{"id":72292,"date":"2024-02-26T08:03:18","date_gmt":"2024-02-26T12:03:18","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=72292"},"modified":"2024-02-26T08:03:22","modified_gmt":"2024-02-26T12:03:22","slug":"kyberswap-hacker-transfers-2-5m-in-stolen-funds-to-ethereum-blockchain","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/kyberswap-hacker-transfers-2-5m-in-stolen-funds-to-ethereum-blockchain\/","title":{"rendered":"KyberSwap Hacker Transfers $2.5M in Stolen Funds to Ethereum Blockchain"},"content":{"rendered":"\n<p>The hacker responsible for the assault on the <a href=\"https:\/\/coinscreed.com\/staging\/kyberswap-hacked-for-46m-users-advised-to-withdraw-funds.html\" target=\"_blank\" rel=\"noreferrer noopener\">KyberSwap decentralized exchange<\/a> (DEX), transferred $2.5 million worth of stolen digital assets from Arbitrum to Ethereum blockchain. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1004\" height=\"560\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png\" alt=\"KyberSwap Hacker Transfers $2.5M in Stolen Funds to Ethereum Blockchain\" class=\"wp-image-65446\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png 1004w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-300x167.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-768x428.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-18x10.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98-750x418.png 750w\" sizes=\"(max-width: 1004px) 100vw, 1004px\" \/><figcaption class=\"wp-element-caption\">KyberSwap Hacker Transfers $2.5M in Stolen Funds to Ethereum Blockchain<\/figcaption><\/figure>\n\n\n\n<p>Blockchain analytics firm PeckShield disclosed transactions originating from the wallet address of the KyberSwap assailant on February 26. According to blockchain data, the intruder transferred 798.8 Ether, valued at nearly $2.5 million, from the Arbitrum network to the <a href=\"https:\/\/coinscreed.com\/staging\/ethereum-network-fee-slash-plan-faces-new-obstacle.html\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum network<\/a>.<\/p>\n\n\n\n<p>In addition to transferring $2.5 million, the intruder moved nearly one million of stablecoins. The exploiter, with one wallet, transferred $826,500 in DAI (DAI) stablecoin to another wallet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"952\" height=\"630\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-97.png\" alt=\"\" class=\"wp-image-72296\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-97.png 952w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-97-300x199.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-97-768x508.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-97-750x496.png 750w\" sizes=\"(max-width: 952px) 100vw, 952px\" \/><figcaption class=\"wp-element-caption\">Fund movements from the KyberSwap attacker\u2019s wallet. Source: PeckShield<\/figcaption><\/figure>\n\n\n\n<p>KyberSwap constituted one of the most extensive breaches of 2023. The DEX notified its users on November 23 that a &#8220;security incident&#8221; had occurred and recommended that they withdraw their funds.<\/p>\n\n\n\n<p>An initial assessment revealed that the exploit resulted in the theft of approximately $46 million of digital assets. Nevertheless, upon further investigation, it came to light that the overall loss had nearly augmented to $49 million.<\/p>\n\n\n\n<p>That day, the hacker informed the KyberSwap team via an on-chain message that negotiations would commence once he had &#8220;completely rested.&#8221; The KyberSwap team responded by presenting the assailant with a bounty of $4.6 million, contingent upon the restitution of 90% of the illicitly acquired funds.<\/p>\n\n\n\n<p>Nevertheless, the hacker's growing discontent with KyberSwap's methodology precipitated a deterioration in the bounty negotiations. The hacker threatened the KyberSwap team with further postponement of negotiations on November 29 in an on-chain message wherein he or she warned of &#8220;unfriendliness&#8221; and legal action if the team persisted in their threats.<\/p>\n\n\n\n<p>Unexpectedly, the intruder demanded complete authority over the KyberSwap organization and its assets. Additionally, the hacker requested provisional complete control and ownership of <a href=\"https:\/\/docs.kyberswap.com\/governance\/kyberdao\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">KyberDAO<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the governance framework for Kyber, and all associated documents. Before the &#8220;treaty fell through,&#8221; the hacker granted the organization until December 10 to decide.<\/p>\n\n\n\n<p>Following the hacker's requests, the KyberSwap team initiated treasury grants supporting the compromised individuals. The team declared on December 2 that it would provide a grant to individuals who suffered unrecovered financial losses due to the exploit. A month after the exploit, the organization reduced its personnel by half as a significant consequence of the breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The hacker responsible for the assault on the KyberSwap decentralized exchange (DEX), transferred $2.5 million worth of stolen digital assets from Arbitrum to Ethereum blockchain. Blockchain analytics firm PeckShield disclosed transactions originating from the wallet address of the KyberSwap assailant on February 26. According to blockchain data, the intruder transferred 798.8 Ether, valued at nearly [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":65446,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[1610,2118,7907],"class_list":["post-72292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-ethereum-blockchain","tag-hacker","tag-kyberswap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-98.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/72292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=72292"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/72292\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/65446"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=72292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=72292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=72292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}