Hacker Withdraws 200 Billion Fake BitBTC From Optimism Bridge

0

[ad_1]

The Optimism bridge supporting privacy coin BitBTC is actively being exploited for 200 billion BitBTC tokens. 

Due to the technicals of the hack, the BitBTC team now has less than 7 days to implement an upgrade to minimize the damages.

A Poorly Designed Bridge

According to Arbitrum tech lead Lee Bousfield on Twitter, the BitBTC bride contained a “critical exploit” that left it “trivially vulnerable.” It involves the bridge’s relationship between Ethereum’s layer 1 (L1) addresses and Optimism’s layer 2 (L2) addresses. 

As Bousfield explained, Optimism’s L2 side of the bridge lets users withdraw any token, and pick the L1 token address to which the tokens will pass on the L1 side of the bridge. 

However, when the L1 side mints tokens, it simply ignores which token was withdrawn by the layer 2 side in the first place. This means an attacker could mint their own worthless token on Optimism, yet set its L1 token address to a real BitBTC L1 address. 

“Then, when the attacker withdraws their malicious token through the BitBTC bridge, it gives them real BitBTC tokens on L1,” explained Bousfield. 

The tech lead added that the hack would take seven days to conduct – leaving a window of opportunity for devs to patch the system if the exploit were targeted. 

Unfortunately, that’s exactly what happened on Monday, as an attacker withdrew 200 billion fake BitBTC from the system. The dollar value of these tokens is unclear, as BitBTC does not have publicly available market data. 

“The BitBTC team has 7 days to fix it on L1!” warned Bousfield.

The tech lead clarified that the bug is exclusive to BitBTC, rather than being the fault of Optimism. He also said he’s contacted the BitBTC team both before and after the bug took place, but is “still looking for signs of life.”

The exploiter has claimed that his attack is merely meant to test the attack vector. 

The Binance Bridge Bug

In a similar fashion, Binance bridge was exploited earlier this month, allowing a hacker to mint $2 million BNB (worth $500 million) out of thin air. 

Bridges are designed to let crypto users transfer their tokens between different blockchains. While some bridges use centralized/federated systems with trusted third parties to manage the bridge, others use more complex systems based on code. The latter, however, can be prone to bugs that let hackers withdraw illegitimate funds. 

At present, blockchain bridges have been the largest victims of DeFi hacks, accounting for $2.5 billion in lost assets. 

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,295.00
ethereum
Ethereum (ETH) $ 2,935.65
tether
Tether (USDT) $ 0.999627
bnb
BNB (BNB) $ 845.79
xrp
XRP (XRP) $ 1.88
usd-coin
USDC (USDC) $ 0.999723
tron
TRON (TRX) $ 0.283146
staked-ether
Lido Staked Ether (STETH) $ 2,938.95
dogecoin
Dogecoin (DOGE) $ 0.129810
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
cardano
Cardano (ADA) $ 0.360706
whitebit
WhiteBIT Coin (WBT) $ 57.10
bitcoin-cash
Bitcoin Cash (BCH) $ 575.38
wrapped-steth
Wrapped stETH (WSTETH) $ 3,590.95
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,177.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,192.62
usds
USDS (USDS) $ 0.999639
wrapped-eeth
Wrapped eETH (WEETH) $ 3,186.08
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999435
chainlink
Chainlink (LINK) $ 12.20
monero
Monero (XMR) $ 442.55
leo-token
LEO Token (LEO) $ 8.04
weth
WETH (WETH) $ 2,940.27
stellar
Stellar (XLM) $ 0.215640
zcash
Zcash (ZEC) $ 413.75
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,311.00
ethena-usde
Ethena USDe (USDE) $ 0.998737
litecoin
Litecoin (LTC) $ 76.24
hyperliquid
Hyperliquid (HYPE) $ 24.10
sui
Sui (SUI) $ 1.43
avalanche-2
Avalanche (AVAX) $ 12.02
susds
sUSDS (SUSDS) $ 1.08
hedera-hashgraph
Hedera (HBAR) $ 0.110571
dai
Dai (DAI) $ 0.999964
shiba-inu
Shiba Inu (SHIB) $ 0.000007
usdt0
USDT0 (USDT0) $ 0.999706
paypal-usd
PayPal USD (PYUSD) $ 1.00
crypto-com-chain
Cronos (CRO) $ 0.094757
uniswap
Uniswap (UNI) $ 5.71
world-liberty-financial
World Liberty Financial (WLFI) $ 0.131309
the-open-network
Toncoin (TON) $ 1.45
mantle
Mantle (MNT) $ 1.06
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
canton-network
Canton (CC) $ 0.083426
polkadot
Polkadot (DOT) $ 1.75
usd1-wlfi
USD1 (USD1) $ 0.999072
rain
Rain (RAIN) $ 0.007992
bitget-token
Bitget Token (BGB) $ 3.46
memecore
MemeCore (M) $ 1.37
tether-gold
Tether Gold (XAUT) $ 4,464.24
Shares