{"id":94092,"date":"2024-09-21T07:53:53","date_gmt":"2024-09-21T11:53:53","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=94092"},"modified":"2024-09-21T07:55:01","modified_gmt":"2024-09-21T11:55:01","slug":"shezmu-recovers-hacked-funds-via-negotiation","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/shezmu-recovers-hacked-funds-via-negotiation\/","title":{"rendered":"Crypto Lender Shezmu Recovers Hacked Funds via Negotiation"},"content":{"rendered":"\n<p>Shezmu negotiated with a hacker to retrieve over $5 million in <a href=\"https:\/\/coinscreed.com\/staging\/crypto-hackers-steal-over-1-2-billion-in-2024.html\" data-type=\"post\" data-id=\"91704\" target=\"_blank\" rel=\"noreferrer noopener\">stolen crypto<\/a> and increase the bounty.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation-1024x512.webp\" alt=\"Shezmu Crypto Lender Recovers Hacked Funds via Negotiation\" class=\"wp-image-94103\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation-1024x512.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation-300x150.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation-768x384.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation-860x430.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Utilizing the Yield Protocol, Shezmu recovered nearly $5 million in stolen funds within hours after successfully negotiating with the hacker.<\/p>\n\n\n\n<p>On September 21, Chaofan Shou, co-founder of blockchain analytics firm Fuzzland, alerted the public to a compromised storage vault belonging to Shezmu. <\/p>\n\n\n\n<p>Although it was unclear whether the event was a rug pull or a legitimate hack, Shou confirmed that approximately $4.9 million in cryptocurrencies had been stolen.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">.<a href=\"https:\/\/twitter.com\/ShezmuTech?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@ShezmuTech<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> has been hacked \/ rugged. ~$4.9M worth of <a href=\"https:\/\/twitter.com\/search?q=%24ShezUSD&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$ShezUSD<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> stolen. <br><br>One of their vaults used collateral that can be minted by anyone. With the free collateral, the attacker can borrow an arbitrary amount of <a href=\"https:\/\/twitter.com\/search?q=%24ShezUSD&src=ctag&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">$ShezUSD<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>. <a href=\"https:\/\/t.co\/eR0bH5rTV2\" target=\"_blank\">pic.twitter.com\/eR0bH5rTV2<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Chaofan Shou (svm\/acc) (@Fried_rice) <a href=\"https:\/\/twitter.com\/Fried_rice\/status\/1837228053862437244?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 20, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Shezmu later verified that one of its ShezmuUSD (ShezUSD) stablecoin vaults had been exploited and promptly urged the hacker to return the funds in exchange for a bounty, promising no legal consequences. <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Dear White Hat,<br><br>The Shezmu team is offering a 10% bounty of the exploited funds, provided that the remaining funds are returned within the next 24 hours. If the funds are not refunded within this time frame, we will escalate the matter through legal channels.\u2026<\/p>&mdash; Shezmu (@ShezmuTech) <a href=\"https:\/\/twitter.com\/ShezmuTech\/status\/1837257349125525786?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 20, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The protocol issued an <a href=\"https:\/\/etherscan.io\/idm?addresses=0x2604c6b2e0cf38e5ba66b2a5dd93461740d1dbee,0xfaf2484adf637837001404ff95716de1fc3b4331&type=1\" target=\"_blank\" rel=\"noreferrer noopener\">on-chain message <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>requesting that 90% of the stolen funds be returned within 24 hours, warning that law enforcement would be involved if the hacker did not comply.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hacker Requests 20% White Hat Bounty<\/h2>\n\n\n\n<p>The hacker responded by demanding a 20% bounty rather than the 10% originally offered by Shezmu. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"473\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010-1024x473.webp\" alt=\"\" class=\"wp-image-94097\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010-1024x473.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010-300x139.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010-768x355.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010-860x397.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/019213fe-5253-7840-a0db-877536471010.webp 1255w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Shezmu\u2019s team negotiates the return of stolen funds with the hacker. Source: Etherscan<\/figcaption><\/figure>\n\n\n\n<p>The protocol agreed to the terms, and within hours, the stolen Dai tokens began to be returned. <\/p>\n\n\n\n<p>The hacker first sent back 282.18 Ether, followed by another refund of 137 Wrapped Ether (WETH).<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Update: An additional 137 WETH was recovered from the shezUSD white hat and returned to the Shezmu Treasury!<a href=\"https:\/\/t.co\/K2AnPkme9F\" target=\"_blank\">https:\/\/t.co\/K2AnPkme9F<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>As we continue to recover the remaining funds, please do not interact with Oasis until further updates. Thank you for your continued support<\/p>&mdash; Shezmu (@ShezmuTech) <a href=\"https:\/\/twitter.com\/ShezmuTech\/status\/1837337759117123778?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 21, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>However, not all the stolen funds had been recovered at the time of writing, and Shezmu advised investors to avoid interacting with the protocol\u2019s Oasis vault until further notice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WazirX Struggles to Recover $235 Million Stolen Funds<\/h2>\n\n\n\n<p>In contrast, <a href=\"https:\/\/coinscreed.com\/staging\/wazirx-seeks-30-day-pause-for-restructuring.html\" target=\"_blank\" data-type=\"post\" data-id=\"91544\" rel=\"noreferrer noopener\">Indian cryptocurrency exchange WazirX<\/a> has not recovered its $230 million in stolen funds, 60 days after being hacked. <\/p>\n\n\n\n<p>WazirX has not acknowledged the hack, instead blaming its custodian, Liminal, for the loss of the funds.<\/p>\n\n\n\n<p>Liminal refuted these claims, announcing on September 9 that an independent audit by multinational firm Grant Thornton found no evidence that the cyberattack originated from Liminal\u2019s web applications or its infrastructure.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">It&#39;s been over a month since WazirX, a major crypto exchange operating in India, claimed that a cyber attack on their platform led to the theft of $230 million (~ Rs 2000 cr) worth of funds.<br><br>We have attempted to be in regular touch with WazirX since the day of the incident but\u2026<\/p>&mdash; CoinSwitch: India&#39;s Simplest Crypto App \ud83d\ude80 (@CoinSwitch) <a href=\"https:\/\/twitter.com\/CoinSwitch\/status\/1828729248133074993?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">August 28, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>WazirX has also faced legal threats from its customers, including rival Indian crypto exchange CoinSwitch, which initiated legal action to recover approximately 2% of its funds, amounting to $6.2 million.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shezmu negotiated with a hacker to retrieve over $5 million in stolen crypto and increase the bounty. Utilizing the Yield Protocol, Shezmu recovered nearly $5 million in stolen funds within hours after successfully negotiating with the hacker. On September 21, Chaofan Shou, co-founder of blockchain analytics firm Fuzzland, alerted the public to a compromised storage [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":94103,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476,21],"tags":[7713,710,128,937,12002],"class_list":["post-94092","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","category-news","tag-altcoin","tag-business","tag-ethereum","tag-hackers","tag-hacks"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/Shezmu-Crypto-Lender-Recovers-Hacked-Funds-via-Negotiation.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=94092"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94092\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/94103"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=94092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=94092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=94092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}