Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Decentralized exchange Velocore addresses $7 million hack in postmortem, offers bounty to hacker

The BlockThe Block2024/06/02 17:13
By:The Block

Quick Take Decentralized exchange Velocore was hacked for around $7 million in tokens last night when a user exploited a vulnerability in the logic governing the exchange’s smart contracts. The hack led the Linea blockchain team to halt block production, which has since resumed. Velocore has offered a 10% bug bounty to the hacker, who has yet to respond.

Decentralized exchange Velocore, which operates on the Telos, zkSync Era, and Linea blockchains, was exploited for about $6.8 million in tokens last night through a vulnerability in the smart contracts which control its liquidity pools.

A hacker was able to exploit the vulnerability in overflow logic in order to trick Velocore into turning a small withdrawal into a large deposit. With the help of a flash loan, the hacker was able to drain Velocore's "volatile pools" on zkSync Era and Linea, though the team was able to safeguard its assets on Telos. "Stable pools" were unaffected.

"Despite undergoing multiple audits and implementing preventive features to ensure security, this unexpected incident happened swiftly. We are deeply saddened and sincerely apologize to our users who have trusted us," Velocore wrote in its post-mortem . Velocore has also disabled the logic flaw used in the exploit, eliminating the chance of a copycat attack.

The incident led the ConsenSys-built Linea Ethereum Layer 2 network to temporarily pause its block production in an unsuccessful attempt to mitigate the losses from the attack.

"Because other avenues of handling this exploit closed, our team halted the sequencer to prevent additional funds bridging out. This was the last resort action to protect users on Linea," the protocol wrote on X . While Linea stated its goal was to eventually take away the ability to halt the network from its team once significant decentralization had occurred, the protocol defended the decision to halt the chain. "Most L2s, including Linea, still rely on centralized technical operations which can be leveraged to protect ecosystem participants. Linea's core value is a permissionless, censorship-resistant environment so it was not a decision we took lightly," the protocol wrote .

Velocore has reached out to the hacker with a message offering a 10% white hat bounty for the return of the remainder of the funds by June 3, 8:00 UTC. The hacker has yet to respond, though the hacker has since deposited about 1700 eth, worth about $7 million, to cryptocurrency mixer Tornado Cash. Velocore, in its postmortem, promised, "For those affected, we have taken a snapshot of the blockchain state prior to the incident. Once operations resume, we will implement an appropriate compensation plan to address the losses incurred to our users."


2

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

Crypto losses from hacks and scams soared by 113% in Q2 2024 to reach $572M

Cointelegraph2024/07/01 17:43

Shiba Inu (SHIB) vs. Ethereum: Analysts Explore Potential for 40x Gains

Coinedition2024/07/01 16:58

VeChain (VET) Surges 11% in a Week: Analysts Predict Further Gains

Coinedition2024/07/01 16:58

EU crypto traders urged to convert non-compliant stablecoins to regulated ones as MiCA framework takes effect

Quick Take EU stablecoin users are urged to convert non-compliant stablecoins to regulated ones as the bloc’s MiCA regulation goes live. The new regulations prohibit stablecoins from exceeding one million daily transactions used to pay for goods or services, whether settled off-chain or on-chain.

The Block2024/07/01 16:52

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
9916.91%
ROI
Total profit $50576.23
WhaleGo_YouTube
WhaleGo_YouTube
insight500/500
1321.82%
ROI
Total profit $3838.06

Bot copy trading

More
Morgee
Morgee
insight69/150
$19751.22
Total profit
Total subscriber profits $-219.74
GoldenEgg
GoldenEgg
insight141/150
$8163.06
Total profit
Total subscriber profits $-284.87