{"id":72538,"date":"2024-02-29T07:46:44","date_gmt":"2024-02-29T11:46:44","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=72538"},"modified":"2024-02-29T07:46:46","modified_gmt":"2024-02-29T11:46:46","slug":"seneca-stablecoin-hacker-returns-5m-following-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/seneca-stablecoin-hacker-returns-5m-following-exploit\/","title":{"rendered":"Seneca Stablecoin Hacker Returns $5M Following Exploit"},"content":{"rendered":"\n<p>Following a $6.4 million <a href=\"https:\/\/coinscreed.com\/staging\/backpack-exchange-banxa-partner-for-off-ramp-digital-assets-solution.html\">digital assets<\/a> exploit from the Seneca stablecoin platform, the hacker has returned over $5 million after the project pledged a 20% bounty to the hacker.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"521\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105-1024x521.png\" alt=\"Seneca Stablecoin Hacker Returns $5M Following Exploit\" class=\"wp-image-72550\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105-1024x521.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105-300x153.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105-768x391.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105-750x382.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105.png 1045w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Seneca Stablecoin Hacker Returns $5M Following Exploit<\/figcaption><\/figure>\n\n\n\n<p>Multiple blockchain security firms identified the vulnerability in the stablecoin protocol on February 28. Enterprises such as CertiK issued advisories to users regarding the vulnerability, imploring them to revoke authorizations from a specific address on the Ethereum and <a href=\"https:\/\/coinscreed.com\/staging\/layer-2-networks-optimism-arbitrum-witness-high-combined-transaction-volume.html\">Arbitrum networks<\/a>. <\/p>\n\n\n\n<p>Initial losses were estimated at $3 million; however, it was discovered that more than 1,900 Ether, valued at approximately $6.4 million, had been stolen from the exploit.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"549\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-103-750x549.png\" alt=\"\" class=\"wp-image-72545\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-103-750x549.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-103-300x220.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-103-768x562.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-103.png 943w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Seneca attacker\u2019s wallet showing about $3 million in Ether. Source: CertiK<\/figcaption><\/figure>\n\n\n\n<p>According to security analysts at CertiK, the exploit occurred because of a critical &#8220;call&#8221; <a href=\"https:\/\/coinscreed.com\/staging\/thirdweb-discloses-common-security-flaw-in-smart-contracts.html\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability in the smart contract<\/a> of the protocol. The attacker could have exploited this vulnerability to initiate external communications to any given address.<\/p>\n\n\n\n<p>Furthermore, the contracts for the project lacked a procedure that would have permitted the team to &#8220;pause&#8221; it. As a consequence, users are required to revoke permissions.<\/p>\n\n\n\n<p>Seneca stated that it is investigating with the assistance of specialists. A bounty of $1.2 million was also offered in exchange for recovering the misappropriated funds. <\/p>\n\n\n\n<p>On February 29, Seneca requested in an on-chain message that the intruder transfer 80% of the stolen funds to an Ethereum address while permissibly retaining 20%.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"548\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-104-750x548.png\" alt=\"\" class=\"wp-image-72547\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-104-750x548.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-104-300x219.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-104-768x561.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-104.png 939w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Seneca\u2019s on-chain message to the exploiter. Source: Seneca<\/figcaption><\/figure>\n\n\n\n<p>Seneca stated in the message that it is conducting joint efforts with law enforcement and security providers to trace the funds. It advised the infiltrator to reimburse the funds to evade potential legal ramifications. It stated, &#8220;Timely action is critical; therefore, we respectfully request that you return the funds without delay to prevent any additional legal proceedings.&#8221;<\/p>\n\n\n\n<p>Hours after Seneca sent the message, the intruder returned to the wallet address Seneca specified approximately 1,537 ETH, worth roughly $5.3 million. <\/p>\n\n\n\n<p>The hacker retained 300 ETH, valued at about $1 million, and agreed to the 20% bounty that <a href=\"https:\/\/senecaprotocol.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Seneca protocol <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>offered. Subsequently, the exploiter split the ETH between two distinct addresses.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following a $6.4 million digital assets exploit from the Seneca stablecoin platform, the hacker has returned over $5 million after the project pledged a 20% bounty to the hacker. Multiple blockchain security firms identified the vulnerability in the stablecoin protocol on February 28. Enterprises such as CertiK issued advisories to users regarding the vulnerability, imploring [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":72550,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[1514,10417,2118,18607],"class_list":["post-72538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-bounty","tag-expliot-2","tag-hacker","tag-seneca-stablecoin"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-105.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/72538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=72538"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/72538\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/72550"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=72538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=72538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=72538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}