{"id":99887,"date":"2024-11-18T03:35:53","date_gmt":"2024-11-18T07:35:53","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=99887"},"modified":"2024-11-18T03:35:59","modified_gmt":"2024-11-18T07:35:59","slug":"thala-labs-recovers-25-5m-from-vulnerability","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/thala-labs-recovers-25-5m-from-vulnerability\/","title":{"rendered":"Thala Labs Recovers $25.5M From v1 Farming Vulnerability Incident"},"content":{"rendered":"\n<p>Thala Labs, a decentralized finance firm, has successfully recovered $25.5 million in liquidity pool tokens from its v1 <a href=\"https:\/\/coinscreed.com\/staging\/yield-farming-strategies-maximizing-profits-in-defi.html\" data-type=\"post\" data-id=\"83115\">farming contracts<\/a>. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" width=\"290\" height=\"174\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/zz.jpg\" alt=\"Thala Labs Recovers $25.5M From v1 Farming Vulnerability Incident\" class=\"wp-image-99897\" style=\"width:672px;height:auto\"\/><figcaption class=\"wp-element-caption\">Thala Labs Recovers $25.5M From v1 Farming Vulnerability Incident<\/figcaption><\/figure>\n\n\n\n<p>Thala disclosed in a post on Nov. 16 that it had experienced a &#8220;security breach&#8221; on Nov. 15 due to an &#8220;isolated vulnerability&#8221; in its v1 farming contracts. This vulnerability enabled the hacker to extract liquidity tokens.<\/p>\n\n\n\n<p>Thala stated that it rapidly identified the perpetrator, halted all pertinent contracts, and froze $11.5 million in Thala-related assets.<\/p>\n\n\n\n<p>Thala stated, &#8220;We were able to promptly identify the exploiter with the assistance of law enforcement, Seal 911, Ogle, and others.&#8221;<\/p>\n\n\n\n<p>Thala reported that they were awarded a $300,000 bounty in exchange for the complete return of user assets. At the same time, crypto sleuth Ogle stated that the intruder returned the funds six hours after the incident. There was no disclosure of the attacker's identity.<\/p>\n\n\n\n<p>Thala emphasized that &#8220;affected users will not require any additional action, and their positions will be fully restored.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"792\" height=\"765\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-23.png\" alt=\"Source: Thala Labs\" class=\"wp-image-99890\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-23.png 792w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-23-300x290.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-23-768x742.png 768w\" sizes=\"(max-width: 792px) 100vw, 792px\" \/><figcaption class=\"wp-element-caption\"><em>Source:\u00a0<\/em><a href=\"https:\/\/x.com\/ThalaLabs\/status\/1857703541089120541\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>Thala Labs<\/em><span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>Thala's front end is now accessible. Subsequently, Thala will implement an &#8220;extensive review&#8221; and re-audit the protocol's codebase, rendering users incapable of staking and unstaking positions.<\/p>\n\n\n\n<p>According to Thala's CEO, Adam Cader, the assault was related to integrating Thala with Move, a network of modular blockchains developed by <a href=\"https:\/\/coinscreed.com\/staging\/movement-labs-joins-polygons-agglayer-to-unify-liquidity.html\" data-type=\"post\" data-id=\"85669\">Movement Labs<\/a>, as mentioned in a post on X on Nov. 16.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cIt\u2019s inevitable some security issues may happen in the future on Move, but why we\u2019re all building here is for these to occur at a far far less frequency and severity and trend to 0 over time as adjacent tooling gets stronger.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>The Thala platform is one of the most prominent DeFi platforms on the Aptos layer-1 blockchain.<\/p>\n\n\n\n<p>CoinGecko reports that the THL token has experienced a 35% decline to $0.51 since the incident.<\/p>\n\n\n\n<p>In the exploit, approximately $2.5 million in THL tokens were stolen, while an additional $9 million was obtained from Thala's Move Dollar (MOD) stablecoin.<\/p>\n\n\n\n<p>DefiLlama data indicates that the total value of Thala has decreased from $240 million on Nov. 15 to $195.6 million at the time of writing.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"891\" height=\"438\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-24.png\" alt=\"Thala protocol\u2019s change in TVL since April 2023. Source: DeFiLlama\" class=\"wp-image-99891\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-24.png 891w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-24-300x147.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-24-768x378.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/image-24-860x423.png 860w\" sizes=\"(max-width: 891px) 100vw, 891px\" \/><figcaption class=\"wp-element-caption\"><em>Thala protocol\u2019s change in TVL since April 2023. Source:\u00a0<\/em><a href=\"https:\/\/defillama.com\/protocol\/thala\" target=\"_blank\" rel=\"noopener\"><em>DeFiLlama<\/em><span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>According to CertiK, a blockchain security firm, exploits were responsible for nearly $130 million theft from victims in October.<\/p>\n\n\n\n<p>The lending protocol <a href=\"https:\/\/coinscreed.com\/staging\/radiant-capital-halts-lending-after-exploit.html\" data-type=\"post\" data-id=\"96719\">Radiant Capital <\/a>experienced the most significant incident in October, resulting in a loss of approximately $54 million.<\/p>\n\n\n\n<p>According to Hacken, a cybersecurity corporation, approximately $460 million was stolen from hackers in 28 incidents during the preceding three months of Q3 2024.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thala Labs, a decentralized finance firm, has successfully recovered $25.5 million in liquidity pool tokens from its v1 farming contracts. Thala disclosed in a post on Nov. 16 that it had experienced a &#8220;security breach&#8221; on Nov. 15 due to an &#8220;isolated vulnerability&#8221; in its v1 farming contracts. This vulnerability enabled the hacker to extract [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":99897,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[197,937,22862,22863],"class_list":["post-99887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-defi","tag-hackers","tag-thala-labs","tag-v1-farming"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/zz.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/99887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=99887"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/99887\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/99897"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=99887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=99887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=99887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}