{"id":67700,"date":"2023-12-27T02:49:23","date_gmt":"2023-12-27T06:49:23","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=67700"},"modified":"2023-12-27T02:49:28","modified_gmt":"2023-12-27T06:49:28","slug":"thunder-terminal-blocks-240k-hacker-ransom-demand-following-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/thunder-terminal-blocks-240k-hacker-ransom-demand-following-exploit\/","title":{"rendered":"Thunder Terminal Blocks $240K Hacker Ransom Demand Following Exploit"},"content":{"rendered":"\n<p>Thunder Terminal, an on-chain <a href=\"https:\/\/coinscreed.com\/staging\/how-to-design-a-trading-app-and-platform-7-things.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">trading platform,<\/a> was hit by an exploit that compromised 114 user wallets and stole $240,000 worth of crypto. The hacker demanded a ransom for the user data, but Thunder Terminal denied the claim and offered refunds and compensation to the affected users.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-1024x576.jpg\" alt=\"\" class=\"wp-image-67702\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-18x10.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><a href=\"https:\/\/eversify.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Thunder Terminal,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>\u00a0a platform that allows users to trade crypto assets on various blockchains, faced a security breach on December 27 that resulted in the loss of<strong> $240,000 worth of crypto.<\/strong> The hacker exploited a vulnerability in the platform\u2019s MongoDB database and accessed a connection URL that enabled them to withdraw <strong>86.5 Ether <\/strong>and <strong>439 Solana<\/strong> from <strong>114 user wallets<\/strong> in just nine minutes.<\/p>\n\n\n\n<p>The trading platform issued an incident report detailing the attack and its aftermath. The platform stated that the exploit was linked to a previous MongoDB attack that occurred eight days before the incident and that it had taken immediate actions to stop the hacker and secure the platform.<\/p>\n\n\n\n<p>Thunder Terminal assured its users that no <a href=\"https:\/\/coinscreed.com\/staging\/safeguarding-your-bitcoin-keeping-your-wallet-keys-private.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">private keys<\/a> or wallets were compromised in the attack and that the hacker only managed to steal a small portion of the platform\u2019s funds. The platform also announced that it would fully refund all the affected users, as well as offer them 0% fees and $100,000 in platform credits as a gesture of apology.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/twitter.com\/ThunderTerminal\/status\/1739813779976982946\n<\/div><\/figure>\n\n\n\n<p>Thunder Terminal emphasized its commitment to security and user protection and said it would take extra measures to prevent similar incidents. The platform also thanked its community for their support and understanding.<\/p>\n\n\n\n<p>However, the hacker disputed Thunder Terminal\u2019s claims and demanded a ransom for the user data that they allegedly possessed. In a message posted on Etherscan, the hacker accused Thunder Terminal of lying and asked for <strong>50 ETH, or $110,000,<\/strong> to delete the user data. The hacker also claimed they had access to all the user data, including private keys, passwords, and personal information.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"464\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-1024x464.jpg\" alt=\"Thunder Terminal Fends Off Hacker\u2019s Ransom Demand After $240K Exploit\" class=\"wp-image-67703\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-1024x464.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-300x136.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-768x348.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-18x8.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-750x340.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message-1140x517.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/thunder-terminal-hacker-message.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Thunder Terminal did not directly respond to the hacker\u2019s demand but reiterated that it could not access users\u2019 private keys, implying that the hacker\u2019s claim was false. The platform also expressed willingness to negotiate with the hacker to recover the stolen funds, showing its dedication to peacefully resolving the situation.<\/p>\n\n\n\n<p>According to Etherscan data, the hacker has already moved some of the stolen funds to another destination. The hacker sent 86.3 ETH to the Railgun protocol, a service that provides anonymity and privacy for transactions on the blockchain. The hacker may have used this service to hide their identity and evade detection.<\/p>\n\n\n\n<p>The fate of the remaining funds and the user data is still unknown, as the hacker has not made any further communication. Thunder Terminal is working hard to enhance its security and restore its reputation, while the crypto community is watching closely for any new developments.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thunder Terminal, an on-chain trading platform, was hit by an exploit that compromised 114 user wallets and stole $240,000 worth of crypto. The hacker demanded a ransom for the user data, but Thunder Terminal denied the claim and offered refunds and compensation to the affected users. Thunder Terminal, \u00a0a platform that allows users to trade [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":67702,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[32],"tags":[16148,17696],"class_list":["post-67700","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-exchange-news","tag-crypto-hack-2","tag-thunder-terminal"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/1703655522-hacker.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/67700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=67700"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/67700\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/67702"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=67700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=67700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=67700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}