Wormhole cryptocurrency platform hacked for $325 million after error on GitHub (2024)

On Wednesday, the decentralized finance (DeFi) platform Wormhole became the victim of the largest cryptocurrency theft this year — andamong the top five largest crypto hacksof all time — when an attacker exploited a security flaw to make off with close to $325 million.

The attack seems to have resulted from a recent update to the project’s GitHub repository, which revealed a fix to a bug that had not yet been deployed to the project itself.

The attack took place on February 2nd and was noticed when a post from the Wormhole Twitter account announced that the network was beingtaken “down for maintenance”while a potential exploit was investigated. Alater postfrom Wormhole confirmed the hack and the amount stolen.

Shortly after the attack, the Wormhole team also offered the hacker a $10 million bounty to return the funds, which was embedded as text in atransactionsent to the attacker’s Ethereum wallet address.

Wormhole provides a service known as a “bridge” between blockchains, essentially an escrow system that allows one type of cryptocurrency to be deposited in order to create assets in another cryptocurrency. This allows a person or entity with holdings in one cryptocurrency to make trades and purchases using another, somewhat like being able to fund a bank account in dollars and then use a bank card to buy something priced in euros.

To carry out the attack, the attacker managed to forge a valid signature for a transaction that allowed them to freely mint 120,000 wETH — a“wrapped” Ethereumequivalent on the Solana blockchain, with value equivalent to $325 million at the time of the theft — without first inputting an equivalent amount. This was then exchanged foraround $250 million in Ethereum that was sent from Wormhole to the hackers’ account, effectively liquidating a large amount of the platform’s Ethereum funds that were being held as collateral for transactions on the Solana blockchain.

Open-source code commits show that code that would have fixed this vulnerability was written as early as January 13th anduploaded to the Wormhole GitHub repositoryon the day of the attack. Just hours later, the vulnerability was exploited by the hacker, suggesting that the updates had not yet been applied to the production application.

As software developer Matthew Garrett observed on Twitter, the code upload was described as if it were a run-of-the-mill version update but actually contained extensive changes — a fact that could have tipped off the attacker to the fact that it was a disguised security fix.

Another file available through the Wormhole Github page alsodetails a security auditconducted by security research company Neodyme between July and September 2021. It is not clear whether the vulnerability was present during the audit period, and Neodyme did not respond to a request for comment.

Due to the nature of cross-chain applications, the attack temporarily left a huge deficit between the amount of wrapped Ethereum and regular Ethereum held in the Wormhole bridge — as if the collateral asset backing a loan had suddenly disappeared. According to Forbes, the attackcaused a 10 percent dropin the value of the Solana cryptocurrency in the aftermath of the hack.

The Wormhole team has announced that more Ethereum will be added to the bridge to replace the stolen collateral funds, effectively meaning that the company will need to find $325 million in assets to plug the gap.

At this stage, it is unclear where the funds will come from. Questions sent to Jump Crypto, parent company of the developers of the Wormhole application, had not received a response at time of publication.

Wormhole cryptocurrency platform hacked for $325 million after error on GitHub (2024)
Top Articles
These Bathroom Trends Are Taking Over 2024
The Intelligent Investor
Terrorist Usually Avoid Tourist Locations
Faint Citrine Lost Ark
Missing 2023 Showtimes Near Cinemark West Springfield 15 And Xd
Big Spring Skip The Games
Beautiful Scrap Wood Paper Towel Holder
Geodis Logistic Joliet/Topco
Craigslist Cars And Trucks Buffalo Ny
Displays settings on Mac
Roblox Character Added
Geometry Escape Challenge A Answer Key
Boat Jumping Female Otezla Commercial Actress
4156303136
Newgate Honda
Blog:Vyond-styled rants -- List of nicknames (blog edition) (TouhouWonder version)
Buy PoE 2 Chaos Orbs - Cheap Orbs For Sale | Epiccarry
Price Of Gas At Sam's
Parent Resources - Padua Franciscan High School
24 Hour Drive Thru Car Wash Near Me
50 Shades Of Grey Movie 123Movies
Danforth's Port Jefferson
Exterior insulation details for a laminated timber gothic arch cabin - GreenBuildingAdvisor
20 Different Cat Sounds and What They Mean
Bennington County Criminal Court Calendar
Slim Thug’s Wealth and Wellness: A Journey Beyond Music
104 Presidential Ct Lafayette La 70503
Powerschool Mcvsd
Feathers
Ullu Coupon Code
Federal Express Drop Off Center Near Me
Imagetrend Elite Delaware
Osrs Important Letter
Helpers Needed At Once Bug Fables
Rush County Busted Newspaper
Prévisions météo Paris à 15 jours - 1er site météo pour l'île-de-France
Babbychula
Pensacola 311 Citizen Support | City of Pensacola, Florida Official Website
Publictributes
Infinite Campus Parent Portal Hall County
Craigslist Florida Trucks
Low Tide In Twilight Manga Chapter 53
The All-New MyUMobile App - Support | U Mobile
Ursula Creed Datasheet
Barstool Sports Gif
Sun Tracker Pontoon Wiring Diagram
Traumasoft Butler
Trending mods at Kenshi Nexus
Tlc Africa Deaths 2021
Parks And Rec Fantasy Football Names
Black Adam Showtimes Near Cinemark Texarkana 14
Latest Posts
Article information

Author: Lilliana Bartoletti

Last Updated:

Views: 5540

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Lilliana Bartoletti

Birthday: 1999-11-18

Address: 58866 Tricia Spurs, North Melvinberg, HI 91346-3774

Phone: +50616620367928

Job: Real-Estate Liaison

Hobby: Graffiti, Astronomy, Handball, Magic, Origami, Fashion, Foreign language learning

Introduction: My name is Lilliana Bartoletti, I am a adventurous, pleasant, shiny, beautiful, handsome, zealous, tasty person who loves writing and wants to share my knowledge and understanding with you.