Hedera confirms exploit on mainnet led to theft of service tokens

0

[ad_1]

Hedera, the team behind distributed ledger Hedera Hashgraph, has confirmed a smart contract exploit on the Hedera Mainnet that has led to the theft of several liquidity pool tokens.

Hedera said the attacker targeted liquidity pool tokens on decentralized exchanges (DEXs) that derived its code from Uniswap v2 on Ethereum, which was ported over for use on the Hedera Token Service.

The Hedera team explained that the suspicious activity was detected when the attacker attempted to move the stolen tokens across the Hashport bridge, which consisted of liquidity pool tokens on SaucerSwap, Pangolin and HeliSwap. Operators acted promptly to temporarily pause the bridge.

Hedera didn’t confirm the amount of tokens that were stolen.

On Feb. 3, Hedera upgraded the network to convert Ethereum Virtual Machine (EVM)-compatible smart contract code onto the Hedera Token Service (HTS).

Part of this process involves the decompiling of Ethereum contract bytecode to the HTS, which is where Hedera-based DEX SaucerSwap believes the attack vector came from. However, Hedera didn’t confirm this in its most recent post.

Earlier, Hedera managed to shut down network access by turning off IP proxies on March 9. The team said it has identified the “root cause” of the exploit and is “working on a solution.”

“Once the solution is ready, Hedera Council members will sign transactions to approve the deployment of updated code on mainnet to remove this vulnerability, at which point the mainnet proxies will be turned back on, allowing normal activity to resume,” the team added.

A notice posted by Hedera on its status webpage cautioned users that its network would not be accessible. Source: Hedera

Since Hedera turned off proxies shortly after it found the potential exploit, the team suggested tokenholders check the balances on their account ID and Ethereum Virtual Machine (EVM) address on hashscan.io for their own “comfort.”

Related: Hedera Governing Council to buy hashgraph IP and open-source project’s code

The price of the network’s token Hedera (HBAR) has fallen 7% since the incident roughly 16 hours ago, in line with the broader market fall over the last 24 hours.

However, the total value locked (TVL) on SaucerSwap fell nearly 30% from $20.7 million to $14.58 million over the same timeframe:

The TVL on SaucerSwap fell sharply following the news of the exploit. Source: DefiLlama

The fall suggests a significant amount of tokenholders acted quickly and withdraw their funds following the initial discussion of a potential exploit.

The incident has potentially spoiled a major milestone for the network, with the Hedera Mainnet surpassing 5 billion transactions on March 9.

This appears to be the first reported network exploit on Hedera since it was launched in July 2017.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 88,155.00
ethereum
Ethereum (ETH) $ 2,976.83
tether
Tether (USDT) $ 0.999617
bnb
BNB (BNB) $ 853.03
xrp
XRP (XRP) $ 1.92
usd-coin
USDC (USDC) $ 0.999800
solana
Solana (SOL) $ 125.96
tron
TRON (TRX) $ 0.280089
staked-ether
Lido Staked Ether (STETH) $ 2,978.16
dogecoin
Dogecoin (DOGE) $ 0.131634
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
cardano
Cardano (ADA) $ 0.375873
whitebit
WhiteBIT Coin (WBT) $ 57.58
bitcoin-cash
Bitcoin Cash (BCH) $ 595.48
wrapped-steth
Wrapped stETH (WSTETH) $ 3,637.82
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,893.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,234.30
usds
USDS (USDS) $ 0.999802
wrapped-eeth
Wrapped eETH (WEETH) $ 3,226.56
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999363
chainlink
Chainlink (LINK) $ 12.60
monero
Monero (XMR) $ 453.86
leo-token
LEO Token (LEO) $ 8.39
weth
WETH (WETH) $ 2,976.54
zcash
Zcash (ZEC) $ 448.04
stellar
Stellar (XLM) $ 0.219050
hyperliquid
Hyperliquid (HYPE) $ 24.98
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 88,150.00
ethena-usde
Ethena USDe (USDE) $ 0.998790
litecoin
Litecoin (LTC) $ 76.87
sui
Sui (SUI) $ 1.46
avalanche-2
Avalanche (AVAX) $ 12.25
hedera-hashgraph
Hedera (HBAR) $ 0.112447
susds
sUSDS (SUSDS) $ 1.07
shiba-inu
Shiba Inu (SHIB) $ 0.000007
usdt0
USDT0 (USDT0) $ 0.999465
dai
Dai (DAI) $ 0.999145
uniswap
Uniswap (UNI) $ 6.21
paypal-usd
PayPal USD (PYUSD) $ 0.999739
mantle
Mantle (MNT) $ 1.17
crypto-com-chain
Cronos (CRO) $ 0.096035
world-liberty-financial
World Liberty Financial (WLFI) $ 0.134291
the-open-network
Toncoin (TON) $ 1.49
canton-network
Canton (CC) $ 0.098986
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
polkadot
Polkadot (DOT) $ 1.83
aave
Aave (AAVE) $ 181.40
usd1-wlfi
USD1 (USD1) $ 0.999024
rain
Rain (RAIN) $ 0.007630
bitget-token
Bitget Token (BGB) $ 3.45
Shares