{"id":24980,"date":"2022-08-05T03:12:56","date_gmt":"2022-08-05T03:12:56","guid":{"rendered":"http:\/\/egrowonline.com\/?p=24980"},"modified":"2022-08-05T03:12:56","modified_gmt":"2022-08-05T03:12:56","slug":"altcoins-affected-by-nomad-hack-collapsed-as-much-as-94","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=24980","title":{"rendered":"Altcoins Affected By Nomad Hack Collapsed As Much As 94%"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n                <!-- image --><\/p>\n<div class=\"td-post-featured-image\">\n                                                            <img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"493\" class=\"entry-thumb\" src=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-768x493.png\" alt=\"Altcoins Affected By Nomad Hack Collapsed As Much As 94%\" title=\"Altcoins Affected By Nomad Hack Collapsed As Much As 94%\" \/>\n                                                    <\/div>\n<p>The most recent in a series of <a target=\"_blank\" href=\"https:\/\/www.valuewalk.com\/a-quick-look-at-what-defi-is-and-how-it-operates\/\" rel=\"noopener\">DeFi<\/a> hacks happened less than 36 hours ago to the Nomad project. The ambitious dApp promised cross-chain interoperability with \u201cincreased safety\u201c, giving developers the option to \u201csecurely build cross-chain applications (or xApps) and bridge assets between chains\u201d. It was namely this feature that got exploited, letting hackers and allegedly random users on public Discord servers drain over $190 million worth of cryptocurrencies through the project\u2019s bridging Smart Contract in what is dubbed as the \u201cFirst Decentralized Robbery\u201c.<\/p>\n<p>\t<!-- Begin Mailigen Signup Form --><\/p>\n<div id=\"MG-placeholder\">\n<div style=\"background:#eee;overflow:hidden;margin-bottom:24px;padding:40px\">\n<div class=\"two-thirds first\">\n<p style=\"font-size:22px;margin:0 0 10px\">Get The Full Series in PDF<\/p>\n<p style=\"line-height:1.4;margin-bottom:0\">Get the entire 10-part series on Charlie Munger in PDF. Save it to your desktop, read it on your tablet, or email to your colleagues.<\/p>\n<\/div>\n<div class=\"one-third\">\n<img decoding=\"async\" src=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2017\/06\/Warren-Buffet-Charlie-Munger-ValueWalk-compound-interest.jpg\" alt=\"Charlie Munger eBook\" style=\"width:100%;height:auto\" \/><img decoding=\"async\" class=\"lazyload\" src=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2017\/06\/Warren-Buffet-Charlie-Munger-ValueWalk-compound-interest.jpg\" alt=\"Charlie Munger eBook\" style=\"width:100%;height:auto\" \/>\n<\/div>\n<\/div>\n<\/div>\n<p><!-- End Mailigen Signup Form --><\/p>\n<p style=\"text-align: center\"><a target=\"_blank\" href=\"https:\/\/valuewalkpremium.com\/q2-2022-hedge-fund-letters-database-maverick-loeb-southpoint-odey-greenlight-carlson-exoduspoint-and-many-more-last-updated-75\/\" rel=\"noopener\"><em><strong>Q2 2022 hedge fund letters, conferences and more<\/strong><\/em><\/a><\/p>\n<p>\u00a0<\/p>\n<div class=\"vwp_ext_post\">\n<p>Statar Capital Is Still Enjoying A Healthy YTD Return Despite June Setbacks [Exclusive]<\/p>\n<p><img decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-1024x678.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"invest Southpoint Capital\" loading=\"lazy\" style=\"float:left;margin:0 15px 15px 0\" srcset=\"https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-1024x678.jpg 1024w, https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-768x509.jpg 768w\" \/><img decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-1024x678.jpg\" class=\"lazyload attachment-large size-large wp-post-image\" alt=\"invest Southpoint Capital\" loading=\"lazy\" style=\"float:left;margin:0 15px 15px 0\" srcset=\"https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-1024x678.jpg 1024w, https:\/\/valuewalkpremium.com\/wp-content\/uploads\/2021\/12\/invest_1639495597-768x509.jpg 768w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>Statar Capital generated a net return of 0.21% for June, bringing its year-to-date return to 23.72% for 2022. Since its inception, the commodity fund has generated a return of 352.88%. Statar Capital has $3.5 billion in assets under management. The fund reported a daily correlation of -0.04 to the S&amp;P 500 and 0.04 to the  <a target=\"_blank\" href=\"https:\/\/valuewalkpremium.com\/this-commodity-fund-is-still-enjoying-a-sizable-ytd-return-despite-june-setbacks\/\" rel=\"noopener\">Read More<\/a><\/div>\n<p>Our <a target=\"_blank\" href=\"https:\/\/www.bestbrokers.com\/2022\/08\/03\/altcoins-affected-by-nomad-hack-collapsed-as-much-as-94\/\" data-auth=\"NotApplicable\" data-linkindex=\"3\" data-ogsc=\"\" rel=\"nofollow noopener\"><span data-ogsc=\"rgb(28, 128, 255)\">Analyst Team at BestBrokers<\/span><\/a> started looking into Blockchain data, related to the hack, in the first hours after the news broke. Our goal was to build the timeline of what happened and diagnose the repercussions. We identified the first 4 hack transactions occurring on 1 August at 21:32:31 UTC, draining the Smart Contract of 100 Bitcoins each. This continued until all 1028 BTC were siphoned off within less than an hour. The hackers then proceeded to divert all 22,880 Ethers, then moved on to the over $107M worth of stablecoins and finally started diverting the altcoins, supported by the project, until there was nothing left in the contract.<\/p>\n<p>This event logically dragged crypto prices down but unlike the established <a target=\"_blank\" href=\"https:\/\/www.valuewalk.com\/best-performing-cryptocurrencies-in-july-2022\/\" rel=\"noopener\">cryptocurrencies<\/a> (BTC and ETH) and stablecoins, some altcoins that were involved suffered as much as 94% decline. Our team got a deeper look into the most affected cryptocurrencies \u2013 CARD.STARTER (CARDS), Charli3 (C3), Covalent (CQT), IAGON (IAG), and GeroWallet (GERO):<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins.png\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2443522\" src=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins.png\" alt=\"Altcoins \" width=\"1170\" height=\"751\" srcset=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins.png 1170w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-300x193.png 300w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-768x493.png 768w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-696x447.png 696w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-1068x686.png 1068w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-654x420.png 654w\" \/><img loading=\"lazy\" decoding=\"async\" class=\"lazyload aligncenter size-full wp-image-2443522\" src=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins.png\" alt=\"Altcoins \" width=\"1170\" height=\"751\" srcset=\"https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins.png 1170w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-300x193.png 300w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-768x493.png 768w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-696x447.png 696w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-1068x686.png 1068w, https:\/\/www.valuewalk.com\/wp-content\/uploads\/2022\/08\/Altcoins-654x420.png 654w\" data-sizes=\"(max-width: 1170px) 100vw, 1170px\" \/><\/a><\/p>\n<h2><span id=\"What_Happened\">What Happened?<\/span><\/h2>\n<p>Just a few days after the cross-chain messaging protocol, Nomad, announced the participants in their $22.4 million seed round of April 2022, again highlighting the importance of security, the company went from hero to zero \u2013 literally. On 2 August the company reported the latest DeFi hack which led to the company\u2019s entire capital being drained. The interesting part is that the whole event could be witnessed live on Twitter, as crypto influencers were reporting as the hack went on.<\/p>\n<p>The hackers took advantage of a wrongly-initialized merkle root, used in cryptocurrencies to ensure that data blocks sent through a peer-to-peer network are whole and unaltered. Nomad\u2019s bridging <a target=\"_blank\" href=\"https:\/\/www.valuewalk.com\/the-seven-top-dexs-for-seven-top-blockchains\/\" rel=\"noopener\">Smart Contract<\/a> in its current version was initialized with the 0x0 merkle root, effectively auto-proving any transaction message to be valid.<\/p>\n<h2><span id=\"The_Writing_Was_On_The_Wall\">The Writing Was On The Wall?<\/span><\/h2>\n<p>The ironic part is that allegedly a similar vulnerability to the one that just got exploited was highlighted in a Security Audit Report done by Quantstamp on 6\/6\/2022. It can be found under \u201cQSP-19 Proving With An Empty Leaf\u201d on page 7 of the still publicly available report and is deemed as \u201cLow Risk\u201d. By the update under the recommendation it is evident that the Nomad team have been made aware of the vulnerability and even responded to Quantstamp\u2019s suggestion with \u201cWe consider it to be effectively impossible to find the preimage of the empty leaf\u201d. The auditors\u2019 comment is reading \u201cWe believe the Nomad team has misunderstood the issue.\u201d The issue in the audit highlighted the possibility for some invalid transactions to be validated unrightfully. What happened in the hack was that due to a wrongly-set merkle root (the number used to \u201cprove\u201d valid transactions) in Nomad\u2019s current Smart Contract ALL transactions were in essence auto-validated.<\/p>\n<h2><span id=\"The_First_Decentralized_Robbery\">The First Decentralized Robbery<\/span><\/h2>\n<p>An interesting aspect of this particular vulnerability is the fact that in order to exploit it, anyone could just copy the initial hacker\u2019s transaction calldata (the data you pass to a Smart Contract) and just modify the destination wallet address to their own. That way it was just a matter of Copy-Pasting the original transaction for anyone to start draining Nomad\u2019s Smart Contract. It is reported that at some point after the original hackers took out all BTC, ETH and part of the stablecoins the hack was touted on some public Discord servers. This is believed to be done by the hackers in order to cover their tracks and soon after random users started joining in on the loot, turning this into the First Decentralized Robbery.<\/p>\n<p>This included some Whitehats that did so just in order to save part of the funds from getting into the wrong hands. They pledged they would return the funds later.<\/p>\n<p>All of the altcoins involved in the heist took serious damage. Despite the great losses, some of them saw strong recoveries with CQT price going from -57% to -26% compared to the pre-hack levels. On the other hand C3 (-93%) has a long way to recover as their prices recovered to -54% at some point but dropped again to -86% currently.\u201c<em>When such significant drops occur, the way back proves to be way too hard for most of the affected assets. Although cryptocurrencies are more volatile and cannot be just written off, the most suffering coins from this hack will most probably have a hard time getting back to previous levels.\u201d<\/em> \u2013 comments Alan Goldberg, analyst at BestBrokers.<\/p>\n<p>The established Ether and <a target=\"_blank\" href=\"https:\/\/www.valuewalk.com\/is-bitcoin-just-a-crisis-currency-or-something-more\/\" rel=\"noopener\">Bitcoin<\/a> suffered a decrease between 3% and 5% which can be considered as normal volatility and they have recovered. This proves that prices of newly released altcoins related to DeFi are way more vulnerable.<\/p>\n<p>On the other hand, Ether proves to become more solid as time passes which is great news for investors who seek not only security but also usability of their crypto assets.<\/p>\n<p>\u201c<em>While in the past hacks were targeting exchanges and were affecting mainly the Bitcoin price, nowadays\u2019 attacks are aimed mostly at DeFi. This year\u2019s DeFi hacks dragged down a lot of altcoins but not the Ether, which proves it is getting closer to Bitcoin in terms of trust.<\/em>\u201d &#8211; commented Alan Goldberg, analyst at BestBrokers.<\/p>\n<p class=\"post-modified-info\">Updated on Aug 4, 2022, 4:32 pm<\/p>\n<p>     <!-- PLACE THIS CODE INSIDE WIDGET LOCATION ON YOUR PAGE -->               <!-- PLACE THIS CODE INSIDE WIDGET LOCATION ON YOUR PAGE -->      <\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.valuewalk.com\/altcoins-affected-by-nomad-hack-collapsed-as-much-as-94\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The most recent in a series of DeFi hacks happened less than 36 hours ago to the Nomad project. The ambitious dApp promised cross-chain interoperability with \u201cincreased safety\u201c, giving developers the option to \u201csecurely build cross-chain applications (or xApps) and bridge assets between chains\u201d. It was namely this feature that got exploited, letting hackers and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24981,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[42],"tags":[7753,200,907,517,5405],"class_list":["post-24980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-altcoins","tag-affected","tag-altcoins","tag-collapsed","tag-hack","tag-nomad"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/08\/Altcoins.png","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/24980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24980"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/24980\/revisions"}],"predecessor-version":[{"id":24982,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/24980\/revisions\/24982"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/24981"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24980"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}