{"id":6780,"date":"2022-02-03T06:38:00","date_gmt":"2022-02-03T06:38:00","guid":{"rendered":"http:\/\/egrowonline.com\/?p=6780"},"modified":"2022-02-03T06:38:00","modified_gmt":"2022-02-03T06:38:00","slug":"wormhole-token-bridge-loses-321m-in-largest-hack-so-far-in-2022","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=6780","title":{"rendered":"Wormhole token bridge loses $321M in largest hack so far in 2022"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-128018ef=\"\">\n<p>The Wormhole token bridge experienced a security exploit today, resulting in the loss of 120,000 wETH tokens ($321 million) from the platform.<\/p>\n<p>Wormhole is a token bridge that allows users to send and receive crypto between Ethereum, Solana, BSC, Polygon, Avalanche, Oasis, and Terra without the use of a centralized exchange (CEX). This is the largest crypto hack of 2022 so far and the second largest DeFi hack to date. The Wormhole team has offered a $10M bug bounty for the return of the funds. <\/p>\n<p>The hack took place on the Solana side of the bridge and there are fears Wormhole\u2019s bridge to Terra could be similarly vulnerable.<\/p>\n<p>The Wormhole team has assured the community that its <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/ethereum-price\" rel=\"noopener\">ETH<\/a> supply would be replenished to \u201censure wETH is backed 1:1,\u201d but there is no word yet on where those funds will come from or when.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">The wormhole network was exploited for 120k wETH. <\/p>\n<p>ETH will be added over the next hours to ensure wETH is backed 1:1. More details to come shortly.<\/p>\n<p>We are working to get the network back up quickly. Thanks for your patience.<\/p>\n<p>\u2014 Wormhole (@wormholecrypto) <a target=\"_blank\" href=\"https:\/\/twitter.com\/wormholecrypto\/status\/1489001949881978883?ref_src=twsrc%5Etfw\" rel=\"noopener\">February 2, 2022<\/a><\/p><\/blockquote>\n<p>The <a target=\"_blank\" href=\"https:\/\/solscan.io\/tx\/2zCz2GgSoSS68eNJENWrYB48dMM1zmH8SZkgYneVDv2G4gRsVfwu5rNXtK5BKFxn7fSqX9BvrBc1rdPAeBEcD6Es\" rel=\"noopener nofollow\">hack<\/a> took place at 6:24pm UTC on Feb. 2. The attacker minted 120,000 wETH (WETH) on Solana, then <a target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x24c7d855a0a931561e412d809e2596c3fd861cc7385566fd1cb528f9e93e5f14\" rel=\"noopener nofollow\">redeemed<\/a> 93,750 WETH for ETH worth $254 million onto the Ethereum network at 6:28pm UTC. The hacker has since used some funds to buy SportX (SX), Meta Capital (MCAP), Finally Usable Crypto Karma (FUCK), and Bored Ape Yacht Club Token (APE).<\/p>\n<p>The <a target=\"_blank\" href=\"https:\/\/solscan.io\/account\/CxegPrfn2ge5dNiQberUrQJkHCcimeR4VXkeawcFBBka#splTransfers\" rel=\"noopener nofollow\">remaining<\/a> WETH was swapped for <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/solana-price-index\" rel=\"noopener\">SOL<\/a> and <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/usdc-price-index\" rel=\"noopener\">USDC<\/a> on Solana. The hacker\u2019s Solana wallet currently holds 432,662 SOL ($44 million). <\/p>\n<p>No other assets or chains served by Wormhole have been reported affected, but <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/certik-s-identification-of-crypto-cars-as-rug-pull-was-a-false-alarm\" rel=\"noopener\">smart contract auditing firm Certik<\/a> said in a report today that \u201cIt is possible that Wormhole\u2019s bridge to the Terra blockchain shares the same vulnerability as their Solana bridge.\u201d<\/p>\n<p>The Wormhole team contacted the hacker through their Ethereum address to offered to let the hacker keep $10 million worth of funds stolen if the remaining funds are returned.<\/p>\n<p>\u201cThis is the Wormhole Deployer: We noticed you were able to exploit the Solana VAA verification and mint tokens. We\u2019d like to offer you a whitehat agreement, and present you a bug bounty of $10 million for exploit details, and returning the wETH you\u2019ve minted. You can reach out to us at contact@certus.one\u201d<\/p>\n<p>As of the time of writing, wETH tokens sent across the bridge are not yet redeemable while the Wormhole team attempts to fix the exploit.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2022-02\/50720678-298a-4878-ac3e-28aae430a576.PNG\" \/><\/figure>\n<p>This is the second smart contract exploit on a token bridge in a week. On Jan. 28, Qubit Finance\u2019s <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/qubit-finance-suffers-80-million-loss-following-hack\" rel=\"noopener\">QBridge was exploited<\/a> for $80 million on BSC. It is also reminiscent of the <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/poly-network-hack-exposes-defi-flaws-but-community-comes-to-the-rescue\" rel=\"noopener\">Poly Network hack<\/a> last August wherein $610 million in crypto was stolen off the platform. In that case, nearly all of the funds were returned by the whitehat hacker.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/2-5b-in-stolen-btc-from-bitfinex-hack-awakens\" rel=\"noopener\"><strong><em>$2.5B in stolen BTC from Bitfinex hack awakens<\/em><\/strong><\/a><\/p>\n<p>The frequency of smart contract hacks on token bridges serves to validate Vitalik Buterin\u2019s Jan. 7 <a target=\"_blank\" href=\"https:\/\/old.reddit.com\/r\/ethereum\/comments\/rwojtk\/ama_we_are_the_efs_research_team_pt_7_07_january\/hrngyk8\/\" rel=\"noopener nofollow\">warning<\/a> that there are \u201cfundamental security limits of bridges.\u201d The Ethereum co-founder\u2019s admonition was within the context of a 51% attack on Ethereum, but his advice was well-timed as he pointed out the general vulnerability apparent on bridges that send tokens across layer-1 blockchains. <\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/wormhole-token-bridge-loses-321m-in-largest-hack-so-far-in-2022\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Wormhole token bridge experienced a security exploit today, resulting in the loss of 120,000 wETH tokens ($321 million) from the platform. Wormhole is a token bridge that allows users to send and receive crypto between Ethereum, Solana, BSC, Polygon, Avalanche, Oasis, and Terra without the use of a centralized exchange (CEX). This is the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6781,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[41],"tags":[4566,4438,517,1170,774,452,4562],"class_list":["post-6780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-321m","tag-bridge","tag-hack","tag-largest","tag-loses","tag-token","tag-wormhole"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/02\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMDIvMGY4ODU5NTctMDBkOS00ODRjLTgzNGUtZTIzZTBmMWY2MmQ0LmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/6780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6780"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/6780\/revisions"}],"predecessor-version":[{"id":6782,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/6780\/revisions\/6782"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/6781"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6780"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}