1020w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">KyberSwap team responded to the hacker and offered a 10% bounty. Source:\u00a0etherscan.io<\/figcaption><\/figure>\n\n\n\n<p>KyberSwap replied to the intruder after a day of silence in which he was expecting the return of 90% of the stolen funds. The group recognized the hacker's expertise and extended the following offer:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cOn the table is a bounty equivalent to 10% of users' funds taken from them by your hack, for the safe return of all of the users' funds. But we both know how this works, so lets cut to the chase so you and these users can all get on with life.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>&#8220;You stay on the run,&#8221; according to KyberSwap, if the hacker does not repay or respond to the transaction by November 25 at 6am UTC. By email, the group is receptive to additional dialogue with the perpetrator.<\/p>\n\n\n\n<p>According to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Decentralized_finance#:~:text=Decentralized%20finance%20(often%20stylized%20as,on%20a%20blockchain%2C%20mainly%20Ethereum.\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized finance<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> (DeFi) expert's analysis of the recent KyberSwap breach, the perpetrator drained funds by exploiting an &#8220;infinite money glitch.&#8221;<\/p>\n\n\n\n<p>Doug Colkitt, the originator of the Ambient exchange, explained that the KyberSwap attacker executed the attack using a &#8220;complex and meticulously engineered smart contract exploit.&#8221;<\/p>\n\n\n\n<p>Subsequently, the assailant replicated this vulnerability against additional Kyberswap pools spanning multiple networks, ultimately escaping with crypto assets worth $46 million.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following the November 22 exploit of $46 Million from the decentralized exchange KyberSwap, a 10% bounty reward worth $4.6M has been offered to the hackers in return for the loot. KyberSwap informed users on November 23 that KyberSwap Elastic, its liquidity solution, had been compromised and recommended that they withdraw their funds. Subsequently, on November [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":65446,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[32],"tags":[6115,1514,7907],"class_list":["post-65438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-exchange-news","tag-hackers-2","tag-bounty","tag-kyberswap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/65438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=65438"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/65438\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/65446"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=65438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=65438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=65438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}