Hedera confirms exploit on mainnet led to theft of service tokens

요약:A possible smart contract exploit on Hedera caused it to close access to the ledger, with the team confirming the network is not affected.

Hedera, the team behind distributed ledger Hedera Hashgraph, has confirmed a smart contract exploit on the Hedera Mainnet that has led to the theft of several liquidity pool tokens.

Hedera said the attacker targeted liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over to use on the Hedera Token Service.

Today, attackers exploited the Smart Contract Service code of the Hedera mainnet to transfer Hedera Token Service tokens held by victims accounts to their own account. (1/6)

— Hedera (@hedera) March 10, 2023

The Hedera team explained that the suspicious activity was detected when the attacker attempted to moved the stolen tokens across the Hashport bridge, which consisted of liquidity pool tokens on SaucerSwap, Pangolin and HeliSwap. However, operators then acted promptly to temporarily pause the bridge.

Hedera didn't confirm the amount of tokens that were stolen.

On Feb. 3, Hedera upgraded the network to convert Ethereum Virtual Machine (EVM)-compatible smart contract code onto the Hedera Token Service (HTS).

Part of this process involves the decompiling of Ethereum contract bytecode to the HTS, which is where Hedera-based DEX SaucerSwap believes the attack vector came from. However, Hedera didn't confirm this in its most recent post.

Earlier, Hedera managed to shut down network access by turning off IP proxies on Mar. 9. The team said it has identified the “root cause” of the exploit and is “working on a solution.”

To prevent the attacker from being able to steal more tokens, Hedera turned off mainnet proxies, which removed user access to the mainnet. The team has identified the root cause of the issue and are working on a solution. (5/6)

— Hedera (@hedera) March 10, 2023

“Once the solution is ready, Hedera Council members will sign transactions to approve the deployment of updated code on mainnet to remove this vulnerability, at which point the mainnet proxies will be turned back on, allowing normal activity to resume,” the team added.

Since Hedera turned off proxies shortly after it found the potential exploit, the team suggested token holders check the balances on their account ID and Ethereum Virtual Machine (EVM) address on hashscan.io for their own “comfort.”

All HashPack functionality will be unavailable during this downtime https://t.co/ngaRmg00Zi

— HashPack Wallet (@HashPackApp) March 9, 2023

The price of the network's token Hedera (HBAR) has fallen 7% since the incident roughly 16 hours ago, in line with the broader market fall over the last 24 hours.

However, the total value locked (TVL) on SaucerSwap fell nearly 30% from $20.7 million to $14.58 million over the same timeframe:

The fall suggests a significant amount of token holders acted quickly and withdraw their funds following the initial discussion of a potential exploit.

The incident has potentially spoiled a major milestone for the network, with the Hedera Mainnet surpassing 5 billion transactions on Mar. 9.

#Hedera: 5 BILLION mainnet transactions!

Real transactions. Real applications. Real-world #utility. Are you watching?

We are witnessing #DLT adoption on an unprecedented scale.

This is only the beginning. pic.twitter.com/n0TbWTJmC0

— Hedera (@hedera) March 8, 2023

This appears to be the first reported network exploit on Hedera since it was launched in July 2017.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

SelfKey Releases AI and zk-Based Solutions for Safer Digital Verification

다음

DaoMaker’s Degen Zoo Builds The Abandoned Logan Paul Game in 30 Days