Whitehat Returns $190K to Renegade After Hacking Them
The white hat hacker sent more than 90% of the stolen funds back within 45 minutes and said in response to the onchain message that the action was taken to protect DeFi users: “I‘ve seen a lot of contempt toward my actions. Although I understand that what I did was not ethical, in the current DeFi cybersecurity, I believe this was the best solution to protect users’ funds and ensure their safety.” The white hat hacker also hinted that Renegade should tighten up its security measures, stating that the vulnerability exploited was “tooooo simple and bad.” North Korean state-backed hackers “would never come to negotiate,” they added. Renegade said the exploit appeared to have resulted from the deployment code failing to assign an explicit owner and from a faulty migration in an April 2025 software update, enabling anyone to rewrite the smart contract tied to its V1 Arbitrum dark pool. Dark pools are private trading platforms that allow large trades to occur without exposing their intentions to, or impacting, the broader market. Renegade added that it would publish a post-mortem with a “full root-cause analysis” explaining the security incident. Renegade said it would fully compensate affected users, and that only 7% of its trading volume was channeled