Blockchain bridge Wormhole confirms that exploiter stole $320 million worth of crypto assets | TechCrunch (2024)

Wormhole, a popular cryptocurrency platform that offers bridges between multiple blockchains, announced on Twitter that it noticed an exploit. The attacker apparently exploited the bridge between the Ethereum and Solana blockchains. It redirected around $320 million worth of ETH to crypto wallets that don’t belong to the Wormhole team.

A bridge is a combination of smart contracts that facilitate interoperability and transactions between different blockchains. Users typically use a web app to take advantage of a bridge. They connect their wallet with the web app and then initiate a transaction.

Once the transaction is confirmed on the origin blockchain, crypto assets are released on the destination blockchain and transferred to the user wallet. For instance, you can send ETH and receive SOL in exchange.

Yesterday, Wormhole took down its website. “The wormhole network is down for maintenance as we look into a potential exploit,” the team wrote on Twitter.

‼️ The wormhole network is down for maintenance as we look into a potential exploit.

📢 We will provide updates here as soon as we have them.

🙏 Thank you for your patience.

— Wormhole🌪 (@wormholecrypto) February 2, 2022

Crypto analysts quickly noticed two suspicious transactions. The exploiter seemingly found an exploit and minted 120,000 wETH that look like Wormhole’s “wrapped” ETH on the Solana blockchain.

Two minutes later, the exploiter bridged 10,000 ETH to the Ethereum blockchain. Twenty-two minutes later, another 80,000 ETH transaction occurred on the Ethereum blockchain. Once again, it seems like the exploiter moved some of its assets to an Ethereum wallet.

From Wormhole’s perspective, the newly minted wETH appeared as regular wETH. Wormhole released ETH to an Ethereum wallet based on those wETH, so the exploiter essentially stole some ETH from Wormhole’s reserves.

To put this into perspective, 120,000 ETH was worth around $320 million at the time of the transactions — one ETH was worth $2,681. ETH is currently trading at $2,622 at the time of this article, down 2.2% since the exploit.

The Wormhole team later confirmed the exploit. “The wormhole network was exploited for 120k wETH,” the team wrote on Twitter.

The wormhole network was exploited for 120k wETH.

ETH will be added over the next hours to ensure wETH is backed 1:1. More details to come shortly.

We are working to get the network back up quickly. Thanks for your patience.

— Wormhole🌪 (@wormholecrypto) February 2, 2022

In another tweet, Wormhole said that “the vulnerability has been patched.” The bridge is still down as I’m writing this.

The vulnerability has been patched.

We are working to get the network back up as soon as possible.

— Wormhole🌪 (@wormholecrypto) February 3, 2022

It’s unclear what’s going to happen next with the assets and if wETH in Wormhole’s reserves are still backed by ETH. Wormhole initiated a transaction to the exploiter with a note. The Wormhole team is willing to offer $10 million in exchange for the assets. It’s going to be a weird decision.

Here’s what Wormhole wrote:

This is the Wormhole Deployer:

We noticed you were able to exploit the Solana VAA verification and mint tokens. We d like to offer you a whitehat agreement, and present you a bug bounty of $10 million for exploit details, and returning the wETH you ve minted. You can reach out to us at [email protected]

As a seasoned cryptocurrency expert deeply immersed in the intricacies of blockchain technology and decentralized finance, I've not only followed the developments in the space but have actively contributed to discussions, analyses, and implementations within the crypto community. My knowledge extends beyond the surface, delving into the underlying principles that govern blockchain networks and the technologies that support them. This expertise is not just theoretical; I have hands-on experience navigating the complex landscape of various blockchain platforms, including Ethereum and Solana.

Now, let's dissect the key concepts embedded in the provided article about the Wormhole cryptocurrency platform exploit:

  1. Wormhole Exploit Overview:

    • The article reports an exploit on Wormhole, a popular cryptocurrency platform specializing in providing bridges between different blockchains.
    • The attacker exploited the bridge connecting Ethereum and Solana blockchains.
  2. Definition of a Bridge:

    • A bridge, as mentioned, is a combination of smart contracts designed to facilitate interoperability and transactions between distinct blockchains.
    • Users typically interact with a web app to leverage a bridge, connecting their wallet to the app and initiating transactions.
  3. Transaction Process on a Bridge:

    • Users initiate a transaction via a web app.
    • Once confirmed on the origin blockchain (in this case, Ethereum), crypto assets are released on the destination blockchain (Solana) and transferred to the user's wallet.
    • This process allows for the exchange of assets between different blockchains, such as sending Ethereum (ETH) and receiving Solana (SOL) in return.
  4. Exploitation Details:

    • The attacker executed a sophisticated exploit that redirected approximately $320 million worth of Ethereum (ETH) from Wormhole to unauthorized crypto wallets.
    • The exploit involved minting 120,000 wrapped ETH (wETH) on the Solana blockchain, which appeared as regular wETH to Wormhole.
    • The attacker then bridged 10,000 ETH to the Ethereum blockchain and later executed an 80,000 ETH transaction on the same blockchain.
  5. Wormhole's Response:

    • In response to the exploit, Wormhole took down its website for maintenance and confirmed the exploit on Twitter.
    • The team later confirmed the vulnerability, patched it, and initiated efforts to bring the network back up.
  6. Complications and Resolution Efforts:

    • There are uncertainties regarding the status of assets, particularly whether wETH in Wormhole's reserves is still backed by ETH.
    • Wormhole initiated a transaction with the exploiter, offering a $10 million bug bounty in exchange for details about the exploit and the return of the minted wETH.
  7. Ongoing Developments:

    • The article concludes with the bridge still being down at the time of writing, indicating that the situation is still evolving.

This incident underscores the ongoing challenges and security considerations within the cryptocurrency ecosystem, highlighting the importance of robust security measures and continuous vigilance in the face of evolving threats.

Blockchain bridge Wormhole confirms that exploiter stole $320 million worth of crypto assets | TechCrunch (2024)

FAQs

Blockchain bridge Wormhole confirms that exploiter stole $320 million worth of crypto assets | TechCrunch? ›

The attacker apparently exploited the bridge between the Ethereum and Solana blockchains. It redirected around $320 million worth of ETH to crypto wallets that don't belong to the Wormhole team. A bridge is a combination of smart contracts that facilitate interoperability and transactions between different blockchains.

What is a blockchain wormhole? ›

Wormhole supports the seamless transfer of tokens and data across different blockchain networks. This enables applications to operate beyond the confines of a single blockchain, accessing a wider variety of tokens, assets, and data from various chains.

What is the wormhole bridge? ›

Initially developed as a bridge between the Ethereum and Solana blockchains, the Wormhole Solana bridge is an interoperability protocol that facilitates the transfer of information and value across otherwise isolated blockchain networks. The protocol initially bridged the divide between Solana and Ethereum networks.

Is wormhole bridge safe? ›

In Brief. CertiK discovered and patched a $5 million security flaw in Aptos' Wormhole bridge. The flaw allowed anyone to call the 'publish_event' function, potentially enabling fake transactions.

What is a blockchain bridge? ›

Blockchain bridges are protocols that facilitate the transfer of assets and data between different blockchains. They act as intermediaries, navigating the technical and security complexities of disparate networks to enable the frictionless flow of value.

What happens when you enter a wormhole? ›

If you ever happen to fall through a wormhole in space, you won't be coming back. It will snap shut behind you. But you may have just enough time to send a message to the rest of us from the other side, researchers report in the Nov. 15 Physical Review D.

How can I buy wormhole crypto? ›

Create a free account on the Binance website or the app. Binance is a centralized exchange where you can buy several cryptocurrencies including Wormhole. Before you can use the Binance platform, you'll need to open an account and verify your identification. Choose how you want to buy the Wormhole asset.

Has the Wormhole been hacked? ›

On Wednesday, the decentralized finance (DeFi) platform Wormhole became the victim of the largest cryptocurrency theft this year — and among the top five largest crypto hacks of all time — when an attacker exploited a security flaw to make off with close to $325 million.

How to redeem a Wormhole transaction? ›

a) Redeeming:

Go to https://portalbridge.com/#/redeem. You need to enter your source chain and the corresponding transaction id (which you can find in your wallet, or with your address in the blockchains explorer)

What chains does Wormhole bridge support? ›

Wormhole supported blockchains
  • Acala.
  • Algorand.
  • Aptos.
  • Arbitrum.
  • Avalanche (c-chain)
  • Base.
  • Blast.
  • BNB Chain.

What happens when a crypto bridge is hacked? ›

An attacker can take money out of the bridge at the other end if they can create a deposit event without making a real deposit or by making a real deposit, or by depositing with a token that has no value.

How long does a bridge take crypto? ›

How long does an Avalanche Bridge™ transfer take on each network? The Ethereum network transaction will typically take approximately 20 minutes (96 confirmations). The Bitcoin network transaction will typically take approximately 1 hour. The Avalanche network transaction will typically take a few seconds.

What happens to your Bitcoin if you use a token-based bridge to make your Bitcoin operable on Ethereum? ›

Cross-chain bridges don't actually move your BTC from the Bitcoin blockchain to the Ethereum blockchain. Instead, the bridge will create equivalent tokens that represent your BTC but are usable on the Ethereum blockchain.

What is the purpose of a wormhole? ›

A wormhole is like a tunnel between two distant points in our universe that cuts the travel time from one point to the other. Instead of traveling for many millions of years from one galaxy to another, under the right conditions one could theoretically use a wormhole to cut the travel time down to hours or minutes.

Do wormholes actually exist? ›

The throat might be a straight stretch, but it could also wind around, taking a longer path than a more conventional route might require. Einstein's theory of general relativity mathematically predicts the existence of wormholes, but none have been discovered to date.

What happens if you get stuck in a wormhole? ›

Once you cross the event horizon of a wormhole you can no longer reach the exterior, for the same reason that you can't re-enter the exterior of an ordinary black hole. As such, when you've crossed this threshold, you're similarly doomed to meet the singularity within the wormhole.

What is the difference between a wormhole and a black hole? ›

The major distinction between a wormhole and a black hole is that a wormhole is a funnel-shaped space-time tunnel between two points between universes, whereas a black hole is a cosmic body with extreme gravity from which nothing can escape.

Top Articles
What is the Difference between IBC and BCH Code ? - MySeaTime
What Is a Hypervisor? Types, Use Cases, and Career Opportunities
Devotion Showtimes Near Xscape Theatres Blankenbaker 16
Steamy Afternoon With Handsome Fernando
Mylife Cvs Login
Baseball-Reference Com
Natureza e Qualidade de Produtos - Gestão da Qualidade
Missing 2023 Showtimes Near Lucas Cinemas Albertville
Globe Position Fault Litter Robot
Craigslist Estate Sales Tucson
Nitti Sanitation Holiday Schedule
Animal Eye Clinic Huntersville Nc
Best Suv In 2010
How pharmacies can help
Curry Ford Accident Today
Panic! At The Disco - Spotify Top Songs
Finalize Teams Yahoo Fantasy Football
Great Clips Grandview Station Marion Reviews
Craigslist Org Appleton Wi
2487872771
Move Relearner Infinite Fusion
Strange World Showtimes Near Savoy 16
Amerisourcebergen Thoughtspot 2023
Xxn Abbreviation List 2017 Pdf
Chelsea Hardie Leaked
Generator Supercenter Heartland
Delta Math Login With Google
What is Software Defined Networking (SDN)? - GeeksforGeeks
Ewg Eucerin
Ipcam Telegram Group
Calvin Coolidge: Life in Brief | Miller Center
The Monitor Recent Obituaries: All Of The Monitor's Recent Obituaries
Kelley Fliehler Wikipedia
Gus Floribama Shore Drugs
Ridge Culver Wegmans Pharmacy
How does paysafecard work? The only guide you need
Ark Unlock All Skins Command
Selfservice Bright Lending
Hotels Near New Life Plastic Surgery
To Give A Guarantee Promise Figgerits
Leena Snoubar Net Worth
Citibank Branch Locations In Orlando Florida
All Obituaries | Sneath Strilchuk Funeral Services | Funeral Home Roblin Dauphin Ste Rose McCreary MB
Phone Store On 91St Brown Deer
Race Deepwoken
Ihop Deliver
Horseneck Beach State Reservation Water Temperature
Oak Hill, Blue Owl Lead Record Finastra Private Credit Loan
Read Love in Orbit - Chapter 2 - Page 974 | MangaBuddy
Intuitive Astrology with Molly McCord
32 Easy Recipes That Start with Frozen Berries
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 5912

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.