Attackers loot $5M from Osmosis in LP exploit, $2M returned soon after

Share This Post

Attackers have exploited a bug in the Osmosis exchange to the tune of $5M as FireStake validators admit to their role in racking up roughly $2M before stepping forward.

Osmosis, a decentralized exchange built on the Cosmos network was halted just before 3am ET on June 8 after attackers exploited a liquidity provider (LP) bug to the tune of roughly $5 million.

The bug was first identified in a Reddit post on the official Cosmos Network page. The user, Straight-Hat3855, brought attention to a “serious problem” with Osmosis (OSMO) that allowed users to arbitrarily grow LPs by 50% simply by adding and removing liquidity. The Reddit post was quickly removed but not before malicious actors took advantage of the bug, which saw approximately $5 million removed from liquidity pools on the Osmosis exchange.

Following the exploit and the identification of the LP bug, the Osmosis exchange was halted at a block height of 4,713,064, according to an announcement from Osmosis block explorer, Mintscan.

Explaining how the bug worked in a series of posts in the Osmosis Discord was project moderator RoboMcGobo, who detailed how the flaw allowed attackers to add liquidity to any Osmosis LP and then immediately withdraw it for a 150% return on their initial deposit: “Essentially, the function would give 50% too many LP shares for a join,” RoboMcGobo wrote just after 4pm on Wednesday, adding: “If one should have gotten 10 LP shares, 15 would be achieved out.”

RoboMcGobo explained that the bug was “exploited intentionally by a small number of users” and “seemingly unintentionally by a few others.” According to a Twitter thread from Osmosis four attackers were responsible for 95% of the total exploit amount, with two of the attackers voluntarily stepping forward to return stolen funds.

Roughly one hour following Osmosis’ tweet concerning the attack, FireStake, a validator in the Cosmos ecosystem, posted a Twitter thread admitting that “a temporary lapse in good judgment” saw two members of its team exploit the bug to the extent of roughly $2 million.

Firestake told their 1,700 Twitter followers that they were “thinking about [their] family’s future” when they continued to exploit the bug. However, after admitting to “stressing through the night” about the event, they decided to voluntarily return the funds and “set things straight.”

According to a post from Osmosis co-founder, Sunny Aggarwal, the other two hackers responsible for the theft made a series of transactions to centralized exchanges, which Aggarwal believes will make it easier to track them down.

RoboMcGobo echoed Aggarwal’s words in the project’s Discord, “Funds have been linked to CEX accounts. Law enforcement has been notified… we’re hopeful that the exploiters will do the right thing here so that aggressive action will not be necessary.”

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitcoin’s Uptober Breakout In Sight: Here Are The Next Potential Critical Levels

October has historically been one of Bitcoin‘s best-performing months, triggering notable price increases over the years Considering the price of BTC this month, several crypto analysts believe

Core Scientific’s AI deal fuels $8.7 billion revenue forecast, shares rise

Bitcoin miner Core Scientific expects to generate roughly $87 billion in revenue over the next 12 years, following an expansion of its hosting agreement with CoreWeave, according to an Oct 22

A Major Improvement to Bitcoin Cash Will Smash Developer Bottlenecks

Andrei Terentiev, CTO of Bitcoincom, explains why Bitcoincom has thrown its full support behind Bitcoin Cash Improvement Proposal 2021-05 CHIP-2021-05 Gains Bitcoincom’s Support With Promise

Bitcoin Cup And Handle Cascade: Analyst Says BTC Price Could Reach $230,000 If It Follows This Structural Path

A crypto analyst has projected a significant break to the upside for Bitcoin, drawing parallels to similar breakouts in traditional assets in the tune of the Gold and the S&P500 According to a

Peter Todd slams HBO for putting his life in danger by calling him Bitcoin’s creator

Canadian cryptographer Peter Todd has entered hiding following the release of an HBO documentary that accuses him of being the elusive creator of Bitcoin, Satoshi Nakamoto, according to an Oct 22

Sky’s Rune Christensen Reveals Star Allocation Proposal—and Possibly a Return to the Old Maker Name

Rune Christensen, founder of Makerdao, has outlined a comprehensive plan for the future of the decentralized finance (defi) ecosystem, highlighting the success of the USDS stablecoin and introducing