White hat hacker exploits Hashflow for $600K, seemingly just to return funds

요약:White hat hacker exploits Hashflow for $600K, seemingly just to return funds

Multi-chain trading platform Hashflow said on June 14 that it suffered an incident affecting hundreds of thousands in funds.

$600K affected

Hashflow did not explicitly confirm that it had been attacked but said that $600,000 of funds had been affected. It wrote that it is “addressing the current situation” and said that all users who were affected by the incident would be made whole.

The project added that its decentralized exchange (DEX) was not affected by the exploit in any way and said that it would later publish a post-mortem.

Hashflow said that it was originally notified of the exploit by PeckShield, a crypto-security firm. PeckShields notice called the attack an “approve-related issue” and said that $215,000 of ETH and $195,000 in ARB had been stolen for a total of $410,000.

Hashflows later statements estimated a higher loss and also said that funds were stolen on Avalanche, BNB Chain, and Polygon as well.

White hat hacker believed to be responsible

Later posts from Peckshield said that the attack was carried out by a white hat hacker. It highlighted the fact that the hackers contract contains a recovery function.

Hashflow has endorsed the hacker‘s recovery contract in its own instructions. Those instructions tell users to revoke token allowances to deprecated contracts. The instructions then tell users to call the recovery function in the hacker’s contract.

Hashflow noted that the hackers contract allows users to fully recover their funds or optionally donate 10% of their recovered funds to the white hat.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

Orderly Network secures funding from India’s CoinDCX Ventures

다음

27조 달러의 자산, 비트코인과 암호화폐에 몰릴까: 코인쉐어즈 CSO