Cyber sleuth alleges $160M Wintermute hack was an inside job

Share This Post

James Edwards bases his accusations on what he feels are dubious transactions and smart contract code that doesn’t match the post-mortem analysis.

A fresh new crypto conspiracy theory is afoot — this time in relation to last week’s $160 million hack on algorithmic market maker Wintermute — which one crypto sleuth alleges was an “inside job.”

Cointelegraph reported on Sept. 20 that a hacker had exploited a bug in a Wintermute smart contract which enabled them to swipe over 70 different tokens including $61.4 million in USD Coin (USDC), $29.5 million in Tether (USDT) and 671 Wrapped Bitcoin (wBTC), worth roughly $13 million at the time.

In an analysis of the hack posted via Medium on Sept. 26, the author known as Librehash argued that due to the way in which Wintermute’s smart contracts were interacted with and ultimately exploited, it suggests that the hack was conducted by an internal party, claiming:

“The relevant transactions initiated by the EOA [externally owned address] make it clear that the hacker was likely an internal member of the Wintermute team.”

The author of the analysis piece, known also as James Edwards, is not a known cybersecurity researcher or analyst. The analysis marks his first post on Medium but so far hasn’t garnered any response from Wintermute or other cybersecurity analysts.

In the post, Edwards suggests that the current theory is that the EOA “that made the call on the ‘compromised’ Wintermute smart contract was itself compromised via the team’s use of a faulty online vanity address generator tool.”

“The idea is that by recovering the private key for that EOA, the attacker was able to make calls on the Wintermute smart contract, which supposedly had admin access,” he said.

Edwards went on to assert that there’s no “uploaded, verified code for the Wintermute smart contract in question,” making it difficult for the public to confirm the current external hacker theory, while also raising transparency concerns.

“This, in itself, is an issue in terms of transparency on behalf of the project. One would expect any smart contract responsible for the management of user/customer funds that’s been deployed onto a blockchain to be publicly verified to allow the general public an opportunity to examine and audit the unflattened Solidity code,” he wrote.

Edwards then went into a deeper analysis via manually decompiling the smart contract code himself, and alleged that the code doesn’t match with what has been attributed to causing the hack.

Related: Almost $1M in crypto stolen from vanity address exploit

Another point that he raises questions about was a specific transfer that happened during the hack, which “shows the transfer of 13.48M USDT from the Wintermute smart contract address to the 0x0248 smart contract (supposedly created and controlled by the Wintermute hacker).”

Edwards highlighted Etherscan transaction history allegedly showing that Wintermute had transferred more than $13 million worth of Tether USD (USDT) from two different exchanges, to address a compromised smart contract.

“Why would the team send $13 million dollars worth of funds to a smart contract they *knew* was compromised? From TWO different exchanges?,” he questioned via Twitter.

His theory has, however, yet to be corroborated by other blockchain security experts, although following the hack last week, there were some murmurs in the community that an inside job could’ve been a possibility.

Providing an update on the hack via Twitter on Sept. 21, Wintermute noted that while it was “very unfortunate and painful,” the rest of its business has not been impacted and that it will continue to service its partners.

“The hack was isolated to our DeFi smart contract and did not affect any of Wintermute’s internal systems. No third party or Wintermute data was compromised.”

Cointelegraph has reached out to Wintermute for comment on the matter but has not received an immediate response at the time of publication. 

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Crypto.com Acquires SEC-Registered Broker-Dealer Watchdog Capital to Expand US Trading Offerings

Cryptocom announced on Thursday the acquisition of Watchdog Capital, LLC, a broker-dealer registered with the SEC and a member of FINRA and SIPC This acquisition will allow Cryptocom’s new

21Shares Files S-1 With SEC for XRP ETF, Joining Bitwise and Canary Capital in Race for Ripple Investment Product

The post 21Shares Files S-1 With SEC for XRP ETF, Joining Bitwise and Canary Capital in Race for Ripple Investment Product appeared first on Coinpedia Fintech News Joining the ranks of several firms

MicroStrategy’s Bold Bitcoin Strategy: Analysts Raise Price Targets Amid Strong Market Outlook

The post MicroStrategy’s Bold Bitcoin Strategy: Analysts Raise Price Targets Amid Strong Market Outlook appeared first on Coinpedia Fintech News MicroStrategy (MSTR), the software company

MAGA Hat, Trump 47 Pumping as Analyst Says to Buy PolitiFi Coins Like FreeDum Fighters for Potential Trump Win

The post MAGA Hat, Trump 47 Pumping as Analyst Says to Buy PolitiFi Coins Like FreeDum Fighters for Potential Trump Win appeared first on Coinpedia Fintech News The 47th US president will be decided

Pepe, Dogecoin Holders are Investing in Pepe Unchained Presale as Experts Predict 10X Rally

The post Pepe, Dogecoin Holders are Investing in Pepe Unchained Presale as Experts Predict 10X Rally appeared first on Coinpedia Fintech News Liquidity is rotating rapidly from blue chip meme coins

Top Ways to Maximize Your Crypto Earnings in 2024: A Guide to Staking, Yield Farming, and More

The post Top Ways to Maximize Your Crypto Earnings in 2024: A Guide to Staking, Yield Farming, and More appeared first on Coinpedia Fintech News Cryptocurrencies have grown rapidly worldwide Among