$20M exploit cripples Sonne Finance, hacker in no mood for negotiation

cyptouser2 months agoCryptocurrencies News41
55966e89>

Lending protocol Sonne Finance was forced to pause operations after suffering a hack that drained $20 million worth of cryptocurrencies from the market.

On May 14, around 10:30 pm UTC, Web3 security firm Cyvers detected an ongoing attack on Sonne Finance’s USD Coin (USDC) and Wrapped Ether (WETH) contracts.

However, when Sonne Finance became aware of the situation 25 minutes later, the hacker had already stolen $20 million in WETH, VELO (VELO), soVELO and Wrapped USDC (USDC.e).

Source: Sonne Finance

On May 15 at 12:11 am UTC, Sonne Finance announced on X that “All markets on Optimism have been paused.” Soon after, the protocol partnered with Cyvers to investigate the situation further.

Sonne is currently exploring all options to retrieve the stolen funds, including negotiating a bug bounty for the hacker. In such situations, the hacker returns most of the stolen funds and keeps roughly 10% of the loot as a reward for finding a security flaw.

However, the hacker seems to be in no mood for negotiations. According to blockchain investigator PeckShield, the exploiter has already moved a large chunk of the loot ($7.8 million) to a new wallet address.

Source: PeckShield

The exploiter then swapped 59 WBTC for roughly 1,185 ETH and 183,000 Dai (DAI). The move suggests an intent to siphon the stolen funds through a privacy protocol like Tornado Cash to deter traceability.

Sonne Finance’s post-mortem found that a donation attack was conducted on Sonne’s Compound v2 forks, which had a known bug, according to X community member PoorBabyCorn.

They accused Sonne Finance of using Compound v2 despite knowing the risks and asked, “If this isn’t a premeditated backdoor, what is?”

In parallel, the main hedge fund of crypto institutional investment firm BlockTower Capital has reportedly been exploited and partially drained.

The funds have not been recovered, and BlockTower has employed blockchain forensic analysts to trace the funds and determine how they were breached. The exploiter has also not been arrested, Bloomberg reported on May 15, citing people familiar with the matter.

Related: Stolen Poloniex Ether worth $53M never made it back to the exchange

Its partners have been informed about the incident. It reportedly has $1.7 billion in assets under management.

BlockTower did not immediately respond to Cointelegraph’s request for comment.

In February last year, BlockTower seemingly lost around $1.5 million in the $2 million exploit of the multichain exchange aggregator Dexible.

Dexible said that around 85% of the stolen funds were from a “few big whales.” On-chain intelligence platform Arkham Intelligence labeled a wallet drained of $1.5 million as belonging to BlockTower.

Magazine: ‘Sic AIs on each other’ to prevent AI apocalypse: David Brin, sci-fi author

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Spanish central bank finalizes partners for wholesale CBDC pilot

The Bank of Spain’s selection of Cecabank, Abanca, and Adhara Blockchain for its wholesale central b...

FBI warns US citizens against using 'unregistered crypto money transmitting services'

The FBI advised US citizens against using unregistered crypto services to transmit assets on April 2...

Crypto firms raised $2.5 billion in Q1, representing 29% quarterly increase

Galaxy reported an assortment of VC investment data, including nearly $2.5 billion invested in the f...

Winklevoss twins receive refund of over $300k from Trump’s campaign

Cameron and Tyler Winklevoss have been collectively refunded around $310,800 by the Trump 47 Committ...

Arbitrum daily revenue surges 16,500% after LayerZero’s ZRO launch

Arbitrum daily revenue surges 16,500% after LayerZero’s ZRO launch

55966e89˃LayerZero’s token launch on June 20 caused a massive surge in fees on Arbitrum, leading to...

Biden's mining tax is the least sensible part of his 2025 budget proposal

Biden's mining tax is the least sensible part of his 2025 budget proposal

1205f261˃President Biden in March released his budget proposal for fiscal year 2025. In it, he propo...