ThorChain loses up to $7.6M in ‘Chaosnet’ exploit, offers hacker a bounty to return funds

ThorChain loses up to $7.6M in ‘Chaosnet’ exploit, offers hacker a bounty to return funds


Popular cross-chain decentralized exchange, ThorChain, has suffered a multi-million dollar breach.Estimates as to the scale of the damage vary, with ThorChain revising the initial estimate that 13,000 ETH (worth $25.1 million) had been stolen, down to 4,000 ETH (roughly $7.6 million) as a ballpark for damages. A subsequent, community-provided rundown of stolen assets suggests the figure is closer to $6M.At this stage the estimate is around ~4000 ETH worth of assets (ETH/ERC20) was taken, not 13k ETH. More detailed assessment and recovery steps will be announced soon. The users who suffered (LPs) will be made whole in the coming weeks. https://t.co/LR2x8VZ2kx— THORChain #ACTIVATETHESYNTHS⚡️ (@THORChain) July 15, 2021

In the ThorChain community Telegram channel, administrators have indicated the project has the funds needed to cover users’ stolen assets, but articulated a preference for the hacker to return the stolen funds in exchange for a bug bounty.“While the treasury has the funds to cover the stolen amount, we request the attacker get in contact with the team to discuss return of funds and a bounty commensurate with the discovery,” a Telegram post stated, adding that user funds “will be available when the issue has been patched & the network resumes.”ThorChain has since tweeted that its preliminary roadmap to recovery is underway, announcing that after the vulnerability is patched and the network restarted, Ether will be donated to liquidity provider pools to reimburse impacted users. From there, the team plans to engage security firms to have its contracts audited. As of this writing, the ThorChain network remains halted.This is a disappointing moment for all, but LPs and Nodes should be unaffected after all is recovered (the funds will be restored). The network will be stronger and more resilient.— THORChain #ACTIVATETHESYNTHS⚡️ (@THORChain) July 16, 2021

Blockchain cybersecurity firm, Halborn Security, is compiling a proposal to the ThorChain community for “Advance Persistent Protection,” offering up a team of up to half a dozen “ethical security engineers working to break every update on ThorChain.”Related: A RUNE with a view: How smart crypto traders caught a 48% price pumpThorchain entered into its guarded “Chaosnet” launch during April, facilitating cross-chain swaps across the Bitcoin, Ethereum, Litecoin, Bitcoin Cash, and Binance Chain networks.DeFi Watch founder Chris Blec said the staged “raise the caps” launch of ThorChain had prevented an even greater loss of funds.Keep in mind – THORchain has been responsibly using a guarded launch approach to its rollout. This exploit could have been *much worse* if they had just recklessly launched without caps on its liquidity pools.— Chris Blec (@ChrisBlec) July 15, 2021

Today’s attack is not the first time ThorChain has been targeted by hackers during its Chaosnet deployment, with the protocol losing at least $140,000 worth of assets last month.

bitcoin
Bitcoin (BTC) $ 61,356.44
ethereum
Ethereum (ETH) $ 3,389.88
tether
Tether (USDT) $ 0.999689
bnb
BNB (BNB) $ 575.08
solana
Solana (SOL) $ 136.26
staked-ether
Lido Staked Ether (STETH) $ 3,388.49
usd-coin
USDC (USDC) $ 1.00
xrp
XRP (XRP) $ 0.478459
the-open-network
Toncoin (TON) $ 7.59
dogecoin
Dogecoin (DOGE) $ 0.123392
cardano
Cardano (ADA) $ 0.387531
tron
TRON (TRX) $ 0.120141
shiba-inu
Shiba Inu (SHIB) $ 0.000017
avalanche-2
Avalanche (AVAX) $ 25.31
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 61,465.47
chainlink
Chainlink (LINK) $ 14.07
polkadot
Polkadot (DOT) $ 5.81
bitcoin-cash
Bitcoin Cash (BCH) $ 377.08
uniswap
Uniswap (UNI) $ 9.46
near
NEAR Protocol (NEAR) $ 5.59
wrapped-eeth
Wrapped eETH (WEETH) $ 3,523.20
leo-token
LEO Token (LEO) $ 5.75
matic-network
Polygon (MATIC) $ 0.569346
litecoin
Litecoin (LTC) $ 70.78
dai
Dai (DAI) $ 0.999409
pepe
Pepe (PEPE) $ 0.000012
fetch-ai
Fetch.ai (FET) $ 1.70
internet-computer
Internet Computer (ICP) $ 8.16
kaspa
Kaspa (KAS) $ 0.156601
ethena-usde
Ethena USDe (USDE) $ 1.00
ethereum-classic
Ethereum Classic (ETC) $ 23.51
renzo-restaked-eth
Renzo Restaked ETH (EZETH) $ 3,417.71
aptos
Aptos (APT) $ 6.96
render-token
Render (RNDR) $ 7.75
monero
Monero (XMR) $ 162.41
hedera-hashgraph
Hedera (HBAR) $ 0.079061
cosmos
Cosmos Hub (ATOM) $ 6.97
arbitrum
Arbitrum (ARB) $ 0.828916
stellar
Stellar (XLM) $ 0.090599
filecoin
Filecoin (FIL) $ 4.43
okb
OKB (OKB) $ 41.50
mantle
Mantle (MNT) $ 0.762210
crypto-com-chain
Cronos (CRO) $ 0.090777
immutable-x
Immutable (IMX) $ 1.59
blockstack
Stacks (STX) $ 1.62
injective-protocol
Injective (INJ) $ 23.06
first-digital-usd
First Digital USD (FDUSD) $ 1.00
sui
Sui (SUI) $ 0.902441
lido-dao
Lido DAO (LDO) $ 2.43
the-graph
The Graph (GRT) $ 0.223945