Munchables recovers $62.5 million in user funds after exploit linked to North Korean hacker

Share This Post

Munchables, a web3 game operating on the Ethereum layer-2 network Blast, has successfully recovered the $62.5 million it recently lost to an exploit.

The platform disclosed that the attacker voluntarily provided all relevant private keys to facilitate the return of user funds. The keys holding the $62.5 million worth of ETH, 73 WETH, and the main owner key were shared.

Pacman, the founder of the layer-2 network, corroborated this development, stating that the hacker returned all stolen funds without demanding any ransom.

Furthermore, Pacman announced that $97 million had been safeguarded in a multisig account controlled by Blast’s core contributors. These funds will soon be redistributed to Munchables and other affected protocols.

He added:

“It’s important that all dev teams, whether directly affected or not, learn from this and take precautions to be more thorough on security.”

The exploit

On March 26, Munchables alerted the crypto community about an exploit on its platform. On-chain investigator ZachXBT promptly identified the address holding the pilfered 17,413 ETH.

According to ZachXBT’s findings, the exploit occurred due to the involvement of a North Korean hacker among Munchables’ core developers.

Further investigation by ZachXBT showed that Munchables had engaged four developers linked to the hacker. Their GitHub usernames were NelsonMurua913, Werewolves0493, BrightDragon0719, and Super1114.

These four accounts likely belonged to a single individual, as they endorsed each other for the job and financially supported each other’s wallets.

Solidity developer 0xQuit said the hacker executed the exploit by creating a backdoor to allocate a balance of 1,000,000 ETH before upgrading the contract implementation. This enabled them to withdraw once the protocol accumulated a significant balance.

North Korean hackers

This incident sheds light on a common tactic employed by North Korean hackers who infiltrate crypto projects as developers and embed backdoors to facilitate future theft.

Ethereum developer Keone Hon referenced an earlier thread outlining signs that a developer might be a North Korean hacker. According to him, these individuals often favor GitHub names such as SupertalentedDev726 or CryptoKnight415, incorporate numbers into their usernames and emails, and use Japanese identities.

He said:

“If you see someone with a cringe bio, a bunch of badges, and a bunch of big repos with only 1 commit (due to squashing the history) just be cautious.”

The post Munchables recovers $62.5 million in user funds after exploit linked to North Korean hacker appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

B2BROKER’s B2TRADER Gets a Major Update with C-Book Routing, Flexible Markups, and Mobile Trading

PRESS RELEASE B2BROKER has released a new version of its multi-asset and multi-market trading platform, B2TRADER The latest release, B2TRADER 22, introduces significant improvements designed to

6 Must-Grab Picks: Crypto Fans Are Flocking to the Best Crypto Presale of the Year Promising Mind-Blowing Returns!

The post 6 Must-Grab Picks: Crypto Fans Are Flocking to the Best Crypto Presale of the Year Promising Mind-Blowing Returns! appeared first on Coinpedia Fintech News Have you ever wondered why

$TRUMP Coin Predicted to Hit $50, While Ozak AI Aims to Reach $1 Before Dogecoin

The post $TRUMP Coin Predicted to Hit $50, While Ozak AI Aims to Reach $1 Before Dogecoin appeared first on Coinpedia Fintech News The $TRUMP Coin, a cryptocurrency associated with the 45th President

Uniswap’s Nemesis 1FUEL Launches Taking Big Investment From NEAR Protocol Holders In January

The post Uniswap’s Nemesis 1FUEL Launches Taking Big Investment From NEAR Protocol Holders In January appeared first on Coinpedia Fintech News Over the years, Uniswap and NEAR Protocol have

China’s 194,000 Bitcoin Completely Sold, Claims CryptoQuant CEO

CryptoQuant CEO and founder Ki Young Ju has stated that Chinese authorities have already liquidated a massive trove of BTC originally tied to the PlusToken scam Posting on X (formerly Twitter) on

Solana Price Prediction Today (24th January 2025)

The post Solana Price Prediction Today (24th January 2025) appeared first on Coinpedia Fintech News The cryptocurrency market has achieved another huge milestone as Donald Trump, President of the