Wormhole token bridge loses $321M in largest hack so far in 2022

Share This Post

The token bridge between Ethereum and Solana saw 120K wETH tokens removed from the platform and distributed between the hacker’s Solana and ETH wallets.

The Wormhole token bridge experienced a security exploit today, resulting in the loss of 120,000 wETH tokens ($321 million) from the platform.

Wormhole is a token bridge that allows users to send and receive crypto between Ethereum, Solana, BSC, Polygon, Avalanche, Oasis, and Terra without the use of a centralized exchange (CEX). This is the largest crypto hack of 2022 so far and the second largest DeFi hack to date. The Wormhole team has offered a $10M bug bounty for the return of the funds.

The hack took place on the Solana side of the bridge and there are fears Wormhole’s bridge to Terra could be similarly vulnerable.

The Wormhole team has assured the community that its ETH supply would be replenished to “ensure wETH is backed 1:1,” but there is no word yet on where those funds will come from or when.

The hack took place at 6:24pm UTC on Feb. 2. The attacker minted 120,000 wETH (WETH) on Solana, then redeemed 93,750 WETH for ETH worth $254 million onto the Ethereum network at 6:28pm UTC. The hacker has since used some funds to buy SportX (SX), Meta Capital (MCAP), Finally Usable Crypto Karma (FUCK), and Bored Ape Yacht Club Token (APE).

The remaining WETH was swapped for SOL and USDC on Solana. The hacker’s Solana wallet currently holds 432,662 SOL ($44 million).

No other assets or chains served by Wormhole have been reported affected, but smart contract auditing firm Certik said in a report today that “It is possible that Wormhole’s bridge to the Terra blockchain shares the same vulnerability as their Solana bridge.”

The Wormhole team contacted the hacker through their Ethereum address to offered to let the hacker keep $10 million worth of funds stolen if the remaining funds are returned.

“This is the Wormhole Deployer: We noticed you were able to exploit the Solana VAA verification and mint tokens. We’d like to offer you a whitehat agreement, and present you a bug bounty of $10 million for exploit details, and returning the wETH you’ve minted. You can reach out to us at [email protected]

As of the time of writing, wETH tokens sent across the bridge are not yet redeemable while the Wormhole team attempts to fix the exploit.

This is the second smart contract exploit on a token bridge in a week. On Jan. 28, Qubit Finance’s QBridge was exploited for $80 million on BSC. It is also reminiscent of the Poly Network hack last August wherein $610 million in crypto was stolen off the platform. In that case, nearly all of the funds were returned by the whitehat hacker.

Related: $2.5B in stolen BTC from Bitfinex hack awakens

The frequency of smart contract hacks on token bridges serves to validate Vitalik Buterin’s Jan. 7 warning that there are “fundamental security limits of bridges.” The Ethereum co-founder’s admonition was within the context of a 51% attack on Ethereum, but his advice was well-timed as he pointed out the general vulnerability apparent on bridges that send tokens across layer-1 blockchains.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitcoin Price Pauses, Eyeing a Fresh Increase: Can Bulls Deliver?

Bitcoin price corrected gains and tested the $61,850 zone BTC is consolidating and might aim for a fresh increase above the $62,500 resistance Bitcoin is holding gains above the $61,850 zone The

Ethereum Fundamentals Hint At Upside Potential As Staking Hits 29% High

Ethereum is at a critical juncture after failing to break above the $2,500 mark yesterday, leaving investors uncertain about its next move As the broader crypto market anticipates a rally, Ethereum

Cardano Price Prediction: Analyst Forecasts ADA Price Rocket To $5

Despite its recent lacklustre price performance, market experts remain extremely bullish about the Cardano price prospects Notably, a crypto analyst has forecasted that Cardano, which is currently

Putin Reveals Over 85% of CIS Trade Now in National Currencies

Russian President Vladimir Putin announced that more than 85% of trade within the Commonwealth of Independent States (CIS) is now conducted in national currencies, highlighting a move toward greater

Solana Trader Turns $800 Into $10 Million In Unreal Meme Coin Trade, Here’s How

A Solana (SOL) trader who initially invested a mere $800 in the popular Solana-based meme coin, Moo Deng, has realized unreal gains, with profits soaring to approximately $10 million However, despite

XRP Army Launches Petition Against SEC Appeal in Ripple Case

The XRP Army is ramping up efforts to push back against the US Securities and Exchange Commission (SEC)’s appeal in the Ripple lawsuit, calling it unnecessary and damaging to the